¡¾Çå¾²Ç÷ÊÆ¡¿¿¨°Í˹»ù2018ÉÏ°ëÄêÎïÁªÍøÍþвµÄÐÂÇ÷ÊÆ
Ðû²¼Ê±¼ä 2018-10-31Òò´ËÔÚÕâÀïÎÒÃÇÑо¿ÁËÒÔÏÂÈý¸öÎÊÌ⣺ÍøÂç·¸·¨·Ö×ÓѬȾÖÇÄÜ×°±¸µÄ¹¥»÷ÏòÁ¿¡¢ÄÄЩ¶ñÒâÈí¼þ±»¼ÓÔص½Óû§µÄϵͳÖÐÒÔ¼°×îеĽ©Ê¬ÍøÂç¶Ô×°±¸ËùÓÐÕߺÍÊܺ¦ÕßÀ´ËµÒâζ×Åʲô¡£
2016Äê ¨C 2018Ä꣬¿¨°Í˹»ùʵÑéÊÒÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÄ¿

ÔÚ½«¶ñÒâÈí¼þÏÂÔص½ÎïÁªÍø×°±¸ÉÏʱ£¬ÍøÂç·¸·¨·Ö×ÓµÄÊ×Ñ¡ÏîÊÇMirai¼Ò×壨20.9%£©¡£

ÒÔÏÂÊÇÎÒÃǼͼµ½µÄTelnet¹¥»÷×î¶àµÄ¹ú¼ÒµÄTop 10£º
2018ÄêµÚ¶þ¼¾¶È£¬ÊÜѬȾװ±¸ÊýÄ¿µÄµØÀíÂþÑÜ
ÓÉÓÚһЩÖÇÄÜ×°±¸µÄËùÓÐÕßÐÞ¸ÄÁËĬÈϵÄTelnetÃÜÂ벢ʹÓÃÖØ´óµÄÃÜÂ룬¶øÐí¶àС¹¤¾ß»ù´¡²»Ö§³ÖÕâÖÖÐÒ飬Òò´ËÍøÂç·¸·¨·Ö×ÓÒ»Ö±ÔÚÑ°ÕÒеÄѬȾÏòÁ¿¡£ÕâÒ»ÇéÐλ¹Êܵ½¶ñÒâÈí¼þ¿ª·¢ÕßÖ®¼äµÄ¾ºÕùËùÍƶ¯£¨ËûÃÇÖ®¼äµÄ¾ºÕùµ¼ÖÂÁ˱©Á¦Æƽ⹥»÷ЧÂÊÔ½À´Ô½µÍ£©£ºÒ»µ©ÀÖ³ÉÆƽâÁËTelnetÃÜÂ룬¹¥»÷Õ߾ͻá¸ü¸Ä×°±¸µÄÃÜÂë²¢×èÖ¹¶ÔTelnetµÄ»á¼û¡£
½©Ê¬ÍøÂçReaper¾ÍÊÇÒ»¸öʹÓá°Ìæ»»ÊÖÒÕ¡±µÄºÜºÃµÄÀý×Ó£¬ËüÔÚ2017Äêµ×ѬȾÁËÔ¼200Íò¸öIoT×°±¸¡£¸Ã½©Ê¬ÍøÂ粢ûÓнÓÄÉTelnet±©Á¦Æƽ⹥»÷£¬¶øÊÇʹÓÃÒÑÖªµÄÈí¼þÎó²î¾ÙÐÐÈö²¥£º
GoAheadÍøÂçÉãÏñ»úÖеÄÎó²î
MVPower CCTVÉãÏñ»úÖеÄÎó²î
Netgear ReadyNASSurveillanceÖеÄÎó²î
Vacron NVRÖеÄÎó²î
Netgear DGN×°±¸ÖеÄÎó²î
Linksys E1500/E2500·ÓÉÆ÷ÖеÄÎó²î
D-Link DIR-600ºÍDIR 300 ¨C HW rev B1·ÓÉÆ÷ÖеÄÎó²î
AVTech×°±¸ÖеÄÎó²î
Ó뱩Á¦ÆƽâÏà±È£¬ÕâÖÖÈö²¥ÒªÁì¾ßÓÐÒÔÏÂÓŵ㣺
¶ÔÓû§¶øÑÔ£¬´ò²¹¶¡Ô¶±ÈÐÞ¸ÄÃÜÂë»ò½ûÓ÷þÎñÒªÄÑ¿°¶à
ÐµĹ¥»÷£¬¾ÉµÄ¶ñÒâÈí¼þ
ϱíÊÇ2018ÄêµÚ¶þ¼¾¶È¹¥»÷ÎÒÃÇÃÛ¹ÞµÄÊÜѬȾIoT×°±¸µÄÀàÐÍÂþÑÜ£º¾ø´ó´ó¶¼¹¥»÷ÈÔÈ»ÊÇÕë¶ÔTelnetºÍSSHÃÜÂëµÄ±©Á¦Æƽ⹥»÷¡£µÚÈý´ó×î³£¼ûµÄ¹¥»÷ÊÇÕë¶ÔSMB·þÎñ£¨ÎļþÔ¶³Ì»á¼û·þÎñ£©µÄ¹¥»÷¡£ÎÒÃÇ»¹Ã»ÓÐÊӲ쵽Õë¶Ô¸Ã·þÎñµÄIoT¶ñÒâÈí¼þ¡£ÎÞÂÛÔõÑù£¬Ä³Ð©°æ±¾µÄSMBÖаüÀ¨ÑÏÖصÄÒÑÖªÎó²î£¬ÈçÓÀºãÖ®À¶£¨Windows£©ºÍÓÀºãÖ®ºì£¨Linux£©¡£¾Ù¸öÀý×Ó£¬ÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þWannaCryºÍÃÅÂÞ±Ò¿ó¹¤ EternalMiner¾ÍʹÓÃÁËÕâЩÎó²î¡£

ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÔËÐÐRouterOSµÄMikroTik×°±¸ÔÚÁбíÖÐÒ»Æï¾ø³¾£¬ÆäÔµ¹ÊÔÓÉÓ¦¸ÃÊÇChimay-RedÎó²î¡£
7547¶Ë¿Ú
ÁíÒ»À๥»÷ÔòÊÇʹÓÃÁËÔËÐÐRouterOS°æ±¾6.38.4֮ϵÄMikroTik·ÓÉÆ÷ÖеÄÎó²îChimay-Red¡£ÔÚ2018Äê3Ô£¬¸Ã¹¥»÷±»Æð¾¢ÓÃÓÚ·Ö·¢Hajime¡£
ÍøÂçÉãÏñ»ú
ÍøÂç·¸·¨·Ö×ÓҲûÓкöÊÓÍøÂçÉãÏñ»ú¡£2017Äê3ÔÂÑо¿Ö°Ô±ÔÚGoAhead×°±¸µÄÈí¼þÖз¢Ã÷Á˼¸¸öÑÏÖصÄÎó²î¡£ÔÚÏà¹ØÐÅÏ¢±»Åû¶µÄÒ»¸öÔºó£¬Ê¹ÓÃÕâЩÎó²îµÄGafgytºÍPersiraiľÂíбäÌå·ºÆðÁË¡£½öÔÚÒ»ÖÜÄÚ£¬ÕâЩ¶ñÒâ³ÌÐò¾ÍÆð¾¢Ñ¬È¾ÁË57000¸ö×°±¸¡£
ÖÕ¶ËÓû§ÃæÁÙµÄжñÒâÈí¼þºÍÍþв
DDoS¹¥»÷
ÓëÒÔÇ°Ò»Ñù£¬ÎïÁªÍø¶ñÒâÈí¼þµÄÖ÷ҪĿµÄÊǾÙÐÐDDoS¹¥»÷¡£ÊÜѬȾµÄÖÇÄÜ×°±¸³ÉΪ½©Ê¬ÍøÂçµÄÒ»²¿·Ö£¬Æ¾Ö¤Ïà¹ØÏÂÁî¹¥»÷Ò»¸öÖ¸¶¨µÄµØµã£¬ºÄ¾¡¸ÃÖ÷»úÓÃÓÚ´¦Öóͷ£ÕæÊÊÓû§ÇëÇóµÄ×ÊÔ´ºÍÄÜÁ¦¡£Ä¾Âí¼Ò×åMirai¼°Æä±äÌ壨ÓÈÆäÊÇHajime£©ÈÔÔÚ°²ÅÅ´ËÀ๥»÷¡£
Õâ¿ÉÄÜÊǶÔÖÕ¶ËÓû§Î£º¦×îСµÄÇéÐÎÁË¡£×ÇéÐΣ¨ºÜÉÙ±¬·¢£©Ò²¾ÍÊÇÊÜѬȾװ±¸µÄÓµÓÐÕß±»ISPÀºÚ¡£²¢ÇÒͨ³£ÇéÐÎϼòÆÓµØÖØÆô×°±¸¾Í¿ÉÒÔ¡°ÖÎÓú¡±¸Ã×°±¸¡£
¼ÓÃÜÇ®±ÒÍÚ¾ò
SatoriľÂíµÄ½¨ÉèÕß·¢Ã÷ÁËÒ»ÖÖ¸üΪ½ÆÕ©ºÍ¿ÉÐеĻñÈ¡¼ÓÃÜÇ®±ÒµÄÒªÁì¡£Ëû½«ÊÜѬȾµÄIoT×°±¸×÷Ϊ»á¼û¸ßÐÔÄÜÅÌËã»úµÄÒ»ÖÖÔ¿³×£º
µÚÒ»²½£¬¹¥»÷ÕßÊ×ÏÈÊÔͼʹÓÃÒÑÖªÎó²îѬȾ¾¡¿ÉÄܶàµÄ·ÓÉÆ÷£¬ÕâЩÎó²î°üÀ¨£º
CVE 2017-17215 ¨C»ªÎªHG532ϵÁзÓÉÆ÷¹Ì¼þÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î
CVE-2018-10561, CVE-2018-10562 ¨CDasan GPON·ÓÉÆ÷ÖеÄÉí·ÝÈÏÖ¤ÈƹýÎó²îºÍí§Òâ´úÂëÖ´ÐÐÎó²î
CVE-2018-10088 ¨CXiongMai uc-httpd 1.0.0ÖеĻº³åÇøÒç³öÎó²î£¬¸Ã²úÆ·±»ÓÃÓÚ²¿·ÖÖйúÖÆÔìµÄ·ÓÉÆ÷ºÍÖÇÄÜ×°±¸µÄ¹Ì¼þÖÐ
Êý¾ÝÇÔÈ¡
ÔÚ2018Äê5Ô¼ì²âµ½µÄVPNFilterľÂíÔò×·ÇóÆäËüµÄÄ¿µÄ¡£ËüÊ×ÏÈ×èµ²ÊÜѬȾװ±¸µÄÁ÷Á¿£¬È»ºó´ÓÖÐÌáÈ¡Ö÷ÒªµÄÊý¾Ý£¨Óû§Ãû¡¢ÃÜÂëµÈ£©²¢·¢Ë͵½ÍøÂç·¸·¨·Ö×ӵķþÎñÆ÷¡£ÏÂÃæÊÇVPNFilterµÄÖ÷Òª¹¦Ð§£º
×ÔÆôÄîÍ·ÖÆ¡£¸ÃľÂí½«×Ô¼ºÐ´Èë±ê×¼LinuxÍýÏëʹÃü³ÌÐòcrontab£¬»¹¿ÉÒÔÐÞ¸Ä×°±¸µÄ·ÇÒ×ʧÐÔ´æ´¢Æ÷£¨NVRAM£©ÖеÄÉèÖÃÉèÖá£
ʹÓÃTORÓëC&C·þÎñÆ÷¾ÙÐÐͨѶ¡£
Äܹ»×Ô»Ù²¢Ê¹×°±¸¡°±äש¡±¡£Ò»µ©ÎüÊÕµ½Ïà¹ØÏÂÁ¸ÃľÂí¾Í»á×ÔÎÒɾ³ý²¢ÓÃÀ¬»øÊý¾ÝÁýÕֹ̼þµÄÒªº¦²¿·Ö£¬È»ºóÖØÆô×°±¸¡£
¸ÃľÂíµÄÈö²¥ÒªÁìÈÔȻδ֪£ºÆä´úÂëÖÐûÓаüÀ¨×ÔÎÒÈö²¥»úÖÆ¡£ÎÞÂÛÔõÑù£¬ÎÒÃÇÇãÏòÓÚÒÔΪËüͨ¹ýʹÓÃ×°±¸Èí¼þÖеÄÒÑÖªÎó²îÀ´Ñ¬È¾×°±¸¡£
µÚÒ»·Ý¹ØÓÚVPNFilterµÄ±¨¸æ³ÆÆäѬȾÁËÔ¼50Íò¸ö×°±¸¡£´ÓÄÇʱÆ𣬸ü¶àµÄ×°±¸±»Ñ¬È¾ÁË£¬²¢ÇÒÒ×Êܹ¥»÷µÄ×°±¸³§ÉÌÁбí´ó´ó¼Ó³¤ÁË¡£µ½ÁùÔÂÖÐÑ®£¬ÆäÄ¿µÄ°üÀ¨ÒÔÏÂÆ·ÅƵÄ×°±¸£º
ASUS
D-LinkHuawei
Linksys
MikroTik
Netgear
QNAP
TP-Link
Ubiquiti
Upvel
ZTE
ÓÉÓÚÕâЩ³§É̵Ä×°±¸²»µ«ÔÚ¹«Ë¾ÍøÂçÖÐʹÓ㬲¢ÇÒ³£±»ÓÃ×÷¼ÒÓ÷ÓÉÆ÷£¬ÕâʹµÃÇéÐαäµÃ¸üÔã¡£
½áÂÛ
Õë¶ÔÖÇÄÜ×°±¸µÄ¶ñÒâÈí¼þ²»µ«ÔÚÊýÄ¿ÉÏÔöÌí£¬²¢ÇÒÔÚÖÊÁ¿ÉÏÒ²ÔÚÔöÌí¡£Ô½À´Ô½¶àµÄexploits£¨Îó²îʹÓóÌÐò£©±»ÍøÂç·¸·¨·Ö×Ó¿ª·¢³öÀ´¡£¶ø³ýÁ˹ŰåµÄDDoS¹¥»÷Ö®Í⣬±»Ñ¬È¾µÄ×°±¸»¹±»ÓÃÓÚÇÔȡСÎÒ˽¼ÒÊý¾ÝºÍÍÚ¾ò¼ÓÃÜÇ®±Ò¡£
ÏÂÃæÊÇһЩ¿ÉÒÔ×ÊÖúïÔÌÖÇÄÜ×°±¸Ñ¬È¾Î£º¦µÄС¼¼ÇÉ£º
°´ÆÚÖØÆôÓÐÖúÓÚɨ³ýÒÑѬȾµÄ¶ñÒâÈí¼þ£¨Ö»¹Ü´ó´ó¶¼ÇéÐÎÏ»¹±£´æÔÙ´ÎѬȾµÄΣº¦£©
°´ÆÚ¼ì²éÊÇ·ñ±£´æа汾µÄ¹Ì¼þ²¢¾ÙÐиüÐÂ
ʹÓÃÖØ´óÃÜÂ루³¤¶ÈÖÁÉÙΪ8룬°üÀ¨¾Þϸд×Öĸ¡¢Êý×ÖºÍÌØÊâ×Ö·û£©
ÔÚ³õʼÉèÖÃʱ¸ü¸Ä³ö³§ÃÜÂ루×ÝÈ»×°±¸Î´ÌáÐÑÄúÕâÑù×ö£©
ÈôÊDZ£´æ¸ÃÑ¡ÏÔò¹Ø±Õ/½ûÓò»Ê¹ÓõĶ˿ڡ£ÀýÈ磬ÈôÊÇÄú²»ÍýÏëͨ¹ýTelnet£¨Õ¼ÓÃTCP¶Ë¿Ú23£©ÅþÁ¬µ½Â·ÓÉÆ÷£¬Ôò×îºÃ½ûÓøö˿ÚÒÔ½µµÍ±»ÈëÇÖµÄΣº¦¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/new-trends-in-the-world-of-iot-threats/87991/