ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ14ÖÜ

Ðû²¼Ê±¼ä 2019-04-08

 ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´45¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspÈÎÒâOSÃüÁîÖ´ÐЩ¶´ £»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐЩ¶´; Fortinet FortiOS¶ÑÒç³ö©¶´ £»TONGDA Office Anywhere SQL×¢È멶´ £»Advantech WebAccess/SCADAÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇSonicWallгÂËß³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥ £»ÒøÐÐľÂíAnubis£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹ £»Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶ £»Facebook 5.4ÒÚÓû§¼Ç¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆعâ £»JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬Ö÷ÒªÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí



1. D-Link DSL-3782 Acl.aspÈÎÒâOSÃüÁîÖ´ÐЩ¶´
D-Link DSL-3782 Acl.asp´¦ÖÃScrIPaddrEndTXT²ÎÊý´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÖ´ÐÐÈÎÒâosÃüÁî¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/

2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐЩ¶´
VMware Workstation/Fusion e1000ÐéÄâÍø¿¨ÊµÏÖ´æÔÚÔ½½ç䩶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html

3. Fortinet FortiOS¶ÑÒç³ö©¶´
Fortinet FortiOS´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://fortiguard.com/psirt/FG-IR-18-388

4. TONGDA Office Anywhere SQL×¢È멶´
TONGDA Office Anywhere´æÔÚsql×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf

5. Advantech WebAccess/SCADAÃüÁî×¢È멶´
Advantech WebAccess/SCADA´æÔÚÍⲿÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐзǷ¨ÃüÁî¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01



 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢SonicWallгÂËß³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾ÝSonicWallµÄÄê¶ÈÍøÂçÍþв³ÂËߣ¨2019°æ£©£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬±È2017ÄêµÄ1030Íò´ÎÔö³¤ÁË217.5£¥¡£ÕâÒ»Ôö³¤µÄÔ­ÒòÊÇIoTÉ豸ÖÆÔìÉÌδÄÜʵʩÊʵ±µÄÄþ¾²¿ØÖÆ¡£È«ÇòÁè¼Ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØÖ·Ô´ÓÚÃÀ¹ú£¬Æä´ÎÊÇÖйú£¨13%£©¡£´ËÍ⣬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´ÎµöÓã¹¥»÷£¬±È2017ÄêϽµ4.1£¥¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/

2¡¢ÒøÐÐľÂíAnubis£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


AndroidÒøÐÐľÂíAnubisÖ÷Ҫͨ¹ýGoogle Play Store·Ö·¢£¬×Ô2017ÄêÒÔÀ´£¬AnubisÒѾ­Ñ¬È¾ÁËÈ«ÇòÁè¼Ý300¼Ò½ðÈÚ»ú¹¹¡£Anubisͨ³£Î±×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊµÓÃС¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍÁÄÌìAPPµÈ£¬ÆäÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£2019Äê3Ô£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67

3¡¢Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖÁè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄ·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬Ö¼ÔÚʵʱ·ÖÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£´ó¶àÊý̻¶µÄʵÀý¶¼Ã»ÓÐÊܵ½± £»¤£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§·ÃÎÊÒDZíÅÌ¡£ÕâЩʵÀýÊôÓÚµç×Óѧϰƽ̨¡¢ÒøÐÐϵͳ¡¢Í£³µ¹ÜÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬ÃÀ¹ú£¨8311¸ö£©ÊÇ̻¶ʵÀý×î¶àµÄ¹ú¼Ò£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£´ËÍ⣬Ðí¶àʵÀý¶¼ÔËÐйýʱµÄÈí¼þ°æ±¾£¨´æÔÚÈÎÒâÎļþ°üÂÞ©¶´£©¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html

4¡¢Facebook 5.4ÒÚÓû§¼Ç¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆعâ

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


UpGuardÑо¿ÍŶӷ¢ÏÖÁ½¸öµÚÈý·½Ó¦ÓõÄÑÇÂíÑ·S3´æ´¢¿â¿É¹ûÈ»·ÃÎÊ£¬ÆäÖд洢ÁËÁè¼Ý5.4ÒÚFacebookÓû§µÄ¼Ç¼¡£ÕâЩÓû§Êý¾Ý°üÂÞµÚÈý·½Ó¦ÓõÄÃ÷ÎÄÃÜÂë¡¢FacebookÕË»§Ãû³Æ¡¢Óû§ID¡¢ÆÀÂÛ¡¢ÐËȤ¡¢¹Øϵ״̬µÈ¡£Ò»¸öÊý¾Ý¿âÊôÓÚÄ«Î÷¸çýÌ幫˾Cultura Colectiva£¬¸ÃÊý¾Ý¿âÃûΪcc-datalake£¬¾ÞϸΪ146GB£¬°üÂÞÔ¼5.4ÒÚÓû§¼Ç¼¡£ÁíÒ»¸öÊý¾Ý¿âÊôÓÚµÚÈý·½Ó¦ÓÃAt the Pool£¬Ö»°üÂÞ2.2ÍòÓû§¼Ç¼¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/

5¡¢JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬Ö÷ÒªÇÔÈ¡ÐÅÓÿ¨ÐÅÏ¢


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÄþ¾²³§ÉÌGroup-IBµÄÒ»·ÝгÂËߣ¬½ü38¸ö²îÒìµÄJS-SnifferѬȾÁËÈ«Çò2440¸öµç×ÓÉÌÎñÍøÕ¾¡£JS-SnifferÊÇÒ»ÖÖJavaScript¶ñÒâ½Å±¾£¬Ö¼ÔÚÀ¹½Ø²¢ÇÔÈ¡Óû§ÊäÈëµÄÒøÐп¨ºÅ¡¢ÐÕÃû¡¢µØÖ·¡¢µÇ¼ÐÅÏ¢ºÍÃÜÂëµÈ¡£Æ¾¾ÝÔ¤¼Æ£¬ÕâЩJS-sniffer¿ª·¢ÕßµÄÊÕÒæ¿É´ïÿÔÂÊýÊ®ÍòÃÀÔª¡£ÔÚÕâЩJS-Sniffer¼Ò×åÖУ¬ÖÁÉÙÓÐ8¸ö֮ǰ´Óδ±»ÊÓ²ì¹ý¡£ÔÚÊÜѬȾµÄÍøÕ¾ÖУ¬Áè¼ÝÒ»°ëµÄ¹¥»÷ÊÇÓÉJS-sniffer¼Ò×åMagentoNameÌᳫµÄ£¬¶øÁè¼Ý13%µÄ¹¥»÷ÊÇÓÉWebRank¼Ò×åÌᳫµÄ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html