ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2021-10-11

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓþܾø·þÎñ©¶´£»Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐЩ¶´£»Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐЩ¶´£»Visual Tools DVR VX cgi-bin/slogin/login.pyÃüÁîÖ´ÐЩ¶´; Google chrome Safe BrowsingÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÓÉÓÚFirebaseÅäÖôíÎó14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢£»Facebook·ÓÉÅäÖôíÎóµ¼ÖÂÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ£»Ó¢¹úÿÈÕµçѶ±¨ElasticsearchÅäÖôíÎóй¶10TBÊý¾Ý£»TwitchÒò·þÎñÆ÷ÅäÖôíÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢£»Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Apache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓþܾø·þÎñ©¶´


Apache HTTP Server´æÔÚĿ¼±éÀú©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎļì²ìϵͳÎļþÄÚÈÝ»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://httpd.apache.org/security/vulnerabilities_24.html


2. Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐЩ¶´


Zoho ManageEngine ADManager Plus´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÉÏ´«¶ñÒâÎļþ£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.manageengine.com/products/ad-manager/release-notes.html#7111


3. Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐЩ¶´


Google Android¿ò¼Ü´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂ룬ÌáÉýȨÏÞ¡£


https://source.android.com/security/bulletin/2021-10-01


4. Visual Tools DVR VX cgi-bin/slogin/login.pyÃüÁîÖ´ÐЩ¶´


Visual Tools DVR VX16  cgi-bin/slogin/login.py Uaer-Agent HTTP´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.exploit-db.com/exploits/50098


5. Google chrome Safe BrowsingÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Google chrome Safe Browsing´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë»òÕßʹӦÓ÷¨Ê½Í߽⡣


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html


 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÓÉÓÚFirebaseÅäÖôíÎó14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢


9ÔÂ30ÈÕ£¬ CyberNews Ñо¿Ô± Martynas Vareikis Ðû²¼³ÂË߳ƣ¬ÓÉÓÚ Firebase Êý¾Ý¿âÅäÖôíÎ󣬵¼ÖÂÊýÒÔǧ¼ÆµÄ iOS / Android Ó¦Ó÷¨Ê½Ð¹Â¶ÁËÁè¼Ý1.4ÒÚÌõÐÅÏ¢¡£Firebase ÊÇ Google ÌṩµÄ¡°ºó¶Ë¼´·þÎñ¡±²úÎÆäÖаüÂÞÁË´óÁ¿·¢·þÎñ£¬Ö¼ÔÚ·½±ãÒƶ¯¿ª·¢ÈËÔ±´´½¨»ùÓÚÕâЩ·þÎñµÄÒƶ¯»ò Web Ó¦Óá£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/security/research-popular-android-apps-with-142-5-million-collective-downloads-are-leaking-user-data/


2¡¢Facebook·ÓÉÅäÖôíÎóµ¼ÖÂÈ«Çò·¶Î§ÄÚ·þÎñÖжÏ


10ÔÂ4ÈÕ£¬FacebookÆì϶à¸öƽ̨ºÍ·þÎñ£¬°üÂÞ Facebook¡¢Instagram¡¢MessengerºÍ WhatsAppµÈ£¬Ïà¼Ì·ºÆðÑÏÖØ·þÎñÖжϡ£Óû§ÎÞ·¨µÇÈ뷨ʽ£¬·¨Ê½ÎÞ·¨Áª»úºÍ¸üУ¬Ã»·¨ÊÕ·¢ÐÅÏ¢£¬¾ÍÁ¬ÒÔ FacebookÕ˺ŵÇÈëµÄ·¨Ê½ºÍ·þÎñÒàÊܵ½Ç£Á¬£¬²»ÄÜÕý³£µÇÈë¡£FacebookÆäºó·¢ÉùÃ÷Ö¸£¬ÄÚ²¿Â·ÓÉÆ÷·ºÆðÎÊÌ⣬Á¬Ëø·´Ó³µ¼Ö·þÎñÈ«ÃæÖжÏ£¬ËäÈ»·þÎñÒѻظ´£¬µ«ÄÚ²¿ÈÔÔÚÈ«Á¦¸ÄÉÆϵͳ£¬ÒԻظ´Õý³£ÊÂÇé״̬¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/facebook-outage-caused-by-faulty-routing-configuration-changes/


3¡¢Ó¢¹úÿÈÕµçѶ±¨ElasticsearchÅäÖôíÎóй¶10TBÊý¾Ý


10ÔÂ6ÈÕ£¬Ñо¿Ô± Bob Diachenko ·¢ÏÖÁËÒ»¸öÊôÓÚÓ¢¹ú±¨Ö½¡°µçѶ±¨¡±µÄδÊܱ£»¤µÄ 10 TB Êý¾Ý¿â¡£²»Äþ¾²µÄÊý¾Ý¿âÓÚ9 Ô 14 ÈÕ±»·¢ÏÖ£¬ÆäÖаüÂÞÄÚ²¿ÈÕÖ¾ºÍ¶©ÔÄÕßÐÅÏ¢¡£Êý¾Ý´æ´¢ÔÚ̻¶µÄ Elasticsearch ¼¯ÈºÉÏ£¬´ó²¿ÃÅÊý¾Ý¶¼¾­¹ý¼ÓÃÜ£¬µ«ÖÁÉÙ 1,200 Ãû Telegraph ¶©ÔÄÕߺÍ×¢²áÕߵĸöÈËÏêϸÐÅÏ¢ÒÔ¼°´óÁ¿ÄÚ²¿·þÎñÆ÷ÈÕÖ¾¶¼ÒѾ­¹ýÃ÷È·²âÊÔ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123020/data-breach/the-telegraph-data-leak.html


4¡¢TwitchÒò·þÎñÆ÷ÅäÖôíÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢


10ÔÂ6ÈÕ£¬ºÚ¿ÍÔÚ4chan¹ûÈ»ÁË°üÂÞ125GBÊý¾ÝµÄtorrentÁ´½Ó£¬³ÆÕâÊÇ´ÓԼĪ6000¸öÄÚ²¿Twitch Git´æ´¢¿âÖÐÇÔÈ¡µÄ£¬°üÂÞÔ´´úÂëºÍÖ§¸¶¼Ç¼µÈÐÅÏ¢¡£´ËÍ⣬¹¥»÷Õß»¹Ê¹ÓÃÁ˱êÇ©#DoBetterTwitch£¬Ö¤Ã÷´Ë´Î¹¥»÷ʼþ¿ÉÄÜÖ¼ÔÚÕë¶ÔTwitch 8Ô·ÝûÓлØÓ¦ºÍµÖÓù¶ÔÖ÷²¥µÄ¹¥»÷»î¶¯¡£TwitchÔÚ10ÔÂ7ÈÕÈ·ÈÏÆäÊý¾Ýй¶ÊÇÓÉÓÚ·þÎñÆ÷ÅäÖôíÎóµ¼ÖµÄ£¬Ã»ÓеǼƾ¾ÝºÍÐÅÓÿ¨ºÅй¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/twitch-no-credentials-or-card-numbers-exposed-in-data-breach/


5¡¢Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Cyberint·¢ÏÖ¶ñÒâÈí¼þVidarÔÚÐÂÒ»ÂÖ¹¥»÷»î¶¯Öлع顣Vidar×Ô2018Äê10ÔÂÒÔÀ´¿ªÊ¼»îÔ¾£¬Ö¼ÔÚ´ÓÄ¿±êϵͳÖÐÇÔÈ¡µç×ÓÓʼþƾ¾Ý¡¢ÁÄÌìÕÊ»§ÏêϸÐÅÏ¢¡¢cookieµÈÊý¾Ý¡£´Ë´Î»î¶¯ÖУ¬¹¥»÷ÕßÊ×ÏȽ¨Á¢MastodonÕ˺Å£¬²¢ÔÚ¸öÈË×ÊÁÏÃèÊö²¿ÃÅÌí¼Ó¶ñÒâÈí¼þʹÓõÄC2µÄIP¡£Æ仹ʹÓÃÁËÁíÒ»ÖÖ·Ö·¢ÒªÁ죬ֱ½ÓÔÚÉ罻ýÌåƽ̨ÉÏ·¢ËÍÏûÏ¢£¬»òÕßÊÇÀûÓÃÆƽâÓÎÏ·µÄtorrent¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2-configuration/