¡¾°²È«Ç÷Ïò¡¿¿¨°Í˹»ù2018ÉϰëÄêÎïÁªÍøÍþвµÄÐÂÇ÷Ïò
°ä²¼¹¦·ò 2018-10-31Òò¶øÔÚÕâÀïÎÒÃÇ×êÑÐÁËÒÔÏÂÈý¸öÎÊÌâ£ºÍøÂç·¸×ï·Ö×ÓϰȾÖÇÄÜÉ豸µÄ¹¥»÷ÏòÁ¿¡¢ÄÄЩ¶ñÒâÈí¼þ±»¼ÓÔØµ½Óû§µÄϵͳÖÐÒÔ¼°×îеĽ©Ê¬ÍøÂç¶ÔÉ豸ËùÓÐÕߺÍÊܺ¦ÕßÀ´ËµÒâζ×Åʲô¡£
2016Äê ¨C 2018Ä꣬¿¨°Í˹»ù³¢ÊÔÊÒÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÁ¿
ÔÚ½«¶ñÒâÈí¼þÏÂÔØµ½ÎïÁªÍøÉ豸ÉÏʱ£¬ÍøÂç·¸×ï·Ö×ÓµÄÊ×Ñ¡ÏîÊÇMirai¼Ò×壨20.9%£©¡£
ÒÔÏÂÊÇÎÒÃǼͼµ½µÄTelnet¹¥»÷×î¶àµÄ¹ú¶ÈµÄTop 10£º
2018ÄêµÚ¶þ¼¾¶È£¬ÊÜϰȾÉ豸ÊýÁ¿µÄµØÀíÉ¢²¼
ÓÉÓÚһЩÖÇÄÜÉ豸µÄËùÓÐÕßÅú¸ÄÁËĬÈϵÄTelnetÃÜÂ벢ʹÓø´ÔÓµÄÃÜÂ룬¶øºÜ¶àÓ×¹¤¾ßµ××Ó²»Ö§³ÖÕâÖÖºÍ̸£¬Òò¶øÍøÂç·¸×ï·Ö×ÓÒ»ÏòÔÚѰÕÒеÄϰȾÏòÁ¿¡£ÕâÒ»Çé¿ö»¹Êܵ½¶ñÒâÈí¼þ¿ª·¢ÕßÖ®¼äµÄ¾ºÕùËùÍÆ¶¯£¨ËûÃÇÖ®¼äµÄ¾ºÕùµ¼ÖÂÁ˱©Á¦ÆÆ½â¹¥»÷ЧÄÜÔ½À´Ô½µÍ£©£ºÒ»µ©³É¹¦ÆÆ½âÁËTelnetÃÜÂ룬¹¥»÷Õ߾ͻá¸ü¸ÄÉ豸µÄÃÜÂë²¢×èÖ¹¶ÔTelnetµÄ½Ó¼û¡£
½©Ê¬ÍøÂçReaper¾ÍÊÇÒ»¸öʹÓá°´úÌæ¼¼Êõ¡±µÄºÜºÃµÄÀý×Ó£¬ËüÔÚ2017Äêµ×ϰȾÁËÔ¼200Íò¸öIoTÉ豸¡£¸Ã½©Ê¬ÍøÂ粢ûÓÐѡȡTelnet±©Á¦ÆÆ½â¹¥»÷£¬¶øÊÇÀûÓÃÒÑÖªµÄÈí¼þ·ì϶½øÐд«²¼£º
GoAheadÍøÂçÉãÏñ»úÖеķì϶
MVPower CCTVÉãÏñ»úÖеķì϶
Netgear ReadyNASSurveillanceÖеķì϶
Vacron NVRÖеķì϶
Netgear DGNÉ豸Öеķì϶
Linksys E1500/E2500·ÓÉÆ÷Öеķì϶
D-Link DIR-600ºÍDIR 300 ¨C HW rev B1·ÓÉÆ÷Öеķì϶
AVTechÉ豸Öеķì϶
Ó뱩Á¦ÆÆ½âÏà±È£¬ÕâÖÖ´«²¼²½ÖèÓµÓÐÒÔÏÂÀûÒæ£º
¶ÔÓû§¶øÑÔ£¬´ò²¹¶¡Ô¶±ÈÅú¸ÄÃÜÂë»ò½ûÓ÷þÎñÒª¿É¹ó¶à
ÐµĹ¥»÷£¬¾ÉµÄ¶ñÒâÈí¼þ
ϱíÊÇ2018ÄêµÚ¶þ¼¾¶È¹¥»÷ÎÒÃÇÃÛ¹ÞµÄÊÜϰȾIoTÉ豸µÄÀàÐÍÉ¢²¼£º¾ø´óÎÞÊý¹¥»÷ÒÀÈ»ÊÇÕë¶ÔTelnetºÍSSHÃÜÂëµÄ±©Á¦ÆÆ½â¹¥»÷¡£µÚÈý´ó×î³£¼ûµÄ¹¥»÷ÊÇÕë¶ÔSMB·þÎñ£¨ÎļþÔ¶³Ì½Ó¼û·þÎñ£©µÄ¹¥»÷¡£ÎÒÃÇ»¹Ã»Óй۲쵽Õë¶Ô¸Ã·þÎñµÄIoT¶ñÒâÈí¼þ¡£ÎÞÂÛÈôºÎ£¬Ä³Ð©°æ±¾µÄSMBÖÐÔ̺¬ÑϳÁµÄÒÑÖª·ì϶£¬ÈçÓÀºãÖ®À¶£¨Windows£©ºÍÓÀºãÖ®ºì£¨Linux£©¡£¾Ù¸öÀý×Ó£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þWannaCryºÍÃÅÂÞ±Ò¿ó¹¤ EternalMiner¾ÍÀûÓÃÁËÕâЩ·ì϶¡£
ÎÒÃÇÄܹ»¿´µ½£¬ÔËÐÐRouterOSµÄMikroTikÉ豸ÔÚÁбíÖÐÒ»Æï¾ø³¾£¬ÆäÔÒòÓ¦¸ÃÊÇChimay-Red·ì϶¡£
7547¶Ë¿Ú
ÁíÒ»À๥»÷ÔòÊÇÀûÓÃÁËÔËÐÐRouterOS°æ±¾6.38.4֮ϵÄMikroTik·ÓÉÆ÷Öеķì϶Chimay-Red¡£ÔÚ2018Äê3Ô£¬¸Ã¹¥»÷±»»ý¼«ÓÃÓÚ·Ö·¢Hajime¡£
ÍøÂçÉãÏñ»ú
ÍøÂç·¸×ï·Ö×ÓҲûÓкöÊÓÍøÂçÉãÏñ»ú¡£2017Äê3ÔÂ×êÑÐÈËÔ±ÔÚGoAheadÉ豸µÄÈí¼þÖз¢ÏÖÁ˼¸¸öÑϳÁµÄ·ì϶¡£ÔÚÓйØÐÅÏ¢±»Åû¶µÄÒ»¸öÔºó£¬ÀûÓÃÕâЩ·ì϶µÄGafgytºÍPersiraiľÂíбäÌå³öÏÖÁË¡£½öÔÚÒ»ÖÜÄÚ£¬ÕâЩ¶ñÒⷨʽ¾Í»ý¼«Ï°È¾ÁË57000¸öÉ豸¡£
ÖÕ¶ËÓû§Ãæ¶ÔµÄжñÒâÈí¼þºÍÍþв
DDoS¹¥»÷
ÓëÒÔǰһÑù£¬ÎïÁªÍø¶ñÒâÈí¼þµÄÖØÒªÖ÷ÕÅÊǽøÐÐDDoS¹¥»÷¡£ÊÜϰȾµÄÖÇÄÜÉ豸³ÉΪ½©Ê¬ÍøÂçµÄÒ»²¿ÃÅ£¬Æ¾¾ÝÓйغÅÁî¹¥»÷Ò»¸öÖ¸¶¨µÄµØÖ·£¬ºÄ¾¡¸ÃÖ÷»úÓÃÓÚ´¦ÖÃÕæÊµÓû§ÒªÇóµÄ×ÊÔ´ºÍÄÜÁ¦¡£Ä¾Âí¼Ò×åMirai¼°Æä±äÌ壨ÓÈÆäÊÇHajime£©ÈÔÔÚ²¿Êð´ËÀ๥»÷¡£
Õâ¿ÉÄÜÊǶÔÖÕ¶ËÓû§·çÏÕ×îÓ×µÄÇé¿öÁË¡£×Çé¿ö£¨ºÜÉÙ²úÉú£©Ò²¾ÍÊÇÊÜϰȾÉ豸µÄÕ¼ÓÐÕß±»ISPÀºÚ¡£²¢ÇÒͨ³£Çé¿öϵ¥Ò»µØ³ÁÆôÉ豸¾ÍÄܹ»¡°ÖÎÓú¡±¸ÃÉ豸¡£
¼ÓÃÜÇ®±ÒÍÚ¾ò
SatoriľÂíµÄ´´½¨Õß·¢ÁËȻһÖÖ¸üΪµó»¬ºÍ¿ÉÐеĻñÈ¡¼ÓÃÜÇ®±ÒµÄ²½Öè¡£Ëû½«ÊÜϰȾµÄIoTÉ豸×÷Ϊ½Ó¼û¸ß»úÄÜÍÆËã»úµÄÒ»ÖÖÔ¿³×£º
µÚÒ»²½£¬¹¥»÷ÕßÊ×ÏÈÊÔIJÀûÓÃÒÑÖª·ì϶ϰȾ¾¡¿ÉÄܶàµÄ·ÓÉÆ÷£¬ÕâЩ·ì϶Ô̺¬£º
CVE 2017-17215 ¨C»ªÎªHG532ϵÁзÓÉÆ÷¹Ì¼þÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶
CVE-2018-10561, CVE-2018-10562 ¨CDasan GPON·ÓÉÆ÷ÖеÄÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶ºÍËÁÒâ´úÂëÖ´Ðзì϶
CVE-2018-10088 ¨CXiongMai uc-httpd 1.0.0ÖеĻº³åÇøÒç¶Âí½Å£¬¸Ã²úÆ·±»ÓÃÓÚ²¿ÃÅÖйúÔì×÷µÄ·ÓÉÆ÷ºÍÖÇÄÜÉ豸µÄ¹Ì¼þÖÐ
Êý¾ÝÇÔÈ¡
ÔÚ2018Äê5Ô¼ì²âµ½µÄVPNFilterľÂíÔò×êÓªÆäËüµÄÖ¸±ê¡£ËüÊ×ÏÈÀ¹½ØÊÜϰȾÉ豸µÄÁ÷Á¿£¬¶øºó´ÓÖÐÌáÈ¡³ÁÒªµÄÊý¾Ý£¨Óû§Ãû¡¢ÃÜÂëµÈ£©²¢·¢Ë͵½ÍøÂç·¸×ï·Ö×ӵķþÎñÆ÷¡£ÏÂÃæÊÇVPNFilterµÄÖØÒªÖ°ÄÜ£º
×ÔÆô¶¯»úÔì¡£¸ÃľÂí½«×Ô¼ºÐ´Èë³ß¶ÈLinux´òË㹤×÷·¨Ê½crontab£¬»¹Äܹ»Åú¸ÄÉ豸µÄ·ÇÒ×ʧÐÔ´æ´¢Æ÷£¨NVRAM£©ÖеÄÅäÖÃÉèÖá£
ʹÓÃTORÓëC&C·þÎñÆ÷½øÐÐͨѶ¡£
¿ÉÄÜ×Ô»Ù²¢Ê¹É豸¡°±äש¡±¡£Ò»µ©½Ó¹Üµ½ÓйغÅÁ¸ÃľÂí¾Í»á×ÔÎÒɾ³ý²¢ÓÃÀ¬»øÊý¾Ý¸²¸Ç¹Ì¼þµÄ¹Ø¼ü²¿ÃÅ£¬¶øºó³ÁÆôÉ豸¡£
¸ÃľÂíµÄ´«²¼²½ÖèÒÀȻδ֪£ºÆä´úÂëÖÐûÓÐÔ̺¬×ÔÎÒ´«²¼»úÔì¡£ÎÞÂÛÈôºÎ£¬ÎÒÃÇÆ«²îÓÚÒÔΪËüͨ¹ýÀûÓÃÉ豸Èí¼þÖеÄÒÑÖª·ì϶À´Ï°È¾É豸¡£
µÚÒ»·Ý¹ØÓÚVPNFilterµÄ»ã±¨³ÆÆäϰȾÁËÔ¼50Íò¸öÉ豸¡£´ÓÄÇʱÆð£¬¸ü¶àµÄÉ豸±»Ï°È¾ÁË£¬²¢ÇÒÒ×Êܹ¥»÷µÄÉ豸³§ÉÌÁбí´ó´ó¼Ó³¤ÁË¡£µ½ÁùÔÂÖÐÑ®£¬ÆäÖ¸±êÔ̺¬ÒÔÏÂÆ·ÅƵÄÉ豸£º
ASUS
D-LinkHuawei
Linksys
MikroTik
Netgear
QNAP
TP-Link
Ubiquiti
Upvel
ZTE
ÓÉÓÚÕâЩ³§É̵ÄÉ豸²»½öÔÚ¹«Ë¾ÍøÂçÖÐʹÓ㬲¢ÇÒ³£±»ÓÃ×÷ÕßÓ÷ÓÉÆ÷£¬ÕâʹµÃÇé¿ö±äµÃ¸üÔã¡£
½áÂÛ
Õë¶ÔÖÇÄÜÉ豸µÄ¶ñÒâÈí¼þ²»½öÔÚÊýÁ¿ÉÏÔö³¤£¬²¢ÇÒÔÚÖÊÁ¿ÉÏÒ²ÔÚÔö³¤¡£Ô½À´Ô½¶àµÄexploits£¨·ì϶ÀûÓ÷¨Ê½£©±»ÍøÂç·¸×ï·Ö×Ó¿ª·¢³öÀ´¡£¶ø³ýÁË´«Í³µÄDDoS¹¥»÷Ö®±í£¬±»Ï°È¾µÄÉ豸»¹±»ÓÃÓÚÇÔÈ¡Ó×ÎÒÊý¾ÝºÍÍÚ¾ò¼ÓÃÜÇ®±Ò¡£
ÏÂÃæÊÇһЩÄܹ»Ô®ÊÖÏ÷¼õÖÇÄÜÉ豸ϰȾ·çÏÕµÄÓ×¼¼ÇÉ£º
¶¨ÆÚ³ÁÆôÓÐÖúÓڶϸùÒÑϰȾµÄ¶ñÒâÈí¼þ£¨Ö»¹Ü´óÎÞÊýÇé¿öÏ»¹´æÔÚÔÙ´ÎϰȾµÄ·çÏÕ£©
¶¨ÆÚ²é³ÊÇ·ñ´æÔÚа汾µÄ¹Ì¼þ²¢½øÐиüÐÂ
ʹÓø´ÔÓÃÜÂ루³¤¶ÈÖÁÉÙΪ8룬Ô̺¬´óÓ×д×Öĸ¡¢Êý×ÖºÍÌØÊâ×Ö·û£©
ÔÚ³õʼÉèÖÃʱ¸ü¸Ä³ö³§ÃÜÂ루¼´±ãÉ豸δÌáÐÑÄúÕâÑù×ö£©
ÈôÊÇ´æÔÚ¸ÃÑ¡ÏÔò¹Ø¹Ø/½ûÓò»Ê¹ÓõĶ˿ڡ£ÀýÈ磬ÈôÊÇÄú²»³ïËãͨ¹ýTelnet£¨Õ¼ÓÃTCP¶Ë¿Ú23£©Ïνӵ½Â·ÓÉÆ÷£¬Ôò×îºÃ½ûÓøö˿ÚÒÔ½µµÍ±»ÈëÇֵķçÏÕ¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/new-trends-in-the-world-of-iot-threats/87991/


¾©¹«Íø°²±¸11010802024551ºÅ