Sophos XG·À»ðǽSQL×¢ÈëÎó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-27

0x00 Îó²î¸ÅÊö


CVE   ID

ÔÝÎÞ

ʱ   ¼ä

2020-04-27

Àà    ÐÍ

SI

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

ËùÓа汾µÄXG·À»ðǽ


0x01 Îó²îÏêÇé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Sophos XG FirewallÊÇÓ¢¹úSophos¹«Ë¾µÄÒ»¿î·À»ðǽװ±¸¡£¡£¡£¡£¡£¡£SFOSÊÇÔËÐÐÔÚÆäÖеÄÒ»ÌײÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£

SophosÓÚUTC 2020Äê4ÔÂ22ÈÕ20:29ÊÕµ½ÁËÓйØXG·À»ðǽµÄ±¨¸æ£¬£¬£¬£¬ £¬£¬£¬¸ÃXG·À»ðǽÔÚÖÎÀí½çÃæÖпɼû¿ÉÒÉ×ֶΡ£¡£¡£¡£¡£¡£ÊӲ췢Ã÷¸ÃÊÂÎñΪ¹¥»÷ÊÂÎñ£¬£¬£¬£¬ £¬£¬£¬¶ø²»ÊDzúÆ·bug¡£¡£¡£¡£¡£¡£ºÚ¿ÍÖ÷ÒªÕë¶ÔµÄÊÇ¿ªÆôHTTPSЧÀÍ»òÕßÓû§¿ØÖÆÃæ°å̻¶ÔÚ»¥ÁªÍøÉϵÄSophos XG Firewall×°±¸¡£¡£¡£¡£¡£¡£

¸Ã¹¥»÷ʹÓÃÒÔǰδ֪µÄSQL×¢ÈëÎó²îÀ´ÏÂÔØpayloads¡£¡£¡£¡£¡£¡£È»ºóÇÔÈ¡Îļþ£¬£¬£¬£¬ £¬£¬£¬¿ÉÄܰüÀ¨·À»ðǽÖÎÀíÔ±£¬£¬£¬£¬ £¬£¬£¬·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÒÔ¼°ÓÃÓÚÔ¶³Ì»á¼û×°±¸µÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£¡£¡£¡£¡£¡£¿ÉÊÇÉí·ÝÑé֤ϵͳ£¨ÀýÈçAD»òLDAP£©µÄÃÜÂë²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£

¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬ÔÚÊÓ²ìÀú³ÌÖУ¬£¬£¬£¬ £¬£¬£¬Ã»Óз¢Ã÷ºÚ¿ÍʹÓÃ͵ÇÔµÄÃÜÂë»á¼ûÁ˿ͻ§ÄÚÍøÉϵÄXG·À»ðǽװ±¸»ò·À»ðǽÒÔÍâµÄÈκÎÄÚÈÝ¡£¡£¡£¡£¡£¡£


0x02 ´¦Öóͷ£½¨Òé


²¹¶¡³ÌÐò»áÔÚXGÖÎÀí½çÃæÉÏÌáÐÑÒ»ÌõÐÂÎÅ£¬£¬£¬£¬ £¬£¬£¬À´ÌáÐÑ´ËXG·À»ðǽÊÇ·ñÊܵ½´Ë¹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£¡£

¼Æ»®1£ºÎ´Ôâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬£¬Ö±½Ó¸üв¹¶¡¼´¿É¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼Æ»®2£ºÈôÊÇÒÑÔâµ½¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ÈçÏÂͼ¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹ØÓÚÔâµ½ÈëÇÖµÄ×°±¸£¬£¬£¬£¬ £¬£¬£¬Sophos½¨Òé½ÓÄÉÒÔϰ취£º

1. ÖØÖÃÃÅ»§ÍøÕ¾ÖÎÀíÔ±ºÍ×°±¸ÖÎÀíÔ±ÕÊ»§

2. ÖØÐÂÆô¶¯XG×°±¸

3. ÖØÖÃËùÓÐÍâµØÓû§ÕÊ»§µÄÃÜÂë

4. Ö»¹ÜÃÜÂëÊǹþÏ£Öµ£¬£¬£¬£¬ £¬£¬£¬µ«½¨ÒéÖØÖÃËùÓÐÕÊ»§ÃÜÂë

×¢ÖØ£º¸üд˲¹¶¡³ÌÐòºó£¬£¬£¬£¬ £¬£¬£¬²¹¶¡³ÌÐò¾¯±¨ÐÂÎŲ»»áÏûÊÅ¡£¡£¡£¡£¡£¡£×ÝÈ»ÒÑÀÖ³ÉÓ¦Óô˲¹¶¡³ÌÐò£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°Íê³ÉÁËÈÎºÎÆäËû²Ù×÷°ì·¨Ö®ºó£¬£¬£¬£¬ £¬£¬£¬¾¯±¨Ò²½«Ò»Á¬ÏÔʾÔÚXGÖÎÀí½çÃæÖС£¡£¡£¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/


0x04 ²Î¿¼Á´½Ó


https://community.sophos.com/kb/en-us/135412


0x05 ʱ¼äÏß


2020-04-25 SophosÐû²¼¸üÐÂ

2020-04-27  VSRCÐû²¼Îó²îͨ¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨