Linux Äں˷ì϶CVE-2023-6200 ¿Éµ¼Ö´úÂëÖ´ÐÐ
°ä²¼¹¦·ò 2024-01-301. Linux Äں˷ì϶CVE-2023-6200 ¿Éµ¼Ö´úÂëÖ´ÐÐ
1ÔÂ28ÈÕ£¬Linux ÄÚºËµÄ IPv6 ʵÏÖÖз¢ÏÖÁËÒ»¸öзì϶¡£¸Ãȱµã±»¼ø±ðΪ CVE-2023-6200£¬CVSS µÃ·Ö¸ß´ï 7.5£¬Â¶³öÁË ICMPv6 Êý¾Ý°ü£¨IPv6ºÍ̸µÄ¹Ø¼ü×é³É²¿ÃÅ£©´¦Öùý³ÌÖеĹؼü¾ºÕùǰÌá¡£ICMPv6 ÊÇ IPv4 ÖÐ ICMP µÄºó¼ÌÕߣ¬¶ÔÓÚÃýÎó»ã±¨ºÍÕï¶ÏÖÁ¹Ø³ÁÒª¡£ËüµÄ²Ù×÷·½Ê½Óë IPv4 ÀàËÆ£¬ÌìÉú¡°Ö¸±êÎÞ·¨´ïµ½¡±µÈÃýÎóÐÂÎÅÒÔ¼°»ØÏÔÒªÇóºÍ»Ø¸´µÈÐÅÏ¢ÐÂÎÅ¡£È»¶ø£¬ICMPv6 ÔÚ IPv6 ÖÐÍÑÓ±¶ø³ö£¬ËüʹÓöಥµØÖ·µÄÁÚ¾Ó·¢ÏÖ£¬¶ø²»ÊÇ IPv4 µÄ´øÓй㲥µØÖ·µÄ ARP¡£µ±´¦Öà ICMPv6 ·ÓÉÆ÷¹«¸æÊý¾Ý°üʱ£¬Ëùʶ´ËÍ⾺ÕùǰÌá²úÉúÔÚ Linux ÄÚºËÖС£¾ßÌåÀ´Ëµ£¬º¯Êý¡®ndisc_router_discovery()¡¯ÔÚÊÕµ½ÕâÑùµÄÊý¾Ý°üʱ±»Å²Óá£ÈôÊÇÊý¾Ý°üÔ̺¬ÓµÓÐÐÔÃüÖÜÆÚµÄ·ÓÉÐÅÏ¢£¬¡°fib6_set_expires()¡±»á½«ÆäÁ´½Óµ½¡°gc_link¡±¡£µ±¡°fib6_clean_expires()¡±È¡µÞÁ´½Ó¡°struct fib6_info¡±ÖйýÆÚµÄ¡°gc_link¡±Ê±£¬¾Í»á³öÏÖ´ËÎÊÌ⣬¿ÉÄܻᵼÖ¿ªÊͺóʹÓà (UAF) Çé¿ö¡£µ±ÆäËû¡°struct fib6_info¡±³¢ÊÔÁ´½Ó/È¡µÞÁ´½Óµ½Í³Ò»¸ö¡°gc_link¡±»ò±éÀú¡°gc_link¡±Ê±£¬¿ÉÄÜ»á²úÉúÕâÖÖÇé¿ö¡£
2. WhiteSnake InfoStealer ¶ñÒâÈí¼þͨ¹ý PyPI Èí¼þ°ü´«²¼
1ÔÂ29ÈÕ£¬ÍøÂ簲ȫ×êÑÐÈËÔ±ÔÚ¿ªÔ´ Python °üË÷Òý (PyPI) ´æ´¢¿âÖз¢ÏÖÁ˶ñÒâ°ü£¬ÕâЩ°üÔÚ Windows ϵͳÉÏ´«²¼ÃûΪWhiteSnake StealerµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£ÕâЩÔ̺¬¶ñÒâÈí¼þµÄÈí¼þ°üÃûΪ nigpal¡¢figflix¡¢telerer¡¢seGMM¡¢fbdebug¡¢sGMM¡¢myGens¡¢NewGends ºÍ TestLibs111¡£ËüÃÇÊÇÓÉÃûΪ¡°WS¡±µÄÍþвÐÐΪÕßÉÏ´«µÄ¡£Fortinet FortiGuard ³¢ÊÔÊÒÔÚÉÏÖܰ䲼µÄÒ»·Ý·ÖÎö»ã±¨ÖаµÊ¾£º¡°ÕâЩÈí¼þ°üÔÚÆä setup.py ÎļþÖй鲢ÁË Base64 ±àÂëµÄ PE Ô´´úÂë»òÆäËû Python ¾ç±¾¡£¡±¡°Æ¾¾ÝÊܺ¦ÕßÉ豸µÄ²Ù×÷ϵͳ£¬×îÖյĶñÒâ¸ºÔØ»áÔÚ×°ÖÃÕâЩ Python °üʱ±»É¾³ý²¢Ö´ÐС£¡±¹ÌÈ» Windows ϵͳϰȾÁË WhiteSnake Stealer£¬µ«ÊÜϰȾµÄ Linux Ö÷»úÈ´ÊÕµ½ÁËÖ¼ÔÚÍøÂçÐÅÏ¢µÄ Python ¾ç±¾¡£¸Ã»î¶¯ÖØÒªÕë¶Ô Windows Óû§£¬ÓëJFrog ºÍ Checkmarx È¥ÄêÅû¶µÄÏÈǰ»î¶¯³Áµþ¡£
3. ÃÀ¹ú¹ú¶È°²È«¾ÖÈÏ¿ÉÔÚûÓÐÊÚȨµÄÇé¿öϲɰ컥ÁªÍøä¯ÀÀÊý¾Ý
1ÔÂ29ÈÕ£¬ÃÀ¹ú²ÎÒéÔ±ÂÞ¶÷¡¤»³µÇ (Ron Wyden) ÉÏÖܰµÊ¾£¬ÃÀ¹ú¹ú¶È°²È«¾Ö (NSA) ÈϿɴÓÊý¾Ý¾¼ÍÈËÄÇÀï²É°ì»¥ÁªÍøä¯ÀÀ¼Í¼£¬ÒÔ¼ø±ðÃÀ¹úÈËʹÓõÄÍøÕ¾ºÍÀûÓ÷¨Ê½£¬²»È»±ØÒª·¨ÔººÅÁî¡£»³µÇÔÚ¸ø¹ú¶Èµý±¨×ܼబޱ¶ù¡¤º£¶÷˹ (Avril Haines) µÄÒ»·âÐÅÖаµÊ¾£¬¡°ÃÀ¹úµ±¾Ö²»Ó¦¸ÃÔÞÖúÒ»¸öºÚÄ»ÐÐÒµ²¢Ê¹ÆäºÏ·¨»¯£¬¸ÃÐÐÒµ¹«¿ª¼Óº¦ÃÀ¹úÈ˵ÄÒþÖÔ²»½öÊDz»Â·µÂµÄ£¬²¢ÇÒ³¤¶Ì·¨µÄ¡£¡±²ÉÈ¡´ëÊ©¡°È·±£ÃÀ¹úµý±¨»ú¹¹Ö»²É°ìÒԺϷ¨·½Ê½»ñµÃµÄÃÀ¹úÈ˵ÄÊý¾Ý¡±¡£ÓйØÓû§ä¯ÀÀϰ¹ßµÄÔªÊý¾Ý¿ÉÄÜ»á´øÀ´ÑϳÁµÄÒþÖÔ·çÏÕ£¬ÓÉÓÚÕâЩÐÅÏ¢¿ÉÓÃÓÚÆ¾¾ÝÓ×ÎÒʱʱ½Ó¼ûµÄÍøÕ¾ÍøÂçÓ×ÎÒ¾ßÌåÐÅÏ¢¡£ÃÀ¹ú¹ú¶È°²È«¾Ö°µÊ¾£¬ËüÒѾÔì¶©Á˺ϹæÔì¶È£¬²¢¡°²ÉÈ¡´ëÊ©¾¡Á¿Ï÷¼õ¶ÔÃÀ¹úÓ×ÎÒÐÅÏ¢µÄÍøÂ硱£¬²¢¡°³ÖÐø½ö»ñÈ¡Ó빤×÷ÒªÇóÓйصÄ×îÓÐЧµÄÊý¾Ý¡±¡£²»Í⣬¸Ã»ú¹¹°µÊ¾£¬Î´¾·¨ÔººÅÁËü²»»á²É°ìºÍʹÓôÓÃÀ¹úʹÓõÄÊÖ»úÍøÂçµÄµØÎ»Êý¾Ý¡£Ëü»¹°µÊ¾£¬Ëü²»Ê¹ÓôÓλÓڸùúµÄ³µÁ¾µÄÆû³µÔ¶³ÌÐÅÏ¢´¦ÖÃϵͳ»ñµÃµÄλÏàÐÅÏ¢¡£
4. ESET Éî¿Ì×êÑÐ MirrorFace ʹÓõĸ´ÔÓ¶ñÒâÈí¼þHiddenFace
1ÔÂ28ÈÕ£¬ESET µÄ¶ñÒâÈí¼þ×êÑÐÔ± Dominik Breitenbacherй©ÁËHiddenFace£¬ÕâÊÇÒ»ÖÖÓÉ MirrorFace APT ×éÖ¯¿ª·¢µÄ¸ß¶È¸´ÔӵĺóÃŶñÒâÈí¼þ¡£¸ÃºóÃÅÒ²³ÆÎª NOOPDOOR£¬ÊÇ MirrorFace ±øÆ÷¿âÖÐ×ÔӵĶñÒâÈí¼þ£¬ÆäÉè¼Æ³Áµã¹Ø×¢Ä£¿é»¯¡£ËüÖ¼ÔÚÊʸõ±Ç°µÄ²Ù×÷ÐèÒª£¬²¢Ñ¡È¡¸÷Àà·´¼ì²âºÍ·´·ÖÎö¼¼Êõ¡£HiddenFace ÒòÆäÄ£¿é»¯ÏµÍ³¶øÍÑÓ±¶ø³ö£¬ÔÊÐí¼¯³ÉÄÚÖú¯ÊýºÍ±í²¿¼ÓÔØµÄ shellcode Ä£¿é¡£ÕâЩģ¿éʹÓà AES-256-CBC ¼ÓÃÜ£¬²¢ÓëÓû§Ìض¨µÄÎļþÃû¡¢ÃÜÔ¿ºÍ³õʼ»¯ÏòÁ¿°ó¶¨£¬Ê¹Æä¸ß¶È°²È«ºÍ¸öÐÔ»¯¡£HiddenFace ʹÓÃÓòÌìÉúËã·¨ (DGA) ºÍ TCP ÉϵÄ×Ô½ç˵ºÍ̸×Ô¶¯Ïνӵ½ºÅÁîºÍ½ÚÔì (C&C) ·þÎñÆ÷¡£Ëü»¹Õ¼Óб»¶¯Í¨Ñ¶Ö°ÄÜ£¬ÕìÌýÓ²±àÂë¶Ë¿Ú²¢³ÁÐÂÅäÖà Windows ·À»ðǽÒÔÔÊÐíͨѶ¡£Í¨Ñ¶Ê¹Óà AES-128-CBC ¼ÓÃÜ£¬½øÒ»²½Õ¹Ê¾ÁËÆä¸´ÔÓµÄÉè¼Æ¡£
5. Phobos ÀÕË÷Èí¼þ±äÖÖÌáÒé¹¥»÷ ¨C FAUST
1ÔÂ25ÈÕ£¬Phobos ÀÕË÷Èí¼þϵÁÐÊÇÒ»×é³ôÃûÔ¶ÑïµÄ¶ñÒâÈí¼þ£¬Ö¼ÔÚ¼ÓÃÜÊܺ¦ÕßÍÆËã»úÉϵÄÎļþ¡£ËüÓÚ 2019 Äê³öÏÖ£¬¶ûºó²Î¼ÓÁËÂÅ´ÎÍøÂç¹¥»÷¡£ÕâÖÖÀÕË÷Èí¼þͨ³£»á¸½¼Ó´øÓÐΨһÀ©´óÃûµÄ¼ÓÃÜÎļþ£¬²¢ÒªÇóÒÔ¼ÓÃÜÇ®±ÒÖ§¸¶Êê½ðÒÔ»ñµÃ½âÃÜÃÜÔ¿¡£FortiGuard Labs ²¶»ñ²¢»ã±¨ÁË Phobos ϵÁеĶà¸öÀÕË÷Èí¼þ±äÌ壬Ô̺¬EKINGºÍ8Base¡£×î½ü£¬FortiGuard ³¢ÊÔÊÒ·¢ÏÖÁËÒ»·Ý Office Îĵµ£¬ÆäÖÐÔ̺¬Ò»¸ö VBA ¾ç±¾£¬Ö¼ÔÚ´«²¼ FAUST ÀÕË÷Èí¼þ£¨Phobos µÄÁíÒ»¸ö±äÌ壩¡£¹¥»÷ÕßÀûÓà Gitea ·þÎñ´æ´¢¶à¸öÒÔ Base64 ±àÂëµÄÎļþ£¬Ã¿¸öÎļþ¶¼Ð¯´ø¶ñÒâ¶þ½øÔìÎļþ¡£µ¹ØâЩÎļþ±»×¢ÈëϵͳÄÚ´æÊ±£¬ËüÃÇ»áÌáÒéÎļþ¼ÓÃܹ¥»÷¡£FAUST ÀÕË÷Èí¼þÊÇ Phobos ϵÁеıäÖÖ£¬ÊÇÒ»ÖÖ¶ÔÊܺ¦ÕßÍÆËã»úÉϵÄÎļþ½øÐмÓÃܵĶñÒâÈí¼þ¡£ËüÒªÇóÖ§¸¶Êê½ðÒÔ»»È¡Ìṩ½âÃÜÃÜÔ¿¡£¸ÃÀÕË÷Èí¼þ½«¡°.faust¡±À©´óÃû¸½¼Óµ½Ã¿¸ö¼ÓÃÜÎļþ£¬²¢ÔÚ¼ÓÃÜÎļþµØµãµÄĿ¼ÖÐÌìÉú info.txt ºÍ info.hta¡£ÕâЩÎļþÊÇÓë¹¥»÷Õß³ÉÁ¢ÁªÏµÒÔ½øÐÐÊê½ð½»ÉæµÄÒ»ÖÖ¼¿Á©¡£
6. Õë¶Ô JENKINS ȱµã CVE-2024-23897 °ä²¼Á˶à¸ö POC
1ÔÂ28ÈÕ£¬enkins ÊÇ×îÊ¢ÐеĿªÔ´×Ô¶¯»¯·þÎñÆ÷£¬ËüÓÉ CloudBees ºÍ Jenkins ÉçÇøÊØ»¤¡£¸Ã×Ô¶¯»¯·þÎñÆ÷Ö§³Ö¿ª·¢ÈËÔ±¹¹½¨¡¢²âÊԺͲ¿ÊðËûÃǵÄÀûÓ÷¨Ê½£¬ËüÔÚÈ«ÇòÓµº±¼ûÊ®Íò¸ö»îÔ¾×°Öã¬Õ¼Óг¬¹ý 100 ÍòÓû§¡£¸Ã¿ªÔ´Æ½Ì¨µÄÊØ»¤ÕßÒѾ½â¾öÁ˾Ÿö°²È«·ì϶£¬ÆäÖÐÔ̺¬Ò»¸ö±»×·×ÙΪ CVE-2024-23897 µÄÑϳÁȱµã£¬¸Ãȱµã¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ (RCE)¡£SonarµÄ×êÑÐÔ± Yaniv Nizry »ã±¨Á˸÷ì϶£¬ ²¢×«Ð´ÁË ¶Ô¸ÃÎÊÌâµÄ¾ßÌå·ÖÎö¡£²¢ÇÒ¶à¸ö¸ÅÏëÑéÖ¤ (PoC) Òѱ»¹«¿ª¡£¹¥»÷ÕßÄܹ»ÀÄÓà Jenkins ½ÚÔìÆ÷¹ý³ÌµÄĬÈÏ×Ö·û±àÂëÀ´¶ÁÈ¡½ÚÔìÆ÷ÎļþϵͳÉϵÄËÁÒâÎļþ¡£¾ßÓÓ×°×ÜÌå/¶ÁÈ¡¡±È¨Ï޵Ĺ¥»÷ÕßÄܹ»¶ÁÈ¡Õû¸öÎļþ£¬¶øÃ»ÓиÃȨÏ޵Ĺ¥»÷ÕßÄܹ»Æ¾¾Ý CLI ºÅÁî¶ÁÈ¡ÎļþµÄǰÈýÐС£


¾©¹«Íø°²±¸11010802024551ºÅ