PillowÑϳÁ·ì϶CVE-2023-50447ÈÃPythonÏîÄ¿Ãæ¶Ô·çÏÕ

°ä²¼¹¦·ò 2024-01-23

1. PillowÑϳÁ·ì϶CVE-2023-50447ÈÃPythonÏîÄ¿Ãæ¶Ô·çÏÕ


1ÔÂ21ÈÕ£¬Pillow×÷ΪºÜ¶àÏîÖ÷ÕÅ»ùʯ£¬×÷Ϊ Python ³ÉÏñ¿â (PIL) µÄÏÖ´ú¼Ì³ÐÕß¡£¸Ã¿âÒòÆä´¦Öø÷ÀàͼÏñ´¦Öù¤×÷µÄ׳´óÖ°ÄܶøÊܵ½Æ÷³Á¡£È»¶ø£¬°²È«×êÑÐÈËÔ± Duarte Santos ×î½ü·¢ÏÖÁËÒ»¸öÑϳÁ·ì϶ CVE-2023-50447£¬¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶µÄ CVSS ÆÀ·ÖΪ 9.0£¬Î»ÓÚ Pillow µÄ¡°PIL.ImageMath.¡±º¯ÊýÖС£¸Ãº¯ÊýÖ¼ÔÚÆÀ¹ÀÉæ¼°Í¼ÏñµÄÊýѧ±í°×ʽ£¬ÎÞÒâÖÐÔÊÐí½ÚÔì´«µÝ¸ø¡°»·¾³¡±²ÎÊýµÄÃÜÔ¿µÄ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£ÎÊÌâÔ´ÓÚ Pillow ÈôºÎ´¦ÖÃÕâЩ±í°×ʽ£¬ËüÒÀÀµÓÚ Python µÄÄÚÖá°¡±£¬µ«ÓµÓÐͼÏñ´¦Öõĸ½¼ÓÖ°ÄÜ¡£¸ÃÀûÓü¼ÊõÝÓÈÆ°Ñ³ÖÆÀ¹À¸ßµÍÎÄÒÔÔ̺¬¶ñÒâ¡°co_names¡±£¬´Ó¶øÈƹýÔ¤ÆÚµÄÏÞ¶È¡£Í¨¹ýÆæÃîµØÊ¹Óà Python µÄ dunder£¨Ë«Ï»®Ïߣ©²½Ö裬¹¥»÷ÕßÄܹ»Å²Óà eval ¸ßµÍÎÄÖдæÔڵĶÔÏóÄÚµÄËÁÒâ²½Ö裬´Ó¶øµ¼Ö´úÂëÖ´ÐС£


2. SmokeLoader¶ñÒâÈí¼þÔÚÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö»ú¹¹ºÍ¹«Ë¾


1ÔÂ19ÈÕ£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ·¢ÏÖ¶à¸ö SmokeLoader ¶ñÒâÈí¼þÔÚ·Ö·¢¸øÎÚ¿ËÀ¼µ±¾ÖºÍ¹«Ë¾¡£½üÆÚÕë¶ÔÎÚ¿ËÀ¼µÄÏ®»÷ÊÂÎñËÆºõÓÐËùÔö³¤¡£Ä¿Ç°È·ÈϵÄÖ¸±êÔ̺¬ÎÚ¿ËÀ¼Ë¾·¨²¿¡¢¹«¹²»ú¹¹¡¢±£ÏÕ¹«Ë¾¡¢Ò½ÁÆ»ú¹¹¡¢¹¹Öþ¹«Ë¾ºÍÔì×÷¹«Ë¾µÈ¡£·Ö·¢µÄµç×ÓÓʼþ×ñÑ­ÎÚ¿ËÀ¼ÓïÌåʽ¡£ÕýÎÄÔ̺¬Ó뷢ƱÓйصÄÐÅÏ¢£¬ÌáÐѶÁÕßÖ´Ðи½¼þ¡£SmokeLoaderÊÇÒ»ÖÖÏÂÔØÆ÷¶ñÒâÈí¼þ£¬ËüÄܹ»ÔÚÏνӵ½C&C·þÎñÆ÷ºóͨ¹ý½Ó¹ÜºÅÁîÀ´ÏÂÔØ¶î±íµÄÄ £¿é»ò¶ñÒâÈí¼þ¡£Ö´ÐÐʱ»á×¢Èëexplorer.exe£¬²¢Í¨¹ýÒÔϼú³Ì½øÐжñÒâ»î¶¯¡£Ê×ÏÈ£¬ËüÔÚ %AppData% õè¾¶Öн«×ÔÉí¸´ÔìΪ¡°ewuabsi¡±£¬°µ²Ø×ÔÉí²¢ÊÚÓèϵͳÎļþÊôÐÔ¡£¶øºó£¬Ëü³¢ÊÔÏνӵ½ÏÂÃæÁгöµÄ C&C ·þÎñÆ÷£¬ÆäÖÐÄܹ»¶î±íÏÂÔØ Lockbit ÀÕË÷Èí¼þºÍ¸÷ÀàÆäËü¶ñÒâÈí¼þ¡£


3. TietoevryÔâÀÕË÷Èí¼þAkira¹¥»÷µ¼ÖÂÈðµäÆóÒµºÍ³ÇÊÐÍ£µç


1ÔÂ21ÈÕ£¬·ÒÀ¼ IT ·þÎñºÍÆóÒµÔÆÍйÜÌṩÉÌ Tietoevry Ôâ·êÀÕË÷Èí¼þ¹¥»÷£¬Ó°ÏìÆäλÓÚÈðµäµÄÒ»¸öÊý¾ÝÖÐÐĵÄÔÆÍйܿͻ§£¬¾Ý±¨Â·£¬Õâ´Î¹¥»÷ÊÇÓÉ Akira ÀÕË÷Èí¼þÍÅ»ïÌáÒéµÄ¡£Tietoevry ÊÇÒ»¼Ò·ÒÀ¼ IT ·þÎñ¹«Ë¾£¬ÎªÆóÒµÌṩÍйܷþÎñºÍÔÆÍйÜ¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÕ¼ÓÐÔ¼ 24,000 ÃûÔ±¹¤£¬2023 ÄêÊÕÈëΪ 31 ÒÚÃÀÔª¡£ÀÕË÷Èí¼þ¹¥»÷¶Ô¸Ã¹«Ë¾µÄÐé¹¹»¯ºÍÖÎÀí·þÎñÆ÷½øÐÐÁ˼ÓÃÜ£¬ÕâЩ·þÎñÆ÷ÓÃÓÚÍйÜÈðµä¶à¶àÆóÒµµÄÍøÕ¾»òÀûÓ÷¨Ê½¡£Èðµä×î´óµÄÁ¬ËøÓ°Ôº Filmstaden ÒÑÈ·ÈÏ ËûÃÇÊܵ½Õâ´Î¹¥»÷µÄÓ°Ï죬Òò¶øÎÞ·¨Í¨¹ýÍøÕ¾»òÒÆ¶¯ÀûÓ÷¨Ê½ÔÚÏ߲ɰìµçӰƱ£»ÆäËûÊܵ½¹¥»÷Ó°ÏìµÄ¹«Ë¾Ô̺¬ÕÛ¿ÛÁãÊÛÁ¬Ëøµê Rusta¡¢Ô­×ÊÁϹ©¸øÉÌ MoelvenºÍũҵ¹©¸øÉÌ Grangn?rden£¬ºóÕß ÔÚ IT ·þÎñ¸´Ô­ÆÚ¼ä±»ÆÈ ¹Ø¹ØÉ̵ꣻͣµç»¹Ó°ÏìÁËÈðµäµÄ¶à¶àµ±¾Ö»ú¹¹ºÍÊÐÕþµ±¾Ö£¬Ô̺¬ Statens ·þÎñÖÐÐÄ¡¢  Vellinge ÊÓ×¢  Bjuv ÊÐºÍ ÎÚÆÕÈøÀ­ÏØ¡£


4. LockBitÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒÑÈëÇÖÃÀ¹ú¿ì²ÍÁ¬ËøµêSubway


1ÔÂ21ÈÕ£¬Subway IP LLC ÊÇÒ»¼ÒÃÀ¹ú¿ç¹ú¿ì²ÍÁ¬Ëøµê£¬Ö÷Óªº£µ×ÈýÃ÷ÖÎ (subs)¡¢¾í±ý¡¢É³À­ºÍÒûÁÏ¡£Lockbit ÀÕË÷Èí¼þ×éÖ¯½« Subway Ôö³¤µ½Æä Tor Êý¾ÝÐ¹Â¶ÍøÕ¾µÄÊܺ¦ÕßÃûµ¥ÖУ¬²¢ÍþвÓÚ 2024 Äê 2 Ô 2 ÈÕ 21:44:16 UTC й¶±»µÁÊý¾Ý¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡ÁËÊý°ÙGBµÄÃô¸ÐÊý¾Ý¡£¸ÃÍŻﰵʾ£¬±»µÁÊý¾ÝÔ̺¬Ô±¹¤¹¤×Ê¡¢ÌØÐí¾­ÓªÈ¨Ê¹Ó÷ѡ¢Ö÷ÌØÐí¾­ÓªÓ¶½ðÖ§¸¶¡¢²ÍÌü½»Ò×¶îµÈ¡£Tor Ð¹Â¶ÍøÕ¾Éϰ䲼µÄÐÂÎÅ£º¡°×î´óµÄÈýÃ÷ÖÎÁ¬Ëøµê¼Ùװʲô¶¼Ã»²úÉú¡£ÎÒÃÇÇÔÈ¡ÁËËûÃÇµÄ SUBS ÄÚ²¿ÏµÍ³£¬ÆäÖÐÔ̺¬Êý°Ù GB µÄÊý¾ÝºÍÌØÐí¾­ÓªÈ¨µÄËùÓвÆÕþÔ¤ÆÚ£¬Ô̺¬Ô±¹¤¹¤×Ê¡¢ÌØÐí¾­ÓªÈ¨Ê¹Ó÷ѡ¢Ö÷ÌØÐí¾­ÓªÓ¶½ðÖ§¸¶¡¢²ÍÌü½»Ò×¶îµÈ¡£ÎÒÃǸøËûÃÇһЩ¹¦·òÀ´±£»¤ÕâЩÊý¾ÝÊý¾Ý£¬ÈôÊÇûÓУ¬ÎÒÃÇÔ¸ÒâÏò¾ºÕùµÐÊÖÏúÊÛ¡£¡± 


5. ×êÑÐÍŶӷ¢ÏÖÀûÓÃCVE-2023-46604µÄ¹¥»÷»î¶¯Godzilla


1ÔÂ22ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±ÖÒ¸æËµ£¬ÍþвÐÐΪÕߵĻ¡°ÏÔ×ÅÔö³¤¡±£¬ËûÃÇ»ý¼«ÀûÓà Apache ActiveMQ ÖÐÏÖÒѽ¨²¹µÄȱµã£¬ÔÚÊÜϰȾµÄÖ÷»úÉÏ´«µÝ Godzilla Web shell¡£¸Ãshell °µ²ØÔÚδ֪µÄ¶þ½øÔìÌåʽÖУ¬Ö¼ÔÚÌӱܰ²È«ºÍ»ùÓÚÊðÃûµÄɨÃ跨ʽ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬Ö»¹Ü¶þ½øÔìÎļþÌåʽδ֪£¬ActiveMQ µÄ JSP ÒýÇæÈÔ³ÖÐø±àÒë²¢Ö´ÐÐ Web shell¡£CVE-2023-46604£¨CVSS ÆÀ·Ö£º10.0£©ÊÇÖ¸Apache ActiveMQ ÖеÄÒ»¸öÑϳÁ·ì϶£¬¸Ã·ì϶¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС£×Ô 2023 Äê 10 ÔÂÏÂÑ®¹«¿ªÅû¶ÒÔÀ´£¬ËüÒѱ»¶à¸öµÐÊÖ»ý¼«ÀûÓã¬ÒÔ²¿ÊðÀÕË÷Èí¼þ¡¢rootkit¡¢¼ÓÃÜÇ®±Ò¿ó¹¤ºÍDDoS ½©Ê¬ÍøÂç¡£


6. °²È«×êÑÐÍŶӰ䲼Ä £¿é»¯Ä¾ÂíZloaderбäÖֵķÖÎö»ã±¨


1ÔÂ22ÈÕ£¬Zloader µ®ÉúÓÚй¶µÄ Zeus Ô´´úÂ룬ÓÚ 2016 Äê³õ´Î³öÏÖ£¬Ö¸±êÊǵ¹úÒøÐС£È»¶ø£¬ËüµÄ»î¶¯Äܹ»×·Òäµ½ 2015 Äê¡£ÔÚ 2018 ÄêÖ®ºóµÄÖжÏÖ®ºó£¬ËüÓÚ 2019 Äêµ×ÒÔ¡°°²È»Ò¹¡±µÄÃûÒå³ÁÐÂáÈÆð£¬¶ÔÆäÖ°ÄÜ´øÀ´Á˳Á´óŤתºÍ¼ÓÇ¿¡£Zloader ´ÓÒøÐÐľÂíµ½ÀÕË÷Èí¼þ¹¥»÷¹¤¾ßµÄ¹ý³Ì·´Ó³ÁËÍøÂçÍþвµÄÊÊÓ¦ÐÔ¡£ÆäÑݱäÔÚ 2021 Äê 9 Ô¿ª·¢³ö 2.0.0.0 °æ±¾Ê±´ïµ½¶¥·å¡£Ö»¹ÜÔÚ 2022 Äê 4 Ô½øÐÐÁËɾ³ý²Ù×÷£¬Zloader ÈÔÓÚ 2023 ÄêÒÔ¸ü¸´Ôӵĸüлع飬չʾÁËÆäµ¯ÐԺͶÔÍøÂ簲ȫµÄ³ÖÐøÍþв¡£Zloader µÄ×îа汾ÓÚ 2023 Äê 9 ÔÂÆðÍ·¿ª·¢£¬ÒýÈëÁËÏȽøµÄ»ìºÏ¼¼Êõ¡¢¸üеÄÓòÌìÉúËã·¨ºÍÓÃÓÚÍøÂçͨѶµÄ RSA ¼ÓÃÜ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¸Ã¼ÓÔØ·¨Ê½´Ë¿ÌÖ§³Ö 64 λ Windows °æ±¾£¬Õâ±ê־ȡÆä²Ù×÷ÄÜÁ¦µÄ³Á´óת±ä¡£Õâ´ÎÑݱäÔ̺¬Ð°汾 2.1.6.0 ºÍ 2.1.7.0£¬Í¹ÆðÁË Zloader µÄ³ÖÐø·¢Õ¹ºÍÍþв¡£