ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ20ÖÜ

Ðû²¼Ê±¼ä 2018-05-21

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇRed Hat DHCP Client Script´úÂëÖ´ÐЩ¶´£»Advantech WebAccessÈÎÒâÎļþɾ³ý©¶´£»Adobe Photoshop CCÔ½½çдÈÎÒâ´úÂëÖ´ÐЩ¶´£»Google Chrome V8 CVE-2018-6122´úÂëÖ´ÐЩ¶´£»Spring Framework CVE-2018-1258Äþ¾²ÈÏÖ¤ÈÆ¹ý©¶´¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊDzÍÒûÁ¬Ëø¹«Ë¾Chili'sÔâµ½¶ñÒâÈí¼þ¹¥»÷£¬Ö´·¨²¿ÃÅÕýÔÚÊÓ²ìÖУ»Ä«Î÷¸çµÄÒøÐеç×ÓÖ§¸¶ÏµÍ³£¨SPEI£©¶à´ÎÔâµ½ºÚ¿Í¹¥»÷£¬±»µÁ×ʽð²»È·¶¨£»Ñо¿ÍŶӷ¢ÏÖÁ½ÆðÀûÓÃUPnPЭÒé½øÐеÄDDoS¹¥»÷ʼþ£»¶íÂÞ˹Áª°î¹ú¼ÊºÏ×÷Êð£¨Rossotrudnichestvo£©¹Ù·½ÍøÕ¾ÔâºÚ¿Í¹¥»÷£»Ñо¿ÍŶӷ¢ÏÖ¶ñÒâPDFÎļþͬʱÀûÓÃWindowsÌáȨ©¶´ºÍAdobe ReaderµÄRCE©¶´¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Red Hat DHCP Client Script´úÂëÖ´ÐЩ¶´

        Red Hat DHCP Client´¦ÖÃÌØÊâµÄDHCPÏìÓ¦´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâÇëÇ󣬿ÉÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://access.redhat.com/security/vulnerabilities/3442151
2¡¢Advantech WebAccessÈÎÒâÎļþɾ³ý©¶´

        Advantech WebAccess´æÔÚÎļþÃû³Æ»ò·¾¶Íⲿ¿ØÖÆÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿Éɾ³ýÈÎÒâÎļþ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://ics-cert.us-cert.gov/advisories/ICSA-18-135-01
3¡¢Adobe Photoshop CCÔ½½çдÈÎÒâ´úÂëÖ´ÐЩ¶´

        Adobe Photoshop CC´¦ÖÃÎļþ´æÔÚÔ½½çд©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/photoshop/apsb18-17.html
4¡¢Google Chrome V8 CVE-2018-6122´úÂëÖ´ÐЩ¶´

        Google Chrome V8´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://chromereleases.googleblog.com/2018/05/stable-channel-update-for-desktop.html
5¡¢Spring Framework CVE-2018-1258Äþ¾²ÈÏÖ¤ÈÆ¹ý©¶´

        Spring FrameworkÔÚʹÓÃÒªÁìÄþ¾²ÐÔ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÄþ¾²ÏÞÖÆÎ´ÊÚȨ·ÃÎÊ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://pivotal.io/security/cve-2018-1258


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢²ÍÒûÁ¬Ëø¹«Ë¾Chili'sÔâµ½¶ñÒâÈí¼þ¹¥»÷£¬Ö´·¨²¿ÃÅÕýÔÚÊÓ²ìÖÐ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ²ÍÒûÁ¬Ëø¹«Ë¾Chili's±¾ÖÜÐû²¼Í¨¸æ³ÆÔâµ½¶ñÒâÈí¼þ¹¥»÷¡£¸Ã¹«Ë¾ÌåÏÖ£¬ÕýÔÚÓëÖ´·¨²¿Ãź͵ÚÈý·½¼ø¶¨×¨¼ÒÒ»ÆðÊÓ²ì´Ëʼþ¡£Æ¾¾ÝÊÕ¼¯µ½µÄ×îÐÂϸ½Ú£¬¸Ã¶ñÒâÈí¼þËÆºõÒѾ­Ñ¬È¾ÁËÆäijЩ֧¸¶ÏµÍ³¡£µ«ÔÚÍøÂçÉÏ·¢ÏָöñÒâÈí¼þ£¬³ÆÓÐÖ¤¾Ý±íÃ÷¸Ã¶ñÒâÈí¼þ½öÔÚ2018Äê3ÔºÍ4ÔÂÖ®¼ä»îÔ¾¡£BrinkerҲûÓÐÌṩ´ó¸ÅÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿£¬µ«ÔÊÐíÔÚÊÓ²ì½øÐÐʱÐû²¼¸ü¶àϸ½Ú¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/card-breach-announced-at-chili-s-restaurant-chain/

2¡¢Ä«Î÷¸çµÄÒøÐеç×ÓÖ§¸¶ÏµÍ³£¨SPEI£©¶à´ÎÔâµ½ºÚ¿Í¹¥»÷£¬±»µÁ×ʽð²»È·¶¨

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ÖÐÑëÒøÐÐÆóÒµÖ§¸¶ºÍ·þÎñϵͳ×ܼàLorenza MartinezÌåÏÖ£¬ÔÚ4ÔºÍ5ÔÂÖÁÉÙ¶ÔÄ«Î÷¸çÑëÐеÄÒøÐмäµç×ÓÖ§¸¶ÏµÍ³£¨SPEI£©ÌᳫÁËÎå´ÎºÚ¿Í¹¥»÷¡£Ò»Ð©Ä«Î÷¸çýÌåÒѾ­½«±»µÁ½ð¶îÉèΪ4ÒÚ±ÈË÷£¨2040ÍòÃÀÔª£©£¬µ«Âí¶¡ÄÚ˹·ñÈÏÁËÕâЩ±¨µÀ¡£Ëý˵±»µÁµÄÇ®ÊôÓÚÒøÐÐ×Ô¼º£¬¿Í»§µÄ×ʽð´ÓδÊܵ½Ó°Ïì¡£ÔÚ·¢ÏÖ¹¥»÷ºó£¬ÒøÐÐת¶ø½ÓÄɽÏÂýµ«¸üÄþ¾²µÄÒªÁ죬Ŀǰ»¹Ã»ÓÐÐµĹ¥»÷¼Ç¼¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/hackers-divert-funds-mexico-banks-amount-unclear-official

3¡¢Ñо¿ÍŶӷ¢ÏÖÁ½ÆðÀûÓÃUPnPЭÒé½øÐеÄDDoS¹¥»÷ʼþ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¹¥»÷ÕßÕýÔÚʵÑé½ÓÄÉͨÓü´²å¼´Óã¨UPnP£©Ð­ÒéÀ´ÆÁ±ÎDDoS·ºÀÄÆÚ¼ä·¢Ë͵ÄÍøÂçÊý¾Ý°üµÄÔ´¶Ë¿Ú£¬´Ó¶øÖÆÖ¹Ê¹ÓÃijЩDDoS»º½â½â¾ö·½°¸µÄÐÂÒªÁì¡£ÔÚÖÜÒ»Ðû²¼µÄÒ»·Ý³ÂËßÖУ¬Imperva¹«Ë¾ÌåÏÖ£¬ËûÃÇ·¢ÏÖÖÁÉÙÓÐÁ½´Î½ÓÄÉÕâÖÖ¼¼ÊõµÄDDoS¹¥»÷¡£Í¨¹ýÆÁ±Î´«ÈëÍøÂçÊý¾Ý°üµÄÔ´¶Ë¿Ú¡£ÒÀ¿¿¶ÁÈ¡´ËÐÅÏ¢À´×èÖ¹¹¥»÷µÄÀÏʽDDoS»º½âϵͳÐèÒª¸üÐÂΪ¸üÅÓ´óµÄ½â¾ö·½°¸£¬ÕâЩ½â¾ö·½°¸ÒÀÀµÓÚÉî¶È°ü¼ì²â£¨DPI£©£¬ÕâÊÇÒ»Öֳɱ¾¸ü¸ß£¬½¨ÒéʹÓ÷ÓÉÆ÷µÄÓû§Èç¹û²»Ê¹Óøù¦Ð§£¬Ôò½ûÓÃUPnPÖ§³Ö¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ddos-attacks-leverage-upnp-protocol-to-avoid-mitigation/

4¡¢¶íÂÞ˹Áª°î¹ú¼ÊºÏ×÷Êð£¨Rossotrudnichestvo£©¹Ù·½ÍøÕ¾ÔâºÚ¿Í¹¥»÷

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        Anonymous¹¥»÷Á˶íÂÞ˹Áª°î¹ú¼ÊºÏ×÷Êð£¨Rossotrudnichestvo£©µÄ¹Ù·½ÍøÕ¾µÄ×ÓÓòÃû£¬¸Ã¹¥»÷ʼþ·¢ÉúÔÚ5ÔÂ10ÈÕ£¬ÒÔ¿¹ÒéÕþ¸®µÄÉó²éÖÆ¶È£¬²¢ÌرðÌáµ½Á˽ûÖ¹TelegramµÄ¹æ¶¨¡£ÉϸöÔ£¬¶íÂÞ˹Õþ¸®·âËøÁ˸ùúµÄTelegramÓ¦Ó÷¨Ê½£¬ÒòΪ¸Ã¹«Ë¾¾Ü¾ø½«ÆäÓû§µÄ¼ÓÃÜÃÜÔ¿½»¸ø¶íÂÞ˹Áª°îÄþ¾²¾Ö£¨FSB£©½øÐÐÊӲ졣×Ô2018Äê5ÔÂ3ÈÕÆð£¬¶íÂÞ˹Ïà¹Ø»ú¹¹½û·âÁË50¶à¸öÐéÄâרÓÃÍøÂ磨VPN£©¡¢ÍøÂçÊðÀíºÍÄäÃûÍøÂç¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72567/hacktivism/anonymous-hask-russia-site.html

5¡¢Ñо¿ÍŶӷ¢ÏÖ¶ñÒâPDFÎļþͬʱÀûÓÃWindowsÌáȨ©¶´ºÍAdobe ReaderµÄRCE©¶´

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ESETµÄÑо¿ÈËÔ±×î½ü·¢ÏÖÁËÒ»¸ö¶ñÒâPDFÎļþ£¬¸Ã¶ñÒâÎĵµÀûÓÃWindowsÖеÄÌØÈ¨Éý¼¶Â©¶´£¨CVE-2018-8120£©ºÍAdobe Reader£¨CVE-2018-4990£©ÖеÄÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£CVE-2018-8120ÊÇMicrosoftÔÚ2018Äê5Ô²¹¶¡¸üÐÂÖÐÐÞ¸´µÄÁ½¸ö0day©¶´Ö®Ò»£¬¶øCVE-2018-4990ÊÇÓÉAdobeÓÚ5ÔÂ14ÈÕÐû²¼µÄ£¬Ðû²¼ÁËÐÞ¸´½ü50¸öÆäËûÎÊÌâµÄ¸üС£Í¨¹ý½áºÏÕâÁ½¸öȱÏÝ£¬¹¥»÷Õß¿ÉÒÔÓÃ×îÉÙµÄÓû§½»»¥ÒÔ¸ü¸ßµÄȨÏÞÖ´ÐÐÈÎÒâ´úÂ룬ÌرðÊÇ´ò¿ª¶ñÒâPDF¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/malicious-pdf-leads-discovery-adobe-reader-windows-zero-days