ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ6ÖÜ
Ðû²¼Ê±¼ä 2021-02-08> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2021Äê02ÔÂ01ÈÕÖÁ02ÔÂ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´66¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Shiro·ÃÎÊÈƹý©¶´£»Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´ÐЩ¶´£»Sonicwall SMA100 SQL×¢È멶´£»Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐЩ¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇCiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËߣ»Azure FunctionsÖдæÔÚÌáȨ©¶´£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯£»Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»»õÔ˹«Ë¾Forward AirѬȾHades£¬Ëðʧ´ï750ÍòÃÀÔª¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
> ÖØÒªÄþ¾²Â©¶´Áбí
1.Apache Shiro·ÃÎÊÈƹý©¶´
Apache ShiroʹÓÃspring´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊ·þÎñ¡£
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E
2.Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐЩ¶´
Apache Dubbo decodeBody´¦ÖôæÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔ·þÎñÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-128/
3.Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´ÐЩ¶´
Siemens Comfort Panel Telnet·þÎñÎÞÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-033-02
4.Sonicwall SMA100 SQL×¢È멶´
Sonicwall SMA100 WEB½Ó¿Ú´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001
5.Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐЩ¶´
Apple macOS CoreText TTF½âÎö´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-149/
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢CiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËß
CiscoÐû²¼ÁË2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËß¡£Ñо¿ÊÓ²ìÁËÀ´×Ô25¸ö¹ú¼ÒºÍµØÓòµÄ4400¶à¸ö×éÖ¯£¬²¢Ì½ÌÖÁËËûÃǶÔÒþ˽¹æÔòµÄ̬¶È¡£³ÂËßÏÔʾ£¬60£¥µÄ×é֯ûÓÐΪԶ³ÌÊÂÇéËùÉæ¼°µÄÒþ˽ºÍÄþ¾²ÒªÇó×öºÃ×¼±¸£¬93£¥µÄ×é֯ͨ¹ýÒþ˽±£»¤ÍŶÓÀ´Ó¦¶ÔÕâЩÌôÕ½£¬87£¥µÄ¸öÈ˵£ÓÇËûÃÇËùʹÓõÄÔ¶³Ì¹¤¾ßµÄÒþ˽±£»¤ÎÊÌâ¡£´ËÍ⣬ÏÖÒÑÓÐ140¶à¸ö˾·¨¹ÜϽÇøÖƶ¨ÁËÒþ˽±£»¤·¨£¬½ü80£¥µÄÊÜ·ÃÕßÈÏΪÕâЩִ·¨¾ßÓлý¼«Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://blogs.cisco.com/security/privacy-comes-of-age-during-the-pandemic
2¡¢Azure FunctionsÖдæÔÚÌáȨ©¶´£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú
Intezer LabµÄÑо¿ÈËÔ±Åû¶ÁËMicrosoft Azure FunctionsÖÐδÐÞ¸´µÄÌáȨ©¶´£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£Azure Functions¿ÉÒÔÓÉHTTPÇëÇó´¥·¢£¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐУ¬µ«ÊÇ´úÂëûÓб»Äþ¾²Ö§½â£¬¶øÇÒ¿ÉÄܱ»ÀÄÓÃÀ´·ÃÎʵײ㻷¾³¡£Ñо¿ÈËÔ±·¢ÏÖ¿ÉÒÔͨ¹ý´´½¨Ò»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell£¬ÒÔÎÞÌØȨµÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏ޵Ľø³Ì½Ó¿Ú¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html
3¡¢NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯
ÍøÂçÄþ¾²¹«Ë¾NCC GroupÖÜÈճƣ¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂçÉ豸ÖÐÁãÈÕ©¶´µÄÖ÷¶¯ÀûÓÃʵÑ顣ĿǰÉв»Çå³þ´Ë©¶´ÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄ©¶´Ïàͬ£¬µ«NCCÈÏΪÕâÊǼ«ÓпÉÄܵġ£SonicWallÔÚÆäSMA 100Äþ¾²Í¨¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢ÏÖµÄÁãÈÕ©¶´£¬ÁгöÁËÊÜÓ°ÏìµÄÉ豸ÐͺŲ¢ÌåÏÖ»áÔÚ2ÔÂ2ÈÕ֮ǰÐû²¼²¹¶¡·¨Ê½¡£ÓйØ©¶´µÄϸ½Ú²¢Î´¹ûÈ»£¬ÒÔ·ÀÖ¹ÆäËû¹¥»÷Õ߶ÔÆä½øÐÐÑо¿²¢·¢¶¯¹¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/
4¡¢Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â
SophosÑо¿ÈËÔ±·¢ÏÖ¼äµýÈí¼þAgent TeslaʵÑé¸Ä¶¯Î¢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍ·ÖÎö¡£Agent TeslaÓÚ2014ÄêÊ״α»·¢ÏÖ£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄÉÌÒµRAT¡£SophosÌåÏÖ£¬¸Ã¶ñÒâÈí¼þÕýÔÚ²»Í£¿ª·¢ÖУ¬Æä.NETÏÂÔØ·¨Ê½¿Éµ÷Óò¢ÏÂÔØÍйÜÔںϷ¨ÍøÕ¾ÉϵĶñÒâ´úÂë¡£ÔÚÀֳɸĶ¯AMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇé¿öÏÂÍêÕû²¿Êð£¬ÒÔÇÔÈ¡Êý¾Ý£¬Ö÷ÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÈÓ¦Óá£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/
5¡¢»õÔ˹«Ë¾Forward AirѬȾHades£¬Ëðʧ´ï750ÍòÃÀÔª
»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª¡£¸Ã¹¥»÷ʼþ·¢ÉúÔÚÈ¥Äê12ÔÂ15ÈÕ£¬ÒòѬȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡ÐëÒªµÄÎļþÒÔͨ¹ýº£¹ØÇå¹ØÔËÊ䣬ÆäÔËÓªÊܵ½ÑÏÖØÆÆ»µ¡£¾¡¹ÜForward AirÌåÏÖÆäÒÑÀֳɵشӹ¥»÷Öлָ´£¬µ«»¹ÊÇÖ§¸¶Á˼«ÖØ´ú¼Û£¬ÆäÔÚµÚËļ¾¶ÈµÄ²ÆÕþÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/