Citrix Sharefile 漏洞检查
CTX-CVE-2020-7473 快速研究详情
创建于 2020.04.16
漏洞检查:
在网页浏览器中打开
https://yoursharefileserver.companyname.com/UploadTest.aspx
或
curl https://yoursharefileserver.companyname.com/UploadTest.aspx --path-as-is
空白页面 = 服务器存在漏洞
错误 404 = 服务器已修补
备注:
如果位于 WAF/Netscaler 之后,输出可能会有所不同:
https://docs.citrix.com/en-us/storage-zones-controller/5-0/install/sf-deploy-cfg-netscaler.html
致谢:https://twitter.com/chris_e_tweets
缓解工具之后的重要更改:
更改 web.config
删除文件 UploadTest.aspx 和 XmlFeed.aspx
已安装:
AjaxControlToolkit
2013.12.14 | 版本:4.1.7.1213
Citrix 缓解工具和详情:
CVE-2020-7473 - CVE-2020-8982 - CVE-2020-8983
https://support.citrix.com/article/CTX269106
致谢 Danske Bank 红队
你有更多提示吗?请在我的 Twitter 上告诉我,我会将其添加到本文档中。
我的 Twitter: https://twitter.com/dimitrinl