ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ5ÖÜ

Ðû²¼Ê±¼ä 2021-02-01

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê01ÔÂ25ÈÕÖÁ01ÔÂ31ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´59¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇGoogle AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´ÐЩ¶´ £»Bosch FSM-2500 serverÃÜÂë鶩¶´ £»Rust SmallVec::insert_many¶ÑÒç³ö©¶´ £»SonicWall SSL-VPN User-AgentÔ¶³ÌÃüÁîÖ´ÐЩ¶´ £»Mozilla Firefox CVE-2021-23964ÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇSonicWall¾¯¸æÀûÓÃÆäVPN²úÎïÖÐ0dayµÄ¹¥»÷»î¶¯ £»ºÚ¿Í¹ûÈ»¼ÓÃÜ»õ±Ò½»Ò×ËùBuyucoinÓû§µÄÊý¾Ý £»AppleÄþ¾²¸üУ¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day £»Sudo©¶´BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ £»È«ÇòÖ´·¨²¿ÃÅÁªºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ© ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Google AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´ÐЩ¶´


Google AndroidÔËÐÐʱ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://source.android.com/security/bulletin/android-11


2.Bosch FSM-2500 serverÃÜÂë鶩¶´


Bosch FSM-2500 serverʹÓõÄÃÜÂë¹þÏ£²»¹»½¡×³£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢ ¡£

https://psirt.bosch.com/security-advisories/BOSCH-SA-332072-BT.html


3.Rust SmallVec::insert_many¶ÑÒç³ö©¶´


Rust SmallVec::insert_many´æÔÚ¶ÑÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://github.com/servo/rust-smallvec/issues/252


4.SonicWall SSL-VPN User-AgentÔ¶³ÌÃüÁîÖ´ÐЩ¶´


Sonicwall ssl-vpn CGI·¨Ê½´¦ÖôæÔÚÂß¼­Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄUser-AgentÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit/


5.Mozilla Firefox CVE-2021-23964ÄÚ´æÆÆ»µ´úÂëÖ´ÐЩ¶´


Mozilla Firefox´¦ÖÃWEBÒ³´æÔÚÄÚ´æÆÆ»µÂ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ £»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£

https://www.auscert.org.au/bulletins/ESB-2021.0291/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢SonicWall¾¯¸æÀûÓÃÆäVPN²úÎïÖÐ0dayµÄ¹¥»÷»î¶¯


1.jpg


Äþ¾²³§ÉÌSonicWallÐû²¼½ô¼±Í¨Öª£¬¾¯¸æÀûÓÃÆäVPN²úÎïÖÐ0dayµÄ¹¥»÷»î¶¯ ¡£¸Ã©¶´Î»ÓÚSecure Mobile Access£¨SMA£©VPNÉ豸¼°NetExtender VPN¿Í»§¶ËÖУ¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³½øÐÐЭͬ¹¥»÷ ¡£SonicWallÉÐδÐû²¼Óйظ鶴µÄÏêϸÐÅÏ¢£¬µ«Æ¾¾Ý»º½â´ëÊ©ÅжÏ£¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑé֤©¶´£¬¿É±»ÓÃÀ´ÔڿɹûÈ»·ÃÎʵÄÉ豸ÉÏÔ¶³ÌÀûÓà ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2¡¢ºÚ¿Í¹ûÈ»¼ÓÃÜ»õ±Ò½»Ò×ËùBuyucoinÓû§µÄÊý¾Ý


2.png


ShinyHuntersÔÚ°µÍøÉϹûȻӡ¶È¼ÓÃÜ»õ±Ò½»Ò×ËùBuyucoinÓû§µÄÊý¾Ý ¡£´Ë´Î×ܹ²Ð¹Â¶ÁËÈý¸öMongoDBÊý¾Ý¿â£¬ÕâЩÊý¾Ý¿â¾ùÒÔʱ¼äÃüÃû£¬·Ö±ðΪ2020Äê6ÔÂ1ÈÕ¡¢2020Äê7ÔÂ14ÈÕºÍ2020Äê9ÔÂ5ÈÕ ¡£Ð¹Â¶Êý¾Ý°üÂÞÓû§¼Ç¼¡¢¼ÓÃÜ»õ±ÒóÒ×½»Òס¢Óû§Á´½ÓµÄÒøÐÐÕÊ»§ÐÅÏ¢ÒÔ¼°½»Ò×ËùÄÚ²¿Ê¹ÓõÄÆäËû±í£¬ÆäÖÐÓû§¼Ç¼±í´æ´¢ÁË161487¸ö³ÉÔ±µÄÐÅÏ¢£¬°üÂÞµç×ÓÓʼþµØÖ·¡¢¹ú¼Ò/µØÓò¡¢¹þÏ£ÃÜÂë¡¢ÊÖ»úºÅÂëºÍGoogleµÇ¼ÁîÅƵÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-at-buyucoin-crypto-exchange-leaks-user-info-trades/


3¡¢AppleÄþ¾²¸üУ¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day


3.png


AppleÐû²¼ÁËÕë¶ÔiOSµÄÄþ¾²¸üУ¬ÐÞ¸´ÁË3¸öÒѱ»ÔÚÒ°ÀûÓõÄ0day ¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùÌõ¼þ©¶´£¨CVE-2021-1782£©£¬Ëü¿ÉÒÔʹ¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ ¡£ÁíÍâÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­Â©¶´£¨CVE-2021-1870ºÍCVE-2021-1871£©£¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë ¡£ÔÚ©¶´ÀûÓÃÁ´ÖУ¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾£¬¸ÃÍøÕ¾ÀûÓÃWebKit©¶´ÔËÐдúÂ룬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ£¬Î£¼°²Ù×÷ϵͳ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


4¡¢Sudo©¶´BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ


4.png


Äþ¾²Éó¼Æ¹«Ë¾Qualys·¢ÏÖSudo©¶´BaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ£¬ÒÑÓнüÊ®ÄêµÄÀúÊ· ¡£¸Ã©¶´ÊÇÓÉÓÚsudo´íÎóµØÔÚ²ÎÊýÖÐתÒåÁË·´Ð±¸Üµ¼Ö»ùÓڶѵĻº³åÇøÒç³ö©¶´£¬±»×·×ÙΪCVE-2021-3156£¬ÔÊÐíÈκε±µØÓû§£¨ÎÞÂÛÊÇ·ñÔÚsudoersÎļþÖУ©ÎÞÐè½øÐÐÉí·ÝÑéÖ¤»ñµÃrootȨÏÞ ¡£ÔÚ¹ýÈ¥Á½ÄêÖз¢ÏÖÁËÁíÍâÁ½¸öSudo©¶´£¨CVE-2019-14287ºÍCVE-2019-18634£©£¬µ«ÊÇ´Ë´ÎÅû¶µÄ©¶´ÊÇÈýÆäÖÐ×îΣÏÕµÄÒ»¸ö ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/


5¡¢È«ÇòÖ´·¨²¿ÃÅÁªºÏÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©


5.png


ÓÉÅ·ÖÞÐ̾¯×éÖ¯£¨Europol£©Áìµ¼µÄÈ«ÇòÖ´·¨Ðж¯ÆÆ»ñÁËÖøÃû½©Ê¬ÍøÂçEmotetµÄ»ù´¡ÉèÊ© ¡£EmotetÖÁÉÙ´Ó2014Ä꿪ʼ»îÔ¾£¬ÓëºÚ¿Í×éÖ¯TA542ÓйØ ¡£Europol³Æ£¬´Ë´ÎÐж¯±»³ÆΪOperation Ladybird£¬ÓɺÉÀ¼¡¢µÂ¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Á¢ÌÕÍð¡¢¼ÓÄôóºÍÎÚ¿ËÀ¼Õþ¸®ÅäºÏºÏ×÷£¬ÆÆ»µ²¢½Ó¹ÜÁËλÓÚ90¶à¸ö¹ú¼ÒµÄEmotetµÄC&C£¬²¢´þ²¶Á˶àÁ½ÃûÍøÂç·¸×ï·Ö×Ó ¡£¾ÝºÉÀ¼¾¯·½³Æ£¬Emotet×ܼÆÔì³ÉÁËÊýÒÚÃÀÔªµÄËðʧ£¬¶øÎÚ¿ËÀ¼Ö´·¨²¿ÃÅËðʧ¶îÔ¤¼ÆΪ25ÒÚÃÀÔª ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113933/cyber-crime/emotet-global-takedown.html