¶íÂÞ˹ISP Beeline 870Íò¿Í»§Êý¾Ýй¶£»D-Link°µÊ¾²»»á½¨¸´Â·ÓÉÆ÷RCE£»HildaCrypt¿ª·¢Õß°ä²¼½âÃÜÃÜÔ¿

°ä²¼¹¦·ò 2019-10-08
1.ºÉÀ¼NCSC°µÊ¾ÐµÄDNS´«ÊäºÍ̸½«Ê¹DNS¼à¿Ø¸´ÔÓ»¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ºÉÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©ÔÚÒ»·Ý»ã±¨ÖаµÊ¾ÐµÄDNS´«ÊäºÍ̸½«Ê¹DNS¼à¿ØÔ½·¢¸´ÔÓ»¯ºÍÔ½·¢ÄÑÌâ ¡£NCSCÚ¹ÊͳÆ£¬ÐµÄDNS´«ÊäºÍ̸ʹ¼à¿Ø»òÅú¸ÄDNSÒªÇó±äµÃÔ½·¢ÄÑÌ⣬Õâ¶ÔÓÚµ±½ñ²»ÊÜÐÅÀµµÄÍøÂçÊÇÓÐÒæµÄ ¡£Í¬Ê±Ô½À´Ô½¶àµØÑ¡È¡ÐµÄDNS´«ÊäºÍ̸£¬ÀýÈç»ùÓÚTLSµÄDNSºÍ̸£¨DoT£©ºÍ»ùÓÚHTTPSµÄDNSºÍ̸£¨DoH£©¿ÉÄÜʹ×éÖ¯µÄ°²È«½ÚÔìʧЧ£¬Õâ»áµ¼ÖÂÄÚ²¿×ÊÔ´¶¨Ãû¶³ö»òÏνӶϿªµÈ¸ºÃæÓ°Ïì ¡£ÕâЩ¸ºÃæÓ°ÏìºÜÄÑÔÚÍøÂç¼¶±ð»º½â£¬²¢ÇÒ±ØÒªÔÚDNS»ù´¡ÉèÊ©ºÍµ¥¸öÉ豸ÉÏ»º½â ¡£GoogleºÍMozilla¶¼ÔÚ½üÆÚΪÆää¯ÀÀÆ÷£¨ChromeºÍFirefox£©½øÐÐDoH²âÊÔ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://english.ncsc.nl/publications/factsheets/2019/oktober/2/factsheet-dns-monitoring-will-get-harder

2.ºÚ¿ÍÈÔÔÚÀûÓÃÒ»Äêǰ½¨¸´µÄDrupalgeddon2·ì϶·Ö·¢¶ñÒâÈí¼þ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÈÔÔÚ»ý¼«ÀûÓÃÒ»Äêǰ½¨¸´µÄDrupalgeddon2·ì϶·Ö·¢¶ñÒâÈí¼þ ¡£¸Ã·ì϶µÄCVE±àºÅΪCVE-2018-7600£¬Ó°ÏìÁËDrupal°æ±¾6¡¢7ºÍ8£¬²¢ÒÑÓÚ2018Äê3Ô±»½¨¸´ ¡£Akamai°²È«×êÑÐÔ±Larry W. Cashdollar·¢Ïָ÷ì϶ÒÀÈ»ÊÇ×î½ü¹Û²ìµ½µÄ¶ñÒâ»î¶¯µÄÖ¸±ê£¬¹¥»÷ÕßÊÔIJÀûÓø÷ì϶ÔÚδ´ò²¹¶¡µÄϵͳÉÏÔËÐÐǶÈëÔÚ.gifÎļþÖеĶñÒâ´úÂë ¡£¸Ã¹¥»÷»î¶¯ËƺõÖØÒªÕë¶ÔÓâÔ½Ãû¶ÈµÄÍøÕ¾£¬²¢ÇÒûÓÐÕë¶ÔÌØ¶¨µÄÐÐÒµ ¡£¸Ã»î¶¯·Ö·¢µÄ¶ñÒâÈí¼þ¿ÉɨÃè±¾µØÎļþÖеÄÍ´´¦¡¢´úÌæ±¾µØ.htaccessÎļþ¡¢É¨ÃèMySQL my.cnfÅäÖÃÎļþ¡¢Ö´ÐÐÔ¶³ÌÎļþ¡¢ÉÏ´«ÎļþÒÔ¼°Æô¶¯Web ShellµÈ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/new-campaign-targets-drupalgeddon2-flaw-install-malware

3.StreetEasyºÍSephoraй¶µÄÊý¾ÝÒѱ»HIBPÍøÕ¾ÊÕ¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

HIBPÒѾ­ÊÕ¼ÁËStreetEasyºÍSephoraÊý¾Ýй¶ÖеÄʧÇÔÊý¾Ý£¬Óû§Äܹ»ÔÚ¸ÃÍøÕ¾Éϲ鳭ÆäÐÅÏ¢ÊÇ·ñÒÑй¶ ¡£Æ¾¾ÝHIBPµÄ˵·¨£¬StreetEasyÔÚ2016Äê6ÔÂÔâµ½Êý¾Ýй¶£¬¹²Óнü100ÍòÓû§Êܵ½Ó°Ï죬й¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëºÍÓû§Ãû ¡£HIBP»¹°µÊ¾Sephora Southeast AsiaÔÚ2017Äê1ÔÂÔâµ½Êý¾Ýй¶£¬ÓÐ78ÍòÃû¿Í»§µÄÊý¾Ý±»µÁ£¬Ô̺¬¿Í»§µÄÉúÈÕ¡¢µç×ÓÓʼþµØÖ·¡¢ÖÖ×å¡¢ÐÔ±ð¡¢ÐÕÃûºÍÉí¶ÎÌØµãµÈÐÅÏ¢ ¡£ÕâÁ½´ÎÊÂÎñÖеÄÊý¾Ý¶¼ÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/check-if-you-are-in-the-sephora-and-streeteasy-data-breaches/

4.ÀÕË÷Èí¼þHildaCrypt¿ª·¢Õß°ä²¼ÆäÖ÷½âÃÜÃÜÔ¿

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÀÕË÷Èí¼þHildaCryptµÄ¿ª·¢ÕßÒѾö¶¨°ä²¼ÆäÖ÷½âÃÜÃÜÔ¿£¬ÀûÓøÃÃÜÔ¿¿É´´½¨½âÃÜÆ÷£¬´Ó¶øÔ®ÊÖÊܺ¦Õ߸´Ô­ÆäÎļþ ¡£±¾ÖÜ×êÑÐÈËÔ±GrujaRS·¢ÏÖÁËÒ»¸öеÄÀÕË÷Èí¼þ±äÖÖ²¢½«Æä¼ø±ðΪSTOP£¬µ«¸ÃÀÕË÷Èí¼þµÄ¿ª·¢ÕßÁªÏµÁË×êÑÐÈËÔ±²¢°µÊ¾ËüÏÖʵÉÏÊÇHildaCrypt±äÖÖ ¡£¸Ã¿ª·¢Õß°µÊ¾¸ÃÀÕË÷Èí¼þÖ»ÊdzöÓÚÓéÀÖÖ÷ÕÅ£¬²¢°ä²¼ÁËÖ÷½âÃÜÃÜÔ¿ ¡£Michael Gillespie×êÑÐÍŶÓÈ·ÈÏÁËÖ÷½âÃÜÃÜÔ¿µÄºÏ·¨ÐÔ£¬²¢°ä²¼ÏàʼûÜÆ÷ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hildacrypt-ransomware-developer-releases-decryption-keys/

5.¶íÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌBeeline870Íò¿Í»§Êý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾Ý¶íÂÞ˹ýÌåµÄ±¨Â·£¬À´×Ô¶íÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌBeelineµÄ870ÍòÃû¿Í»§Êý¾ÝÔÚÍøÉÏÏúÊۺ͹²Ïí ¡£ÕâЩÊý¾ÝÔ̺¬¾ßÌåµÄÓ×ÎÒÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢ÊÖ»úºÅÂëºÍ¼ÒÍ¥µç»°ºÅÂëµÈ ¡£BeelineÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬²¢°µÊ¾Êý¾Ýй¶²úÉúÔÚ2017Ä꣬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ2016Äê11ÔÂ֮ǰע²á¼ÒÍ¥¿í´øµÄ¶íÂÞ˹Óû§ ¡£ÆäʱBeelineÕÒµ½ÁËÊý¾Ýй¶µÄÔðÈÎÈË£¬µ«Î´¹«¿ª´ËÊÂÎñ ¡£ÕâЩÊý¾ÝÒѾ­±»ÔÚÍøÉϹ²Ïí£¬Ô̺¬ÔÚTelegramƵ·ÉϹ²Ïí ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-breach-at-russian-isp-impacts-8-7-million-customers/

6.D-Link°µÊ¾²»»á½¨¸´½üÆÚÅû¶µÄ·ÓÉÆ÷RCE·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Fortinet×êÑÐÈËÔ±Åû¶ÁËÓ°ÏìһϵÁÐD-Link·ÓÉÆ÷µÄRCE·ì϶£¬µ«D-Link°µÊ¾½«²»»á½¨¸´¸Ã·ì϶ ¡£Æ¾¾Ý×êÑÐÈËÔ±Thanh Nguyen NguyenµÄ˵·¨£¬¸Ã·ì϶£¨CVE-2019-16920£©ÓÚ2019Äê9Ô±»·¢ÏÖ£¬ÊôÓÚδ¾­Éí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ӰÏìÁËDIR-655¡¢DIR-866L¡¢DIR-652ºÍDHP-1565²úƷϵÁÐÖеÄD-Link¹Ì¼þ ¡£¸Ã·ì϶µÄCVSS v3.1¸ù±¾·ÖÊýΪ9.8£¬CVSS v2.0¸ù±¾·ÖÊýΪ10.0 ¡£D-Link°µÊ¾ÓÉÓÚ²úÆ·ÒÑ´ïµ½ÐÔÃüÖÜÆÚ£¨EOL£©£¬Òò¶ø²»»á°ä²¼½¨¸´²¹¶¡ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/d-link-routers-contain-remote-code-execution-vulnerability/