WordPress²å¼þDuplicatorÇå¾²Îó²îΣº¦Í¨¸æ

Ðû²¼Ê±¼ä 2020-02-25

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º7.5£¬£¬£¬£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Duplicator 1.3.28֮ǰ°æ±¾

Duplicator Pro 3.8.7.1֮ǰ°æ±¾


Îó²î¸ÅÊö


DuplicatorÊÇÒ»¸ö¼òÆÓµÄ±¸·ÝºÍÕ¾µãǨáãÊÊÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ËüʹWordPressÍøÕ¾ÖÎÀíÔ±Äܹ»Ç¨á㣬£¬£¬£¬¸´ÖÆ£¬£¬£¬£¬Òƶ¯»ò¿ËÂ¡ÍøÕ¾¡£¡£¡£¡£¡£¡£¡£¡£


WordPressÌåÏÖ£¬£¬£¬£¬¸ÃÈí¼þÒѾ­±»ÏÂÔØÁè¼Ý1500Íò´Î£¬£¬£¬£¬²¢ÔÚÁè¼Ý100Íò¸öÍøÕ¾ÉÏʹÓᣡ£¡£¡£¡£¡£¡£¡£


ÔÚ°æ±¾1.3.28֮ǰµÄDuplicatorºÍ°æ±¾3.8.7.1֮ǰµÄDuplicator Pro°üÀ¨Ò»¸öδ¾­Éí·ÝÑéÖ¤µÄí§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¡£¡£¡£Î´ÂÄÀúÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²î£¬£¬£¬£¬Í¨¹ýʹÓÃÒ×Êܹ¥»÷µÄDuplicator²å¼þÏòWordPressÍøÕ¾·¢ËÍÌØÖÆÇëÇóÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£¡£¡£


¹¥»÷Õß¿ÉÒÔʹÓ÷¾¶±éÏòÀ´»á¼ûDuplicatorÖ¸¶¨Â·¾¶Ö®ÍâµÄÎļþ£¬£¬£¬£¬ÕâЩÎļþ¿ÉÄܰüÀ¨wp-config.phpÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÕâÊÇWordPressÕ¾µãÉèÖÃÎļþ£¬£¬£¬£¬¸ÃÎļþ°üÀ¨Êý¾Ý¿âƾ֤¡¢Éí·ÝÑéÖ¤ÃÜÔ¿ºÍÑΡ£¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÕâЩƾ֤£¬£¬£¬£¬ÈôÊÇÔÊÐíÔ¶³ÌÅþÁ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖ±½Ó»á¼ûÊܺ¦Õ¾µãµÄÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓô˻á¼ûȨÏÞ½¨Éè×Ô¼ºµÄÖÎÀíÔ±ÕÊ»§²¢½øÒ»²½Î£º¦Õ¾µã£¬£¬£¬£¬»òÕßÖ»Ðè²åÈëÄÚÈÝ»ò»ñÈ¡Êý¾Ý¼´¿É¡£¡£¡£¡£¡£¡£¡£¡£


Ñо¿Ö°Ô±¿´µ½µÄÏÕЩËùÓй¥»÷¶¼À´×Ôͳһ¸öIPµØµã£¬£¬£¬£¬¿ÉÒÔʹÓÃÒÔÏÂIOCÀ´È·¶¨ÄúµÄÕ¾µãÊÇ·ñÊܵ½¹¥»÷£º


IP:77.71.115.52


´øÓÐÒÔÏÂÅÌÎÊ×Ö·û´®µÄGETÇëÇó£º

action=duplicator_download

file=/../wp-config.php


Îó²îÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬»ñÈ¡Á´½Ó£ºhttps://wordpress.org/plugins/duplicator/¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://threatpost.com/active-attacks-duplicator-wordpress-plugin/153138/