¹«º£²Ê´¬¡¤6600(ÖйúÓÎ)¹Ù·½ÍøÕ¾

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨·¢²¼
Ô¤Ô¼Ö±²¥
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ

©¶´Ó¦¼±|Oracle Weblogic ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2021-2109£©

·¢²¼Ê±¼ä£º2021-01-25

½üÈÕ£¬¹«º£²Ê´¬¡¤6600ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶӹØ×¢µ½Oracle¹Ù·½·¢²¼ÁË2021Äê1Ô¹ؼü²¹¶¡¸üй«¸æ£¬¸Ã²¹¶¡ÖÐÐÞ²¹Á˰üÀ¨ CVE-2021-2109 Weblogic ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´ÔÚÄڵĶà¸ö¸ßΣÑÏÖØÂ©¶´¡£ÔÚCVE-2021-2109©¶´ÖУ¬¹¥»÷Õ߿ɹ¹Ôì¶ñÒâÇëÇó£¬Ôì³ÉJNDI×¢Èë¡¢Ö´ÐÐÈÎÒâ´úÂ룬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£

 

Õë¶ÔÒÔÉÏ©¶´£¬¹«º£²Ê´¬¡¤6600°²È«Äܹ»½øÐЩ¶´É¨ÃèÓë¼ì²â£¬²¢×ö°²È«·À»¤¡£

 

©¶´¸´ÏÖ

 

  • »·¾³£ºWebLogic10.3.6.0.0

  • ·ÃÎÊ¿ØÖÆÌ¨½çÃæ·ÃÎÊ

    http://192.168.102:49163/console¼´¿É¿´µ½Ò³Ãæ

     

 

  • µÇ¼֮ºó½øÈ룺

 

 

  • Æô¶¯LDAP:

     

 

  • POC½Å±¾:

 

 

  • Æô¶¯POC£¬²¢·¢ËÍ£º

 

 

ÊÜÓ°Ïìϵͳ

 

Oracle WebLogic Server 14.1.1.0.0
Oracle WebLogic Server 12.2.1.4.0
Oracle WebLogic Server 12.2.1.3.0
Oracle WebLogic Server 12.1.3.0.0
Oracle WebLogic Server 10.3.6.0.0

 

¹Ù·½²¹¶¡

 

OracleÒѾ­Îª´Ë·¢²¼ÁËÒ»¸ö°²È«¹«¸æ£¨2021-01-19£©ÒÔ¼°ÏàÓ¦²¹¶¡:
2021-01-19£ºOracle Critical Patch Update Advisory -January 2021

Á´½Ó£ºhttps://www.oracle.com/security-alerts/cpujan2021.html

 

¹«º£²Ê´¬¡¤6600ÍøÂ簲ȫÆÀ¹ÀÓë¼ì²â¡¢·À»¤²úÆ·

 

²úÆ·

˵Ã÷

RG-WALLϵÁÐÏÂÒ»´ú

·À»ðǽ

 

ÏÂÒ»´ú·À»ðǽ½áºÏ·À²¡¶¾ÒÔ¼°ÍþвÇ鱨¼ì²â¡£ÔÚ°²È«ÄÜÁ¦ÉÏ£¬²»½öÖ§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ´«Í³°²È«¹¦ÄÜ£¬Ò²Ö§³Ö·á¸»µÄÓ¦Óü¶°²È«¹¦ÄÜ£¬°üÀ¨²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵È¡£Ìṩ¶àά¶ÈµÄÓ¦Óòã¼à¿ØÓë·ÖÎö£¬°ïÖúÓû§ÕÆÎÕ·çÏÕ£¬¾«×¼Ô¤¾¯¡£

RG-IDPϵÁÐÈëÇÖ¼ì²â

·ÀÓùϵͳ

¹«º£²Ê´¬¡¤6600ÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢°²È«·À»¤¡¢ÉÏÍøÐÐΪ¹ÜÀíµÈ¼¼Êõ½áºÏµÄÈëÇÖ¼ì²â·ÀÓùϵͳÉ豸¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ½øÐÐ׼ȷµÄ·ÖÎöÅжÏ£¬Ö÷¶¯ÓÐЧµÄ±£»¤ÍøÂ簲ȫ¡£ÅäºÏʵʱ¸üеÄÈëÇÖ¹¥»÷ÌØÕ÷¿â£¬¿É¼ì²â·À»¤3500ÖÖÒÔÉϵÄÍøÂç¹¥»÷ÐÐΪ£¬°üº¬DoS/DDoS¡¢²¡¶¾¡¢È䳿¡¢½©Ê¬ÍøÂ硢ľÂí¡¢¿ÉÒÉ´úÂ롢̽²âÓëɨÃèµÈ¸÷ÖÖÍøÂçÍþв¡£

RG-ScanϵÁЩ¶´ÆÀ¹Àϵͳ

RG-Scanͨ¹ý¶Ôϵͳ©¶´¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢Èë©¶´ÒÔ¼°¿çÕ¾½Å±¾µÈ¹¥»÷ÊֶζàÄêµÄÑо¿»ýÀÛ£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢ÏÖ¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈ¼¼Êõ£¬¿ÉÒÔͨ¹ýÖÇÄܱéÀú¹æÔò¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄÊֶΣ¬ÉîÈë׼ȷµÄ¼ì²â³öϵͳºÍÍøÕ¾ÖдæÔڵĩ¶´ºÍÈõµã¡£

RG-WG  WEBGuardÓ¦Óñ£»¤ÏµÍ³

¹«º£²Ê´¬¡¤6600RG-WG WebGuardÓ¦Óñ£»¤ÏµÍ³£¬Í¨¹ý¶Ô½ø³öWeb·þÎñÆ÷µÄHTTP/HTTPSÁ÷Á¿Ïà¹ØÄÚÈݵÄʵʱ·ÖÎö¼ì²â¡¢¹ýÂË£¬À´¾«È·Åж¨²¢×èÖ¹¸÷ÖÖWebÓ¦ÓÃÈëÇÖÐÐΪ£¬×è¶Ï¶ÔWeb·þÎñÆ÷µÄ¶ñÒâ·ÃÎÊÓë·Ç·¨²Ù×÷¡£

 

ÆäÖУ¬WEBGuardÓ¦Óñ£»¤ÏµÍ³ÅäÖòßÂÔ£º

²½Öè1£ºµÇ¼WG WEB¹ÜÀí½çÃæ

²½Öè2£ºÔÚ“·ÃÎÊ¿ØÖÆ-URLºÚÃûµ¥”Ìí¼ÓÈçϲßÂÔ

 

 

 

Ô´IP

0.0.0.0

WebÖ÷»ú

¿Õ

URL

/console/consolejndi.portal

 

²½Öè3£º¼ì²éÅäÖýá¹û

 

 

°²È«½¨Òé

 

 

1.  ½ûÓÃT3ЭÒ飺

 

Èç¹ûÄú²»ÒÀÀµT3ЭÒé½øÐÐJVMͨÐÅ£¬¿Éͨ¹ýÔÝʱ×è¶ÏT3ЭÒ黺½â´Ë©¶´´øÀ´µÄÓ°Ïì

 

  • ½øÈëWeblogic¿ØÖÆÌ¨£¬ÔÚbase_domainÅäÖÃÒ³ÃæÖУ¬½øÈë“°²È«”Ñ¡Ïî¿¨Ò³Ãæ£¬µã»÷“ɸѡÆ÷”£¬ÅäÖÃɸѡÆ÷¡£

     

  • ÔÚÁ¬½ÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬ÔÚÁ¬½ÓɸѡÆ÷¹æÔò¿òÖÐÊäÈ룺* * 7001 deny t3 t3s¡£

 

 

 

2.  ½ûÖ¹ÆôÓÃIIOP£º

 

µÇ½Weblogic¿ØÖÆÌ¨£¬ÕÒµ½ÆôÓÃIIOPÑ¡ÏȡÏû¹´Ñ¡£¬ÖØÆôÉúЧ¡£

 

 

 

 

 

3.  ÁÙʱ¹Ø±Õºǫ́/console/console.portal¶ÔÍâ·ÃÎÊ

 

ÍŶӽéÉÜ

 

¹«º£²Ê´¬¡¤6600ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶÓ£¬¸ú×Ù×îл¥ÁªÍøÍþвʼþ£¬Õë¶Ô×îа²È«Â©¶´£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö;Ϊ²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤²ßÂÔÓë½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø¡£

 

 

¹«º£²Ê´¬¡¤6600“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö·¢»Ó£¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯£¬¸æ±ð°²È«¹Âµº£¬¹¹³ÉÕûÍøÁª¶¯µÄ°²È«±£ÕÏÌåϵ£¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£

 

 

ÈçÄúÐèÒª¹«º£²Ê´¬¡¤6600°²È«£¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½

 

¹Ø×¢¹«º£²Ê´¬¡¤6600
¹Ø×¢¹«º£²Ê´¬¡¤6600¹ÙÍøÎ¢ÐÅ
ËæÊ±Á˽⹫˾×îж¯Ì¬

·µ»Ø¶¥²¿

ÊÕÆð
ÎĵµAIÖúÊÖ
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶Ôµ±Ç°Ò³ÃæµÄÂúÒâ¶ÈÈçºÎ£¿
²»Õ¦µÎ
·Ç³£ºÃ
ÄúÂúÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
¸ÐлÄúµÄ·´À¡£¡
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´À¡ Òâ¼û·´À¡
Òâ¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿