еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷

Ðû²¼Ê±¼ä 2024-08-27

1. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷


8ÔÂ25ÈÕ £¬£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ £¬£¬£¬£¬£¬ËüÓÉ×·Çó¾­¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ £¬£¬£¬£¬£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃØ¹¥»÷¡£¡£¡£¡£×Ô2022ÄêÆð £¬£¬£¬£¬£¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä £¬£¬£¬£¬£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£¡£¡£¡£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ £¬£¬£¬£¬£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ £¬£¬£¬£¬£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£¡£¡£¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖà £¬£¬£¬£¬£¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷ £¬£¬£¬£¬£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄÚ´æ £¬£¬£¬£¬£¬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ £¬£¬£¬£¬£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¡£¡£¡£¸üΪ½ÆÕ©µÄÊÇ £¬£¬£¬£¬£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚЧÀÍÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂë £¬£¬£¬£¬£¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾­¼ÃÀûÒæµ¼Ïò¡£¡£¡£¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö £¬£¬£¬£¬£¬ÔÚÒÑÊӲ참ÀýÖÐ £¬£¬£¬£¬£¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ £¬£¬£¬£¬£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò £¬£¬£¬£¬£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²ØÏµÍ³¡£¡£¡£¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍâ £¬£¬£¬£¬£¬ÒÔ¾­¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖØ´ó»¯¡£¡£¡£¡£


https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html


2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992


8ÔÂ25ÈÕ £¬£¬£¬£¬£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992 £¬£¬£¬£¬£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2 £¬£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5 £¬£¬£¬£¬£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¡£¡£¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î £¬£¬£¬£¬£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß £¬£¬£¬£¬£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£¡£¡£¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î £¬£¬£¬£¬£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖÆµØ»á¼ûϵͳÄÚµÄí§ÒâÎļþ £¬£¬£¬£¬£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£¡£¡£¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ £¬£¬£¬£¬£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ £¬£¬£¬£¬£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕæ £¬£¬£¬£¬£¬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¡£¡£¡£¼øÓÚpandasµÄÆÕ±éÓ¦Óà £¬£¬£¬£¬£¬´ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв £¬£¬£¬£¬£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾­ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£¡£¡£¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´ £¬£¬£¬£¬£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥ £¬£¬£¬£¬£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas £¬£¬£¬£¬£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥ £¬£¬£¬£¬£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£¡£¡£¡£


https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/


3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷ £¬£¬£¬£¬£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý


8ÔÂ25ÈÕ £¬£¬£¬£¬£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer £¬£¬£¬£¬£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPNЧÀÍWarpVPNµÄÍøÂç´¹ÂÚÊÖ¶Î £¬£¬£¬£¬£¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£¡£¡£¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆ­Óû§ÏÂÔØ²¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò £¬£¬£¬£¬£¬Ò»µ©µ½ÊÖ £¬£¬£¬£¬£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ £¬£¬£¬£¬£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ £¬£¬£¬£¬£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»£»£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»£»£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ £¬£¬£¬£¬£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø £¬£¬£¬£¬£¬ÆµµÀÄÚÆµÈÔÐû´«Ã°³äVPNЧÀÍ £¬£¬£¬£¬£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£¡£¡£¡£CRILµÄÑо¿Õ¹ÏÖ £¬£¬£¬£¬£¬¹¥»÷Õß³õÆÚÌṩÕýµ±Ð§ÀÍÒÔ»ýÀÛÐÅÈÎ £¬£¬£¬£¬£¬ËæºóתÏò¶ñÒâ»î¶¯ £¬£¬£¬£¬£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾ £¬£¬£¬£¬£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³ £¬£¬£¬£¬£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£¡£¡£¡£


https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/


4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163


8ÔÂ25ÈÕ £¬£¬£¬£¬£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£© £¬£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNCЧÀÍÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷ £¬£¬£¬£¬£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£¡£¡£¡£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ £¬£¬£¬£¬£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍЧÀÍÆ÷ÁìÓò £¬£¬£¬£¬£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸ £¬£¬£¬£¬£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂç £¬£¬£¬£¬£¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNCЧÀÍÆ÷µÄÔË×÷»úÖÆ £¬£¬£¬£¬£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ £¬£¬£¬£¬£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£¡£¡£¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇó £¬£¬£¬£¬£¬Ê¹CNCЧÀÍÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⠣¬£¬£¬£¬£¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£¡£¡£¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß £¬£¬£¬£¬£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ £¬£¬£¬£¬£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£¡£¡£¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ £¬£¬£¬£¬£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNCЧÀÍÆ÷µÄ³¡¾°¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬Ëû»¹¹ûÕæÁËÎó²î´úÂë £¬£¬£¬£¬£¬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£¡£¡£¡£


https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/


5. Magentoƽ̨ÔâÍøÂç¹¥»÷ £¬£¬£¬£¬£¬µÁË¢³ÌÐòÇÔȡ֧¸¶Êý¾Ý


8ÔÂ25ÈÕ £¬£¬£¬£¬£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷ £¬£¬£¬£¬£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂë £¬£¬£¬£¬£¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡ £¬£¬£¬£¬£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£Malwarebytesר¼ÒÖ¸³ö £¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î £¬£¬£¬£¬£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾 £¬£¬£¬£¬£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£¡£¡£¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ £¬£¬£¬£¬£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£¡£¡£¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø £¬£¬£¬£¬£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì £¬£¬£¬£¬£¬ÄÑÒÔ±»Óû§²ì¾õ¡£¡£¡£¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿ÍЧÀÍÆ÷ £¬£¬£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ £¬£¬£¬£¬£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ £¬£¬£¬£¬£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑé £¬£¬£¬£¬£¬Í¨¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£¡£¡£¡£È»¶ø £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥ £¬£¬£¬£¬£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£¡£¡£¡£±ðµÄ £¬£¬£¬£¬£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢ £¬£¬£¬£¬£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£Òò´Ë £¬£¬£¬£¬£¬Óû§Èô·¢Ã÷Òì³£ £¬£¬£¬£¬£¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬ £¬£¬£¬£¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£


https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/


6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬72.6Íò¿Í»§Êý¾Ýй¶


8ÔÂ26ÈÕ £¬£¬£¬£¬£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚЧÀÍ»ú¹¹ £¬£¬£¬£¬£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä £¬£¬£¬£¬£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷ £¬£¬£¬£¬£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶ £¬£¬£¬£¬£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ £¬£¬£¬£¬£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂç £¬£¬£¬£¬£¬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â £¬£¬£¬£¬£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ £¬£¬£¬£¬£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö £¬£¬£¬£¬£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎΣ»£»£»ú £¬£¬£¬£¬£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ £¬£¬£¬£¬£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§À͵ÄÑ¡Ïî £¬£¬£¬£¬£¬×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£¡£¡£¡£Í¬Ê± £¬£¬£¬£¬£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøÎ»ÖÃÐû²¼ÖÒÑÔ £¬£¬£¬£¬£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©Æ­Î£º¦ £¬£¬£¬£¬£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/