WebLogic T3ÐÒé·´ÐòÁл¯ 0day Îó²î
Ðû²¼Ê±¼ä 2021-04-190x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-04-19 | |
Àà ÐÍ | RCE | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | |
PoC/EXP | ÒѹûÕæ | ÔÚҰʹÓà | ÊÇ |
0x01 Îó²îÏêÇé

¿ËÈÕ£¬£¬£¬£¬£¬WebLogic±»Åû¶±£´æÒ»¸öT3ÐÒé·´ÐòÁл¯0 dayÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÔì³ÉÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬ÏÖÔÚ¸ÃÎó²î´¦ÓÚÔÚÒ°0day״̬£¬£¬£¬£¬£¬²¢ÇÒPoC/EXPÒÑÔÚGithubÉϹûÕæ¡£¡£¡£¡£¡£¡£¡£
ÔÚ¸ÃÎó²îµÄpocÖУ¬£¬£¬£¬£¬Ê¹ÓÃÁËjava.rmi.MarshalledObjectÀ࣬£¬£¬£¬£¬²¢½«objBytesÊôÐÔ×÷Ϊ·´ÐòÁл¯µÄÁ÷£¬£¬£¬£¬£¬´ÓÖÐÆÊÎö¹¤¾ß£¬£¬£¬£¬£¬¿ÉÒÔͨ¹ý°ÑobjBytesÌæ»»ÎªÖ¸¶¨·´ÐòÁл¯¾Í¿ÉÒÔʵÏÖweblogicºÚÃûµ¥Èƹý¡£¡£¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé
½¨Ò齫jdkÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬²¢½ûÓÃiiop/t3ÐÒéÒÔ×÷ΪÔÝʱ»º½â²½·¥¡£¡£¡£¡£¡£¡£¡£
½ûÓÃT3ÐÒ飬£¬£¬£¬£¬Ïêϸ²Ù×÷ÈçÏ£º
1£©½øÈëWebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬ÔÚbase_domainµÄÉèÖÃÒ³ÃæÖУ¬£¬£¬£¬£¬½øÈë¡°Çå¾²¡±Ñ¡Ïî¿¨Ò³Ãæ£¬£¬£¬£¬£¬µã»÷¡°É¸Ñ¡Æ÷¡±£¬£¬£¬£¬£¬½øÈëÅþÁ¬É¸Ñ¡Æ÷ÉèÖᣡ£¡£¡£¡£¡£¡£
2)ÔÚÅþÁ¬É¸Ñ¡Æ÷ÖÐÊäÈ룺weblogic.security.net.ConnectionFilterImpl£¬£¬£¬£¬£¬ÔÚÅþÁ¬É¸Ñ¡Æ÷¹æÔòÖÐÊäÈ룺127.0.0.1 * * allow t3t3s£¬£¬£¬£¬£¬0.0.0.0/0 * *deny t3 t3s(t3ºÍt3sÐÒéµÄËùÓж˿ÚÖ»ÔÊÐíÍâµØ»á¼û)¡£¡£¡£¡£¡£¡£¡£
3£©ÉúÑĺóÐèÖØÐÂÆô¶¯£¬£¬£¬£¬£¬¹æÔò·½¿ÉÉúЧ¡£¡£¡£¡£¡£¡£¡£

½ûÓÃIIOPÐÒ飬£¬£¬£¬£¬Ïêϸ²Ù×÷ÈçÏ£º
Éϰ¶WebLogic¿ØÖÆÌ¨£¬£¬£¬£¬£¬base_domain >ЧÀÍÆ÷ÌáÒª >AdminServer

ÏÂÔØÁ´½Ó£º
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x03 ²Î¿¼Á´½Ó
https://github.com/hhroot/2021_Hvv/commit/8dcfdd7786ded69f404d52a162a8c4dfcbfd34b9
https://www.oracle.com/cn/java/technologies/javase/javase-jdk8-downloads.html
0x04 ʱ¼äÏß
2021-04-18 Ñо¿Ö°Ô±Åû¶Îó²î
2021-04-19 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ