ʱ¼ä£º2022-11-02 ×÷ÕߣºÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT

Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT
ÖÂÁ¦ÓÚµÚһʱ¼äΪÆóÒµ¼¶Óû§ÌṩÇ徲Σº¦Í¨¸æºÍÓÐÓýâ¾ö¼Æ»®¡£¡£¡£¡£¡£¡£
Ç徲ͨ¸æ
OpenSSLÊÇÓÃÓÚ´«Êä²ãÇå¾²(TLS)ÐÒ飨ÒÔǰ³ÆÎªÇå¾²Ì×½Ó×Ö²ã(SSL)ÐÒ飩µÄǿʢ¡¢ÉÌÒµ¼¶¡¢¹¦Ð§ÆëÈ«µÄ¿ªÔ´¹¤¾ß°ü£¬£¬£¬£¬£¬£¬£¬£¬ÐÒéʵÏÖ»ùÓÚȫǿ¶ÈͨÓÃÃÜÂë¿â£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚ±£»£»£»£»£»£»£»¤ÅÌËã»úÍøÂçÉϵÄͨѶÃâÊÜÇÔÌý£¬£¬£¬£¬£¬£¬£¬£¬±»»¥ÁªÍøÐ§ÀÍÆ÷ÆÕ±éʹÓ㨰üÀ¨´ó´ó¶¼HTTPSÍøÕ¾£©¡£¡£¡£¡£¡£¡£
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERT¼à²âµ½OpenSSL¹Ù·½Ðû²¼ÁËÎó²îÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨OpenSSL¾Ü¾øÐ§ÀÍÎó²î(CVE-2022-3786)ºÍOpenSSLÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2022-3602)£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃCVE-2022-3786Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÖÆ×÷°üÀ¨¶ñÒâµç×ÓÓʼþµØµãµÄÖ¤Ê飬£¬£¬£¬£¬£¬£¬£¬ÒÔÒç³ö°üÀ¨"."µÄí§Òâ×Ö½ÚÊý£¬£¬£¬£¬£¬£¬£¬£¬´Ë»º³åÇøÒç³ö¿ÉÄܵ¼ÖÂЧÀÍÍ߽⡣¡£¡£¡£¡£¡£CVE-2022-3602Îó²î±£´æÓÚossl_punycode_decodeº¯Êý£¬£¬£¬£¬£¬£¬£¬£¬µ±¿Í»§¶Ë»òЧÀÍÆ÷ÉèÖÃΪÑéÖ¤X.509Ö¤ÊéʱŲÓô˺¯Êý£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÔÚµç×ÓÓʼþµØµã×ֶεÄÓòÖн¨Éè°üÀ¨punycodeµÄÌØÖÆÖ¤ÊéÀ´Ê¹ÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂЧÀÍÍ߽⻣»£»£»£»£»£»òDZÔÚµÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£
ÓÉÓÚCVE-2022-3602¿ÉÄÜÒý·¢Ô¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬£¬£¬¹Ù·½ÔÚÔ¤ÏÈͨ¸æÖн«ÆäÊÓΪ“ÑÏÖØ”Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚÐí¶àƽ̨ÒѾʵÏÖÁË¿ÍÕ»Òç³ö±£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ½µµÍÔ¶³Ì´úÂëÖ´ÐÐʹÓÃΣº¦£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇ´ËÎó²î±»½µ¼¶Îª“¸ßΣ”Îó²î¡£¡£¡£¡£¡£¡£
´ËǰÓÐ¶àÆªÎÄÕ½«CVE-2022-3602Îó²îÓë2014ÄêµÄHeartBleedÏàÌá²¢ÂÛ£¬£¬£¬£¬£¬£¬£¬£¬ÒýÆð´ó×ÚÇå¾²Ö°Ô±µÄ¹Ø×¢£¬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚ´ËÎó²îʹÓÃÌõ¼þÌõ¼þÊDZØÐèÉèÖÿͻ§¶Ë»òЧÀÍÆ÷ÒÔÑéÖ¤Ö¤ÊéÖжñÒâµç×ÓÓʼþµØµã£¬£¬£¬£¬£¬£¬£¬£¬Í¬Ê±½öÓ°ÏìOpenSSL3.x£¬£¬£¬£¬£¬£¬£¬£¬½øÒ»²½ÏÞÖÆÁËÎó²îµÄʹÓùæÄ££¬£¬£¬£¬£¬£¬£¬£¬´Ë´Î¸üеÄÎó²î¿ÉÄܲ»ÏñHeartBleedÄÇÑùÈÝÒ׿ɱ»ÆÕ±éʹÓ㬣¬£¬£¬£¬£¬£¬£¬ÒÔÊÇÓû§²»±Ø¹ýÓÚ¾ª»Å£¬£¬£¬£¬£¬£¬£¬£¬µ«ÈÔ½¨Ò龡¿ìÉý¼¶µ½Çå¾²°æ±¾¡£¡£¡£¡£¡£¡£
Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERTµÚһʱ¼äÆÊÎö²¢¸´ÏÖÁËOpenSSLÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2022-3602)£¬£¬£¬£¬£¬£¬£¬£¬¸´ÏÖ½ØÍ¼ÈçÏÂ:

ÍþвÆÀ¹À
´¦Öóͷ£½¨Òé
Ò»¡¢OpenSSL3.x²úÆ·¼ì²â¹æÔò
1.YARA¼ì²â¹æÔò
(1)OpenSSLµÄËùÓо²Ì¬±àÒë¶¼°üÀ¨Ò»¸ö°æ±¾×Ö·û´®£¬£¬£¬£¬£¬£¬£¬£¬Èç'OpenSSL3.0.62022Äê10ÔÂ11ÈÕ'£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ3.0.6Êǰ汾ºÅ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔϹæÔòÖ÷Òª¼ì²âÆäÖеÄ×Ö·û´®¡£¡£¡£¡£¡£¡£
ruleopenssl_version{
strings:
$re1=/OpenSSL\s3\.[0-6]{1}\.[0-9]{1}[a-z]{,1}/
condition:
$re1
(2)¸Ã¹æÔò˼Ð÷Ö÷ÒªÊDzéÕÒÒÀÀµOpenSSLµÄÖ÷Ó¦ÓóÌÐò£¬£¬£¬£¬£¬£¬£¬£¬µ«ÆÊÎö¿ÉÖ´ÐÐÎļþµÄµ¼Èë¡£¡£¡£¡£¡£¡£
import"elf"
import"pe"
ruleelf_import_openssl{
condition:
(elf.type==elf.ET_EXECorelf.type==elf.ET_DYN)and
foranyiin(0..elf.symtab_entries):
elf.symtab[i].namecontains"@OPENSSL_3"
rulepe_import_openssl{
condition:
pe.is_peand
foranyiin(0..pe.number_of_imports):
pe.import_details[i].library_namecontains"libcrypto-3"orpe.import_details[i].library_namecontains"libssl-3"
2.OSQueryÅÌÎÊ
ʹÓÃOsqueryµÄYARA±íÔÚËùÓÐÕýÔÚÔËÐеÄÀú³ÌÉÏÔËÐÐÒÔϹæÔò¡£¡£¡£¡£¡£¡£
WITHFIRST_QUERYAS(SELECTDISTINCT
proc.pid,
proc.path,
proc.cmdline,
proc.cwd,
mmap.pathASmmap_path
FROMprocess_memory_mapASmmap
LEFTJOINprocessesASprocUSING(pid))
SELECT*
FROMFIRST_QUERY
JOINyaraONyara.path=FIRST_QUERY.mmap_path
WHEREsigrule='ruleopenssl_3{
strings:
$re1=/OpenSSL\s3\.[0-6]{1}\.[0-9]{1}[a-z]{,1}/
condition:
$re1
'
ANDyara.count>0
¸ü¶àÎó²îÖ§³Ö²Î¿¼£ºhttps://www.akamai.com/blog/security-research/openssl-vulnerability-how-to-effectively-prepare
¶þ¡¢Îó²îÓ°Ïì²úÆ·ÅŲé
ÓÉÓÚOpenSSLÊÇÒ»¸ö½¹µãµÄ¿ªÔ´×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬Ðí¶àÈí¼þ»ò²úÆ·¿ÉÄÜ»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬£¬£¬Óû§ÐèҪʵʱ¹Ø×¢ÒÑʹÓÃÈí¼þµÄÇ徲ͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÔÚ²¿·Ö³§ÉÌÒѾÐû²¼×ÔÉí²úÆ·ÊÜÓ°ÏìµÄÏà¹ØÍ¨¸æ£º
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-W9sdCc2a
Èý¡¢°æ±¾Éý¼¶
ÏÖÔÚOpenSSL¹Ù·½ÒÑÕýʽÐû²¼ÐÞ¸´°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬½¨ÒéÊÜÓ°ÏìÓû§¾¡¿ìÉý¼¶ÖÁÇå¾²°æ±¾¡£¡£¡£¡£¡£¡£
OpenSSL3.xÉý¼¶µ½3.0.7°æ±¾£¬£¬£¬£¬£¬£¬£¬£¬¿É´ÓµØµãÖÐÏÂÔØÉý¼¶£ºhttps://www.openssl.org/source/mirror.html
×¢£ºÈôʹÓõÄÓ¦ÓóÌÐò×ÔÐдò°üOpenSSLʱ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçNode.js17.x¡¢18.x»ò19.x£¬£¬£¬£¬£¬£¬£¬£¬ÔòÐèÒªÉý¼¶Ó¦ÓóÌÐò×Ô¼º¡£¡£¡£¡£¡£¡£
²Î¿¼×ÊÁÏ
[1]https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html
[2]https://www.helpnetsecurity.com/2022/10/25/cve-2022-42827/
[3]https://github.com/NCSC-NL/OpenSSL-2022/blob/main/software/README.md
[4]https://mta.openssl.org/pipermail/openssl-announce/2022-November/000241.html
[5]https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c42165b5706e42f67ef8ef4c351a9a4c5d21639a
[6]https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=fe3b639dc19b325846f4f6801f2f4604f56e3de3
[7]https://www.akamai.com/blog/security-research/openssl-vulnerability-how-to-effectively-prepare
[8]https://securitylabs.datadoghq.com/articles/openssl-november-1-vulnerabilities/
[9]https://github.com/DataDog/security-labs-pocs/tree/main/proof-of-concept-exploits/openssl-punycode-vulnerability
[10]https://www.openssl.org/news/vulnerabilities.html
[11]https://www.openssl.org/news/secadv/20221101.txt
[12]https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0023
[13]https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-W9sdCc2a
[14]https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/
ʱ¼äÏß
2022Äê11ÔÂ2ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!CERTÐû²¼Ç徲Σº¦Í¨¸æ¡£¡£¡£¡£¡£¡£
µ½Òâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!NOX-Çå¾²¼à²âƽ̨ÅÌÎʸü¶àÎó²îÏêÇé
ʱ¼ä£º2026-04-22
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-20
ʱ¼ä£º2026-04-18
Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ¿ÉÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
½«Äú¶ÔÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!µÄÈκÎÒÉÎÊ
ÓÃÒÔÏ·½·¨¸æËßÎÒÃÇ
¿ì½Ý´°¿Ú
ÆìÏÂÍøÕ¾
¹ØÓÚÒâ°ºÌåÓý-¿Æ¼¼¸³Äܳ¡¾°,ÈÃÓéÀÖ¸üÓÐȤ!
95015ЧÀÍÈÈÏß
΢ÐŹ«ÖÚºÅ
Á¬Ã¦²¦´ò