еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
Ðû²¼Ê±¼ä 2024-08-271. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
8ÔÂ25ÈÕ£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬£¬ËüÓÉ×·Çó¾¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃØ¹¥»÷¡£¡£¡£¡£¡£×Ô2022ÄêÆð£¬£¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£¡£¡£¡£¡£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ£¬£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£¡£¡£¡£¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖ㬣¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷£¬£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬£¬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¡£¡£¡£¡£¸üΪ½ÆÕ©µÄÊÇ£¬£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚЧÀÍÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬£¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾¼ÃÀûÒæµ¼Ïò¡£¡£¡£¡£¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö£¬£¬ÔÚÒÑÊӲ참ÀýÖУ¬£¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ£¬£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²ØÏµÍ³¡£¡£¡£¡£¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍ⣬£¬ÒÔ¾¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖØ´ó»¯¡£¡£¡£¡£¡£
https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html
2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992
8ÔÂ25ÈÕ£¬£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992£¬£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¡£¡£¡£¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß£¬£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£¡£¡£¡£¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖÆµØ»á¼ûϵͳÄÚµÄí§ÒâÎļþ£¬£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£¡£¡£¡£¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ£¬£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕæ£¬£¬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¡£¡£¡£¡£¼øÓÚpandasµÄÆÕ±éÓ¦Ó㬣¬´ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£¡£¡£¡£¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥£¬£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas£¬£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥£¬£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£¡£¡£¡£¡£
https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/
3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷£¬£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý
8ÔÂ25ÈÕ£¬£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer£¬£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPNЧÀÍWarpVPNµÄÍøÂç´¹ÂÚÊֶΣ¬£¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£¡£¡£¡£¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆÓû§ÏÂÔØ²¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò£¬£¬Ò»µ©µ½ÊÖ£¬£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ£¬£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»£»£»£»£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»£»£»£»£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø£¬£¬ÆµµÀÄÚÆµÈÔÐû´«Ã°³äVPNЧÀÍ£¬£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£¡£¡£¡£¡£CRILµÄÑо¿Õ¹ÏÖ£¬£¬¹¥»÷Õß³õÆÚÌṩÕýµ±Ð§ÀÍÒÔ»ýÀÛÐÅÈΣ¬£¬ËæºóתÏò¶ñÒâ»î¶¯£¬£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³£¬£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£¡£¡£¡£¡£
https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/
4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163
8ÔÂ25ÈÕ£¬£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNCЧÀÍÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷£¬£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£¡£¡£¡£¡£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍЧÀÍÆ÷ÁìÓò£¬£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸£¬£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂ磬£¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNCЧÀÍÆ÷µÄÔË×÷»úÖÆ£¬£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ£¬£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£¡£¡£¡£¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇ󣬣¬Ê¹CNCЧÀÍÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬£¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£¡£¡£¡£¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ£¬£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£¡£¡£¡£¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ£¬£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNCЧÀÍÆ÷µÄ³¡¾°¡£¡£¡£¡£¡£±ðµÄ£¬£¬Ëû»¹¹ûÕæÁËÎó²î´úÂ룬£¬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£¡£¡£¡£¡£
https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/
5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬£¬µÁË¢³ÌÐòÇÔȡ֧¸¶Êý¾Ý
8ÔÂ25ÈÕ£¬£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬£¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡£¬£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£Malwarebytesר¼ÒÖ¸³ö£¬£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î£¬£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾£¬£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£¡£¡£¡£¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£¡£¡£¡£¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø£¬£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬£¬ÄÑÒÔ±»Óû§²ì¾õ¡£¡£¡£¡£¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿ÍЧÀÍÆ÷£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬£¬Í¨¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£¡£¡£¡£¡£È»¶ø£¬£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥£¬£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£¡£¡£¡£¡£±ðµÄ£¬£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢£¬£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£¡£Òò´Ë£¬£¬Óû§Èô·¢Ã÷Òì³££¬£¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬£¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£
https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/
6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬72.6Íò¿Í»§Êý¾Ýй¶
8ÔÂ26ÈÕ£¬£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚЧÀÍ»ú¹¹£¬£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶£¬£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ£¬£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬£¬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â£¬£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎΣ»£»£»£»£»ú£¬£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§À͵ÄÑ¡Ï£¬×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøÎ»ÖÃÐû²¼ÖÒÑÔ£¬£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©ÆÎ£º¦£¬£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/


¾©¹«Íø°²±¸11010802024551ºÅ