ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ26ÖÜ

Ðû²¼Ê±¼ä 2019-07-08

±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´46¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Mesos Ô¶³Ì´úÂëÖ´ÐЩ¶´£»TRENDnet TEW-827DRU apply.cgiÃüÁî×¢È멶´£»NLnet Labs Name Server Daemon CVE-2019-13207»º³åÇøÒç³ö©¶´£»Nortek Security£¦Control Linear eMerge E3-Series CVE-2019-7253Ŀ¼±éÀú©¶´£»NetApp AFF A700s Baseboard Management Controller CVE-2019-5497ÃüÁî×¢È멶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇAndroid¹ã¸æÈí¼þHiddenAd£¬ÏÂÔØÁ¿´ï930Íò´Î£»CloudflareÔٴη¢×÷¹ÊÕÏ£¬´óÁ¿Íøվ崻ú£»ÖÇÄܼҾӳ§ÉÌOrviboÒâÍâй¶Áè¼Ý20ÒÚÌõÓû§¼Ç¼£»Ñо¿ÈËÔ±·¢ÏÖÊ׸öÀÄÓÃDNS over HTTPSЭÒéµÄ¶ñÒâÈí¼þGodlua£»Áè¼Ý30¸öVMware²úÎïÊܵ½Linux SACK©¶´Ó°Ïì ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£



ÖØÒªÄþ¾²Â©¶´Áбí



1. Apache Mesos Ô¶³Ì´úÂëÖ´ÐЩ¶´


Apache Mesos×é¼þ´æÔÚÁýÕÖ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄDockerÓ³Ïñ£¬¿ÉÁýÕÖinit helperÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c@%3Cdev.mesos.apache.org%3E


2. TRENDnet TEW-827DRU apply.cgiÃüÁî×¢È멶´


TRENDnet TEW-827DRU apply.cgiʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄ»ûÐÎÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâOSÃüÁî ¡£
https://github.com/TeamSeri0us/pocs/blob/master/iot/trendnet/cmdinject678.jpg

3. NLnet Labs Name Server Daemon CVE-2019-13207»º³åÇøÒç³ö©¶´


NLnet Labs Name Server Daemon dname.cÎļþµÄ¡®dname_concatenate()¡¯º¯Êý´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄ»ûÐÎÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://github.com/NLnetLabs/nsd/issues/20

4. Nortek Security£¦Control Linear eMerge E3-Series CVE-2019-7253Ŀ¼±éÀú©¶´


Nortek Security£¦Control Linear eMerge E3-Series´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄ»ûÐÎÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎĶÁÈ¡ÈÎÒâÎļþ ¡£
https://www.applied-risk.com/resources/ar-2019-005

5. NetApp AFF A700s Baseboard Management Controller CVE-2019-5497ÃüÁî×¢È멶´


NetApp AFF A700s Baseboard Management Controller´æÔÚÊäÈëÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐÈÎÒâOSÃüÁî ¡£
https://security.netapp.com/advisory/ntap-20190627-0001/


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢Android¹ã¸æÈí¼þHiddenAd£¬ÏÂÔØÁ¿´ï930Íò´Î

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Ç÷ÊƿƼ¼ÊӲ쵽һ¸ö»îÔ¾µÄ¹ã¸æÈí¼þ»î¶¯£¨AndroidOS_HiddenAd.HRXAAºÍAndroidOS_HiddenAd.GCLA£©£¬¸Ã¹ã¸æÈí¼þÒþ²ØÔÚ182¸ö¿ÉÒÔÃâ·ÑÏÂÔصÄÓÎÏ·ºÍÏà»úAPPÖУ¬ÆäÖÐ111¸ö¿ÉÔÚGoogle PlayÉ̵êÖÐÕÒµ½£¬ÆäËü¶ñÒâAPPÔòÔÚ9AppsºÍPP AssistantÆ·¼¶Èý·½Ó¦ÓÃÉ̵êÖзºÆð ¡£ÔÚ±»Ï¼Ü֮ǰ£¬ÕâЩ¶ñÒâAPPµÄ×ÜÏÂÔØÁ¿´ï934.9Íò´Î ¡£¸Ã¹ã¸æÈí¼þ¿ÉÒÔÒþ²Ø¶ñÒâAPPµÄͼ±ê£¬ÏòÓû§ÍÆËÍÎÞ·¨Á¢¼´¹Ø±Õ»òÍ˳öµÄÈ«ÆÁ¹ã¸æ£¬»¹¿ÉÒÔÌÓ±ÜɳºÐµÄ¼ì²â ¡£


Ô­ÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/adware-campaign-identified-from-182-game-and-camera-apps-on-google-play-and-third-party-stores-like-9apps/

2¡¢CloudflareÔٴη¢×÷¹ÊÕÏ£¬´óÁ¿Íøվ崻ú


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CDN¼ÓËÙ·þÎñÉÌCloudflareÔÚ±±¾©Ê±¼ä7ÔÂ2ÈÕÍí¼ä·ºÆð´óÃæ»ýå´»ú£¬Óû§·ÃÎÊʹÓÃÁËCloudflareµÄÍøÕ¾·ºÆð502´íÎó ¡£´Ë´Îå´»úÔ­ÒòÊÇCloudflareÔÚеÄWebÓ¦Óòã·À»ðǽ(WAF£©Öв¿ÊðÁËÒ»¸öÅäÖôíÎóµÄ¹æÔò£¬ÇÒÕâЩ¹æÔòÒ»´ÎÐÔÔÚËùÓнڵãÉϲ¿Ê𣬴Ӷøµ¼ÖÂÁËÈ«Çò´óÃæ»ýå´»ú ¡£¸Ã´íÎóµÄ¹æÔò°üÂÞÒ»¸öÕýÔò±í´ïʽ£¬µ¼ÖÂCloudflare·þÎñÆ÷ÉϵÄCPUÕ¼ÓÃì­ÉýÖÁ100% ¡£ËæºóCloudflare»Ø¹öÁË´íÎóµÄ¹æÔò£¬Ä¿Ç°Ïà¹Ø·þÎñÒѻָ´Õý³£ ¡£ÕâÒѾ­ÊÇCloundflare±¾Ôµڶþ´Î·ºÆðå´»úʼþ ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.cloudflare.com/cloudflare-outage/

3¡¢ÖÇÄܼҾӳ§ÉÌOrviboÒâÍâй¶Áè¼Ý20ÒÚÌõÓû§¼Ç¼


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


vpnMentorÑо¿ÈËÔ±·¢ÏÖÖÇÄܼҾӳ§ÉÌOrviboµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÈ»·ÃÎÊ£¬ÆäÖÐй¶ÁËÁè¼Ý20ÒÚÌõÓû§¼Ç¼ ¡£Æ¾¾ÝÓû§ÈÕÖ¾£¬ÐÅÏ¢±»Ð¹Â¶µÄÓû§À´×ÔÖйú¡¢ÈÕ±¾¡¢Ì©¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢Ä«Î÷¸ç¡¢·¨¹ú¡¢°Ä´óÀûÑǺͰÍÎ÷ ¡£Ð¹Â¶µÄÐÅÏ¢°üÂÞµç×ÓÓʼþµØÖ·¡¢ÃÜÂë¡¢ÕÊ»§ÖØÖôúÂë¡¢¾«È·µÄµØÀíλÖá¢IPµØÖ·¡¢Óû§ÃûºÍÓû§ID ¡£ÆäÖÐÃÜÂëΪδ¼ÓÑεÄMD5¹þÏ£¸ñʽ ¡£³ý´ËÖ®Í⣬Êý¾Ý¿âÖл¹°üÂÞ¼ÒÍ¥ID¡¢¼ÒÍ¥Ãû³Æ¡¢¹ØÁªÖÇÄÜÉ豸ÐÅÏ¢ºÍ¼Æ»®ÈÎÎñµÈ ¡£ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÀ´ÓÀ¾ÃËø¶¨Óû§µÄÕË»§ ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/unprotected-database-of-smart-home-vendor-exposes-billions-of-records-23f3a56b

4¡¢Ñо¿ÈËÔ±·¢ÏÖÊ׸öÀÄÓÃDNS over HTTPSЭÒéµÄ¶ñÒâÈí¼þGodlua


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ñо¿ÈËÔ±·¢ÏÖÊ׸öÀÄÓÃDNS over HTTPS£¨DoH£©Ð­ÒéµÄ¶ñÒâÈí¼þGodlua£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öÓÃLua±àдµÄ¶ñÒâÈí¼þ£¬Æä×÷ÓÃÀàËÆÓÚºóÃÅ ¡£¹¥»÷ÕßÀûÓ鶴£¨CVE-2019-3396£©À´Ñ¬È¾Linux·þÎñÆ÷ ¡£Ñо¿ÈËÔ±·¢ÏÖµÄÁ½¸öGodluaÑù±¾¶¼Ê¹ÓÃDNS over HTTPSÇëÇóÀ´»ñÈ¡ÓòÃûTXT£¬ÆäÖд洢ÁËC£¦C·þÎñÆ÷µÄURL ¡£ÕâÖÖ´ÓDNSÎı¾¼Ç¼ÖмìË÷µÚ¶þ/µÚÈý½×¶ÎC£¦C·þÎñÆ÷URLµØÖ·µÄ¼¼Êõ²¢²»ÐÂÏÊ£¬µ«Ê¹ÓÃDoHÇëÇó¶ø²»ÊÇ´«Í³µÄDNSÇëÇóΪÊ״ηºÆð ¡£DoH£¨DNS£©ÇëÇó¶ÔµÚÈý·½ÊÓ²ìÕß¼ÓÃÜÇÒ²»Ðмû£¬Õâ°üÂÞÒÀÀµ±»¶¯DNS¼à¿ØÀ´×èÖ¹¶ÔÒÑÖª¶ñÒâÓòÇëÇóµÄÍøÂçÄþ¾²Èí¼þ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/first-ever-malware-strain-spotted-abusing-new-doh-dns-over-https-protocol/

5¡¢Áè¼Ý30¸öVMware²úÎïÊܵ½Linux SACK©¶´Ó°Ïì

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VMwareÈ·ÈÏSACK PanicºÍSACK Slowness©¶´Ó°ÏìÆä¶à¸ö²úÎï ¡£¸Ã¹«Ë¾Òѽ«SACK PanicÆÀ¼¶ÎªÖØÒª²¢¸³Óè7.5µÄCVSSÆÀ·Ö£¬SACK SlownessΪÖеȺÍCVSSÆÀ·Ö5.3 ¡£Æ¾¾ÝVMwareÐû²¼µÄÄþ¾²Í¨¸æ£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܻᵼÖÂÄ¿±êϵͳ±ÀÀ£»òÑÏÖؽµµÍÐÔÄÜ ¡£ÊÜÓ°ÏìµÄ²úÎï°üÂÞvCenter Server Appliance¡¢vCloud¡¢vRealizeºÍvSphereµÈ ¡£VMwareÕýÔÚΪÿ¸öÊÜÓ°ÏìµÄ²úÎ↑·¢²¹¶¡£¬µ«µ½Ä¿Ç°ÎªÖ¹Ëü½öÐû²¼ÁËSD-WANÈí¼þ¡¢Unified Access GatewayºÍvCenter Server ApplianceµÄ¸üР¡£

Ô­ÎÄÁ´½Ó£º
https://www.securityweek.com/many-vmware-products-affected-sack-linux-vulnerabilities