ืคื’ื™ืขื•ืช ื”ื ื™ืชื ืช ืœื ื™ืฆื•ืœ ืžืจื—ื•ืง ื‘ืกื•ื›ืŸ OMI ืฉื ื›ืคื” ื‘ืกื‘ื™ื‘ื•ืช Linux ืฉืœ Microsoft Azure

ืœืงื•ื—ื•ืช ืฉืœ ืคืœื˜ืคื•ืจืžืช ื”ืขื ืŸ ืฉืœ Microsoft Azure ื”ืžืฉืชืžืฉื™ื ื‘-Linux ื‘ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ื ืชืงืœื• ื‘ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2021-38647) ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืžืจื—ื•ืง ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื”ืคื’ื™ืขื•ืช ืงื™ื‘ืœื” ืืช ืฉื ื”ืงื•ื“ OMIGOD ื•ื”ื™ื ื‘ื•ืœื˜ืช ื‘ืขื•ื‘ื“ื” ืฉื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ืืคืœื™ืงืฆื™ื™ืช OMI Agent, ื”ืžื•ืชืงื ืช ื‘ืฉืงื˜ ื‘ืกื‘ื™ื‘ื•ืช ืœื™ื ื•ืงืก.

OMI Agent ืžื•ืชืงืŸ ื•ืžื•ืคืขืœ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืฉื™ืจื•ืชื™ื ื›ื’ื•ืŸ Azure Automation, Azure Automatic Update, Azure Operations Management Suite, Azure Log Analytics, Azure Configuration Management, Azure Diagnostics ื•-Azure Container Insights. ืœื“ื•ื’ืžื”, ืกื‘ื™ื‘ื•ืช ืœื™ื ื•ืงืก ื‘-Azure ืฉืขื‘ื•ืจืŸ ืžื•ืคืขืœ ื ื™ื˜ื•ืจ ืจื’ื™ืฉื•ืช ืœื”ืชืงืคื•ืช. ื”ืกื•ื›ืŸ ื”ื•ื ื—ืœืง ืžื—ื‘ื™ืœืช OMI ื”ืคืชื•ื—ื” (Open Management Infrastructure Agent) ืขื ื”ื˜ืžืขืช ืžื—ืกื ื™ืช DMTF CIM/WBEM ืœื ื™ื”ื•ืœ ืชืฉืชื™ื•ืช IT.

OMI Agent ืžื•ืชืงืŸ ื‘ืžืขืจื›ืช ืชื—ืช ืžืฉืชืžืฉ omsagent ื•ื™ื•ืฆืจ ื”ื’ื“ืจื•ืช ื‘-/etc/sudoers ืœื”ืคืขืœืช ืกื“ืจื” ืฉืœ ืกืงืจื™ืคื˜ื™ื ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื‘ืžื”ืœืš ื”ื”ืคืขืœื” ืฉืœ ืฉื™ืจื•ืชื™ื ืžืกื•ื™ืžื™ื, ื ื•ืฆืจื™ื ืฉืงืขื™ ืจืฉืช ื”ืื–ื ื” ื‘ื™ืฆื™ืื•ืช ื”ืจืฉืช 5985, 5986 ื•-1270. ืกืจื™ืงื” ื‘ืฉื™ืจื•ืช Shodan ืžืจืื” ื ื•ื›ื—ื•ืช ืฉืœ ื™ื•ืชืจ ืž-15 ืืœืฃ ืกื‘ื™ื‘ื•ืช ืœื™ื ื•ืงืก ืคื’ื™ืขื•ืช ื‘ืจืฉืช. ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืื‘ ื˜ื™ืคื•ืก ืขื•ื‘ื“ ืฉืœ ื”ื ื™ืฆื•ืœ ื›ื‘ืจ ื”ื™ื” ื–ืžื™ืŸ ืœืฆื™ื‘ื•ืจ, ื•ืžืืคืฉืจ ืœืš ืœื”ืคืขื™ืœ ืืช ื”ืงื•ื“ ืฉืœืš ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ ื‘ืžืขืจื›ื•ืช ื›ืืœื”.

ื”ื‘ืขื™ื” ืžื—ืžื™ืจื” ื‘ืฉืœ ื”ืขื•ื‘ื“ื” ืฉื”ืฉื™ืžื•ืฉ ื‘-OMI ืื™ื ื• ืžืชื•ืขื“ ื‘ืžืคื•ืจืฉ ื‘-Azure ื•ื”-OMI Agent ืžื•ืชืงืŸ ืœืœื ืื–ื”ืจื” - ืจืง ืฆืจื™ืš ืœื”ืกื›ื™ื ืœืชื ืื™ ื”ืฉื™ืจื•ืช ื”ื ื‘ื—ืจ ื‘ืขืช ื”ื’ื“ืจืช ื”ืกื‘ื™ื‘ื” ื•ื”-OMI Agent ื™ื”ื™ื” ืžื•ืคืขืœ ืื•ื˜ื•ืžื˜ื™ืช, ื›ืœื•ืžืจ. ืจื•ื‘ ื”ืžืฉืชืžืฉื™ื ืืคื™ืœื• ืœื ืžื•ื“ืขื™ื ืœื ื•ื›ื—ื•ืชื•.

ืฉื™ื˜ืช ื”ื ื™ืฆื•ืœ ื”ื™ื ื˜ืจื™ื•ื•ื™ืืœื™ืช - ืคืฉื•ื˜ ืฉืœื— ื‘ืงืฉืช XML ืœืกื•ื›ืŸ, ื”ืกืจืช ื”ื›ื•ืชืจืช ื”ืื—ืจืื™ืช ืขืœ ื”ืื™ืžื•ืช. OMI ืžืฉืชืžืฉ ื‘ืื™ืžื•ืช ื‘ืขืช ืงื‘ืœืช ื”ื•ื“ืขื•ืช ื‘ืงืจื”, ื•ืžืืžืช ืฉืœืœืงื•ื— ื™ืฉ ืืช ื”ื–ื›ื•ืช ืœืฉืœื•ื— ืคืงื•ื“ื” ืžืกื•ื™ืžืช. ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื›ืืฉืจ ื”ื›ื•ืชืจืช "Authentication", ื”ืื—ืจืื™ืช ืขืœ ื”ืื™ืžื•ืช, ืžื•ืกืจืช ืžื”ื”ื•ื“ืขื”, ื”ืฉืจืช ืจื•ืื” ืฉื”ืื™ืžื•ืช ืžื•ืฆืœื—, ืžืงื‘ืœ ืืช ื”ื•ื“ืขืช ื”ื‘ืงืจื” ื•ืžืืคืฉืจ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื›ื“ื™ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ืฉืจื™ืจื•ืชื™ื•ืช ื‘ืžืขืจื›ืช, ืžืกืคื™ืง ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ื”ืกื˜ื ื“ืจื˜ื™ืช ExecuteShellCommand_INPUT ื‘ื”ื•ื“ืขื”. ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœื”ืคืขื™ืœ ืืช ื›ืœื™ ื”ืฉื™ืจื•ืช "id", ืคืฉื•ื˜ ืฉืœื— ื‘ืงืฉื”: curl -H "Content-Type: application/soap+xml;charset=UTF-8" -k โ€”data-binary "@http_body.txt" https: //10.0.0.5. 5986:3/wsman ... ืชึฐืขื•ึผื“ึทืช ื–ึถื”ื•ึผืช 2003

ืžื™ืงืจื•ืกื•ืคื˜ ื›ื‘ืจ ื”ื•ืฆื™ืื” ืืช ืขื“ื›ื•ืŸ OMI 1.6.8.1 ืฉืžืชืงืŸ ืืช ื”ืคื’ื™ืขื•ืช, ืืš ื”ื•ื ืขื“ื™ื™ืŸ ืœื ื ืžืกืจ ืœืžืฉืชืžืฉื™ Microsoft Azure (ื”ื’ืจืกื” ื”ื™ืฉื ื” ืฉืœ OMI ืขื“ื™ื™ืŸ ืžื•ืชืงื ืช ื‘ืกื‘ื™ื‘ื•ืช ื—ื“ืฉื•ืช). ืขื“ื›ื•ื ื™ ืกื•ื›ื ื™ื ืื•ื˜ื•ืžื˜ื™ื™ื ืื™ื ื ื ืชืžื›ื™ื, ืœื›ืŸ ื”ืžืฉืชืžืฉื™ื ื—ื™ื™ื‘ื™ื ืœื‘ืฆืข ืขื“ื›ื•ืŸ ื—ื‘ื™ืœื” ื™ื“ื ื™ ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื•ืช "dpkg -l omi" ื‘-Debian/Ubuntu ืื• "rpm -qa omi" ื‘-Fedora/RHEL. ื›ืคืชืจื•ืŸ ืื‘ื˜ื—ื”, ืžื•ืžืœืฅ ืœื—ืกื•ื ื’ื™ืฉื” ืœื™ืฆื™ืื•ืช ืจืฉืช 5985, 5986 ื•-1270.

ื‘ื ื•ืกืฃ ืœ-CVE-2021-38647, OMI 1.6.8.1 ืžื˜ืคืœ ื’ื ื‘ืฉืœื•ืฉ ื ืงื•ื“ื•ืช ืชื•ืจืคื” (CVE-2021-38648, CVE-2021-38645 ื•-CVE-2021-38649) ืฉืขืœื•ืœื•ืช ืœืืคืฉืจ ืœืžืฉืชืžืฉ ืžืงื•ืžื™ ืœืœื ื”ืจืฉืื•ืช ืœื”ืคืขื™ืœ ืงื•ื“ ื›ืฉื•ืจืฉ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”