¡¾ºÚ¿Í×·»÷¡¿¾³ÍâºÚ¿Í×éÖ¯ÌáÇ°Ðж¯£¬Ãé×¼ÎÒ¹ú¹«Ë¾ÊµÊ©ÍøÂç¹¥»÷

Ðû²¼Ê±¼ä 2020-02-09

Ò»¡¢ºÚ¿Í×îй¥»÷¶¯Ïò


½üÈÕ£¬¾³ÍâºÚ¿Í×éÖ¯£¨°üÂÞÄäÃûÕß×éÖ¯ÔÚÄڵĶà¸öºÚ¿Í×éÖ¯×é³ÉµÄºÚ¿ÍÁªÃË£©Éù³Æ½«ÓÚ2020Äê2ÔÂ13ÈÕÕë¶ÔÎÒ¹úÊÓƵ¼à¿ØϵͳʵʩÍøÂç¹¥»÷ÆÆ»µ»î¶¯£¬²¢Ðû²¼ÁËÆäÒÑÕÆÎÕµÄÒ»ÅúÔÚÏßÊÓƵ¼à¿ØϵͳµÄ¾³ÄÚIPµØÖ·£¬¸ÃÉùÃ÷ÒýÆðÁËÍøÂçÄþ¾²ÒµÄڵĸ߶ȹØ×¢¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶«É­Æ½Ì¨ADLab×·×ÙÁ˸Ã×éÖ¯ÔÚPastebinÉϵÄÏà¹Ø¹¥»÷»î¶¯¼Ç¼£¬·¢ÏÖÆäÀúÊ·ÉÏÔø¶à´Î½«¹¥»÷Ä¿±êËø¶¨ÖÁÎÒ¹úµÄÕþ¸®ºÍÆóÒµÍøÕ¾¡£


¹¥»÷ÀÖ³ÉÔò»áչʾ¸Ã×éÖ¯µÄÏà¹Ø¹¥»÷Ò³Ãæ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖµµÃ×¢ÒâµÄÊÇ£¬ËäÈ»¾àÀëºÚ¿ÍÐû³ÆµÄ¹¥»÷ÈÕÆÚ»¹ÓÐÊýÈÕ£¬µ«ºÚ¿Í×éÖ¯ÒѾ­¿ªÊ¼ÌᳫÐж¯¡£2020Äê2ÔÂ9ÈÕÁ賿4ʱ£¬¸ÃÍÅ»ïÔÙ´ÎÐû²¼ÍÆÎÄÐû²¼ÁËÆäÕë¶ÔÖйúijº£Ô˼¯ÍŹ«Ë¾ÍøÕ¾½øÐеÄÉø͸¹¥»÷»î¶¯¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶«É­Æ½Ì¨ADLabÄþ¾²Ñо¿ÈËԱѸËÙ¶Ô¸Ãʼþ½øÐÐÁË·ÖÎö£¬¹¥»÷Êý¾ÝÏÔʾ¸ÃÍøÕ¾¿ÉÄÜ´æÔÚoracle©¶´CVE-2012-1675£¬ºÚ¿ÍÀûÓø鶴½øÐеĹ¥»÷¿ÉÒÔµ¼ÖÂoracle×é¼þºÍºÏ·¨Êý¾Ý¿âÖ®¼äÔâµ½ÖмäÈ˹¥»÷¡¢»á»°½Ù³Ö»ò¾Ü¾ø·þÎñ¹¥»÷µÈ£¬ÐèÒªÒýÆðÏà¹ØÆóÒµµÄ¸ß¶ÈÖØÊÓ¡£


¶þ¡¢¹¥»÷ϸ½Ú·ÖÎö


ÎÒÃǴӺڿ͵ÄPastebinչʾҳÃæÖз¢ÏÖÁ˴˴ι¥»÷µÄ²¿ÃÅÊý¾Ý£¬¸ÃÍÅ»ïͨ¹ý±©Á¦²Â½â¡¢Â©¶´ÀûÓõȷ½Ê½×îÖÕÓпÉÄÜÇÔÈ¡µ½Ä¿±êµÄoracleÊý¾Ý¿âÊý¾Ý£¬Ïà¹Ø¹¥»÷Á÷³ÌÈçÏ£º


¹¥»÷ÍÅ»ïÊ×ÏÈÀûÓÃnmap¹¤¾ßÕë¶ÔÄ¿±êÍøÕ¾½øÐÐɨÃ裬»ñÈ¡µ½Ä¿±ê·þÎñÆ÷µÄÏà¹ØÖ¸ÎÆÐÅÏ¢¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ä¿±ê·þÎñÆ÷¿ªÆôÁËoracleÊý¾Ý¿âµÄĬÈϼàÌý¶Ë¿Ú1521£¬ÇÒÊý¾Ý¿âÏàÓ¦°æ±¾½ÏµÍ£¬¿ÉÄÜ´æÔÚÖî¶à©¶´£¬ÕâÒ²¸øÁ˹¥»÷ÍÅ»ï¿É³ËÖ®»ú£¨1521¶Ë¿ÚÊÇoracleÊý¾Ý¿âĬÈϵĶ˿Ú£¬Ö÷Òª×÷ÓÃÊÇÓÃÀ´¼àÌýÀ´×Ô¿Í»§¶ËµÄÊý¾Ý¿âÁ´½ÓÇëÇ󣩡£


¹¥»÷ÍÅ»ï½øÒ»²½Õë¶Ô1521¶Ë¿ÚµÄoracle Êý¾Ý¿âʵʩÁËÉø͸²âÊԺ͹¥»÷£¬¹¥»÷¹ý³ÌÖй²Ê¹Óõ½Á½¸ö¿ªÔ´µÄoracleÉø͸²âÊÔÏîÄ¿£¨odat¹¥»÷¿ò¼Ü½øÐÐÔ¶³Ì²âÊÔOracleÊý¾Ý¿âµÄÄþ¾²ÐÔ ; oracle-tns-poison½øÐй¥»÷Ͷ¶¾£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2.1 ÀûÓÃodat¹¥»÷¿ò¼Ü½øÐÐÄþ¾²ÐÔ²âÊÔ


Ê×ÏÈ£¬¹¥»÷Õßͨ¹ýodat¹¥»÷¿ò¼ÜÁ¬½ÓÖÁÄ¿±êoracleÊý¾Ý¿â£¬²¢½øÒ»²½Í¨¹ýPasswordGuesserÄ£¿é½øÐб©Á¦²Â½â¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͬʱ̽²âµ½µ±Ç°oracle°æ±¾¿ÉÄÜ´æÔÚTNS poisoning (CVE-2012-1675)©¶´¹¥»÷¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹¥»÷ÍÅ»ï½øÒ»²½Í¨¹ýMetasploit5Éø͸²âÊÔ¿ò¼ÜµÄtnspoison_checkerÄ£¿é¶Ôoracle½øÐÐÁË©¶´¼ì¿¼ÊÔÖ¤¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


·µ»ØÐÅÏ¢±íÃ÷´æÔÚCVE-2012-1675©¶´£¬²¢½øÒ»²½»ñÈ¡µ½oracleµÄOracle System ID(SID£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2.2 ͨ¹ýoracle-tns-poisonÏîĿʵʩͶ¶¾¹¥»÷


¹¥»÷¹²·ÖΪÈý¸ö²½Ö裺


£¨1£©Í¨¹ýcheck_tns_poisonÄ£¿éÔÙ´ÎÑé֤©¶´µÄ¿ÉÓÃÐÔ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨2£©Í¨¹ýproxyÄ£¿é½«Ô¶³Ì·þÎñÆ÷µÄoracleÊý¾ÝÊðÀíת·¢ÖÁµ±µØ¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


£¨3£©Ö´ÐÐtnspoisonv1Ä£¿é£¬Õë¶ÔÄ¿±êÊý¾Ý¿â½øÐÐͶ¶¾¹¥»÷£¨CVE-2012-1675£©¡£


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2.3 CVE-2012-1675©¶´½éÉÜ


CVE-2012-1675©¶´ÊÇOracleÔÊÐí¹¥»÷ÕßÔÚ²»ÌṩÓû§Ãû¼°ÃÜÂëµÄÇé¿öÏ£¬ÏòÔ¶³Ì¡°TNS Listener¡±×é¼þ´¦ÖõÄÊý¾ÝͶ¶¾µÄ©¶´¡£¹¥»÷Õß¿ÉÀûÓ鶴½«Êý¾Ý¿â·þÎñÆ÷µÄºÏ·¨¡°TNS Listener¡±×é¼þÖеÄÊý¾Ýת·¢¸ø¹¥»÷Õߵĵ±µØϵͳ£¬Ôì³É×é¼þºÍºÏ·¨Êý¾Ý¿âÖ®¼äµÄÖмäÈ˹¥»÷¡¢»á»°½Ù³Ö»ò¾Ü¾ø·þÎñ¹¥»÷£¬Ïà¹ØʾÒâͼÈçÏ£º


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¡ôÏà¹Ø·À»¤ºÍÐÞ¸´½¨Òé


½¨Á¢×㹻ǿ½¡µÄ¿ÚÁÇÐÎðʹÓÃ8λÒÔÏÂÃÜÂë»ò×Öµä¿âÖеĿÚÁ¶¨ÆÚ¸ü»»Äþ¾²ÃÜÂë½øÐÐÔ¤·À¡£


Õë¶ÔOracle½øÐв¹¶¡Éý¼¶£¨¸üÐÂcpuoct2012-1515893²¹¶¡£©£»×¢Ò⣺¶ÔÓÚcpuoct2012-1515893²¹¶¡ÒªÇó·þÎñÆ÷¶ËºÍÓ¦Ó÷þÎñÆ÷¶ËͬʱÉý¼¶£¬·ñÔòÓ¦ÓÃϵͳ½«ÎÞ·¨·ÃÎÊOracle¡£


ÈôÎÞ·¨¶ÔOracleÉý¼¶£¬Ð蹺Öûò°²×°¾ß±¸ÐéÄâ²¹¶¡¹¦Ð§µÄÊý¾Ý¿âÄþ¾²²úÎ·ÀÖ¹¶ÔCVE-2012-1675¼°ÆäËü©¶´µÄÀûÓá£

¿ÉÕë¶ÔÊý¾Ý¿â½øÐÐÈ«¿â»òÕßÃô¸Ð×ֶμÓÃÜ£¬±£Ö¤¼´Ê¹TNS Listener±»¹¥»÷£¬ºËÐÄÊý¾ÝÒÀ¾É²»»áй¶¡£


Èý¡¢×Ü ½á


ÒÀ¾ÝÄ¿Ç°ÕÆÎÕµÄÇé¿ö£¬¸Ã¾³ÍâºÚ¿Í×éÖ¯Éó¤Éø͸¹¥»÷ºÍ©¶´ÀûÓã¬ÇÒÓпÉÄÜÒѾ­ÕÆÎÕÁË´óÁ¿ÎïÁªÍøÉ豸Äþ¾²Â©¶´£¬²¢¾ß±¸½øÒ»²½ÀûÓõÄÄÜÁ¦¡£ÓÉÓÚ¸Ã×éÖ¯ºã¾ÃÕë¶ÔÎÒ¹ú½øÐй¥»÷£¬Ï£ÍûÏà¹ØÓû§ºÍÆóÒµ¼ÓÇ¿×ÔÉíÍøÂç·çÏÕÅŲéºÍÄþ¾²¼Ó¹ÌÊÂÇ飬½øÒ»²½Ìá¸ß·À»¤Òâʶ£¬¸ß¶È¾¯Ìè¾³ÍâºÚ¿Í×éÖ¯ÏÂÒ»²½¿ÉÄܵĹ¥»÷Ðж¯¡£