Z6×ðÁú¿­Ê±ADLab£ºÐÛÂõ¶à¸öÉãÏñÍ·Îó²îÖÒÑÔ¼°ÐÞ¸´£¨¸½¹¤¾ß£©

Ðû²¼Ê±¼ä 2018-10-19
 Ò»¡¢¸ÅÊö 

¿ËÈÕ£¬ £¬£¬£¬£¬ÍâÑóÇå¾²Ñо¿Ö°Ô±¹ûÕæÁËÐÛÂõ²úÆ·µÄ¶à¸öÇå¾²Îó²î£¨CVE-2018-17915¡¢CVE-2018-17917¡¢CVE-2018-17919£©£¬ £¬£¬£¬£¬ÕâЩÎó²î¿ÉÓ°ÏìÐÛÂõ¹«Ë¾µÄÖ÷ÒªÉãÏñÍ·²úÆ·¼°Ïà¹ØµÄÉãÏñÍ·Ä£×é ¡£¡£¡£¡£¡£¡£Í¨¹ýÕâЩÎó²î£¬ £¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ýÄÚÍâÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢Ìᳫ´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ ¡£¡£¡£¡£¡£¡£


ͨ¹ýCVE-2018-17915£¨ÔÆÆ½Ì¨×°±¸ÐòÁкÅÐÅϢй¶£©ºÍCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©µÄ×éºÏ£¬ £¬£¬£¬£¬Ö»Òª×°±¸ÄÜ»á¼û»¥ÁªÍø£¬ £¬£¬£¬£¬¹¥»÷Õ߾ͿÉÒÔÔ¶³Ì¶ÔÄÚÍø×°±¸Ìᳫ¹¥»÷£¬ £¬£¬£¬£¬Ê¹µÃCVE-2018-17919µÄÎó²îÓ°ÏìÃæ½øÒ»²½À©´ó ¡£¡£¡£¡£¡£¡£


Ϊ°ü¹Ü¹«¹²Çå¾²£¬ £¬£¬£¬£¬Z6×ðÁú¿­Ê±ADLab½¨Ò飺


  • ÔÚÎó²îδÍêÈ«ÐÞ¸´Ç°£¬ £¬£¬£¬£¬×°±¸Ê¹Ó÷½Ó¦ÏÞÖÆÎÊÌâ×°±¸µÄ»¥ÁªÍø»á¼ûȨÏÞ ¡£¡£¡£¡£¡£¡£
  • ÔÚ¹ûÕæµÄÎó²îÖÐÓ°Ïì×î´óµÄÊÇCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©£¬ £¬£¬£¬£¬ÏÖÔÚÎó²îÒѾ­¹ûÕæ£¬ £¬£¬£¬£¬´ó×ÚµÄÔÚÍø×°±¸Êܵ½Çå¾²Íþв£»£»£»Z6×ðÁú¿­Ê±ADLabµÚһʱ¼äÐû²¼ÁËCVE-2018-17919Îó²îÐÞ¸´¹¤¾ß£¬ £¬£¬£¬£¬Ïà¹ØÓû§Ç뾡¿ì¿ÉʹÓô˹¤¾ß¶ÔÎó²î¾ÙÐмì²âÓëÐÞ¸´ ¡£¡£¡£¡£¡£¡£

 ¶þ¡¢Îó²îÓ°ÏìÃæ 

ƾ֤2018Äê3ÔÂCNCERTÐû²¼µÄ¡¶ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ¡·£¬ £¬£¬£¬£¬ÐÛÂõÒÔ6.25%µÄÕ¼±ÈÃûÁÐÈ«ÇòµÚËÄ£»£»£»Í¬Ê±£¬ £¬£¬£¬£¬ÐÛÂõÉãÏñÍ·Ä£×鼯»®±»´ó×Ú³§É̽ÓÄÉ£¬ £¬£¬£¬£¬½ö²¿·ÖÖªÏþµÄOEM³§¼ÒºÍÖÇÄܼҾӳ§¼ÒÒÑÁè¼Ý°Ù¼Ò£»£»£»Òò´Ë³ýÐÛÂõÆ·ÅÆÍ⣬ £¬£¬£¬£¬ÆäËûÆ·ÅÆµÄÉãÏñÍ·Ïà¹Ø×°±¸Ò²Ó¦ÒýÆð¸ß¶ÈÖØÊÓ ¡£¡£¡£¡£¡£¡£Æ¾Ö¤¼à²âÊý¾Ý£¬ £¬£¬£¬£¬ÏÖÔÚÊÜÓ°ÏìµÄÔÚÍø×°±¸ÊýÄ¿ÔÚ°ÙÍòÒÔÉÏ ¡£¡£¡£¡£¡£¡£


Z6¡¤×ðÁú¿­Ê±¡¸ÖйúÇø¡¹¹Ù·½ÍøÕ¾

²¿·Ö½ÓÄÉÐÛÂõ¼Æ»®µÄ³§¼Ò
Êý¾ÝȪԴ£ºhttps://github.com/tothi/pwn-hisilicon-dvr


 Èý¡¢Îó²îÏÈÈÝ 


ÐÛÂõÊÇ2016ÄêmiraiľÂí´ó¹æÄ£DDoS¹¥»÷ÊÂÎñµÄÖ÷ÒªÊÜÓ°Ïì³§¼Ò£¬ £¬£¬£¬£¬½üÆÚÍâÑóÇå¾²Ñо¿Ö°Ô±ÐÂÐû²¼µÄÏà¹ØÎó²îÇéÐÎÈçÏ£º


CVE񅧏
ÎÊÌâ
Σº¦
CVE-2018-17915
ÔÆÆ½Ì¨µÄ×°±¸ÐòÁкſÉÒÔͨ¹ý×°±¸µÄMACµØµãÍÆËã³ö
¹¥»÷Õß¿ÉÒÔͨ¹ýÐÛÂõ×°±¸µÄMACµØµãÍÆËã³ö×°±¸µÄÔÆÆ½Ì¨ÕË»§£¬ £¬£¬£¬£¬²¢¿ÉÒÔ»ñµÃÕË»§µÄÔÚÏßÇéÐÎ ¡£¡£¡£¡£¡£¡£
ÎÞ
adminÓû§±£´æ³õʼÃÜÂë
ÔÚ×îÖÕÓû§Ã»ÓÐÐÞ¸ÄadminÓû§³õʼÃÜÂëµÄÇéÐÎÏ£¬ £¬£¬£¬£¬¸Ã³õʼÃÜÂë¿ÉÒÔ±»¹¥»÷ÕßÔ¶³ÌʹÓ㬠£¬£¬£¬£¬ÍêÈ«¿ØÖÆÉãÏñÍ·£¬ £¬£¬£¬£¬×°ÖöñÒâÈí¼þ ¡£¡£¡£¡£¡£¡£
CVE-2018-17919
ÄÚÖÃdefaultÕË»§
¹¥»÷Õß¿ÉʹÓÃdefaultÕË»§¼°ÆäÄÚÖõÄÃÜÂ룬 £¬£¬£¬£¬Ô¶³ÌÇÔÌýÊÓÆµÔ´ ¡£¡£¡£¡£¡£¡£
CVE-2018-17917
ͨѶͨµÀȱÉÙÓÐÓõļÓÃܱ£»£»£»¤
¹¥»÷Õß¿Éͨ¹ý¼àÌýÉãÏñÍ·µÄÍøÂçͨѶ£¬ £¬£¬£¬£¬»ñÈ¡ÉãÏñÍ·µÄÊÓÆµµã²¥µØµã£¬ £¬£¬£¬£¬´Ó¶øÇÔÌýÊÓÆµÔ´ºÍÓû§Éϰ¶Æ¾Ö¤ ¡£¡£¡£¡£¡£¡£
ÎÞ
¹Ì¼þµÄÍêÕûÐÔ¼°Çå¾²ÐÔȱÉÙÓÐÓñ£»£»£»¤»úÖÆ
¹¥»÷Õß¿ÉÔÚ»ñµÃÉϰ¶Æ¾Ö¤µÄÇéÐÎÏ£¬ £¬£¬£¬£¬½á¹¹¶ñÒâ¹Ì¼þ£¬ £¬£¬£¬£¬´Ó¶øÈÃÉãÏñÍ·Ö´ÐÐí§ÒâÏÂÁî ¡£¡£¡£¡£¡£¡£

ÒÔÉÏÎó²î£¬ £¬£¬£¬£¬Z6×ðÁú¿­Ê±ADLab¾ùÔÚÏà¹ØÐͺŵÄ×îй̼þ°æ±¾ÉϾÙÐÐÁËÑéÖ¤ ¡£¡£¡£¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬Í¨¹ý¶Ô³§¼ÒµÄ¹ÙÍøÉÏÆäËûÐͺŵĹ̼þ¾ÙÐÐÆÊÎö£¬ £¬£¬£¬£¬·¢Ã÷Ïà¹ØÎó²îÎÊÌâÔÚÆäËû°²·ÀÉãÏñÍ·µÄÐͺÅÉÏÒ²±£´æ£¬ £¬£¬£¬£¬Îó²îÓ°Ïì¹æÄ£½ÏÁ¿ÆÕ±é ¡£¡£¡£¡£¡£¡£ÂÄÀúÖ¤£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÄÚÍâÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂ롢ʹÓÃÎó²îÌᳫ´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ ¡£¡£¡£¡£¡£¡£


 ËÄ¡¢Îó²îÓ¦¶ÔÕ½ÂÔ½¨Òé 


4.1 CVE-2018-17919Îó²î¼ì²âÓëÐÞ¸´

4.1.1 Îó²îÔ­Àí

ÔÚÉãÏñÍ·¹Ì¼þµÄÏà¹Øº¯ÊýÖб£´æÎÊÌâ´úÂ룬 £¬£¬£¬£¬ÐÛÂõÉãÏñÍ·ÔÚ³ö³§ÉèÖÃʱԤÖÃÁËdefaultÕʺż°Ä¬ÈÏÃÜÂ룬 £¬£¬£¬£¬¸ÃÕ˺ÅÔÚ¿Í»§¶ËÎÞ·¨¾ÙÐÐɾ³ý£¬ £¬£¬£¬£¬Ò²²»»áÏÔʾÔÚ¿Í»§¶Ë ¡£¡£¡£¡£¡£¡£


4.1.2 Îó²î¼ì²âÓëÐÞ¸´


Õë¶Ô´ËÎó²î£¬ £¬£¬£¬£¬Z6×ðÁú¿­Ê±ADLabµÚһʱ¼äÐû²¼ÁËÎó²îÐÞ¸´¹¤¾ß£¬ £¬£¬£¬£¬Ïà¹ØÓû§¿ÉʹÓøù¤¾ß¾ÙÐмì²âÓëÐÞ¸´ ¡£¡£¡£¡£¡£¡££¨ÇëÔÚ¹«ÖÚºÅÖз¢ËÍÒªº¦´Ê£ºXM¹¤¾ß£¬ £¬£¬£¬£¬»ñÈ¡ÐÞ¸´¹¤¾ß ¡£¡£¡£¡£¡£¡£ÈçʹÓÃÖÐÓöµ½ÎÊÌ⣬ £¬£¬£¬£¬Ç뽫װ±¸Ðͺź͹̼þ°æ±¾ºÅ¼û¸æÎÒÃÇ£©


1.ÏÂÔØfix_tools.exe ¡£¡£¡£¡£¡£¡£


2.ÔÚ¿ØÖÆÌ¨£¬ £¬£¬£¬£¬Ö´ÐÐfix_tools.exe camera_ip username password£¬ £¬£¬£¬£¬ÆäÖÐcamera_ip²ÎÊýΪÉãÏñÍ·IP£¬ £¬£¬£¬£¬usernameΪÉãÏñÍ·AdminÓû§Ãû£¬ £¬£¬£¬£¬passwordΪAdminÓû§ÃÜÂë ¡£¡£¡£¡£¡£¡£

È磺fix_tools.exe 192.168.0.88 admin 123456


3. ÈôÊDZ£´æÎó²î£¬ £¬£¬£¬£¬Ôò»áÌáÐÑ£º
[*] vuln(cve-2018-17919) found!¡±
[*] Do you want to fix it?(y/n):

ÊäÈëy,¼´×îÏÈÐÞ¸´Îó²î ¡£¡£¡£¡£¡£¡£


4. ÈôÊÇÎó²îÐÞ¸´Àֳɣ¬ £¬£¬£¬£¬Ôò»áÌáÐÑ £º
[*] vuln fix success!!!!!!!!!

×¢ÖØ£ºµ±Óû§¶ÔÉãÏñÍ·¾ÙÐлָ´³ö³§ÉèÖÃʱ£¬ £¬£¬£¬£¬ÓÉÓÚdefaultÕË»§ÖØÐ±»¹Ì¼þдÈ룬 £¬£¬£¬£¬Óû§ÐèÒªÖØÐÂÖ´ÐÐfix_tools¹¤¾ßÐÞ¸´ ¡£¡£¡£¡£¡£¡£


5. ÈôÊÇÄ¿µÄ×°±¸²»±£´æ¸ÃÎó²î£¬ £¬£¬£¬£¬Ôò»áÌáÐÑ£º
[!] vuln not found


ÐÞ¸´¹¤¾ßÔÚÒÔÏÂ×°±¸²âÊÔͨ¹ý£º
[*] HardWare= RM50H20L_8188EU_S38 
SoftWareVersion= V4.02.R12.C4420813.10002.144002.00000
[*] HardWare= 53H13-E_18EV200_8188EU_S38

SoftWareVersion= V4.02.R12.A6420240.10002.140802.00000


4.2 ÆäËûÎó²î»º½âÒªÁì

Ϊ°ü¹Ü¹«¹²Çå¾²£¬ £¬£¬£¬£¬Ê£ÓàÎó²îµÄ¼ì²âÒªÁìÔݲ»¹ûÕæ£»£»£»Ïà¹ØÓû§¿É²Î¿¼ÈçÏ»º½â½¨Ò飬 £¬£¬£¬£¬Ó¦¶Ô¿ÉÄܱ¬·¢µÄ¹¥»÷ÊÂÎñ£º


  • ͨ¹ý¿Í»§¶Ë¶ÔadminÓû§ÉèÖÃÖØ´óÃÜÂ룬 £¬£¬£¬£¬±ÜÃâadminȨÏÞ±»¹¥»÷Õß»ñµÃ ¡£¡£¡£¡£¡£¡£
  • ͨ¹ý·ÓÉÆ÷ÉèÖÃÏÞÖÆÕ½ÂÔ£¬ £¬£¬£¬£¬¹Ø±ÕÉãÏñÍ·µÄ»¥ÁªÍø»á¼ûȨÏÞ£¬ £¬£¬£¬£¬Ö»ÄÜͨ¹ýÄÚÍø»á¼ûÉãÏñÍ· ¡£¡£¡£¡£¡£¡£
  • ÔÚ³§¼ÒÌṩеÄÎó²î²¹¶¡ºó£¬ £¬£¬£¬£¬ÊµÊ±¸üÐÂÉãÏñÍ·¹Ì¼þ²¹¶¡ ¡£¡£¡£¡£¡£¡£



²Î¿¼Á´½Ó£º

¡¾1¡¿ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂçÇå¾²Ì¬ÊÆ±¨¸æ
https://www.ics-cert.org.cn/portal/page/131/be9def54499644afb6ce4b119e5e7d42.html
¡¾2¡¿ÃÀ¹ú¹¤Òµ»¥ÁªÍøÇå¾²ÏìÓ¦ÖÐÐÄͨ¸æ
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06