΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£© £»Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ

°ä²¼¹¦·ò 2020-03-11

1.΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©£¬ÉÐÎÞ½¨¸´²¹¶¡


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©µÄÐÅÏ¢ÔÚÍøÉÏÒâ±íй¶£¬Ä¿Ç°ÉÐδ°ä²¼¸Ã·ì϶µÄÈκμ¼Êõϸ½Ú£¬µ«Cisco TalosºÍFortinetµÄÍøÕ¾ÉÏÒѰ䲼Á˸÷ì϶µÄ¼ò¶Ì¸ÅÊö ¡£¸Ã·ì϶δÔ̺¬ÔÚ3Եݲȫ¸üÐÂÖУ¬²¢ÇÒÉв»Ã÷ÏÔºÎʱ½¨¸´ ¡£Æ¾¾ÝFortinetµÄ˵·¨£¬¸Ã·ì϶±»ÃèÊöΪ¡°Microsoft SMB·þÎñÆ÷ÖеĻº³åÇøÒç¶Âí½Å¡±£¬²¢»ñµÃÁË×î¸ßÑϳÁµÈ¼¶£¬¡°Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÀûÓ÷¨Ê½µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë ¡£¡±Ë¼¿ÆTalos°µÊ¾¸Ã·ì϶ʹϵͳÒ×Ôâ¡°È䳿»¯¡±¹¥»÷£¬ÕâÒâζ×ÅÔÚÊܺ¦ÕßÖ®¼äµÄ×ªÒÆºÜÈÝÒ× ¡£¸Ã·ì϶½öÓ°ÏìSMBv3£¬ÊÜÓ°ÏìµÄϵͳÔ̺¬Windows 10 v1903¡¢Windows 10 v1909¡¢Windows Server v1903ºÍWindows Server v1909 ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-about-new-smb-wormable-bug-leak-in-microsoft-patch-tuesday-snafu/


2.Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Å·ÖÞµçÁ¦ÔËÓªÉÌͬÃË£¨ENTSO-E£©ÔÚÒ»·Ý¼ò¶ÌµÄÉêÃ÷ÖаµÊ¾£¬½üÆÚÆä°ì¹«ÍøÂçÔâµ½ºÚ¿ÍÈëÇÖ ¡£ÓÉÓÚ¸Ã°ì¹«ÍøÂ粢δÏνӵ½ÈκÎÔËÓªÖеĵçÁ¦´«Êäϵͳ£¬ÕâÒâζ׏¥»÷½öÏÞÓÚITϵͳ£¬Ã»ÓÐÓ°Ïì¹Ø¼ü½ÚÔìϵͳ ¡£ENTSO-E×ܲ¿Î»ÓÚ²¼Â³Èû¶û£¬ÓÉ35¸öÅ·ÖÞ¹ú¶ÈµÄ42¼ÒµçÍøÔËÓªÉÌ×é³É ¡£ENTSO-E°µÊ¾ÒѾ­½øÐÐÁË·çÏÕÆÀ¹ÀºÍÔì¶©ÁËÓ¦¼±´òË㣬ÒÔÏ÷¼õ½øÒ»²½¹¥»÷µÄ·çÏÕºÍÓ°Ï죬µ«Ã»ÓÐй©ÓëÈëÇÖºÎʱÆðÍ·ÒÔ¼°Ë­¿ÉÄܶԹ¥»÷ÕÆ¹ÜÓйصľßÌåÐÅÏ¢ ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/european-entso-breach-fingrid/


3.¶ñÒâÈí¼þбäÖÖ¿ÉÈÆ¹ýChrome 80ÖеÄcookie¼ÓÃÜËã·¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹È¸èÓÚ2Ô³õÍÆ³öÁËChrome 80£¬²¢ÔÚÆäÖжÔcookieºÍÃÜÂëÔö³¤ÁËAES-256¼ÓÃÜËã·¨½øÐб £»¤£¬Ä¿Ç°ÒÑÓÐÖÁÉÙËĸö¶ñÒâÈí¼þÍÆ³öÁË¿ÉÈÆ¹ý¸Ã¼ÓÃܵÄбäÖÖ£¬Ô̺¬ÐÅÏ¢ÇÔȡľÂíKPot¡¢Raccoon¡¢RedlineÒÔ¼°AZORult ¡£ÔÚChrome 80֮ǰ£¬cookieºÍÃÜÂë¶¼ÊÇͨ¹ýWindows DPAPI½øÐмÓÃÜ£¬ÔÚChrome 80Ö®ºó£¬Êý¾ÝÊ×ÏÈͨ¹ýAES¼ÓÃÜ£¬¶øºóÀûÓÃCrypProtectData DPAPI¶ÔÃÜÔ¿½øÐмÓÃÜ£¬Òò¶ø¿Éͨ¹ýCryptUnprotectDataÄæ×ª¸Ã¹ý³Ì»ñµÃAES-256µÄÃÜÔ¿ ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-unfazed-by-google-chromes-new-password-cookie-encryption/


4.¹¥»÷ÕßÀûÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ç÷Ïò¿Æ¼¼°²È«×êÑÐÈËÔ±¹Û²ìµ½¹¥»÷ÕßÀûÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹ ¡£¹¥»÷ÕßÖØÒªÒÀ¸½´øÓÐËæ»úÌìÉúµÄ·þÎñÆ÷Ö÷»úÃûµÄ·Ç¹Ù·½ÍøÒ³À´·Ö·¢¸ÃÒøÐÐľÂí£¬¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶ÔÎÞ·¨½Ó¼ûGoogle PlayÉ̵êµÄAndroidÓû§ÒÔ¼°ÄÇЩƫ²îÓÚËÑË÷Google¹Ù·½AndroidÊг¡Éϲ»³ÉÓÃAPPµÄÓû§ ¡£¸Ã¶ñÒâÈí¼þÃûΪ¡°§å§ã§ä§Ñ§ß§à§Ó§Ü§Ñ¡±£¨¶íÓï¡°ÉèÖá±£©£¬Ê¹ÓÃGoogle Play logoÓÕʹÓû§ÏÂÔØºÍ×°Öã¬ËüÒªÇóÊܺ¦ÕßÊÚÓèÆäÖÎÀíÔ±ÌØÈ¨£¬Ô̺¬½Ó¼ûSMS¶ÌÐŵÄÄÜÁ¦ÒÔ´Ó¶íÂÞË¹ÒøÐзþÎñ½Ó¹ÜÈ·È϶ÌÐÅ ¡£Geost³õ´Î³öÏÖÓÚ2019Äê10Ô£¬Æäʱ¸ÃľÂíϰȾÁ˳¬¹ý80ÍòÃûÊܺ¦Õß ¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/news/geost-banking-trojan-targets-russian-banks-via-unofficial-webpages/?web_view=true


5.˼¿ÆTalosÅû¶WAGO e!COCKPITÖеĶà¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿ÆTalosÅû¶WAGO e!COCKPIT²úÆ·ÖеĶà¸ö·ì϶ ¡£e!COCKPITÊÇÒ»¸ö¼¯³É¿ª·¢»·¾³£¬Ö¼ÔÚ¼Ó¿ì×Ô¶¯»¯¹¤×÷ÒÔ¼°»úеºÍÏîÖ÷ÕÅÆô¶¯¿ìÂÊ ¡£e!COCKPITÈí¼þÓë·ÖÆçµÄ×Ô¶¯»¯½ÚÔìÆ÷£¨Ô̺¬PFC100ºÍPFC200£©´æÔÚ½Ó¿Ú£¬ËüÃÇÖеķì϶ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐи÷Àà¶ñÒâ»î¶¯£¬Ô̺¬ºÅÁî×¢Èë¡¢ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐÐ ¡£ÆëÈ«·ì϶ºÍÊÜÓ°Ïì¹Ì¼þ°æ±¾ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó ¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/03/wago-vulnerability-spotlight-march-2020.html


6.ÃÀComcast Xfinityй¶½ü20Íò¸¶·Ñ¿Í»§ÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úComcast XfinityÔÚ¹«Ë¾µÄÔÚÏßĿ¼ÖÐй¶Á˽ü20Íò¿Í»§µÄ¾ßÌåÐÅÏ¢ ¡£ÕâЩ¿Í»§ÏòComcast XfinityÖ§¸¶ÁËÓöÈ£¬ÒÔ½«ÆäÐÕÃû¡¢µç»°ºÅÂëºÍµØÖ·µÈÓ×ÎÒ¾ßÌåÐÅÏ¢´æ´¢ÔÚ¹«¹²Êý¾Ý¿âÖ®±í£¬µ«ComcastÔÚÆäecolisting.comÍøÕ¾ÉÏ»¹ÊÇÁгöÁËËûÃǵÄÐÅÏ¢ ¡£ComcastÔÚ2ÔÂ5ÈÕ°µÊ¾£¬¸Ã¹«Ë¾ÔÚÒâʶµ½ÃýÎóºóÂíÉÑþ³ØýÁËÃô¸ÐÐÅÏ¢£¬²¢ÇÒÕâЩÐÅÏ¢ÔÚÍøÉ϶³öµÄ¹¦·òÓ×ÓÚÒ»¸öÔ ¡£Ä¿Ç°¸ÃÍøÕ¾ÏÔʾXfinityÓïÒô·þÎñ½«²»ÔÙÌṩĿ¼ÁбíÖ°ÄÜ ¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.grahamcluley.com/comcast-xfinity-200000-customers-privacy/