VoIPmonitor GUI¿çÕ¾¾ç±¾Îó²î

Ðû²¼Ê±¼ä 2021-06-17

0x00 Îó²î¸ÅÊö

CVE   ID


ʱ    ¼ä

2021-06-17

Àà    ÐÍ

XSS

µÈ    ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó


¿ÉÓÃÐÔ


Óû§½»»¥


ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

 

SIP (Session Initiation Protocol£¬£¬£¬£¬£¬£¬¼´»á»°ÌᳫЭÒé)ÊÇÒ»¸öÓ¦ÓòãµÄÐÅÁî¿ØÖÆÐ­Ò飬£¬£¬£¬£¬£¬ÓÃÓÚ½¨Éè¡¢Ð޸ĺÍÊÍ·ÅÒ»¸ö»ò¶à¸ö¼ÓÈëÕߵĻỰ¡£¡£¡£¡£SIPÊÇ¿ÉÓÃÓÚʵÏÖVoIPµÄÖÚ¶àЭÒéÖ®Ò»£¬£¬£¬£¬£¬£¬ÊÇÆÕ±éʹÓõÄÐÐÒµ±ê׼ЭÒé¡£¡£¡£¡£

VoIPmonitorÊÇ¿ªÔ´µÄÍøÂçÊý¾Ý°üÐá̽Æ÷Èí¼þ£¬£¬£¬£¬£¬£¬¿É×¥°üÆÊÎöSIPºÍRTPµÈЭÒé¡£¡£¡£¡£

2021Äê06ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬Enable Security µÄÇå¾²Ñо¿Ô± Juxhin Dyrmishi Brigjaj ¹ûÕæÅû¶ÁËVoIPmonitor GUIÖеÄÒ»¸ö¿çÕ¾µã¾ç±¾ (XSS) Îó²î¡£¡£¡£¡£Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ SIP ÐÂÎÅÔÚÄ¿µÄϵͳÉÏÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬ÉõÖÁ»ñµÃ¶ÔÄ¿µÄϵͳµÄ³¤ÆÚºóÃÅ»á¼û¡£¡£¡£¡£

Ñо¿Ö°Ô±Í¨¹ý½«User-AgentÉèÖÃΪ<img src=x alert(1)>£¬£¬£¬£¬£¬£¬ÈôÊÇËüÔÚ DOM ÖзºÆð£¬£¬£¬£¬£¬£¬ä¯ÀÀÆ÷½«ÎÞ·¨»ñÈ¡ÏÂ/xµÄͼÏñ£¬£¬£¬£¬£¬£¬²¢ÔÚʧ°ÜʱִÐжñÒâ´úÂ룺

image.png

 

Ñо¿Ö°Ô±Ê¹ÓôËÎó²î½¨ÉèÁËÒ»¸öºóÃÅÖÎÀíÓû§£¬£¬£¬£¬£¬£¬½«ÔÝʱȨÏÞÌáÉýΪÓÀÊÀÖÎÀíÔ±»á¼ûȨÏÞ£º

image.png

 

±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÄÜÌᳫÒÔϹ¥»÷»î¶¯£º

l  ÉøÍ¸Í¨¹ýÕýµ± VoIP ¿Í»§¶ËµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£ÕâÔÚÏÖÕæÏàÐÎÖÐÌØÊâÓÐÓ㬣¬£¬£¬£¬£¬VoIPmonitor GUI½«ÔÚÄÚ²¿ÔËÐУ¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý´øÍâDNSЧÀÍÆ÷£¨»òÆäËüÒªÁ죩ÇÔÈ¡Êý¾Ý£»£»£»£»

l  Ó뽨ÉèÖÎÀíÔ±Óû§µÄ·½·¨ÀàËÆ£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔɾ³ý»á¼û½çÃæµÄÆäËûÕýµ±ÖÎÀíÔ±£»£»£»£»

l  ¿ÉÒÔÔڵǼÆÁÄ»ÉÏǶÈë¼üÅ̼ͼÆ÷×÷ΪºóÃÅ£¬£¬£¬£¬£¬£¬ÍøÂçÖÎÀíԱƾ֤£»£»£»£»

l  ʹÓÃÄÚ²¿ Web Ó¦ÓóÌÐò¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

VoIPmonitor GUI

 

0x02 ´¦Öóͷ£½¨Òé

VoIPmonitor GUIÒѾ­Ðû²¼ÁË´ËÎó²îµÄÇå¾²²¹¶¡£¬£¬£¬£¬£¬£¬½¨Ò龡¿ìÉý¼¶µ½×îа汾¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

http://www.voipmonitor.org/download?WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr

 

ͨÓÃÇå¾²½¨Òé

¶ÔÊäÈë»òÊä³ö¾ÙÐбàÂ룻£»£»£»

½¨ÒéÔÚÓ¦ÓóÌÐòÖÐʹÓüòµ¥±àÂëÕ½ÂÔ£¬£¬£¬£¬£¬£¬×èÖ¹Ë«ÖØ±àÂë»òË«ÖØ½âÂëÆÆËð½çÃæ»òµ¼ÖÂXSS¹¥»÷£»£»£»£»

ÈôÊÇÓû§ÊäÈë¾ßÓÐÔ¤ÆÚµÄÃûÌᢽṹºÍ¿É½ÓÊܵÄÖµ£¬£¬£¬£¬£¬£¬ÇëÊ×ÏÈÑéÖ¤ÕâЩ²¢¹ýÂËÎÞЧÊäÈë¡£¡£¡£¡£

Õë¶ÔDOM-XSSµÈ¿Í»§¶ËÊäÈë¾ÙÐÐתÒåºÍ±àÂë¡£¡£¡£¡£

 

 

0x03 ²Î¿¼Á´½Ó

https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/

http://www.voipmonitor.org/changelog-gui?major=5&WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr

https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/


0x04 ʱ¼äÏß

2021-06-10  Ñо¿Ö°Ô±¹ûÕæÅû¶Îó²î

2021-06-17  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png