ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ22ÖÜ

Ðû²¼Ê±¼ä 2018-06-04

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ28ÈÕÖÁ06ÔÂ01ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö£¬ÖµµÃ¹Ø×¢µÄÊǶà¿îTP-LINK²úÎïÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý©¶´£»strongSwan CVE-2018-5388»º³åÇøÒç³ö©¶´£»BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶©¶´¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄеöÓã»î¶¯£»Ñо¿ÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯£»¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄÊý¾Ýй¶£»Ñо¿ÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷ÆÆ»µHDDºÍµ¼ÖÂϵͳÍ߽⣻±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖôíÎ󣬵¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢¶à¿îTP-LINK²úÎïÔ¶³Ì´úÂëÖ´ÐЩ¶´

        ¶à¿îTP-LINK²úÎïÖеÄ/usr/lib/lua/luci/torchlight/validator.luaÎļþ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄJSONÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCE
2¡¢Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´ÐЩ¶´

        Git ÔÚÓÃgit cloneʱûÓжÔsubmoduleµÄÎļþ¼ÐÃüÃû×ö×ã¹»µÄÑéÖ¤£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»¶ñÒâµÄ.gitmodulesÎļþ£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://git-scm.com
3¡¢Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý©¶´

        Huawei 1288H V5ºÍ2288H V5´æÔÚJSON×¢Èë©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬Ð޸ĹÜÀíÔ±ÃÜÂ룬»ñȡϵͳµÄ¹ÜÀíȨÏÞ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en
4¡¢strongSwan CVE-2018-5388»º³åÇøÒç³ö©¶´

        strongSwan´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ɺľ¡×ÊÔ´£¬½øÐоܾø·þÎñ¹¥»÷¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.strongswan.org/blog
5¡¢BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶©¶´

        BeaconMedaes TotalAlert Scroll Medical Air Systems WEB·þÎñÆ÷´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-144-01


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄеöÓã»î¶¯

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        RiskIQÑо¿ÍŶӷ¢ÏÖÕë¶ÔMyEtherWalletµÄÒ»¸öеöÓã»î¶¯¡£¹¥»÷Õßͨ¹ý½¨Á¢Ò»¸öαװ³ÉMyEtherWalletÖ§³ÖÍŶӵÄTelegramÁÄÌìȺ×éÀ´·Ö·¢¶ñÒâMyEtherWallet¿Í»§¶Ë¡£¸Ã¶ñÒⷨʽͨ¹ýGoNative.io½«WebÓ¦ÓÃ×÷Ϊµ±µØÓ¦ÓÃÐû²¼£¬ÓÃÓÚÇÔÈ¡Óû§µÄƾ¾Ý¡£Ñо¿ÈËÔ±Ðû²¼ÁËÏà¹ØIoC¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/myetherwallet-android/

2¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        FireEyeÑо¿ÍŶӷ¢ÏÖÀûÓÃRIG Exploit Kit£¨EK£©Á÷´«Ä¾ÂíGrobiosµÄ¶ñÒâ¹¥»÷»î¶¯£¬¸Ã»î¶¯´Ó2018Äê3ÔÂ10ÈÕ¿ªÊ¼¡£GrobiosʹÓÃÁ˶àÖÖÌӱܼì²â¼¼Êõ£¬²¢Í¨¹ý¶à¸ö±¸·ÝºÍ´´½¨×Ô¶¯ÔËÐÐ×¢²á±íÏî¼°¼Æ»®ÈÎÎñÀ´ÊµÏÖ³Ö¾ÃÐÔ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72954/malware/rig-exploit-kit-grobios-campaign.html

3¡¢¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄÊý¾Ýй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¼ÓÄôóµÄÁ½¼ÒÒøÐÐSimplii FinancialºÍÃÉÌØÀû¶ûÒøÐÐÔÚÖÜÒ»·¢±íÉùÃ÷³Æ·¢ÉúÍøÂçÄþ¾²Ê¼þ£¬Simplii FinancialÌåÏÖ£¬ËüÔÚÉÏÖÜÄ©·¢ÏÖ¹¥»÷Õß·ÃÎÊÁËÔ¼4ÍòÃûSimplii¿Í»§µÄÕË»§ÐÅÏ¢¡£µ«ÊÇSimplii FinancialÔÊÐí100£¥·µ»¹ËùÊÜÓ°ÏìµÄÕË»§µÄËðʧ¡£ÔÚSimplii·¢±íÉùÃ÷һСʱºó£¬ÃÉÌØÀû¶ûÒøÐÐÒ²Ðû²¼ÁËÀàËÆµÄÉùÃ÷¡£¸ÃÒøÐÐÌåÏÖ£¬ºÚ¿Í×Ô¼ºÔÚÉÏÖÜÈÕÁªÏµÁËËûÃÇ£¬Éù³ÆÓµÓпͻ§Êý¾Ý¡£ÃÉÌØÀû¶ûÒøÐÐûÓÐ͸¶Óм¸¶à¿Í»§µÄÐÅϢй¶£¬µ«ÌåÏÖËûÃÇÏàÐÅÒѾ­¹Ø±ÕÁ˺ڿͽøÈëÆäϵͳµÄÈë¿Úµã¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/two-canadian-banks-announce-hacks-over-the-weekend/

4¡¢Ñо¿ÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷ÆÆ»µHDDºÍµ¼ÖÂϵͳÍß½â

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        À´×ÔÃÜЪ¸ù´óѧºÍÕã½­´óѧµÄÒ»¸öÑо¿Ð¡×鳯¿Éͨ¹ýÉù²¨/³¬Éù²¨¹¥»÷À´ÆÆ»µÓ²ÅÌ£¨HDD£©µÄ¶ÁÈ¡¡¢Ð´ÈëºÍ´æ´¢¹¦Ð§ÒÔ¼°µ¼Ö²Ù×÷ϵͳÍ߽⡣Ñо¿ÈËÔ±ÌåÏÖÕâÖÖ¹¥»÷¿ÉÒÔͨ¹ý×ÔÖÆµĄ̈ʽµçÄÔ»òÌõ¼Ç±¾µçÄÔµÄÑïÉùÆ÷½øÐУ¬Ò»ÖÖ¿ÉÄܵĹ¥»÷³¡¾°ÊÇ£¬Óû§·ÃÎÊÁ˶ñÒâÍøÕ¾²¢²¥·ÅÁ˾ßÓÐÆÆ»µÐԵĶñÒâÉù²¨¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/sonic-tone-attacks-damage-hard-disk-drives-crashes-os/132343/

5¡¢±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖôíÎ󣬵¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ƾ¾ÝKromtech SecurityµÄ³ÂËߣ¬±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄ2¸öAmazon S3¿É¹ûÈ»·ÃÎÊ£¬µ¼ÖÂÁè¼Ý5ÍòÃûÓû§µÄÐÅϢй¶¡£Õâ2¸öAWS bucket°üÂÞ±¾ÌïÒÆ¶¯Ó¦ÓÃHonda ConnectµÄÓû§µÄÏêϸÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÐÔ±ð¡¢Óû§¼°Æä¿ÉÐÅÁªÏµÈ˵ĵ绰ºÅÂëºÍµç×ÓÓʼþµØÖ·¡¢ÕË»§ÃÜÂë¡¢Æû³µVINÂëºÍÆû³µConnect IDµÈ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/honda-india-left-details-of-50-000-customers-exposed-on-an-aws-s3-server/