ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ42ÖÜ

Ðû²¼Ê±¼ä 2018-10-22

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇLibssh CVE-2018-10933·þÎñÆ÷Éí·ÝÑéÖ¤Èƹý©¶´£»Pivotal Spring Security OAuthȨÏÞÌáÉý©¶´£»Dell EMC Secure Remote ServicesȨÏÞÌáÉý©¶´£»Opto 22 PAC Control CVE-2018-14807»º³åÇøÒç³ö©¶´£»HPE Intelligent Management Center PLAT´úÂëÖ´ÐЩ¶´ ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄÂÃÐмǼй¶£»ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷£»Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Ç¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ£»±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬FBIÒѽéÈëÊӲ죻Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼ÄÜÔ´¹«Ë¾µÄÐÂAPT×éÖ¯GreyEnergy ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£

¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1. Libssh CVE-2018-10933·þÎñÆ÷Éí·ÝÑéÖ¤Èƹý©¶´


Libsshͨ¹ýÏò·þÎñÆ÷ÌṩSSH2_MSG_USERAUTH_SUCCESSÏûÏ¢À´È¡´ú·þÎñÆ÷Õý³£Æô¶¯Éí·ÝÑéÖ¤µÄSSH2_MSG_USERAUTH_REQUESTÏûϢʱ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÎÞÐèÑé֤δÊÚȨ·ÃÎÊ ¡£


https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/

2. Pivotal Spring Security OAuthȨÏÞÌáÉý©¶´


Pivotal Spring Security OAuth´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÌáÉýȨÏÞ ¡£

https://pivotal.io/security/cve-2018-15758

3. Dell EMC Secure Remote ServicesȨÏÞÌáÉý©¶´


Dell EMC Secure Remote Services°üÂÞ¶à¸ö¾ßÓÐÈ«¾Ö¿É¶ÁȨÏÞµÄÅäÖÃÎļþ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬ÌáÉýȨÏÞ ¡£


https://www.dellemc.com/

4. Opto 22 PAC Control CVE-2018-14807»º³åÇøÒç³ö©¶´

Opto 22 PAC Control´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½»òÖ´ÐÐÈÎÒâ´úÂë ¡£


https://www.opto22.com/support/resources-tools/knowledgebase/kb87547

5. HPE Intelligent Management Center PLAT´úÂëÖ´ÐЩ¶´


HPE Intelligent Management Center PLAT´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£


https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03901en_us

Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄÂÃÐмǼй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÀ¹ú¹ú·À²¿£¨Îå½Ç´óÂ¥£©µÄ²¿Ãžü·½ºÍÎÄÖ°ÈËÔ±µÄ¸öÈËÐÅÏ¢ºÍÐÅÓÿ¨Êý¾Ýй¶ £¬Ô¼3ÍòÈËÊܵ½Ó°Ïì ¡£ÕâÒ»Êý¾Ýй¶Ê¼þ¿ÉÄÜ·¢ÉúÔÚ¼¸¸öÔÂÇ° £¬µ«Ö±µ½×î½ü²Å±»·¢ÏÖ ¡£¸ÃʼþÉæ¼°µ½Ò»¼ÒΪ¹ú·À²¿Ìṩ·þÎñµÄµÚÈý·½¹©Ó¦ÉÌ £¬Ä¿Ç°¸Ã¹©Ó¦É̵ÄÉí·ÝÈÔÈ»²»Ã÷È· ¡£ÕâһʼþÈÔÈ»ÔÚ½øÒ»²½µÄÊÓ²ìÖ®ÖÐ £¬µ«Ã»ÓÐÈκλúÃÜÐÅÏ¢Ô⵽й¶ ¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77097/data-breach/pentagon-travel-records-data-breach.html

2¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎÚ¿ËÀ¼Äþ¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷ ¡£SBUר¼ÒÖ¸³ö £¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ £¬Æ书Ч°üÂÞÔ¶³Ì¹ÜÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍÀ¹½ØÃÜÂëµÈ ¡£Æ¾¾ÝSBUºÍÒ»¸öÄþ¾²³§É̵ÄÊÓ²ì £¬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå ¡£´ËÍâ £¬SBU»¹·¢ÏÖÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÕ¼¹¤¾ß ¡£


Ô­ÎÄÁ´½Ó£º
https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html

3¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Ç¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿ÈËÔ±ÔÚ°µÍøÂÛ̳ÉÏ·¢ÏÖÒ»¸ö°üÂÞ´óÁ¿Ñ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ ¡£¸ÃÊý¾Ý¿â°üÂÞÀ´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Ç¼ ¡£ÕâЩ¼Ç¼°üÂÞÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ ¡£Ñо¿ÈËÔ±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾½øÐÐÁËÉó²é £¬È·ÈÏÕâЩÊý¾ÝÓÐЧ¶øÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶÈ ¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´ £¬ÕâЩ鶵ÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆ»µÑ¡¾Ù»ò½øÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯ ¡£


Ô­ÎÄÁ´½Ó£º
https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/

4¡¢±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳÔâÀÕË÷Èí¼þ¹¥»÷ £¬FBIÒѽéÈëÊÓ²ì

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖÜÒ»ONWASA£¨°ºË¹Â幩ˮºÍÎÛË®¹ÜÀí¾Ö£©Ðû²¼ÏûÏ¢³Æ £¬±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳµÄÄÚ²¿¼ÆËã»úϵͳ£¨°üÂÞ·þÎñÆ÷ºÍ¸öÈ˵çÄÔ£©Ôâµ½ÀÕË÷Èí¼þEmotet¹¥»÷ ¡£ONWASAûÓÐÅû¶¾ßÌåµÄÊê½ð½ð¶î ¡£¸Ã¹¥»÷·¢ÉúÔÚ10ÔÂ4ÈÕ £¬Çé¿öËæºóÒѵõ½¿ØÖÆ ¡£ËäȻûÓпͻ§ÐÅÏ¢Ôڴ˴ι¥»÷ÖÐÊܵ½Ó°Ïì £¬µ«Ðí¶àÊý¾Ý¿âÐèÒªÖؽ¨ ¡£Ä¿Ç°FBI¡¢¹úÍÁÄþ¾²²¿ºÍ±±¿¨ÂÞÀ´ÄÉÖÝÕþ¸®ÒѽéÈëÊÓ²ì ¡£


Ô­ÎÄÁ´½Ó£º
https://www.securityweek.com/feds-investigate-after-hackers-attack-water-utility

5¡¢Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼ÄÜÔ´¹«Ë¾µÄÐÂAPT×éÖ¯GreyEnergy

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ESETÑо¿ÍŶӷ¢ÏÖÒ»¸öеÄAPT×éÖ¯GreyEnergy £¬¸ÃAPT×éÖ¯±»ÈÏΪÊÇBlackEnergyµÄ¼Ì³ÐÕß ¡£ÔÚ¹ýÈ¥ÈýÄêÄÚ £¬GreyEnergyÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼µÄÄÜÔ´¹«Ë¾µÈ¸ß¼ÛֵĿ±ê ¡£GreyEnergyµÄ¶ñÒâÈí¼þ¿ò¼ÜÓëBlackEnergy¾ßÓкܶàÏàËÆÖ®´¦ ¡£Ñо¿ÈËÔ±²¢Ã»ÓÐÊӲ쵽רÃÅÕë¶ÔICSµÄ¶ñÒâÈí¼þÄ£¿é £¬µ«GreyEnergyµÄ¹¥»÷¼ÆıһֱÊÇÕë¶ÔÒªº¦»ù´¡ÉèÊ©ÖеÄSCADAÊÂÇéÕ¾ºÍ·þÎñÆ÷µÈ ¡£


Ô­ÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí