Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

ʱ¼ä£º2021-10-28 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐÄ

·ÖÏíµ½£º

    Åä¾°

    ¿ËÈÕ £¬£¬£¬£¬£¬ £¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!ÍþвÇ鱨ÖÐÐĺìÓêµÎÍŶÓÍŽáºìÓêµÎÔÆÉ³Ïä²ú³öµÄÏà¹ØIOCÇ鱨 £¬£¬£¬£¬£¬ £¬£¬²¢ÅäºÏÄÚ²¿ÃÛ¹Þϵͳ £¬£¬£¬£¬£¬ £¬£¬ÔÚÈ«Çò¹æÄ£ÄÚÊ׸ö¼à²âµ½¶àÀý×éºÏʹÓÃChromeä¯ÀÀÆ÷¸ßΣÎó²îºÍWindowsÄÚºËȨÏÞÌáÉýÎó²îÓÃÓÚ´©Í¸Chromeä¯ÀÀÆ÷ɳºÐʵÏÖÔ¶³Ì´úÂëÖ´Ðе͍Ïò¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬ÊµÏÖÁË»ùÓÚÍþвÇ鱨ºÍÁ÷Á¿ÆÊÎöµÄÔÚÒ°Chromeä¯ÀÀÆ÷Îó²î¹¥»÷¼ì²âµÄÍ»ÆÆ ¡£¡£¡£¡£¡£¡£¡£¡£

    ¹ØÓÚPuzzleMaker

    Í¨Ì«¹ýÎöÑÐÅÐ £¬£¬£¬£¬£¬ £¬£¬ºìÓêµÎÍŶӲ¶»ñµ½µÄChromeä¯ÀÀÆ÷ÍêÕûÎó²îʹÓù¥»÷Á´ÒÉËÆ½ñÄê6ÔÂ8ÈÕÓÉ¿¨°Í˹»ùÅû¶µÄPuzzleMaker×éÖ¯Õë¶Ô¶à¼Ò¹«Ë¾µÄ¸ß¶ÈÕë¶ÔÐÔ¹¥»÷Ô˶¯ÖÐËùʹÓõÄÎó²î¹¥»÷Á´ £¬£¬£¬£¬£¬ £¬£¬PuzzleMakerÔÚ¹¥»÷Öд®ÁªÊ¹ÓÃÁËChromeºÍWindows10µÄ0dayÎó²î £¬£¬£¬£¬£¬ £¬£¬ÆäÖаüÀ¨Ò»¸öChrome0dayºÍÁ½¸öWindows100day ¡£¡£¡£¡£¡£¡£¡£¡£¶øÆäʱµÄÏà¹ØÑо¿Ö°Ô±²¢Î´»¹Ô­ÍêÕûµÄ¹¥»÷Á´ £¬£¬£¬£¬£¬ £¬£¬Ò²ÔÝδ²¶»ñ´øÓÐÍêÕûÎó²îʹÓõÄJavaScript´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£¹Ê±¾´ÎÊÇÊ״β¶»ñµ½ÔÚÒ°µÄÍêÕûÎó²îʹÓù¥»÷ ¡£¡£¡£¡£¡£¡£¡£¡£

    ÓÉÓÚ¸ÃÎó²îÒѾ­ÓÃÓÚÕæÊµµÄAPT¹¥»÷ £¬£¬£¬£¬£¬ £¬£¬ºìÓêµÎÍŶӵÚһʱ¼ä¸´ÏÖ²¢È·Èϲ¶»ñµ½µÄÑù±¾¿ÉÓà £¬£¬£¬£¬£¬ £¬£¬²¢¶Ô¸ÃÎó²îʹÓõÄÏà¹ØÊÖÒÕϸ½Ú¾ÙÐÐÁËÆÊÎö £¬£¬£¬£¬£¬ £¬£¬ÒÔ±ãÇå¾²³§ÉÌ¿ÉÒÔÔöÌíÏìÓ¦µÄ·À»¤²½·¥ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    https://twitter.com/RedDrip7/status/1453291780078714880

    ´©Í¸ChromeɳºÐµÄÎó²îʹÓÃÑÝʾÊÓÆµ

    ºìÓêµÎÍŶӸ´ÏÖµÄÔÚÒ°Chrome´©Í¸É³ºÐÎó²îʹÓÃÊÓÆµÈçÏ£º

    Îó²îʹÓÃÆÊÎö

    ¸ÃÔÚÒ°Îó²îʹÓÃÁ´Í¨¹ýChromeÎó²îCVE-2021-21224ºÍWindowsÄÚºËÌáȨÎó²îCVE-2021-31956¾ÙÐÐ×éºÏ¹¥»÷ ¡£¡£¡£¡£¡£¡£¡£¡£Õû¸öʹÓûùÓÚ4ÔµÄй¶EXP £¬£¬£¬£¬£¬ £¬£¬¿ÉÊDz¿·Ö×Ö¶Î×öÁËÏìÓ¦µÄ»ìÏý ¡£¡£¡£¡£¡£¡£¡£¡£

    ÔÚËæºóÆÊÎö¸ÃEXPʹÓôúÂëµÄʱ¼ä·¢Ã÷ £¬£¬£¬£¬£¬ £¬£¬Ê¹ÓÃÖлñÈ¡µ½í§ÒâµØµã¶Áдԭ×Óºó £¬£¬£¬£¬£¬ £¬£¬Ð´ÈëÖ´ÐеÄShellCodeÓÐÁ½¶Î £¬£¬£¬£¬£¬ £¬£¬ÕâÀïÒýÆðÁËÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!×¢ÖØ £¬£¬£¬£¬£¬ £¬£¬Ò»Ñùƽ³£À´ËµChromeÎó²îÊÇÎÞ·¨×ÔÁ¦Ö´ÐÐµÄ £¬£¬£¬£¬£¬ £¬£¬ÐèÒªÒ»¸öÌáȨµÄÎó²îÓÃÓÚɳÏäÈÆ¹ý ¡£¡£¡£¡£¡£¡£¡£¡£

    ¾­ÓɲâÊÔ·¢Ã÷Õû¸öÎó²îCVE-2021-21224²¿·ÖÄÜÕý³£Ö´ÐÐ £¬£¬£¬£¬£¬ £¬£¬ÈçÏÂËùʾµÚÒ»¶ÎShellCodeдÈëµ½ÁËWASM¹¤¾ßµÄ¿É¶Á¿Éд¿ÉÖ´ÐÐÄÚ´æÒ³ÃæÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    Á½¶ÎShellCodeÖдó×ÚµÄAPIŲÓÃͨ¹ýsyscallµÄ·½·¨Íê³É ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    Í¨¹ýµ÷ÊÔ·¢Ã÷ £¬£¬£¬£¬£¬ £¬£¬µÚÒ»¶ÎдÈëµÄShellCodeÏÖʵÉÏÊÇCVE-2021-31956µÄʹÓôúÂë £¬£¬£¬£¬£¬ £¬£¬¸Ã0dayÎó²îÓÚ½ñÄêÁùÔ±»¿¨°Í˹»ùÅû¶ÔÚPuzzleMakerÍÅ»ïµÄ¹¥»÷Öб»Ê¹Óà £¬£¬£¬£¬£¬ £¬£¬ÇɺϵÄÊǸÃÎó²îÔÚ¿¨°Í˹»ùµÄ±¨¸æÖлùÓÚʱ¼äÍÆ²âÊÇ×÷ΪCVE-2021-21224Õâ¸öChrome0dayÎó²î¾ÙÐй¥»÷ʱµÄÌáȨģ¿£¿£¿£¿£¿£¿ £¿£¿é(ÓÉÓÚÔÚÏÖʵµÄ¹¥»÷Öв¢Ã»Óв¶»ñµ½ChromeÎó²îµÄ¹¥»÷´úÂë) £¬£¬£¬£¬£¬ £¬£¬Òò´ËÕâÀïÓÐÀíÓÉÏÓÒɸôι¥»÷¿ÉÄܺÍPuzzleMakerÓÐ¹Ø £¬£¬£¬£¬£¬ £¬£¬±ðµÄÖ»¹Ü4¸öÔÂÒÑÍùÁË £¬£¬£¬£¬£¬ £¬£¬CVE-2021-31956Õâ¸öÎó²î×Ô¼ºµÄʹÓôúÂëûÓб»¹ûÕæ ¡£¡£¡£¡£¡£¡£¡£¡£

    ¸ÃÎó²î±¬·¢ÔÚÄÚºËÄ£¿£¿£¿£¿£¿£¿ £¿£¿éntfs.sysµÄº¯ÊýNtfsQueryEaUserEaListÖÐ £¬£¬£¬£¬£¬ £¬£¬ÈκÎÔÚNTFS·ÖÇøÉÏÓÐдÈëȨÏÞµÄÎļþ¾ä±úµÄÀú³Ì¶¼¿ÉÒÔ»á¼ûËü £¬£¬£¬£¬£¬ £¬£¬ÕâÀï¾Í°üÀ¨ÁËChromeµÄäÖȾÀú³Ì £¬£¬£¬£¬£¬ £¬£¬Òò´Ë¸ÃÎó²îºÜÊÇÊÊÓÃÓÚÍ»ÆÆÉ³Ïä £¬£¬£¬£¬£¬ £¬£¬µ±NtfsQueryEaUserEaList´¦Öóͷ£ÎļþµÄÍØÕ¹ÊôÐÔÁÐ±í £¬£¬£¬£¬£¬ £¬£¬²¢½«Öµ·µ»Øµ½´æ´¢µÄ»º´æÇøÊ± £¬£¬£¬£¬£¬ £¬£¬±£´æÒ»´¦ÕûÊýÏÂÒç £¬£¬£¬£¬£¬ £¬£¬´Ó¶øµ¼ÖÂÖ®ºóµÄÒç³ö ¡£¡£¡£¡£¡£¡£¡£¡£

    ÕâÀï½¹µãµÄÒç³öÂß¼­ÔÚea_block_size

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    out_buf_length/paddingÖµ°´ÈçÏ·½·¨ÌìÉú £¬£¬£¬£¬£¬ £¬£¬paddingµÄȡֵΪ0 £¬£¬£¬£¬£¬ £¬£¬1 £¬£¬£¬£¬£¬ £¬£¬2 £¬£¬£¬£¬£¬ £¬£¬3 £¬£¬£¬£¬£¬ £¬£¬Òò´ËÕâÀï¹¥»÷Õßͨ¹ýÊʵ±µÄ½á¹¹ £¬£¬£¬£¬£¬ £¬£¬µ±Ñ­»·ÖÐÌìÉúout_buf_lengthΪ0ʱ £¬£¬£¬£¬£¬ £¬£¬out_buf_length–padding½«·ºÆðÏÂÒç ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    ÕâÀïÒç³öдÈëµÄµØµãΪÎó²îº¯Êý¸¸º¯ÊýNtfsCommonQueryEaÖзÖÅɵÄÄں˷ÖÒ³³ØÖÐ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    Îó²îʹÓÃÁËWNFÄ£¿£¿£¿£¿£¿£¿ £¿£¿éÀ´Íê³Éí§ÒâµØµã¶ÁдÒÔ¼°Ô½½ç¶Áд²Ù×÷ £¬£¬£¬£¬£¬ £¬£¬Ê×ÏÈNtUpdateWnfStateData/NtDeleteWnfStateData¾ÙÐжÔÓ¦µÄÄÚ´æ½á¹¹ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    Å²Óú¯ÊýNtQueryEaFile´¥·¢ÏÂÒç ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    ×îÖÕͨ¹ýÐÞˢгÌtokenÌáÉýȨÏÞ £¬£¬£¬£¬£¬ £¬£¬ÕâÀïÏêϸµÄʹÓÃÆÊÎö²»ÔÙ׸Êö £¬£¬£¬£¬£¬ £¬£¬nccgroupµÄÎÄÕ“CVE-2021-31956exploitingthewindowskernelntfswithwnf”ÒѾ­ÆÊÎöµÃºÜÇåÎú £¬£¬£¬£¬£¬ £¬£¬¸ÐÐËȤµÄ¶ÁÕß¿ÉÒԴӲο¼Á´½ÓÕÒµ½¶ÔÓ¦ÎÄÕ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    ÈçÏÂËùʾ £¬£¬£¬£¬£¬ £¬£¬µÚÒ»¶Î°üÀ¨CVE-2021-31956ʹÓôúÂëµÄShellCodeÖ´ÐÐÍê±Ïºó £¬£¬£¬£¬£¬ £¬£¬¶ÔÓ¦expÒ³ÃæµÄäÖȾÀú³ÌÒѾ­ÊÇsystemȨÏÞ £¬£¬£¬£¬£¬ £¬£¬ºóÐøÖ´Ðеĵڶþ¶ÎShellCode½«ÒÔsystemµÄȨÏÞÔÚÊܺ¦Õß»úеÉÏÔËÐÐÈκζñÒâ´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    Í¨¹ýµÚÒ»¶ÎShellCodeÌáȨ´©¹ýɳÏäºó £¬£¬£¬£¬£¬ £¬£¬Ö´Ðеڶþ¶ÎShellCode £¬£¬£¬£¬£¬ £¬£¬×îÖÕ¿ªÆôÒ»¸öÏ̺߳ÍccµÄͨѶ ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    ÈçÏÂËùʾ»ñÈ¡wininetÏà¹ØµÄÁªÍøº¯ÊýºóʵÑé»á¼ûºóÐøµÄ¹¥»÷´úÂë ¡£¡£¡£¡£¡£¡£¡£¡£

¶À¼Ò²¶»ñ£¡ÔÚÒ°ÍêÕûChromeä¯ÀÀÆ÷Îó²îʹÓù¥»÷Á´ÆÊÎö

    ×ܽá

    ÏÖÔÚ°üÀ¨ÌìÑ۸߼¶Íþв¼ì²â²úÆ·ÔÚÄÚµÄÌìÇæÖÕ¶ËÇå¾²ÖÎÀíϵͳ¡¢NGSOC¡¢TIPÍþвÇ鱨ƽ̨¡¢Öǻ۷À»ðǽµÈÈ«ÏßÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!¹¥»÷¼ì²âÀà²úÆ·¶¼ÒѾ­Ö§³Ö¶Ô´ËÍþвµÄ¼ì²â £¬£¬£¬£¬£¬ £¬£¬Óû§¿ÉÒÔÉý¼¶Ïà¹ØµÄ×°±¸µ½×îеİ汾ºÍ¹æÔò¿â ¡£¡£¡£¡£¡£¡£¡£¡£

    ²Î¿¼Á´½Ó

    https://securelist.com/puzzlemaker-chrome-zero-day-exploit-chain/102771/

    https://research.nccgroup.com/2021/07/15/cve-2021-31956-exploiting-the-windows-kernel-ntfs-with-wnf-part-1/

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015ÍøÂçÇ徲ЧÀÍÈÈÏß

95015ÍøÂçÇ徲ЧÀÍÈÈÏß

ɨһɨ¹Ø×¢

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! ÔÚÏ߿ͷþ Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ! 95015

Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ

ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ

¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿