¶íÂÞ˹ISP Beeline 870Íò¿Í»§Êý¾Ýй¶£»D-Link°µÊ¾²»»á½¨¸´Â·ÓÉÆ÷RCE£»HildaCrypt¿ª·¢Õß°ä²¼½âÃÜÃÜÔ¿
°ä²¼¹¦·ò 2019-10-08
ºÉÀ¼¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©ÔÚÒ»·Ý»ã±¨ÖаµÊ¾ÐµÄDNS´«ÊäºÍ̸½«Ê¹DNS¼à¿ØÔ½·¢¸´ÔÓ»¯ºÍÔ½·¢ÄÑÌâ¡£NCSCÚ¹Êͳƣ¬ÐµÄDNS´«ÊäºÍ̸ʹ¼à¿Ø»òÅú¸ÄDNSÒªÇó±äµÃÔ½·¢ÄÑÌ⣬Õâ¶ÔÓÚµ±½ñ²»ÊÜÐÅÀµµÄÍøÂçÊÇÓÐÒæµÄ¡£Í¬Ê±Ô½À´Ô½¶àµØÑ¡È¡ÐµÄDNS´«ÊäºÍ̸£¬ÀýÈç»ùÓÚTLSµÄDNSºÍ̸£¨DoT£©ºÍ»ùÓÚHTTPSµÄDNSºÍ̸£¨DoH£©¿ÉÄÜʹ×éÖ¯µÄ°²È«½ÚÔìʧЧ£¬Õâ»áµ¼ÖÂÄÚ²¿×ÊÔ´¶¨Ãû¶³ö»òÏνӶϿªµÈ¸ºÃæÓ°Ïì¡£ÕâЩ¸ºÃæÓ°ÏìºÜÄÑÔÚÍøÂç¼¶±ð»º½â£¬²¢ÇÒ±ØÒªÔÚDNS»ù´¡ÉèÊ©ºÍµ¥¸öÉ豸ÉÏ»º½â¡£GoogleºÍMozilla¶¼ÔÚ½üÆÚΪÆää¯ÀÀÆ÷£¨ChromeºÍFirefox£©½øÐÐDoH²âÊÔ¡£
ÔÎÄÁ´½Ó£º
https://english.ncsc.nl/publications/factsheets/2019/oktober/2/factsheet-dns-monitoring-will-get-harder2.ºÚ¿ÍÈÔÔÚÀûÓÃÒ»Äêǰ½¨¸´µÄDrupalgeddon2·ì϶·Ö·¢¶ñÒâÈí¼þ
×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÈÔÔÚ»ý¼«ÀûÓÃÒ»Äêǰ½¨¸´µÄDrupalgeddon2·ì϶·Ö·¢¶ñÒâÈí¼þ¡£¸Ã·ì϶µÄCVE±àºÅΪCVE-2018-7600£¬Ó°ÏìÁËDrupal°æ±¾6¡¢7ºÍ8£¬²¢ÒÑÓÚ2018Äê3Ô±»½¨¸´¡£Akamai°²È«×êÑÐÔ±Larry W. Cashdollar·¢Ïָ÷ì϶ÒÀÈ»ÊÇ×î½ü¹Û²ìµ½µÄ¶ñÒâ»î¶¯µÄÖ¸±ê£¬¹¥»÷ÕßÊÔIJÀûÓø÷ì϶ÔÚδ´ò²¹¶¡µÄϵͳÉÏÔËÐÐǶÈëÔÚ.gifÎļþÖеĶñÒâ´úÂë¡£¸Ã¹¥»÷»î¶¯ËƺõÖØÒªÕë¶ÔÓâÔ½Ãû¶ÈµÄÍøÕ¾£¬²¢ÇÒûÓÐÕë¶ÔÌØ¶¨µÄÐÐÒµ¡£¸Ã»î¶¯·Ö·¢µÄ¶ñÒâÈí¼þ¿ÉɨÃè±¾µØÎļþÖеÄÍ´´¦¡¢´úÌæ±¾µØ.htaccessÎļþ¡¢É¨ÃèMySQL my.cnfÅäÖÃÎļþ¡¢Ö´ÐÐÔ¶³ÌÎļþ¡¢ÉÏ´«ÎļþÒÔ¼°Æô¶¯Web ShellµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/new-campaign-targets-drupalgeddon2-flaw-install-malware3.StreetEasyºÍSephoraй¶µÄÊý¾ÝÒѱ»HIBPÍøÕ¾ÊÕ¼
HIBPÒѾÊÕ¼ÁËStreetEasyºÍSephoraÊý¾Ýй¶ÖеÄʧÇÔÊý¾Ý£¬Óû§Äܹ»ÔÚ¸ÃÍøÕ¾ÉÏ²é³ÆäÐÅÏ¢ÊÇ·ñÒÑй¶¡£Æ¾¾ÝHIBPµÄ˵·¨£¬StreetEasyÔÚ2016Äê6ÔÂÔâµ½Êý¾Ýй¶£¬¹²Óнü100ÍòÓû§Êܵ½Ó°Ï죬й¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÐÕÃû¡¢ÃÜÂëºÍÓû§Ãû¡£HIBP»¹°µÊ¾Sephora Southeast AsiaÔÚ2017Äê1ÔÂÔâµ½Êý¾Ýй¶£¬ÓÐ78ÍòÃû¿Í»§µÄÊý¾Ý±»µÁ£¬Ô̺¬¿Í»§µÄÉúÈÕ¡¢µç×ÓÓʼþµØÖ·¡¢ÖÖ×å¡¢ÐÔ±ð¡¢ÐÕÃûºÍÉí¶ÎÌØµãµÈÐÅÏ¢¡£ÕâÁ½´ÎÊÂÎñÖеÄÊý¾Ý¶¼ÒÑÔÚ°µÍøÂÛ̳ÉÏÏúÊÛ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/check-if-you-are-in-the-sephora-and-streeteasy-data-breaches/4.ÀÕË÷Èí¼þHildaCrypt¿ª·¢Õß°ä²¼ÆäÖ÷½âÃÜÃÜÔ¿
ÀÕË÷Èí¼þHildaCryptµÄ¿ª·¢ÕßÒѾö¶¨°ä²¼ÆäÖ÷½âÃÜÃÜÔ¿£¬ÀûÓøÃÃÜÔ¿¿É´´½¨½âÃÜÆ÷£¬´Ó¶øÔ®ÊÖÊܺ¦Õ߸´ÔÆäÎļþ¡£±¾ÖÜ×êÑÐÈËÔ±GrujaRS·¢ÏÖÁËÒ»¸öеÄÀÕË÷Èí¼þ±äÖÖ²¢½«Æä¼ø±ðΪSTOP£¬µ«¸ÃÀÕË÷Èí¼þµÄ¿ª·¢ÕßÁªÏµÁË×êÑÐÈËÔ±²¢°µÊ¾ËüÏÖʵÉÏÊÇHildaCrypt±äÖÖ¡£¸Ã¿ª·¢Õß°µÊ¾¸ÃÀÕË÷Èí¼þÖ»ÊdzöÓÚÓéÀÖÖ÷ÕÅ£¬²¢°ä²¼ÁËÖ÷½âÃÜÃÜÔ¿¡£Michael Gillespie×êÑÐÍŶÓÈ·ÈÏÁËÖ÷½âÃÜÃÜÔ¿µÄºÏ·¨ÐÔ£¬²¢°ä²¼ÏàʼûÜÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hildacrypt-ransomware-developer-releases-decryption-keys/
5.¶íÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌBeeline870Íò¿Í»§Êý¾Ýй¶
ƾ¾Ý¶íÂÞ˹ýÌåµÄ±¨Â·£¬À´×Ô¶íÂÞ˹»¥ÁªÍø·þÎñÌṩÉÌBeelineµÄ870ÍòÃû¿Í»§Êý¾ÝÔÚÍøÉÏÏúÊۺ͹²Ïí¡£ÕâЩÊý¾ÝÔ̺¬¾ßÌåµÄÓ×ÎÒÐÅÏ¢£¬ÈçÐÕÃû¡¢µØÖ·¡¢ÊÖ»úºÅÂëºÍ¼ÒÍ¥µç»°ºÅÂëµÈ¡£BeelineÈ·ÈÏÁËÕâÒ»ÊÂÎñ£¬²¢°µÊ¾Êý¾Ýй¶²úÉúÔÚ2017Ä꣬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ2016Äê11ÔÂ֮ǰע²á¼ÒÍ¥¿í´øµÄ¶íÂÞ˹Óû§¡£ÆäʱBeelineÕÒµ½ÁËÊý¾Ýй¶µÄÔðÈÎÈË£¬µ«Î´¹«¿ª´ËÊÂÎñ¡£ÕâЩÊý¾ÝÒѾ±»ÔÚÍøÉϹ²Ïí£¬Ô̺¬ÔÚTelegramƵ·ÉϹ²Ïí¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/data-breach-at-russian-isp-impacts-8-7-million-customers/
6.D-Link°µÊ¾²»»á½¨¸´½üÆÚÅû¶µÄ·ÓÉÆ÷RCE·ì϶
Fortinet×êÑÐÈËÔ±Åû¶ÁËÓ°ÏìһϵÁÐD-Link·ÓÉÆ÷µÄRCE·ì϶£¬µ«D-Link°µÊ¾½«²»»á½¨¸´¸Ã·ì϶¡£Æ¾¾Ý×êÑÐÈËÔ±Thanh Nguyen NguyenµÄ˵·¨£¬¸Ã·ì϶£¨CVE-2019-16920£©ÓÚ2019Äê9Ô±»·¢ÏÖ£¬ÊôÓÚδ¾Éí·ÝÑéÖ¤µÄºÅÁî×¢Èë·ì϶£¬¸Ã·ì϶ӰÏìÁËDIR-655¡¢DIR-866L¡¢DIR-652ºÍDHP-1565²úƷϵÁÐÖеÄD-Link¹Ì¼þ¡£¸Ã·ì϶µÄCVSS v3.1¸ù±¾·ÖÊýΪ9.8£¬CVSS v2.0¸ù±¾·ÖÊýΪ10.0¡£D-Link°µÊ¾ÓÉÓÚ²úÆ·ÒÑ´ïµ½ÐÔÃüÖÜÆÚ£¨EOL£©£¬Òò¶ø²»»á°ä²¼½¨¸´²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/d-link-routers-contain-remote-code-execution-vulnerability/


¾©¹«Íø°²±¸11010802024551ºÅ