À´Ô´£ºZDNet°²È«ÆµµÀ
¼¼Êõ¹©Ó¦ÉÌ˼¿Æ¡¢¼×¹ÇÎÄ¡¢Õ°²©ºÍÆäËû³§ÉÌ·×·×ÍÆ³ö°²È«¸üУ¬Îª¿Í»§½â¾öLinuxºÍUnixϵͳÀï¾ß¸ß¶ÈÕë¶ÔÐÔµÄShellshock©¶´¡£¸Ã©¶´¿ÉʹµÃ·¸×ï·Ö×ÓÓлú»á·ÃÎʺÍÍêÈ«¿ØÖÆÒ»Ð©ÖØÒªÏµÍ³¡£
ShellshockÊÇBashÃüÁîÐнâÊÍÆ÷ÀïµÄÒ»¸ö©¶´¡£Â©¶´¸¡ÏÖºóBashÒѾ±»¸üйý£¬µ«°²È«×¨¼ÒÖ¸£¬ÍøÂçÉ豸ºÍÆäËûϵͳºÍÓ¦ÓóÌÐòµÄÔçÆÚ²¹¶¡³ÌÐò¿ÉÄÜûÓÐÍêÈ«¶Âס©¶´£¬Î´ÄÜ·ÀÖ¹¹¥»÷ÕߵĹ¥»÷¡£Shellshock©¶´ºÍÈý¸öÆäËûÏà¹ØBugÔÚ¡°Í¨Óð²È«Â©¶´ÆÀ·Öϵͳ¡±£¨Common Vulnerability Scoring System£©µÃ·ÖΪ10£¬ÊÇ×î¸ß·Ö£¬±íÃ÷©¶´ºÍBugºÜÈÝÒ×±»ÀûÓᢹ¥»÷Õß¿ÉÒԺܷ½±ã»ñµÃ¹«¿ª¶ñÒâ´úÂë¡£GNU Bash 4.3¼°Ö®Ç°µÄÿһ¸ö°æ±¾¶¼Êܵ½Ó°Ïì¡£
Bash£¨È«³ÆBourne Again Shell£©¹ã·ºÓÃÓÚ¸÷ÖÖÉ豸¡¢ÐéÄâ·þÎñºÍÍøÂçÉ豸ÖС£½â¾ö·½°¸¹©Ó¦ÉÌÖ¸£¬¹¥»÷ÕßÀûÓÃÒ»¿îÍøÒ³³ÌÐòͨ¹ýÍøÂç̽²â·¢ÏÖ´æÔÚ©¶´µÄϵͳºó£¬¿ÉÔ¶³Ìµ÷ÓÃBash¡£°²È«³§É̽¨ÒéÓû§ÔÚ¿ÉÐеĸüгÌÐò·¢²¼Ç°²¿ÊðÈëÇÖ·ÀÓùºÍÌØÕ÷¼ì²â£¬ÒÔ¼ì²âºÍʵÏÖÓÐЧµÄÈëÇÖÔ¤·À¡£ÏµÍ³¹ÜÀíÔ±ÕâÒ»ÕóÒ²ÔÚæ×ŲÉÓù©Ó¦ÉÌ·¢³öµÄ½â¾ö·½·¨ºÍ°²È«¸üнøÐв¹¾È¡£
Íйܰ²È«·þÎñÌṩÉÌSolutionaryµÄ×ܲ¿ÉèÔÚÃÀ¹ú?²¼À˹¼ÓÖÝOmaha£¬ÊÇNTT¼¯Íŵĸ½Êô¹«Ë¾¡£SolutionaryÑо¿Ö÷¹ÜRob Kraus±íʾ£¬·þÎñÌṩÉÌÓ¦¸ÃÐÖú¿Í»§ÕÒ³öÊÜÓ°ÏìµÄ²úÆ·£¬½«¶ÔÓ¦µÄÌØÕ÷¼ì²âÌí¼Óµ½É豸Àï¡£
Kraus¸æËß¼ÇÕߣ¬¡°Õâ¶«Î÷¿Ï¶¨Î޿ײ»È룬ӦÃÜÇмà²â¡£Ã¿¼Ò¹«Ë¾¶¼Ó¦¸ÃÓж¯Ì¬¹ý³ÌµÄÐÞ²¹´ëÊ©¡£¡±
Óнâ¾ö·½°¸ÌṩÉ̸æËß¼ÇÕߣ¬Ò»Ð©IPS£¨Ó¢ÎÄIntrusion prevention systemsµÄËõд£º·ÀÇÖÈëϵͳ£©ÌØÕ÷µÄÎó±¨Âʽϸߡ£
¾ÝSolutionaryµÄ×ÊÁÏÏÔʾ£¬ÔÚʶ±ðÄÇЩÊÔͼÀûÓÃShellshock©¶´µÄÉ豸ÖУ¬¾ÓǰÎåλµÄÉ豸Ϊ£ºSourcefireºÍÖ§³ÖSnort IPSÌØÕ÷µÄÍøÂçÉ豸£»À´×ÔÅÁÂå°¢¶ûÍеÄÉ豸£»À´×ÔCheck PointµÄÉ豸£»À´×ÔÈüÃÅÌú¿ËµÄÉ豸ºÍÀ´×ÔJuniperµÄÉ豸¡£°²È«×¨¼Ò½«ShellshockÍþвºÍ·ºÀĵÄHeartbleed OpenSSL©¶´×ö¹ý¶Ô±È¡£Èç¹û¹¥»÷Shellshock©¶´³É¹¦µÄ»°£¬¹¥»÷Õß¿ÉÒÔÖ±½Óµ¼ÖÂϵͳ±ÀÀ££¬»òÊÇÔÚϵͳÉÏÔËÐи÷ÖÖ¶ñÒâÈí¼þ£¬ÕâÒ»µã¶Ôº¬ÓнÏΪÃô¸ÐµÄÊý¾Ý·þÎñÆ÷ºÜÖØÒª£¬ÁíÍ⣬¹¥»÷ÕßÒ²¿ÉÒÔ»ñµÃÓÐЧÓû§ÔÚÍøÂçÉϵÄÉí·Ý×ÊÁÏ¡£
ÈÎÖ°µÄÓÚ×ܲ¿ÉèÔÚÃÀ¹úÊ¥µØÑǸçµÄ¹ÜÀí·þÎñÌṩÉÌNWTechµÄStuart Maskell¸æËß¼ÇÕߣ¬ËûµÄ¹«Ë¾ÒѾ¾ÍShellshock©¶´ÁªÏµ¹ýÓû§¡£Maskell±íʾ£¬´ó¶àÊýÓû§ÒѾȷ¶¨ÁËʵÓõĽâ¾ö·½°¸²¢ÕýÔÚʵʩÆäËû´ëÊ©£¬ÒÔ¼õÉÙ¹¥»÷Ãæ£¬ÀýÈçÈ·±£ËùÓеÄÌØÕ÷¿ÉÒÔ¼ì²âµ½ÍþвÒÔ¼°ÔÚÏàÓ¦µÄ°²È«²¹¶¡·¢²¼Ê±ËæÊ±½øÐв¿Êð¡£
ºìñºÍ¼¸ºõËùÓÐÆäËûLinux·¢Ðа涼Êܵ½ShellshockµÄÓ°Ï졣ƻ¹ûÒ²Êܵ½Ó°Ï졣ƻ¹û·¢²¼Á˰²È«¸üÐÂÐÞ¸´ShellshockȱÏÝ¡£Ë¼¿ÆÈ·ÈÏÁ˼¸Ê®¸öÍøÂçÉ豸¡¢·À»ðǽºÍÆäËûÉ豸Êܵ½Shellshock©¶´Ó°Ïì¡£Fortinet¡¢F5 Networks¡¢´÷¶û£¬Check Point¡¢Blue CoatºÍBarracuda NetworksÉ豸µÄÓû§Ò²Êܵ½Shellshock©¶´µÄÓ°Ïì¡£
Õ°²©ÍøÂ繫˾ÉÏÖܼ±¼±ÎªÆìϵÄSSL VPN¡¢UAC¡¢MAGºÍSAϵÁÐÍøÂçÉ豸·¢²¼¸üгÌÐò¡£Õ°²©»¹ÓÚÖܶþΪÆäÍøÂ簲ȫ¹ÜÀíÉè±¸ÍÆ³ö¸üС£
Âõ¿Ë·ÆÕýÔÚ¼ì²éÆäÆìϵIJúÆ·¡£Âõ¿Ë·Æ¹«Ë¾ÈÔÔÚΪÆäStonesoftÏÂÒ»´ú·À»ðǽ¡¢µç×ÓÓʼþºÍÍøÒ³Íø¹ØÉ豸ºÍSSL VPN¿ª·¢°²È«¸üУ¬½â¾öShellshockȱÏÝ¡£Âõ¿Ë·Æ¹«Ë¾¶Ø´ÙStonesoftÏÂÒ»´ú·À»ðǽµÄÓû§ÀûÓÃÓйØÌØÕ÷¼ì²â¹¥»÷£¬Âõ¿Ë·Æ»¹ÌáÐÑÓû§£¬¹¥»÷³É¹¦Ôò¿ÉÒÔÔÚ¸ùĿ¼ִÐжñÒâ´úÂ룬ÍêÈ«¿ØÖÆÓЩ¶´µÄÉ豸¡£
¼×¹ÇÎÄÒ²·¢²¼ÁËÒ»¸ö´øÍ⣨Out-of-band£©°²È«¸üУ¬¶ÔÆìϵÄÊý¾Ý¿â¹ÜÀíϵͳÉ豸¡¢´æ´¢·þÎñÆ÷SolarisºÍÐéÄâ¼ÆËãÓ¦ÓÃÈí¼þ½øÐÐÐÞ²¹¡£¼×¹ÇÎݲȫ¹¤³ÌʦÍŶÓÕýÔÚ¿ª·¢ºÍ²âÊÔ°üÀ¨´óÊý¾ÝÉ豸¡¢Í¨µÀ½»»»»ú¡¢ÔÆÍø¹ØÒÔ¼°ÈÚºÏÓ¦ÓùÜÀí¹¤¾ßµÈÔÚÄÚµÄ40¶à¸ö²úÆ·µÄ°²È«²¹¶¡¡£
»ÝÆÕµÄ°²È«ÏìÓ¦ÍŶÓÔÚÖÜÈÕ·¢³öShellshock¾¯±¨£¬²¢·¢²¼ÁËÒ»¸ö½â¾öÔËÐÐBash ShellµÄ»ÝÆÕNonStop·þÎñÆ÷©¶´µÄ¸üС£IBMÒ²·¢ÁËͨ±¨ÌáÐÑÓû§£¬ÆìÏ»ùÓÚApacheµÄWebSphereÓ¦Ó÷þÎñÆ÷Ò²´æÔÚShellshockȱÏÝ¡£
VMware·¢²¼ÁËÐéÄâ»ú¹ÜÀí³ÌÐòÈí¼þµÚ4°æºÍ4.1°æµÄ°²È«¸üУ¬ÐéÄâ»ú¹ÜÀí³ÌÐòµÄ¾É°æ±¾ÒѾ¹ýÁËÖ§³ÖÈÕÆÚ¡£vSphere¡¢vCloudºÍÆäËû³¬¹ý30¸öÐéÄâÉ豸ҲÊܵ½Shellshock°²È«Â©¶´µÄÓ°Ïì¡£VMwareÖÜÒ»·¢²¼ÏûÏ¢ÌáÐÑÓû§£¬Ö¸Ä¿Ç°µÄ¸üÐÂδÄܽâ¾öShellshockÎÊÌâ¡£
VMware±íʾ£¬¡°Ä¿Ç°µÄ²¹¶¡ºÍÐÞ¸´³ÌÐòδÄÜÍêÈ«½â¾öÐí¶àÏÖ´æµÄ¹¥»÷ÏòÁ¿£¬ÐèÒª¶Ô©¶´½øÐнøÒ»²½Ñо¿£¬ÒÔ´ïµ½¸ü¿É¿¿µÄÐÞ¸´ºÍ²¹¾È¼Æ»®¡£VMwareÕýÈÕÒÔ¼ÌÒ¹µØÓëºÏ×÷»ï°é/¹©Ó¦É̺Ï×÷ѰÇó½â¾ö·½·¨¡£VMwareµÄÄ¿±êÊÇÈ«ÃæÎª¿Í»§Ìṩ¿É¿¿ºÍÓÐЧµÄÐÞ¸´³ÌÐò¡£¡±
×ܲ¿Î»ÓÚÓ¢¹úµÄ°²È«³§ÉÌSophosÈÔÔÚΪÆäµç×ÓÓʼþ²úÆ·¡¢ÍøÒ³É豸ºÍ¸½ÓÐBashµÄSophos UTM²úÆ·¿ª·¢°²È«¸üгÌÐò¡£SophosÖ¸ÆìϵÄvShield·À¶¾Èí¼þÒ²Êܵ½Ó°Ïì¡£
SophosÔÚÒ»¸öͨ¸æÖгƣ¬¡°´ÓÁ¼ºÃµÄ°²È«Êµ¼ù³ö·¢£¬ÎÒÃÇ»áÔÚBashά»¤ÉÌÌṩÎȶ¨¶øÓÐЧµÄÐÞ²¹³ÌÐòºó¾¡¿ì¸üи÷ÖÖSophosµÄ Bash°æ±¾¡£¡±