code 区域172.18.0.90 8888/http open struts2 vuln found
扫描到一台struts,看一下:
system权限的xp,发现是个运维的机子,而且此人管理了大量的系统:
其中就有出口IP(172.18.0.1),用之前破解的H3C的帐号密码登陆,有几组是通用的:
code 区域C720_10G_A#show running
Building configuration...
Current configuration : 130718 bytes
!
! Last configuration change at 17:30:40 BeiJing Thu Mar 27 2014 by yujing
! NVRAM config last updated at 07:05:22 BeiJing Thu Mar 20 2014 by jianqingma
如果被不法分子获取,危害还是蛮大的,注意这几行:
code 区域interface Vlan106
description wangjian_guanli_ip
ip address 192.168.204.1 255.255.255.0
!
interface Vlan110
description gonganju_3148guanli
ip address 192.168.110.110 255.255.255.252