ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ3ÖÜ

Ðû²¼Ê±¼ä 2019-01-21

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBrocade Network Advisor CVE-2018-6443Ó²±àÂëƾ֤©¶´£»systemd-journaldÕ»»º³åÇøÒç³ö©¶´£»SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»IDenticard PremisysÊý¾Ý¿âĬÈÏƾ֤©¶´£»LCDS LAquis SCADAδÊÚȨ·ÃÎÊ©¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØ©¶´£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾;ÃÀOklahomaÖÝÕþ¸®·þÎñÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý;Ó¢¹úBSIAÐû²¼»¥ÁªÄþ¾²ÏµÍ³×î¼Ñʵ¼ùÖ¸ÄÏ;VoIP·þÎñÉÌVOIPOÒâÍâй¶¹ýÈ¥ËÄÄêµÄ¿Í»§Êý¾Ý;ESÎļþä¯ÀÀÆ÷Á½¸ö©¶´Ê¹µÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙ·çÏÕ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1. Brocade Network Advisor CVE-2018-6443Ó²±àÂëƾ֤©¶´
Brocade Network Advisor´æÔÚÓ²±àÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɵǼµ½JBoss Administration½çÃæ²¢°²×°ÆäËûJEEÓ¦Ó÷¨Ê½¡£
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743

2. systemd-journaldÕ»»º³åÇøÒç³ö©¶´
systemd-journaldʵÏÖ´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ê¹systemd-journald±ÀÀ£»òÒÔjournaldȨÏÞÖ´ÐдúÂë¡£
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864

3. SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
SAS Web Infrastructure PlatformµÄ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.sas.com/kb/63/391.html

4. IDenticard PremisysÊý¾Ý¿âĬÈÏƾ֤©¶´
IDenticard Premisys Identicard·þÎñÔÚ°²×°Ê±Ê¹ÓÃĬÈϵÄÊý¾Ý¿âÓû§ÃûºÍÃÜÂ룬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Î´ÊÚȨ·ÃÎÊÊý¾Ý¿âȨÏÞ¡£
http://www.securityfocus.com/bid/106552

5. LCDS LAquis SCADAδÊÚȨ·ÃÎÊ©¶´
LCDS LAquis SCADAʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÉí·ÝÑéÖ¤£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØ©¶´£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÔÉ«ÁÐÄþ¾²Ñо¿Ô±Noam Rotem·¢ÏÖ»úƱԤ¶©ÏµÍ³Amadeus´æÔÚÒ»¸öÑÏÖصÄÄþ¾²Â©¶´£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤¶©»úƱʱ·¢ÏÖÁËÕâÒ»ÎÊÌ⣬ÔÚÔ¤¶©º½°àºó£¬ÂÿͻáÊÕµ½PNRºÅÂëºÍÓÃÓÚ¼ì²ìÔ¤¶©ÐÅÏ¢µÄÁ´½Ó¡£Rotem·¢ÏÖͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÐÞ¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿É¼ì²ìËûÈ˵ÄÔ¤¶©ÐÅÏ¢£¬¹¥»÷Õß»¹¿ÉÀûÓÃÕâЩÐÅÏ¢·ÃÎÊELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬°üÂÞ¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤ¶©ÏµÍ³±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Ó㨰üÂÞÃÀ¹úÁªºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬Òò´Ë¸Ã©¶´¿ÉÄÜÓ°ÏìÁËÊýÒÚÂÿÍ¡£Ä¿Ç°AmadeusÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html



2¡¢ÃÀOklahomaÖÝÕþ¸®·þÎñÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



UpGuardÑо¿ÈËÔ±Greg Pollock·¢ÏÖÊôÓÚÃÀ¹ú¶í¿ËÀ­ºÉÂíÖÝ֤ȯ²¿ODSµÄһ̨·þÎñÆ÷¿É¹ûÈ»·ÃÎÊ£¬µ¼Ö°üÂÞÊý°ÙÍòÃô¸ÐÎļþµÄÔ¼3TBÕþ¸®Êý¾Ý̻¶¡£ÕâЩÊý¾Ý°üÂÞ֤ȯίԱ»áÊýÊ®ÄêµÄ»úÃÜÎļþºÍÐí¶àÃô¸ÐµÄFBIÊÓ²ìÎļþ£¬ÒÔ¼°Ô¼1ÍòÃû¹ÉƱ¾­¼ÍÈ˵ĵç×ÓÓʼþ¡¢Éç»áÄþ¾²ºÅÂë¡¢ÐÕÃûºÍµØÖ·ÐÅÏ¢µÈ¡£ShodanÏÔʾ¸Ã·þÎñÆ÷ÖÁÉÙ´Ó2018Äê11ÔÂ30ÈÕ¿ªÊ¼¿É¹ûÈ»·ÃÎÊ£¬Ô¼Ò»ÖܺóODSÊÕµ½Í¨Öª²¢¶Ô¸Ã·þÎñÆ÷ʵʩÁ˱£»¤´ëÊ©¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/oklahoma-fbi-data-leak.html


3¡¢Ó¢¹úBSIAÐû²¼»¥ÁªÄþ¾²ÏµÍ³×î¼Ñʵ¼ùÖ¸ÄÏ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Ó¢¹ú°²·ÀÐÐҵЭ»á£¨BSIA£©Ðû²¼»¥ÁªÄþ¾²ÏµÍ³×î¼Ñʵ¼ùÖ¸ÄÏ¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×î´óÏ޶ȵؼõÉÙµç×ÓÄþ¾²ÏµÍ³ÖеÄÍøÂçÁ¬½ÓÉ豸¡¢Èí¼þºÍϵͳµÄÊý×ÖÆÆ»µ·çÏÕ¡£¸ÃÖ¸ÄÏÒÔÐÐÒµµÄ×î¼Ñ¹ú¼Êʵ¼ùΪ»ù´¡£¬²¢²Î¿¼¹«ÈϵĹú¼ÊÖ¸ÄϺͳ߶È£¬¿ÉÒÔ×ÊÖú»¥ÁªÄþ¾²ÏµÍ³¹©Ó¦Á´ÖеÄÉè¼ÆÕß¡¢ÖÆÔìÉÌ¡¢°²×°ÈËÔ±¡¢Î¬»¤ÈËÔ±¡¢·þÎñÌṩÉ̺ÍÓû§ÌáÉýÄþ¾²Á¬½ÓµÄÐÅÐÄ¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/


4¡¢VoIP·þÎñÉÌVOIPOÒâÍâй¶¹ýÈ¥ËÄÄêµÄ¿Í»§Êý¾Ý

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Ñо¿ÈËÔ±Justin Paineͨ¹ýShodan·¢ÏÖÒ»¸ö¿É¹ûÈ»·ÃÎʵÄElasticSearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊôÓÚVoIP·þÎñÉÌVOIPO£¬ÆäÖаüÂÞÁ˸ù«Ë¾¹ýÈ¥ËÄÄêµÄ¿Í»§Êý¾Ý¡£Æ¾¾ÝPaineµÄ˵·¨£¬¸ÃÊý¾Ý¿â°üÂÞ¿É×·ËÝÖÁ2017Äê7ÔµÄ670ÍòÌõͨ»°¼Ç¼¡¢¿É×·ËÝÖÁ2015Äê12ÔµÄ600ÍòÌõ¶ÌÐÅ/²ÊÐÅÈÕÖ¾ÒÔ¼°100ÍòÌõ°üÂÞÄÚ²¿ÏµÍ³API KEYµÄÈÕÖ¾¡£Ñо¿ÈËÔ±ÓÚ1ÔÂ8ÈÕÏòVOIPOͨ±¨ÁËÕâÒ»·¢ÏÖ£¬¸Ã¹«Ë¾ÔÚͬһÌ콫Êý¾Ý¿â½øÐÐÁËÍÑ»ú±£»¤¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html



5¡¢ESÎļþä¯ÀÀÆ÷Á½¸ö©¶´Ê¹µÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙ·çÏÕ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Äþ¾²Ñо¿Ô±Robert BaptisteÔÚESÎļþä¯ÀÀÆ÷Öз¢ÏÖÒ»¸öʼÖÕÔÚºǫ́ÔËÐеÄÒþ²ØWeb·þÎñÆ÷£¨¶Ë¿Ú59777£©£¬ÓëÊܺ¦Õß´¦ÓÚͬһµ±µØÍøÂçµÄ¹¥»÷Õß¿É»ñÈ¡Êܺ¦ÕßÊÖ»úµÄ´óÁ¿ÓÐÓÃÐÅÏ¢£¨°üÂÞÉ豸ÐÅÏ¢¡¢app°²×°ÐÅÏ¢¡¢ÎļþµÈ)£¬ÉõÖÁ¿ÉÒÔÔ¶³ÌÆô¶¯app¡£¸Ã©¶´±»¸ú×ÙΪCVE-2019-6447£¬Ñо¿ÈËÔ±»¹Ðû²¼ÁËPOC½Å±¾¡£´ËÍ⣬ESETÑо¿ÈËÔ±Lukas Stefanko·¢ÏÖÁËÁíÒ»ÆäÖмäÈË£¨MitM£©¹¥»÷©¶´£¬Ó°ÏìÁË4.1.9.7.4¼°Ö®Ç°µÄ°æ±¾¡£ESÎļþä¯ÀÀÆ÷¿ª·¢ÍŶÓÌåÏÖÐÞ¸´²¹¶¡½«ÔÚԼĪÁ½ÌìºóÍƳö¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/es-file-explorer-flaws-put-100-million-users-data-at-risk-fix-promised/


ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí