еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
Ðû²¼Ê±¼ä 2024-08-271. еÄLinux¶ñÒâÈí¼þsedexpʹÓÃUdev¹æÔòÒþ²ØÐÅÓÿ¨µÁË¢Æ÷
8ÔÂ25ÈÕ£¬£¬£¬£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÁËÒ»ÖÖÃûΪsedexpµÄÐÂÐÍLinux¶ñÒâÈí¼þ£¬£¬£¬£¬ËüÓÉ×·Çó¾¼ÃÀûÒæµÄÍþвÐÐΪÕßÉè¼Æ£¬£¬£¬£¬½ÓÄÉÁËÒ»ÖÖÆæÒìµÄÕ½ÂÔÒÔʵÏÖºã¾ÃDZÔÚºÍÒþÃØ¹¥»÷¡£¡£¡£¡£¡£×Ô2022ÄêÆð£¬£¬£¬£¬¸Ã¸ß¼¶Íþв±ãÒþÄäÓÚÍøÂç¿Õ¼ä£¬£¬£¬£¬Îª¹¥»÷ÕßÌṩÁË·´ÏòshellͨµÀºÍ׿ԽµÄÒþ²ØÊֶΡ£¡£¡£¡£¡£Æä½¹µãÌØÉ«ÔÚÓÚʹÓÃudev¹æÔòÀ´Î¬³ÖÆäÔÚϵͳÄڵij¤ÆÚÐÔ£¬£¬£¬£¬ÕâÊÇͨ¹ý¼à²âϵͳ½¹µã×ÊÔ´Èç/dev/randomµÄ¼ÓÔØÀ´ÊµÏÖ£¬£¬£¬£¬Ã¿µ±ÏµÍ³ÖØÆôʱ¼´×Ô¶¯¼¤»î¶ñÒâ³ÌÐò¡£¡£¡£¡£¡£sedexpͨ¹ýudevµÄÖØ´óÉèÖ㬣¬£¬£¬Äܹ»ÔÚ²»±»²ì¾õµÄÇéÐÎÏÂÖ´ÐжñÒâ²Ù×÷£¬£¬£¬£¬²¢ÇÉÃîµØÐÞ¸ÄϵͳÄڴ棬£¬£¬£¬Òþ²Øº¬ÓÐÆä±êʶ¡°sedexp¡±µÄÎļþ£¬£¬£¬£¬ÓÐÓùæ±ÜÁËͨÀý¼ì²â¹¤¾ßÈçlsºÍfindµÄÕì²é¡£¡£¡£¡£¡£¸üΪ½ÆÕ©µÄÊÇ£¬£¬£¬£¬ËüÒѱ»ÊӲ쵽ÓÃÓÚÔÚЧÀÍÆ÷ÉÏÒþÃØ°²ÅÅÐÅÓÿ¨Êý¾ÝÇÔÈ¡´úÂ룬£¬£¬£¬Í¹ÏÔÁËÆäÃ÷È·µÄ¾¼ÃÀûÒæµ¼Ïò¡£¡£¡£¡£¡£Stroz FriedbergÊÂÎñÏìÓ¦ÍŶÓÖ¸³ö£¬£¬£¬£¬ÔÚÒÑÊӲ참ÀýÖУ¬£¬£¬£¬sedexp²»µ«Òþ²ØÁËWeb ShellºÍÐ޻ڸĵÄApacheÉèÖÃÎļþ£¬£¬£¬£¬»¹×ÔÐÐÐÞ¸ÄÁËudev¹æÔò£¬£¬£¬£¬ÐγÉÁËÒ»¸ö±Õ»·µÄÒþ²ØÏµÍ³¡£¡£¡£¡£¡£ÕâÒ»·¢Ã÷Õ¹ÏÖÁ˳ýÀÕË÷Èí¼þÍ⣬£¬£¬£¬ÒÔ¾¼ÃΪĿµÄµÄÍøÂç¹¥»÷ÊÖ¶ÎÕýÈÕÒæÖØ´ó»¯¡£¡£¡£¡£¡£
https://thehackernews.com/2024/08/new-linux-malware-sedexp-hides-credit.html
2. Ê¢ÐÐPython¿âPandasÆØÇå¾²Îó²îCVE-2024-42992
8ÔÂ25ÈÕ£¬£¬£¬£¬ÆÕ±éʹÓÃµÄ Python ¿âpandasÖз¢Ã÷ÁËÒ»¸öÇå¾²Îó²îCVE-2024-42992£¬£¬£¬£¬¸ÃÎó²î²¨¼°ËùÓа汾ֱÖÁ×îеÄ2.2.2£¬£¬£¬£¬ÆäCVSSÆÀ·Ö¸ß´ï7.5£¬£¬£¬£¬Í¹ÏÔÁËÓû§ÃæÁÙµÄÖØ´óΣº¦¡£¡£¡£¡£¡£¼øÓÚpandasÏÂÔØÁ¿Òѳ¬5400Íò´Î£¬£¬£¬£¬³ÉΪÊý¾Ý´¦Öóͷ£ÓëÆÊÎöµÄ½¹µã¹¤¾ß£¬£¬£¬£¬ÕâÒ»·¢Ã÷ÓÈΪÁîÈ˵£ÐÄ¡£¡£¡£¡£¡£´ËÎó²îΪí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬ÄÜÈù¥»÷ÕßÎÞÏÞÖÆµØ»á¼ûϵͳÄÚµÄí§ÒâÎļþ£¬£¬£¬£¬°üÀ¨Ãô¸ÐÈçUnixϵͳÓû§ÕË»§ÐÅÏ¢µÄ¡°/etc/passwd¡±Îļþ¡£¡£¡£¡£¡£ÆäȪԴÔÚÓÚpandasÔÚ´¦Öóͷ£Îļþ·¾¶ÊäÈëʱȱ·¦ÐëÒªµÄÏÞÖÆ£¬£¬£¬£¬Ê¹µÃ¶ñÒâÓû§ÄÜÖ¸¶¨í§Òâ·¾¶ÒÔÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¸ÃÎó²îÔÚ¶à¸öÔÚÏßÇéÐÎÖÐÒ×ÓÚ¸´ÏÖ£¬£¬£¬£¬ÇÒÆä¿´·¨ÑéÖ¤´úÂëÒÑÔÚGitHubÉϹûÕæ£¬£¬£¬£¬ÏÔÖøÔöÌíÁ˱»¶ñÒâʹÓõÄΣº¦¡£¡£¡£¡£¡£¼øÓÚpandasµÄÆÕ±éÓ¦Ó㬣¬£¬£¬´ËÎó²î¶ÔϵͳÉñÃØÐÔºÍÍêÕûÐÔ×é³ÉÁËÑÏÖØÍþв£¬£¬£¬£¬Êý¾Ýй¶ºÍÃô¸ÐÐÅϢδ¾ÊÚȨ»á¼ûµÄΣº¦ÖèÔö¡£¡£¡£¡£¡£ÃæÁÙÉÐÎÞ¹Ù·½²¹¶¡µÄÏÖ×´£¬£¬£¬£¬Óû§ÐèÁ¬Ã¦½ÓÄÉÔ¤·À²½·¥£¬£¬£¬£¬ÈçÏÞÖÆÔÚÃôÇéÐ÷ÐÎÖÐʹÓÃpandas£¬£¬£¬£¬²¢Ôöǿϵͳ¼à¿ØÓëÇå¾²²½·¥£¬£¬£¬£¬ÒÔ¼ì²âºÍ·ÀÓùDZÔÚ¹¥»÷¡£¡£¡£¡£¡£
https://securityonline.info/critical-flaw-discovered-in-popular-python-library-pandas-no-patch-available-for-cve-2024-42992/
3. Cheana StealerÌᳫ¿çƽ̨VPN´¹ÂÚ¹¥»÷£¬£¬£¬£¬ÇÔÈ¡Óû§Ãô¸ÐÊý¾Ý
8ÔÂ25ÈÕ£¬£¬£¬£¬Cyble Ñо¿ÓëÇ鱨ʵÑéÊÒ ( CRIL ) ·¢Ã÷µÄ×îÐÂÍþвCheana Stealer£¬£¬£¬£¬¸Ã¶ñÒ⹤¾ßͨ¹ýαװ³É×ÅÃûVPNЧÀÍWarpVPNµÄÍøÂç´¹ÂÚÊֶΣ¬£¬£¬£¬¿çƽ̨¹¥»÷Windows¡¢Linux¼°macOSÓû§¡£¡£¡£¡£¡£Cheana StealerʹÓÃÈ«ÐÄÉè¼ÆµÄ´¹ÂÚÍøÕ¾ÓÕÆÓû§ÏÂÔØ²¢×°ÖÃαװ³ÉÕýµ±VPNÈí¼þµÄÇÔÈ¡³ÌÐò£¬£¬£¬£¬Ò»µ©µ½ÊÖ£¬£¬£¬£¬±ãÇÄÎÞÉùÏ¢µØÍøÂç°üÀ¨ä¯ÀÀÆ÷ÃÜÂë¡¢¼ÓÃÜÇ®±ÒÇ®°ü¡¢SSHÃÜÔ¿µÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£Õë¶Ô²î±ð²Ù×÷ϵͳ£¬£¬£¬£¬Cheana Stealer½ÓÄɲî±ðµÄÊÖÒÕÊֶΣºÔÚWindowsÉÏ£¬£¬£¬£¬ËüʹÓÃPowerShellÖ´ÐжñÒâ¾ç±¾£»£»£»£»Linux°æÔòͨ¹ýαװCloudflare Warp VPNµÄshell¾ç±¾ÊµÑé¹¥»÷£»£»£»£»macOSÉÏÔòʹÓÃÐéαϵͳÌáÐÑÇÔÈ¡Keychain¼°¼ÓÃÜÇ®±ÒÇ®°üÐÅÏ¢¡£¡£¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬¸ÃÇÔÈ¡³ÌÐòµÄÈö²¥ÓëÒ»¸öÓµÓÐÊýÍò¶©ÔÄÕßµÄTelegramƵµÀϸÃÜÏà¹Ø£¬£¬£¬£¬ÆµµÀÄÚÆµÈÔÐû´«Ã°³äVPNЧÀÍ£¬£¬£¬£¬¼«´óÖú³¤Á˹¥»÷¹æÄ£¡£¡£¡£¡£¡£CRILµÄÑо¿Õ¹ÏÖ£¬£¬£¬£¬¹¥»÷Õß³õÆÚÌṩÕýµ±Ð§ÀÍÒÔ»ýÀÛÐÅÈΣ¬£¬£¬£¬ËæºóתÏò¶ñÒâ»î¶¯£¬£¬£¬£¬Í¨¹ýTelegramµÈÐÅÓþƽ̨¼°¸ß¶È·ÂÕæµÄ´¹ÂÚÍøÕ¾£¬£¬£¬£¬ÀÖ³ÉÈëÇÖÁ˶à¸ö²Ù×÷ϵͳƽ̨µÄ´ó×ÚÓû§ÏµÍ³£¬£¬£¬£¬Í¹ÏÔÁËÄ¿½ñÍøÂçÇå¾²ÌôÕ½µÄÑÏËàÐÔ¡£¡£¡£¡£¡£
https://securityonline.info/cheana-stealer-targets-vpn-users-across-windows-linux-and-macos-in-sophisticated-phishing-campaign/
4. Mirai½©Ê¬ÍøÂçÖз¢Ã÷ÑÏÖØÎó²îCVE-2024-45163
8ÔÂ25ÈÕ£¬£¬£¬£¬Çå¾²Ñо¿Ô±Jacob MasseÕ¹ÏÖÁËMirai½©Ê¬ÍøÂçÖеÄÒ»¸öÑÏÖØÎó²îCVE-2024-45163£¨CVSSÆÀ·ÖΪ9.1£©£¬£¬£¬£¬¸ÃÎó²îÔÊÐí¶Ô½©Ê¬ÍøÂçµÄCNCЧÀÍÆ÷¾ÙÐÐÔ¶³ÌDoS¹¥»÷£¬£¬£¬£¬ÑÏÖØÍþвµ½Mirai½©Ê¬ÍøÂçµÄÔËÐС£¡£¡£¡£¡£Mirai×÷ΪһÖÖÎÛÃûÕÑÖøµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬×Ô2016ÄêÆð±ãÈÅÂÒÎïÁªÍøºÍЧÀÍÆ÷ÁìÓò£¬£¬£¬£¬Í¨¹ýʹÓÃÈõÃÜÂëµÈÎó²î¿ØÖÆ´ó×Ú×°±¸£¬£¬£¬£¬ÐγÉÖØ´óµÄ½©Ê¬ÍøÂ磬£¬£¬£¬Ö´ÐÐDDoS¹¥»÷µÈ¶ñÒâ»î¶¯¡£¡£¡£¡£¡£Jacob Masseͨ¹ýÉîÈëÑо¿CNCЧÀÍÆ÷µÄÔË×÷»úÖÆ£¬£¬£¬£¬·¢Ã÷ÁËÆäÔÚ´¦Öóͷ£²¢·¢ÅþÁ¬ÇëÇóʱµÄȱÏÝ£¬£¬£¬£¬ÌØÊâÊÇÔÚÔ¤ÈÏÖ¤½×¶Î¡£¡£¡£¡£¡£ÕâÒ»Îó²îÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍ´ó×Ú¼òÆÓµÄÉí·ÝÑéÖ¤ÇëÇ󣬣¬£¬£¬Ê¹CNCЧÀÍÆ÷×ÊÔ´ºÄ¾¡²¢Í߽⣬£¬£¬£¬´Ó¶øÌ±»¾Õû¸ö½©Ê¬ÍøÂç¡£¡£¡£¡£¡£CVE-2024-45163µÄÅû¶²»µ«ÎªÖ´·¨»ú¹¹ÌṩÁËÍß½âMirai½©Ê¬ÍøÂçµÄÓÐÁ¦¹¤¾ß£¬£¬£¬£¬Ò²Òý·¢Á˹ØÓÚÆ·µÂʹÓõÄÌÖÂÛ£¬£¬£¬£¬ÓÉÓÚʹÓôËÎó²î¿ÉÄÜÒâÍâÖÐÖ¹Õýµ±²âÊÔÖеĽ©Ê¬ÍøÂç¡£¡£¡£¡£¡£Masseͨ¹ýPoCÑÝʾÁËÎó²îµÄÓÐÓÃÐÔ£¬£¬£¬£¬Õ¹Ê¾ÁËÔÚÓÐÏÞ×ÊԴϼ´¿ÉÀֳɹرÕCNCЧÀÍÆ÷µÄ³¡¾°¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ëû»¹¹ûÕæÁËÎó²î´úÂ룬£¬£¬£¬Ôö½øÁËÍøÂçÇå¾²ÉçÇøµÄÑо¿Óë·ÀÓùÊÂÇé¡£¡£¡£¡£¡£
https://securityonline.info/hacking-the-hacker-researcher-found-critical-flaw-cve-2024-45163-in-mirai-botnet/
5. Magentoƽ̨ÔâÍøÂç¹¥»÷£¬£¬£¬£¬µÁË¢³ÌÐòÇÔȡ֧¸¶Êý¾Ý
8ÔÂ25ÈÕ£¬£¬£¬£¬ÖÚ¶à½ÓÄÉMagentoƽ̨µÄÔÚÏßÊÐËÁ½üÆÚÔâÓöÁËÑÏÖØÍøÂç¹¥»÷£¬£¬£¬£¬ÆäÖ§¸¶Ò³Ãæ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬£¬µ¼Ö¿ͻ§Ö§¸¶¿¨Êý¾Ý±»²»·¨ÇÔÈ¡£¬£¬£¬£¬°üÀ¨¿¨ºÅ¡¢ÓÐÓÃÆÚ¼°Çå¾²ÂëµÈÖ÷ÒªÐÅÏ¢¡£¡£¡£¡£¡£Malwarebytesר¼ÒÖ¸³ö£¬£¬£¬£¬ºÚ¿ÍʹÓÃMagentoϵͳÎó²î£¬£¬£¬£¬ÔÚÖ§¸¶Á÷³ÌÖвåÈëÒ»Ðо籾£¬£¬£¬£¬¸Ã¾ç±¾ÄÜÔ¶³Ì¼ÓÔØ²¢Ö´ÐÐÊý¾ÝÇÔÈ¡²Ù×÷¡£¡£¡£¡£¡£Êý°Ù¼ÒµêËÁÒÑÈ·ÈÏÊÜÇÖ£¬£¬£¬£¬ºÚ¿Íͨ¹ý×Ô½¨ÍøÕ¾ÍøÂç±»µÁÊý¾Ý¡£¡£¡£¡£¡£´ËÀàÊý×ÖµÁË¢Æ÷¼«ÆäÒþ²Ø£¬£¬£¬£¬Äܹ»ÎÞ·ìÈÚÈëÕý¹æÖ§¸¶Á÷³Ì£¬£¬£¬£¬ÄÑÒÔ±»Óû§²ì¾õ¡£¡£¡£¡£¡£ËüÃÇÔÚÓû§ÊäÈëÖ§¸¶ÐÅϢʱ¼´Ê±²¶»ñ²¢×ª·¢ÖÁºÚ¿ÍЧÀÍÆ÷£¬£¬£¬£¬ÉõÖÁÔÚijЩÇéÐÎÏ£¬£¬£¬£¬Äܹ»ÈƹýµÚÈý·½Ö§¸¶´¦Öóͷ£Á÷³ÌÖ±½Ó×èµ²Êý¾Ý¡£¡£¡£¡£¡£ÐÒÔ˵ÄÊÇ£¬£¬£¬£¬Ç徲ר¼ÒÒÑ×èµ²Áè¼Ý1,100´ÎÊý¾ÝÇÔȡʵÑ飬£¬£¬£¬Í¨¹ýʶ±ð²¢·â±ÕÊýÊ®¸ö¶ñÒâÓòÃûÓÐÓÃ×èÖ¹Á˲¿·Ö¹¥»÷¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬ÊÜÓ°ÏìµÄµêËÁËäÒѽÓÄÉɾ³ý¶ñÒâ´úÂë»òÔÝÍ£ÔËÓªµÈ²½·¥£¬£¬£¬£¬µ«²¿·ÖÍøÕ¾ÈÔÃæÁÙÒ»Á¬Íþв¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Êý¾Ýй¶²»µ«ÏÞÓÚ²ÆÎñÐÅÏ¢£¬£¬£¬£¬»¹Éæ¼°Óû§µÄµç×ÓÓʼþ¡¢×¡Ö·¼°µç»°ºÅÂëµÈСÎÒ˽¼ÒÒþ˽¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬Óû§Èô·¢Ã÷Òì³££¬£¬£¬£¬Ó¦Á¬Ã¦ÁªÏµÒøÐÐÌæ»»¿¨Æ¬£¬£¬£¬£¬²¢Ë¼Á¿ÆôÓÃÉí·Ý±£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£
https://securityonline.info/cyberattack-on-magento-hackers-inject-skimmer-card-data-stolen/
6. PatelcoÔâRansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬72.6Íò¿Í»§Êý¾Ýй¶
8ÔÂ26ÈÕ£¬£¬£¬£¬PatelcoÐÅÓÃÏàÖúÉçÊÇÒ»¼Ò×ʲú³¬90ÒÚÃÀÔªµÄÃÀ¹ú·ÇÓªÀûÐÔ½ðÈÚЧÀÍ»ú¹¹£¬£¬£¬£¬½üÆÚÔâÓöÑÏÖØÊý¾Ýй¶ÊÂÎñ¡£¡£¡£¡£¡£½ñÄêÔçЩʱ¼ä£¬£¬£¬£¬¸ÃÉçÊܵ½RansomHubÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬Ö»¹ÜÆäʱδÁ¬Ã¦È·ÈÏÊý¾Ýй¶£¬£¬£¬£¬µ«ËæºóÊÓ²ìÕ¹ÏÖ£¬£¬£¬£¬¹¥»÷ÕßÓÚ5ÔÂ23ÈÕDZÈëÍøÂ磬£¬£¬£¬²¢ÓÚ6ÔÂ29ÈÕ»á¼ûÊý¾Ý¿â£¬£¬£¬£¬ÇÔÈ¡ÁË´ó×Ú¿Í»§Ð¡ÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£ÕâЩÃô¸ÐÐÅÏ¢°üÀ¨ÐÕÃû¡¢Éç»áÇå¾²ºÅÂë¡¢¼ÝʻִÕÕºÅÂë¡¢³öÉúÈÕÆÚ¼°µç×ÓÓʼþµÈ£¬£¬£¬£¬ÓëRansomHubÍÅ»ïÔÚ8ÔÂ15ÈÕÓÚÆäÀÕË÷ÍøÕ¾ÉÏÐû²¼µÄÊý¾ÝÒ»Ö£¬£¬£¬£¬¸ÃÍÅ»ïÉù³ÆÔÚ̸ÅÐδ¹ûЧ¹ûÕæÁËÊý¾Ý¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñ²¨¼°PatelcoµÄ726,000Ãû¿Í»§¡£¡£¡£¡£¡£ÎªÓ¦¶Ô´Ë´ÎΣ»£»£»£»ú£¬£¬£¬£¬PatelcoÒÑÏòÊÜÓ°ÏìµÄ¿Í»§·¢ËÍÊý¾Ýй¶֪ͨ£¬£¬£¬£¬²¢Ìṩͨ¹ýExperian×¢²áÁ½ÄêÃâ·ÑÉí·Ý±£»£»£»£»¤ºÍÐÅÓÃ¼à¿ØÐ§À͵ÄÑ¡Ï£¬£¬£¬×èÖ¹ÈÕÆÚΪ11ÔÂ19ÈÕ¡£¡£¡£¡£¡£Í¬Ê±£¬£¬£¬£¬¸ÃÉçÔÚÆäÍøÕ¾ÏÔÖøÎ»ÖÃÐû²¼ÖÒÑÔ£¬£¬£¬£¬ÌáÐÑ»áԱСÐÄÍøÂç´¹ÂÚ¡¢Éç»á¹¤³Ì¼°Õ©ÆÎ£º¦£¬£¬£¬£¬Ç¿µ÷¹Ù·½¾ø²»»áÖ±½ÓË÷È¡¿¨ÏêÇéµÈÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/patelco-notifies-726-000-customers-of-ransomware-data-breach/