¡¾Çå¾²Íþвͨ¸æ¡¿vBulletinÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-16759£©
2019-09-27
×ÛÊö
vBulletinÊÇÒ»¿îǿʢ£¬ÎÞа²¢¿ÉÍêȫƾ֤×Ô¼ºµÄÐèÒª¶¨ÖƵÄÂÛ̳³ÌÐòÌ×¼þ¡£Ö»¹ÜÊÇÉÌÒµ²úÆ·£¬µ«´ÓÊг¡·Ý¶îºÍÏÖʵʹÓÃÁ¿ÉÏ¿´£¬vBulletinÕվɵ±½ñ×îÊܽӴýµÄWebÂÛ̳Èí¼þ°ü¡£
ÍâµØÊ±¼ä24ºÅ£¬¾ÝÍâý±¨µÀ£¬ÓÐÄäÃûÇå¾²Ñо¿Ô±ÔÚ¹ûÕæÓʼþÁбíÖÐÐû²¼ÁËvBulletinµÄÒ»¸ö0dayÎó²îÏêÇé¡£¸ÃÎó²îÔÊÐí¹¥»÷ÕßÔÚ²»ÓµÓÐÄ¿µÄÂÛ̳ÕË»§µÄÇéÐÎÏ£¬ÔÚÔËÐÐvBulletinµÄ·þÎñÆ÷ÉÏÖ´ÐÐShellÏÂÁÊÇÒ»¸öÎÞÐèÉí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
Îó²î¹ûÕæÐû²¼Ö®³õ£¬Éв»ÇåÎúÄäÃûÑо¿Ö°Ô±ÊÇ·ñÏòvBulletinÍŶӱ¨¸æÁ˸ÃÎó²î»òÕßvBulletinÍŶÓÊÇ·ñδÄÜʵʱ½â¾ö´ËÎÊÌ⣬´Ó¶ø´ÙʹÑо¿Ö°Ô±¹ûÕæÐû²¼¡£¸Ã0day½öÓ°ÏìvBulletin 5.x°æ±¾¡£
ÔÚÒÔºóµÄ¼¸ÌìÄÚ£¬ÓÐ×éÖ¯±¨¸æ·¢Ã÷ÓÐÔÚÒ°¹¥»÷ÕßÊÔͼʹÓÃCVE-2019-16759¾ÙÐй¥»÷¡£Ò»Ð©vBulletinÂÛ̳µÄÖÎÀíÔ±Ò²·´Ó¦ÔÚ¸ÃÎó²îÅû¶ºó£¬ÖÎÀíµÄÍøÕ¾ÉÏ·ºÆðÁËweb shell¡£
ÍâµØÊ±¼ä26ÈÕ£¬vBulletin¿ª·¢ÕßÐû²¼ÁËÕë¶Ô¸ÃÎó²îµÄ²¹¶¡¡£ÇëÏà¹ØÓû§²Î¿¼ÒÔÏÂÇå¾²½¨Òé¾ÙÐÐÐÞ¸´¡£
²Î¿¼Á´½Ó£º
[1]https://www.zdnet.com/article/anonymous-researcher-drops-vbulletin-zero-day-impacting-tens-of-thousands-of-sites/
[2]¹ûÕæÓʼþÁбí
https://seclists.org/fulldisclosure/2019/Sep/31
[3]http://feedproxy.google.com/~r/Securityweek/~3/MqX-Favv0oU/vbulletin-patches-vulnerability-exploited-wild
[4]¹Ù·½Í¨¸æ
https://forum.vbulletin.com/forum/vbulletin-announcements/vbulletin-announcements_aa/4422707-vbulletin-security-patch-released-versions-5-5-2-5-5-3-and-5-5-4
Çå¾²½¨Òé
vBulletin¹Ù·½ÒÑÐû²¼Õë¶ÔÒÔϰ汾µÄÇå¾²²¹¶¡£¬ÇëǰÍùhttps://www.vbulletin.com/en/customer/account/login/?goto=aHR0cHM6Ly9tZW1iZXJzLnZidWxsZXRpbi5jb20vcGF0Y2hlcy5waHA%3D ÏÂÔØ£º
l 5.5.4 Patch Level 1
l 5.5.3 Patch Level 1
l 5.5.2 Patch Level 1
½¨ÒéʹÓÃ5.5.2֮ǰ°æ±¾µÄÓû§¾¡¿ìÉý¼¶µ½Êܱ£»¤µÄ°æ±¾¡£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
¹ØÓÚAG¹«Ë¾¿Æ¼¼
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾£¨¼ò³ÆAG¹«Ë¾¿Æ¼¼£©½¨ÉèÓÚ2000Äê4Ô£¬×ܲ¿Î»ÓÚ±±¾©¡£ÔÚº£ÄÚÍâÉèÓÐ30¶à¸ö·ÖÖ§»ú¹¹£¬ÎªÕþ¸®¡¢ÔËÓªÉÌ¡¢½ðÈÚ¡¢ÄÜÔ´¡¢»¥ÁªÍøÒÔ¼°½ÌÓý¡¢Ò½ÁƵÈÐÐÒµÓû§£¬Ìṩ¾ßÓн¹µã¾ºÕùÁ¦µÄÇå¾²²úÆ·¼°½â¾ö¼Æ»®£¬×ÊÖú¿Í»§ÊµÏÖÓªÒµµÄÇ徲˳³©ÔËÐС£
»ùÓÚ¶àÄêµÄÇå¾²¹¥·ÀÑо¿£¬AG¹«Ë¾¿Æ¼¼ÔÚÍøÂç¼°ÖÕ¶ËÇå¾²¡¢»¥ÁªÍø»ù´¡Çå¾²¡¢ºÏ¹æ¼°Çå¾²ÖÎÀíµÈÁìÓò£¬Îª¿Í»§ÌṩÈëÇÖ¼ì²â/·À»¤¡¢¿¹¾Ü¾ø·þÎñ¹¥»÷¡¢Ô¶³ÌÇå¾²ÆÀ¹ÀÒÔ¼°WebÇå¾²·À»¤µÈ²úÆ·ÒÔ¼°×¨ÒµÇå¾²·þÎñ¡£
±±¾©ÉñÖÝAG¹«Ë¾ÐÅÏ¢Çå¾²¿Æ¼¼¹É·ÝÓÐÏÞ¹«Ë¾ÓÚ2014Äê1ÔÂ29ÈÕÆðÔÚÉîÛÚ֤ȯÉúÒâËù´´Òµ°åÉÏÊУ¬¹ÉƱ¼ò³Æ£ºAG¹«Ë¾¿Æ¼¼£¬¹ÉƱ´úÂ룺300369¡£

AG¹«Ë¾ÔÆ





