8827Ì«Ñô¼¯ÍÅADLab£ºÐÛÂõ¶à¸öÉãÏñÍ··ì϶ÖҸ漰½¨¸´£¨¸½¹¤¾ß£©

°ä²¼¹¦·ò 2018-10-19
 Ò»¡¢¸ÅÊö 

½üÈÕ£¬ £¬£¬£¬£¬£¬¹ú±í°²È«×êÑÐÈËÔ±¹«¿ªÁËÐÛÂõ²úÆ·µÄ¶à¸ö°²È«·ì϶£¨CVE-2018-17915¡¢CVE-2018-17917¡¢CVE-2018-17919£©£¬ £¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÓ°ÏìÐÛÂõ¹«Ë¾µÄÖØÒªÉãÏñÍ·²úÆ·¼°ÓйصÄÉãÏñÍ·Ä£×é¡£¡£¡£¡£ ¡£Í¨¹ýÕâЩ·ì϶£¬ £¬£¬£¬£¬£¬¶ñÒâ¹¥»÷ÕßÄܹ»Í¨¹ýÄÚ±íÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£¡£¡£¡£ ¡£


ͨ¹ýCVE-2018-17915£¨ÔÆÆ½Ì¨É豸ÐòÁкÅÐÅϢй¶£©ºÍCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©µÄ×éºÏ£¬ £¬£¬£¬£¬£¬Ö»ÓÐÉ豸ÄܽӼû»¥ÁªÍø£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¾ÍÄܹ»Ô¶³Ì¶ÔÄÚÍøÉ豸ÌáÒé¹¥»÷£¬ £¬£¬£¬£¬£¬Ê¹µÃCVE-2018-17919µÄ·ì϶ӰÏìÃæ½øÒ»²½À©´ó¡£¡£¡£¡£ ¡£


Ϊ±£ÏÕ¹«¹²°²È«£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab½¨Ò飺


  • ÔÚ·ì϶δÆëÈ«½¨¸´Ç°£¬ £¬£¬£¬£¬£¬É豸ʹÓ÷½Ó¦ÏÞ¶ÈÎÊÌâÉ豸µÄ»¥ÁªÍø½Ó¼ûȨÏÞ¡£¡£¡£¡£ ¡£
  • ÔÚ¹«¿ªµÄ·ì϶ÖÐÓ°Ïì×î´óµÄÊÇCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©£¬ £¬£¬£¬£¬£¬Ä¿Ç°·ì϶ÒѾ­¹«¿ª£¬ £¬£¬£¬£¬£¬´óÁ¿µÄÔÚÍøÉ豸Êܵ½°²È«Íþв£»£» £»£»£»8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò°ä²¼ÁËCVE-2018-17919·ì϶½¨¸´¹¤¾ß£¬ £¬£¬£¬£¬£¬ÓйØÓû§Ç뾡¿ì¿ÉʹÓô˹¤¾ß¶Ô·ì϶½øÐмì²âÓ뽨¸´¡£¡£¡£¡£ ¡£

 ¶þ¡¢·ì϶ӰÏìÃæ 

ƾ¾Ý2018Äê3ÔÂCNCERT°ä²¼µÄ¡¶ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨¡·£¬ £¬£¬£¬£¬£¬ÐÛÂõÒÔ6.25%µÄÕ¼±ÈÃûÁÐÈ«ÇòµÚËÄ£»£» £»£»£»Í¬Ê±£¬ £¬£¬£¬£¬£¬ÐÛÂõÉãÏñÍ·Ä£×鹿»®±»´óÁ¿³§ÉÌѡȡ£¬ £¬£¬£¬£¬£¬½ö²¿ÃÅͨ´ïµÄOEM³§¼ÒºÍÖÇÄܼҾӳ§¼ÒÒѳ¬¹ý°Ù¼Ò£»£» £»£»£»Òò¶ø³ýÐÛÂõÆ·ÅÆ±í£¬ £¬£¬£¬£¬£¬ÆäËûÆ·ÅÆµÄÉãÏñÍ·ÓйØÉ豸ҲӦÒýÆð¸ß¶ÈÆ÷³Á¡£¡£¡£¡£ ¡£Æ¾¾Ý¼à²âÊý¾Ý£¬ £¬£¬£¬£¬£¬Ä¿Ç°ÊÜÓ°ÏìµÄÔÚÍøÉ豸ÊýÁ¿ÔÚ°ÙÍòÒÔÉÏ¡£¡£¡£¡£ ¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

²¿ÃÅѡȡÐÛÂõ¹æ»®µÄ³§¼Ò
Êý¾ÝÆðÔ´£ºhttps://github.com/tothi/pwn-hisilicon-dvr


 Èý¡¢·ì϶½éÉÜ 


ÐÛÂõÊÇ2016ÄêmiraiľÂí´ó¹æÄ£DDoS¹¥»÷ÊÂÎñµÄÖØÒªÊÜÓ°Ïì³§¼Ò£¬ £¬£¬£¬£¬£¬½üÆÚ¹ú±í°²È«×êÑÐÈËԱа䲼µÄÓйطì϶Çé¿öÈçÏ£º


CVE񅧏
ÎÊÌâ
·çÏÕ
CVE-2018-17915
ÔÆÆ½Ì¨µÄÉ豸ÐòÁкÅÄܹ»Í¨¹ýÉ豸µÄMACµØÖ·ÍÆËã³ö
¹¥»÷ÕßÄܹ»Í¨¹ýÐÛÂõÉ豸µÄMACµØÖ·ÍÆËã³öÉ豸µÄÔÆÆ½Ì¨ÕË»§£¬ £¬£¬£¬£¬£¬²¢Äܹ»»ñµÃÕË»§µÄÔÚÏßÇé¿ö¡£¡£¡£¡£ ¡£
ÎÞ
adminÓû§´æÔÚ³õʼÃÜÂë
ÔÚ×îÖÕÓû§Ã»ÓÐÅú¸ÄadminÓû§³õʼÃÜÂëµÄÇé¿öÏ£¬ £¬£¬£¬£¬£¬¸Ã³õʼÃÜÂëÄܹ»±»¹¥»÷ÕßÔ¶³ÌÀûÓ㬠£¬£¬£¬£¬£¬ÆëÈ«½ÚÔìÉãÏñÍ·£¬ £¬£¬£¬£¬£¬×°ÖöñÒâÈí¼þ¡£¡£¡£¡£ ¡£
CVE-2018-17919
ÄÚÖÃdefaultÕË»§
¹¥»÷Õß¿ÉÀûÓÃdefaultÕË»§¼°ÆäÄÚÖõÄÃÜÂ룬 £¬£¬£¬£¬£¬Ô¶³ÌÇÔÌýÊÓÆµÔ´¡£¡£¡£¡£ ¡£
CVE-2018-17917
ͨѶͨ·¶ÌȱÓÐЧµÄ¼ÓÃܱ£»£» £»£»£»¤
¹¥»÷Õß¿Éͨ¹ý¼àÌýÉãÏñÍ·µÄÍøÂçͨѶ£¬ £¬£¬£¬£¬£¬»ñÈ¡ÉãÏñÍ·µÄÊÓÆµµã²¥µØÖ·£¬ £¬£¬£¬£¬£¬´Ó¶øÇÔÌýÊÓÆµÔ´ºÍÓû§µÇ½ƾ֤¡£¡£¡£¡£ ¡£
ÎÞ
¹Ì¼þµÄÆëÈ«ÐÔ¼°°²È«ÐÔ¶ÌȱÓÐЧ±£»£» £»£»£»¤»úÔì
¹¥»÷Õß¿ÉÔÚ»ñµÃµÇ½ƾ֤µÄÇé¿öÏ£¬ £¬£¬£¬£¬£¬»ú¹Ø¶ñÒâ¹Ì¼þ£¬ £¬£¬£¬£¬£¬´Ó¶øÈÃÉãÏñÍ·Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£ ¡£

ÒÔÉÏ·ì϶£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLab¾ùÔÚÓйØÐͺŵÄ×îй̼þ°æ±¾ÉϽøÐÐÁËÑéÖ¤¡£¡£¡£¡£ ¡£´Ë±í£¬ £¬£¬£¬£¬£¬Í¨¹ý¶Ô³§¼ÒµÄ¹ÙÍøÉÏÆäËûÐͺŵĹ̼þ½øÐзÖÎö£¬ £¬£¬£¬£¬£¬·¢ÏÖÓйطì϶ÎÊÌâÔÚÆäËû°²·ÀÉãÏñÍ·µÄÐͺÅÉÏÒ²´æÔÚ£¬ £¬£¬£¬£¬£¬·ì϶ӰÏìÁìÓò±ÈÁ¦¿í·º¡£¡£¡£¡£ ¡£¾­ÑéÖ¤£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÄÚ±íÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢ÀûÓ÷ì϶ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£¡£¡£¡£ ¡£


 ËÄ¡¢·ì϶Ӧ¶ÔÕ½Êõ½¨Òé 


4.1 CVE-2018-17919·ì϶¼ì²âÓ뽨¸´

4.1.1 ·ì϶µÀÀí

ÔÚÉãÏñÍ·¹Ì¼þµÄÓйغ¯ÊýÖдæÔÚÎÊÌâ´úÂ룬 £¬£¬£¬£¬£¬ÐÛÂõÉãÏñÍ·ÔÚ³ö³§ÉèÖÃʱԤÖÃÁËdefaultÕʺż°Ä¬ÈÏÃÜÂ룬 £¬£¬£¬£¬£¬¸ÃÕ˺ÅÔÚ¿Í»§¶ËÎÞ·¨½øÐÐɾ³ý£¬ £¬£¬£¬£¬£¬Ò²²»»áÏÔʾÔÚ¿Í»§¶Ë¡£¡£¡£¡£ ¡£


4.1.2 ·ì϶¼ì²âÓ뽨¸´


Õë¶Ô´Ë·ì϶£¬ £¬£¬£¬£¬£¬8827Ì«Ñô¼¯ÍÅADLabµÚÒ»¹¦·ò°ä²¼ÁË·ì϶½¨¸´¹¤¾ß£¬ £¬£¬£¬£¬£¬ÓйØÓû§¿ÉʹÓøù¤¾ß½øÐмì²âÓ뽨¸´¡£¡£¡£¡£ ¡££¨ÇëÔÚ¹«¼ÒºÅÖз¢Ë͹ؼü´Ê£ºXM¹¤¾ß£¬ £¬£¬£¬£¬£¬»ñÈ¡½¨¸´¹¤¾ß¡£¡£¡£¡£ ¡£ÈçʹÓÃÖÐÓöµ½ÎÊÌ⣬ £¬£¬£¬£¬£¬Ç뽫É豸Ðͺź͹̼þ°æ±¾ºÅ·î¸æÎÒÃÇ£©


1.ÏÂÔØfix_tools.exe¡£¡£¡£¡£ ¡£


2.ÔÚ½ÚÔį̀£¬ £¬£¬£¬£¬£¬Ö´ÐÐfix_tools.exe camera_ip username password£¬ £¬£¬£¬£¬£¬ÆäÖÐcamera_ip²ÎÊýΪÉãÏñÍ·IP£¬ £¬£¬£¬£¬£¬usernameΪÉãÏñÍ·AdminÓû§Ãû£¬ £¬£¬£¬£¬£¬passwordΪAdminÓû§ÃÜÂë¡£¡£¡£¡£ ¡£

È磺fix_tools.exe 192.168.0.88 admin 123456


3. ÈôÊÇ´æÔÚ·ì϶£¬ £¬£¬£¬£¬£¬Ôò»áÌáÐÑ£º
[*] vuln(cve-2018-17919) found!¡±
[*] Do you want to fix it?(y/n):

ÊäÈëy,¼´ÆðÍ·½¨¸´·ì϶¡£¡£¡£¡£ ¡£


4. ÈôÊÇ·ì϶½¨¸´³É¹¦£¬ £¬£¬£¬£¬£¬Ôò»áÌáÐÑ £º
[*] vuln fix success!!!!!!!!!

°ÑÎÈ£ºµ±Óû§¶ÔÉãÏñÍ·½øÐи´Ô­³ö³§ÉèÖÃʱ£¬ £¬£¬£¬£¬£¬ÓÉÓÚdefaultÕË»§³Áб»¹Ì¼þдÈ룬 £¬£¬£¬£¬£¬Óû§±ØÒª³ÁÐÂÖ´ÐÐfix_tools¹¤¾ß½¨¸´¡£¡£¡£¡£ ¡£


5. ÈôÊÇÖ¸±êÉ豸²»´æÔڸ÷ì϶£¬ £¬£¬£¬£¬£¬Ôò»áÌáÐÑ£º
[!] vuln not found


½¨¸´¹¤¾ßÔÚÒÔÏÂÉ豸²âÊÔͨ¹ý£º
[*] HardWare= RM50H20L_8188EU_S38 
SoftWareVersion= V4.02.R12.C4420813.10002.144002.00000
[*] HardWare= 53H13-E_18EV200_8188EU_S38

SoftWareVersion= V4.02.R12.A6420240.10002.140802.00000


4.2 ÆäËû·ì϶»º½â²½Öè

Ϊ±£ÏÕ¹«¹²°²È«£¬ £¬£¬£¬£¬£¬Ôü×Ò·ì϶µÄ¼ì²â²½ÖèÔݲ»¹«¿ª£»£» £»£»£»ÓйØÓû§¿É²Î¿¼ÈçÏ»º½â½¨Ò飬 £¬£¬£¬£¬£¬Ó¦¶Ô¿ÉÄܲúÉúµÄ¹¥»÷ÊÂÎñ£º


  • ͨ¹ý¿Í»§¶Ë¶ÔadminÓû§ÉèÖø´ÔÓÃÜÂ룬 £¬£¬£¬£¬£¬Ô¤·ÀadminȨÏÞ±»¹¥»÷Õß»ñµÃ¡£¡£¡£¡£ ¡£
  • ͨ¹ý·ÓÉÆ÷ÉèÖÃÏÞ¶ÈÕ½Êõ£¬ £¬£¬£¬£¬£¬¹Ø¹ØÉãÏñÍ·µÄ»¥ÁªÍø½Ó¼ûȨÏÞ£¬ £¬£¬£¬£¬£¬Ö»ÄÜͨ¹ýÄÚÍø½Ó¼ûÉãÏñÍ·¡£¡£¡£¡£ ¡£
  • ÔÚ³§¼ÒÌṩеķì϶²¹¶¡ºó£¬ £¬£¬£¬£¬£¬ÊµÊ±¸üÐÂÉãÏñÍ·¹Ì¼þ²¹¶¡¡£¡£¡£¡£ ¡£



²Î¿¼Á´½Ó£º

¡¾1¡¿ÁªÍøÊÓÆµ¼à¿ØÏµÍ³ÍøÂç°²È«Ì¬ÊÆ»ã±¨
https://www.ics-cert.org.cn/portal/page/131/be9def54499644afb6ce4b119e5e7d42.html
¡¾2¡¿ÃÀ¹ú¹¤Òµ»¥ÁªÍø°²È«ÏìÓ¦ÖÐÐIJ¼¸æ
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06