¡¾Îó²îͨ¸æ¡¿SonarQubeδÊÚȨ»á¼ûÎó²î£¨CNVD-2021-84502£©

Ðû²¼Ê±¼ä 2021-11-24

0x00 Îó²î¸ÅÊö

2021Äê11ÔÂ5ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¹ú¼ÒÐÅÏ¢Çå¾²Îó²î¹²ÏíÆ½Ì¨£¨CNVD£©ÊÕ¼ÁËSonarQubeϵͳδÊÚȨ»á¼ûÎó²î£¨CNVD-2021-84502£©¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚδÊÚȨµÄÇéÐÎÏ»ñÈ¡Ãô¸Ð´úÂëÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚSonarQube¹«Ë¾ÒѾ­Ðû²¼ÁË´ËÎó²îµÄ²¹¶¡£¡£¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬£¬£¬µ«Îó²îµÄʹÓÃϸ½ÚÒѹûÕæ¡£¡£¡£¡£¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

SonarQubeÊÇÒ»¸ö¿ªÔ´´úÂëÖÊÁ¿ÖÎÀíºÍÆÊÎöÉ󼯯½Ì¨£¬ £¬£¬£¬£¬£¬£¬£¬Ö§³Ö°üÀ¨Java£¬ £¬£¬£¬£¬£¬£¬£¬C#£¬ £¬£¬£¬£¬£¬£¬£¬C/C++£¬ £¬£¬£¬£¬£¬£¬£¬PL/SQL£¬ £¬£¬£¬£¬£¬£¬£¬Cobol£¬ £¬£¬£¬£¬£¬£¬£¬JavaScript£¬ £¬£¬£¬£¬£¬£¬£¬GroovyµÈ¶þÊ®¶àÖÖ±à³ÌÓïÑԵĴúÂëÖÊÁ¿ÖÎÀí£¬ £¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÔÏîÄ¿ÖеÄÖØ¸´´úÂë¡¢³ÌÐò¹ýʧ¡¢±àд¹æ·¶¡¢Çå¾²Îó²îµÈÎÊÌâ¾ÙÐмì²â£¬ £¬£¬£¬£¬£¬£¬£¬²¢½«Ð§¹ûͨ¹ýSonarQube Web½çÃæ¾ÙÐзºÆð¡£¡£¡£¡£¡£¡£¡£¡£

SonarQube ϵͳÔÚĬÈÏÉèÖÃÏ£¬ £¬£¬£¬£¬£¬£¬£¬»á½«Í¨¹ýÉ󼯵ÄÔ´´úÂëÉÏ´«ÖÁSonarQubeƽ̨¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚSonarQubeȱÉÙ¶ÔAPI½Ó¿Ú»á¼ûµÄ¼øÈ¨¿ØÖÆ£¬ £¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎÏÂͨ¹ý»á¼ûÉÏÊöAPI½Ó¿Ú£¬ £¬£¬£¬£¬£¬£¬£¬»ñÈ¡SonarQubeƽ̨ÉϵijÌÐòÔ´´úÂ룬 £¬£¬£¬£¬£¬£¬£¬Ôì³ÉÏîĿԴ´úÂëÊý¾Ýй¶Σº¦¡£¡£¡£¡£¡£¡£¡£¡£

2021Äê10ÔÂÒÔÀ´£¬ £¬£¬£¬£¬£¬£¬£¬¿­·¢k8¼à²âµ½¾³ÍâºÚ¿Í×éÖ¯AgainstTheWest£¨¼ò³Æ¡°ATW¡±£©Õë¶ÔSonarQubeƽ̨¾ÙÐй¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡ÁËÎÒ¹ú¶à¼ÒÕþÆó»ú¹¹µÄÐÅϢϵͳԴ´úÂ룬 £¬£¬£¬£¬£¬£¬£¬²¢ÔÚÍâÑóºÚ¿ÍÂÛ̳RaidForumsÉϾÙÐв»·¨ÊÛÂô¡£¡£¡£¡£¡£¡£¡£¡£

ÔçÔÚ2020Äê4Ô£¬ £¬£¬£¬£¬£¬£¬£¬Áª°îÊÓ²ì¾Ö£¨FBI£©¾Í·¢Ã÷ºÚ¿ÍʹÓÃSonarQube´ÓÃÀ¹ú¸÷¸öÐÐÒµºÍÕþ¸®»ú¹¹ÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

 

Ó°Ïì¹æÄ£

SonarQube < 8.6

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚSonarQube¹«Ë¾ÒѾ­ÐÞ¸´ÁË´ËÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶¸üе½SonarQube 8.6»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£

»º½â²½·¥£º

l  ¸ü¸ÄSonarQube ĬÈÏÉèÖ㬠£¬£¬£¬£¬£¬£¬£¬°üÀ¨¸ü¸ÄĬÈÏÖÎÀíÔ±Óû§Ãû¡¢ÃÜÂëºÍ¶Ë¿Ú(9000)¡£¡£¡£¡£¡£¡£¡£¡£

l  ÉèÖÿªÆôÈÏÖ¤¹¦Ð§£¬ £¬£¬£¬£¬£¬£¬£¬¹¹½¨Ë«ÒòËØÈÏÖ¤£¬ £¬£¬£¬£¬£¬£¬£¬²¢¼ì²éδ¾­ÊÚȨµÄÓû§ÊÇ·ñ»á¼ûÁ˸ÃʵÀý¡£¡£¡£¡£¡£¡£¡£¡£

l  ÈôÊÇ¿ÉÐУ¬ £¬£¬£¬£¬£¬£¬£¬×÷·Ï¶ÔÔÚ SonarQube ʵÀýÖйûÕæµÄÈκÎÓ¦ÓóÌÐò±à³Ì½Ó¿ÚÃÜÔ¿»òÆäËûƾ֤µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£

l  ½«SonarQube ʵÀýÉèÖÃΪ×éÖ¯µÄ·À»ðǽºÍÆäËûÍâΧ·ÀÓùÖ®ºó£¬ £¬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâδ¾­Éí·ÝÑéÖ¤µÄ»á¼û¡£¡£¡£¡£¡£¡£¡£¡£

 

0x03 ²Î¿¼Á´½Ó

https://mp.weixin.qq.com/s/BSnfaLJX7cuIt3ZfuxpKTA

https://mp.weixin.qq.com/s/mcYlZVGnm9Ubty1qWx3sCQ

https://docs.sonarqube.org/latest/setup/get-started-2-minutes/

https://www.bleepingcomputer.com/news/security/fbi-hackers-stole-government-source-code-via-sonarqube-instances/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-11-24

Ê×´ÎÐû²¼

 

0x05 ¹ØÓÚ¿­·¢k8

¿­·¢k8¼ò½é

¿­·¢k8¹«Ë¾½¨ÉèÓÚ1996Ä꣬ £¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉî½»ËùÖÐС°åÕýʽ¹ÒÅÆÉÏÊУ¬ £¬£¬£¬£¬£¬£¬£¬ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·ºÍÇå¾²ÖÎÀíÆ½Ì¨¡¢Ç徲ЧÀÍÓë½â¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°£¬ £¬£¬£¬£¬£¬£¬£¬ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ £¬£¬£¬£¬£¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ£»£»£»£»£» £»£»£»²¢ÔÚ»ª±±¡¢»ª¶«¡¢Î÷ÄϺͻªÄϽṹËÄ´óÑз¢ÖÐÐÄ£¬ £¬£¬£¬£¬£¬£¬£¬»®·ÖΪ±±¾©Ñз¢×ܲ¿¡¢ÉϺ£Ñз¢ÖÐÐÄ¡¢³É¶¼Ñз¢ÖÐÐĺ͹ãÖÝÑз¢ÖÐÐÄ¡£¡£¡£¡£¡£¡£¡£¡£

¶àÄêÀ´£¬ £¬£¬£¬£¬£¬£¬£¬¿­·¢k8ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬ £¬£¬£¬£¬£¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬ £¬£¬£¬£¬£¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£¡£¡£¡£

 

¹ØÓÚ¿­·¢k8

¿­·¢k8Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖ÷ÒªÇå¾²Îó²îµÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÇå¾²±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£

¹Ø×¢ÒÔϹ«Öںţ¬ £¬£¬£¬£¬£¬£¬£¬»ñȡȫÇò×îÐÂÇå¾²×ÊѶ£º

image.png