RedisδÊÚȨ»á¼ûÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚRedis 2.x£¬£¬£¬3.x£¬£¬£¬4.x£¬£¬£¬5.x¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


RedisÊÇÃÀ¹úRedisLabs¹«Ë¾ÔÞÖúµÄÒ»Ì׿ªÔ´µÄʹÓÃANSIC±àд¡¢Ö§³ÖÍøÂç¡¢¿É»ùÓÚÄÚ´æÒà¿É³¤ÆÚ»¯µÄÈÕÖ¾ÐÍ¡¢¼üÖµ£¨Key-Value£©´æ´¢Êý¾Ý¿â£¬£¬£¬²¢Ìṩ¶àÖÖÓïÑÔµÄAPI¡£¡£¡£¡£¡£


RedisÖб£´æÎ´ÊÚȨ»á¼ûÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚÔÚReids 4.x¼°ÒÔÉϰ汾ÖÐÐÂÔöÁËÄ£¿£¿£¿é¹¦Ð§£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÍâ²¿ÍØÕ¹£¬£¬£¬ÔÚ redisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁî¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøù¦Ð§ÒýÈëÄ£¿£¿£¿é£¬£¬£¬Ê¹±»¹¥»÷ЧÀÍÆ÷ÖмÓÔØ¶ñÒâµÄ.soÎļþ£¬£¬£¬´Ó¶øÊµÏÖ¶ñÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£ÈôRedisΪ4.0ÒÔϰ汾£¨2.x£¬£¬£¬3.x£©£¬£¬£¬Í¬Ê±redis-serverÒÔrootȨÏÞÆô¶¯£¬£¬£¬Ôò¹¥»÷Õß¿ÉÔÚЧÀÍÆ÷ÉϽ¨Éèí§ÒâÎļþ¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢Õ¥È¡Íⲿ»á¼ûRedisЧÀÍ¶Ë¿Ú £»£»£»£»£»£»£»
2¡¢Õ¥È¡Ê¹ÓÃrootȨÏÞÆô¶¯redisЧÀÍ £»£»£»£»£»£»£»

3¡¢ÉèÖÃÇå¾²×飬£¬£¬ÏÞÖÆ¿ÉÅþÁ¬RedisЧÀÍÆ÷µÄIP¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://2018.zeronights.ru/wp-content/uploads/materials/15-redis-post-exploitation.pdf