WordPress CMS 佨¸´·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2018-06-27

·ì϶±àºÅºÍ¼¶±ð


CVE-2018-12895  ¸ßΣ  CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


¸Ã·ì϶ӰÏìËùÓÐWordPress CMS°æ±¾£¬Ô̺¬×îа汾v4.9.6¡£


·ì϶¸ÅÊö


ÀûÓô˷ì϶ʹ¹¥»÷Õß¿ÉÄÜɾ³ýWordPress×°ÖõÄÈκÎÎļþ£¨+ PHP·þÎñÆ÷ÉϵÄÈÎºÎÆäËûÎļþ£¬PHP¹ý³ÌÓû§ÓµÓÐÊʵ±µÄɾ³ýȨÏÞ£©¡£ ³ýÁËɾ³ýÕû¸öWordPress×°ÖõĿÉÄÜÐÔ£¨ÈôÊÇûÓе±Ç°±¸·Ý¿ÉÓûᵼÖ¿àÄÑÐÔºó¹û£©£¬¹¥»÷ÕßÄܹ»ÀûÓÃËÁÒâÎļþɾ³ýÖ°ÄÜÈÆ¹ýһЩ°²È«´ëÊ©²¢ÔÚWeb·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£ ¸üÈ·ÇеØËµ£¬Äܹ»É¾³ýÒÔÏÂÎļþ£º


.htaccess£º ͨ³££¬É¾³ý´ËÎļþ²»»áÓÐÈκΰ²È«ºó¹û¡£ µ«ÊÇ£¬ÔÚijЩÇé¿öÏ£¬ .htaccess ÎļþÔ̺¬Ó밲ȫÓйصÄÔ¼Êø£¨ÀýÈ磬¶ÔijЩÎļþ¼ÐµÄ½Ó¼ûÏÞ¶È£©¡£ ɾ³ý´ËÎļþ½«»á½ûÓÃÕâЩ°²È«ÏÞ¶È¡£


index.phpÎļþ£º ͨ³£Çé¿öÏ£¬½«¿ÕµÄ index.php Îļþ¸éÖõ½Ä¿Â¼ÖУ¬ÒÔÔ¤·ÀWeb·þÎñÆ÷ÎÞ·¨Ö´ÐеÄÇé¿öϵÄĿ¼Áбí¡£ ɾ³ýÕâЩÎļþ½«Îª¹¥»÷ÕßÌṩһ·ÝÁбí£¬ÁгöÊÜ´Ë´ëÊ©±£»¤µÄĿ¼ÖеÄËùÓÐÎļþ¡£


wp-config.php£º ɾ³ýÕâ¸öWordPress×°ÖÃÎļþ»á±ÉÈ˴νӼû¸ÃÍøÕ¾Ê±´¥·¢WordPress×°Öùý³Ì¡£ ÕâÊÇÓÉÓÚ wp-config.php Ô̺¬Êý¾Ý¿âƾ֤£¬ÈôÊÇûÓÐËü£¬WordPressµÄÐÐΪ¾ÍÈçͬËüÉÐδװÖᣠ¹¥»÷ÕßÄܹ»É¾³ý¸ÃÎļþ£¬Ê¹ÓÃÖÎÀíÔ¹ØÊ»§Ñ¡ÔñµÄÍ´´¦½øÐÐ×°Öùý³Ì£¬×îºóÔÚ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£


·ì϶ÑéÖ¤


·ì϶ÑéÖ¤ÊÓÆµ


http://player.youku.com/embed/XMzY4OTIzNDc4NA==


½¨¸´½¨Òé


·ì϶·¢ÏÖÕߣ¬°ä²¼ÁËÒ»¸öһʱ½¨²¹²½Ö裺


²Î¿¼https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
Temporary Hotfix

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

 

¹¦·òÏß


2017Äê11ÔÂ20ÈÕÔÚHackeroneÉÏÏòWordPress°²È«ÍŶӻ㱨·ì϶¡£
2017Äê11ÔÂ22ÈÕÕâ¸ö·ì϶±»°²È«ÍŶӷÖÀàºÍÑéÖ¤¡£
2017Äê12ÔÂ12ÈÕѯÎʽøÕ¹Çé¿ö¡£
2017Äê12ÔÂ18ÈÕWordpressÔÚ¿ª·¢Ò»¸ö²¹¶¡·¨Ê½¡£ ÒªÇó°ä²¼ÈÕÆÚ¡£ ûÓз´Ó³¡£
2018Äê01ÔÂ09ÈÕÒªÇó°ä²¼ÈÕÆÚ¡£Ã»Óз´Ó³¡£
2018Äê01ÔÂ20ÈÕÓÉÓÚÎÊÌâµÄÑϳÁÐԺͲ»×㹵ͨ£¬±»ÒªÇó¶ÔHackerone½øÐÐÅŽâ¡£
2018Äê01ÔÂ24ÈÕWordPress°²È«ÍŶӹÀ¼Æ±ØÒª6¸öԵŦ·òÄÜÁ¦½¨¸´¡£
2018Äê05ÔÂ24ÈÕѯÎÊÓйØÎÊÌâµÄ½øÕ¹ºÍ/»ò´òË㣬²¢ÌáÐÑÎÒÃǾ¡¿ì°ä²¼¡£Ã»Óз´Ó³¡£
2018Äê05ÔÂ24ÈÕ½«ÍÆÌØDM·¢Ë͸ø°²È«ÍŶÓ£¬ÒÔÈ·±£ËûÃDz»»áºöÂÔHackeroneÉϵÄÐÂÎÅ¡£
2018Äê06ÔÂ26Èջ㱨ʵÏÖºó7¸öÔÂÒÔÉÏÈÔδ½â¾öÎÊÌâ¡£


²Î¿¼Á´½Ó


https://blog.ripstech.com/2018/wordpress-file-delete-to-code-execution/
https://nvd.nist.gov/vuln/detail/CVE-2018-12895