еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷

Ðû²¼Ê±¼ä 2024-08-27

1. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷


8ÔÂ25ÈÕ£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬£¬£¬ËüÓÉ×·Çó¾­¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬£¬£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃØ¹¥»÷¡£¡£¡£¡£×Ô2022ÄêÆð£¬£¬£¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬£¬£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£¡£¡£¡£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ£¬£¬£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬£¬£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£¡£¡£¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖ㬣¬£¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷£¬£¬£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬£¬£¬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬£¬£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¡£¡£¡£¸üΪ½ÆÕ©µÄÊÇ£¬£¬£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚЧÀÍÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬£¬£¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾­¼ÃÀûÒæµ¼Ïò¡£¡£¡£¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö£¬£¬£¬ÔÚÒÑÊӲ참ÀýÖУ¬£¬£¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ£¬£¬£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬£¬£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²ØÏµÍ³¡£¡£¡£¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍ⣬£¬£¬ÒÔ¾­¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖØ´ó»¯¡£¡£¡£¡£


https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html


2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992


8ÔÂ25ÈÕ£¬£¬£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992£¬£¬£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬£¬£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¡£¡£¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬£¬£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß£¬£¬£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£¡£¡£¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖÆµØ»á¼ûϵͳÄÚµÄí§ÒâÎļþ£¬£¬£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£¡£¡£¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬£¬£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ£¬£¬£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕæ£¬£¬£¬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¡£¡£¡£¼øÓÚpandasµÄÆÕ±éÓ¦Ó㬣¬£¬´ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬£¬£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾­ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£¡£¡£¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬£¬£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥£¬£¬£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas£¬£¬£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥£¬£¬£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£¡£¡£¡£


https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/


3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷£¬£¬£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý


8ÔÂ25ÈÕ£¬£¬£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer£¬£¬£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPNЧÀÍWarpVPNµÄÍøÂç´¹ÂÚÊֶΣ¬£¬£¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£¡£¡£¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆ­Óû§ÏÂÔØ²¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò£¬£¬£¬Ò»µ©µ½ÊÖ£¬£¬£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬£¬£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ£¬£¬£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»£»£»£»£»£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»£»£»£»£»£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø£¬£¬£¬ÆµµÀÄÚÆµÈÔÐû´«Ã°³äVPNЧÀÍ£¬£¬£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£¡£¡£¡£CRILµÄÑо¿Õ¹ÏÖ£¬£¬£¬¹¥»÷Õß³õÆÚÌṩÕýµ±Ð§ÀÍÒÔ»ýÀÛÐÅÈΣ¬£¬£¬ËæºóתÏò¶ñÒâ»î¶¯£¬£¬£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬£¬£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³£¬£¬£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£¡£¡£¡£


https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/


4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163


8ÔÂ25ÈÕ£¬£¬£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNCЧÀÍÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷£¬£¬£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£¡£¡£¡£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬£¬£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍЧÀÍÆ÷ÁìÓò£¬£¬£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸£¬£¬£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂ磬£¬£¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNCЧÀÍÆ÷µÄÔË×÷»úÖÆ£¬£¬£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ£¬£¬£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£¡£¡£¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇ󣬣¬£¬Ê¹CNCЧÀÍÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬£¬£¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£¡£¡£¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬£¬£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ£¬£¬£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£¡£¡£¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ£¬£¬£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNCЧÀÍÆ÷µÄ³¡¾°¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ëû»¹¹ûÕæÁËÎó²î´úÂ룬£¬£¬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£¡£¡£¡£


https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/


5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬£¬£¬µÁË¢³ÌÐòÇÔȡ֧¸¶Êý¾Ý


8ÔÂ25ÈÕ£¬£¬£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬£¬£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡£¡£¡£¡£¬£¬£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£Malwarebytesר¼ÒÖ¸³ö£¬£¬£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î£¬£¬£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾£¬£¬£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£¡£¡£¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬£¬£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£¡£¡£¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø£¬£¬£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬£¬£¬ÄÑÒÔ±»Óû§²ì¾õ¡£¡£¡£¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿ÍЧÀÍÆ÷£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬£¬£¬Í¨¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£¡£¡£¡£È»¶ø£¬£¬£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥£¬£¬£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£¡£¡£¡£±ðµÄ£¬£¬£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢£¬£¬£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£Òò´Ë£¬£¬£¬Óû§Èô·¢Ã÷Òì³££¬£¬£¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬£¬£¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£


https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/


6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬72.6Íò¿Í»§Êý¾Ýй¶


8ÔÂ26ÈÕ£¬£¬£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚЧÀÍ»ú¹¹£¬£¬£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶£¬£¬£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ£¬£¬£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬£¬£¬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â£¬£¬£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬£¬£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬£¬£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎΣ»£»£»£»£»£»ú£¬£¬£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬£¬£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»£»£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§À͵ÄÑ¡Ï£¬£¬×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£¡£¡£¡£Í¬Ê±£¬£¬£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøÎ»ÖÃÐû²¼ÖÒÑÔ£¬£¬£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©Æ­Î£º¦£¬£¬£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/