»úеÈËÊÖÒÕÇå¾²ÐÔ¸ÅÀÀ±¨¸æ£»Linux sudoȨÏÞÈÆ¹ýÎó²î£»ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×ÙÆÊÎö

Ðû²¼Ê±¼ä 2019-10-15
1¡¢Linux sudoȨÏÞÈÆ¹ýÎó²î£¬¿ÉÒÔrootȨÏÞÖ´ÐÐÏÂÁî

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

Linux sudoÆØ³öÌáȨÎó²î£¬¿ÉÈÆ¹ýRunasÓû§ÏÞÖÆÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¸ÃÎó²î£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢Çå¾²²¿·ÖµÄJoe Vennix·¢Ã÷£¬ÈôÊǽ«sudoÉèÖÃΪÔÊÐíÓû§ÒÔí§ÒâÓû§Éí·ÝÔËÐÐÏÂÁÔò¿ÉÒÔͨ¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½·¨ÒÔrootÉí·ÝÔËÐÐÏÂÁî¡£ÕâÊÇÓÉÓÚ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÒÔΪ0£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£±ðµÄ£¬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»±£´æ£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä£¿é¡£¸ÃÎó²îÓ°Ïì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.sudo.ws/alerts/minus_1_uid.html

2¡¢¿¨°Í˹»ùÐû²¼¡¶»úеÈËÊÖÒÕÇå¾²ÐÔ¸ÅÀÀ¡·±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


¿¨°Í˹»ùÑо¿ÍŶÓÐû²¼Ä¿½ñ»úеÈËÊÖÒÕµÄÇå¾²ÐÔ¸ÅÀÀ±¨¸æ£¬ÕâЩ»úеÈ˺­¸ÇÖÖÖÖ×°±¸£¬ÀýÈ繤³§ÖеĻúе±Û»òËÍ»õ»úеÈË¡¢×Ô¶¯¼ÝÊ»Æû³µ¡¢±£Ä·»úеÈ˵È¡£ÍøÂç¹¥»÷ÕýÔÚÍþв»úеÈ˲Ù×÷ϵͳ£¨ROS£©µÄÍêÕûÐÔ£¬»úеÈË¿ÉÒÔʹÓô«¸ÐÆ÷¸Ð²âÎïÀíÌìÏ£¬Ò²¿ÉÒÔͨ¹ýÆäÖ´ÐÐÆ÷Ö±½Ó¸Ä±äÎïÀíÌìÏ£¬Òò´ËÈôÊÇÔâδÊÚȨ»á¼û£¬»úеÈË¿ÉÄÜ»á×ß©ÓÐ¹ØÆäÇéÐεÄÃô¸ÐÐÅÏ¢£¬ÀýÈç´«¸ÐÆ÷»òÉãÏñ»úÊý¾Ý£¬ÉõÖÁ½Óµ½Òƶ¯ÏÂÁîµÈ£¬Õ⽫´øÀ´Òþ˽ºÍÇ徲Σº¦¡£ÔÚ2018Ä꣬¶ÔInternet IPv4µØµã¿Õ¼äµÄÆÊÎöÒѾ­Ê¶±ð³ö100¶à¸ö¿É¹ûÕæ»á¼ûµÄÔËÐÐROSÖ÷½ÚµãµÄÖ÷»ú£¬ËüÃÇ¿ÉÄÜ»áÔ⵽δÊÚȨµÄÏÂÁî×¢Èë¡¢Êý¾Ý»á¼û»ò¾Ü¾ø·þÎñµÈ¹¥»÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/robots-social-impact/94431/

3¡¢ESETÐû²¼·¸·¨ÍÅ»ïWinnti GroupжñÒâÔ˶¯µÄÆÊÎö±¨¸æ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

ESETÑо¿ÍŶÓÐû²¼Ò»·Ý¹ØÓÚ·¸·¨ÍÅ»ïWinnti GroupµÄ¶ñÒ⹤¾ß¼°Ô˶¯¸üÐÂµÄ°×Æ¤Êé¡£Winnti GroupÒÑÓнüÊ®ÄêµÄÀúÊ·£¬ËüÖ÷ÒªÕë¶ÔÓÎÏ·ÐÐÒµ£¬ÆäÊ×Ñ¡¹¥»÷·½·¨ÊÇͨ¹ýÉøÍ¸ÓÎÏ·¿ª·¢Ö°Ô±½«ºóÃÅÖ²ÈëÓÎÏ·µÄ¹¹½¨ÇéÐΣ¬È»ºó·Ö·¢¶ñÒâÈí¼þ¡£ÑÇÖÞÓÎÏ·Íæ¼ÒÊÇÆä×î½üÒ»´Î¹©Ó¦Á´¹¥»÷µÄÄ¿µÄ£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄÔ¤¼Æ£¬ÊÜÓ°ÏìµÄÈËÊý¿É´ïÊýǧÈË£¬Áè¼ÝÒ»°ëµÄÊܺ¦Õߣ¨55%£©Î»ÓÚÌ©¹ú¡£Winnti GroupʹÓôò°üµÄºóÃÅPortReuse£¬ESETÖÒÑÔÑÇÖÞµÄÒ»¼ÒÖ÷ÒªÒÆ¶¯Èí¼þºÍÓ²¼þÖÆÔìÉÌÊܵ½PortReuseµÄѬȾ¡£ESET»¹ÆÊÎöÁËWinnti GroupʹÓõÄÁíÒ»¸öºóÃÅShadownpadµÄбäÌå¡£Ö»¹ÜWinntiÖ÷ÒªÒÔÌØ¹¤Ô˶¯¶øÖøÃû£¬µ«Ñо¿Ö°Ô±·¢Ã÷¸Ã×éÖ¯»¹Ê¹Óý©Ê¬ÍøÂçÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/

4¡¢McAfeeÐû²¼ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×ÙÆÊÎö±¨¸æ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


McAfeeÔÚÒ»·Ýб¨¸æÖÐ×·×ÙÁËSodinokibi RaaSµÄ×ʽðÔ˶¯¡£Ò»¸öÃûΪLalartuµÄ»áÔ±ÔÚÂÛ̳Ìû×ÓÖÐÐû²¼Á˲¿Ñ§ÉúÒâIDµÄÆÁÄ»½ØÍ¼£¬ÏÔʾÔÚ72СʱÄÚÔ¼ÓÐ28.75ÍòÃÀÔªÊê½ðÖ§¸¶¡£Í¨¹ýÉó²éÀÕË÷Èí¼þµÄÏÖÓÐÑù±¾£¬McAfeeÄܹ»È·¶¨Æ½¾ùÊê½ðÔÚ0.44ÖÁ0.45±ÈÌØ±ÒÖ®¼ä£¬Ô¼Îª4000ÃÀÔª¡£ÔÚÇø¿éÁ´Êý¾ÝÆÊÎö¹«Ë¾ChainalysisµÄ×ÊÖúÏ£¬McAfee¼ìË÷µ½ÁËÍêÕûµÄÉúÒâID£¬²¢Ê¹ÓÃËüÃÇÀ´Ó³ÉäÏà¹ØµÄ±ÈÌØ±ÒÉúÒâ¡£Æ¾Ö¤ÍøÂçµ½µÄÐÅÏ¢£¬McAfeeÄܹ»Éó²éÆäËû»áÔ±Êê½ðÖ§¸¶µÄÇéÐΣ¬ÒÔ¼°»áÔ±ºÍÔËÓªÉÌÖ®¼äµÄÊÕÈë·ÖÅÉΪ60/40»ò70/30¡£ÆäËû»áÔ±»¹Ê¹ÓñÈÌØ±ÒÔÚµØÏÂÊг¡ÉϹºÖ÷þÎñ£¬ÕâЩµØÏÂÊг¡½ÓÊܶ¾Æ·¡¢ÎäÆ÷ºÍºÚ¿Í·þÎñµÈ²»·¨ÎïÆ·µÄ±ÈÌØ±ÒÉúÒâ¡£McAfeeÄܹ»×·×Ùµ½µÄÒ»¸ö½Ï´óµÄ¹ØÁª·½Ç®°üÀïÓÐ443±ÈÌØ±Ò£¬Ô¼Îª450ÍòÃÀÔª¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-following-the-affiliate-money-trail/

5¡¢Silent LibrarianʹÓô¹ÂÚ¹¥»÷Ãé×¼±±ÃÀ¼°Å·ÖÞ´óѧ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÒÁÀÊ·¸·¨ÍÅ»ïSilent LibrarianÕýÔÚÒ»Ö±¸üÐÂÆäÕ½ÂÔºÍÊÖÒÕ£¬ÒÔͨ¹ý´¹ÂÚ¹¥»÷Ãé×¼ÃÀ¹úºÍÅ·Ö޵Ĵóѧ¡£´Ó6Ôµ½10Ô£¬¸ÃÍÅ»ïµÄÍøÂç´¹ÂÚÔ˶¯Ô½·¢ÆµÈÔ£¬Æä´¹ÂÚÖ÷Ìâ»ù±¾¼á³ÖÎȹÌ£¬×î³£¼ûµÄÊÇÎÞ·¨»á¼ûͼÊé¹Ý×ÊÔ´£¬ÀýÈçÕË»§ÓâÆÚµÈ¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÍÅ»ïÓëÒÁÀÊÕþ¸®±£´æ¹ØÁª£¬ÆäÄ¿µÄÊÇ´ÓÈ«Çò´óѧÇÔȡ֪ʶ²úȨ¡£Ö»¹ÜÈ¥ÄêÃÀ¹ú˾·¨²¿Îª´Ë¹¥»÷Ô˶¯Ö¸¿ØÁË9ÃûºÚ¿Í£¬µ«¸Ã¹¥»÷Ô˶¯ÈÔÔÚ¾ÙÐÐÖС£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iranian-hackers-create-credible-phishing-to-steal-library-access/

6¡¢ÃÀ¹ú·Ñ³ÇÎÀÉúÊð¹ÙÍøÒâÍâ̻¶ÊýǧÃû¸ÎÑ×»¼ÕßÐÅÏ¢


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹ú·Ñ³ÇÎÀÉúÊðµÄÒ»¸ö¹«¹²Êý¾Ý¹¤¾ßÒâÍâй¶ÁËÊýǧÃû¸ÎÑ×»¼ÕßµÄÒþ˽ÐÅÏ¢¡£ÉÏÖÜÎåÒ»Ãû¼ÇÕß·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢Í¨ÖªÁ˸ò¿·Ö¡£¸Ã²¿·ÖÔÚ¼¸·ÖÖÓºóɾ³ýÁË̻¶µÄÊý¾Ý£¬ÏÖÔÚÉв»ÇåÎúÕâЩÐÅϢ̻¶Á˶೤ʱ¼ä¡£¸ÃÊеÄÒ»Ãû½²»°ÈËÌåÏÖÈÔÔÚ¶ÔÊÂÎñµÄ¹æÄ£¾ÙÐÐÊӲ죬²¢ÇÒÔÚ½øÒ»²½Ïàʶ֮ǰ²»½ÒÏþ̸ÂÛ¡£Æ¾Ö¤¼ÇÕߵķ¢Ã÷£¬¸Ã̻¶µÄÊý¾Ý°üÀ¨2.3Íò±ûÐ͸ÎÑײ¡ÀýµÄСÎÒ˽¼Ò¼Í¼£¬ÐÅÏ¢°üÀ¨Ã¿Î»»¼ÕßµÄÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ£¬µØµãºÍÕï¶ÏЧ¹û£¬ÔÚijЩÇéÐÎÏ£¬»¹°üÀ¨Éç»áÇå¾²ºÅÂë¼°Ò½ÎñÖ°Ô±µÄ¼Í¼¡£Êý¾ÝËÆºõº­¸ÇÁË2013Äêµ½2018Äêµ×µÄÐÂÕï¶ÏЧ¹û¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.inquirer.com/news/philadelphia-health-department-data-breach-opioids-tableau-hepatitis-20191011.html