Citrix | ShareFile¶à¸ö°²È«·ì϶¹«¸æ

°ä²¼¹¦·ò 2020-05-07

0x00 ·ì϶¸ÅÊö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


0x01 ·ì϶ÏêÇé


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Citrix ShareFileÊÇÃÀ¹ú˼½Üϵͳ£¨Citrix Systems£©¹«Ë¾µÄÒ»Ì×Îļþ¹²Ïí½â¾ö¹æ»®¡£¡£¡£¡£¡£ShareFileÊÇÒ»¸ö»ùÓÚÔÆµÄÎļþ¹²Ïí·þÎñ£¬£¬£¬£¬£¬Ê¹Óû§¿ÉÄÜÇáËÉ£¬£¬£¬£¬£¬°²È«µØ»¥»»Îļþ¡£¡£¡£¡£¡£ShareFileÄÜÌṩÆóÒµ¼¶·þÎñ£¬£¬£¬£¬£¬×é¼þÔ̺¬StorageZones½ÚÔìÆ÷ºÍÓû§ÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£

2020Äê5ÔÂ5ÈÕCitrix¹ÙÍø°ä²¼²¼¸æÉêÃ÷£¬£¬£¬£¬£¬Citrix ShareFile´æ´¢ÇøÓò½ÚÔìÆ÷Öз¢ÏÖÁ˶à¸ö°²È«·ì϶£¬£¬£¬£¬£¬Î´¾­ÈÏÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓÃÕâЩ·ì϶À´ÈëÇÖ´æ´¢ÇøÓò½ÚÔìÆ÷£¬£¬£¬£¬£¬²¢½Ó¼ûShareFileÓû§µÄÎĵµºÍÎļþ¼Ó×£¡£¡£¡£¡£

з¢ÏֵݲȫÎÊÌâ (CTX-CVE-2020-7473) Ó°ÏìµÄÊǿͻ§ÖÎÀí±¾µØCitrix ShareFile ´æ´¢Çø½ÚÔìÆ÷£¬£¬£¬£¬£¬¸Ã×é¼þÊÜ·À»ðǽ±£»£»£» £»£»£»£»£»¤£¬£¬£¬£¬£¬´æ´¢ÆóÒµÊý¾Ý¡£¡£¡£¡£¡£ÉÏÊö¶à¸ö°²È«·ì϶Ô̺¬CVE-2020-7473¡¢CVE-2020-8982ºÍCVE-2020-8983¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


0x02 ´ëÖý¨Òé


ÈôÊÇÄãµØµã¹«Ë¾Ê¹ÓõÄÊDZ¾µØShareFile´æ´¢Çø½ÚÔìÆ÷°æ±¾5.9.0/5.8.0/5.7.0/5.6.0/5.5.0¼°¸üÔç°æ±¾£¬£¬£¬£¬£¬ÔòÊÜÓ°Ï죬£¬£¬£¬£¬²¢½¨ÒéÁ¢¼´½«Æ½Ì¨¸üÐÂÖÁ5.10.0/5.9.1/5.8.1»òºóÐø°æ±¾¡£¡£¡£¡£¡£

һʱ´ëÊ©£º

±ØÒª°ÑÎȵijÁÒªÒ»µãÊÇ£ºÈçÄãµÄ´æ´¢ÇøÊÇÔÚÒÔÉÏÊÜÓ°Ïì°æ±¾ÉÏ´´½¨µÄ£¬£¬£¬£¬£¬ÄÇôֻÊǽ«Èí¼þ¸üÐÂÖÁ½¨¸´°æ±¾½«ÎÞ·¨ÆëÈ«½â¾ö·ì϶ÎÊÌâ¡£¡£¡£¡£¡£Îª´Ë£¬£¬£¬£¬£¬CitrixרÃŰ䲼ÁËÒ»¿î»º½â¹¤¾ß£¬£¬£¬£¬£¬Óû§¿ÉÊ×ÏÈÔÚÖ÷´æ´¢Çø½ÚÔìÆ÷ÉÏÔËÐУ¬£¬£¬£¬£¬Ö®ºóÔÚ¶þ¼¶½ÚÔìÆ÷ÉÏÔËÐУ¬£¬£¬£¬£¬¡°Ò»µ©¸Ã¹¤¾ßÔÚÖ÷ÇøÔËÐгɹ¦£¬£¬£¬£¬£¬ÇëÎð»¹Ô­¸ü¸Ä£¬£¬£¬£¬£¬²»È»½«µ¼ÖÂÇøÓò²»³ÉÓᣡ£¡£¡£¡£¡±


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


³ýÁ˱¾µØ½â¾ö¹æ»®±í£¬£¬£¬£¬£¬ShareFile´æ´¢Çø½ÚÔìÆ÷µÄÔÆ°æ±¾Ò²ÊÜÓ°Ï죬£¬£¬£¬£¬µ«Ë¼½ÜÒѽ¨¸´ÕâЩÎÊÌâÇÒÎÞÐèÓû§Ö´ÐÐÈκνøÒ»²½µÄ²Ù×÷¡£¡£¡£¡£¡£

½ØÖÁĿǰ»¹Ã»ÓйØÓÚÕâЩ·ì϶µÄµ×²ã¼¼Êõ·ÖÎö£¬£¬£¬£¬£¬µ«ÊÇÆ¾¾Ý²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬×êÑÐÈËÔ±·ÖÎöÒÔΪÖÁÉÙÓÐÒ»¸ö·ì϶¿ÉÄÜλÓÚCitrix SharefileʹÓõÄÀϰ汾ASP.net ToolkitÖÓ×£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


2015Äê·¢ÏÖµÄCVE-2015-4670·ì϶¾ÍÊÇÒ»¸öAjaxControlToolkitµÄĿ¼±éÀúºÍÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬£¬£¬£¬Ó°Ïì¶ÔÓ¦µÄShareFileÈí¼þ°æ±¾¡£¡£¡£¡£¡£

ΪÁËÈ·¶¨µ±Ç°Citrix ShareFileʵÏÖÊÇ·ñÊܵ½Ó°Ï죬£¬£¬£¬£¬Äܹ»½Ó¼ûÏÂÃæµÄURL£¬£¬£¬£¬£¬ÈôÊÇÒ³Ãæ·µ»ØÎª¿Õ£¬£¬£¬£¬£¬¾Í×¢Ã÷Êܵ½¸Ã·ì϶µÄÓ°Ï죬£¬£¬£¬£¬ÈôÊÇ·µ»ØµÄÊÇ404ÃýÎ󣬣¬£¬£¬£¬¾Í×¢Ã÷²»Êܸ÷ì϶µÄÓ°Ïì»òÒѾ­±»½¨¸´ÁË¡£¡£¡£¡£¡£Á´½ÓΪ£ºhttps://yoursharefileserver.companyname.com/UploadTest.aspx

×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬Citrix°ä²¼µÄ·ì϶»º½â¹¤¾ß»á¶Ôweb.configÎļþ½øÐÐÅú¸Ä£¬£¬£¬£¬£¬Ò²»á´ÓÊÜÓ°ÏìµÄ·þÎñÆ÷ÉÑþ³ØýUploadTest.aspxºÍXmlFeed.aspx¡£¡£¡£¡£¡£


0x03 ÓйØÐÂÎÅ


https://thehackernews.com/2020/05/citrix-sharefile-vulnerability.html


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX269106


0x05 ¹¦·òÏß


2020-05-05  Citrix°ä²¼²¼¸æ

2020-05-07  VSRC°ä²¼·ì϶¹«¸æ



8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website