¶«É­Æ½Ì¨ADLab£ºÐÛÂõ¶à¸öÉãÏñͷ©¶´¾¯¸æ¼°ÐÞ¸´£¨¸½¹¤¾ß£©

Ðû²¼Ê±¼ä 2018-10-19
 Ò»¡¢¸ÅÊö 

½üÈÕ£¬¹úÍâÄþ¾²Ñо¿ÈËÔ±¹ûÈ»ÁËÐÛÂõ²úÎïµÄ¶à¸öÄþ¾²Â©¶´£¨CVE-2018-17915¡¢CVE-2018-17917¡¢CVE-2018-17919£©£¬ÕâЩ©¶´¿ÉÓ°ÏìÐÛÂõ¹«Ë¾µÄÖ÷ÒªÉãÏñÍ·²úÎï¼°Ïà¹ØµÄÉãÏñÍ·Ä£×顣ͨ¹ýÕâЩ©¶´£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ýÄÚÍâÍø½Ø»ñÉãÏñÍ·ÊÓƵԴ¡¢°²×°¶ñÒâ´úÂë¡¢Ìᳫ´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£


ͨ¹ýCVE-2018-17915£¨ÔÆƽ̨É豸ÐòÁкÅÐÅϢй¶£©ºÍCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©µÄ×éºÏ£¬Ö»ÒªÉ豸ÄÜ·ÃÎÊ»¥ÁªÍø£¬¹¥»÷Õ߾ͿÉÒÔÔ¶³Ì¶ÔÄÚÍøÉ豸Ìᳫ¹¥»÷£¬Ê¹µÃCVE-2018-17919µÄ©¶´Ó°ÏìÃæ½øÒ»²½À©´ó¡£


Ϊ±£ÕϹ«¹²Äþ¾²£¬¶«É­Æ½Ì¨ADLab½¨Ò飺


  • ÔÚ©¶´Î´ÍêÈ«ÐÞ¸´Ç°£¬É豸ʹÓ÷½Ó¦ÏÞÖÆÎÊÌâÉ豸µÄ»¥ÁªÍø·ÃÎÊȨÏÞ¡£
  • ÔÚ¹ûÈ»µÄ©¶´ÖÐÓ°Ïì×î´óµÄÊÇCVE-2018-17919£¨ÄÚÖÃdefaultÕË»§£©£¬Ä¿Ç°Â©¶´ÒѾ­¹ûÈ»£¬´óÁ¿µÄÔÚÍøÉ豸Êܵ½Äþ¾²Íþв£»¶«É­Æ½Ì¨ADLabµÚһʱ¼äÐû²¼ÁËCVE-2018-17919©¶´ÐÞ¸´¹¤¾ß£¬Ïà¹ØÓû§Ç뾡¿ì¿ÉʹÓô˹¤¾ß¶Ô©¶´½øÐмì²âÓëÐÞ¸´¡£

 ¶þ¡¢Â©¶´Ó°ÏìÃæ 

ƾ¾Ý2018Äê3ÔÂCNCERTÐû²¼µÄ¡¶ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÄþ¾²Ì¬ÊƳÂËß¡·£¬ÐÛÂõÒÔ6.25%µÄÕ¼±ÈÃûÁÐÈ«ÇòµÚËÄ£»Í¬Ê±£¬ÐÛÂõÉãÏñÍ·Ä£×é·½°¸±»´óÁ¿³§É̽ÓÄÉ£¬½ö²¿ÃÅÖªÏþµÄOEM³§¼ÒºÍÖÇÄܼҾӳ§¼ÒÒÑÁè¼Ý°Ù¼Ò£»Òò´Ë³ýÐÛÂõÆ·ÅÆÍ⣬ÆäËûÆ·ÅƵÄÉãÏñÍ·Ïà¹ØÉ豸ҲӦÒýÆð¸ß¶ÈÖØÊÓ¡£Æ¾¾Ý¼à²âÊý¾Ý£¬Ä¿Ç°ÊÜÓ°ÏìµÄÔÚÍøÉ豸ÊýÁ¿ÔÚ°ÙÍòÒÔÉÏ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

²¿ÃŽÓÄÉÐÛÂõ·½°¸µÄ³§¼Ò
Êý¾ÝÀ´Ô´£ºhttps://github.com/tothi/pwn-hisilicon-dvr


 Èý¡¢Â©¶´½éÉÜ 


ÐÛÂõÊÇ2016ÄêmiraiľÂí´ó¹æÄ£DDoS¹¥»÷ʼþµÄÖ÷ÒªÊÜÓ°Ï쳧¼Ò£¬½üÆÚ¹úÍâÄþ¾²Ñо¿ÈËÔ±ÐÂÐû²¼µÄÏà¹Ø©¶´Çé¿öÈçÏ£º


CVE񅧏
ÎÊÌâ
Σº¦
CVE-2018-17915
ÔÆƽ̨µÄÉ豸ÐòÁкſÉÒÔͨ¹ýÉ豸µÄMACµØÖ·ÍÆËã³ö
¹¥»÷Õß¿ÉÒÔͨ¹ýÐÛÂõÉ豸µÄMACµØÖ·ÍÆËã³öÉ豸µÄÔÆƽ̨ÕË»§£¬²¢¿ÉÒÔ»ñµÃÕË»§µÄÔÚÏßÇé¿ö¡£
ÎÞ
adminÓû§´æÔÚ³õʼÃÜÂë
ÔÚ×îÖÕÓû§Ã»ÓÐÐÞ¸ÄadminÓû§³õʼÃÜÂëµÄÇé¿öÏ£¬¸Ã³õʼÃÜÂë¿ÉÒÔ±»¹¥»÷ÕßÔ¶³ÌÀûÓã¬ÍêÈ«¿ØÖÆÉãÏñÍ·£¬°²×°¶ñÒâÈí¼þ¡£
CVE-2018-17919
ÄÚÖÃdefaultÕË»§
¹¥»÷Õß¿ÉÀûÓÃdefaultÕË»§¼°ÆäÄÚÖõÄÃÜÂ룬Զ³ÌÇÔÌýÊÓƵԴ¡£
CVE-2018-17917
ͨÐÅͨµÀȱÉÙÓÐЧµÄ¼ÓÃܱ£»¤
¹¥»÷Õß¿Éͨ¹ý¼àÌýÉãÏñÍ·µÄÍøÂçͨÐÅ£¬»ñÈ¡ÉãÏñÍ·µÄÊÓƵµã²¥µØÖ·£¬´Ó¶øÇÔÌýÊÓƵԴºÍÓû§µÇ½ƾ֤¡£
ÎÞ
¹Ì¼þµÄÍêÕûÐÔ¼°Äþ¾²ÐÔȱÉÙÓÐЧ±£»¤»úÖÆ
¹¥»÷Õß¿ÉÔÚ»ñµÃµÇ½ƾ֤µÄÇé¿öÏ£¬½á¹¹¶ñÒâ¹Ì¼þ£¬´Ó¶øÈÃÉãÏñÍ·Ö´ÐÐÈÎÒâÃüÁî¡£

ÒÔÉÏ©¶´£¬¶«É­Æ½Ì¨ADLab¾ùÔÚÏà¹ØÐͺŵÄ×îй̼þ°æ±¾ÉϽøÐÐÁËÑéÖ¤¡£´ËÍ⣬ͨ¹ý¶Ô³§¼ÒµÄ¹ÙÍøÉÏÆäËûÐͺŵĹ̼þ½øÐзÖÎö£¬·¢ÏÖÏà¹Ø©¶´ÎÊÌâÔÚÆäËû°²·ÀÉãÏñÍ·µÄÐͺÅÉÏÒ²´æÔÚ£¬Â©¶´Ó°Ï췶Χ±ÈÁ¦¹ã·º¡£¾­ÑéÖ¤£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÄÚÍâÍø½Ø»ñÉãÏñÍ·ÊÓƵԴ¡¢°²×°¶ñÒâ´úÂë¡¢ÀûÓ鶴Ìᳫ´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£


 ËÄ¡¢Â©¶´Ó¦¶Ô¼Æı½¨Òé 


4.1 CVE-2018-17919©¶´¼ì²âÓëÐÞ¸´

4.1.1 ©¶´Ô­Àí

ÔÚÉãÏñÍ·¹Ì¼þµÄÏà¹Øº¯ÊýÖдæÔÚÎÊÌâ´úÂ룬ÐÛÂõÉãÏñÍ·ÔÚ³ö³§ÉèÖÃʱԤÖÃÁËdefaultÕʺż°Ä¬ÈÏÃÜÂ룬¸ÃÕ˺ÅÔÚ¿Í»§¶ËÎÞ·¨½øÐÐɾ³ý£¬Ò²²»»áÏÔʾÔÚ¿Í»§¶Ë¡£


4.1.2 ©¶´¼ì²âÓëÐÞ¸´


Õë¶Ô´Ë©¶´£¬¶«É­Æ½Ì¨ADLabµÚһʱ¼äÐû²¼ÁË©¶´ÐÞ¸´¹¤¾ß£¬Ïà¹ØÓû§¿ÉʹÓøù¤¾ß½øÐмì²âÓëÐÞ¸´¡££¨ÇëÔÚ¹«ÖÚºÅÖз¢ËÍÒªº¦´Ê£ºXM¹¤¾ß£¬»ñÈ¡ÐÞ¸´¹¤¾ß¡£ÈçʹÓÃÖÐÓöµ½ÎÊÌ⣬Ç뽫É豸Ðͺź͹̼þ°æ±¾ºÅ¼û¸æÎÒÃÇ£©


1.ÏÂÔØfix_tools.exe¡£


2.ÔÚ¿ØÖÆ̨£¬Ö´ÐÐfix_tools.exe camera_ip username password£¬ÆäÖÐcamera_ip²ÎÊýΪÉãÏñÍ·IP£¬usernameΪÉãÏñÍ·AdminÓû§Ãû£¬passwordΪAdminÓû§ÃÜÂë¡£

È磺fix_tools.exe 192.168.0.88 admin 123456


3. Èç¹û´æÔÚ©¶´£¬Ôò»áÌáʾ£º
[*] vuln(cve-2018-17919) found!¡±
[*] Do you want to fix it?(y/n):

ÊäÈëy,¼´¿ªÊ¼ÐÞ¸´Â©¶´¡£


4. Èç¹û©¶´ÐÞ¸´Àֳɣ¬Ôò»áÌáʾ £º
[*] vuln fix success!!!!!!!!!

×¢Ò⣺µ±Óû§¶ÔÉãÏñÍ·½øÐлָ´³ö³§ÉèÖÃʱ£¬ÓÉÓÚdefaultÕË»§ÖØб»¹Ì¼þдÈ룬Óû§ÐèÒªÖØÐÂÖ´ÐÐfix_tools¹¤¾ßÐÞ¸´¡£


5. Èç¹ûÄ¿±êÉ豸²»´æÔڸ鶴£¬Ôò»áÌáʾ£º
[!] vuln not found


ÐÞ¸´¹¤¾ßÔÚÒÔÏÂÉ豸²âÊÔͨ¹ý£º
[*] HardWare= RM50H20L_8188EU_S38 
SoftWareVersion= V4.02.R12.C4420813.10002.144002.00000
[*] HardWare= 53H13-E_18EV200_8188EU_S38

SoftWareVersion= V4.02.R12.A6420240.10002.140802.00000


4.2 ÆäËû©¶´»º½âÒªÁì

Ϊ±£ÕϹ«¹²Äþ¾²£¬Ê£Ó੶´µÄ¼ì²âÒªÁìÔݲ»¹ûÈ»£»Ïà¹ØÓû§¿É²Î¿¼ÈçÏ»º½â½¨Ò飬Ӧ¶Ô¿ÉÄÜ·¢ÉúµÄ¹¥»÷ʼþ£º


  • ͨ¹ý¿Í»§¶Ë¶ÔadminÓû§ÉèÖÃÅÓ´óÃÜÂ룬·ÀÖ¹adminȨÏÞ±»¹¥»÷Õß»ñµÃ¡£
  • ͨ¹ý·ÓÉÆ÷ÉèÖÃÏÞÖƼÆı£¬¹Ø±ÕÉãÏñÍ·µÄ»¥ÁªÍø·ÃÎÊȨÏÞ£¬Ö»ÄÜͨ¹ýÄÚÍø·ÃÎÊÉãÏñÍ·¡£
  • ÔÚ³§¼ÒÌṩеĩ¶´²¹¶¡ºó£¬¼°Ê±¸üÐÂÉãÏñÍ·¹Ì¼þ²¹¶¡¡£



²Î¿¼Á´½Ó£º

¡¾1¡¿ÁªÍøÊÓƵ¼à¿ØϵͳÍøÂçÄþ¾²Ì¬ÊƳÂËß
https://www.ics-cert.org.cn/portal/page/131/be9def54499644afb6ce4b119e5e7d42.html
¡¾2¡¿ÃÀ¹ú¹¤Òµ»¥ÁªÍøÄþ¾²ÏìÓ¦ÖÐÐÄͨ¸æ
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06