WebLogic T3ЭÒé·´ÐòÁл¯ 0day Îó²î

Ðû²¼Ê±¼ä 2021-04-19

0x00 Îó²î¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-04-19

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£


PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

ÊÇ

 

0x01 Îó²îÏêÇé

image.png

 

¿ËÈÕ£¬£¬£¬£¬£¬ £¬WebLogic±»Åû¶±£´æÒ»¸öT3ЭÒé·´ÐòÁл¯0 dayÎó²î£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬ £¬ÏÖÔÚ¸ÃÎó²î´¦ÓÚÔÚÒ°0day״̬£¬£¬£¬£¬£¬ £¬²¢ÇÒPoC/EXPÒÑÔÚGithubÉϹûÕæ¡£ ¡£¡£¡£¡£

ÔÚ¸ÃÎó²îµÄpocÖУ¬£¬£¬£¬£¬ £¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀ࣬£¬£¬£¬£¬ £¬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷£¬£¬£¬£¬£¬ £¬´ÓÖÐÆÊÎö¹¤¾ß£¬£¬£¬£¬£¬ £¬¿ÉÒÔͨ¹ý°ÑobjBytesÌæ»»ÎªÖ¸¶¨·´ÐòÁл¯¾Í¿ÉÒÔʵÏÖweblogicºÚÃûµ¥Èƹý¡£ ¡£¡£¡£¡£

image.png

 

0x02 ´¦Öóͷ£½¨Òé

½¨Ò齫jdkÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬ £¬²¢½ûÓÃiiop/t3ЭÒéÒÔ×÷ΪÔÝʱ»º½â²½·¥¡£ ¡£¡£¡£¡£

½ûÓÃT3ЭÒ飬£¬£¬£¬£¬ £¬Ïêϸ²Ù×÷ÈçÏ£º

1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ £¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬ £¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬ £¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬ £¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣠ¡£¡£¡£¡£

2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ £¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬ £¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sЭÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£ ¡£¡£¡£¡£

3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬ £¬¹æÔò·½¿ÉÉúЧ¡£ ¡£¡£¡£¡£

image.png

 

 

½ûÓÃIIOPЭÒ飬£¬£¬£¬£¬ £¬Ïêϸ²Ù×÷ÈçÏ£º

Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ £¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

image.png

 

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x04 ʱ¼äÏß

2021-04-18  Ñо¿Ö°Ô±Åû¶Îó²î

2021-04-19  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png