ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ29ÖÜ
Ðû²¼Ê±¼ä 2019-07-29> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ22ÈÕÖÁ28ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇProFTPD SITE CPFR/CPTOÈÎÒâ¶Á䩶´£»Apple Webkit ¶à¸öÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´£»Zeroshell http²ÎÊýÃüÁî×¢È멶´£»Apache Storm·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»McAfee Data Loss Prevention Endpoint ePOÀ©Õ¹ÃüÁî×¢È멶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǶíÂÞ˹Áª°îÄþ¾²¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬»úÃÜÏîÄ¿Æع⣻ProFTPD RCE©¶´£¬Áè¼Ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ï죻ӡ¶ÈС¶îÐÅ´ûÒøÐÐJana CashÒâÍâй¶260ÍòÓû§½»Ò×ÐÅÏ¢£»RiskIQÐû²¼2019»¥ÁªÍø·¸×ï³ÂËߣ¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª£»Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯¡£
> ÖØÒªÄþ¾²Â©¶´Áбí
1. ProFTPD SITE CPFR/CPTOÈÎÒâ¶Á䩶´
ProFTPD SITE CPFR/CPTOûÓÐÕýÈ·´¦ÖÃ
2. Apple Webkit CVE-2019-8644ÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´
Apple iOS°üÂÞµÄWebKit´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://support.apple.com/zh-cn/HT2103563. Zeroshell http²ÎÊýÃüÁî×¢È멶´
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt
4. Apache Storm·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E
5. McAfee Data Loss Prevention Endpoint ePOÀ©Õ¹ÃüÁî×¢È멶´
https://kc.mcafee.com/corporate/index?page=content&id=SB10289
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/
2¡¢ProFTPD RCE©¶´£¬Áè¼Ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/
3¡¢Ó¡¶ÈС¶îÐÅ´ûÒøÐÐJana CashÒâÍâй¶260ÍòÓû§½»Ò×ÐÅÏ¢
ÔÎÄÁ´½Ó£ºhttps://securitydiscovery.com/jana-bank-data-leak/
4¡¢RiskIQÐû²¼2019»¥ÁªÍø·¸×ï³ÂËߣ¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/external-threat-management/2019-evil-internet-minute/
5¡¢Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/siemens-contractor-pleads-guilty-to-planting-logic-bomb-in-company-spreadsheets/