¡¾Êý¾Ý°²È«ÐÂÌôÕ½¡¿Õë¶ÔÐé¹¹»¯Æ½Ì¨VMware vSphereµÄÀÕË÷¹¥»÷רÏî·ÖÎö

°ä²¼¹¦·ò 2021-09-22

Ò»¡¢¸Å Êö


¡¶ÖлªÈËÃñ¹²ºÍ¹úÊý¾Ý°²È«·¨¡·ÓÚ½ñÈÕÆð£¨2021Äê9ÔÂ1ÈÕ£©ÕýʽִÐÐ £¬ÕâÊÇÒ»²¿Êý¾ÝÁìÓòµÄ»ù´¡ÐÔ˾·¨ £¬Ò²Êǹú¶È°²È«ÁìÓòµÄÒ»²¿³ÁҪ˾·¨¡£Êý×Ö»¯¶¦ÐÂÍÆ¶¯×Źú¶È³ö²úģʽµÄˢР£¬Ëæ×ž­¼ÃÊý×Ö»¯¡¢µÐÔÖÊý×Ö»¯¡¢ÆóÒµÊý×Ö»¯µÄ½¨Éè £¬Êý¾ÝÒѾ­³ÉΪÎÒ¹úµ±¾ÖºÍÆóÒµ×îΪÖ÷ÌâµÄ×ʲúÖ®Ò»¡£¶øÕë¶ÔÕâЩÖ÷ÌâÊý¾Ý×ʲúµÄÍøÂç¹¥»÷È´ÖðÄêµÝÔö £¬³ýÁËÔ½À´Ô½ÆµÈÔµÄÊý¾Ýй¶°²È«ÊÂÎñ±í £¬ÈÕÒæ·è¿ñµÄÀÕË÷¹¥»÷ÊÇÊý¾Ý°²È«Ãæ¶ÔµÄ×îΪÑϳÁÇÒΣÏÕµÄÍþв £¬ÆäÓµÓзÛËéÐÔ´ó¡¢ÄäÃûÐԸߡ¢¸´Ô­ÄѵÈÌØµã¡£Ò»µ©Êý¾Ý×ʲúÔâµ½¹¥»÷ £¬³ýÁË´óÁ¿¹óÖØµÄÊý¾Ý±»·ÛËé±í £¬»¹»áµ¼Ö¹¤³§Ðª¹¤Í£²ú£¨È磺¸»Ê¿¿Â·ÕË÷¹¥»÷µ¼ÖÂЪ¹¤µÄÊÂÎñ£© £¬ÉõÖÁ»áÍþвµ½¹ú¶È°²È«£¨È磺ȼÓ͹Ü·¹«Ë¾Colonial PipelineÀÕË÷¹¥»÷ÊÂÎñ£©¡£


Ŀǰ £¬ÀÕË÷×éÖ¯ÆÕ±éÀûÓ÷ì϶»òÕßÈËÎªÉøÈëµÄ¼¿Á©½øÈëÆóÒµ/×éÖ¯ÄÚ²¿ÏµÍ³ £¬²¢ÔÚÆäÖÐÖ²ÈëÀÕË÷²¡¶¾ £¬²¢ÀûÓÃÀÕË÷²¡¶¾¶ÔÆäÆóÒµµÄ³ÁÒªÊý¾Ý×ʲú½øÐмÓÃܶøºóÖ´ÐÐÊê½ðÀÕË÷¡£½ö½ñÄêÒÔÀ´ £¬¾Í³öÏÖÁ˶àÆð³Á´óµÄÀÕË÷²¡¶¾¹¥»÷ÊÂÎñ¡£5Ô·Ý £¬ÃÀ¹ú×î´óµÄȼÓ͹Ü·¹«Ë¾Colonial PipelineÔâ·êÀÕË÷²¡¶¾¹¥»÷ £¬´Ó¶øµ¼ÖÂÃÀ¹ú¶«²¿17¸öÖݺÍÊ×¶¼µØµãµÄ»ªÊ¢¶ÙÌØÇø°ä·¢½øÈ봹Σ״̬£»7Ô·Ý £¬ÃÀ¹úITÖÎÀíÈí¼þÔì×÷ÉÌKaseyaÊܵ½¹©¸øÁ´¹¥»÷ £¬ºÚ¿ÍÀûÓÃÆäÈí¼þÖдæÔڵķì϶ÏòÆä¿Í»§·¢ËÍÀÕË÷Èí¼þ £¬³¬¹ý1500¼ÒÆóÒµÊܵ½ÀÕË÷¹¥»÷Ó°Ïì¡£


Ëæ×ÅÊг¡ºÍ¼¼ÊõµÄˢР£¬ÀÕË÷×éÖ¯Ò²ÔÚ²»ÐÝ×·ÇóÐµĹ¥»÷Ö¸±êºÍ¹¥»÷¼¿Á©ÒÔ»ñÈ¡¸ü·á¸»µÄÊê½ð¡£¾Ýµ÷²é·¢ÏÖ £¬×ÔÈ¥ÄêÆðÍ· £¬ÀÕË÷×éÖ¯½«Ö¸±êÀ©´óµ½ÁËVMwareµÄÆóÒµ²úÆ·vSphereÖв¢ÇÒ¶ÔÏàÓ¦ÀÕË÷Èí¼þ½øÐÐÕë¶ÔÐÔÉý¼¶ÒÔÊÊÅäÕë¶ÔVMwareÐé¹¹»úµÄÀÕË÷¡£µ½Ä¿Ç°ÎªÖ¹ £¬¶à¼ÒʹÓÃvSphereµÄÆóÒµÒѾ­Ôâµ½ÀÕË÷ £¬ÓÉÓÚʹÓÃvSphereµÄÆóÒµ±ØÒªÔÚVMware ESX/ESXiÖ÷»úÉϲ¿Êð¶ą̀Ðé¹¹»úÒÔÂú×ãÈÕ³£µÄ·þÎñÆ÷»òÊý¾Ý¿âÐèÒª £¬ÀÕË÷×éÖ¯Ö»ÓÐÉè·¨µÇ¼µ½ÆóÒµµÄVMware ESX/ESXiÖ÷»ú £¬¾ÍÄܲ¿ÊðÀÕË÷Èí¼þ¶ÔÖ÷»úÉϵĶą̀Ðé¹¹»úÔ´Îļþ½øÐмÓÃÜÖ´ÐÐÀÕË÷¡£ÓëÒÔÍù´«Í³µÄÀÕË÷¹¥»÷·ÖÆç £¬ÒÔÍùµÄÀÕË÷¹¥»÷½ö½öÊÇÕë¶Ôij̨»òÊý̨·þÎñÆ÷ÖеIJ¿ÃųÁÒªÊý¾Ý¼ÓÃÜ £¬¶øÏµÍ³ÈÔ¾ÉÄܹ»Õý³£ÔËÐУ»¶øÕë¶ÔvSphereµÄÀÕË÷¹¥»÷¿ÉÖ±½Ó¼ÓÃÜVMware ESX/ESXiÖ÷»úÖеÄËùÓеÄÐé¹¹»úÔ´Îļþ £¬Õ⽫ֱ½Óµ¼ÖÂÊý̨¹¤×÷·þÎñÆ÷»òÊý¾Ý¿â·þÎñÆ÷ÎÞ·¨Õý³£ÔËÐÐ £¬Ê¹ÆóÒµ/×éÖ¯µÄÖØÒªÒµÎñÖжÏÉõÖÁϵͳ̱»¾ £¬Õâ¶ÔÆóÒµ/×éÖ¯À´Ëµ½«ÊÇÖÂÃüµÄ½ø¹¥¡£


ÀÕË÷¹¥»÷ÒѾ­³ÉΪ¸÷´óÆóÒµ/×éÖ¯µÄ³ÁÒªÍøÂ簲ȫÍþвÆðÔ´ £¬ÕâÖÖÐÂÊ¢ÐеÄÕë¶ÔvSphereµÄÀÕË÷¹¥»÷½«´øÀ´±ÈÒÔÍùµÄÀÕË÷¹¥»÷¸ü´óµÄÍþв¡£±¾ÎĶԡ°Õë¶ÔVMware vSphereµÄÀÕË÷¹¥»÷¡±½øÐÐÁËÈ«ÃæµØ·ÖÎö £¬Í¨¹ý½áºÏ¼¼Êõ²¼¾°ºÍÓйØÊÂÎñ»î¶¯·ÖÎöÁËÀÕË÷×éÖ¯½«¹¥»÷Ö¸±êÀ©´óµ½VMware vSphereµÄÔ­Òò £¬²¢ÇÒÆ¾¾ÝÓйع¥»÷Ñù±¾µÄ·ÖÎö¸æ·¢ÁË´ËÀàÀÕË÷¹¥»÷µÄÀÕË÷Á÷³Ì £¬Í¬Ê±Æ¾¾ÝÓйØ×ÊÁÏΪ¿í´óÆóÒµ/×éÖ¯ÌṩÁËÓйصķÀÓù½¨Òé¡£


¶þ¡¢¹¥»÷Ö¸±ê£ºvSphere


VMware vSphere£¨¼ò³ÆvSphere£©ÊÇVMwareÆìϵÄÒ»ÕûÌ×ÔÆÍÆËã»ù´¡¼Ü¹¹Ðé¹¹»¯Æ½Ì¨ £¬×Ô°ä²¼¸üÐÂÒÔÀ´ÔÚÈ«ÇòÒѾ­Õ¼Óг¬¹ý250000¿Í»§ £¬Æä¿Í»§Ô̺¬µ±¾Ö¡¢¾ü¶Ó¡¢Ò½ÁÆ¡¢ÄÜÔ´¡¢½»Í¨¡¢½ÌÓýµÈÔÚÄڵĻù´¡ÉèÊ©ÁìÓò £¬Èçͼ1Ëùʾ£»Í¬Ê± £¬¹È¸èÔÆ¡¢°¢ÀïÔÆ¡¢ÑÇÂíÑ·ÔÆµÈÔÆ·þÎñÌṩ³§É̾ù¶Ô¿Í»§ÌṩÆëÈ«µÄvSphereÐé¹¹»¯·þÎñ £¬ÓйØÊг¡Ò²Í¬ÑùÖØ´ó £¬Èçͼ2Ëùʾ¡£Õ¼ÓÐÈç´ËÖØ´óµÄÊг¡ £¬vSphere±»ÀÕË÷×éÖ¯¶¢ÉÏÒ²²»¼°ÎªÆæ £¬µ«ÊÇÆä¿Í»§ÏÕЩº­¸ÇËùÓÐÁìÓò £¬Ò»µ©²úÆ·³öÏÖ·ì϶±»¹¥»÷ÕßÀûÓõ¼ÖÂÖ÷»ú±»ÀÕË÷²¡¶¾¹¥»÷ £¬²»½ö½«Ôì³É²Æ¸»Ëðʧ £¬¸üÓпÉÄÜÖ±½ÓÍþв¹ú¶È°²È«¡£


ͼ1. vSphereµÄ¿Í»§ÁìÓòÉ¢²¼.png


ͼ1. vSphereµÄ¿Í»§ÁìÓòÉ¢²¼


ͼ2. ÔÆ·þÎñÉÌÌṩVMware·þÎñʾÀý.png


ͼ2. ÔÆ·þÎñÉÌÌṩVMware·þÎñʾÀý


VMware ESX/ESXi£¨¼ò³ÆESX/ESXi£©ÊÇvSphereµÄÖ÷Ìâ×é¼þÖ®Ò»¡£ÔÚvSphereÖÐ £¬ESX/ESXiÊÇÒ»¸öÐé¹¹»úÖÎÀí·¨Ê½ £¬ÓÃÓÚ´´½¨¡¢ÔËÐкÍÖÎÀíÐé¹¹»ú¹ý³ÌµÄÖÐÑëÈí¼þ²ã £¬ÔËÐÐÔÚ»ù´¡ÎïÀí·þÎñÆ÷ºÍ²Ù×÷ϵͳ֮¼ä £¬²¢ÇÒÔʺܶà¸ö²Ù×÷ϵͳ¹²ÏíÖ÷»úÓ²¼þ¡£Æäʵ £¬ESX/ESXi²¢²»ÒÀÀµÆäËü²Ù×÷ϵͳ £¬¶øÊÇÖ±½Ó×°ÖÃÔÚÎïÀíÉ豸ÉÏ £¬¶øºóÒÔISO µÄ´ó¾ÖÌṩ·þÎñ£»Óû§Ö±½ÓÔÚESX/ESXiÖд´½¨¡¢ÔËÐкÍÖÎÀí×Ô¼ºµÄÐé¹¹»ú £¬Èçͼ3Ëùʾ¡£


ÔÚÏÖʵ³¡¾°ÖÐ £¬ÆóҵΪÁËÌá¸ß»úÄܺͳɱ¾Ð§ÒæÍ¬Ê±ÊµÏÖ¼ò»¯Êý¾ÝÖÐÐĺͷ½±ã´ó¹æÄ£ÖÎÀí £¬ÍùÍù»áÔÚһ̨ESX/ESXi·þÎñÆ÷Öв¿ÊðÊý̨ÉõÖÁÊýʮ̨Ðé¹¹»ú×÷ΪÈÕ³£µÄ¹¤×÷·þÎñÖ÷»ú»òÕßÊý¾Ý¿â¡£ËùÒÔ £¬ESX/ESXiÖ÷»úÖлᱣÁô×ÅÓëËüÔÚͳһÎïÀíÖ÷»úÉÏµÄÆäËûÐé¹¹»úµÄÔ´ÎļþÒÔ±ã¶ÔÕâЩÐé¹¹»ú½øÐÐÖÎÀí £¬Ëü¾ÍºÃ±È´æ·Å×ÅÊý̨·þÎñÆ÷µÄ»ú·¿ £¬ÈôÊÇ»ú·¿±»È˽ٳÖ £¬½«¶ÔÒ»¸öÆóÒµ»ò×éÖ¯Ôì³ÉÄÑÒÔ¹À¼ÆµÄËðʧ £¬ÕâÒ²ÊÇESX/ESXiÖ÷»úÓö³ÉΪÀÕË÷×éÖ¯¹¥»÷Ö¸±êµÄÖØÒªÔ­ÒòÖ®Ò»£»ÁíÒ»¸öÔ­ÒòÔòÊÇ £¬ESX/ESXiÉϲ¿ÊðµÄ·þÎñÆ÷/Êý¾Ý¿â¿ÉÄܱØÒªÏò¿Í»§Ìṩ·þÎñ £¬ÕâҲʹµÃ¹¥»÷ÕßÓлúÓöÖ±½Ó´ÓÍøÂç½Ó´¥µ½VMware ESX/ESXiÖ÷»ú £¬Îª¹¥»÷ÕßÌṩÁËÈëÇֵĿÉÄÜÐÔ¡£VMware¹«Ë¾µ±È»Ò²¼«¶ÈÃ÷ÏÔÆä²úÆ·°²È«µÄ³ÁÒªÐÔ £¬vSphere 5.0 ֮ǰµÄ°æ±¾ÖоùѡȡESXϵͳ½á¹¹À´ÊµÏÖ¶ÔÐé¹¹»úµÄÖÎÀí £¬ESXÊÇÒÀÀµÓÚLinuxµÄ½ÚÔį̀²Ù×÷ϵͳ (COS) À´ÊµÏÖ¿ÉÊØ»¤ÐԺͻùÓÚ´úÀíµÄºÏ×÷ͬ°é¼¯³ÉµÄ £¬¶øLinux×÷Ϊ¿ªÔ´ÏµÍ³ £¬ÓëLinuxÓйصķì϶ÔÚ¸÷´ó°²È«ÉçÇøºÍµØÏ²úÒµÖвã³ö²»Çî £¬Õ⽫VMware ESX¼Ü¹¹ÖÃÓÚÒ»¸ö¸ß·çÏÕ´¦¾³£»ÎªÁËÌá¸ß»ù´¡¼Ü¹¹µÄ°²È«ÐÔ £¬vSphere 5.0Ö®ºóµÄ°æ±¾ÖÐÔòѡȡÁ˶ÀÁ¢ÓڰѳÖϵͳµÄРESXi ϵͳ½á¹¹ £¬²¢ÇÒÔÚ×Ô¼ºÑз¢µÄÖ÷Ìâ VMkernel ÖÐʵÏÖÁ˱ر¸µÄÐé¹¹»úÖÎÀíÖ°ÄÜ £¬ÕâÒ²¾Í¶ã±ÜÁËÓëͨÓòÙ×÷ϵͳÓйصݲȫ·ì϶Òý·¢µÄ°²È«·çÏÕ¡£


¹¤×÷½á¹¹.png


ͼ3. VMware ESX/ ESXi ¹¤×÷½á¹¹


VMware vCenter Server£¨¼ò³ÆvCenter Server£©ÊÇvSphereµÄÁí±íÒ»¸öÖ÷Ìâ×é¼þ £¬ËüÊÇÒ»¸öÄܹ»Ô®ÊÖÓû§ÖÎÀí¶à¸öVMwareÐé¹¹»¯Æ½Ì¨µÄÈí¼þ £¬±ØÒªµ¥¶À×°ÖÃÔÚһ̨·þÎñÆ÷ÖС£ÔÚvSphereÖÐ £¬Óû§Äܹ»½«¶à¸öESX/ESXi Ö÷»úÔö³¤µ½vCenter Server ÖÎÀíÆ½Ì¨ÖÐ £¬¶øºóͨ¹ývCenter ServerÖÎÀíESX/ESXiÖ÷»úºÍÆäÖд´½¨µÄËùÓÐÐé¹¹»ú £¬Õû¸ö¹¤×÷½á¹¹Èçͼ4Ëùʾ¡£¹ÌȻĿǰ·¢ÏÖµÄÀÕË÷Èí¼þÕë¶ÔµÄÊÇESX/ESXiÖ÷»ú £¬µ«vCenter ServerÄܹ»Ö±ÊÕÊÜÀíESX/ESXi¶ą̀Ö÷»ú¡£ÈôÊÇvCenter Server´æÔÚ·ì϶±»¹¥»÷ÕßÀûÓà £¬ÄÇô¾ÍÎÞÒɽ«Êý̨ESX/ESXiÖ÷»úµÄ´óÃÅÏò¹¥»÷Õß³¨¿ª £¬¹¥»÷ÕßÄܹ»ËÁÒâÔÚESX/ESXiÖв¿ÊðÀÕË÷Èí¼þ £¬Æäºó¹ûµÄÑϳÁÐÔ¿ÉÏë¶øÖª¡£


ͼ4½á¹¹Í¼.png

ͼ4. vCenter Server ¹¤×÷½á¹¹


Èý¡¢ Õë¶ÔvSphereÀÕË÷µÄÓйػ


²¡¶¾ÀÕË÷×÷Ϊ½üÄêÀ´Ê¢ÐеÄÍøÂç¹¥»÷¼¿Á© £¬Öð²½»ñµÃºÚ¿ÍÍÅ»ïÇàíù £¬Ô½À´Ô½¶àµÄÀÕË÷×éÖ¯³Ê´Ë¿Ì¹«¹²ÊÓÒ° £¬¸÷´ó²¡¶¾ÀÕË÷ÊÂÎñÒ²Öð²½Õ¼¾ÝÁ˳Á´óÍøÂç¹¥»÷ÊÂÎñµÄÍ·°æÍ·Ìõ¡£½ü¼¸Äê £¬ÀÕË÷¹¥»÷ÊÂÎñ²ã³ö²»Çî £¬¶ÔÊܺ¦ÆóÒµ/×éÖ¯Ôì³É³Á´ó²Æ¸»Ëðʧ £¬ÀÕË÷²¡¶¾ÒѾ­³ÉΪ¸÷µ±²¿ÃÅÃÅ¡¢×éÖ¯ºÍÆóÒµ±ØÒªÃæ¶ÔµÄ³ÁÒªÍøÂç·çÏÕÖ®Ò»¡£×ÔÈ¥ÄêÆðÍ· £¬ÀÕË÷×éÖ¯Öð²½ÆðÍ·°ÑÖ¸±êÑÓ³¤µ½VMware vSphereƽ̨ÉÏ £¬Í¨¹ý¶ÔÆäÖÐESX/ESXi·þÎñÆ÷ÉϵÄÊý̨Ðé¹¹»úϵͳÎļþ½øÐмÓÃÜ´Ó¶øÏòÊܺ¦×éÖ¯/ÆóÒ·ÕË÷¸ß¶îµÄÊê½ð¡£È¥Äê7Ô £¬Sprite SpiderÀÕË÷×éÖ¯¾ÍÆðÍ·¶ÔÆäÀÕË÷Èí¼þ½øÐÐÉý¼¶ £¬Ê¹ÆäÔÚ¼ì²âµ½ESXiÖ÷»úºó²¿ÊðRansomEXX¶ñÒⷨʽÊÔͼÇÔÈ¡µÇ¼ƾ֤ÏòvCenter½øÐÐÉí·ÝÈÏÖ¤£»Í¬Ñù¶ÔÀÕË÷Èí¼þ½øÐÐESX/ESXiÕë¶ÔÐÔÉý¼¶µÄ»¹ÓÐÀÕË÷×éÖ¯carbon spider¡¢BabukLocker¡¢REvilºÍBlackMatter¡£×ÔÈ¥ÄêÆðÍ· £¬Õë¶ÔVMwareÐé¹¹»úµÄÀÕË÷²¡¶¾¹¥»÷ÊÂÎñÒ²ÆðͷƵ·¢ £¬È¥Äê11Ô°ÍÎ÷¸ßµµ·¨Ôº£¨STJ£©Êܵ½´ó¹æÄ£ RansomExx ÀÕË÷Èí¼þ¹¥»÷ £¬³¬¹ý1000̨Ðé¹¹»úÎļþ±»¼ÓÃÜ £¬Õâ´ÎÊÂÎñÓë7Ô·ݽøÐÐVMware ESX/ESXiÈí¼þÉý¼¶µÄSprite SpiderÀÕË÷×éÖ¯ÊÇ·ñÓйØÁª £¬ÎÒÃÇÎÞ´ÓµÃÖª£»²»½ö¹ú±íÓû§Ôâ·êÁËÕë¶ÔVMware ESX/ESXiµÄÀÕË÷¹¥»÷ £¬¹úÄÚÓû§Í¬ÑùÒ²Ôâ·êÁË´ËÀ๥»÷ £¬ÔÚ½ñÄê3Ô £¬¹úÄÚij¹«Ë¾ÔËάÈËÔ±·¢ÏÖ¹«Ë¾ÄÚ²¿VMware ESXiÖ÷»úÉÏ´óÁ¿Ðé¹¹»úÎļþ±»¼ÓÃÜ £¬ÎÒÃÇÕû¶ÙµÄÓйصÄÊÂÎñ¹¦·òÏßÈçͼ5¡£


ÀÕË÷²¡¶¾Õë¶ÔvSphereÓйØÊÂÎñ¹¦·òÏß.png


ͼ5. ÀÕË÷²¡¶¾Õë¶ÔvSphereÓйØÊÂÎñ¹¦·òÏß


´ÓÈ¥ÄêÆðÍ· £¬IABsÍŶÓÖð²½ÓëÀÕË÷²¡¶¾Ò»Â·½øÈ빫¼ÒµÄÊÓÒ°¡£IABsÍŶÓ×÷ÎªÍøÂç¹¥»÷µØÏ²úÒµµÄ³Ö¾Ã»îÔ¾²Î¼ÓÕß £¬Í¨¹ýÔÚ¸÷´óÂÛ̳ÏúÊÛÖ÷»úȨÏÞÀ´»ñÈ¡ÀûÒæ £¬ËüÃǽ«Êܺ¦ÕßÖ÷»úµÄrootȨÏÞÏúÊÛ¸øÆäËûÍøÂç¹¥»÷´ÓÒµÕß £¬ÓÉÆäËûÍøÂç¹¥»÷Õß·¢Õ¹ÏÂÒ»²½µÄ¹¥»÷»î¶¯ £¬IABsÍŶӲ¢²»Ö±½Ó²Î¼Ó¹¥»÷ £¬ÕâÒ²Ï÷¼õÁËËüÃDZ»ÆäËû·¨ÂÉ»ú¹¹×·×ٵķçÏÕ¡£ÔÚÒÔÍùµÄÀÕË÷¹¥»÷ÖÐ £¬ÎÒÃÇÎÞ·¨È·¶¨ÀÕË÷×éÖ¯ÊÇ·ñÊÇ´ÓIABsÍŶÓÊÖÖвɰìÊܺ¦ÕßÖ÷»úȨÏÞ £¬ÀÕË÷×éÖ¯ÓëIABsÍŶӺÏ×÷ÕâÖÖģʽ¿ÉÄÜÔçÒѳöÏÖ £¬µ«ÊÇÕâÖÖºÏ×÷ģʽÔÚÖð²½±»¸÷¸öÀÕË÷×é֯ѡȡ£º¾ÝÐÂÎųÆ £¬ÃÀ¹ú×î´óȼÓ͹Ü·ÀÕË÷ÊÂÎñÖеÄÖ÷½ÇDarkSideÔÚÀÕË÷ÃÀ¹úʯÓ͹Ü·ÔËÓªÉÌColonial Pipeline֮ǰ¾ÍÔøÔÚµØÏÂÂÛ̳·¢ÎÄѰÕÒ¿ÉÄÜÈÃÆä½Ó´¥µ½ÊÐÖµ4ÒÚÃÀÔª¹«Ë¾µÄIABsºÏ×÷ £¬Èçͼ6 £¬ÃÀ¹úȼÓ͹Ü·ÀÕË÷ÊÂÎñÊÇ·ñÓÐIABsÍŶӲμÓ £¬ÎÒÃÇÎÞ´Ó¿¼Ö¤£»Áí±í £¬ÔÚµØÏÂÂÛ̳ÖÐ £¬ÎÒÃÇÒ²¹Û²ìµ½Óжà¸öIABsÔÚ×·ÇóÀÕË÷ÍŶӺÏ×÷²¢ÏúÊÛvCenter/ESXiµÄRootȨÏÞ £¬Èçͼ7¡£


ͼ6. DarkSide×·ÇóÓëIABsÍŶӺÏ×÷.png


ͼ6. DarkSide×·ÇóÓëIABsÍŶӺÏ×÷


ÀÕË÷×èÖ¹½á¹¹.png


ͼ7. IABsÍŶÓ×·ÇóÓëÀÕË÷×éÖ¯ºÏ×÷


ËÄ¡¢ Õë¶ÔvSphereÀÕË÷µÄÔ­Òò·ÖÎö


¶à¶àÀÕË÷×éÖ¯ÆðÍ·½«Ö¸±êÑÓ³¤µ½vSphereƽ̨ÉÏ £¬ÎÞ·ÇÊÇΪÁ˼ÓÃܸü¶à¸ü³ÁÒªµÄÊý¾ÝÒÔÀÕË÷¸ü¸ß¶îµÄÊê½ð¡£Õë¶ÔvSphereƽ̨µÄÀÕË÷¹¥»÷ £¬¿ÉÄÜʹÀÕË÷×éÖ¯Ïñ½ÚÔìÒ»¼äÆóÒµ·þÎñÆ÷µÄ»ú·¿Ò»Ñù¶ÔÊý̨·þÎñÆ÷½øÐнÚÔì £¬¹¥»÷Õß¶ÔÕâЩÐé¹¹»úµÄÔ´Îļþ½øÐмÓÃÜ £¬¿ÉÄÜÖ±½ÓÔì³ÉÊý¾Ý¿â±»¼ÓÃÜ¡¢¶Ô±íÌṩ·þÎñÖжÏÉõ´ó¹«Ë¾ÏµÍ³Ì±»¾ £¬ÀÕË÷×éÖ¯ÍùÍù¿ª³ö¸ü¸ß¶îµÄÊê½ð¡£Èç´Ë¸ªµ×³éнµÄÀÕË÷·½Ê½ £¬ÈÃÊܺ¦Õ߯óÒµ/×éÖ¯¶Ì¹¦·òÄÑÒÔÓ¦³ê £¬¼«´óµØÔö³¤ÁËÀÕË÷¹¥»÷µÄ³É¹¦ÂʺÍÊÕÒæ¡£Æäʵ £¬Ëæ×Å»¥ÁªÍø¼¼ÊõµÄ¸Ä¸ï £¬ÀÕË÷×éÖ¯Ò»ÏòÔÚ²»ÐÝѰÕÒÐµĹ¥»÷Ö¸±êºÍ¹¥»÷¼¿Á© £¬ÀÕË÷×éÖ¯×ö³ö ¡°Õë¶ÔvSphereƽ̨¹¥»÷¡± µÄÕâÖÖŤת²¢·ÇÎÞÒâ £¬½áºÏÓйØ×ÊÁÏ £¬ÎÒÃǽ«ÔÚ±¾Õ¶ÔÀÕË÷×éÖ¯µÄÕâÖÖŤת½øÐÐÒ»¸öÔ­Òò·ÖÎö¡£


²¼¾°Ç°Ìá£ºËæ×Å»¥ÁªÍø¼¼ÊõµÄ¼±¾ç¸üР£¬ÍøÂçÓû§Á¿¾çÔö £¬¸÷¸öµ±²¿ÃÅÃÅ¡¢×éÖ¯ºÍÆóÒµ¶ÔÍÆËã×ÊÔ´ºÍ´æ´¢×ÊÔ´µÄÐèÒªÖèÔö£»ÔÆÍÆËãºÍÐé¹¹¼¼ÊõµÄ¹ÄÆðÈø÷´óÔÆ·þÎñÌṩÉ̺ÍÐé¹¹»¯¼¼Êõ¹«Ë¾Îª¸÷¸öµ±²¿ÃÅÃÅ¡¢×éÖ¯ºÍÆóÒµÌṩÁ˶¨Ô컯×ÊÔ´·þÎñºÍÐé¹¹»¯½â¾ö¹æ»®ÒÔÂú×ãÈÕ³£×ÊÔ´ÐèÒª¡£VMware×÷ÎªÔÆ·þÎñºÍÐé¹¹»¯ÁìÓòµÄÁìÍ·ÆóÒµ £¬Æä¿Í»§ÏÕЩº­¸ÇËùÓÐÁìÓò£»³ý´ËÖ®±í £¬¸÷´óÔÆ·þÎñÌṩÉÌҲΪÆä¿Í»§Ìṩ¼ä½ÓµÄVMwareÐé¹¹»¯·þÎñ £¬´Óͼ8 ¡°2020Äê·þÎñÆ÷Ðé¹¹»¯Êг¡É¢²¼¡± ÖÐÄܹ»¿´³ö £¬VMwareÒѾ­³ÉΪÐé¹¹»¯Êг¡µÄ¾ø¶Ô°ÔÖ÷¡£Õë¶ÔVMware vSphere½øÐÐÀÕË÷Äܹ»Õ¼Óжà¶àÀÕË÷¶ÔÏó £¬Í¬Ê±¿ÉÄÜͨ¹ýÐé¹¹»¯Æ½Ì¨vSphere½ÚÔìÆóÒµ/×éÖ¯µÄ´óÁ¿Êý×Ö×ʲú £¬¼«´óµØÌá¸ßÁËÀÕË÷µÄÊÕÒæºÍ³É¹¦ÂÊ¡£


·þÎñÆ÷Ç÷Ïò.png


ͼ8. 2020Äê·þÎñÆ÷Ðé¹¹»¯½â¾ö¹æ»®µÄÒµÎñÊг¡É¢²¼£¨ÆðÔ´£ºspiceworks£©


¼¼ÊõǰÌ᣺2019Äêµ×ºÍ2020Äê £¬VMware±ðÀë°ä²¼°²È«¹«¸æ½¨¸´Á˶à¸ö²úÆ··ì϶ £¬ÆäÖÐVMware ESXiµÄÁ½¸ö·ì϶CVE-2019-5544ºÍCVE-2020-3992½«µ¼ÖÂVMware ESXi·þÎñÆ÷ÉϵÄÔ¶³Ì´úÂëÖ´ÐÐ £¬VMwareÒѾ­¶ÔÕâÁ½¸ö·ì϶½øÐÐÁËÆÀ¹À £¬²¢¶¨¼¶ÎªÑϳÁ £¬CVSSv3 ÆÀ·Ö 9.8¡£ÕâÁ½¸ö·ì϶½«Ó°Ïì¶à¸ö°æ±¾µÄVMware vSphereÓû§ £¬ËæºóVMwareÌṩ½¨¸´²¹¶¡ £¬µ«ÈÔÓдóÅú¿Í»§ÓÉÓÚ¸÷ÀàÔ­Òò²¢Î´¶ÔÆäʹÓõÄESX/ESXi½øÐв¹¶¡ £¬ÕâΪ¹¥»÷ÕßÌṩÁ˱ã½ÝµÄÈëÇÖVMware ESX/ESXiÖ÷»úµÄ²½ÖèºÍ¼¿Á©¡£


±í²¿Ç°Ì᣺×Ô2020ÄêÆð £¬IABsÒ²½«ÆäÖ¸±êÀ©´óµ½ÁËVMware vSphereƽ̨ÉÏ¡£¶Ô´ó²¿ÃÅÀÕË÷×éÖ¯À´Ëµ £¬ÓëIABsºÏ×÷ÊÇÒ»Ïî¹²Ó®µÄÑ¡Ôñ,ÓÉÓÚ´ÓIABsÊÖÉϲɰìESX/ESXiÖ÷»úȨÏ޵ļÛÖµÒ²½ö½öÖ»ÊÇÊê½ðµÄ¼«Óײ¿ÃÅ £¬Í¨¹ýÕâÖÖ·½Ê½ £¬ËûÃÇ¿ÉÄÜʡȥ´óÁ¿µÄÈËÁ¦¡¢¹¦·ò¡¢×ÊÔ´È¥»ñÈ¡ESX/ESXiÖ÷»úµÄRootȨÏÞ £¬Ö±½Óͨ¹ý²É°ìµÄÖ÷»úRootȨÏÞ½øÐÐÊܺ¦ÕßÖ÷»úµÇ¼ £¬¶øºóÆðÍ·²¿ÊðÀÕË÷Èí¼þ½øÐÐÀÕË÷¡£Í¬Ê± £¬ÎÒÃǹ۲쵽ÓÐIABs£¨Initial access brokers£©ÆðÍ·ÔÚµØÏºڿÍÂÛ̳ÉÏÒÔ250ÃÀ½ðµ½500ÃÀ½ðÖ®¼ä¼ÛÖµÏúÊÛESX/ESXiµÄRootȨÏÞ £¬²¢Õ¹Ê¾³ö¸ü¶à¹ØÓÚÊܺ¦Ö÷»úµÄÐÅÏ¢À´ÎüÒý¿Í»§²É°ì £¬ºÃ±ÈµØÓòÐÅÏ¢¡¢È¨ÏÞÐÅÏ¢¡¢CPUÐÅÏ¢¡¢Ó²ÅÌÐÅÏ¢µÈ £¬Èçͼ9Ëùʾ £¬¹úÄÚijÓû§µÄVMware ESXÖ÷»úµÄRootȨÏÞÔÚµØÏºڿÍÂÛ̳±»ÏúÊÛ¡£


IABsÔÚµØÏÂÂÛ̳ÉÏÊÛÂôESXȨÏÞ.png


ͼ9. IABsÔÚµØÏÂÂÛ̳ÉÏÊÛÂôESXȨÏÞ


Îå¡¢ Õë¶ÔvSphereµÄÀÕË÷Ñù±¾·ÖÎö


×ÔÈ¥ÄêÆðÍ· £¬¸÷´óÀÕË÷×éÖ¯ÆðÍ·°ä²¼Õë¶ÔVMware vSphereÐ鹹ƽ̨°æ±¾µÄÀÕË÷·¨Ê½ £¬ÒѾ­Óжà¼ÒÆóÒµ/×éÖ¯Ôâµ½¹¥»÷²¢ÇÒËðʧ²Ò³Á¡£ÔÚ±¾Ó×½ÚÖÐ £¬ÎÒÃǽ«ÒÔADLab¶ÔÀÕË÷¼Ò×åµÄ³ÖÐø×êÑÐΪ»ù´¡ £¬½áºÏ²¿ÃŹú±í°²È«³§É̶ԴËÀ๥»÷»î¶¯µÄÅû¶À´¶Ô²¿ÃÅÀÕË÷×éÖ¯µÄÑù±¾½øÐзÖÎö £¬Í¬Ê±½áºÏÏÖʵ¹¥»÷°¸Àý¶Ô´ËÀ๥»÷µÄ¹¥»÷Á÷³Ì½øÐÐÁË×ܽá¡£Èçͼ10 £¬ÔÚÏÖʵ³¡¾°ÖÐ £¬ESX/ESXiÖ÷»úÉϻᲿÊð¶ą̀Ðé¹¹»ú¶Ôͨ³£Óû§Ìṩ¸ù»ù·þÎñ £¬ÈôÊÇÅäÖò»µ± £¬Í¨³£Óû§ÄÜͨ¹ýÍøÂçÄܽӼûESX/ESXiÖ÷»ú £¬Õâ¾Í»á¸øºÚ¿ÍÌṩ¿É³ËÖ®»ú£»Í¨³£Çé¿öÏ £¬ºÚ¿ÍÊ×ÏÈ»áÔÚµØÏÂÂÛ̳ÖÐ×·ÇóÖ¸¶¨°æ±¾µÄESX/ESXi·ì϶ÀûÓ÷¨Ê½»òrootµÇ¼ȨÏÞ £¬µ±»ñÈ¡µ½·ì϶ÀûÓ÷¨Ê½»òrootµÇ¼ȨÏÞºó £¬ºÚ¿Í¾ÍÄÜÖ±½ÓÈëÇÖESX/ESXiÖ÷»ú²¢ÇÒÔÚÆäÖв¿ÊðÀÕË÷Èí¼þ¶ÔÆäÖеÄÐé¹¹»ú½øÐмÓÃܲ¢ÀÕË÷Êê½ð¡£´ÓͼÖÐÄܹ»¿´³ö £¬ÈôÊÇÀÕË÷¹¥»÷¶ÔÏóÊÇÔÆ·þÎñÌṩÉÌ/Ðé¹¹·þÎñÌṩÉ̵ÄESX/ESXiÖ÷»ú £¬ÄÇô¸ÃÌṩÉ̵Ķà¶à¿Í»§¶¼½«Êܵ½Ó°Ïì £¬´óÃæ»ýµÄÆóÒµÓû§Ö÷»ú½«Ôâµ½ÀÕË÷²¡¶¾Ï°È¾ £¬Õ⽫´øÀ´Óë½ñÄêÃÀ¹úITÖÎÀíÈí¼þÔì×÷ÉÌKaseyaÔâµ½µÄ¹©¸øÁ´Ê½ÀÕË÷¹¥»÷ÀàËÆµÄÁ˾Ö £¬¶øKaseyaµÄÀÕË÷¹¥»÷ÒѾ­Ï°È¾Á˳¬¹ý100Íò¸öϵͳ £¬³¬¹ý1500¼ÒÆóÒµÊܵ½Ó°Ïì¡£


Õë¶ÔvSphereÐ鹹ƽ̨µÄÀÕË÷¹¥»÷³¡¾°.png


ͼ10. Õë¶ÔvSphereÐ鹹ƽ̨µÄÀÕË÷¹¥»÷³¡¾°


½ÓÏÂÀ´ £¬ÎÒÃǽ«¶Ô²¿ÃÅÀÕË÷×éÖ¯µÄÑù±¾½øÐоßÌå¼¼Êõ·ÖÎö £¬Í¨¹ýºáÏò±È¶Ô £¬Äܹ»×ܽá³öÕâЩÕë¶ÔVMware vSphereÐ鹹ƽ̨ÀÕË÷·¨Ê½µÄÖ´ÐÐÌØµã£ºÍ¨³£Çé¿öÏ £¬ÀÕË÷Èí¼þÊ×ÏÈ»áʹÓÃESX/ESXiµÄesxcliÖ¸Áî²éÕÒÐé¹¹»ú¹ý³Ì£»¶øºó £¬¶ñÒⷨʽ»áʹÓÃesxcliÖ¸Áî¹Ø¹ØÐé¹¹»ú £¬ÕâÒ»²½Í¨³£ÊÇΪÁËÔ¤·À¶ÔÐé¹¹»úÎļþ½øÐмÓÃÜʱ¶ÔÐé¹¹»úÔ­ÎļþÔì³É·ÛËé £¬´Ó¶øµ¼Ö¼ÓÃÜʧ°Ü£»½ÓÏÂÀ´ £¬¶ñÒⷨʽ½«ÔÚÖ¸¶¨õ辶ϽøÐÐÐé¹¹»úÓйØÎļþËÑË÷£¨Í¨³£Ô̺¬Ðé¹¹»úÐé¹¹´ÅÅÌÎļþvmdk¡¢Ðé¹¹»úÐé¹¹ÄÚ´æÎļþvmem¡¢Ðé¹¹»úÒ³»¥»»Îļþvswp £¬ÈÕÖ¾Îļþlog¡¢Ðé¹¹»ú¿ìÕÕÎļþvmsnµÈ£©£»×îºó £¬¶ñÒⷨʽ½«¶ÔËÑË÷µ½µÄÐé¹¹»úÓйØÎļþ½øÐмÓÃÜ £¬Í¬Ê±·î¸æÊܺ¦Õß½ÉÄÉÊê½ð¡£


5.1 DarkSide

DarkSideÀÕË÷Èí¼þ×îÔçÓÚ2020Äê8Ô±»·¢ÏÖ £¬ÊÇÒ»Ö§·Ç³£»îÔ¾µÄÐÂÐËÀÕË÷ÍŻDarkSide×éÖ¯×Ô2020Äê8ÔÂÆðͷƵÈԻ £¬²¢ÔÚ½ñÄê5Ô¹¥»÷ÁËÃÀ¹ú×î´óµÄȼÓ͹Ü·¹«Ë¾Colonial Pipeline £¬µ¼ÖÂÃÀ¹ú¶«²¿Ñغ£ÖØÒª³ÇÊÐÊäËÍÓÍÆøµÄ¹Ü·ϵͳ±»ÆÈÏÂÏß £¬17¸öÖݺÍÊ×¶¼µØµãµÄ»ªÊ¢¶ÙÌØÇø°ä·¢½øÈ봹Σ״̬ £¬ÒýÆðÁ˾޴óµÄºä¶¯ºÍÈ«ÇòµÄ¹Ø×¢¡£×îÖÕ £¬Colonial PipelineÖ§¸¶Á˽ü75±ÈÌØ±Ò£¨Ô¼ºÏ½ü500ÍòÃÀÔª£©²ÅʹÊý¾ÝµÃÒÔ¸´Ô­ £¬ÔËÊ乤×÷Õý³£ÔËÐС£Í¬Ê±ÎÒÃÇÒ²·¢ÏÖ £¬DarkSideÔÚÈ¥Äê¾ÍÒѾ­¾ß±¸¹¥»÷ESXiµÄÖ°ÄÜ¡£


Ñù±¾¼¼Êõ·ÖÎö


ΪÁ˸üºÃµØ¼ÓÃÜÐé¹¹»ú £¬DarkSideʹÓÃÁ˺ܶàESXiÉ϶ÀÓеÄesxcliºÅÁî £¬ÈçÔÚ¼ÓÃÜÐé¹¹»úǰ»áʹÓÃesxcliºÅÁîÀ´±éÀú³öESXiÉÏÔÚÔËÐеÄÐé¹¹»ú¡£


DarkSideʹÓÃesxcliºÅÁîÇ¿Ôì¹Ø¹ØÔÚÔËÐеÄÐé¹¹»ú.png


³ýÁËÒÔÉϺÅÁî £¬ÔÚDarkSide»¹ÓÃÁ˺ܶàesxcliºÅÁî £¬¾ßÌåÈçϱíËùʾ£º

¼ÓÃÜõè¾¶.png

DarkSideͨ¹ý±éÀúÎļþ £¬²¢ÇÒÅжÏÎļþºó׺ÊÇ·ñΪvmdk£¨Ðé¹¹»úÐé¹¹´ÅÅÌÎļþ£© £¬vmem£¨Ðé¹¹»úÐé¹¹ÄÚ´æÎÄÎļþ£© £¬vswp£¨Ðé¹¹»úÒ³»¥»»Îļþ£© £¬log£¨ÈÕÖ¾Îļþ£© £¬vmsn£¨Ðé¹¹»ú¿ìÕÕÎļþ£©À´¾ö¶¨ÊÇ·ñ½øÐмÓÃÜ £¬¼ÓÃܳɹ¦ºó»áÔÚÔ­Îļþºó׺ºó²ÎÓëdarkside¡£


Îļþ´óÓ×ÅжÏ.png


×îºó £¬DarkSide»áÁôÏÂÀÕË÷ÐÅÖÒ¸æÊܺ¦Õß £¬²¢ÇÒÔÚÐÅÖÐÁôÏ»¹Ô­Êý¾ÝµÄ·½Ê½ÒÔ¼°½»Êê½ðµÄµØÖ· 


ÀÕË÷ÐÅ.png


5.2 REvil


REvilÒ²±»³ÆÎªSodinokibi £¬ÊÇÒ»¸ö³ôÃûÔ¶ÑïµÄÀÕË÷ÍÅ»ï £¬Æä¹¥»÷×îÔçÄܹ»×·Òäµ½2019Äê4Ô¡£¸ÃÀÕË÷ÍÅ»ï×÷°¸ÆµÈÔ £¬²¢Ôø¹¥»÷¹ý¶à¸ö´óÐ͹«Ë¾ÈçÃÀ¹úµ±ÏȵÄÊÓÆµ´«ÊäÌṩÉÌSeaChange International¡¢³ÛÃûÓ²¼þºÍµç×Ó¹«Ë¾ºê»ù¹«Ë¾¡¢È«ÇòÔÙÉúÄÜÔ´¾Þë¢Invenergy¹«Ë¾¡¢È«Çò×î´óÈâÀ๩¸øÉÌJBS¹«Ë¾¡£¶øÔÚ½ñÄê7ÔÂÃÀ¹úÔ¶³ÌITÖÎÀíÈí¼þ³§ÉÌKaseyaÒ²Ôâ·êµ½ÁËREvilµÄ¹¥»÷ £¬µ¼ÖÂÈ«Çò³¬¹ý10000¼ÒµÄKaseya¿Í»§ £¬ÆäÖÐÔ̺¬50%ÒÔÉϵÄÈ«Çò100Ç¿ITÖÎÀí·þÎñÌṩÉ̼°¸÷´óÁúÍ·Êܵ½ÀÕË÷¹¥»÷µÄ·çÏÕ¡£¾Ý³ÆÕâ´Î¹¥»÷ÊÇREvilÓÐÊ·ÒÔÀ´¹æÄ£×î´óµÄÒ»´Î¹¥»÷ £¬¾ÝÆä¹ÙÍøÐû³Æ £¬ËûÃÇÒѾ­Ëø¶¨Á˳¬¹ý100Íò¸öϵͳ £¬²¢ÏòKaseyaË÷È¡70000000ÃÀÔªµÄÊê½ð¡£¶øÔÚ½ñÄê5Ô £¬ÎÒÃǹ۲쵽REvilÔËÓªÉÌÔÚµØÏºڿÍÂÛ̳Éϰ䲼ÁËÕë¶ÔVmware ESXiµÄLinux°æ±¾¡£


Ñù±¾¼¼Êõ·ÖÎö


ΪÁËÔ¤·ÀÐé¹¹»úÓйصÄÎļþÊܵ½²»ÓÃÒªµÄ°Ü»µ £¬REvilÔÚ¼ÓÃÜǰҲͬÑù»áÏȹعØESXiÉÏÔÚÔËÐеÄÐé¹¹»ú £¬µ«ÓëDarkSide·ÖÆçµÄÊÇREvilÏÈʹÓÃpkill -9µÄºÅÁî¹Ø¹ØÓëÐé¹¹»úÓйصĹý³Ì¡£


ºÅÁî¹Ø¹Ø.png

¶øºóREvilʹÓÃexcliºÅÁî±éÀú³öËùÓÐÔÚÔËÐеÄESXiÐé¹¹»ú²¢ÇҹعØËüÃÇ £¬Ê¹Óô˺ÅÁî»á¹Ø¹Ø´æ´¢ÔÚ /vmmfs/ Îļþ¼ÐÖеÄÐé¹¹»ú´ÅÅÌ (VMDK) Îļþ £¬Ô¤·ÀREvil¶ÔÕâЩÎļþ½øÐмÓÃÜʱÓÉÓÚ±» ESXi Ëø¶¨¶øµ¼Ö¼ÓÃÜʧ°Ü¡£


ºÅÁî¹Ø¹Ø»úе.png

ÓëÆäËûÕë¶ÔESXiµÄÀÕË÷Èí¼þ·ÖÆçµÄÊÇ £¬REvil²»»á¶ÔÐé¹¹»úÎļþµÄºó׺½øÐÐÅжÏ £¬¶øÊǶԼÓÃÜõè¾¶ÏÂËùÓеÄÎļþ¶¼½øÐмÓÃÜ £¬²¢ÅжϸÃÎļþÊÇ·ñÒѾ­±»¼ÓÃÜÁ˺ÍÊÇ·ñÓµÓÐRWXȨÏÞ»òÕßRWȨÏÞ£¨ÈôÊÇÓµÓÐÕâЩȨÏÞ £¬ÔòÕâЩÎļþÊDZ»ÏµÍ³±£»¤µÄ£©À´¾ö¶¨ÊÇ·ñ½øÐмÓÃÜ¡£ 


¼ÓÃÜÎļþ¹ý³Ì.png


×îºó £¬REvilÁôÏÂÀÕË÷ÐÅÖÒ¸æÊܺ¦Õß²¢ÇÒÔÚÐÅÖÐÁôÏ»¹Ô­Êý¾ÝµÄ·½Ê½ÒÔ¼°½»Êê½ðµÄµØÖ·¡£


ͼ20. REvilµÄÀÕË÷ÐÅ.png

ͼ20. REvilµÄÀÕË÷ÐÅ



5.3 HelloKitty


HelloKittyÀÕË÷Èí¼þ¹¥»÷»î¶¯×îÔçÄܹ»×·Òäµ½2020Äê £¬ÖØÒªÕë¶ÔWindowsϵͳ¡£ÆäÔÚ2021Äê2Ô¹¥»÷ÁËCD Projekt Red¹«Ë¾²¢Ðû³ÆÇÔÈ¡Á˸ù«Ë¾³öÆ·µÄ¡°Cyberpunk 2077¡±¡¢¡°Witcher 3¡±¡¢¡°Gwent ¡±ºÍÆäËûÓÎÏ·µÄÔ´´úÂë¡£¶øÔÚ½ñÄê7Ô £¬ÎÒÃǹ۲쵽¸ÃľÂíµÄLinux±äÌåÆðÍ·Õë¶ÔVmware ESXi½øÐй¥»÷¡£ÆäÖÐ £¬±»¹¥»÷µÄÖ¸±êÔ̺¬Òâ´óÀûºÍºÉÀ¼µÄÔìÒ©¹«Ë¾¡¢Ò»¼ÒµÂ¹úÔì×÷ÉÌ¡¢Ò»¼Ò°Ä´óÀûÑÇÌṩ¹¤Òµ×Ô¶¯»¯½â¾ö¹æ»®µÄ¹«Ë¾ÒÔ¼°ÃÀ¹úÒ»¼ÒÒ½Áư칫ÊÒºÍ¹ÉÆ±¾­¼ÍÈË¡£ÔÚÊê½ð·½Ãæ £¬¹¥»÷Õß»áÒò¹¥»÷Ö¸±ê¹«Ë¾µÄ¹æÄ£·ÖÆç £¬¶øÒªÇóÖ§¸¶·ÖÆç½ð¶îµÄÊê½ð £¬ÆäÀÕË÷µÄÊê½ð×î¸ß¿É´ï1000ÍòÃÀ½ð¡£


Ñù±¾¼¼Êõ·ÖÎö


HelloKittyÀÕË÷Èí¼þÊ×ÏÈ»áʹÓÃesxcliºÅÁîÀ´±éÀú³öµ±Ç°ÊÜϰȾ»úеÉÏÔÚÔËÐеÄÐé¹¹»ú¹ý³Ì £¬²¢³¢ÊԹعØÕâЩÐé¹¹»ú¡£ÎªÁËÔ¤·ÀÐé¹¹»úÓйصÄÎļþÔâµ½²»ÓÃÒªµÄ°Ü»µ £¬¸Ã²¡¶¾ÔÚ¼ÓÃÜÎļþǰ»áÏȽ«Ðé¹¹»ú¹Ø¹Ø¡£


¸ÃÀÕË÷Èí¼þ³õ´Î¹Ø¹ØÐé¹¹»ú £¬»áʹÓÃÈíÖÕÖ¹À´ÊµÏָùý³Ì¡£


ºÅÁesxcli vm process kill -t=soft -w=%d


ÈôÊÇÈÔÓÐÐé¹¹»úÔÚÔËÐÐ £¬¸Ã²¡¶¾½«»áʹÓÃÓ²ÖÕÖ¹À´ÊµÏָùý³Ì¡£


ºÅÁesxcli vm process kill -t=hard -w=%d


ÈôÊÇ»¹ÓÐÐé¹¹»úδ±»¹Ø¹Ø £¬Ôò»áʹÓÃÇ¿ÔìÖÕÖ¹À´ÊµÏָùý³Ì¡£


ºÅÁî·û.png

Êê½ðÎı¾.png


5.4 BlackMatter

2021Äê7Ô £¬Ò»¸öÃûΪBlackMatterµÄÐÂÀÕË÷Èí¼þ×éÖ¯ÔڲɰìÆóÒµÍøÂçµÄ½Ó¼ûȨÏÞ £¬Í¬Ê±Ðû³ÆÆäÏîÄ¿Òѽ«REvilºÍDarkSideµÄ×î¼ÑÖ°ÄÜÈÚÈëÆäÖС£BlackMatter»¹°µÊ¾ £¬ËûÃǵÄÀÕË÷Èí¼þºÏÓÃÓÚ¶àÖÖ·ÖÆçµÄ²Ù×÷ϵͳ°æ±¾ºÍ¼Ü¹¹ £¬²¢ÒÔ¶àÖÖÌåʽÌṩ¡£Ô̺¬Ö§³Ö°²È«Ä£Ê½µÄWindows±äÌ壨Windows Server2003+x86/x64ºÍWindows7+x86/x64£©ºÍÖ§³ÖNASµÄLinux±äÌ壨ESXI5+¡¢Ubuntu¡¢DebianºÍCenOs£© £¬ÇÒÕâЩ±äÌåÔÚÒ»ÑùϵͳÉϾùÒѲâÊԳɹ¦¡£


Ñù±¾¼¼Êõ·ÖÎö


BlackMatterÔÚESXI·þÎñÆ÷ÉÏÔËÐÐʱ £¬ÆäÊ×ÏÈʹÓÃesxcliºÅÁîÁгöËùÓÐÔÚÔËÐеÄVMwareÐé¹¹»ú¡£


Ðé¹¹»ú.png

½Ó×Å £¬BlackMatter»á»ñÈ¡µ±Ç°ÏµÍ³ËùÓÐÔÚÔËÐеĹý³Ì £¬²¢½«ÕâЩ¹ý³ÌÇ¿ÔìʵÏÖ¡£ 


ÅäÖÃÎļþ.png

¼ÓÃÜÎļþºó׺.png

ÀÕË÷Îı¾.png

Áù¡¢ ×ܽáÓ뽨Òé


Õë¶ÔÐé¹¹»¯Æ½Ì¨VMware vSphereµÄÀÕË÷¹¥»÷³ÉΪÀÕË÷×éÖ¯µÄÐÂÐ͹¥»÷·½Ïò £¬±¾ÎÄ´Ó¶à¸ö½Ç¶È¶Ô´ËÀ๥»÷½øÐÐÁË×ۺϷÖÎö¡£Õë¶ÔÐé¹¹»¯Æ½Ì¨VMware vSphereµÄÀÕË÷¹¥»÷¿ÉÄÜ»áÔ½·¢ÆµÈÔ£ºÊ×ÏÈ £¬¹¥»÷Õß¶ÔÐé¹¹»úÖÎÀíÆ½Ì¨µÄESX/ESXiÖ÷»ú½øÐÐϰȾºóÄܹ»¶ÔÆäÖеÄÊý̨Ðé¹¹»úÔ´Îļþ½øÐмÓÃÜ £¬½«Ö±½ÓÓ°ÏìÊܺ¦ÆóÒµ/×éÖ¯µÄ¶ą̀ÀûÓ÷þÎñÆ÷/Êý¾Ý¿â £¬ÕâÖÖ·½Ê½½ÚÔìÁËÔ½·¢³ÁÒªÆóÒµ/×éÖ¯µÄÊý×Ö×ʲú £¬¿ÉÄÜÀÕË÷¸ü¸ß¶îµÄÊê½ð²¢ÇÒ´ó´óÌá¸ß³É¹¦ÂÊ £¬ÕâÕýÊÇÀÕË÷×éÖ¯µÄÖ÷±êÌâ±ê£»Æä´Î £¬Ô½À´Ô½¶àµÄºÚ¿Í½«Ö¸±êתÏòÁËVMware vSphere £¬Óйصݲȫ·ì϶ÔÙÈý±»·¢ÏÖ £¬µ«ºÜ¶à¿Í»§ÓÉÓÚ¸÷ÀàÔ­ÒòÏ޶Ȳ¢Î´ÄÜʵʱ²¹¶¡ £¬ÕâҲΪÀÕË÷×éÖ¯ÈëÇÖµ½ÆóÒµµÄESX/ESXiÖ÷»úÌṩÁË·½±ã£»Áí±í £¬IABsÍŶÓÔÚµØÏÂÂÛ̳ÖÐÕë¶ÔVMware vSphereµÄ»î¶¯Ò²Ô½¼ÓƵÈÔ £¬Í¬Ê±ËüÃÇÒ²ÔÚ»ý¼«×·ÇóÓëÀÕË÷×éÖ¯½øÐкÏ×÷ £¬IABsÍŶӿÉÄÜÌṩרҵESX/ESXiÖ÷»úµÄÈëÇÖ·þÎñ £¬ËüÓëÀÕË÷×éÖ¯µÄºÏ×÷½«»á°ÑÕë¶ÔvSphereµÄÀÕË÷¹¥»÷ÍÆÉÏÐÂÒ»ÂÖµÄÈȳ±¡£


Äܹ»¿´³ö £¬Ëæ×Å»¥ÁªÍø¼¼ÊõµÄ²»ÐݸĸïºÍÊг¡µÄ±ä¶¯ £¬ÀÕË÷×éÖ¯Ò²ÔÚ²»ÐÝÀ©´óËüÃǵĹ¥»÷·½ÏòºÍ×·Çó¸üÓÐЧµÄ¹¥»÷ÊÖ·¨ £¬ÒÔ±ãÔÚÀÕË÷¹¥»÷ÖлñÈ¡¸ü¸ß¶îµÄÊê½ðͬʱ´ó·ùÌá¸ßÀÕË÷µÄ³É¹¦ÂÊ¡£VMware vSphereÖ»ÊǶà¶àÐé¹¹»¯Æ½Ì¨µÄÆäÖÐÒ»¸ö £¬Ö»ÊÇÓÉÓÚËüµÄÊг¡ÖØ´ó £¬³ÉΪÁ˹¥»÷ÕßµÄÊ×ѡָ±ê£»Ëæ×ʦ·òµÄÍÆÒÆ £¬ÆäËûÐé¹¹»¯Æ½Ì¨È磺Microsoft¡¢OracleºÍRed HatµÈºÜ¿ÉÄÜ»á³ÉΪ¹¥»÷ÕßµÄÐÂÖ¸±ê £¬¸÷´óÆóÒµ/×éÖ¯¸Ãµ±°ÑÎÈÌáǰ×öºÃÕë¶ÔÐÔ·ÀÓù¡£Õë¶ÔvSphereÐ鹹ƽ̨µÄÀÕË÷¹¥»÷½«¶ÔÊܺ¦Õ߯óÒµ´øÀ´ÄÑÒÔ¹À¼ÆµÄËðʧ £¬ÎÒÃǽ«½áºÏ±¾ÎĵķÖÎöºÍÓйØ×ÊÁÏÏòvSphereÓû§Ìá³öÏÂÃæ¼¸ÌõÕë¶ÔÐÔ·ÀÓù½¨Ò飺


½¨ÒéʹÓà TPM 2.0 оƬ½øÐÐvSphere½øÐа²È«ÅäÖá£


ÔÚÎïÀí·þÎñÆ÷ÉÏÆôÓÃUEFI°²È«Æô¶¯Ö°ÄÜ £¬Í¨¹ýÈ·±£ÔÚÊèµ¼ÖмÓÔØµÄËùÓдúÂë¶¼¾­¹ýÊý×ÖÊðÃûÇÒδ±»´Û¸Ä £¬´Ó¶ø¼ÓÇ¿²Ù×÷ϵͳµÄ°²È«ÐÔ¡£


²»ÈÝÔÚESX/ESXiÖ÷»úÉÏÖ´ÐÐ×Ô½ç˵´úÂë £¬±£ÕÏESX/ESXiÖ÷»ú»Ø¾øÖ´ÐÐÈκÎδͨ¹ýÈÏÖ¤ºÏ×÷ͬ°éÊðÃûµÄ VIB °ü×°ÖõĴúÂë¡£


µ±vSphereƽ̨ÓйصIJúÆ·´æÔÚ°²È«²¹¶¡°ä²¼Ê± £¬»ý¼«²Î¼Óϵͳ¼°ÓйصÄÐé¹¹»¯Æ½Ì¨×é¼þ£¨vCenter·þÎñÆ÷¡¢ESX/ESXiÖ÷»ú¡¢VMware¹¤¾ßµÈ£©µÄ¸üС£


¶ÔÐé¹¹»úƽ̨µÄÖÎÀíÕË»§Ê¹ÓøßÇ¿¶ÈÃÜÂë¡£


ÔÚÄÚ²¿ÍøÂçÖнøÐÐÍøÂçÇøÓò»®·Ö £¬½«¶Ô±í·þÎñµÄÖ÷»úºÍ½öÄÚ²¿½Ó¼ûµÄÖ÷»ú½øÐзָôÖÎÀí £¬²¢ÇÒΪÐ鹹ƽ̨ÖÎÀíÔ±ÌṩרÓõÄvCenter·þÎñÆ÷ºÍESX/ESXiÖÎÀí½Ó¿ÚÒÔ¼°×¨ÓõŤ×÷Õ¾¡£


ÅäÖü¯ÖÐʽµÄ¼Í¼ÈÕÖ¾ £¬Ô¤·ÀÖÎÀíϵͳÅäÖúͻ·¾³Ôâµ½´Û¸Ä¡£


¾¡¿ÉÄ܏߯µÂʵؽøÐÐϵͳ±¸·Ý £¬ÒÔ±ãÔÚÔâµ½ÀÕË÷¹¥»÷ºóÄܾ¡¿ìµØÊµÏÖϵͳ¸´Ô­¡£