WebLogic T3ºÍ̸·´ÐòÁл¯ 0day ·ì϶
°ä²¼¹¦·ò 2021-04-190x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-19 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ·ì϶ÏêÇé

½üÈÕ£¬WebLogic±»Åû¶´æÔÚÒ»¸öT3ºÍ̸·´ÐòÁл¯0 day·ì϶£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬Ä¿Ç°¸Ã·ì϶´¦ÓÚÔÚÒ°0day״̬£¬²¢ÇÒPoC/EXPÒÑÔÚGithubÉϹ«¿ª¡£
Ôڸ÷ì϶µÄpocÖУ¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀ࣬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷£¬´ÓÖнâÎö¶ÔÏó£¬Äܹ»Í¨¹ý°ÑobjBytes´úÌæÎªÖ¸¶¨·´ÐòÁл¯¾ÍÄܹ»ÊµÏÖweblogicºÚÃûµ¥Èƹý¡£

0x02 ´ëÖý¨Òé
½¨Ò齫jdkÉý¼¶µ½×îа汾£¬²¢½ûÓÃiiop/t3ºÍ̸ÒÔ×÷Ϊһʱ»º½â´ëÊ©¡£
½ûÓÃT3ºÍ̸£¬¾ßÌå²Ù×÷ÈçÏ£º
1£©½øÈëWebLogic½ÚÔį̀£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬½øÈëÏνÓɸѡÆ÷ÅäÖá£
2)ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û)¡£
3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬¹æ¶¨·½¿ÉÉúЧ¡£

½ûÓÃIIOPºÍ̸£¬¾ßÌå²Ù×÷ÈçÏ£º
µÇ½WebLogic½ÚÔį̀£¬base_domain >·þÎñÆ÷¸ÅÒª >AdminServer

ÏÂÔØÁ´½Ó£º
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x03 ²Î¿¼Á´½Ó
https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x04 ¹¦·òÏß
2021-04-18 ×êÑÐÈËÔ±Åû¶·ì϶
2021-04-19 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ