Sophos XG·À»ðǽSQL×¢Èë·ì϶¹«¸æ
°ä²¼¹¦·ò 2020-04-270x00 ·ì϶¸ÅÊö
|
CVE ID |
ÔÝÎÞ |
ʱ ¼ä |
2020-04-27 |
|
Àà ÐÍ |
SI |
µÈ ¼¶ |
¸ßΣ |
|
Ô¶³ÌÀûÓà |
ÊÇ |
Ó°ÏìÁìÓò |
ËùÓа汾µÄXG·À»ðǽ |
0x01 ·ì϶ÏêÇé

Sophos XG FirewallÊÇÓ¢¹úSophos¹«Ë¾µÄÒ»¿î·À»ðǽÉ豸¡£SFOSÊÇÔËÐÐÔÚÆäÖеÄÒ»ÌײÙ×÷ϵͳ¡£
SophosÓÚUTC 2020Äê4ÔÂ22ÈÕ20:29ÊÕµ½ÁËÓйØXG·À»ðǽµÄ»ã±¨£¬¸ÃXG·À»ðǽÔÚÖÎÀí½çÃæÖпɼû¿ÉÒÉ×ֶΡ£µ÷²é·¢ÏÖ¸ÃÊÂÎñΪ¹¥»÷ÊÂÎñ£¬¶ø²»ÊDzúÆ·bug¡£ºÚ¿ÍÖØÒªÕë¶ÔµÄÊÇ¿ªÆôHTTPS·þÎñ»òÕßÓû§½ÚÔìÃæ°å¶³öÔÚ»¥ÁªÍøÉϵÄSophos XG FirewallÉ豸¡£
¸Ã¹¥»÷ʹÓÃÒÔǰδ֪µÄSQL×¢Èë·ì϶À´ÏÂÔØpayloads¡£¶øºóÇÔÈ¡Îļþ£¬¿ÉÄÜÔ̺¬·À»ðǽÖÎÀíÔ±£¬·À»ðǽÃÅ»§ÍøÕ¾ÖÎÀíÔ±ÒÔ¼°ÓÃÓÚÔ¶³Ì½Ó¼ûÉ豸µÄÓû§ÃûºÍ¹þÏ£ÃÜÂë¡£µ«ÊÇÉí·ÝÑé֤ϵͳ£¨ÀýÈçAD»òLDAP£©µÄÃÜÂë²»ÊÜÓ°Ïì¡£
¸Ã¹«Ë¾°µÊ¾£¬ÔÚµ÷²é¹ý³ÌÖУ¬Ã»Óз¢ÏÖºÚ¿ÍʹÓÃ͵ÇÔµÄÃÜÂë½Ó¼ûÁ˿ͻ§ÄÚÍøÉϵÄXG·À»ðǽÉ豸»ò·À»ðǽÒÔ±íµÄÈκÎÄÚÈÝ¡£
0x02 ´ëÖý¨Òé
²¹¶¡·¨Ê½»áÔÚXGÖÎÀí½çÃæÉÏÌáÐÑÒ»ÌõÐÂÎÅ£¬À´ÌáÐÑ´ËXG·À»ðǽÊÇ·ñÊܵ½´Ë¹¥»÷µÄÓ°Ïì¡£
¹æ»®1£ºÎ´Ôâµ½¹¥»÷£¬Ö±½Ó¸üв¹¶¡¼´¿É¡£
¹æ»®2£ºÈôÊÇÒÑÔâµ½¹¥»÷£¬ÈçÏÂͼ¡£
¶ÔÓÚÔâµ½ÈëÇÖµÄÉ豸£¬Sophos½¨Òé²ÉÈ¡ÒÔϲ½Ö裺
1. ³ÁÖÃÃÅ»§ÍøÕ¾ÖÎÀíÔ±ºÍÉ豸ÖÎÀíÔ¹ØÊ»§
2. ³ÁÐÂÆô¶¯XGÉ豸
3. ³ÁÖÃËùÓб¾µØÓû§ÕÊ»§µÄÃÜÂë
4. Ö»¹ÜÃÜÂëÊǹþÏ£Öµ£¬µ«½¨Òé³ÁÖÃËùÓÐÕÊ»§ÃÜÂë
°ÑÎÈ£º¸üд˲¹¶¡·¨Ê½ºó£¬²¹¶¡·¨Ê½¾¯±¨ÐÂÎŲ»»áÒþû¡£¼´±ãÒѳɹ¦ÀûÓô˲¹¶¡·¨Ê½£¬ÒÔ¼°ÊµÏÖÁËÈÎºÎÆäËû²Ù×÷²½ÖèÖ®ºó£¬¾¯±¨Ò²½«³ÖÐøÏÔʾÔÚXGÖÎÀí½çÃæÖС£
0x03 ÓйØÐÂÎÅ
https://www.zdnet.com/article/hackers-are-exploiting-a-sophos-firewall-zero-day/
0x04 ²Î¿¼Á´½Ó
https://community.sophos.com/kb/en-us/135412
0x05 ¹¦·òÏß
2020-04-25 Sophos°ä²¼¸üÐÂ
2020-04-27 VSRC°ä²¼·ì϶¹«¸æ


¾©¹«Íø°²±¸11010802024551ºÅ