¡¾Îó²îͨ¸æ¡¿Apache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-44228£©
Ðû²¼Ê±¼ä 2021-12-10
0x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-44228 | ʱ ¼ä | 2021-12-9 |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | |
Óû§½»»¥ | ËùÐèȨÏÞ | ||
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | ÊÇ |
0x01 Îó²îÏêÇé
Apache Log4j2ÊÇÒ»¸ö¿ªÔ´µÄJavaÈÕÖ¾¿ò¼Ü£¬£¬£¬£¬£¬£¬±»ÆÕ±éµØÓ¦ÓÃÔÚÖÐÐļþ¡¢¿ª·¢¿ò¼ÜÓëWebÓ¦ÓÃÖС£¡£¡£
12ÔÂ9ÈÕ£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐļà²âµ½ÍøÉÏÅû¶Apache Log4j2 ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬£¬£¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØ¶¨¶ñÒâÊý¾Ý°ü£¬£¬£¬£¬£¬£¬¿ÉÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
ÏÖÔÚÒÑÖªÊÜÓ°ÏìµÄÓ¦ÓúÍ×é¼þ£ºApache Solr¡¢Apache Flink¡¢Apache Druid¡¢srping-boot-strater-log4j2ÒÔ¼°VMwareµÈ£¬£¬£¬£¬£¬£¬¸ü¶àÐÅÏ¢¿É²Î¿¼ÏÂÃæµÄµØµã£º
https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/usages?p=1
×èÖ¹12ÔÂ12ÈÕ£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÓÃÒÑ¾È«ÍøÂþÒ磬£¬£¬£¬£¬£¬ÍøÂç·¸·¨×éÖ¯£¨ÈçMuhstik½©Ê¬ÍøÂ磩Òѽ«¸ÃÎó²îÎäÆ÷»¯ÒÔÌá³«ÍøÂç¹¥»÷¡£¡£¡£
Ó°Ïì¹æÄ£
ÂÄÀúÖ¤2.15.0-rc1¿É±»Èƹý£¬£¬£¬£¬£¬£¬ÏÖʵÊÜÓ°ÏìµÄ°æ±¾Îª£¨1.*°æ±¾²»ÊÜÓ°Ï죩£º
Apache Log4j 2.x < 2.15.0-rc2
0x02 ´¦Öóͷ£½¨Òé
Ç¿ÁÒ½¨ÒéÊÜÓ°ÏìÓû§Éý¼¶µ½log4j-2.15.0-rc2¡£¡£¡£
Ïà¹ØÓû§¿É²Î¿¼¼øºÚµ£±£ÍøWAF¡¢IPS¡¢TAR¡¢CSP¡¢IDS¡¢CS¡¢APTµÈ²úÆ·Ïà¹ØµÄ½â¾ö¼Æ»®£º
https://mp.weixin.qq.com/s/RZDibu2pZwICjTEuTpQ4JA
ÏÂÔØÁ´½Ó£º
https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc2
ÔÝʱ¼Æ»®£º
l ½¨ÒéJDKʹÓÃ6u211¡¢7u201¡¢8u191¡¢11.0.1¼°ÒÔÉϵİ汾£»£»£»£»
l Ìí¼ÓjvmÆô¶¯²ÎÊý:-Dlog4j2.formatMsgNoLookups=true£»£»£»£»
l Ìí¼Ólog4j2.component.propertiesÉèÖÃÎļþ£¬£¬£¬£¬£¬£¬ÔöÌíÈçÏÂÄÚÈÝΪ£ºlog4j2.formatMsgNoLookups=true£»£»£»£»
l ϵͳÇéÐαäÁ¿Öн«LOG4J_FORMAT_MSG_NO_LOOKUPSÉèÖÃΪtrue£»£»£»£»
l եȡװÖÃlog4jµÄЧÀÍÆ÷»á¼ûÍâÍø£¬£¬£¬£¬£¬£¬²¢ÔÚ½çÏß¶ÔdnslogÏà¹ØÓòÃû»á¼û¾ÙÐмì²â¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://github.com/apache/logging-log4j2
https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc2
https://mp.weixin.qq.com/s/J5H9aZVhwQaVn3LvKi2Kqw
0x04 ¸üа汾
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2021-12-9 | Ê×´ÎÐû²¼ |
V2.0 | 2021-12-10 | ÐÞ¸Äϸ½Ú |
V3.0 | 2021-12-10 | ÐÞ¸Äbug |
V4.0 | 2021-12-12 | ÐÂÔöCVE£ID¼°²¿·ÖÄÚÈÝ¡¢Ð޸Ļº½â²½·¥¡£¡£¡£ |
0x05 ¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£Íø¼ò½é
¼øºÚµ£±£Íø¹«Ë¾½¨ÉèÓÚ1996Ä꣬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬£¬£¬£¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£¡£¡£
¶àÄêÀ´£¬£¬£¬£¬£¬£¬¼øºÚµ£±£ÍøÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£
¹ØÓÚ¼øºÚµ£±£Íø
¼øºÚµ£±£ÍøÇå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£
¹Ø×¢ÒÔϹ«Öںţ¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º