½üÈÕ£¬»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ¸ù¾ÝÀÕË÷²¡¶¾ÍþвÇ鱨£¬·¢ÏÖÁËÒ»¿îÕë¶Ô VMware ESXi ·þÎñÆ÷µÄÐÂÐÍÀÕË÷Èí¼þ£¨ESXiArgs£©ÕýÔÚÈ«Çò·¶Î§ÄÚ´ó¹æÄ£´«²¥¡£¸ÃÀÕË÷Èí¼þÓÚ½ñÄê2Ô¿ªÊ¼´ó¹æÄ£³öÏÖ¡£¹¥»÷ÕßÀûÓÃÁ½Äêǰδ¾ÐÞ²¹µÄ RCE ©¶´ CVE-2021-21974 ½«¶ñÒâÎļþ´«ÊäÖÁ ESXi µ¼Ö OpenSLP ·þÎñÖеĶÑÒç³ö£¬´Ó¶ø»ñµÃ½»»¥Ê½·ÃÎÊ£¬½èÒÔ²¿ÊðÐ嵀 ESXiArgs ÀÕË÷²¡¶¾¡£
CVE-2021-21974©¶´Óë OpenSLP Ïà¹Ø£¬¹¥»÷ÕßÔÚ¿É·ÃÎÊ427¶Ë¿ÚµÄÌõ¼þÏ£¬¹¹Ôì¶ñÒâµÄSLPÇëÇó´¥·¢OpenSLP·þÎñÖеĶÑÒç³ö£¬´Ó¶øµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë¡£¹úÄÚ´æÔڸé¶´Ó°ÏìµÄ·þÎñÆ÷ÊýÁ¿ÈçÏÂËùʾ£¨»ùÓÚshodanͳ¼ÆÊý¾Ý£©£º
°æ±¾ | ÊýÁ¿Í³¼Æ |
ESXi 6.5 | 715 |
ESXi 6.7 | 3184 |
ESXi 7.0 | 1271 |
ESXi 6.0.0 | 665 |
| 342
|
ESXiArgsÀÕË÷Èí¼þÔÚÊܸÐȾµÄ ESXi ·þÎñÆ÷ÉÏʹÓÃ.vmxf¡¢.vmx¡¢.vmdk¡¢.vmsd ºÍ .nvram À©Õ¹Ãû¼ÓÃÜÎļþ£¬²¢ÎªÃ¿¸ö°üº¬ÔªÊý¾Ý£¨¿ÉÄÜÐèÒª½âÃÜ£©µÄ¼ÓÃÜÎĵµ´´½¨Ò»¸ö.argsÎļþ¡£
ËäÈ»Õâ´Î¹¥»÷±³ºóµÄÍþвÐÐΪÕßÉù³ÆÇÔÈ¡ÁËÊý¾Ý£¬µ«Ò»ÃûÊܺ¦ÕßÔÚ BleepingComputer ÂÛ̳Éϱ¨¸æËµ£¬ËûÃǵÄʼþ²¢·ÇÈç´Ë¡£
Êܺ¦Õß»¹ÔÚËø¶¨µÄϵͳÉÏ·¢ÏÖÁËÃûΪ¡°ransom.html¡±ºÍ¡°How to Restore Your Files.html¡±µÄÊê½ðƱ¾Ý£¬Ö¸Ê¾Êܺ¦Õßͨ¹ý TOX_IDÓë¹¥»÷ÕßÈ¡µÃÁªÏµ£¬ÒÔ»Ö¸´¼ÓÃÜÎļþ»ò·ÀÖ¹Êý¾Ý±»Ð¹Â¶¡£

1.ÀÕË÷·çÏÕ×Ô²é
1)¼ì²é/store/packages/Ŀ¼ÏÂÊÇ·ñ´æÔÚvmtools.pyºóÃÅÎļþ¡£Èç¹û´æÔÚ£¬½¨ÒéÁ¢¼´É¾³ý¸ÃÎļþ¡£
2)¼ì²é/tmp/Ŀ¼ÏÂÊÇ·ñ´æÔÚencrypt¡¢encrypt.sh¡¢public.pem¡¢motd¡¢index.htmlÎļþ£¬Èç¹û´æÔÚ£¬Ó¦¼°Ê±É¾³ý¡£
2.ÀÕË÷´¦Öý¨Òé
1)Á¢¼´¸ôÀëÊܸÐȾµÄ·þÎñÆ÷£¬½øÐжÏÍø
2)ʹÓÃÊý¾Ý»Ö¸´¹¤¾ß»Ö¸´Êý¾Ý»ò֨װESXi
ÃÀ¹úCISA·¢²¼ÁË ESXiArgs ÀÕË÷Èí¼þ»Ö¸´½Å±¾£¬Ïà¹ØÁ´½ÓÈçÏ£º
https://github.com/cisagov/ESXiArgs-Recover
3)ÖØ¸´¡°ÀÕË÷·çÏÕ×Բ顱²½Öè
4)»Ö¸´Ð޸ĺóµÄ²¿·ÖÎļþ
3.©¶´¼Ó¹Ì
ÔÚ ESXi ÖнûÓà OpenSLP ·þÎñ£¬»òÕßÉý¼¶ÖÁ ESXi 7.0 U2c »ò ESXi 8.0 GA£¬ESXi 7.0 U2c»ò ESXi 8.0 GA °æ±¾Ä¬ÈÏÇé¿öϽûÓø÷þÎñ¡£
4.Êý¾Ý±¸·Ý
Õë¶ÔÖØÒªµÄÊý¾Ý½øÐÐË«»ú±¸·Ý»òÔÆ±¸·Ý¡£
5.°²×°»Æ½ð³ÇŵÑÇ·ÀÀÕË÷
»Æ½ð³Çͨ¹ý¶Ô´óÁ¿ÀÕË÷²¡¶¾µÄ·ÖÎö£¬»ùÓÚÁãÐÅÈΡ¢Êذ×ÖªºÚÔÔò£¬´´ÔìÐÔµØÑо¿³öÕë¶ÔÀÕË÷²¡¶¾µÄÖն˲úÆ·¡¾ÅµÑÇ·ÀÀÕË÷ϵͳ¡¿¡£ÅµÑÇ·ÀÀÕË÷ÔÚ²»¹ØÐÄ©¶´´«²¥·½Ê½µÄÇé¿öÏ£¬¿É·À»¤ÈκÎÒÑÖª»òδ֪µÄÀÕË÷²¡¶¾¡£
¼øÓÚÀÕË÷²¡¶¾µÄÎÞ²î±ð¹ãÆ×ÌØÕ÷£¬ÅµÑÇ·ÀÀÕË÷Ö§³Ö½«ÒÑÖª²¡¶¾¿âµ¼È룬¿ÉÏÈÆ¥Å䣬ÄÚÖò¡¶¾ÓÕ²¶¹¦ÄÜ£¬¾«È·Ê¶±ðÀÕË÷²¡¶¾µÄÈëÇֺ͸澯¡£¡¾ÅµÑÇ·ÀÀÕË÷ϵͳ¡¿ÒÑÖ§³Ö²éɱÀ¹½Ø´Ë´ÎʼþʹÓõÄESXiArgs ÀÕË÷Èí¼þ¡£
Õë¶ÔÔ±¹¤PC¡¢·þÎñÆ÷µÄÎĵµ½øÐзÀ»¤£¬È磺ºËÐÄ»úÃÜÎĵµ¡¢ÈÕ³£°ì¹«Îĵµ¡¢¸ß¼ÛÖµÎļþ¡¢¸÷ÀàÒþ˽Îĵµ¡£
Õë¶ÔOracle¡¢Sql Server¡¢Mysql¡¢DB2¡¢DM¡¢ÈË´ó½ð²Ö¡¢´ïÃΡ¢ÓÅìŵÈÖ÷Á÷Êý¾Ý¿â¡¢¹ú²úÊý¾Ý¿â£¬Ö¸¶¨Êý¾Ý¿âÀàÐÍ»òÌí¼ÓÊý¾Ý¿â¿ÉÖ´ÐгÌÐò£¬ÔÊÐíÖ»ÓÐÊý¾Ý¿â±¾Éí²ÅÄܶÔÊý¾ÝÎļþ½øÐÐÐ޸ĵȲÙ×÷¡£
Õë¶Ô¹ã·ºÊ¹ÓÃÑÆÖն˵ĹؼüÐÔÐÐÒµ£¬ÈçÒøÐеÄATM»ú¡¢¼ÓÓÍÕ¾×ÔÖú»ú¡¢Ò½Ôº×ÔÖú²éѯ»úµÈ¡£ÔÚ±¤ÀÝģʽÏ£¬ÈκÎеÄÈí¼þ¶¼ÎÞ·¨ÔËÐУ¬ÀÕË÷Èí¼þÔËÐÐʧ°Ü£¬´Ó¶øÎÞ·¨ÆÆ»µÎļþ¡£