½ð²Ê»ã

µã»÷ÏÂÔØ¡¶ÍòÕ×Ô°ÇøÒÔÌ«²Ê¹â×êÑл㱨¡· £¬½âËøÍòÕ×Ô°ÇøÍøÂ罨ÉèÖ¸ÄÏ
Á¢¼´ÏÂÔØ
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
½ð²Ê»ã - Ê×Ò³
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
½ð²Ê»ã - Ê×Ò³

΢Èí Exchange·þÎñÆ÷¶à¸ö¸ßΣ·ì϶¹«¸æ

½ð²Ê»ã - Ê×Ò³ °ä²¼¹¦·ò£º2021-03-04
½ð²Ê»ã - Ê×Ò³

2021Äê3ÔÂ3ÈÕ £¬½ð²Ê»ãÍøÂ簲ȫӦ¼±ÍŶÓ×·×Ùµ½Î¢ÈíÓÚ2021Äê3ÔÂ2ÈÕ Õë¶ÔExchange·þÎñÆ÷°ä²¼Á˶à¸ö¸ßΣ·ì϶µÄ·çÏÕ¹«¸æ £¬·ì϶±àºÅΪCVE-2021-26855,CVE-2021-26857,CVE-2021-26858,CVE-2021-27065 £¬ÔÚCVSSÖжÔÕâЩ·ì϶¸ø³öÁ˱ÈÁ¦¸ßµÄÆÀ·Ö¡£ÍþвÐж¯ÕßÀûÓÃÕâЩ·ì϶½Ó¼û±¾µØExchange·þÎñÆ÷ £¬´Ó¶øÄܹ»½Ó¼ûµç×ÓÓʼþÕÊ»§ £¬²¢ÔÊÐí×°ÖÃÆäËû¶ñÒâÈí¼þÒÔÍÆ½ø¶ÔÊܺ¦Õß»·¾³µÄ³Ö¾Ã½Ó¼û¡£


¶Ô´Ë £¬½ð²Ê»ãÍøÂ簲ȫӦ¼±ÍŶӽ¨Òé¿í´óÓû§ÊµÊ±½«ExchangeÉý¼¶µ½×îа汾¡£Óë´Ëͬʱ £¬Çë×öºÃ×ʲú×Ô²éÒÔ¼°Ô¤·À¹¤×÷ £¬ÒÔÃâÔâ·êºÚ¿Í¹¥»÷¡£

 


Ó°Ïì°æ±¾

Exchange server£º2010/2013/2016/2019
Exchange online£º²»ÊÜÓ°Ïì¡£


·ì϶ÏêÇé

 

1.    CVE-2021-26855: ·þÎñ¶ËÒªÇóαÔì·ì϶

Exchange ·þÎñÆ÷¶ËÒªÇóαÔ죨SSRF£©·ì϶ £¬ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÄÜ·¢ËÍËÁÒâ HTTP ÒªÇó²¢Í¨¹ý Exchange Server ½øÐÐÉí·ÝÑéÖ¤¡£


2.   CVE-2021-26857: ÐòÁл¯·ì϶

Exchange ·´ÐòÁл¯·ì϶ £¬¸Ã·ì϶±ØÒªÖÎÀíԱȨÏÞ £¬ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»ÔÚ Exchange ·þÎñÆ÷ÉÏÒÔ SYSTEM Éí·ÝÔËÐдúÂë¡£


3.   CVE-2021-26858: ËÁÒâÎļþдÈë·ì϶

Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó £¬Äܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκÎõè¾¶¡£¸Ã·ì϶Äܹ» ¹²Í¬ CVE-2021-26855 SSRF ·ì϶½øÐÐ×éºÏ¹¥»÷¡£


4.   CVE-2021-27065: ËÁÒâÎļþдÈë·ì϶

Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄËÁÒâÎļþдÈë·ì϶¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó £¬Äܹ»ÀûÓô˷ì϶½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκÎõè¾¶¡£¸Ã·ì϶Äܹ» ¹²Í¬ CVE-2021-26855 SSRF ·ì϶½øÐÐ×éºÏ¹¥»÷¡£


°²È«½¨Òé

΢ÈíÒѰ䲼Óйذ²È«¸üР£¬Óû§¿É¸ú½øÒÔÏÂÁ´½Ó½øÐÐÉý¼¶:


CVE-2021-26855: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26855

CVE-2021-26857: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26857
CVE-2021-26858: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26858
CVE-2021-27065: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-27065


¹¥»÷¼ì²â½¨Òé

 

01 CVE-2021-26855

Äܹ»Í¨¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾½øÐмì²â£º


%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy

Äܹ»Í¨¹ýÔÚÈÕÖ¾Ìõ¿îÖÐËÑË÷AuthenticatedUserÊÇ·ñΪ¿Õ²¢ÇÒAnchorMailboxÊÇ·ñÔ̺¬ServerInfo?* / *ģʽ¼ø±ð·ì϶ÀûÓá£ÒÔÏÂPowershell¿ÉÖ±½Ó½øÐÐÈÕÖ¾¼ì²â £¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷£º


Import-Csv-Path(Get-ChildItem-Recurse-Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy”- Filter ‘*.log’).FullName | Where-Object {  $_.AuthenticatedUser -eq ” -and $_.AnchorMailbox -like ‘ServerInfo~*/*’ } | select DateTime, AnchorMailbox

ÈôÊǼì²âµ½ÁËÈëÇÖ £¬Äܹ»Í¨¹ý¼ì²âAnchorMailboxõè¾¶ÖÐÖ¸¶¨Ìض¨ÀûÓ÷¨Ê½µÄÈÕÖ¾À´»ñÈ¡¹¥»÷Õß²ÉÈ¡ÁËÄÄЩ»î¶¯£º


%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging

 

02 CVE-2021-26858

ͨ¹ýExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-26858ÀûÓãº


ÈÕ־Ŀ¼£º
C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog


¿Éͨ¹ýÒÔϺÅÁî½øÐм±¾çä¯ÀÀ £¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷£º


findstr /snip /c:”Download failed and temporary file” “%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log”


03 CVE-2021-26857

ͨ¹ýWindowsÀûÓ÷¨Ê½ÊÂÎñÈÕÖ¾¼ì²âCVE-2021-26857ÀûÓà £¬ÀûÓô˷´ÐòÁл¯ÃýÎ󽫴´½¨ÓµÓÐÒÔÏÂÊôÐÔµÄÀûÓ÷¨Ê½ÊÂÎñ£º


ÆðÔ´£ºMSExchangeͳһÐÂÎÅ
EntryType£ºÃýÎó
ÊÂÎñÐÂÎÅÔ̺¬£ºSystem.InvalidCastExceptio


¸Ã·ì϶µ¥¶ÀÀûÓÃÄѶÈÉÔ¸ß £¬¿ÉÀûÓÃÒÔϺÅÁîÔÚÀûÓ÷¨Ê½ÊÂÎñÈÕÖ¾ÖвéÎÊÕâЩÈÕÖ¾Ìõ¿î £¬²¢²é³­ÊÇ·ñÊܵ½¹¥»÷¡£


Get-EventLog -LogName Application -Source “MSExchange Unified Messaging” -EntryType Error | Where-Object { $_.Message -like “*System.InvalidCastException*” }


04 CVE-2021-27065

ͨ¹ýÒÔÏÂExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-27065ÀûÓà £¬


C£º\ Program Files \ Microsoft \ Exchange Server \ V15 \ Logging \ ECP \ Server

ËùÓÐSet- <AppName> VirtualDirectoryÊôÐÔ¶¼²»Ó¦Ô̺¬¾ç±¾¡£InternalUrlºÍExternalUrlÓ¦¸Ã½öÊÇÓÐЧUris¡£


ͨ¹ýpowershellºÅÁî½øÐÐÈÕÖ¾¼ì²â £¬²¢²é³­ÊÇ·ñÔâµ½¹¥»÷:


Select-String -Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log” -Pattern ‘Set-.+VirtualDirectory’


°²È«·À»¤»º½â

¹¥»÷ÕßÀûÓÃÉÏÊö·ì϶Äܹ»½øÐÐwebshell¡¢¶ñÒâÎļþÉÏ´«ÒÔ¼°¶ñÒâÍøÂçͨѶÐÐΪ¡£Îª»º½â¹¥»÷ÕßÀûÓÃÕâЩ·ì϶½øÐкóÐøµÄ¹¥»÷Ðж¯ £¬½¨Òé¿Í»§ÊµÊ±Ñ¡È¡°²È«Íø¹Ø²úÆ·½øÐÐʵʱµÄ¹¥»÷·À»¤Ó뻺½â¡£

 

 

²úÆ·

×¢Ã÷

RG-APT¸ß¼¶Íþв¼ì²âϵͳ

½ð²Ê»ã¸ß¼¶Íþв¼ì²âϵͳ£¨RG-APT£©»ùÓÚ“Îļþ+Á÷Á¿”˫ά¶È·ÖÎö¼Ü¹¹¡£Í¨¹ý¶ÀÓеİ˴óÖ÷ÌâÒýÇæ £¬×ÛºÏÍþвµý±¨¡¢ÐÐΪģÐÍ¡¢»úе½ø½¨¡¢Ðé¹¹»¯É³ÏäºÍ°²È«Ìصã¿âµÈ¼ì²â¼¼Êõ¸²¸Çʽ·¢Ïָ߼¶Î´ÖªÍþв.

RG-WALLϵÁÐÏÂÒ»´ú·À»ðǽ

ÏÂÒ»´ú·À»ðǽ½áºÏ·À²¡¶¾ÒÔ¼°Íþвµý±¨¼ì²â¡£¼ì²âÖ÷Á÷½©Ä¾Èä £¬aptÑù±¾¡£

RG-BDS-TSP

½ð²Ê»ãNFA̽Õëϵͳ £¬½áºÏ×îеÄÍþвµý±¨ £¬ÊµÊ±Õç±ðÍøÂçÖд«ÊäÎļþ £¬ÅжÏDZÔÚ²¡¶¾¡£

 

ÍŶӽéÉÜ

 

½ð²Ê»ãÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶÓ £¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ £¬Õë¶Ô×îа²È«·ì϶ £¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤Õ½ÊõÓë½â¾ö¹æ»®¡£

 

½ð²Ê»ã“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö²ûÑï £¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯ £¬ÎÕ±ð°²È«¹Âµº £¬×é³ÉÕûÍøÁª¶¯µÄ°²È«±£ÏÕϵͳ £¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì¹Ø»·¡£

 

½ð²Ê»ã - Ê×Ò³
?ÈçÄú±ØÒª½ð²Ê»ã°²È« £¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½

¹Ø×¢½ð²Ê»ã
gfwx_logo
¹Ø×¢½ð²Ê»ã¹ÙÍøÎ¢ÐÅ
ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
½ð²Ê»ã - Ê×Ò³

·µ»Ø¶¥²¿

ÊÕÆð
½ð²Ê»ã - Ê×Ò³ ÎĵµAI¸±ÊÖ
½ð²Ê»ã - Ê×Ò³ ÎĵµÆÀ¼Û
ev-close ev-close-m
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close ev-close-m
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close ev-close-m
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
Äú¶ÔÎĵµÊÇ·ñ»¹ÓÐÆäËüµÄÎÊÌâ»ò½¨Ò飿
Ϊ¾¡¿ì½â¾öÎÊÌâ £¬ÇëÄúÁôÏÂÁªÏµ·½Ê½Òﱋȯ¸´
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
½ð²Ê»ã - Ê×Ò³
½ð²Ê»ã - Ê×Ò³
½ð²Ê»ã - Ê×Ò³
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿