»úеÈËÊÖÒÕÇå¾²ÐÔ¸ÅÀÀ±¨¸æ£»£»£»£»£»Linux sudoȨÏÞÈÆ¹ýÎó²î£»£»£»£»£»ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×ÙÆÊÎö
Ðû²¼Ê±¼ä 2019-10-15
Linux sudoÆØ³öÌáȨÎó²î£¬£¬£¬£¬¿ÉÈÆ¹ýRunasÓû§ÏÞÖÆÒÔrootȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-14287£©ÓÉÆ»¹ûÐÅÏ¢Çå¾²²¿·ÖµÄJoe Vennix·¢Ã÷£¬£¬£¬£¬ÈôÊǽ«sudoÉèÖÃΪÔÊÐíÓû§ÒÔí§ÒâÓû§Éí·ÝÔËÐÐÏÂÁ£¬£¬£¬Ôò¿ÉÒÔͨ¹ýÖ¸¶¨Óû§IDΪ-1»ò4294967295µÄ·½·¨ÒÔrootÉí·ÝÔËÐÐÏÂÁî¡£¡£¡£¡£¡£¡£ÕâÊÇÓÉÓÚ½«Óû§IDת»»ÎªÓû§ÃûµÄº¯Êý£¬£¬£¬£¬»á½«-1£¨»òµÈЧµÄ4294967295£©ÎóÒÔΪ0£¬£¬£¬£¬¶øÕâÕýºÃÊÇrootÓû§µÄUser ID¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ÓÉÓÚͨ¹ý-uÑ¡ÏîÖ¸¶¨µÄUser IDÔÚÃÜÂëÊý¾Ý¿âÖв»±£´æ£¬£¬£¬£¬Òò´Ë²»»áÔËÐÐÈκÎPAM»á»°Ä£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°Ïì°æ±¾1.8.28֮ǰµÄËùÓÐSudo°æ±¾¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.sudo.ws/alerts/minus_1_uid.html2¡¢¿¨°Í˹»ùÐû²¼¡¶»úеÈËÊÖÒÕÇå¾²ÐÔ¸ÅÀÀ¡·±¨¸æ
ÔÎÄÁ´½Ó£º
https://securelist.com/robots-social-impact/94431/3¡¢ESETÐû²¼·¸·¨ÍÅ»ïWinnti GroupжñÒâ»î¶¯µÄÆÊÎö±¨¸æ
ESETÑо¿ÍŶÓÐû²¼Ò»·Ý¹ØÓÚ·¸·¨ÍÅ»ïWinnti GroupµÄ¶ñÒ⹤¾ß¼°»î¶¯¸üÐÂµÄ°×Æ¤Êé¡£¡£¡£¡£¡£¡£Winnti GroupÒÑÓнüÊ®ÄêµÄÀúÊ·£¬£¬£¬£¬ËüÖ÷ÒªÕë¶ÔÓÎÏ·ÐÐÒµ£¬£¬£¬£¬ÆäÊ×Ñ¡¹¥»÷·½·¨ÊÇͨ¹ýÉøÍ¸ÓÎÏ·¿ª·¢Ö°Ô±½«ºóÃÅÖ²ÈëÓÎÏ·µÄ¹¹½¨ÇéÐΣ¬£¬£¬£¬È»ºó·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£ÑÇÖÞÓÎÏ·Íæ¼ÒÊÇÆä×î½üÒ»´Î¹©Ó¦Á´¹¥»÷µÄÄ¿µÄ£¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄÔ¤¼Æ£¬£¬£¬£¬ÊÜÓ°ÏìµÄÈËÊý¿É´ïÊýǧÈË£¬£¬£¬£¬Áè¼ÝÒ»°ëµÄÊܺ¦Õߣ¨55%£©Î»ÓÚÌ©¹ú¡£¡£¡£¡£¡£¡£Winnti GroupʹÓôò°üµÄºóÃÅPortReuse£¬£¬£¬£¬ESETÖÒÑÔÑÇÖÞµÄÒ»¼ÒÖ÷ÒªÒÆ¶¯Èí¼þºÍÓ²¼þÖÆÔìÉÌÊܵ½PortReuseµÄѬȾ¡£¡£¡£¡£¡£¡£ESET»¹ÆÊÎöÁËWinnti GroupʹÓõÄÁíÒ»¸öºóÃÅShadownpadµÄбäÌå¡£¡£¡£¡£¡£¡£Ö»¹ÜWinntiÖ÷ÒªÒÔÌØ¹¤»î¶¯¶øÖøÃû£¬£¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷¸Ã×éÖ¯»¹Ê¹Óý©Ê¬ÍøÂçÀ´ÍÚ¾ò¼ÓÃÜÇ®±Ò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.welivesecurity.com/2019/10/14/connecting-dots-exposing-arsenal-methods-winnti/4¡¢McAfeeÐû²¼ÀÕË÷Èí¼þSodinokibiµÄ×ʽð¸ú×ÙÆÊÎö±¨¸æ
McAfeeÔÚÒ»·Ýб¨¸æÖÐ×·×ÙÁËSodinokibi RaaSµÄ×ʽð»î¶¯¡£¡£¡£¡£¡£¡£Ò»¸öÃûΪLalartuµÄ»áÔ±ÔÚÂÛ̳Ìû×ÓÖÐÐû²¼Á˲¿Ñ§ÉúÒâIDµÄÆÁÄ»½ØÍ¼£¬£¬£¬£¬ÏÔʾÔÚ72СʱÄÚÔ¼ÓÐ28.75ÍòÃÀÔªÊê½ðÖ§¸¶¡£¡£¡£¡£¡£¡£Í¨¹ýÉó²éÀÕË÷Èí¼þµÄÏÖÓÐÑù±¾£¬£¬£¬£¬McAfeeÄܹ»È·¶¨Æ½¾ùÊê½ðÔÚ0.44ÖÁ0.45±ÈÌØ±ÒÖ®¼ä£¬£¬£¬£¬Ô¼Îª4000ÃÀÔª¡£¡£¡£¡£¡£¡£ÔÚÇø¿éÁ´Êý¾ÝÆÊÎö¹«Ë¾ChainalysisµÄ×ÊÖúÏ£¬£¬£¬£¬McAfee¼ìË÷µ½ÁËÍêÕûµÄÉúÒâID£¬£¬£¬£¬²¢Ê¹ÓÃËüÃÇÀ´Ó³ÉäÏà¹ØµÄ±ÈÌØ±ÒÉúÒâ¡£¡£¡£¡£¡£¡£Æ¾Ö¤ÍøÂçµ½µÄÐÅÏ¢£¬£¬£¬£¬McAfeeÄܹ»Éó²éÆäËû»áÔ±Êê½ðÖ§¸¶µÄÇéÐΣ¬£¬£¬£¬ÒÔ¼°»áÔ±ºÍÔËÓªÉÌÖ®¼äµÄÊÕÈë·ÖÅÉΪ60/40»ò70/30¡£¡£¡£¡£¡£¡£ÆäËû»áÔ±»¹Ê¹ÓñÈÌØ±ÒÔÚµØÏÂÊг¡ÉϹºÖÃЧÀÍ£¬£¬£¬£¬ÕâЩµØÏÂÊг¡½ÓÊܶ¾Æ·¡¢ÎäÆ÷ºÍºÚ¿ÍЧÀ͵Ȳ»·¨ÎïÆ·µÄ±ÈÌØ±ÒÉúÒâ¡£¡£¡£¡£¡£¡£McAfeeÄܹ»×·×Ùµ½µÄÒ»¸ö½Ï´óµÄ¹ØÁª·½Ç®°üÀïÓÐ443±ÈÌØ±Ò£¬£¬£¬£¬Ô¼Îª450ÍòÃÀÔª¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-following-the-affiliate-money-trail/
5¡¢Silent LibrarianʹÓô¹ÂÚ¹¥»÷Ãé×¼±±ÃÀ¼°Å·ÖÞ´óѧ
ÒÁÀÊ·¸·¨ÍÅ»ïSilent LibrarianÕýÔÚÒ»Ö±¸üÐÂÆäÕ½ÂÔºÍÊÖÒÕ£¬£¬£¬£¬ÒÔͨ¹ý´¹ÂÚ¹¥»÷Ãé×¼ÃÀ¹úºÍÅ·Ö޵Ĵóѧ¡£¡£¡£¡£¡£¡£´Ó6Ôµ½10Ô£¬£¬£¬£¬¸ÃÍÅ»ïµÄÍøÂç´¹ÂڻԽ·¢ÆµÈÔ£¬£¬£¬£¬Æä´¹ÂÚÖ÷Ìâ»ù±¾¼á³ÖÎȹ̣¬£¬£¬£¬×î³£¼ûµÄÊÇÎÞ·¨»á¼ûͼÊé¹Ý×ÊÔ´£¬£¬£¬£¬ÀýÈçÕË»§ÓâÆÚµÈ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÍÅ»ïÓëÒÁÀÊÕþ¸®±£´æ¹ØÁª£¬£¬£¬£¬ÆäÄ¿µÄÊÇ´ÓÈ«Çò´óѧÇÔȡ֪ʶ²úȨ¡£¡£¡£¡£¡£¡£Ö»¹ÜÈ¥ÄêÃÀ¹ú˾·¨²¿Îª´Ë¹¥»÷»î¶¯Ö¸¿ØÁË9ÃûºÚ¿Í£¬£¬£¬£¬µ«¸Ã¹¥»÷»î¶¯ÈÔÔÚ¾ÙÐÐÖС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iranian-hackers-create-credible-phishing-to-steal-library-access/
6¡¢ÃÀ¹ú·Ñ³ÇÎÀÉúÊð¹ÙÍøÒâÍâ̻¶ÊýǧÃû¸ÎÑ×»¼ÕßÐÅÏ¢
ÃÀ¹ú·Ñ³ÇÎÀÉúÊðµÄÒ»¸ö¹«¹²Êý¾Ý¹¤¾ßÒâÍâй¶ÁËÊýǧÃû¸ÎÑ×»¼ÕßµÄÒþ˽ÐÅÏ¢¡£¡£¡£¡£¡£¡£ÉÏÖÜÎåÒ»Ãû¼ÇÕß·¢Ã÷ÁËÕâÒ»ÊÂÎñ²¢Í¨ÖªÁ˸ò¿·Ö¡£¡£¡£¡£¡£¡£¸Ã²¿·ÖÔÚ¼¸·ÖÖÓºóɾ³ýÁË̻¶µÄÊý¾Ý£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÕâЩÐÅϢ̻¶Á˶೤ʱ¼ä¡£¡£¡£¡£¡£¡£¸ÃÊеÄÒ»Ãû½²»°ÈËÌåÏÖÈÔÔÚ¶ÔÊÂÎñµÄ¹æÄ£¾ÙÐÐÊӲ죬£¬£¬£¬²¢ÇÒÔÚ½øÒ»²½Ïàʶ֮ǰ²»½ÒÏþ̸ÂÛ¡£¡£¡£¡£¡£¡£Æ¾Ö¤¼ÇÕߵķ¢Ã÷£¬£¬£¬£¬¸Ã̻¶µÄÊý¾Ý°üÀ¨2.3Íò±ûÐ͸ÎÑײ¡ÀýµÄСÎÒ˽¼Ò¼Í¼£¬£¬£¬£¬ÐÅÏ¢°üÀ¨Ã¿Î»»¼ÕßµÄÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚ£¬£¬£¬£¬µØµãºÍÕï¶ÏЧ¹û£¬£¬£¬£¬ÔÚijЩÇéÐÎÏ£¬£¬£¬£¬»¹°üÀ¨Éç»áÇå¾²ºÅÂë¼°Ò½ÎñÖ°Ô±µÄ¼Í¼¡£¡£¡£¡£¡£¡£Êý¾ÝËÆºõº¸ÇÁË2013Äêµ½2018Äêµ×µÄÐÂÕï¶ÏЧ¹û¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.inquirer.com/news/philadelphia-health-department-data-breach-opioids-tableau-hepatitis-20191011.html


¾©¹«Íø°²±¸11010802024551ºÅ