ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ49ÖÜ

Ðû²¼Ê±¼ä 2021-12-06

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Äþ¾²Â©¶´58¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇDell Emc Streaming Data Platform sql×¢È멶´ £»EFM ipTIME C200 IP CameraÈÎÒâÃüÁîÖ´ÐЩ¶´ £»ohmyzsh rand-quoteºÍhitokoto²å¼þÈÎÒâÃüÁîÖ´ÐЩ¶´ £»Open Solutions For Education openSIS GetStuListFnc.php SQL×¢È멶´ £»Sunnet eHRD·ÃÎÊ¿ØÖÆ´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇTP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐЩ¶´ £»IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦¼¼ÊõµÄÔ¤²â³ÂËß £»ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶Ê¼þ £»°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀ¾Ã¹Ø±Õ £»KasperskyÅû¶APT37ÀûÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1. Dell Emc Streaming Data Platform sql×¢È멶´


Dell Emc Streaming Data Platform´æÔÚsql×¢È멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.dell.com/support/kbdoc/zh-cn/000193697/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities


2. EFM ipTIME C200 IP CameraÈÎÒâÃüÁîÖ´ÐЩ¶´


EFM ipTIME C200 IP CameraÓëipTIME NASͬ²½Ê±´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


http://iptime.com/iptime/?page_id=126&diffid=&dfsid=19&dftid=541


3. ohmyzsh rand-quoteºÍhitokoto²å¼þÈÎÒâÃüÁîÖ´ÐЩ¶´


ohmyzsh rand-quoteºÍhitokoto²å¼þ´æÔÚÄþ¾²Â©¶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://github.com/ohmyzsh/ohmyzsh/commit/72928432


4. Open Solutions For Education openSIS GetStuListFnc.php SQL×¢È멶´


Open Solutions For Education openSIS GetStuListFnc.php´æÔÚsql×¢È멶´ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇó £¬²Ù×÷Êý¾Ý¿â £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£


https://github.com/OS4ED/openSIS-Classic/issues/202


5. Sunnet eHRD·ÃÎÊ¿ØÖÆ´úÂëÖ´ÐЩ¶´


Sunnet eHRDδÕýÈ·ÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´·ÃÎÊ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó £¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html


>ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢TP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐЩ¶´


ResecurityÑо¿ÈËÔ±TP-LinkµÄÉ豸ÖдæÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£ÊÜÓ°ÏìÉ豸µÄÐͺÅΪTL-XVR1800L £¬ÊÇÆóÒµ¼¶AX1800˫ƵǧÕ×Wi-Fi 6ÎÞÏßVPN·ÓÉÆ÷¡£¹¥»÷Õß¿ÉÀûÓø鶴ÍêÈ«¿ØÖÆÉ豸»òÇÔÈ¡Ãô¸ÐÊý¾Ý £¬Ëü¿ÉÄÜ»¹´æÔÚÓÚͬһϵÁеÄÆäËûÉ豸ÖС£ResecurityÔÚ10ÔÂÉÏÑ®·¢ÏÖÁËÕë¶Ô¸ÃÉ豸µÄ¹¥»÷»î¶¯ £¬²¢ÓÚ11ÔÂ19ÈÕ֪ͨÁËTP-Link £¬TP-LinkÔÚµÚ¶þÌìÈ·ÈÏÁ˸鶴²¢ÔÊÐí»áÔÚÒ»ÖÜÄÚÐû²¼²¹¶¡¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html


2¡¢IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦¼¼ÊõµÄÔ¤²â³ÂËß


IEEEÔÚ½üÆÚÐû²¼ÁËδÀ´Òªº¦¼¼ÊõµÄÔ¤²â³ÂËß¡£³ÂËßÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢Öйú¡¢Ó¡¶ÈºÍ°ÍÎ÷µÄ350λCTO¡¢CIOºÍIT×ܼà £¬Ô¤²âÁË2022Äê×îÖØÒªµÄ¼¼Êõ¡¢À´ÄêÊܼ¼ÊõÓ°Ïì×î´óµÄÐÐÒµÒÔ¼°Î´À´Ê®ÄêµÄ¼¼ÊõÇ÷ÊÆ¡£21%µÄÊÜ·ÃÕßÈÏΪÈ˹¤ÖÇÄܺͻúÆ÷ѧϰ½«³ÉΪÃ÷Äê×îÖØÒªµÄ¼¼Êõ £¬Æä´ÎΪÔƼÆËã(20%)ºÍ5G(17%) £»25%µÄÈËÈÏΪÖÆÔìÒµ»áÊÇ2022ÄêÊܼ¼ÊõÓ°Ïì×î´óµÄÐÐÒµ £¬Æä´ÎΪ½ðÈÚ·þÎñ(19%)¡¢Ò½ÁƱ£½¡(16%)ºÍÄÜÔ´(13%)ÐÐÒµ¡£


Ô­ÎÄÁ´½Ó£º

https://transmitter.ieee.org/impact-of-technology-2022/


3¡¢ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶Ê¼þ


ÈÕ±¾¿ç¹ú¹«Ë¾ËÉÏÂPanasonicÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷ £¬È·ÈÏÆ䲿ÃÅÊý¾ÝÒѾ­Ð¹Â¶¡£¹¥»÷·¢ÉúÔÚ6ÔÂ22ÈÕ £¬µ«Ö±µ½11ÔÂ11Èղű»·¢ÏÖ¡£¾­¹ýÄÚ²¿ÊÓ²ìÈ·¶¨ £¬¹¥»÷ÕßÒÑÔÚÕâ4¸öÔÂÖзÃÎÊÁË·þÎñÆ÷ÉϵIJ¿ÃÅÊý¾Ý¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÆäËüÏêϸÐÅÏ¢ £¬µ«ÈÕ±¾ÐÂÎÅÍøÕ¾MainichiºÍNHK±¨µÀ³Æ £¬¹¥»÷ÕßÒѾ­»ñµÃÁ˹«Ë¾¼¼Êõ¡¢ºÏ×÷»ï°é¼°¹«Ë¾Ô±¹¤µÈÏà¹ØÐÅÏ¢¡£ÔçÔÚ2020Äê11Ô £¬ËÉÏÂÓ¡¶È·Ö¹«Ë¾ÔøÒòÍøÂç¹¥»÷й¶Á˲ÆÕþµÈÏà¹ØÐÅÏ¢¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/


4¡¢°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀ¾Ã¹Ø±Õ


2021Äê11ÔÂ23ÈÕ £¬°µÍøÊг¡CannazonµÄ¹ÜÀíÔ±Ðû²¼½«ÓÀ¾Ã¹Ø±Õ¸ÃÍøÕ¾¡£¾ÝϤ £¬¸ÃÍøÕ¾ÔÚ11Ô³õÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷ £¬¹ÜÀíԱͨ¹ý¼õÉÙ¶©µ¥ÊýÁ¿ºÍ¹Ø±Õ²¿ÃÅϵͳÒÔ»º½âÎÊÌâ¡£µ«ÕâÔÚÉçÇøÖÐÒýÆðÁ˺䶯 £¬Óû§µ£ÓÇÕâÊÇÒ»³¡Í˳öÆ­¾Ö¡£¹ÜÀíÔ±ÔÚÐû²¼¹Ø±Õͨ¸æʱ £¬¶ÔÓÚÕâÖÖ´¦ÖÃÒªÁìÌåÏÖǸÒâ £¬³ÆûÓйûÈ»¹¥»÷»î¶¯ÊÇΪÁ˱ £»¤Óû§ºÍÉçÇø £¬ÒÔ·ÀÖ¹¹©Ó¦ÉÌÊÔͼ·¢¶¯¼ÓÃÜ»õ±ÒÍ˳öÆ­¾Ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/


5¡¢KasperskyÅû¶APT37ÀûÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯


KasperskyÔÚ11ÔÂ29ÈÕÅû¶³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖ³ÆScarCruft»òTemp.Reaper£©ÔÚ½üÆڵĹ¥»÷»î¶¯¡£ScarCruft´Ó2012Ä꿪ʼ»îÔ¾ £¬Ö÷ÒªÕë¶Ôº«¹úµÄ¹Ù·½»ú¹¹»ò¹«Ë¾¡£´Ë´Î»î¶¯¿ªÊ¼ÓÚ2021Äê8Ô £¬³õʼѬȾý½éÊÇÓã²æʽµöÓã»î¶¯ £¬Ö®ºóÀûÓÃIEä¯ÀÀÆ÷ÖеÄÁ½¸ö©¶´ÔÚº«¹úµÄÍøÕ¾Öа²×°×Ô½ç˵¶ñÒâÈí¼þBLUELIGHT £¬Ìᳫˮ¿Ó¹¥»÷¡ £»î¶¯»¹ÀûÓÃÁ˶ñÒâÈí¼þChinotto £¬Ëü¾ßÓÐÕë¶ÔPowerShell¡¢WindowsºÍAndroidµÄ¶à¸ö±äÌå¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/