VoIPmonitor GUI¿çÕ¾¾ç±¾Îó²î
Ðû²¼Ê±¼ä 2021-06-170x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-17 | |
Àà ÐÍ | XSS | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | ¿ÉÓÃÐÔ | ||
Óû§½»»¥ | ËùÐèȨÏÞ | ÎÞ | |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé

SIP (Session Initiation Protocol£¬£¬¼´»á»°ÌᳫÐÒé)ÊÇÒ»¸öÓ¦ÓòãµÄÐÅÁî¿ØÖÆÐÒ飬£¬ÓÃÓÚ½¨Éè¡¢Ð޸ĺÍÊÍ·ÅÒ»¸ö»ò¶à¸ö¼ÓÈëÕߵĻỰ¡£¡£SIPÊÇ¿ÉÓÃÓÚʵÏÖVoIPµÄÖÚ¶àÐÒéÖ®Ò»£¬£¬ÊÇÆÕ±éʹÓõÄÐÐÒµ±ê×¼ÐÒé¡£¡£
VoIPmonitorÊÇ¿ªÔ´µÄÍøÂçÊý¾Ý°üÐá̽Æ÷Èí¼þ£¬£¬¿É×¥°üÆÊÎöSIPºÍRTPµÈÐÒé¡£¡£
2021Äê06ÔÂ10ÈÕ£¬£¬Enable Security µÄÇå¾²Ñо¿Ô± Juxhin Dyrmishi Brigjaj ¹ûÕæÅû¶ÁËVoIPmonitor GUIÖеÄÒ»¸ö¿çÕ¾µã¾ç±¾ (XSS) Îó²î¡£¡£Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ SIP ÐÂÎÅÔÚÄ¿µÄϵͳÉÏÖ´ÐжñÒâ´úÂ룬£¬ÉõÖÁ»ñµÃ¶ÔÄ¿µÄϵͳµÄ³¤ÆÚºóÃÅ»á¼û¡£¡£
Ñо¿Ö°Ô±Í¨¹ý½«User-AgentÉèÖÃΪ<img src=x alert(1)>£¬£¬ÈôÊÇËüÔÚ DOM ÖзºÆð£¬£¬ä¯ÀÀÆ÷½«ÎÞ·¨»ñÈ¡ÏÂ/xµÄͼÏñ£¬£¬²¢ÔÚʧ°ÜʱִÐжñÒâ´úÂ룺

Ñо¿Ö°Ô±Ê¹ÓôËÎó²î½¨ÉèÁËÒ»¸öºóÃÅÖÎÀíÓû§£¬£¬½«ÔÝʱȨÏÞÌáÉýΪÓÀÊÀÖÎÀíÔ±»á¼ûȨÏÞ£º

±ðµÄ£¬£¬¹¥»÷Õß»¹¿ÉÄÜÌᳫÒÔϹ¥»÷»î¶¯£º
l ÉøÍ¸Í¨¹ýÕýµ± VoIP ¿Í»§¶ËµÄÃô¸ÐÊý¾Ý¡£¡£ÕâÔÚÏÖÕæÏàÐÎÖÐÌØÊâÓÐÓ㬣¬VoIPmonitor GUI½«ÔÚÄÚ²¿ÔËÐУ¬£¬¿ÉÒÔͨ¹ý´øÍâDNSЧÀÍÆ÷£¨»òÆäËüÒªÁ죩ÇÔÈ¡Êý¾Ý£»£»£»£»£»£»
l Ó뽨ÉèÖÎÀíÔ±Óû§µÄ·½·¨ÀàËÆ£¬£¬Ò²¿ÉÒÔɾ³ý»á¼û½çÃæµÄÆäËûÕýµ±ÖÎÀíÔ±£»£»£»£»£»£»
l ¿ÉÒÔÔڵǼÆÁÄ»ÉÏǶÈë¼üÅ̼ͼÆ÷×÷ΪºóÃÅ£¬£¬ÍøÂçÖÎÀíԱƾ֤£»£»£»£»£»£»
l ʹÓÃÄÚ²¿ Web Ó¦ÓóÌÐò¡£¡£
Ó°Ïì¹æÄ£
VoIPmonitor GUI
0x02 ´¦Öóͷ£½¨Òé
VoIPmonitor GUIÒѾÐû²¼ÁË´ËÎó²îµÄÇå¾²²¹¶¡£¡£¬£¬½¨Ò龡¿ìÉý¼¶µ½×îа汾¡£¡£
ÏÂÔØÁ´½Ó£º
http://www.voipmonitor.org/download?WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
ͨÓÃÇå¾²½¨Òé
¶ÔÊäÈë»òÊä³ö¾ÙÐбàÂ룻£»£»£»£»£»
½¨ÒéÔÚÓ¦ÓóÌÐòÖÐʹÓüòµ¥±àÂëÕ½ÂÔ£¬£¬×èÖ¹Ë«ÖØ±àÂë»òË«ÖØ½âÂëÆÆËð½çÃæ»òµ¼ÖÂXSS¹¥»÷£»£»£»£»£»£»
ÈôÊÇÓû§ÊäÈë¾ßÓÐÔ¤ÆÚµÄÃûÌᢽṹºÍ¿É½ÓÊܵÄÖµ£¬£¬ÇëÊ×ÏÈÑéÖ¤ÕâЩ²¢¹ýÂËÎÞЧÊäÈë¡£¡£
Õë¶ÔDOM-XSSµÈ¿Í»§¶ËÊäÈë¾ÙÐÐתÒåºÍ±àÂë¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.rtcsec.com/post/2021/06/abusing-sip-for-cross-site-scripting-most-definitely/
http://www.voipmonitor.org/changelog-gui?major=5&WHMCSwxPBfGDQsX5v=t8vcrgugv6jq8uukuk0gf3untr
https://latesthackingnews.com/2021/06/16/xss-vulnerability-in-sip-protocol-risks-rce-attacks-on-voip-software/
0x04 ʱ¼äÏß
2021-06-10 Ñо¿Ö°Ô±¹ûÕæÅû¶Îó²î
2021-06-17 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ