超高危險性 CVE-2021-22005 vCenter漏洞影片示範
最近被評分為 CVSS 9.8/10 的VMware vCenter漏洞.
官方雖然有公告跟補丁了,不過一直沒有POC攻擊程式放出.
越南資安專家 @testanull 一貫以分析原廠補丁作風(如Exchange ProxyLogon漏洞),分析出1 day漏洞原理,並且立刻實作出半實驗品POC(攻擊程式) .
攻擊有二個步驟
1.VC有啟動了VMware 客戶經驗改進計畫 (CEIP) ,可以上傳檔案,內容和路徑可以任意修改,但檔案名必須有擴展名“.json”,不能寫web shell並執行!
2.任意 ˋ建立Web Shell
繞過rhttpproxy跟結合端點“/dataapp/agent”的漏洞,調用GLOBAL-logger 1.將日誌路徑設置為任意檔案
2.通過日誌記錄編寫 web shell
3.關閉日誌紀錄檔案並恢復.
POC (不太完整)
https://gist.github.com/testanull/c2f6fd061c496ea90ddee151d6738d2e
修補方法
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
影片與內容出處 (越南文)
https://testbnull.medium.com/quick-note-of-vcenter-rce-cve-2021-22005-4337d5a817ee
#OSSLab #所以啥客戶體驗計畫我都關光光的
同時也有10000部Youtube影片,追蹤數超過2,910的網紅コバにゃんチャンネル,也在其Youtube影片中提到,...
「global security exchange」的推薦目錄:
- 關於global security exchange 在 OSSLab Geek Lab Facebook 的精選貼文
- 關於global security exchange 在 Facebook 的精選貼文
- 關於global security exchange 在 美國在台協會 AIT Facebook 的最讚貼文
- 關於global security exchange 在 コバにゃんチャンネル Youtube 的最佳貼文
- 關於global security exchange 在 大象中醫 Youtube 的精選貼文
- 關於global security exchange 在 大象中醫 Youtube 的精選貼文
- 關於global security exchange 在 ASIS Global Security Exchange (GSX) - 首頁| Facebook 的評價
- 關於global security exchange 在 Explore Global Security Exchange Plus (GSX+) - YouTube 的評價
- 關於global security exchange 在 GSX+ Global Security Exchange Plus - Pinterest 的評價
global security exchange 在 Facebook 的精選貼文
【vGCTF:強化全球及各國防災韌性】
AIT處長孫曉雅今天偕同科技部部長吳政忠、外交部次長曾厚仁、日本台灣交流協會代表泉裕泰、英國在台辦事處代表鄧元翰,以及澳洲辦事處代表露珍怡共同參加全球合作暨訓練架構線上國際研討會(vGCTF)「強化全球及各國防災韌性」。
AIT處長孫曉雅於開幕致詞中強調:「在救災與災害應變的議題上,美國會致力與我們的夥伴攜手合作。在英國康瓦爾舉行的七國峰會(G7)中,拜登總統與合作夥伴一同宣布了他們對全球基礎建設發展的一致願景,並共同推出了『重建更好世界』(Build Back Better World)倡議。『重建更好世界』是一項價值導向、高標準、透明的基礎建設夥伴關係,目的在動員基礎建設投資,將其導入中低收入國家,以支持這些地方各項基礎建設的永續發展,包括氣候、衛生與衛生安全、科技、及兩性公平與性別平等等領域。這些都是缺一不可的關鍵要素,能夠大大增進各社會與經濟體的防災韌性。」
Today, AIT Director Sandra Oudkirk, Minister of Science and Technology Wu Tsung-Tsong, Deputy Foreign Minister Tseng Ho-jen, Japan-Taiwan Exchange Association Chief Representative Hiroyasu Izumi, British Office Representative John Dennis, and Australia Office Representative Jennifer Bloomfield participated in a virtual Global Cooperation and Training Framework (GCTF) workshop titled “Building Disaster Resilience at Global and National Levels.” In her opening remarks, Director Oudkirk highlighted, “The United States is committed to working with partners on disaster relief and response. At the G7 meeting in Cornwall, President Biden and partners announced a unified vision for global infrastructure development and introduced the Build Back Better World initiative. Build Back Better World is a value-driven, high-standard, and transparent infrastructure partnership aimed at mobilizing infrastructure investments in low- and middle-income countries to support sustainable infrastructure development in the areas of climate, health and health security, technology, and gender equity and equality.”
global security exchange 在 美國在台協會 AIT Facebook 的最讚貼文
美國在台協會處長孫曉雅於本周繼續拜會台灣官員,她與 #行政院 院長蘇貞昌討論如何就投資及貿易合作等議題深化美台關係、與 #陸委會 主委邱太三討論兩岸議題、與 #法務部 部長蔡清祥商討反貪腐及洗錢防制、與 #衛福部 部長陳時中討論美台公衛合作、與 #中央銀行 總裁楊金龍就當前經濟趨勢和全球供應鏈議題交換意見、與 #立法院 院長游錫堃討論立法院議事。
在這些會面中,孫處長重申她深化美台夥伴關係的承諾,並強調美台共享的民主和經濟價值,以及美國對台灣恆久的承諾。
拜會日期與細節詳見新聞稿:https://www.ait.org.tw/zhtw/ait-dir-oudkirks-august-16-20-meetings-with-taiwan-officials-zh/
AIT Director Sandra Oudkirk continued to have introductory meetings with Taiwan counterparts this week. She met with Premier Su Tseng-chang on August 16 to discuss the deepening U.S.-Taiwan relationship including investment and trade cooperation. The following day, Director Oudkirk met with Mainland Affairs Council Minister Chiu Tai-san to talk about cross-Strait relations and with Minister of Justice Tsai Ching-hsiang to share perspectives on cyber security, human rights, anti-corruption, and anti-money laundering. On August 18, Director Oudkirk met with Minister of Health and Welfare Chen Shih-chung to discuss U.S.-Taiwan health cooperation and with Central Bank Governor Yang Chin-long to exchange views on economic trends and global supply chains. Yesterday, she met with Legislative Yuan President You Si-kun to learn about Taiwan’s current legislative agenda and domestic political developments.
During these meetings, Director Oudkirk reiterated her commitment to advancing and deepening the U.S.-Taiwan partnership, stressed the common democratic and economic values that the United States and Taiwan share, and emphasized the United States’ enduring commitment to Taiwan.
To view AIT’s press release on the meetings, visit: https://www.ait.org.tw/ait-dir-oudkirks-august-16-20-meetings-with-taiwan-officials/
global security exchange 在 Explore Global Security Exchange Plus (GSX+) - YouTube 的美食出口停車場

Cyber, operational, and physical security professionals from across the private and public sectors, allied organizations and partners, ... ... <看更多>
global security exchange 在 GSX+ Global Security Exchange Plus - Pinterest 的美食出口停車場
Today we will be attending the Virtual GSX+ Global Security Exchange Plus! Learn more about our #security #solutions by visiting our website! #GSXPlus # ... ... <看更多>
global security exchange 在 ASIS Global Security Exchange (GSX) - 首頁| Facebook 的美食出口停車場
Global Security Exchange (GSX), 27-29 September 2021, brings to together the global security... 1625 Prince St., 美国弗吉尼亚州亚历山德里亚22314. ... <看更多>