Apache Axis Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-12

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-0227£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


ÊÜÓ°ÏìµÄ°æ±¾


Apache Axis Version = 1.4


²»ÊÜÓ°Ïì°æ±¾


Apache Axis2 ËùÓа汾£¨ÏÖÔÚÔÝʱûÓз¢Ã÷Axis2µÄЧÀͱ£´æÍâÁªÕ÷Ïó£©


Îó²î¸ÅÊö


Apache AxisÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¸ö¿ªÔ´¡¢»ùÓÚXMLµÄWebЧÀͼܹ¹¡£ ¡£¡£¡£¡£¸Ã²úÆ·°üÀ¨ÁËJavaºÍC++ÓïÑÔʵÏÖµÄSOAPЧÀÍÆ÷£¬£¬£¬ÒÔ¼°ÖÖÖÖ¹«ÓÃЧÀͼ°API£¬£¬£¬ÒÔÌìÉúºÍ°²ÅÅWebЧÀÍÓ¦Óᣠ¡£¡£¡£¡£


Axis¸½´øµÄĬÈÏЧÀÍStockQuoteService.jws°üÀ¨Ò»¸öÓ²±àÂëµÄHTTP URL£¬£¬£¬¿ÉÓÃÓÚ´¥·¢HTTPÇëÇó¡£ ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓòÃû£¨www.xmltoday.com£©½ÓÊÜ»òÕßͨ¹ýARPÓÕÆ­Ð§ÀÍÆ÷´Ó¶øÖ´ÐÐMITM¹¥»÷£¬£¬£¬²¢½«HTTPÇëÇóÖØ¶¨Ïòµ½¶ñÒâWebЧÀÍÆ÷£¬£¬£¬ÔÚApache AxisЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂ루CVE-2019-0227£©¡£ ¡£¡£¡£¡£


ÏÖÔÚΪÁ˱ÜÃâÓòÃûwww.xmltoday.com±»¶ñÒâ¹¥»÷ÕßʹÓ㬣¬£¬ÒѾ­Óа×ñ×Ó½«Æä¹ºÖᣠ¡£¡£¡£¡£


Îó²îÑéÖ¤


POC£ºhttps://github.com/RhinoSecurityLabs/CVEs/tree/master/CVE-2019-0227¡£ ¡£¡£¡£¡£


ÔÚAxisµÄĬÈÏ×°ÖÃÖУ¬£¬£¬ÓÐÒ»¸öÃûΪ¡°StockQuoteService.jws¡±µÄĬÈÏʾÀýWebЧÀÍ£¬£¬£¬¿ÉÒÔ¹ûÕæ»á¼û¡£ ¡£¡£¡£¡£´ËЧÀ͵ÄÄ¿µÄÊǾÙÀý˵Ã÷Äú¿ÉÒÔʹÓÃJava Web ServiceÖ´ÐеIJÙ×÷¡£ ¡£¡£¡£¡£´ËÌØ¶¨Ê¾ÀýÖ¼ÔÚ´ÓפÁôÔÚÍⲿURLÉϵÄÍⲿЧÀͼìË÷¹ÉƱ´úÂëµÄ¼ÛÇ®¡£ ¡£¡£¡£¡£¿ £¿£¿£¿£¿£¿£¿£¿´Ò»ÏÂÕâÏîЧÀ͵ĴúÂ룬£¬£¬ËüÕýÔÚÏòwww.xmltoday.com·¢³öHTTPÇëÇóÒÔ¼ìË÷һЩXML²¢ÏÔʾ´ÓÏìÓ¦ÖÐÆÊÎö³öÀ´µÄ¹ÉƱ´úÂëµÄ¼ÛÇ®¡£ ¡£¡£¡£¡£ÔÚÏÂÃæµÄÆÁÄ»½ØÍ¼ÖУ¬£¬£¬¿ÉÒÔ¿´µ½¶ÔÍⲿЧÀÍÖ´ÐÐHTTPÇëÇóµÄ´úÂ룬£¬£¬www.xmltoday.com¡£ ¡£¡£¡£¡£ 

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


XMLUtils.newDocument¡°ÊµÑé´ÓÒªÆÊÎöµÄÓòÖмìË÷XMLÎĵµ¡£ ¡£¡£¡£¡£ÓÉÓÚÓû§¿ØÖÆ·¢Ë͵½www.xmltoday.comµÄ¡°·ûºÅ¡±²ÎÊý£¬£¬£¬È¥¿´ÏÂwww.xmltoday.com¿ÉÒÔ¿´µ½¸ÃÓòÃû¿É¹©ÈκÎÈ˹ºÖᣠ¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÓÉÓÚwww.xmltoday.comÕýÔÚ³öÊÛ£¬£¬£¬ÕâÒâζ×ÅÎÒÃÇ¿ÉÒÔ¹ºÖôËÓò²¢½«ÆäÉèÖÃΪ½«ÈκÎÇëÇóÖØ¶¨Ïòµ½ÌØÖƵÄlocalhost URL¡£ ¡£¡£¡£¡£½«´ËÓëSSRFÓëRCE¼¼ÇÉÏàÁ¬Ïµ£¬£¬£¬¾Í¿ÉÒÔÔÚÈκÎAxisЧÀÍÆ÷ÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£¡£¡£ÎªÁËÑéÖ¤ÕâÒ»µã£¬£¬£¬¿´Ï¡°XMLUtils.newDocument¡±º¯ÊýÈçÄÇÀïÖÃÖØ¶¨Ïò¡£ ¡£¡£¡£¡£ÏÂͼÏÔʾÁË¡°XMLUtils.newDocument¡±Ê¹Óõġ°HttpURLConnection¡±µÄÊôÐÔ¡£ ¡£¡£¡£¡£

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


Éó²éAxisÔ´ÖеÄXMLutils£¬£¬£¬¿ÉÒÔ¿´µ½¡°setInstanceFollowRedirects¡±ÊôÐÔÉèÖÃΪ¡°true¡±¡£ ¡£¡£¡£¡£Õâ֤ʵÁË¡°XMLUtils.newDocument¡±ÏÖʵÉÏ»á×ñÕÕÖØ¶¨Ïò¡£ ¡£¡£¡£¡£


ÓµÓдËÓò²¢²»ÊÇÀÄÓá°StockQuoteService.jws¡±»òÀ´×ÔAxisЧÀÍÆ÷µÄÈÎºÎÆäËûHTTPÇëÇóµÄΨһҪÁì¡£ ¡£¡£¡£¡£ÓÉÓÚÇëÇóÊÇͨ¹ýHTTP¾ÙÐе쬣¬£¬ÕâÒâζ×ÅÈôÊÇÄúÓëAxisЧÀÍÆ÷λÓÚÍ³Ò»ÍøÂçÉÏ£¬£¬£¬Ôò¿ÉÒÔÖ´ÐÐÕë¶Ô¸ÃЧÀÍÆ÷µÄÖÐÐÄÈ˹¥»÷£¬£¬£¬È»ºóʹÓá°StockQuoteService.jws¡±´¥·¢Æ÷»òÆÚ´ýHTTPÇëÇó²¢Ôٴν«´ËÇëÇóÖØ¶¨Ïòµ½localhostÒÔʹÓÃSSRF¼¼ÇÉ¡£ ¡£¡£¡£¡£Ê¹ÓÃËüµÄ°ì·¨ÈçÏ£ºARPÖж¾Ä¿µÄAxisЧÀÍÆ÷¡£ ¡£¡£¡£¡£


½«ÈκÎHTTPÁ÷Á¿Öض¨Ïòµ½Äú×Ô¼ºµÄWebЧÀÍÆ÷¡£ ¡£¡£¡£¡£


ÖØ¶¨Ïòµ½ÌØÖƵÄlocalhost URL£¬£¬£¬¸ÃURLÔÚAxisÖÐÆô¶¯Ð§ÀÍ¡£ ¡£¡£¡£¡£


´¥·¢HTTPÇëÇóÒÔÖØ¶¨ÏòÇëÇó¡°StockQuoteService.jws¡±¡£ ¡£¡£¡£¡£


Îó²îʹÓÃÀÖ³ÉÈçÏÂͼ£º

 

ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾


ÐÞ¸´½¨Òé


ÈôÊÇÕýÔÚʹÓÃAxis£¬£¬£¬¿ÉÒÔɾ³ýAxis¸ùĿ¼ÖÐStockQuoteService.jwsÎļþ¡£ ¡£¡£¡£¡£
È·±£ÔÚAxis»òAxis2ÖÐÔËÐеÄÈκοâ»òЧÀͲ»±£´æÍâÁªµÄHTTP/HTTPSÇëÇó¡£ ¡£¡£¡£¡£
Apache Axis2µÄÏÂÔØµØµãΪ£º

http://axis.apache.org/axis2/java/core/download.html


²Î¿¼Á´½Ó


https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/