˼¿ÆµÄ°²È«Ç鱨Ñо¿ÍŶÓTalos GroupÖ¸³ö£¬QualysÈÕǰËù½Ò¶µÄGHOST©¶´ÔÊÐíº§¿Í×ÔÔ¶¶ËÖ´ÐÐÈÎÒâ³Ìʽ£¬ËäÈ»ÊǸöÖØ´ó©¶´£¬µ«²¢Ã»ÄÇô¿ÉÅ¡£
¸Ã©¶´³öÏÖÔÚGNU Cº¯Ê½¿â£¨glibc£©Öн«Ö÷»úÃû³Æ×ªÎªIPλַµÄGetHostº¯Êý£¬Òò´Ë±»¼ò³ÆÎªGHOST¡£QualysÔÚ __nss_hostname_digits_dots() ·¢ÏÖÒ»¸ö»º?ÇøÒçλ©¶´£¬²»ÂÛÊÇÖ´ÐÐgethostbyname()»ògethostbyname2()¹¦Äܶ¼ÓпÉÄÜ´¥·¢¸Ã©¶´£¬ÔÊÐíÔ¶¶Ë¹¥»÷ÕßÖ´ÐÐÈÎÒâ³Ìʽ²¢ÕÆ¿ØÏµÍ³¡£
²»¹ý£¬Talos GroupÈÏΪ´ËÒ»ÖØ´ó©¶´²¢Ã»ÓÐÄÇô¿ÉÅ¡£ÆäÖÐÒ»¸öÔÒòÊÇÕâÁ½ÏÄÜÒòδ֧ԮIPv6£¬ËùÒÔÔ¼ÔÚ15Äêǰ¾ÍÈÕ½¥±»ÌÔÌ£¬Ö§Ô®IPv6ÇÒÓÃÀ´Ìæ´úÉÏÊö¹¦ÄÜ µÄgetaddrinfo()²¢²»´æÔڸé¶´¡£Æä´ÎÊDZØÐëÒª½ÓÊÜÒÔÖ÷»úÃû³ÆÊäÈëÇÒÈÔʹÓÃgethostbyname()»ò gethostbyname2()¹¦ÄܵÄÓ¦ÓóÌʽ²Å¿ÉÄܱ»¹¥»÷¡£
ÔÙÕߣ¬Ïà¹Ø¹¦ÄÜÏÞÖÆÁË¿ÉʹÓõÄÖ÷»úÃû³Æ¸ñʽ£¬³ýÁËÒªÇóÖ÷»úÃû³ÆÖ»ÄÜÓÉÊý×ÖÓë .£¨dot£©×é³ÉÖ®Í⣬ҲҪÇóÖ÷»úÃû³ÆµÄµÚÒ»¸ö×ÖÔª±ØÐëÊÇ .£¬µ«×îºóÒ»¸ö×ÖÔª²»ÄÜÊÇ .£¬ºÜÉÙÓÐÓ¦ÓóÌʽ½ÓÊÜÕâÖÖ×ÊÁϸñʽµÄÊäÈë¡£
Talos Group±íʾ£¬¼´Ê¹ÕâÊÇÒ»¸öÔÊÐíÔ¶¶Ë³Ìʽ¹¥»÷µÄ©¶´£¬µ«ÆäÏÞÖÆ½µµÍÁËËüµÄÍþвÐÔ£¬º§¿Í±ØÐëʹÓÃgethostbyname()»ò gethostbyname2()µÄÆäÖÐÒ»ÏÄÜ£¬»¹µÃ·ûºÏÆæ¹ÖµÄ¹æÔò£¬ÔÚʵ¼Ê³¡¾°×îÓпÉÄÜ·¢ÉúµÄ½á¹ûÊÇÔì³É¼ÇÒäÌåÇø¶Î´íÎó¶ø·ÇÔ¶¶Ë³Ìʽ¹¥»÷¡£
ĿǰTalos Group²¢Î´·¢ÏÖÈκÎÕë¶Ô¸Ã©¶´µÄ¹¥»÷±¨¸æ£¬µ«Ô¤ÆÚÔÚÒµÕß°ÑÏà¹ØÂ©¶´µÄ¸ÅÄîÐÔÑéÖ¤³Ìʽ¼ÓÖÁMetasploitÉøÍ¸¹¤¾ß°üÖ®ºóÇé¿ö¿ÉÄܾͻáÓÐËù¸Ä±ä¡£
??/ITHome ??Àò