еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷

Ðû²¼Ê±¼ä 2024-08-27

1. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷


8ÔÂ25ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬ËüÓÉ×·Çó¾­¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃع¥»÷¡£×Ô2022ÄêÆ𣬸ø߼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖã¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¸üΪ½ÆÕ©µÄÊÇ£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚ·þÎñÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬͹ÏÔÁËÆäÃ÷È·µÄ¾­¼ÃÀûÒæµ¼Ïò¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö£¬ÔÚÒÑÊӲ참ÀýÖУ¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²Øϵͳ¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍ⣬ÒÔ¾­¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖش󻯡£


https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html


2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992


8ÔÂ25ÈÕ£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖƵػá¼ûϵͳÄÚµÄí§ÒâÎļþ£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕ棬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¼øÓÚpandasµÄÆÕ±éÓ¦Ó㬴ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾­ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£


https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/


3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý


8ÔÂ25ÈÕ£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPN·þÎñWarpVPNµÄÍøÂç´¹ÂÚÊֶΣ¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆ­Óû§ÏÂÔز¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò£¬Ò»µ©µ½ÊÖ£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£ÖµµÃ×¢ÖصÄÊÇ£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø£¬ÆµµÀÄÚƵÈÔÐû´«Ã°³äVPN·þÎñ£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£CRILµÄÑо¿Õ¹ÏÖ£¬¹¥»÷Õß³õÆÚÌṩÕýµ±·þÎñÒÔ»ýÀÛÐÅÍУ¬ËæºóתÏò¶ñÒâÔ˶¯£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£


https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/


4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163


8ÔÂ25ÈÕ£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNC·þÎñÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍ·þÎñÆ÷ÁìÓò£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂ磬ִÐÐDDoS¹¥»÷µÈ¶ñÒâÔ˶¯¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNC·þÎñÆ÷µÄÔË×÷»úÖÆ£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇó£¬Ê¹CNC·þÎñÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬´Ó¶ø̱»¾Õû¸ö½©Ê¬ÍøÂç¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNC·þÎñÆ÷µÄ³¡¾°¡£±ðµÄ£¬Ëû»¹¹ûÕæÁËÎó²î´úÂ룬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£


https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/


5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬µÁË¢³ÌÐòÇÔÈ¡Ö§¸¶Êý¾Ý


8ÔÂ25ÈÕ£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£Malwarebytesר¼ÒÖ¸³ö£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔز¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬ÄÑÒÔ±»Óû§²ì¾õ¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿Í·þÎñÆ÷£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£ÐÒÔ˵ÄÊÇ£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬ͨ¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£È»¶ø£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£±ðµÄ£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£Òò´Ë£¬Óû§Èô·¢Ã÷Òì³££¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»¤·þÎñ¡£


https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/


6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬72.6Íò¿Í»§Êý¾Ýй¶


8ÔÂ26ÈÕ£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚ·þÎñ»ú¹¹£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£½ñÄêÔçЩʱ¼ä£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£ÎªÓ¦¶Ô´Ë´ÎΣ»ú£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»¤ºÍÐÅÓüà¿Ø·þÎñµÄÑ¡Ï×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£Í¬Ê±£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøλÖÃÐû²¼ÖÒÑÔ£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©Æ­Î£º¦£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/