WebLogic T3ºÍ̸·´ÐòÁл¯ 0day ·ì϶

°ä²¼¹¦·ò 2021-04-19

0x00 ·ì϶¸ÅÊö

CVE  ID


ʱ   ¼ä

2021-04-19

Àà   ÐÍ

RCE

µÈ   ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò


PoC/EXP

Òѹ«¿ª

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ·ì϶ÏêÇé

image.png

 

½üÈÕ£¬£¬£¬£¬£¬£¬£¬£¬WebLogic±»Åû¶´æÔÚÒ»¸öT3ºÍ̸·´ÐòÁл¯0 day·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°¸Ã·ì϶´¦ÓÚÔÚÒ°0day״̬£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒPoC/EXPÒÑÔÚGithubÉϹ«¿ª¡£¡£¡£¡£¡£

Ôڸ÷ì϶µÄpocÖУ¬£¬£¬£¬£¬£¬£¬£¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀ࣬£¬£¬£¬£¬£¬£¬£¬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷£¬£¬£¬£¬£¬£¬£¬£¬´ÓÖнâÎö¶ÔÏ󣬣¬£¬£¬£¬£¬£¬£¬Äܹ»Í¨¹ý°ÑobjBytes´úÌæÎªÖ¸¶¨·´ÐòÁл¯¾ÍÄܹ»ÊµÏÖweblogicºÚÃûµ¥Èƹý¡£¡£¡£¡£¡£

image.png

 

0x02 ´ëÖý¨Òé

½¨Ò齫jdkÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬£¬£¬£¬²¢½ûÓÃiiop/t3ºÍ̸ÒÔ×÷Ϊһʱ»º½â´ëÊ©¡£¡£¡£¡£¡£

½ûÓÃT3ºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌå²Ù×÷ÈçÏ£º

1£©½øÈëWebLogic½ÚÔį̀£¬£¬£¬£¬£¬£¬£¬£¬ÔÚbase_domainµÄÅäÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬£¬£¬£¬½øÈë¡°°²È«¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬£¬£¬£¬½øÈëÏνÓɸѡÆ÷ÅäÖᣡ£¡£¡£¡£

2)ÔÚÏνÓɸѡÆ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÏνÓɸѡÆ÷¹æ¶¨ÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sºÍ̸µÄËùÓж˿ÚÖ»ÔÊÐí±¾µØ½Ó¼û)¡£¡£¡£¡£¡£

3£©±£ÁôºóÐè³ÁÐÂÆô¶¯£¬£¬£¬£¬£¬£¬£¬£¬¹æ¶¨·½¿ÉÉúЧ¡£¡£¡£¡£¡£

image.png

 

 

½ûÓÃIIOPºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬¾ßÌå²Ù×÷ÈçÏ£º

µÇ½WebLogic½ÚÔį̀£¬£¬£¬£¬£¬£¬£¬£¬base_domain >·þÎñÆ÷¸ÅÒª >AdminServer

image.png

 

ÏÂÔØÁ´½Ó£º

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9

https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html

 

0x04 ¹¦·òÏß

2021-04-18  ×êÑÐÈËÔ±Åû¶·ì϶

2021-04-19  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png