Ebili nke supercomputer hacks maka ngwuputa cryptocurrency

N'ọtụtụ nnukwu ụyọkọ mgbakọ dị na ụlọ ọrụ supercomputing na UK, Germany, Switzerland na Spain, mara Usoro mbanye akụrụngwa na ntinye nke malware maka ngwupụta zoro ezo nke Monero (XMR) cryptocurrency. Nchịkọta zuru ezu nke ihe omume ahụ adịbeghị, ma dị ka data mbụ si dị, usoro ndị ahụ mebiri emebi n'ihi na-ezu ohi nke nzere site na usoro nke ndị nchọpụta nwere ike ịrụ ọrụ na ụyọkọ (na nso nso a, ọtụtụ ụyọkọ na-enye ohere ịnweta. Ndị nyocha nke atọ na-amụ SARS-CoV-2 coronavirus na-eduzi usoro ihe ngosi metụtara ọrịa COVID-19). Mgbe ha nwetachara ụyọkọ ahụ n'otu n'ime ikpe ndị ahụ, ndị mwakpo ahụ jiri adịghị ike ahụ mee ihe CVE-2019-15666 na Linux kernel iji nweta mgbọrọgwụ ma wụnye rootkit.

pụtara iche ihe omume abụọ nke ndị na-awakpo na-eji nzere ejidere n'aka ndị ọrụ na Mahadum Krakow (Poland), Shanghai Transport University (China) na Chinese Science Network. E weghaara nzere site n'aka ndị sonyere na mmemme nyocha mba ụwa wee jiri jikọọ na ụyọkọ site na SSH. Otu esi weghara nzere ndị ahụ amabeghị nke ọma, mana na sistemụ ụfọdụ (ọ bụghị ihe niile) nke ndị mgbapu okwuntughe metụtara, achọpụtara faịlụ SSH nwere ike ime.

N'ihi ya, ndị na-awakpo nwee ike nweta ohere ịnweta ụyọkọ UK (Mahadum nke Edinburgh). na-agba ụta, họọrọ 334th na Top500 nnukwu supercomputers. Ndị na-eso ụdị ntinye a bụ mara na ụyọkọ bwUniCluster 2.0 (Karlsruhe Institute of Technology, Germany), ForHLR II (Karlsruhe Institute of Technology, Germany), bwForCluster JUSTUS (Ulm University, Germany), bwForCluster BinAC (Mahadum nke Tübingen, Germany) na Hawk (Mahadum nke Stuttgart, Germany).
Ozi gbasara mmemme nchekwa ụyọkọ na National Supercomputer Center nke Switzerland (CSCS), Jülich Research Center (Ebe mbu n'elu 500), Mahadum Munich (Germany) na Ụlọ ọrụ Kọmputa Leibniz (9, 85 и 86 Ebe dị na Top500). Na mgbakwunye, site na ndị ọrụ natara Ozi gbasara nkwekọrịta nke akụrụngwa nke High Performance Computing Center na Barcelona (Spain) ekwenyebeghị n'ihu ọha.

Анализ mgbanwe
gosiri, na ebudatara faịlụ abụọ nwere ike ime ihe ọjọọ na sava ndị mebiri emebi, nke edobere ọkọlọtọ suid: "/etc/fonts/.fonts" na"/etc/fonts/.low". Nke mbụ bụ bootloader maka ịgba ọsọ iwu shei nwere ikike mgbọrọgwụ, nke abụọ bụ ihe nhicha log maka iwepu akara ọrụ ndị mwakpo. Ejila usoro dị iche iche zoo ihe ndị dị njọ, gụnyere ịwụnye rootkit. Ahịa edo, kwajuru dị ka modul maka Linux kernel. N'otu oge, usoro ngwuputa ihe malitere nanị n'abalị, ka ọ ghara ịdọrọ uche.

Ozugbo a kpọbatara ya, enwere ike iji onye ọbịa ahụ rụọ ọrụ dị iche iche, dị ka Mining Monero (XMR), na-agba ọsọ proxy (iji kparịta ụka na ndị na-egwuputa ihe ndị ọzọ na ihe nkesa na-ahazi Ngwuputa), na-agba ọsọ proxy SOCKS dabeere na microSOCKS (ịnabata mpụga. njikọ site na SSH) na mbugharị SSH (isi ebe ntinye n'ime ya site na iji akaụntụ mebiri emebi nke ahaziri onye ntụgharị okwu maka iziga na netwọk dị n'ime). Mgbe ị na-ejikọ ya na ndị ọbịa emebiela, ndị mwakpo na-eji ndị ọbịa nwere proxies SOCKS ma na-ejikọkarị ya site na Tor ma ọ bụ sistemu ndị ọzọ mebiri emebi.

isi: opennet.ru

Tinye a comment