ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ50ÖÜ

Ðû²¼Ê±¼ä 2020-12-14

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ30ÈÕÖÁ12ÔÂ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇZeroshell cgi-bin kerbynet StartSessionSubmit×¢È멶´£»Western Digital My Cloud OS devicesÉí·ÝÑéÖ¤Èƹý©¶´£»SourceCodester Car Rental Management System SQL×¢È멶´£»Crux Linux Docker images root¿ÕÃÜÂ멶´£»HPE Edgeline Infrastructure ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇоƬ³§ÉÌAdvantechѬȾConti£¬±»ÀÕË÷1300ÍòÃÀÔª£»Carding Action 2020Ðж¯ÆÆ»ñÒ»Æð´ó¹æÄ£Õ©Æ­°¸¼þ£»Cisco TalosÅû¶WebKitÖжà¸öÑÏÖصÄ©¶´£»Ñо¿ÍŶӷ¢ÏÖ½©Ê¬ÍøÂçXantheÀûÓÃDockerAPIѬȾLinux£»GitHubÐû²¼2020Äê¶ÈOctoverse̬ÊƵķÖÎö³ÂËß ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Microsoft Exchange Server CVE-2020-17142Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft Exchange Server´æÔÚδÃ÷Äþ¾²Â©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://msrc.microsoft.com/update-guide/zh-CN/vulnerability/CVE-2020-17142


2.uIP-Contiki-OS DNS¼Ç¼½âÎö»º³åÇøÒç³ö©¶´


uIP-Contiki-OS DNS¼Ç¼½âÎö´æÔÚÔ½½ç¶Á©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓÃÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01


3.Siemens LOGO! 8 BMδÊÚȨ·ÃÎÊ©¶´


Siemens LOGO! 8 BMijЩ·þÎñȱÉÙÊÚȨ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ¿ØÖÆÉ豸 ¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-343-10



4.Schneider Electric Easergy T300ÊÚȨȱʧ©¶´


Schneider Electric Easergy T300´æÔÚÊÚȨȱʧ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸 ¡£

https://www.se.com/ww/en/download/document/SEVD-2020-315-06/


5.Aruba Networks ArubaOS PAPIÃüÁî×¢È멶´


Aruba Networks ArubaOS PAPI´æÔÚÈÎÒâÃüÁî×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ


1.jpg


ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊ»úÃÜ£¬ÏÖÒѱ»Òâ´óÀû¾¯·½´þ²¶ ¡£LeonardoÊÇÊÀ½çÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾­¼ÃºÍ²ÆÕþ²¿ ¡£´Ë´Î鶵ÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼Æ¹ÜÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ʱ¾»õÎïµÄ²É¹ººÍ·ÖÅä¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤¸öÈËÐÅÏ¢ ¡£¾ÝϤ£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈƹý¼ì²â ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/


2¡¢¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÖÆÔÚÆ乫ÃñÉ豸ÉÏ°²×°¸ùÖ¤Êé


2.jpg


¹þÈø¿Ë˹̹Õþ¸®ÒÔÍøÂçÄþ¾²ÑÝϰΪ»Ï×Ó£¬Ç¿ÆÈÊ׶¼Å¬¶ûËÕµ¤µÄ¹«ÃñÔÚÆäÉ豸ÉÏ°²×°Êý×ÖÖ¤Êé ¡£Èç¹û²»°²×°Õþ¸®µÄ¸ùÖ¤Ê飬¹«Ãñ½«ÎÞ·¨·ÃÎÊGoogle¡¢Twitter¡¢YouTube¡¢Facebook¡¢InstagramºÍNetflixµÈÍøÕ¾ ¡£Ò»µ©°²×°£¬¸ÃÖ¤Ê齫ÔÊÐíÕþ¸®Í¨¹ýÒ»ÖÖ³ÆΪMitM£¨ÖмäÈË£©µÄ¼¼ÊõÀ´À¹½ØÓû§É豸·¢³öµÄËùÓÐHTTPSÁ÷Á¿ ¡£ÕâÊǹþÈø¿Ë˹̹Õþ¸®×Ô2015ÄêÒÔÀ´µÚÈý´ÎÇ¿ÖÆÔÚÆ乫ÃñÉ豸ÉÏ°²×°¸ùÖ¤Êé ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/kazakhstan-government-is-intercepting-https-traffic-in-its-capital/


3¡¢FireEyeÈ·ÈÏÔâµ½APT¹¥»÷£¬ÒÑÐû²¼ÉùÃ÷²¢¿ªÔ´Ïà¹Ø¹¤¾ß


3.jpg


FireEye³ÆÆäÔâµ½ÁËÓɹú¼ÒÔÞÖúµÄ¸ß¶ÈÅÓ´óµÄºÚ¿ÍµÄ¹¥»÷£¬¹¥»÷Õßδ¾­ÊÚȨ·ÃÎÊÆäRed Team¹¤¾ß ¡£FireEyeÌåÏÖÕâÊÇÒ»´ÎÓµÓÐÒ»Á÷½ø¹¥ÄÜÁ¦µÄ¹ú¼ÒµÄ¹¥»÷£¬ÓëÒÔÍùʼþ²îÒ죬´Ë´Î¹¥»÷רÃÅÕë¶ÔºÍ¹¥»÷FireEye ¡£¾­ÊӲ죬¹¥»÷Õß·ÃÎÊÁËÓÃÓÚ²âÊÔ¿Í»§Äþ¾²ÐÔµÄRed TeamÆÀ¹À¹¤¾ß£¬µ«ÆäÖв¢Ã»ÓаüÂÞ0day©¶´ ¡£Ä¿Ç°CISAÉÐδÊÕµ½ÓйØÕâЩ¹¤¾ß±»¶ñÒâʹÓõijÂËߣ¬FireEye¿ª·¢ÁË300¶àÖֶԲߣ¬ÒÔ¼õÉÙ´ËʼþµÄDZÔÚÓ°Ïì ¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html


4¡¢Ñо¿ÍŶÓÅû¶Ëĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö©¶´Amnesia:33


4.jpg


ForescoutµÄÑо¿ÍŶÓÅû¶ÁËËĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö©¶´£¬²¢½«ËüÃÇÃüÃûΪAmnesia:33 ¡£ÕâËĸö¿ªÔ´¿â·Ö±ðΪuIP¡¢FNET¡¢picoTCPºÍNut/Net£¬Ó°ÏìÁË150¶à¼Ò¹©Ó¦É̵IJúÎï ¡£ForescoutÌåÏÖ£¬ºÚ¿Í¿ÉÀûÓÃÕâ33¸ö©¶´ÌᳫԶ³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷ÒÔ¿ØÖÆÄ¿±êÉ豸£¬¾Ü¾ø·þÎñ£¨DoS£©¹¥»÷ÒÔÓ°Ï칫˾ҵÎñÔËÓª£¬ÐÅϢй©£¨infoleak£©¹¥»÷ÒÔ»ñȡDZÔÚµÄÃô¸ÐÐÅÏ¢£¬DNS»º´æÖж¾¹¥»÷ÒÔ½«É豸ָÏò¶ñÒâÍøÕ¾ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/amnesia33-vulnerabilities-impact-millions-of-smart-and-industrial-devices/


5¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý8Íò¸öSQLÊý¾Ý¿â£¬Ã¿¸ö550ÃÀÔª


5.jpg


ºÚ¿ÍÔÚ°µÍøÒÔÿ¸ö550ÃÀÔªµÄ¼Û¸ñ³öÊÛÁè¼Ý85000¸öSQLÊý¾Ý¿â ¡£ºÚ¿Í×éÖ¯ÔÚ²»Í£µØÈëÇÖMySQLÊý¾Ý¿â£¬ÏÂÔرí¸ñ£¬É¾³ýԭʼÎĵµ£¬²¢ÁôÏÂÊê½ð¼Ç¼£¬Í¨ÖªÊܺ¦ÕßÓëÆäÁªÏµÒÔÈ¡»ØÆäÊý¾Ý ¡£Èç¹ûÊܺ¦ÕßÔÚ¾ÅÌìÄÚûÓи¶¿î£¬ËûÃǵÄÊý¾Ý½«ÔÚÊý¾Ýй¶ÍøÕ¾±»ÅÄÂô ¡£Ëæ×ÅÊܺ¦ÕßÊýÁ¿µÄÔö¶à£¬¹¥»÷Õß¿ªÊ¼Ê¹ÓÃ×Ô¶¯»¯µÄÈëÇÖÁ÷³ÌºÍÅÄÂôÍøÒ³£¬²¢²»»á·ÖÎö±»ÈëÇÖµÄÊý¾Ý¿âÖеÄÊý¾Ý ¡£´ËÍ⣬ÕâЩÊý¾Ý¿âµÄÊÛ¼Û»áËæ×ÅBTC/ USD»ãÂʵĵßô¤ÓÐËù±ä»¯£¬µ«Í¨³£Ê¼ÖÕ±£³ÖÔÚ500ÃÀÔª×óÓÒ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hackers-are-selling-more-than-85000-sql-databases-on-a-dark-web-portal/