×ðÁú¿Ê±Ðû²¼Apache Log4j2Îó²î´¦Öóͷ£¼Æ»®£¬Çë×¥½ôÅŲéÉý¼¶~
¿ËÈÕ£¬×ðÁú¿Ê±°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚ Log4j2í§Òâ´úÂëÖ´ÐÐÎó²îµÄʹÓôúÂë¡£Log4j2Öб£´æJNDI×¢ÈëÎó²î£¬µ±³ÌÐò½«¿Í»§ÊäÈëµÄÊý¾Ý¾ÙÐÐÈÕÖ¾¼Í¼ʱ£¬¼´¿É´¥·¢´ËÎó²î£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¸Ã×é¼þÓ¦ÓùæÄ£ºÜÊÇÆÕ±é£¬È磺Apache Struts2¡¢Apache Solr¡¢Apache DruidµÈ¿ª·¢¿ò¼Ü¼°ÖÐÐļþÖУ¬Îó²îÏà¹ØÏ¸½ÚÓëPOCÒÑÔÚ»¥ÁªÍø¹ûÕæ£¬Îó²îʹÓüòÆÓ£¬Î£º¦Öش󣬽¨Òé¿Í»§¾¡¿ì¿ªÕ¹×Բ鲢¸üÐÂÖÁ×îа汾»òÆôÓÃÇå¾²·À»¤²úÆ·ÒÔ·ÀÓùÎó²î¡£
¸ÃÎó²îÀíÂÛÉÏÀ´½²ÊÇlog4j2×Ô¼ºµÄÕý³£¹¦Ð§£¬Ö»ÊǸù¦Ð§±»¶ñÒâʹÓá£Òªº¦µã´ÓMessagePatternConverter.formatÒªÁì×îÏÈ£¬Ê×ÏȸÃÒªÌå»áÅжÏÊäÈëµÄ×Ö·û´®ÖÐÊÇ·ñ°üÀ¨"${"

ÈôÊDZ£´æÔò»á½øÈëÅжÏÖУ¬Å²ÓÃconfig.getStrSubstitutor().replace(event, value)£¬ÎÊÌâconfig.getStrSubstitutor().replace(event, value)£¬config.getStrSubstitutor()Ö´ÐÐÍê³Éºó·µ»ØÒ»¸öStrSubstitutor¹¤¾ß£¬½ô½Ó×ÅŲÓÃStrSubstitutor.replaceÒªÁ죬ȻºóÔÚ¸ÃÒªÁìÖÐÓÖŲÓÃÁËsubstituteÒªÁì¡£

¸ÃÎó²î»á½«"${}"ÖеÄÄÚÈÝ¿´³É±í´ïʽ£¬´Ó¶ø¾ÙÐÐÔ¶³Ì¼ÓÔØ£¬ÔÚÕâÀïlog4j2µÄ±¾ÒâÓ¦¸ÃÊǽ«ldap·þÎñÆ÷ÉϸõصãÖÐËù¼Í¼µÄ¹¤¾ß¼ÓÔØµ½ÍâµØ£¬À´¾ÙÐÐÒ»¸ö×Ö·û´®Ìæ»»¡£ÏêϸµÄŲÓÃÕ»ÈçÏ£º

ÊÜÓ°Ïì°æ±¾¼°Ïà¹Ø²úÆ·
ÊÜÓ°Ïì°æ±¾
Apache log4j2 2.* <= Apache log4j2 2.15.1.rc1
Ö÷Á÷Ïà¹Ø²úÆ·
Spring-Boot-strater-log4j2
Apache Struts2
Apache Solr
Apache Flink
Apache Druid
ElasticSearch
Flume
Dubbo
Redis
¸ü¶à×é¼þ¿É²Î¿¼ÈçÏÂÁ´½Ó£º
https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/usages?p=1
Îó²î¼ì²âÒªÁì
ÊÖ¶¯¼ì²â
1.°×ºÐµÄÇéÐÎÏ¿ÉÒÔ¿´´úÂëÓÐûÓÐʹÓõ½Log4j2µÍ°æ±¾µÄjar°üÀ´¿ìËÙÅжϡ£ÒÔMaven¹¹½¨µÄÏîĿΪÀý£¬¿ÉÒÔÉó²éÆäpom.xmlÖÐÊÇ·ñÌí¼ÓÁ˵Ͱ汾log4j2µÄÒÀÀµ¡£

2. ʹÓúںвâÊÔ²åÈëPOC²âÊÔÏà¹Ø¹¦Ð§µãÊÇ·ñ±£´æÎó²î¡£


×ðÁú¿Ê±²úÆ·¼ì²â
# ×ðÁú¿Ê±Å³ÈõÐÔɨÃèÓëÖÎÀíϵͳ #
×ðÁú¿Ê±Å³ÈõÐÔɨÃèÓëÖÎÀíϵͳ¼¯³ÉÁËϵͳ©ɨ¡¢Web©ɨ¡¢Êý¾Ý¿â©ɨ¡¢Èõ¿ÚÁî¼ì²â¡¢»ùÏߺ˲éµÈ¹¦Ð§£¬´Ó¶à½Ç¶È¾ÙÐÐÐÅÏ¢×ʲúµÄųÈõÐÔÉ󼯣¬ÌṩרҵµÄÇå¾²ÆÊÎöºÍÐÞ²¹½¨Òé¡£
ÏÖÔÚ×ðÁú¿Ê±Å³ÈõÐÔɨÃèÓëÖÎÀíϵͳÒѽôÆÈ¸üÐÂLog4j2í§Òâ´úÂëÖ´ÐÐÎó²î¼ì²é²å¼þ£¬×ÊÖú¿Í»§¾ÙÐÐÎó²îÅŲ顣
ÅŲ齨Òé
×ðÁú¿Ê±Å³ÈõÐÔɨÃèÓëÖÎÀíϵͳÕë¶Ô´ËÎó²îµÄ¹æÔò¿â¸üÐÂÈçÏÂͼ£º

×ðÁú¿Ê±Å³ÈõÐÔɨÃèÓëÖÎÀíϵͳÕë¶Ô¸ÃÎó²î¼ì²éЧ¹ûÈçÏÂͼËùʾ £º

ÅŲéÒªÁì
1. ÔÚÏß×Ô¶¯Éý¼¶£¬ÔÚ¡°³¬µÈÖÎÀíÔ±¡±Õ˺š¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾²å¼þ¿âÉý¼¶¡¿¡ú¡¾Á¬Ã¦¸üС¿¡úÁ¬Ã¦Éý¼¶¡£
2.½¨ÉèÎó²îɨÃèʹÃü£¬É¨ÃèÍê³ÉºóÉó²é±¨¸æ£¬Èç±£´æ¸ÃÎó²î£¬¿Éƾ֤±¨¸æÖеÄÐÞ¸´½¨Òé¾ÙÐС°²¹È±¡±¡£
Îó²î»º½â¼Æ»®
¹Ù·½Éý¼¶
1. Apache Log4j2 2.15.1.rc1Òѱ»·¢Ã÷±£´æÈƹý£¬ÏÖÔÚÐè¸üÐÂÖÁ×îа汾2.15.1.rc2£¬ÏÂÔØµØµãÈçÏ£º
https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc2
2. ½¨Òé¶ÔÏà¹ØÁªÖ÷Á÷²úÆ·Èç Apache Struts2/Apache Solr/Apache Flink/Apache Druid µÈÒÑÖªÊÜÓ°ÏìµÄÓ¦Óü°×é¼þ¾ÙÐÐÉý¼¶
ÔÝʱ·À»¤²½·¥
1.ÔÚÏîÄ¿ÖÐÌí¼Ólog4j2.component.propertiesÎļþ£¬ÔÚÆäÖÐдÈëÄÚÈÝlog4j2.formatMsgNoLookups=true

2. Ìí¼ÓjvmÆô¶¯²ÎÊý£º
-Dlog4j2.formatMsgNoLookups=true
3. ϵͳÇéÐαäÁ¿ FORMAT_MESSAGES_PATTERN_DISABLE_LOOKUPS ÉèÖÃΪtrue
4. ¹Ø±Õ¶ÔÓ¦Ó¦ÓõÄÍøÂçÍâÁ¬£¬Õ¥È¡×Ô¶¯ÍâÁ¬¡£
×ðÁú¿Ê±²úÆ··À»¤
×ðÁú¿Ê±ÏÂÒ»´ú·À»ðǽ¡¢UTM¡¢WAF¡¢IPS¡¢IDS¡¢½©Ä¾ÈäµÈ²úÆ·¹æÔò¿â¾ùÒÑÉý¼¶Íê±Ï£¬¿ÉµÇ¼ftp://ftp.topsec.com.cnÉý¼¶ÖÐÐÄÏÂÔØ×îÐÂÉý¼¶°ü¡£
ÏÂÒ»´ú·À»ðǽ²úÆ·£¨NGFW£©¡¢UTM²úÆ·
×ðÁú¿Ê±ÒѾ½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨ips-v2021.12.10.tir£©£¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨£¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£
µã»÷¡¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾ÏµÍ³Î¬»¤¡¿¡ú¡¾ÏµÍ³¸üС¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿£¬Ñ¡Ôñ¡°ÈëÇÖ·ÀÓùÌØÕ÷¿â¡±ºóµã»÷¡°µ¼È롱¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

WebÓ¦Ó÷À»ðǽ²úÆ·£¨TopWAF£©
×ðÁú¿Ê±ÒѾ½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨waf-v2021.12.10£©£¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨£¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£
µã»÷¡¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾ÏµÍ³Î¬»¤¡¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿£¬¹´Ñ¡¡°WAF¹æÔò¿â¡±¸´Ñ¡¿ò£¬µã»÷¡°µ¼È롱¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

ÈëÇÖ¼ì²â²úÆ·£¨TopSentry£©¡¢ÈëÇÖ·ÀÓù²úÆ·£¨TopIDP£©¡¢½©Ä¾Èä¼ì²â²úÆ·£¨TopTVD£©
×ðÁú¿Ê±ÒѾ½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨ips-v2021.12.10.tir¡¢ngips-v2021.12.10.003.tor£©£¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨£¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£
µã»÷¡¾ÏµÍ³¡¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿£¬Ñ¡Ôñ¡°¹¥»÷¼ì²â¹æÔò¿â¡±µÄ¸´Ñ¡¿òºó£¬µã»÷¡°µ¼È롱¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

×ðÁú¿Ê±Ôƶ˷þÎñÉêÇë
×ðÁú¿Ê±Çå¾²ÔÆ·þÎñÒÀÍÐÔÆ¶Ë´óÊý¾Ýƽ̨£¬ÍŽáÌìϰ²ÅŵÄ̽Õë½Úµã¼°ÔÆ·þÎñÔËÓªÍŶӣ¬7x24СʱΪ¿Í»§Ìṩ»ùÓÚSaaSµÄÍøÂç×ʲú²â»æ¡¢ÍøÕ¾¼à²â¡¢ÔÆ·À»¤ÒÔ¼°ÍþвÇ鱨ÆÊÎöµÈ·þÎñ¡£
ÏÖÔÚ×ðÁú¿Ê±Çå¾²ÔÆ·þÎñƽ̨ÒѾ߱¸¶ÔApache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄÔ¶³Ì¼ì²âºÍ·À»¤ÄÜÁ¦¡£
×ʲúÌ»Â¶Ãæ¼ì²â·þÎñ£º¶ÔÄ¿µÄÍøÂç¿ìËÙ¡¢ÖÜÈ«µÄ̽²â£¬Ê¶±ðÊÜ¡°Log4j2¡±°æ±¾Ó°ÏìµÄ×ʲúÐÅÏ¢£¬¿ìËÙÏàʶΣº¦×ʲúÂþÑܼ°×°±¸ÏêÇé¡£
ÔÆ¼ì²â·þÎñ£ºÏßÉϽÓÈ룬µÚһʱ¼ä¶Ô¿Í»§ÍøÂçÇéÐξÙÐÐÎó²îɨÃ裬¿ìËÙÅŲéÊÇ·ñ±£´æ´ËÎó²î£¬Ç徲ר¼ÒÔ¶³ÌÌṩÐÞ¸´Ö§³Ö¡£
ÔÆWAF·À»¤£º»ùÓÚAIµÄһվʽWebӪҵΣº¦·À»¤·þÎñ£¬Äܹ»ÊµÊ±±£»¤ÍøÕ¾Çå¾²£¬Ìá¸ßWebÕ¾µãµÄÇå¾²ÐԺͿɿ¿ÐÔ¡£ÏÖÔÚÒÑÉý¼¶¹æÔò²¢¾ß±¸¶Ô¸ÃÎó²îµÄ·À»¤ÄÜÁ¦¡£
ÏêÇé¿É×Éѯ×ðÁú¿Ê±ÍâµØÏúÊÛ£¬»òͨ¹ý¹«Ë¾ÓÊÏ䣬Óʼþ·¢ËÍÖÁ£º
zhangkai@topsec.com.cn
yan_songqi@topsec.com.cn
×ÉѯÈÈÏߣº
18310916559¡¢13718958574