Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

告知一个情况 用锐捷的朋友注意了 #235

Open
GoogleCodeExporter opened this issue Jul 26, 2015 · 5 comments
Open

告知一个情况 用锐捷的朋友注意了 #235

GoogleCodeExporter opened this issue Jul 26, 2015 · 5 comments

Comments

@GoogleCodeExporter
Copy link

我渗透过学校的锐捷服务器 
发现锐捷的安装使用的是脚本包安装的 
也就是说MSSQL很大的可能性就是sa/null 弱口令 
是可以提权到system修改T_USER的LEFT_FEE跟LEFT_TIME字段是可以加网
费的 
可以尝试用扫描工具扫描整个学校网段尝试1433端口的弱口 
部分老版的锐捷2.x的版本 JBOSS漏洞可以直接提权到system 
这个去网上搜索 

Original issue reported on code.google.com by [email protected] on 20 Jun 2013 at 12:05

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant