Weblogic WLS×é¼þÎó²î¹¥»÷ʹÓÃÔ¤¾¯
2017-12-22
Ò». Ô¤¾¯ÕªÒª
½üÆÚ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Ó¦¼±ÏìÓ¦ÍŶÓÂ½Ðø½Óµ½À´×Ô½ðÈÚ¡¢ÔËÓªÉÌ¡¢»¥ÁªÍøµÈ¶à¸öÐÐÒµ¿Í»§µÄÇå¾²ÊÂÎñ·´Ï죬·¢Ã÷¶ą̀²î±ð°æ±¾WebLogicÖ÷»ú¾ù±»Ö²ÈëÁËÏàͬµÄ¶ñÒâ³ÌÐò£¬¸Ã³ÌÐò»áÏûºÄ´ó×ÚµÄÖ÷»úCPU×ÊÔ´¡£
¾ÆÊÎö£¬¹¥»÷ÕßÕë¶ÔWebLogic WLS×é¼þÖб£´æµÄCVE-2017-10271Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬½á¹¹ÇëÇó¶ÔÔËÐеÄWebLogicÖÐÐļþÖ÷»ú¾ÙÐй¥»÷£¬ÓÉÓÚ¸ÃÎó²îʹÓ÷½·¨¼òÆÓ£¬ÇÒÄܹ»Ö±½Ó»ñȡĿµÄ·þÎñÆ÷µÄ¿ØÖÆÈ¨ÏÞ£¬Ó°Ïì¹æÄ£½Ï¹ã£¬½üÆÚ·¢Ã÷´ËÎó²îµÄʹÓ÷½·¨ÎªÈö²¥ÐéÄâ±ÒÍÚ¿ó³ÌÐò£¬²»É¨³ý»á±»ºÚ¿ÍÓÃÓÚÆäËûÄ¿µÄµÄ¹¥»÷¡£
Oracle¹Ù·½ÍøÕ¾ÔÚ10Ô·ݵĸüв¹¶¡ÖжԴËÎó²î¾ÙÐÐÁËÐÞ¸´£¬½¨ÒéÆóÒµ×öºÃÇå¾²·À»¤²½·¥£¬²¢ÊµÊ±ÐÞ¸´£¬ïÔÌÒò´ËÎó²îÔì³ÉµÄËðʧ¡£¹Ù·½ÐÞ¸´ÏêÇé²Î¿¼ÈçÏÂÁ´½Ó£º
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
¶þ. Çå¾²·À»¤
ÓÉÓÚ¹¥»÷ÕßʹÓõÄÊÇWebLogic wls×é¼þ¾ÙÐеĹ¥»÷£¬µ±WebLogic¿ØÖÆÌ¨¶Ô¹«Íø¿ª·ÅÇÒδʵʱÉý¼¶Çå¾²²¹¶¡µÄ»°£¬¾Í»á±£´æ±»Ê¹ÓõÄΣº¦¡£
2.1 ¹Ù·½Éý¼¶¼Æ»®
Oracle¹Ù·½¹ØÓÚWebLogic WLS ×é¼þÎó²î(CVE-2017-10271)ÔÚ10Ô·ݵĸüв¹¶¡ÖÐÒѾ¾ÙÐÐÁËÐÞ¸´£¬½¨ÒéʵʱÏÂÔØ¸üаü£¬²¢Éý¼¶WebLogic¡£Éý¼¶Àú³Ì¿É²Î¿¼ÈçÏÂÁ´½Ó£º
http://blog.csdn.net/qqlifu/article/details/49423839
2.2 ÔÝʱ·À»¤½¨Òé
ƾ֤¹¥»÷ÕßʹÓÃPOCÆÊÎö·¢Ã÷ËùʹÓõÄΪwls-wsat×é¼þµÄCoordinatorPortType½Ó¿Ú£¬ÈôWeblogic·þÎñÆ÷¼¯ÈºÖÐδӦÓôË×é¼þ£¬½¨ÒéÔÝʱ±¸·Ýºó½«´Ë×é¼þɾ³ý£¬µ±ÐγɷÀ»¤ÄÜÁ¦ºó£¬ÔÙ¾ÙÐлָ´¡£
1. ƾ֤ÏÖÕæÏàÐη¾¶£¬É¾³ýWebLogic wls-wsat×é¼þ£º

2. ÖØÆôWeblogicÓò¿ØÖÆÆ÷·þÎñ¡£
¹ØÓÚÖØÆôWeblogic·þÎñµÄÏêϸÐÅÏ¢£¬¿É²Î¿¼ÈçϹٷ½Îĵµ£º
https://docs.oracle.com/cd/E13222_01/wls/docs90/server_start/overview.html
2.3 ²úÆ··À»¤¼Æ»®
2.3.1 WAF·À»¤¼Æ»®
°²ÅÅÓоÅÓÎÀÏ¸ç¿Æ¼¼WAFµÄÓû§¿Éͨ¹ý×Ô½ç˵¹æÔòµÄ·½·¨ÓÃÀ´ÊµÊ±·À»¤WebLogic WLS×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬×Ô½ç˵¹æÔòÈçÏ£º
![]()
ÉèÖÃЧ¹ûÈçÏÂͼËùʾ£º

2.3.2 NIPS·À»¤¼Æ»®
°²ÅÅÓоÅÓÎÀÏ¸ç¿Æ¼¼NIPS/NIDSµÄÓû§£¬¿Éͨ¹ý×Ô½ç˵¹æÔò£¬ÐγɶÔWebLogic WLS×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓõļì²âºÍ·À»¤¡£ÉèÖÃÐÅÏ¢ÈçϱíËùʾ£º
Èý. ѬȾÖ÷»úÅŲé
ÓÉÓڴ˴ι¥»÷Ö÷ҪĿµÄΪÏÂÔØÖ´ÐÐÍÚ¿ó³ÌÐò£¬´ÓÖ÷»ú²ãÃæ¿Éͨ¹ý¼à¿ØÖ÷»úϵͳ×ÊÔ´»òÀú³ÌÆÊÎö·½·¨¾ÙÐмì²â£¬´ÓÍøÂç²ãÃæ¿É¶ÔC&CµØµã¼°¿ó³ØÏà¹ØÓòÃû/IP¾ÙÐÐ¼à¿Ø£¬ÒÔ·¢Ã÷ÆäËûÊÜѬȾÖ÷»ú¡£

¾ÅÓÎÀϸçÔÆ





