ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ29ÖÜ
°ä²¼¹¦·ò 2019-07-29> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ22ÈÕÖÁ28ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶£»Apple Webkit ¶à¸öÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶£»Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶£»McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶíÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬»úÃÜÏîÄ¿ÆØ¹â£»ProFTPD RCE·ì϶£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ï죻ӡ¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢£»RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª£»Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯¡£
> ³ÁÒª°²È«·ì϶Áбí
1. ProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶
ProFTPD SITE CPFR/CPTOûÓÐÕýÈ·´¦ÖÃ
2. Apple Webkit CVE-2019-8644ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
Apple iOSÔ̺¬µÄWebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://support.apple.com/zh-cn/HT2103563. Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt
4. Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E
5. McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶
https://kc.mcafee.com/corporate/index?page=content&id=SB10289
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/
2¡¢ProFTPD RCE·ì϶£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/
3¡¢Ó¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢
ÔÎÄÁ´½Ó£ºhttps://securitydiscovery.com/jana-bank-data-leak/
4¡¢RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/external-threat-management/2019-evil-internet-minute/
5¡¢Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/siemens-contractor-pleads-guilty-to-planting-logic-bomb-in-company-spreadsheets/


¾©¹«Íø°²±¸11010802024551ºÅ