¡¾·ì϶¹«¸æ¡¿SolarWinds Serv-UÊäÈëÑéÖ¤·ì϶ (CVE-2021-35247)
°ä²¼¹¦·ò 2022-01-210x00 ·ì϶¸ÅÊö
CVE ID | CVE-2021-35247 | ʱ ¼ä | 2022-01-18 |
Àà ÐÍ | ÊäÈëÑéÖ¤ÃýÎó | µÈ ¼¶ | ÖÐΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | Óû§½»»¥ | ÊÇ |
PoC/EXP | ÔÚÒ°ÀûÓÃ |
0x01 ·ì϶ÏêÇé
SolarWinds Serv-UÊÇÃÀ¹úSolarWinds¹«Ë¾µÄÒ»Ì×FTPºÍMFTÎļþ´«ÊäÈí¼þ¡£
1ÔÂ18ÈÕ£¬SolarWinds°ä²¼°²È«²¼¸æ£¬Serv-UÖдæÔÚÒ»¸öÊäÈëÑéÖ¤·ì϶ (CVE-2021-35247)£¬ÆäCVSSv3ÆÀ·Ö×î¸ßΪ5.3¡£
ÓÉÓÚServ-UµÄÊäÈëÑéÖ¤´æÔÚ°²È«ÎÊÌ⣬LDAP Éí·ÝÑéÖ¤µÄ Serv-U Web µÇ¼δ³ä·Ö¹ýÂË×Ö·û¡£Ä¿Ç°SolarWinds ÒѸüÐÂÊäÈë»úÔì¡£
1ÔÂ19ÈÕ£¬Î¢ÈíÔÚÆä¹Ù·½²©¿ÍÖÐÅû¶ÁËCVE-2021-35247£¬²¢°µÊ¾Òѹ۲쵽ÀûÓô˷ì϶ʵÏÖÓë Log4jÓйصĹ¥»÷»î¶¯¡£
×ÔÈ¥Äê12ÔÂÅû¶ÒÔÀ´£¬Log4j·ì϶Òѱ»¶à¸öºÚ¿ÍÍÅ»ïÀûÓã¬Í¨¹ý¶ÔÒ×Êܹ¥»÷µÄÍøÂç½øÐдó¹æÄ£É¨ÃèºÍÉøÈ룬À´²¿ÊðºóÃÅ¡¢¼ÓÃܿ󹤡¢ÀÕË÷Èí¼þºÍÔ¶³Ì shell£¬´Ó¶øÎª½øÒ»²½µÄ»î¶¯Ìá¹©ÓÆ¾Ã½Ó¼ûȨÏÞ¡£
Ó°ÏìÁìÓò
SolarWinds Serv-U <= 15.2.5
0x02 °²È«½¨Òé
Ŀǰ´Ë·ì϶ÒѾ½¨¸´£¬½¨ÒéÊÜÓ°ÏìÓû§ÊµÊ±Éý¼¶¸üе½Serv-U 15.3»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://www.solarwinds.com/serv-u-managed-file-transfer-server
×¢£ºSolarWinds¹Ù·½²¼¸æ°µÊ¾£¬ÓÉÓÚ LDAP ·þÎñÆ÷ºöÂÔÁËijЩ×Ö·û£¬Òò¶øÎ´¼ì²âµ½ÏÂÓÎÊÇ·ñÊÜÓ°Ïì¡£
0x03 ²Î¿¼Á´½Ó
https://www.solarwinds.com/trust-center/security-advisories/cve-2021-35247
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#CVE-2021-35247
https://thehackernews.com/2022/01/microsoft-hackers-exploiting-new.html
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | Åú¸ÄÄÚÈÝ |
V1.0 | 2022-01-21 | ³õ´Î°ä²¼ |
0x05 ¸½Â¼
GA»Æ½ð¼×¼ò½é
GA»Æ½ð¼×¹«Ë¾³ÉÁ¢ÓÚ1996Ä꣬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐÓ×°åÕýʽ¹ÒÅÆÉÏÊУ¬ÊǹúÄÚ¼«¾ßʵÁ¦µÄ¡¢Õ¼ÓÐÆëÈ«×ÔÖ÷֪ʶ²úȨµÄÍøÂ簲ȫ²úÆ·¡¢¿ÉÐŰ²È«ÖÎÀíÆ½Ì¨¡¢°²È«·þÎñÓë½â¾ö¹æ»®µÄ×ÛºÏÌṩÉÌ¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ÔÚÈ«¹ú¸÷Ê¡¡¢ÊÓ×¢×ÔÖÎÇøÉèÓзÖÖ§»ú¹¹£¬Õ¼Óи²¸ÇÈ«¹úµÄÇþ·ϵͳºÍ¼¼ÊõÖ§³ÖÖÐÐÄ£¬²¢ÔÚ±±¾©¡¢ÉϺ£¡¢³É¶¼¡¢¹ãÖÝ¡¢³¤É³¡¢º¼ÖÝµÈ¶àµØÉèÓÐÑз¢ÖÐÐÄ¡£
¶àÄêÀ´£¬GA»Æ½ð¼×ÖÂÁ¦ÓÚÌṩӵÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´Ðµİ²È«²úÆ·ºÍ×î¼Ñʵ¼Ê·þÎñ£¬Ô®ÊÖ¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄ°²È«ÐԺͳö²úЧÁ¦£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢°²È«²úÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸ÖÂÁ¦¡£
¹ØÓÚGA»Æ½ð¼×
GA»Æ½ð¼×°²È«Ó¦¼±ÏìÓ¦ÖÐÐÄÖØÒªÕë¶Ô³ÁÒª°²È«·ì϶µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвµý±¨ºÍ°²È«»ã±¨¡£
¹Ø×¢ÒÔϹ«¼ÒºÅ£¬»ñȡȫÇò×îа²È«×ÊѶ£º



¾©¹«Íø°²±¸11010802024551ºÅ