¡¾°²È«Ç÷Ïò¡¿¿¨°Í˹»ù2018ÉϰëÄêÎïÁªÍøÍþвµÄÐÂÇ÷Ïò
°ä²¼¹¦·ò 2018-10-31Òò¶øÔÚÕâÀïÎÒÃÇ×êÑÐÁËÒÔÏÂÈý¸öÎÊÌ⣺£ºÍøÂç·¸×ï·Ö×ÓϰȾÖÇÄÜÉ豸µÄ¹¥»÷ÏòÁ¿¡¢¡¢ÄÄЩ¶ñÒâÈí¼þ±»¼ÓÔØµ½Óû§µÄϵͳÖÐÒÔ¼°×îеĽ©Ê¬ÍøÂç¶ÔÉ豸ËùÓÐÕߺÍÊܺ¦ÕßÀ´ËµÒâζ×Åʲô¡£
2016Äê ¨C 2018Ä꣬£¬¿¨°Í˹»ù³¢ÊÔÊÒÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÁ¿
ÔÚ½«¶ñÒâÈí¼þÏÂÔØµ½ÎïÁªÍøÉ豸ÉÏʱ£¬£¬ÍøÂç·¸×ï·Ö×ÓµÄÊ×Ñ¡ÏîÊÇMirai¼Ò×壨20.9%£©¡£
ÒÔÏÂÊÇÎÒÃǼͼµ½µÄTelnet¹¥»÷×î¶àµÄ¹ú¶ÈµÄTop 10£º£º
2018ÄêµÚ¶þ¼¾¶È£¬£¬ÊÜϰȾÉ豸ÊýÁ¿µÄµØÀíÉ¢²¼
ÓÉÓÚһЩÖÇÄÜÉ豸µÄËùÓÐÕßÅú¸ÄÁËĬÈϵÄTelnetÃÜÂ벢ʹÓø´ÔÓµÄÃÜÂ룬£¬¶øºÜ¶àС¹¤¾ßµ××Ó²»Ö§³ÖÕâÖÖºÍ̸£¬£¬Òò¶øÍøÂç·¸×ï·Ö×ÓÒ»ÏòÔÚѰÕÒеÄϰȾÏòÁ¿¡£ÕâÒ»Çé¿ö»¹Êܵ½¶ñÒâÈí¼þ¿ª·¢ÕßÖ®¼äµÄ¾ºÕùËùÍÆ¶¯£¨ËûÃÇÖ®¼äµÄ¾ºÕùµ¼ÖÂÁ˱©Á¦ÆÆ½â¹¥»÷ЧÄÜÔ½À´Ô½µÍ£©£º£ºÒ»µ©³É¹¦ÆÆ½âÁËTelnetÃÜÂ룬£¬¹¥»÷Õ߾ͻá¸ü¸ÄÉ豸µÄÃÜÂë²¢×èÖ¹¶ÔTelnetµÄ½Ó¼û¡£
½©Ê¬ÍøÂçReaper¾ÍÊÇÒ»¸öʹÓá°´úÌæ¼¼Êõ¡±µÄºÜºÃµÄÀý×Ó£¬£¬ËüÔÚ2017Äêµ×ϰȾÁËÔ¼200Íò¸öIoTÉ豸¡£¸Ã½©Ê¬ÍøÂ粢ûÓÐѡȡTelnet±©Á¦ÆÆ½â¹¥»÷£¬£¬¶øÊÇÀûÓÃÒÑÖªµÄÈí¼þ·ì϶½øÐд«²¼£º£º
GoAheadÍøÂçÉãÏñ»úÖеķì϶
MVPower CCTVÉãÏñ»úÖеķì϶
Netgear ReadyNASSurveillanceÖеķì϶
Vacron NVRÖеķì϶
Netgear DGNÉ豸Öеķì϶
Linksys E1500/E2500·ÓÉÆ÷Öеķì϶
D-Link DIR-600ºÍDIR 300 ¨C HW rev B1·ÓÉÆ÷Öеķì϶
AVTechÉ豸Öеķì϶
Ó뱩Á¦ÆÆ½âÏà±È£¬£¬ÕâÖÖ´«²¼²½ÖèÓµÓÐÒÔÏÂÀûÒæ£º£º
¶ÔÓû§¶øÑÔ£¬£¬´ò²¹¶¡Ô¶±ÈÅú¸ÄÃÜÂë»ò½ûÓ÷þÎñÒª¿É¹ó¶à
ÐµĹ¥»÷£¬£¬¾ÉµÄ¶ñÒâÈí¼þ
ϱíÊÇ2018ÄêµÚ¶þ¼¾¶È¹¥»÷ÎÒÃÇÃÛ¹ÞµÄÊÜϰȾIoTÉ豸µÄÀàÐÍÉ¢²¼£º£º¾ø´óÎÞÊý¹¥»÷ÒÀÈ»ÊÇÕë¶ÔTelnetºÍSSHÃÜÂëµÄ±©Á¦ÆÆ½â¹¥»÷¡£µÚÈý´ó×î³£¼ûµÄ¹¥»÷ÊÇÕë¶ÔSMB·þÎñ£¨ÎļþÔ¶³Ì½Ó¼û·þÎñ£©µÄ¹¥»÷¡£ÎÒÃÇ»¹Ã»Óй۲쵽Õë¶Ô¸Ã·þÎñµÄIoT¶ñÒâÈí¼þ¡£ÎÞÂÛÈôºÎ£¬£¬Ä³Ð©°æ±¾µÄSMBÖÐÔ̺¬ÑÏÖØµÄÒÑÖª·ì϶£¬£¬ÈçÓÀºãÖ®À¶£¨Windows£©ºÍÓÀºãÖ®ºì£¨Linux£©¡£¾Ù¸öÀý×Ó£¬£¬³ôÃûÔ¶ÑïµÄÀÕË÷Èí¼þWannaCryºÍÃÅÂÞ±Ò¿ó¹¤ EternalMiner¾ÍÀûÓÃÁËÕâЩ·ì϶¡£
ÎÒÃÇÄܹ»¿´µ½£¬£¬ÔËÐÐRouterOSµÄMikroTikÉ豸ÔÚÁбíÖÐÒ»Æï¾ø³¾£¬£¬ÆäÔÒòÓ¦¸ÃÊÇChimay-Red·ì϶¡£
7547¶Ë¿Ú
ÁíÒ»À๥»÷ÔòÊÇÀûÓÃÁËÔËÐÐRouterOS°æ±¾6.38.4֮ϵÄMikroTik·ÓÉÆ÷Öеķì϶Chimay-Red¡£ÔÚ2018Äê3Ô£¬£¬¸Ã¹¥»÷±»»ý¼«ÓÃÓÚ·Ö·¢Hajime¡£
ÍøÂçÉãÏñ»ú
ÍøÂç·¸×ï·Ö×ÓҲûÓкöÊÓÍøÂçÉãÏñ»ú¡£2017Äê3ÔÂ×êÑÐÈËÔ±ÔÚGoAheadÉ豸µÄÈí¼þÖз¢ÏÖÁ˼¸¸öÑÏÖØµÄ·ì϶¡£ÔÚÓйØÐÅÏ¢±»Åû¶µÄÒ»¸öÔº󣬣¬ÀûÓÃÕâЩ·ì϶µÄGafgytºÍPersiraiľÂíбäÌå³öÏÖÁË¡£½öÔÚÒ»ÖÜÄÚ£¬£¬ÕâЩ¶ñÒⷨʽ¾Í»ý¼«Ï°È¾ÁË57000¸öÉ豸¡£
ÖÕ¶ËÓû§Ãæ¶ÔµÄжñÒâÈí¼þºÍÍþв
DDoS¹¥»÷
ÓëÒÔǰһÑù£¬£¬ÎïÁªÍø¶ñÒâÈí¼þµÄÖØÒªÖ÷ÕÅÊǽøÐÐDDoS¹¥»÷¡£ÊÜϰȾµÄÖÇÄÜÉ豸³ÉΪ½©Ê¬ÍøÂçµÄÒ»²¿ÃÅ£¬£¬Æ¾¾ÝÓйغÅÁî¹¥»÷Ò»¸öÖ¸¶¨µÄµØÖ·£¬£¬ºÄ¾¡¸ÃÖ÷»úÓÃÓÚ´¦ÖÃÕæÊµÓû§ÒªÇóµÄ×ÊÔ´ºÍÄÜÁ¦¡£Ä¾Âí¼Ò×åMirai¼°Æä±äÌ壨ÓÈÆäÊÇHajime£©ÈÔÔÚ²¿Êð´ËÀ๥»÷¡£
Õâ¿ÉÄÜÊǶÔÖÕ¶ËÓû§Î£º£º¦×îСµÄÇé¿öÁË¡£×Çé¿ö£¨ºÜÉÙ²úÉú£©Ò²¾ÍÊÇÊÜϰȾÉ豸µÄÕ¼ÓÐÕß±»ISPÀºÚ¡£²¢ÇÒͨ³£Çé¿öϵ¥Ò»µØÖØÆôÉ豸¾ÍÄܹ»¡°ÖÎÓú¡±¸ÃÉ豸¡£
¼ÓÃÜÇ®±ÒÍÚ¾ò
SatoriľÂíµÄ´´½¨Õß·¢ÁËȻһÖÖ¸üΪµó»¬ºÍ¿ÉÐеĻñÈ¡¼ÓÃÜÇ®±ÒµÄ²½Öè¡£Ëû½«ÊÜϰȾµÄIoTÉ豸×÷Ϊ½Ó¼û¸ß»úÄÜÍÆËã»úµÄÒ»ÖÖÔ¿³×£º£º
µÚÒ»²½£¬£¬¹¥»÷ÕßÊ×ÏÈÊÔIJÀûÓÃÒÑÖª·ì϶ϰȾ¾¡¿ÉÄܶàµÄ·ÓÉÆ÷£¬£¬ÕâЩ·ì϶Ô̺¬£º£º
CVE 2017-17215 ¨C»ªÎªHG532ϵÁзÓÉÆ÷¹Ì¼þÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶
CVE-2018-10561, CVE-2018-10562 ¨CDasan GPON·ÓÉÆ÷ÖеÄÉí·ÝÈÏÖ¤ÈÆ¹ý·ì϶ºÍËÁÒâ´úÂëÖ´Ðзì϶
CVE-2018-10088 ¨CXiongMai uc-httpd 1.0.0ÖеĻº³åÇøÒç³ö·ì϶£¬£¬¸Ã²úÆ·±»ÓÃÓÚ²¿ÃÅÖйúÖÆ×÷µÄ·ÓÉÆ÷ºÍÖÇÄÜÉ豸µÄ¹Ì¼þÖÐ
Êý¾ÝÇÔÈ¡
ÔÚ2018Äê5Ô¼ì²âµ½µÄVPNFilterľÂíÔò×·ÇóÆäËüµÄÖ¸±ê¡£ËüÊ×ÏÈÀ¹½ØÊÜϰȾÉ豸µÄÁ÷Á¿£¬£¬¶øºó´ÓÖÐÌáÈ¡ÖØÒªµÄÊý¾Ý£¨Óû§Ãû¡¢¡¢ÃÜÂëµÈ£©²¢·¢Ë͵½ÍøÂç·¸×ï·Ö×ӵķþÎñÆ÷¡£ÏÂÃæÊÇVPNFilterµÄÖØÒªÖ°ÄÜ£º£º
×ÔÆô¶¯»úÖÆ¡£¸ÃľÂí½«×Ô¼ºÐ´Èë³ß¶ÈLinux´òË㹤×÷·¨Ê½crontab£¬£¬»¹Äܹ»Åú¸ÄÉ豸µÄ·ÇÒ×ʧÐÔ´æ´¢Æ÷£¨NVRAM£©ÖеÄÅäÖÃÉèÖá£
ʹÓÃTORÓëC&C·þÎñÆ÷½øÐÐͨѶ¡£
¿ÉÄÜ×Ô»Ù²¢Ê¹É豸¡°±äש¡±¡£Ò»µ©½Ó¹Üµ½ÓйغÅÁ£¬¸ÃľÂí¾Í»á×ÔÎÒɾ³ý²¢ÓÃÀ¬»øÊý¾Ý¸²¸Ç¹Ì¼þµÄ¹Ø¼ü²¿ÃÅ£¬£¬¶øºóÖØÆôÉ豸¡£
¸ÃľÂíµÄ´«²¼²½ÖèÒÀȻδ֪£º£ºÆä´úÂëÖÐûÓÐÔ̺¬×ÔÎÒ´«²¼»úÖÆ¡£ÎÞÂÛÈôºÎ£¬£¬ÎÒÃÇÆ«²îÓÚÒÔΪËüͨ¹ýÀûÓÃÉ豸Èí¼þÖеÄÒÑÖª·ì϶À´Ï°È¾É豸¡£
µÚÒ»·Ý¹ØÓÚVPNFilterµÄ»ã±¨³ÆÆäϰȾÁËÔ¼50Íò¸öÉ豸¡£´ÓÄÇʱÆð£¬£¬¸ü¶àµÄÉ豸±»Ï°È¾ÁË£¬£¬²¢ÇÒÒ×Êܹ¥»÷µÄÉ豸³§ÉÌÁбí´ó´ó¼Ó³¤ÁË¡£µ½ÁùÔÂÖÐÑ®£¬£¬ÆäÖ¸±êÔ̺¬ÒÔÏÂÆ·ÅƵÄÉ豸£º£º
ASUS
D-LinkHuawei
Linksys
MikroTik
Netgear
QNAP
TP-Link
Ubiquiti
Upvel
ZTE
ÓÉÓÚÕâЩ³§É̵ÄÉ豸²»½öÔÚ¹«Ë¾ÍøÂçÖÐʹÓ㬣¬²¢ÇÒ³£±»ÓÃ×÷ÕßÓ÷ÓÉÆ÷£¬£¬ÕâʹµÃÇé¿ö±äµÃ¸üÔã¡£
½áÂÛ
Õë¶ÔÖÇÄÜÉ豸µÄ¶ñÒâÈí¼þ²»½öÔÚÊýÁ¿ÉÏÔö³¤£¬£¬²¢ÇÒÔÚÖÊÁ¿ÉÏÒ²ÔÚÔö³¤¡£Ô½À´Ô½¶àµÄexploits£¨·ì϶ÀûÓ÷¨Ê½£©±»ÍøÂç·¸×ï·Ö×Ó¿ª·¢³öÀ´¡£¶ø³ýÁË´«Í³µÄDDoS¹¥»÷Ö®Í⣬£¬±»Ï°È¾µÄÉ豸»¹±»ÓÃÓÚÇÔȡСÎÒÊý¾ÝºÍÍÚ¾ò¼ÓÃÜÇ®±Ò¡£
ÏÂÃæÊÇһЩÄܹ»Ô®ÊÖÏ÷¼õÖÇÄÜÉ豸ϰȾ·çÏÕµÄС¼¼ÇÉ£º£º
¶¨ÆÚÖØÆôÓÐÖúÓڶϸùÒÑϰȾµÄ¶ñÒâÈí¼þ£¨Ö»¹Ü´óÎÞÊýÇé¿öÏ»¹´æÔÚÔÙ´ÎϰȾµÄ·çÏÕ£©
¶¨ÆÚ²é³ÊÇ·ñ´æÔÚа汾µÄ¹Ì¼þ²¢½øÐиüÐÂ
ʹÓø´ÔÓÃÜÂ루³¤¶ÈÖÁÉÙΪ8룬£¬Ô̺¬¾Þϸд×Öĸ¡¢¡¢Êý×ÖºÍÌØÊâ×Ö·û£©
ÔÚ³õʼÉèÖÃʱ¸ü¸Ä³ö³§ÃÜÂ루¼´±ãÉ豸δÌáÐÑÄúÕâÑù×ö£©
ÈôÊÇ´æÔÚ¸ÃÑ¡Ï£¬Ôò¹Ø±Õ/½ûÓò»Ê¹ÓõĶ˿ڡ£ÀýÈ磬£¬ÈôÊÇÄú²»³ïËãͨ¹ýTelnet£¨Õ¼ÓÃTCP¶Ë¿Ú23£©Ïνӵ½Â·ÓÉÆ÷£¬£¬Ôò×îºÃ½ûÓøö˿ÚÒÔ½µµÍ±»ÈëÇֵķçÏÕ¡£
ÔÎÄÁ´½Ó£º£ºhttps://securelist.com/new-trends-in-the-world-of-iot-threats/87991/


¾©¹«Íø°²±¸11010802024551ºÅ