¡¾Â©¶´Í¨¸æ¡¿WordPress Tatsu Builder²å¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´ £¨CVE-2021-25094£©

Ðû²¼Ê±¼ä 2022-05-18

 

0x00 ©¶´¸ÅÊö

CVE   ID

CVE-2021-25094

·¢ÏÖʱ¼ä

2022-05-16

Àà    ÐÍ

RCE

µÈ      ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°Ï췶Χ


¹¥»÷ÅÓ´ó¶È

¸ß

Óû§½»»¥

ÎÞ

PoC/EXP

ÊÇ

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ©¶´ÏêÇé

WordPress Tatsu Builder²å¼þÊÇÒ»¸öÁ÷ÐеÄÎÞ´úÂëÒ³Ãæ¹¹½¨Æ÷£¬ËüÌṩÁ˼¯³Éµ½ÍøÂçä¯ÀÀÆ÷ÖеÄÇ¿´óÄ£°å±à¼­¹¦Ð§¡£

2022Äê5ÔÂ16ÈÕ£¬Wordfence ÍþвÇ鱨ÍŶÓÅû¶ÁËÕë¶ÔTatsu Builder ²å¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-25094£©µÄ´ó¹æÄ£¹¥»÷¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.1£¬¿ÉÒÔÀûÓøÃ©¶´ÔÚδ¾­Éí·ÝÑéÖ¤µÄÇé¿öÏÂÎÞÏÞÖÆÉÏ´«Îļþ²¢ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

ÓÉÓÚ3.3.12֮ǰµÄTatsu WordPress²å¼þadd_custom_font²Ù×÷¿ÉÒÔÔÚδÈÏÖ¤µÄÇé¿öϱ»ÓÃÀ´ÉÏ´«¶ñÒâzipÎļþ£¬¸ÃÎļþÔÚWordPressµÄÉÏ´«Ä¿Â¼ÏÂûÓб»Ñ¹Ëõ¡£¿ÉÒÔͨ¹ýÌí¼ÓÒ»¸öÎļþÃûÒÔµã". "¿ªÍ·µÄPHP shellÀ´Èƹý²å¼þÖÐʵÏÖµÄÀ©Õ¹¿ØÖÆ¡£´ËÍ⣬ÓÉÓÚzip ÌáÈ¡¹ý³ÌÖдæÔÚ¾ºÕùÌõ¼þ£¬Ê¹µÃ shell ÎļþÔÚÎļþϵͳÉϵĴæÔÚʱ¼ä½Ï³¤£¬¶ø¿ÉÒÔ±»µ÷Ó᣸é¶´µÄϸ½Ú¼°ÆäPoCÒÑÓÚ2022 Äê3 Ô±»¹ûÈ»Åû¶¡£

WordfenceÑо¿ÈËÔ±ÌåÏÖ£¬¸Ã²å¼þµÄ°²×°Á¿ÔÚ 20,000 - 50,000 Ö®¼ä£¬ÇÒÆä¿Í»§ÔÚ5ÔÂÔâÊÜÁËÕë¶Ô´Ë©¶´µÄÊý°ÙÍò´Î¹¥»÷£¬¹¥»÷ÕßÊÔͼÔÚ wp-content/uploads/typehub/custom/Ŀ¼µÄ×ÓÎļþ¼ÐÖÐ×¢Èë¶ñÒâÈí¼þdropper£¬²¢Ê¹Æä³ÉΪÒþ²ØÎļþ¡£¸ÃdropperÃûΪ".sp3ctra_XO.php"£¬ÆäMD5¹þϣֵΪ3708363c5b7bf582f8477b1c82c8cbf8¡£

ƾ¾ÝWordfenceµÄ³ÂËߣ¬Áè¼Ý°ÙÍò´ÎµÄ¹¥»÷½öÀ´×ÔÈý¸öIPµØÖ·£º148.251.183[.]254¡¢176.9.117[.]218ºÍ217.160.145[.]62£¬½¨ÒéʹÓÃWordPress Tatsu Builder²å¼þµÄÍøÕ¾¹ÜÀíÔ±½«ÕâЩIPÌí¼Óµ½ºÚÃûµ¥£¨²»Îȶ¨£©²¢¼°Ê±¸üе½×îа汾¡£

 

Ó°Ï췶Χ

Wordpress Tatsu Builder ²å¼þ°æ±¾ < 3.3.12

 

0x02 Äþ¾²½¨Òé

Ŀǰ´Ë©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶¸üе½Tatsu Builder ²å¼þ×îа汾3.3.13¡£

ÏÂÔØÁ´½Ó£º

https://tatsubuilder.com/

×¢£º3.3.12°æ±¾°üÂÞ²¿ÃŲ¹¶¡£¬µ«²¢Î´ÍêÈ«ÐÞ¸´¡£

 

0x03 ²Î¿¼Á´½Ó

https://www.wordfence.com/blog/2022/05/millions-of-attacks-target-tatsu-builder-plugin/

https://darkpills.com/wordpress-tatsu-builder-preauth-rce-cve-2021-25094/

https://www.bleepingcomputer.com/news/security/hackers-target-tatsu-wordpress-plugin-in-millions-of-attacks/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2022-05-18

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶¶È¦Îª¶Ä¶øÉú¼ò½é

¶¶È¦Îª¶Ä¶øÉú¹«Ë¾½¨Á¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂçÄþ¾²²úÎï¡¢¿ÉÐÅÄþ¾²¹ÜÀíÆ½Ì¨¡¢Äþ¾²·þÎñÓë½â¾ö·½°¸µÄ×ÛºÏÌṩÉÌ¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬ÓµÓÐÁýÕÖÈ«¹úµÄÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£

¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£


¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú

¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png