ÐÅÏ¢Äþ¾²Öܱ¨-2019ÄêµÚ34ÖÜ

Ðû²¼Ê±¼ä 2019-09-02

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö



2019Äê8ÔÂ26ÈÕÖÁ9ÔÂ01ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco REST API ContainerÑéÖ¤Èƹý©¶´£»BloodHound components/Modals/HelpModal.jsxÈÎÒâÃüÁîÖ´ÐЩ¶´£»Datalogic AV7000 Linear Barcode ScannerÉí·ÝÑéÖ¤Èƹý©¶´£»Delta Controls enteliBUS Controllers»º³åÇøÒç³ö©¶´£»Linux kernel net/wireless/marvell/mwifiex»º³åÇøÒç³ö©¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÍйܷþÎñÉÌHostinger½ü1400ÍòÓû§ÐÅÏ¢±»ÍϿ⣻2019ÄêÉÏ°ëÄê³ÂËߵĩ¶´ÖÐÁè¼Ý34%δÐÞ¸´£»Android¶ñÒâÓ¦ÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ£»2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª£»ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£



>ÖØÒªÄþ¾²Â©¶´Áбí



1. Cisco REST API ContainerÑéÖ¤Èƹý©¶´


Cisco REST API Container REST APIÑé֤ʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Óû§µÄÁîÅÆID£¬ÈƹýÄþ¾²ÏÞÖÆ£¬Î´ÊÚȨ·ÃÎÊ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190828-iosxe-rest-auth-bypass

2. BloodHound components/Modals/HelpModal.jsxÈÎÒâÃüÁîÖ´ÐЩ¶´


BloodHound components/Modals/HelpModal.jsx´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴ͨ¹ý´´½¨´øJS´úÂëÃû³ÆµÄGPO£¬´¥·¢search-autocomplete¹¦Ð§£¬¿ÉÖ´ÐÐÈÎÒâOSÃüÁî¡£
https://github.com/BloodHoundAD/BloodHound

3. Datalogic AV7000 Linear Barcode ScannerÉí·ÝÑéÖ¤Èƹý©¶´


Datalogic AV7000 Linear Barcode ScannerʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬ÈƹýÉí·ÝÑéÖ¤Ö´ÐÐÈÎÒâ´úÂë¡£
https://www.us-cert.gov/ics/advisories/icsa-19-239-02

4. Delta Controls enteliBUS Controllers»º³åÇøÒç³ö©¶´


Delta Controls enteliBUS ControllersʵÏÖ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬴¥·¢»º³åÇøÒç³öÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9569

5. Linux kernel net/wireless/marvell/mwifiex»º³åÇøÒç³ö©¶´


Linux kernel net/wireless/marvell/mwifiex´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éʹ·þÎñ·¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://vigilance.fr/vulnerability/Linux-kernel-buffer-overflow-via-net-wireless-marvell-mwifiex-30180



>ÖØÒªÄþ¾²Ê¼þ×ÛÊö



1¡¢ÍйܷþÎñÉÌHostinger½ü1400ÍòÓû§ÐÅÏ¢±»ÍÏ¿â

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÍйܷþÎñÉÌHostingerÐû²¼Í¨¸æ³Æ½ü1400ÍòÓû§ÐÅÏ¢±»ÍÏ¿â¡£¸ÃʼþÓÚ8ÔÂ23ÈÕÐÇÆÚÎå±»·¢ÏÖ£¬¸Ã¹«Ë¾ÌåÏÖ¹¥»÷Õß»ñÈ¡ÁËÄÚ²¿·þÎñÆ÷µÄ·ÃÎÊȨÏÞ£¬È»ºóÕÒµ½ÁËÄÚ²¿APIµÄÊÚȨÁîÅÆ£¬µ÷ÓÃAPIÇÔÈ¡ÁËÓû§ÐÅÏ¢¡£Ð¹Â¶µÄÓû§ÐÅÏ¢°üÂÞÓû§Ãû¡¢IPµØÖ·¡¢ÐÕÃû¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·ºÍ¼ÒÍ¥µØÖ·µÈ£¬»¹°üÂÞSHA1Ëã·¨¼ÓÃܵĹþÏ£ÃÜÂë¡£¸Ã¹«Ë¾ÌåÏÖûÓвÆÕþÐÅÏ¢Êܵ½Ë𺦣¬µ«Î´Í¸Â¶ÊÜÓ°ÏìµÄ¾ßÌåÈËÊý¡£¸Ã¹«Ë¾»¹ÌåÏÖ¾ö¶¨Ç¿ÖÆÖØÖÃËùÓÐÊÜÓ°ÏìÕÊ»§µÄÃÜÂë¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/hostinger-resets-customer-passwords-after-security-incident/

2¡¢2019ÄêÉÏ°ëÄê³ÂËߵĩ¶´ÖÐÁè¼Ý34%δÐÞ¸´

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRisk Based SecurityÐû²¼µÄ¡¶2019ÄêÄêÖЩ¶´»Ø¹Ë³ÂËß¡·£¬2019ÄêÉÏ°ëÄê³ÂËßµÄËùÓЩ¶´ÖÐÁè¼Ý34£¥£¨3771¸ö£©µÄ©¶´Î´ÐÞ¸´¡£´ËÍ⣬ÔÚ³ÂËßµÄ×ܹ²11092¸ö©¶´ÖУ¬14.7%£¨1630¸ö£©µÄ©¶´CVSS V2µÃ·ÖÁè¼Ý9.0£¬54.5£¥£¨6045¸ö£©µÄ©¶´ÓëWebÓйØ£¬Ô¼53%£¨5878¸ö£©µÄ©¶´¿ÉÒÔÔ¶³ÌÀûÓã¬66%µÄ©¶´ÓëSQL×¢Èë¹¥»÷ÓйØ£¬Ô¼2.8%µÄ©¶´ÓëSCADAÓйØ¡£

Ô­ÎÄÁ´½Ó£º
https://pages.riskbasedsecurity.com/2019-midyear-vulnerability-quickview-report

3¡¢Android¶ñÒâÓ¦ÓÃCamScannerÏÂÔØÁ¿³¬1ÒÚ


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÑо¿ÈËÔ±·¢ÏÖCamScannerµÄÃâ·Ñ°æ´æÔÚÒ»¸öÒþ²ØµÄTrojan DropperÄ£¿é£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂÏÂÔغͰ²×°¶ñÒⷨʽ¡£CamScannerÊÇÒ»¿îÊÜ»¶Ó­µÄÊÖ»úPDF´´½¨APP£¬ËüÔÚGoogle PlayÉ̵êµÄÏÂÔØÁ¿Áè¼Ý1ÒÚ¡£¶ñÒâÄ£¿éʵ¼ÊÉϲ¢²»´æÔÚÓÚCamScanner×Ô¼ºµÄ´úÂëÖУ¬¶øÊÇÔÚµÚÈý·½¹ã¸æ¿âÖУ¬Òò´Ë¿ÉÒÔÍƶÏÕâÊÇÈí¼þ¿ª·¢ÕߺͲ»µÀµÂµÄ¹ã¸æÉ̺Ï×÷µÄ½á¹û¡£¸ÃÄ£¿é¿ÉÒÔͨ¹ý¶àÖÖ·½Ê½ÀûÓÃÊÜѬȾµÄÉ豸£¬´ÓÏÔʾÇÖÈëÐÔ¹ã¸æµ½¸¶·Ñ¶©ÔÄÇÔÈ¡»°·ÑµÈ¡£Ó¦¸Ã×¢ÒâµÄÊÇ£¬CamScannerµÄ¸¶·Ñ°æ±¾²»°üÂÞµÚÈý·½¹ã¸æ¿â¡£GoogleÒѾ­´Ó¹Ù·½PlayÉ̵êÖÐɾ³ýÁ˸ÃAPP¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/08/android-camscanner-malware.html

4¡¢2024ÄêÈ«ÇòÊý¾Ýй¶³É±¾Ô¤¼Æ½«´ï5ÍòÒÚÃÀÔª

¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÕ°²©ÍøÂçµÄ×îÐÂÔ¤²â£¬Ëæ׿à¹Ü·£¿îµÄʵʩÒÔ¼°ÆóÒµÔ½·¢ÒÀÀµÓÚÊý×Öϵͳ£¬µ½2024ÄêÈ«ÇòÊý¾Ýй¶µÄ³É±¾Ô¤¼Æ½«Ôö¼Óµ½5ÍòÒÚÃÀÔªÒÔÉÏ¡£ÕâÒ»Êý¾ÝÀ´×ÔÓڸù«Ë¾Ðû²¼µÄ×îгÂËß¡¶ÍøÂç·¸×ïºÍÄþ¾²µÄδÀ´£º2019-2024Íþв·ÖÎö¡¢Ó°ÏìÆÀ¹ÀºÍ»º½â¼Æı³ÂËß¡·¡£¸Ã¹«Ë¾Éù³Æ£¬ÔÚ³ÂËßÆÚ¼äÄÚÔ¤¼ÆÊý¾Ýй¶³É±¾½«´Ó2019ÄêµÄ3ÍòÒÚÃÀԪÿÄêÔö³¤11%¡£³ÂËßÖл¹³ÆËäÈ»´ó¹æÄ£µÄÊý¾Ýй¶¿ÉÄܳÉΪͷÌõÐÂÎÅ£¬µ«ËüÃDz¢·×Æ綨»áÖ±½ÓÓ°Ïì³É±¾£¬ÒòΪ·£¿îºÍÒµÎñËðʧÓëÊý¾Ýй¶µÄ¹æÄ£²¢²»½ôÃÜÏà¹Ø¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/breach-costs-trillion/

5¡¢ÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷


¶«É­¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


8ÔÂ26ÈÕÃÀ¹úÊý°Ù¼ÒÑÀ¿ÆÕïËùÔâÀÕË÷Èí¼þSodinokibi¹¥»÷£¬»¼ÕßÐÅÏ¢±»¼ÓÃÜ¡£ÕâÊǹ¥»÷Õßͨ¹ýÈëÇÖÈí¼þ¹©Ó¦É̲¢ÀûÓÃÆä²úÎïÔÚ¿Í»§ÏµÍ³ÉÏÖ²ÈëÀÕË÷Èí¼þµÄÁíÒ»¸ö°¸Àý¡£ÔÚ±¾ÆðʼþÖУ¬Èí¼þ¹©Ó¦ÉÌÊÇThe Digital Dental RecordºÍPerCSoft£¬ËûÃǺÏ×÷¿ª·¢ÁËÒ½ÁƼǼÉú´æºÍ±¸·ÝÈí¼þDDS Safe¡£ÉÏÖÜÄ©ºÚ¿ÍÍÅ»ïÈëÇÖÁ˸ÃÈí¼þ±³ºóµÄ»ù´¡ÉèÊ©£¬²¢ÀûÓÃËüÔÚÊý°Ù¸öÑÀÒ½ÕïËùµÄ¼ÆËã»úÉϲ¿ÊðÁËÀÕË÷Èí¼þSodinokibi¡£ÕâÁ½¼Ò¹«Ë¾Ñ¡ÔñÖ§¸¶Êê½ð»ñÈ¡½âÃÜÆ÷£¬µ«Ä¿Ç°»Ö¸´½ø¶È»ºÂý£¬Ò»Ð©ÑÀ¿ÆÕïËùÉù³Æ½âÃÜÆ÷Ҫô²»Æð×÷Óã¬ÒªÃ´Ã»Óлָ´ËùÓÐÊý¾Ý¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/ransomware-hits-hundreds-of-dentist-offices-in-the-us/