ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ9ÖÜ

°ä²¼¹¦·ò 2019-03-04

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ25ÈÕÖÁ3ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶42¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Airflow AirflowÔªÊý¾Ý¿âËÁÒâ´úÂëÖ´Ðзì϶£»F5 BIG-IPÑéÖ¤SSLÔ¶³Ì»Ø¾ø·þÎñ·ì϶; Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌºÅÁîÖ´Ðзì϶£»Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶Áд·ì϶£»OpenSSL°²È«ÈƹýÐÅϢй¶·ì϶¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǽü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍøÏúÊÛ£¬ÊÛ¼Û½ü350ÍòÃÀÔª£»Èý¸ö4G/5G·ì϶£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½Êõ£»Õë¶ÔInstagramÓû§µÄ¼±¾çÖ¸»È¦Ì×£¬Ú¿Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷£»Chrome 0day·ì϶£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢£»CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£

³ÁÒª°²È«·ì϶Áбí


1. Apache Airflow AirflowÔªÊý¾Ý¿âËÁÒâ´úÂëÖ´Ðзì϶
Apache Airflow±à×ëAirflowÔªÊý¾Ý¿âÖжÔÏóµÄ״̬´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b@%3Cdev.airflow.apache.org%3E

2. F5 BIG-IPÑéÖ¤SSLÔ¶³Ì»Ø¾ø·þÎñ·ì϶
F5 BIG-IPÑéÖ¤SSL´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐлؾø·þÎñ¹¥»÷¡£
https://support.f5.com/csp/article/K54167061

3. Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌºÅÁîÖ´Ðзì϶
Cisco?RV110W Wireless-N VPN Firewall¡¢RV130W Wireless-N Multifunction VPN RouterºÍRV215W Wireless-N VPN Router WEB½Ó¿Ú´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex

4. Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶Áд·ì϶
Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cûÓгä·Ö²é³­ASN.1³¤¶È£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐлؾø·þÎñ¹¥»÷»òÖ´ÐÐËÁÒâ´úÂë¡£
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc

5. OpenSSL°²È«ÈƹýÐÅϢй¶·ì϶
OpenSSL´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÈÆ¹ý°²È«ÏÞ¶È£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£
https://www.openssl.org/news/secadv/20190226.txt

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢½ü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍøÏúÊÛ£¬ÊÛ¼Û½ü350ÍòÃÀÔª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Group-IB×êÑÐÈËÔ±·¢ÏÖ69189ÕŰͻùË¹Ì¹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉÏÏúÊÛ¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1Ôµ×ÔÚJoker's StashÉϰ䲼µÄ£¬¹²Ô̺¬1535ÕÅÒøÐп¨ÐÅÏ¢£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйØ¡£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉϰ䲼µÄ£¬Ô̺¬67654ÕÅÒøÐп¨ÐÅÏ¢£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйØ¡£ÕâЩÊý¾Ý¿ÉÄܽ²ÁËÈ»¸ÃµØÓòÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕߵĻ¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html

2¡¢Èý¸ö4G/5G·ì϶£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½Êõ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ2019ÄêNDSS×êÑлáÉÏ£¬Ò»¸ö×êÑÐÍŶÓÅû¶ÁËÔÚ4GºÍ5G LTEºÍ̸·äÎÑÍøÂçÖз¢ÏÖµÄÈý¸öа²È«·ì϶£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶À¹½ØÓû§Í¨»°ºÍ×·×ÙÓû§µØÎ»¡£×êÑÐÈËÔ±Åû¶µÄµÚÒ»ÖÖ¹¥»÷²½ÖèÊÇTorpedo¹¥»÷£¬ËüÀûÓÃÁËѰºôºÍ̸Öеķì϶£¬Ôڶ̹¦·òÄÚ·¢³öºÍÈ¡µÞ¶à¸öµç»°Äܹ»´¥·¢Ñ°ºôÐÂÎÅ£¬¶ø²»»áÏòÖ¸±êÉ豸·¢³öÀ´µç¾¯±¨¡£¹¥»÷ÕßÄܹ»¸ú×ÙÖ¸±êµÄµØÎ»£¬½Ù³ÖѰºôÐÅ·ºÍ×¢ÈëαÔìµÄѰºôÐÂÎÅÀ´ÌáÒéDoS¹¥»÷¡£´Ë±í£¬ToRPEDO¹¥»÷»¹ÎªÁí±íÁ½ÖÖ¹¥»÷-PIERCERºÍIMSI-Cracking¹¥»÷-ÌṩÁË¿ÉÄÜ£¬Ê¹µÃ¹¥»÷ÕßÄܹ»»ñÈ¡Óû§µÄIMSI¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/location-tracking-imsi-catchers.html

3¡¢Õë¶ÔInstagramÓû§µÄ¼±¾çÖ¸»È¦Ì×£¬Ú¿Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹ú¹ú¶ÈڲƭºÍÍøÂç·¸×ïͳ¼ÆÖÐÐÄAction Fraud°µÊ¾£¬Ò»¸öÕë¶ÔInstagramÓû§µÄ¡°¼±¾çÖ¸»¡±È¦Ì×ÒѾ­ÀÛ¼ÆÚ¿Æ­Á˸ߴï300ÍòÓ¢°÷µÄ½ð¶î¡£¸ÃÚ¿Æ­»î¶¯ÖØÒªÕë¶Ô20ÖÁ30ËêµÄÄêÇáÈË£¬×Ô2018Äê10ÔÂÒÔÀ´£¬ÒÑÓÐ356ÆðÓйØÊÂÎñµÄ»ã±¨£¬Êܺ¦Õß¾ùÔÈÿÈËËðʧ8900Ó¢°÷¡£¸ÃÚ¿Æ­»î¶¯ÏòÓû§³Ðŵ¿ÉÔÚ24Ó×ʱÄÚ»ñµÃ¸ß¶î»Ø±¨£¬µ«±ØÐëÏÈͶ×Ê600Ó¢°÷£¬µ±Êܺ¦ÕßתÕ˺ó£¬Ú²Æ­Õß»áÏòËûÃÇ·¢ËÍÒ»¸öÆÁÄ»½ØÍ¼£¬ÏÔʾÆäÕË»§ÒÑÊÕÈëÊýǧӢ°÷¡£µ«µ±Êܺ¦ÕßÒªÇóÌáÏÖʱ£¬Ú²Æ­Õ߾ͻáÖÕ³¡ÁªÏµ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-get-rich-quick-scheme-costs-instagram-users-over-3-million-61d5d384

4¡¢Chrome 0day·ì϶£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


EdgeSpot×êÑÐÈËÔ±¹Û²ìµ½ÀûÓÃChromeÁãÈÕ·ì϶ÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâPDFÎļþ¡£µ±Óû§Í¨¹ýChromeµÄPDF²é¿´Æ÷´ò¿ª¸Ã¶ñÒâÎļþʱ£¬¹¥»÷Õß¿ÉÀûÓ÷ìÏ¶ÍøÂçÓû§µÄÐÅÏ¢£¬²¢·¢ËÍÖÁÔ¶³Ì·þÎñÆ÷¡£ÕâЩÐÅÏ¢Ô̺¬ÏµÍ³µÄ¾ßÌåÐÅÏ¢£¬ÀýÈçIPµØÖ·¡¢²Ù×÷ϵͳ°æ±¾ºÅ¡¢Chrome°æ±¾ºÅ¡¢PDFÎļþõè¾¶µÈ¡£ÖµÍ×ÌùÐĵÄÊÇ£¬¶ñÒâPDFÎļþÔÚAdobe ReaderÖв»»áÖ´ÐÐÈκζñÒâ»î¶¯¡£GoogleÈ·ÈÏÁËÕâÒ»·ì϶£¬²¢³Ðŵ½«ÔÚ4Ôµ׽øÐн¨¸´¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d

5¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¼ÓÃÜÇ®±ÒÇ®°üCoinomiÔÚÇ®°üÉèÖùý³ÌÖлὫÓû§µÄÃ÷ÎÄÃÜÂëͨ¹ýHTTP·¢ËÍÖÁ¹È¸èµÄƴд²é³­·¨Ê½£¬µ¼ÖÂÓû§µÄÕË»§ºÍ×ʽðÒ×ÊÜÖÐÑëÈË£¨MiTM£©¹¥»÷¡£¹¥»÷ÕßÄܹ»ÀûÓÃÀ¹½Øµ½µÄÃÜÂëµÇ¼Óû§µÄÕË»§²¢Çå¿ÕÆä×ʽð¡£Ò»¸öÓû§Al Maawali°µÊ¾£¬ÆäÕË»§ÖеÄ×ʽðÒò¶øËðʧÁË90%£¬¼ÛÖµÔ¼7ÍòÃÀÔª¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù