ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ10ÖÜ

°ä²¼¹¦·ò 2019-03-11

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼°²È«·ì϶51¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇCisco NX-OS Software CLI CVE-2019-1610ºÅÁî×¢Èë·ì϶ £»Google Chrome FileReader¿ªÊͺóʹÓôúÂëÖ´Ðзì϶; Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞ¶ÈÈÆ¹ý·ì϶ £»Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´Ðзì϶ £»Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç¶Âí½Å ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢Èí°ä²¼°²È«»ã±¨Volume 24 £¬2018Äê´¹µö¹¥»÷Ôö³¤250£¥ £»×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ £¬±È2017ÄêÔö³¤424% £»Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û £¬500¶àÍòÓû§Êý¾Ýй¶ £»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖÐ £¬WordPressÕ¼90% £»×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý ¡£

ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖÐ ¡£

³ÁÒª°²È«·ì϶Áбí


1. Cisco NX-OS Software CLI CVE-2019-1610ºÅÁî×¢Èë·ì϶
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý´æÔÚ°²È«·ì϶ £¬ÔÊÐí±¾µØ¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÌáÉýȨÏÞÖ´ÐÐËÁÒâosºÅÁî ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610

2. Google Chrome FileReader¿ªÊͺóʹÓôúÂëÖ´Ðзì϶
Google Chrome FileReaderµÄʵÏÖ´æÔÚ¿ªÊͺóʹÓ÷ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶¹¹½¨¶ñÒâWEBÒ³ £¬ÓÕʹÓû§½âÎö £¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ £»òÖ´ÐÐËÁÒâ´úÂë ¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html

3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞ¶ÈÈÆ¹ý·ì϶
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬ÉÏ´«ËÁÒâÎļþ £¬²¢Ö´ÐÐ ¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html

4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´Ðзì϶
Samsung Galaxy S9 GameServiceReceiver¸üлúÔì´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÖ´ÐÐËÁÒâ´úÂë ¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/

5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç¶Âí½Å
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦ÖÃÌØÊâµÄHTTP POSTÒªÇó´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉÖ´ÐÐËÁÒâ´úÂë ¡£
https://www.tenable.com/security/research/tra-2019-09

 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Î¢Èí°ä²¼°²È«»ã±¨Volume 24 £¬2018Äê´¹µö¹¥»÷Ôö³¤250£¥

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ƾ¾Ý΢ÈíµÄ°²È«µý±¨»ã±¨£¨SIR£©Volume 24 £¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂÆÚ¼ä £¬ÍøÂç´¹µö¹¥»÷Ôö³¤ÁË250% ¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹µö»î¶¯Ê±Ñ¡È¡¶àÑù»¯µÄ»ù´¡ÉèÊ© £¬Ô̺¬ÍйܷþÎñÆ÷ºÍ¹«¹²ÔƵÈ ¡£ÁíÒ»·½Ãæ £¬2018ÄêÆÚ¼ä¶ñÒâÈí¼þµÄÊýÁ¿½µÂäÁËÔ¼34% ¡£´Ë±í £¬Ëæ×Å2018ÄêËêĺ¼ÓÃÜÇ®±Ò¼ÛÖµµÄ×ÅÂä £¬¶ñÒâÍÚ¿ó»î¶¯Ò²½µÂäÁË36% ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/

2¡¢×êÑÐÅú×¢2018Äê²úÉú12449ÆðÊý¾Ýй¶ÊÂÎñ £¬±È2017ÄêÔö³¤424%

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝÍþвµý±¨¹«Ë¾4IQµÄÒ»·Ýл㱨 £¬2018ÄêÒÑÈ·ÈϵÄÊý¾Ýй¶ÊÂÎñµÄÊýÁ¿´ï12449Æð £¬Óë2017ÄêÏà±ÈÔö³¤424% £¬ÆäÖÐ47%µÄÊÂÎñÓëÃÀ¹úºÍÖйúµÄ¹«Ë¾ÓйØ ¡£¸Ã¹«Ë¾Í³¼ÆµÄÊÇÒÑÈ·ÈϵÄÊý¾Ýй¶ÊÂÎñ £¬¹ÌÈ»ÊÂÎñµÄÊýÁ¿ÔÚ2018Äê´ó·ùÌáÉý £¬µ«¾ùÔÈй¶¹æÄ£Ôò½µÂäÖÁ216884±Ê¼Í¼ £¬±È2017ÄêÒªÓ×4.7±¶ ¡£´Ë±í £¬2018ÄêÓÐ149ÒÚ±»µÁµÄԭʼÉí·Ý¼Í¼ÔÚ°µÍøÉϽøÐд«²¼ £¬µ«Ö»ÓÐ36ÒÚÊÇеĺÍÕæÊµµÄ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/

3¡¢Dalil¹«Ë¾MongoDB¿É¹«¿ª½Ó¼û £¬500¶àÍòÓû§Êý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


VPNMentor×êÑÐÍŶӷ¢ÏÖÉ³ÌØ°¢À­²®Í¨Ñ¶APP DalilµÄMongoDBÊý¾Ý¿â¿É¹«¿ª½Ó¼û £¬µ¼Ö³¬¹ý500ÍòÓû§µÄÓ×ÎÒÐÅϢй¶ ¡£Dalilͨ¹ýÍøÂçÓû§ÐÅÏ¢ £¬Äܹ»Ô®ÊÖÓû§¼ø±ðδ֪µÄµç»°ºÅÂë £¬´Ó¶øÔ¤·ÀɧÈŵ绰»òÍÆÏúµç»°µÈ ¡£×êÑÐÈËÔ±·¢ÏÔìäMongoDBÊý¾Ý¿âδÉèÃÜÂë £¬ÕâÒâζÕß¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É½Ó¼ûÓû§µÄÊý¾Ý £¬Ô̺¬ÊÖ»úºÅÂë¡¢IPµØÖ·¡¢É豸Ðͺš¢ÐòÁкš¢²Ù×÷ϵͳ¡¢IMEI¡¢SIM¿¨ÐÅÏ¢¡¢GPSÐÅÏ¢ÒÔ¼°ÓÊÏäÕË»§¡¢ÐÕÃû¡¢ÐÔ±ðºÍÖ°ÒµµÈ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/

4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖÐ £¬WordPressÕ¼90%

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝSucuriµÄÒ»·Ýµ÷²é»ã±¨ £¬ÔÚ2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾µÄCMSÉ¢²¼ÖÐ £¬WordPressÒ£Ò£µ±ÏÈ £¬Õ¼90% £¬¶þÈýËÄÃû±ðÀëÊÇMagento£¨4.6£¥£©¡¢Joomla£¨4.3£¥£©ºÍDrupal£¨3.7£¥£© ¡£68%µÄÊÜÏ°È¾ÍøÕ¾±»Ö²ÈëÁ˺óÃÅ £¬56%µÄÊÜÏ°È¾ÍøÕ¾ÍйÜÁËÆäËü¶ñÒâÈí¼þ ¡£´Ë±í £¬51%µÄÊÜÏ°È¾ÍøÕ¾±»²¿ÊðÁËSEOÀ¬»øÐÅÏ¢Ò³Ãæ £¬2017ÄêÕâÒ»Êý×ÖÊÇ44% ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/

5¡¢×êÑÐÍŶӷ¢ÏÖ2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Malwarebytes Labs×êÑÐÍŶӷ¢ÏÖÀÕË÷Èí¼þTroldesh£¨±ðÃûShade£©ÔÚ2018ÄêQ4µ½2019ÄêQ1ÆÚ¼äµÄ¼ì²âÊýÁ¿¼±¾çÔö³¤ ¡£Shadeͨ³£Í¨¹ý´¹µöÓʼþ½øÐд«²¼ £¬Æä¸½¼þÊÇÔ̺¬Javascript¾ç±¾µÄzipÎļþ ¡£ShadeµÄÖØÒª¹¥»÷Ö¸±êÊÇWindowsϵͳ £¬ÆäѡȡAES 256 CBCËã·¨½øÐмÓÃÜ ¡£²¿ÃÅShadeµÄ±äÖÖ´æÔÚÃâ·ÑµÄ½âÃܹ¤¾ß £¬Óû§¿ÉÔÚNoMoreRansom.orgÍøÕ¾ÉÏÕÒµ½ËüÃÇ ¡£

Ô­ÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù