• Ìá½»ÐèÇó
    *
    *

    *
    *
    *
    Á¢¼´Ìá½»
    µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

    logo

      ²úÆ·Óë·þÎñ
      ½â¾ö·½°¸
      ¼¼ÊõÖ§³Ö
      ºÏ×÷·¢Õ¹
      ¹ØÓڻƽð³Ç

      ÉêÇëÊÔÓÃ
        ¡¾Ô¤¾¯¡¿ÒÔÈ«Çò VMware ESXi ·þÎñÆ÷ΪĿ±êµÄESXiArgs ÀÕË÷Èí¼þÒѵ½´ïÕ½³¡£¡£¡£¡
        ·¢²¼Ê±¼ä£º2023-02-10 ÔĶÁ´ÎÊý£º 950 ´Î
        ¸Å  ¿ö

        ½üÈÕ£¬»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ¸ù¾ÝÀÕË÷²¡¶¾ÍþвÇ鱨£¬·¢ÏÖÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄÐÂÐÍÀÕË÷Èí¼þ£¨ESXiArgs£©ÕýÔÚÈ«Çò·¶Î§ÄÚ´ó¹æÄ£´«²¥¡£¸ÃÀÕË÷Èí¼þÓÚ½ñÄê2Ô¿ªÊ¼´ó¹æÄ£³öÏÖ¡£¹¥»÷ÕßÀûÓÃÁ½Äêǰδ¾­ÐÞ²¹µÄ RCE ©¶´ CVE-2021-21974 ½«¶ñÒâÎļþ´«ÊäÖÁ ESXi µ¼Ö OpenSLP ·þÎñÖеĶÑÒç³ö£¬´Ó¶ø»ñµÃ½»»¥Ê½·ÃÎÊ£¬½èÒÔ²¿ÊðÐ嵀 ESXiArgs ÀÕË÷²¡¶¾¡£

        ©¶´ÀûÓÃ
        CVE-2021-21974©¶´Óë OpenSLP Ïà¹Ø£¬¹¥»÷ÕßÔÚ¿É·ÃÎÊ427¶Ë¿ÚµÄÌõ¼þÏ£¬¹¹Ôì¶ñÒâµÄSLPÇëÇó´¥·¢OpenSLP·þÎñÖеĶÑÒç³ö£¬´Ó¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£
        ¹úÄÚ´æÔڸé¶´Ó°ÏìµÄ·þÎñÆ÷ÊýÁ¿ÈçÏÂËùʾ£¨»ùÓÚshodanͳ¼ÆÊý¾Ý£©£º

        °æ±¾

        ÊýÁ¿Í³¼Æ

        ESXi 6.5

        715

        ESXi 6.7

        3184

        ESXi 7.0

        1271

        ESXi 6.0.0

        665

        ESXi 5.0.0
        342

        ¶ñÒâÎļþ·ÖÎö

        ESXiArgsÀÕË÷Èí¼þÔÚÊܸÐȾµÄ ESXi ·þÎñÆ÷ÉÏʹÓÃ.vmxf¡¢.vmx¡¢.vmdk¡¢.vmsd ºÍ .nvram À©Õ¹Ãû¼ÓÃÜÎļþ£¬²¢ÎªÃ¿¸ö°üº¬ÔªÊý¾Ý£¨¿ÉÄÜÐèÒª½âÃÜ£©µÄ¼ÓÃÜÎĵµ´´½¨Ò»¸ö.argsÎļþ¡£

        ËäÈ»Õâ´Î¹¥»÷±³ºóµÄÍþвÐÐΪÕßÉù³ÆÇÔÈ¡ÁËÊý¾Ý£¬µ«Ò»ÃûÊܺ¦ÕßÔÚ BleepingComputer ÂÛ̳Éϱ¨¸æËµ£¬ËûÃǵÄʼþ²¢·ÇÈç´Ë¡£

        Êܺ¦Õß»¹ÔÚËø¶¨µÄϵͳÉÏ·¢ÏÖÁËÃûΪ¡°ransom.html¡±ºÍ¡°How to Restore Your Files.html¡±µÄÊê½ðƱ¾Ý£¬Ö¸Ê¾Êܺ¦Õßͨ¹ý TOX_IDÓë¹¥»÷ÕßÈ¡µÃÁªÏµ£¬ÒÔ»Ö¸´¼ÓÃÜÎļþ»ò·ÀÖ¹Êý¾Ý±»Ð¹Â¶¡£

        ͼƬ

        ½â¾ö·½°¸

        1.ÀÕË÷·çÏÕ×Ô²é

        1)¼ì²é/store/packages/Ŀ¼ÏÂÊÇ·ñ´æÔÚvmtools.pyºóÃÅÎļþ¡£Èç¹û´æÔÚ£¬½¨ÒéÁ¢¼´É¾³ý¸ÃÎļþ¡£

        2)¼ì²é/tmp/Ŀ¼ÏÂÊÇ·ñ´æÔÚencrypt¡¢encrypt.sh¡¢public.pem¡¢motd¡¢index.htmlÎļþ£¬Èç¹û´æÔÚ£¬Ó¦¼°Ê±É¾³ý¡£

        2.ÀÕË÷´¦Öý¨Òé

        1)Á¢¼´¸ôÀëÊܸÐȾµÄ·þÎñÆ÷£¬½øÐжÏÍø

        2)ʹÓÃÊý¾Ý»Ö¸´¹¤¾ß»Ö¸´Êý¾Ý»ò֨װESXi

        ÃÀ¹úCISA·¢²¼ÁË ESXiArgs ÀÕË÷Èí¼þ»Ö¸´½Å±¾£¬Ïà¹ØÁ´½ÓÈçÏ£º


        https://github.com/cisagov/ESXiArgs-Recover

        3)ÖØ¸´¡°ÀÕË÷·çÏÕ×Բ顱²½Öè

        4)»Ö¸´Ð޸ĺóµÄ²¿·ÖÎļþ

        • ²é¿´/usr/lib/vmwareĿ¼ÏµÄindex.htmlÎļþÊÇ·ñΪÀÕË÷ÐÅ£¬Èç¹ûÊÇ£¬Á¢¼´É¾³ý¸ÃÎļþ¡£

        • ¿´/etc/Ŀ¼ÏÂÊÇ·ñ´æÔÚmotdÎļþ£¬Èç¹û´æÔÚ£¬Á¢¼´É¾³ý¡£

        3.©¶´¼Ó¹Ì

        ÔÚ ESXi ÖнûÓà OpenSLP ·þÎñ£¬»òÕßÉý¼¶ÖÁ ESXi 7.0 U2c »ò ESXi 8.0 GA£¬ESXi 7.0 U2c»ò ESXi 8.0 GA °æ±¾Ä¬ÈÏÇé¿öϽûÓø÷þÎñ¡£

        4.Êý¾Ý±¸·Ý

        Õë¶ÔÖØÒªµÄÊý¾Ý½øÐÐË«»ú±¸·Ý»òÔÆ±¸·Ý¡£

        5.°²×°»Æ½ð³ÇŵÑÇ·ÀÀÕË÷

        »Æ½ð³Çͨ¹ý¶Ô´óÁ¿ÀÕË÷²¡¶¾µÄ·ÖÎö£¬»ùÓÚÁãÐÅÈΡ¢Êذ×ÖªºÚÔ­Ôò£¬´´ÔìÐÔµØÑо¿³öÕë¶ÔÀÕË÷²¡¶¾µÄÖն˲úÆ·¡¾ÅµÑÇ·ÀÀÕË÷ϵͳ¡¿¡£ÅµÑÇ·ÀÀÕË÷ÔÚ²»¹ØÐÄ©¶´´«²¥·½Ê½µÄÇé¿öÏ£¬¿É·À»¤ÈκÎÒÑÖª»òδ֪µÄÀÕË÷²¡¶¾¡£

        ¼øÓÚÀÕË÷²¡¶¾µÄÎÞ²î±ð¹ãÆ×ÌØÕ÷£¬ÅµÑÇ·ÀÀÕË÷Ö§³Ö½«ÒÑÖª²¡¶¾¿âµ¼È룬¿ÉÏÈÆ¥Å䣬ÄÚÖò¡¶¾ÓÕ²¶¹¦ÄÜ£¬¾«È·Ê¶±ðÀÕË÷²¡¶¾µÄÈëÇֺ͸澯¡£¡¾ÅµÑÇ·ÀÀÕË÷ϵͳ¡¿ÒÑÖ§³Ö²éɱÀ¹½Ø´Ë´ÎʼþʹÓõÄESXiArgs ÀÕË÷Èí¼þ¡£

        ͼƬ

        • Îĵµ·ÀÀÕË÷

        Õë¶ÔÔ±¹¤PC¡¢·þÎñÆ÷µÄÎĵµ½øÐзÀ»¤£¬È磺ºËÐÄ»úÃÜÎĵµ¡¢ÈÕ³£°ì¹«Îĵµ¡¢¸ß¼ÛÖµÎļþ¡¢¸÷ÀàÒþ˽Îĵµ¡£

        • Êý¾Ý¿â·ÀÀÕË÷

        Õë¶ÔOracle¡¢Sql Server¡¢Mysql¡¢DB2¡¢DM¡¢ÈË´ó½ð²Ö¡¢´ïÃΡ¢ÓÅìŵÈÖ÷Á÷Êý¾Ý¿â¡¢¹ú²úÊý¾Ý¿â£¬Ö¸¶¨Êý¾Ý¿âÀàÐÍ»òÌí¼ÓÊý¾Ý¿â¿ÉÖ´ÐгÌÐò£¬ÔÊÐíÖ»ÓÐÊý¾Ý¿â±¾Éí²ÅÄܶÔÊý¾ÝÎļþ½øÐÐÐ޸ĵȲÙ×÷¡£

        • ÑÆÖÕ¶Ë·ÀÀÕË÷

        Õë¶Ô¹ã·ºÊ¹ÓÃÑÆÖն˵ĹؼüÐÔÐÐÒµ£¬ÈçÒøÐеÄATM»ú¡¢¼ÓÓÍÕ¾×ÔÖú»ú¡¢Ò½Ôº×ÔÖú²éѯ»úµÈ¡£ÔÚ±¤ÀÝģʽÏ£¬ÈκÎеÄÈí¼þ¶¼ÎÞ·¨ÔËÐУ¬ÀÕË÷Èí¼þÔËÐÐʧ°Ü£¬´Ó¶øÎÞ·¨ÆÆ»µÎļþ¡£


        Ãâ·ÑÊÔÓÃ
        ·þÎñÈÈÏß

        ÂíÉÏ×Éѯ

        400-811-3777

        »Øµ½¶¥²¿
        ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿