¡¾Îó²îͨ¸æ¡¿PHP CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-4577£©

Ðû²¼Ê±¼ä 2024-06-07


Ò»¡¢Îó²î¸ÅÊö

Îó²îÃû³Æ

  PHP   CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î

CVE   ID

CVE-2024-4577

Îó²îÀàÐÍ

²ÎÊý×¢Èë¡¢RCE

·¢Ã÷ʱ¼ä

2024-06-07

Îó²îÆÀ·Ö

9.8

Îó²îÆ·¼¶

ÑÏÖØ

¹¥»÷ÏòÁ¿

ÍøÂç

ËùÐèȨÏÞ

ÎÞ

ʹÓÃÄѶÈ

µÍ

Óû§½»»¥

ÎÞ

PoC/EXP

ÒѹûÕæ

ÔÚҰʹÓÃ

δ·¢Ã÷

 

PHPÊÇÒ»ÃÅͨÓÿªÔ´¾ç±¾ÓïÑÔ£¬£¬ÆäÓï·¨½è¼øÎüÊÕC¡¢JavaºÍPerlµÈÊ¢ÐÐÅÌËã»úÓïÑÔµÄÌØµã£¬£¬Òò´ËÀûÓÚѧϰ£¬£¬Ê¹ÓÃÆÕ±é£¬£¬Ö÷ÒªÊÊÓÃÓÚWeb¿ª·¢ÁìÓò¡£¡£

6ÔÂ7ÈÕ£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍÅVSRC¼à²âµ½PHPÐû²¼Çå¾²¸üУ¬£¬ÐÞ¸´ÁËPHP CGI Windowsƽ̨Զ³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-4577£©£¬£¬ÏÖÔÚ¸ÃÎó²îµÄϸ½ÚÒѹûÕæ¡£¡£

PHPÓïÑÔÔÚÉè¼ÆÊ±ºöÂÔÁËWindowsϵͳÄÚ²¿¶Ô×Ö·û±àÂëת»»µÄBest-FitÌØÕ÷£¬£¬µ±PHPÔËÐÐÔÚWindowƽ̨ÇÒʹÓÃÁËÈç·±ÌåÖÐÎÄ(´úÂëÒ³950)¡¢¼òÌåÖÐÎÄ(´úÂëÒ³936)ºÍÈÕÎÄ(´úÂëÒ³932)µÈÓïϵʱ£¬£¬ÍþвÕ߿ɽṹ¶ñÒâÇëÇóÈÆ¹ýCVE-2012-1823µÄ·À»¤£¬£¬Í¨¹ý²ÎÊý×¢ÈëµÈ¹¥»÷ÔÚÄ¿µÄPHPЧÀÍÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£

 

¶þ¡¢Îó²î¸´ÏÖ

image.png


Èý¡¢Ó°Ïì¹æÄ£

PHP 8.3 < 8.3.8

PHP 8.2 < 8.2.20

PHP 8.1 < 8.1.29

×¢£º¸ÃÎó²îÓ°Ïì×°ÖÃÓÚWindowsϵͳÉϵÄPHP °æ±¾¡£¡£ÓÉÓÚPHP 8.0 ·ÖÖ§¡¢PHP 7 ÒÔ¼°PHP 5 ¹Ù·½ÒѲ»ÔÙά»¤£¬£¬ÍøÕ¾ÖÎÀíÔ±¿ÉÉó²éÊÇ·ñÊܸÃÎó²îÓ°Ïì²¢Ó¦ÓÃÏà¹Ø»º½â²½·¥¡£¡£

 

 

ËÄ¡¢Çå¾²²½·¥

4.1 Éý¼¶°æ±¾

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½PHP°æ±¾8.3.8¡¢8.2.20¡¢8.1.29»ò¸ü¸ß°æ±¾¡£¡£

ÏÂÔØÁ´½Ó£º

https://github.com/php/php-src/tags

4.2 ÔÝʱ²½·¥

Windowsƽ̨ÖÐApache HTTP Server ¼ÓÉÏPHP ×éºÏ¡¢XAMPP for Windows×°ÖõÄÒÔϳ¡¾°¿ÉÄÜÒ×ÊܸÃÎó²îÓ°Ï죺

1.     ½«PHP É趨ÓÚCGI ģʽÏÂÖ´ÐС£¡£ÔÚApache Httpd ÉèÖÃÎļþÖÐͨ¹ýActionÓï·¨½«¶ÔÓ¦µÄHTTP ÇëÇ󽻸øPHP-CGI¾ç±¾Îļþ´¦Öóͷ£Ê±£¬£¬ÊÜ´ËÎó²îÓ°Ï죬£¬³£¼ûÉ趨°üÀ¨µ«²»ÏÞÓÚ£º

AddHandler cgi-script .php

Action cgi-script "/cgi-bin/php-cgi.exe"

 »ò

    SetHandler application/x-httpd-php-cgi

Action application/x-httpd-php-cgi "/php-cgi/php-cgi.exe"

2. ½«PHP¾ç±¾Îļþ̻¶ÔÚÍâ(XAMPP Ô¤Éè×°ÖÃÉ趨)¡£¡£½«PHP ¾ç±¾Îļþ̻¶ÔÚCGI Ŀ¼ÏÂÒ²ÊÜ´ËÎó²îÓ°Ï죬£¬³£¼ûÇéÐΰüÀ¨µ«²»ÏÞÓÚ:

1)     ½«php.exe»òphp-cgi.exe¸´ÖƵ½/cgi-bin/Ŀ¼ÖС£¡£

2)     ½«PHP ×°ÖÃĿ¼ͨ¹ýScriptAlias̻¶µ½Í⣬£¬È磺

ScriptAlias /php-cgi/ "C:/xampp/php/"

»º½â£º

1.¹ØÓÚÎÞ·¨Á¬Ã¦Éý¼¶PHPµÄÓû§¡£¡£

¿Éͨ¹ýÏÂÁÐRewrite ¹æÔò×èÖ¹¹¥»÷£¬£¬Çë×¢ÖØÕâЩ¹æÔò½ö×÷Ϊ·±ÌåÖÐÎÄ¡¢¼òÌåÖÐÎļ°ÈÕÎÄÓïÑÔÇéÐÎÖеÄÔÝʱÐÔ»º½â»úÖÆ£¬£¬ÏÖʵ²Ù×÷Öн¨Òé¸üе½ÒÑÐÞ¸´°æ±¾»ò¸ü¸Ä¼Ü¹¹¡£¡£

RewriteEngine On

RewriteCond %{QUERY_STRING} ^%ad [NC]

RewriteRule .? - [F,L]

2.¹ØÓÚXAMPP for Windows Óû§¡£¡£

ÏÖÔÚXAMPP ÔÝδÕë¶Ô¸ÃÎó²îÐû²¼Ïà¹Ø¸üУ¬£¬ÈçÈ·ÈÏXAMPP ²»ÐèҪʹÓÃPHP CGI ¹¦Ð§£¬£¬¿Éͨ¹ýÐÞ¸ÄÏÂÁÐApache Httpd ÉèÖÃÎĵµÀ´»º½â¸ÃÎó²îÓ°Ïì:

ÔÚ¶ÔӦװÖÃĿ¼Ï£¬£¬ÈçC:/xampp/apache/conf/extra/httpd-xampp.confÖУ¬£¬ÕÒµ½ÏìÓ¦µÄÐУº

ScriptAlias /php-cgi/ "C:/xampp/php/"

½«Æä×¢Ê͵ô£¬£¬ÉúÑĺóÖØÆôЧÀÍ£º

# ScriptAlias /php-cgi/ "C:/xampp/php/"

4.3 ͨÓý¨Òé

l  °´ÆÚ¸üÐÂϵͳ²¹¶¡£¡£¬£¬ïÔ̭ϵͳÎó²î£¬£¬ÌáÉýЧÀÍÆ÷µÄÇå¾²ÐÔ¡£¡£

l  ÔöǿϵͳºÍÍøÂçµÄ»á¼û¿ØÖÆ£¬£¬Ð޸ķÀ»ðǽսÂÔ£¬£¬¹Ø±Õ·ÇÐëÒªµÄÓ¦Óö˿ڻòЧÀÍ£¬£¬ïÔÌ­½«Î£ÏÕЧÀÍ£¨ÈçSSH¡¢RDPµÈ£©Ì»Â¶µ½¹«Íø£¬£¬ïÔÌ­¹¥»÷Ãæ¡£¡£

l  ʹÓÃÆóÒµ¼¶Çå¾²²úÆ·£¬£¬ÌáÉýÆóÒµµÄÍøÂçÇå¾²ÐÔÄÜ¡£¡£

l  ÔöǿϵͳÓû§ºÍȨÏÞÖÎÀí£¬£¬ÆôÓöàÒòËØÈÏÖ¤»úÖÆºÍ×îСȨÏÞÔ­Ôò£¬£¬Óû§ºÍÈí¼þȨÏÞÓ¦¼á³ÖÔÚ×îµÍÏÞ¶È¡£¡£

l  ÆôÓÃÇ¿ÃÜÂëÕ½ÂÔ²¢ÉèÖÃΪ°´ÆÚÐ޸ġ£¡£

4.4 ²Î¿¼Á´½Ó

https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability/

https://bodhi.fedoraproject.org/updates/FEDORA-2024-52c23ef1ec

https://www.kb.cert.org/vuls/id/520827

https://www.php.net/downloads

 

 

Îå¡¢°æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

±¸×¢

V1.0

2024-06-07

Ê×´ÎÐû²¼

 

 

Áù¡¢¸½Â¼

6.1 ¿­Ðý¹ú¼ÊÓÎÏ·¼ò½é

¿­Ðý¹ú¼ÊÓÎÏ·½¨ÉèÓÚ1996Ä꣬£¬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ½¨ÉèµÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Çå¾²¸ß¿Æ¼¼ÆóÒµ¡£¡£ÊǺ£ÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Çå¾²²úÆ·¡¢Ç徲ЧÀͽâ¾ö¼Æ»®µÄÁ캽ÆóÒµÖ®Ò»¡£¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¿­Ðý¹ú¼ÊÓÎÏ·´óÏ㬣¬¹«Ë¾Ô±¹¤6000ÓàÈË£¬£¬Ñз¢ÍŶÓ1200ÓàÈË, ÊÖÒÕЧÀÍÍŶÓ1300ÓàÈË¡£¡£ÔÚÌìϸ÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬£¬ÓµÓÐÁýÕÖÌìϵÄÏúÊÛϵͳ¡¢ÇþµÀϵͳºÍÊÖÒÕÖ§³Öϵͳ¡£¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС£¡££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷Á¢ÒìµÄÇå¾²²úÆ·ºÍ×î¼Ñʵ¼ùЧÀÍ£¬£¬×ÊÖú¿Í»§ÖÜÈ«ÌáÉýÆäIT»ù´¡ÉèÊ©µÄÇå¾²ÐÔºÍÉú²úЧÄÜ£¬£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Çå¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Æð¾¢¡£¡£

6.2 ¹ØÓÚ¿­Ðý¹ú¼ÊÓÎÏ·

¿­Ðý¹ú¼ÊÓÎÏ·Çå¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÒÑÐû²¼1000¶à¸öÎó²îͨ¸æºÍΣº¦Ô¤¾¯£¬£¬ÎÒÃǽ«Ò»Á¬¸ú×ÙÈ«Çò×îеÄÍøÂçÇå¾²ÊÂÎñºÍÎó²î£¬£¬ÎªÆóÒµµÄÐÅÏ¢Çå¾²±£¼Ý»¤º½¡£¡£

¹Ø×¢ÎÒÃÇ£º

image.png