¡¾Ç徲ͨ¸æ¡¿SolarWinds?Serv-U?Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35211£©Í¨¸æ
2021-07-13
Ò». Îó²î¸ÅÊö
¿ËÈÕ£¬AG¹«Ë¾¿Æ¼¼CERT¼à²âµ½SolarWindsÐû²¼Ç徲ͨ¸æ£¬ÐÞ¸´ÁËServ-UÖб£´æµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-35211£©£¬¸ÃÎó²îΪ΢Èí·¢Ã÷ÔÚҰʹÓúóÏòSolarWinds±¨¸æ£¬²¢ÌṩÁËÎó²îʹÓõĿ´·¨Ö¤Êµ¡£Î´¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßʹÓôËÎó²î¿ÉÔÚÊÜÓ°ÏìµÄ·þÎñÆ÷ÉÏÒÔÌØÊâȨÏÞÖ´ÐÐí§Òâ´úÂ룬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£
SolarWindsÌåÏÖ´ËÎó²î±£´æÓÚSSHÐÒéÖУ¬Óë SUNBURST ¹©Ó¦Á´¹¥»÷Î޹أ¬½öÓ°ÏìSolarWinds Serv-U Managed File TransferºÍServ-U Secure FTP¡£Ê¹ÓÃServ-UÖÎÀí¿ØÖÆÌ¨Ïòµ¼½¨ÉèÓòʱ»áĬÈÏÑ¡ÔñÆôÓÃSSH£¬ÈôServ-UÇéÐÎÖÐδÆôÓÃSSHÔò²»ÊÜ´ËÎó²îÓ°Ïì¡£
²Î¿¼Á´½Ó£º
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35211
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
Serv-U < = 15.2.3 HF1
²»ÊÜÓ°Ïì°æ±¾
Serv-U = 15.2.3 HF2
Èý. ÍþвÅŲé
1¡¢Óû§¿É¼ì²éServ-UÇéÐÎÖÐÊÇ·ñÆôÓÃÁËSSH£º
×¢£ºÊ¹ÓÃServ-UÖÎÀí¿ØÖÆÌ¨Ïòµ¼½¨ÉèÓòʱ»áĬÈÏÑ¡ÔñÆôÓÃSSH£¬Èôδ×÷·Ï¹´Ñ¡ÔòÊÜ´ËÎó²îÓ°Ïì¡£
2¡¢¼ì²éServ-UÇéÐÎÊÇ·ñÓÐÅ׳öÒì³£
ÍøÂçDebugSocketlog.txtÈÕÖ¾Îļþ£¬Éó²éÊÇ·ñ±£´æÏÂÁÐÒì³£ÈÕÖ¾£º
|
07] Tue 01Jun21 02:42:58 - EXCEPTION: C0000005; CSUSSHSocket::ProcessReceive(); Type: 30; puchPayLoad = 0x041ec066; nPacketLength = 76; nBytesReceived = 80; nBytesUncompressed = 156; uchPaddingLength = 5 |
3¡¢Óû§¿ÉÅŲéSSHÊÇ·ñ±£´æ¿ÉÒÉÅþÁ¬
SolarWindsÐû²¼µÄDZÔÚ¹¥»÷Ö¸±êIP£º
98.176.196.89
68.235.178.32
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÕë¶Ô¸ÃÎó²îÐû²¼ÁËÐÞ¸´³ÌÐò£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì×°ÖøüоÙÐзÀ»¤£¬¹Ù·½ÏÂÔØÁ´½Ó£º https://customerportal.solarwinds.com/
|
ÊÜÓ°Ïì°æ±¾ |
Éý¼¶·½·¨ |
|
Serv-U 15.2.3 HF1°æ±¾ |
Ö±½ÓÉý¼¶¸üÐÂÖÁServ-U 15.2.3 HF2 |
|
Serv-U 15.2.3°æ±¾ |
ÏÈÉý¼¶ÖÁServ-U 15.2.3 HF1£¬È»ºóÔÙ¸üÐÂÖÁServ-U 15.2.3 HF2¡£ |
|
Serv-U < 15.2.3°æ±¾ |
ÏÈÉý¼¶ÖÁServ-U15.2.3£¬ÔÙ¸üÐÂÖÁServ-U 15.2.3 HF1£¬È»ºóÔÙÉý¼¶¸üÐÂÖÁ Serv-U 15.2.3 HF2¡£ |
ÏêϸװÖý̳ÌÇë²Î¿¼£ºhttps://support.solarwinds.com/SuccessCenter/s/article/Serv-U-15-2-3-HotFix-2?language=en_US
4.2 ÆäËû·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶¸üУ¬Ò²¿ÉÔÚÖÎÀí¿ØÖÆÌ¨ÖнûÓÃSSH¼àÌýÆ÷¶Ô´ËÎó²î¾ÙÐзÀ»¤£º
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

AG¹«Ë¾ÔÆ







