链接:http://xforce.iss.net/xforce/xfdb/80476 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-6066 http://www.tenable.com/plugins/index.php?view=single&id=63223 http://www.exploit-db.com/exploits/23080/ *>测试方法: --------------------------------------------------------------------------------警 告以下程序(方法)可能带有攻击性,仅供安全研究与教学之用。使用者风险自负! FreeSSHD all version Remote Authentication Bypass ZERODAY Discovered & Exploited by Kingcope Year 2011 http://www.exploit-db.com/sploits/23080.zip Run like: ssh.exe -l<valid username> <host> valid username might be: root admin administrator webadmin sysadmin netadmin guest user web test ssh sftp ftp or anything you can imagine. The vulnerable banner of the most recent version is: SSH-2.0-WeOnlyDo 2.1.3 For your pleasure, KingcopeFreeSSHD all version Remote Authentication Bypass ZERODAY Discovered & Exploited by Kingcope Year 2011 Run like: ssh.exe -l<valid username> <host> valid username might be: root admin administrator webadmin sysadmin netadmin guest user web test ssh sftp ftp or anything you can imagine. The vulnerable banner of the most recent version is: SSH-2.0-WeOnlyDo 2.1.3 For your pleasure, Kingcope建议: -------------------------------------------------------------------------------- 厂商补丁: