éžæåºæºïŒ
ä»åèæ ®ãããè匱æ§ã®éžæåºæºã¯åãã§ããïŒä»åã¯ä»ã®ã¿ã€ãã®è匱æ§ãèŠããã£ãããšãé€ããŠïŒïŒ
- ãšã¯ã¹ããã€ããããã¯ãã§ã-ã¢ããããŒãã®åã«ããã¹ãŠãã²ã©ã
æªçšããããã®åŸããããè¯ããªã£ãããšã確èªããããšæããŸãã - è匱æ§ã¯éèŠïŒçæ³çã«ã¯RCEïŒã§ãããé«åŸç¹ã§ããå¿ èŠããããŸãã
- 補åã¯ãªãŒãã³ãœãŒã¹ã§ãªããã°ãªããŸããã
- 補åãæŸæ£ããŠç©æ¥µçã«äœ¿çšããªãã§ãã ããã
- è匱æ§ã¯æ¯èŒçæ°ããã¯ãã§ãã
- ãã€ãã®ããã«ãäž»ãªããšã¯ç§ãã¡èªèº«ãèå³ãæã£ãŠãããšããããšã§ãã
ç§ãéžãã ãã®ãšæ¹æ³ïŒ
ç§ã¯vulners.comã«ã¢ã¯ã»ã¹ããéå»æ°é±éã§ãã¹ãŠã®ãšã¯ã¹ããã€ããexploit-db.comã§è¡šç€ºããããã«é Œã¿ãŸããã ä»åã®Webã«ããŽãªã§ã¯ãã»ãšãã©ãã¹ãŠã®ãšã¯ã¹ããã€ãã¯Ihsan Sencanã«ãã£ãŠäœæãããŸãããããµããŒããããŠããªãå€ãã¢ããªã±ãŒã·ã§ã³ããã³ãã©ã°ã€ã³ã§ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã«æãé »ç¹ã«é¢é£ãããããããããåé€ããŸããã æ®ãã®è£œåã®ãã¡ãè匱æ§CVE-2018-18924ã®ããProjeQtOrãããžã§ã¯ã管çããŒã«7.2.5ã®ã¿ããæŸæ£ããããç©æ¥µçã«éçºãããŠãããã«ããŽãªã«åé¡ãããŸããã
ãã®è匱æ§ã¯ããã¹ãŠã®éžæåºæºãæºãããŸããã
- ãšã¯ã¹ããã€ãããããŸãã
- RCEã®è匱æ§ïŒãŠãŒã¶ãŒã®æ¿èªãå¿ èŠã§ããïŒ;
- 補åã¯éåžžã«ãªãŒãã³ãœãŒã¹ã§ãã
- 補åã¯æŸæ£ãããã2018幎ã«ã¯28ã®ãªãªãŒã¹ããããsourceforge.netã«ã¯702ã®ããŠã³ããŒããããããŸããã§ããïŒãããŠãã»ãšãã©ã®æŽæ°ããŠã³ããŒãã¯CVEã®åé¡ã解決ããŸãã
- CVEã¯11æ4æ¥ããšã¯ã¹ããã€ãã¯10æ25æ¥ãããã¯æ°èŠæ§ã®èŠä»¶ãæºãããŠããŸãã
- ç§ã¯åé¡ãšãã®è§£æ±ºçãèŠãŠããããç§ã«ãšã£ãŠèå³æ·±ããã®ã«ãªããŸããïŒããã«ã€ããŠã¯åŸã§è©³ãã説æããŸãïŒã
ProjeQtOrãããžã§ã¯ã管çããŒã«ã«ã€ããŠ
ãšã¯ã¹ããã€ãã®èª¬æãšnist.govã®CVEã®èª¬æãèªããšãããŒãžã§ã³7.2.5ã¯èš±å¯ããããŠãŒã¶ãŒã«å¯ŸããŠã®ã¿è匱ã§ããããšãããããŸãã ãŸãã.shtmlãã¡ã€ã«ãç»åãšããŠã¢ããããŒãã§ããŸããã ããã®ãã¡ã€ã«ã¯æå¹ãªç»åã§ã¯ãããŸããããšãããšã©ãŒã¡ãã»ãŒãžã衚瀺ãããŸããããã¡ã€ã«ã¯åŒãç¶ããµãŒããŒäžã®ç»åã«ä¿åããã ãã¹ã/ãã¡ã€ã«/ã®çŽæ¥ãªã³ã¯ããã¢ã¯ã»ã¹ã§ããŸãimages / image_name ã
çŽæ¥ãªã³ã¯ãä»ããã¢ã¯ã»ã·ããªãã£ãŒã¯è¯å¥œã§ãããããã§ã¯ããã¡ã€ã«ã®ããŠã³ããŒãã«äœ¿çšããååãæšæž¬ããå¿ èŠããããŸãã 幞éã§ãããã©ã³ãã ã§ã¯ãããŸããããçŸåšã®æå»ãã幎ãæãæ¥ãæéãåãç§ã®åœ¢åŒã§çæãããŸãã çµæã¯ã20181114140320ã®ãããªæ°åã«ãªããŸãããã®åŸããŠãŒã¶ãŒIDã«ç¶ããŠå ã®ãã¡ã€ã«åã«äžç·ãä»ããŸãã ããªãå€ãã®æªç¥æ°ããããŸãïŒ
- ãµãŒããŒã®ã¿ã€ã ãŸãŒã³
- ãµãŒããŒã®ã¯ããã¯ãããŠã³ããŠããå Žå;
- ãŠãŒã¶ãŒID
ç¹°ãè¿ãã«ãªããŸãããæå¹ãªç»åãã¢ããããŒããããšããããã®ãã©ã¡ãŒã¿ãŒããã¹ãŠå ±åãããŸãã ãªã³ã¯ã®ããã€ãã®ãªãã·ã§ã³ãããã«å®è¡ããããšã¯é£ãããããŸããïŒæ°ç§ãããŸãããããã«ãããã«å ¥ãããšã¯å°é£ã§ãïŒã
äžè¬ã«ããã¡ã€ã«åã®ååŸã¯åé¡ã§ã¯ãããŸããã å ã«é²ã¿ãŸãã ãããŠããªãPHPã¹ã¯ãªãããã¢ããããŒãããªãã®ã§ããããïŒ ããŠã³ããŒãããããšãããšãåããŠã£ã³ããŠããããã¢ããããŸããããã¡ã€ã«ã¯ãã£ã¬ã¯ããªã«è¡šç€ºãããŸããã ã³ãŒãã調ã¹ãæéã§ãïŒ
ã¹ã¯ãªããuploadImage.phpã¯ãããŒãžã§ã³7.2.5ã§ãµãŒããŒã«ç»åãã¢ããããŒããã圹å²ãæ ã£ãŠããã100ã117è¡ç®ã«é¢å¿ããããŸãã
if (substr($ext,0,3)=='php' or substr($ext,0,4)=='phtm') { if(@!getimagesize($uploadedFile['tmp_name'])) { $error=i18n('errorNotAnImage'); } else { traceHack("Try to upload php file as image in CKEditor"); } } else { if ( ! move_uploaded_file($uploadedFile['tmp_name'], $uploadfile)) { $error = htmlGetErrorMessage(i18n('errorUploadFile','hacking ?')); errorLog(i18n('errorUploadFile','hacking ?')); } } } if (!$error) { if(@!getimagesize($uploadfile)) { $error=i18n('errorNotAnImage'); } }
è¡100ã¯ããã¡ã€ã«æ¡åŒµåã®ç¢ºèªãæ åœããŸããphpãŸãã¯phtmã®å Žåããã¡ã€ã«ã¯ç Žæ£ãããä¿åãããŸããã ãããã£ãŠãphpãã¡ã€ã«ã¯ãfiles / images /ããã£ã¬ã¯ããªã«è¡šç€ºãããŸããã è¡115ã¯ã衚瀺ããããšã©ãŒãäœæããŸããããã¡ã€ã«ã«ã¯äœãããŸããã
ããŠããšã¯ã¹ããã€ãã«è¿œãã€ãã.shtmlãã¡ã€ã«ãã¢ããããŒãããŸãããã ããã§ã¯ãå°ãäœè«ãããŠã.shtmlãäœã§ãäœãäžç·ã«é£ã¹ãããããäŒãã䟡å€ããããŸãã
SHTMLããã³SSI
ãŠã£ãããã£ã¢ã®å®çŸ©ïŒ
SSIïŒãµãŒããŒåŽã€ã³ã¯ã«ãŒã-ãµãŒããŒåŽã®ã€ã³ã¯ã«ãŒãïŒã¯ãåã ã®ã³ã³ããŒãã³ããããµãŒããŒäžã®WebããŒãžãåçã«ãã¢ã»ã³ããªãããåä¿¡ããHTMLããã¥ã¡ã³ããã¯ã©ã€ã¢ã³ãã«é ä¿¡ããããã®ã·ã³ãã«ãªèšèªã§ãã mod_includeã¢ãžã¥ãŒã«ã䜿çšããŠApache WebãµãŒããŒã«å®è£ ãããŸãã WebãµãŒããŒã®ããã©ã«ãèšå®ã«å«ãŸããæ©èœã«ãããHTMLãã¡ã€ã«ãå«ããããšãã§ããŸãããããã£ãŠãæ瀺ã䜿çšããã«ã¯ããã¡ã€ã«ã®æ¡åŒµåã.shtmlã.stmããŸãã¯.shtmã§ããå¿ èŠããããŸãã
ããªãèªèº«ã®èšèã§ïŒ
SHTMLã¯ããµãŒããŒåŽã®åœä»€ã»ãããå®è¡ã§ããHTMLã§ãã 䟿å©ãªæ©èœã®ãã¡ããµãŒããŒäžã§ä»»æã®ã³ãã³ããå®è¡ããexecé¢æ°ããããŸãïŒã¯ããHTMLã³ãŒãã䜿çšããŠãã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ã§ããŸãïŒã
ä»»æã®ã³ãŒããå®è¡ãããµã³ãã«ã³ãŒãã次ã«ç€ºããŸãã
<!--#exec cmd=âlsâ -->
幞ããªããšã«ããã®æ©èœã¯Apache2ãµãŒããŒã§ã¯ããã©ã«ãã§æå¹ã«ãªã£ãŠããªããããæå¹ã«ããã«ã¯ã¿ã³ããªã³ã§èžãå¿ èŠããããŸãã æ§æãéžæããŠããæ°æéã§ãç°å¢å€æ°ã®æ»ãå€ãæ©èœãããããšãã§ããŸããããã³ãã³ãã¯æ©èœããŸããã§ããã ãããç§ã®SSIã³ãŒãã§ãã
<html> <head> <title>thegeekstuff.com</title> </head> <body> <p> Today is <!--#echo var="DATE_LOCAL" --> <!--#exec cmd="ls" --> </p> </body> </html> : Today is Wednesday, 14-Nov-2018 17:29:14 MSK [an error occurred while processing this directive]
誰ããèšå®ã§äœãæžãã¹ãããæããŠããããæ£ããåäœããããã«ãªã£ãããç§ã¯ãããèªã¿ããã§ãã
ãšã¯ã¹ããã€ãã®è匱æ§
æãåæããããshtmlãã¡ã€ã«ãããŠã³ããŒãããŠãä»»æã®ã³ãã³ããå®è¡ã§ããŸãïŒãŸãã¯ãç§ã®ããã«ããµãŒããŒã®æå»ã確èªããŸãïŒã
ããããèŠã
次ã®ããŒãžã§ã³ã¯7.2.6ã§ãããç§ãã¡ãèå³ãæã£ãŠããè匱æ§ã«é¢ããå€æŽã¯ãããŸããïŒnist.govãåã³æ¬ºãããŸããïŒã
ããŒãžã§ã³7.2.7ãèŠããšããã¹ãŠãä¿®æ£ãããŠããããã§ãïŒéçºè èªèº«ã¯ããã®ããŒãžã§ã³ã§ãã¹ãŠãä¿®æ£ããããšèšã£ãŠããŸãïŒã 2ã€ã®éèŠãªå€æŽç¹ããããŸãã
1.çŠæ¢ãããŠããæ¡åŒµæ©èœã®äžã«ããshtmããè¿œå ãããŸããïŒæåã®4æåããã®ãããªå Žåãshtmlãããã«å«ãŸããŸãïŒã
if (substr($ext,0,3)=='php' or substr($ext,0,4)=='phtm' or substr($ext,0,4)=='shtm') {
2.åçã§ã¯ãªããã¡ã€ã«ã¯åé€ãããŸãã
if(@!getimagesize($uploadfile)) { $error=i18n('errorNotAnImage'); kill($uploadfile); }
éç»åã¯åé€ãããshtmlã¯çãæ®ãããšããªãã®ã§ãåå²ã§ããããã«æãããŸãã ãããã圌ãããã©ãã¯ãªã¹ãã®åé¡ã解決ããããšããå Žåãç§ã¯ãã€ãããã奜ãã§ã¯ãªãã£ãã ããšãã°ãäžéšã®åœã§ã¯ãäŒæ¥ã¯ãœãŒã·ã£ã«ãããã¯ãŒã¯ãçŠæ¢ããŠããŸãã ããã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒããçãŸãããœãŒã·ã£ã«ãããã¯ãŒã¯ã®ããã©ãŒãã䜿çšãå§ãããšããäºå®ã«ã€ãªãããŸãã ãããã®ãã¹ã¯ãŒãã¯äŒæ¥ã®ãã¹ã¯ãŒããšäžèŽããŸãããã³ãŒããŒã飲ã¿ãªããã€ã³ã¹ã¿ã°ã©ã ãèŠã蟌ãåŸæ¥å¡ãããã¯ããã«å€§ããªåé¡ãçºçããå¯èœæ§ããããŸãã
Webããã°ã©ãã³ã°ãšãã®ã»ãã¥ãªãã£ã§ã¯ããã©ãã¯ãªã¹ããæªã§ãã
ProjeQtOrãããã©ãã¯ãªã¹ãããã€ãã¹ããŸã
ãŸãããã¹ãŠãç°¡åã§ãã æåã«ãApache2 + PHPãããã©ã«ãèšå®ã§è§£éã§ãããã¡ã€ã«ãèŠãŠã¿ãŸãããïŒãã¹ãŠãæŽæ°ããããªããžããªã§ubuntu 16.04ã«ã€ã³ã¹ããŒã«ãããŸããïŒã ãFilesMatchããã£ã¬ã¯ãã£ãã¯ããã¡ã€ã«ã解éããæ©èœãæ åœããŸãã ã³ãã³ã "grep -r" <FilesMatch "/ etc / apache2"ã䜿çšããŠæ€çŽ¢ãããšãçµæã¯æ¬¡ã®ããã«ãªããŸãã
/etc/apache2/mods-available/php7.0.conf:<FilesMatch ".+\.ph(p[3457]?|t|tml)$"> /etc/apache2/mods-available/php7.0.conf:<FilesMatch ".+\.phps$"> /etc/apache2/mods-available/php7.0.conf:<FilesMatch "^\.ph(p[3457]?|t|tml|ps)$"> /etc/apache2/sites-available/default-ssl.conf: <FilesMatch "\.(cgi|shtml|phtml|php)$"> /etc/apache2/apache2.conf:<FilesMatch "^\.ht">
default-ssl.confæ§æã§ã¯ããã¹ãŠã®æ¡åŒµæ©èœãåçŽã«ãªã¹ããããŠããŸã;ãããã¯ãcgiãshtmlãphtmlãphpã§ãã æ®å¿µãªãããcgi以å€ã¯ãã¹ãŠProjeQtOrã§é€å€ãããŸãã
php7.0.conf configã¯ããã«èå³æ·±ããã®ã§ãæ¡åŒµæ©èœã¯æ£èŠè¡šçŸã«ãã£ãŠèšå®ãããŸãã ååŸãããã®ïŒ
å»¶é· | ãã£ã«ã¿ãªã³ã°ããããã® |
---|---|
php | substrïŒ$ extã0.3ïŒ== 'php' |
php3 | substrïŒ$ extã0.3ïŒ== 'php' |
php4 | substrïŒ$ extã0.3ïŒ== 'php' |
php5 | substrïŒ$ extã0.3ïŒ== 'php' |
php7 | substrïŒ$ extã0.3ïŒ== 'php' |
pht | äœã |
phtml3 | substrïŒ$ extã0.4ïŒ== 'phtm' |
çŽ æŽãããããã£ã«ã¿ãªã³ã°ãããŠããªããã¡ã€ã«æ¡åŒµåãèŠã€ãããŸããã æ¬åœã«è§£éãããããšã確èªããŸãã
次ã®å 容ã§test.phtãã¡ã€ã«ãäœæããŸãã
<?php phpinfo();
ãã©ãŠã¶ã§ãã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããã€ã³ã¹ããŒã«ãããŠããphpã«é¢ããæ å ±ã確èªããŸãã é©ãã¹ãããšã«ããã©ãã¯ãªã¹ãã¯ãã€ãã¹ãããŸããããããã©ã«ã以å€ã®èšå®ã§ã¯ãäœããã®çç±ã§ã解éã®ããã®ä»ã®æ¡åŒµãèš±å¯ãããå¯èœæ§ããããŸããã
ProjeQtOrãããžã§ã¯ã管çããŒã«ã«ãã¹ããã¡ã€ã«ãããŒãããŸãã ãã¡ãããããã¯åçã§ã¯ãªããããšã©ãŒãçºçããŸãïŒ7.2.7ããåã®ããŒãžã§ã³ã§ã¯ãphpinfoãã³ãã³ãã®å®è¡ã«å€æŽããã®ã¯é£ãããªãããããµãŒããŒäžã§æ¢ã«ã³ãŒããå®è¡ãããŠããŸãïŒã ããŒãžã§ã³7.2.7ã§ã¯ããã¡ã€ã«ã¯åé€ãããã³ãŒãã¯å®è¡ãããŸããã
ããããç§ãã¡ã¯åæºãããåçã®ãã§ãã¯ããã€ãã¹ããŸãã
PHPã®ç»å
ããŠã³ããŒããããã¡ã€ã«ãProjeQtOrãããžã§ã¯ã管çããŒã«ã§ç»åã§ãããã©ããã確èªããã«ã¯ãgetimagesizeé¢æ°ã䜿çšããŸãããã®é¢æ°ã¯ã転éããããã¡ã€ã«ã®ããããŒãåçŽã«èª¿ã¹ãŸãã
phpãã¡ã€ã«ã«ãŽããååšããå¯èœæ§ããããšããäºå®ãå©çšããphpã³ãŒãã®è§£éã¯æåã<ïŒ åçãšããŠããšã©ãŒãŠã£ã³ããŠã®ã¹ã¯ãªãŒã³ã·ã§ãããéä¿¡ããŸãã 3è¡ã®Pythonã³ãŒãã§å®äºã§ãã
data = open ('test.png','rb').read() data += open ('test.pht','rb').read() open ('new_pht_png.pht','wb').write(data)
ããããããã¡ã€ã«ã®å é ã«æå¹ãªç»åã®ã¿ã€ãã«ãæžãã ãã§ããã®ã§ãããããã¯ç°¡åã§ãããã«å€ãã®å Žåããã¹ãŠã®ãã¥ãŒã¢ã§ç»åã衚瀺ãããŸãã
ãã®äœæç©ããµãŒããŒã«ã¢ããããŒããããšãèŠãããããèªã¿èŸŒãŸãïŒãã¥ãŒã¢ãŒã«ç»åãšããŠè¡šç€ºãããŸãïŒããã®ãã¡ã€ã«ãããŠã³ããŒãããããšãã®ãã«ããŒã ã衚瀺ãããã®ãããããšã§ãã
ããŠã³ããŒããããã¡ã€ã«localhost / files / images / 20181114171730_1_new_pht_png.phtã«ç§»åããããŠã³ããŒãããç»åãããã¹ããšããŠè¡šç€ºãããã®äžã«ããphpinfoåºåã確èªããŸãã phpinfoãåçŽãªWebã·ã§ã«ã«çœ®ãæããããšã¯é£ãããªãããšã¯æããã§ãã ããšãã°ã次ã®ããã«ãªããŸãã<ïŒPhp systemïŒ$ _ GET ['cmd']ïŒ;
ãã¡ã€ã«ã®ããŠã³ããŒãã®éžæãéå§ãããããžã§ããçµäºãããã©ãã¯ãªã¹ãã®æç¡ã«ããããããã¡ã€ã«ã®ããŠã³ããŒããããå Žæã確èªããå¿ èŠããããŸãã
å¥ã®ãã¡ã€ã«ã®ã¢ããããŒã
ææ°ã®å©çšå¯èœãªããŒãžã§ã³ã§èŠèŽããŸãã 以åãšåãé¢æ°ã䜿çšããŠãã¡ã€ã«ãã¢ããããŒããããšä»®å®ãããšãã€ãŸã move_uploaded_fileããããžã§ã¯ããã£ã¬ã¯ããªãgrep -rãmove_uploaded_fileã./ãã§æ€çŽ¢ããŸãã 次ã®5ã€ã®ãã¡ã€ã«ãååŸããŸãã
./tool/uploadImage.php
./tool/saveDocumentVersion.php
./tool/uploadPlugin.php
./tool/import.php
./tool/saveAttachment.php
ãã¡ã€ã«uploadImage.php-æ¢ã«èŠãŸããã
ãã¡ã€ã«saveDocumentVersion.php-ããã¥ã¡ã³ãã®ããŒãžã§ã³ãããŠã³ããŒãããŸãïŒååã瀺ããšããïŒã ç§ãã¡ã¯ããã¥ã¡ã³ããããŠã³ããŒãããŠèŠãããšããŠããŸãïŒæåã¯åžžã«ç»åãããŒãããŸãïŒã ããŠã³ããŒãåŸãæ¡åŒµå.1ããã¡ã€ã«ã«è¿œå ãããŠããããšãããããŸãã ã³ãŒãã®ååã®ååŸæ¹æ³ã調ã¹ãŸãïŒããã¯229è¡ç®ã§è¡ãããŸãïŒã
$uploadfile = $dv->getUploadFileName();
getUploadFileNameé¢æ°ã¯ãDocumentVersionMain.phpãã¡ã€ã«ã§å®£èšãããŠããŸãã 227è¡ç®ã§ã¯ããããã衚瀺ãããè¿ãããååã«ããã¥ã¡ã³ãIDãè¿œå ãããŠããŸãã è¿œå ããããã€ã³ãã§ããåé¿ããããšã¯ã§ããŸããã
return $uploaddir . $paramPathSeparator . $fileName . '.' . $this->id;
uploadPlugin.phpãã¡ã€ã«ã¯ç®¡çè ã®ã¿ãã¢ã¯ã»ã¹ã§ãããã©ã°ã€ã³ã«äžé©åãªã³ãŒããå«ãŸããŠããå¯èœæ§ããããšããäºå®ã¯éåžžã«è«ççã§ããããã©ã°ã€ã³æ€èšŒãå ¥åããã«åãé€ãããšã¯å°é£ã§ãïŒäžè¬çãªCMSã®ããã«ïŒã ãã¡ãããããã«äœããããŠã³ããŒãããããšãããšãæ£åžžã«ããŒããããå®è¡ãããŸãã
import.phpãã¡ã€ã«ã¯ã管çè ã®ã¿ãå©çšã§ããŸãã ãã¡ã€ã«ãããŠã³ããŒããããšããcsvãã¡ã€ã«ãŸãã¯xlsxãã¡ã€ã«ã§ãªããã°ãªããªãããšãéç¥ãããŸãã ãã¡ãããphpãã¡ã€ã«ãããŒãããããšãããšãšã©ãŒã衚瀺ãããŸãã
ãšã©ãŒ-æå®ããããã¡ã€ã«ã¿ã€ããšéžæããããã¡ã€ã«åœ¢åŒãäžèŽããŸãã
ã€ã³ããŒããäžæ¢ãããŸãã
åé¡ã¯ãCVEã®å ã®ãã°ã®ããã«ããã¡ã€ã«ã¯åé€ãããã localhost / files / attach / import / test.phpã§å©çšå¯èœãªãŸãŸã§ãããšããããšã§ãã
saveAttachmentãã¡ã€ã«ã¯ãæ·»ä»ãã¡ã€ã«ãããŒããããšãïŒããšãã°ãç¬èªã®ã€ã¡ãŒãžãããŒããããšãïŒã«äœ¿çšãããŸãã 次ã®åœ¢åŒã®ä¿è·ããããããPHPã¹ã¯ãªããã¯ããã§ã¯ããŒã«ããŸããã
if (substr($ext,0,3)=='php' or substr($ext,0,4)=='phtm' or substr($ext,0,4)=='shtm') { $attachmentâfileName.=".projeqtor";
æ¡åŒµåãã¡ã€ã«php *ãphtm *ãshtm *ãè¿œå ãããŸããæ¡åŒµåã.projeqtorããè¿œå ãããŸããã€ãŸããæããã«ãphtãã¡ã€ã«ã¯ããã«ã¯ããŒã«ããŸãïŒåçãã¯ããŒã«ããªããŠãïŒã è©ŠããŠã¿ãŠãã¢ãã¬ã¹localhost / files / attach / attachment_1 / test.phtã§ãã¹ãŠãååŸããŸãã
ããã«èŠã€ãã£ã5ã€ã®ãã¡ã€ã«ã¢ããããŒãå Žæã®æçµçµæïŒ
- phpãŸãã¯phtã¹ã¯ãªããã4åããŒãã§ããŸããã
- ãã©ãã¯ãªã¹ãæ€èšŒã¯2ã€ãããŸãã
- ãã¯ã€ããªã¹ãã®æ€èšŒã¯ã©ãã«ããããŸããã
- ãã¡ã€ã«ã®ããŠã³ããŒãã«å€±æããïŒããŠã³ããŒãã«å€±æããããå®è¡ã«å€±æããïŒ æ¡åŒµãå€åããŠãã
ProjeQtOrãããžã§ã¯ã管çããŒã«ãšCVE-2018-18924ã®çµè«
- å ±åãããè匱æ§ã¯äºå®äžæé€ãããŸããã
- ã³ãŒãã«ã¯ä»ã®è匱æ§ããããŸãïŒéçºè ã«å ±åãããããã«æ¡åŒµæ©èœã®ãã¯ã€ããªã¹ããçŽæããŸããïŒã
- Apache2ãµãŒããŒãé©åã«æ§æããããšã§ããã¹ãŠã®ããšããç§ãã¡ãæãããšãã§ããŸãïŒå®è¡åœ¢åŒãå¿ èŠãªãã®ã ãã«å¶éãããŠãŒã¶ãŒãã©ã«ããŒå ã®ã¹ã¯ãªããã®å®è¡ãçŠæ¢ããŸãïŒ
- nist.govã«ã¯ãææ°ã®è匱ãªããŒãžã§ã³ã¯å«ãŸããŠããŸããã
æ人ã¡ã¢
- ãã©ãã¯ãªã¹ããå¯èœãªéãæåŠããŸãïŒãããã©ãã§äžå¯èœãã¯ããããŸããïŒã
- ããŠã³ããŒããããã¡ã€ã«ãåŠçãããšãã¯æ³šæããŠæ³šæããŠãã ããïŒ1ãæã«é 眮ãã5ã€ãŸã§æ¡æ£ããªãããšããå§ãããŸãïŒã
- é©åã«æ§æãããWebãµãŒããŒã¯ããããžã§ã¯ãã³ãŒãã®å€ãã®åé¡ãé²ããŸãïŒã³ãŒããèšè¿°ãããµãŒããŒãé©åã«æ§æããããšãéèŠã§ãïŒã
éçºè ããã®è©³çŽ°ãªåç
éçºè ããã®æåã®çãã¯ãããã¹ãŠãä¿®æ£ããã®ã§ãä¿®æ£ãããã³ãŒããåç §ããŠãã ããããšãããããªãã®ã§ããã ããã€ãã®åé¡ãã©ãã«ãããã©ã®ããã«ããããæªçšãããå¯èœæ§ãããã®ãââã詳现ã«ãã€ã³ãããå¿ èŠããããŸããã
ãã®åŸã圌ã¯è©³çŽ°ãªåçãåãåããŸããããåé¡ããããŸããåé¡ã¯ããŒãžã§ã³7.3.0ã§ä¿®æ£ãããŸãã ãã¯ã€ããªã¹ãã¯ãxlslxãšcsvã®äž¡æ¹ã®ç»åã«ãè¿œå ãããŸãã ãŸããã€ã³ã¹ããŒã«æé ã§ãWebã¢ã¯ã»ã¹ã®å€ã«ãæ·»ä»ããã£ã¬ã¯ããªãšãããã¥ã¡ã³ãããã£ã¬ã¯ããªãè¿œå ããããšãæšå¥šããŠãããšæžããŠããŸãã
éçºè ã¯ãCVEãç»é²ããæŽæ°åŸã«èšäºãæžãããšãèš±å¯ããŸããïŒå ¬éããã ããŠã³ããŒãå¯èœã§ãïŒã
ãããã«
åé ã§æžããããã«ãCVEã決å®ããã¢ããããŒãã¯éåžžã«å€ãã®äººïŒ500以äžã®ããŠã³ããŒãïŒã«ãã£ãŠããŠã³ããŒããããè匱ãªãœãããŠã§ã¢ãã¢ããããŒãããã®ã¯ã¯ãŒã«ã§ããããœãããŠã§ã¢ãè匱ãªãŸãŸã§ããã®ã¯æ®å¿µã§ãã
ãã®çµæã4ã€ã®CVEãç§ãšåœç€Ÿã«å²ãåœãŠãããŸããïŒCVE-2018-19307ãCVE-2018-19308ãCVE-2018-19309ãCVE-2018-19310ã