Malicious ransomware nres kuaj pom ntawm Git repositories

Qhia hais txog nthwv dej ntawm kev tawm tsam tsom rau encrypting Git repositories hauv GitHub, GitLab thiab Bitbucket cov kev pabcuam. Cov neeg tawm tsam tshem tawm qhov chaw cia khoom thiab tawm lus thov kom koj xa 0.1 BTC (kwv yees li $ 700) kom rov qab tau cov ntaub ntawv los ntawm daim ntawv theej thaub qab (qhov tseeb, lawv tsuas yog ua txhaum cov lus cog tseg thiab cov ntaub ntawv yuav yog. rov qab los). Ntawm GitHub twb zoo ib yam Muaj kev txom nyem 371 repositories.

Qee cov neeg raug tsim txom tau lees paub tias siv cov passwords tsis muaj zog lossis tsis nco qab tshem tawm cov tokens los ntawm cov ntawv thov qub. Qee tus ntseeg (rau tam sim no qhov no tsuas yog kev cia siab thiab qhov kev xav tsis tau lees paub) tias yog vim li cas rau qhov xau ntawm daim ntawv pov thawj yog kev cuam tshuam ntawm daim ntawv thov SourceTree, uas muab GUI rau kev ua haujlwm nrog Git los ntawm macOS thiab Windows. Lub Peb Hlis, ob peb tseem ceeb vulnerabilities, tso cai rau koj los tswj hwm kev tswj hwm kev ua haujlwm hauv thaj chaw thaum nkag mus rau cov chaw khaws cia tswj los ntawm tus neeg tawm tsam.

Txhawm rau rov kho qhov chaw cia tom qab kev tawm tsam, tsuas yog khiav "git checkout keeb kwm / tus tswv", tom qab ntawd
nrhiav SHA hash ntawm koj qhov kev cog lus zaum kawg uas siv "git reflog" thiab rov pib dua cov kev hloov pauv hloov nrog "git reset {SHA}" hais kom ua. Yog tias koj muaj daim ntawv theej hauv zos, qhov teeb meem raug daws los ntawm kev khiav "git push origin HEAD: master -force".

Tau qhov twg los: opennet.ru

Ntxiv ib saib