WordPress²å¼þDuplicator°²È«·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-02-25·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Duplicator 1.3.28֮ǰ°æ±¾
Duplicator Pro 3.8.7.1֮ǰ°æ±¾
·ì϶¸ÅÊö
DuplicatorÊÇÒ»¸öµ¥Ò»µÄ±¸·ÝºÍÕ¾µãǨáãʵÓ÷¨Ê½¡£ËüʹWordPressÍøÕ¾ÖÎÀíÔ±¿ÉÄÜǨá㣬¸´Ôì£¬ÒÆ¶¯»ò¿ËÂ¡ÍøÕ¾¡£
WordPress°µÊ¾£¬¸ÃÈí¼þÒѾ±»ÏÂÔØ³¬¹ý1500Íò´Î£¬²¢ÔÚ³¬¹ý100Íò¸öÍøÕ¾ÉÏʹÓá£
ÔÚ°æ±¾1.3.28֮ǰµÄDuplicatorºÍ°æ±¾3.8.7.1֮ǰµÄDuplicator ProÔ̺¬Ò»¸öδ¾Éí·ÝÑéÖ¤µÄËÁÒâÎļþÏÂÔØ·ì϶¡£Î´¾ÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶£¬Í¨¹ýʹÓÃÒ×Êܹ¥»÷µÄDuplicator²å¼þÏòWordPressÍøÕ¾·¢ËÍÌØÔìÒªÇóÀ´ÀûÓô˷ì϶¡£
¹¥»÷ÕßÄܹ»Ê¹ÓÃõè¾¶±é´ÓÀ´½Ó¼ûDuplicatorÖ¸¶¨õè¾¶Ö®±íµÄÎļþ£¬ÕâЩÎļþ¿ÉÄÜÔ̺¬wp-config.phpÎļþ¡£ÕâÊÇWordPressÕ¾µãÅäÖÃÎļþ£¬¸ÃÎļþÔ̺¬Êý¾Ý¿âÍ´´¦¡¢Éí·ÝÑéÖ¤ÃÜÔ¿ºÍÑΡ£Í¨¹ýÕâЩʹ´¦£¬ÈôÊÇÔÊÐíÔ¶³ÌÏνӣ¬¹¥»÷ÕßÄܹ»Ö±½Ó½Ó¼ûÊܺ¦Õ¾µãµÄÊý¾Ý¿â¡£¹¥»÷ÕßÄܹ»Ê¹Óô˽ӼûȨÏÞ´´½¨×Ô¼ºµÄÖÎÀíÔ¹ØÊ»§²¢½øÒ»²½·çÏÕÕ¾µã£¬»òÕßÖ»Ðè²åÈëÄÚÈÝ»ò»ñÈ¡Êý¾Ý¼´¿É¡£
×êÑÐÈËÔ±¿´µ½µÄÏÕЩËùÓй¥»÷¶¼À´×Ôͳһ¸öIPµØÖ·£¬Äܹ»Ê¹ÓÃÒÔÏÂIOCÀ´È·¶¨ÄúµÄÕ¾µãÊÇ·ñÊܵ½¹¥»÷£º
IP:77.71.115.52
´øÓÐÒÔϲéÎÊ×Ö·û´®µÄGETÒªÇó£º
action=duplicator_download
file=/../wp-config.php
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£
½¨¸´½¨Òé
Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬»ñÈ¡Á´½Ó£ºhttps://wordpress.org/plugins/duplicator/¡£
²Î¿¼Á´½Ó
https://threatpost.com/active-attacks-duplicator-wordpress-plugin/153138/


¾©¹«Íø°²±¸11010802024551ºÅ