¡¾Îó²îͨ¸æ¡¿PHP CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-4577£©

Ðû²¼Ê±¼ä 2024-06-07


Ò»¡¢Îó²î¸ÅÊö

Îó²îÃû³Æ

  PHP   CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2024-4577

Îó²îÀàÐÍ

²ÎÊý×¢Èë¡¢RCE

·¢Ã÷ʱ¼ä

2024-06-07

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

PHPÊÇÒ»ÃÅͨÓÿªÔ´¾ç±¾ÓïÑÔ£¬ £¬£¬£¬ÆäÓï·¨½è¼øÎüÊÕC¡¢JavaºÍPerlµÈÊ¢ÐÐÅÌËã»úÓïÑÔµÄÌØµã£¬ £¬£¬£¬Òò´ËÀûÓÚѧϰ£¬ £¬£¬£¬Ê¹ÓÃÆÕ±é£¬ £¬£¬£¬Ö÷ÒªÊÊÓÃÓÚWeb¿ª·¢ÁìÓò¡£¡£¡£¡£¡£

6ÔÂ7ÈÕ£¬ £¬£¬£¬c7c7ÓéÀÖÆ½Ì¨¼¯ÍÅVSRC¼à²âµ½PHPÐû²¼Çå¾²¸üУ¬ £¬£¬£¬ÐÞ¸´ÁËPHP CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-4577£©£¬ £¬£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚÒѹûÕæ¡£¡£¡£¡£¡£

PHPÓïÑÔÔÚÉè¼ÆÊ±ºöÂÔÁËWindowsϵͳÄÚ²¿¶Ô×Ö·û±àÂëת»»µÄBest-FitÌØÕ÷£¬ £¬£¬£¬µ±PHPÔËÐÐÔÚWindowƽ̨ÇÒʹÓÃÁËÈç·±ÌåÖÐÎÄ(´úÂëÒ³950)¡¢¼òÌåÖÐÎÄ(´úÂëÒ³936)ºÍÈÕÎÄ(´úÂëÒ³932)µÈÓïϵʱ£¬ £¬£¬£¬ÍþвÕ߿ɽṹ¶ñÒâÇëÇóÈÆ¹ýCVE-2012-1823µÄ·À»¤£¬ £¬£¬£¬Í¨¹ý²ÎÊý×¢ÈëµÈ¹¥»÷ÔÚÄ¿µÄPHPЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£

 

¶þ¡¢Îó²î¸´ÏÖ

image.png


Èý¡¢Ó°Ïì¹æÄ£

PHP 8.3 < 8.3.8

PHP 8.2 < 8.2.20

PHP 8.1 < 8.1.29

×¢£º¸ÃÎó²îÓ°Ïì×°ÖÃÓÚWindowsϵͳÉϵÄPHP °æ±¾¡£¡£¡£¡£¡£ÓÉÓÚPHP 8.0 ·ÖÖ§¡¢PHP 7 ÒÔ¼°PHP 5 ¹Ù·½ÒѲ»ÔÙά»¤£¬ £¬£¬£¬ÍøÕ¾ÖÎÀíÔ±¿ÉÉó²éÊÇ·ñÊܸÃÎó²îÓ°Ïì²¢Ó¦ÓÃÏà¹Ø»º½â²½·¥¡£¡£¡£¡£¡£

 

 

ËÄ¡¢Çå¾²²½·¥

4.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬ £¬£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½PHP°æ±¾8.3.8¡¢8.2.20¡¢8.1.29»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/php/php-src/tags

4.2 ÔÝʱ²½·¥

Windowsƽ̨ÖÐApache HTTP Server ¼ÓÉÏPHP ×éºÏ¡¢XAMPP for Windows×°ÖõÄÒÔϳ¡¾°¿ÉÄÜÒ×ÊܸÃÎó²îÓ°Ï죺

1.     ½«PHP É趨ÓÚCGI ģʽÏÂÖ´ÐС£¡£¡£¡£¡£ÔÚApache Httpd ÉèÖÃÎļþÖÐͨ¹ýActionÓï·¨½«¶ÔÓ¦µÄHTTP ÇëÇ󽻸øPHP-CGI¾ç±¾Îļþ´¦Öóͷ£Ê±£¬ £¬£¬£¬ÊÜ´ËÎó²îÓ°Ï죬 £¬£¬£¬³£¼ûÉ趨°üÀ¨µ«²»ÏÞÓÚ£º

AddHandler cgi-script .php

Action cgi-script "/cgi-bin/php-cgi.exe"

 »ò

    SetHandler application/x-httpd-php-cgi

Action application/x-httpd-php-cgi "/php-cgi/php-cgi.exe"

2. ½«PHP¾ç±¾Îļþ̻¶ÔÚÍâ(XAMPP Ô¤Éè×°ÖÃÉ趨)¡£¡£¡£¡£¡£½«PHP ¾ç±¾Îļþ̻¶ÔÚCGI Ŀ¼ÏÂÒ²ÊÜ´ËÎó²îÓ°Ï죬 £¬£¬£¬³£¼ûÇéÐΰüÀ¨µ«²»ÏÞÓÚ:

1)     ½«php.exe»òphp-cgi.exe¸´ÖƵ½/cgi-bin/Ŀ¼ÖС£¡£¡£¡£¡£

2)     ½«PHP ×°ÖÃĿ¼ͨ¹ýScriptAlias̻¶µ½Í⣬ £¬£¬£¬È磺

ScriptAlias /php-cgi/ "C:/xampp/php/"

»º½â£º

1.¹ØÓÚÎÞ·¨Á¬Ã¦Éý¼¶PHPµÄÓû§¡£¡£¡£¡£¡£

¿Éͨ¹ýÏÂÁÐRewrite ¹æÔò×èÖ¹¹¥»÷£¬ £¬£¬£¬Çë×¢ÖØÕâЩ¹æÔò½ö×÷Ϊ·±ÌåÖÐÎÄ¡¢¼òÌåÖÐÎļ°ÈÕÎÄÓïÑÔÇéÐÎÖеÄÔÝʱÐÔ»º½â»úÖÆ£¬ £¬£¬£¬ÏÖʵ²Ù×÷Öн¨Òé¸üе½ÒÑÐÞ¸´°æ±¾»ò¸ü¸Ä¼Ü¹¹¡£¡£¡£¡£¡£

RewriteEngine On

RewriteCond %{QUERY_STRING} ^%ad [NC]

RewriteRule .? - [F,L]

2.¹ØÓÚXAMPP for Windows Óû§¡£¡£¡£¡£¡£

ÏÖÔÚXAMPP ÔÝδÕë¶Ô¸ÃÎó²îÐû²¼Ïà¹Ø¸üУ¬ £¬£¬£¬ÈçÈ·ÈÏXAMPP ²»ÐèҪʹÓÃPHP CGI ¹¦Ð§£¬ £¬£¬£¬¿Éͨ¹ýÐÞ¸ÄÏÂÁÐApache Httpd ÉèÖÃÎĵµÀ´»º½â¸ÃÎó²îÓ°Ïì:

ÔÚ¶ÔӦװÖÃĿ¼Ï£¬ £¬£¬£¬ÈçC:/xampp/apache/conf/extra/httpd-xampp.confÖУ¬ £¬£¬£¬ÕÒµ½ÏìÓ¦µÄÐУº

ScriptAlias /php-cgi/ "C:/xampp/php/"

½«Æä×¢Ê͵ô£¬ £¬£¬£¬ÉúÑĺóÖØÆôЧÀÍ£º

# ScriptAlias /php-cgi/ "C:/xampp/php/"

4.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¬ £¬£¬£¬ïÔ̭ϵͳÎó²î£¬ £¬£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£¡£¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬ £¬£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬ £¬£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬ £¬£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬ £¬£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£¡£¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬ £¬£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£¡£¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬ £¬£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬ £¬£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£¡£¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£¡£¡£¡£

4.4 ²Î¿¼Á´½Ó

https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability/

https://bodhi.fedoraproject.org/updates/FEDORA-2024-52c23ef1ec

https://www.kb.cert.org/vuls/id/520827

https://www.php.net/downloads

 

 

Îå¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-06-07

Ê×´ÎÐû²¼

 

 

Áù¡¢¸½Â¼

6.1 c7c7ÓéÀÖÆ½Ì¨¼ò½é

c7c7ÓéÀÖÆ½Ì¨½¨ÉèÓÚ1996Ä꣬ £¬£¬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£¡£¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£¡£¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°c7c7ÓéÀÖÆ½Ì¨´óÏ㬠£¬£¬£¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬ £¬£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£¡£¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ £¬£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¡£¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡£¡£¡£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬ £¬£¬£¬c7c7ÓéÀÖÆ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬ £¬£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬ £¬£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£¡£¡£¡£

6.2 ¹ØÓÚc7c7ÓéÀÖÆ½Ì¨

c7c7ÓéÀÖÆ½Ì¨Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬ £¬£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬ £¬£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£¡£¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png