2025Äê©¶´¸´ÏÖ£¨2025Äê©¶´¸´ÏÖ2024£©
¡¾Â©¶´¸´ÏÖ-druid-ÈÎÒâÎļþ¶ÁÈ¡¡¿vulfocus/druid-cve_2021_36749_°Ù¶È...
¸Ã©¶´ÊÇÓÉÓÚÓû§Ö¸¶¨µÄ HTTP InputSource ûÓÐ×ö³ö×ã¹»µÄÏÞÖÆ£¬µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý½«Îļþ URL ´«µÝ¸ø HTTP InputSource À´ÈƹýÓ¦ÓóÌÐò¼¶±ðµÄÏÞÖÆ¡£ÀûÓôË©¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇé¿öϹ¹Ôì¶ñÒâÇëÇóÖ´ÐÐÎļþ¶ÁÈ¡£¬×îÖÕÔì³É·þÎñÆ÷Ãô¸ÐÐÔÐÅϢй¶¡£

¡¾Â©¶´¸´ÏÖ¡¿cve-2019-14287
1¡¢×ܽáCVE-2019-14287ÊÇÒ»¸öÑÏÖØµÄ±¾µØÌáȨ©¶´£¬Í¨¹ýÐÞ¸Ä/etc/sudoersÎļþ²¢ÀûÓÃSudoµÄȨÏÞÌáÉý»úÖÆ£¬¹¥»÷Õß¿ÉÒÔ»ñµÃrootȨÏÞ¡£Òò´Ë£¬½¨Òéϵͳ¹ÜÀíÔ±¼°Ê±Éý¼¶Sudoµ½×îа汾£¬²¢¶¨ÆÚ¼ì²éϵͳµÄ°²È«ÅäÖã¬ÒÔ·ÀÖ¹´ËÀà©¶´µÄÀûÓá£ÔÚ¸´ÏÖ©¶´Ê±£¬Îñ±ØÔÚÊܿغͺϷ¨µÄ»·¾³ÖнøÐУ¬ÒÔ±ÜÃâ¶ÔÉú²úϵͳÔì³É²»±ØÒªµÄË𺦡£
2¡¢Sudo ¿ª·¢Õ߳ƣº ¡°Ö»Òª Runas ¹æ·¶Ã÷È·½ûÖ¹ root ·ÃÎÊ¡¢Ê×ÏÈÁгö ALL ¹Ø¼ü×Ö£¬¾ßÓÐ×ã¹» sudo ȨÏÞµÄÓû§¾Í¿ÉÒÔʹÓÃËüÀ´ÒÔ root Éí·ÝÔËÐÐÃüÁî¡£¡±¾ÝϤ£¬¸Ã©¶´ÓÉ Æ»¹û ÐÅÏ¢°²È«²¿ÃÅµÄ Joe Vennix ×·×Ù·¢ÏÖ£¨CVE-2019-14287£©¡£ÇÒÏëÒªÀûÓÃÕâ¸ö bug£¬Ö»Ðè Sudo User ID -1 »ò 4294967295 ¡£
3¡¢¾ÝϤ£¬¸Ã©¶´ÓÉÆ»¹ûÐÅÏ¢°²È«²¿ÃÅµÄ Joe Vennix ×·×Ù·¢ÏÖ£¨Â©¶´µÄ CVE ID Ϊ CVE-2019-14287£©¡£
4¡¢¸Ã©¶´ÓÉÆ»¹ûÐÅÏ¢°²È«²¿ÃÅµÄ Joe Vennix ×·×Ù·¢ÏÖ£¬Â©¶´µÄ CVE ID Ϊ CVE201914287¡£ÐÞ¸´´Ë©¶´µÄ·½·¨Êǽ« sudo Éý¼¶µ½ 28 ×îа汾¡£¸Ã©¶´»áÓ°Ïì 28 ֮ǰµÄËùÓа汾¡£½¨Ò飺 ¾¡¿ì½«ÏµÍ³ÖÐµÄ sudo Éý¼¶µ½×îа汾£¬ÒÔ±ÜÃâ¸Ã©¶´´øÀ´µÄ°²È«·çÏÕ¡£
Log4j2©¶´¸´ÏÖ-ÔÀí-²¹¶¡Èƹý
1¡¢Log4j2©¶´µÄ¸´ÏÖÖ÷Òª»ùÓÚJNDI×¢Èë¡£¹¥»÷Õßͨ¹ýÔÚÈÕÖ¾ÖвåÈë°üº¬¶ñÒâLDAP»òRMIÐÒéÄÚÈݵÄ×Ö·û´®£¬´¥·¢Log4j2½âÎö²¢Ö´ÐÐÔ¶³Ì·þÎñÆ÷ÉϵĶñÒâClassÎļþ£¬´Ó¶ø´ïµ½¹¥»÷Ä¿µÄ¡£¸´ÏÖ²½Öè¼òÊöÈçÏ£º»·¾³×¼±¸£º´î½¨Ò»¸ö°üº¬Log4j2ÒÀÀµµÄJavaÏîÄ¿£¬²¢È·±£ÏîĿʹÓõÄJDK°æ±¾´æÔÚ©¶´£¨ÈçJDK 8u202ÒÔϰ汾£©¡£
2¡¢Log4j2©¶´µÄÔÀíÖ÷ÒªÔÚÓÚlookupº¯ÊýµÄÓû§¿É¿ØÐÔ£¬ÒÔ¼°¶ÔschemeºÍhostµÄ°×Ãûµ¥Ð£Ñé²»×ã¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚÈÕÖ¾ÖвåÈë¶ñÒâµÄJNDIÁ´½Ó£¬´¥·¢lookupº¯ÊýÈ¥¼ÓÔØºÍÖ´ÐжñÒâµÄClassÎļþ¡£Èç¹ûlog4j2µÄÅäÖÃÖÐûÓÐÕýÈ·ÉèÖð×Ãûµ¥£¬»òÕß°×Ãûµ¥±»ÀÄÓ㬾ͻá³ÉΪ¹¥»÷ÕßµÄÈÆ¹ýµã£¬´Ó¶øµ¼Ö©¶´±»ÀûÓá£
3¡¢log4j2ÖдæÔÚJNDI×¢Èë©¶´£¬µ±³ÌÐò¼Ç¼Óû§ÊäÈëµÄÊý¾Ýʱ£¬Èç¹ûδ¶Ô×Ö·ûºÏ·¨ÐÔ½øÐÐÑϸñµÄÏÞÖÆ£¬¹¥»÷Õß¿ÉÒÔ¹¹Ôì¶ñÒâµÄURLµØÖ·ÈÃÆä½âÎö£¬ÀûÓÃJNDIÐÒé¼ÓÔØµÄÔ¶³Ì¶ñÒâ½Å±¾£¬´Ó¶øÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¡£
4¡¢Log4J2©¶´ÔÀí¼°¸´ÏÖ Â©¶´ÔÀíÉîÈëÆÊÎö£º Log4j2¹¦ÄÜ£ºApache Log4j2ÊÇÒ»¸ö¿ªÔ´µÄÈÕÖ¾¹ÜÀí¿â£¬ÎªJavaÓ¦ÓóÌÐòÌṩǿ´óµÄÈÕÖ¾¹¦ÄÜ¡£ËüÔÊÐíʹÓøñʽ»¯²ÎÊýÀ´¼Ç¼ÈÕÖ¾£¬ÀýÈçlogger.info¡£ JNDI×¢Èë·çÏÕ£ºµ±ÊäÈë²ÎÊýÎªÌØ¶¨¸ñʽʱ£¬Log4j2»á½âÎö²¢·µ»ØÊµ¼ÊµÄJava°æ±¾£¬Õâ¹¹³ÉÁËDZÔڵݲȫ·çÏÕ¡£
©¶´¸´ÏÖ¡ª¡ªÓÀºãÖ®À¶
ΪÁ˳ɹ¦¸´ÏÖÓÀºãÖ®À¶Â©¶´£¬ÐèҪ׼±¸ÒÔÏ»·¾³£º¹¥»÷»ú£ºÊ¹ÓÃKaliÐéÄâ»ú£¬²¢°²×°Metasploit£¨MSF£©¿ò¼Ü¡£°Ð»ú£ºÊ¹ÓÃWindows 7ϵͳ£¬²¢È·±£¹Ø±Õ·À»ðǽ»ò¿ªÆô445¶Ë¿Ú¡£Í¬Ê±£¬¹¥»÷»úºÍ°Ð»úÐèҪȷ±£»¥Ïà¿ÉÒÔpingͨ¡£
©¶´¸ÅÊö MS17-010ÊÇ΢ÈíÔÚ2017Äê·¢²¼µÄÒ»¸ö°²È«²¹¶¡£¬ÓÃÓÚÐÞ¸´WindowsϵͳÖдæÔڵġ°ÓÀºãÖ®À¶¡±Â©¶´¡£¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ýSMB£¨Server Message Block£©ÐÒéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂ룬¶Ôδ´ò²¹¶¡µÄϵͳ¹¹³ÉÑÏÖØÍþв¡£±¾ÎÄÖ¼ÔÚ¼òÒª¸´Ïָé¶´£¬ÒÔչʾÆäDZÔÚΣº¦£¬²¢Ç¿µ÷¼°Ê±´ò²¹¶¡µÄÖØÒªÐÔ¡£
¾ßÌå©¶´ÔÀí¼ûÎÄÄ©£ºNSA Eternalblue SMB ©¶´·ÖÎö - 360 ºËÐݲȫ¼¼Êõ²©¿Í¡£´Ë©¶´¿Éʹ¹¥»÷ÕßÔÚÄ¿±êϵͳִÐÐÈÎÒâ´úÂ룬ͨ¹ýɨÃ迪·Å445¶Ë¿ÚµÄWindows»úÆ÷ʵÏÖ·ÇÊÚȨµÄÈëÇÖ£¬Ö²ÈëÀÕË÷Èí¼þ¡¢Ô¶³Ì¿ØÖÆÄ¾ÂíµÈ¶ñÒâ³ÌÐò¡£ÓÀºãÖ®À¶Â©¶´µÄ·ÀÓù´ëÊ©½¨ÒéΪ£ºÊ¹Óò¹¶¡¹ÜÀí¹¤¾ßÈ·±£ÏµÍ³»ñµÃ¼°Ê±¸üС£
¸´ÏÖ¹ý³Ì£º»·¾³´î½¨£ºÐèÒªÈý̨»úÆ÷£¬·Ö±ðÊǵ÷ÊÔ»ú¡¢°Ð»úºÍ¹¥»÷»ú¡£µ÷ÊÔ»úÓÃÓÚµ÷Ê԰лú£¬¹¥»÷»úÓÃÓÚ·¢¶¯¹¥»÷¡£µ÷ÊÔÓëÅäÖãºÔÚµ÷ÊÔ»úÉÏÅäÖÃË«»úÄں˵÷ÊÔÒÔµ÷Ê԰лú£¬Í¬Ê±ÔÚ¹¥»÷»úÉϰ²×°²¢ÅäÖÃfuzzbunch¹¤¾ß£¬¸Ã¹¤¾ßÓÃÓÚʵÏÖ¡°ÓÀºãÖ®À¶¡±Â©¶´µÄ¸´ÏÖ¡£
½ñÌìÒªÌÖÂ۵ĩ¶´¡ª¡ªCVE-2017-7494£¬ËäÈ»ÔÚ2017Äê5ÔÂÓëWannaCryÓÀºãÖ®À¶²¡¶¾Í¬Ê±±¬·¢£¬µ«Æä¹¥»÷ÍþÁ¦ºÍ¼ÛÖµ²¢Î´µÃµ½Ó¦ÓеÄÖØÊÓ¡£Samba¹Ù·½ÔÚ2017Äê5ÔÂ24ÈÕ·¢²¼4°æ±¾Ê±£¬Ðû²¼ÐÞ¸´ÁËÕâһ©¶´£¬Äܹ»ÊµÏÖÔ¶³Ì´úÂëÖ´ÐУ¬Ó°ÏìLinux/UnixÉ豸µÄ°²È«¡£
ÀûÓÃMetasploitËÑË÷ms17_010©¶´£¬·µ»ØËÄÌõÊý¾Ý£¬Ñ¡ÔñµÚÈýÌõ½øÐй¥»÷£¬ÏÈÓõڶþÌõ²âÊÔÄ¿±êµçÄÔÊÇ·ñ°üº¬¸Ã©¶´£¬´æÔÚÔòÖ´Ðй¥»÷£¬·ñÔòѰÕÒÆäËûÄ¿±ê¡£Ê¹ÓÃÓÀºãÖ®À¶Â©¶´£¬Ö´ÐÐÃüÁîuse exploit/windows/smb/ms17_010_eternalblueÆô¶¯¹¥»÷£¬²¢ÏÔʾËùÐè²ÎÊý¡£
MS17-010ÓÀºãÖ®À¶Â©¶´¸´ÏÖ
1¡¢MS17-010ÊÇ΢ÈíÔÚ2017Äê·¢²¼µÄÒ»¸ö°²È«²¹¶¡£¬ÓÃÓÚÐÞ¸´WindowsϵͳÖдæÔڵġ°ÓÀºãÖ®À¶¡±Â©¶´¡£¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ýSMB£¨Server Message Block£©ÐÒéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂ룬¶Ôδ´ò²¹¶¡µÄϵͳ¹¹³ÉÑÏÖØÍþв¡£±¾ÎÄÖ¼ÔÚ¼òÒª¸´Ïָé¶´£¬ÒÔչʾÆäDZÔÚΣº¦£¬²¢Ç¿µ÷¼°Ê±´ò²¹¶¡µÄÖØÒªÐÔ¡£
2¡¢ÀûÓÃMetasploitËÑË÷ms17_010©¶´£¬·µ»ØËÄÌõÊý¾Ý£¬Ñ¡ÔñµÚÈýÌõ½øÐй¥»÷£¬ÏÈÓõڶþÌõ²âÊÔÄ¿±êµçÄÔÊÇ·ñ°üº¬¸Ã©¶´£¬´æÔÚÔòÖ´Ðй¥»÷£¬·ñÔòѰÕÒÆäËûÄ¿±ê¡£Ê¹ÓÃÓÀºãÖ®À¶Â©¶´£¬Ö´ÐÐÃüÁîuse exploit/windows/smb/ms17_010_eternalblueÆô¶¯¹¥»÷£¬²¢ÏÔʾËùÐè²ÎÊý¡£
3¡¢ÓÀºãÖ®À¶£¨Eternal Blue£©£¬Ò»ÖÖÀûÓÃWindowsϵͳµÄSMBÐÒé©¶´µÄ¶ñÒâÈí¼þ£¬Æä¶Ôϵͳ½øÐÐ×î¸ßȨÏÞ»ñÈ¡£¬´Ó¶øÊµÏÖ¶Ô±»¹¥»÷¼ÆËã»úµÄ¿ØÖÆ¡£
4¡¢»ùÓÚÓÀºãÖ®À¶ÊµÏÖWindows GetshellµÄ©¶´¸´ÏÖ²½ÖèÈçÏ£º×¼±¸»·¾³£ºÊ¹ÓÃKali Linux 20103»ò2018°æ×÷Ϊ¹¥»÷»ú£¬ÒòΪÕâÁ½¸ö°æ±¾ÕûºÏÁËMS17010µÄÉøÍ¸²âÊÔ´úÂë¡£×¼±¸Ò»Ì¨°²×°ÁËWindows 7 sp1µÄ°Ð»ú£¬ÓÃÓÚ©¶´¸´ÏÖ¡£µÇ¼Kali Linux£ºÆô¶¯Kali Linux£¬²¢µÇ¼µ½ÏµÍ³¡£
5¡¢MS17-010ÓÀºãÖ®À¶¸´ÏÖÖ¸ÄÏ Â©¶´¸ÅÊö MS17-010£¬Ò²±»³ÆÎªÓÀºãÖ®À¶£¬ÊÇÒ»¸öÓ°Ïì¹ã·ºµÄWindows²Ù×÷ϵͳ©¶´¡£¸Ã©¶´ÔÊÐí¹¥»÷Õßͨ¹ý445¶Ë¿ÚÔ¶³ÌÖ´ÐдúÂ룬½ø¶ø¿ØÖÆÊܺ¦ÕߵĵçÄÔ¡£ÓÀºãÖ®À¶Â©¶´±»¶àÖÖÀÕË÷²¡¶¾¼°Æä±äÖÖËùÀûÓã¬Ôì³ÉÁËÑÏÖØµÄÍøÂ簲ȫÍþв¡£
Geoserver©¶´¸´ÏÖ
1¡¢½«GeoServerµÄWar°ü½âѹ²¢²¿ÊðÔÚTomcatµÄ/webappsĿ¼Ï¡£ÖØÆôTomcat·þÎñ¡£·ÃÎÊGeoServer¹ÜÀí½çÃæ£º10.1£º8080/geoserver£¬Ê¹ÓÃĬÈÏÕ˺ÅÃÜÂ룺admin/geoserverµÇ¼¡£Â©¶´¸´ÏÖ²½Öè н¨¹¤×÷Çø µÇ¼GeoServerºó£¬µã»÷×ó²à²Ëµ¥À¸µÄ¡°¹¤×÷Çø¡±£¬È»ºóµã»÷¡°Ð½¨¡±¡£Ìîд¹¤×÷ÇøÃû³ÆµÈÏà¹ØÐÅÏ¢£¬µã»÷¡°±£´æ¡±¡£