²Ä0057´Á¡E2021.06.20 µo¦æ
ISSN 2077-8813

­º­¶ >±MÃD³ø¾É

Microsoft Exchange Proxylogon º|¬}»¡©ú

§@ªÌ¡G¼B®aºû/»OÆW¤j¾Ç­p¸ê¤¤¤ß¥_°Ï¾Ç³N¸ê°T¦w¥þºû¹B¤¤¤ß¤uµ{®v
        §õ¬ü¶²/»OÆW¤j¾Ç­pºâ¾÷¤Î¸ê°Tºô¸ô¤¤¤ßµ{¦¡³]­p®v

·L³n©ó3¤ë2¤é¦w¥þ¤½§i¤¤­×¸É¤F4¶µExchange Server ªºZero Dayº|¬}¡A¥B¤wµo²{¦h­ÓÀb«È²Õ´¦ê³s¥|¶µº|¬}¦¨¥\Àb¤JExchange Server Àô¹Ò¡A³z¹L´Ó¤JWebshell «áªùµ{¦¡¡A§ðÀ»ªÌ¯à°÷ªø´Á´x±±¨ü®`²Õ´¶l¥ó¦øªA¾¹¡AÅѨú¾÷±K¸ê®Æ¡C
®Ú¾Ú¸ê¦w´CÅéKrebsonSecurity³ø¾É¡Aº|¬}°T®§¤½¶}«á°w¹ï¦¹º|¬}ªº§ðÀ»¦æ¬°©ó¼Æ¤é¤º¿E¼W¡A¥þ¥@¬É¤w¦³¼Æ¤Q¸U¥xªºExchange Server ¨ü®`¡A¦¹¦¸ªº¥|¶µZero Dayº|¬}¤]³Q²ÎºÙ¬°¡uProxylogon º|¬}¡v¡C¥»½g±NµÛ­«©ó°Q½×Proxylogon º|¬}§ðÀ»¬yµ{¤Îº|¬}¨¾Å@ªº«Øij³B²z±¹¬I¡C


Exchange Serverº|¬}»¡©ú

Microsoft Exchange¬°·L³nµo¦æªº¤@®M¹q¤l¶l¥ó¦øªA¾¹°Ó·~³nÅé¡A¨ä¤ä´©¦hºØ¹q¤l¶l¥ó¶Ç¿é¨óij¡A¦pSMTP¡BNNTP¡BPOP3©MIMAP4¡A³Q¥@¬É¦U¥ø·~¤Î¾Ç®Õ¼sªx§Q¥Î©ó«Øºc²Õ´¤º³¡ªº¹q¤l¶l¥ó¨t²Î¡A¥»¦¸ªºProxylogon º|¬}ÄÝ©ó¥i¶¹L¨­¤ÀÅçÃÒªº»·ºÝ°õ¦æ¥ô·Nµ{¦¡º|¬}(Remote Code Execution¡ARCE)¡A¦]¨ä¥iµ{¦¡¤Æ¤Î¦Û°Ê¶i¦æ½d³ò§ðÀ»ªº¯S©Ê¡A¦bµu®É¶¡¤º¬ü°ê¹Ò¤º¤w³Qµo²{¹O¤T¸U¥x³]³Æ¾D´Ó¤JWebshell«áªùµ{¦¡ÅѨú¾÷±Kªº¶l¥ó¸ê®Æ¡A²£·~§O§ó¬O¾î¸ó¤F¬F©²³æ¦ì¡Bª÷¿Ä¾÷ºc¡B¹q«H¤½¥qµ¥µ¥¡A¼vÅT³W¼Ò¬Û·í¥¨¤j¡C
©ó¦¹¦¸ªºExchange ¶l¥ó¦øªA¾¹º|¬}­·¼É¤¤¥xÆW¥ø·~¤]¾D¨üªi¤Î¡A¾Ú¥~´C³ø¾É°ê»Úª¾¦Wªº¹q¸£¤j¼t§»ùÖ¹q¸£(Acer)¤]¦¨¬°¤FProxylogon º|¬}ªº¨ü®`ªÌ¡A¨ä¼Ú¬ü¤À¤½¥q©ó3¤ë20¤é¾DÀb«È¹ÎÅéREvilµo°Ê°Ç¯Á§ðÀ»¡A¨Ã­n¨D°ª¹F5000¸U¬ü¤¸ªº¤Ñ»ùÅ«ª÷¡A¤]¬OºI¦Ü¥Ø«e¬°¤î¥þ¥@¬ÉExchangeº|¬}¾D§ðÀ»¨Æ¥ó³Q°Ç¯Á³Ì°ªª÷ÃBªº®×¨Ò¡C
»OÆW¸ê¦w¤½¥qÀ¹¤Ò±Fº¸(DEVCORE)¬O¦¹¦¸º|¬}ªºµo²{ªÌ¡A´£¥Xªºº|¬}»¡©ú»P´¦ÅS®É¶¡ªí¤¤«ü¥X Proxylogon º|¬}¬°³z¹L¦êÁp¤U¦C4¶µExchange Server Zero Dayº|¬}¹F¨ì»·ºÝ´Ó¤J«áªùµ{¦¡ªº¥Øªº¡G

1. CVE-2021-26855 ¥¼¸g¨­¤ÀÅçÃÒªº¦øªA¾¹ºÝ½Ð¨D°°³y¡]SSRF¡^º|¬}
2. CVE-2021-26857 ³q¹L¨­¤ÀÅçÃÒ«áUnified MessagingªA°Èªº¤Ï§Ç¦C¤Æº|¬}
3. CVE-2021-26858ÀÉ®×¼g¤Jº|¬}¡A³q¹L¨­¤ÀÅçÃÒ«á¥i¥ô·N¼g¤Jµ{¦¡
4. CVE-2021-27065ÀÉ®×¼g¤Jº|¬}¡A³q¹L¨­¤ÀÅçÃÒ«á¥i¥ô·N¼g¤Jµ{¦¡

¨ä¤¤CVE-2021-26855—SSRF¡]Server Side Request Forgery¡A¦øªA¾¹½Ð¨D°°³y¡^¬°¦¹¨Æ¥ó¤¤ªº®Ö¤ßº|¬}¡A¤]¬OÀb«È¯à°÷¦¨¥\¤J«Iªº²Ä¤@¨B¡C
¾ÚPraetorian°w¹ï¥»¨Æ¥óªº¤ÀªR¤å³¹¤¤©Ò­z¡Aº|¬}CVE-2021-26855µo¥ÍÂI¦ì©óC:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\binÀɮץؿý¤Uªº°ÊºA³sµ²¨ç¦¡®wMicrosoft.Exchange.FrontEndHttpProxy.dll·í¤¤¡C¦]Exchange ©ó³B²z«È¤áºÝµo°eªºRequest«Ê¥]®É¡A¹ïX-BEResourceÄæ¦ì¦r¦ê³B²z¤£·í¡A¨Ï±o§ðÀ»ªÌ¥i³z¹L¦XªkªºSID¶i¦Ó¨ú±o¦³®ÄCookie ¶¹L¨­¤ÀÅçÃÒÅçÃÒ¶¥¬q¡A¨Ãµ²¦X«áÄò¤T­Óº|¬}¹F¨ì»·ºÝ°õ¦æ¥ô·Nµ{¦¡(Remote Code Execution¡ARCE)ªº³Ì²×¥Øªº¡C

 

³z¹L·§©ÀÅçÃÒ§ðÀ»(Proof of concept Exploit, PoC)¦Û§ÚÀË´ú

·L³n¡]Microsoft¡^µo¥¬ªºº|¬}­×¸Éµ{¦¡¤½¶}«á¡A¨C¤é¤´µM¦³¼Æ¸U°_°w¹ï¥þ²y²Õ´ªº§ðÀ»¡A¬°½T»{²Õ´¤º³¡ªºExchange ¦øªA¾¹¬O§_¤w³B©ó¦w¥þª¬ºA¡A§Q¥Î©óGithub©Î¦U¶µº|¬}´ú¸Õ¤u¨ã¤W¤½¶}ªº·§©ÀÅçÃÒ§ðÀ»µ{¦¡¶i¦æ¦Û§ÚÀË´ú¡A¬O­Ó§Ö³t¥B¦³®Äªº¤èªk¡C


¹Ï1. Github¨Ï¥ÎªÌ0xAbdullah¶}µoªº·§©ÀÅçÃÒ§ðÀ»µ{¦¡
(https://github.com/0xAbdullah/CVE-2021-26855)


¹Ï2. ¿é¤JURL§Ö³tÀË´úCVE-2021-26855 SSRF¦øªA¾¹ºÝ½Ð¨D°°³yº|¬}¡A
(https://github.com/0xAbdullah/CVE-2021-26855)

³z¹Lº|¬}´ú¸Õ¤u¨ã¤§·§©ÀÅçÃÒ§ðÀ»µ{¦¡¯à°÷ª½Æ[ªº½T»{Exchange¦øªA¾¹¬O§_¥]§t SSRFº|¬}¡A¨Ã¦³®Äªº¨ó§U²Õ´¤º³¡½T»{­×¸É±¹¬Iªº¦³®Ä©Ê¡C

 

¼vÅT½d³ò¤Î«Øij³B²z±¹¬I

Proxylogonº|¬}¼vÅT½d³ò²[»\¤F2013¡B2016¤Î2019 ªºExchange ¦øªA¾¹ª©¥»¡A¬°ÁקK²Õ´¤º³¡ªºExchange¾D¨üº|¬}«Â¯Ù¡AºÉ³t§ó·s©Ò¦³ªºExchange ¦øªA¾¹¬O³ÌÀu¥ýªº¸Ñ¨M¤è®×¡A·L³n¡]Microsoft¡^¤]©ó3¤ë22¤é«Å¥¬¬°¤F¨¾¤î¤Ö¼Æ¥Î¤á¨S¦³¤â°Ê°õ¦æ§ó·s¡A±N©óWindows Update¦Û°Ê¬°¥Î¤á±À°e¦w¸Ë¦w¥þ©Ê¥H­×¸ÉProxylogonº|¬}¡C
¦p²Õ´¤º³¡¦]¯S®íª¬ªpµLªk¥ß§Y§ó·s¤Î­×¸ÉExchange¦øªA¾¹¡A¥i³z¹L¥H¤U½w¸Ñ±¹¬I­°§C¾D¨ü§ðÀ»ªº­·ÀI¡C

1. Microsoft Exchange On-Premises Mitigation Tool¡]EOMT¡^
EOMT³z¹L¦Û°Ê§ó§ïURL Rewrite°t¸m¡A¤Î°õ¦æMicrosoft Safety Scanner¥i¦Û°Ê½w¸Ñ®Ö¤ßº|¬}©Ò³y¦¨ªº«Â¯Ù¡C

2. WAF(Web Application Firewall, ºô¯¸À³¥Îµ{¦¡¨¾¤õÀð)¡BIPS(Intrusion Prevention System, ¤J«I°»´ú¨¾Å@¨t²Î)
³z¹L¤w§ó·s¯S¼x­È°»´ú³W«hªºWAF©ÎIPS¸ê¦w¨¾Å@³]³Æ¡A°»´ú¤Îªý¾×±a¦³´c·N¯S¼xªº²§±`³s½u¦æ¬°¡C

3. °±¥Î³¡¤ÀExchange ¥\¯à
³z¹L©ó°±¥Î¾ã¦X³q°TªA°È¡]Unified Messaging¡^¡BÂ÷½u³q°T¿ý¡]OAB¡^ªºµêÀÀ¥Ø¿ý¤Î¹LÂo¾¹¥[¤JIISÂмg³W«hµ¥µ¥¡A¥i´£°ªÀb«Èº|¬}§Q¥ÎªºÃø«×¡A­°§C¨ü®`­·ÀI¡C

 

µ²½×

¸ê¦w±q·~¤H­ûÀ³®É¨èÃöª`¸ê¦w·s»D»P®zÂI­×¸É¤½§i¡A¦b­±Á{¦pProxylogon­«¤jº|¬}µo¥Í®É¡A©ó²Ä¤@®É¶¡ÀÀ©w­×¸É­pµe¡C¦p³B¦b­×¸Éµ{¦¡©|¥¼ÄÀ¥XªºªÅµ¡´Á¡A»ÝÀ˵ø²Õ´¦Û¨­ªº¸ê¦w¨¾Å@¬Fµ¦¬O§_¥i´£°ª¤J«IªùÂe¡A­°§C¦]º|¬}³y¦¨²Õ´³Q§ðÀ»ªº¦M¾÷¡C

 

°Ñ¦Ò¸ê®Æ

1. iThome (¦h®a¸ê¦w¼t°Ó´£¥X«Øijªº½w¸Ñ±¹¬I)¡Ghttps://www.ithome.com.tw/news/143305
2. iThome(·L³nExchange¶l¥ó¦øªA¾¹º|¬}¬ã¨s»P´¦ÅS®É¶¡ªí)¡G
https://www.ithome.com.tw/news/143316
3. iThome(¦p¦ó§êºt¤@­ÓºÙ¾ªº¥ø·~¸ê¦w¤H­û)¡Ghttps://www.ithome.com.tw/news/108014
4. Microsoft Security Response Center(EOMT Tool)¡G
https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/
5. TechNews (Exchange Server ¹s®É®tº|¬}§ðÀ»ÀW¶Ç¡A¥i¥Î¥|©Û¦]À³)¡Ghttps://technews.tw/2021/03/16/exchange-server/
6. ¦w¥þ«È(Microsoft Exchange Server CVE-2021–26855 º|¬}§Q¥Î)¡Ghttps://www.anquanke.com/post/id/234607
7. ¼R§q½×¾Â(Microsoft Exchange Proxylogonº|¬}§Q¥ÎÃì)¡Ghttps://www.4hou.com/posts/q66D
8. Praetorian(Reproducing the Microsoft Exchange Proxylogon Exploit Chain)¡G
https://www.praetorian.com/blog/reproducing-proxylogon-exploit/
9. Github(0xAbdullah /CVE-2021-26855)¡Ghttps://github.com/0xAbdullah/CVE-2021-26855
10. ZDNet(Everything you need to know about the Microsoft Exchange Server hack)¡G
https://www.zdnet.com/article/everything-you-need-to-know-about-microsoft-exchange-server-hack/