CVE-2020-1631| Juniper HTTP/HTTPS·þÎñÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-04-30

0x00 Îó²î¸ÅÊö


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


0x01 Îó²îÏêÇé


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!



2020Äê4ÔÂ28ÈÕ£¬Juniper¹Ù·½Ðû²¼ÁËJunos OS×°±¸»ùÓÚHTTP/HTTPSºÍJ-Web·þÎñ±£´æÍâµØÎļþ°üÀ¨¡¢ÏÂÁî×¢ÈëµÈÇå¾²Îó²îµÄͨ¸æ¡£

Juniper Networks Junos OSÊÇÃÀ¹úÕ°²©ÍøÂ磨Juniper Networks£©¹«Ë¾µÄÒ»Ì×רÓÃÓڸù«Ë¾µÄÓ²¼þ×°±¸µÄÍøÂç²Ù×÷ϵͳ¡£¸Ã²Ù×÷ϵͳÌṩÁËÇå¾²±à³Ì½Ó¿ÚºÍJunos SDK¡£

Junos OS×°±¸µÄJ-Web¡¢WebÉí·ÝÑé֤ģ¿é¡¢¶¯Ì¬VPN£¨DVPN£©£¬ºÍ´øÓÐWebÖØ¶¨ÏòµÄ·À»ðǽÉí·ÝÑéÖ¤¡¢Áã½Ó´¥ÉèÖã¨ZTP£©ËùʹÓõÄHTTP/HTTPS·þÎñÖб£´æÇå¾²Îó²î£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÖ´ÐÐÍâµØÎļþ°üÀ¨£¨LFI£©»ò·¾¶±éÀú¡£

¹¥»÷Õß¿ÉÄÜͨ¹ý½«ÏÂÁî×¢Èëµ½httpd.logÈÕÖ¾ÖУ¬ÒÔ¾ßÓС°world¡±¿É¶ÁÎļþµÄȨÏÞ¶ÁÈ¡Îļþ£¬»òÕß»ñÈ¡J-Web»á»°ÁîÅÆ¡£

ÔÚÏÂÁî×¢ÈëµÄÇéÐÎÏ£¬ÓÉÓÚHTTP·þÎñÒÔ¡°nobody¡±Óû§Éí·ÝÔËÐУ¬ÒÔÊÇÓ°ÏìÊÇÓÐÏ޵ģ¬CVSSÆÀ·Ö5.3¡£

ÔÚJunos OS 19.3R1¼°¸ü¸ß°æ±¾ÖУ¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½«Äܹ»Í¨¹ý¾ßÓС°world¡±¿É¶ÁȨÏÞ¶ÁÈ¡ÉèÖÃÎļþ£¬CVSSÆÀ·Ö5.9¡£

ÈôÊÇÆôÓÃJ-Web£¬¹¥»÷Õß¿ÉÒÔ»ñµÃÓëµÇ¼J-WebµÄÈκÎÈËÏàͬµÄ»á¼û¼¶±ð¡£ÈôÊÇÖÎÀíÔ±µÇ¼£¬Ôò¹¥»÷Õß¿ÉÒÔ»ñµÃÖÎÀíÔ±¶ÔJ-WebµÄ»á¼ûȨÏÞ£¬CVSSÆÀ·Ö8.8¡£


0x02 ´¦Öóͷ£½¨Òé


ʵʱÏÂÔØ²¢×°ÖøüгÌÐòºÍ²¹¶¡£¬ÏÂÔØÁ´½Ó£ºhttps://www.juniper.net/support/downloads/¡£

ÔÝʱ²½·¥£º

¸ÃÎó²îÖ÷ÒªÓ°ÏìÆôÓÃÁËHTTP/HTTPS·þÎñµÄJuniper Networks Junos OS×°±¸£¬½ûÓÃHTTP/HTTPS·þÎñµÄJunos OS×°±¸²»ÊÜÓ°Ïì¡£

¿ÉÒÔͨ¹ýÒÔÏÂÏÂÁîÈ·ÈÏhttpdÊÇ·ñÆô¶¯£º

user@device> show system processes | match http

5260 - S 0:00.13 /usr/sbin/httpd-gk -N

5797 - I 0:00.10 /usr/sbin/httpd--config /jail/var/etc/httpd.conf

ÈôÊÇ¿´µ½Àú³Ì±£´æ£¬ÔòÌåÏÖ·þÎñÆô¶¯¡£

ͬʱ¿ÉÒÔÅŲéÈÕÖ¾ÖÐÊÇ·ñÒѾ­±£´æÊ¹ÓÃÕâÒ»Îó²îµÄ¹¥»÷ʵÑ飬ÏÂÁîʾÀý£º

user@device> show log httpd.log | match "=*;*&|=*%3b*&"

user@device> show log httpd.log.0.gz | match "=*;*&|=*%3b*&"

user@device> show log httpd.log.1.gz | match "=*;*&|=*%3b*&"

ÈôÊÇ·¢Ã÷ÓÐ"=*;*&"»ò"*%3b*&"ÌØÕ÷£¬¿ÉÄÜÌåÏÖÓÐʵÑé¹¥»÷ÐÐΪÒѾ­±¬·¢£¬½¨Ò龡¿ìÉý¼¶×°±¸²¢×öÖÜÈ«ÍþвÆÊÎö£¬Í¬Ê±¹¥»÷ÕßÒ²¿ÉÄÜ»áÕûÀíÈÕÖ¾Ïû³ý¹¥»÷ºÛ¼£¡£

»ùÓÚHTTP/HTTPS·þÎñÏà¹ØÉèÖýÚʾÀý²Î¿¼£º

[system services web-management http]

[system services web-management https]

[security dynamic-vpn]


0x03 Ïà¹ØÐÂÎÅ


https://www.securezoo.com/2020/04/juniper-releases-out-of-band-security-update-to-fix-vulnerability-in-j-web-and-web-based-services/


0x04 ²Î¿¼Á´½Ó


https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11021


0x05 ʱ¼äÏß


2020-04-28 Juniper¹Ù·½Ðû²¼Îó²îͨ¸æ

2020-04-29  VSRCÐû²¼Îó²îͨ¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!