Feem ntau cov tshuaj tiv thaiv kab mob tau tawm tsam los ntawm cov cim txuas

Cov kws tshawb fawb los ntawm RACK911 Labs pom tias yuav luag tag nrho cov kab mob antivirus rau Windows, Linux thiab macOS yog qhov yooj yim rau kev tawm tsam kev tswj hwm haiv neeg thaum lub sijhawm tshem tawm cov ntaub ntawv uas malware tau kuaj pom.

Txhawm rau ua qhov kev tawm tsam, koj yuav tsum rub tawm cov ntaub ntawv uas lub antivirus pom tau tias ua phem (piv txwv li, koj tuaj yeem siv daim ntawv xeem kos npe), thiab tom qab qee lub sijhawm, tom qab lub antivirus pom cov ntaub ntawv tsis zoo, tab sis tam sim ntawd ua ntej hu rau lub luag haujlwm. rho tawm nws, hloov cov npe nrog cov ntaub ntawv nrog cov cim txuas. Hauv Windows, kom ua tiav cov txiaj ntsig zoo ib yam, kev hloov pauv cov npe yog ua los ntawm kev sib txuas cov npe. Qhov teeb meem yog tias yuav luag tag nrho cov antiviruses tsis zoo xyuas cov cim txuas thiab, ntseeg tias lawv tau rho tawm cov ntaub ntawv tsis zoo, tshem tawm cov ntaub ntawv hauv cov npe uas cov cim txuas cov ntsiab lus.

Hauv Linux thiab macOS nws tau qhia tias yuav ua li cas nyob rau hauv txoj kev no tus neeg siv tsis tsim nyog tuaj yeem rho tawm /etc/passwd lossis lwm yam ntaub ntawv kaw lus, thiab hauv Windows lub tsev qiv ntawv DDL ntawm tus kab mob nws tus kheej los thaiv nws txoj haujlwm (hauv Windows qhov kev tawm tsam tsuas yog txwv rau kev rho tawm. cov ntaub ntawv uas tam sim no tsis siv los ntawm lwm cov ntawv thov). Piv txwv li, tus neeg tawm tsam tuaj yeem tsim cov "exploit" directory thiab upload cov ntaub ntawv EpSecApiLib.dll nrog rau qhov kuaj kab mob kos npe rau hauv nws, thiab tom qab ntawd hloov cov "exploit" directory nrog qhov txuas "C:\Program Files (x86)\McAfee\ Endpoint Security\Endpoint Security" ua ntej rho tawm nws lub Platform", uas yuav ua rau kom tshem tawm cov tsev qiv ntawv EpSecApiLib.dll los ntawm cov ntawv teev tshuaj tiv thaiv kab mob. Hauv Linux thiab macos, qhov ua kom yuam kev zoo sib xws tuaj yeem ua tiav los ntawm kev hloov cov npe nrog "/ thiab lwm yam" txuas.

#! / bin / sh
rm -rf /home/user/exploit ; mkdir /home/user/exploit/
wget -q https://www.eicar.org/download/eicar.com.txt -O /home/user/exploit/passwd
thaum inotifywait -m "/home/user/exploit/passwd" | grep -m 5 "OPEN"
do
rm -rf /home/user/exploit ; ln -s /etc /home/user/exploit
ua li cas



Tsis tas li ntawd, ntau cov tshuaj tiv thaiv kab mob rau Linux thiab macOS tau pom tias siv cov npe cov ntaub ntawv xav tau thaum ua haujlwm nrog cov ntaub ntawv ib ntus hauv / tmp thiab / ntiag tug / tmp directory, uas tuaj yeem siv los ua kom muaj cai rau cov neeg siv hauv paus.

Los ntawm tam sim no, cov teeb meem twb tau kho los ntawm cov neeg muag khoom feem ntau, tab sis nws tseem ceeb heev uas cov ntawv ceeb toom thawj zaug txog qhov teeb meem raug xa mus rau cov tuam txhab thaum lub caij nplooj zeeg xyoo 2018. Txawm hais tias tsis yog txhua tus neeg muag khoom tau tso tawm qhov hloov tshiab, lawv tau muab tsawg kawg 6 lub hlis rau thaj, thiab RACK911 Labs ntseeg tias tam sim no nws muaj kev ywj pheej los nthuav tawm qhov tsis zoo. Nws tau raug sau tseg tias RACK911 Labs tau ua haujlwm los txheeb xyuas qhov tsis zoo rau lub sijhawm ntev, tab sis nws tsis xav tias nws yuav nyuaj heev rau kev ua haujlwm nrog cov npoj yaig los ntawm kev lag luam tiv thaiv kab mob vim tias qeeb hauv kev tso tawm tshiab thiab tsis quav ntsej qhov yuav tsum tau kho sai sai. teeb meem.

Cov khoom raug cuam tshuam (lub pob dawb antivirus ClamAV tsis muaj npe):

  • Linux
    • BitDefender GravityZone
    • Comodo Xaus Txoj Kev Ruaj Ntseg
    • Eset Ua Cov Ntaub Ntawv Security
    • F-Luag Linux Ruaj Ntseg
    • Kaspersy Endpoint Kev Nyab Xeeb
    • McAfee Endpoint Kev Ruaj Ntseg
    • Sophos Anti-Virus rau Linux
  • lub qhov rais
    • Avast Dawb Anti-Virus
    • Avira Cov Tshuaj Tiv Thaiv Dawb
    • BitDefender GravityZone
    • Comodo Xaus Txoj Kev Ruaj Ntseg
    • F-Qhov Kev Tiv Thaiv Kev Nyab Xeeb Hauv Computer
    • FireEye Endpoint Kev Ruaj Ntseg
    • Kev cuam tshuam X (Sophos)
    • Kaspersky Endpoint Kev Ruaj Ntseg
    • Malwarebytes rau lub Windows
    • McAfee Endpoint Kev Ruaj Ntseg
    • Panda dome
    • Webroot Luag Txhua Qhov Chaw
  • MacOS
    • AVG
    • BitDefender Tag Nrho Ruaj Ntseg
    • Eset Cyber ​​Security
    • Kaspersky Internet Security
    • McAfee Kev Tivthaiv Tagnrho
    • Microsoft Defender (BETA)
    • Norton Security
    • Sophos Tsev
    • Webroot Luag Txhua Qhov Chaw

    Tau qhov twg los: opennet.ru

Ntxiv ib saib