ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ49ÖÜ

Ðû²¼Ê±¼ä 2020-12-08

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ30ÈÕÖÁ12ÔÂ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇZeroshell cgi-bin kerbynet StartSessionSubmit×¢È멶´£»Western Digital My Cloud OS devicesÉí·ÝÑéÖ¤Èƹý©¶´£»SourceCodester Car Rental Management System SQL×¢È멶´£»Crux Linux Docker images root¿ÕÃÜÂ멶´£»HPE Edgeline Infrastructure ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇоƬ³§ÉÌAdvantechѬȾConti £¬±»ÀÕË÷1300ÍòÃÀÔª£»Carding Action 2020Ðж¯ÆÆ»ñÒ»Æð´ó¹æÄ£Õ©Æ­°¸¼þ£»Cisco TalosÅû¶WebKitÖжà¸öÑÏÖصÄ©¶´£»Ñо¿ÍŶӷ¢ÏÖ½©Ê¬ÍøÂçXantheÀûÓÃDockerAPIѬȾLinux£»GitHubÐû²¼2020Äê¶ÈOctoverse̬ÊƵķÖÎö³ÂËß ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Zeroshell cgi-bin kerbynet StartSessionSubmit×¢È멶´


Zeroshell cgi-bin kerbynet StartSessionSubmit´æÔÚÊäÈëÑé֤©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿É×¢ÈëÈÎÒâÃüÁî²¢Ö´ÐÐ ¡£

https://blog.quake.so/post/zeroshell_linux_router_rce/


2.Western Digital My Cloud OS devicesÉí·ÝÑéÖ¤Èƹý©¶´


Western Digital My Cloud OS devices¹ÜÀíƽ̨´æÔÚÑéÖ¤Èƹý©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£

https://www.westerndigital.com/support/productsecurity/wdc-20009-os5-firmware-5-06-115


3.SourceCodester Car Rental Management System SQL×¢È멶´


Sourcecodester SourceCodester Car Rental Management System´æÔÚSQL×¢È멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://github.com/BigTiger2020/Car-Rental-Management-System/blob/main/README.md


4.Crux Linux Docker images root¿ÕÃÜÂ멶´


Crux Linux Docker images´æÔÚROOT¿ÕÃÜÂ멶´ £¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÌáÉýȨÏÞ ¡£

https://github.com/koharin/koharin2/blob/main/CVE-2020-29389


5.HPE Edgeline Infrastructure ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´


HPE Edgeline Infrastructure Manager´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë ¡£

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn04063en_us


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ð¾Æ¬³§ÉÌAdvantechѬȾConti £¬±»ÀÕË÷1300ÍòÃÀÔª


1.jpg


¹¤Òµ×Ô¶¯»¯ºÍ¹¤ÒµÎïÁªÍø£¨IIoT£©Ð¾Æ¬ÖÆÔìÉÌAdvantechѬȾÀÕË÷Èí¼þConti £¬±»ÀÕË÷750 BTC£¨Ô¼Îª12600000ÃÀÔª£© ¡£AdvantechÊÇIT²úÎïºÍ½â¾ö·½°¸µÄÈ«ÇòÁìÏÈÖÆÔìÉÌ £¬²úÎï°üÂÞǶÈëʽPC¡¢ÍøÂçÉ豸¡¢IoT¡¢·þÎñÆ÷ºÍÒ½ÁƱ£½¡½â¾ö·½°¸ ¡£11ÔÂ26ÈÕ £¬ºÚ¿ÍÔÚÆäй¶ÍøÕ¾ÉÏÐû²¼ÁË3.03GB±»µÁÊý¾ÝÖеÄ2£¥ £¬ÒÔ¼°Ò»¸ö°üÂÞÁ˱»µÁÎļþÁбíµÄÎı¾Îĵµ ¡£Ä¿Ç° £¬Advantech¹«Ë¾ÉÐδ¶Ô´ËÊ·¢±íÆÀÂÛ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/iiot-chip-maker-advantech-hit-by-ransomware-125-million-ransom/


2¡¢Carding Action 2020Ðж¯ÆÆ»ñÒ»Æð´ó¹æÄ£Õ©Æ­°¸¼þ


2.jpg


ÍøÂçÄþ¾²¹«Ë¾Group-IBÓëÅ·ÖÞµÄÐÙÑÀÀû¡¢Ó¢¹úºÍÒâ´óÀûÕþ¸®ºÏ×÷ £¬ÌᳫCarding Action 2020Ðж¯ £¬ÆÆ»ñÒ»Æð´ó¹æÄ£ÐÅÓÿ¨½»Ò×Õ©Æ­°¸¼þ ¡£¸Ã»î¶¯Õë¶Ô¶à¸ö°µÍøÊг¡ £¬ÔÚÐÅÓÿ¨½»Ò×É̵êºÍ°µÍø½»Ò×ƽ̨ÉϲéÕÒÓëÂòÂô±»µÁ¿¨ÏêϸÐÅÏ¢ÓйصÄÆÛÕ©Õß £¬Ö¼ÔÚ¼õÇáºÍ·ÀÖ¹½ðÈÚ»ú¹¹ºÍ³Ö¿¨ÈËÔâÊÜËðʧ £¬Ä¿Ç°Ô¼×èÖ¹ÁË4000ÍòÅ·ÔªµÄËðʧ ¡£¹ú¼ÊÐ̾¯×éÖ¯Ðû²¼´þ²¶ÁËÈýÃûÀ´×ÔÄáÈÕÀûÑǵÄÏÓÒÉÈË £¬¾ÝÐÅËûÃÇÊÇÒ»¸ö¹¥»÷ÁË150¸öÕþ¸®×éÖ¯ºÍ¹«Ë¾µÄÍÅ»ïµÄ³ÉÔ± ¡£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/authorities-disrupt-dark-web-credit-card-trading-scam/


3¡¢Cisco TalosÅû¶WebKitÖжà¸öÑÏÖصÄ©¶´


3.jpg


Cisco TalosÅû¶WebKitä¯ÀÀÆ÷ÒýÇæ´æÔÚ¶à¸öÑÏÖصÄ©¶´ ¡£ÕâЩ©¶´ÓëWebKitµÄWebSocket¡¢AudioSourceProviderGStreamerºÍImageDecoderGStreamer¹¦Ð§ÓйØ ¡£·Ö±ðΪWebSocket´úÂëÖ´ÐЩ¶´£¨CVE-2020-13543£© £¬¿Éͨ¹ý´¥·¢ÊͷźóʹÓ鶴À´Ô¶³ÌÖ´ÐдúÂ룻ImageDecoderGStreamerÊͷźóʹÓ鶴£¨CVE-2020-13584£© £¬¿Éµ¼ÖÂÔ¶³ÌÖ´ÐдúÂë £¬ÒÔ¼°±»×·×ÙΪCVE-2020-13543µÄ©¶´ ¡£    


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/webkit-vulnerabilities-allow-remote-code-execution-malicious-websites


4¡¢Ñо¿ÍŶӷ¢ÏÖ½©Ê¬ÍøÂçXantheÀûÓÃDockerAPIѬȾLinux


4.jpg


Ñо¿ÍŶӷ¢ÏÖÁËÒ»¸öÃûΪXantheµÄÃÅÂÞ±Ò¼ÓÃܽ©Ê¬ÍøÂç £¬¿ÉÀûÓÃÅäÖôíÎóµÄDocker APIÀ´Ñ¬È¾Linuxϵͳ ¡£¸Ã¶ñÒâÈí¼þ¿ÉÀûÓöàÖÖÒªÁì½øÐÐÁ÷´« £¬ÈçÊÕ¼¯¿Í»§¶ËÖ¤ÊéÒÔͨ¹ýSSHÁ÷´«µ½Ä¿±êÖ÷»ú ¡£´ËÍâ £¬Xanthe¾ßÓÐËĸöÓÃÀ´Èƹý¼ì²â²¢Ôö¼Ó³Ö¾ÃÐԵĸ½¼ÓÄ£¿é £¬·Ö±ðΪ½ø³ÌÒþ²ØÄ£¿é£¨libprocesshider.so£©£»½ûÓÃÆäËû¿ó¹¤ºÍÄþ¾²·þÎñµÄshell½Å±¾£¨xesa.txt£©£»ÓÃÓÚɾ³ýDockerÈÝÆ÷ÖеľºÕùÐÔDockerÄ¿±ê¼ÓÃÜľÂíµÄshell½Å±¾(fczyo)ºÍXMRig¶þ½øÖÆÎļþ£¨ÒÔ¼°JSONÅäÖÃÎļþconfig.json£© ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/misconfigured-docker-servers-xanthe-malware/161732/


5¡¢GitHubÐû²¼2020Äê¶ÈOctoverse̬ÊƵķÖÎö³ÂËß


5.jpg


GitHubÐû²¼ÁË2020Äê¶ÈOctoverse̬ÊƵķÖÎö³ÂËß ¡£¸Ã³ÂËßÖ÷Ҫͳ¼ÆÁËÁè¼Ý5600ÍòÃû¿ª·¢ÈËÔ±ÔÚ2020Äê´´½¨µÄÁè¼Ý6000Íò¸öд洢¿â ¡£Ñо¿·¢ÏÖ £¬Óë2019ÄêÏà±È £¬ÏÖÔÚ94£¥µÄÏîÄ¿ÒÀÀµ¿ªÔ´×é¼þ £¬Æ½¾ùÓнӽü700¸öÒÀÀµÏî £¬JavaScriptÖÐÓÐ94£¥µÄ¿ªÔ´ÒÀÀµ¹Øϵ £¬¶øRubyºÍ.NETÖÐÓÐ90£¥µÄ¿ªÔ´ÒÀÀµ¹Øϵ ¡£´ËÍâ £¬¿ªÔ´Èí¼þÖеĴó¶àÊý©¶´²¢²»ÊǶñÒâµÄ £¬Ïà·´ £¬GitHub·¢³öµÄCVE¾¯±¨ÖÐÓÐ83£¥µÄ©¶´ÊÇÓÉÈËΪ´íÎóÒýÆðµÄ ¡£


Ô­ÎÄÁ´½Ó£º

https://octoverse.github.com/