ื”ืชืงืคื” ืžืกื™ื‘ื™ืช ืขืœ ืฉืจืชื™ ื“ื•ืืจ ืคื’ื™ืขื™ื ืžื‘ื•ืกืกื™ Exim

ื—ื•ืงืจื™ ืื‘ื˜ื—ื” ืž-Cybereason ื”ื–ื”ื™ืจ ืžื ื”ืœื™ ืฉืจืชื™ ื“ื•ืืจ ืขืœ ื–ื™ื”ื•ื™ ื”ืชืงืคื” ืื•ื˜ื•ืžื˜ื™ืช ืžืกื™ื‘ื™ืช ืชื•ืš ื ื™ืฆื•ืœ ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2019-10149) ื‘-Exim, ื”ืชื’ืœื” ื‘ืฉื‘ื•ืข ืฉืขื‘ืจ. ื‘ืžื”ืœืš ื”ืžืชืงืคื”, ื”ืชื•ืงืคื™ื ืžืฉื™ื’ื™ื ื‘ื™ืฆื•ืข ืฉืœ ื”ืงื•ื“ ืฉืœื”ื ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื•ืžืชืงื™ื ื™ื ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช ื‘ืฉืจืช ืœื›ืจื™ื™ืช ืžื˜ื‘ืขื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ื™ื.

ืœืคื™ ื—ื•ื“ืฉ ื™ื•ื ื™ ืกืงืจ ืื•ื˜ื•ืžื˜ื™ ื—ืœืงื” ืฉืœ ืืงืกื™ื ืขื•ืžื“ ืขืœ 57.05% (ืœืคื ื™ ืฉื ื” 56.56%), Postfix ื ืžืฆื ื‘ืฉื™ืžื•ืฉ ื‘-34.52% (33.79%) ืžืฉืจืชื™ ื”ื“ื•ืืจ, Sendmail - 4.05% (4.59%), Microsoft Exchange - 0.57% (0.85%). ืขืœ ื™ื“ื™ ืขืœ ืคื™ ืฉื™ืจื•ืช Shodan ื ื•ืชืจ ืคื’ื™ืข ื‘ืคื•ื˜ื ืฆื™ื” ืœื™ื•ืชืจ ืž-3.6 ืžื™ืœื™ื•ืŸ ืฉืจืชื™ ื“ื•ืืจ ื‘ืจืฉืช ื”ื’ืœื•ื‘ืœื™ืช ืฉืœื ืขื•ื“ื›ื ื• ืœื’ืจืกื” ื”ืขื“ื›ื ื™ืช ื”ืื—ืจื•ื ื” ืฉืœ Exim 4.92. ื›-2 ืžื™ืœื™ื•ืŸ ืฉืจืชื™ื ืฉืขืœื•ืœื™ื ืœื”ื™ื•ืช ืคื’ื™ืขื™ื ื ืžืฆืื™ื ื‘ืืจืฆื•ืช ื”ื‘ืจื™ืช, 192 ืืœืฃ ื‘ืจื•ืกื™ื”. ืขืœ ื™ื“ื™ ืžื™ื“ืข ื—ื‘ืจืช RiskIQ ื›ื‘ืจ ืขื‘ืจื” ืœื’ืจืกื” 4.92 ืžืชื•ืš 70% ืžื”ืฉืจืชื™ื ืขื Exim.

ื”ืชืงืคื” ืžืกื™ื‘ื™ืช ืขืœ ืฉืจืชื™ ื“ื•ืืจ ืคื’ื™ืขื™ื ืžื‘ื•ืกืกื™ Exim

ืžื•ืžืœืฅ ืœืžื ื”ืœื™ ืžืขืจื›ืช ืœื”ืชืงื™ืŸ ื‘ื“ื—ื™ืคื•ืช ืขื“ื›ื•ื ื™ื ืฉื”ื•ื›ื ื• ืขืœ ื™ื“ื™ ืขืจื›ื•ืช ื”ืคืฆื” ื‘ืฉื‘ื•ืข ืฉืขื‘ืจ (ื“ื‘ื™ืืŸ, ืื•ื‘ื•ื ื˜ื•, openSUSE, Arch Linux, ืคื“ื•ืจื”, EPEL ืขื‘ื•ืจ RHEL/CentOS). ืื ืœืžืขืจื›ืช ื™ืฉ ื’ืจืกื” ืคื’ื™ืขื” ืฉืœ Exim (ืž-4.87 ืขื“ 4.91 ื›ื•ืœืœ), ืขืœื™ืš ืœื•ื•ื“ื ืฉื”ืžืขืจื›ืช ืœื ื›ื‘ืจ ื ืคื’ืขืช ืขืœ ื™ื“ื™ ื‘ื“ื™ืงืช crontab ืœืื™ืชื•ืจ ืฉื™ื—ื•ืช ื—ืฉื•ื“ื•ืช ื•ืœื•ื•ื“ื ืฉืื™ืŸ ืžืคืชื—ื•ืช ื ื•ืกืคื™ื ื‘-/root/. ืกืคืจื™ื™ืช ssh. ื ื™ืชืŸ ืœื”ืฆื‘ื™ืข ืขืœ ื”ืชืงืคื” ื’ื ืขืœ ื™ื“ื™ ื ื•ื›ื—ื•ืช ื‘ื™ื•ืžืŸ ื”ืคืขื™ืœื•ืช ืฉืœ ื—ื•ืžืช ื”ืืฉ ืฉืœ ื”ืžืืจื—ื™ื an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io ื•-an7kmd2wp4xo7hpr.onion.sh, ื”ืžืฉืžืฉื™ื ืœื”ื•ืจื“ืช ืชื•ื›ื ื•ืช ื–ื“ื•ื ื™ื•ืช.

ื ื™ืกื™ื•ื ื•ืช ืจืืฉื•ื ื™ื ืœืชืงื•ืฃ ืฉืจืชื™ Exim ืชื•ืงืŸ ื”-9 ื‘ื™ื•ื ื™. ืขื“ ื”ืคื™ื’ื•ืข ื‘-13 ื‘ื™ื•ื ื™ ืœืงื— ืžืกื” ืื•ืคื™. ืœืื—ืจ ื ื™ืฆื•ืœ ื”ืคื’ื™ืขื•ืช ื“ืจืš ืฉืขืจื™ื ืฉืœ tor2web, ืžื•ืจื™ื“ื™ื ืกืงืจื™ืคื˜ ืžื”ืฉื™ืจื•ืช ื”ื ืกืชืจ ืฉืœ Tor (an7kmd2wp4xo7hpr) ืฉื‘ื•ื“ืง ืืช ื ื•ื›ื—ื•ืชื• ืฉืœ OpenSSH (ืื ืœื ืกื˜ื™ื), ืžืฉื ื” ืืช ื”ื”ื’ื“ืจื•ืช ืฉืœื• (ืžืืคืฉืจ ื›ื ื™ืกื” ืœืฉื•ืจืฉ ื•ืื™ืžื•ืช ืžืคืชื—) ื•ืžื’ื“ื™ืจ ืืช ื”ืžืฉืชืžืฉ ืœ-root ืžืคืชื— RSA, ื”ืžืกืคืง ื’ื™ืฉื” ืžื•ืขื“ืคืช ืœืžืขืจื›ืช ื‘ืืžืฆืขื•ืช SSH.

ืœืื—ืจ ื”ื’ื“ืจืช ื”ื“ืœืช ื”ืื—ื•ืจื™ืช, ืกื•ืจืง ื™ืฆื™ืื•ืช ืžื•ืชืงืŸ ื‘ืžืขืจื›ืช ื›ื“ื™ ืœื–ื”ื•ืช ืฉืจืชื™ื ืคื’ื™ืขื™ื ืื—ืจื™ื. ื”ืžืขืจื›ืช ื’ื ืžื—ืคืฉืช ืžืขืจื›ื•ืช ื›ืจื™ื™ื” ืงื™ื™ืžื•ืช, ืืฉืจ ื ืžื—ืงื•ืช ืื ืžื–ื•ื”ื•ืช. ื‘ืฉืœื‘ ื”ืื—ืจื•ืŸ, ื›ื•ืจื” ืžืฉืœืš ืžื•ืจื™ื“ ื•ื ืจืฉื ื‘-crontab. ื”ื›ื•ืจื” ืžื•ืจื™ื“ ื‘ืžืกื•ื•ื” ืฉืœ ืงื•ื‘ืฅ ico (ืœืžืขืฉื” ื–ื”ื• ืืจื›ื™ื•ืŸ zip ืขื ื”ืกื™ืกืžื” "no-password"), ื”ืžื›ื™ืœ ืงื•ื‘ืฅ ื”ืคืขืœื” ื‘ืคื•ืจืžื˜ ELF ืขื‘ื•ืจ ืœื™ื ื•ืงืก ืขื Glibc 2.7+.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”