VoIPmonitor GUI¿çÕ¾¾ç±¾Îó²î
Ðû²¼Ê±¼ä 2021-06-170x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-17 | |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
SIP (Session Initiation Protocol£¬£¬£¬£¬£¬£¬¼´»á»°ÌᳫÐÒé)ÊÇÒ»¸öÓ¦ÓòãµÄÐÅÁî¿ØÖÆÐÒ飬£¬£¬£¬£¬£¬ÓÃÓÚ½¨Éè¡¢Ð޸ĺÍÊÍ·ÅÒ»¸ö»ò¶à¸ö¼ÓÈëÕߵĻỰ¡£¡£¡£¡£SIPÊÇ¿ÉÓÃÓÚʵÏÖVoIPµÄÖÚ¶àÐÒéÖ®Ò»£¬£¬£¬£¬£¬£¬ÊÇÆÕ±éʹÓõÄÐÐÒµ±ê×¼ÐÒé¡£¡£¡£¡£
VoIPmonitorÊÇ¿ªÔ´µÄÍøÂçÊý¾Ý°üÐá̽Æ÷Èí¼þ£¬£¬£¬£¬£¬£¬¿É×¥°üÆÊÎöSIPºÍRTPµÈÐÒé¡£¡£¡£¡£
2021Äê06ÔÂ10ÈÕ£¬£¬£¬£¬£¬£¬Enable Security µÄÇå¾²Ñо¿Ô± Juxhin Dyrmishi Brigjaj ¹ûÕæÅû¶ÁËVoIPmonitor GUIÖеÄÒ»¸ö¿çÕ¾µã¾ç±¾ (XSS) Îó²î¡£¡£¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ SIP ÐÂÎÅÔÚÄ¿µÄϵͳÉÏÖ´ÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬ÉõÖÁ»ñµÃ¶ÔÄ¿µÄϵͳµÄ³¤ÆÚºóÃÅ»á¼û¡£¡£¡£¡£
Ñо¿Ö°Ô±Í¨¹ý½«User-AgentÉèÖÃΪ<img src=x alert(1)>£¬£¬£¬£¬£¬£¬ÈôÊÇËüÔÚ DOM ÖзºÆð£¬£¬£¬£¬£¬£¬ä¯ÀÀÆ÷½«ÎÞ·¨»ñÈ¡ÏÂ/xµÄͼÏñ£¬£¬£¬£¬£¬£¬²¢ÔÚʧ°ÜʱִÐжñÒâ´úÂ룺
Ñо¿Ö°Ô±Ê¹ÓôËÎó²î½¨ÉèÁËÒ»¸öºóÃÅÖÎÀíÓû§£¬£¬£¬£¬£¬£¬½«ÔÝʱȨÏÞÌáÉýΪÓÀÊÀÖÎÀíÔ±»á¼ûȨÏÞ£º
±ðµÄ£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÄÜÌᳫÒÔϹ¥»÷»î¶¯£º
l ÉøÍ¸Í¨¹ýÕýµ± VoIP ¿Í»§¶ËµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£ÕâÔÚÏÖÕæÏàÐÎÖÐÌØÊâÓÐÓ㬣¬£¬£¬£¬£¬VoIPmonitor GUI½«ÔÚÄÚ²¿ÔËÐУ¬£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý´øÍâDNSЧÀÍÆ÷£¨»òÆäËüÒªÁ죩ÇÔÈ¡Êý¾Ý£»£»£»£»
l Ó뽨ÉèÖÎÀíÔ±Óû§µÄ·½·¨ÀàËÆ£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔɾ³ý»á¼û½çÃæµÄÆäËûÕýµ±ÖÎÀíÔ±£»£»£»£»
l ¿ÉÒÔÔڵǼÆÁÄ»ÉÏǶÈë¼üÅ̼ͼÆ÷×÷ΪºóÃÅ£¬£¬£¬£¬£¬£¬ÍøÂçÖÎÀíԱƾ֤£»£»£»£»
l ʹÓÃÄÚ²¿ Web Ó¦ÓóÌÐò¡£¡£¡£¡£
Ó°Ïì¹æÄ£
VoIPmonitor GUI
0x02 ´¦Öóͷ£½¨Òé
VoIPmonitor GUIÒѾÐû²¼ÁË´ËÎó²îµÄÇå¾²²¹¶¡£¬£¬£¬£¬£¬£¬½¨Ò龡¿ìÉý¼¶µ½×îа汾¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
http://www.voipmonitor.org/download?WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
ͨÓÃÇå¾²½¨Òé
¶ÔÊäÈë»òÊä³ö¾ÙÐбàÂ룻£»£»£»
½¨ÒéÔÚÓ¦ÓóÌÐòÖÐʹÓüòµ¥±àÂëÕ½ÂÔ£¬£¬£¬£¬£¬£¬×èÖ¹Ë«ÖØ±àÂë»òË«ÖØ½âÂëÆÆËð½çÃæ»òµ¼ÖÂXSS¹¥»÷£»£»£»£»
ÈôÊÇÓû§ÊäÈë¾ßÓÐÔ¤ÆÚµÄÃûÌᢽṹºÍ¿É½ÓÊܵÄÖµ£¬£¬£¬£¬£¬£¬ÇëÊ×ÏÈÑéÖ¤ÕâЩ²¢¹ýÂËÎÞЧÊäÈë¡£¡£¡£¡£
Õë¶ÔDOM-XSSµÈ¿Í»§¶ËÊäÈë¾ÙÐÐתÒåºÍ±àÂë¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
http://www.voipmonitor.org/changelog-gui?major=5&WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/
0x04 ʱ¼äÏß
2021-06-10 Ñо¿Ö°Ô±¹ûÕæÅû¶Îó²î
2021-06-17 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/