ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ ื”ืชืงื ื™ ืจืฉืช Juniper ื”ื ืฉืœื—ื™ื ืขื JunOS

ื–ื•ื”ื• ืžืกืคืจ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ J-Web, ื”ืžืฉืžืฉ ื‘ืžื›ืฉื™ืจื™ ืจืฉืช Juniper ื”ืžืฆื•ื™ื“ื™ื ื‘ืžืขืจื›ืช ื”ื”ืคืขืœื” JunOS, ื›ืืฉืจ ื”ืžืกื•ื›ื ืช ืฉื‘ื”ืŸ (CVE-2022-22241) ืžืืคืฉืจืช ืœืš ืœื‘ืฆืข ืžืจื—ื•ืง ืืช ื”ืงื•ื“ ืฉืœืš ื‘ืžืขืจื›ืช ืœืœื ืื™ืžื•ืช ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช HTTP ืฉืชื•ื›ื ื ื” ื‘ืžื™ื•ื—ื“. ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ื ื‘ืฆื™ื•ื“ ื’'ื•ื ื™ืคืจ ืœื”ืชืงื™ืŸ ืขื“ื›ื•ื ื™ ืงื•ืฉื—ื”, ื•ืื ื”ื“ื‘ืจ ืื™ื ื• ืืคืฉืจื™, ืœื•ื•ื“ื ืฉื”ื’ื™ืฉื” ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ื—ืกื•ืžื” ืžืจืฉืชื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื•ืžื•ื’ื‘ืœืช ืœืžืืจื—ื™ื ืžื”ื™ืžื ื™ื ื‘ืœื‘ื“.

ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื ืชื™ื‘ ื”ืงื•ื‘ืฅ ืฉืขื•ื‘ืจ ื”ืžืฉืชืžืฉ ืžืขื•ื‘ื“ ื‘ืกืงืจื™ืคื˜ /jsdm/ajax/logging_browse.php ืžื‘ืœื™ ืœืกื ืŸ ืืช ื”ืงื™ื“ื•ืžืช ืขื ืกื•ื’ ื”ืชื•ื›ืŸ ื‘ืฉืœื‘ ืฉืœืคื ื™ ื‘ื“ื™ืงืช ื”ืื™ืžื•ืช. ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืขื‘ื™ืจ ืงื•ื‘ืฅ phar ื–ื“ื•ื ื™ ื‘ืžืกื•ื•ื” ืฉืœ ืชืžื•ื ื” ื•ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ื”-PHP ื”ืžืžื•ืงื ื‘ืืจื›ื™ื•ืŸ ื”-phar ื‘ืืžืฆืขื•ืช ืฉื™ื˜ืช ื”ืชืงืคืช "Phar deserialization" (ืœื“ื•ื’ืžื”, ืฆื™ื•ืŸ "filepath=phar:/path/pharfile.jpg " ื‘ื‘ืงืฉื”).

ื”ื‘ืขื™ื” ื”ื™ื ืฉื›ืืฉืจ ื‘ื•ื“ืงื™ื ืงื•ื‘ืฅ ืฉื”ื•ืขืœื” ื‘ืืžืฆืขื•ืช ืคื•ื ืงืฆื™ื™ืช ื”-PHP is_dir(), ืคื•ื ืงืฆื™ื” ื–ื• ืžื‘ื˜ืœืช ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ืืช ื”ืžื˜ื-ื ืชื•ื ื™ื ืžืืจื›ื™ื•ืŸ ื”-Phar ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื™ื‘ื™ื ื”ืžืชื—ื™ืœื™ื ื‘-"phar://". ืืคืงื˜ ื“ื•ืžื” ื ืฆืคื” ื‘ืขืช ืขื™ื‘ื•ื“ ื ืชื™ื‘ื™ ืงื‘ืฆื™ื ืฉืกื•ืคืงื• ืขืœ ื™ื“ื™ ื”ืžืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื•ืช file_get_contents(), fopen(), file(), file_exists(), md5_file(), filemtime() ื•- filesize().

ื”ื”ืชืงืคื” ืžืกื•ื‘ื›ืช ื‘ืฉืœ ื”ืขื•ื‘ื“ื” ืฉื‘ื ื•ืกืฃ ืœืชื—ื™ืœืช ื”ื‘ื™ืฆื•ืข ืฉืœ ืืจื›ื™ื•ืŸ ื”-Phar, ืขืœ ื”ืชื•ืงืฃ ืœืžืฆื•ื ื“ืจืš ืœื”ื•ืจื™ื“ ืื•ืชื• ืœืžื›ืฉื™ืจ (ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืœ- /jsdm/ajax/logging_browse.php, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืจืง ืืช ื”ื ืชื™ื‘ ืืœ ืœื‘ืฆืข ืงื•ื‘ืฅ ืฉื›ื‘ืจ ืงื™ื™ื). ืชืจื—ื™ืฉื™ื ืืคืฉืจื™ื™ื ืœื›ื ื™ืกืช ืงื‘ืฆื™ื ืœืžื›ืฉื™ืจ ื›ื•ืœืœื™ื ื”ื•ืจื“ืช ืงื•ื‘ืฅ PHAR ื”ืžื—ื•ืคืฉ ืœืชืžื•ื ื” ื“ืจืš ืฉื™ืจื•ืช ื”ืขื‘ืจืช ืชืžื•ื ื•ืช ื•ื”ื—ืœืคืช ื”ืงื•ื‘ืฅ ื‘ืงื•ื‘ืฅ ื”ืฉืžื•ืจ ืฉืœ ืชื•ื›ืŸ ื”ืื™ื ื˜ืจื ื˜.

ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืื—ืจื•ืช:

  • CVE-2022-22242 - ื”ื—ืœืคื” ืฉืœ ืคืจืžื˜ืจื™ื ื—ื™ืฆื•ื ื™ื™ื ืœื ืžืกื•ื ื ื™ื ื‘ืคืœื˜ ืฉืœ ื”ืกืงืจื™ืคื˜ error.php, ื”ืžืืคืฉืจ ืกืงืจื™ืคื˜ื™ื ื‘ื™ืŸ-ืืชืจื™ื ื•ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ JavaScript ืฉืจื™ืจื•ืชื™ ื‘ื“ืคื“ืคืŸ ืฉืœ ื”ืžืฉืชืžืฉ ื‘ืขืช ื‘ื™ืฆื•ืข ืงื™ืฉื•ืจ (ืœื“ื•ื’ืžื”, "https:// JUNOS_IP/error.php?SERVER_NAME= alert(0) " ื”ืคื’ื™ืขื•ืช ืขืœื•ืœื” ืœืฉืžืฉ ื›ื“ื™ ืœื™ื™ืจื˜ ืคืจืžื˜ืจื™ื ืฉืœ ื”ืคืขืœื” ืฉืœ ืžื ื”ืœ ืžืขืจื›ืช ืื ืชื•ืงืคื™ื ืžืฆืœื™ื—ื™ื ืœื’ืจื•ื ืœืžื ื”ืœ ื”ืžืขืจื›ืช ืœืคืชื•ื— ืงื™ืฉื•ืจ ืฉืชื•ื›ื ืŸ ื‘ืžื™ื•ื—ื“.
  • CVE-2022-22243, CVE-2022-22244 ื”ื—ืœืคืช ื‘ื™ื˜ื•ื™ XPATH ื‘ืืžืฆืขื•ืช jsdm/ajax/wizards/setup/setup.php ื•-/modules/monitor/interfaces/interface.php scripts ืžืืคืฉืจื™ื ืœืžืฉืชืžืฉ ืžืื•ืžืช ืœืœื ื”ืจืฉืื•ืช ืœืชืคืขืœ ื”ืคืขืœื•ืช ื ื™ื”ื•ืœ.
  • CVE-2022-22245 ื—ื•ืกืจ ื—ื™ื˜ื•ื™ ื ืื•ืช ืฉืœ ืจืฆืฃ ".." ื‘ื ืชื™ื‘ื™ื ื”ืžืขื•ื‘ื“ื™ื ื‘ืกืงืจื™ืคื˜ Upload.php ืžืืคืฉืจ ืœืžืฉืชืžืฉ ืžืื•ืžืช ืœื”ืขืœื•ืช ืืช ืงื•ื‘ืฅ ื”-PHP ืฉืœื• ืœืกืคืจื™ื™ื” ื”ืžืืคืฉืจืช ืœื”ืคืขื™ืœ ืกืงืจื™ืคื˜ื™ื ืฉืœ PHP (ืœื“ื•ื’ืžื”, ืขืœ ื™ื“ื™ ื”ืขื‘ืจืช ื”ื ืชื™ื‘ "fileName=\. .\..\..\..\www\dir\new\shell.php").
  • CVE-2022-22246 - ืืคืฉืจื•ืช ืœื‘ื™ืฆื•ืข ืงื•ื‘ืฅ PHP ืžืงื•ืžื™ ืฉืจื™ืจื•ืชื™ ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ืžืื•ืžืช ืฉืœ ื”ืกืงืจื™ืคื˜ jrest.php, ืฉื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืคืจืžื˜ืจื™ื ื—ื™ืฆื•ื ื™ื™ื ืœื™ืฆื™ืจืช ืฉื ื”ืงื•ื‘ืฅ ืฉื ื˜ืขืŸ ืขืœ ื™ื“ื™ ื”ืคื•ื ืงืฆื™ื” "require_once()" (ืขื‘ื•ืจ ืœื“ื•ื’ืžื”, "/jrest.php?payload =alol/lol/any\..\..\..\..\any\file")

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”