D-Link NASµÄÈÎÒâÃüÁî×¢ÈëºÍÓ²±àÂëºóÃÅ

Ðû²¼Ê±¼ä 2024-04-08
1. D-Link NASµÄÈÎÒâÃüÁî×¢ÈëºÍÓ²±àÂëºóÃÅ


4ÔÂ6ÈÕ£¬ÍþвÑо¿ÈËÔ±Åû¶Á˶à¸ö²»ÔÚÖ§³ÖµÄ D-Link ÍøÂ總¼Ó´æ´¢ (NAS) É豸ÐͺÅÖдæÔÚеÄÈÎÒâÃüÁî×¢ÈëºÍÓ²±àÂëºóÃÅȱÏÝ¡£¸ÃÎÊÌâ´æÔÚÓÚ¡°/cgi-bin/nas_sharing.cgi¡±½Å±¾ÖУ¬Ó°ÏìÆä HTTP GET ÇëÇó´¦Ö÷¨Ê½×é¼þ¡£µ¼Ö¸ÃȱÏÝ£¨±àºÅΪ CVE-2024-3273£©µÄÁ½¸öÖ÷ÒªÎÊÌâÊÇͨ¹ýÓ²±àÂëÕÊ»§£¨Óû§Ãû£º¡°messagebus¡±ºÍ¿ÕÃÜÂ룩´Ù³ÉµÄºóÃÅÒÔ¼°Í¨¹ý¡°system¡±²ÎÊýµÄÃüÁî×¢ÈëÎÊÌâ¡£ÃüÁî×¢ÈëȱÏÝÊÇÓÉÓÚͨ¹ý HTTP GET ÇëÇó½« Base64 ±àÂëµÄÃüÁîÌí¼Óµ½¡°system¡±²ÎÊý£¬È»ºóÖ´ÐиÃÃüÁî¶øÒýÆðµÄ¡£D-LinkΪ¾ÉÉ豸½¨Á¢ÁË ×¨ÃŵÄÖ§³ÖÒ³Ãæ £¬Óû§¿ÉÒÔÔÚÆäÖÐä¯ÀÀµµ°¸ÒÔ²éÕÒ×îеÄÄþ¾²ºÍ¹Ì¼þ¸üС£


https://www.bleepingcomputer.com/news/security/over-92-000-exposed-d-link-nas-devices-have-a-backdoor-account/


2. Áè¼Ý1.6Íò¸öIVANTI VPNÈÔÈ»Ò×Êܵ½CVE-2024-21894µÄ¹¥»÷


4ÔÂ6ÈÕ£¬Shadowserver Ñо¿ÈËÔ±³ÂË߳ƣ¬Ô¼Äª 16500 ¸ö Ivanti Connect Secure ºÍ Poly Secure Íø¹ØÈÝÒ×Êܵ½×î½ü³ÂËßµÄ RCE CVE-2024-21894µÄÓ°Ïì¡£¸Ã¹«Ë¾ÒÑÐû²¼ÁËÄþ¾²¸üУ¬ÒÔ½â¾öÓ°Ïì Connect Secure ºÍ¼ÆıÄþ¾²Íø¹ØµÄËĸöÄþ¾²Â©¶´£¬ÕâЩ©¶´¿ÉÄܵ¼Ö´úÂëÖ´Ðк;ܾø·þÎñ (DoS)£¬°üÂÞCVE-2024-21894¡£CVE-2024-21894£¨CVSS ÆÀ·Ö 8.2£©ÊÇ Ivanti Connect Secure£¨9.x¡¢22.x£©ºÍ Ivanti Policy Secure µÄ IPSec ×é¼þÖеĶÑÒç³ö©¶´£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¶ñÒâÓû§ÔÚÒÔÏÂλÖ÷¢ËÍÌØÖÆÇëÇó£ºÃüÁî - ʹ·þÎñÍß½â´Ó¶øµ¼Ö DoS ¹¥»÷¡£ÔÚijЩÇé¿öÏ£¬Õâ¿ÉÄܻᵼÖÂÖ´ÐÐÈÎÒâ´úÂë¡£Shadowserver Ñо¿ÈËԱɨÃèÁË»¥ÁªÍøÉÏÊÇ·ñ´æÔÚÒ×ÊÜ CVE-2024-21894 Ó°ÏìµÄʵÀý£¬²¢³ÂËß³ÆÔ¼ÓÐ 16,500 ¸öʵÀýÈÔÈ»ÈÝÒ×Êܵ½¹¥»÷¡£´ó¶àÊýÒ×Êܹ¥»÷µÄϵͳλÓÚÃÀ¹ú£¨½ØÖÁ׫д±¾ÎÄʱÓÐ 4686 ¸ö£©£¬Æä´ÎÊÇÈÕ±¾£¨2009 Ä꣩ºÍÓ¢¹ú£¨1032 ¸ö£©¡£


https://securityaffairs.com/161544/security/ivanti-16500-vulnerable-istances.html


3. ÃÀ¹úÎÀÉú²¿¾¯¸æÒ½Ôº IT ·þÎñ̨Ò×Ôâµ½ºÚ¿Í¹¥»÷


4ÔÂ6ÈÕ£¬ÃÀ¹úÎÀÉúÓ빫ÖÚ·þÎñ²¿ (HHS) ¾¯¸æ³Æ£¬ºÚ¿ÍÏÖÔÚÕýÔÚʹÓÃÉç»á¹¤³Ì¼ÆıÀ´¹¥»÷Ò½ÁƱ£½¡ºÍ¹«¹²ÎÀÉú (HPH) ÁìÓòµÄ IT ·þÎñ̨¡£ÎÀÉú²¿ÃÅÍøÂçÄþ¾²Ð­µ÷ÖÐÐÄ (HC3) ±¾ÖÜÐû²¼µÄ²¿Ãž¯±¨³Æ£¬ÕâЩ¼ÆıÔÊÐí¹¥»÷Õßͨ¹ý×¢²á×Ô¼ºµÄ¶àÖØÉí·ÝÑéÖ¤ (MFA) É豸À´·ÃÎÊÄ¿±ê×éÖ¯µÄϵͳ¡£ÔÚÕâЩ¹¥»÷ÖУ¬ÍþвÐÐΪÕßʹÓõ±µØÓòÓò´úÂëÖµçð³ä²ÆÕþ²¿ÃÅÔ±¹¤µÄ×éÖ¯£¬²¢ÌṩÇÔÈ¡µÄÉí·ÝÑéÖ¤ÏêϸÐÅÏ¢£¬°üÂÞ¹«Ë¾ ID ºÍÉç»áÄþ¾²ºÅÂë¡£ËûÃÇÀûÓÃÕâЩÃô¸ÐÐÅÏ¢²¢Éù³Æ×Ô¼ºµÄÖÇÄÜÊÖ»úÒÑË𻵣¬Ëµ·þ IT ×ÊÖų́ÔÚ¹¥»÷ÕߵĿØÖÆÏÂÔÚ MFA ÖÐ×¢²áÐÂÉ豸¡£ÕâʹËûÃÇÄܹ»·ÃÎʹ«Ë¾×ÊÔ´£¬²¢ÔÊÐíËûÃÇÔÚÉÌÒµµç×ÓÓʼþй¶¹¥»÷ÖÐÖض¨ÏòÒøÐн»Òס£


https://www.bleepingcomputer.com/news/security/us-health-dept-warns-hospitals-of-hackers-targeting-it-help-desks/


4. ÒÔÉ«ÁÐ˾·¨²¿Ôںڿͻ·Ö×ÓÉù³ÆÈëÇÖºóÉó²éÍøÂçʼþ


4ÔÂ6ÈÕ£¬ ÒÔÉ«ÁÐ˾·¨²¿ÌåÏÖ£¬ÕýÔÚÊÓ²ìÒ»ÆðÍøÂçʼþ£¬·¶Î§ÈÔÔÚÉó²éÖУ¬ÐèҪʱ¼äÀ´¼ì²éй¶ÎļþµÄÄÚÈݺͷ¶Î§¼°ÆäÀ´Ô´¡£Ò»¸öÃûΪ Anonymous for Justice µÄ×éÖ¯Éù³Æ¶Ô´Ë´Îй¶ÂôÁ¦£¬²¢³Æ´Ë´Îй¶°üÂÞ¼ìË÷½ü 300 GB µÄÊý¾Ý¡£¸Ã×éÖ¯ÔÚÆäÍøÕ¾ÉÏÌåÏÖ£¬½«¼ÌÐø¹¥»÷ÒÔÉ«ÁУ¬¡°Ö±µ½¼ÓɳսÕùÍ£Ö¹¡±¡£¸Ã×éÖ¯Ðû²¼Á˾ݳÆÔÚ¹¥»÷»î¶¯ÖлñµÃµÄÎļþ£¬ÀýÈçÖ´·¨Îļþ£¬°üÂÞ±ê־Ϊ»úÃܵÄË«±ßЭÒéºÍºÏͬ²Ý°¸¡£Â·Í¸ÉçÎÞ·¨¶ÀÁ¢ºËʵй¶ÎļþµÄÕæʵÐÔ¡£Ë¾·¨²¿ÔÚÌû×ÓÖÐÌåÏÖ£¬ÒÑÕë¶ÔÕâÖÖÇé¿öÌáÇ°×öºÃ×¼±¸£¬¶øÇÒÆäÐж¯²»»áÖжÏ¡£¹ú¼ÒÍøÂç¾Ö±¾ÖÜÔçЩʱºòÌåÏÖ£¬Ô¤¼ÆÒÁÀÊÄê¶ÈÊ¥³ÇÈÕÖÜÄ©µÄÍøÂç¹¥»÷ʵÑ齫»áÔö¼Ó¡£


https://www.reuters.com/world/middle-east/israels-justice-ministry-reviewing-cyber-incident-after-hacktivists-claim-breach-2024-04-05/


5. ÈÕ±¾ Hoya µÄ IT ϵͳÔâÊܹ¥»÷ºóÔÝÍ£Éú²ú


4ÔÂ5ÈÕ£¬ÈÕ±¾µÄ Hoya¡ª¡ªÒ»¼ÒÑÛ¾µºÍÒþÐÎÑÛ¾µÖÆÔìÉÌ£¬ÒÔ¼°ÓÃÓÚÖÆÔì°ëµ¼ÌåÖÆÔ졢ƽ°åÏÔʾÆ÷ºÍÓ²ÅÌÇý¶¯Æ÷µÄÌ×¼þ¡ª¡ª IT ϵͳÔâÊܹ¥»÷ºó£¬¸Ã¹«Ë¾ÒÑÍ£Ö¹²¿ÃÅÉú²úºÍÏúÊۻ¡£¹Ù·½¶ÔËù·¢ÉúʼþµÄ¿´·¨ÊÇÄ£ºýµÄ¡£¸Ã¹«Ë¾ÔÊÐí¡°½«½ÓÄÉ´ëÊ©»Ö¸´Éú²úºÍÏúÊۻËùÐèµÄϵͳ£¬²¢¾¡¿ì»Ö¸´Ïò¿Í»§Ìṩ²úÎïµÄ¹©Ó¦ÏµÍ³¡±¡£Hoya Ä¿Ç°Éв»Çå³þ¡°¹«Ë¾³ÖÓеĻúÃÜ»ò¸öÈËÐÅÏ¢ÊÇ·ñÒѱ»Ð¹Â¶»ò±»µÚÈý·½·ÃÎÊ¡±£¬²¢¾¯¸æ³Æ¡°È«Ãæ·ÖÎöÔ¤¼ÆÐèÒªÏ൱³¤µÄʱ¼ä¡±¡£


https://www.theregister.com/2024/04/05/hoya_infosec_incident/


6. ºÚ¿ÍÀûÓà Magento ©¶´ÇÔÈ¡µç×ÓÉÌÎñÍøÕ¾Ö§¸¶Êý¾Ý


4ÔÂ6ÈÕ£¬¸Ã¹¥»÷ÀûÓÃÁËCVE-2024-20720£¨CVSS ÆÀ·Ö£º9.1£©£¬Adobe ½«ÆäÃèÊöΪ¡°ÌØÊâÔªËصIJ»Í×Öк͡±°¸Àý£¬¿ÉÄÜΪÈÎÒâ´úÂëÖ´ÐÐÆÌƽÃÅ·¡£¹«Ë¾ÔÚ 2024 Äê 2 Ô 13 ÈÕÐû²¼µÄÄþ¾²¸üÐÂÖнâ¾öÁËÕâ¸öÎÊÌâ¡£Sansec ÌåÏÖ£¬ËüÔÚÊý¾Ý¿âÖз¢ÏÖÁËÒ»¸ö¡°¾«ÐÄÉè¼ÆµÄ½á¹¹Ä£°å¡±£¬¸ÃÄ£°å±»ÓÃÀ´×Ô¶¯×¢Èë¶ñÒâ´úÂëÒÔÖ´ÐÐÈÎÒâÃüÁî¡£¹¥»÷Õß½« Magento ½á¹¹½âÎöÆ÷Óë beberlei/assert °ü£¨Ä¬ÈÏ°²×°£©½áºÏÆðÀ´Ö´ÐÐϵͳÃüÁî¡£ÓÉÓڽṹ¿éÓë½áÕʳµÏà¹ØÁª£¬Òò´Ëÿµ±ÇëÇó <store>/checkout/cart ʱ¶¼ÊÐÖ´ÐдËÃüÁî¡£ÓÐÎÊÌâµÄÃüÁîÊÇsed£¬ËüÓÃÓÚ²åÈëÒ»¸ö´úÂëÖ´ÐкóÃÅ£¬È»ºóÂôÁ¦Ìṩ StripeÖ§¸¶ä¯ÀÀÆ÷ÒÔ²¶×½²ÆÕþÐÅÏ¢²¢½«Æä鶵½ÁíÒ»¸öÊÜѬȾµÄ Magento É̵ê¡£


https://thehackernews.com/2024/04/hackers-exploit-magento-bug-to-steal.html