΢ÈíIE 0DAY XXEÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-04-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


IE 11 £¬£¬£¬£¬£¬£¬£¬Ó°Ïì Windows 7¡¢10ºÍ Server 2012 R2 °æ±¾


Îó²î¸ÅÊö


Ñо¿Ö°Ô±John Page¹ûÕæÁËÒ»¸ö¿Éµ¼ÖºڿʹÓWindowsϵͳÖÐÇÔÈ¡ÎļþµÄ IE ä¯ÀÀÆ÷ 0day Îó²îµÄÏêÇéºÍ PoC ´úÂë ¡£¡£¡£¡£¡£¡£¸ÃÎó²îΪ±£´æÓÚ IE 11 ÖеÄXXEÍⲿʵÌå×¢ÈëÎó²î £¬£¬£¬£¬£¬£¬£¬±£´æÓÚ IE ´¦Öóͷ£ MHT ÎļþµÄ·½·¨ÖÐ £¬£¬£¬£¬£¬£¬£¬Ó°Ïì Windows 7¡¢10ºÍ Server 2012 R2 °æ±¾ ¡£¡£¡£¡£¡£¡£


MHT¼´¡°MHTML Web Archive¡± £¬£¬£¬£¬£¬£¬£¬ÊÇËùÓÐ IE ä¯ÀÀÆ÷¼á³ÖÍøÒ³£¨µã»÷ CTRL+S£©µÄĬÈϱê×¼ ¡£¡£¡£¡£¡£¡£ËäÈ»ÏÖ´úä¯ÀÀÆ÷²»ÔÙÒÔ MHT ÃûÌÃÉúÑÄÍøÒ³ £¬£¬£¬£¬£¬£¬£¬¶øÊÇʹÓñê×¼µÄ HTML ÎļþÃûÌà £¬£¬£¬£¬£¬£¬£¬È»¶øÐí¶àÏÖ´úä¯ÀÀÆ÷ÈÔȻ֧³Ö´¦Öóͷ£¸ÃÃûÌà ¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


Page ÌåÏÖ £¬£¬£¬£¬£¬£¬£¬IEä¯ÀÀÆ÷Ò×ÊÜXMLÍⲿʵÌå¹¥»÷ £¬£¬£¬£¬£¬£¬£¬Ìõ¼þÊÇÓû§ÔÚÍâµØ·­¿ªÒ»¸öÌØÊâ½á¹¹µÄ .MHT Îļþ ¡£¡£¡£¡£¡£¡£

Ëü¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÇÔÈ¡ÍâµØÎļþ²¢Ô¶³ÌÕì̽ÍâµØ×°ÖõijÌÐò°æ±¾ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£ÀýÈç £¬£¬£¬£¬£¬£¬£¬¡±c:\python27\NEWS.txt¡±µÄÇëÇó¿É»á¼û¸Ã³ÌÐòµÄ°æ±¾ÐÅÏ¢ ¡£¡£¡£¡£¡£¡£


ÍâµØ·­¿ª¶ñÒâ¡°.MHT¡±Îļþºó £¬£¬£¬£¬£¬£¬£¬ËüÓ¦¸Ã»áÆô¶¯ IE ä¯ÀÀÆ÷ ¡£¡£¡£¡£¡£¡£Ö®ºó £¬£¬£¬£¬£¬£¬£¬Óû§½»»¥ÈçÖØ¸´Ñ¡Ï¡°Ctrl+K¡± ¡£¡£¡£¡£¡£¡£ÆäËü½»»¥ÈçÓÒ»÷ÍøÒ³Éϵġ°´òÓ¡Ô¤ÀÀ¡±»ò¡°´òÓ¡¡±ÏÂÁî¿ÉÄܻᴥ·¢Õâ¸öXXE Îó²î ¡£¡£¡£¡£¡£¡£


È»¶ø¶Ôwindow.print() £¬£¬£¬£¬£¬£¬£¬Javascript º¯ÊýµÄ¼òÆÓŲÓÿÉÔÚÎÞÐèÓû§ºÍÍøÒ³½»»¥µÄÇéÐÎÏÂʵÑé¹¥»÷ ¡£¡£¡£¡£¡£¡£Ö÷ÒªµÄÊÇ £¬£¬£¬£¬£¬£¬£¬ÈôÊÇÎļþÊÇ´ÓÍøÂçÒÔѹËõÎĵµµÄÐÎʽÏÂÔØ²¢Ê¹ÓÃijÖִ浵ʹÓóÌÐò MOTW ·­¿ªµÄ £¬£¬£¬£¬£¬£¬£¬ÄÇô¿ÉÄܾͲ»»áÆð×÷Óà ¡£¡£¡£¡£¡£¡£


ͨ³£ÔÚʵÀý»¯ActiveX Objects Èç¡°Microsoft.XMLHTTP¡±Ê± £¬£¬£¬£¬£¬£¬£¬Óû§½«»áÔÚ IE Öп´µ½Çå¾²À¸ÖÒÑÔ²¢±»ÌáÐѼ¤»î±»×èÖ¹µÄÄÚÈÝ ¡£¡£¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬£¬£¬µ±·­¿ªÊ¹ÓöñÒâ<xml>±ê¼Ç·­¿ªÌØÊâ½á¹¹µÄ .MHT Îļþʱ £¬£¬£¬£¬£¬£¬£¬Óû§½«ÎÞ·¨»ñµÃ´ËÀà»î¶¯ÄÚÈÝ»òÇå¾²À¸ÖÒÑÔ ¡£¡£¡£¡£¡£¡£


ÀýÈ磺

C:\sec>python -m SimpleHTTPServer
Serving HTTP on 0.0.0.0 port 8000 ...
127.0.0.1 - - [10/Apr/2019 20:56:28] "GET /datatears.xml HTTP/1.1" 200 -
127.0.0.1 - - [10/Apr/2019 20:56:28] "GET /?;%20for%2016-bit%20app%20support[386Enh]woafont=dosapp.fonEGA80WOA.FON=EGA80WOA.FONEGA40WOA.FON=EGA40WOA.FONCGA80WOA.FON=CGA80WOA.FONCGA40WOA.FON=CGA40WOA.FON[drivers]wave=mmdrv.dlltimer=timer.drv[mci] HTTP/1.1" 200 -
PageÔÚ×°ÖÃÍêÕû²¹¶¡µÄWin7/10 ºÍServer 2012 R2ÉϵÄ×îа汾IE ä¯ÀÀÆ÷°æ±¾V11²âÊÔÀÖ³É ¡£¡£¡£¡£¡£¡£
POC£ºhttp://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt ¡£¡£¡£¡£¡£¡£
POCÊÓÆµ£ºhttps://youtu.be/fbLNbCjgJeY ¡£¡£¡£¡£¡£¡£
´ËPoC´úÂëΪÇÔÈ¡ Windows ¡°system.ini¡±ÎļþµÄ£¨×¢£º¿Éƾ֤ÐèÒª±à¼­¾ç±¾ÖеĹ¥»÷ÕßЧÀÍÆ÷ IP£©
£¨1£©Ê¹Óþ籾½¨Éè¡°datatears.xml¡± XML ºÍǶÈë XXE µÄ¡°msie-xxe-0day.mht¡± MHT Îļþ
£¨2£©Python ¨Cm SimpleHTTPServer
£¨3£©½«ÌìÉúµÄ¡°datatears.xml¡±·ÅÔÚ Python ЧÀÍÆ÷ web-root ÖÐ ¡£¡£¡£¡£¡£¡£

£¨4£©·­¿ªÌìÉúµÄ¡°msie-xxe-0day.mht¡±Îļþ £¬£¬£¬£¬£¬£¬£¬ÊÓ²ìÎļþ½«±»ÇÔÈ¡ ¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ΢ÈíûÓÐÐû²¼²¹¶¡ ¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.zdnet.com/article/internet-explorer-zero-day-lets-hackers-steal-files-from-windows-pcs/
http://hyp3rlinx.altervista.org/advisories/MICROSOFT-INTERNET-EXPLORER-v11-XML-EXTERNAL-ENTITY-INJECTION-0DAY.txt