»úеÈ˼¼Êõ°²È«ÐÔ¸ÅÀÀ»ã±¨£»Linux sudoȨÏÞÈÆ¹ý·ì϶£»ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×Ù·ÖÎö

°ä²¼¹¦·ò 2019-10-15
1¡¢Linux sudoȨÏÞÈÆ¹ý·ì϶£¬Äܹ»rootȨÏÞÖ´ÐкÅÁî

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Linux sudoÆØ³öÌáȨ·ì϶£¬¿ÉÈÆ¹ýRunasÓû§ÏÞ¶ÈÒÔrootȨÏÞÖ´ÐкÅÁî¡£¸Ã·ì϶£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢°²È«ÊýÃŵÄJoe Vennix·¢ÏÖ£¬ÈôÊǽ«sudoÅäÖÃΪÔÊÐíÓû§ÒÔËÁÒâÓû§Éí·ÝÔËÐкÅÁÔòÄܹ»Í¨¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½Ê½ÒÔrootÉí·ÝÔËÐкÅÁî¡£ÕâÊÇÓÉÓÚ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÒÔΪ0£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£´Ë±í£¬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬Òò¶ø²»»áÔËÐÐÈκÎPAM»á»°Ä£¿é¡£¸Ã·ì϶ӰÏì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.sudo.ws/alerts/minus_1_uid.html

2¡¢¿¨°Í˹»ù°ä²¼¡¶»úеÈ˼¼Êõ°²È«ÐÔ¸ÅÀÀ¡·»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù×êÑÐÍŶӰ䲼µ±Ç°»úеÈ˼¼ÊõµÄ°²È«ÐÔ¸ÅÀÀ»ã±¨£¬ÕâЩ»úеÈ˺­¸Ç¸÷ÀàÉ豸£¬ÀýÈ繤³§ÖеĻúе±Û»òËÍ»õ»úеÈË¡¢×Ô¶¯¼ÝÊ»Æû³µ¡¢±£Ä·»úеÈ˵È¡£ÍøÂç¹¥»÷ÔÚÍþв»úеÈ˲Ù×÷ϵͳ£¨ROS£©µÄÆëÈ«ÐÔ£¬»úеÈËÄܹ»Ê¹Óô«¸ÐÆ÷¸Ð²âÎïÀíÊÀ½ç£¬Ò²Äܹ»Í¨¹ýÆäÖ´ÐÐÆ÷Ö±½ÓŤתÎïÀíÊÀ½ç£¬Òò¶øÈôÊÇÔâδÊÚȨ½Ó¼û£¬»úеÈË¿ÉÄÜ»áй©ÓÐ¹ØÆä»·¾³µÄÃô¸ÐÐÅÏ¢£¬ÀýÈç´«¸ÐÆ÷»òÉãÏñ»úÊý¾Ý£¬ÉõÖÁ½Óµ½Òƶ¯ºÅÁîµÈ£¬Õ⽫´øÀ´ÒþÖԺͰ²È«·çÏÕ¡£ÔÚ2018Ä꣬¶ÔInternet IPv4µØÖ·¿Õ¼äµÄ·ÖÎöÒѾ­¼ø±ð³ö100¶à¸ö¿É¹«¿ª½Ó¼ûµÄÔËÐÐROSÖ÷½ÚµãµÄÖ÷»ú£¬ËüÃÇ¿ÉÄÜ»áÔ⵽δÊÚȨµÄºÅÁî×¢Èë¡¢Êý¾Ý½Ó¼û»ò»Ø¾ø·þÎñµÈ¹¥»÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/robots-social-impact/94431/

3¡¢ESET°ä²¼·¸×ïÍÅ»ïWinnti GroupжñÒâ»î¶¯µÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ESET×êÑÐÍŶӰ䲼һ·Ý¹ØÓÚ·¸×ïÍÅ»ïWinnti GroupµÄ¶ñÒ⹤¾ß¼°»î¶¯¸üÐÂµÄ°×Æ¤Êé¡£Winnti GroupÒÑÓнüÊ®ÄêµÄº¹Ç࣬ËüÖØÒªÕë¶ÔÓÎÏ·ÐÐÒµ£¬ÆäÊ×Ñ¡¹¥»÷·½Ê½ÊÇͨ¹ýÉøÈëÓÎÏ·¿ª·¢ÈËÔ±½«ºóÃÅÖ²ÈëÓÎÏ·µÄ¹¹½¨»·¾³£¬¶øºó·Ö·¢¶ñÒâÈí¼þ¡£ÑÇÖÞÓÎÏ·Íæ¼ÒÊÇÆä×î½üÒ»´Î¹©¸øÁ´¹¥»÷µÄÖ¸±ê£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ¹À¼Æ£¬ÊÜÓ°ÏìµÄÈËÊý¿É´ïÊýǧÈË£¬³¬¹ýÒ»°ëµÄÊܺ¦Õߣ¨55%£©Î»ÓÚÌ©¹ú¡£Winnti GroupʹÓôò°üµÄºóÃÅPortReuse£¬ESETÖÒ¸æÑÇÖÞµÄÒ»¼ÒÖØÒªÒÆ¶¯Èí¼þºÍÓ²¼þÔì×÷ÉÌÊܵ½PortReuseµÄϰȾ¡£ESET»¹·ÖÎöÁËWinnti GroupʹÓõÄÁíÒ»¸öºóÃÅShadownpadµÄбäÌå¡£Ö»¹ÜWinntiÖØÒªÒÔ¼äµý»î¶¯¶øÎÅÃû£¬µ«×êÑÐÈËÔ±·¢ÏÖ¸Ã×éÖ¯»¹Ê¹Óý©Ê¬ÍøÂçÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/

4¡¢McAfee°ä²¼ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×Ù·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


McAfeeÔÚÒ»·Ýл㱨ÖÐ×·×ÙÁËSodinokibi RaaSµÄ×ʽð»î¶¯¡£Ò»¸öÃûΪLalartuµÄ»áÔ±ÔÚÂÛ̳Ìû×ÓÖа䲼Á˲¿ÃÅÂòÂôIDµÄÆÁÄ»½ØÍ¼£¬ÏÔʾÔÚ72Ó×ʱÄÚÔ¼ÓÐ28.75ÍòÃÀÔªÊê½ðÖ§¸¶¡£Í¨¹ý²é¿´ÀÕË÷Èí¼þµÄÏÖÓÐÑù±¾£¬McAfee¿ÉÄÜÈ·¶¨¾ùÔÈÊê½ðÔÚ0.44ÖÁ0.45±ÈÌØ±ÒÖ®¼ä£¬Ô¼Îª4000ÃÀÔª¡£ÔÚÇø¿éÁ´Êý¾Ý·ÖÎö¹«Ë¾ChainalysisµÄÔ®ÊÖÏ£¬McAfee¼ìË÷µ½ÁËÆëÈ«µÄÂòÂôID£¬²¢Ê¹ÓÃËüÃÇÀ´Ó³ÉäÓйصıÈÌØ±ÒÂòÂô¡£Æ¾¾ÝÍøÂçµ½µÄÐÅÏ¢£¬McAfee¿ÉÄܲ鿴ÆäËû»áÔ±Êê½ðÖ§¸¶µÄÇé¿ö£¬ÒÔ¼°»áÔ±ºÍÔËÓªÉÌÖ®¼äµÄÊÕÈë·ÖÅäΪ60/40»ò70/30¡£ÆäËû»áÔ±»¹Ê¹ÓñÈÌØ±ÒÔÚµØÏÂÊг¡Éϲɰì·þÎñ£¬ÕâЩµØÏÂÊг¡½ÓÊܶ¾Æ·¡¢±øÆ÷ºÍºÚ¿Í·þÎñµÈ·¸·¨ÎïÆ·µÄ±ÈÌØ±ÒÂòÂô¡£McAfee¿ÉÄÜ×·×Ùµ½µÄÒ»¸ö½Ï´óµÄ¹ØÁª·½Ç®°üÀïÓÐ443±ÈÌØ±Ò£¬Ô¼Îª450ÍòÃÀÔª¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-following-the-affiliate-money-trail/

5¡¢Silent LibrarianÀûÓô¹µö¹¥»÷¶Ô×¼±±ÃÀ¼°Å·ÖÞ´óѧ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÁÀÊ·¸×ïÍÅ»ïSilent LibrarianÔÚ²»ÐݸüÐÂÆäÕ½ÊõºÍ¼¼Êõ£¬ÒÔͨ¹ý´¹µö¹¥»÷¶Ô×¼ÃÀ¹úºÍÅ·Ö޵Ĵóѧ¡£´Ó6Ôµ½10Ô£¬¸ÃÍÅ»ïµÄÍøÂç´¹µö»î¶¯Ô½·¢ÆµÈÔ£¬Æä´¹µöÖ÷Ìâ¸ù»ùά³Ö²»±ä£¬×î³£¼ûµÄÊÇÎÞ·¨½Ó¼ûͼÊé¹Ý×ÊÔ´£¬ÀýÈçÕË»§¹ýÆÚµÈ¡£×êÑÐÈËÔ±ÒÔΪ¸ÃÍÅ»ïÓëÒÁÀʵ±¾Ö´æÔÚ¹ØÁª£¬ÆäÖ÷ÕÅÊÇ´ÓÈ«Çò´óѧÇÔȡ֪ʶ²úȨ¡£Ö»¹ÜÈ¥ÄêÃÀ¹ú˾·¨²¿Îª´Ë¹¥»÷»î¶¯Ö¸¿ØÁË9ÃûºÚ¿Í£¬µ«¸Ã¹¥»÷»î¶¯ÈÔÔÚ½øÐÐÖС£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iranian-hackers-create-credible-phishing-to-steal-library-access/

6¡¢ÃÀ¹ú·Ñ³ÇÎÀÉúÊð¹ÙÍøÒⱩ¶³öÊýǧÃû¸ÎÑ×»¼ÕßÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú·Ñ³ÇÎÀÉúÊðµÄÒ»¸ö¹«¹²Êý¾Ý¹¤¾ßÒâ±íй¶ÁËÊýǧÃû¸ÎÑ×»¼ÕßµÄÒþÖÔÐÅÏ¢¡£ÉÏÖÜÎåÒ»Ãû¼ÇÕß·¢ÏÖÁËÕâÒ»ÊÂÎñ²¢Í¨ÖªÁ˸ò¿ÃÅ¡£¸Ã²¿ÃÅÔÚ¼¸·ÖÖÓºóɾ³ýÁ˶³öµÄÊý¾Ý£¬Ä¿Ç°Éв»Ã÷ÏÔÕâЩÐÅϢ¶³öÁ˶೤¹¦·ò¡£¸ÃÊеÄÒ»Ãû½²»°È˰µÊ¾ÈÔÔÚ¶ÔÊÂÎñµÄÁìÓò½øÐе÷²é£¬²¢ÇÒÔÚ½øÒ»²½Ïàʶ֮ǰ²»°ä·¢ÆÀÂÛ¡£Æ¾¾Ý¼ÇÕߵķ¢ÏÖ£¬¸Ã¶³öµÄÊý¾ÝÔ̺¬2.3Íò±ûÐ͸ÎÑײ¡ÀýµÄÓ×ÎҼͼ£¬ÐÅÏ¢Ô̺¬Ã¿Î»»¼ÕßµÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ£¬µØÖ·ºÍÕï¶ÏÁ˾Ö£¬ÔÚijЩÇé¿öÏ£¬»¹Ô̺¬Éç»á°²È«ºÅÂë¼°Ò½ÎñÈËÔ±µÄ¼Í¼¡£Êý¾ÝËÆºõº­¸ÇÁË2013Äêµ½2018Äêµ×µÄÐÂÕï¶ÏÁ˾Ö¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.inquirer.com/news/philadelphia-health-department-data-breach-opioids-tableau-hepatitis-20191011.html