¡¾Â©¶´Í¨¸æ¡¿Kaseya VSA 7Ô¶à¸öÄþ¾²Â©¶´

Ðû²¼Ê±¼ä 2021-07-12

0x00 ©¶´¸ÅÊö

Kaseya VSAÊÇÍйܷþÎñÌṩÉÌ (MSP) ³£ÓÃÀ´¹ÜÀí¿Í»§ÍøÂçµÄ RMM£¨Ô¶³Ì¼à¿ØºÍ¹ÜÀí£©Èí¼þ¡£

2021Äê7ÔÂ11ÈÕ£¬KaseyaÐû²¼VSA 9.5.7a (9.5.7.2994)µÄÄþ¾²¸üУ¬ÐÞ¸´ÁËCVE-2021-30116¡¢CVE-2021-30119 ºÍ CVE-2021-30120©¶´£¬ÒÔ¼°»á»° cookie δʹÓÃÄþ¾²±êÖ¾¡¢±©Á¦ÆÆ½âºÍÎļþÉÏ´«µÈÎÊÌâ¡£

 

0x01 ©¶´ÏêÇé

image.png

½ñÄê4Ô£¬ºÉÀ¼Â©¶´Åû¶Ñо¿Ëù (DIVD) Ïò Kaseya Åû¶ÁËÆß¸ö©¶´£º

CVE-2021-30116£ºÐÅϢй¶©¶´£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£

CVE-2021-30117£ºSQL ×¢Èë©¶´£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡ÖÐÐÞ¸´¡££¨VSA 9.5.6£©

CVE-2021-30118£ºÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÒÑÔÚ 4 Ô 10 ÈյIJ¹¶¡ÖÐÐÞ¸´¡£(v9.5.5)

CVE-2021-30119£ºXSS©¶´£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£

CVE-2021-30120 £º2FA ÈÆ¹ý©¶´£¬Ó°Ïì9.5.7 ֮ǰµÄ°æ±¾¡£

CVE-2021-30121£ºµ±µØÎļþ°üÂÞ©¶´£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡ÖÐÐÞ¸´¡££¨VSA 9.5.6£©

CVE-2021-30201£ºXML ÍⲿʵÌå©¶´£¬ÒÑÔÚ 5 Ô 8 ÈյIJ¹¶¡ÖÐÐÞ¸´¡££¨VSA 9.5.6£©

 

ʼþÏêÇé

2021Äê7ÔÂ2ÈÕ£¬REvil ÍÅ»ïÀûÓà Kaseya VSA Èí¼þÖеÄÄþ¾²Â©¶´Õë¶ÔÈ«Çò¶à¸öMSP¼°Æä¿Í»§Ìᳫ¹©Ó¦Á´¹¥»÷¡£¾ÝÌåÏÖ£¬¹¥»÷Õß¿ÉÄܵ¥¶ÀÀûÓûò×éºÏÀûÓÃÁËCVE-2021-30116¡¢CVE-2021-30119 ºÍ CVE-2021-30120£¬ÒÔÈÆ¹ýÈÏÖ¤²¢ÔËÐÐÈÎÒâÃüÁî¡£

×÷ΪÏìÓ¦£¬Kaseya½¨ÒéÁ¢¼´¹Ø±ÕVSA ·þÎñÆ÷¡£Ö®ºó£¬¿É´ÓInternet ·ÃÎ浀 Kaseya VSA ʵÀýÊýÁ¿ÒÑ´Ó2200 ¶à¸öϽµµ½²»µ½ 140 ¸ö¡£

image.png

ʺó£¬KaseyaÌåÏÖ£¬REvil¹©Ó¦Á´ÀÕË÷Èí¼þ¹¥»÷ÈëÇÖÁËÔ¼60¸öʹÓøù«Ë¾VSAÄÚ²¿²úÎïµÄ¿Í»§µÄϵͳ£¬Êܺ¦Õß½ü1500Ãû£¬ÒòΪËûÃǵÄÍøÂçÊÇÓÉMSPʹÓÃKaseyaÔ¶³Ì¹ÜÀí¹¤¾ß¹ÜÀíµÄ¡£´ËÍ⣬RevilµÄ¹¥»÷ÕßÊÇͨ¹ýVSA ²úÎ﹦Ч²¿ÊðÀÕË÷Èí¼þµÄ£¬Ä¿Ç°Ã»ÓÐÖ¤¾Ý±íÃ÷ Kaseya µÄ VSA ´úÂë¿âÒѱ»¸Ä¶¯¡£

REvilÉù³ÆÒѾ­¼ÓÃÜÁËÁè¼Ý 1,000,000 ¸öϵͳ£¬×î³õÆäÒªÇó 7000 ÍòÃÀÔªµÄÊê½ð£¬ÏÖÔÚÒªÇó 5000 ÍòÃÀÔª¹ºÖÃͨÓýâÃÜÆ÷¡£

 

Ó°Ï췶Χ

Kaseya VSA < 9.5.7a

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬½¨ÒéÉý¼¶ÖÁVSA 9.5.7a (9.5.7.2994) °æ±¾¡£

ÆäËü´ëÊ©

1.Kaseya ¶Ø´Ù¿Í»§ÔÚ°²×°¸üÐÂ֮ǰ×ñÑ­¡°µ±µØ VSA Æô¶¯×¼±¸Ö¸ÄÏ¡±²½Ö裬ÒÔ·ÀÖ¹¹¥»÷ÐÐΪ¡£ÒÔÏÂÊǹÜÀíÔ±ÔÚÔÙ´ÎÆô¶¯ VSA ·þÎñÆ÷²¢½«ËüÃÇÁ¬½Óµ½ Internet ֮ǰӦ¸ÃÖ´ÐеĻù±¾²½Ö裺£¨Öص㣺²»ÄÜ´Ó Internet ¹ûÈ»·ÃÎʵ±µØ VSA ·þÎñÆ÷£©

l  È·±£ÄúµÄ VSA ·þÎñÆ÷ÊǸôÀëµÄ £»

l  ¼ì²éϵͳµÄÍ×Эָ±ê (IOC)  £»

l  °²×°VSA·þÎñÆ÷²Ù×÷ϵͳ²¹¶¡ £»

l  ʹÓà URL Rewrite ¿ØÖÆÍ¨¹ý IIS ¶Ô VSA µÄ·ÃÎÊ £»

l  °²×° FireEye ÊðÀí £»

l  ɾ³ý¹ÒÆðµÄ½Å±¾/×÷Òµ¡£

 

2.´ËÍ⣬Kaseya »¹¶Ø´Ù¿Í»§Ê¹ÓÃËûÃǵÄPowerShell ½Å±¾µÄ¡°ÈëÇÖ¼ì²â¹¤¾ß¡±À´¼ì²â VSA ·þÎñÆ÷»ò¶ËµãÊÇ·ñÒѱ»ÈëÇÖ£º½Å±¾½«¼ì²é VSA ·þÎñÆ÷ÊÇ·ñ´æÔÚ¡°Kaseya\webpages\managedfiles\vsaticketfiles\agent.crt¡±ºÍ¡°Kaseya\webpages\managedfiles\vsaticketfiles\agent.exe¡±ÒÔ¼°¡°agent.crt¡±ºÍ¡°agent.exe¡±Ôڶ˵ãÉÏ¡££¨×¢£ºREvil ÍÅ»ïʹÓà agent.crt ºÍ agent.exe ÎļþÀ´²¿Êð REvil ÀÕË÷Èí¼þ¿ÉÖ´ÐÐÎļþ£©¡£

 

3. ΪÁËÌá¸ßÄþ¾²ÐÔ£¬Kaseya »¹½¨ÒéÄÚ²¿²¿ÊðµÄ VSA ¹ÜÀíÔ±½«¶Ô Web GUI µÄ·ÃÎÊȨÏÞÏÞÖÆÎªµ±µØ IP µØÖ·ºÍÒÑÖªÄþ¾²²úÎïʹÓÃµÄ IP µØÖ·¡£

 

ÏÂÔØÁ´½Ó£º

https://helpdesk.kaseya.com/hc/en-gb/articles/4403785889041

https://kaseya.app.box.com/s/0ysvgss7w48nxh8k1xt7fqhbcjxhas40

 

0x03 ²Î¿¼Á´½Ó

https://helpdesk.kaseya.com/hc/en-gb/articles/4403785889041

https://mp.weixin.qq.com/s/aoSf0HFH7lOz6bGXGKboNg

https://www.bleepingcomputer.com/news/security/kaseya-patches-vsa-vulnerabilities-used-in-revil-ransomware-attack/

 

0x04 ¸üа汾

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2021-07-12

Ê×´ÎÐû²¼

 

0x05 Îĵµ¸½Â¼

CNVD£ºwww.cnvd.org.cn

CNNVD£ºwww.cnnvd.org.cn

CVE£ºcve.mitre.org

NVD£ºnvd.nist.gov

CVSS£ºwww.first.org

 

0x06 ¹ØÓÚ¶«É­Æ½Ì¨

¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡¸ü¶à×ÊѶ£º

image.png         image.png