PillowÑϳÁ·ì϶CVE-2023-50447ÈÃPythonÏîÄ¿Ãæ¶Ô·çÏÕ
°ä²¼¹¦·ò 2024-01-231. PillowÑϳÁ·ì϶CVE-2023-50447ÈÃPythonÏîÄ¿Ãæ¶Ô·çÏÕ
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬Pillow×÷ΪºÜ¶àÏîÖ÷ÕÅ»ùʯ£¬£¬£¬£¬£¬£¬£¬×÷Ϊ Python ³ÉÏñ¿â (PIL) µÄÏÖ´ú¼Ì³ÐÕß¡£¡£¡£¡£¡£¡£¡£¸Ã¿âÒòÆä´¦Öø÷ÀàͼÏñ´¦Öù¤×÷µÄ׳´óÖ°ÄܶøÊܵ½Æ÷³Á¡£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬°²È«×êÑÐÈËÔ± Duarte Santos ×î½ü·¢ÏÖÁËÒ»¸öÑϳÁ·ì϶ CVE-2023-50447£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶µÄ CVSS ÆÀ·ÖΪ 9.0£¬£¬£¬£¬£¬£¬£¬Î»ÓÚ Pillow µÄ¡°PIL.ImageMath.¡±º¯ÊýÖС£¡£¡£¡£¡£¡£¡£¸Ãº¯ÊýÖ¼ÔÚÆÀ¹ÀÉæ¼°Í¼ÏñµÄÊýѧ±í°×ʽ£¬£¬£¬£¬£¬£¬£¬ÎÞÒâÖÐÔÊÐí½ÚÔì´«µÝ¸ø¡°»·¾³¡±²ÎÊýµÄÃÜÔ¿µÄ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£ÎÊÌâÔ´ÓÚ Pillow ÈôºÎ´¦ÖÃÕâЩ±í°×ʽ£¬£¬£¬£¬£¬£¬£¬ËüÒÀÀµÓÚ Python µÄÄÚÖá°¡±£¬£¬£¬£¬£¬£¬£¬µ«ÓµÓÐͼÏñ´¦Öõĸ½¼ÓÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£¸ÃÀûÓü¼ÊõÝÓÈÆ°Ñ³ÖÆÀ¹À¸ßµÍÎÄÒÔÔ̺¬¶ñÒâ¡°co_names¡±£¬£¬£¬£¬£¬£¬£¬´Ó¶øÈƹýÔ¤ÆÚµÄÏÞ¶È¡£¡£¡£¡£¡£¡£¡£Í¨¹ýÆæÃîµØÊ¹Óà Python µÄ dunder£¨Ë«Ï»®Ïߣ©²½Ö裬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»Å²Óà eval ¸ßµÍÎÄÖдæÔڵĶÔÏóÄÚµÄËÁÒâ²½Ö裬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£
2. SmokeLoader¶ñÒâÈí¼þÔÚÕë¶ÔÎÚ¿ËÀ¼È·µ±¾Ö»ú¹¹ºÍ¹«Ë¾
1ÔÂ19ÈÕ£¬£¬£¬£¬£¬£¬£¬AhnLab °²È«µý±¨ÖÐÐÄ (ASEC) ·¢ÏÖ¶à¸ö SmokeLoader ¶ñÒâÈí¼þÔÚ·Ö·¢¸øÎÚ¿ËÀ¼µ±¾ÖºÍ¹«Ë¾¡£¡£¡£¡£¡£¡£¡£½üÆÚÕë¶ÔÎÚ¿ËÀ¼µÄÏ®»÷ÊÂÎñËÆºõÓÐËùÔö³¤¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°È·ÈϵÄÖ¸±êÔ̺¬ÎÚ¿ËÀ¼Ë¾·¨²¿¡¢¹«¹²»ú¹¹¡¢±£ÏÕ¹«Ë¾¡¢Ò½ÁÆ»ú¹¹¡¢¹¹Öþ¹«Ë¾ºÍÔì×÷¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£¡£·Ö·¢µÄµç×ÓÓʼþ×ñÑÎÚ¿ËÀ¼ÓïÌåʽ¡£¡£¡£¡£¡£¡£¡£ÕýÎÄÔ̺¬Ó뷢ƱÓйصÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÌáÐѶÁÕßÖ´Ðи½¼þ¡£¡£¡£¡£¡£¡£¡£SmokeLoaderÊÇÒ»ÖÖÏÂÔØÆ÷¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»ÔÚÏνӵ½C&C·þÎñÆ÷ºóͨ¹ý½Ó¹ÜºÅÁîÀ´ÏÂÔØ¶î±íµÄÄ£¿£¿£¿£¿£¿é»ò¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£Ö´ÐÐʱ»á×¢Èëexplorer.exe£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ýÒÔϼú³Ì½øÐжñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¡£Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬ËüÔÚ %AppData% õè¾¶Öн«×ÔÉí¸´ÔìΪ¡°ewuabsi¡±£¬£¬£¬£¬£¬£¬£¬°µ²Ø×ÔÉí²¢ÊÚÓèϵͳÎļþÊôÐÔ¡£¡£¡£¡£¡£¡£¡£¶øºó£¬£¬£¬£¬£¬£¬£¬Ëü³¢ÊÔÏνӵ½ÏÂÃæÁгöµÄ C&C ·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÄܹ»¶î±íÏÂÔØ Lockbit ÀÕË÷Èí¼þºÍ¸÷ÀàÆäËü¶ñÒâÈí¼þ¡£¡£¡£¡£¡£¡£¡£
3. TietoevryÔâÀÕË÷Èí¼þAkira¹¥»÷µ¼ÖÂÈðµäÆóÒµºÍ³ÇÊÐÍ£µç
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬·ÒÀ¼ IT ·þÎñºÍÆóÒµÔÆÍйÜÌṩÉÌ Tietoevry Ôâ·êÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÆäλÓÚÈðµäµÄÒ»¸öÊý¾ÝÖÐÐĵÄÔÆÍйܿͻ§£¬£¬£¬£¬£¬£¬£¬¾Ý±¨Â·£¬£¬£¬£¬£¬£¬£¬Õâ´Î¹¥»÷ÊÇÓÉ Akira ÀÕË÷Èí¼þÍÅ»ïÌáÒéµÄ¡£¡£¡£¡£¡£¡£¡£Tietoevry ÊÇÒ»¼Ò·ÒÀ¼ IT ·þÎñ¹«Ë¾£¬£¬£¬£¬£¬£¬£¬ÎªÆóÒµÌṩÍйܷþÎñºÍÔÆÍйܡ£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚÈ«ÇòÕ¼ÓÐÔ¼ 24,000 ÃûÔ±¹¤£¬£¬£¬£¬£¬£¬£¬2023 ÄêÊÕÈëΪ 31 ÒÚÃÀÔª¡£¡£¡£¡£¡£¡£¡£ÀÕË÷Èí¼þ¹¥»÷¶Ô¸Ã¹«Ë¾µÄÐé¹¹»¯ºÍÖÎÀí·þÎñÆ÷½øÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬ÕâЩ·þÎñÆ÷ÓÃÓÚÍйÜÈðµä¶à¶àÆóÒµµÄÍøÕ¾»òÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£Èðµä×î´óµÄÁ¬ËøÓ°Ôº Filmstaden ÒÑÈ·ÈÏ ËûÃÇÊܵ½Õâ´Î¹¥»÷µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬Òò¶øÎÞ·¨Í¨¹ýÍøÕ¾»òÒÆ¶¯ÀûÓ÷¨Ê½ÔÚÏ߲ɰìµçӰƱ£»£»£»£»£»£»ÆäËûÊܵ½¹¥»÷Ó°ÏìµÄ¹«Ë¾Ô̺¬ÕÛ¿ÛÁãÊÛÁ¬Ëøµê Rusta¡¢Ô×ÊÁϹ©¸øÉÌ MoelvenºÍũҵ¹©¸øÉÌ Grangn?rden£¬£¬£¬£¬£¬£¬£¬ºóÕß ÔÚ IT ·þÎñ¸´ÔÆÚ¼ä±»ÆÈ ¹Ø¹ØÉ̵ꣻ£»£»£»£»£»Í£µç»¹Ó°ÏìÁËÈðµäµÄ¶à¶àµ±¾Ö»ú¹¹ºÍÊÐÕþµ±¾Ö£¬£¬£¬£¬£¬£¬£¬Ô̺¬ Statens ·þÎñÖÐÐÄ¡¢ Vellinge ÊÓ×¢ Bjuv ÊÐºÍ ÎÚÆÕÈøÀÏØ¡£¡£¡£¡£¡£¡£¡£
4. LockBitÀÕË÷Èí¼þÍÅ»ïÐû³ÆÒÑÈëÇÖÃÀ¹ú¿ì²ÍÁ¬ËøµêSubway
1ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬Subway IP LLC ÊÇÒ»¼ÒÃÀ¹ú¿ç¹ú¿ì²ÍÁ¬Ëøµê£¬£¬£¬£¬£¬£¬£¬Ö÷Óªº£µ×üɽÖÎ (subs)¡¢¾í±ý¡¢É³ÀºÍÒûÁÏ¡£¡£¡£¡£¡£¡£¡£Lockbit ÀÕË÷Èí¼þ×éÖ¯½« Subway Ôö³¤µ½Æä Tor Êý¾ÝÐ¹Â¶ÍøÕ¾µÄÊܺ¦ÕßÃûµ¥ÖУ¬£¬£¬£¬£¬£¬£¬²¢ÍþвÓÚ 2024 Äê 2 Ô 2 ÈÕ 21:44:16 UTC й¶±»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯Ðû³ÆÇÔÈ¡ÁËÊý°ÙGBµÄÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻﰵʾ£¬£¬£¬£¬£¬£¬£¬±»µÁÊý¾ÝÔ̺¬Ô±¹¤¹¤×Ê¡¢ÌØÐí¾ÓªÈ¨Ê¹Ó÷ѡ¢Ö÷ÌØÐí¾ÓªÓ¶½ðÖ§¸¶¡¢²ÍÌü½»Ò×¶îµÈ¡£¡£¡£¡£¡£¡£¡£Tor Ð¹Â¶ÍøÕ¾Éϰ䲼µÄÐÂÎÅ£º¡°×î´óµÄüɽÖÎÁ¬Ëøµê¼Ùװʲô¶¼Ã»²úÉú¡£¡£¡£¡£¡£¡£¡£ÎÒÃÇÇÔÈ¡ÁËËûÃÇµÄ SUBS ÄÚ²¿ÏµÍ³£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Êý°Ù GB µÄÊý¾ÝºÍÌØÐí¾ÓªÈ¨µÄËùÓвÆÕþÔ¤ÆÚ£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ô±¹¤¹¤×Ê¡¢ÌØÐí¾ÓªÈ¨Ê¹Ó÷ѡ¢Ö÷ÌØÐí¾ÓªÓ¶½ðÖ§¸¶¡¢²ÍÌü½»Ò×¶îµÈ¡£¡£¡£¡£¡£¡£¡£ÎÒÃǸøËûÃÇһЩ¹¦·òÀ´±£»£»£»£»£»£»¤ÕâЩÊý¾ÝÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÈôÊÇûÓУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÔ¸ÒâÏò¾ºÕùµÐÊÖÏúÊÛ¡£¡£¡£¡£¡£¡£¡£¡±
5. ×êÑÐÍŶӷ¢ÏÖÀûÓÃCVE-2023-46604µÄ¹¥»÷»î¶¯Godzilla
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬ÍøÂ簲ȫ×êÑÐÈËÔ±ÖÒ¸æËµ£¬£¬£¬£¬£¬£¬£¬ÍþвÐÐΪÕߵĻ¡°ÏÔ×ÅÔö³¤¡±£¬£¬£¬£¬£¬£¬£¬ËûÃÇ»ý¼«ÀûÓà Apache ActiveMQ ÖÐÏÖÒѽ¨²¹µÄȱµã£¬£¬£¬£¬£¬£¬£¬ÔÚÊÜϰȾµÄÖ÷»úÉÏ´«µÝ Godzilla Web shell¡£¡£¡£¡£¡£¡£¡£¸Ãshell °µ²ØÔÚδ֪µÄ¶þ½øÔìÌåʽÖУ¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚÌӱܰ²È«ºÍ»ùÓÚÊðÃûµÄɨÃ跨ʽ¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü¶þ½øÔìÎļþÌåʽδ֪£¬£¬£¬£¬£¬£¬£¬ActiveMQ µÄ JSP ÒýÇæÈÔ³ÖÐø±àÒë²¢Ö´ÐÐ Web shell¡£¡£¡£¡£¡£¡£¡£CVE-2023-46604£¨CVSS ÆÀ·Ö£º10.0£©ÊÇÖ¸Apache ActiveMQ ÖеÄÒ»¸öÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£×Ô 2023 Äê 10 ÔÂÏÂÑ®¹«¿ªÅû¶ÒÔÀ´£¬£¬£¬£¬£¬£¬£¬ËüÒѱ»¶à¸öµÐÊÖ»ý¼«ÀûÓ㬣¬£¬£¬£¬£¬£¬ÒÔ²¿ÊðÀÕË÷Èí¼þ¡¢rootkit¡¢¼ÓÃÜÇ®±Ò¿ó¹¤ºÍDDoS ½©Ê¬ÍøÂç¡£¡£¡£¡£¡£¡£¡£
6. °²È«×êÑÐÍŶӰ䲼ģ¿£¿£¿£¿£¿é»¯Ä¾ÂíZloaderбäÖֵķÖÎö»ã±¨
1ÔÂ22ÈÕ£¬£¬£¬£¬£¬£¬£¬Zloader µ®ÉúÓÚй¶µÄ Zeus Ô´´úÂ룬£¬£¬£¬£¬£¬£¬ÓÚ 2016 Äê³õ´Î³öÏÖ£¬£¬£¬£¬£¬£¬£¬Ö¸±êÊǵ¹úÒøÐС£¡£¡£¡£¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬£¬ËüµÄ»î¶¯Äܹ»×·Òäµ½ 2015 Äê¡£¡£¡£¡£¡£¡£¡£ÔÚ 2018 ÄêÖ®ºóµÄÖжÏÖ®ºó£¬£¬£¬£¬£¬£¬£¬ËüÓÚ 2019 Äêµ×ÒÔ¡°°²È»Ò¹¡±µÄÃûÒå³ÁÐÂáÈÆð£¬£¬£¬£¬£¬£¬£¬¶ÔÆäÖ°ÄÜ´øÀ´Á˳Á´óŤתºÍ¼ÓÇ¿¡£¡£¡£¡£¡£¡£¡£Zloader ´ÓÒøÐÐľÂíµ½ÀÕË÷Èí¼þ¹¥»÷¹¤¾ßµÄ¹ý³Ì·´Ó³ÁËÍøÂçÍþвµÄÊÊÓ¦ÐÔ¡£¡£¡£¡£¡£¡£¡£ÆäÑݱäÔÚ 2021 Äê 9 Ô¿ª·¢³ö 2.0.0.0 °æ±¾Ê±´ïµ½¶¥·å¡£¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÚ 2022 Äê 4 Ô½øÐÐÁËɾ³ý²Ù×÷£¬£¬£¬£¬£¬£¬£¬Zloader ÈÔÓÚ 2023 ÄêÒÔ¸ü¸´Ôӵĸüлع飬£¬£¬£¬£¬£¬£¬Õ¹Ê¾ÁËÆäµ¯ÐԺͶÔÍøÂ簲ȫµÄ³ÖÐøÍþв¡£¡£¡£¡£¡£¡£¡£Zloader µÄ×îа汾ÓÚ 2023 Äê 9 ÔÂÆðÍ·¿ª·¢£¬£¬£¬£¬£¬£¬£¬ÒýÈëÁËÏȽøµÄ»ìºÏ¼¼Êõ¡¢¸üеÄÓòÌìÉúËã·¨ºÍÓÃÓÚÍøÂçͨѶµÄ RSA ¼ÓÃÜ¡£¡£¡£¡£¡£¡£¡£ÖµÍ×ÌùÐĵÄÊÇ£¬£¬£¬£¬£¬£¬£¬¸Ã¼ÓÔØ·¨Ê½´Ë¿ÌÖ§³Ö 64 λ Windows °æ±¾£¬£¬£¬£¬£¬£¬£¬Õâ±ê־ȡÆä²Ù×÷ÄÜÁ¦µÄ³Á´óת±ä¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÑݱäÔ̺¬Ð°汾 2.1.6.0 ºÍ 2.1.7.0£¬£¬£¬£¬£¬£¬£¬Í¹ÆðÁË Zloader µÄ³ÖÐø·¢Õ¹ºÍÍþв¡£¡£¡£¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ