ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ38ÖÜ

°ä²¼¹¦·ò 2018-09-25
 Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö

2018Äê09ÔÂ17ÈÕÖÁ23ÈÕ¹²ÊÕ¼°²È«·ì϶55¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache SpamAssassin meta ruleÓï·¨ËÁÒâ´úÂëÖ´Ðзì϶£»Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´Ðзì϶£»Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´Ðзì϶£»Adobe AcrobatºÍReader CVE-2018-12848Ô½½çд·ì϶£»Apple iOS Core Bluetooth  CVE-2018-4330ËÁÒâ´úÂëÖ´Ðзì϶¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӳƳ¬¹ý20ÒŲ́É豸ÈÔÊÜBlueBorne·ì϶µÄÓ°Ï죻Ӣ¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ì죻MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û£»GovPayNet¹ÙÍø´æÔÚ·ì϶£¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶£»ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£

¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1. Apache SpamAssassin meta ruleÓï·¨ËÁÒâ´úÂëÖ´Ðзì϶


Apache SpamAssassin meta ruleÓï·¨´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://lists.apache.org/thread.html/7f6a16bc0fd0fd5e67c7fd95bd655069a2ac7d1f88e42d3c853e601c@%3Cannounce.apache.org%3E


2. Rockwell Automation CIPÕ»Òç³ö´úÂëÖ´Ðзì϶


RSLinx Classic´¦ÖÃÌØÊâµÄCIP±¨ÎÄ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇóµ½44818¶Ë¿Ú£¬¿Éʹϵͳ±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1075712


3. Adobe ColdFusion CVE-2018-15965·´ÐòÁл¯´úÂëÖ´Ðзì϶


Adobe ColdFusion·´ÐòÁл¯´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html


4. Adobe AcrobatºÍReader CVE-2018-12848Ô½½çд·ì϶


Adobe AcrobatºÍReader´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://helpx.adobe.com/security/products/acrobat/apsb18-34.html


5. Apple iOS Core Bluetooth  CVE-2018-4330ËÁÒâ´úÂëÖ´Ðзì϶


Apple iOS Core Bluetooth×é¼þ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://support.apple.com/en-us/HT208848

 Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢×êÑÐÍŶӳƳ¬¹ý20ÒŲ́É豸ÈÔÊÜBlueBorne·ì϶µÄÓ°Ïì

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Armis Labs×êÑÐÍŶӳƳ¬¹ý20ÒÚÉ豸ÈÔÊÜÒ»ÄêǰÅû¶µÄBlueBorne·ì϶µÄÓ°Ïì¡£BlueBorneÔ̺¬9¸öÀ¶ÑÀ·ì϶£¬ÓÚ2017Äê9Ô±»Åû¶²¢Ëæºó½øÐн¨¸´¡£µ½Ò»ÄêºóµÄ½ñÌ죬ԼÈý·ÖÖ®¶þµÄÊÜÓ°ÏìÉ豸ÒѾ­½øÐÐÁ˸üУ¬µ«ÈÔÓдóÁ¿µÄ·þÎñÆ÷¡¢ÖÇÄÜÍó±í¡¢Ò½ÁÆÉ豸ºÍ¹¤ÒµÉ豸µÈ»¹Î´½øÐн¨¸´£¬Ô̺¬7.68ÒŲ́LinuxÉ豸¡¢7.34ÒŲ́ÔËÐÐAndroid5.1¼°¸üÔç°æ±¾µÄÉ豸¡¢2.61ÒŲ́ÔËÐÐAndroid6¼°¸üÔç°æ±¾µÄÉ豸¡¢2ÒŲ́WindowsÉ豸ÒÔ¼°5000Íǫ̀ÔËÐÐiOS9.3.5¼°¸üÔç°æ±¾µÄÉ豸¡£


Ô­ÎÄÁ´½Ó£º
https://www.armis.com/blueborne-one-year-later/


2¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑÖÕ³¡·þÎñÁ½Ìì¡£¸Ã»ú³¡µÄ½²»°È˰µÊ¾º½°à²»ÊÜÓ°Ï죬µ«±ØÐëʹÓÃÓ¦¼±´ëÊ©ºÍÊÖ¶¯µÄÁ÷³Ì£¬Ô̺¬°×°åºÍ¼ÇºÅ±ÊµÈÀ´°ü°ìÏÔʾÆÁ¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬¶øÊÇËæ»úµÄ¹¥»÷¡£¸Ã»ú³¡ÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚ³ÁÐÂÉÏÏß֮ǰÊǰ²È«µÄ¡£


Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html


3¡¢MongoDBÅäÖÃÃýÎóµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹«¿ª½Ó¼û


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄMongoDB£¬¸ÃÊý¾Ý¿âÖÐÔ̺¬Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£Êý¾Ý¿âµÄ´óÓ×Ϊ43.5GB£¬Ô̺¬ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØÖ·¡¢ÓÊÕþ±àÂëºÍ¾Óס³ÇÊеÈÓ×ÎÒÐÅÏ¢¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬Ä¿Ç°»¹²»ÖªÂ·¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£


Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/


4¡¢GovPayNet¹ÙÍø´æÔÚ·ì϶£¬³¬¹ý1400ÍòÓû§¼Í¼ÒÉй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ΪÃÀ¹úÖݵ±¾ÖºÍ´¦Ëùµ±¾ÖÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com´æÔÚ°²È«·ì϶£¬³¬¹ý1400ÍòÓû§µÄÓ×ÎÒÐÅÏ¢ÒÉй¶¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öµ±¾Ö»ú¹¹Ìṩ·þÎñ£¬¹«ÃñÄܹ»Í¨¹ýËüÀ´Ö§¸¶·£¿î¡¢ÅÉ˾·ÑºÍÕ˵¥µÈ¡£Æ¾¾ÝBrian KrebsµÄ˵·¨£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´°¤´Î±àºÅµÄ£¬¹¥»÷ÕßÄܹ»Í¨¹ýÅú¸ÄURLÖеÄÊý×ÖÀ´²é¿´ÆäËüÈ˵ļͼ¡£ÕâЩ¼Í¼Ô̺¬Óû§µÄÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¸Ã¹«Ë¾°µÊ¾ÒÑÔÚÖÜÄ©½¨¸´ÁËÕâÒ»ÎÊÌâ¡£


Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/government-payment-service-exposes/


5¡¢ÃÀ¹ú¹úÎñÔºµç×ÓÓʼþϵͳÔâºÚ¿Í¹¥»÷£¬Ô¼1%Ô±¹¤µÄÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú¹úÎñÔºµÄµç×ÓÓʼþϵͳÔâµ½ºÚ¿Í¹¥»÷£¬ÉÙÊýÔ±¹¤£¨²»µ½1%£©µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜй¶¡£Æ¾¾Ý¹úÎñÔº°ä²¼µÄ²¼¸æ£¬¸Ãµç×ÓÓʼþϵͳ³¤¶Ì»úÃÜÐÔµç×ÓÓʼþϵͳ£¬Æä±»ÃèÊöΪÃô¸Ðµ«²»Éæ¼°»úÃÜ¡£¹úÎñÔº½²»°ÈËNicole Thompson°µÊ¾ÕâÒ»ÊÂÎñ»¹ÔÚµ÷²éÖ®ÖУ¬¹úÎñÔºÔÚÓëºÏ×÷ͬ°éºÍ˽Ӫ²¿ÃÅ·þÎñÉ̹²Í¬½øÐÐÈ«ÃæµÄÆÀ¹À¡£


Ô­ÎÄÁ´½Ó£º
https://www.politico.com/story/2018/09/17/state-department-email-personal-information-792665


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù