°ä²¼¹¦·ò£º2021-03-04
2021Äê3ÔÂ3ÈÕ£¬GA»Æ½ð¼×ÍøÂ簲ȫӦ¼±ÍŶÓ×·×Ùµ½Î¢ÈíÓÚ2021Äê3ÔÂ2ÈÕ Õë¶ÔExchange·þÎñÆ÷°ä²¼Á˶à¸ö¸ßΣ·ì϶µÄ·çÏÕ¹«¸æ£¬·ì϶±àºÅΪCVE-2021-26855,CVE-2021-26857,CVE-2021-26858,CVE-2021-27065£¬ÔÚCVSSÖжÔÕâЩ·ì϶¸ø³öÁ˱ÈÁ¦¸ßµÄÆÀ·Ö¡£ÍþвÐж¯ÕßÀûÓÃÕâЩ·ì϶½Ó¼û±¾µØExchange·þÎñÆ÷£¬´Ó¶øÄܹ»½Ó¼ûµç×ÓÓʼþÕÊ»§£¬²¢ÔÊÐí×°ÖÃÆäËû¶ñÒâÈí¼þÒÔÍÆ½ø¶ÔÊܺ¦Õß»·¾³µÄ³Ö¾Ã½Ó¼û¡£
¶Ô´Ë£¬GA»Æ½ð¼×ÍøÂ簲ȫӦ¼±ÍŶӽ¨Òé¿í´óÓû§ÊµÊ±½«ExchangeÉý¼¶µ½×îа汾¡£Óë´Ëͬʱ£¬Çë×öºÃ×ʲú×Ô²éÒÔ¼°Ô¤·À¹¤×÷£¬ÒÔÃâÔâ·êºÚ¿Í¹¥»÷¡£
Ó°Ïì°æ±¾
Exchange server£º2010/2013/2016/2019
Exchange online£º²»ÊÜÓ°Ïì¡£
·ì϶ÏêÇé
1. CVE-2021-26855: ·þÎñ¶ËÒªÇóαÔì·ì϶
Exchange ·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶£¬ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâ HTTP ÒªÇó²¢Í¨¹ý Exchange Server ½øÐÐÉí·ÝÑéÖ¤¡£
2. CVE-2021-26857: ÐòÁл¯·ì϶
Exchange ·´ÐòÁл¯·ì϶£¬¸Ã·ì϶±ØÒªÖÎÀíԱȨÏÞ£¬ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚ Exchange ·þÎñÆ÷ÉÏÒÔ SYSTEM Éí·ÝÔËÐдúÂë¡£
3. CVE-2021-26858: ËÁÒâÎļþдÈë·ì϶
Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬Äܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκÎõè¾¶¡£¸Ã·ì϶Äܹ» ¹²Í¬ CVE-2021-26855 SSRF ·ì϶½øÐÐ×éºÏ¹¥»÷¡£
4. CVE-2021-27065: ËÁÒâÎļþдÈë·ì϶
Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬Äܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκÎõè¾¶¡£¸Ã·ì϶Äܹ» ¹²Í¬ CVE-2021-26855 SSRF ·ì϶½øÐÐ×éºÏ¹¥»÷¡£
°²È«½¨Òé
΢ÈíÒѰ䲼Óйذ²È«¸üУ¬Óû§¿É¸ú½øÒÔÏÂÁ´½Ó½øÐÐÉý¼¶:
CVE-2021-26855: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26855
CVE-2021-26857: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26857
CVE-2021-26858: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26858
CVE-2021-27065: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-27065
¹¥»÷¼ì²â½¨Òé
01 CVE-2021-26855
Äܹ»Í¨¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾½øÐмì²â£º
%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy
Äܹ»Í¨¹ýÔÚÈÕÖ¾Ìõ¿îÖÐËÑË÷AuthenticatedUserÊÇ·ñΪ¿Õ²¢ÇÒAnchorMailboxÊÇ·ñÔ̺¬ServerInfo?* / *ģʽ¼ø±ð·ì϶ÀûÓá£ÒÔÏÂPowershell¿ÉÖ±½Ó½øÐÐÈÕÖ¾¼ì²â£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷£º
Import-Csv-Path(Get-ChildItem-Recurse-Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy”- Filter ‘*.log’).FullName | Where-Object { $_.AuthenticatedUser -eq ” -and $_.AnchorMailbox -like ‘ServerInfo~*/*’ } | select DateTime, AnchorMailbox
ÈôÊǼì²âµ½ÁËÈëÇÖ£¬Äܹ»Í¨¹ý¼ì²âAnchorMailboxõè¾¶ÖÐÖ¸¶¨Ìض¨ÀûÓ÷¨Ê½µÄÈÕÖ¾À´»ñÈ¡¹¥»÷Õß²ÉÈ¡ÁËÄÄЩ»î¶¯£º
%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging
02 CVE-2021-26858
ͨ¹ýExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-26858ÀûÓãº
ÈÕ־Ŀ¼£º
C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog
¿Éͨ¹ýÒÔϺÅÁî½øÐм±¾çä¯ÀÀ£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷£º
findstr /snip /c:”Download failed and temporary file” “%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log”
03 CVE-2021-26857
ͨ¹ýWindowsÀûÓ÷¨Ê½ÊÂÎñÈÕÖ¾¼ì²âCVE-2021-26857ÀûÓã¬ÀûÓô˷´ÐòÁл¯ÃýÎ󽫴´½¨ÓµÓÐÒÔÏÂÊôÐÔµÄÀûÓ÷¨Ê½ÊÂÎñ£º
ÆðÔ´£ºMSExchangeͳһÐÂÎÅ
EntryType£ºÃýÎó
ÊÂÎñÐÂÎÅÔ̺¬£ºSystem.InvalidCastExceptio
¸Ã·ì϶µ¥¶ÀÀûÓÃÄѶÈÉԸߣ¬¿ÉÀûÓÃÒÔϺÅÁîÔÚÀûÓ÷¨Ê½ÊÂÎñÈÕÖ¾ÖвéÎÊÕâЩÈÕÖ¾Ìõ¿î£¬²¢²é³ÊÇ·ñÊܵ½¹¥»÷¡£
Get-EventLog -LogName Application -Source “MSExchange Unified Messaging” -EntryType Error | Where-Object { $_.Message -like “*System.InvalidCastException*” }
04 CVE-2021-27065
ͨ¹ýÒÔÏÂExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-27065ÀûÓã¬
C£º\ Program Files \ Microsoft \ Exchange Server \ V15 \ Logging \ ECP \ Server
ËùÓÐSet- <AppName> VirtualDirectoryÊôÐÔ¶¼²»Ó¦Ô̺¬¾ç±¾¡£InternalUrlºÍExternalUrlÓ¦¸Ã½öÊÇÓÐЧUris¡£
ͨ¹ýpowershellºÅÁî½øÐÐÈÕÖ¾¼ì²â£¬²¢²é³ÊÇ·ñÔâµ½¹¥»÷:
Select-String -Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log” -Pattern ‘Set-.+VirtualDirectory’
°²È«·À»¤»º½â
¹¥»÷ÕßÀûÓÃÉÏÊö·ì϶Äܹ»½øÐÐwebshell¡¢¶ñÒâÎļþÉÏ´«ÒÔ¼°¶ñÒâÍøÂçͨѶÐÐΪ¡£Îª»º½â¹¥»÷ÕßÀûÓÃÕâЩ·ì϶½øÐкóÐøµÄ¹¥»÷Ðж¯£¬½¨Òé¿Í»§ÊµÊ±Ñ¡È¡°²È«Íø¹Ø²úÆ·½øÐÐʵʱµÄ¹¥»÷·À»¤Ó뻺½â¡£
|
²úÆ· |
×¢Ã÷ |
|
RG-APT¸ß¼¶Íþв¼ì²âϵͳ |
GA»Æ½ð¼×¸ß¼¶Íþв¼ì²âϵͳ£¨RG-APT£©»ùÓÚ“Îļþ+Á÷Á¿”˫ά¶È·ÖÎö¼Ü¹¹¡£Í¨¹ý¶ÀÓеİ˴óÖ÷ÌâÒýÇæ£¬×ÛºÏÍþвµý±¨¡¢ÐÐΪģÐÍ¡¢»úе½ø½¨¡¢Ðé¹¹»¯É³ÏäºÍ°²È«Ìصã¿âµÈ¼ì²â¼¼Êõ¸²¸Çʽ·¢Ïָ߼¶Î´ÖªÍþв. |
|
RG-WALLϵÁÐÏÂÒ»´ú·À»ðǽ |
ÏÂÒ»´ú·À»ðǽ½áºÏ·À²¡¶¾ÒÔ¼°Íþвµý±¨¼ì²â¡£¼ì²âÖ÷Á÷½©Ä¾È䣬aptÑù±¾¡£ |
|
RG-BDS-TSP |
GA»Æ½ð¼×NFA̽Õëϵͳ£¬½áºÏ×îеÄÍþвµý±¨£¬ÊµÊ±Õç±ðÍøÂçÖд«ÊäÎļþ£¬ÅжÏDZÔÚ²¡¶¾¡£ |
ÍŶӽéÉÜ
GA»Æ½ð¼×ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶӣ¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬Õë¶Ô×îа²È«·ì϶£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤Õ½ÊõÓë½â¾ö¹æ»®¡£
GA»Æ½ð¼×“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö²ûÑï£¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯£¬ÎÕ±ð°²È«¹Âµº£¬×é³ÉÕûÍøÁª¶¯µÄ°²È«±£ÏÕϵͳ£¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì¹Ø»·¡£

?ÈçÄú±ØÒªGA»Æ½ð¼×°²È«£¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½
