зì϶Dirty PipeÓ°ÏìËùÓÐÖ÷Á÷µÄLinux¿¯Ðа汾

°ä²¼¹¦·ò 2022-03-09

зì϶Dirty PipeÓ°ÏìËùÓÐÖ÷Á÷µÄLinux¿¯Ðа汾


3ÔÂ7ÈÕ £¬ £¬£¬£¬£¬£¬×êÑÐÈËÔ±Max KellermannÅû¶ÁËDirty Pipe·ì϶£¨CVE-2022-0847£©µÄϸ½Ú £¬ £¬£¬£¬£¬£¬ÒÔ¼°Ò»¸ö¸ÅÏëÑéÖ¤ (PoC) ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý×¢ÈëºÍ¸²¸ÇÖ»¶ÁÎļþÖеÄÊý¾Ý £¬ £¬£¬£¬£¬£¬»ñµÃrootȨÏÞ ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁËLinux Kernel 5.8¼°¸ü¸ß°æ±¾ £¬ £¬£¬£¬£¬£¬ÉõÖÁÔ̺¬AndroidÉ豸 ¡£¡£¡£¡£¡£¡£¡£Kellerman°µÊ¾ £¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÀàËÆÓÚ2016Ä꽨¸´µÄDirty COW·ì϶(CVE-2016-5195) ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬ £¬£¬£¬£¬£¬ËüÒÑÔÚLinuxÄÚºË5.16.11¡¢5.15.25ºÍ5.10.102Öн¨¸´ ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-linux-bug-gives-root-on-all-major-distros-exploit-released/


¿ªÔ´Ó²¼þ¹«Ë¾Adafruitǰ¹ÍԱй¶Æä¿Í»§µÄ²¿ÃÅÊý¾Ý


3ÔÂ4ÈÕ £¬ £¬£¬£¬£¬£¬¿ªÔ´Ó²¼þ¹«Ë¾AdafruitÈ·ÈÏÒ»¸ö¹«¿ªµÄGitHub´æ´¢¿âÖÐÔ̺¬Æä¿Í»§µÄ²¿ÃÅÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢Ô̺¬ÐÕÃû¡¢ÓʼþµØÖ·¡¢Õ˵¥µØÖ·¡¢¶©µ¥¾ßÌåÐÅÏ¢ºÍ¶©µ¥µÄ״̬µÈ ¡£¡£¡£¡£¡£¡£¡£ÓÐȤµÄÊÇ £¬ £¬£¬£¬£¬£¬Ð¹Â¶Êý¾Ý²¢·ÇÀ´×ÔAdafruitµÄGitHub´æ´¢¿â £¬ £¬£¬£¬£¬£¬¶øÊÇÀ´×Ըù«Ë¾µÄÒ»Ãûǰ¹ÍÔ± £¬ £¬£¬£¬£¬£¬¸ÃÔ±¹¤ÔÚÆäGitHub´æ´¢¿âÖÐʹÓÃÁËÕæÊµµÄ¿Í»§ÐÅÏ¢½øÐÐÅàѵºÍÊý¾Ý·ÖÎö²Ù×÷ ¡£¡£¡£¡£¡£¡£¡£Ä¿Ç° £¬ £¬£¬£¬£¬£¬AdafruitÒÑ֪ͨ¸ÃÔ±¹¤É¾³ýÁËÓйصÄGitHub´æ´¢¿â ¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/adafruit-discloses-data-leak-from-ex-employees-github-repo/


ASEC·¢ÏÖ¼Ù×°³É˰Îñ·¢Æ±µÄ´¹µöÓʼþ·Ö·¢Remcos RAT


      ASECÔÚ3ÔÂ7ÈÕ°ä²¼»ã±¨ £¬ £¬£¬£¬£¬£¬ÏêÊöÁ˼Ù×°³É˰Îñ·¢Æ±µÄ´¹µöÓʼþ·Ö·¢Remcos RATµÄ»î¶¯ ¡£¡£¡£¡£¡£¡£¡£´¹µöÓʼþµÄ¸½¼þTax.gz¿É±»½âѹËõ³ÉÃûΪTax.comµÄ¿ÉÖ´ÐÐÎļþ £¬ £¬£¬£¬£¬£¬ÈôÊÇÖ´Ðл·¾³ÊÇ64λ±ã»áÖ±½ÓÏÂÔØ²¢Ö´ÐжñÒâÈí¼þ £»£»£»£»£»£»²»È» £¬ £¬£¬£¬£¬£¬»áÏÂÔØÒ»¸öpowershellÎļþ3xp1r3Exp.ps1 ¡£¡£¡£¡£¡£¡£¡£powershell¾ç±¾Ô̺¬ÎªUAC BypassÏÂÔØ¸Ô¶×ãļþ(version.dll)µÄÄÚÈÝ £¬ £¬£¬£¬£¬£¬Ëü»¹»á´´½¨Ò»¸ötrickÎļþ¼Ð(Mock Directory) £¬ £¬£¬£¬£¬£¬²¢Ê¹ÓÃDLL½Ù³Ö²½Öè ¡£¡£¡£¡£¡£¡£¡£×îÖÕ £¬ £¬£¬£¬£¬£¬¸Ã»î¶¯»á×°ÖÃRemcos RAT ¡£¡£¡£¡£¡£¡£¡£


https://asec.ahnlab.com/en/32376/


Cluster25·¢ÏÖÕë¶ÔÃÀ¹úýÌåÐÐÒµ·Ö·¢RuRATµÄ´¹µö»î¶¯


      Cluster25ÔÚ3ÔÂ3ÈÕ¹«¿ªÁËÐÂÒ»ÂÖ´¹µö»î¶¯µÄ¾ßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£2ÔÂ23ÈÕ £¬ £¬£¬£¬£¬£¬ÐÂÎÅýÌå×éÖ¯BleepingComputerÊÕµ½×Ô³ÆÊÇ·çÏÕ×Êͬ×ÚµÄÓʼþ £¬ £¬£¬£¬£¬£¬Ðû³Æµ«Ô¸Í¶×Ê»ò²É°ìÊÕ¼þÈ˵ÄÍøÕ¾ ¡£¡£¡£¡£¡£¡£¡£¾­·ÖÎö £¬ £¬£¬£¬£¬£¬ÕâÊÇÒ»´ÎÓã²æÊ½´¹µö»î¶¯ ¡£¡£¡£¡£¡£¡£¡£ÓʼþÀ´×ÔÀ´×ÔÓ¢¹úÐé¹¹·þÎñÆ÷¹«Ë¾IPµØÖ· £¬ £¬£¬£¬£¬£¬²¢ÒªÇóÖ¸±êÏÂÔØVuxnerChat½øÐÐ̸Ìì ¡£¡£¡£¡£¡£¡£¡£Ò»µ©Ö¸±êµã»÷¡°ÏÂÔØVuxner¡± £¬ £¬£¬£¬£¬£¬¾Í»áÏÂÔØÃûΪVuxnerChat.exeµÄÎļþ£¨55MB£© ¡£¡£¡£¡£¡£¡£¡£Ö´ÐиÃexeÎļþºó £¬ £¬£¬£¬£¬£¬»áÊ×ÏÈ×°ÖÃÒ»¸öºÏ·¨Èí¼þTrillian £¬ £¬£¬£¬£¬£¬×îÖÕÀûÓøÃÈí¼þ×°ÖÃRuRAT ¡£¡£¡£¡£¡£¡£¡£


https://cluster25.io/2022/03/03/rurat-used-in-spear-phishing-attacks-against-media-organisations-in-united-states/


Kaspersky°ä²¼2021ϰëÄêICSÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨


3ÔÂ3ÈÕ £¬ £¬£¬£¬£¬£¬Kaspersky°ä²¼ÁË2021ϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³£¨ICS£©ÍþÐ²Ì¬ÊÆµÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£¡£»ã±¨Ö¸³ö £¬ £¬£¬£¬£¬£¬ÔÚ2021ÄêH2KasperskyÔÚICS×ܹ²×èÖ¹ÁËÀ´×Ô5230¸ö¼Ò×åµÄ20000¶à¸ö¶ñÒâÈí¼þ±äÖÖ £»£»£»£»£»£»ÖØÒªÍþвÆðÔ´ÈÔÊÇ»¥ÁªÍø £¬ £¬£¬£¬£¬£¬Æä´ÎÊÇ¿ÉÒÆ¶¯É豸ºÍµç×ÓÓʼþ¿Í»§¶Ë £»£»£»£»£»£»ÔÚICSÍÆËã»úÖмì²âµ½µÄ¼äµýÈí¼þ¡¢¶ñÒâ¾ç±¾ºÍÍøÂç´¹µöÒ³Ãæ¡¢¼ÓÃÜÇ®±Ò¿ó¹¤ºÍÀÕË÷Èí¼þµÄ°Ù·Ö±Å×ÐËùÔö³¤ £»£»£»£»£»£»Êܹ¥»÷ICSÍÆËã»úÕ¼±È×î¶àµÄµØÓòΪ¶«ÄÏÑÇ£¨47.6%£© £¬ £¬£¬£¬£¬£¬Æä´Î³¤¶ÌÖÞ£¨43.4%£©ºÍ¶«ÑÇ£¨40.5%£© ¡£¡£¡£¡£¡£¡£¡£


https://ics-cert.kaspersky.com/publications/reports/2022/03/03/threat-landscape-for-industrial-automation-systems-statistics-for-h2-2021/


Rapid7°ä²¼¹ØÓÚGitLabÖзì϶CVE-2021-4191µÄ»ã±¨


Rapid7ÔÚ3ÔÂ3ÈÕ°ä²¼ÁË¿ªÔ´DevOpsÈí¼þGitLabÖзì϶CVE-2021-4191µÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÊÇÔÚÖ´ÐÐijЩGitLab GraphQL API²éÎÊʱ¶ÌȱÉí·ÝÑéÖ¤²é³­µ¼Ö嵀 £¬ £¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÀûÓÃÆä¸´Ô­ÓëÓû§ÓйصÄÐÅÏ¢ £¬ £¬£¬£¬£¬£¬ÈçGitLabÓû§Ãû¡¢Ãû³ÆºÍµç×ÓÓʼþµØÖ·µÈ ¡£¡£¡£¡£¡£¡£¡£ËüÓ°ÏìÁË×Ô13.0ÒÔÀ´µÄGitLab°æ±¾ £¬ £¬£¬£¬£¬£¬¿ÉÓ뱩Á¦ÆÆ½âºÍƾ֤Ìî³ä¹¥»÷½áºÏʹÓà ¡£¡£¡£¡£¡£¡£¡£2ÔÂ25ÈÕ £¬ £¬£¬£¬£¬£¬GitLab°ä²¼Á˸÷ì϶µÄ½¨¸´·¨Ê½ ¡£¡£¡£¡£¡£¡£¡£


https://www.rapid7.com/blog/post/2022/03/03/cve-2021-4191-gitlab-graphql-api-user-enumeration-fixed/



°²È«¹¤¾ß


IOC Scraper


ÀûÓÃIOCPARSER·þÎñ´Ó·ÖÆçµÄ¹©¸øÉ̲©¿Í¡¢PDF ºÍ CSV ÎļþÖлñÈ¡ IOC ¡£¡£¡£¡£¡£¡£¡£


https://github.com/chaitanyakrishna/iocscraper


Chaya


Ëüͨ¹ýÒþдÊõ¡¢ÃÜÂëѧºÍѹËõÀ´± £»£»£»£»£»£»¤Óû§µÄÒþÖÔ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/xerohackcom/chaya


Ocr Recon


´Ë¹¤¾ß¿ÉÓÃÓÚʹÓà tesseract µÄ OCR Ö°ÄÜÔÚ URL ÁбíÖвéÕÒÌØ¶¨×Ö·û´® ¡£¡£¡£¡£¡£¡£¡£


https://github.com/stark0de/ocr-recon


Project Ares


»ùÓÚ Transacted Hollowing ¼¼ÊõÓà C/C++ ±àдµÄ PoC ¼ÓÔØÆ÷ ¡£¡£¡£¡£¡£¡£¡£


https://github.com/Cerbersec/Ares


Epagneul


Epagneul ÊÇÒ»¸ö¿ÉÊÓ»¯ºÍµ÷²é Windows ÊÂÎñÈÕÖ¾µÄ¹¤¾ß ¡£¡£¡£¡£¡£¡£¡£


https://github.com/jurelou/epagneul


°²È«·ÖÎö


Windows 11 °æ±¾ 22H2 È·ÈϽñÄêÍíЩʱ³½ÍƳö


https://news.softpedia.com/news/windows-11-version-22h2-confirmed-launch-later-this-year-534989.shtml


Æ»¹û±¾ÖÜ¿ÉÄÜÍÆ³ö M2 оƬ


https://news.softpedia.com/news/apple-could-launch-the-m2-chip-this-week-534990.shtml


×êÑÐÈËԹعʾÁ˶Ô̬ͬ¼ÓÃܵÄвàÐÅ·¹¥»÷


https://news.ncsu.edu/2022/03/stealing-homomorphic-encryption-data/


ÎÚ¿ËÀ¼´óÁ¿ÍøÕ¾Ôâ·ê´ó¹æÄ£¹¥»÷


https://securityaffairs.co/wordpress/128613/cyber-warfare-2/ukrainian-wordpress-sites-attacks.html


×êÑÐÈËÔ±°µÊ¾ÉÙÓÚÆß¸ö×Ö·ûµÄÃÜÂë¿É¡°Á¢¼´¡±±»ÆÆ½â


https://www.darkreading.com/attacks-breaches/8-character-passwords-can-be-cracked-in-less-than-60-minutes