Apache Axis Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-04-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0227£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


ÊÜÓ°ÏìµÄ°æ±¾


Apache Axis Version = 1.4


²»ÊÜÓ°Ïì°æ±¾


Apache Axis2 ËùÓа汾£¨Ä¿Ç°ÁÙʱûÓз¢ÏÖAxis2µÄ·þÎñ´æÔÚ±íÁª¾°Ïó£©


·ì϶¸ÅÊö


Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWeb·þÎñ¼Ü¹¹¡£¸Ã²úÆ·Ô̺¬ÁËJavaºÍC++˵»°ÊµÏÖµÄSOAP·þÎñÆ÷£¬ÒÔ¼°¸÷À๫Ó÷þÎñ¼°API£¬ÒÔÌìÉúºÍ²¿ÊðWeb·þÎñÀûÓá£


Axis¸½´øµÄĬÈÏ·þÎñStockQuoteService.jwsÔ̺¬Ò»¸öÓ²±àÂëµÄHTTP URL£¬¿ÉÓÃÓÚ´¥·¢HTTPÒªÇó¡£¹¥»÷ÕßÄܹ»Í¨¹ýÓòÃû£¨www.xmltoday.com£©ÊÕÊÜ»òÕßͨ¹ýARPºýŪ·þÎñÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬²¢½«HTTPÒªÇó³Á¶¨Ïòµ½¶ñÒâWeb·þÎñÆ÷£¬ÔÚApache Axis·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ루CVE-2019-0227£©¡£


ĿǰΪÁËÔ¤·ÀÓòÃûwww.xmltoday.com±»¶ñÒâ¹¥»÷ÕßÀûÓã¬ÒѾ­Óа×ñ×Ó½«Æä²É°ì¡£


·ì϶ÑéÖ¤


POC£ºhttps://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-0227¡£


ÔÚAxisµÄĬÈÏ×°ÖÃÖУ¬ÓÐÒ»¸öÃûΪ¡°StockQuoteService.jws¡±µÄĬÈÏʾÀýWeb·þÎñ£¬Äܹ»¹«¿ª½Ó¼û¡£´Ë·þÎñµÄÖ÷ÕÅÊǾÙÀý×¢Ã÷ÄúÄܹ»Ê¹ÓÃJava Web ServiceÖ´ÐеIJÙ×÷¡£´ËÌØ¶¨Ê¾ÀýÖ¼ÔÚ´ÓפÁôÔÚ±í²¿URLÉÏµÄ±í²¿·þÎñ¼ìË÷¹ÉƱ´úÂëµÄ¼ÛÖµ¡ £¿´Ò»ÏÂÕâÏî·þÎñµÄ´úÂ룬ËüÔÚÏòwww.xmltoday.com·¢³öHTTPÒªÇóÒÔ¼ìË÷һЩXML²¢ÏÔʾ´ÓÏìÓ¦ÖнâÎö³öÀ´µÄ¹ÉƱ´úÂëµÄ¼ÛÖµ¡£±ÉÈËÃæµÄÆÁÄ»½ØÍ¼ÖУ¬Äܹ»¿´µ½¶Ô±í²¿·þÎñÖ´ÐÐHTTPÒªÇóµÄ´úÂ룬www.xmltoday.com¡£ 

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


XMLUtils.newDocument¡°³¢ÊÔ´ÓÒª½âÎöµÄÓòÖмìË÷XMLÎĵµ¡£ÓÉÓÚÓû§½ÚÔì·¢Ë͵½www.xmltoday.comµÄ¡°·ûºÅ¡±²ÎÊý£¬È¥¿´ÏÂwww.xmltoday.comÄܹ»¿´µ½¸ÃÓòÃû¿É¹©ÈκÎÈ˲ɰì¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚwww.xmltoday.comÔÚÏúÊÛ£¬ÕâÒâζ×ÅÎÒÃÇÄܹ»²É°ì´ËÓò²¢½«ÆäÉèÖÃΪ½«ÈκÎÒªÇó³Á¶¨Ïòµ½ÌØÔìµÄlocalhost URL¡£½«´ËÓëSSRFÓëRCE¼¼ÇÉÏà½áºÏ£¬¾ÍÄܹ»ÔÚÖ°ºÎAxis·þÎñÆ÷ÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐС£ÎªÁËÑéÖ¤ÕâÒ»µã£¬¿´Ï¡°XMLUtils.newDocument¡±º¯ÊýÈôºÎ´¦ÖóÁ¶¨Ïò¡£ÏÂͼÏÔʾÁË¡°XMLUtils.newDocument¡±Ê¹Óõġ°HttpURLConnection¡±µÄÊôÐÔ¡£

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²é¿´AxisÔ´ÖеÄXMLutils£¬Äܹ»¿´µ½¡°setInstanceFollowRedirects¡±ÊôÐÔÉèÖÃΪ¡°true¡±¡£Õâ֤ʵÁË¡°XMLUtils.newDocument¡±ÏÖʵÉÏ»á×ñÑ­³Á¶¨Ïò¡£


Õ¼ÓдËÓò²¢²»ÊÇÀÄÓá°StockQuoteService.jws¡±»òÀ´×ÔAxis·þÎñÆ÷µÄÈÎºÎÆäËûHTTPÒªÇóµÄΨһ²½Öè¡£ÓÉÓÚÒªÇóÊÇͨ¹ýHTTP½øÐеÄ£¬ÕâÒâζ×ÅÈôÊÇÄúÓëAxis·þÎñÆ÷λÓÚÍ³Ò»ÍøÂçÉÏ£¬ÔòÄܹ»Ö´ÐÐÕë¶Ô¸Ã·þÎñÆ÷µÄÖÐÑëÈ˹¥»÷£¬¶øºóʹÓá°StockQuoteService.jws¡±´¥·¢Æ÷»òÆÚ´ýHTTPÒªÇó²¢Ôٴν«´ËÒªÇó³Á¶¨Ïòµ½localhostÒÔÀûÓÃSSRF¼¼ÇÉ¡£ÀûÓÃËüµÄ²½ÖèÈçÏ£ºARPÖж¾Ö¸±êAxis·þÎñÆ÷¡£


½«ÈκÎHTTPÁ÷Á¿³Á¶¨Ïòµ½Äú×Ô¼ºµÄWeb·þÎñÆ÷¡£


³Á¶¨Ïòµ½ÌØÔìµÄlocalhost URL£¬¸ÃURLÔÚAxisÖÐÆô¶¯·þÎñ¡£


´¥·¢HTTPÒªÇóÒÔ³Á¶¨ÏòÒªÇó¡°StockQuoteService.jws¡±¡£


·ì϶ÀûÓóɹ¦ÈçÏÂͼ£º

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


½¨¸´½¨Òé


ÈôÊÇÔÚʹÓÃAxis£¬Äܹ»É¾³ýAxis¸ùĿ¼ÖÐStockQuoteService.jwsÎļþ¡£
È·±£ÔÚAxis»òAxis2ÖÐÔËÐеÄÈκοâ»ò·þÎñ²»´æÔÚ±íÁªµÄHTTP/HTTPSÒªÇó¡£
Apache Axis2µÄÏÂÔØµØÖ·Îª£º

http://axis.apache.org/axis2/java/core/download.html


²Î¿¼Á´½Ó


https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/