¡¾Â©¶´Í¨¸æ¡¿SolarWinds Serv-UÊäÈëÑé֤©¶´ (CVE-2021-35247)
Ðû²¼Ê±¼ä 2022-01-210x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-35247 | ʱ ¼ä | 2022-01-18 |
Àà ÐÍ | ÊäÈëÑéÖ¤´íÎó | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | Óû§½»»¥ | ÊÇ |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ©¶´ÏêÇé
SolarWinds Serv-UÊÇÃÀ¹úSolarWinds¹«Ë¾µÄÒ»Ì×FTPºÍMFTÎļþ´«ÊäÈí¼þ¡£
1ÔÂ18ÈÕ£¬SolarWindsÐû²¼Äþ¾²Í¨¸æ£¬Serv-UÖдæÔÚÒ»¸öÊäÈëÑé֤©¶´ (CVE-2021-35247)£¬ÆäCVSSv3ÆÀ·Ö×î¸ßΪ5.3¡£
ÓÉÓÚServ-UµÄÊäÈëÑéÖ¤´æÔÚÄþ¾²ÎÊÌ⣬LDAP Éí·ÝÑéÖ¤µÄ Serv-U Web µÇ¼δ³äʵ¹ýÂË×Ö·û¡£Ä¿Ç°SolarWinds ÒѸüÐÂÊäÈë»úÖÆ¡£
1ÔÂ19ÈÕ£¬Î¢ÈíÔÚÆä¹Ù·½²©¿ÍÖÐÅû¶ÁËCVE-2021-35247£¬²¢ÌåÏÖÒÑÊӲ쵽ÀûÓôË©¶´ÊµÏÖÓë Log4jÏà¹ØµÄ¹¥»÷»î¶¯¡£
×ÔÈ¥Äê12ÔÂÅû¶ÒÔÀ´£¬Log4j©¶´Òѱ»¶à¸öºÚ¿ÍÍÅ»ïÀûÓã¬Í¨¹ý¶ÔÒ×Êܹ¥»÷µÄÍøÂç½øÐдó¹æÄ£É¨ÃèºÍÉøÍ¸£¬À´²¿ÊðºóÃÅ¡¢¼ÓÃܿ󹤡¢ÀÕË÷Èí¼þºÍÔ¶³Ì shell£¬´Ó¶øÎª½øÒ»²½µÄ»î¶¯Ìṩ³Ö¾Ã·ÃÎÊȨÏÞ¡£
Ó°Ï췶Χ
SolarWinds Serv-U <= 15.2.5
0x02 Äþ¾²½¨Òé
Ŀǰ´Ë©¶´ÒѾÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìÓû§¼°Ê±Éý¼¶¸üе½Serv-U 15.3»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.solarwinds.com/serv-u-managed-file-transfer-server
×¢£ºSolarWinds¹Ù·½Í¨¸æÌåÏÖ£¬ÓÉÓÚ LDAP ·þÎñÆ÷ºöÂÔÁËijЩ×Ö·û£¬Òò´Ëδ¼ì²âµ½ÏÂÓÎÊÇ·ñÊÜÓ°Ïì¡£
0x03 ²Î¿¼Á´½Ó
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#CVE-2021-35247
https://thehackernews.com/2022/01/microsoft-hackers-exploiting-new.html
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-01-21 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º