ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ16ÖÜ

Ðû²¼Ê±¼ä 2019-04-22

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê4ÔÂ15ÈÕÖÁ21ÈÕ±¾ÖÜ

¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAtlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú©¶´ £»Sangfor Sundray WLAN ControllerȨÏÞÌáÉý©¶´; GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý©¶´ £»Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³ö©¶´ £»Cloud Foundry Cloud Controller APIÑé֤©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇ΢ÈíÔâºÚ¿Í¹¥»÷£¬²¿ÃÅÓû§µÄOutLookÕÊ»§ÐÅϢй¶ £»Gnosticplayers³öÊÛµÚÎåÅúÓû§Êý¾Ý£¬°üÂÞ6500¶àÍò¸öÕ˺Å £»³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬½Ù³Ö5ÒÚiOSÓû§»á»° £»JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄ¸öÈËÐÅÏ¢ £»FacebookÐÂÊý¾Ý³óÎÅ£¬Î´¾­Óû§Ðí¿ÉÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



ÖØÒªÄþ¾²Â©¶´Áбí



1. Atlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú©
Atlassian Confluence ServerºÍAtlassian Data Center downloadallattachments×ÊÔ´´æÔÚ·¾¶±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎļì²ìϵͳÎļþÄÚÈÝ¡£
https://jira.atlassian.com/browse/CONFSERVER-58102

2. Sangfor Sundray WLAN ControllerȨÏÞÌáÉý©¶´
Sundray WLAN Controller nginx_webconsole.php´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɶÁÈ¡adminÃÜÂ룬»ñȡȨÏÞ¡£
https://nvd.nist.gov/vuln/detail/CVE-2019-9161

3. GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý©¶´
GitLab impersonate user¹¦Ð§´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÌáÉýÓû§È¨ÏÞ¡£
https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/

4. Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³ö©¶´
Delta Electronics Delta Industrial Automation CNCSoft´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë»ò½øÐоܾø·þÎñ¹¥»÷¡£

https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01


5. Cloud Foundry Cloud Controller APIÑé֤©¶´
Cloud Foundry Cloud Controller APIÑé֤ʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.cloudfoundry.org/blog/cve-2019-3798


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢Î¢ÈíÔâºÚ¿Í¹¥»÷£¬²¿ÃÅÓû§µÄOutLookÕÊ»§ÐÅϢй¶

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

΢Èí֤ʵ1ÔÂ1ÈÕÖÁ3ÔÂ29ÈÕÆڼ乥»÷ÕßÈëÇÖÁËÒ»¸ö¿Í»§Ö§³ÖÊðÀíÕË»§£¬²¢ÀûÓøÃÕË»§·ÃÎÊÁË¿Í»§Ö§³ÖÃÅ»§ÍøÕ¾¼°²¿ÃÅOutLookÓû§µÄÏà¹ØÐÅÏ¢¡£ÕâЩÐÅÏ¢°üÂÞµç×ÓÓʼþµØÖ·¡¢Îļþ¼ÐÃû³Æ¡¢ÓʼþÖ÷Ìâ¼°ÁªÏµÈ˵ç×ÓÓʼþµØÖ·£¬µ«²»°üÂÞÓʼþ¼°¸½¼þµÄÄÚÈÝ¡£Ä¿Ç°Éв»Çå³þ¹¥»÷µÄ¾ßÌåϸ½Ú£¬µ«Î¢ÈíÌåÏÖÒѾ­½ûÓÃÁ˸ÃÊðÀíÕË»§µÄƾ¾Ý£¬²¢Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§¡£Î¢ÈíҲûÓÐ͸¶ÊÜÓ°ÏìµÄÓû§×ÜÊý¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/microsoft-outlook-email-hack.html

2¡¢Gnosticplayers³öÊÛµÚÎåÅúÓû§Êý¾Ý£¬°üÂÞ6500¶àÍò¸öÕ˺Å

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍGnosticplayersÔÚ°µÍøÂÛ̳DreamMarketÉϳöÊÛµÚÎåÅú±»µÁµÄÓû§Êý¾Ý£¬ÕâÅúÊý¾Ý°üÂÞÁè¼Ý6500Íò¸öÓû§ÕË»§£¬ÊÛ¼ÛΪ0.8463±ÈÌرң¨4350ÃÀÔª£©¡£ÕâÅú±»µÁµÄÓû§¼Ç¼ÊôÓÚÁù¼Òй«Ë¾£¬°üÂÞÓÎϷƽ̨Mindjolt£¨2800Íò£©¡¢ÔÚÏß¹ºÎïÉçÇøWanelo£¨2300Íò£©¡¢Æ»¹ûάÐÞÖÐÐÄiCracked£¨150Íò£©¡¢ÂÃÓι«Ë¾Yanolja£¨150Íò£©¡¢µç×ÓÑûÇë·þÎñEvite£¨1000Íò£©ºÍÅ®×ÓʱװµêModa Operandi£¨150Íò£©¡£Ä¿Ç°ÎªÖ¹Gnosticplayers³öÊ۵ı»µÁÓû§¼Ç¼×ÜÊýÒÑ´ï9.32ÒÚÌõ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/gnosticplayers-hacker-returns-with-fifth-dataset-containing-over-65-million-user-accounts-for-sale-95450e99

3¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬½Ù³Ö5ÒÚiOSÓû§»á»°


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äþ¾²³§ÉÌConfiant·¢ÏÖ·¸×ïÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬ÒѽٳÖ5ÒÚiOSÓû§µÄ»á»°¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕ¿ªÊ¼£¬Á¬ÐøÁË6ÌìµÄʱ¼ä£¬¹¥»÷ÕßʹÓÃÁË8¸ö²îÒìµÄ¶ñÒâ¹ã¸æϵÁкÍ30¶à¸öÐé¼Ù¹ã¸æ£¬Ã¿¸öÐé¼Ù¹ã¸æϵÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬²¢ÔÚ¹¥»÷ÖÐÀûÓÃÁËChromeä¯ÀÀÆ÷ÖеÄ©¶´ÒÔÈƹýɳºÐ¼ì²â¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĵöÓãÍøÕ¾£¬¾­¹ý¶ÌÔݵÄÍ£¶ÙÖ®ºó£¬ÓÖתÏò.siteÓòÃûµÄµöÓãÍøÕ¾¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬ÕâЩµöÓãÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

4¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄ¸öÈËÐÅÏ¢

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äþ¾²Ñо¿Ô±Rajshekhar Rajaharia·¢ÏÖÓ¡¶Èµ±µØËÑË÷·þÎñ¹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ £»¤£¬¿É±»ÈκÎÈËÀûÓÃÒÔ¼ìË÷Áè¼Ý100ÍòÓû§µÄ¸öÈËÐÅÏ¢¡£Ð¹Â¶µÄÊý¾Ý°üÂÞÓû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢¾ÓסµØÖ·¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ÕÕƬ¡¢¾ÍÖ°¹«Ë¾µÈ¡£ËäÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹ûÈ»·ÃÎÊ£¬µ«Éв»Çå³þÊÇ·ñÒÑÓÐÈËÀûÓÃËüÀ´ÊÕ¼¯JustDialÓû§µÄ¸öÈËÐÅÏ¢¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

5¡¢FacebookÐÂÊý¾Ý³óÎÅ£¬Î´¾­Óû§Ðí¿ÉÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚÖÜÈýÐû²¼µÄÒ»·ÝÉùÃ÷ÖУ¬FacebookÌåÏÖ×Ô2016Äê5ÔÂÒÔÀ´¸Ã¹«Ë¾¡°ÎÞÒâ¼ä¡±ÔÚδ¾­Óû§Ðí¿ÉµÄÇé¿öÏÂÏò·þÎñÆ÷ÉÏ´«Á˶à´ï150ÍòÓû§µÄµç×ÓÓʼþÁªÏµÈË¡£ÕâÊÇFacebook½üÆÚÃæÁÙµÄһϵÁÐÒþ˽Ïà¹ØÎÊÌâºÍÕùÒéÖеÄ×îÐÂʼþ¡£FacebookÌåÏÖÒÑÔÚÒ»¸öÔÂÇ°Í£Ö¹ÁË¿ÉÒɵĵç×ÓÓʼþÑéÖ¤¹ý³Ì£¬²¢ÏòÓû§±£Ö¤Î´·ÖÏíÕâЩÁªÏµÈËÐÅÏ¢¼°ÒѾ­¿ªÊ¼É¾³ýÕâЩÁªÏµÈË¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/facebook-email-database.html