
Zeekパッケージは、HTTP ServerヘッダーとTLS punycodeの異常を介してCVE-2022-3602の悪用試行と脆弱なOpenSSLサーバーを検出し、インシデント対応のための実用的な通知を生成します。
参考文献:
このパッケージは以下の通知を生成します:
CVE20223602::CVE_2022_3602_Exploit_AttemptCVE20223602::CVE_2022_3602_Vulnerable_Server通知には、sub フィールド内に通知をトリガーしたアーティファクトも含まれており、IR トリアージに役立ちます。
#separator \x09
#set_separator ,
#empty_field (empty)
#unset_field -
#path notice
#open 2022-11-04-11-13-50
#fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p fuid file_mime_type file_desc proto note msg sub src dst p n peer_descr actions email_dest suppress_for remote_location.country_code remote_location.region remote_location.city remote_location.latitude remote_location.longitude
#types time string addr port addr port string string string enum enum string string addr addr port count string set[enum] set[string] interval string string string double double
1667182702.131152 CKgObk3hwP00kyaoVd 127.0.0.1 53240 127.0.0.1 80 - - - tcp CVE20223602::CVE_2022_3602_Vulnerable_Server Potential OpenSSL CVE_2022_3602 Vulnerable server version (v3.0.0-3.0.6) SERVER value in HTTP header = 'Apache/2.4.54 (Fedora Linux) OpenSSL/3.0.5' 127.0.0.1 127.0.0.1 80 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
1667383240.417527 CYgEWD2cUZDWalTz9h 192.168.56.2 50478 192.168.56.3 3000 - - - tcp CVE20223602::CVE_2022_3602_Exploit_Attempt Potential OpenSSL CVE_2022_3602 exploit attempt (punycode) ext$value = 'Permitted:\x0a email:xn--3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2ba\x0a' 192.168.56.2 192.168.56.3 3000 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
1667390605.051174 CTKv5h4LdOlflhiM66 192.168.56.2 46590 192.168.56.3 3000 - - - tcp CVE20223602::CVE_2022_3602_Exploit_Attempt Potential OpenSSL CVE_2022_3602 exploit attempt (punycode) ext$value = 'Permitted:\x0a email:xn--3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2b3B-ww4c5e180e575a65lsy2ba@example.com\x0a' 192.168.56.2 192.168.56.3 3000 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
1667393702.130181 CycBH72ljVsUydqGn5 192.168.56.2 46594 192.168.56.3 3000 - - - tcp CVE20223602::CVE_2022_3602_Exploit_Attempt Potential OpenSSL CVE_2022_3602 exploit attempt (punycode) ext$value = 'Permitted:\x0a email:[email protected]\x0a' 192.168.56.2 192.168.56.3 3000 - - Notice::ACTION_LOG (empty) 3600.000000 - - - - -
#close 2022-11-04-11-13-50
このパッケージは、以下のコマンドを使用して zkg でインストールできます:
$ zkg refresh
$ zkg install cve-2022-3602
Corelight のお客様は、CVE バンドルを更新することでインストールできます。