SOS Online Backupй¶1.35Òڱʼͼ£»GoDaddyÔ±¹¤Ôâ´¹µö¹¥»÷£¬¿Í»§ÓòÉèÖÃȨÏÞ±»´Û¸Ä
°ä²¼¹¦·ò 2020-04-021.½©Ê¬ÍøÂçVollgarÀûÓÃMSSQL·þÎñÆ÷ÍÚ¿ó£¬ÒÑ»îÔ¾½üÁ½Äê
Guardicore×êÑÐÈËÔ±·¢ÏÖ×Ô2018Äê5ÔÂÒÔÀ´£¬½©Ê¬ÍøÂçVollgarÒ»ÏòÔÚÕë¶ÔMicrosoft SQL£¨MSSQL£©Êý¾Ý¿âÌáÒ鱩Á¦¹¥»÷£¬ÊÔͼÊÕÊÜ·þÎñÆ÷²¢×°ÖÃMoneroºÍVollar¿ó¹¤¡£VollgarÔÚ´Óǰ¼¸ÖÜÄÚÿÌì³É¹¦Ï°È¾Á˽ü2000-3000̨Êý¾Ý¿â·þÎñÆ÷£¬Ç±ÔÚµÄÊܺ¦Õß±ðÀëÀ´×ÔÖйú¡¢Ó¡¶È¡¢ÃÀ¹ú¡¢º«¹úºÍÍÁ¶úÆäµÄÒ½ÁƱ£½¡¡¢º½¿Õ¡¢IT&µçÐÅÒÔ¼°¸ßµµ½ÌÓýÐÐÒµ¡£¹¥»÷ÕßµÄÓÐЧºÉÔØÊÇSQLAGENTIDC.exe»òSQLAGENTVDC.exe£¬ËüÊ×ÏÈɱËÀÒ»³¤´®¹ý³Ì£¬ÒÔÈ·±£Õ¼ÓÐ×î´óÊýÁ¿µÄϵͳ×ÊÔ´ºÍ½â³ýÆäËü¹¥»÷ÕߵĻ£¬Ëü»¹³äÈÎ·ÖÆçRATÒÔ¼°»ùÓÚXMRigµÄ¼ÓÃܿ󹤵ÄͶµÝÆ÷¡£×êÑÐÈËÔ±»¹°ä²¼ÁËÒ»¸ö¾ç±¾£¬ÒÔÔ®ÊÖϵͳÖÎÀíÔ±¼ì²âÆäMSSQL·þÎñÆ÷ÊÇ·ñÒÑϰȾ´ËÍþв¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/backdoor-.html
2.GoDaddyÔ±¹¤Ôâ´¹µö¹¥»÷£¬¿Í»§ÓòÉèÖÃȨÏÞ±»´Û¸Ä
ƾ¾ÝKrebsOnSecurityµÄ±¨Â·£¬È«Çò×î´óµÄÓòÃû×¢²áÉÌGoDaddy.comµÄÒ»Ãû¿Í»§·þÎñÔ±¹¤Ôâµ½´¹µö¹¥»÷£¬¸ÃÊÂÎñʹ¹¥»÷Õß¿ÉÄܲ鿴ºÍÅú¸Ä¹Ø¼ü¿Í»§µÄ¼Í¼£¬Ô̺¬6Ãû¿Í»§£¨ÀýÈçÂòÂô¾¼ÍÍøÕ¾escrow.com£©µÄÓòÉèÖýӼûȨÏÞ¡£escrow.comÊ×ϯִÐйÙMatt Barrie°µÊ¾£¬ÔÚÊÂÎñ²úÉúÆÚ¼äºÚ¿Í½«escrow.comµÄDNS¼Í¼¸ü¸ÄΪָÏòµÚÈý·½Web·þÎñÆ÷¡£escrow.com½«ÔÚ½«À´¼¸ÌìÄÚ¹²ÏíÓë´ËÊÂÎñÓйصĸü¶àÐÅÏ¢£¬µ«BarrieÇ¿µ÷´ËÊÂÎñûÓзÛËéescrow.comϵͳ£¬Ò²²»»á°Ü»µ¿Í»§Êý¾Ý¡¢×ʽð»òÓòÃû¡£GoDaddyÈϿɹ«Ë¾ÓÚ3ÔÂ30ÈÕÊÕµ½Óйؿͻ§ÓòÃûÔâ·ê°²È«ÊÂÎñµÄ¾¯±¨£¬²¢°µÊ¾Áí±í5Ãû¿Í»§Êܵ½¡°Ç±ÔÚ¡±Ó°Ï죬µ«Ã»ÓÐй©¸ü¶à¾ßÌåÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://krebsonsecurity.com/2020/03/phish-of-godaddy-employee-jeopardized-escrow-com-among-others/
3.×êÑÐÈËÔ±°ä²¼SMBGhost·ì϶£¨CVE-2020-0796£©µÄPoC
×êÑÐÈËÔ±°ä²¼Õë¶ÔWindows SMBGhost·ì϶£¨CVE-2020-0796£©µÄPoC£¬¿ÉÀûÓø÷ì϶½øÐб¾µØÌØÈ¨Éý¼¶¡£Æ¾¾Ý°²È«³§ÉÌZecOpsµÄÃèÊö£¬¸Ã·ì϶ÊÇÕûÊýÒç³öÃýÎó£¬Ëü²úÉúÔÚsrv2.sys SMB·þÎñÆ÷Çý¶¯·¨Ê½µÄSrv2DecompressDataº¯ÊýÖУ¬×êÑÐÈËÔ±°ä²¼µÄPoC¿ÉÀûÓø÷ì϶½«ÌØÈ¨Éý¼¶µ½SYSTEM¡£±ØÒª°ÑÎȵÄÊÇ£¬¸Ã·ì϶ÀûÓýöÏÞÓÚÖÐµÈÆëÈ«ÐÔ¼¶±ð£¬ÓÉÓÚËüÒÀÀµÓÚ½ÏµÍÆëÈ«ÐÔ¼¶±ð²»³ÉÓõÄAPIŲÓá£Î¢Èí°ä²¼ÁËÕë¶ÔWindows 10°æ±¾1903ºÍ1909ºÍWindows Server 2019°æ±¾1903ºÍ1909µÄKB4551762¸üÐÂÀ´½¨¸´¸Ã·ì϶£¬½¨ÒéÓû§¾¡¿ìÀûÓøøüС£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/100882/hacking/cve-2020-0796-poc-rce.html
4.Rank Math SEO²å¼þ·ì϶ӰÏ쳬¹ý20Íò¸öWordPressÍøÕ¾
°²È«³§ÉÌDefiant»ã±¨³Æ£¬Rank Math SEO²å¼þÖеÄÒ»¸ö¹Ø¼ü·ì϶¿ÉÄÜÔÊÐí¹¥»÷Õß½«ÖÎÀíÔ±Ëø¶¨ÔÚ×Ô¼ºµÄÍøÕ¾Ö®±í¡£¸Ã·ì϶µÄCVSSÆÀ·ÖΪ10·Ö£¬Ó°ÏìÁ˲å¼þ¸üÐÂÌû×ÓÔªÊý¾ÝµÄÖ°ÄÜ¡£¾ßÌåÀ´Ëµ£¬¸Ã²å¼þ×¢²áÁËÒ»¸öREST-API¶Ëµã£¨rankmath/v1/updateMeta£©£¬µ«ÓÉÓÚ²»×ãÓÃÓÚÖ°Äܲ鳵ÄPermission_callback£¬Ê¹Æä¶³ö¸ø¹¥»÷Õß¡£¶ËµãʹÓÃupdate_metadataº¯Êýɾ³ý»ò¸üÐÂÌû×Ó¡¢ÆÀÂÛºÍÊõÓïµÄÔªÊý¾Ý£¬µ«Ò²¿ÉÒÔΪÓû§¸üÐÂÔªÊý¾Ý£¬´Ó¶øµ¼Ö´˷ì϶¡£WordPressÖеÄÓû§È¨ÏÞ´æ´¢ÔÚusermeta±íÖУ¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓô˷ì϶ÊÚÓèÈκÎÒÑ×¢²áÓû§ÖÎÀíȨÏÞ£¬ÉõÖÁÆëÈ«²Ã³·ÏÖÓÐÖÎÀíÔ±µÄÌØÈ¨¡£¸Ã²å¼þµÄ×°ÖÃÁ¿³¬¹ý20Íò£¬¿ª·¢ÍŶÓÒѾÔÚа汾10.0.41Öн¨¸´ÁË·ì϶£¬Ç¿ÁÒ½¨ÒéÓû§¸üС£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/critical-flaw-seo-plugin-exposes-many-wordpress-sites-attacks
5.Zoom¿Í»§¶ËÒ×ÊÜUNCõè¾¶×¢Èë¹¥»÷£¬¿ÉÇÔÈ¡WindowsÍ´´¦
Zoom Windows¿Í»§¶ËµÄ̸ÌìÖ°ÄÜÒ×ÊÜUNCõè¾¶×¢Èë¹¥»÷£¬¹¥»÷Õß¿ÉÄÜÀûÓô˷ì϶ÇÔÈ¡Óû§µÄWindowsÍ´´¦¡£ÔÚʹÓÃZoom¿Í»§¶Ëʱ£¬Óë»áÈËÔ±Äܹ»Í¨¹ý̸Ìì½çÃæ·¢ËÍÎı¾ÐÂÎÅÀ´»¥¶©»¥»»£¬µ«ËùÓз¢Ë͵ÄURL¶¼½«×ª»»Îª³¬Á´½Ó£¬ÒÔ±ãÆäËû³ÉÔ±Äܹ»µ¥»÷ËüÃÇÔÚÆäĬÈÏä¯ÀÀÆ÷Öдò¿ªÍøÒ³¡£ÎÊÌâÊǰ²È«×êÑÐÔ±@_g0dmode·¢ÏÖZoom¿Í»§¶Ë»¹½«WindowsÍøÂçUNCõ辶Ҳת»»Îª¿Éµ¥»÷Á´½Ó£¬ÈôÊÇÓû§µ¥»÷¸ÃÁ´½Ó£¬ÔòWindows½«³¢ÊÔʹÓÃSMBÎļþ¹²ÏíºÍ̸Ïνӵ½Ô¶³ÌÕ¾µã£¬²¢ÔÚĬÈÏÇé¿öÏ·¢ËÍÓû§µÄµÇ¼ÃûºÍËûÃǵÄNTLMÃÜÂë¹þÏ££¬¹¥»÷ÕßÄܹ»ÆÆ½â¸Ã¹þÏ£»ñÈ¡Óû§µÄÃÜÂë¡£³ýÁËÇÔÈ¡WindowsÍ´´¦±í£¬UNC×¢ÈëÒ²¿ÉÓÃÓÚÔÚ±¾µØÍÆËã»úÉÏÆô¶¯·¨Ê½¡£Zoom°µÊ¾ÒѾÊÕµ½´Ë·ì϶µÄ֪ͨ£¬µ«ÓÉÓÚ´Ë·ì϶ÉÐ佨¸´£¬½¨ÒéÓû§Ê¹ÓôúÌæµÄÊÓÆµ»áÒéÈí¼þ»òÔÚWebä¯ÀÀÆ÷ÖÐʹÓÃZoom°ü°ìʹÓÿͻ§¶Ë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2020/04/zoom-windows-password.html
6.ÔÚÏß±¸·Ý¹«Ë¾SOS Online Backupй¶1.35Òڱʼͼ
vpnMentor·¢ÏÖ¼ÓÀû¸£ÄáÑÇÖÝÔÚÏß±¸·Ý¹«Ë¾SOS Online BackupµÄÒ»¸ö¿É¹«¿ª½Ó¼ûµÄÊý¾Ý¿âй¶³¬¹ý1.35Òڱʼͼ¡£¸ÃÊý¾Ý¿âÖÐÔ̺¬½ü70GBÓëÓû§ÕÊ»§ÓйصÄÔªÊý¾Ý£¬ÕâÔ̺¬½á¹¹¡¢²Î¿¼¡¢ÃèÊöÐÔºÍÖÎÀíÐÔÔªÊý¾Ý£¬º¸ÇÁËSOSÔÆ·þÎñµÄºÜ¶à·½Ãæ¡£´Ë±í£¬Â¶³öµÄÊý¾Ý¿âÖл¹Ô̺¬Ó×ÎÒ¼ø±ðÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÒµÎñ¾ßÌåÐÅÏ¢£¨Õë¶Ô¹«Ë¾¿Í»§£©ºÍÓû§Ãû¡£¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩÊý¾ÝÕë¶ÔSOS¼°Æä¿Í»§ÌáÒé¸÷Ààڲƹ¥»÷¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/secure-backup-company-leaks-135/


¾©¹«Íø°²±¸11010802024551ºÅ