Sophos XG·À»ðǽSQL×¢ÈëÎó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-270x00 Îó²î¸ÅÊö
|
CVE ID |
ÔÝÎÞ |
ʱ ¼ä |
2020-04-27 |
|
Àà ÐÍ |
SI |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌʹÓà |
ÊÇ |
Ó°Ïì¹æÄ£ |
ËùÓа汾µÄXG·À»ðǽ |
0x01 Îó²îÏêÇé

Sophos XG FirewallÊÇÓ¢¹úSophos¹«Ë¾µÄÒ»¿î·À»ðǽװ±¸¡£¡£¡£¡£¡£¡£SFOSÊÇÔËÐÐÔÚÆäÖеÄÒ»ÌײÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£
SophosÓÚUTC 2020Äê4ÔÂ22ÈÕ20:29ÊÕµ½ÁËÓйØXG·À»ðǽµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬¸ÃXG·À»ðǽÔÚÖÎÀí½çÃæÖпɼû¿ÉÒÉ×ֶΡ£¡£¡£¡£¡£¡£ÊӲ췢Ã÷¸ÃÊÂÎñΪ¹¥»÷ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¶ø²»ÊDzúÆ·bug¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖ÷ÒªÕë¶ÔµÄÊÇ¿ªÆôHTTPSЧÀÍ»òÕßÓû§¿ØÖÆÃæ°å̻¶ÔÚ»¥ÁªÍøÉϵÄSophos XG Firewall×°±¸¡£¡£¡£¡£¡£¡£
¸Ã¹¥»÷ʹÓÃÒÔǰδ֪µÄSQL×¢ÈëÎó²îÀ´ÏÂÔØpayloads¡£¡£¡£¡£¡£¡£È»ºóÇÔÈ¡Îļþ£¬£¬£¬£¬£¬£¬£¬¿ÉÄܰüÀ¨·À»ðǽÖÎÀíÔ±£¬£¬£¬£¬£¬£¬£¬·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÒÔ¼°ÓÃÓÚÔ¶³Ì»á¼û×°±¸µÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¿ÉÊÇÉí·ÝÑé֤ϵͳ£¨ÀýÈçAD»òLDAP£©µÄÃÜÂë²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£
¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ÔÚÊÓ²ìÀú³ÌÖУ¬£¬£¬£¬£¬£¬£¬Ã»Óз¢Ã÷ºÚ¿ÍʹÓÃ͵ÇÔµÄÃÜÂë»á¼ûÁ˿ͻ§ÄÚÍøÉϵÄXG·À»ðǽװ±¸»ò·À»ðǽÒÔÍâµÄÈκÎÄÚÈÝ¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
²¹¶¡³ÌÐò»áÔÚXGÖÎÀí½çÃæÉÏÌáÐÑÒ»ÌõÐÂÎÅ£¬£¬£¬£¬£¬£¬£¬À´ÌáÐÑ´ËXG·À»ðǽÊÇ·ñÊܵ½´Ë¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£
¼Æ»®1£ºÎ´Ôâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ö±½Ó¸üв¹¶¡¼´¿É¡£¡£¡£¡£¡£¡£
¼Æ»®2£ºÈôÊÇÒÑÔâµ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÈçÏÂͼ¡£¡£¡£¡£¡£¡£
¹ØÓÚÔâµ½ÈëÇÖµÄ×°±¸£¬£¬£¬£¬£¬£¬£¬Sophos½¨Òé½ÓÄÉÒÔϰ취£º
1. ÖØÖÃÃÅ»§ÍøÕ¾ÖÎÀíÔ±ºÍ×°±¸ÖÎÀíÔ±ÕÊ»§
2. ÖØÐÂÆô¶¯XG×°±¸
3. ÖØÖÃËùÓÐÍâµØÓû§ÕÊ»§µÄÃÜÂë
4. Ö»¹ÜÃÜÂëÊǹþÏ£Öµ£¬£¬£¬£¬£¬£¬£¬µ«½¨ÒéÖØÖÃËùÓÐÕÊ»§ÃÜÂë
×¢ÖØ£º¸üд˲¹¶¡³ÌÐòºó£¬£¬£¬£¬£¬£¬£¬²¹¶¡³ÌÐò¾¯±¨ÐÂÎŲ»»áÏûÊÅ¡£¡£¡£¡£¡£¡£×ÝÈ»ÒÑÀÖ³ÉÓ¦Óô˲¹¶¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Íê³ÉÁËÈÎºÎÆäËû²Ù×÷°ì·¨Ö®ºó£¬£¬£¬£¬£¬£¬£¬¾¯±¨Ò²½«Ò»Á¬ÏÔʾÔÚXGÖÎÀí½çÃæÖС£¡£¡£¡£¡£¡£
0x03 Ïà¹ØÐÂÎÅ
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
0x04 ²Î¿¼Á´½Ó
https://community.sophos.com/kb/en-us/135412
0x05 ʱ¼äÏß
2020-04-25 SophosÐû²¼¸üÐÂ
2020-04-27 VSRCÐû²¼Îó²îͨ¸æ


¾©¹«Íø°²±¸11010802024551ºÅ