ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ50ÖÜ
Ðû²¼Ê±¼ä 2020-12-14> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ30ÈÕÖÁ12ÔÂ06ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇZeroshell cgi-bin kerbynet StartSessionSubmit×¢È멶´£»Western Digital My Cloud OS devicesÉí·ÝÑéÖ¤Èƹý©¶´£»SourceCodester Car Rental Management System SQL×¢È멶´£»Crux Linux Docker images root¿ÕÃÜÂ멶´£»HPE Edgeline Infrastructure ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇоƬ³§ÉÌAdvantechѬȾConti£¬±»ÀÕË÷1300ÍòÃÀÔª£»Carding Action 2020Ðж¯ÆÆ»ñÒ»Æð´ó¹æÄ£Õ©Æ°¸¼þ£»Cisco TalosÅû¶WebKitÖжà¸öÑÏÖصÄ©¶´£»Ñо¿ÍŶӷ¢ÏÖ½©Ê¬ÍøÂçXantheÀûÓÃDockerAPIѬȾLinux£»GitHubÐû²¼2020Äê¶ÈOctoverse̬ÊƵķÖÎö³ÂËß¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Microsoft Exchange Server CVE-2020-17142Ô¶³Ì´úÂëÖ´ÐЩ¶´
Microsoft Exchange Server´æÔÚδÃ÷Äþ¾²Â©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://msrc.microsoft.com/update-guide/zh-CN/vulnerability/CVE-2020-17142
2.uIP-Contiki-OS DNS¼Ç¼½âÎö»º³åÇøÒç³ö©¶´
uIP-Contiki-OS DNS¼Ç¼½âÎö´æÔÚÔ½½ç¶Á©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓÃÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01
3.Siemens LOGO! 8 BMδÊÚȨ·ÃÎÊ©¶´
Siemens LOGO! 8 BMijЩ·þÎñȱÉÙÊÚȨ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ¿ØÖÆÉ豸¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-10
4.Schneider Electric Easergy T300ÊÚȨȱʧ©¶´
Schneider Electric Easergy T300´æÔÚÊÚȨȱʧ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸¡£
https://www.se.com/ww/en/download/document/SEVD-2020-315-06/
5.Aruba Networks ArubaOS PAPIÃüÁî×¢È멶´
Aruba Networks ArubaOS PAPI´æÔÚÈÎÒâÃüÁî×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî¡£
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢ºÚ¿ÍÇÔÈ¡Òâ´óÀûLeonardo SpAµÄ10GB¾üÊ»úÃÜ
ºÚ¿ÍÇÔÈ¡¹ú·À¹«Ë¾Leonardo SpAµÄ10 GB¾üÊ»úÃÜ£¬ÏÖÒѱ»Òâ´óÀû¾¯·½´þ²¶¡£LeonardoÊÇÊÀ½çÉÏ×î´óµÄ¹ú·À³Ð°üÉÌÖ®Ò»£¬Æä30£¥µÄ¹É·ÝÊôÓÚÒâ´óÀû¾¼ÃºÍ²ÆÕþ²¿¡£´Ë´Î鶵ÄÐÅÏ¢Éæ¼°µ½ÐÐÕþ»á¼Æ¹ÜÀí¡¢ÈËÁ¦×ÊÔ´¡¢×ʱ¾»õÎïµÄ²É¹ººÍ·ÖÅä¡¢ÃñÓ÷ɻúÁ㲿¼þºÍ¾üÓ÷ɻúµÄÉè¼Æ¡¢Ô±¹¤¸öÈËÐÅÏ¢¡£¾ÝϤ£¬ºÚ¿ÍʹÓÃUSBÃÜÔ¿Ïò94¸öÊÂÇéÕ¾·Ö·¢cftmon.exeľÂí£¬²¢ÒÔÕý°æWindowsÎļþÃüÃû¸ÃľÂíÒÔÈƹý¼ì²â¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/police-arrest-two-in-data-theft-cyberattack-on-leonardo-defense-corp/
2¡¢¹þÈø¿Ë˹̹µÚÈý´ÎÇ¿ÖÆÔÚÆ乫ÃñÉ豸ÉÏ°²×°¸ùÖ¤Êé
¹þÈø¿Ë˹̹Õþ¸®ÒÔÍøÂçÄþ¾²ÑÝϰΪ»Ï×Ó£¬Ç¿ÆÈÊ׶¼Å¬¶ûËÕµ¤µÄ¹«ÃñÔÚÆäÉ豸ÉÏ°²×°Êý×ÖÖ¤Êé¡£Èç¹û²»°²×°Õþ¸®µÄ¸ùÖ¤Ê飬¹«Ãñ½«ÎÞ·¨·ÃÎÊGoogle¡¢Twitter¡¢YouTube¡¢Facebook¡¢InstagramºÍNetflixµÈÍøÕ¾¡£Ò»µ©°²×°£¬¸ÃÖ¤Ê齫ÔÊÐíÕþ¸®Í¨¹ýÒ»ÖÖ³ÆΪMitM£¨ÖмäÈË£©µÄ¼¼ÊõÀ´À¹½ØÓû§É豸·¢³öµÄËùÓÐHTTPSÁ÷Á¿¡£ÕâÊǹþÈø¿Ë˹̹Õþ¸®×Ô2015ÄêÒÔÀ´µÚÈý´ÎÇ¿ÖÆÔÚÆ乫ÃñÉ豸ÉÏ°²×°¸ùÖ¤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/kazakhstan-government-is-intercepting-https-traffic-in-its-capital/
3¡¢FireEyeÈ·ÈÏÔâµ½APT¹¥»÷£¬ÒÑÐû²¼ÉùÃ÷²¢¿ªÔ´Ïà¹Ø¹¤¾ß
FireEye³ÆÆäÔâµ½ÁËÓɹú¼ÒÔÞÖúµÄ¸ß¶ÈÅÓ´óµÄºÚ¿ÍµÄ¹¥»÷£¬¹¥»÷Õßδ¾ÊÚȨ·ÃÎÊÆäRed Team¹¤¾ß¡£FireEyeÌåÏÖÕâÊÇÒ»´ÎÓµÓÐÒ»Á÷½ø¹¥ÄÜÁ¦µÄ¹ú¼ÒµÄ¹¥»÷£¬ÓëÒÔÍùʼþ²îÒ죬´Ë´Î¹¥»÷רÃÅÕë¶ÔºÍ¹¥»÷FireEye¡£¾ÊӲ죬¹¥»÷Õß·ÃÎÊÁËÓÃÓÚ²âÊÔ¿Í»§Äþ¾²ÐÔµÄRed TeamÆÀ¹À¹¤¾ß£¬µ«ÆäÖв¢Ã»ÓаüÂÞ0day©¶´¡£Ä¿Ç°CISAÉÐδÊÕµ½ÓйØÕâЩ¹¤¾ß±»¶ñÒâʹÓõijÂËߣ¬FireEye¿ª·¢ÁË300¶àÖֶԲߣ¬ÒÔ¼õÉÙ´ËʼþµÄDZÔÚÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/products-and-services/2020/12/fireeye-shares-details-of-recent-cyber-attack-actions-to-protect-community.html
4¡¢Ñо¿ÍŶÓÅû¶Ëĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö©¶´Amnesia:33
ForescoutµÄÑо¿ÍŶÓÅû¶ÁËËĸö¿ªÔ´TCP/IP¿âÖеÄ33¸ö©¶´£¬²¢½«ËüÃÇÃüÃûΪAmnesia:33¡£ÕâËĸö¿ªÔ´¿â·Ö±ðΪuIP¡¢FNET¡¢picoTCPºÍNut/Net£¬Ó°ÏìÁË150¶à¼Ò¹©Ó¦É̵IJúÎï¡£ForescoutÌåÏÖ£¬ºÚ¿Í¿ÉÀûÓÃÕâ33¸ö©¶´ÌᳫԶ³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷ÒÔ¿ØÖÆÄ¿±êÉ豸£¬¾Ü¾ø·þÎñ£¨DoS£©¹¥»÷ÒÔÓ°Ï칫˾ҵÎñÔËÓª£¬ÐÅϢй©£¨infoleak£©¹¥»÷ÒÔ»ñȡDZÔÚµÄÃô¸ÐÐÅÏ¢£¬DNS»º´æÖж¾¹¥»÷ÒÔ½«É豸ָÏò¶ñÒâÍøÕ¾¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/amnesia33-vulnerabilities-impact-millions-of-smart-and-industrial-devices/
5¡¢ºÚ¿ÍÔÚ°µÍø³öÊÛÁè¼Ý8Íò¸öSQLÊý¾Ý¿â£¬Ã¿¸ö550ÃÀÔª
ºÚ¿ÍÔÚ°µÍøÒÔÿ¸ö550ÃÀÔªµÄ¼Û¸ñ³öÊÛÁè¼Ý85000¸öSQLÊý¾Ý¿â¡£ºÚ¿Í×éÖ¯ÔÚ²»Í£µØÈëÇÖMySQLÊý¾Ý¿â£¬ÏÂÔرí¸ñ£¬É¾³ýÔʼÎĵµ£¬²¢ÁôÏÂÊê½ð¼Ç¼£¬Í¨ÖªÊܺ¦ÕßÓëÆäÁªÏµÒÔÈ¡»ØÆäÊý¾Ý¡£Èç¹ûÊܺ¦ÕßÔÚ¾ÅÌìÄÚûÓи¶¿î£¬ËûÃǵÄÊý¾Ý½«ÔÚÊý¾Ýй¶ÍøÕ¾±»ÅÄÂô¡£Ëæ×ÅÊܺ¦ÕßÊýÁ¿µÄÔö¶à£¬¹¥»÷Õß¿ªÊ¼Ê¹ÓÃ×Ô¶¯»¯µÄÈëÇÖÁ÷³ÌºÍÅÄÂôÍøÒ³£¬²¢²»»á·ÖÎö±»ÈëÇÖµÄÊý¾Ý¿âÖеÄÊý¾Ý¡£´ËÍ⣬ÕâЩÊý¾Ý¿âµÄÊÛ¼Û»áËæ×ÅBTC/ USD»ãÂʵĵßô¤ÓÐËù±ä»¯£¬µ«Í¨³£Ê¼ÖÕ±£³ÖÔÚ500ÃÀÔª×óÓÒ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/hackers-are-selling-more-than-85000-sql-databases-on-a-dark-web-portal/