ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ51ÖÜ

Ðû²¼Ê±¼ä 2018-12-24
±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê12ÔÂ17ÈÕ23ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇWordPress two-factor-authentication²å¼þ¿çÕ¾ÇëÇóαÔ쩶´ £»ABB GATE-E1ºÍGATE-E2ÑéÖ¤Èƹý©¶´ £»Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç³ö©¶´ £»DedeCMS uploads/include/dialog/select_images_post.phpÈÎÒâ´úÂëÖ´ÐЩ¶´ £»TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀDoD³ÆÆ䵯µÀµ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂçÄþ¾²Éó¼Æ £»Å·ÖÞÒé»áºÍÀíÊ»áÐû²¼¡¶Å·Ã˵ç×ÓͨÐŹ淶£¨EECC£©¡· £»Elasticsearch Kibana¿ØÖÆ̨Îļþ°üÂÞ©¶´£¬PoC´úÂëÒÑÐû²¼ £»NASAÅû¶Êý¾Ýй¶Ê¼þ£¬²¿ÃÅÔ±¹¤µÄPIIÐÅÏ¢±»µÁ £»SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δÐÞ¸´µÄWindows 0day¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1. WordPress two-factor-authentication²å¼þ¿çÕ¾ÇëÇóαÔ쩶´


WordPress two-factor-authentication²å¼þ´æÔÚ¿çÕ¾ÇëÇóαÔ쩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴¹¹½¨¶ñÒâURI£¬ÓÕʹÇëÇ󣬿ÉÒÔÄ¿±êÓû§ÉÏÏÂÎÄÖ´ÐжñÒâ²Ù×÷¡£

https://wordpress.org/plugins/two-factor-authentication/#developers

2. ABB GATE-E1ºÍGATE-E2ÑéÖ¤Èƹý©¶´


ABB GATE-E1ºÍGATE-E2ÔÚ¹ÜÀítelnet»òweb½Ó¿ÚÖдæÔÚÑéÖ¤ÅäÖ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖØÖÃÉ豸¡¢¶ÁÈ¡»òÐÞ¸Ä×¢²á±í¡¢ÐÞ¸ÄIPµØÖ·µÈ¡£

https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01

3. Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç³ö©¶´


Advantech WebAccess/SCADA´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://ics-cert.us-cert.gov/advisories/ICSA-18-352-02

4. DedeCMS uploads/include/dialog/select_images_post.phpÈÎÒâ´úÂëÖ´ÐЩ¶´


DedeCMS uploads/include/dialog/select_images_post.php´æÔÚÊäÈëÑéÖ¤ ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄË«ÖØÀ©Õ¹¼°Ð޸ĵÄ.php×Ó×Ö·û´®ÇëÇ󣬿ÉÉÏ´«ÈÎÒâÎļþ²¢Ö´ÐС£

http://www.iwantacve.cn/index.php/archives/88/

5. TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç³ö©¶´


TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£

http://packetstormsecurity.com/files/150693/TRENDnet-Command-Injection-Buffer-Overflow-Cross-Site-Scripting.html


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀDoD³ÆÆ䵯µÀµ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂçÄþ¾²Éó¼Æ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý³ÂËߣ¬ÃÀ¹úµÄµ¯µÀµ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂçÄþ¾²Éó¼Æ¡£¸Ã³ÂËßÖ¸³öBMDSÉèʩδÄÜʵʩӦÓеÄÄþ¾²¿ØÖÆ´ëÊ©£¬°üÂÞ¶àÒòËØÉí·ÝÈÏÖ¤¡¢Â©¶´ÆÀ¹ÀºÍ»º½â¡¢·þÎñÆ÷»ú¼ÜÄþ¾²¡¢¿ÉÒƶ¯Ã½ÌåÉϵĻúÃÜÊý¾Ý± £»¤ºÍ¼¼ÊõÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£´ËÍ⣬һЩÎïÀíÄþ¾²´ëʩҲûÓе½Î»£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»Óа²×°ÔÚÐèÒª°²×°µÄλÖ᣼à²ì³¤°ì¹«ÊÒÕýÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕÇ°»ØÓ¦¸Ã·Ý³ÂËß¡£

Ô­ÎÄÁ´½Ó£º
https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF

2¡¢Å·ÖÞÒé»áºÍÀíÊ»áÐû²¼¡¶Å·Ã˵ç×ÓͨÐŹ淶£¨EECC£©¡·

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Å·ÖÞÒé»áºÍÀíÊ»áÐû²¼¡¶Å·Ã˵ç×ÓͨÐŹ淶£¨EECC£©¡·£¬¸Ã¹æ·¶ÊǶÔ2009ÄêÐû²¼µÄÏÖÓеç×ÓͨÐÅÁ¢·¨¿ò¼ÜµÄÖØÐÂÐÞ¶©¡£Å·Ã˳ÉÔ±¹ú½«ÓÐÁ½ÄêµÄʱ¼ä½«¸Ã¹æ·¶µÄÏà¹ØÌõ¿îת»»Îª±¾¹úµÄÖ´·¨¡¢¹æÔòºÍÐÐÕþ¹æ¶¨£¬ÕâÒ»×îºóÆÚÏÞÊÇ2020Äê12Ô¡£¸Ã¹æ·¶µÄÕûÌåÄ¿±êÊÇ¡°Ê¹Å·ÃËÔÚ2025ÄêÕ¾ÔÚ»¥ÁªÍøÁ¬½ÓµÄ×îÇ°ÑØ-´´½¨Ò»¸öǧÕ×Éç»á¡±¡£¸Ã¹æ·¶»¹°üÂÞ¶ÔÄþ¾²µÄ¹æ¶¨Ìõ¿î£ºµç×ÓͨÐÅÍøÂç·þÎñÉÌÐèÒª½ÓÄÉÏàÓ¦µÄ¼¼ÊõºÍ»úÖÆ£¬ÒÔ×î´óÏ޶ȵؼõÉÙÄþ¾²Ê¼þ¡£


Ô­ÎÄÁ´½Ó£º
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018L1972

3¡¢Elasticsearch Kibana¿ØÖÆ̨Îļþ°üÂÞ©¶´£¬PoC´úÂëÒÑÐû²¼

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



KibanaÊÇElasticsearchµÄÊý¾Ý¿ÉÊÓ»¯¹¤¾ß£¬ÆäConsole²å¼þ´æÔÚµ±µØÎļþ°üÂÞ£¨LFI£©Â©¶´£¬Ñо¿ÈËÔ±Ðû²¼Á˸鶴µÄPoC´úÂë¡£¸Ã©¶´£¨CVE-2018-17246£©Ó°ÏìÁË6.4.3ºÍ5.6.13֮ǰµÄKibana°æ±¾£¬ÀÖ³ÉÀûÓø鶴¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ElasticÒÑÔÚ×îа汾µÄKibanaÖÐÐÞ¸´Á˸鶴£¬Èç¹ûÓû§ÔÝʱÎÞ·¨¸üУ¬Ò²¿ÉÒÔÔÚÅäÖÃÎļþÖнûÓøÃConsole²å¼þÀ´¹æ±ÜÕâÒ»ÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/file-inclusion-bug-in-kibana-console-for-elasticsearch-gets-exploit-code/

4¡¢NASAÅû¶Êý¾Ýй¶Ê¼þ£¬²¿ÃÅÔ±¹¤µÄPIIÐÅÏ¢±»µÁ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



NASA±»ºÚ£¬Æ¾¾Ý¸Ã»ú¹¹µÄ˵·¨£¬NASAÔÚ10ÔÂ23ÈÕ·¢ÏÖÁËÕâÒ»Êý¾Ýй¶Ê¼þ£¬ÆäÒ»¸ö´æ´¢¸öÈËÉí·ÝÐÅÏ¢£¨PII£©µÄ·þÎñÆ÷Ôâµ½ºÚ¿ÍÈëÇÖ£¬2006Äê7ÔÂÖÁ2018Äê10ÔÂÆÚ¼ä¼ÓÈëNASAµÄÔ±¹¤µÄPIIÐÅϢй¶£¬°üÂÞÀëÖ°»òµ÷Ö°µÄÔ±¹¤¡£NASAÄ¿Ç°ÓµÓÐÔ¼17300ÃûÔ±¹¤¡£¸Ã»ú¹¹ÌåÏÖûÓÐÌ«¿ÕÈÎÎñÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/nasa-hack-data-breach.html

5¡¢SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δÐÞ¸´µÄWindows 0day

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Ñо¿ÈËÔ±SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δÐÞ¸´µÄWindows 0day£¬¶øÇÒÐû²¼ÁËÏà¹ØPoC¡£Õâ¸öеĩ¶´´æÔÚÓÚWindowsµÄMsiAdvertiseProduct¹¦Ð§ÖУ¬Æ¾¾Ý¸ÃÑо¿ÈËÔ±µÄ˵·¨£¬ÓÉÓÚûÓÐÕýÈ·ÑéÖ¤£¬¹¥»÷Õß¿ÉÀûÓøù¦Ð§Ç¿ÆÈ°²×°·þÎñÒÔSYSTEMȨÏÞ¸´ÖÆÈÎÒâÎļþ²¢¶ÁÈ¡ÆäÄÚÈÝ£¬´Ó¶øµ¼ÖÂÈÎÒâÎļþ¶Áȡ©¶´¡£SandboxEscaper»¹ÔÚGithubÉÏÐû²¼Á˸鶴µÄPoC£¬µ«¸ÃGithubÕË»§Ä¿Ç°Òѱ»É¾³ý¡£SandboxEscaperÔøÔÚ2018Äê8Ô·ݺÍ10Ô·ݷֱðÔÚTwitterÉÏÅû¶ÁËÁ½¸öWindows 0day¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/windows-zero-day-exploit.html


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí