ºìÁªLinuxÃÅ»§
Linux°ïÖú

´óÁ¿ Redis ·þÎñÆ÷´æÔÚ SSH ȨÏÞÇÔÈ¡·çÏÕ

·¢²¼Ê±¼ä:2016-07-10 13:21:42À´Ô´:ºìÁª×÷Õß:Ronny
ÍêÈ«ÎÞÊÓ°²È«¹¦ÄÜµÄ Redis ·þÎñÆ÷×Ô´´½¨ÒÔÀ´±¥Êܸ÷ÖÖ°²È«·çÏÕµÄÀ§ÈÅ£¬Risk Based Security (RBS) ×î½ü·¢ÏÖÁË 6338 ̨Êܵ½ÇÖÈëµÄ Redis ·þÎñÆ÷Redis ÊÇÒ»¸öÔÚÄÚ´æÖÐÒÔ¼üÖµ¶Ô·½Ê½´æ´¢Êý¾ÝµÄ NOSQL Êý¾Ý¿â¡£¾Ý DB-Engines µÄͳ¼ÆÊý¾Ý£¬ËüÔÚ 2015 Äê¶ÈµÄÊý¾Ý¿âÁ÷ÐжÈλÁеÚÊ®£¬¶øÔÚ¼üÖµ¶ÔÊý¾Ý¿âÖÐÅÅÃûµÚÒ»¡£
ÓÉÓÚ Redis ÒÔÐÔÄÜΪµÚÒ»¿¼Á¿£¬ËùÒÔĬÈÏÅäÖÃϸÃÊý¾Ý¿âûÓÐÈκεÄÈÏÖ¤»òÆäËüµÄ°²È«¿ØÖƹ¦ÄÜ¡£

Redis ·þÎñÆ÷´æÔÚ SSH ÃÜÔ¿´´½¨Â©¶´
ÈκÎÈËÖ»ÒªÖªµÀÄãµÄ IP µØÖ·ºÍ Redis µÄ¶Ë¿Ú£¬¾Í¿ÉÒÔ·ÃÎÊÆäÖеÄÈÎÒâÄÚÈÝ¡£¸üÔã¸âµÄÊÇ£¬ÔÚ 2015 ÄêÄ©£¬·¢ÏÖÁËÒ»ÖÖ¹¥»÷·½Ê½¿ÉÒÔÈÃÈκÎÈËÔÚÄãµÄ Redis ·þÎñÆ÷É쵀 authorized_keys ÎļþÖд洢 SSH ÃÜÔ¿----ÕâÒâζ×Å£¬¹¥»÷Õß½«²»ÐèÒªÈκÎÃÜÂë¼´¿ÉÈ¡µÃ Redis ·þÎñÆ÷É쵀 SSH ·ÃÎÊȨÏÞ¡£

¶øÏÖÔÚ£¬ÖÁÉÙÓÐÈýÍǫ̀ûÓÐÈκÎÑéÖ¤´ëÊ©µÄ Redis ·þÎñÆ÷±©Â¶ÔÚ»¥ÁªÍøÉÏ£¬¾Ý RBS Ñо¿ÈËÔ±µÄ³Æ£¬ÒѾ­ÓÐ 6338 ̨ Redis ±»ÇÔÈ¡ÁË SSH ȨÏÞ¡£

¸Ã¹«Ë¾ÔÚͨ¹ý Shodan ½øÐÐÁË·ÇÇÖÈëʽɨÃèÖ®ºóµÃ³öÁËÈçÉϽáÂÛ¡£RBS µÄÑо¿ÈËÔ±ÔÚ·ÖÎöÁ˱»ÈëÇֵķþÎñÆ÷Ö®ºó·¢ÏÖ£¬ËüÃÇÉÏÃæ´æÔÚ×ÅÒ»¸öÃûΪ¡°crackit¡± µÄ SSH ÃÜÔ¿£¬Æä¹ØÁªµÄÓʼþµØÖ· ryan@exploit.im ÔøÔÚ֮ǰµÄÆäËüÈëÇÖʼþÖгöÏÖ¹ý¡£³ýÁË ryan@exploit.im Õâ¸öµØÖ·³öÏÖ¹ý 5892 ´ÎÖ®Í⣬root@chickenmelone.chicken.com ºÍ root@dedi10243.hostsailor.com Ò²·Ö±ð³öÏÖÁË 385 ´ÎºÍ 211 ´Î¡£³ýÁË¡°crackit¡± Ö®Í⣬»¹ÓÐһЩÃûΪ¡°crackit_key¡±£¬ ¡°qwe¡± £¬¡°ck¡± ºÍ ¡°crack¡± Ö®ÀàµÄÃÜÔ¿Ãû¡£¾Ý RBS ·ÖÎö£¬Õâ±íÃ÷ËüÃÇÀ´×Ô¶à¸ö×éÖ¯»ò¸öÈË¡£

¹¥»÷Õß²¢²»Õë¶ÔÌØ¶¨µÄ Redis °æ±¾£¬Èκΰ汾¶¼¿ÉÄܱ»ºÚ
ÕâЩ±»¹¥»÷µÄ Redis ·þÎñÆ÷µÄ°æ±¾¶à´ï 106 ¸ö£¬´ÓÔçÆÚµÄ 1.2.0. µ½×îÐ嵀 3.2.1 ¶¼ÓС£

¡°´Ó¶ÔÕâЩÊý¾ÝµÄ·ÖÎöÖеò»µ½¸ü½øÒ»²½µÄ½á¹û£¬Ö»ÄÜÈ·ÈÏÁ½¼þÊ£¬µÚÒ»¼þÊÂÊÇÕâ²¢·ÇгöÏֵĩ¶´£¬µÚ¶þÊÇ£¬ÓÐЩ·þÎñÆ÷Ö»ÊDZ»ÇÖÈëÁË£¬µ«ÊDz¢Ã»Óб»ÀûÓᣡ±RBS Ñо¿ÈËÔ±½âÊÍ˵¡£

¸Ã¹«Ë¾½¨Òéϵͳ¹ÜÀíÔ±ÃÇÉý¼¶Æä Redis ·þÎñÆ÷µ½×îеİ汾£¬²¢ÆôÓà 3.2 °æ±¾ÐÂÒýÈëµÄ¡°±£»¤Ä£Ê½¡±¡£ÁíÍ⣬²»Òª½« Redis ·þÎñÆ÷»òÕ߯äËüµÄÊý¾Ý¿â±©Â¶ÔÚ»¥ÁªÍøÉÏÊÇ×îÆðÂëµÄ°²È«×¼Ôò¡£

±¾ÎĵØÖ·£ºhttp://www.linuxprobe.com/redis-server-ssh-risk.html
ÎÄÕÂÆÀÂÛ

¹²ÓÐ 1 ÌõÆÀÂÛ

  1. Ronny ÓÚ 2016-07-10 13:22:10·¢±í:

    ÍøÂ簲ȫÊÇÒ»¸ö³¤ÆÚÐèÒª¹Ø×¢µÄ»°Ìâ