破壳企业应急安全(防御方向)课程 应急响应 勒索病毒 挖矿木马 DDOS 日志分析

ShopEx某分站源码泄漏

编号117205
Urlhttp://www.wooyun.org/bug.php?action=view&id=117205
漏洞状态漏洞已经通知厂商但是厂商忽略漏洞
漏洞标题ShopEx某分站源码泄漏
漏洞类型敏感信息泄露
厂商ShopEx
白帽子Alan*
提交日期2015-06-01 12:25:00
公开日期2015-06-06 12:26:00
修复时间(not set)
确认时间0000-00-00 00:00:00
Confirm Spend-1
漏洞标签
关注数0
收藏数0
白帽评级
白帽自评rank10
厂商评级
厂商评rank0
漏洞简介
ShopEx某分站存在.git
漏洞细节

分站地址:http://i.shopex.cn/
http://i.shopex.cn/.git/config

20150530211648.png


20150530211634.png


20150530212513.png


配置文件泄漏一些APPKEY和邮箱信息

//套件对应的APPKEY
$config['secret'] = array(
'usercenter'=>array(
'key' => '5ryvwids',
'secret' => 'p57dek2u3vjvmzjpwwoy',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'oauth'=>array(
// 'oauth'=>'https://oauth.omnisale.cn',
// 'site'=>'https://oauth.omnisale.cn',
'oauth'=>'https://openapi.shopex.cn/oauth',
'site'=>'https://openapi.shopex.cn/api',
'key'=>'F2UUBZ',
'secret'=>'8EOXVFDRLLL5G3TOKA6P'
),
'group_fxsuzs'=>array(
'key' => '2KNNDJ',
'secret' => 'B9GFRN6FDC6C0FVA6A4L',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsujc'=>array(
'key' => 'DZ6GTJ',
'secret' => 'EZ0977E9W6KDH4KI558K',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsubz'=>array(
'key' => '90CUTA',
'secret' => 'ET97US31LT8GM0HZTRMS',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqy'=>array(
'key' => '4NZ7HM',
'secret' => 'A07H1M32A80NPHEL9T3W',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqj'=>array(
'key' => 'DO7GN1',
'secret' => '1B5TTHRPHGB1LVFLHN15',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsujc3y'=>array(
'key' => '1LAGFY',
'secret' => 'EWBVLUF4XBL35X2YA1ZG',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsubz3y'=>array(
'key' => '4GJW45',
'secret' => '927D7S0EVLMUN6MO50XN',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqy3y'=>array(
'key' => '6W4N3M',
'secret' => 'E5UJJUK7RUFWL125KJHP',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
),
'group_fxsuqj3y'=>array(
'key' => 'F52AT8',
'secret' => '680JDRWPUD6XBWDS2IO7',
'site' => 'https://openapi.ishopex.cn/api',
'oauth' => 'https://oauth.shopex.cn',
)
);
//邮件服务
$config['smtp'] = array(
"url" => "mail.shopex.cn",
"port" => "25",
"username" => "[email protected]",
"password" => "Shopex123",
"from" => "[email protected]"
);

POC

20150530211634.png


20150530212513.png

修复方案

状态信息 2015-06-01: 细节已通知厂商并且等待厂商处理中
2015-06-06: 厂商已经主动忽略漏洞,细节向公众公开
厂商回复None漏洞Rank:2 (WooYun评价)
回应信息危害等级:无影响厂商忽略忽略时间:2015-06-06 12:26