2017Äê·´ÐòÁл¯Îó²îÄê¶È±¨¸æ
2018-01-24
2017ÄêOWASPÐû²¼ÁËеÄÊ®´ówebÎó²îÍþв£¬ÆäÖÐA8:2017¾ÍÊDz»Çå¾²µÄ·´ÐòÁл¯£¬A9:2017-ʹÓú¬ÓÐÒÑÖªÎó²îµÄ×é¼þÒ²ºÍ·´ÐòÁл¯Ï¸ÃÜÏàÁ¬£¬ÕâÊÇÓÉÓÚÔÚJava¿ª·¢ÖÐÐí¶à´úÂë¶¼ÒÀÀµÓÚµÚÈý·½×é¼þ£¬¶øÕâЩ×é¼þ¿ÉÄܻᱣ´æ·´ÐòÁÐÎó²î£¬µä·¶µÄÀý×Ó¾ÍÊÇJackson£¬fastjson£¬XStream£¬XMLDecoderµÈ¿ªÔ´×é¼þ¡£ÐòÁл¯Êǹ¤¾ßת»»³É¶þ½øÖÆ£¬json£¬xmlµÈ´æ´¢ÃûÌ᣶ø·´ÐòÁл¯Ç¡Ç¡Ïà·´£¬ÔòÊǽ«¶þ½øÖÆ£¬json£¬xmlת»»³ÉÏìÓ¦µÄÀà¡£
ÔÚ2017ÄêAG¹«Ë¾¿Æ¼¼NS-SRC ´¦Öóͷ£µÄÎó²îÓ¦¼±ÖоÍÓкܴóÒ»²¿·ÖÊÇ·´ÐòÁл¯Îó²î£¬ÏÂÃæÎÒÃÇÀ´ÖðÒ»ÆÊÎö2017ÄêÎÒÃÇÓ¦¼±µÄÄÇЩ·´ÐòÁл¯Îó²î¡£ ×ܵÃÀ´Ëµ£¬2017Äê·ºÆðµÄ·´ÐòÁл¯Îó²îºÍÒÔÍù·´ÐòÁÐÎó²îÔÚÎó²îÐγɷ½·¨Éϲ»Ì«Ò»Ñù£¬ÔÚÒÔÍù¶¼ÊÇÓÉÓÚJava×ÔÉíµÄ·´ÐòÁÐÌØÕ÷µ¼ÖµÄÎó²î£¬2017ÄêÔò¶àÁËfastjson£¬JacksonµÈ£¬ÕâÁ½¸ö¿â¶¼Äܽ«jsonÎı¾×ª»»³ÉÏêϸµÄjava bean£¬ÔÚÕâ¸öת»»Àú³ÌÖлáŲÓÃÏìÓ¦µÄsetterÒªÁìºÍgetterÒªÁì´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£2017Ä껹·ºÆð¹ØÓÚXMLDecoderºÍXStreamµÄÓ¦¼±£¬¶¼ÊÇÓÉÓÚÒÀÀµÎÊÌâµ¼ÖµÄȱÏÝ¡£ ±¾±¨¸æÖØµã»ØÊ×2017ÄêAG¹«Ë¾¿Æ¼¼ÖصãÓ¦¼±£¬Ó°ÏìÃæºÜÊǹãµÄÄÇЩ·´ÐòÁл¯Îó²î¡£´ÓÕâ¸ö±¨¸æÖÐÄÜ¿´³ö·´ÐòÁл¯Îó²îµÄÉú³¤£¬¹¥»÷·½ºÍ·ÀÓù·½Ò»Ö±µÄ¶Ô¿¹Àú³Ì£¬bypassºÍ·´bypassÔÚÕâ¸öÀú³ÌÖÐÌåÏÖµÃÁÜÀ쾡Ö¡£
¸ÅÊö
Ó¦¼±õè¾¶
´Ó3Ô·ݱ¬³öFastjsonµÄ·´ÐòÁл¯ÌØÕ÷µ¼ÖµÄÔ¶³Ì´úÂëÖ´ÐУ¬ËÄÔ·ÝÔòÊÇJackson£¬Log4j2£¬JenkinsµÄ·´ÐòÁл¯Ôì³ÉµÄÔ¶³Ì´úÂëÖ´ÐУ¬½Ó×Å6Ô·ÝÁ÷³öÁËWeblogic CVE-2017-3248µÄʹÓôúÂë¡£ÉÔ΢ÏûÍ£ÁËÒ»»á£¬Struts2ÓÖ±»Çå¾²Ñо¿Ö°Ô±¶¢ÉÏ£¬±¬³öStruts2-052£¬ÓÖÊÇÒ»¸öÔ¶³Ì´úÂëÖ´ÐС£ÔÚ11Ô·ݣ¬ÓÉÓÚJackson¹Ù·½¶ÔÎó²î²»Ãô¸Ð£¬½Ó×ÅÓÖ±»ÆØCVE-2017-15095£¬ÓÖÒ»¸öÈÆ¹ý¡£½øÈë12Ô·ݣ¬FastjsonºÍJacksonÏà¼ÌÐû²¼Á˼¸¸ö²¹¶¡ÐÞ¸´ÄÇЩºÚÃûµ¥µÄÈÆ¹ý£»Weblogic XMLDecoder(CVE-2017-10352)µÄÎó²î±»ÆÕ±éÓ¦ÓÃÓÚÓÚÍÚ¿Ó¡£ÓÉÓÚÐí¶àÎó²î¶¼ÊÇÔ¶³Ì´úÂëÖ´ÐУ¬ÓеÄÒ»¸öHTTP POSTÇëÇó¾ÍÄÜgetshell£¬ÒÔÊDZ¸ÊܺڲúÇ×íù¡£
·´ÐòÁл¯Îó²î
1 fastjson·´ÐòÁл¯Îó²î
2017Äê3ÔÂ15ÈÕ£¬fastjson¹Ù·½Ðû²¼Ç徲ͨ¸æÌåÏÖfastjsonÔÚ1.2.24¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²îÔ¶³ÌÖ´ÐжñÒâ´úÂëÀ´ÈëÇÖ·þÎñÆ÷¡£fastjson¹Ù·½½¨ÒéÖ±½ÓÉý¼¶µ½1.2.28/1.2.29»òÕ߸üаæÔÀ´°ü¹ÜϵͳÇå¾²¡£4ÔÂ29ÈÕ£¬±¾ÎÄ×÷ÕßAG¹«Ë¾¿Æ¼¼Çå¾²Ñо¿Ô±ÁÎÐÂϲ£¨xxlegend£©½á¹¹³öÁËFastjsonµÄ·´ÐòÁÐÎó²îµÄPoC£¬ÒýÆðÁËÇ徲ȦµÄÆÕ±éÌÖÂÛ¡£ÏêϸµÄÆÊÎö¿É²ÎÕÕ1£¬ÏÂÃæ×ö¼òÆÓµÄ»ØÊס£
ºóÐø¹Ù·½ÐÞ²¹
fastjson¹Ù·½ºóÐøÓÖÌí¼ÓÁËһЩ²¹¶¡£¬±¾ÎÄ×÷Õ߸øfastjson¹Ù·½Ìá½»ÁËÁ½´ÎÈÆ¹ý£¬fastjson¹Ù·½¶¼Ðû²¼ÁËÏìÓ¦¸üС£ÏêϸÈçÏ£º
1. fastjson-1.2.34°æ±¾Ðû²¼£¬µ±autoType=trueʱÔöÇ¿Çå¾²·À»¤
2. fastjson-1.2.42°æ±¾Ðû²¼ BugÐÞ¸´Çå¾²¼Ó¹Ì
3. fastjson-1.2.43°æ±¾Ðû²¼ BugÐÞ¸´Çå¾²¼Ó¹Ì
4. fastjson-1.2.44°æ±¾Ðû²¼ BugÐÞ¸´Çå¾²¼Ó¹Ì
ÔÚfastjson-1.2.42°æ±¾ÖÐͨ¹ýÒì»ò²Ù×÷»ìÏýÁËÆäºÚÃûµ¥£¬¿ÉÒÔ×èµ²Ò»²¿·ÖÈËÆÊÎöÆäºÚÃûµ¥ÄÚÈÝ£¬×ÅʵÕâÊÇ×ÔÆÛÆÛÈ˵ġ£ÏêϸµÄºÚÃûµ¥ÆÊÎö¶ÁÕß¿ÉÒÔ×ÔÐÐÑо¿¡£
2 Jackson·´ÐòÁл¯
JacksonÊÇÒ»¸ö¿ªÔ´µÄJavaÐòÁл¯Óë·´ÐòÁл¯¹¤¾ß£¬¿ÉÒÔ½«java¹¤¾ßÐòÁл¯Îªxml»òjsonÃûÌõÄ×Ö·û´®£¬»òÕß·´ÐòÁл¯»Ø¶ÔÓ¦µÄ¹¤¾ß£¬ÓÉÓÚÆäʹÓüòÆÓ£¬ËÙÂʽϿ죬ÇÒ²»ÒÀÀµ³ýJDKÍâµÄÆäËû¿â£¬±»ÖÚ¶àÓû§ËùʹÓ᣿ÉÊÇÆä×é¼þJackson-databind¿ÉÒÔÖ¸¶¨Ìض¨µÄ·´ÐòÁл¯À࣬ÕâÑù¾Í±£´æ´úÂëÖ´ÐеÄΣº¦¡£
ºóÐø¹Ù·½ÐÞ²¹
CVE-2017-15095ÊÇCVE-2017-7525µÄÑÓÐø£¬Õâ¸öÎó²îͬÑùÒ²ÊDZ¾ÎÄ×÷Õß±¨¸æµÄ¡£Í¬ÑùÊǺÚÃûµ¥µÄÈÆ¹ý¡£ CVE-2017-17485ÊÇCVE-2017-7525µÄÑÓÐø£¬Õâ¸öÎó²îÒýÈëµÄÀàÊÇorg.springframework.context.support.ClassPathXmlApplicationContextʹÓÃÕâ¸ö¿âµÄbeanÖØÐÂÌìÉúÀ࣬¶øÕâ¸öbeanËùÒÀÀµµÄxmlÊÇÓɹ¥»÷ÕßÀ´¶¨ÖƵġ£´ÓÕâÀïÒ²¿ÉÒÔ¿´³öºÚÃûµ¥¾ÍÊǸöÎÞµ×¶´£¬Éî²»¿É¼û£¬bypassÒ²ÊDz»Íê¡£ÓÉÓÚJacksonµÄÌØÕ÷£¬¿ÉÒÔÕ¹Íû£¬JacksonÔÚ2018Ä껹½«·ºÆð¸ü¶àµÄÈÆ¹ý¡£
3 Struts2
struts2ºÅ³ÆÎó²îÖ®Íõ£¬2017Ó¦¼±Öоʹ¦Öóͷ£ÁËS2-045£¬S2-046£¬S2-48£¬S2-052£¬S2-055£¬¶¼ÊÇÔ¶³Ì´úÂëÖ´Ðм¶±ðµÄÎó²î¡£S2-045µÄPoCÏÖÔÚ»¹±»ºÚ¿ÍÓÃÓÚÖÖÖÖÎó²îɨÃ裬ÍÚ¿ó¡£¼ÈÈ»ÊÇÎó²îÖ®Íõ£¬ÄÇ×ÔÈ»ÉÙ²»ÁË·´ÐòÁл¯£¬S2-052£¨CVE-2017-9805£©¾ÍÊÇXStreamʹÓò»µ±Ôì³ÉµÄ·´ÐòÁл¯¡£S2-055ÔòÊÇÓÉÓÚJackson-databindµ¼Öµķ´ÐòÁл¯¡£ÕâÁ½¸öÎó²îµÄµä·¶Ìص㶼ÊDz»Êʵ±µÄʹÓõÚÈý·½¿âµ¼Öµġ£
S2-052ÆÊÎö
ƾ֤¹Ù·½µÄÐÎòÐÅÏ¢À´¿´£¬ÊÇREST²å¼þʹÓõ½XStreamHandler´¦Öóͷ£xmlÊý¾ÝµÄʱ¼ä£¬ÓÉÓÚδ¶ÔxmlÊý¾Ý×öÈκιýÂË£¬ÔÚ¾ÙÐз´ÐòÁн«xmlÊý¾Ýת»»³ÉObjectʱµ¼ÖµÄRCE¡£
S2-055ÆÊÎö
2017Äê12ÔÂ1ÈÕ£¬Apache StrutsÐû²¼×îеÄÇ徲ͨ¸æ£¬Apache Struts 2.5.x REST²å¼þ±£´æÔ¶³Ì´úÂëÖ´ÐеÄÖÐΣÎó²î£¬Îó²î±àºÅÓëCVE-2017-7525Ïà¹Ø¡£Îó²îµÄ³ÉÒòÊÇÓÉÓÚʹÓõÄJackson°æ±¾¹ýµÍÔÚ¾ÙÐÐJSON·´ÐòÁл¯µÄʱ¼äûÓÐÈκÎÀàÐ͹ýÂ˵¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ËäÈ»¹Ù·½ËµµÄÓ°ÏìÊÇδ֪£¬×ÅʵÕâÀïÊÇÔ¶³Ì´úÂëÖ´ÐС£
4 Weblogic
ÔÚ2017Ä꣬Õû¸öOracleµÄ²úÆ·Ïß¶¼ÉîÊÜ·´ÐòÁл¯Ó°Ï죬ÆäÖÐWeblogicÓ°ÏìÃæÓÈÆäÆÕ±é£¬Ðí¶àÎó²îµÄCVSSÆÀ·Ö¶¼ÊÇ9.8£¬9.9ÉõÖÁΪ10¡£
²¢ÇÒCVE-2017-3248µÄPoCÒѾÔÚgithubÉÏ£¬²¢ÇÒ±»ÓÃÓÚºÚ²ú£¬CVE-2017-10352 PoCÒ²±»Ð¹Â¶Í¬Ñù±»ÓÃÓÚºÚ²ú¡£
CVE-2017-3248 ÆÊÎö
Õâ¸öÎó²î(CVE-2017-3248)¾ÍÊÇʹÓÃrmi»úÖÆµÄȱÏÝ£¬Í¨¹ýJRMPÐÒéµÖ´ïÖ´ÐÐí§Òâ·´ÐòÁл¯payloadµÄÄ¿µÄ¡£Ê¹Óð취¿ÉÒÔ·ÖΪÁ½²½£¬µÚÒ»²½½¨ÉèJRMP¼àÌý¶Ë¿Ú£¬µÚ¶þ²½Ö´Ðз´ÐòÁл¯²Ù×÷£¬Æä·´ÐòÁл¯ÄÚÈÝÖ¸ÏòÍⲿµÄJRMP¼àÌý¶Ë¿Ú£¬ÕâÑùÔÚ·´ÐòÁеÄÀú³ÌÖоͻá´ÓÔ¶³ÌJRMP¼àÌý¶Ë¿Ú¼ÓÔØÄÚÈݲ¢Ö´ÐÐÐòÁл¯²Ù×÷£¬ÏêϸµÄʹÓù¤¾ß¿ÉÒÔʹÓÃysoserial¡£
CVE-2017-10352 ÆÊÎö
Õâ¸öÎó²îÊÇÓÉÓÚXMLDecoderÕâ¸öȱÏݿⱣ´æ´úÂëÖ´ÐÐÎÊÌ⣬ͬÑùÒ²ÊÇÓÉÓÚ±»ºÚ²úʹÓöø±»¸÷ÈËÆÕ±éµÃÖª¡£×ÅʵÔÚCVE-2017-3506ÖУ¬Weblogic¹Ù·½ÒѾ×öÁËÒ»´ÎÐÞ²¹£¬Ö»ÊÇÆäʱµÄÐÞ²¹²»·ó³¹µ×£¬ØÊºóÓÐÑо¿Ô±¸øWeblogicÌṩÁËÈÆ¹ýµÄPoC£¬Weblogic¹Ù·½ÔÙ´ÎÍêÕûÐÞ²¹¡£Í¬Ê±Õâ¸öPoCÒ²±»Ð¹Â¶£¬ºÜÊǶàµÄÓû§ÖÐÕС£
¶Ôsrcip£º173.212.217.181ËÝÔ´¸ú×Ù£¬´ÓAG¹«Ë¾¿Æ¼¼ÍþвÇ鱨ÖÐÐÄNTIÖеÄÊý¾ÝÒ²ÄÜ¿´³ö£¬¸ÃIP´Ó2017Äê8Ô·Ý×îÏÈ£¬Ò»Ö±±»ÓÃÓÚÌØ¶¨Îó²îɨÃèÒԱ㷢Ã÷¸ü¶à¾ßÓÐųÈõÐÔµÄÖ÷»ú¡£
×ܽá
´ÓOWASP 2017 top ten±¨¸æÖпÉÒÔ¿´³ö·´ÐòÁл¯ÊÇÒ»¸öÒµÄÚ¶¼×îÏȹØ×¢ÖØÊÓµÄÎó²îÀàÐÍ£¬Ò»¸öÔµ¹ÊÔÓɾÍÊǸÃÎó²îÐí¶àʱ¼ä¶¼ÊÇͨ¹ýºÚÃûµ¥µÄ·½·¨µÄÐÞ¸´£¬Õâ¾Íµ¼ÖÂÁ˲ã³ö²»ÇîµÄÈÆ¹ý£¬´ÓJackson£¬fastjson£¬weblogicÒ»¼ûüĿ£¬¶¼ÊÇÐÞ¸´£¬Èƹý£¬ÔÙÐÞ¸´£¬ÔÙÈÆ¹ý£¬Ã»ÓÐÖ¹¾³¡£ÁíÍâÒ»¸öÔµ¹ÊÔÓɾÍÊǸÃÎó²îµÄΣº¦ºÜÊÇ´ó£¬Í¨³£¶¼ÊÇRCE£¬Ò»¸öPoCÖ±½Ó»ñȡϵͳȨÏÞ£¬²»¹ÜÊǺڲú£¬»Ò²ú£¬¿ª·¢£¬ÔËάÉÐÓа×ñÇå¾²Ö°Ô±¶¼ºÜÊÇÖØÊÓ¸ÃÀàÐ͵ÄÎó²î¡£´ÓϵͳµÄÖ÷ÒªÐÔÀ´¿´£¬º£ÄÚÐí¶àÉÌҵϵͳ¶¼ÊÇ»ùÓÚJava¿ò¼Ü¿ª·¢£¬ÕâЩÖÐÐļþ»òÕßWebÈÝÆ÷Ò»µ©·ºÆðÎó²î£¬Õû¸öϵͳ¶¼±äµÃ²»¿°Ò»»÷£¬¿ÉÄÜÔì³É²»¿ÉÍì»ØµÄÓ°Ïì¡£ ¹ØÓÚ·´ÐòÁÐÎó²îµÄ·ÀÓù£¬ÒµÄÚÒ²ÊÇÒ»¸öÄÑÌ⣬Ê×ÏȵÃÈ·±£ËùÓеÄÒÀÀµ¿âºÍÈÝÆ÷ÒѾ¸üе½×îа汾£¬ÕâÑùÄܱÜÃâÒÑÖªÎó²îµÄ¹¥»÷¡£ÁíÍâAG¹«Ë¾¿Æ¼¼µÄIPS£¬WAF¶¼ÒѾ¾ß±¸¶ÔÕâЩÎó²îµÄ·À»¤ÄÜÁ¦£¬¸ü¶àµÄ·À»¤Õ½ÂÔÇë²Î¿¼AG¹«Ë¾¿Æ¼¼ÏÂһƪ¹ØÓÚ·´ÐòÁл¯Îó²î·ÀÓùµÄÎĵµ¡£

AG¹«Ë¾ÔÆ





