еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷

Ðû²¼Ê±¼ä 2024-08-27

1. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷


8ÔÂ25ÈÕ£¬ÍøÂçÄþ¾²Ñо¿ÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬ËüÓÉÑ°Çó¾­¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬½ÓÄÉÁËÒ»ÖÖÆæÌصļÆıÒÔʵÏÖºã¾ÃDZ·üºÍÒþÃع¥»÷¡£×Ô2022ÄêÆ𣬸ø߼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ±ÎÊֶΡ£ÆäºËÐÄÌØÉ«ÔÚÓÚÀûÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij־ÃÐÔ£¬ÕâÊÇͨ¹ý¼à²âϵͳºËÐÄ×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒⷨʽ¡£sedexpͨ¹ýudevµÄÅÓ´óÅäÖã¬Äܹ»ÔÚ²»±»²ì¾õµÄÇé¿öÏÂÖ´ÐжñÒâ²Ù×÷£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬ÓÐЧ¹æ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¸üΪ½Æ»«µÄÊÇ£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚ·þÎñÆ÷ÉÏÒþÃز¿ÊðÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬͹ÏÔÁËÆäÃ÷È·µÄ¾­¼ÃÀûÒæµ¼Ïò¡£Stroz FriedbergʼþÏìÓ¦ÍŶÓÖ¸³ö£¬ÔÚÒÑÊӲ참ÀýÖУ¬sedexp²»½öÒþ²ØÁËWeb ShellºÍÐ޸ĹýµÄApacheÅäÖÃÎļþ£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ±Îϵͳ¡£ÕâÒ»·¢ÏÖ½ÒʾÁ˳ýÀÕË÷Èí¼þÍ⣬ÒÔ¾­¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÅӴ󻯡£


https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html


2. Á÷ÐÐPython¿âPandasÆØÄþ¾²Â©¶´CVE-2024-42992


8ÔÂ25ÈÕ£¬¹ã·ºÊ¹ÓÃµÄ Python ¿âpandasÖз¢ÏÖÁËÒ»¸öÄþ¾²Â©¶´CVE-2024-42992£¬¸Ã©¶´²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´ó·çÏÕ¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬³ÉΪÊý¾Ý´¦ÖÃÓë·ÖÎöµÄºËÐŤ¾ß£¬ÕâÒ»·¢ÏÖÓÈΪÁîÈ˵£ÓÇ¡£´Ë©¶´ÎªÈÎÒâÎļþ¶Áȡ©¶´£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖƵطÃÎÊϵͳÄÚµÄÈÎÒâÎļþ£¬°üÂÞÃô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦ÖÃÎļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨ÈÎÒâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸Ã©¶´ÔÚ¶à¸öÔÚÏß»·¾³ÖÐÒ×ÓÚ¸´ÏÖ£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÈ»£¬ÏÔÖøÔö¼ÓÁ˱»¶ñÒâÀûÓõķçÏÕ¡£¼øÓÚpandasµÄ¹ã·ºÓ¦Ó㬴˩¶´¶Ôϵͳ»úÃÜÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾­ÊÚȨ·ÃÎʵķçÏÕÖèÔö¡£Ãæ¶ÔÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬Óû§ÐèÁ¢¼´½ÓÄÉÔ¤·À´ëÊ©£¬ÈçÏÞÖÆÔÚÃô¸Ð»·¾³ÖÐʹÓÃpandas£¬²¢¼Óǿϵͳ¼à¿ØÓëÄþ¾²´ëÊ©£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£


https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/


3. Cheana StealerÌᳫ¿çƽ̨VPNµöÓã¹¥»÷£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý


8ÔÂ25ÈÕ£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢ÏÖµÄ×îÐÂÍþвCheana Stealer£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³ÉÖªÃûVPN·þÎñWarpVPNµÄÍøÂçµöÓãÊֶΣ¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£Cheana StealerÀûÓþ«ÐÄÉè¼ÆµÄµöÓãÍøÕ¾ÓÕÆ­Óû§ÏÂÔز¢°²×°Î±×°³ÉºÏ·¨VPNÈí¼þµÄÇÔÈ¡·¨Ê½£¬Ò»µ©µÃÊÖ£¬±ãÇÄÎÞÉùÏ¢µØÊÕ¼¯°üÂÞä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜ»õ±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£Õë¶Ô²îÒì²Ù×÷ϵͳ£¬Cheana Stealer½ÓÄɲîÒìµÄ¼¼ÊõÊֶΣºÔÚWindowsÉÏ£¬ËüÀûÓÃPowerShellÖ´ÐжñÒâ½Å±¾ £»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell½Å±¾ÊµÊ©¹¥»÷ £»macOSÉÏÔòÀûÓÃÐé¼ÙϵͳÌáʾÇÔÈ¡Keychain¼°¼ÓÃÜ»õ±ÒÇ®°üÐÅÏ¢¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¸ÃÇÔÈ¡·¨Ê½µÄÁ÷´«ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀ½ôÃÜÏà¹Ø£¬ÆµµÀÄÚƵ·±Ðû´«¼ÙðVPN·þÎñ£¬¼«´óÖú³¤Á˹¥»÷·¶Î§¡£CRILµÄÑо¿½Òʾ£¬¹¥»÷Õß³õÆÚÌṩºÏ·¨·þÎñÒÔ»ýÀÛÐÅÈΣ¬ËæºóתÏò¶ñÒâ»î¶¯£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄµöÓãÍøÕ¾£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´óÁ¿Óû§ÏµÍ³£¬Í¹ÏÔÁ˵±Ç°ÍøÂçÄþ¾²ÌôÕ½µÄÑϾþÐÔ¡£


https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/


4. Mirai½©Ê¬ÍøÂçÖз¢ÏÖÑÏÖØ©¶´CVE-2024-45163


8ÔÂ25ÈÕ£¬Äþ¾²Ñо¿Ô±Jacob Masse½ÒʾÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØ©¶´CVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬¸Ã©¶´ÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNC·þÎñÆ÷½øÐÐÔ¶³ÌDoS¹¥»÷£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬×Ô2016ÄêÆð±ãÇÖÈÅÎïÁªÍøºÍ·þÎñÆ÷ÁìÓò£¬Í¨¹ýÀûÓÃÈõÃÜÂëµÈ©¶´¿ØÖÆ´óÁ¿É豸£¬ÐγÉÅÓ´óµÄ½©Ê¬ÍøÂ磬ִÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNC·þÎñÆ÷µÄÔË×÷»úÖÆ£¬·¢ÏÖÁËÆäÔÚ´¦Öò¢·¢Á¬½ÓÇëÇóʱµÄȱÏÝ£¬ÌرðÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£Õâһ©¶´ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿¼òµ¥µÄÉí·ÝÑéÖ¤ÇëÇó£¬Ê¹CNC·þÎñÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬´Ó¶ø̱»¾Õû¸ö½©Ê¬ÍøÂç¡£CVE-2024-45163µÄÅû¶²»½öΪִ·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬Ò²Òý·¢Á˹ØÓÚµÀµÂʹÓõÄÌÖÂÛ£¬ÒòΪÀûÓôË©¶´¿ÉÄÜÒâÍâÖжϺϷ¨²âÊÔÖеĽ©Ê¬ÍøÂç¡£Masseͨ¹ýPoCÑÝʾÁË©¶´µÄÓÐЧÐÔ£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNC·þÎñÆ÷µÄ³¡¾°¡£´ËÍ⣬Ëû»¹¹ûÈ»ÁË©¶´´úÂ룬´Ù½øÁËÍøÂçÄþ¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£


https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/


5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬µÁË¢·¨Ê½ÇÔÈ¡Ö§¸¶Êý¾Ý


8ÔÂ25ÈÕ£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÉ̵ê½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»·Ç·¨ÇÔÈ¡£¬°üÂÞ¿¨ºÅ¡¢ÓÐЧÆÚ¼°Äþ¾²ÂëµÈÖØÒªÐÅÏ¢¡£Malwarebytesר¼ÒÖ¸³ö£¬ºÚ¿ÍÀûÓÃMagentoϵͳ©¶´£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðнű¾£¬¸Ã½Å±¾ÄÜÔ¶³Ì¼ÓÔز¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÊÕ¼¯±»µÁÊý¾Ý¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ±Î£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬ÄÑÒÔ±»Óû§²ì¾õ¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶×½²¢×ª·¢ÖÁºÚ¿Í·þÎñÆ÷£¬ÉõÖÁÔÚijЩÇé¿öÏ£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦ÖÃÁ÷³ÌÖ±½ÓÀ¹½ØÊý¾Ý¡£ÐÒÔ˵ÄÊÇ£¬Äþ¾²×¨¼ÒÒÑÀ¹½ØÁè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬ͨ¹ýʶ±ð²¢·âËøÊýÊ®¸ö¶ñÒâÓòÃûÓÐЧֹͣÁ˲¿ÃŹ¥»÷¡£È»¶ø£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ´ëÊ©£¬µ«²¿ÃÅÍøÕ¾ÈÔÃæÁÙÁ¬ÐøÍþв¡£´ËÍ⣬Êý¾Ýй¶²»½öÏÞÓÚ²ÆÕþÐÅÏ¢£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈ¸öÈËÒþ˽¡£Òò´Ë£¬Óû§Èô·¢ÏÖÒì³££¬Ó¦Á¢¼´ÁªÏµÒøÐиü»»¿¨Æ¬£¬²¢¿¼ÂÇÆôÓÃÉí·Ý± £»¤·þÎñ¡£


https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/


6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬72.6Íò¿Í»§Êý¾Ýй¶


8ÔÂ26ÈÕ£¬PatelcoÐÅÓúÏ×÷ÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚ·þÎñ»ú¹¹£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶Ê¼þ¡£½ñÄêÔçЩʱºò£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬¾¡¹ÜÆäʱδÁ¢¼´È·ÈÏÊý¾Ýй¶£¬µ«ËæºóÊÓ²ì½Òʾ£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬²¢ÓÚ6ÔÂ29ÈÕ·ÃÎÊÊý¾Ý¿â£¬ÇÔÈ¡ÁË´óÁ¿¿Í»§¸öÈËÐÅÏ¢¡£ÕâЩÃô¸ÐÐÅÏ¢°üÂÞÐÕÃû¡¢Éç»áÄþ¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûºó¹ûÈ»ÁËÊý¾Ý¡£´Ë´Îʼþ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£ÎªÓ¦¶Ô´Ë´ÎÎ £»ú£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý± £»¤ºÍÐÅÓüà¿Ø·þÎñµÄÑ¡Ï½ØÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£Í¬Ê±£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøλÖÃÐû²¼¾¯¸æ£¬ÌáÐÑ»áÔ±¾¯ÌèÍøÂçµöÓã¡¢Éç»á¹¤³Ì¼°Õ©Æ­·çÏÕ£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/