mail.zis.gov.rs RCE
#1
Evo pošto će za 6 dana tačno godinu dana kako sam ovo prijavio CERT-u i ništa nije preduzeto, mislim da je sasvim u redu da ovde okačim.

mail.zis.gov.rs (212.200.105.75), mejl server Zavoda za Intelektualnu Svojinu je podložan na nekoliko ranjivosti vezanih za Microsoft Exchange Server.
Tačnije CVE-2021-34473, CVE-2021-26858, CVE-2021-26857, CVE-2021-26855, CVE-2021-31207, CVE-2021-31206, CVE-2021-34523, CVE-2021-27065.

https://www.shodan.io/host/212.200.105.75
https://msrc.microsoft.com/update-guide/...2021-34473
https://cve.mitre.org/cgi-bin/cvename.cg...2021-34473
https://www.rapid7.com/db/vulnerabilitie...021-34473/
Reply
#2
ni manje ni vise, nego oni... 

[Image: 869fa1da8a7b493450135d5abeaf2e9d.png]
daj da podnesemo prijavu u njihovo ime ^^

p.s: good catch!
Reply
#3
p.s: e`o jos jedan, za koji nisu jos patched https://devco.re/blog/2022/10/19/a-new-a...roxyRelay/
Reply
#4
Preporuka: Instalirati security zakrpe.
“If you think you are too small to make a difference, try sleeping with a mosquito.” - Dalai Lama XIV
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)