΢ÈíIE 0DAY XXE·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


IE 11£¬£¬£¬£¬£¬Ó°Ïì Windows 7¡¢10ºÍ Server 2012 R2 °æ±¾


·ì϶¸ÅÊö


×êÑÐÈËÔ±John Page¹«¿ªÁËÒ»¸ö¿Éµ¼ÖºڿʹÓWindowsϵͳÖÐÇÔÈ¡ÎļþµÄ IE ä¯ÀÀÆ÷ 0day ·ì϶µÄÏêÇéºÍ PoC ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶Ϊ´æÔÚÓÚ IE 11 ÖеÄXXE±í²¿ÊµÌå×¢Èë·ì϶£¬£¬£¬£¬£¬´æÔÚÓÚ IE ´¦Öà MHT ÎļþµÄ·½Ê½ÖУ¬£¬£¬£¬£¬Ó°Ïì Windows 7¡¢10ºÍ Server 2012 R2 °æ±¾¡£¡£¡£¡£¡£¡£¡£¡£


MHT¼´¡°MHTML Web Archive¡±£¬£¬£¬£¬£¬ÊÇËùÓÐ IE ä¯ÀÀÆ÷ά³ÖÍøÒ³£¨µã»÷ CTRL+S£©µÄĬÈϳ߶È¡£¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»ÏÖ´úä¯ÀÀÆ÷²»ÔÙÒÔ MHT Ìåʽ±£ÁôÍøÒ³£¬£¬£¬£¬£¬¶øÊÇʹÓÃ³ß¶ÈµÄ HTML ÎļþÌåʽ£¬£¬£¬£¬£¬È»¶øºÃ¶àÏÖ´úä¯ÀÀÆ÷ÒÀȻ֧³Ö´¦ÖøÃÌåʽ¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


Page °µÊ¾£¬£¬£¬£¬£¬IEä¯ÀÀÆ÷Ò×ÊÜXML±í²¿ÊµÌå¹¥»÷£¬£¬£¬£¬£¬Ç°ÌáÊÇÓû§ÔÚ±¾µØ´ò¿ªÒ»¸öÌØÊâ»ú¹ØµÄ .MHT Îļþ¡£¡£¡£¡£¡£¡£¡£¡£

Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÇÔÈ¡±¾µØÎļþ²¢Ô¶³Ì¿úËű¾µØ×°Öõķ¨Ê½°æ±¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬¡±c:\python27\NEWS.txt¡±µÄÒªÇó¿É½Ó¼û¸Ã·¨Ê½µÄ°æ±¾ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


±¾µØ´ò¿ª¶ñÒâ¡°.MHT¡±Îļþºó£¬£¬£¬£¬£¬ËüÓ¦¸Ã»áÆô¶¯ IE ä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬£¬£¬£¬Óû§½»»¥Èç³Á¸´Ñ¡Ï¡°Ctrl+K¡±¡£¡£¡£¡£¡£¡£¡£¡£ÆäËü½»»¥ÈçÓÒ»÷ÍøÒ³Éϵġ°´òÓ¡Ô¤ÀÀ¡±»ò¡°´òÓ¡¡±ºÅÁî¿ÉÄܻᴥ·¢Õâ¸öXXE ·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


È»¶ø¶Ôwindow.print()£¬£¬£¬£¬£¬Javascript º¯ÊýµÄµ¥Ò»Å²ÓÿÉÔÚÎÞÐèÓû§ºÍÍøÒ³½»»¥µÄÇé¿öÏÂÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£¡£³ÁÒªµÄÊÇ£¬£¬£¬£¬£¬ÈôÊÇÎļþÊÇ´ÓÍøÂçÒÔѹËõÎĵµµÄ´ó¾ÖÏÂÔØ²¢Ê¹ÓÃijÖִ浵ʹÓ÷¨Ê½ MOTW ´ò¿ªµÄ£¬£¬£¬£¬£¬ÄÇô¿ÉÄܾͲ»»áÆð×÷Óᣡ£¡£¡£¡£¡£¡£¡£


ͨ³£ÔÚÊ·ý»¯ActiveX Objects Èç¡°Microsoft.XMLHTTP¡±Ê±£¬£¬£¬£¬£¬Óû§½«»áÔÚ IE Öп´µ½°²È«À¸ÖҸ沢±»ÌáÐѼ¤»î±»×èÖ¹µÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬µ±´ò¿ªÊ¹ÓöñÒâ<xml>ÏóÕ÷´ò¿ªÌØÊâ»ú¹ØµÄ .MHT Îļþʱ£¬£¬£¬£¬£¬Óû§½«ÎÞ·¨»ñµÃ´ËÀà»î¶¯ÄÚÈÝ»ò°²È«À¸ÖҸ档¡£¡£¡£¡£¡£¡£¡£


ÀýÈ磺

C:\sec>python -m SimpleHTTPServer
Serving HTTP on 0.0.0.0 port 8000 ...
127.0.0.1 - - [10/Apr/2019 20:56:28] "GET /datatears.xml HTTP/1.1" 200 -
127.0.0.1 - - [10/Apr/2019 20:56:28] "GET /?;%20for%2016-bit%20app%20support[386Enh]woafont=dosapp.fonEGA80WOA.FON=EGA80WOA.FONEGA40WOA.FON=EGA40WOA.FONCGA80WOA.FON=CGA80WOA.FONCGA40WOA.FON=CGA40WOA.FON[drivers]wave=mmdrv.dlltimer=timer.drv[mci] HTTP/1.1" 200 -
PageÔÚ×°ÖÃÆëÈ«²¹¶¡µÄWin7/10 ºÍServer 2012 R2ÉϵÄ×îа汾IE ä¯ÀÀÆ÷°æ±¾V11²âÊԳɹ¦¡£¡£¡£¡£¡£¡£¡£¡£
POC£ºhttp://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt¡£¡£¡£¡£¡£¡£¡£¡£
POCÊÓÆµ£ºhttps://youtu.be/fbLNbCjgJeY¡£¡£¡£¡£¡£¡£¡£¡£
´ËPoC´úÂëΪÇÔÈ¡ Windows ¡°system.ini¡±ÎļþµÄ£¨×¢£º¿Éƾ¾Ý±ØÒª±à×ë¾ç±¾ÖеĹ¥»÷Õß·þÎñÆ÷ IP£©
£¨1£©Ê¹Óþ籾´´½¨¡°datatears.xml¡± XML ºÍǶÈë XXE µÄ¡°msie-xxe-0day.mht¡± MHT Îļþ
£¨2£©Python ¨Cm SimpleHTTPServer
£¨3£©½«ÌìÉúµÄ¡°datatears.xml¡±·ÅÔÚ Python ·þÎñÆ÷ web-root ÖС£¡£¡£¡£¡£¡£¡£¡£

£¨4£©´ò¿ªÌìÉúµÄ¡°msie-xxe-0day.mht¡±Îļþ£¬£¬£¬£¬£¬¹Û²ìÎļþ½«±»ÇÔÈ¡¡£¡£¡£¡£¡£¡£¡£¡£


½¨¸´½¨Òé


Ŀǰ΢ÈíûÓа䲼²¹¶¡¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/internet-explorer-zero-day-lets-hackers-steal-files-from-windows-pcs/
http://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt