·¢²¼Ê±¼ä£º2021-01-25
½üÈÕ£¬¹«º£²Ê´¬¡¤6600ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶӹØ×¢µ½Oracle¹Ù·½·¢²¼ÁË2021Äê1Ô¹ؼü²¹¶¡¸üй«¸æ£¬¸Ã²¹¶¡ÖÐÐÞ²¹Á˰üÀ¨ CVE-2021-2109 Weblogic ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ÔÚÄڵĶà¸ö¸ßΣÑÏÖØÂ©¶´¡£ÔÚCVE-2021-2109©¶´ÖУ¬¹¥»÷Õ߿ɹ¹Ôì¶ñÒâÇëÇó£¬Ôì³ÉJNDI×¢Èë¡¢Ö´ÐÐÈÎÒâ´úÂ룬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£
Õë¶ÔÒÔÉÏ©¶´£¬¹«º£²Ê´¬¡¤6600°²È«Äܹ»½øÐЩ¶´É¨ÃèÓë¼ì²â£¬²¢×ö°²È«·À»¤¡£
©¶´¸´ÏÖ
»·¾³£ºWebLogic10.3.6.0.0
·ÃÎÊ¿ØÖÆÌ¨½çÃæ·ÃÎÊ
http://192.168.102:49163/console¼´¿É¿´µ½Ò³Ãæ

µÇ¼֮ºó½øÈ룺

Æô¶¯LDAP:

POC½Å±¾:

Æô¶¯POC£¬²¢·¢ËÍ£º

ÊÜÓ°Ïìϵͳ
Oracle WebLogic Server 14.1.1.0.0
Oracle WebLogic Server 12.2.1.4.0
Oracle WebLogic Server 12.2.1.3.0
Oracle WebLogic Server 12.1.3.0.0
Oracle WebLogic Server 10.3.6.0.0
¹Ù·½²¹¶¡
OracleÒѾΪ´Ë·¢²¼ÁËÒ»¸ö°²È«¹«¸æ£¨2021-01-19£©ÒÔ¼°ÏàÓ¦²¹¶¡:
2021-01-19£ºOracle Critical Patch Update Advisory -January 2021
Á´½Ó£ºhttps://www.oracle.com/security-alerts/cpujan2021.html
¹«º£²Ê´¬¡¤6600ÍøÂ簲ȫÆÀ¹ÀÓë¼ì²â¡¢·À»¤²úÆ·
|
²úÆ· |
˵Ã÷ |
|
RG-WALLϵÁÐÏÂÒ»´ú ·À»ðǽ
|
ÏÂÒ»´ú·À»ðǽ½áºÏ·À²¡¶¾ÒÔ¼°ÍþвÇ鱨¼ì²â¡£ÔÚ°²È«ÄÜÁ¦ÉÏ£¬²»½öÖ§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ´«Í³°²È«¹¦ÄÜ£¬Ò²Ö§³Ö·á¸»µÄÓ¦Óü¶°²È«¹¦ÄÜ£¬°üÀ¨²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵ȡ£Ìṩ¶àά¶ÈµÄÓ¦Óòã¼à¿ØÓë·ÖÎö£¬°ïÖúÓû§ÕÆÎÕ·çÏÕ£¬¾«×¼Ô¤¾¯¡£ |
|
RG-IDPϵÁÐÈëÇÖ¼ì²â ·ÀÓùϵͳ |
¹«º£²Ê´¬¡¤6600ÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢°²È«·À»¤¡¢ÉÏÍøÐÐΪ¹ÜÀíµÈ¼¼Êõ½áºÏµÄÈëÇÖ¼ì²â·ÀÓùϵͳÉ豸¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ½øÐÐ׼ȷµÄ·ÖÎöÅжϣ¬Ö÷¶¯ÓÐЧµÄ±£»¤ÍøÂ簲ȫ¡£ÅäºÏʵʱ¸üеÄÈëÇÖ¹¥»÷ÌØÕ÷¿â£¬¿É¼ì²â·À»¤3500ÖÖÒÔÉϵÄÍøÂç¹¥»÷ÐÐΪ£¬°üº¬DoS/DDoS¡¢²¡¶¾¡¢È䳿¡¢½©Ê¬ÍøÂ硢ľÂí¡¢¿ÉÒÉ´úÂ롢̽²âÓëɨÃèµÈ¸÷ÖÖÍøÂçÍþв¡£ |
|
RG-ScanϵÁЩ¶´ÆÀ¹Àϵͳ |
RG-Scanͨ¹ý¶Ôϵͳ©¶´¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢Èë©¶´ÒÔ¼°¿çÕ¾½Å±¾µÈ¹¥»÷ÊֶζàÄêµÄÑо¿»ýÀÛ£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢ÏÖ¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈ¼¼Êõ£¬¿ÉÒÔͨ¹ýÖÇÄܱéÀú¹æÔò¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄÊֶΣ¬ÉîÈë׼ȷµÄ¼ì²â³öϵͳºÍÍøÕ¾ÖдæÔڵĩ¶´ºÍÈõµã¡£ |
|
RG-WG WEBGuardÓ¦Óñ£»¤ÏµÍ³ |
¹«º£²Ê´¬¡¤6600RG-WG WebGuardÓ¦Óñ£»¤ÏµÍ³£¬Í¨¹ý¶Ô½ø³öWeb·þÎñÆ÷µÄHTTP/HTTPSÁ÷Á¿Ïà¹ØÄÚÈݵÄʵʱ·ÖÎö¼ì²â¡¢¹ýÂË£¬À´¾«È·Åж¨²¢×èÖ¹¸÷ÖÖWebÓ¦ÓÃÈëÇÖÐÐΪ£¬×è¶Ï¶ÔWeb·þÎñÆ÷µÄ¶ñÒâ·ÃÎÊÓë·Ç·¨²Ù×÷¡£ |
ÆäÖУ¬WEBGuardÓ¦Óñ£»¤ÏµÍ³ÅäÖòßÂÔ£º
²½Öè1£ºµÇ¼WG WEB¹ÜÀí½çÃæ
²½Öè2£ºÔÚ“·ÃÎÊ¿ØÖÆ-URLºÚÃûµ¥”Ìí¼ÓÈçϲßÂÔ

|
Ô´IP |
0.0.0.0 |
|
WebÖ÷»ú |
¿Õ |
|
URL |
/console/consolejndi.portal |
²½Öè3£º¼ì²éÅäÖýá¹û

°²È«½¨Òé
1. ½ûÓÃT3ÐÒ飺
Èç¹ûÄú²»ÒÀÀµT3ÐÒé½øÐÐJVMͨÐÅ£¬¿Éͨ¹ýÔÝʱ×è¶ÏT3ÐÒ黺½â´Ë©¶´´øÀ´µÄÓ°Ïì
½øÈëWeblogic¿ØÖÆÌ¨£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈë“°²È«”Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷“ɸѡÆ÷”£¬ÅäÖÃɸѡÆ÷¡£
ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔò¿òÖÐÊäÈ룺* * 7001 deny t3 t3s¡£

2. ½ûÖ¹ÆôÓÃIIOP£º
µÇ½Weblogic¿ØÖÆÌ¨£¬ÕÒµ½ÆôÓÃIIOPÑ¡ÏȡÏû¹´Ñ¡£¬ÖØÆôÉúЧ¡£


3. ÁÙʱ¹Ø±Õºǫ́/console/console.portal¶ÔÍâ·ÃÎÊ
ÍŶӽéÉÜ
¹«º£²Ê´¬¡¤6600ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶӣ¬¸ú×Ù×îл¥ÁªÍøÍþвʼþ£¬Õë¶Ô×îа²È«Â©¶´£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö;Ϊ²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤²ßÂÔÓë½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø¡£

¹«º£²Ê´¬¡¤6600“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö·¢»Ó£¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯£¬¸æ±ð°²È«¹Âµº£¬¹¹³ÉÕûÍøÁª¶¯µÄ°²È«±£ÕÏÌåϵ£¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£

ÈçÄúÐèÒª¹«º£²Ê´¬¡¤6600°²È«£¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½
