¹«º£²Ê´¬¡¤6600(ÖйúÓÎ)¹Ù·½ÍøÕ¾


µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨·¢²¼
Ô¤Ô¼Ö±²¥
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ

΢Èí Exchange·þÎñÆ÷¶à¸ö¸ßΣ©¶´Í¨¸æ

·¢²¼Ê±¼ä£º2021-03-04

2021Äê3ÔÂ3ÈÕ£¬¹«º£²Ê´¬¡¤6600ÍøÂ簲ȫӦ¼±ÍŶÓ×·×Ùµ½Î¢ÈíÓÚ2021Äê3ÔÂ2ÈÕ Õë¶ÔExchange·þÎñÆ÷·¢²¼Á˶à¸ö¸ßΣ©¶´µÄ·çÏÕͨ¸æ£¬Â©¶´±àºÅΪCVE-2021-26855,CVE-2021-26857,CVE-2021-26858,CVE-2021-27065£¬ÔÚCVSSÖжÔÕâЩ©¶´¸ø³öÁË±È½Ï¸ßµÄÆÀ·Ö¡£ÍþвÐж¯ÕßÀûÓÃÕâЩ©¶´·ÃÎʱ¾µØExchange·þÎñÆ÷£¬´Ó¶ø¿ÉÒÔ·ÃÎʵç×ÓÓʼþÕÊ»§£¬²¢ÔÊÐí°²×°ÆäËû¶ñÒâÈí¼þÒÔ´Ù½ø¶ÔÊܺ¦Õß»·¾³µÄ³¤ÆÚ·ÃÎÊ¡£


¶Ô´Ë£¬¹«º£²Ê´¬¡¤6600ÍøÂ簲ȫӦ¼±ÍŶӽ¨Òé¹ã´óÓû§¼°Ê±½«ExchangeÉý¼¶µ½×îа汾¡£Óë´Ëͬʱ£¬Çë×öºÃ×ʲú×Ô²éÒÔ¼°Ô¤·À¹¤×÷£¬ÒÔÃâÔâÊܺڿ͹¥»÷¡£

 


Ó°Ïì°æ±¾

Exchange server£º2010/2013/2016/2019
Exchange online£º²»ÊÜÓ°Ïì¡£


©¶´ÏêÇé

 

1.    CVE-2021-26855: ·þÎñ¶ËÇëÇóαÔì©¶´

Exchange ·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©Â©¶´£¬ÀûÓôË©¶´µÄ¹¥»÷ÕßÄܹ»·¢ËÍÈÎÒâ HTTP ÇëÇó²¢Í¨¹ý Exchange Server ½øÐÐÉí·ÝÑéÖ¤¡£


2.   CVE-2021-26857: ÐòÁл¯Â©¶´

Exchange ·´ÐòÁл¯Â©¶´£¬¸Ã©¶´ÐèÒª¹ÜÀíԱȨÏÞ£¬ÀûÓôË©¶´µÄ¹¥»÷Õß¿ÉÒÔÔÚ Exchange ·þÎñÆ÷ÉÏÒÔ SYSTEM Éí·ÝÔËÐдúÂë¡£


3.   CVE-2021-26858: ÈÎÒâÎļþдÈë©¶´

Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄÈÎÒâÎļþдÈë©¶´¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬¿ÉÒÔÀûÓôË©¶´½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£¸Ã©¶´¿ÉÒÔ ÅäºÏ CVE-2021-26855 SSRF ©¶´½øÐÐ×éºÏ¹¥»÷¡£


4.   CVE-2021-27065: ÈÎÒâÎļþдÈë©¶´

Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄÈÎÒâÎļþдÈë©¶´¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬¿ÉÒÔÀûÓôË©¶´½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£¸Ã©¶´¿ÉÒÔ ÅäºÏ CVE-2021-26855 SSRF ©¶´½øÐÐ×éºÏ¹¥»÷¡£


°²È«½¨Òé

΢ÈíÒÑ·¢²¼Ïà¹Ø°²È«¸üУ¬Óû§¿É¸ú½øÒÔÏÂÁ´½Ó½øÐÐÉý¼¶:


CVE-2021-26855: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26855

CVE-2021-26857: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26857
CVE-2021-26858: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26858
CVE-2021-27065: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-27065


¹¥»÷¼ì²â½¨Òé

 

01 CVE-2021-26855

¿ÉÒÔͨ¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾½øÐмì²â£º


%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy

¿ÉÒÔͨ¹ýÔÚÈÕÖ¾ÌõÄ¿ÖÐËÑË÷AuthenticatedUserÊÇ·ñΪ¿Õ²¢ÇÒAnchorMailboxÊÇ·ñ°üº¬ServerInfo?* / *ģʽʶ±ð©¶´ÀûÓá£ÒÔÏÂPowershell¿ÉÖ±½Ó½øÐÐÈÕÖ¾¼ì²â£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷£º


Import-Csv-Path(Get-ChildItem-Recurse-Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy”- Filter ‘*.log’).FullName | Where-Object {  $_.AuthenticatedUser -eq ” -and $_.AnchorMailbox -like ‘ServerInfo~*/*’ } | select DateTime, AnchorMailbox

Èç¹û¼ì²âµ½ÁËÈëÇÖ£¬¿ÉÒÔͨ¹ý¼ì²âAnchorMailbox·¾¶ÖÐÖ¸¶¨Ìض¨Ó¦ÓóÌÐòµÄÈÕÖ¾À´»ñÈ¡¹¥»÷Õß²ÉÈ¡ÁËÄÄЩ»î¶¯£º


%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging

 

02 CVE-2021-26858

ͨ¹ýExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-26858ÀûÓãº


ÈÕ־Ŀ¼£º
C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog


¿Éͨ¹ýÒÔÏÂÃüÁî½øÐпìËÙä¯ÀÀ£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷£º


findstr /snip /c:”Download failed and temporary file” “%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log”


03 CVE-2021-26857

ͨ¹ýWindowsÓ¦ÓóÌÐòʼþÈÕÖ¾¼ì²âCVE-2021-26857ÀûÓã¬ÀûÓô˷´ÐòÁл¯´íÎ󽫴´½¨¾ßÓÐÒÔÏÂÊôÐÔµÄÓ¦ÓóÌÐòʼþ£º


À´Ô´£ºMSExchangeͳһÏûÏ¢
EntryType£º´íÎó
ʼþÏûÏ¢°üº¬£ºSystem.InvalidCastExceptio


¸Ã©¶´µ¥¶ÀÀûÓÃÄѶÈÉԸߣ¬¿ÉÀûÓÃÒÔÏÂÃüÁîÔÚÓ¦ÓóÌÐòʼþÈÕÖ¾ÖвéѯÕâЩÈÕÖ¾ÌõÄ¿£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷¡£


Get-EventLog -LogName Application -Source “MSExchange Unified Messaging” -EntryType Error | Where-Object { $_.Message -like “*System.InvalidCastException*” }


04 CVE-2021-27065

ͨ¹ýÒÔÏÂExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-27065ÀûÓã¬


C£º\ Program Files \ Microsoft \ Exchange Server \ V15 \ Logging \ ECP \ Server

ËùÓÐSet- <AppName> VirtualDirectoryÊôÐÔ¶¼²»Ó¦°üº¬½Å±¾¡£InternalUrlºÍExternalUrlÓ¦¸Ã½öÊÇÓÐЧUris¡£


ͨ¹ýpowershellÃüÁî½øÐÐÈÕÖ¾¼ì²â£¬²¢¼ì²éÊÇ·ñÔâµ½¹¥»÷:


Select-String -Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log” -Pattern ‘Set-.+VirtualDirectory’


°²È«·À»¤»º½â

¹¥»÷ÕßÀûÓÃÉÏÊö©¶´¿ÉÒÔ½øÐÐwebshell¡¢¶ñÒâÎļþÉÏ´«ÒÔ¼°¶ñÒâÍøÂçͨÐÅÐÐΪ¡£Îª»º½â¹¥»÷ÕßÀûÓÃÕâЩ©¶´½øÐкóÐøµÄ¹¥»÷Ðж¯£¬½¨Òé¿Í»§¼°Ê±²ÉÓð²È«Íø¹Ø²úÆ·½øÐм°Ê±µÄ¹¥»÷·À»¤Ó뻺½â¡£

 

 

²úÆ·

˵Ã÷

RG-APT¸ß¼¶Íþв¼ì²âϵͳ

¹«º£²Ê´¬¡¤6600¸ß¼¶Íþв¼ì²âϵͳ£¨RG-APT£©»ùÓÚ“Îļþ+Á÷Á¿”˫ά¶È·ÖÎö¼Ü¹¹¡£Í¨¹ý¶ÀÓеİ˴óºËÐÄÒýÇæ£¬×ÛºÏÍþвÇ鱨¡¢ÐÐΪģÐÍ¡¢»úÆ÷ѧϰ¡¢ÐéÄ⻯ɳÏäºÍ°²È«ÌØÕ÷¿âµÈ¼ì²â¼¼Êõ¸²¸Çʽ·¢Ïָ߼¶Î´ÖªÍþв.

RG-WALLϵÁÐÏÂÒ»´ú·À»ðǽ

ÏÂÒ»´ú·À»ðǽ½áºÏ·À²¡¶¾ÒÔ¼°ÍþвÇ鱨¼ì²â¡£¼ì²âÖ÷Á÷½©Ä¾È䣬aptÑù±¾¡£

RG-BDS-TSP

¹«º£²Ê´¬¡¤6600NFA̽Õëϵͳ£¬½áºÏ×îеÄÍþвÇ鱨£¬ÊµÊ±¼ø±ðÍøÂçÖд«ÊäÎļþ£¬ÅжÏDZÔÚ²¡¶¾¡£

 

ÍŶӽéÉÜ

 

¹«º£²Ê´¬¡¤6600ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶÓ£¬¸ú×Ù×îл¥ÁªÍøÍþвʼþ£¬Õë¶Ô×îа²È«Â©¶´£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤²ßÂÔÓë½â¾ö¹«º£²Ê´¬¡¤6600¹ÙÍø¡£

 

¹«º£²Ê´¬¡¤6600“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö·¢»Ó£¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯£¬¸æ±ð°²È«¹Âµº£¬¹¹³ÉÕûÍøÁª¶¯µÄ°²È«±£ÕÏÌåϵ£¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£

 


?ÈçÄúÐèÒª¹«º£²Ê´¬¡¤6600°²È«£¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½

¹Ø×¢¹«º£²Ê´¬¡¤6600
¹Ø×¢¹«º£²Ê´¬¡¤6600¹ÙÍøÎ¢ÐÅ
ËæÊ±Á˽⹫˾×îж¯Ì¬

·µ»Ø¶¥²¿

ÊÕÆð
ÎĵµAIÖúÊÖ
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
Äú¶Ôµ±Ç°Ò³ÃæµÄÂúÒâ¶ÈÈçºÎ£¿
²»Õ¦µÎ
·Ç³£ºÃ
ÄúÂúÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
¸ÐлÄúµÄ·´À¡£¡
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´À¡ Òâ¼û·´À¡
Òâ¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿