¡¾Äþ¾²Ç÷ÊÆ¡¿¿¨°Í˹»ù2018ÉÏ°ëÄêÎïÁªÍøÍþвµÄÐÂÇ÷ÊÆ
Ðû²¼Ê±¼ä 2018-10-31Òò´ËÔÚÕâÀïÎÒÃÇÑо¿ÁËÒÔÏÂÈý¸öÎÊÌ⣺ÍøÂç·¸×ï·Ö×ÓѬȾÖÇÄÜÉ豸µÄ¹¥»÷ÏòÁ¿¡¢ÄÄЩ¶ñÒâÈí¼þ±»¼ÓÔص½Óû§µÄϵͳÖÐÒÔ¼°×îеĽ©Ê¬ÍøÂç¶ÔÉ豸ËùÓÐÕߺÍÊܺ¦ÕßÀ´ËµÒâζ×Åʲô¡£
2016Äê ¨C 2018Ä꣬¿¨°Í˹»ùʵÑéÊÒÊÕ¼¯µ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÁ¿

ÔÚ½«¶ñÒâÈí¼þÏÂÔص½ÎïÁªÍøÉ豸ÉÏʱ£¬ÍøÂç·¸×ï·Ö×ÓµÄÊ×Ñ¡ÏîÊÇMirai¼Ò×壨20.9%£©¡£

ÒÔÏÂÊÇÎÒÃǼǼµ½µÄTelnet¹¥»÷×î¶àµÄ¹ú¼ÒµÄTop 10£º
2018ÄêµÚ¶þ¼¾¶È£¬ÊÜѬȾÉ豸ÊýÁ¿µÄµØÀíÂþÑÜ
ÓÉÓÚһЩÖÇÄÜÉ豸µÄËùÓÐÕßÐÞ¸ÄÁËĬÈϵÄTelnetÃÜÂ벢ʹÓÃÅÓ´óµÄÃÜÂ룬¶øÐí¶àС¹¤¾ß»ù´¡²»Ö§³ÖÕâÖÖÐÒ飬Òò´ËÍøÂç·¸×ï·Ö×ÓÒ»Ö±ÔÚÑ°ÕÒеÄѬȾÏòÁ¿¡£ÕâÒ»Çé¿ö»¹Êܵ½¶ñÒâÈí¼þ¿ª·¢ÕßÖ®¼äµÄ¾ºÕùËùÍƶ¯£¨ËûÃÇÖ®¼äµÄ¾ºÕùµ¼ÖÂÁ˱©Á¦Æƽ⹥»÷ЧÂÊÔ½À´Ô½µÍ£©£ºÒ»µ©ÀÖ³ÉÆƽâÁËTelnetÃÜÂ룬¹¥»÷Õ߾ͻá¸ü¸ÄÉ豸µÄÃÜÂë²¢×èÖ¹¶ÔTelnetµÄ·ÃÎÊ¡£
½©Ê¬ÍøÂçReaper¾ÍÊÇÒ»¸öʹÓá°Ìæ´ú¼¼Êõ¡±µÄºÜºÃµÄÀý×Ó£¬ËüÔÚ2017Äêµ×ѬȾÁËÔ¼200Íò¸öIoTÉ豸¡£¸Ã½©Ê¬ÍøÂ粢ûÓнÓÄÉTelnet±©Á¦Æƽ⹥»÷£¬¶øÊÇÀûÓÃÒÑÖªµÄÈí¼þ©¶´½øÐÐÁ÷´«£º
GoAheadÍøÂçÉãÏñ»úÖеÄ©¶´
MVPower CCTVÉãÏñ»úÖеÄ©¶´
Netgear ReadyNASSurveillanceÖеÄ©¶´
Vacron NVRÖеÄ©¶´
Netgear DGNÉ豸ÖеÄ©¶´
Linksys E1500/E2500·ÓÉÆ÷ÖеÄ©¶´
D-Link DIR-600ºÍDIR 300 ¨C HW rev B1·ÓÉÆ÷ÖеÄ©¶´
AVTechÉ豸ÖеÄ©¶´
Ó뱩Á¦ÆƽâÏà±È£¬ÕâÖÖÁ÷´«ÒªÁì¾ßÓÐÒÔÏÂÓŵ㣺
¶ÔÓû§¶øÑÔ£¬´ò²¹¶¡Ô¶±ÈÐÞ¸ÄÃÜÂë»ò½ûÓ÷þÎñÒªÄѵöà
ÐµĹ¥»÷£¬¾ÉµÄ¶ñÒâÈí¼þ
ϱíÊÇ2018ÄêµÚ¶þ¼¾¶È¹¥»÷ÎÒÃÇÃÛ¹ÞµÄÊÜѬȾIoTÉ豸µÄÀàÐÍÂþÑÜ£º¾ø´ó¶àÊý¹¥»÷ÈÔÈ»ÊÇÕë¶ÔTelnetºÍSSHÃÜÂëµÄ±©Á¦Æƽ⹥»÷¡£µÚÈý´ó×î³£¼ûµÄ¹¥»÷ÊÇÕë¶ÔSMB·þÎñ£¨ÎļþÔ¶³Ì·ÃÎÊ·þÎñ£©µÄ¹¥»÷¡£ÎÒÃÇ»¹Ã»ÓÐÊӲ쵽Õë¶Ô¸Ã·þÎñµÄIoT¶ñÒâÈí¼þ¡£ÎÞÂÛÈçºÎ£¬Ä³Ð©°æ±¾µÄSMBÖаüÂÞÑÏÖصÄÒÑ֪©¶´£¬ÈçÓÀºãÖ®À¶£¨Windows£©ºÍÓÀºãÖ®ºì£¨Linux£©¡£¾Ù¸öÀý×Ó£¬ÎÛÃûÕÑÖøµÄÀÕË÷Èí¼þWannaCryºÍÃÅÂÞ±Ò¿ó¹¤ EternalMiner¾ÍÀûÓÃÁËÕâЩ©¶´¡£

ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÔËÐÐRouterOSµÄMikroTikÉ豸ÔÚÁбíÖÐÒ»Æï¾ø³¾£¬ÆäÔÒòÓ¦¸ÃÊÇChimay-Red©¶´¡£
7547¶Ë¿Ú
ÁíÒ»À๥»÷ÔòÊÇÀûÓÃÁËÔËÐÐRouterOS°æ±¾6.38.4֮ϵÄMikroTik·ÓÉÆ÷ÖеÄ©¶´Chimay-Red¡£ÔÚ2018Äê3Ô£¬¸Ã¹¥»÷±»»ý¼«ÓÃÓÚ·Ö·¢Hajime¡£
ÍøÂçÉãÏñ»ú
ÍøÂç·¸×ï·Ö×ÓҲûÓкöÊÓÍøÂçÉãÏñ»ú¡£2017Äê3ÔÂÑо¿ÈËÔ±ÔÚGoAheadÉ豸µÄÈí¼þÖз¢ÏÖÁ˼¸¸öÑÏÖصÄ©¶´¡£ÔÚÏà¹ØÐÅÏ¢±»Åû¶µÄÒ»¸öÔºó£¬ÀûÓÃÕâЩ©¶´µÄGafgytºÍPersiraiľÂíбäÌå·ºÆðÁË¡£½öÔÚÒ»ÖÜÄÚ£¬ÕâЩ¶ñÒⷨʽ¾Í»ý¼«Ñ¬È¾ÁË57000¸öÉ豸¡£
ÖÕ¶ËÓû§ÃæÁÙµÄжñÒâÈí¼þºÍÍþв
DDoS¹¥»÷
ÓëÒÔÇ°Ò»Ñù£¬ÎïÁªÍø¶ñÒâÈí¼þµÄÖ÷ҪĿµÄÊǽøÐÐDDoS¹¥»÷¡£ÊÜѬȾµÄÖÇÄÜÉ豸³ÉΪ½©Ê¬ÍøÂçµÄÒ»²¿ÃÅ£¬Æ¾¾ÝÏà¹ØÃüÁî¹¥»÷Ò»¸öÖ¸¶¨µÄµØÖ·£¬ºÄ¾¡¸ÃÖ÷»úÓÃÓÚ´¦ÖÃÕæʵÓû§ÇëÇóµÄ×ÊÔ´ºÍÄÜÁ¦¡£Ä¾Âí¼Ò×åMirai¼°Æä±äÌ壨ÓÈÆäÊÇHajime£©ÈÔÔÚ²¿Êð´ËÀ๥»÷¡£
Õâ¿ÉÄÜÊǶÔÖÕ¶ËÓû§Î£º¦×îСµÄÇé¿öÁË¡£×Çé¿ö£¨ºÜÉÙ·¢Éú£©Ò²¾ÍÊÇÊÜѬȾÉ豸µÄÓµÓÐÕß±»ISPÀºÚ¡£¶øÇÒͨ³£Çé¿öϼòµ¥µØÖØÆôÉ豸¾Í¿ÉÒÔ¡°ÖÎÓú¡±¸ÃÉ豸¡£
¼ÓÃÜ»õ±ÒÍÚ¾ò
SatoriľÂíµÄ´´½¨Õß·¢ÏÖÁËÒ»ÖÖ¸üΪ½Æ»«ºÍ¿ÉÐеĻñÈ¡¼ÓÃÜ»õ±ÒµÄÒªÁì¡£Ëû½«ÊÜѬȾµÄIoTÉ豸×÷Ϊ·ÃÎʸßÐÔÄܼÆËã»úµÄÒ»ÖÖÔ¿³×£º
µÚÒ»²½£¬¹¥»÷ÕßÊ×ÏÈÊÔͼÀûÓÃÒÑ֪©¶´Ñ¬È¾¾¡¿ÉÄܶàµÄ·ÓÉÆ÷£¬ÕâЩ©¶´°üÂÞ£º
CVE 2017-17215 ¨C»ªÎªHG532ϵÁзÓÉÆ÷¹Ì¼þÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´
CVE-2018-10561, CVE-2018-10562 ¨CDasan GPON·ÓÉÆ÷ÖеÄÉí·ÝÈÏÖ¤Èƹý©¶´ºÍÈÎÒâ´úÂëÖ´ÐЩ¶´
CVE-2018-10088 ¨CXiongMai uc-httpd 1.0.0ÖеĻº³åÇøÒç³ö©¶´£¬¸Ã²úÎï±»ÓÃÓÚ²¿ÃÅÖйúÖÆÔìµÄ·ÓÉÆ÷ºÍÖÇÄÜÉ豸µÄ¹Ì¼þÖÐ
Êý¾ÝÇÔÈ¡
ÔÚ2018Äê5Ô¼ì²âµ½µÄVPNFilterľÂíÔò×·ÇóÆäËüµÄÄ¿±ê¡£ËüÊ×ÏÈÀ¹½ØÊÜѬȾÉ豸µÄÁ÷Á¿£¬È»ºó´ÓÖÐÌáÈ¡ÖØÒªµÄÊý¾Ý£¨Óû§Ãû¡¢ÃÜÂëµÈ£©²¢·¢Ë͵½ÍøÂç·¸×ï·Ö×ӵķþÎñÆ÷¡£ÏÂÃæÊÇVPNFilterµÄÖ÷Òª¹¦Ð§£º
×ÔÆô¶¯»úÖÆ¡£¸ÃľÂí½«×Ô¼ºÐ´Èë³ß¶ÈLinux¼Æ»®ÈÎÎñ·¨Ê½crontab£¬»¹¿ÉÒÔÐÞ¸ÄÉ豸µÄ·ÇÒ×ʧÐÔ´æ´¢Æ÷£¨NVRAM£©ÖеÄÅäÖÃÉèÖá£
ʹÓÃTORÓëC&C·þÎñÆ÷½øÐÐͨÐÅ¡£
Äܹ»×Ô»Ù²¢Ê¹É豸¡°±äש¡±¡£Ò»µ©½ÓÊÕµ½Ïà¹ØÃüÁ¸ÃľÂí¾Í»á×ÔÎÒɾ³ý²¢ÓÃÀ¬»øÊý¾ÝÁýÕֹ̼þµÄÒªº¦²¿ÃÅ£¬È»ºóÖØÆôÉ豸¡£
¸ÃľÂíµÄÁ÷´«ÒªÁìÈÔȻδ֪£ºÆä´úÂëÖÐûÓаüÂÞ×ÔÎÒÁ÷´«»úÖÆ¡£ÎÞÂÛÈçºÎ£¬ÎÒÃÇÇãÏòÓÚÈÏΪËüͨ¹ýÀûÓÃÉ豸Èí¼þÖеÄÒÑ֪©¶´À´Ñ¬È¾É豸¡£
µÚÒ»·Ý¹ØÓÚVPNFilterµÄ³ÂËß³ÆÆäѬȾÁËÔ¼50Íò¸öÉ豸¡£´ÓÄÇʱÆ𣬸ü¶àµÄÉ豸±»Ñ¬È¾ÁË£¬¶øÇÒÒ×Êܹ¥»÷µÄÉ豸³§ÉÌÁбí´ó´ó¼Ó³¤ÁË¡£µ½ÁùÔÂÖÐÑ®£¬ÆäÄ¿±ê°üÂÞÒÔÏÂÆ·ÅƵÄÉ豸£º
ASUS
D-LinkHuawei
Linksys
MikroTik
Netgear
QNAP
TP-Link
Ubiquiti
Upvel
ZTE
ÓÉÓÚÕâЩ³§É̵ÄÉ豸²»½öÔÚ¹«Ë¾ÍøÂçÖÐʹÓ㬶øÇÒ³£±»ÓÃ×÷¼ÒÓ÷ÓÉÆ÷£¬ÕâʹµÃÇé¿ö±äµÃ¸üÔã¡£
½áÂÛ
Õë¶ÔÖÇÄÜÉ豸µÄ¶ñÒâÈí¼þ²»½öÔÚÊýÁ¿ÉÏÔö³¤£¬¶øÇÒÔÚÖÊÁ¿ÉÏÒ²ÔÚÔö³¤¡£Ô½À´Ô½¶àµÄexploits£¨Â©¶´ÀûÓ÷¨Ê½£©±»ÍøÂç·¸×ï·Ö×Ó¿ª·¢³öÀ´¡£¶ø³ýÁË´«Í³µÄDDoS¹¥»÷Ö®Í⣬±»Ñ¬È¾µÄÉ豸»¹±»ÓÃÓÚÇÔÈ¡¸öÈËÊý¾ÝºÍÍÚ¾ò¼ÓÃÜ»õ±Ò¡£
ÏÂÃæÊÇһЩ¿ÉÒÔ×ÊÖú¼õÉÙÖÇÄÜÉ豸ѬȾ·çÏÕµÄС¼¼ÇÉ£º
¶¨ÆÚÖØÆôÓÐÖúÓÚÇå³ýÒÑѬȾµÄ¶ñÒâÈí¼þ£¨¾¡¹Ü´ó¶àÊýÇé¿öÏ»¹´æÔÚÔÙ´ÎѬȾµÄ·çÏÕ£©
¶¨ÆÚ¼ì²éÊÇ·ñ´æÔÚа汾µÄ¹Ì¼þ²¢½øÐиüÐÂ
ʹÓÃÅÓ´óÃÜÂ루³¤¶ÈÖÁÉÙΪ8룬°üÂÞ¾Þϸд×Öĸ¡¢Êý×ÖºÍÌØÊâ×Ö·û£©
ÔÚ³õʼÉèÖÃʱ¸ü¸Ä³ö³§ÃÜÂ루¼´Ê¹É豸δÌáʾÄúÕâÑù×ö£©
Èç¹û´æÔÚ¸ÃÑ¡ÏÔò¹Ø±Õ/½ûÓò»Ê¹ÓõĶ˿ڡ£ÀýÈ磬Èç¹ûÄú²»¼Æ»®Í¨¹ýTelnet£¨Õ¼ÓÃTCP¶Ë¿Ú23£©Á¬½Óµ½Â·ÓÉÆ÷£¬Ôò×îºÃ½ûÓøö˿ÚÒÔ½µµÍ±»ÈëÇֵķçÏÕ¡£
ÔÎÄÁ´½Ó£ºhttps://securelist.com/new-trends-in-the-world-of-iot-threats/87991/