ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ14ÖÜ
°ä²¼¹¦·ò 2019-04-08±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼°²È«·ì϶45¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspËÁÒâOSºÅÁîÖ´Ðзì϶£»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´Ðзì϶; Fortinet FortiOS¶ÑÒç¶Âí½Å£»TONGDA Office Anywhere SQL×¢Èë·ì϶£»Advantech WebAccess/SCADAºÅÁî×¢Èë·ì϶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
³ÁÒª°²È«·ì϶Áбí
D-Link DSL-3782 Acl.asp´¦ÖÃScrIPaddrEndTXT²ÎÊý´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»Ö´ÐÐËÁÒâosºÅÁî¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/
2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´Ðзì϶
VMware Workstation/Fusion e1000Ðé¹¹Íø¿¨ÊµÏÖ´æÔÚÔ½½çд·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÌáÉýȨÏÞ¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
3. Fortinet FortiOS¶ÑÒç¶Âí½Å
Fortinet FortiOS´æÔÚ¶ÑÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://fortiguard.com/psirt/FG-IR-18-388
4. TONGDA Office Anywhere SQL×¢Èë·ì϶
TONGDA Office Anywhere´æÔÚsql×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf
5. Advantech WebAccess/SCADAºÅÁî×¢Èë·ì϶
Advantech WebAccess/SCADA´æÔÚ±í²¿ÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´Ðз¸·¨ºÅÁî¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01
³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢SonicWallл㱨³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥
ƾ¾ÝSonicWallµÄÄê¶ÈÍøÂçÍþв»ã±¨£¨2019°æ£©£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬±È2017ÄêµÄ1030Íò´ÎÔö³¤ÁË217.5£¥¡£ÕâÒ»Ôö³¤µÄÔÒòÊÇIoTÉ豸Ôì×÷ÉÌδÄÜÖ´ÐÐÊʵ±µÄ°²È«½ÚÔ졣ȫÇò³¬¹ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØÖ·Ô´ÓÚÃÀ¹ú£¬Æä´ÎÊÇÖйú£¨13%£©¡£´Ë±í£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹µö¹¥»÷£¬±È2017Äê½µÂä4.1£¥¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/
2¡¢ÒøÐÐľÂíAnubis£¬×Ô2017ÄêÀ´ÒÑϰȾ300¶à¼Ò½ðÈÚ»ú¹¹
AndroidÒøÐÐľÂíAnubisÖØÒªÍ¨¹ýGoogle Play Store·Ö·¢£¬×Ô2017ÄêÒÔÀ´£¬AnubisÒѾϰȾÁËÈ«Çò³¬¹ý300¼Ò½ðÈÚ»ú¹¹¡£Anubisͨ³£¼Ù×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊµÓÃÓ×¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬ÆäÖØÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£2019Äê3Ô£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67
3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html
4¡¢Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/
5¡¢JS-SnifferϰȾȫÇò2440¸öÍøÕ¾£¬ÖØÒªÇÔÊØÐÅÓþ¿¨ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ