»úеÈ˼¼Êõ°²È«ÐÔ¸ÅÀÀ»ã±¨£»Linux sudoȨÏÞÈÆ¹ý·ì϶£»ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×Ù·ÖÎö
°ä²¼¹¦·ò 2019-10-15
Linux sudoÆØ³öÌáȨ·ì϶£¬¿ÉÈÆ¹ýRunasÓû§ÏÞ¶ÈÒÔrootȨÏÞÖ´ÐкÅÁî¡£¸Ã·ì϶£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢°²È«ÊýÃŵÄJoe Vennix·¢ÏÖ£¬ÈôÊǽ«sudoÅäÖÃΪÔÊÐíÓû§ÒÔËÁÒâÓû§Éí·ÝÔËÐкÅÁÔòÄܹ»Í¨¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½Ê½ÒÔrootÉí·ÝÔËÐкÅÁî¡£ÕâÊÇÓÉÓÚ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÒÔΪ0£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£´Ë±í£¬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»´æÔÚ£¬Òò¶ø²»»áÔËÐÐÈκÎPAM»á»°Ä£¿é¡£¸Ã·ì϶ӰÏì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£
ÔÎÄÁ´½Ó£º
https://www.sudo.ws/alerts/minus_1_uid.html2¡¢¿¨°Í˹»ù°ä²¼¡¶»úеÈ˼¼Êõ°²È«ÐÔ¸ÅÀÀ¡·»ã±¨
ÔÎÄÁ´½Ó£º
https://securelist.com/robots-social-impact/94431/3¡¢ESET°ä²¼·¸×ïÍÅ»ïWinnti GroupжñÒâ»î¶¯µÄ·ÖÎö»ã±¨
ESET×êÑÐÍŶӰ䲼һ·Ý¹ØÓÚ·¸×ïÍÅ»ïWinnti GroupµÄ¶ñÒ⹤¾ß¼°»î¶¯¸üÐÂµÄ°×Æ¤Êé¡£Winnti GroupÒÑÓнüÊ®ÄêµÄº¹Ç࣬ËüÖØÒªÕë¶ÔÓÎÏ·ÐÐÒµ£¬ÆäÊ×Ñ¡¹¥»÷·½Ê½ÊÇͨ¹ýÉøÈëÓÎÏ·¿ª·¢ÈËÔ±½«ºóÃÅÖ²ÈëÓÎÏ·µÄ¹¹½¨»·¾³£¬¶øºó·Ö·¢¶ñÒâÈí¼þ¡£ÑÇÖÞÓÎÏ·Íæ¼ÒÊÇÆä×î½üÒ»´Î¹©¸øÁ´¹¥»÷µÄÖ¸±ê£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ¹À¼Æ£¬ÊÜÓ°ÏìµÄÈËÊý¿É´ïÊýǧÈË£¬³¬¹ýÒ»°ëµÄÊܺ¦Õߣ¨55%£©Î»ÓÚÌ©¹ú¡£Winnti GroupʹÓôò°üµÄºóÃÅPortReuse£¬ESETÖÒ¸æÑÇÖÞµÄÒ»¼ÒÖØÒªÒÆ¶¯Èí¼þºÍÓ²¼þÔì×÷ÉÌÊܵ½PortReuseµÄϰȾ¡£ESET»¹·ÖÎöÁËWinnti GroupʹÓõÄÁíÒ»¸öºóÃÅShadownpadµÄбäÌå¡£Ö»¹ÜWinntiÖØÒªÒÔ¼äµý»î¶¯¶øÎÅÃû£¬µ«×êÑÐÈËÔ±·¢ÏÖ¸Ã×éÖ¯»¹Ê¹Óý©Ê¬ÍøÂçÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/4¡¢McAfee°ä²¼ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×Ù·ÖÎö»ã±¨
McAfeeÔÚÒ»·Ýл㱨ÖÐ×·×ÙÁËSodinokibi RaaSµÄ×ʽð»î¶¯¡£Ò»¸öÃûΪLalartuµÄ»áÔ±ÔÚÂÛ̳Ìû×ÓÖа䲼Á˲¿ÃÅÂòÂôIDµÄÆÁÄ»½ØÍ¼£¬ÏÔʾÔÚ72Ó×ʱÄÚÔ¼ÓÐ28.75ÍòÃÀÔªÊê½ðÖ§¸¶¡£Í¨¹ý²é¿´ÀÕË÷Èí¼þµÄÏÖÓÐÑù±¾£¬McAfee¿ÉÄÜÈ·¶¨¾ùÔÈÊê½ðÔÚ0.44ÖÁ0.45±ÈÌØ±ÒÖ®¼ä£¬Ô¼Îª4000ÃÀÔª¡£ÔÚÇø¿éÁ´Êý¾Ý·ÖÎö¹«Ë¾ChainalysisµÄÔ®ÊÖÏ£¬McAfee¼ìË÷µ½ÁËÆëÈ«µÄÂòÂôID£¬²¢Ê¹ÓÃËüÃÇÀ´Ó³ÉäÓйصıÈÌØ±ÒÂòÂô¡£Æ¾¾ÝÍøÂçµ½µÄÐÅÏ¢£¬McAfee¿ÉÄܲ鿴ÆäËû»áÔ±Êê½ðÖ§¸¶µÄÇé¿ö£¬ÒÔ¼°»áÔ±ºÍÔËÓªÉÌÖ®¼äµÄÊÕÈë·ÖÅäΪ60/40»ò70/30¡£ÆäËû»áÔ±»¹Ê¹ÓñÈÌØ±ÒÔÚµØÏÂÊг¡Éϲɰì·þÎñ£¬ÕâЩµØÏÂÊг¡½ÓÊܶ¾Æ·¡¢±øÆ÷ºÍºÚ¿Í·þÎñµÈ·¸·¨ÎïÆ·µÄ±ÈÌØ±ÒÂòÂô¡£McAfee¿ÉÄÜ×·×Ùµ½µÄÒ»¸ö½Ï´óµÄ¹ØÁª·½Ç®°üÀïÓÐ443±ÈÌØ±Ò£¬Ô¼Îª450ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-following-the-affiliate-money-trail/
5¡¢Silent LibrarianÀûÓô¹µö¹¥»÷¶Ô×¼±±ÃÀ¼°Å·ÖÞ´óѧ
ÒÁÀÊ·¸×ïÍÅ»ïSilent LibrarianÔÚ²»ÐݸüÐÂÆäÕ½ÊõºÍ¼¼Êõ£¬ÒÔͨ¹ý´¹µö¹¥»÷¶Ô×¼ÃÀ¹úºÍÅ·Ö޵Ĵóѧ¡£´Ó6Ôµ½10Ô£¬¸ÃÍÅ»ïµÄÍøÂç´¹µö»î¶¯Ô½·¢ÆµÈÔ£¬Æä´¹µöÖ÷Ìâ¸ù»ùά³Ö²»±ä£¬×î³£¼ûµÄÊÇÎÞ·¨½Ó¼ûͼÊé¹Ý×ÊÔ´£¬ÀýÈçÕË»§¹ýÆÚµÈ¡£×êÑÐÈËÔ±ÒÔΪ¸ÃÍÅ»ïÓëÒÁÀʵ±¾Ö´æÔÚ¹ØÁª£¬ÆäÖ÷ÕÅÊÇ´ÓÈ«Çò´óѧÇÔȡ֪ʶ²úȨ¡£Ö»¹ÜÈ¥ÄêÃÀ¹ú˾·¨²¿Îª´Ë¹¥»÷»î¶¯Ö¸¿ØÁË9ÃûºÚ¿Í£¬µ«¸Ã¹¥»÷»î¶¯ÈÔÔÚ½øÐÐÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iranian-hackers-create-credible-phishing-to-steal-library-access/
6¡¢ÃÀ¹ú·Ñ³ÇÎÀÉúÊð¹ÙÍøÒⱩ¶³öÊýǧÃû¸ÎÑ×»¼ÕßÐÅÏ¢
ÃÀ¹ú·Ñ³ÇÎÀÉúÊðµÄÒ»¸ö¹«¹²Êý¾Ý¹¤¾ßÒâ±íй¶ÁËÊýǧÃû¸ÎÑ×»¼ÕßµÄÒþÖÔÐÅÏ¢¡£ÉÏÖÜÎåÒ»Ãû¼ÇÕß·¢ÏÖÁËÕâÒ»ÊÂÎñ²¢Í¨ÖªÁ˸ò¿ÃÅ¡£¸Ã²¿ÃÅÔÚ¼¸·ÖÖÓºóɾ³ýÁ˶³öµÄÊý¾Ý£¬Ä¿Ç°Éв»Ã÷ÏÔÕâЩÐÅϢ¶³öÁ˶೤¹¦·ò¡£¸ÃÊеÄÒ»Ãû½²»°È˰µÊ¾ÈÔÔÚ¶ÔÊÂÎñµÄÁìÓò½øÐе÷²é£¬²¢ÇÒÔÚ½øÒ»²½Ïàʶ֮ǰ²»°ä·¢ÆÀÂÛ¡£Æ¾¾Ý¼ÇÕߵķ¢ÏÖ£¬¸Ã¶³öµÄÊý¾ÝÔ̺¬2.3Íò±ûÐ͸ÎÑײ¡ÀýµÄÓ×ÎҼͼ£¬ÐÅÏ¢Ô̺¬Ã¿Î»»¼ÕßµÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚ£¬µØÖ·ºÍÕï¶ÏÁ˾֣¬ÔÚijЩÇé¿öÏ£¬»¹Ô̺¬Éç»á°²È«ºÅÂë¼°Ò½ÎñÈËÔ±µÄ¼Í¼¡£Êý¾ÝËÆºõº¸ÇÁË2013Äêµ½2018Äêµ×µÄÐÂÕï¶ÏÁ˾֡£
ÔÎÄÁ´½Ó£º
https://www.inquirer.com/news/philadelphia-health-department-data-breach-opioids-tableau-hepatitis-20191011.html


¾©¹«Íø°²±¸11010802024551ºÅ