ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืคื•ืŸ ื“ื–ืฉื•ื ื™ืคึผืขืจ ื ืขืฅ ื“ืขื•ื•ื™ืกืขืก ืฉื™ืคึผื˜ ืžื™ื˜ JunOS

ืขื˜ืœืขื›ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืื™ืŸ ื“ื™ J-Web ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“, ื•ื•ืึธืก ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ื–ืฉื•ื ื™ืคึผืขืจ ื ืขืฅ ื“ืขื•ื•ื™ืกืขืก ื™ืงื•ื•ื™ืคึผื˜ ืžื™ื˜ ื“ื™ JunOS ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื, ื“ื™ ืžืขืจืกื˜ ื’ืขืคืขืจืœืขืš ืคื•ืŸ ื•ื•ืึธืก (CVE-2022-22241) ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื•ื™ืกืคื™ืจืŸ ื“ื™ื™ืŸ ืงืึธื“ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื. ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฉืœื™ ื“ื™ื–ื™ื™ื ื“ ื”ื˜ื˜ืคึผ ื‘ืขื˜ืŸ. ื™ื•ื–ืขืจื– ืคื•ืŸ ื“ื–ืฉื•ื ื™ืคึผืขืจ ื•ื™ืกืจื™ื›ื˜ ื–ืขื ืขืŸ ืึทื“ื•ื•ื™ื™ื–ื“ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืคื™ืจืžื•ื•ืึทืจืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ, ืื•ืŸ ืื•ื™ื‘ ื“ืึธืก ืื™ื– ื ื™ื˜ ืžืขื’ืœืขืš, ืขื ืฉื•ืจ ืึทื– ืึทืงืกืขืก ืฆื• ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืื™ื– ื‘ืœืึทืงื˜ ืคึฟื•ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ืขื˜ื•ื•ืึธืจืงืก ืื•ืŸ ืœื™ืžื™ื˜ืขื“ ื‘ืœื•ื™ื– ืฆื• ื˜ืจืึทืกื˜ื™ื“ ืžื—ื ื•ืช.

ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทื– ื“ืขืจ ื˜ืขืงืข ื“ืจืš ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ื“ื•ืจืš ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ื– ืคึผืจืึทืกืขืกื˜ ืื™ืŸ ื“ื™ /jsdm/ajax/logging_browse.php ืฉืจื™ืคื˜ ืึธืŸ ืคื™ืœื˜ืขืจื™ื ื’ ื“ื™ ืคึผืจืขืคื™ืงืก ืžื™ื˜ ื“ื™ ืื™ื ื”ืึทืœื˜ ื˜ื™ืคึผ ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ืื™ื™ื“ืขืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื˜ืฉืขืง. ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ื™ื‘ืขืจืฉื™ืงืŸ ืึท ื‘ื™ื™ื–ืข ืคืึทืจ ื˜ืขืงืข ืื•ื ื˜ืขืจ ื“ื™ ื’ื™ื™ื– ืคื•ืŸ ืึท ื‘ื™ืœื“ ืื•ืŸ ื“ืขืจื’ืจื™ื™ื›ืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ PHP ืงืึธื“ ืื™ืŸ ื“ื™ ืคืึทืจ ืึทืจืงื™ื™ื•ื• ืžื™ื˜ ื“ื™ "Phar deserialization" ื‘ืึทืคืึทืœืŸ ืื•ืคึฟืŸ (ืœืžืฉืœ, ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ "filepath=phar:/path/pharfile.jpg "ืื™ืŸ ื“ืขืจ ื‘ืงืฉื”).

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืึทื– ื•ื•ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจื•ื ื’ ืึท ื•ืคึผืœืึธืึทื“ืขื“ ื˜ืขืงืข ื ื™ืฆืŸ ื“ื™ PHP ืคึฟื•ื ืงืฆื™ืข is_dir (), ื“ื™ ืคึฟื•ื ืงืฆื™ืข ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื“ืขืกืขืจื™ืึทืœื™ื– ื“ื™ ืžืขื˜ืึทื“ืึทื˜ืึท ืคื•ืŸ ื“ื™ Phar ืึทืจื˜ืฉื™ื•ื•ืข ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ืคึผืึทื˜ืก ืกื˜ืึทืจื˜ื™ื ื’ ืžื™ื˜ "phar: //". ื ืขื ืœืขืš ื•ื•ื™ืจืงื•ื ื’ ืื™ื– ื‘ืืžืขืจืงื˜ ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื‘ืึทื ื™ืฆืขืจ-ืกืึทืคึผืœื™ื™ื“ ื˜ืขืงืข ืคึผืึทื˜ืก ืื™ืŸ ื“ื™ ืคืึทื ื’ืงืฉืึทื ื– file_get_contents(), fopen(), file(), file_exists(), md5_file(), filemtime() ืื•ืŸ ืคื™ืœืขืกื™ื–ืข().

ื“ื™ ื‘ืึทืคืึทืœืŸ ืื™ื– ืงืึธืžืคึผืœื™ืฆื™ืจื˜ ื“ื•ืจืš ื“ืขื ืคืึทืงื˜ ืึทื– ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ืคืึทืจ ืึทืจืงื™ื™ื•ื•, ื“ืขืจ ืึทื˜ืึทืงืขืจ ืžื•ื–ืŸ ื’ืขืคึฟื™ื ืขืŸ ืึท ื•ื•ืขื’ ืฆื• ืึธืคึผืœืึธื“ื™ืจืŸ ืขืก ืฆื• ื“ื™ ืžื™ื˜ืœ (ื“ื•ืจืš ืึทืงืกืขืก /jsdm/ajax/logging_browse.php, ืื™ืจ ืงืขื ื˜ ื‘ืœื•ื™ื– ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ืขื ื“ืจืš ืฆื• ื“ื™ ืžื™ื˜ืœ. ื•ื™ืกืคื™ืจืŸ ืึทืŸ ืฉื•ื™ืŸ ื™ื’ื–ื™ืกื˜ื™ื ื’ ื˜ืขืงืข). ืžืขื’ืœืขืš ืกื™ื ืขืจื™ืึธื•ื– ืคึฟืึทืจ ื˜ืขืงืขืก ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึทื ื˜ื• ื“ื™ ืžื™ื˜ืœ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื“ืึทื•ื ืœืึธื•ื“ื™ื ื’ ืึท Phar ื˜ืขืงืข ื“ื™ืกื’ื™ื™ื–ื“ ื•ื•ื™ ืึท ื‘ื™ืœื“ ื“ื•ืจืš ืึท ื‘ื™ืœื“ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ื ืกื˜ ืื•ืŸ ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ ื˜ืขืงืข ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืื™ื ื”ืึทืœื˜ ืงืึทืฉ.

ืื ื“ืขืจืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–:

  • CVE-2022-22242 - ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ืคื•ืŸ ืึทื ืคื™ืœื˜ืขืจื“ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื™ืŸ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ error.php ืฉืจื™ืคื˜, ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืจื™ื™ึทื–-ืคึผืœืึทืฅ ืกืงืจื™ืคึผื˜ื™ื ื’ ืื•ืŸ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื“ื–ืฉืึทื•ื•ืึทืกืงืจื™ืคึผื˜ ืงืึธื“ ืื™ืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ 'ืก ื‘ืœืขื˜ืขืจืขืจ ื•ื•ืขืŸ ืื™ืจ ื ืึธื›ืคืึธืœื’ืŸ ืึท ืœื™ื ืง (ืœืžืฉืœ, "https:// JUNOS_IP/error.php?SERVER_NAME= alert(0) " ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ื–ื™ื™ืŸ ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ื˜ืขืจืกืขืคึผื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืกืขืกื™ืข ืคึผืึทืจืึทืžืขื˜ืขืจืก ืื•ื™ื‘ ืึทื˜ืึทืงืขืจื– ืคื™ืจืŸ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืฆื• ืขืคึฟืขื ืขืŸ ืึท ืกืคึผืขืฆื™ืขืœ ื“ื™ื–ื™ื™ื ื“ ืœื™ื ืง.
  • CVE-2022-22243, CVE-2022-22244 XPATH ืื•ื™ืกื“ืจื•ืง ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ ื“ื•ืจืš jsdm/ajax/wizards/setup/setup.php ืื•ืŸ /modules/monitor/interfaces/interface.php ืกืงืจื™ืคึผืก ืึทืœืึทื•ื– ืึทืŸ ืึทื ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉื“ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืžืึทื ื™ืคึผื•ืœื™ืจืŸ ืึทื“ืžื™ืŸ ืกืขืฉืึทื ื–.
  • CVE-2022-22245 ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ืกืึทื ื™ื˜ื™ื–ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ".." ืกื™ืงื•ื•ืึทื ืก ืื™ืŸ ืคึผืึทื˜ืก ืคึผืจืึทืกืขืกื˜ ืื™ืŸ ื“ื™ Upload.php ืฉืจื™ืคื˜ ืึทืœืึทื•ื– ืึทืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืฆื•ืคึฟืขืœื™ืงืขืจ ื–ื™ื™ืขืจ PHP ื˜ืขืงืข ืฆื• ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื•ื•ืึธืก ืึทืœืึทื•ื– ืคืคึผ ืกืงืจื™ืคึผืก ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ (ืœืžืฉืœ, ื“ื•ืจืš ื’ื™ื™ื˜ ืคืืจื‘ื™ื™ ื“ืขืจ ื“ืจืš "ื˜ืขืงืขื ืึทืžืข=\. .\..\..\..\www\dir\new\shell.php").
  • CVE-2022-22246 - ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ื”ื™ื’ืข PHP ื˜ืขืงืข ื“ื•ืจื›ืคื™ืจื•ื ื’ ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ื“ื•ืจืš ืึท ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ ืคื•ืŸ ื“ื™ jrest.php ืฉืจื™ืคื˜, ืื™ืŸ ื•ื•ืึธืก ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืคึผืึทืจืึทืžืขื˜ืขืจืก ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืคืึธืจืขื ื“ื™ ื ืึธืžืขืŸ ืคื•ืŸ ื“ืขืจ ื˜ืขืงืข ืœืึธื•ื“ื™ื“ ื“ื•ืจืš ื“ื™ "require_once ()" ืคึฟื•ื ืงืฆื™ืข (ืคึฟืึทืจ ื‘ื™ื™ืฉืคึผื™ืœ, "/ื“ื–ืฉืจืขืกื˜.ืคืคึผ?ืคึผื™ื™ืœืึธืึทื“ =ืึทืœืึธืœ/ืœืึธืœ/ืขื ื™\..\..\..\..\ืึทื ื™\ ื˜ืขืงืข")

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’