Citrix | ShareFile¶à¸öÇå¾²Îó²îͨ¸æ

Ðû²¼Ê±¼ä 2020-05-07

0x00 Îó²î¸ÅÊö


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


0x01 Îó²îÏêÇé


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Citrix ShareFileÊÇÃÀ¹ú˼½Üϵͳ£¨Citrix Systems£©¹«Ë¾µÄÒ»Ì×Îļþ¹²Ïí½â¾ö¼Æ»® ¡£¡£¡£ShareFileÊÇÒ»¸ö»ùÓÚÔÆµÄÎļþ¹²ÏíЧÀÍ £¬ £¬£¬£¬£¬£¬£¬Ê¹Óû§Äܹ»ÇáËÉ £¬ £¬£¬£¬£¬£¬£¬Çå¾²µØ½»Á÷Îļþ ¡£¡£¡£ShareFileÄÜÌṩÆóÒµ¼¶Ð§ÀÍ £¬ £¬£¬£¬£¬£¬£¬×é¼þ°üÀ¨StorageZones¿ØÖÆÆ÷ºÍÓû§ÖÎÀí¹¤¾ß ¡£¡£¡£

2020Äê5ÔÂ5ÈÕCitrix¹ÙÍøÐû²¼Í¨¸æÉùÃ÷ £¬ £¬£¬£¬£¬£¬£¬Citrix ShareFile´æ´¢ÇøÓò¿ØÖÆÆ÷Öз¢Ã÷Á˶à¸öÇå¾²Îó²î £¬ £¬£¬£¬£¬£¬£¬Î´¾­ÈÏÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²îÀ´ÈëÇÖ´æ´¢ÇøÓò¿ØÖÆÆ÷ £¬ £¬£¬£¬£¬£¬£¬²¢»á¼ûShareFileÓû§µÄÎĵµºÍÎļþ¼Ð ¡£¡£¡£

з¢Ã÷µÄÇå¾²ÎÊÌâ (CTX-CVE-2020-7473) Ó°ÏìµÄÊǿͻ§ÖÎÀíÍâµØCitrix ShareFile ´æ´¢Çø¿ØÖÆÆ÷ £¬ £¬£¬£¬£¬£¬£¬¸Ã×é¼þÊÜ·À»ðǽ±£»£»£»£»£»¤ £¬ £¬£¬£¬£¬£¬£¬´æ´¢ÆóÒµÊý¾Ý ¡£¡£¡£ÉÏÊö¶à¸öÇå¾²Îó²î°üÀ¨CVE-2020-7473¡¢CVE-2020-8982ºÍCVE-2020-8983 ¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


0x02 ´¦Öóͷ£½¨Òé


ÈôÊÇÄãËùÔÚ¹«Ë¾Ê¹ÓõÄÊÇÍâµØShareFile´æ´¢Çø¿ØÖÆÆ÷°æ±¾5.9.0/5.8.0/5.7.0/5.6.0/5.5.0¼°¸üÔç°æ±¾ £¬ £¬£¬£¬£¬£¬£¬ÔòÊÜÓ°Ïì £¬ £¬£¬£¬£¬£¬£¬²¢½¨ÒéÁ¬Ã¦½«Æ½Ì¨¸üÐÂÖÁ5.10.0/5.9.1/5.8.1»òºóÐø°æ±¾ ¡£¡£¡£

ÔÝʱ²½·¥£º

ÐèÒª×¢ÖØµÄÖ÷ÒªÒ»µãÊÇ£ºÈçÄãµÄ´æ´¢ÇøÊÇÔÚÒÔÉÏÊÜÓ°Ïì°æ±¾ÉϽ¨ÉèµÄ £¬ £¬£¬£¬£¬£¬£¬ÄÇôֻÊǽ«Èí¼þ¸üÐÂÖÁÐÞ¸´°æ±¾½«ÎÞ·¨ÍêÈ«½â¾öÎó²îÎÊÌâ ¡£¡£¡£Îª´Ë £¬ £¬£¬£¬£¬£¬£¬CitrixרÃÅÐû²¼ÁËÒ»¿î»º½â¹¤¾ß £¬ £¬£¬£¬£¬£¬£¬Óû§¿ÉÊ×ÏÈÔÚÖ÷´æ´¢Çø¿ØÖÆÆ÷ÉÏÔËÐÐ £¬ £¬£¬£¬£¬£¬£¬Ö®ºóÔÚ¶þ¼¶¿ØÖÆÆ÷ÉÏÔËÐÐ £¬ £¬£¬£¬£¬£¬£¬¡°Ò»µ©¸Ã¹¤¾ßÔÚÖ÷ÇøÔËÐÐÀÖ³É £¬ £¬£¬£¬£¬£¬£¬ÇëÎð»¹Ô­¸ü¸Ä £¬ £¬£¬£¬£¬£¬£¬²»È»½«µ¼ÖÂÇøÓò²»¿ÉÓà ¡£¡£¡£¡±


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


³ýÁËÍâµØ½â¾ö¼Æ»®Íâ £¬ £¬£¬£¬£¬£¬£¬ShareFile´æ´¢Çø¿ØÖÆÆ÷µÄÔÆ°æ±¾Ò²ÊÜÓ°Ïì £¬ £¬£¬£¬£¬£¬£¬µ«Ë¼½ÜÒÑÐÞ¸´ÕâЩÎÊÌâÇÒÎÞÐèÓû§Ö´ÐÐÈκνøÒ»²½µÄ²Ù×÷ ¡£¡£¡£

×èÖ¹ÏÖÔÚ»¹Ã»ÓйØÓÚÕâЩÎó²îµÄµ×²ãÊÖÒÕÆÊÎö £¬ £¬£¬£¬£¬£¬£¬¿ÉÊÇÆ¾Ö¤²¹¶¡ £¬ £¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±ÆÊÎöÒÔΪÖÁÉÙÓÐÒ»¸öÎó²î¿ÉÄÜλÓÚCitrix SharefileʹÓõÄÀϰ汾ASP.net ToolkitÖÐ ¡£¡£¡£


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


2015Äê·¢Ã÷µÄCVE-2015-4670Îó²î¾ÍÊÇÒ»¸öAjaxControlToolkitµÄĿ¼±éÀúºÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬ £¬£¬£¬£¬£¬£¬Ó°Ïì¶ÔÓ¦µÄShareFileÈí¼þ°æ±¾ ¡£¡£¡£

ΪÁËÈ·¶¨Ä¿½ñCitrix ShareFileʵÏÖÊÇ·ñÊܵ½Ó°Ïì £¬ £¬£¬£¬£¬£¬£¬¿ÉÒÔ»á¼ûÏÂÃæµÄURL £¬ £¬£¬£¬£¬£¬£¬ÈôÊÇÒ³Ãæ·µ»ØÎª¿Õ £¬ £¬£¬£¬£¬£¬£¬¾Í˵Ã÷Êܵ½¸ÃÎó²îµÄÓ°Ïì £¬ £¬£¬£¬£¬£¬£¬ÈôÊÇ·µ»ØµÄÊÇ404¹ýʧ £¬ £¬£¬£¬£¬£¬£¬¾Í˵Ã÷²»ÊܸÃÎó²îµÄÓ°Ïì»òÒѾ­±»ÐÞ¸´ÁË ¡£¡£¡£Á´½ÓΪ£ºhttps://yoursharefileserver.companyname.com/UploadTest.aspx

Ñо¿Ö°Ô±³Æ £¬ £¬£¬£¬£¬£¬£¬CitrixÐû²¼µÄÎó²î»º½â¹¤¾ß»á¶Ôweb.configÎļþ¾ÙÐÐÐÞ¸Ä £¬ £¬£¬£¬£¬£¬£¬Ò²»á´ÓÊÜÓ°ÏìµÄЧÀÍÆ÷ÉÑþ³ØýUploadTest.aspxºÍXmlFeed.aspx ¡£¡£¡£


0x03 Ïà¹ØÐÂÎÅ


https://thehackernews.com/2020/05/citrix-sharefile-vulnerability.html


0x04 ²Î¿¼Á´½Ó


https://support.citrix.com/article/CTX269106


0x05 ʱ¼äÏß


2020-05-05  CitrixÐû²¼Í¨¸æ

2020-05-07  VSRCÐû²¼Îó²îͨ¸æ



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾