ืจื•ื‘ ื”ืื ื˜ื™-ื•ื™ืจื•ืกื™ื ื”ื•ืชืงืคื• ื‘ืืžืฆืขื•ืช ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื

ื—ื•ืงืจื™ื ืžืžืขื‘ื“ื•ืช RACK911 ืžืฉืš ืชืฉื•ืžืช ืœื‘ ืฉื›ืžืขื˜ ื›ืœ ื—ื‘ื™ืœื•ืช ื”ืื ื˜ื™-ื•ื™ืจื•ืก ืœ-Windows, Linux ื•-macOS ื”ื™ื• ื—ืฉื•ืคื•ืช ืœื”ืชืงืคื•ืช ื”ืžืฉืคื™ืขื•ืช ืขืœ ืชื ืื™ ื”ื’ื–ืข ื‘ืžื”ืœืš ืžื—ื™ืงืช ืงื‘ืฆื™ื ืฉื‘ื”ื ื–ื•ื”ืชื” ืชื•ื›ื ื” ื–ื“ื•ื ื™ืช.

ื›ื“ื™ ืœื‘ืฆืข ืชืงื™ืคื” ืฆืจื™ืš ืœื”ืขืœื•ืช ืงื•ื‘ืฅ ืฉื”ืื ื˜ื™-ื•ื™ืจื•ืก ืžื–ื”ื” ื›ื–ื“ื•ื ื™ (ืœืžืฉืœ ืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื—ืชื™ืžืช ื‘ื“ื™ืงื”), ื•ืœืื—ืจ ื–ืžืŸ ืžืกื•ื™ื, ืื—ืจื™ ืฉื”ืื ื˜ื™-ื•ื™ืจื•ืก ืžื–ื”ื” ืืช ื”ืงื•ื‘ืฅ ื”ื–ื“ื•ื ื™, ืื‘ืœ ืžื™ื“ ืœืคื ื™ ื”ืงืจื™ืื” ืœืคื•ื ืงืฆื™ื” ื›ื“ื™ ืœืžื—ื•ืง ืื•ืชื•, ื”ื—ืœืฃ ืืช ื”ืกืคืจื™ื™ื” ื‘ืงื•ื‘ืฅ ืขื ืงื™ืฉื•ืจ ืกืžืœื™. ื‘-Windows, ื›ื“ื™ ืœื”ืฉื™ื’ ืืช ืื•ืชื• ืืคืงื˜, ื”ื—ืœืคืช ืกืคืจื™ื•ืช ืžืชื‘ืฆืขืช ื‘ืืžืฆืขื•ืช ืฆื•ืžืช ืกืคืจื™ื•ืช. ื”ื‘ืขื™ื” ื”ื™ื ืฉื›ืžืขื˜ ื›ืœ ื”ืื ื˜ื™-ื•ื™ืจื•ืกื™ื ืœื ื‘ื“ืงื• ื›ืจืื•ื™ ืงื™ืฉื•ืจื™ื ืกื™ืžื‘ื•ืœื™ื™ื, ื•ื”ืืžื™ื ื• ืฉื”ื ืžื•ื—ืงื™ื ืงื•ื‘ืฅ ื–ื“ื•ื ื™, ืžื—ืงื• ืืช ื”ืงื•ื‘ืฅ ื‘ืกืคืจื™ื™ื” ืฉืืœื™ื” ืžืคื ื” ื”ืงื™ืฉื•ืจ ื”ืกืžืœื™.

ื‘-Linux ื•-macOS ืžื•ืฆื’ ื›ื™ืฆื“ ื‘ื“ืจืš ื–ื• ืžืฉืชืžืฉ ื—ืกืจ ื–ื›ื•ื™ื•ืช ื™ื›ื•ืœ ืœืžื—ื•ืง /etc/passwd ืื• ื›ืœ ืงื•ื‘ืฅ ืžืขืจื›ืช ืื—ืจ, ื•ื‘-Windows ืกืคืจื™ื™ืช ื”-DDL ืฉืœ ื”ืื ื˜ื™ ื•ื™ืจื•ืก ืขืฆืžื• ื›ื“ื™ ืœื—ืกื•ื ืืช ืขื‘ื•ื“ืชื• (ื‘-Windows ื”ื”ืชืงืคื” ืžื•ื’ื‘ืœืช ืจืง ืœืžื—ื™ืงื” ืงื‘ืฆื™ื ืฉืื™ื ื ื ืžืฆืื™ื ื‘ืฉื™ืžื•ืฉ ื›ืขืช ืขืœ ื™ื“ื™ ื™ื™ืฉื•ืžื™ื ืื—ืจื™ื). ืœื“ื•ื’ืžื”, ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ืฆื•ืจ ืกืคืจื™ื™ืช "ื ื™ืฆื•ืœ" ื•ืœื”ืขืœื•ืช ืœืชื•ื›ื• ืืช ื”ืงื•ื‘ืฅ EpSecApiLib.dll ืขื ื—ืชื™ืžืช ื•ื™ืจื•ืก ื‘ื“ื™ืงื”, ื•ืœืื—ืจ ืžื›ืŸ ืœื”ื—ืœื™ืฃ ืืช ืกืคืจื™ื™ืช "ื ืฆืœ" ื‘ืงื™ืฉื•ืจ "C:\Program Files (x86)\McAfee\ Endpoint Security\Endpoint Security" ืœืคื ื™ ืžื—ื™ืงืชื• Platform", ืžื” ืฉื™ื•ื‘ื™ืœ ืœื”ืกืจื” ืฉืœ ืกืคืจื™ื™ืช EpSecApiLib.dll ืžืงื˜ืœื•ื’ ื”ืื ื˜ื™-ื•ื™ืจื•ืก. ื‘ืœื™ื ื•ืงืก ื•ื‘-macos, ื ื™ืชืŸ ืœืขืฉื•ืช ื˜ืจื™ืง ื“ื•ืžื” ืขืœ ื™ื“ื™ ื”ื—ืœืคืช ื”ืกืคืจื™ื™ื” ื‘ืงื™ืฉื•ืจ "/etc".

# / Bin / sh
rm -rf /home/user/exploit ; mkdir /home/user/exploit/
wget -q https://www.eicar.org/download/eicar.com.txt -O /home/user/exploit/passwd
ื‘ืขื•ื“ inotifywait -m "/home/user/exploit/passwd" | grep -m 5 "OPEN"
do
rm -rf /home/user/exploit ; ln -s /etc /home/user/exploit
ืขืฉื”



ื™ืชืจื” ืžื›ืš, ื ืžืฆื ื›ื™ ืื ื˜ื™-ื•ื™ืจื•ืกื™ื ืจื‘ื™ื ืขื‘ื•ืจ Linux ื•-macOS ืžืฉืชืžืฉื™ื ื‘ืฉืžื•ืช ืงื‘ืฆื™ื ืฆืคื•ื™ื™ื ื‘ืขืช ืขื‘ื•ื“ื” ืขื ืงื‘ืฆื™ื ื–ืžื ื™ื™ื ื‘ืกืคืจื™ื™ืช /tmp ื•-/private/tmp, ืืฉืจ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ื ื›ื“ื™ ืœื”ืขืœื•ืช ื”ืจืฉืื•ืช ืœืžืฉืชืžืฉ ื”ืฉื•ืจืฉ.

ื‘ืฉืœื‘ ื–ื”, ื”ื‘ืขื™ื•ืช ื›ื‘ืจ ืชื•ืงื ื• ืขืœ ื™ื“ื™ ืจื•ื‘ ื”ืกืคืงื™ื, ืืš ืจืื•ื™ ืœืฆื™ื™ืŸ ื›ื™ ื”ื”ื•ื“ืขื•ืช ื”ืจืืฉื•ื ื•ืช ืขืœ ื”ื‘ืขื™ื” ื ืฉืœื—ื• ืœื™ืฆืจื ื™ื ื‘ืกืชื™ื• 2018. ืœืžืจื•ืช ืฉืœื ื›ืœ ื”ืกืคืงื™ื ืคืจืกืžื• ืขื“ื›ื•ื ื™ื, ื”ื ืงื™ื‘ืœื• ืœืคื—ื•ืช 6 ื—ื•ื“ืฉื™ื ืœืชื™ืงื•ืŸ, ื•-RACK911 Labs ืžืืžื™ื ื” ืฉื›ืขืช ื”ื™ื ื—ื•ืคืฉื™ืช ืœื—ืฉื•ืฃ ืืช ื”ืคื’ื™ืขื•ื™ื•ืช. ื™ืฆื•ื™ืŸ ื›ื™ RACK911 Labs ืขื•ื‘ื“ืช ืขืœ ื–ื™ื”ื•ื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืžื–ื” ื–ืžืŸ ืจื‘, ืืš ื”ื™ื ืœื ืฆื™ืคืชื” ืฉื™ื”ื™ื” ื›ืœ ื›ืš ืงืฉื” ืœืขื‘ื•ื“ ืขื ืขืžื™ืชื™ื ืžืชืขืฉื™ื™ืช ื”ืื ื˜ื™ ื•ื™ืจื•ืก ืขืงื‘ ืขื™ื›ื•ื‘ื™ื ื‘ืฉื—ืจื•ืจ ืขื“ื›ื•ื ื™ื ื•ื”ืชืขืœืžื•ืช ืžื”ืฆื•ืจืš ื‘ืชื™ืงื•ืŸ ืื‘ื˜ื—ื” ื“ื—ื•ืฃ ื‘ืขื™ื•ืช.

ืžื•ืฆืจื™ื ืžื•ืฉืคืขื™ื (ื—ื‘ื™ืœืช ื”ืื ื˜ื™-ื•ื™ืจื•ืก ื”ื—ื™ื ืžื™ืช ClamAV ืื™ื ื” ืžื•ืคื™ืขื” ื‘ืจืฉื™ืžื”):

  • ืœื™ื ื•ืงืก
    • BitDefender GravityZone
    • ืงื•ืžื•ื“ื• ืื‘ื˜ื—ืช ืงืฆื”
    • ืื‘ื˜ื—ืช ืฉืจืช ื”ืงื‘ืฆื™ื Eset
    • ืื‘ื˜ื—ืช ืœื™ื ื•ืงืก F-Secure
    • ืื‘ื˜ื—ืช ื ืงื•ื“ื•ืช ืงืฆื” ืฉืœ ืงืกืคืจืกื™
    • McAfee Endpoint Security
    • Sophos Anti-Virus ืœ- Linux
  • Windows
    • ืื ื˜ื™ ื•ื™ืจื•ืก ื‘ื—ื™ื ื Avast
    • ืื ื˜ื™-ื•ื™ืจื•ืก ื—ื™ื ื ืฉืœ Avira
    • BitDefender GravityZone
    • ืงื•ืžื•ื“ื• ืื‘ื˜ื—ืช ืงืฆื”
    • ื”ื’ื ืช F-Secure Computer
    • ืื‘ื˜ื—ืช ื ืงื•ื“ื•ืช ืงืฆื” ืฉืœ FireEye
    • ื™ื™ืจื˜ X (ืกื•ืคื•ืก)
    • ืื‘ื˜ื—ืช ื ืงื•ื“ื•ืช ืงืฆื” ืฉืœ ืงืกืคืจืกืงื™
    • Malwarebytes ืขื‘ื•ืจ Windows
    • McAfee Endpoint Security
    • ื›ื™ืคืช ืคื ื“ื”
    • Webroot ืžืื•ื‘ื˜ื— ื‘ื›ืœ ืžืงื•ื
  • MacOS
    • AVG
    • ื‘ื™ื˜ื—ื•ืŸ ืžื•ื—ืœื˜ ืฉืœ BitDefender
    • ืืกื˜ ืื‘ื˜ื—ืช ืกื™ื™ื‘ืจ
    • ืงืกืคืจืกืงื™ ืื™ื ื˜ืจื ื˜ ืกืงื™ื•ืจื™ื˜ื™
    • ื”ื’ื ื” ืžืงื™ืคื” ืฉืœ McAfee
    • Microsoft Defender (ื‘ื™ื˜ื)
    • ื ื•ืจื˜ื•ืŸ
    • ืกื•ืคื•ืก
    • Webroot ืžืื•ื‘ื˜ื— ื‘ื›ืœ ืžืงื•ื

    ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”