RedisδÊÚȨ»á¼ûÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚRedis 2.x£¬3.x£¬4.x£¬5.x¡£


Îó²î¸ÅÊö


RedisÊÇÃÀ¹úRedisLabs¹«Ë¾ÔÞÖúµÄÒ»Ì׿ªÔ´µÄʹÓÃANSIC±àд¡¢Ö§³ÖÍøÂç¡¢¿É»ùÓÚÄÚ´æÒà¿É³¤ÆÚ»¯µÄÈÕÖ¾ÐÍ¡¢¼üÖµ£¨Key-Value£©´æ´¢Êý¾Ý¿â£¬²¢Ìṩ¶àÖÖÓïÑÔµÄAPI¡£


RedisÖб£´æÎ´ÊÚȨ»á¼ûÎó²î£¬¸ÃÎó²îÔ´ÓÚÔÚReids 4.x¼°ÒÔÉϰ汾ÖÐÐÂÔöÁËÄ£¿é¹¦Ð§£¬¹¥»÷Õß¿Éͨ¹ýÍâ²¿ÍØÕ¹£¬ÔÚ redisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁî¡£¹¥»÷Õß¿ÉÒÔʹÓøù¦Ð§ÒýÈëÄ£¿é£¬Ê¹±»¹¥»÷·þÎñÆ÷ÖмÓÔØ¶ñÒâµÄ.soÎļþ£¬´Ó¶øÊµÏÖ¶ñÒâ´úÂëÖ´ÐС£ÈôRedisΪ4.0ÒÔϰ汾£¨2.x£¬3.x£©£¬Í¬Ê±redis-serverÒÔrootȨÏÞÆô¶¯£¬Ôò¹¥»÷Õß¿ÉÔÚ·þÎñÆ÷ÉϽ¨Éèí§ÒâÎļþ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£


ÐÞ¸´½¨Òé


1¡¢Õ¥È¡Íⲿ»á¼ûRedis·þÎñ¶Ë¿Ú£»
2¡¢Õ¥È¡Ê¹ÓÃrootȨÏÞÆô¶¯redis·þÎñ£»

3¡¢ÉèÖÃÇå¾²×飬ÏÞÖÆ¿ÉÅþÁ¬Redis·þÎñÆ÷µÄIP¡£


²Î¿¼Á´½Ó


https://2018.zeronights.ru/wp-content/uploads/materials/15-redis-post-exploitation.pdf