97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
¾Ü¾øÓªÒµ¡°µôÁ´×Ó¡±£º2025 97¹ú¼ÊÍøÂç ¡°½µ¹ÊÕÏ?Ç¿·À»¤¡± ÐÐÒµÔËάʵս½»Á÷»á
Ô¤Ô¼Ö±²¥
97¹ú¼Êî£Ò× 97¹ú¼Ê¹Ù·½É̳Ç
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÖÐÎÄ

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
  • Global / English
  • France / Fran?ais
  • Germany / Deutsch
  • Indonesia / Indonesian
  • Italy / Italiano
  • Japan / ÈÕ±¾ÕZ
  • Kazakhstan / P§å§ã§ã§Ü§Ú§Û
  • Poland / Polski
  • Portugal / Portugu¨ºs
  • Spain / Espa?ol (Espa?a)
  • Thailand / ???????
  • Vietnam / Vi?t Nam
  • LATAM / Espa?ol
    (Am¨¦rica Latina)
  • T¨¹rkiye / T¨¹rk?e
  • Brazil / Portugu¨ºs(Brazil)
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·

½»Á÷»ú

½»Á÷»úËùÓвúÆ·
< ·µ»Ø²úÆ·
½»Á÷»úÖ÷Ò³
½»Á÷»ú

ÎÞÏß

ÎÞÏßËùÓвúÆ·
< ·µ»Ø²úÆ·
ÎÞÏßÖ÷Ò³
ÎÞÏß

ÎÞÏß¹ÜÀíÓëÓ¦ÓÃ

ÔÆ×ÀÃæ

ÔÆ×ÀÃæ²úÆ·¼Æ»®ÖÐÐÄ
< ·µ»Ø²úÆ·
ÔÆ×ÀÃæÖ÷Ò³
ÔÆ×ÀÃæ

Çå¾²

Çå¾²ËùÓвúÆ·
< ·µ»Ø²úÆ·
Çå¾²Ö÷Ò³
Çå¾²

ËùÓÐÊÖÒÕ½â¾ö¼Æ»®

·þÎñ²úÆ·

·þÎñ²úÆ·ËùÓвúÆ·
< ·µ»Ø²úÆ·
·þÎñ²úÆ·Ö÷Ò³
·þÎñ²úÆ·
·þÎñÖ§³Ö
< ·µ»ØÖ÷²Ëµ¥
·þÎñÓëÖ§³ÖÖÐÐÄ
·þÎñÓëÖ§³Ö
·þÎñ¹¤¾ß
·þÎñƽ̨
  • ÔÆ×ÀÃæ·þÎñƽ̨
  • î£Ò×·þÎñƽ̨
  • ºÏ×÷»ï°é·þÎñƽ̨
½Ìѧ·þÎñ
  • 97¹ú¼ÊICTÈ˲ŽÌÓýÖÐÐÄ
  • УÆóºÏ×÷
  • ÈÏ֤ϵͳ
  • ÅàѵÍýÏë
ºÏ×÷»ï°é
< ·µ»ØÖ÷²Ëµ¥
ºÏ×÷»ï°éÖÐÐÄ
ºÏ×÷»ï°é
³ÉΪ97¹ú¼Ê»ï°é
ÊÛǰӪÏú
  • Êг¡×ÊÁÏ¿â(ºÏ×÷»ï°é)
  • 97¹ú¼Ê²úÆ·ÉèÖÃÆ÷
  • ÓªÏú×ÊÁÏÆ½Ì¨
  • ÊÛǰÈÏÖ¤
  • ÊÛǰ¹¤¾ß°ü
  • ºÏ×÷»ï°éÀñÎï¿â
  • e-Learning
  • ²úÆ·×ÊÖÊÅÌÎÊ
  • Ô¶³ÌPOC
ÏúÊÛÓë¶©µ¥
ÊÛºó¼°·þÎñ
  • ÊÛºóÈÏÖ¤
  • Êۺ󹤾߰ü
  • RSDP 97¹ú¼Ê·þÎñ½»¸¶Æ½Ì¨
  • ÊÛºó·þÎñÈÏÖ¤
  • ÊÛºó֪ʶƽ̨
  • ÇþµÀ·þÎñ¹ÜÀíϵͳ£¨CSM£©
  • SMBÇþµÀ¿Í»§·þÎñƽ̨£¨CCSP£©
Óû§ÖÐÐÄ
  • ϵͳָµ¼´óÈ«
  • Õ˺ŹÜÀí
  • ÏÂÔØµç×ÓÊÚÈ¨ÅÆ
  • ǩԼÐÅÏ¢Éó²é
  • ×ÊÖÊÅÌÎÊ
  • ǩչÜÀí
  • ·µÀû¹ÜÀí
  • î£Ò×ÊÖÒÕÈÏÖ¤ÅÌÎÊ
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
  • Global / English
  • Japan / ÈÕ±¾ÕZ
  • T¨¹rkiye / T¨¹rk?e
  • Vietnam / Vi?t Nam
  • Indonesia / Indonesian
  • Thailand / ???????
  • Spain / Espa?ol (Espa?a)
  • Portugal / Portugu¨ºs
  • France / Fran?ais
  • Poland / Polski
  • Kazakhstan / P§å§ã§ã§Ü§Ú§Û
  • Germany / Deutsch
  • Italy / Italiano
  • Brazil / Portugu¨ºs(Brazil)
  • LATAM / Espa?ol (Am¨¦rica Latina))
  • 97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    ΢Èí Exchange·þÎñÆ÷¶à¸ö¸ßΣÎó²îͨ¸æ

    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ Ðû²¼Ê±¼ä£º2021-03-04
    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    2021Äê3ÔÂ3ÈÕ£¬97¹ú¼ÊÍøÂçÇå¾²Ó¦¼±ÍŶÓ×·×Ùµ½Î¢ÈíÓÚ2021Äê3ÔÂ2ÈÕ Õë¶ÔExchange·þÎñÆ÷Ðû²¼Á˶à¸ö¸ßΣÎó²îµÄΣº¦Í¨¸æ£¬Îó²î±àºÅΪCVE-2021-26855,CVE-2021-26857,CVE-2021-26858,CVE-2021-27065£¬ÔÚCVSSÖжÔÕâЩÎó²î¸ø³öÁ˽ÏÁ¿¸ßµÄÆÀ·Ö¡£ÍþвÐж¯ÕßʹÓÃÕâЩÎó²î»á¼ûÍâµØExchange·þÎñÆ÷£¬´Ó¶ø¿ÉÒÔ»á¼ûµç×ÓÓʼþÕÊ»§£¬²¢ÔÊÐí×°ÖÃÆäËû¶ñÒâÈí¼þÒÔÔö½ø¶ÔÊܺ¦ÕßÇéÐεĺã¾Ã»á¼û¡£


    ¶Ô´Ë£¬97¹ú¼ÊÍøÂçÇå¾²Ó¦¼±ÍŶӽ¨Òé¿í´óÓû§ÊµÊ±½«ExchangeÉý¼¶µ½×îа汾¡£Óë´Ëͬʱ£¬Çë×öºÃ×ʲú×Ô²éÒÔ¼°Ô¤·ÀÊÂÇ飬ÒÔÃâÔâÊܺڿ͹¥»÷¡£

     


    Ó°Ïì°æ±¾

    Exchange server£º2010/2013/2016/2019
    Exchange online£º²»ÊÜÓ°Ïì¡£


    Îó²îÏêÇé

     

    1.    CVE-2021-26855: ·þÎñ¶ËÇëÇóαÔìÎó²î

    Exchange ·þÎñÆ÷¶ËÇëÇóαÔ죨SSRF£©Îó²î£¬Ê¹ÓôËÎó²îµÄ¹¥»÷ÕßÄܹ»·¢ËÍí§Òâ HTTP ÇëÇó²¢Í¨¹ý Exchange Server ¾ÙÐÐÉí·ÝÑéÖ¤¡£


    2.   CVE-2021-26857: ÐòÁл¯Îó²î

    Exchange ·´ÐòÁл¯Îó²î£¬¸ÃÎó²îÐèÒª¹ÜÀíԱȨÏÞ£¬Ê¹ÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚ Exchange ·þÎñÆ÷ÉÏÒÔ SYSTEM Éí·ÝÔËÐдúÂë¡£


    3.   CVE-2021-26858: í§ÒâÎļþдÈëÎó²î

    Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄí§ÒâÎļþдÈëÎó²î¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬¿ÉÒÔʹÓôËÎó²î½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£¸ÃÎó²î¿ÉÒÔ ÅäºÏ CVE-2021-26855 SSRF Îó²î¾ÙÐÐ×éºÏ¹¥»÷¡£


    4.   CVE-2021-27065: í§ÒâÎļþдÈëÎó²î

    Exchange ÖÐÉí·ÝÑéÖ¤ºóµÄí§ÒâÎļþдÈëÎó²î¡£¹¥»÷Õßͨ¹ý Exchange ·þÎñÆ÷½ø ÐÐÉí·ÝÑéÖ¤ºó£¬¿ÉÒÔʹÓôËÎó²î½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£¸ÃÎó²î¿ÉÒÔ ÅäºÏ CVE-2021-26855 SSRF Îó²î¾ÙÐÐ×éºÏ¹¥»÷¡£


    Çå¾²½¨Òé

    ΢ÈíÒÑÐû²¼Ïà¹ØÇå¾²¸üУ¬Óû§¿É¸ú½øÒÔÏÂÁ´½Ó¾ÙÐÐÉý¼¶:


    CVE-2021-26855: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26855

    CVE-2021-26857: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26857
    CVE-2021-26858: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-26858
    CVE-2021-27065: https://msrc.microsoft.com/update-guide/vulnerability/CVE2021-27065


    ¹¥»÷¼ì²â½¨Òé

     

    01 CVE-2021-26855

    ¿ÉÒÔͨ¹ýÒÔÏÂExchange HttpProxyÈÕÖ¾¾ÙÐмì²â£º


    %PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\HttpProxy

    ¿ÉÒÔͨ¹ýÔÚÈÕÖ¾ÌõÄ¿ÖÐËÑË÷AuthenticatedUserÊÇ·ñΪ¿Õ²¢ÇÒAnchorMailboxÊÇ·ñ°üÀ¨ServerInfo?* / *ģʽʶ±ðÎó²îʹÓá£ÒÔÏÂPowershell¿ÉÖ±½Ó¾ÙÐÐÈÕÖ¾¼ì²â£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷£º


    Import-Csv-Path(Get-ChildItem-Recurse-Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy”- Filter ‘*.log’).FullName | Where-Object {  $_.AuthenticatedUser -eq ” -and $_.AnchorMailbox -like ‘ServerInfo~*/*’ } | select DateTime, AnchorMailbox

    ÈôÊǼì²âµ½ÁËÈëÇÖ£¬¿ÉÒÔͨ¹ý¼ì²âAnchorMailbox·¾¶ÖÐÖ¸¶¨Ìض¨Ó¦ÓóÌÐòµÄÈÕÖ¾À´»ñÈ¡¹¥»÷Õß½ÓÄÉÁËÄÄЩÔ˶¯£º


    %PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging

     

    02 CVE-2021-26858

    ͨ¹ýExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-26858ʹÓãº


    ÈÕ־Ŀ¼£º
    C:\Program Files\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog


    ¿Éͨ¹ýÒÔÏÂÏÂÁî¾ÙÐпìËÙä¯ÀÀ£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷£º


    findstr /snip /c:”Download failed and temporary file” “%PROGRAMFILES%\Microsoft\Exchange Server\V15\Logging\OABGeneratorLog\*.log”


    03 CVE-2021-26857

    ͨ¹ýWindowsÓ¦ÓóÌÐòÊÂÎñÈÕÖ¾¼ì²âCVE-2021-26857ʹÓã¬Ê¹Óô˷´ÐòÁл¯¹ýʧ½«½¨Éè¾ßÓÐÒÔÏÂÊôÐÔµÄÓ¦ÓóÌÐòÊÂÎñ£º


    ȪԴ£ºMSExchangeͳһÐÂÎÅ
    EntryType£º¹ýʧ
    ÊÂÎñÐÂÎŰüÀ¨£ºSystem.InvalidCastExceptio


    ¸ÃÎó²îµ¥¶ÀʹÓÃÄѶÈÉԸߣ¬¿ÉʹÓÃÒÔÏÂÏÂÁîÔÚÓ¦ÓóÌÐòÊÂÎñÈÕÖ¾ÖÐÅÌÎÊÕâЩÈÕÖ¾ÌõÄ¿£¬²¢¼ì²éÊÇ·ñÊܵ½¹¥»÷¡£


    Get-EventLog -LogName Application -Source “MSExchange Unified Messaging” -EntryType Error | Where-Object { $_.Message -like “*System.InvalidCastException*” }


    04 CVE-2021-27065

    ͨ¹ýÒÔÏÂExchangeÈÕÖ¾Îļþ¼ì²âCVE-2021-27065ʹÓã¬


    C£º\ Program Files \ Microsoft \ Exchange Server \ V15 \ Logging \ ECP \ Server

    ËùÓÐSet- <AppName> VirtualDirectoryÊôÐÔ¶¼²»Ó¦°üÀ¨¾ç±¾¡£InternalUrlºÍExternalUrlÓ¦¸Ã½öÊÇÓÐÓÃUris¡£


    ͨ¹ýpowershellÏÂÁî¾ÙÐÐÈÕÖ¾¼ì²â£¬²¢¼ì²éÊÇ·ñÔâµ½¹¥»÷:


    Select-String -Path “$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\ECP\Server\*.log” -Pattern ‘Set-.+VirtualDirectory’


    Çå¾²·À»¤»º½â

    ¹¥»÷ÕßʹÓÃÉÏÊöÎó²î¿ÉÒÔ¾ÙÐÐwebshell¡¢¶ñÒâÎļþÉÏ´«ÒÔ¼°¶ñÒâÍøÂçͨѶÐÐΪ¡£Îª»º½â¹¥»÷ÕßʹÓÃÕâЩÎó²î¾ÙÐкóÐøµÄ¹¥»÷Ðж¯£¬½¨Òé¿Í»§ÊµÊ±½ÓÄÉÇå¾²Íø¹Ø²úÆ·¾ÙÐÐʵʱµÄ¹¥»÷·À»¤Ó뻺½â¡£

     

     

    ²úÆ·

    ˵Ã÷

    RG-APT¸ß¼¶Íþв¼ì²âϵͳ

    97¹ú¼Ê¸ß¼¶Íþв¼ì²âϵͳ£¨RG-APT£©»ùÓÚ“Îļþ+Á÷Á¿”˫ά¶ÈÆÊÎö¼Ü¹¹¡£Í¨¹ý¶ÀÍ̵İ˴󽹵ãÒýÇæ£¬×ÛºÏÍþвÇ鱨¡¢ÐÐΪģ×Ó¡¢»úеѧϰ¡¢ÐéÄ⻯ɳÏäºÍÇå¾²ÌØÕ÷¿âµÈ¼ì²âÊÖÒÕÁýÕÖʽ·¢Ã÷¸ß¼¶Î´ÖªÍþв.

    RG-WALLϵÁÐÏÂÒ»´ú·À»ðǽ

    ÏÂÒ»´ú·À»ðǽÍŽá·À²¡¶¾ÒÔ¼°ÍþвÇ鱨¼ì²â¡£¼ì²âÖ÷Á÷½©Ä¾È䣬aptÑù±¾¡£

    RG-BDS-TSP

    97¹ú¼ÊNFA̽Õëϵͳ£¬ÍŽá×îеÄÍþвÇ鱨£¬ÊµÊ±ÅбðÍøÂçÖд«ÊäÎļþ£¬ÅжÏDZÔÚ²¡¶¾¡£

     

    ÍŶÓÏÈÈÝ

     

    97¹ú¼ÊÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶÓ£¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬Õë¶Ô×îÐÂÇå¾²Îó²î£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ÙºÍÆÊÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐÓõÄÇå¾²·À»¤Õ½ÂÔÓë½â¾ö¼Æ»®¡£

     

    97¹ú¼Ê“ÍøÂç+Çå¾²”Ö÷ÕŽ«ÍøÂç×°±¸µÄÇå¾²ÄÜÁ¦³ä·ÖÑéÕ¹£¬ÍøÂç×°±¸¡¢Çå¾²×°±¸ÓëÇ徲ƽ̨ÖÇÄÜÁª¶¯£¬Àë±ðÇå¾²¹Âµº£¬×é³ÉÕûÍøÁª¶¯µÄÇå¾²°ü¹Üϵͳ£¬ÊµÏÖ·À»¤¡¢Çå¾²Õ¹Íû¡¢ÆÊÎöºÍÏìÓ¦µÈÇå¾²ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£

     

    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
    ?ÈçÄúÐèÒª97¹ú¼ÊÇå¾²£¬ÇëÁôÏÂÄúµÄÁªÏµ·½·¨

    ¹Ø×¢97¹ú¼Ê
    ¹Ø×¢97¹ú¼Ê¹ÙÍøÎ¢ÐÅ
    ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

    ·µ»Ø¶¥²¿

    ÊÕÆð
    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
    97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
    ÇëÑ¡Ôñ·þÎñÏîÄ¿
    ¹Ø±Õ×Éѯҳ
    ÊÛǰ×Éѯ ÊÛǰ×Éѯ
    ÊÛǰ×Éѯ
    ÊÛºó·þÎñ ÊÛºó·þÎñ
    ÊÛºó·þÎñ
    Òâ¼û·´Ïì Òâ¼û·´Ïì
    Òâ¼û·´Ïì
    ¸ü¶àÁªÏµ·½·¨
    ÍøÕ¾µØÍ¼