RedisδÊÚȨ»á¼ûÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚRedis 2.x£¬£¬3.x£¬£¬4.x£¬£¬5.x¡£¡£¡£


Îó²î¸ÅÊö


RedisÊÇÃÀ¹úRedisLabs¹«Ë¾ÔÞÖúµÄÒ»Ì׿ªÔ´µÄʹÓÃANSIC±àд¡¢Ö§³ÖÍøÂç¡¢¿É»ùÓÚÄÚ´æÒà¿É³¤ÆÚ»¯µÄÈÕÖ¾ÐÍ¡¢¼üÖµ£¨Key-Value£©´æ´¢Êý¾Ý¿â£¬£¬²¢Ìṩ¶àÖÖÓïÑÔµÄAPI¡£¡£¡£


RedisÖб£´æÎ´ÊÚȨ»á¼ûÎó²î£¬£¬¸ÃÎó²îÔ´ÓÚÔÚReids 4.x¼°ÒÔÉϰ汾ÖÐÐÂÔöÁËÄ£¿£¿£¿£¿é¹¦Ð§£¬£¬¹¥»÷Õß¿Éͨ¹ýÍâ²¿ÍØÕ¹£¬£¬ÔÚ redisÖÐʵÏÖÒ»¸öеÄRedisÏÂÁî¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓøù¦Ð§ÒýÈëÄ£¿£¿£¿£¿é£¬£¬Ê¹±»¹¥»÷ЧÀÍÆ÷ÖмÓÔØ¶ñÒâµÄ.soÎļþ£¬£¬´Ó¶øÊµÏÖ¶ñÒâ´úÂëÖ´ÐС£¡£¡£ÈôRedisΪ4.0ÒÔϰ汾£¨2.x£¬£¬3.x£©£¬£¬Í¬Ê±redis-serverÒÔrootȨÏÞÆô¶¯£¬£¬Ôò¹¥»÷Õß¿ÉÔÚЧÀÍÆ÷ÉϽ¨Éèí§ÒâÎļþ¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


1¡¢Õ¥È¡Íⲿ»á¼ûRedisЧÀͶ˿ڣ»£»£»£»£»£»
2¡¢Õ¥È¡Ê¹ÓÃrootȨÏÞÆô¶¯redisЧÀÍ£»£»£»£»£»£»

3¡¢ÉèÖÃÇå¾²×飬£¬ÏÞÖÆ¿ÉÅþÁ¬RedisЧÀÍÆ÷µÄIP¡£¡£¡£


²Î¿¼Á´½Ó


https://2018.zeronights.ru/wp-content/uploads/materials/15-redis-post-exploitation.pdf