CVE-2020-1631| Juniper HTTP/HTTPSЧÀÍÇå¾²Îó²îͨ¸æ
Ðû²¼Ê±¼ä 2020-04-300x00 Îó²î¸ÅÊö
0x01 Îó²îÏêÇé
2020Äê4ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬£¬Juniper¹Ù·½Ðû²¼ÁËJunos OS×°±¸»ùÓÚHTTP/HTTPSºÍJ-WebЧÀͱ£´æÍâµØÎļþ°üÀ¨¡¢ÏÂÁî×¢ÈëµÈÇå¾²Îó²îµÄͨ¸æ¡£¡£¡£¡£¡£¡£¡£
Juniper Networks Junos OSÊÇÃÀ¹úÕ°²©ÍøÂ磨Juniper Networks£©¹«Ë¾µÄÒ»Ì×רÓÃÓڸù«Ë¾µÄÓ²¼þ×°±¸µÄÍøÂç²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£¸Ã²Ù×÷ϵͳÌṩÁËÇå¾²±à³Ì½Ó¿ÚºÍJunos SDK¡£¡£¡£¡£¡£¡£¡£
Junos OS×°±¸µÄJ-Web¡¢WebÉí·ÝÑé֤ģ¿£¿£¿é¡¢¶¯Ì¬VPN£¨DVPN£©£¬£¬£¬£¬£¬£¬£¬ºÍ´øÓÐWebÖØ¶¨ÏòµÄ·À»ðǽÉí·ÝÑéÖ¤¡¢Áã½Ó´¥ÉèÖã¨ZTP£©ËùʹÓõÄHTTP/HTTPSЧÀÍÖб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÍâµØÎļþ°üÀ¨£¨LFI£©»ò·¾¶±éÀú¡£¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÄÜͨ¹ý½«ÏÂÁî×¢Èëµ½httpd.logÈÕÖ¾ÖУ¬£¬£¬£¬£¬£¬£¬ÒÔ¾ßÓС°world¡±¿É¶ÁÎļþµÄȨÏÞ¶ÁÈ¡Îļþ£¬£¬£¬£¬£¬£¬£¬»òÕß»ñÈ¡J-Web»á»°ÁîÅÆ¡£¡£¡£¡£¡£¡£¡£
ÔÚÏÂÁî×¢ÈëµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚHTTPЧÀÍÒÔ¡°nobody¡±Óû§Éí·ÝÔËÐУ¬£¬£¬£¬£¬£¬£¬ÒÔÊÇÓ°ÏìÊÇÓÐÏ޵쬣¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö5.3¡£¡£¡£¡£¡£¡£¡£
ÔÚJunos OS 19.3R1¼°¸ü¸ß°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½«Äܹ»Í¨¹ý¾ßÓС°world¡±¿É¶ÁȨÏÞ¶ÁÈ¡ÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö5.9¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÆôÓÃJ-Web£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ»ñµÃÓëµÇ¼J-WebµÄÈκÎÈËÏàͬµÄ»á¼û¼¶±ð¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÖÎÀíÔ±µÇ¼£¬£¬£¬£¬£¬£¬£¬Ôò¹¥»÷Õß¿ÉÒÔ»ñµÃÖÎÀíÔ±¶ÔJ-WebµÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬£¬£¬CVSSÆÀ·Ö8.8¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ʵʱÏÂÔØ²¢×°ÖøüгÌÐòºÍ²¹¶¡£¬£¬£¬£¬£¬£¬£¬ÏÂÔØÁ´½Ó£ºhttps://www.juniper.net/support/downloads/¡£¡£¡£¡£¡£¡£¡£
ÔÝʱ²½·¥£º
¸ÃÎó²îÖ÷ÒªÓ°ÏìÆôÓÃÁËHTTP/HTTPSЧÀ͵ÄJuniper Networks Junos OS×°±¸£¬£¬£¬£¬£¬£¬£¬½ûÓÃHTTP/HTTPSЧÀ͵ÄJunos OS×°±¸²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£
¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÈ·ÈÏhttpdÊÇ·ñÆô¶¯£º
user@device> show system processes | match http
5260 - S 0:00.13 /usr/sbin/httpd-gk -N
5797 - I 0:00.10 /usr/sbin/httpd--config /jail/var/etc/httpd.conf
ÈôÊÇ¿´µ½Àú³Ì±£´æ£¬£¬£¬£¬£¬£¬£¬ÔòÌåÏÖЧÀÍÆô¶¯¡£¡£¡£¡£¡£¡£¡£
ͬʱ¿ÉÒÔÅŲéÈÕÖ¾ÖÐÊÇ·ñÒѾ±£´æÊ¹ÓÃÕâÒ»Îó²îµÄ¹¥»÷ʵÑ飬£¬£¬£¬£¬£¬£¬ÏÂÁîʾÀý£º
user@device> show log httpd.log | match "=*;*&|=*%3b*&"
user@device> show log httpd.log.0.gz | match "=*;*&|=*%3b*&"
user@device> show log httpd.log.1.gz | match "=*;*&|=*%3b*&"
ÈôÊÇ·¢Ã÷ÓÐ"=*;*&"»ò"*%3b*&"ÌØÕ÷£¬£¬£¬£¬£¬£¬£¬¿ÉÄÜÌåÏÖÓÐʵÑé¹¥»÷ÐÐΪÒѾ±¬·¢£¬£¬£¬£¬£¬£¬£¬½¨Ò龡¿ìÉý¼¶×°±¸²¢×öÖÜÈ«ÍþвÆÊÎö£¬£¬£¬£¬£¬£¬£¬Í¬Ê±¹¥»÷ÕßÒ²¿ÉÄÜ»áÕûÀíÈÕÖ¾Ïû³ý¹¥»÷ºÛ¼£¡£¡£¡£¡£¡£¡£¡£
»ùÓÚHTTP/HTTPSЧÀÍÏà¹ØÉèÖýÚʾÀý²Î¿¼£º
[system services web-management http]
[system services web-management https]
[security dynamic-vpn]
0x03 Ïà¹ØÐÂÎÅ
https://www.securezoo.com/2020/04/juniper-releases-out-of-band-security-update-to-fix-vulnerability-in-j-web-and-web-based-services/
0x04 ²Î¿¼Á´½Ó
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11021
0x05 ʱ¼äÏß
2020-04-28 Juniper¹Ù·½Ðû²¼Îó²îͨ¸æ
2020-04-29 VSRCÐû²¼Îó²îͨ¸æ