作者归档:root

centos7挂载本地yum源的方法

centos7虚拟机环境,光驱连接centos安装镜像。

一、创建目录挂载镜像
mkdir -p /mnt/cdrom
mount /dev/sr0 /mnt/cdrom/

二、创建本地yum源
在/etc/yum.repos.d目录下创建local.repo文件,写入内容:
[local]
name=local repo
baseurl=file:///mnt/cdrom
enable=1
gpgckeck=1
gpgkey=file:///mnt/cdrom/RPM-GPG-KEY-CentOS-7

三、将/etc/yum.repos.d目录下其余文件删除,或者移动到别的目录,使得/etc/yum.repos.d目录下只有local.repo

四、更新yum源
yum clean all
yum makecache
yum repolist all
步骤完成,可以使用yum命令安装了。

HPE 1500 iLO 4 Configuration is temporarily unavailable

  1. Set the ilo 4 Security Override Switch on the system board to the ON position. The location of the switch is printed on a label located on the inside of the server blade hood cover. On the same maintenance switch, set switch number 3 to the ON position.
  2. Download the Smart Update Firmware Maintenance DVD version 9.10 B and later.
  3. Create a bootable USB key containing the contents of the Smart Update Firmware DVD.
  4. Download the desired version of the ilo 4 firmware smart component for Linux (cp0xxxxx.scexe where xxxxx is an appropriate 5 digit number).
  5. Copy the downloaded ilo 4 firmware to the directory /hp/swpackages on the USB key.
  6. Put the server blade back into the enclosure and power the server blade ON. Boot to the USB key containing the Smart Update Firmware DVD and select interactive firmware update.
  7. Use the following key sequence to exit out of the Smart Update Firmware Maintenance DVD interface. A command prompt will be displayed:
    CTRL + ALT + d + b + x (Keep the CTRL and ALT keys pressed when typing d b x. )
    The command prompt takes approximately 30 seconds to be displayed.
  8. At the command prompt, navigate to the Smart Update Firmware DVD directory containing the supplemental ilo 4 firmware update by using the following command:
    bash-3.1# cd /mnt/cdrom/hp/swpackages
  9. Use the following command to unload the HPILO module:
    rmmod hpilo
  10. Use the following command to execute the ilo 4 firmware update in direct mode:
    sh cp0xxxxx.scexe – – direct (This parameter requires two dash ( ) characters.).
  11. After the ilo 4 firmware upgrade is completed, power the server blade OFF and set the ilo 4 Security Override Switch on the system board to the OFF position. On the same maintenance switch, set switch number 3 to the OFF position

HPE Integrated Lights-Out 4 (iLO 4) – HPE Active Health System (AHS) Logs and HPE OneView Profiles May Be Unavailable Causing iLO Self-Test Error 8192, Embedded Media Manager and Other Errors

On an HPE Gen8-series or HPE ProLiant Gen9-series servers with HPE Integrated Lights-Out 4 (iLO 4), the NAND flash device may not initialize or mount properly, which may cause a variety of symptoms, which are listed below:

AHS Errors

  • AHS Logs display a blank date when performing the following:
    “Select a range of the Active Health log in days From: _______ To:_________”
    AHS file system mount may fail with (I/O Error) or (No Such Device).
  • The HP Active Health System (AHS) Logs are unable to be downloaded. AHS Data is not available due to a filesystem error.
  • The iLO Diagnostic tab will display the following error message: “Embedded media manager failed initialization” or “The AHS file system mount failed with (No such device) or “The AHS file system mount failed with (I/O error)” or “Controller firmware revision 2.09.00 Could not partition embedded media device.”
  • Unable to download AHS log and “bb_dl_disabled” is displayed.

Embedded Media Errors

  • Controller Firmware Version 2.09.00 may fail to restart.
  • Unable to partition Embedded media device.
  • Embedded media manager may fail initialization.

Intelligent Provisioning Errors

  • Intelligent Provisioning will not execute when selecting F10.

OneView Errors

  • Remote Insight/Integrated Lights-Out Self-Test Error 8192.
  • Unable to register this HP OneView instance with iLO: There was a problem with posting a command to the iLO.
  • Unable to register this HP OneView instance with iLO: The iLO initialization was unable to complete.
  • Unable to determine if this server hardware is being managed by another management system. Received an error from iLO <ip address of iLO> with Error: Blob Store is not yet initialized. and Status: 126

SCOPE

Any HPE ProLiant Gen8-series or HPE ProLiant Gen9-series server running iLO 4.

RESOLUTION

The resolution for this issue may take several steps that need to be completed in the order specified below.

OVERVIEW

Step 1) Upgrade the iLO 4 firmware to version 2.61
Step 2) Perform a NAND format
Step 3) Check the iLO status If the iLO status is normal, then skip to Step 6 If the iLO status is still degraded, continue to Step 4
Step 4) Schedule downtime; AC power-cycle and repeat the NAND format
Step 5) Check the iLO status If the iLO status is normal, continue to
Step 6 If the iLO status is still degraded, then skip to Step 7
Step 6) Perform these final steps if the system board does not need to be replaced: Reboot the server; reinstall IP; and refresh the server in OneView (if server is managed by OneView)
Step 7) If steps 1-4 did not resolve the degraded iLO, replace the system board.

Note: The 2.61 iLO 4 firmware is a critical update. As such, HPE requires users to update to this version immediately. Install this update to take advantage of significant improvements to the write algorithm for the embedded 4 GB non-volatile flash memory (also known as the NAND). These improvements increase the NAND lifespan.

Additional considerations before performing a NAND format

A NAND format can be performed while the server is online in most cases.

Exception: For ESXi hosts booting from the Embedded SD Card – it isstrongly recommended to perform the NAND format with the ESXi OSshutdown.This recommendation also applies when updating the iLO 4firmware or resetting the iLO for ESXi hosts booting from the Embedded SDCard

A server AC power removal may be required (prior to the NAND format) in order for the NAND format to be successful. This can be accomplished for ML or DL servers by shutting down the server and disconnecting the power cables for a few seconds. For blade servers, an E-fuse can be accomplished by logging into the OA CLI and typing “reset server #” where “#” is the bay number of the blade.

An AuxPwrCycle feature was added in iLO 4 firmware version 2.55 so that the equivalent of an AC power removal can be performed remotely on a server.
Refer to Customer Notice “HPE Integrated Lights Out (iLO) 4 – RESTful Command to Allow an Auxiliary Power-Cycle Is Available in Firmware Version 2.55 (and Later)” located at the following URL:

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00047494en_us

Required steps to perform after a successful NAND format

  • If the server is powered on when performing the NAND format, a server reboot is required after a successful NAND format. This reboot repopulates the RIS and RESTful data on the server during the next server POST with iLO 4 firmware version 2.53 or newer installed. If iLO 4 firmware version 2.50 or older is installed, connect to the iLO CLI (using putty) and use the following command “oemHP_clearRESTapistate” before rebooting the server to repopulate the RIS and RESTful data on the server.
  • Reinstall Intelligent Provisioning (IP) to ensure that it is working properly and reported as installed in the iLO 4 GUI “System Information – Firmware Information” page.
  • If using OneView: After the server is rebooted (to repopulate the RIS and RESTful data on the server), perform a server refresh in OneView; any existing errors in OneView will need to be marked as cleared after the refresh.

Detailed steps

Step 1. Upgrade the iLO 4 firmware to version 2.61. To download the firmware. The latest version of the iLO 4 firmware is available as follows:

Note: For ESXi hosts booting from the Embedded SD Card (Gen8/Gen9)- it is strongly recommended to perform this step with the ESXi OS shutdown.

  1. Click the following link:
    https://support.hpe.com/hpesc/public/home
  2. Enter a product name (e.g., “DL380 Gen9”) in the text search field and wait for a list of products to populate. From the products displayed, identify the desired product and click on the Drivers & software icon to the right of the product.
  3. From the Drivers & software dropdown menus on the left side of the page:
    • Select the Software Type – (e.g. Firmware)
    • Select the Software Sub Type – (e.g. Network)
    • For further filtering if needed – Select the specific Operating System from the Operating Environment.
  4. Select the latest release of Firmware – Lights-Out Management iLO 4 firmware version 2.61 (or later). Note: To ensure the latest version will be downloaded, click on the Revision History tab to check if a new version of the firmware/driver is available.
  5. Click Download.

Step 2. Perform NAND format using one of the methods detailed in the customer advisory: using one of the methods detailed in the customer advisory: HPE Integrated Lights-Out 4 (iLO 4) – How to Format the NAND Used to Store AHS logs, OneView Profiles, and Intelligent Provisioning
Find the document at:

https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-a00048622en_us


Note: iLO 4 firmware version 2.44 (or later) is required to format the NAND using the following steps.

Step 3. Check the iLO status using the options available in the customer advisory: HPE Integrated Lights-Out 4 (iLO 4) – How to Format the NAND Used to Store AHS logs, OneView Profiles, and Intelligent Provisioning (find the document at the link in Step 2).

If the iLO status is normal based on the above criteria, then skip to Step 6 If the iLO status is still degraded, continue to Step 4

Step 4. If the iLO status is still degraded, perform the following steps:

a) Schedule a maintenance window
b) Shut down the server
c) Perform an E-fuse (server blade) or AC Power Pull (DL / ML series servers) d) Perform the NAND format again (refer to the instructions in Step 2 above)

Step 5. Check the iLO status (refer to the instructions in Step 3 above)
If the iLO status is normal, continue to Step 6
If the iLO status is still degraded, then skip to Step 7

Step 6. Perform these final steps after the NAND format is successful:
a) Reboot the server
b) Reinstall Intelligent Provisioning (see additional details below)
c) If the server is managed by HPE OneView, perform a server refresh to bring the server back under management.

Note: Any existing errors in OneView will need to be marked as cleared after the refresh.

Step 7. If steps 1-4 did not resolve the degraded iLO, contact HPE support to arrange a system board replacement. Follow these steps to complete the remediation:

a) Open an HPE support case to arrange for a replacement system board / arrange a maintenance window
b) During the maintenance window, shutdown the server
c) Unassign the OneView profile (if the server is under OneView management)
d) Replace the system board
e) Enter Server Model and Serial Number via RBSU
f) Update to iLO 4 firmware 2.61 (or later)
g) Check iLO status (refer to Step 3 above)
h) Reassign the OneView profile (if the server is under OneView management)

Note: Any existing errors in OneView will need to be marked as cleared after the OneView profile is applied.

If additional assistance is needed, contact HPE support and reference Advisory a00019495en_us as follows:

Click on the following URL to locate the HPE Customer Support phone number in your country:

https://h20195.www2.hpe.com/v2/Getdocument.aspx?docname=A00039121ENW .

OneView Considerations

OneView relies on the NAND to be accessible to perform many operations such as adding a new server or applying a profile. Because of this there are several things that need to be understood when dealing with this issue in an OneView environment.

  1. OneView interaction with the NAND – OneView uses a portion of the NAND called the iLO blob store. If the blob store is not accessible, adding a server to OneView or assigning a profile to the server cannot be completed.
  2. Impact of an inaccessible NAND when managed by OneView – If the NAND becomes inaccessible after the server was added in OneView, there are several things that can cause an outage:
    1. E-fuse – If an E-fuse reset is performed, the server will not be able to be brought back under management until the NAND issue is remediated and this will cause an unexpected outage.
    2. Server is removed and reinserted – This would essentially be the same as performing an E-fuse, so the same information in the E-fuse section applies here.
    3. Un-assign a server profile – If a server profile is unassigned, the server profile will not be able to be reassigned until the NAND issue is remediated.
  3. Migration from Virtual Connect to OneView – If an enclosure is migrated from Virtual Connect and a server has an inaccessible NAND, that server will not be able to be added properly until the NAND issue is remediated. If an in-service migration is attempted on a server with an inaccessible NAND, an unexpected outage will occur. Reference advisoryhttps://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c05384185for more detail.
  4. Formatting of the NAND – The NAND format wipes the iLO blob store that is used by OneView. It is important to issue a server refresh after a successful NAND format to recover the blob that OneView uses.

Reinstalling Intelligent Provisioning Considerations

There are online and offline options for reinstalling Intelligent Provisioning

  • Intelligent Provisioning can be reinstalled online if the server is running Windows (HPE ProLiant Gen8-series servers/HPE ProLiant Gen9-series servers only) or Linux (HPE ProLiant Gen8-series servers/HPE ProLiant Gen9-series servers). The available online Windows packages are older versions of Intelligent Provisioning.
  • Intelligent Provisioning must be reinstalled offline if the server is running VMware (HPE ProLiant Gen8-series servers/HPE ProLiant Gen9-series servers).
  • The Intelligent Provisioning software download links are provided below. Intelligent Provisioning versions
  • HPE ProLiant Gen8-series servers are only supported with Intelligent Provisioning 1.x
  • ” HPE ProLiant Gen9-series servers are only supported with Intelligent Provisioning 2.x

Note: Intelligent Provisioning version 3.x is for HPE ProLiant Gen10-series servers only.

Offline method considerations:

  • Run the Intelligent Provisioning Restore Media to restore the Intelligent Provisioning data. Instructions to restore Intelligent Provisioning are as follows:
  • Instructions to create a bootable DVD with the IP image are provided on the HPE Intelligent Provisioning recovery media download site under the Installation Instructions tab.

Reference:
https://support.hpe.com/hpsc/swd/public/detail?swItemId=MTX_170e0ac3cb6e4439bf313f137a#tab3

Note: The DVD can be used multiple times.

Please note the Intelligent Provisioning Recovery Media DVD may be remotely mounted using HPE Integrated Lights-Out 4 (iLO 4) Virtual Media functionality, in order to reinstall Intelligent Provisioning. Additional information is available in the HPE iLO 4 User Guide at the following URL regarding how to mount an ISO image (federated or un-federated) and perform basic virtual media operations. Reference Pages 189 and 223-237:

HPE iLO 4 User Guide:
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c03334051-16

In addition, it is possible to write a script that utilizes HPE Integrated Lights-Out 4 (iLO 4) to reinstall Intelligent Provisioning on multiple servers. HPE Lights-Out management processors support an advanced scripting interface for group configuration and server actions. Scripts would need to be customized for the specific environment and task. Sample scripts are available for customers to reference at the following URL: HPE Lights-Out XML Scripting Sample for Windows: https://support.hpe.com/hpsc/swd/public/detail?swItemId=MTX_459b8adc29c04317ad1d6a6752

Intelligent Provisioning software download links

HPE ProLiant Gen8-series servers are only supported with Intelligent Provisioning 1.x
HPE ProLiant Gen9-series servers are only supported with Intelligent Provisioning 2.x

a.) Linux RPM located at the following URLs: For HPE Gen8-series servers: http://downloads.linux.hpe.com/SDR/repo/ip/rhel/current/x86_64/gen8/

For HPE Gen9-series servers: http://downloads.linux.hpe.com/SDR/repo/ip/rhel/current/x86_64/gen9/firmware-intelligentprovisioning-ip-2.71-1.1.x86_64.rpm

b.) The Windows files are located at the following URLs:

For HPE ProLiant Gen8-series servers: Intelligent Provisioning for Microsoft Windows 64-bit Operating Systems 1.64.0.0 (2 Mar 2017) cp031302.exe https://support.hpe.com/hpsc/swd/public/detail?swItemId=MTX_01b900175afc4ae68be6c87b39
For HPE ProLiant Gen9-series servers: Intelligent Provisioning for Windows x64 2.50.0.0(6 Jan 2017) cp031091.exe https://support.hpe.com/hpsc/swd/public/detail?swItemId=MTX_b031497eafd94b9ea2156cdef6

c) ISO images (e.g. for VMware) on Hewlett Packard Enterprise Support Center located at the following: https://support.hpe.com/hpesc/public/home/driverHome?sp4ts.oid=1008862660

For HPE ProLiant Gen8-series servers: Intelligent Provisioning Recovery Media, version 1.70(9 Oct 2017)
For HPE ProLiant Gen9-series servers: Intelligent Provisioning for Gen9 Servers, version 2.70(b)(28 Feb 2018)

HP DL380G9服务器开机无F10的处理办法

HP服务器的F10功能是一个安装在主板NAND空间上的独立的linux内核系统,主要功能是系统快速安装和服务器维护诊断。

如果开机自检时没有出现F10按钮的提示,有三种可能。

一、主板BIOS设置问题,可以通过恢复BIOS默认设置或者单独设置F10。
按F9进入主板BIOS设置,System Utilities——System Configuration——menucascade-separatorBIOS/
Platform Configuration (RBSU)(BIOS/平台配置)——menucascade-separatorServer Security(服务器安
全性)——menucascade-separatorIntelligent Provisioning (F10 Prompt)(F10 提示),选择Enabled启用,按F10保存即可。

二、F10系统崩溃,此时需要在HP官网下载F10镜像进行重新安装。
需要进入ilo integrated remote console控制台界面,挂载镜像,然后从F11从镜像启动。

选择第一个直接安装镜像,等待安装完成即可,安装完成后会自动重启,重启后即可使用F10功能。

三、NAND空间受损,如此功能受损,将会在ilo上看到有类似”Embedded Flash/SD-CARD:Failed restart”的报错,这种情况下,如果ILO版本较高,可以在ilo里直接format reset下ilo。

或者通过HP Lights-Out 配置实用程序HPQLOCFG命令行的方式来重新格式化NAND。

linux新增一块硬盘并做LVM分区的方法

linux新增了一块硬盘,首先通过fdisk -l查看:

然后fdisk /dev/vdb创建分区

以此输入n p

first sector和last sector默认,直接回车,输入t L

输入8e,采用LVM分区

按w保存。

然后pvcreate /dev/vdb1,vgcreate vg_vdb /dev/vdb1

lvcreate -L 1000G -n lv_u01 vg_vdb,mkfs.xfs /dev/vg_vdb/lv_u01

新建/u01目录,挂载分区mount /dev/vg_vdb/lv_u01 /u01

在/etc/fstab中添加/dev/mapper/vg_vdb-lv_u01 /u01 xfs defaults 0 0,即可。

Linux LVM分区扩容方法,可以参见https://www.eumz.com/2018-04/1461.html

redhat5、redhat6安装HP DL380 DL580 G5 G6服务器网卡驱动步骤

Installing the RPM Package

  1. This package requires a build environment. Please refer to the
    “Build Environment Setup” Section before proceding to the next step.
  2. Install the source RPM package. rpm -ivh hp-e1000e-.src.rpm
  3. Build the binary RPM for the e1000e driver. RHEL 5: rpmbuild -bb /usr/src/redhat/SPECS/hp-e1000e.spec RHEL 6: rpmbuild -bb ~/rpmbuild/SPECS/hp-e1000e.spec SLES: rpmbuild -bb /usr/src/packages/SPECS/hp-e1000e.spec If you get an error during the build process, refer to the
    “Build Environment Setup” section. NOTE: One can build binary RPM for a specfic kernel flavor as follows: rpmbuild -bb SPECS/hp-e1000e.spec –define “KVER ” NOTE: RHEL 5 x86 installations require the “–target” switch when
    building on Intel compatible machines. Please see the “Caveats”
    section below for more details. rpmbuild –target=i686 -bb /usr/src/redhat/SPECS/hp-e1000e.spec
  4. Check for the existence of a current version of the e1000e package as follows: RHEL rpm -q kmod-hp-e1000e- SLES rpm -q hp-e1000e-kmp- If an old version of the package exists, the RPM package should be
    removed. Remove the corresponding tools package before removing
    driver package. RHEL rpm -e kmod-hp-e1000e- SLES rpm -e hp-e1000e-kmp- Verify if the old hp-e1000e package has been removed as follows: RHEL rpm -q kmod-hp-e1000e- SLES rpm -q hp-e1000e-kmp-
  5. Install the new binary RPM package. RHEL 5 rpm -ivh \ /usr/src/redhat/RPMS//kmod-hp-e1000e–..rpm RHEL 6 rpm -ivh \ ~/rpmbuild/RPMS//kmod-hp-e1000e–..rpm The modules are installed in the following directory:
    /lib/modules//extra/hp-e1000e Note: The “–nodeps” switch is required when installing on RHEL 5.5. See
    “Caveats” section below for more details. rpm -ivh \ /usr/src/redhat/RPMS//kmod-hp-e1000e–..rpm –nodeps SLES rpm -ivh RPMS//hp-e1000e-kmp–..rpm The modules are installed in the following directory:
    /lib/modules//updates/hp-e1000e
  6. Configure your network setting and address. You may need to refer to your
    Linux vendor documentation. Helpful network configuration tools such as
    “yast2” in SLES or linuxconf/redhat-config-network/netconfig in Red Hat
    exist for easy configuration.

For SLES, user may have to specify the module as e1000e while configuring
the network. The module can be specified in Hardware Details of Advanced
configuration

  1. Ensure that the /etc/modules.conf file is configured similar to the example
    listed below. The example below is presented as if more than one adapter is
    present. If so, one eth# instance should exist for each ethernet port. Refer to
    the modules.conf man page for more information. alias eth0 e1000e
    alias eth1 e1000e

For SLES, the configuration file is /etc/modprobe.conf or /etc/modprobe.conf.local

  1. You can now reboot your server or restart the network services. Upon reboot
    the network should start with the e1000e driver loaded

To verify that the e1000e driver is loaded use the following command.

# lsmod

You should find e1000e listed. You can also verify if the correct e1000e driver is
loaded through any of the following methods. Note that version of the driver loaded
should be same as that of the package version.

A. Look for driver load messages in the system log.

#dmesg | grep Intel

You should see messages of the following type,

Intel(R) PRO/1000 Network Driver - version x.x.x

B. Check the /var/log/messages file for a similar message as indicated in method A.

Note: To load the driver from command line use ‘modprobe’ instead of ‘insmod’.
Refer to the man pages for lsmod, ifconfig, rmmod, insmod, modprobe, modules.conf
and modprobe.conf for more detailed information.

Uninstalling the RPM

The following command will uninstall the RPM.

Red Hat
# rpm -e kmod-hp-e1000e-<kernel flavor>

SLES
# rpm -e hp-e1000e-kmp-<kernel flavor>

Limitations

Some Linux distributions may not add the default route back to a specified network
device when a network stop/start command is used. Use the route command to add the
default router back to the network device.

Some Linux distributions may not add the default assigned IP address back to a
specified network device when using the following:

ifconfig eth(x) down
rmmod <module name>
insmod <module name> <optional parameter changes>
ifconfig eth(x) up

Another step to reassign the IP address back to the device may be required:

ifconfig eth(x) <ip address>

Some Linux distributions may add multiple IP addresses with the same system name in
the /etc/hosts file when configuring multiple network devices.

电脑配置静态地址无法ping通网关问题处理说明

现有一台电脑接了双网卡,连接外网网卡配置IP地址网关,连接内网的网卡通过DHCP获取地址,由于此时系统上有两个网关,会导致部分网段无法正常访问,需要将内网的网关去掉,到内网网段写路由。关于双网卡的配置,参见windows下双网卡双网关的设置https://www.eumz.com/2012-05/251.html

该内网网卡DHCP获取到的地址是192.168.1.113/24,网关192.168.1.1,此时关闭DHCP,配置静态地址192.168.1.113和24位掩码,不配置网关,此时发现ping网关192.168.1.1不通。在电脑接入的交换机上查看DHCP地址池配置,发现DHCP地址池是192.168.1.2-192.168.1.200,为电脑配置地址池之外的IP192.168.1.201,这时到192.168.1.1是通的,然后配置到内网网段的路由即可。

对于这种情况,静态地址配置成DHCP获取到的地址无法使用,就需要配置成DHCP地址池外的地址。

centos7进入单用户模式修改密码的办法

启动linux,在这个界面时,按e,

按向下的箭头键,在linux16这一行的末尾LANG=en_US.UTF-8后面输入init=/bin/sh

然后按ctrl+x,进入单用户模式

此时在单用户模式下还不能修改密码,需要输入命令mount -o remount,rw /

然后通过passwd修改root密码,修改完成后,一定要输入touch /.autorelabel,不然启动不了

输入 touch /.autorelabel后输入exec /sbin/init即可使用刚才修改的root密码进入系统

centos6进入单用户模式的方法

centos6进入单用户模式方法如下:
启动到这个步骤时,按e

在kernel这一行按e

在quiet后面输入single,或者输入1按回车

回到这个界面

再按b启动,即可进入单用户模式,在单用户模式可以修改root密码等。

供应链攻击

供应链攻击是一种以软件开发人员和供应商为目标的新出现的威胁。 目标是通过感染合法应用来分发恶意软件来访问源代码、构建过程或更新机制。

供应链攻击如何工作

攻击者搜寻不安全的网络协议、未受保护的服务器基础结构和不安全的编码实践。 它们在生成和更新过程中会中断、更改源代码并隐藏恶意软件。

由于软件由受信任的供应商生成和发布,因此这些应用和更新已经过签名和认证。 在软件供应链攻击中,供应商可能不知道他们的应用或更新在公开发布时受到恶意代码的感染。 然后,恶意代码以与应用相同的信任和权限运行。

鉴于某些应用的热门程度,潜在隐患的数量很大。 发生了一种情况,其中免费文件压缩应用被病毒化,并部署到作为顶级实用工具应用的国家/地区的客户。

一般软件供应链分三个环节,每个环节都可能被攻击。

1、生产节点被攻击(开发软件) 
软件开发涉及到的软硬件开发环境、开发工具、第三方库、软件开发实施等等,并且软件开发实施的具体过程还包括需求分析、设计、实现和测试等,软件产品在这一环节中形成最终用户可用的形态。 

  • 攻击案例:xCodeGhost, xshell攻击 

2、交付节点被攻击(软件上线的平台、硬件) 
用户通过软件官网、公共仓库、在线商店、免费网络下载、购买软件安装光盘等存储介质、资源共享等方式获取到所需软件产品的过程。受攻击对象比如著名的软件下载站、Python官方镜像源、Github等。 

  • 攻击案例:中文版Putty后门事件、思科后门事件

3、使用节点被攻击(软硬件使用者) 使用软硬件产品的整个生命周期,包括产品更新升级、维护等过程。 

  • 攻击案例:powercdn软件升级劫持攻击

根据赛门铁克2019 年《互联网安全威胁报告》,供应链攻击和离地攻击现已成为网络犯罪的主流:2018年供应链攻击增加了78%。特别在很多发布平台的安全能力较弱甚至没有的情况下,软件供应链攻击仅需要作者的一个上传、发布即可轻松完成钓鱼。

供应链攻击的类型

  • 损坏的软件生成工具或更新的基础结构
  • 被盗的代码签名证书或使用开发人员公司的标识签名的恶意应用
  • 硬件或固件组件中附带的已泄露的专用代码
  • 在相机、USB、手机 (设备上预安装的恶意软件)

如何防范供应链攻击

  • 部署强代码完整性策略以仅允许运行授权的应用。
  • 使用可以自动检测和修正可疑活动的终结点检测和响应解决方案。

适用于软件供应商和开发人员

  • 维护高度安全的生成和更新基础结构。
    • 立即为操作系统和软件应用安全修补程序。
    • 实施强制完整性控制,以确保仅运行受信任的工具。
    • 要求管理员进行多重身份验证。
  • 构建安全的软件更新程序,作为软件开发生命周期的一部分。
    • 更新通道和实现证书固定需要 SSL。
    • 对一切内容进行签名,包括配置文件、脚本、XML 文件和程序包。
    • 检查数字签名,不要让软件更新程序接受常规输入和命令。
  • 制定针对供应链攻击的事件响应流程。
    • 披露供应链事件,并及时准确地通知客户

附录:
[1] xCodeGhost:https://security.tencent.com/index.php/blog/msg/96
[2] xshell攻击:https://security.tencent.com/index.php/blog/msg/120
[3] 中文版Putty后门事件:https://www.cnbeta.com/articles/tech/171116.htm
[4] 思科后门事件: https://www.guancha.cn/TMT/2014_03_31_218296.shtml
[5] powercdn软件升级劫持攻击:https://www.freebuf.com/news/140079.html