¡¸Îó²îͨ¸æ¡¹Junos OS HTTP&HTTPS ·þÎñ¸ßΣÎó²î £¨CVE-2020-1631£©
2020-05-01
Ò»¡¢Îó²î¸ÅÊö
4ÔÂ28ÈÕ£¬Juniper¹Ù·½Ðû²¼Ç徲ͨ¸æÐÞ¸´Juniper Networks Junos OSÖÐJ-WebºÍ»ùÓÚWebµÄ£¨HTTP / HTTPS£©·þÎñÖеÄÎó²î£¨CVE-2020-1631£©£¬Junos OS×°±¸µÄJ-Web·þÎñ¡¢WebÉí·ÝÑé֤ģ¿é¡¢¶¯Ì¬VPN£¨DVPN£©¡¢´øÓÐWebÖØ¶¨ÏòµÄ·À»ðǽÉí·ÝÑéÖ¤¼°Áã½Ó´¥ÉèÖã¨ZTP£©ËùʹÓõÄHTTP/HTTPS·þÎñ½Ó¿Ú±£´æÍâµØÎļþ°üÀ¨£¨LFI£©ºÍ·¾¶±éÀúÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÏòhttpd.logÎļþ×¢ÈëÏÂÁ¶ÁÈ¡Îļþ»ò»ñÈ¡J-Web»á»°ÁîÅÆ¡£½¨ÒéʹÓøÃϵͳµÄÓû§¾¡¿ìÉý¼¶°æ±¾»ò½ÓÄÉ»º½â²½·¥¾ÙÐзÀ»¤¡£
Juniper Networks Junos OSÊÇÃÀ¹úÕ°²©ÍøÂ磨Juniper Networks£©¹«Ë¾µÄÒ»Ì×רÓÃÓڸù«Ë¾µÄÓ²¼þ×°±¸µÄÍøÂç²Ù×÷ϵͳ¡£¸Ã²Ù×÷ϵͳÒÔ¿É¿¿ÐÔ¡¢Çå¾²ÐÔºÍÎÞаÐÔΪ½¹µã£¬ÌṩÁËÇå¾²±à³Ì½Ó¿ÚºÍJunos SDK¡£
²Î¿¼Á´½Ó£º
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA11021
¶þ¡¢Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
- Junos OS 12.3
- Junos OS 12.3X48
- Junos OS 14.1X53
- Junos OS 15.1
- Junos OS 15.1X49
- Junos OS 17.2
- Junos OS 17.3
- Junos OS 17.4
- Junos OS 18.1
- Junos OS 18.2
- Junos OS 18.3
- Junos OS 18.4
- Junos OS 19.1
- Junos OS 19.2
- Junos OS 19.3
- Junos OS 19.4
- Junos OS 20.1
²»ÊÜÓ°Ïì°æ±¾£º
- Junos OS 12.3X48-D101
- Junos OS 12.3X48-D105
- Junos OS 15.1X49-D211
- Junos OS 15.1X49-D220
- Junos OS 15.1R7-S7
- Junos OS 16.1R7-S8
- Junos OS 17.2R3-S4
- Junos OS 17.4R2-S11
- Junos OS 17.3R3-S8
- Junos OS 17.4R3-S2
- Junos OS 18.1R3-S10
- Junos OS 18.2R2-S7
- Junos OS 18.2R3-S4
- Junos OS 18.3R2-S4
- Junos OS 18.3R3-S2
- Junos OS 18.4R1-S7
- Junos OS 18.4R3-S2
- Junos OS 19.1R1-S5
- Junos OS 19.1R3-S1
- Junos OS 19.2R2
- Junos OS 19.3R2-S3
- Junos OS 19.3R3
- Junos OS 19.4R1-S2
- Junos OS 19.4R2
- Junos OS 20.1R1-S1
- Junos OS 20.1R2 and all subsequent releases
Èý¡¢Îó²î¼ì²â
3.1 È˹¤¼ì²â
- Ïà¹ØÓû§¿Éͨ¹ý°æ±¾¼ì²âµÄ·½·¨ÅжÏÄ¿½ñϵͳÊÇ·ñ±£´æÎ£º¦
ʹÓÃÒÔÏÂÏÂÁî¼ì²éJunos OSµÄ°æ±¾ÐÅÏ¢
|
1
|
show version
|

- ¿Éͨ¹ýÒÔÏÂÏÂÁîÉó²éϵͳÊÇ·ñÓÐhttpdÀú³ÌÅжϷþÎñÊÇ·ñÆô¶¯£º
|
1
2
3
|
show system processes | match http
5260 - S 0:00.13 /usr/sbin/httpd-gk –N
5797 - I 0:00.10 /usr/sbin/httpd --config /jail/var/etc/httpd.conf
|
Èô·¢Ã÷Àú³Ì±£´æ£¬ÔòÌåÏÖHTTP / HTTPS·þÎñÒÑÆô¶¯¡£
- ¹¥»÷ÈÕÖ¾ÅŲé
ϵͳÖÎÀíÔ±¿ÉÒÔͨ¹ýʹÓÃÒÔÏÂÏÂÁîÔÚ/var/log/httpd.logÖÐËÑË÷ÌØÕ÷“ =*;*&”»ò“ *%3b*&” ²éÕÒ¹¥»÷ºÛ¼£¡£
|
1
|
show log httpd.log | match "=*;*&|=*%3b*&"
|
ÈôÊÇ´ËÏÂÁî·µ»ØÊä³ö£¬Ôò¿ÉÄܱ£´æ¶ñÒâ¹¥»÷ʵÑé»òɨÃèÔ˶¯£¬¿É¼ÌÐøÊ¹ÓÃÒÔÏÂÏÂÁîÀ´¼ì²éÑ»·ÈÕÖ¾£º
|
1
2
|
show log httpd.log.0.gz | match "=*;*&|=*%3b*&"
show log httpd.log.1.gz | match
$(".info_chag img").each(function () {
$(this).css({ "max-width": "100%","height": "auto","display":"inline-block" }).parent().css({"text-align":"center"});
});
?
ÄúµÄÁªÏµ·½·¨? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ |

¾ÅÓÎÀϸçÔÆ







