¡¾´¦Öóͷ£ÊÖ²á¸üС¿Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î
2021-12-11
|
Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î´¦Öóͷ£ÊÖ²á |
|||
|
¡ö ͨ¸æ±àºÅ |
NS-2021-0045 |
¡ö Ðû²¼ÈÕÆÚ |
2021-12-10 |
|
¡ö Îó²îΣº¦ |
¹¥»÷ÕßʹÓôËÎó²î£¬¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС£ |
||
|
¡ö TAG |
Log4j2¡¢JNDI¡¢RCE |
||

|
© 2021 ¾ÅÓÎÀÏ¸ç¿Æ¼¼ |
Ò». Îó²î¸ÅÊö
12ÔÂ9ÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼CERT¼à²âµ½ÍøÉÏÅû¶Apache Log4j2 Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÓÉÓÚApache Log4j2ijЩ¹¦Ð§±£´æµÝ¹éÆÊÎö¹¦Ð§£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÊâ½á¹¹µÄÊý¾ÝÇëÇó°ü£¬¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£Îó²îPoCÒÑÔÚÍøÉϹûÕæ£¬Ä¬ÈÏÉèÖü´¿É¾ÙÐÐʹÓ㬸ÃÎó²îÓ°Ïì¹æÄ£¼«¹ã£¬½¨ÒéÏà¹ØÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐÐÅŲéÓë·À»¤¡£
12ÔÂ10ÈÕ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼CERT·¢Ã÷Apache Log4j 2.15.0-rc1 °æ±¾½öÐÞ¸´LDAPºÍÔöÌíÁËhost°×Ãûµ¥£¬¿ÉÒÔ±»ÈƹýʹÓ㬹ٷ½Ðû²¼ÁËApache Log4j 2.15.0-rc2°æ±¾¾ÙÐÐÐÞ¸´£¬ÔöÌíÁ˶ÔurIÒì³£µÄ´¦Öóͷ£¡£
Apache Log4j2ÊÇÒ»¿î¿ªÔ´µÄJavaÈÕÖ¾¿ò¼Ü£¬±»ÆÕ±éµØÓ¦ÓÃÔÚÖÐÐļþ¡¢¿ª·¢¿ò¼ÜÓëWebÓ¦ÓÃÖУ¬ÓÃÀ´¼Í¼ÈÕÖ¾ÐÅÏ¢¡£
Îó²îÀֳɸ´ÏÖ½ØÍ¼£º

2.15.0-rc1ÈÆ¹ý¸´ÏÖ½ØÍ¼£º

|
Îó²îϸ½Ú |
Îó²îPoC |
Îó²îEXP |
ÔÚҰʹÓà |
|
ÒѹûÕæ |
ÒѹûÕæ |
ÒѹûÕæ |
±£´æ |
²Î¿¼Á´½Ó£º
https://issues.apache.org/jira/projects/LOG4J2/issues/LOG4J2-3201?filter=allissues
¶þ. Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾
l 2.0 <= Apache Log4j <= 2.15.0-rc1
×¢£ºÊ¹ÓÃApache Log4j 1.X°æ±¾µÄÓ¦Óã¬Èô¿ª·¢Õß¶ÔJMS AppenderʹÓò»µ±£¬¿É¶ÔÓ¦Óñ¬·¢Ç±ÔÚµÄÇå¾²Ó°Ïì¡£
¹©Ó¦Á´Ó°Ïì¹æÄ££º
ÒÑÖªÊÜÓ°ÏìÓ¦Óü°×é¼þ£º
Apache Solr
Apache Struts2
Apache Flink
Apache Druid
spring-boot-strater-log4j2
¸ü¶à×é¼þ¿É²Î¿¼ÈçÏÂÁ´½Ó£º
https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/usages?p=1
²»ÊÜÓ°Ïì°æ±¾
l Apache log4j-2.15.0-rc2£¨Óë¹ÙÍøµÄ2.15.0Îȹ̰æÏàͬ£©
Èý. Îó²î¼ì²â
3.1 È˹¤¼ì²â
1¡¢Ïà¹ØÓû§¿Éƾ֤Java jar½âѹºóÊÇ·ñ±£´æorg/apache/logging/log4jÏà¹ØÂ·¾¶½á¹¹£¬ÅжÏÊÇ·ñʹÓÃÁ˱£´æÎó²îµÄ×é¼þ£¬Èô±£´æÏà¹ØJava³ÌÐò°ü£¬ÔòºÜ¿ÉÄܱ£´æ¸ÃÎó²î¡£

2¡¢Èô³ÌÐòʹÓÃMaven´ò°ü£¬Éó²éÏîÄ¿µÄpom.xmlÎļþÖÐÊÇ·ñ±£´æÏÂͼËùʾµÄÏà¹Ø×ֶΣ¬Èô°æ±¾ºÅΪСÓÚ2.15.0-rc2£¬Ôò±£´æ¸ÃÎó²î¡£

3¡¢Èô³ÌÐòʹÓÃgradle´ò°ü£¬¿ÉÉó²ébuild.gradle±àÒëÉèÖÃÎļþ£¬ÈôÔÚdependencies²¿·Ö±£´æorg.apache.logging.log4jÏà¹Ø×ֶΣ¬ÇÒ°æ±¾ºÅΪСÓÚ2.15.0-rc2£¬Ôò±£´æ¸ÃÎó²î¡£

3.2 ¹¥»÷ÅŲé
1¡¢¹¥»÷ÕßÔÚʹÓÃǰͨ³£½ÓÄÉdnslog·½·¨¾ÙÐÐɨÃ衢̽²â£¬³£¼ûµÄÎó²îʹÓ÷½·¨¿Éͨ¹ýÓ¦ÓÃϵͳ±¨´íÈÕÖ¾ÖеÄ"javax.naming.CommunicationException"¡¢"javax.naming.NamingException: problem generating object using object factory"¡¢"Error looking up JNDI resource"Òªº¦×Ö¾ÙÐÐÅŲ顣

2¡¢¹¥»÷Õß·¢Ë͵ÄÊý¾Ý°üÖпÉÄܱ£´æ"${jndi:}" ×ÖÑù£¬ÍƼöʹÓÃÈ«Á÷Á¿»òWAF×°±¸¾ÙÐмìË÷ÅŲ顣

3.3 ²úÆ·¼ì²â
¾ÅÓÎÀÏ¸ç¿Æ¼¼Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS£©ÓëWEBÓ¦ÓÃÎó²îɨÃèϵͳ(WVSS)¡¢ÍøÂçÈëÇÖ¼ì²âϵͳ£¨IDS£©¡¢×ÛºÏÍþв̽Õ루UTS£©ÒѾ߱¸¶Ô¸ÃÎó²îµÄɨÃèÓë¼ì²âÄÜÁ¦£¬ÇëÓа²ÅÅÒÔÉÏ×°±¸µÄÓû§Éý¼¶ÖÁ×îа汾¡£
|
|
Éý¼¶°ü°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
|
RSAS V6ϵͳ²å¼þ°ü |
V6.0R02F01.2508 |
http://update.nsfocus.com/update/downloads/id/121946 |
|
RSAS V6 Web²å¼þ°ü |
V6.0R02F00.2406 |
https://update.nsfocus.com/update/listRsasDetail/v/vulweb |
|
WVSS V6²å¼þÉý¼¶°ü |
V6.0R03F00.232 |
https://update.nsfocus.com/update/listWvssDetail/v/6/t/plg |
|
IDS |
5.6.9.26697 |
https://update.nsfocus.com/update/downloads/id/121948 |
|
5.6.10.26697 |
http://update.nsfocus.com/update/downloads/id/121949 |
|
|
5.6.11.26697 |
http://update.nsfocus.com/update/downloads/id/121950 |
|
|
UTS |
5.6.10.26697 |
http://update.nsfocus.com/update/downloads/id/121958 |
¹ØÓÚRSASµÄÉý¼¶ÉèÖÃÖ¸µ¼£¬Çë²Î¿¼ÈçÏÂÁ´½Ó£º
https://mp.weixin.qq.com/s/SgOaCZeKrNn-4uR8Yj_C3Q
3.4 ÉêÇëÔÆ¼ì²â
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÃæÏòÓû§ÌṩԶ³Ì¼ì²â·þÎñ£¬Òò¸ÃÎó²îµÄ¼ì²â±£´æÒ»¶¨Î£º¦£¬Ïà¹Ø¿Í»§ÈçÐèÒªÉêÇëÔÆ¼ì²â£¬ÇëÁªÏµÏúÊÛ»òÏîĿ˾ÀíÏàͬ£¬»òÓÃСÎÒ˽¼ÒµÄ¹«Ë¾ÓÊÏä·¢ÓʼþÖÁrs@nsfocus.com£¬ÔÚÕýÎÄÖÐÌṩÐèҪɨÃèµÄ×ʲúÇåµ¥£¬¿ÉÒÔɨÃèµÄʱ¼ä£¬ÁªÏµ·½·¨£¬·þÎñÖ°Ô±»áÓëÄúÁªÏµ¡£
7x24h¿Í·þ×ÉѯÈÈÏߣº400-818-6868ת2
ËÄ. Îó²î·À»¤
4.1 ¹Ù·½Éý¼¶
ÏÖÔÚ¹Ù·½ÒÑÐû²¼log4j-2.15.0-rc2²âÊÔ°æ±¾Óëapache-log4j-2.15.0Îȹ̰æÐÞ¸´¸ÃÎó²î£¬ÊÜÓ°ÏìÓû§¿ÉÏȽ«Apache Log4j2ËùÓÐÏà¹ØÓ¦Óõ½ÒÔÉϰ汾£¬ÏÂÔØÁ´½Ó£ºhttps://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc2»òhttps://logging.apache.org/log4j/2.x/download.html
×¢£º¿ÉÄÜ·ºÆð²»Îȹ̵ÄÇéÐΣ¬½¨ÒéÓû§ÔÚ±¸·ÝÊý¾ÝºóÔÙ¾ÙÐÐÉý¼¶¡£
Éý¼¶¹©Ó¦Á´ÖÐÒÑÖªÊÜÓ°ÏìµÄÓ¦Óü°×é¼þ£ºApache Solr¡¢Apache Struts2¡¢Apache Flink¡¢Apache Druid¡¢spring-boot-strater-log4j2
4.2 ²úÆ··À»¤
Õë¶Ô´ËÎó²î£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼WEBÓ¦Ó÷À»¤ÏµÍ³(WAF)ÓëÍøÂçÈëÇÖ·À»¤ÏµÍ³(IPS)ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÇëÏà¹ØÓû§Éý¼¶¹æÔò£¬ÒÔÐγÉÇå¾²²úÆ··À»¤ÄÜÁ¦¡£Çå¾²·À»¤²úÆ·¹æÔò°æ±¾ºÅÈçÏ£º
|
Çå¾²·À»¤²úÆ· |
¹æÔò°æ±¾ºÅ |
Éý¼¶°üÏÂÔØÁ´½Ó |
¹æÔò±àºÅ |
|
IPS |
5.6.11.26697 |
http://update.nsfocus.com/update/downloads/id/121950 |
[25475] |
|
5.6.10.26697 |
http://update.nsfocus.com/update/downloads/id/121949 |
||
|
5.6.9.26697 |
http://update.nsfocus.com/update/downloads/id/121948 |
||
|
WAF |
6.0.7.3.50737 |
http://update.nsfocus.com/update/downloads/id/121944 |
27005085 |
²úÆ·¹æÔòÉý¼¶µÄ²Ù×÷°ì·¨Ïê¼ûÈçÏÂÁ´½Ó£º
IPS£ºhttps://mp.weixin.qq.com/s/DxQ3aaap8aujqZf-3VbNJg
WAF£ºhttps://mp.weixin.qq.com/s/7F8WCzWsuJ5T2E9e01wNog
4.3 ÔÝʱ·À»¤²½·¥
ÈôÏà¹ØÓû§ÔÝʱÎÞ·¨¾ÙÐÐÉý¼¶²Ù×÷£¬¿ÉÏÈÓÃÏÂÁв½·¥¾ÙÐÐÔÝʱ»º½â£º
1¡¢Ìí¼ÓjvmÆô¶¯²ÎÊý:-Dlog4j2.formatMsgNoLookups=true

2¡¢ÔÚÓ¦ÓÃclasspathÏÂÌí¼Ólog4j2.component.propertiesÉèÖÃÎļþ£¬ÎļþÄÚÈÝΪ£ºlog4j2.formatMsgNoLookups=true

3¡¢½¨ÒéJDKʹÓÃ11.0.1¡¢8u191¡¢7u201¡¢6u211¼°ÒÔÉϵĸ߰汾
4¡¢ÏÞÖÆÊÜÓ°ÏìÓ¦ÓöÔÍâ»á¼û»¥ÁªÍø£¬²¢ÔÚ½çÏß¶ÔdnslogÏà¹ØÓòÃû»á¼û¾ÙÐмì²â¡£
²¿·Ö¹«¹²dnslogƽ̨ÈçÏ£º
ceye.io
dnslog.link
dnslog.cn
dnslog.io
tu4.org
burpcollaborator.net
s0x.cn
4.4 ƽ̨¼à²â
¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨£¨ESP-H£©Óë¾ÅÓÎÀϸçÖÇÄÜÇå¾²ÔËӪƽ̨£¨ISOP£©ÒѾ¾ß±¸Õë¶Ô´ËÎó²îµÄ¼ì²âÄÜÁ¦£¬°²ÅÅÓоÅÓÎÀÏ¸ç¿Æ¼¼Æ½Ì¨Àà²úÆ·µÄÓû§£¬¿ÉʵÏÖ¶ÔÎó²îµÄƽ̨¼à²âÄÜÁ¦¡£
|
Ç徲ƽ̨ |
Éý¼¶°ü/¹æÔò°æ±¾ºÅ |
|
ESP-H£¨¾ÅÓÎÀϸçÆóÒµÇ徲ƽ̨£© |
ʹÓÃ×îйæÔòÉý¼¶°ü vulnDict-2021121001.dat |
|
ISOP£¨¾ÅÓÎÀϸçÖÇÄÜÇå¾²ÔËӪƽ̨£© |
Éý¼¶¹¥»÷ʶ±ð¹æÔò°üÖÁ×îРattack_rule.1.0.0.1.1048648.dat |
ÉùÃ÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
<<ÉÏһƪ
¾ÅÓÎÀÏ¸ç¿Æ¼¼³µÁªÍøÇå¾²¼à²âÓë·À»¤ÏµÍ³»ñ×î¼Ñ¼ÝÊ»Çå¾²½â¾ö¼Æ»®½±>>ÏÂһƪ
ÖÇÔ쳤ɳ Çå¾²»¤º½£ü¾ÅÓÎÀÏ¸ç¿Æ¼¼ÁÁÏà2021Öв¿£¨³¤É³£©È˹¤ÖÇÄܹ¤ÒµÕ¹ÀÀ»á
¾ÅÓÎÀϸçÔÆ





