ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ7ÖÜ

Ðû²¼Ê±¼ä 2021-02-18

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ08ÈÕÖÁ02ÔÂ14ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´62¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇHPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç³ö©¶´£»Micro Focus Operation Bridge´úÂëÖ´ÐЩ¶´£»Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Advantech iView SQL×¢È멶´£»Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇMozillaÐû²¼FirefoxÄþ¾²¸üР£¬ÐÞ¸´NTFSËð»µÎÊÌ⣻ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÂÞ¶ñÒâ´úÂ룻WordPressµÄ²å¼þÖÐδÐÞ¸´µÄXSS©¶´¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾£»ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö £¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿£»KasperskyÐû²¼2020ÄêÕÊ»§½Ó¹Ü¹¥»÷ʼþµÄ»Ø¹Ë³ÂËß¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash»º³åÇøÒç³ö©¶´


HPE Apollo 70 System BMC¹Ì¼þLibifc.so WebStartFlash´æÔÚ»º³åÇøÒç³ö©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf04080en_us


2.Micro Focus Operation Bridge´úÂëÖ´ÐЩ¶´


Micro Focus Operation Bridge´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://softwaresupport.softwaregrp.com/doc/KM03775947


3.Microsoft Windows DNS·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐЩ¶´


Microsoft Windows DNS·þÎñÆ÷´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿Éʹϵͳ±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24078


4.Advantech iView SQL×¢È멶´


Advantech Iview´æÔÚSQL×¢È멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-040-02


5.Adobe Animate CVE-2021-21052Ô½½çд´úÂëÖ´ÐЩ¶´


Adobe Animate´¦ÖÃÎļþ´æÔÚÔ½½ç䩶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴¹¹½¨¶ñÒâÎļþ £¬ÓÕʹÓû§½âÎö £¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://helpx.adobe.com/security/products/animate/apsb21-11.html


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢MozillaÐû²¼FirefoxÄþ¾²¸üР£¬ÐÞ¸´NTFSËð»µÎÊÌâ


1.png


MozillaÐû²¼ÁËFirefox 85.0.1 £¬ÐÞ¸´ÁË¿É´¥·¢NTFSË𻵵ÄÎÊÌâ¡£Windows 10ºÍWindows XPÖдæÔÚÔÊÐí·ÇÌØȨÓû§½«NTFS·ÖÇø±ê־Ϊ¡°ÔࡱµÄ©¶´ £¬Õâ»áµ¼ÖÂÇý¶¯Æ÷Ë𻵲¢ÐèÒªÓû§ÖØÐÂÆô¶¯ÒÔÐÞ¸´¡£Firefox¿ÉÒÔͨ¹ý·ÃÎÊÌØÖÆ·¾¶À´´¥·¢NTFSËð»µÎÊÌâ £¬Ä¿Ç°¸Ã·¾¶Òѱ»½ûÖ¹¡£´ËÍâ £¬´Ë´ÎÄþ¾²¸üл¹ÐÞ¸´Á˶à¸ö©¶´ £¬ÈçmacOSÉ豸ÉÏʹÓÃSPNEGO¶ÔÍøÕ¾½øÐÐÉí·ÝÑé֤ʱµÄÍß½âÎÊÌâµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/mozilla-fixes-windows-10-ntfs-corruption-bug-in-firefox/


2¡¢ÏÂÔØÁè¼Ý200Íò´ÎµÄChromeÀ©Õ¹Great Suspender°üÂÞ¶ñÒâ´úÂë


2.png


Á÷ÐеÄChromeÀ©Õ¹The Great Suspender°üÂÞ¶ñÒâ´úÂë £¬Òѱ»ÏÂÔØÁè¼Ý200Íò´Î¡£¸ÃÀ©Õ¹ÓÃÓÚÔÝͣδʹÓõÄÑ¡Ï £¬²¢½«ÔÝÍ£µÄÒ³ÃæÌ滻Ϊ¿Õ°×Ò³ÃæÖ±µ½Óû§ÔÙ´ÎʹÓÃΪֹ £¬Ö¼ÔÚ½ÚÊ¡×ÊÔ´¡£GoogleÑо¿ÈËÔ±·¢ÏÖ¿ª·¢ÕßÌí¼ÓÁËй¦Ð§ £¬¿É´ÓÔ¶³Ì·þÎñÆ÷Ö´ÐÐÈÎÒâ´úÂë £¬ÕâÄܱ»ÓÃÀ´½øÐйã¸æÆÛÕ©ºÍ¸ú×ٵȶñÒâ»î¶¯¡£Ä¿Ç° £¬GoogleÒÑÓÚÉÏÖÜËĽ«¸ÃÀ©Õ¹´ÓÍøÉÏÉ̵êÖÐɾ³ý £¬»¹½«Æä´ÓÓû§µÄ¼ÆËã»úÖнûÓá£


Ô­ÎÄÁ´½Ó£º

https://www.hackread.com/the-great-suspender-chrome-extension-malware/


3¡¢WordPressµÄ²å¼þÖÐδÐÞ¸´µÄXSS©¶´¿ÉÓ°ÏìÊýÍò¸öÍøÕ¾


3.png


WordPressµÄ²å¼þContact Form 7 StyleÖÐδÐÞ¸´µÄXSS©¶´¿ÉÓ°ÏìÁè¼Ý5Íò¸öÍøÕ¾¡£¸Ã²å¼þÓÃÓÚ´´½¨ÍøվʹÓõÄÁªÏµ±íµ¥ £¬ÔÊÐíÓû§×Ô½ç˵ÍøÕ¾µÄ¼¶ÁªÑùʽ±í(CSS)´úÂëÀ´Ö¸¶¨wordpressµÄÍøÕ¾µÄÍâ¹Û¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8 £¬ÊÇÓÉÓÚ×Ô½ç˵CSS´úÂëµÄ¹¦Ð§È±ÉÙ¶ÔÊý¾ÝµÄÇåÀíºÍ¶ÔËæ»úÊýµÄ±£»¤»úÖÆ £¬Ê¹¹¥»÷Õß¿ÉÒÔÌá½»ÏòÍøÕ¾×¢Èë¶ñÒâJavaScriptµÄÇëÇó¡£Ä¿Ç° £¬»¹Î´Ðû²¼Õë¶Ô¸Ã©¶´µÄ²¹¶¡·¨Ê½¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/unpatched-wordpress-plugin-code-injection/163706/


4¡¢ÀÕË÷ÍÅ»ïZiggyÐû²¼Í˳ö £¬²¢Ðû²¼Æä½âÃÜÃÜÔ¿


4.png


ÖÜÄ© £¬ÀÕË÷ÍÅ»ïZiggyÔÚTelegramÉÏÐû²¼Æ佫Í˳ö £¬²¢Ðû²¼ËùÓнâÃÜÃÜÔ¿¡£2ÔÂ7ÈÕ £¬ZiggyÍÅ»ïÐû²¼ÁËÒ»¸ö°üÂÞÁË922¸ö½âÃÜÃÜÔ¿µÄSQLÎļþºÍÓë½âÃÜÃÜÔ¿Ò»ÆðʹÓõĽâÃÜÆ÷¡£³ý´ËÖ®Íâ £¬Ziggy»¹Ðû²¼ÁËÀëÏߵĽâÃÜÃÜÔ¿ºÍ²îÒì½âÃÜÆ÷µÄÔ´´úÂë £¬ÓÃÓÚÒòÔâµ½¹¥»÷¶øÎÞ·¨Á¬½Óµ½Internet»òC&CÎÞ·¨·ÃÎʵÄÊܺ¦Õß½øÐнâÃÜ¡£Ñо¿ÈËÔ±³Æ×î½üµ·»ÙEmotetºÍNetwalkerÐж¯¿ÉÄÜ»áʹ¸ü¶àÍÅ»ï¸ÐӦΣÏÕ²¢Í˳ö £¬EmsisoftÒ²¼´½«Ðû²¼Æä½âÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/ziggy-ransomware-shuts-down-and-releases-victims-decryption-keys/


5¡¢KasperskyÐû²¼2020ÄêÕÊ»§½Ó¹Ü¹¥»÷ʼþµÄ»Ø¹Ë³ÂËß


5.png


KasperskyÐû²¼ÁËÓйØ2020ÄêÕÊ»§½Ó¹Ü¹¥»÷ʼþµÄ»Ø¹Ë³ÂËß¡£³ÂËßÏÔʾ £¬ÕË»§½Ó¹ÜʼþÕ¼½ðÈÚ·þÎñÐÐÒµÆÛÕ©»î¶¯µÄ±ÈÀýÉÏÉýÁË19% £¬´Ó2019ÄêµÄ34£¥¼¤ÔöÖÁ2020ÄêµÄ54£¥¡£³ýÁ˽ӹÜÕÊ»§Ö®Íâ £¬¹¥»÷Õß»¹ÀÄÓÃÖîÈçTeamViewerÖ®ÀàµÄºÏ·¨Ô¶³Ì¹ÜÀí¹¤¾ß£¨RAT£©À´ÊµÑé·ÃÎÊÓû§ÕÊ»§¡£Kaspersky½¨Òé×é֯ͨ¹ýÏÞÖƽ»Ò×µÄʵÑé´ÎÊý¡¢½øÐÐÄê¶ÈÄþ¾²ÉóºËºÍÉø͸²âÊÔÒÔ¼°ÊµÊ©¶àÒòËØÉí·ÝÑéÖ¤µÄ·½Ê½À´Ô¤·À´ËÀ๥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.kaspersky.com/about/press-releases/2021_share-of-account-takeover-incidents-increased-by-20-percentage-points