еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æ¶¨°µ²ØÐÅÓþ¿¨µÁË¢Æ÷

°ä²¼¹¦·ò 2024-08-27

1. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æ¶¨°µ²ØÐÅÓþ¿¨µÁË¢Æ÷


8ÔÂ25ÈÕ  £¬ÍøÂ簲ȫ×êÑÐÈËÔ±·¢ÏÖÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ  £¬ËüÓÉ×·Çó¾­¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ  £¬Ñ¡È¡ÁËÒ»ÖÖ¹ÖÒìµÄÕ½ÊõÒÔʵÏÖ³Ö¾ÃÂñ·üºÍÒþÃØ¹¥»÷¡£×Ô2022ÄêÆð  £¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä  £¬Îª¹¥»÷ÕßÌṩÁË·´Ïòshellͨ·ºÍ׿ԽµÄÒñ±Î¼¿Á©¡£ÆäÖ÷ÌâÌØÉ«ÔÚÓÚÀûÓÃudev¹æ¶¨À´Î¬³ÔìäÔÚϵͳÄÚµÄÓÆ¾ÃÐÔ  £¬ÕâÊÇͨ¹ý¼à²âϵͳÖ÷Ìâ×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ  £¬Ã¿µ±ÏµÍ³³ÁÆôʱ¼´×Ô¶¯¼¤»î¶ñÒⷨʽ¡£sedexpͨ¹ýudevµÄ¸´ÔÓÅäÖà  £¬¿ÉÄÜÔÚ²»±»¾õ²ìµÄÇé¿öÏÂÖ´ÐжñÒâ²Ù×÷  £¬²¢ÆæÃîµØÅú¸ÄϵͳÄÚ´æ  £¬°µ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ  £¬ÓÐЧ¶ã±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄ¿úËÅ¡£¸üΪµó»¬µÄÊÇ  £¬ËüÒѱ»¹Û²ìµ½ÓÃÓÚÔÚ·þÎñÆ÷ÉÏÒþÃØ²¿ÊðÐÅÓþ¿¨Êý¾ÝÇÔÈ¡´úÂë  £¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾­¼ÃÀûÒæµ¼Ïò¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö  £¬ÔÚÒѵ÷²é°¸ÀýÖÐ  £¬sedexp²»½ö°µ²ØÁËWeb ShellºÍ½¨»Ú¸ÄµÄApacheÅäÖÃÎļþ  £¬»¹×ÔÐÐÅú¸ÄÁËudev¹æ¶¨  £¬ÐγÉÁËÒ»¸ö¹Ø»·µÄÒñ±Îϵͳ¡£ÕâÒ»·¢ÏÖ½ÒʾÁ˳ýÀÕË÷Èí¼þ±í  £¬ÒÔ¾­¼ÃΪÖ÷ÕŵÄÍøÂç¹¥»÷¼¿Á©ÕýÈÕÒæ¸´ÔÓ»¯¡£


https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html


2. Ê¢ÐÐPython¿âPandasÆØ°²È«·ì϶CVE-2024-42992


8ÔÂ25ÈÕ  £¬¿í·ºÊ¹ÓÃµÄ Python ¿âpandasÖз¢ÏÖÁËÒ»¸ö°²È«·ì϶CVE-2024-42992  £¬¸Ã·ì϶²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2  £¬ÆäCVSSÆÀ·Ö¸ß´ï7.5  £¬Í¹ÏÔÁËÓû§Ãæ¶ÔµÄ³Á´ó·çÏÕ¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î  £¬³ÉΪÊý¾Ý´¦ÖÃÓë·ÖÎöµÄÖ÷Ì⹤¾ß  £¬ÕâÒ»·¢ÏÖÓÈΪÁîÈËÓÇÓô¡£´Ë·ì϶ΪËÁÒâÎļþ¶ÁÈ¡·ì϶  £¬ÄÜÈù¥»÷ÕßÎÞÏ޶ȵؽӼûϵͳÄÚµÄËÁÒâÎļþ  £¬Ô̺¬Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£Æä±¾Ô­ÔÚÓÚpandasÔÚ´¦ÖÃÎļþõè¾¶ÊäÈëʱ²»×ã±ØÒªµÄÏÞ¶È  £¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨ËÁÒâõè¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¸Ã·ì϶ÔÚ¶à¸öÔÚÏß»·¾³ÖÐÒ×ÓÚ¸´ÏÖ  £¬ÇÒÆä¸ÅÏëÑéÖ¤´úÂëÒÑÔÚGitHubÉϹ«¿ª  £¬ÏÔÖøÔö³¤Á˱»¶ñÒâÀûÓõķçÏÕ¡£¼øÓÚpandasµÄ¿í·ºÀûÓà  £¬´Ë·ì϶¶Ôϵͳ»úÃÜÐÔºÍÆëÈ«ÐÔ×é³ÉÁËÑϳÁÍþв  £¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾­ÊÚȨ½Ó¼ûµÄ·çÏÕÖèÔö¡£Ãæ¶ÔÉÐÎÞ¹Ù·½²¹¶¡µÄ½ü¿ö  £¬Óû§ÐèÁ¢¼´²ÉȡԤ·À´ëÊ©  £¬ÈçÏÞ¶ÈÔÚÃô¸Ð»·¾³ÖÐʹÓÃpandas  £¬²¢¼Óǿϵͳ¼à¿ØÓ밲ȫ´ëÊ©  £¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£


https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/


3. Cheana StealerÌáÒé¿çƽ̨VPN´¹µö¹¥»÷  £¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý


8ÔÂ25ÈÕ  £¬Cyble ×êÑÐÓëµý±¨³¢ÊÔÊÒ ( CRIL ) ·¢ÏÖµÄ×îÐÂÍþвCheana Stealer  £¬¸Ã¶ñÒ⹤¾ßͨ¹ý¼Ù×°³É³ÛÃûVPN·þÎñWarpVPNµÄÍøÂç´¹µö¼¿Á©  £¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£Cheana StealerÀûÓþ«ÐÄÉè¼ÆµÄ´¹µöÍøÕ¾ÓÕÆ­Óû§ÏÂÔØ²¢×°ÖüÙ×°³ÉºÏ·¨VPNÈí¼þµÄÇÔÈ¡·¨Ê½  £¬Ò»µ©µÃÊÖ  £¬±ãÇÄÎÞÉùÏ¢µØÍøÂçÔ̺¬ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£Õë¶Ô·ÖÆç²Ù×÷ϵͳ  £¬Cheana Stealerѡȡ·ÖÆçµÄ¼¼Êõ¼¿Á©£ºÔÚWindowsÉÏ  £¬ËüÀûÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»Linux°æÔòͨ¹ý¼Ù×°Cloudflare Warp VPNµÄshell¾ç±¾Ö´Ðй¥»÷£»macOSÉÏÔòÀûÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£ÖµÍ×ÌùÐĵÄÊÇ  £¬¸ÃÇÔÈ¡·¨Ê½µÄ´«²¼ÓëÒ»¸öÓµº±¼ûÍò¶©ÔÄÕßµÄTelegramƵ·çÇÃÜÓйØ  £¬ÆµÂ·ÄÚÆµÈÔÐû´«¼ÙðVPN·þÎñ  £¬¼«´óÖú³¤Á˹¥»÷ÁìÓò¡£CRILµÄ×êÑнÒʾ  £¬¹¥»÷Õß³õÆÚÌṩºÏ·¨·þÎñÒԶѼ¯ÐÅÀµ  £¬ËæºóתÏò¶ñÒâ»î¶¯  £¬Í¨¹ýTelegramµÈŵÑÔÆ½Ì¨¼°¸ß¶È·ÂÕæµÄ´¹µöÍøÕ¾  £¬³É¹¦ÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´óÁ¿Óû§ÏµÍ³  £¬Í¹ÏÔÁ˵±Ç°ÍøÂ簲ȫÌôÕ½µÄÑϸñÐÔ¡£


https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/


4. Mirai½©Ê¬ÍøÂçÖз¢ÏÖÑϳÁ·ì϶CVE-2024-45163


8ÔÂ25ÈÕ  £¬°²È«×êÑÐÔ±Jacob Masse½ÒʾÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑϳÁ·ì϶CVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©  £¬¸Ã·ì϶ÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNC·þÎñÆ÷½øÐÐÔ¶³ÌDoS¹¥»÷  £¬ÑϳÁÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£Mirai×÷ΪһÖÖ³ôÃûÔ¶ÑïµÄ¶ñÒâÈí¼þ  £¬×Ô2016ÄêÆð±ãÇÖÈÅÎïÁªÍøºÍ·þÎñÆ÷ÁìÓò  £¬Í¨¹ýÀûÓÃÈõÃÜÂëµÈ·ì϶½ÚÔì´óÁ¿É豸  £¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂç  £¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£Jacob Masseͨ¹ýÉî¿Ì×êÑÐCNC·þÎñÆ÷µÄÔË×÷»úÔì  £¬·¢ÏÖÁËÆäÔÚ´¦Öò¢·¢ÏνÓÒªÇóʱµÄȱµã  £¬³ö¸ñÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£ÕâÒ»·ì϶ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´óÁ¿µ¥Ò»µÄÉí·ÝÑéÖ¤ÒªÇó  £¬Ê¹CNC·þÎñÆ÷×ÊÔ´ºÄ¾¡²¢±ÀÀ£  £¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£CVE-2024-45163µÄÅû¶²»½öΪ·¨ÂÉ»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß  £¬Ò²Òý·¢Á˹ØÓÚ·µÂʹÓõĻáÉÌ  £¬ÓÉÓÚÀûÓô˷ì϶¿ÉÄÜÒâ±íÖжϺϷ¨²âÊÔÖеĽ©Ê¬ÍøÂç¡£Masseͨ¹ýPoCÑÝʾÁË·ì϶µÄÓÐЧÐÔ  £¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿É³É¹¦¹Ø¹ØCNC·þÎñÆ÷µÄ³¡¾°¡£´Ë±í  £¬Ëû»¹¹«¿ªÁË·ì϶´úÂë  £¬ÍƽøÁËÍøÂ簲ȫÉçÇøµÄ×êÑÐÓë·ÀÓù¹¤×÷¡£


https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/


5. Magentoƽ̨ÔâÍøÂç¹¥»÷  £¬µÁË¢·¨Ê½ÇÔȡ֧¸¶Êý¾Ý


8ÔÂ25ÈÕ  £¬¶à¶àѡȡMagentoƽ̨µÄÔÚÏßÉ̵ê½üÆÚÔâ·êÁËÑϳÁÍøÂç¹¥»÷  £¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂë  £¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»·¸·¨ÇÔÈ¡  £¬Ô̺¬¿¨ºÅ¡¢ÓÐЧÆÚ¼°°²È«ÂëµÈ³ÁÒªÐÅÏ¢¡£Malwarebytesר¼ÒÖ¸³ö  £¬ºÚ¿ÍÀûÓÃMagentoϵͳ·ì϶  £¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾  £¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£Êý°Ù¼ÒµêÆÌÒÑÈ·ÈÏÊÜÇÖ  £¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒñ±Î  £¬¿ÉÄÜÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì  £¬ÄÑÒÔ±»Óû§¾õ²ì¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿Í·þÎñÆ÷  £¬ÉõÖÁÔÚijЩÇé¿öÏ  £¬¿ÉÄÜÈÆ¹ýµÚÈý·½Ö§¸¶´¦ÖÃÁ÷³ÌÖ±½ÓÀ¹½ØÊý¾Ý¡£ÐÒÔ˵ÄÊÇ  £¬°²È«×¨¼ÒÒÑÀ¹½Ø³¬¹ý1,100´ÎÊý¾ÝÇÔÈ¡³¢ÊÔ  £¬Í¨¹ý¼ø±ð²¢¹Ø±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐЧ¶ôÔìÁ˲¿ÃŹ¥»÷¡£È»¶ø  £¬ÊÜÓ°ÏìµÄµêÆÌËäÒѲÉȡɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ´ëÊ©  £¬µ«²¿ÃÅÍøÕ¾ÈÔÃæ¶Ô³ÖÐøÍþв¡£´Ë±í  £¬Êý¾Ýй¶²»½öÏÞÓÚ²ÆÕþÐÅÏ¢  £¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈÓ×ÎÒÒþÖÔ¡£Òò¶ø  £¬Óû§Èô·¢ÏÖÒì³£  £¬Ó¦Á¢¼´ÁªÏµÒøÐиü»»¿¨Æ¬  £¬²¢Ë¼¿¼ÆôÓÃÉí·Ý±£»¤·þÎñ¡£


https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/


6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷  £¬72.6Íò¿Í»§Êý¾Ýй¶


8ÔÂ26ÈÕ  £¬PatelcoÐÅÓþºÏ×÷ÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇͶ»úÐÔ½ðÈÚ·þÎñ»ú¹¹  £¬½üÆÚÔâ·êÑϳÁÊý¾Ýй¶ÊÂÎñ¡£½ñÄêÔçЩʱ³½  £¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷  £¬Ö»¹ÜÆäʱδÁ¢¼´È·ÈÏÊý¾Ýй¶  £¬µ«Ëæºóµ÷²é½Òʾ  £¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂç  £¬²¢ÓÚ6ÔÂ29ÈÕ½Ó¼ûÊý¾Ý¿â  £¬ÇÔÈ¡ÁË´óÁ¿¿Í»§Ó×ÎÒÐÅÏ¢¡£ÕâЩÃô¸ÐÐÅÏ¢Ô̺¬ÐÕÃû¡¢Éç»á°²È«ºÅÂë¡¢¼ÝÊ»ÅÆÕÕºÅÂë¡¢µ®ÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ  £¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾Éϰ䲼µÄÊý¾ÝÒ»Ö  £¬¸ÃÍÅ»ïÐû³ÆÔÚ½»ÉæÎ´¹ûºó¹«¿ªÁËÊý¾Ý¡£Õâ´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£ÎªÓ¦¶ÔÕâ´ÎΣ»ú  £¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ  £¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»¤ºÍÐÅÓþ¼à¿Ø·þÎñµÄÑ¡Ïî  £¬½ØÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£Í¬Ê±  £¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøµØÎ»°ä²¼ÖÒ¸æ  £¬ÌáÐÑ»áÔ±¾¯ÌèÍøÂç´¹µö¡¢Éç»á¹¤³Ì¼°Ú¿Æ­·çÏÕ  £¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/