OpenSSH ¸ßΣ·ì϶À´Ï®£¡£¡£¡OG¶«·½ÌüÌṩ½â¾ö¹æ»®
°ä²¼¹¦·ò 2024-07-037ÔÂ1ÈÕ£¬£¬OpenSSH¹Ù·½¸üÐÂÁËÒ»¸ö´æÔÚÓÚOpenSSHÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-6387£©¡£¡£¡£¸Ã·ì϶ÓÉÓÚOpenSSH·þÎñÆ÷£¨sshd£©ÖеÄÐźŴ¦Ö÷¨Ê½¾ºÕùÎÊÌ⣬£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚLinuxϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£CVSSĿǰÆÀ·Ö8.1·Ö£¬£¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì²ÉÈ¡´ëÊ©½øÐзÀ»¤¡£¡£¡£

Ŀǰ¸Ã·ì϶POC£¨¸ÅÄîÑéÖ¤´úÂ룩Òѹ«¿ª£¬£¬ËæÊ±´æÔÚ±»ÍøÂçºÚ²úÀûÓýøÐÐÍÚ¿óľÂíºÍ½©Ê¬ÍøÂçµÈ¹¥»÷ÐÐΪµÄ·çÏÕ¡£¡£¡£¸Ã·ì϶µÄ×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡£¡£¡±¡£¡£¡£
·ì϶³ÉÒò
CVE-2024-6387ÊÇOpenSSH·þÎñÖеÄÒ»¸öÑÏÖØ·ì϶£¬£¬Ó°Ïì»ùÓÚglibcµÄLinuxϵͳ¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ÔÚÎÞÐèÈÏÖ¤µÄÇé¿öÏ£¬£¬Í¨¹ý¾ºÌ¬Ç°ÌáÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£
ÈôÊǿͻ§¶ËδÔÚLoginGraceTime ÃëÄÚ£¨Ä¬ÈÏÇé¿öÏÂΪ120Ã룬£¬¾É°æOpenSSHÖÐΪ600Ã룩½øÐÐÉí·ÝÑéÖ¤£¬£¬ÔòsshdµÄSIGALRM´¦Ö÷¨Ê½½«±»Ò첽ŲÓ㬣¬µ«¸ÃÐźŴ¦Ö÷¨Ê½»áŲÓø÷Àà·Çasync-signal-safeµÄº¯Êý£¨ÀýÈçsyslog()£©£¬£¬ÍþвÕß¿ÉÀûÓø÷ì϶ÔÚ»ùÓÚglibcµÄLinuxϵͳÉÏÒÔrootÉí·ÝʵÏÖδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£¡£¡£
ÐÞ¸´½¨Òé
1¡¢¡¢Éý¼¶²¹¶¡
Ŀǰ¸Ã·ì϶ÒѾÐÞ¸´£¬£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½OpenSSH 9.8p1 ÒÔÉϰ汾¡£¡£¡£ÏÂÔØÁ´½Ó£º£º£º
https://www.openssh.com/releasenotes.html
OG¶«·½Ìü½â¾ö¹æ»®
½¨ÒéÒ»£º£º£ºOG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳÉý¼¶×îа汾
1¡¢¡¢Â©É¨6075°æ±¾
OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ6075°æ±¾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐзÇÊÚȨɨÃ裬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£6070°æ±¾Éý¼¶°üΪ607000573£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º£º£ºhttps://venustech.download.venuscloud.cn/

Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶
2¡¢¡¢Â©É¨608XϵÁа汾
OG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒÑ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐзÇÊÚȨɨÃ裬£¬Óû§Éý¼¶³ß¶È·ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃ裺£º£º
608XϵÁа汾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000126-S6080000127.svs©ɨ²å¼þ°üÏÂÔØµØÖ·£º£º£º
https://venustech.download.venuscloud.cn/
Éý¼¶ºóÒÑÖ§³Ö¸Ã·ì϶
3¡¢¡¢Â©É¨»ùÏߺ˲é
ͨ¹ýOG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ-ÅäÖú˲éÄ£¿£¿£¿é¶Ô¸Ã·ì϶ӰÏìµÄ openssh-server Èí¼þ°ü°æ±¾½øÐлñÈ¡£¬£¬Ê¹ÓÃÖÇÄÜ»¯·ÖÎöÑÐÅлúÖÆÑéÖ¤¸Ã·ì϶ÊÇ·ñ´æÔÚ£¬£¬ÈôÊÇ´æÔڸ÷ì϶½¨Òé¸üе½°²È«°æ±¾¡£¡£¡£ÈçͼËùʾ£º£º£º

»ùÏߺ˲éÒÑÖ§³Ö¸Ã·ì϶²é³ÄÜÁ¦
ÇëʹÓÃOG¶«·½ÌüÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£¡£¡£
½¨Òé¶þ£º£º£ºOG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨(ASM)ÅŲéÊÜÓ°Ïì×ʲú
OG¶«·½Ìü×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±²É¼¯²¢¸üеý±¨ÐÅÏ¢£¬£¬¶ÔÈë¿â×ʲú·ì϶OpenSSH Ô¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-6387£©½øÐÐÖÎÀí£¬£¬ÈçͼËùʾ£º£º£º

µý±¨ÖÎÀíÄ£¿£¿£¿éÒÑÈë¿âµÄOpenSSH Ô¶³Ì´úÂëÖ´Ðзì϶
×ʲúÓë´àÈõÐÔÖÎÀíÆ½Ì¨Æ¾¾Ýµý±¨ÐÅÏ¢¸üеķì϶ÊÜÓ°ÏìʵÌ广¶¨ÒÔ¼°ÏÖ³¡×ʲúÖÎÀíʵÀýµÄ°æ±¾ÐÅÏ¢½øÐÐ×Ô¶¯»¯Åöײ£¬£¬¿ÉµÚÒ»¹¦·òÉäÖÐÊܸ÷ì϶ӰÏìµÄ×ʲú£¬£¬ÈçͼËùʾ£º£º£º

µý±¨ÉäÖеÄ×ʲúÐÅÏ¢
½¨ÒéÈý£º£º£º»ùÓÚ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨½øÐйØÁª·ÖÎö
¿í´óÓû§Äܹ»Í¨¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨£¬£¬½øÐйØÁªÕ½ÊõÅäÖ㬣¬½áºÏÏÖʵ»·¾³ÖÐϵͳÈÕÖ¾ºÍ°²È«É豸µÄ¸æ¾¯ÐÅÏ¢½øÐгÖÐø¼à¿Ø£¬£¬´Ó¶ø·¢ÏÖ¡°OpenSSHÔ¶³Ì´úÂëÖ´ÐС±µÄ·ì϶ÀûÓù¥»÷ÐÐΪ¡£¡£¡£
1£©ÔÚÌ©ºÏµÄƽ̨ÖУ¬£¬Í¨¹ý´àÈõÐÔ·¢ÏÖÖ°ÄÜÕë¶Ô¡°OpenSSHÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2024-6387£©¡±·ì϶ɨÃ蹤×÷£¬£¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´Ë·ì϶ӰÏìµÄÖØÒª×ʲú£»£»£»

2£©Æ½Ì¨¡°¹ØÁª·ÖÎö¡±Ä£¿£¿£¿éÖУ¬£¬Ôö³¤¡°L2_OpenSSHÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓá±£¬£¬Í¨¹ýOG¶«·½Ìü¼ì²âÉ豸¡¢¡¢Ö¸±êÖ÷»úϵͳµÈÉ豸µÄ¸æ¾¯ÈÕÖ¾£¬£¬·¢ÏÖÍⲿ¹¥»÷ÐÐΪ£»£»£»

ͨ¹ý¶ÈÎö¹æ¶¨×Ô¶¯½«L2_OpenSSHÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓõĿÉÒÉÐÐΪԴµØÖ·Ôö³¤µ½¹Û²ìÁÐ±í¡°¸ß·çÏÕÏνӡ±ÖУ¬£¬×÷ΪÄÚ²¿µý±¨Êý¾ÝʹÓ㻣»£»
3£©Ôö³¤¡°L3_OpenSSHÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓóɹ¦¡±£¬£¬Ç°ÌáÈÕÖ¾Ãû³ÆµÈÓÚ»òÔ̺¬¡°L2_OpenSSHÔ¶³Ì´úÂëÖ´Ðзì϶ÀûÓá±£¬£¬¹¥»÷Á˾ֵÈÓÚ¡°¹¥»÷³É¹¦¡±£¬£¬Ö÷ÕŵØÖ·ÒýÓÃ×ʲú·ì϶»òÔ´µØÖ·Æ¥ÅäÍþвµý±¨£¬£¬´Ó¶øÌáÉý¹ØÁª¹æ¶¨µÄÏàÐŶȡ£¡£¡£

½¨ÒéËÄ£º£º£ºATT&CK¹¥»÷Á´Ìõ·ÖÎöÓëSOAR´ëÖý¨Òé
1¡¢¡¢ATT&CK¹¥»÷Á´·ÖÎö
ƾ¾Ý¶ÔCVE-2024-6387·ì϶µÄ¹¥»÷ÀûÓùý³Ì½øÐзÖÎö£¬£¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍ¼¼Êõ½×¶Î£¬£¬¸²¸ÇµÄTTPÔ̺¬£º£º£º
TA0001³õʼ½Ó¼û£º£º£º T1190ÀûÓÃÃæÏò¹«¼ÒµÄÀûÓ÷¨Ê½
TA0002Ö´ÐУº£º£º T1059ºÅÁîºÍ¾ç±¾Ú¹ÊÍÆ÷
TA0004ȨÏÞÌáÉý£º£º£º T1548ÀÄÓÃÌáȨ½ÚÖÆ»úÖÆ
2¡¢¡¢ ´ëÖù滮½¨ÒéºÍSOAR¾ç±¾±àÅÅ

ͨ¹ýÌ©ºÏ°²È«ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´ëÖÃÄÜÁ¦£¬£¬Õë¶Ô¸Ã·ì϶ÀûÓõĸ澯ÊÂÎñ±àÅž籾£¬£¬½øÐÐ×Ô¶¯»¯´ëÖÃ
¹ØÓÚ±±Ú¤Êý¾Ý³¢ÊÔÊÒ
±±Ú¤Êý¾Ý³¢ÊÔÊÒ×ñÊØÒÔÓû§ÐèҪΪÖÐÐÄ¡¢¡¢ÖªÊ¶¸³ÄܲúƷΪָ±êµÄÖ÷ÌâÀíÄ£¬×¨Ò»ÓÚÉî¿Ì×êÑкͿª·¢ÍøÂç¿Õ¼ä°²È«µÄ»ù´¡ÖªÊ¶¡£¡£¡£Í¨¹ýÕûºÏÍþвºÍ·ì϶µý±¨¡¢¡¢ÍøÂç¿Õ¼ä×ʲúÒÔ¼°Ôư²È«¼à²âÊý¾Ý£¬£¬Öƶ©È«ÃæµÄ°²È«·ÖÎö·À»¤Õ½Êõ£¬£¬ÒÔÂú×ãÓû§ÏÖʵ³¡¾°µÄÐèÒª¡£¡£¡£Í¬Ê±£¬£¬ÖÂÁ¦ÓÚ¹¹½¨×Ô¶¯»¯µ÷²éºÍ´ëÖÃÏìÓ¦´ëÊ©£¬£¬Ðγɳ¡¾°»¯¡¢¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ£¬£¬Îª¸÷Àలȫ²úÆ·¡¢¡¢Æ½Ì¨ºÍ°²È«ÔËÓªÌṩ׳´óµÄ֪ʶ¸³ÄÜ¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ