ืืŸ ืื ื“ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ Apache httpd ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืงืกืขืก ืึทืจื•ื™ืก ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืคื•ืŸ ื“ืขื ืคึผืœืึทืฅ

ื ื ื™ื™ึทืข ื‘ืึทืคืึทืœืŸ ื•ื•ืขืงื˜ืึธืจ ืื™ื– ื’ืขืคึฟื•ื ืขืŸ ื’ืขื•ื•ืึธืจืŸ ืคึฟืึทืจ ื“ื™ ืึทืคึผืึทื˜ืฉื™ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ, ื•ื•ืึธืก ืื™ื– ื’ืขื‘ืœื™ื‘ืŸ ืึทื ืงืขืจืขืงื˜ื™ื“ ืื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ 2.4.50 ืื•ืŸ ืึทืœืึทื•ื– ืึทืงืกืขืก ืฆื• ื˜ืขืงืขืก ืคึฟื•ืŸ ื’ืขื‘ื™ื˜ืŸ ืึทืจื•ื™ืก ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืคื•ืŸ ื“ืขื ืคึผืœืึทืฅ. ืื™ืŸ ื“ืขืจืฆื•, ืจื™ืกืขืจื˜ืฉืขืจื– ื”ืึธื‘ืŸ ื’ืขืคึฟื•ื ืขืŸ ืึท ืžืขื˜ืึธื“ ื•ื•ืึธืก ืึทืœืึทื•ื–, ืื™ืŸ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื–ื™ื›ืขืจ ื ื™ื˜-ื ืึธืจืžืึทืœ ืกืขื˜ื˜ื™ื ื’ืก, ื ื™ื˜ ื‘ืœื•ื™ื– ืฆื• ืœื™ื™ืขื ืขืŸ ืกื™ืกื˜ืขื ื˜ืขืงืขืก, ืึธื‘ืขืจ ืื•ื™ืš ืจื™ืžืึธื•ื˜ืœื™ ื•ื™ืกืคื™ืจืŸ ื–ื™ื™ืขืจ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื‘ืœื•ื™ื– ืื™ืŸ ืจื™ืœื™ืกื™ื– 2.4.49 ืื•ืŸ 2.4.50; ืคืจื™ืขืจ ื•ื•ืขืจืกื™ืขืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“. ืฆื• ืขืœื™ืžื™ื ื™ืจืŸ ื“ื™ ื ื™ื™ึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, Apache httpd 2.4.51 ืื™ื– ื’ืขืฉื•ื•ื™ื ื“ ื‘ืืคืจื™ื™ื˜.

ืื™ืŸ ื–ื™ื™ืŸ ื”ืึทืจืฅ, ื“ื™ ื ื™ื™ึทืข ืคึผืจืึธื‘ืœืขื (CVE-2021-42013) ืื™ื– ื’ืึธืจ ืขื ืœืขืš ืฆื• ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2021-41773) ืื™ืŸ 2.4.49, ื“ืขืจ ื‘ืœื•ื™ื– ื—ื™ืœื•ืง ืื™ื– ืึท ืึทื ื“ืขืจืฉ ืงืึธื“ื™ืจื•ื ื’ ืคื•ืŸ ื“ื™ ".." ืื•ืชื™ื•ืช. ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ืื™ืŸ ืžืขืœื“ื•ื ื’ 2.4.50 ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ ืกื™ืงื•ื•ืึทื ืก "% 2e" ืฆื• ืขื ืงืึธื•ื“ ืึท ืคื•ื ื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ืืคื’ืขืฉื˜ืขืœื˜, ืึธื‘ืขืจ ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ื˜ืึธืคึผืœ ืงืึธื“ื™ืจื•ื ื’ ืื™ื– ื’ืขื•ื•ืขืŸ ืžื™ืกื˜ - ื•ื•ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืกื™ืงื•ื•ืึทื ืก "%% 32% 65", ื“ื™ ืกืขืจื•ื•ืขืจ ื“ื™ืงืึธื•ื“ื™ื“ ืขืก ืื™ืŸ "% 2e" ืื•ืŸ ื“ืขืจื ืึธืš ืื™ืŸ ".", ื“"ื”. ื“ื™ "../" ืื•ืชื™ื•ืช ืฆื• ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืงืขืŸ ื–ื™ื™ืŸ ืงืึธื“ืขื“ ื•ื•ื™ ".%%32%65/".

ื•ื•ื™ ืคึฟืึทืจ ืขืงืกืคึผืœื•ื™ื˜ื™ื ื’ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื“ื•ืจืš ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’, ื“ืึธืก ืื™ื– ืžืขื’ืœืขืš ื•ื•ืขืŸ mod_cgi ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ืื•ืŸ ื“ื™ ื‘ืึทื–ืข ื•ื•ืขื’ ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ ื•ื•ืึธืก ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ CGI ืกืงืจื™ืคึผืก ืื™ื– ืขืจืœื•ื™ื‘ื˜ (ืœืžืฉืœ, ืื•ื™ื‘ ื“ื™ ScriptAlias โ€‹โ€‹ื“ื™ืจืขืงื˜ื™ื•ื• ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ ืึธื“ืขืจ ื“ื™ ืขืงืกืขืงืงื’ื™ ืคืึธืŸ ืื™ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ืึธืคึผืฆื™ืขืก ื“ื™ืจืขืงื˜ื™ื•ื•). ื ืžืึทื ื“ืึทื˜ืึธืจื™ ืคืึธื“ืขืจื•ื ื’ ืคึฟืึทืจ ืึท ื’ืขืจืึธื˜ืŸ ื‘ืึทืคืึทืœืŸ ืื™ื– ืื•ื™ืš ืฆื• ื‘ืคื™ืจื•ืฉ ืฆื•ืฉื˜ืขืœืŸ ืึทืงืกืขืก ืฆื• ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ืžื™ื˜ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืขืก, ืึทื–ืึท ื•ื•ื™ / bin, ืึธื“ืขืจ ืึทืงืกืขืก ืฆื• ื“ืขืจ ื˜ืขืงืข ืกื™ืกื˜ืขื ื•ื•ืึธืจืฆืœ "/" ืื™ืŸ ื“ื™ ืึทืคึผืึทื˜ืฉื™ ืกืขื˜ื˜ื™ื ื’ืก. ื–ื™ื ื˜ ืึทื–ืึท ืึทืงืกืขืก ืื™ื– ื ื™ืฉื˜ ื˜ื™ืคึผื™ืงืœื™ ื’ืขื’ืขื‘ืŸ, ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื ืคืืœืŸ ื”ืึธื‘ืŸ ืงืœื™ื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืฆื• ืคืึทืงื˜ื™ืฉ ืกื™ืกื˜ืขืžืขืŸ.

ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ื“ื™ ื‘ืึทืคืึทืœืŸ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืกื™ืกื˜ืขื ื˜ืขืงืขืก ืื•ืŸ ืžืงื•ืจ ื˜ืขืงืกื˜ืŸ ืคื•ืŸ ื•ื•ืขื‘ ืกืงืจื™ืคึผืก, ืœื™ื™ื ืขื•ื•ื“ื™ืง ื“ื•ืจืš ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืื•ื ื˜ืขืจ ื•ื•ืึธืก ื“ื™ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ืื™ื– ืคืœื™ืกื ื“ื™ืง, ื‘ืœื™ื™ื‘ื˜ ื‘ืึทื˜ื™ื™ึทื˜ื™ืง. ืฆื• ื“ื•ืจื›ืคื™ืจืŸ ืึทื–ืึท ืึท ื‘ืึทืคืึทืœืŸ, ืขืก ืื™ื– ื’ืขื ื•ื’ ืฆื• ื”ืึธื‘ืŸ ืึท ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื•ื™ืฃ ื“ืขื ืคึผืœืึทืฅ ืงืึทื ืคื™ื’ื™ืขืจื“ ืžื™ื˜ ื“ื™ "ืึทืœื™ืึทืก" ืึธื“ืขืจ "ืกืงืจื™ืคึผื˜ืึทืœื™ืึทืก" ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื– (DocumentRoot ืื™ื– ื ื™ืฉื˜ ื’ืขื ื•ื’), ืึทื–ืึท ื•ื•ื™ "cgi-bin".

ืึท ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืึท ื’ื•ื•ื•ืจืข ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื™ืกืคื™ืจืŸ ื“ื™ "ืฉื™ื™ึทืŸ" ื ื•ืฆืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ: ืงืขืจืœ 'http://192.168.0.1/cgi-bin/.%%32%65/.%%32%65/.%% 32% 65 / .%% 32% 65 / .%% 32% 65 / ื‘ื™ืŸ / ืฉ ' โ€” ื“ืึทื˜ืŸ 'ืขืงืึธื• ืื™ื ื”ืึทืœื˜-ื˜ื™ืคึผ: ื˜ืขืงืกื˜ / ืงืœืึธืจ; echo; id' uid = 1 (ื“ืขืžืึธืŸ) gid = 1 (ื“ืขืžืึธืŸ) ื’ืจื•ืคึผืขืก = 1 (ื“ืขืžืึธืŸ)

ื ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืขืงืกืคึผืœื•ื™ืฅ ืึทื– ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื•ื™ื™ึทื–ืŸ ื“ื™ ืื™ื ื”ืึทืœื˜ ืคื•ืŸ /etc/passwd ืื•ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ื•ื•ืขื‘ ืกืงืจื™ืคึผืก (ืฆื• ืึทืจื•ื™ืกืคื™ืจืŸ ื“ื™ ืฉืจื™ืคื˜ ืงืึธื“, ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ื“ื™ืคื™ื™ื ื“ ื“ื•ืจืš ื“ื™ "ืึทืœื™ืึทืก" ื“ื™ืจืขืงื˜ื™ื•ื•, ืคึฟืึทืจ ื•ื•ืึธืก ืฉืจื™ืคื˜ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืื™ื– ื ื™ืฉื˜ ืขื ื™ื™ื‘ืึทืœื“, ืžื•ื–ืŸ ื–ื™ื™ืŸ ืกืคึผืขืกื™ืคื™ืขื“ ื•ื•ื™ ื“ื™ ื‘ืึทื–ืข ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ): ืงืขืจืœ 'http://192.168.0.1 .32/cgi-bin/.%%65%32/.%%65%32/.%%65%32/.%%65%32/.% %65%192.168.0.1/etc/passwd' ืงืขืจืœ 'http: //32/aliaseddir/.%%65%32/.%%65%32/.%%65%32/.%%65%32/. %%65%2/usr/local/apacheXNUMX/cgi -bin/test.cgi'

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ื“ืขืจ ื”ื•ื™ืคึผื˜ ืึทืคืขืงืฅ ืงืึทื ื˜ื™ื ื™ื•ืึทืกืœื™ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืึทื–ืึท ื•ื•ื™ ืคืขื“ืึธืจืึท, ืึทืจื˜ืฉ ืœื™ื ื•ืงืก ืื•ืŸ ื’ืขื ื˜ืึธืึธ, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืคึผืึธืจืฅ ืคื•ืŸ FreeBSD. ืคึผืึทืงืงืึทื’ืขืก ืื™ืŸ ื“ื™ ืกื˜ืึทื‘ื™ืœ ืฆื•ื•ื™ื™ื’ืŸ ืคื•ืŸ ื“ื™ ืงืึธื ืกืขืจื•ื•ืึทื˜ื™ื•ื•ืข ืกืขืจื•ื•ืขืจ ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– Debian, RHEL, Ubuntu ืื•ืŸ SUSE ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืงืขืŸ ื ื™ืฉื˜ ืคึผืึทืกื™ืจืŸ ืื•ื™ื‘ ืึทืงืกืขืก ืฆื• ื“ื™ื™ืจืขืงื˜ืขืจื™ื– ืื™ื– ื‘ืคื™ืจื•ืฉ ื’ืขืœื™ื™ืงื ื˜ ืžื™ื˜ ื“ื™ "ืคืึธื“ืขืจืŸ ืึทืœืข ื’ืขืœื™ื™ืงื ื˜" ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’