RedisδÊÚȨ»á¼ûÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚRedis 2.x £¬3.x £¬4.x £¬5.x ¡£


Îó²î¸ÅÊö


RedisÊÇÃÀ¹úRedisLabs¹«Ë¾ÔÞÖúµÄÒ»Ì׿ªÔ´µÄʹÓÃANSIC±àд¡¢Ö§³ÖÍøÂç¡¢¿É»ùÓÚÄÚ´æÒà¿É³¤ÆÚ»¯µÄÈÕÖ¾ÐÍ¡¢¼üÖµ£¨Key-Value£©´æ´¢Êý¾Ý¿â £¬²¢Ìṩ¶àÖÖÓïÑÔµÄAPI ¡£


RedisÖб£´æÎ´ÊÚȨ»á¼ûÎó²î £¬¸ÃÎó²îÔ´ÓÚÔÚReids 4.x¼°ÒÔÉϰ汾ÖÐÐÂÔöÁËÄ£¿é¹¦Ð§ £¬¹¥»÷Õß¿Éͨ¹ýÍâ²¿ÍØÕ¹ £¬ÔÚ redisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁî ¡£¹¥»÷Õß¿ÉÒÔʹÓøù¦Ð§ÒýÈëÄ£¿é £¬Ê¹±»¹¥»÷·þÎñÆ÷ÖмÓÔØ¶ñÒâµÄ.soÎļþ £¬´Ó¶øÊµÏÖ¶ñÒâ´úÂëÖ´ÐÐ ¡£ÈôRedisΪ4.0ÒÔϰ汾£¨2.x £¬3.x£© £¬Í¬Ê±redis-serverÒÔrootȨÏÞÆô¶¯ £¬Ôò¹¥»÷Õß¿ÉÔÚ·þÎñÆ÷ÉϽ¨Éèí§ÒâÎļþ ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


ÐÞ¸´½¨Òé


1¡¢Õ¥È¡Íⲿ»á¼ûRedis·þÎñ¶Ë¿Ú£»
2¡¢Õ¥È¡Ê¹ÓÃrootȨÏÞÆô¶¯redis·þÎñ£»

3¡¢ÉèÖÃÇå¾²×é £¬ÏÞÖÆ¿ÉÅþÁ¬Redis·þÎñÆ÷µÄIP ¡£


²Î¿¼Á´½Ó


https://2018.zeronights.ru/wp-content/uploads/materials/15-redis-post-exploitation.pdf