ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ48ÖÜ

Ðû²¼Ê±¼ä 2021-11-29

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDell Networking X-Series firmwareÑéÖ¤Èƹý©¶´£»D-Link DWR-932C E1 debug_fcgi OSÃüÁî×¢È멶´£»Commvault CommCell AppStudioUploadHandlerÈÎÒâÎļþÉÏ´«Â©¶´£»HejHome GKW-IC052 IP CameraÓ²±àÂ멶´£»QNAP QVR²»ÕýÈ·Ñé֤©¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇRedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿±êÉæ¼°¸÷Ðи÷Òµ£»LinuxºóÃÅlinux_avp¿ÉÈƹýµçÉÌƽ̨µÄÄþ¾²¼ì²â£»CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Â©¶´£»AppGalleryÖжà¿îÓÎÏ·Ó¦ÓôæÔÚľÂí£¬ÒÑѬȾ900¶àÍòÉ豸£»KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Dell Networking X-Series firmwareÑéÖ¤Èƹý©¶´


Dell Networking X-Series firmware´æÔÚÑéÖ¤Èƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽٳֻỰ£¬Í¨¹ýαÔì»á»°id·ÃÎÊweb·þÎñÆ÷ ¡£


https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-x-series-security-update-for-multiple-security-vulnerabilities


2. D-Link DWR-932C E1 debug_fcgi OSÃüÁî×¢È멶´


D-Link DWR-932C E1 debug_fcgi´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£


https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10246


3. Commvault CommCell AppStudioUploadHandlerÈÎÒâÎļþÉÏ´«Â©¶´


Commvault CommCell AppStudioUploadHandlerÀà´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÉÏ´«Îļþ²¢Ö´ÐÐ ¡£


https://www.zerodayinitiative.com/advisories/ZDI-21-1332/


4. HejHome GKW-IC052 IP CameraÓ²±àÂ멶´


HejHome GKW-IC052 IP Camera´æÔÚÓ²±àÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɿØÖÆϵͳδÊÚȨ½øÐвÙ×÷ ¡£


https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359


5. QNAP QVR²»ÕýÈ·Ñé֤©¶´


NAP QVR´æÔÚ²»ÕýÈ·Ñé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊϵͳ ¡£


https://www.qnap.com.cn/en/security-advisory/qsa-21-52


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿±êÉæ¼°¸÷Ðи÷Òµ


Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄл ¡£ÍøÂç¼äµýºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020ÄêÆڼ䣬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÓòµÄ½¨Öþ¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢±£ÏÕºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾ ¡£¸ÃÍÅ»ïÔÚÖжÏ7¸öÔºó¾íÍÁÖØÀ´£¬×Ô2021Äê³õÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷£¬ÆäÖаüÂÞ¶íÂÞ˹×î´óµÄÅú·¢É̵ê ¡£Group-IB³Æ£¬RedCurlÔÚÿ´Î¹¥»÷Öж¼ÊÐʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈƹý¼ì²â ¡£


Ô­ÎÄÁ´½Ó£º

https://www.group-ib.com/media/red-curl-threat-report/


2¡¢LinuxºóÃÅlinux_avp¿ÉÈƹýµçÉÌƽ̨µÄÄþ¾²¼ì²â


SansecÍþвÑо¿ÍŶÓÔÚ11ÔÂ18µÄ×îÐÂÑо¿·¢ÏÖÁËLinuxºóÃÅlinux_avp ¡£Ñо¿ÈËÔ±³Æ£¬¹¥»÷ÕßÔÚµçÉÌÍøÕ¾×¢ÈëÐÅÓÿ¨ÇÔÈ¡Æ÷ºó£¬»¹»áÔÚ±»ÈëÇֵķþÎñÆ÷ÉÏ°²×°LinuxºóÃÅ ¡£linux_avpÒ»µ©Æô¶¯£¬¾ÍÁ¢¼´½«×Ô¼º´Ó´ÅÅÌÖÐɾ³ý£¬Î±×°³Éps -ef½ø³Ì£¬ÓÃÓÚ»ñÈ¡µ±Ç°ÕýÔÚÔËÐеĽø³ÌÁÐ±í²¢Èƹý¼ì²â ¡£¸ÃÑù±¾ÓÚ10ÔÂ8ÈÕÊ×´ÎÉÏ´«£¬Ä¿Ç°VirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÈÔδ¼ì²âµ½Ëü ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hackers-deploy-linux-malware-web-skimmer-on-e-commerce-servers/


3¡¢CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Â©¶´


Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÎïImunify360ÖеÄPHP·´ÐòÁл¯Â©¶´ ¡£¸Ã²úÎïÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄÄþ¾²Æ½Ì¨£¬Óû§¿ÉÀûÓÃÆäͨ¹ýÖÖÖÖÅäÖÃÀ´ÊµÊ±±£»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄÄþ¾² ¡£¸Ã©¶´(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬´æÔÚÓÚAi-Bolit¹¦Ð§ÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸Ã©¶´ÔÚÄ¿±êϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룬»òÍêÈ«¿ØÖÆ·þÎñÆ÷ ¡£Ä¿Ç°£¬CloudLinuxÒÑÐÞ¸´¸Ã©¶´ ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html


4¡¢AppGalleryÖжà¿îÓÎÏ·Ó¦ÓôæÔÚľÂí£¬ÒÑѬȾ900¶àÍòÉ豸


11ÔÂ23ÈÕ£¬Dr. WebµÄÑо¿ÈËÔ±Åû¶»ªÎªÓ¦ÓÃÉ̵êAppGalleryÖеÄ190¿îÓÎÏ·ÖдæÔÚľÂíAndroid.Cynos.7.origin£¬ÒÑ°²×°Ô¼9300000´Î ¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌ壬ּÔÚÊÕ¼¯Óû§µÄÐÅÏ¢ ¡£ÕâЩÓÎÏ·Ö÷ҪʹÓöíÓï¡¢ÖÐÎĺÍÓ¢ÓÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î ¡£Ñо¿ÈËÔ±³Æ£¬¸ÃľÂí¿É·¢ËͺÍÀ¹½Ø¶ÌÐÅ¡¢ÏÂÔغÍÆô¶¯ÆäËüÄ£¿é£¬ÒÔ¼°ÏÂÔغͰ²×°ÆäËûÓ¦Óà ¡£Ä¿Ç°£¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎÏ·ÏÂ¼Ü ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html


5¡¢KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß


11ÔÂ22ÈÕ£¬KasperskyÐû²¼2021ÄêºÚÎåÆÚ¼äÕ©Æ­»î¶¯µÄ·ÖÎö³ÂËß ¡£³ÂËßÖ÷Òª·ÖÎöÁËÓëÈ«Çò·ÃÎÊÁ¿×î´óµÄÎå¸öÁãÊÛƽ̨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre ¡£Ñо¿·¢ÏÖ£¬2021ÄêÇ°10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌƽ̨ÒÔ¼°ÒøÐлú¹¹µÄµöÓã¹¥»÷£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄµöÓã»î¶¯Ôö¼ÓÁË208%£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢ÏÖÁË221745·âÓëºÚÎåÓйصÄÓʼþ ¡£³ÂËßÖ¸³ö£¬ºÚÉ«ÐÇÆÚÎå²»½ö¶Ô¹ºÎïÕßÀ´ËµÊÇÖØÒªµÄÒ»Ì죬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÈç´Ë ¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/black-friday-2021/104915/