Щ¶´Dirty PipeÓ°ÏìËùÓÐÖ÷Á÷µÄLinux¿¯Ðа汾

Ðû²¼Ê±¼ä 2022-03-09

Щ¶´Dirty PipeÓ°ÏìËùÓÐÖ÷Á÷µÄLinux¿¯Ðа汾


3ÔÂ7ÈÕ£¬Ñо¿ÈËÔ±Max KellermannÅû¶ÁËDirty Pipe©¶´£¨CVE-2022-0847£©µÄϸ½Ú£¬ÒÔ¼°Ò»¸ö¿´·¨ÑéÖ¤ (PoC) ¡£¹¥»÷Õß¿Éͨ¹ý×¢ÈëºÍÁýÕÖÖ»¶ÁÎļþÖеÄÊý¾Ý£¬»ñµÃrootȨÏÞ¡£¸Ã©¶´Ó°ÏìÁËLinux Kernel 5.8¼°¸ü¸ß°æ±¾£¬ÉõÖÁ°üÂÞAndroidÉ豸¡£KellermanÌåÏÖ£¬¸Ã©¶´ÀàËÆÓÚ2016ÄêÐÞ¸´µÄDirty COW©¶´(CVE-2016-5195)¡£Ä¿Ç°£¬ËüÒÑÔÚLinuxÄÚºË5.16.11¡¢5.15.25ºÍ5.10.102ÖÐÐÞ¸´¡£


https://www.bleepingcomputer.com/news/security/new-linux-bug-gives-root-on-all-major-distros-exploit-released/


¿ªÔ´Ó²¼þ¹«Ë¾AdafruitÇ°¹ÍԱй¶Æä¿Í»§µÄ²¿ÃÅÊý¾Ý


3ÔÂ4ÈÕ£¬¿ªÔ´Ó²¼þ¹«Ë¾AdafruitÈ·ÈÏÒ»¸ö¹ûÈ»µÄGitHub´æ´¢¿âÖаüÂÞÆä¿Í»§µÄ²¿ÃÅÐÅÏ¢¡£ÕâЩÐÅÏ¢°üÂÞÐÕÃû¡¢ÓʼþµØÖ·¡¢Õ˵¥µØÖ·¡¢¶©µ¥ÏêϸÐÅÏ¢ºÍ¶©µ¥µÄ״̬µÈ¡£ÓÐȤµÄÊÇ£¬Ð¹Â¶Êý¾Ý²¢·ÇÀ´×ÔAdafruitµÄGitHub´æ´¢¿â£¬¶øÊÇÀ´×Ըù«Ë¾µÄÒ»ÃûÇ°¹ÍÔ±£¬¸ÃÔ±¹¤ÔÚÆäGitHub´æ´¢¿âÖÐʹÓÃÁËÕæʵµÄ¿Í»§ÐÅÏ¢½øÐÐÅàѵºÍÊý¾Ý·ÖÎö²Ù×÷¡£Ä¿Ç°£¬AdafruitÒÑ֪ͨ¸ÃÔ±¹¤É¾³ýÁËÏà¹ØµÄGitHub´æ´¢¿â¡£


https://www.bleepingcomputer.com/news/security/adafruit-discloses-data-leak-from-ex-employees-github-repo/


ASEC·¢ÏÖαװ³ÉË°Îñ·¢Æ±µÄµöÓãÓʼþ·Ö·¢Remcos RAT


      ASECÔÚ3ÔÂ7ÈÕÐû²¼³ÂËߣ¬ÏêÊöÁËαװ³ÉË°Îñ·¢Æ±µÄµöÓãÓʼþ·Ö·¢Remcos RATµÄ»î¶¯¡£µöÓãÓʼþµÄ¸½¼þTax.gz¿É±»½âѹËõ³ÉÃûΪTax.comµÄ¿ÉÖ´ÐÐÎļþ£¬Èç¹ûÖ´Ðл·¾³ÊÇ64λ±ã»áÖ±½ÓÏÂÔز¢Ö´ÐжñÒâÈí¼þ£»·ñÔò£¬»áÏÂÔØÒ»¸öpowershellÎļþ3xp1r3Exp.ps1¡£powershell½Å±¾°üÂÞΪUAC BypassÏÂÔظ½¼ÓÎļþ(version.dll)µÄÄÚÈÝ£¬Ëü»¹»á´´½¨Ò»¸ötrickÎļþ¼Ð(Mock Directory)£¬²¢Ê¹ÓÃDLL½Ù³ÖÒªÁì¡£×îÖÕ£¬¸Ã»î¶¯»á°²×°Remcos RAT¡£


https://asec.ahnlab.com/en/32376/


Cluster25·¢ÏÖÕë¶ÔÃÀ¹úýÌåÐÐÒµ·Ö·¢RuRATµÄµöÓã»î¶¯


      Cluster25ÔÚ3ÔÂ3ÈÕ¹ûÈ»ÁËÐÂÒ»ÂÖµöÓã»î¶¯µÄÏêϸÐÅÏ¢¡£2ÔÂ23ÈÕ£¬ÐÂÎÅýÌå×éÖ¯BleepingComputerÊÕµ½×Ô³ÆÊÇ·çÏÕ×ʱ¾¼ÒµÄÓʼþ£¬Éù³ÆÏ£ÍûͶ×Ê»ò¹ºÖÃÊÕ¼þÈ˵ÄÍøÕ¾¡£¾­·ÖÎö£¬ÕâÊÇÒ»´ÎÓã²æʽµöÓã»î¶¯¡£ÓʼþÀ´×ÔÀ´×ÔÓ¢¹úÐéÄâ·þÎñÆ÷¹«Ë¾IPµØÖ·£¬²¢ÒªÇóÄ¿±êÏÂÔØVuxnerChat½øÐÐÁÄÌì¡£Ò»µ©Ä¿±êµã»÷¡°ÏÂÔØVuxner¡±£¬¾Í»áÏÂÔØÃûΪVuxnerChat.exeµÄÎļþ£¨55MB£©¡£Ö´ÐиÃexeÎļþºó£¬»áÊ×ÏÈ°²×°Ò»¸öºÏ·¨Èí¼þTrillian£¬×îÖÕÀûÓøÃÈí¼þ°²×°RuRAT¡£


https://cluster25.io/2022/03/03/rurat-used-in-spear-phishing-attacks-against-media-organisations-in-united-states/


KasperskyÐû²¼2021Ï°ëÄêICSÍþв̬ÊƵķÖÎö³ÂËß


3ÔÂ3ÈÕ£¬KasperskyÐû²¼ÁË2021Ï°ëÄ깤ҵ×Ô¶¯»¯ÏµÍ³£¨ICS£©Íþв̬ÊƵķÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚ2021ÄêH2KasperskyÔÚICS×ܹ²×èÖ¹ÁËÀ´×Ô5230¸ö¼Ò×åµÄ20000¶à¸ö¶ñÒâÈí¼þ±äÖÖ£»Ö÷ÒªÍþвÀ´Ô´ÈÔÊÇ»¥ÁªÍø£¬Æä´ÎÊÇ¿ÉÒƶ¯É豸ºÍµç×ÓÓʼþ¿Í»§¶Ë£»ÔÚICS¼ÆËã»úÖмì²âµ½µÄ¼äµýÈí¼þ¡¢¶ñÒâ½Å±¾ºÍÍøÂçµöÓãÒ³Ãæ¡¢¼ÓÃÜ»õ±Ò¿ó¹¤ºÍÀÕË÷Èí¼þµÄ°Ù·Ö±ÈÓÐËùÔö¼Ó£»Êܹ¥»÷ICS¼ÆËã»úÕ¼±È×î¶àµÄµØÓòΪ¶«ÄÏÑÇ£¨47.6%£©£¬Æä´ÎÊÇ·ÇÖÞ£¨43.4%£©ºÍ¶«ÑÇ£¨40.5%£©¡£


https://ics-cert.kaspersky.com/publications/reports/2022/03/03/threat-landscape-for-industrial-automation-systems-statistics-for-h2-2021/


Rapid7Ðû²¼¹ØÓÚGitLabÖЩ¶´CVE-2021-4191µÄ³ÂËß


Rapid7ÔÚ3ÔÂ3ÈÕÐû²¼ÁË¿ªÔ´DevOpsÈí¼þGitLabÖЩ¶´CVE-2021-4191µÄ·ÖÎö³ÂËß¡£¸Ã©¶´ÊÇÔÚÖ´ÐÐijЩGitLab GraphQL API²éѯʱȱÉÙÉí·ÝÑéÖ¤¼ì²éµ¼ÖµÄ£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆä»Ö¸´ÓëÓû§Ïà¹ØµÄÐÅÏ¢£¬ÈçGitLabÓû§Ãû¡¢Ãû³ÆºÍµç×ÓÓʼþµØÖ·µÈ¡£ËüÓ°ÏìÁË×Ô13.0ÒÔÀ´µÄGitLab°æ±¾£¬¿ÉÓ뱩Á¦ÆƽâºÍƾ֤Ìî³ä¹¥»÷½áºÏʹÓá£2ÔÂ25ÈÕ£¬GitLabÐû²¼Á˸鶴µÄÐÞ¸´·¨Ê½¡£


https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/



Äþ¾²¹¤¾ß


IOC Scraper


ÀûÓÃIOCPARSER·þÎñ´Ó²îÒìµÄ¹©Ó¦É̲©¿Í¡¢PDF ºÍ CSV ÎļþÖлñÈ¡ IOC¡£


https://github.com/chaitanyakrishna/iocscraper


Chaya


Ëüͨ¹ýÒþдÊõ¡¢ÃÜÂëѧºÍѹËõÀ´±£»¤Óû§µÄÒþ˽¡£


https://github.com/xerohackcom/chaya


Ocr Recon


´Ë¹¤¾ß¿ÉÓÃÓÚʹÓà tesseract µÄ OCR ¹¦Ð§ÔÚ URL ÁбíÖвéÕÒÌض¨×Ö·û´®¡£


https://github.com/stark0de/ocr-recon


Project Ares


»ùÓÚ Transacted Hollowing ¼¼ÊõÓà C/C++ ±àдµÄ PoC ¼ÓÔØÆ÷¡£


https://github.com/Cerbersec/Ares


Epagneul


Epagneul ÊÇÒ»¸ö¿ÉÊÓ»¯ºÍÊÓ²ì Windows ʼþÈÕÖ¾µÄ¹¤¾ß¡£


https://github.com/jurelou/epagneul


Äþ¾²·ÖÎö


Windows 11 °æ±¾ 22H2 È·ÈϽñÄêÍíЩʱºòÍƳö


https://news.softpedia.com/news/windows-11-version-22h2-confirmed-launch-later-this-year-534989.shtml


Æ»¹û±¾ÖÜ¿ÉÄÜÍƳö M2 оƬ


https://news.softpedia.com/news/apple-could-launch-the-m2-chip-this-week-534990.shtml


Ñо¿ÈËԱչʾÁ˶Ô̬ͬ¼ÓÃܵÄвàÐŵÀ¹¥»÷


https://news.ncsu.edu/2022/03/stealing-homomorphic-encryption-data/


ÎÚ¿ËÀ¼´óÁ¿ÍøÕ¾ÔâÊÜ´ó¹æÄ£¹¥»÷


https://securityaffairs.co/wordpress/128613/cyber-warfare-2/ukrainian-wordpress-sites-attacks.html


Ñо¿ÈËÔ±ÌåÏÖÉÙÓÚÆ߸ö×Ö·ûµÄÃÜÂë¿É¡°Á¢¼´¡±±»Æƽâ


https://www.darkreading.com/attacks-breaches/8-character-passwords-can-be-cracked-in-less-than-60-minutes