stake¹ÙÍø

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹âÑо¿±¨¸æ¡·£¬£¬£¬£¬£¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¬Ã¦ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨Ðû²¼
Ô¤Ô¼Ö±²¥
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

Îó²îÓ¦¼±|Oracle Weblogic ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2021-2109£©

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾ Ðû²¼Ê±¼ä£º2021-01-25
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

¿ËÈÕ£¬£¬£¬£¬£¬stake¹ÙÍøÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶӹØ×¢µ½Oracle¹Ù·½Ðû²¼ÁË2021Äê1ÔÂÒªº¦²¹¶¡¸üÐÂͨ¸æ£¬£¬£¬£¬£¬¸Ã²¹¶¡ÖÐÐÞ²¹Á˰üÀ¨ CVE-2021-2109 Weblogic ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÄڵĶà¸ö¸ßΣÑÏÖØÎó²î¡£¡£¡£ ¡£¡£¡£ÔÚCVE-2021-2109Îó²îÖУ¬£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬Ôì³ÉJNDI×¢Èë¡¢Ö´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬´Ó¶ø¿ØÖÆ·þÎñÆ÷¡£¡£¡£ ¡£¡£¡£

 

Õë¶ÔÒÔÉÏÎó²î£¬£¬£¬£¬£¬stake¹ÙÍøÇå¾²Äܹ»¾ÙÐÐÎó²îɨÃèÓë¼ì²â£¬£¬£¬£¬£¬²¢×öÇå¾²·À»¤¡£¡£¡£ ¡£¡£¡£

 

Îó²î¸´ÏÖ

 

  • ÇéÐΣºWebLogic10.3.6.0.0

  • »á¼û¿ØÖÆÌ¨½çÃæ»á¼û

    http://192.168.102:49163/console¼´¿É¿´µ½Ò³Ãæ

     

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

  • µÇ¼֮ºó½øÈ룺

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

  • Æô¶¯LDAP:

     

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

  • POC¾ç±¾:

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

  • Æô¶¯POC£¬£¬£¬£¬£¬²¢·¢ËÍ£º

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

ÊÜÓ°Ïìϵͳ

 

Oracle WebLogic Server 14.1.1.0.0
Oracle WebLogic Server 12.2.1.4.0
Oracle WebLogic Server 12.2.1.3.0
Oracle WebLogic Server 12.1.3.0.0
Oracle WebLogic Server 10.3.6.0.0

 

¹Ù·½²¹¶¡

 

OracleÒѾ­Îª´ËÐû²¼ÁËÒ»¸öÇ徲ͨ¸æ£¨2021-01-19£©ÒÔ¼°ÏìÓ¦²¹¶¡:
2021-01-19£ºOracle Critical Patch Update Advisory -January 2021

Á´½Ó£ºhttps://www.oracle.com/security-alerts/cpujan2021.html

 

stake¹ÙÍøÍøÂçÇå¾²ÆÀ¹ÀÓë¼ì²â¡¢·À»¤²úÆ·

 

²úÆ·

˵Ã÷

RG-WALLϵÁÐÏÂÒ»´ú

·À»ðǽ

 

ÏÂÒ»´ú·À»ðǽÍŽá·À²¡¶¾ÒÔ¼°ÍþвÇ鱨¼ì²â¡£¡£¡£ ¡£¡£¡£ÔÚÇå¾²ÄÜÁ¦ÉÏ£¬£¬£¬£¬£¬²»µ«Ö§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ¹Å°åÇå¾²¹¦Ð§£¬£¬£¬£¬£¬Ò²Ö§³Ö¸»ºñµÄÓ¦Óü¶Çå¾²¹¦Ð§£¬£¬£¬£¬£¬°üÀ¨²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵ȡ£¡£¡£ ¡£¡£¡£Ìṩ¶àά¶ÈµÄÓ¦Óòã¼à¿ØÓëÆÊÎö£¬£¬£¬£¬£¬×ÊÖúÓû§ÕÆÎÕΣº¦£¬£¬£¬£¬£¬¾«×¼Ô¤¾¯¡£¡£¡£ ¡£¡£¡£

RG-IDPϵÁÐÈëÇÖ¼ì²â

·ÀÓùϵͳ

stake¹ÙÍøÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢Çå¾²·À»¤¡¢ÉÏÍøÐÐΪ¹ÜÀíµÈÊÖÒÕÍŽáµÄÈëÇÖ¼ì²â·ÀÓùϵͳװ±¸¡£¡£¡£ ¡£¡£¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ¾ÙÐÐ׼ȷµÄÆÊÎöÅжϣ¬£¬£¬£¬£¬×Ô¶¯ÓÐÓõı£»£»£»£»£»¤ÍøÂçÇå¾²¡£¡£¡£ ¡£¡£¡£ÅäºÏʵʱ¸üеÄÈëÇÖ¹¥»÷ÌØÕ÷¿â£¬£¬£¬£¬£¬¿É¼ì²â·À»¤3500ÖÖÒÔÉϵÄÍøÂç¹¥»÷ÐÐΪ£¬£¬£¬£¬£¬°üÀ¨DoS/DDoS¡¢²¡¶¾¡¢È䳿¡¢½©Ê¬ÍøÂ硢ľÂí¡¢¿ÉÒÉ´úÂ롢̽²âÓëɨÃèµÈÖÖÖÖÍøÂçÍþв¡£¡£¡£ ¡£¡£¡£

RG-ScanϵÁÐÎó²îÆÀ¹Àϵͳ

RG-Scanͨ¹ý¶ÔϵͳÎó²î¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢ÈëÎó²îÒÔ¼°¿çÕ¾¾ç±¾µÈ¹¥»÷ÊֶζàÄêµÄÑо¿»ýÀÛ£¬£¬£¬£¬£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢Ã÷¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈÊÖÒÕ£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýÖÇÄܱéÀú¹æÔò¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄÊֶΣ¬£¬£¬£¬£¬ÉîÈë׼ȷµÄ¼ì²â³öϵͳºÍÍøÕ¾Öб£´æµÄÎó²îºÍÈõµã¡£¡£¡£ ¡£¡£¡£

RG-WG  WEBGuardÓ¦Óñ£»£»£»£»£»¤ÏµÍ³

stake¹ÙÍøRG-WG WebGuardÓ¦Óñ£»£»£»£»£»¤ÏµÍ³£¬£¬£¬£¬£¬Í¨¹ý¶ÔÊÕÖ§Web·þÎñÆ÷µÄHTTP/HTTPSÁ÷Á¿Ïà¹ØÄÚÈݵÄʵʱÆÊÎö¼ì²â¡¢¹ýÂË£¬£¬£¬£¬£¬À´×¼È·Åжϲ¢×èÖ¹ÖÖÖÖWebÓ¦ÓÃÈëÇÖÐÐΪ£¬£¬£¬£¬£¬×è¶Ï¶ÔWeb·þÎñÆ÷µÄ¶ñÒâ»á¼ûÓë²»·¨²Ù×÷¡£¡£¡£ ¡£¡£¡£

 

ÆäÖУ¬£¬£¬£¬£¬WEBGuardÓ¦Óñ£»£»£»£»£»¤ÏµÍ³ÉèÖÃÕ½ÂÔ£º

°ì·¨1£ºµÇ¼WG WEB¹ÜÀí½çÃæ

°ì·¨2£ºÔÚ“»á¼û¿ØÖÆ-URLºÚÃûµ¥”Ìí¼ÓÈçÏÂÕ½ÂÔ

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

 

Ô´IP

0.0.0.0

WebÖ÷»ú

¿Õ

URL

/console/consolejndi.portal

 

°ì·¨3£º¼ì²éÉèÖÃЧ¹û

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

Çå¾²½¨Òé

 

 

1.  ½ûÓÃT3ЭÒ飺

 

ÈôÊÇÄú²»ÒÀÀµT3ЭÒé¾ÙÐÐJVMͨѶ£¬£¬£¬£¬£¬¿Éͨ¹ýÔÝʱ×è¶ÏT3ЭÒ黺½â´ËÎó²î´øÀ´µÄÓ°Ïì

 

  • ½øÈëWeblogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë“Çå¾²”Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷“ɸѡÆ÷”£¬£¬£¬£¬£¬ÉèÖÃɸѡÆ÷¡£¡£¡£ ¡£¡£¡£

     

  • ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔò¿òÖÐÊäÈ룺* * 7001 deny t3 t3s¡£¡£¡£ ¡£¡£¡£

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

 

2.  Õ¥È¡ÆôÓÃIIOP£º

 

Éϰ¶Weblogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÕÒµ½ÆôÓÃIIOPÑ¡Ï£¬£¬£¬£¬×÷·Ï¹´Ñ¡£¡£¡£ ¡£¡£¡£¬£¬£¬£¬£¬ÖØÆôÉúЧ¡£¡£¡£ ¡£¡£¡£

 

 

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

3.  ÔÝʱ¹Ø±Õºǫ́/console/console.portal¶ÔÍâ»á¼û

 

ÍŶÓÏÈÈÝ

 

stake¹ÙÍøÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶӣ¬£¬£¬£¬£¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬£¬£¬£¬£¬Õë¶Ô×îÐÂÇå¾²Îó²î£¬£¬£¬£¬£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ÙºÍÆÊÎö;Ϊ²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐÓõÄÇå¾²·À»¤Õ½ÂÔÓë½â¾ö¼Æ»®¡£¡£¡£ ¡£¡£¡£

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

stake¹ÙÍø“ÍøÂç+Çå¾²”Ö÷ÕŽ«ÍøÂç×°±¸µÄÇå¾²ÄÜÁ¦³ä·ÖÑéÕ¹£¬£¬£¬£¬£¬ÍøÂç×°±¸¡¢Çå¾²×°±¸ÓëÇ徲ƽ̨ÖÇÄÜÁª¶¯£¬£¬£¬£¬£¬Àë±ðÇå¾²¹Âµº£¬£¬£¬£¬£¬×é³ÉÕûÍøÁª¶¯µÄÇå¾²°ü¹Üϵͳ£¬£¬£¬£¬£¬ÊµÏÖ·À»¤¡¢Çå¾²Õ¹Íû¡¢ÆÊÎöºÍÏìÓ¦µÈÇå¾²ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£¡£¡£ ¡£¡£¡£

 

Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

 

ÈçÄúÐèÒªstake¹ÙÍøÇå¾²£¬£¬£¬£¬£¬ÇëÁôÏÂÄúµÄÁªÏµ·½·¨

 

¹Ø×¢stake¹ÙÍø
¹Ø×¢stake¹ÙÍø¹ÙÍøÎ¢ÐÅ
ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾ ÎĵµAIÖúÊÖ
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿£¿£¿£¿£¿£¿ £¿£¿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù£¿£¿£¿£¿£¿£¿ £¿£¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£¡£¡£ ¡£¡£¡£©£¿£¿£¿£¿£¿£¿ £¿£¿
Äú¶ÔÎĵµÊÇ·ñÉÐÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿£¿£¿£¿£¿£¿ £¿£¿
Ϊ¾¡¿ì½â¾öÎÊÌ⣬£¬£¬£¬£¬ÇëÄúÁôÏÂÁªÏµ·½·¨Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´Ï죡£¡£ ¡£¡£¡£¡
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾
Stake(ÖйúÇø)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼