ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ Nostromo ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ื•ื•ืึธืก ืคื™ืจืŸ ืฆื• ื•ื•ื™ื™ึทื˜ ืงืึธื“ ื“ื•ืจื›ืคื™ืจื•ื ื’

ืื™ืŸ ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ื ืึธืกื˜ืจืึธืžืึธ (nhttpd) ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™
(CVE-2019-16278), ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืŸ ืึทื˜ืึทืงืขืจ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ ื“ื•ืจืš ืฉื™ืงืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืงืจืึทืคื˜ืขื“ ื”ื˜ื˜ืคึผ ื‘ืขื˜ืŸ. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ื“ืขืจ ืžืขืœื“ื•ื ื’ 1.9.7 (ื ืึธืš ื ื™ืฉื˜ ืืจื•ื™ืก). ืื•ื™ื‘ ืžืฉืคื˜ืŸ ืœื•ื™ื˜ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ Shodan ื–ื•ื›ืŸ ืžืึธื˜ืึธืจ, ื“ื™ Nostromo ื”ื˜ื˜ืคึผ ืกืขืจื•ื•ืขืจ ืื™ื– ื’ืขื ื™ืฆื˜ ืื•ื™ืฃ ื‘ืขืขืจืขืš 2000 ืขืคื ื˜ืœืขืš ืฆื•ื˜ืจื™ื˜ืœืขืš ืžื—ื ื•ืช.

ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืึท ื˜ืขื•ืช ืื™ืŸ ื“ื™ http_verify ืคึฟื•ื ืงืฆื™ืข, ื•ื•ืึธืก ืคืขืœืŸ ืึทืงืกืขืก ืฆื• ื˜ืขืงืข ืกื™ืกื˜ืขื ืื™ื ื”ืึทืœื˜ ืึทืจื•ื™ืก ื“ื™ ื•ื•ืึธืจืฆืœ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืคื•ืŸ ื“ืขื ืคึผืœืึทืฅ ื“ื•ืจืš ืคืึธืจืŸ ื“ื™ ืกื™ืงื•ื•ืึทื ืก ".%0d./" ืื™ืŸ ื“ืขื ื“ืจืš. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืึทืงืขืจื– ื•ื•ื™ื™ึทืœ ืึท ื˜ืฉืขืง ืคึฟืึทืจ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ "../" ืื•ืชื™ื•ืช ืื™ื– ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืื™ื™ื“ืขืจ ื“ื™ ื•ื•ืขื’ ื ืึธืจืžืึทืœื™ื–ื™ื™ืฉืึทืŸ ืคึฟื•ื ืงืฆื™ืข ืื™ื– ืขืงืกืึทืงื™ื•ื˜ืึทื“, ืื™ืŸ ื•ื•ืึธืก ื ืขื•ื•ืœื™ื™ืŸ ืื•ืชื™ื•ืช (% 0 ื“) ื–ืขื ืขืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืคื•ืŸ ื“ื™ ืฉื˜ืจื™ืงืœ.

ืคืึทืจ ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ืื™ืจ ืงืขื ืขืŸ ืึทืงืกืขืก /bin/sh ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ืึท CGI ืฉืจื™ืคื˜ ืื•ืŸ ื•ื™ืกืคื™ืจืŸ ืงื™ื™ืŸ ืฉืึธืœ ื‘ื•ื™ืขืŸ ื“ื•ืจืš ืฉื™ืงืŸ ืึท POST ื‘ืขื˜ืŸ ืฆื• ื“ื™ URI "/.%0d./.%0d./.%0d./.%0d./bin / sh " ืื•ืŸ ืคืึธืจืŸ ื“ื™ ืงืึทืžืึทื ื“ื– ืื™ืŸ ื“ื™ ื’ื•ืฃ ืคื•ืŸ ื“ื™ ื‘ืงืฉื”. ื™ื ื˜ืขืจืขืกื˜ื™ื ื’ืœื™, ืื™ืŸ 2011, ืึท ืขื ืœืขืš ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2011-0751) ืื™ื– ืฉื•ื™ืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ Nostromo, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืึทืŸ ื‘ืึทืคืึทืœืŸ ื“ื•ืจืš ืฉื™ืงืŸ ื“ื™ ื‘ืขื˜ืŸ "/..% 2f..% 2f..% 2fbin/sh".

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’