¡¾Êý¾ÝÄþ¾²ÐÂÌôÕ½¡¿Õë¶ÔÐéÄ⻯ƽ̨VMware vSphereµÄÀÕË÷¹¥»÷רÏî·ÖÎö

Ðû²¼Ê±¼ä 2021-09-22

Ò»¡¢¸Å Êö


¡¶ÖлªÈËÃñ¹²ºÍ¹úÊý¾ÝÄþ¾²·¨¡·ÓÚ½ñÈÕÆð£¨2021Äê9ÔÂ1ÈÕ£©ÕýʽʩÐУ¬ÕâÊÇÒ»²¿Êý¾ÝÁìÓòµÄ»ù´¡ÐÔÖ´·¨£¬Ò²Êǹú¼ÒÄþ¾²ÁìÓòµÄÒ»²¿ÖØÒªÖ´·¨¡£Êý×Ö»¯¸ïÐÂÍƶ¯×Źú¼ÒÉú²úģʽµÄÀå¸ï£¬Ëæמ­¼ÃÊý×Ö»¯¡¢Õþ¸®Êý×Ö»¯¡¢ÆóÒµÊý×Ö»¯µÄ½¨É裬Êý¾ÝÒѾ­³ÉΪÎÒ¹úÕþ¸®ºÍÆóÒµ×îΪºËÐĵÄ×ʲúÖ®Ò»¡£¶øÕë¶ÔÕâЩºËÐÄÊý¾Ý×ʲúµÄÍøÂç¹¥»÷È´ÖðÄêµÝÔö£¬³ýÁËÔ½À´Ô½Æµ·±µÄÊý¾Ýй¶Äþ¾²Ê¼þÍ⣬ÈÕÒæ·ÅËÁµÄÀÕË÷¹¥»÷ÊÇÊý¾ÝÄþ¾²ÃæÁÙµÄ×îΪÑÏÖØÇÒΣÏÕµÄÍþв£¬Æä¾ßÓÐÆÆ»µÐÔ´ó¡¢ÄäÃûÐԸߡ¢»Ö¸´ÄѵÈÌصã¡£Ò»µ©Êý¾Ý×ʲúÔâµ½¹¥»÷£¬³ýÁË´óÁ¿Ãû¹óµÄÊý¾Ý±»ÆÆ»µÍ⣬»¹»áµ¼Ö¹¤³§Í£¹¤Í£²ú£¨È磺¸»Ê¿¿µÀÕË÷¹¥»÷µ¼ÖÂÍ£¹¤µÄʼþ£©£¬ÉõÖÁ»áÍþвµ½¹ú¼ÒÄþ¾²£¨È磺ȼÓ͹ܵÀ¹«Ë¾Colonial PipelineÀÕË÷¹¥»÷ʼþ£©¡£


Ä¿Ç°£¬ÀÕË÷×éÖ¯ÆÕ±éÀûÓ鶴»òÕßÈ˹¤Éø͸µÄÊֶνøÈëÆóÒµ/×éÖ¯ÄÚ²¿ÏµÍ³£¬²¢ÔÚÆäÖÐÖ²ÈëÀÕË÷²¡¶¾£¬²¢ÀûÓÃÀÕË÷²¡¶¾¶ÔÆäÆóÒµµÄÖØÒªÊý¾Ý×ʲú½øÐмÓÃÜÈ»ºóʵʩÊê½ðÀÕË÷¡£½ö½ñÄêÒÔÀ´£¬¾Í·ºÆðÁ˶àÆðÖØ´óµÄÀÕË÷²¡¶¾¹¥»÷ʼþ¡£5Ô·Ý£¬ÃÀ¹ú×î´óµÄȼÓ͹ܵÀ¹«Ë¾Colonial PipelineÔâÓöÀÕË÷²¡¶¾¹¥»÷£¬´Ó¶øµ¼ÖÂÃÀ¹ú¶«²¿17¸öÖݺÍÊ׶¼ËùÔڵĻªÊ¢¶ÙÌØÇøÐû²¼½øÈë½ô¼±×´Ì¬£»7Ô·Ý£¬ÃÀ¹úIT¹ÜÀíÈí¼þÖÆÔìÉÌKaseyaÊܵ½¹©Ó¦Á´¹¥»÷£¬ºÚ¿ÍÀûÓÃÆäÈí¼þÖдæÔڵĩ¶´ÏòÆä¿Í»§·¢ËÍÀÕË÷Èí¼þ£¬Áè¼Ý1500¼ÒÆóÒµÊܵ½ÀÕË÷¹¥»÷Ó°Ïì¡£


Ëæ×ÅÊг¡ºÍ¼¼ÊõµÄÀå¸ï£¬ÀÕË÷×éÖ¯Ò²ÔÚ²»Í£Ñ°ÇóÐµĹ¥»÷Ä¿±êºÍ¹¥»÷ÊÖ¶ÎÒÔ»ñÈ¡¸ü·áÊ¢µÄÊê½ð¡£¾ÝÊӲ췢ÏÖ£¬×ÔÈ¥Ä꿪ʼ£¬ÀÕË÷×éÖ¯½«Ä¿±êÀ©Õ¹µ½ÁËVMwareµÄÆóÒµ²úÎïvSphereÖжøÇÒ¶ÔÏàÓ¦ÀÕË÷Èí¼þ½øÐÐÕë¶ÔÐÔÉý¼¶ÒÔÊÊÅäÕë¶ÔVMwareÐéÄâ»úµÄÀÕË÷¡£µ½Ä¿Ç°ÎªÖ¹£¬¶à¼ÒʹÓÃvSphereµÄÆóÒµÒѾ­Ôâµ½ÀÕË÷£¬ÓÉÓÚʹÓÃvSphereµÄÆóÒµÐèÒªÔÚVMware ESX/ESXiÖ÷»úÉϲ¿Êð¶ą̀ÐéÄâ»úÒÔÂú×ãÈÕ³£µÄ·þÎñÆ÷»òÊý¾Ý¿âÐèÇó£¬ÀÕË÷×éÖ¯Ö»ÒªÉè·¨µÇ¼µ½ÆóÒµµÄVMware ESX/ESXiÖ÷»ú£¬¾ÍÄܲ¿ÊðÀÕË÷Èí¼þ¶ÔÖ÷»úÉϵĶą̀ÐéÄâ»úÔ´Îļþ½øÐмÓÃÜʵʩÀÕË÷¡£ÓëÒÔÍù´«Í³µÄÀÕË÷¹¥»÷²îÒ죬ÒÔÍùµÄÀÕË÷¹¥»÷½ö½öÊÇÕë¶Ôij̨»òÊý̨·þÎñÆ÷ÖеIJ¿ÃÅÖØÒªÊý¾Ý¼ÓÃÜ£¬¶øϵͳÒÀ¾É¿ÉÒÔÕý³£ÔËÐУ»¶øÕë¶ÔvSphereµÄÀÕË÷¹¥»÷¿ÉÖ±½Ó¼ÓÃÜVMware ESX/ESXiÖ÷»úÖеÄËùÓеÄÐéÄâ»úÔ´Îļþ£¬Õ⽫ֱ½Óµ¼ÖÂÊý̨ÊÂÇé·þÎñÆ÷»òÊý¾Ý¿â·þÎñÆ÷ÎÞ·¨Õý³£ÔËÐУ¬Ê¹ÆóÒµ/×éÖ¯µÄÖ÷ÒªÒµÎñÖжÏÉõÖÁϵͳ̱»¾£¬Õâ¶ÔÆóÒµ/×éÖ¯À´Ëµ½«ÊÇÖÂÃüµÄ¹¥»÷¡£


ÀÕË÷¹¥»÷ÒѾ­³ÉΪ¸÷´óÆóÒµ/×éÖ¯µÄÖØÒªÍøÂçÄþ¾²ÍþвÀ´Ô´£¬ÕâÖÖÐÂÁ÷ÐеÄÕë¶ÔvSphereµÄÀÕË÷¹¥»÷½«´øÀ´±ÈÒÔÍùµÄÀÕË÷¹¥»÷¸ü´óµÄÍþв¡£±¾ÎĶԡ°Õë¶ÔVMware vSphereµÄÀÕË÷¹¥»÷¡±½øÐÐÁËÈ«ÃæµØ·ÖÎö£¬Í¨¹ý½áºÏ¼¼ÊõÅä¾°ºÍÏà¹Øʼþ»î¶¯·ÖÎöÁËÀÕË÷×éÖ¯½«¹¥»÷Ä¿±êÀ©Õ¹µ½VMware vSphereµÄÔ­Òò£¬¶øÇÒƾ¾ÝÏà¹Ø¹¥»÷Ñù±¾µÄ·ÖÎö½Ò¶ÁË´ËÀàÀÕË÷¹¥»÷µÄÀÕË÷Á÷³Ì£¬Í¬Ê±Æ¾¾ÝÏà¹ØÖÊÁÏΪ¹ã´óÆóÒµ/×éÖ¯ÌṩÁËÏà¹ØµÄ·ÀÓù½¨Òé¡£


¶þ¡¢¹¥»÷Ä¿±ê£ºvSphere


VMware vSphere£¨¼ò³ÆvSphere£©ÊÇVMwareÆìϵÄÒ»ÕûÌ×ÔƼÆËã»ù´¡¼Ü¹¹ÐéÄ⻯ƽ̨£¬×ÔÐû²¼¸üÐÂÒÔÀ´ÔÚÈ«ÇòÒѾ­ÓµÓÐÁè¼Ý250000¿Í»§£¬Æä¿Í»§°üÂÞÕþ¸®¡¢¾ü¶Ó¡¢Ò½ÁÆ¡¢ÄÜÔ´¡¢½»Í¨¡¢½ÌÓýµÈÔÚÄڵĻù´¡ÉèÊ©ÁìÓò£¬Èçͼ1Ëùʾ£»Í¬Ê±£¬¹È¸èÔÆ¡¢°¢ÀïÔÆ¡¢ÑÇÂíÑ·ÔƵÈÔÆ·þÎñÌṩ³§É̾ù¶Ô¿Í»§ÌṩÍêÕûµÄvSphereÐéÄ⻯·þÎñ£¬Ïà¹ØÊг¡Ò²Í¬ÑùÅÓ´ó£¬Èçͼ2Ëùʾ¡£ÓµÓÐÈç´ËÅÓ´óµÄÊг¡£¬vSphere±»ÀÕË÷×éÖ¯¶¢ÉÏÒ²²»×ãΪÆ棬µ«ÊÇÆä¿Í»§¼¸ºõº­¸ÇËùÓÐÁìÓò£¬Ò»µ©²úÎï·ºÆ𩶴±»¹¥»÷ÕßÀûÓõ¼ÖÂÖ÷»ú±»ÀÕË÷²¡¶¾¹¥»÷£¬²»½ö½«Ôì³É¹¤ÒµËðʧ£¬¸üÓпÉÄÜÖ±½ÓÍþв¹ú¼ÒÄþ¾²¡£


ͼ1. vSphereµÄ¿Í»§ÁìÓòÂþÑÜ.png


ͼ1. vSphereµÄ¿Í»§ÁìÓòÂþÑÜ


ͼ2. ÔÆ·þÎñÉÌÌṩVMware·þÎñʾÀý.png


ͼ2. ÔÆ·þÎñÉÌÌṩVMware·þÎñʾÀý


VMware ESX/ESXi£¨¼ò³ÆESX/ESXi£©ÊÇvSphereµÄºËÐÄ×é¼þÖ®Ò»¡£ÔÚvSphereÖУ¬ESX/ESXiÊÇÒ»¸öÐéÄâ»ú¹ÜÀí·¨Ê½£¬ÓÃÓÚ´´½¨¡¢ÔËÐк͹ÜÀíÐéÄâ»ú½ø³ÌµÄÖмäÈí¼þ²ã£¬ÔËÐÐÔÚ»ù´¡ÎïÀí·þÎñÆ÷ºÍ²Ù×÷ϵͳ֮¼ä£¬¶øÇÒÔÊÐí¶à¸ö²Ù×÷ϵͳ¹²ÏíÖ÷»úÓ²¼þ¡£Æäʵ£¬ESX/ESXi²¢²»ÒÀÀµÆäËü²Ù×÷ϵͳ£¬¶øÊÇÖ±½Ó°²×°ÔÚÎïÀíÉ豸ÉÏ£¬È»ºóÒÔISO µÄÐÎʽÌṩ·þÎñ£»Óû§Ö±½ÓÔÚESX/ESXiÖд´½¨¡¢ÔËÐк͹ÜÀí×Ô¼ºµÄÐéÄâ»ú£¬Èçͼ3Ëùʾ¡£


ÔÚʵ¼Ê³¡¾°ÖУ¬ÆóҵΪÁËÌá¸ßÐÔÄܺͳɱ¾Ð§ÒæͬʱʵÏÖ¼ò»¯Êý¾ÝÖÐÐĺͷ½±ã´ó¹æÄ£¹ÜÀí£¬ÍùÍù»áÔÚһ̨ESX/ESXi·þÎñÆ÷Öв¿ÊðÊý̨ÉõÖÁÊýʮ̨ÐéÄâ»ú×÷ΪÈÕ³£µÄÊÂÇé·þÎñÖ÷»ú»òÕßÊý¾Ý¿â¡£ËùÒÔ£¬ESX/ESXiÖ÷»úÖлáÉú´æ×ÅÓëËüÔÚͬһÎïÀíÖ÷»úÉϵÄÆäËûÐéÄâ»úµÄÔ´ÎļþÒÔ±ã¶ÔÕâЩÐéÄâ»ú½øÐйÜÀí£¬Ëü¾ÍºÃ±È´æ·Å×ÅÊý̨·þÎñÆ÷µÄ»ú·¿£¬Èç¹û»ú·¿±»È˽ٳÖ£¬½«¶ÔÒ»¸öÆóÒµ»ò×éÖ¯Ôì³ÉÄÑÒÔ¹ÀÁ¿µÄËðʧ£¬ÕâÒ²ÊÇESX/ESXiÖ÷»ú»á³ÉΪÀÕË÷×éÖ¯¹¥»÷Ä¿±êµÄÖ÷ÒªÔ­ÒòÖ®Ò»£»ÁíÒ»¸öÔ­ÒòÔòÊÇ£¬ESX/ESXiÉϲ¿ÊðµÄ·þÎñÆ÷/Êý¾Ý¿â¿ÉÄÜÐèÒªÏò¿Í»§Ìṩ·þÎñ£¬ÕâҲʹµÃ¹¥»÷ÕßÓлú»áÖ±½Ó´ÓÍøÂç½Ó´¥µ½VMware ESX/ESXiÖ÷»ú£¬Îª¹¥»÷ÕßÌṩÁËÈëÇֵĿÉÄÜÐÔ¡£VMware¹«Ë¾ËäȻҲ·Ç³£Çå³þÆä²úÎïÄþ¾²µÄÖØÒªÐÔ£¬vSphere 5.0 ֮ǰµÄ°æ±¾Öоù½ÓÄÉESXÌåϵ½á¹¹À´ÊµÏÖ¶ÔÐéÄâ»úµÄ¹ÜÀí£¬ESXÊÇÒÀÀµÓÚLinuxµÄ¿ØÖÆ̨²Ù×÷ϵͳ (COS) À´ÊµÏÖ¿Éά»¤ÐԺͻùÓÚÊðÀíµÄºÏ×÷»ï°é¼¯³ÉµÄ£¬¶øLinux×÷Ϊ¿ªÔ´ÏµÍ³£¬ÓëLinuxÏà¹ØµÄ©¶´ÔÚ¸÷´óÄþ¾²ÉçÇøºÍµØϹ¤ÒµÖвã³ö²»ÇÕ⽫VMware ESX¼Ü¹¹ÖÃÓÚÒ»¸ö¸ß·çÏÕ´¦¾³£»ÎªÁËÌá¸ß»ù´¡¼Ü¹¹µÄÄþ¾²ÐÔ£¬vSphere 5.0Ö®ºóµÄ°æ±¾ÖÐÔò½ÓÄÉÁ˶ÀÁ¢ÓÚÀûÓÃϵͳµÄРESXi Ìåϵ½á¹¹£¬¶øÇÒÔÚ×Ô¼ºÑз¢µÄºËÐÄ VMkernel ÖÐʵÏÖÁ˱ر¸µÄÐéÄâ»ú¹ÜÀí¹¦Ð§£¬ÕâÒ²¾Í¹æ±ÜÁËÓëͨÓòÙ×÷ϵͳÏà¹ØµÄÄþ¾²Â©¶´Òý·¢µÄÄþ¾²·çÏÕ¡£


ÊÂÇé½á¹¹.png


ͼ3. VMware ESX/ ESXi ÊÂÇé½á¹¹


VMware vCenter Server£¨¼ò³ÆvCenter Server£©ÊÇvSphereµÄÁíÍâÒ»¸öºËÐÄ×é¼þ£¬ËüÊÇÒ»¸ö¿ÉÒÔ×ÊÖúÓû§¹ÜÀí¶à¸öVMwareÐéÄ⻯ƽ̨µÄÈí¼þ£¬ÐèÒªµ¥¶À°²×°ÔÚһ̨·þÎñÆ÷ÖС£ÔÚvSphereÖУ¬Óû§¿ÉÒÔ½«¶à¸öESX/ESXi Ö÷»úÌí¼Óµ½vCenter Server ¹ÜÀíƽ̨ÖУ¬È»ºóͨ¹ývCenter Server¹ÜÀíESX/ESXiÖ÷»úºÍÆäÖд´½¨µÄËùÓÐÐéÄâ»ú£¬Õû¸öÊÂÇé½á¹¹Èçͼ4Ëùʾ¡£ËäȻĿǰ·¢ÏÖµÄÀÕË÷Èí¼þÕë¶ÔµÄÊÇESX/ESXiÖ÷»ú£¬µ«vCenter Server¿ÉÒÔÖ±½Ó¹ÜÀíESX/ESXi¶ą̀Ö÷»ú¡£Èç¹ûvCenter Server´æÔÚ©¶´±»¹¥»÷ÕßÀûÓã¬ÄÇô¾ÍÎÞÒɽ«Êý̨ESX/ESXiÖ÷»úµÄ´óÃÅÏò¹¥»÷Õß³¨¿ª£¬¹¥»÷Õß¿ÉÒÔËÁÒâÔÚESX/ESXiÖв¿ÊðÀÕË÷Èí¼þ£¬Æäºó¹ûµÄÑÏÖØÐÔ¿ÉÏë¶øÖª¡£


ͼ4½á¹¹Í¼.png

ͼ4. vCenter Server ÊÂÇé½á¹¹


Èý¡¢ Õë¶ÔvSphereÀÕË÷µÄÏà¹Ø»î¶¯


²¡¶¾ÀÕË÷×÷Ϊ½üÄêÀ´Á÷ÐеÄÍøÂç¹¥»÷ÊֶΣ¬Öð½¥»ñµÃºÚ¿ÍÍÅ»ïÇàíù£¬Ô½À´Ô½¶àµÄÀÕË÷×éÖ¯·ºÆðÔÚ¹«¹²ÊÓÒ°£¬¸÷´ó²¡¶¾ÀÕË÷ʼþÒ²Öð½¥Õ¼¾ÝÁËÖØ´óÍøÂç¹¥»÷ʼþµÄÍ·°æÍ·Ìõ¡£½ü¼¸Ä꣬ÀÕË÷¹¥»÷ʼþ²ã³ö²»Ç¶ÔÊܺ¦ÆóÒµ/×éÖ¯Ôì³ÉÖØ´ó¹¤ÒµËðʧ£¬ÀÕË÷²¡¶¾ÒѾ­³ÉΪ¸÷Õþ¸®²¿ÃÅ¡¢×éÖ¯ºÍÆóÒµÐèÒªÃæÁÙµÄÖØÒªÍøÂçΣº¦Ö®Ò»¡£×ÔÈ¥Ä꿪ʼ£¬ÀÕË÷×éÖ¯Ö𽥿ªÊ¼°ÑÄ¿±êÑÓÉìµ½VMware vSphereƽ̨ÉÏ£¬Í¨¹ý¶ÔÆäÖÐESX/ESXi·þÎñÆ÷ÉϵÄÊý̨ÐéÄâ»úϵͳÎļþ½øÐмÓÃÜ´Ó¶øÏòÊܺ¦×éÖ¯/ÆóÒµÀÕË÷¸ß¶îµÄÊê½ð¡£È¥Äê7Ô£¬Sprite SpiderÀÕË÷×éÖ¯¾Í¿ªÊ¼¶ÔÆäÀÕË÷Èí¼þ½øÐÐÉý¼¶£¬Ê¹ÆäÔÚ¼ì²âµ½ESXiÖ÷»úºó²¿ÊðRansomEXX¶ñÒⷨʽÊÔͼÇÔÈ¡µÇ¼ƾ֤ÏòvCenter½øÐÐÉí·ÝÈÏÖ¤£»Í¬Ñù¶ÔÀÕË÷Èí¼þ½øÐÐESX/ESXiÕë¶ÔÐÔÉý¼¶µÄ»¹ÓÐÀÕË÷×éÖ¯carbon spider¡¢BabukLocker¡¢REvilºÍBlackMatter¡£×ÔÈ¥Ä꿪ʼ£¬Õë¶ÔVMwareÐéÄâ»úµÄÀÕË÷²¡¶¾¹¥»÷ʼþÒ²¿ªÊ¼Æµ·¢£¬È¥Äê11Ô°ÍÎ÷¸ßµÈ·¨Ôº£¨STJ£©Êܵ½´ó¹æÄ£ RansomExx ÀÕË÷Èí¼þ¹¥»÷£¬Áè¼Ý1000̨ÐéÄâ»úÎļþ±»¼ÓÃÜ£¬´Ë´ÎʼþÓë7Ô·ݽøÐÐVMware ESX/ESXiÈí¼þÉý¼¶µÄSprite SpiderÀÕË÷×éÖ¯ÊÇ·ñÓйØÁª£¬ÎÒÃÇÎÞ´ÓµÃÖª£»²»½ö¹úÍâÓû§ÔâÓöÁËÕë¶ÔVMware ESX/ESXiµÄÀÕË÷¹¥»÷£¬¹úÄÚÓû§Í¬ÑùÒ²ÔâÓöÁË´ËÀ๥»÷£¬ÔÚ½ñÄê3Ô£¬¹úÄÚij¹«Ë¾ÔËάÈËÔ±·¢ÏÖ¹«Ë¾ÄÚ²¿VMware ESXiÖ÷»úÉÏ´óÁ¿ÐéÄâ»úÎļþ±»¼ÓÃÜ£¬ÎÒÃÇÕûÀíµÄÏà¹ØµÄʼþʱ¼äÏßÈçͼ5¡£


ÀÕË÷²¡¶¾Õë¶ÔvSphereÏà¹Øʼþʱ¼äÏß.png


ͼ5. ÀÕË÷²¡¶¾Õë¶ÔvSphereÏà¹Øʼþʱ¼äÏß


´ÓÈ¥Ä꿪ʼ£¬IABsÍŶÓÖð½¥ÓëÀÕË÷²¡¶¾Ò»Æð½øÈ빫ÖÚµÄÊÓÒ°¡£IABsÍŶÓ×÷ΪÍøÂç¹¥»÷µØϹ¤ÒµµÄºã¾Ã»îÔ¾¼ÓÈëÕߣ¬Í¨¹ýÔÚ¸÷´óÂÛ̳³öÊÛÖ÷»úȨÏÞÀ´»ñÈ¡ÀûÒ棬ËüÃǽ«Êܺ¦ÕßÖ÷»úµÄrootȨÏÞ³öÊÛ¸øÆäËûÍøÂç¹¥»÷´ÓÒµÕߣ¬ÓÉÆäËûÍøÂç¹¥»÷Õß¿ªÕ¹ÏÂÒ»²½µÄ¹¥»÷»î¶¯£¬IABsÍŶӲ¢²»Ö±½Ó¼ÓÈë¹¥»÷£¬ÕâÒ²¼õÉÙÁËËüÃDZ»ÆäËûÖ´·¨»ú¹¹×·×ٵķçÏÕ¡£ÔÚÒÔÍùµÄÀÕË÷¹¥»÷ÖУ¬ÎÒÃÇÎÞ·¨È·¶¨ÀÕË÷×éÖ¯ÊÇ·ñÊÇ´ÓIABsÍŶÓÊÖÖйºÖÃÊܺ¦ÕßÖ÷»úȨÏÞ£¬ÀÕË÷×éÖ¯ÓëIABsÍŶӺÏ×÷ÕâÖÖģʽ¿ÉÄÜÔçÒÑ·ºÆ𣬵«ÊÇÕâÖÖºÏ×÷ģʽÕýÔÚÖð½¥±»¸÷¸öÀÕË÷×éÖ¯½ÓÄÉ£º¾ÝÏûÏ¢³Æ£¬ÃÀ¹ú×î´óȼÓ͹ܵÀÀÕË÷ʼþÖеÄÖ÷½ÇDarkSideÔÚÀÕË÷ÃÀ¹úʯÓ͹ܵÀÔËÓªÉÌColonial Pipeline֮ǰ¾ÍÔøÔÚµØÏÂÂÛ̳·¢ÎÄÑ°ÕÒÄܹ»ÈÃÆä½Ó´¥µ½ÊÐÖµ4ÒÚÃÀÔª¹«Ë¾µÄIABsºÏ×÷£¬Èçͼ6£¬ÃÀ¹úȼÓ͹ܵÀÀÕË÷ʼþÊÇ·ñÓÐIABsÍŶӼÓÈ룬ÎÒÃÇÎÞ´Ó¿¼Ö¤£»ÁíÍ⣬ÔÚµØÏÂÂÛ̳ÖУ¬ÎÒÃÇÒ²ÊӲ쵽Óжà¸öIABsÕýÔÚÑ°ÇóÀÕË÷ÍŶӺÏ×÷²¢³öÊÛvCenter/ESXiµÄRootȨÏÞ£¬Èçͼ7¡£


ͼ6. DarkSideÑ°ÇóÓëIABsÍŶӺÏ×÷.png


ͼ6. DarkSideÑ°ÇóÓëIABsÍŶӺÏ×÷


ÀÕË÷×èÖ¹½á¹¹.png


ͼ7. IABsÍŶÓÑ°ÇóÓëÀÕË÷×éÖ¯ºÏ×÷


ËÄ¡¢ Õë¶ÔvSphereÀÕË÷µÄÔ­Òò·ÖÎö


ÖÚ¶àÀÕË÷×éÖ¯¿ªÊ¼½«Ä¿±êÑÓÉìµ½vSphereƽ̨ÉÏ£¬ÎÞ·ÇÊÇΪÁ˼ÓÃܸü¶à¸üÖØÒªµÄÊý¾ÝÒÔÀÕË÷¸ü¸ß¶îµÄÊê½ð¡£Õë¶ÔvSphereƽ̨µÄÀÕË÷¹¥»÷£¬Äܹ»Ê¹ÀÕË÷×éÖ¯Ïñ¿ØÖÆÒ»¼äÆóÒµ·þÎñÆ÷µÄ»ú·¿Ò»Ñù¶ÔÊý̨·þÎñÆ÷½øÐпØÖÆ£¬¹¥»÷Õ߶ÔÕâЩÐéÄâ»úµÄÔ´Îļþ½øÐмÓÃÜ£¬¿ÉÄÜÖ±½ÓÔì³ÉÊý¾Ý¿â±»¼ÓÃÜ¡¢¶ÔÍâÌṩ·þÎñÖжÏÉõÖÁ¹«Ë¾ÏµÍ³Ì±»¾£¬ÀÕË÷×éÖ¯ÍùÍù¿ª³ö¸ü¸ß¶îµÄÊê½ð¡£Èç´Ë¸ªµ×³éнµÄÀÕË÷·½Ê½£¬ÈÃÊܺ¦ÕßÆóÒµ/×éÖ¯¶Ìʱ¼äÄÑÒÔÓ¦¸¶£¬¼«´óµØÔö¼ÓÁËÀÕË÷¹¥»÷µÄÀÖ³ÉÂʺÍÊÕÒæ¡£Æäʵ£¬Ëæ×Å»¥ÁªÍø¼¼ÊõµÄ¸ïУ¬ÀÕË÷×éÖ¯Ò»Ö±ÔÚ²»Í£Ñ°ÕÒÐµĹ¥»÷Ä¿±êºÍ¹¥»÷ÊֶΣ¬ÀÕË÷×éÖ¯×ö³ö ¡°Õë¶ÔvSphereƽ̨¹¥»÷¡± µÄÕâÖָı䲢·ÇżȻ£¬½áºÏÏà¹Ø×ÊÁÏ£¬ÎÒÃǽ«ÔÚ±¾Õ¶ÔÀÕË÷×éÖ¯µÄÕâÖָıä½øÐÐÒ»¸öÔ­Òò·ÖÎö¡£


Åä¾°Ìõ¼þ£ºËæ×Å»¥ÁªÍø¼¼ÊõµÄ¿ìËÙ¸üУ¬ÍøÂçÓû§Á¿¾çÔö£¬¸÷¸öÕþ¸®²¿ÃÅ¡¢×éÖ¯ºÍÆóÒµ¶Ô¼ÆËã×ÊÔ´ºÍ´æ´¢×ÊÔ´µÄÐèÇóÖèÔö£»ÔƼÆËãºÍÐéÄâ¼¼ÊõµÄÐËÆðÈø÷´óÔÆ·þÎñÌṩÉ̺ÍÐéÄ⻯¼¼Êõ¹«Ë¾Îª¸÷¸öÕþ¸®²¿ÃÅ¡¢×éÖ¯ºÍÆóÒµÌṩÁ˶¨ÖÆ»¯×ÊÔ´·þÎñºÍÐéÄ⻯½â¾ö·½°¸ÒÔÂú×ãÈÕ³£×ÊÔ´ÐèÇó¡£VMware×÷ΪÔÆ·þÎñºÍÐéÄ⻯ÁìÓòµÄÁìÍ·ÆóÒµ£¬Æä¿Í»§¼¸ºõº­¸ÇËùÓÐÁìÓò£»³ý´ËÖ®Í⣬¸÷´óÔÆ·þÎñÌṩÉÌҲΪÆä¿Í»§Ìṩ¼ä½ÓµÄVMwareÐéÄ⻯·þÎñ£¬´Óͼ8 ¡°2020Äê·þÎñÆ÷ÐéÄ⻯Êг¡ÂþÑÜ¡± ÖпÉÒÔ¿´³ö£¬VMwareÒѾ­³ÉΪÐéÄ⻯Êг¡µÄ¾ø¶Ô°ÔÖ÷¡£Õë¶ÔVMware vSphere½øÐÐÀÕË÷¿ÉÒÔÓµÓÐÖÚ¶àÀÕË÷¹¤¾ß£¬Í¬Ê±Äܹ»Í¨¹ýÐéÄ⻯ƽ̨vSphere¿ØÖÆÆóÒµ/×éÖ¯µÄ´óÁ¿Êý×Ö×ʲú£¬¼«´óµØÌá¸ßÁËÀÕË÷µÄÊÕÒæºÍÀÖ³ÉÂÊ¡£


·þÎñÆ÷Ç÷ÊÆ.png


ͼ8. 2020Äê·þÎñÆ÷ÐéÄ⻯½â¾ö·½°¸µÄÒµÎñÊг¡ÂþÑÜ£¨À´Ô´£ºspiceworks£©


¼¼ÊõÌõ¼þ£º2019Äêµ×ºÍ2020Ä꣬VMware·Ö±ðÐû²¼Äþ¾²Í¨¸æÐÞ¸´Á˶à¸ö²úÎ勇´£¬ÆäÖÐVMware ESXiµÄÁ½¸ö©¶´CVE-2019-5544ºÍCVE-2020-3992½«µ¼ÖÂVMware ESXi·þÎñÆ÷ÉϵÄÔ¶³Ì´úÂëÖ´ÐУ¬VMwareÒѾ­¶ÔÕâÁ½¸ö©¶´½øÐÐÁËÆÀ¹À£¬²¢¶¨¼¶ÎªÑÏÖØ£¬CVSSv3 ÆÀ·Ö 9.8¡£ÕâÁ½¸ö©¶´½«Ó°Ïì¶à¸ö°æ±¾µÄVMware vSphereÓû§£¬ËæºóVMwareÌṩÐÞ¸´²¹¶¡£¬µ«ÈÔÓдóÅú¿Í»§ÒòΪÖÖÖÖÔ­Òò²¢Î´¶ÔÆäʹÓõÄESX/ESXi½øÐв¹¶¡£¬ÕâΪ¹¥»÷ÕßÌṩÁ˱ã½ÝµÄÈëÇÖVMware ESX/ESXiÖ÷»úµÄÒªÁìºÍÊֶΡ£


ÍⲿÌõ¼þ£º×Ô2020ÄêÆð£¬IABsÒ²½«ÆäÄ¿±êÀ©Õ¹µ½ÁËVMware vSphereƽ̨ÉÏ¡£¶Ô´ó²¿ÃÅÀÕË÷×éÖ¯À´Ëµ£¬ÓëIABsºÏ×÷ÊÇÒ»Ïî¹²Ó®µÄÑ¡Ôñ,ÒòΪ´ÓIABsÊÖÉϹºÖÃESX/ESXiÖ÷»úȨÏ޵ļ۸ñÒ²½ö½öÖ»ÊÇÊê½ðµÄ¼«Ð¡²¿ÃÅ£¬Í¨¹ýÕâÖÖ·½Ê½£¬ËûÃÇÄܹ»Ê¡È¥´óÁ¿µÄÈËÁ¦¡¢Ê±¼ä¡¢×ÊÔ´È¥»ñÈ¡ESX/ESXiÖ÷»úµÄRootȨÏÞ£¬Ö±½Óͨ¹ý¹ºÖõÄÖ÷»úRootȨÏÞ½øÐÐÊܺ¦ÕßÖ÷»úµÇ¼£¬È»ºó¿ªÊ¼²¿ÊðÀÕË÷Èí¼þ½øÐÐÀÕË÷¡£Í¬Ê±£¬ÎÒÃÇÊӲ쵽ÓÐIABs£¨Initial access brokers£©¿ªÊ¼ÔÚµØϺڿÍÂÛ̳ÉÏÒÔ250ÃÀ½ðµ½500ÃÀ½ðÖ®¼ä¼Û¸ñ³öÊÛESX/ESXiµÄRootȨÏÞ£¬²¢Õ¹Ê¾³ö¸ü¶à¹ØÓÚÊܺ¦Ö÷»úµÄÐÅÏ¢À´ÎüÒý¿Í»§¹ºÖ㬺ñȵØÓòÐÅÏ¢¡¢È¨ÏÞÐÅÏ¢¡¢CPUÐÅÏ¢¡¢Ó²ÅÌÐÅÏ¢µÈ£¬Èçͼ9Ëùʾ£¬¹úÄÚijÓû§µÄVMware ESXÖ÷»úµÄRootȨÏÞÔÚµØϺڿÍÂÛ̳±»³öÊÛ¡£


IABsÔÚµØÏÂÂÛ̳ÉÏÊÛÂôESXȨÏÞ.png


ͼ9. IABsÔÚµØÏÂÂÛ̳ÉÏÊÛÂôESXȨÏÞ


Îå¡¢ Õë¶ÔvSphereµÄÀÕË÷ÑùÌìÖ°Îö


×ÔÈ¥Ä꿪ʼ£¬¸÷´óÀÕË÷×éÖ¯¿ªÊ¼Ðû²¼Õë¶ÔVMware vSphereÐéÄâƽ̨°æ±¾µÄÀÕË÷·¨Ê½£¬ÒѾ­Óжà¼ÒÆóÒµ/×éÖ¯Ôâµ½¹¥»÷¶øÇÒËðʧ²ÒÖØ¡£ÔÚ±¾Ð¡½ÚÖУ¬ÎÒÃǽ«ÒÔADLab¶ÔÀÕË÷¼Ò×åµÄÁ¬ÐøÑо¿Îª»ù´¡£¬½áºÏ²¿ÃŹúÍâÄþ¾²³§É̶ԴËÀ๥»÷»î¶¯µÄÅû¶À´¶Ô²¿ÃÅÀÕË÷×éÖ¯µÄÑù±¾½øÐзÖÎö£¬Í¬Ê±½áºÏʵ¼Ê¹¥»÷°¸Àý¶Ô´ËÀ๥»÷µÄ¹¥»÷Á÷³Ì½øÐÐÁË×ܽá¡£Èçͼ10£¬ÔÚʵ¼Ê³¡¾°ÖУ¬ESX/ESXiÖ÷»úÉϻᲿÊð¶ą̀ÐéÄâ»ú¶ÔÆÕͨÓû§Ìṩ»ù±¾·þÎñ£¬Èç¹ûÅäÖò»Í×£¬ÆÕͨÓû§ÄÜͨ¹ýÍøÂçÄÜ·ÃÎÊESX/ESXiÖ÷»ú£¬Õâ¾Í»á¸øºÚ¿ÍÌṩ¿É³ËÖ®»ú£»Í¨³£Çé¿öÏ£¬ºÚ¿ÍÊ×ÏÈ»áÔÚµØÏÂÂÛ̳ÖÐÑ°ÇóÖ¸¶¨°æ±¾µÄESX/ESXi©¶´ÀûÓ÷¨Ê½»òrootµÇ¼ȨÏÞ£¬µ±»ñÈ¡µ½Â©¶´ÀûÓ÷¨Ê½»òrootµÇ¼ȨÏ޺󣬺ڿ;ÍÄÜÖ±½ÓÈëÇÖESX/ESXiÖ÷»ú¶øÇÒÔÚÆäÖв¿ÊðÀÕË÷Èí¼þ¶ÔÆäÖеÄÐéÄâ»ú½øÐмÓÃܲ¢ÀÕË÷Êê½ð¡£´ÓͼÖпÉÒÔ¿´³ö£¬Èç¹ûÀÕË÷¹¥»÷¹¤¾ßÊÇÔÆ·þÎñÌṩÉÌ/ÐéÄâ·þÎñÌṩÉ̵ÄESX/ESXiÖ÷»ú£¬ÄÇô¸ÃÌṩÉ̵ÄÖÚ¶à¿Í»§¶¼½«Êܵ½Ó°Ï죬´óÃæ»ýµÄÆóÒµÓû§Ö÷»ú½«Ôâµ½ÀÕË÷²¡¶¾Ñ¬È¾£¬Õ⽫´øÀ´Óë½ñÄêÃÀ¹úIT¹ÜÀíÈí¼þÖÆÔìÉÌKaseyaÔâµ½µÄ¹©Ó¦Á´Ê½ÀÕË÷¹¥»÷ÏàËƵĽá¹û£¬¶øKaseyaµÄÀÕË÷¹¥»÷ÒѾ­Ñ¬È¾ÁËÁè¼Ý100Íò¸öϵͳ£¬Áè¼Ý1500¼ÒÆóÒµÊܵ½Ó°Ïì¡£


Õë¶ÔvSphereÐéÄâƽ̨µÄÀÕË÷¹¥»÷³¡¾°.png


ͼ10. Õë¶ÔvSphereÐéÄâƽ̨µÄÀÕË÷¹¥»÷³¡¾°


½ÓÏÂÀ´£¬ÎÒÃǽ«¶Ô²¿ÃÅÀÕË÷×éÖ¯µÄÑù±¾½øÐÐÏêϸ¼¼Êõ·ÖÎö£¬Í¨¹ýºáÏò±È¶Ô£¬¿ÉÒÔ×ܽá³öÕâЩÕë¶ÔVMware vSphereÐéÄâƽ̨ÀÕË÷·¨Ê½µÄÖ´ÐÐÌص㣺ͨ³£Çé¿öÏ£¬ÀÕË÷Èí¼þÊ×ÏÈ»áʹÓÃESX/ESXiµÄesxcliÖ¸Áî²éÕÒÐéÄâ»ú½ø³Ì£»È»ºó£¬¶ñÒⷨʽ»áʹÓÃesxcliÖ¸Áî¹Ø±ÕÐéÄâ»ú£¬ÕâÒ»²½Í¨³£ÊÇΪÁË·ÀÖ¹¶ÔÐéÄâ»úÎļþ½øÐмÓÃÜʱ¶ÔÐéÄâ»úÔ­ÎļþÔì³ÉÆÆ»µ£¬´Ó¶øµ¼Ö¼ÓÃÜʧ°Ü£»½ÓÏÂÀ´£¬¶ñÒⷨʽ½«ÔÚÖ¸¶¨Â·¾¶Ï½øÐÐÐéÄâ»úÏà¹ØÎļþËÑË÷£¨Í¨³£°üÂÞÐéÄâ»úÐéÄâ´ÅÅÌÎļþvmdk¡¢ÐéÄâ»úÐéÄâÄÚ´æÎļþvmem¡¢ÐéÄâ»úÒ³½»»»Îļþvswp£¬ÈÕÖ¾Îļþlog¡¢ÐéÄâ»ú¿ìÕÕÎļþvmsnµÈ£©£»×îºó£¬¶ñÒⷨʽ½«¶ÔËÑË÷µ½µÄÐéÄâ»úÏà¹ØÎļþ½øÐмÓÃÜ£¬Í¬Ê±¼û¸æÊܺ¦Õß½ÉÄÉÊê½ð¡£


5.1 DarkSide

DarkSideÀÕË÷Èí¼þ×îÔçÓÚ2020Äê8Ô±»·¢ÏÖ£¬ÊÇÒ»Ö§·Ç³£»îÔ¾µÄÐÂÐËÀÕË÷ÍŻDarkSide×éÖ¯×Ô2020Äê8Ô¿ªÊ¼Æµ·±»î¶¯£¬²¢ÔÚ½ñÄê5Ô¹¥»÷ÁËÃÀ¹ú×î´óµÄȼÓ͹ܵÀ¹«Ë¾Colonial Pipeline£¬µ¼ÖÂÃÀ¹ú¶«²¿Ñغ£Ö÷Òª¶¼ÊÐÊäËÍÓÍÆøµÄ¹ÜµÀϵͳ±»ÆÈÏÂÏߣ¬17¸öÖݺÍÊ׶¼ËùÔڵĻªÊ¢¶ÙÌØÇøÐû²¼½øÈë½ô¼±×´Ì¬£¬ÒýÆðÁ˾޴óµÄºä¶¯ºÍÈ«ÇòµÄ¹Ø×¢¡£×îÖÕ£¬Colonial PipelineÖ§¸¶Á˽ü75±ÈÌرң¨Ô¼ºÏ½ü500ÍòÃÀÔª£©²ÅʹÊý¾ÝµÃÒÔ»Ö¸´£¬ÔËÊäÊÂÇéÕý³£ÔËÐС£Í¬Ê±ÎÒÃÇÒ²·¢ÏÖ£¬DarkSideÔÚÈ¥Äê¾ÍÒѾ­¾ß±¸¹¥»÷ESXiµÄ¹¦Ð§¡£


Ñù±¾¼¼Êõ·ÖÎö


ΪÁ˸üºÃµØ¼ÓÃÜÐéÄâ»ú£¬DarkSideʹÓÃÁËÐí¶àESXiÉ϶ÀÕ¼µÄesxcliÃüÁÈçÔÚ¼ÓÃÜÐéÄâ»úÇ°»áʹÓÃesxcliÃüÁîÀ´±éÀú³öESXiÉÏÕýÔÚÔËÐеÄÐéÄâ»ú¡£


DarkSideʹÓÃesxcliÃüÁîÇ¿ÖƹرÕÕýÔÚÔËÐеÄÐéÄâ»ú.png


³ýÁËÒÔÉÏÃüÁÔÚDarkSide»¹ÓÃÁËÐí¶àesxcliÃüÁ¾ßÌåÈçϱíËùʾ£º

¼ÓÃÜ·¾¶.png

DarkSideͨ¹ý±éÀúÎļþ£¬¶øÇÒÅжÏÎļþºó׺ÊÇ·ñΪvmdk£¨ÐéÄâ»úÐéÄâ´ÅÅÌÎļþ£©£¬vmem£¨ÐéÄâ»úÐéÄâÄÚ´æÎÄÎļþ£©£¬vswp£¨ÐéÄâ»úÒ³½»»»Îļþ£©£¬log£¨ÈÕÖ¾Îļþ£©£¬vmsn£¨ÐéÄâ»ú¿ìÕÕÎļþ£©À´¾ö¶¨ÊÇ·ñ½øÐмÓÃÜ£¬¼ÓÃÜÀֳɺó»áÔÚÔ­Îļþºó׺ºó¼ÓÈëdarkside¡£


Îļþ¾ÞϸÅжÏ.png


×îºó£¬DarkSide»áÁôÏÂÀÕË÷О¯¸æÊܺ¦Õߣ¬¶øÇÒÔÚÐÅÖÐÁôÏ»¹Ô­Êý¾ÝµÄ·½Ê½ÒÔ¼°½»Êê½ðµÄµØÖ· 


ÀÕË÷ÐÅ.png


5.2 REvil


REvilÒ²±»³ÆΪSodinokibi£¬ÊÇÒ»¸öÎÛÃûÕÑÖøµÄÀÕË÷ÍŻÆä¹¥»÷×îÔç¿ÉÒÔ×·Ëݵ½2019Äê4Ô¡£¸ÃÀÕË÷ÍÅ»ï×÷°¸Æµ·±£¬²¢Ôø¹¥»÷¹ý¶à¸ö´óÐ͹«Ë¾ÈçÃÀ¹úÁìÏȵÄÊÓƵ´«ÊäÌṩÉÌSeaChange International¡¢ÖøÃûÓ²¼þºÍµç×Ó¹«Ë¾ºê»ù¹«Ë¾¡¢È«ÇòÔÙÉúÄÜÔ´¾Þë¢Invenergy¹«Ë¾¡¢È«Çò×î´óÈâÀ๩ӦÉÌJBS¹«Ë¾¡£¶øÔÚ½ñÄê7ÔÂÃÀ¹úÔ¶³ÌIT¹ÜÀíÈí¼þ³§ÉÌKaseyaÒ²ÔâÊܵ½ÁËREvilµÄ¹¥»÷£¬µ¼ÖÂÈ«ÇòÁè¼Ý10000¼ÒµÄKaseya¿Í»§£¬ÆäÖаüÂÞ50%ÒÔÉϵÄÈ«Çò100Ç¿IT¹ÜÀí·þÎñÌṩÉ̼°¸÷´óÁúÍ·Êܵ½ÀÕË÷¹¥»÷µÄ·çÏÕ¡£¾Ý³Æ´Ë´Î¹¥»÷ÊÇREvilÓÐÊ·ÒÔÀ´¹æÄ£×î´óµÄÒ»´Î¹¥»÷£¬¾ÝÆä¹ÙÍøÐû³Æ£¬ËûÃÇÒѾ­Ëø¶¨ÁËÁè¼Ý100Íò¸öϵͳ£¬²¢ÏòKaseyaË÷È¡70000000ÃÀÔªµÄÊê½ð¡£¶øÔÚ½ñÄê5Ô£¬ÎÒÃÇÊӲ쵽REvilÔËÓªÉÌÔÚµØϺڿÍÂÛ̳ÉÏÐû²¼ÁËÕë¶ÔVmware ESXiµÄLinux°æ±¾¡£


Ñù±¾¼¼Êõ·ÖÎö


ΪÁËÖÆÖ¹ÐéÄâ»úÏà¹ØµÄÎļþÊܵ½²»ÐëÒªµÄË𻵣¬REvilÔÚ¼ÓÃÜǰҲͬÑù»áÏȹرÕESXiÉÏÕýÔÚÔËÐеÄÐéÄâ»ú£¬µ«ÓëDarkSide²îÒìµÄÊÇREvilÏÈʹÓÃpkill -9µÄÃüÁî¹Ø±ÕÓëÐéÄâ»úÏà¹ØµÄ½ø³Ì¡£


ÃüÁî¹Ø±Õ.png

È»ºóREvilʹÓÃexcliÃüÁî±éÀú³öËùÓÐÕýÔÚÔËÐеÄESXiÐéÄâ»ú¶øÇҹرÕËüÃÇ£¬Ê¹ÓôËÃüÁî»á¹Ø±Õ´æ´¢ÔÚ /vmmfs/ Îļþ¼ÐÖеÄÐéÄâ»ú´ÅÅÌ (VMDK) Îļþ£¬·ÀÖ¹REvil¶ÔÕâЩÎļþ½øÐмÓÃÜʱÒòΪ±» ESXi Ëø¶¨¶øµ¼Ö¼ÓÃÜʧ°Ü¡£


ÃüÁî¹Ø±Õ»úÆ÷.png

ÓëÆäËûÕë¶ÔESXiµÄÀÕË÷Èí¼þ²îÒìµÄÊÇ£¬REvil²»»á¶ÔÐéÄâ»úÎļþµÄºó׺½øÐÐÅжÏ£¬¶øÊǶԼÓÃÜ·¾¶ÏÂËùÓеÄÎļþ¶¼½øÐмÓÃÜ£¬²¢ÅжϸÃÎļþÊÇ·ñÒѾ­±»¼ÓÃÜÁ˺ÍÊÇ·ñ¾ßÓÐRWXȨÏÞ»òÕßRWȨÏÞ£¨Èç¹û¾ßÓÐÕâЩȨÏÞ£¬ÔòÕâЩÎļþÊDZ»ÏµÍ³±£»¤µÄ£©À´¾ö¶¨ÊÇ·ñ½øÐмÓÃÜ¡£ 


¼ÓÃÜÎļþ¹ý³Ì.png


×îºó£¬REvilÁôÏÂÀÕË÷О¯¸æÊܺ¦Õ߶øÇÒÔÚÐÅÖÐÁôÏ»¹Ô­Êý¾ÝµÄ·½Ê½ÒÔ¼°½»Êê½ðµÄµØÖ·¡£


ͼ20. REvilµÄÀÕË÷ÐÅ.png

ͼ20. REvilµÄÀÕË÷ÐÅ



5.3 HelloKitty


HelloKittyÀÕË÷Èí¼þ¹¥»÷»î¶¯×îÔç¿ÉÒÔ×·Ëݵ½2020Ä꣬Ö÷ÒªÕë¶ÔWindowsϵͳ¡£ÆäÔÚ2021Äê2Ô¹¥»÷ÁËCD Projekt Red¹«Ë¾²¢Éù³ÆÇÔÈ¡Á˸ù«Ë¾³öÆ·µÄ¡°Cyberpunk 2077¡±¡¢¡°Witcher 3¡±¡¢¡°Gwent ¡±ºÍÆäËûÓÎÏ·µÄÔ´´úÂë¡£¶øÔÚ½ñÄê7Ô£¬ÎÒÃÇÊӲ쵽¸ÃľÂíµÄLinux±äÌ忪ʼÕë¶ÔVmware ESXi½øÐй¥»÷¡£ÆäÖУ¬±»¹¥»÷µÄÄ¿±ê°üÂÞÒâ´óÀûºÍºÉÀ¼µÄÖÆÒ©¹«Ë¾¡¢Ò»¼ÒµÂ¹úÖÆÔìÉÌ¡¢Ò»¼Ò°Ä´óÀûÑÇÌṩ¹¤Òµ×Ô¶¯»¯½â¾ö·½°¸µÄ¹«Ë¾ÒÔ¼°ÃÀ¹úÒ»¼ÒÒ½Áư칫ÊҺ͹ÉƱ¾­¼ÍÈË¡£ÔÚÊê½ð·½Ã棬¹¥»÷Õß»áÒò¹¥»÷Ä¿±ê¹«Ë¾µÄ¹æÄ£²îÒ죬¶øÒªÇóÖ§¸¶²îÒì½ð¶îµÄÊê½ð£¬ÆäÀÕË÷µÄÊê½ð×î¸ß¿É´ï1000ÍòÃÀ½ð¡£


Ñù±¾¼¼Êõ·ÖÎö


HelloKittyÀÕË÷Èí¼þÊ×ÏÈ»áʹÓÃesxcliÃüÁîÀ´±éÀú³öµ±Ç°ÊÜѬȾ»úÆ÷ÉÏÕýÔÚÔËÐеÄÐéÄâ»ú½ø³Ì£¬²¢ÊµÑé¹Ø±ÕÕâЩÐéÄâ»ú¡£ÎªÁËÖÆÖ¹ÐéÄâ»úÏà¹ØµÄÎļþÔâµ½²»ÐëÒªµÄË𻵣¬¸Ã²¡¶¾ÔÚ¼ÓÃÜÎļþÇ°»áÏȽ«ÐéÄâ»ú¹Ø±Õ¡£


¸ÃÀÕË÷Èí¼þÊ״ιرÕÐéÄâ»ú£¬»áʹÓÃÈíÖÕÖ¹À´½áÊø¸Ã½ø³Ì¡£


ÃüÁesxcli vm process kill -t=soft -w=%d


Èç¹ûÈÔÓÐÐéÄâ»úÕýÔÚÔËÐУ¬¸Ã²¡¶¾½«»áʹÓÃÓ²ÖÕÖ¹À´½áÊø¸Ã½ø³Ì¡£


ÃüÁesxcli vm process kill -t=hard -w=%d


Èç¹û»¹ÓÐÐéÄâ»úδ±»¹Ø±Õ£¬Ôò»áʹÓÃÇ¿ÖÆÖÕÖ¹À´½áÊø¸Ã½ø³Ì¡£


ÃüÁî·û.png

Êê½ðÎı¾.png


5.4 BlackMatter

2021Äê7Ô£¬Ò»¸öÃûΪBlackMatterµÄÐÂÀÕË÷Èí¼þ×éÖ¯ÕýÔÚ¹ºÖÃÆóÒµÍøÂçµÄ·ÃÎÊȨÏÞ£¬Í¬Ê±Éù³ÆÆäÏîÄ¿Òѽ«REvilºÍDarkSideµÄ×î¼Ñ¹¦Ð§ÈÚÈëÆäÖС£BlackMatter»¹ÌåÏÖ£¬ËûÃǵÄÀÕË÷Èí¼þÊÊÓÃÓÚ¶àÖÖ²îÒìµÄ²Ù×÷ϵͳ°æ±¾ºÍ¼Ü¹¹£¬²¢ÒÔ¶àÖÖ¸ñʽÌṩ¡£°üÂÞÖ§³ÖÄþ¾²Ä£Ê½µÄWindows±äÌ壨Windows Server2003+x86/x64ºÍWindows7+x86/x64£©ºÍÖ§³ÖNASµÄLinux±äÌ壨ESXI5+¡¢Ubuntu¡¢DebianºÍCenOs£©£¬ÇÒÕâЩ±äÌåÔÚÏàͬϵͳÉϾùÒѲâÊÔÀֳɡ£


Ñù±¾¼¼Êõ·ÖÎö


BlackMatterÔÚESXI·þÎñÆ÷ÉÏÔËÐÐʱ£¬ÆäÊ×ÏÈʹÓÃesxcliÃüÁîÁгöËùÓÐÕýÔÚÔËÐеÄVMwareÐéÄâ»ú¡£


ÐéÄâ»ú.png

½Ó×Å£¬BlackMatter»á»ñÈ¡µ±Ç°ÏµÍ³ËùÓÐÕýÔÚÔËÐеĽø³Ì£¬²¢½«ÕâЩ½ø³ÌÇ¿ÖƽáÊø¡£ 


ÅäÖÃÎļþ.png

¼ÓÃÜÎļþºó׺.png

ÀÕË÷Îı¾.png

Áù¡¢ ×ܽáÓ뽨Òé


Õë¶ÔÐéÄ⻯ƽ̨VMware vSphereµÄÀÕË÷¹¥»÷³ÉΪÀÕË÷×éÖ¯µÄÐÂÐ͹¥»÷Æ«Ïò£¬±¾ÎÄ´Ó¶à¸ö½Ç¶È¶Ô´ËÀ๥»÷½øÐÐÁË×ۺϷÖÎö¡£Õë¶ÔÐéÄ⻯ƽ̨VMware vSphereµÄÀÕË÷¹¥»÷¿ÉÄÜ»áÔ½·¢Æµ·±£ºÊ×ÏÈ£¬¹¥»÷Õ߶ÔÐéÄâ»ú¹ÜÀíƽ̨µÄESX/ESXiÖ÷»ú½øÐÐѬȾºó¿ÉÒÔ¶ÔÆäÖеÄÊý̨ÐéÄâ»úÔ´Îļþ½øÐмÓÃÜ£¬½«Ö±½ÓÓ°ÏìÊܺ¦ÆóÒµ/×éÖ¯µÄ¶ą̀ӦÓ÷þÎñÆ÷/Êý¾Ý¿â£¬ÕâÖÖ·½Ê½¿ØÖÆÁËÔ½·¢ÖØÒªÆóÒµ/×éÖ¯µÄÊý×Ö×ʲú£¬Äܹ»ÀÕË÷¸ü¸ß¶îµÄÊê½ð¶øÇÒ´ó´óÌá¸ßÀÖ³ÉÂÊ£¬ÕâÕýÊÇÀÕË÷×éÖ¯µÄºËÐÄÄ¿µÄ£»Æä´Î£¬Ô½À´Ô½¶àµÄºÚ¿Í½«Ä¿±êתÏòÁËVMware vSphere£¬Ïà¹ØµÄÄþ¾²Â©¶´ÆµÆµ±»·¢ÏÖ£¬µ«Ðí¶à¿Í»§ÓÉÓÚÖÖÖÖÔ­ÒòÏÞÖƲ¢Î´Äܼ°Ê±²¹¶¡£¬ÕâҲΪÀÕË÷×éÖ¯ÈëÇÖµ½ÆóÒµµÄESX/ESXiÖ÷»úÌṩÁ˱ãÀû£»ÁíÍ⣬IABsÍŶÓÔÚµØÏÂÂÛ̳ÖÐÕë¶ÔVMware vSphereµÄ»î¶¯Ò²Ô½¼ÓƵ·±£¬Í¬Ê±ËüÃÇÒ²ÔÚ»ý¼«Ñ°ÇóÓëÀÕË÷×éÖ¯½øÐкÏ×÷£¬IABsÍŶÓÄܹ»ÌṩרҵESX/ESXiÖ÷»úµÄÈëÇÖ·þÎñ£¬ËüÓëÀÕË÷×éÖ¯µÄºÏ×÷½«»á°ÑÕë¶ÔvSphereµÄÀÕË÷¹¥»÷ÍÆÉÏÐÂÒ»ÂÖµÄÈȳ±¡£


¿ÉÒÔ¿´³ö£¬Ëæ×Å»¥ÁªÍø¼¼ÊõµÄ²»Í£¸ïкÍÊг¡µÄ±ä»¯£¬ÀÕË÷×éÖ¯Ò²ÔÚ²»Í£À©Õ¹ËüÃǵĹ¥»÷Æ«ÏòºÍÑ°Çó¸üÓÐЧµÄ¹¥»÷ÊÖ·¨£¬ÒÔ±ãÔÚÀÕË÷¹¥»÷ÖлñÈ¡¸ü¸ß¶îµÄÊê½ðͬʱ´ó·ùÌá¸ßÀÕË÷µÄÀÖ³ÉÂÊ¡£VMware vSphereÖ»ÊÇÖÚ¶àÐéÄ⻯ƽ̨µÄÆäÖÐÒ»¸ö£¬Ö»ÊÇÓÉÓÚËüµÄÊг¡ÅӴ󣬳ÉΪÁ˹¥»÷ÕßµÄÊ×Ñ¡Ä¿±ê£»Ëæ×Åʱ¼äµÄÍÆÒÆ£¬ÆäËûÐéÄ⻯ƽ̨È磺Microsoft¡¢OracleºÍRed HatµÈºÜ¿ÉÄÜ»á³ÉΪ¹¥»÷ÕßµÄÐÂÄ¿±ê£¬¸÷´óÆóÒµ/×éÖ¯Ó¦µ±×¢ÒâÌáÇ°×öºÃÕë¶ÔÐÔ·ÀÓù¡£Õë¶ÔvSphereÐéÄâƽ̨µÄÀÕË÷¹¥»÷½«¶ÔÊܺ¦ÕßÆóÒµ´øÀ´ÄÑÒÔ¹ÀÁ¿µÄËðʧ£¬ÎÒÃǽ«½áºÏ±¾ÎĵķÖÎöºÍÏà¹Ø×ÊÁÏÏòvSphereÓû§Ìá³öÏÂÃ漸ÌõÕë¶ÔÐÔ·ÀÓù½¨Ò飺


½¨ÒéʹÓà TPM 2.0 оƬ½øÐÐvSphere½øÐÐÄþ¾²ÅäÖá£


ÔÚÎïÀí·þÎñÆ÷ÉÏÆôÓÃUEFIÄþ¾²Æô¶¯¹¦Ð§£¬Í¨¹ýÈ·±£ÔÚÒýµ¼ÖмÓÔصÄËùÓдúÂ붼¾­¹ýÊý×ÖÇ©ÃûÇÒδ±»¸Ä¶¯£¬´Ó¶ø¼ÓÇ¿²Ù×÷ϵͳµÄÄþ¾²ÐÔ¡£


½ûÖ¹ÔÚESX/ESXiÖ÷»úÉÏÖ´ÐÐ×Ô½ç˵´úÂ룬±£Ö¤ESX/ESXiÖ÷»ú¾Ü¾øÖ´ÐÐÈκÎδͨ¹ýÈÏÖ¤ºÏ×÷»ï°éÇ©ÃûµÄ VIB °ü°²×°µÄ´úÂë¡£


µ±vSphereƽ̨Ïà¹ØµÄ²úÎï´æÔÚÄþ¾²²¹¶¡Ðû²¼Ê±£¬»ý¼«¼ÓÈëϵͳ¼°Ïà¹ØµÄÐéÄ⻯ƽ̨×é¼þ£¨vCenter·þÎñÆ÷¡¢ESX/ESXiÖ÷»ú¡¢VMware¹¤¾ßµÈ£©µÄ¸üС£


¶ÔÐéÄâ»úƽ̨µÄ¹ÜÀíÕË»§Ê¹ÓøßÇ¿¶ÈÃÜÂë¡£


ÔÚÄÚ²¿ÍøÂçÖнøÐÐÍøÂçÇøÓò»®·Ö£¬½«¶ÔÍâ·þÎñµÄÖ÷»úºÍ½öÄÚ²¿·ÃÎʵÄÖ÷»ú½øÐÐÀ뿪¹ÜÀí£¬¶øÇÒΪÐéÄâƽ̨¹ÜÀíÔ±ÌṩרÓõÄvCenter·þÎñÆ÷ºÍESX/ESXi¹ÜÀí½Ó¿ÚÒÔ¼°×¨ÓõÄÊÂÇéÕ¾¡£


ÅäÖü¯ÖÐʽµÄ¼Ç¼ÈÕÖ¾£¬·ÀÖ¹¹ÜÀíϵͳÅäÖúͻ·¾³Ôâµ½¸Ä¶¯¡£


¾¡¿ÉÄܸßƵÂʵؽøÐÐϵͳ±¸·Ý£¬ÒÔ±ãÔÚÔâµ½ÀÕË÷¹¥»÷ºóÄܾ¡¿ìµØʵÏÖϵͳ»Ö¸´¡£