ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ9ÖÜ

Ðû²¼Ê±¼ä 2019-03-04

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ25ÈÕÖÁ3ÔÂ03ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Airflow AirflowÔªÊý¾Ý¿âÈÎÒâ´úÂëÖ´ÐЩ¶´£»F5 BIG-IPÑéÖ¤SSLÔ¶³Ì¾Ü¾ø·þÎñ©¶´; Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌÃüÁîÖ´ÐЩ¶´£»Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶Á䩶´£»OpenSSLÄþ¾²ÈƹýÐÅϢ鶩¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǽü7ÍòÕÅ°Í»ù˹̹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ÊÛ¼Û½ü350ÍòÃÀÔª£»Èý¸ö4G/5G©¶´£¬¿Éµ¼Ö¹¥»÷ÕßÈƹýÆä·À»¤¼Æı£»Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»Æ­¾Ö£¬Õ©Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷£»Chrome 0day©¶´£¬¹¥»÷Õß¿Éͨ¹ýPDFÊÕ¼¯Óû§ÐÅÏ¢£»CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£

ÖØÒªÄþ¾²Â©¶´Áбí


1. Apache Airflow AirflowÔªÊý¾Ý¿âÈÎÒâ´úÂëÖ´ÐЩ¶´
Apache Airflow±à¼­AirflowÔªÊý¾Ý¿âÖй¤¾ßµÄ״̬´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b@%3Cdev.airflow.apache.org%3E

2. F5 BIG-IPÑéÖ¤SSLÔ¶³Ì¾Ü¾ø·þÎñ©¶´
F5 BIG-IPÑéÖ¤SSL´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷¡£
https://support.f5.com/csp/article/K54167061

3. Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌÃüÁîÖ´ÐЩ¶´
Cisco?RV110W Wireless-N VPN Firewall¡¢RV130W Wireless-N Multifunction VPN RouterºÍRV215W Wireless-N VPN Router WEB½Ó¿Ú´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex

4. Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶Á䩶´
Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cûÓгäʵ¼ì²éASN.1³¤¶È£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷»òÖ´ÐÐÈÎÒâ´úÂë¡£
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc

5. OpenSSLÄþ¾²ÈƹýÐÅϢ鶩¶´
OpenSSL´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÈƹýÄþ¾²ÏÞÖÆ£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://www.openssl.org/news/secadv/20190226.txt

 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢½ü7ÍòÕÅ°Í»ù˹̹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ÊÛ¼Û½ü350ÍòÃÀÔª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Group-IBÑо¿ÈËÔ±·¢ÏÖ69189ÕÅ°Í»ù˹̹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1Ôµ×ÔÚJoker's StashÉÏÐû²¼µÄ£¬¹²°üÂÞ1535ÕÅÒøÐп¨ÐÅÏ¢£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйØ¡£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉÏÐû²¼µÄ£¬°üÂÞ67654ÕÅÒøÐп¨ÐÅÏ¢£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйØ¡£ÕâЩÊý¾Ý¿ÉÄܱíÃ÷Á˸õØÓòÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕߵĻ¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html

2¡¢Èý¸ö4G/5G©¶´£¬¿Éµ¼Ö¹¥»÷ÕßÈƹýÆä·À»¤¼Æı

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ2019ÄêNDSSÑÐÌÖ»áÉÏ£¬Ò»¸öÑо¿ÍŶÓÅû¶ÁËÔÚ4GºÍ5G LTEЭÒé·äÎÑÍøÂçÖз¢ÏÖµÄÈý¸öÐÂÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ©¶´À¹½ØÓû§Í¨»°ºÍ×·×ÙÓû§Î»Öá£Ñо¿ÈËÔ±Åû¶µÄµÚÒ»ÖÖ¹¥»÷ÒªÁìÊÇTorpedo¹¥»÷£¬ËüÀûÓÃÁËÑ°ºôЭÒéÖеÄ©¶´£¬ÔÚ¶Ìʱ¼äÄÚ·¢³öºÍÈ¡Ïû¶à¸öµç»°¿ÉÒÔ´¥·¢Ñ°ºôÏûÏ¢£¬¶ø²»»áÏòÄ¿±êÉ豸·¢³öÀ´µç¾¯±¨¡£¹¥»÷Õß¿ÉÒÔ¸ú×ÙÄ¿±êµÄλÖ㬽ٳÖÑ°ºôÐŵÀºÍ×¢ÈëαÔìµÄÑ°ºôÏûÏ¢À´ÌᳫDoS¹¥»÷¡£´ËÍ⣬ToRPEDO¹¥»÷»¹ÎªÁíÍâÁ½ÖÖ¹¥»÷-PIERCERºÍIMSI-Cracking¹¥»÷-ÌṩÁË¿ÉÄÜ£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔ»ñÈ¡Óû§µÄIMSI¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/location-tracking-imsi-catchers.html

3¡¢Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»Æ­¾Ö£¬Õ©Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú¹ú¼ÒÆÛÕ©ºÍÍøÂç·¸×ïͳ¼ÆÖÐÐÄAction FraudÌåÏÖ£¬Ò»¸öÕë¶ÔInstagramÓû§µÄ¡°¿ìËÙÖ¸»¡±Æ­¾ÖÒѾ­ÀÛ¼ÆÕ©Æ­Á˸ߴï300ÍòÓ¢°÷µÄ½ð¶î¡£¸ÃÕ©Æ­»î¶¯Ö÷ÒªÕë¶Ô20ÖÁ30ËêµÄÄêÇáÈË£¬×Ô2018Äê10ÔÂÒÔÀ´£¬ÒÑÓÐ356ÆðÏà¹ØʼþµÄ³ÂËߣ¬Êܺ¦Õßƽ¾ùÿÈËËðʧ8900Ó¢°÷¡£¸ÃÕ©Æ­»î¶¯ÏòÓû§ÔÊÐí¿ÉÔÚ24СʱÄÚ»ñµÃ¸ß¶î»Ø±¨£¬µ«±ØÐëÏÈͶ×Ê600Ó¢°÷£¬µ±Êܺ¦ÕßתÕ˺ó£¬ÆÛÕ©Õß»áÏòËûÃÇ·¢ËÍÒ»¸öÆÁÄ»½Øͼ£¬ÏÔʾÆäÕË»§ÒÑÊÕÈëÊýǧӢ°÷¡£µ«µ±Êܺ¦ÕßÒªÇóÌáÏÖʱ£¬ÆÛÕ©Õ߾ͻáÍ£Ö¹ÁªÏµ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-get-rich-quick-scheme-costs-instagram-users-over-3-million-61d5d384

4¡¢Chrome 0day©¶´£¬¹¥»÷Õß¿Éͨ¹ýPDFÊÕ¼¯Óû§ÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


EdgeSpotÑо¿ÈËÔ±ÊӲ쵽ÀûÓÃChromeÁãÈÕ©¶´ÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâPDFÎļþ¡£µ±Óû§Í¨¹ýChromeµÄPDF¼ì²ìÆ÷´ò¿ª¸Ã¶ñÒâÎļþʱ£¬¹¥»÷Õß¿ÉÀûÓ鶴ÊÕ¼¯Óû§µÄÐÅÏ¢£¬²¢·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£ÕâЩÐÅÏ¢°üÂÞϵͳµÄÏêϸÐÅÏ¢£¬ÀýÈçIPµØÖ·¡¢²Ù×÷ϵͳ°æ±¾ºÅ¡¢Chrome°æ±¾ºÅ¡¢PDFÎļþ·¾¶µÈ¡£ÖµµÃ×¢ÒâµÄÊÇ£¬¶ñÒâPDFÎļþÔÚAdobe ReaderÖв»»áÖ´ÐÐÈκζñÒâ»î¶¯¡£GoogleÈ·ÈÏÁËÕâһ©¶´£¬²¢ÔÊÐí½«ÔÚ4Ôµ׽øÐÐÐÞ¸´¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d

5¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÃÜ»õ±ÒÇ®°üCoinomiÔÚÇ®°üÉèÖùý³ÌÖлὫÓû§µÄÃ÷ÎÄÃÜÂëͨ¹ýHTTP·¢ËÍÖÁ¹È¸èµÄƴд¼ì²é·¨Ê½£¬µ¼ÖÂÓû§µÄÕË»§ºÍ×ʽðÒ×ÊÜÖмäÈË£¨MiTM£©¹¥»÷¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÀ¹½Øµ½µÄÃÜÂëµÇ¼Óû§µÄÕË»§²¢Çå¿ÕÆä×ʽð¡£Ò»¸öÓû§Al MaawaliÌåÏÖ£¬ÆäÕË»§ÖеÄ×ʽðÒò´ËËðʧÁË90%£¬¼ÛÖµÔ¼7ÍòÃÀÔª¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c

ÉùÃ÷£º±¾×ÊѶÓɶ«É­Æ½Ì¨Î¬ËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí