ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ14ÖÜ
Ðû²¼Ê±¼ä 2019-04-08±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´45¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspÈÎÒâOSÃüÁîÖ´ÐЩ¶´£»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐЩ¶´; Fortinet FortiOS¶ÑÒç³ö©¶´£»TONGDA Office Anywhere SQL×¢È멶´£»Advantech WebAccess/SCADAÃüÁî×¢È멶´¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
ÖØÒªÄþ¾²Â©¶´Áбí
D-Link DSL-3782 Acl.asp´¦ÖÃScrIPaddrEndTXT²ÎÊý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÖ´ÐÐÈÎÒâosÃüÁî¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/
2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐЩ¶´
VMware Workstation/Fusion e1000ÐéÄâÍø¿¨ÊµÏÖ´æÔÚÔ½½ç䩶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
3. Fortinet FortiOS¶ÑÒç³ö©¶´
Fortinet FortiOS´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://fortiguard.com/psirt/FG-IR-18-388
4. TONGDA Office Anywhere SQL×¢È멶´
TONGDA Office Anywhere´æÔÚsql×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf
5. Advantech WebAccess/SCADAÃüÁî×¢È멶´
Advantech WebAccess/SCADA´æÔÚÍⲿÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐзǷ¨ÃüÁî¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01
ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢SonicWallгÂËß³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥

ƾ¾ÝSonicWallµÄÄê¶ÈÍøÂçÍþв³ÂËߣ¨2019°æ£©£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬±È2017ÄêµÄ1030Íò´ÎÔö³¤ÁË217.5£¥¡£ÕâÒ»Ôö³¤µÄÔÒòÊÇIoTÉ豸ÖÆÔìÉÌδÄÜʵʩÊʵ±µÄÄþ¾²¿ØÖÆ¡£È«ÇòÁè¼Ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØÖ·Ô´ÓÚÃÀ¹ú£¬Æä´ÎÊÇÖйú£¨13%£©¡£´ËÍ⣬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´ÎµöÓã¹¥»÷£¬±È2017ÄêϽµ4.1£¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/
2¡¢ÒøÐÐľÂíAnubis£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹
AndroidÒøÐÐľÂíAnubisÖ÷Ҫͨ¹ýGoogle Play Store·Ö·¢£¬×Ô2017ÄêÒÔÀ´£¬AnubisÒѾѬȾÁËÈ«ÇòÁè¼Ý300¼Ò½ðÈÚ»ú¹¹¡£Anubisͨ³£Î±×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊµÓÃС¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍÁÄÌìAPPµÈ£¬ÆäÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£2019Äê3Ô£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67
3¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html
4¡¢Facebook 5.4ÒÚÓû§¼Ç¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆعâ
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/
5¡¢JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬Ö÷ÒªÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html