ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
È«Ììºò7x24СʱЧÀÍ£º 400-777-0777
Çå¾²ÔÆÐ§ÀÍ

ׯÏÐÓÎÏ·Ðû²¼Apache Log4j2Îó²î´¦Öóͷ£¼Æ»® £¬ £¬Çë×¥½ôÅŲéÉý¼¶~

Apache Log4j2 ÊÇÒ»¸ö»ùÓÚ Java µÄÈÕÖ¾¼Í¼¹¤¾ß¡£¡£¡£¡£¡£¸Ã¹¤¾ßÖØÐ´ÁË Log4j ¿ò¼Ü £¬ £¬²¢ÇÒÒýÈëÁË´ó×Ú¸»ºñµÄÌØÕ÷¡£¡£¡£¡£¡£¸ÃÈÕÖ¾¿ò¼Ü±»´ó×ÚÓÃÓÚӪҵϵͳ¿ª·¢ £¬ £¬ÓÃÀ´¼Í¼ÈÕÖ¾ÐÅÏ¢¡£¡£¡£¡£¡£

ׯÏÐÓÎÏ·Ðû²¼Apache Log4j2Îó²î´¦Öóͷ£¼Æ»® £¬ £¬Çë×¥½ôÅŲéÉý¼¶~

Ðû²¼Ê±¼ä£º2021-12-10
ä¯ÀÀ´ÎÊý£º4569
·ÖÏí£º

¿ËÈÕ £¬ £¬×¯ÏÐÓÎÏ·°¢¶û·¨ÊµÑéÊÒ¼à²âµ½»¥ÁªÍøÉϹûÕæÐû²¼Á˹ØÓÚ Log4j2í§Òâ´úÂëÖ´ÐÐÎó²îµÄʹÓôúÂë¡£¡£¡£¡£¡£Log4j2Öб£´æJNDI×¢ÈëÎó²î £¬ £¬µ±³ÌÐò½«¿Í»§ÊäÈëµÄÊý¾Ý¾ÙÐÐÈÕÖ¾¼Í¼ʱ £¬ £¬¼´¿É´¥·¢´ËÎó²î £¬ £¬ÀÖ³ÉʹÓôËÎó²î¿ÉÒÔÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¸Ã×é¼þÓ¦ÓùæÄ£ºÜÊÇÆÕ±é £¬ £¬È磺Apache Struts2¡¢Apache Solr¡¢Apache DruidµÈ¿ª·¢¿ò¼Ü¼°ÖÐÐļþÖÐ £¬ £¬Îó²îÏà¹ØÏ¸½ÚÓëPOCÒÑÔÚ»¥ÁªÍø¹ûÕæ £¬ £¬Îó²îʹÓüòÆÓ £¬ £¬Î£º¦ÖØ´ó £¬ £¬½¨Òé¿Í»§¾¡¿ì¿ªÕ¹×Բ鲢¸üÐÂÖÁ×îа汾»òÆôÓÃÇå¾²·À»¤²úÆ·ÒÔ·ÀÓùÎó²î¡£¡£¡£¡£¡£

¸ÃÎó²îÀíÂÛÉÏÀ´½²ÊÇlog4j2×Ô¼ºµÄÕý³£¹¦Ð§ £¬ £¬Ö»ÊǸù¦Ð§±»¶ñÒâʹÓᣡ£¡£¡£¡£Òªº¦µã´ÓMessagePatternConverter.formatÒªÁì×îÏÈ £¬ £¬Ê×ÏȸÃÒªÌå»áÅжÏÊäÈëµÄ×Ö·û´®ÖÐÊÇ·ñ°üÀ¨"${"

ÈôÊDZ£´æÔò»á½øÈëÅжÏÖÐ £¬ £¬Å²ÓÃconfig.getStrSubstitutor().replace(event, value) £¬ £¬ÎÊÌâconfig.getStrSubstitutor().replace(event, value) £¬ £¬config.getStrSubstitutor()Ö´ÐÐÍê³Éºó·µ»ØÒ»¸öStrSubstitutor¹¤¾ß £¬ £¬½ô½Ó×ÅŲÓÃStrSubstitutor.replaceÒªÁì £¬ £¬È»ºóÔÚ¸ÃÒªÁìÖÐÓÖŲÓÃÁËsubstituteÒªÁì¡£¡£¡£¡£¡£

¸ÃÎó²î»á½«"${}"ÖеÄÄÚÈÝ¿´³É±í´ïʽ £¬ £¬´Ó¶ø¾ÙÐÐÔ¶³Ì¼ÓÔØ £¬ £¬ÔÚÕâÀïlog4j2µÄ±¾ÒâÓ¦¸ÃÊǽ«ldapЧÀÍÆ÷ÉϸõصãÖÐËù¼Í¼µÄ¹¤¾ß¼ÓÔØµ½ÍâµØ £¬ £¬À´¾ÙÐÐÒ»¸ö×Ö·û´®Ìæ»»¡£¡£¡£¡£¡£ÏêϸµÄŲÓÃÕ»ÈçÏ£º

ÊÜÓ°Ïì°æ±¾¼°Ïà¹Ø²úÆ·
ÊÜÓ°Ïì°æ±¾

Apache log4j2 2.* <= Apache log4j2 2.15.1.rc1

Ö÷Á÷Ïà¹Ø²úÆ·

Spring-Boot-strater-log4j2

Apache Struts2

Apache Solr

Apache Flink

Apache Druid

ElasticSearch

Flume

Dubbo

Redis

¸ü¶à×é¼þ¿É²Î¿¼ÈçÏÂÁ´½Ó£º

https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/usages?p=1

Îó²î¼ì²âÒªÁì
ÊÖ¶¯¼ì²â

1.°×ºÐµÄÇéÐÎÏ¿ÉÒÔ¿´´úÂëÓÐûÓÐʹÓõ½Log4j2µÍ°æ±¾µÄjar°üÀ´¿ìËÙÅжÏ¡£¡£¡£¡£¡£ÒÔMaven¹¹½¨µÄÏîĿΪÀý £¬ £¬¿ÉÒÔÉó²éÆäpom.xmlÖÐÊÇ·ñÌí¼ÓÁ˵Ͱ汾log4j2µÄÒÀÀµ¡£¡£¡£¡£¡£

2. ʹÓúںвâÊÔ²åÈëPOC²âÊÔÏà¹Ø¹¦Ð§µãÊÇ·ñ±£´æÎó²î¡£¡£¡£¡£¡£

ׯÏÐÓÎÏ·²úÆ·¼ì²â
# ׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳ #

ׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳ¼¯³ÉÁËϵͳ©ɨ¡¢Web©ɨ¡¢Êý¾Ý¿â©ɨ¡¢Èõ¿ÚÁî¼ì²â¡¢»ùÏߺ˲éµÈ¹¦Ð§ £¬ £¬´Ó¶à½Ç¶È¾ÙÐÐÐÅÏ¢×ʲúµÄųÈõÐÔÉó¼Æ £¬ £¬ÌṩרҵµÄÇå¾²ÆÊÎöºÍÐÞ²¹½¨Òé¡£¡£¡£¡£¡£

ÏÖÔÚׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳÒѽôÆÈ¸üÐÂLog4j2í§Òâ´úÂëÖ´ÐÐÎó²î¼ì²é²å¼þ £¬ £¬×ÊÖú¿Í»§¾ÙÐÐÎó²îÅŲé¡£¡£¡£¡£¡£

ÅŲ齨Òé

ׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳÕë¶Ô´ËÎó²îµÄ¹æÔò¿â¸üÐÂÈçÏÂͼ£º

ׯÏÐÓÎϷųÈõÐÔɨÃèÓëÖÎÀíϵͳÕë¶Ô¸ÃÎó²î¼ì²éЧ¹ûÈçÏÂͼËùʾ £º

ÅŲéÒªÁì

1. ÔÚÏß×Ô¶¯Éý¼¶ £¬ £¬ÔÚ¡°³¬µÈÖÎÀíÔ±¡±Õ˺š¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾²å¼þ¿âÉý¼¶¡¿¡ú¡¾Á¬Ã¦¸üС¿¡úÁ¬Ã¦Éý¼¶¡£¡£¡£¡£¡£

2.½¨ÉèÎó²îɨÃèʹÃü £¬ £¬É¨ÃèÍê³ÉºóÉó²é±¨¸æ £¬ £¬Èç±£´æ¸ÃÎó²î £¬ £¬¿Éƾ֤±¨¸æÖеÄÐÞ¸´½¨Òé¾ÙÐС°²¹È±¡±¡£¡£¡£¡£¡£

Îó²î»º½â¼Æ»®

¹Ù·½Éý¼¶

1. Apache Log4j2 2.15.1.rc1Òѱ»·¢Ã÷±£´æÈƹý £¬ £¬ÏÖÔÚÐè¸üÐÂÖÁ×îа汾2.15.1.rc2 £¬ £¬ÏÂÔØµØµãÈçÏ£º

https://github.com/apache/logging-log4j2/releases/tag/log4j-2.15.0-rc2

2. ½¨Òé¶ÔÏà¹ØÁªÖ÷Á÷²úÆ·Èç Apache Struts2/Apache Solr/Apache Flink/Apache Druid µÈÒÑÖªÊÜÓ°ÏìµÄÓ¦Óü°×é¼þ¾ÙÐÐÉý¼¶

ÔÝʱ·À»¤²½·¥

1.ÔÚÏîÄ¿ÖÐÌí¼Ólog4j2.component.propertiesÎļþ £¬ £¬ÔÚÆäÖÐдÈëÄÚÈÝlog4j2.formatMsgNoLookups=true

2. Ìí¼ÓjvmÆô¶¯²ÎÊý£º

-Dlog4j2.formatMsgNoLookups=true

3. ϵͳÇéÐαäÁ¿ FORMAT_MESSAGES_PATTERN_DISABLE_LOOKUPS ÉèÖÃΪtrue

4. ¹Ø±Õ¶ÔÓ¦Ó¦ÓõÄÍøÂçÍâÁ¬ £¬ £¬Õ¥È¡×Ô¶¯ÍâÁ¬¡£¡£¡£¡£¡£

ׯÏÐÓÎÏ·²úÆ··À»¤

ׯÏÐÓÎÏ·ÏÂÒ»´ú·À»ðǽ¡¢UTM¡¢WAF¡¢IPS¡¢IDS¡¢½©Ä¾ÈäµÈ²úÆ·¹æÔò¿â¾ùÒÑÉý¼¶Íê±Ï £¬ £¬¿ÉµÇ¼ftp://ftp.topsec.com.cnÉý¼¶ÖÐÐÄÏÂÔØ×îÐÂÉý¼¶°ü¡£¡£¡£¡£¡£

ÏÂÒ»´ú·À»ðǽ²úÆ·£¨NGFW£©¡¢UTM²úÆ·

ׯÏÐÓÎÏ·ÒѾ­½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨ips-v2021.12.10.tir£© £¬ £¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨ £¬ £¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£¡£¡£¡£¡£

µã»÷¡¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾ÏµÍ³Î¬»¤¡¿¡ú¡¾ÏµÍ³¸üС¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿ £¬ £¬Ñ¡Ôñ¡°ÈëÇÖ·ÀÓùÌØÕ÷¿â¡±ºóµã»÷¡°µ¼È롱¡£¡£¡£¡£¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

WebÓ¦Ó÷À»ðǽ²úÆ·£¨TopWAF£©

ׯÏÐÓÎÏ·ÒѾ­½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨waf-v2021.12.10£© £¬ £¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨ £¬ £¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£¡£¡£¡£¡£

µã»÷¡¾ÏµÍ³ÖÎÀí¡¿¡ú¡¾ÏµÍ³Î¬»¤¡¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿ £¬ £¬¹´Ñ¡¡°WAF¹æÔò¿â¡±¸´Ñ¡¿ò £¬ £¬µã»÷¡°µ¼È롱¡£¡£¡£¡£¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

ÈëÇÖ¼ì²â²úÆ·£¨TopSentry£©¡¢ÈëÇÖ·ÀÓù²úÆ·£¨TopIDP£©¡¢½©Ä¾Èä¼ì²â²úÆ·£¨TopTVD£©

ׯÏÐÓÎÏ·ÒѾ­½ôÆÈÐû²¼ÌØÕ÷¿âÉý¼¶°ü£¨ips-v2021.12.10.tir¡¢ngips-v2021.12.10.003.tor£© £¬ £¬¿Éͨ¹ýÔÚÏßÉý¼¶»òÀëÏßÉý¼¶µÄ·½·¨ £¬ £¬¼´¿É¶Ô´Ë¹¥»÷¾ÙÐмì²âºÍ·À»¤¡£¡£¡£¡£¡£

µã»÷¡¾ÏµÍ³¡¿¡ú¡¾¹æÔò¿âÉý¼¶¡¿ £¬ £¬Ñ¡Ôñ¡°¹¥»÷¼ì²â¹æÔò¿â¡±µÄ¸´Ñ¡¿òºó £¬ £¬µã»÷¡°µ¼È롱¡£¡£¡£¡£¡£

Éý¼¶ºó¿ÉÒýÓÃÏà¹ØÎó²î¹æÔò£º

ׯÏÐÓÎÏ·ÔÆ¶ËЧÀÍÉêÇë

ׯÏÐÓÎÏ·Çå¾²ÔÆÐ§ÀÍÒÀÍÐÔÆ¶Ë´óÊý¾Ýƽ̨ £¬ £¬Á¬ÏµÌìϰ²ÅŵÄ̽Õë½Úµã¼°ÔÆÐ§ÀÍÔËÓªÍÅ¶Ó £¬ £¬7x24СʱΪ¿Í»§Ìṩ»ùÓÚSaaSµÄÍøÂç×ʲú²â»æ¡¢ÍøÕ¾¼à²â¡¢ÔÆ·À»¤ÒÔ¼°ÍþвÇ鱨ÆÊÎöµÈЧÀÍ¡£¡£¡£¡£¡£

ÏÖÔÚׯÏÐÓÎÏ·Çå¾²ÔÆÐ§ÀÍÆ½Ì¨ÒѾ߱¸¶ÔApache Log4j2Ô¶³Ì´úÂëÖ´ÐÐÎó²îµÄÔ¶³Ì¼ì²âºÍ·À»¤ÄÜÁ¦¡£¡£¡£¡£¡£

×ʲúÌ»Â¶Ãæ¼ì²âЧÀÍ£º¶ÔÄ¿µÄÍøÂç¿ìËÙ¡¢ÖÜÈ«µÄ̽²â £¬ £¬Ê¶±ðÊÜ¡°Log4j2¡±°æ±¾Ó°ÏìµÄ×ʲúÐÅÏ¢ £¬ £¬¿ìËÙÏàʶΣº¦×ʲúÂþÑܼ°×°±¸ÏêÇé¡£¡£¡£¡£¡£

ÔÆ¼ì²âЧÀÍ£ºÏßÉϽÓÈë £¬ £¬µÚһʱ¼ä¶Ô¿Í»§ÍøÂçÇéÐξÙÐÐÎó²îɨÃè £¬ £¬¿ìËÙÅŲéÊÇ·ñ±£´æ´ËÎó²î £¬ £¬Ç徲ר¼ÒÔ¶³ÌÌṩÐÞ¸´Ö§³Ö¡£¡£¡£¡£¡£

ÔÆWAF·À»¤£º»ùÓÚAIµÄһվʽWebӪҵΣº¦·À»¤Ð§ÀÍ £¬ £¬Äܹ»ÊµÊ±±£»£»¤ÍøÕ¾Çå¾² £¬ £¬Ìá¸ßWebÕ¾µãµÄÇå¾²ÐԺͿɿ¿ÐÔ¡£¡£¡£¡£¡£ÏÖÔÚÒÑÉý¼¶¹æÔò²¢¾ß±¸¶Ô¸ÃÎó²îµÄ·À»¤ÄÜÁ¦¡£¡£¡£¡£¡£

ÏêÇé¿É×ÉѯׯÏÐÓÎÏ·ÍâµØÏúÊÛ £¬ £¬»òͨ¹ý¹«Ë¾ÓÊÏä £¬ £¬Óʼþ·¢ËÍÖÁ£º

zhangkai@topsec.com.cn

yan_songqi@topsec.com.cn

×ÉѯÈÈÏߣº

18310916559¡¢13718958574

¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿