ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ2ÖÜ

Ðû²¼Ê±¼ä 2019-01-14

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ07ÈÕÖÁ11ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´63¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Identity Services Engine CVE-2018-15456ÃÜÂë»Ö¸´Â©¶´£»Imperva SecureSphereÌí¼ÓÈÎÒâsshÃÜԿ©¶´£»Juniper Junos OS BGP¾Ü¾ø·þÎñ©¶´£»Microsoft Visual Studio CVE-2019-0546ÈÎÒâ´úÂëÖ´ÐЩ¶´£»Microsoft Exchange ServerÔ¶³ÌÐÅϢ鶩¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÐÂDNS½Ù³ÖÀ˳±Ï¯¾íÈ«Çò£¬ÒÉΪÒÁÀʺڿÍËùΪ£»Google PlayϼÜ85¸ö¹ã¸æapp£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§£»Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆع⣻AvastÐû²¼2019ÄêÍøÂçÍþв̬ÊƵÄÔ¤²â³ÂËߣ»IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1. Cisco Identity Services Engine CVE-2018-15456ÃÜÂë»Ö¸´Â©¶´
Cisco Identity Services Engine Admin Portal²»ÕýÈ·Éú´æÃÜÂëÐÅÏ¢£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬼ì²ìÃ÷ÎÄÃÜÂëÐÅÏ¢£¬Î´ÊÚȨ·ÃÎÊ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-passwd

2. Imperva SecureSphereÌí¼ÓÈÎÒâsshÃÜԿ©¶´
Imperva SecureSphere´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÏò¹ÜÀíÔ±Óû§µÄauthorized_keysÌí¼ÓÈÎÒâsshÃÜÔ¿¡£
https://www.exploit-db.com/exploits/45130

3. Juniper Junos OS BGP¾Ü¾ø·þÎñ©¶´
Juniper Junos OS´¦ÖÃBGPÏûÏ¢´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷¡£
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10912&actp=METADATA

4. Microsoft Visual Studio CVE-2019-0546ÈÎÒâ´úÂëÖ´ÐЩ¶´
Microsoft Visual StudioÔÚC++±àÒëÆ÷δÕýÈ·´¦ÖÃC++½á¹¹Ìض¨×éºÏ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Óù¦Ð§·¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0546

5. Microsoft Exchange ServerÔ¶³ÌÐÅϢ鶩¶´
Microsoft Exchange Server PowerShell APIÔÚcalendar contributorsȨÏÞ¹ÜÀíÖдæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÈÕÀúµÈÃô¸ÐÐÅÏ¢¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0588


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÐÂDNS½Ù³ÖÀ˳±Ï¯¾íÈ«Çò£¬ÒÉΪÒÁÀʺڿÍËùΪ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


FireEye·¢ÏÖÒ»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNS½Ù³ÖÀ˳±£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£ÕâЩÓòÃûÊôÓÚÕþ¸®¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£ËäȻĿǰÑо¿ÈËÔ±»¹Ã»Óн«´Ë»î¶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬µ«¿ª¶ËµÄÑо¿±íÃ÷¹¥»÷ÕßÒÉÓëÒÁÀÊÓйØ¡£¸Ã¹¥»÷»î¶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂÆÚ¼äÒ»Ö±´¦ÓÚ»îԾ״̬£¬¶øÇÒ´æÔÚ¶à¸ö²»Öظ´µÄÓòÃû¡¢IPµØÖ·¼¯Èº¡£ÕâÒâζןù¥»÷»î¶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕߵĻ¡£¹¥»÷Õߵļ¼ÊõÖ÷ÒªÉæ¼°ÐÞ¸ÄDNS A¼Ç¼¡¢NS¼Ç¼ºÍÖض¨Ïò¡£

Ô­ÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html

2¡¢Google PlayϼÜ85¸ö¹ã¸æapp£¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Ç÷ÊƿƼ¼µÄÑо¿ÈËÔ±ÔÚGoogle PlayÉ̵귢ÏÖ85¸ö¹ã¸æÓ¦Óã¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿ØÆ÷µÈ£¬ÔÚÉ豸ºǫ́¾²Ä¬ÔËÐУ¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§É豸¡£Ñо¿ÈËÔ±·¢ÏÖÕâЩappÀ´×ÔÓÚ²îÒìµÄ¿ª·¢ÈËÔ±£¬¶øÇÒÓµÓвîÒìµÄAPKÖ¤Ê鹫Կ£¬µ«ËüÃǵĴúÂëºÍÃüÃû·½Ê½¶¼Ê®·ÖÏàËÆ¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓá£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html

3¡¢Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆعâ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Äþ¾²Ñо¿Ô±Justin Paine·¢ÏÖÒ»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷£¬¸Ã·þÎñÆ÷°üÂÞÀ´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý£¬ÆäÖаüÂÞÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍ·ÏßÐÅÏ¢¡£²îÒìÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ïàͬ£¬ÔÚijЩ°¸ÀýÖУ¬»¹°üÂÞ´î¿ÍµÄÓû§ÃûºÍµç×ÓÓʼþµØÖ·¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆعâÁËÈýÖܵÄʱ¼ä¡£ÔÚPaine֪ͨӡ¶ÈCERTºó£¬¸Ã·þÎñÆ÷µÃµ½±£»¤£¬µ«CERT¾Ü¾ø͸¶¸Ã·þÎñÆ÷µÄËùÓÐÕß¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/

4¡¢AvastÐû²¼2019ÄêÍøÂçÍþв̬ÊƵÄÔ¤²â³ÂËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



AvastµÄ2019ÄêÍþв̬ÊÆÔ¤²â³ÂËßÖ¸³ö£¬ÔÚ2019Äê·´¿¹ÐÔAI½«Ó­À´ÀèÃ÷¡£Ñо¿ÈËÔ±Ô¤²âDeepAttacks¹¥»÷½«¸üƵ·±µØ·ºÆð£¨ÕâÀ๥»÷ͨ³£ÀûÓÃAIÉú³ÉµÄÄÚÈÝÀ´ÌÓ±ÜAIÄþ¾²¿ØÖÆ´ëÊ©£©¡£´ËÍ⣬ÎïÁªÍøÍþв½«±äµÃÔ½·¢ÅÓ´ó£¬Â·ÓÉÆ÷Ò²½«Ô½À´Ô½¶àµØ³ÉΪ¹¥»÷Ä¿±ê£¬¹ã¸æ¡¢µöÓãºÍÐé¼ÙÓ¦Óý«¼ÌÐøÖ÷µ¼Òƶ¯ÍþвÁìÓò¡£


Ô­ÎÄÁ´½Ó£º
https://cdn2.hubspot.net/hubfs/486579/Avast_Threat_Landscape_Report_2019.pdf

5¡¢IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌáÆðËßËÏ£¬¿Ø¸æIBM×Ó¹«Ë¾TWCµÄÌìÆøÓ¦Óã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþ˽Êý¾Ý²¢½«ÕâЩÐÅÏ¢³öÊÛ¸øµÚÈý·½£¬°üÂÞ¹ã¸æ¹«Ë¾¡£Âåɼí¶Êз½ÃæÌåÏÖ£¬Weather ChannelÔÚÐí¶àÓû§²»ÖªÇéµÄÇé¿öϸú×ÙÓû§µÄµØÀíλÖÃÊý¾Ý£¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÌìÆøÔ¤±¨ÍêÈ«Î޹صĹã¸æµÈÉÌÒµÓÃ;¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí