ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ29ÖÜ

°ä²¼¹¦·ò 2019-07-29

>  ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ22ÈÕÖÁ28ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶£»Apple Webkit ¶à¸öÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶£»Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶£»McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶíÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬»úÃÜÏîÄ¿ÆØ¹â£»ProFTPD RCE·ì϶£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ï죻ӡ¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢£»RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª£»Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£



>  ³ÁÒª°²È«·ì϶Áбí



1. ProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶


ProFTPD SITE CPFR/CPTOûÓÐÕýÈ·´¦ÖúÍÅäÖã¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ¶Áд²Ù×÷¡£

http://bugs.proftpd.org/show_bug.cgi?id=4372

2. Apple Webkit CVE-2019-8644ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Apple iOSÔ̺¬µÄWebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£

https://support.apple.com/zh-cn/HT210356

3. Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶


Zeroshell´¦ÖÃhttp²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt

4. Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Storm´¦Öò»³ÉÐÅÊý¾Ý´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E

5. McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶


McAfee Data Loss Prevention Endpoint ePOÀ©´ó´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£
https://kc.mcafee.com/corporate/index?page=content&id=SB10289



 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢¶íÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬»úÃÜÏîÄ¿ÆØ¹â


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©µÄ³Ð°üÉÌSyTechÔâºÚ¿ÍÈëÇÖ£¬¸Ã¹«Ë¾ÎªFSB¿ª·¢µÄ»úÃÜÏîÄ¿±»ÆØ¹â¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ7ÔÂ13ÈÕ£¬ºÚ¿ÍÍÅ»ï0v1ru$ÈëÇÖÁËSyTechµÄ·þÎñÆ÷£¬²¢ÇÔÈ¡ÁË7.5TBµÄÊý¾Ý¡£ÕâЩÊý¾ÝËæºó±»·ÖÏí¸øºÚ¿ÍÍÅ»ïDigitalRevolution£¬ºóÕßÏòýÌå½øÐÐÁËÆØ¹â¡£ÕâЩ»úÃÜÏîÄ¿Ô̺¬Ö¼ÔÚ¸ôÀë¶íÂÞ˹»¥ÁªÍøµÄNadezhdaÏîÄ¿¡¢Ö¼ÔÚÍøÂçÉ罻ýÌåÓû§ÐÅÏ¢µÄNautilusÏîÄ¿ÒÔ¼°Ö¼ÔÚ¶ÔTorÍøÂçÓû§½øÐÐÈ¥ÄäÃû»¯µÄNautilus-SÏîÄ¿µÈ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/

2¡¢ProFTPD RCE·ì϶£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ProFTPD°ä²¼Ð°汾1.3.6£¬½¨¸´Ò»¸ö¿Éµ¼ÖÂRCEµÄ·ì϶¡£¸Ã·ì϶£¨CVE-2019- 12815£©ÓëProFTPDµÄmod_copyÄ £¿éÓйØ£¬·ì϶ԭÒòÊÇmod_copyÄ £¿éµÄ×Ô½ç˵SITE CPFRºÍSITE CPTOºÅÁîûÓа´Ô¤ÆÚÅäÖù¤×÷¡£ÖÎÀíÔ±¿Éͨ¹ý½ûÓÃmod_copyÄ £¿éÀ´»º½â¸Ã·ì϶¡£Æ¾¾ÝShodanµÄËÑË÷Á˾Ö£¬Ä¿Ç°Óг¬¹ý100Íò¸öProFTPd·þÎñÆ÷ÉÐδÉý¼¶½¨¸´²¹¶¡¡£µÂ¹úCERT-BundÒ²Õë¶Ô¸Ã·ì϶ÏòÓû§·¢³ö¾¯±¨¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/

3¡¢Ó¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÓ¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashµÄÒ»¸öÊý¾Ý¿âδÊÜÃÜÂë±£»¤£¬µ¼ÖÂÊý°ÙÍòÓû§µÄÂòÂôÐÅÏ¢¿É±»¹«¿ª½Ó¼û¡£Ð¹Â¶µÄÃô¸ÐÐÅÏ¢Ô̺¬260ÍòÓû§µÄÂòÂô¼Í¼£¬ÒÔ¼°ËûÃǵÄKYC PIIÐÅÏ¢£¬ÀýÈçÇ®°üID¡¢Óû§Ãû¡¢µç×ÓÓʼþ¡¢IPµØÖ·ºÍ¶Ë±êÓïµÈ¡£ÔÚ×êÑÐÈËÔ±´«µÝ¸Ã¹«Ë¾ºó£¬¸Ã¹«Ë¾ÒѶÔElasticÊý¾Ý¿â½øÐб£»¤¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿â¶³öÁ˶೤¹¦·òÒÔ¼°ÊÇ·ñÒѱ»ÆäËûÈ˽Ӽû¡£

Ô­ÎÄÁ´½Ó£ºhttps://securitydiscovery.com/jana-bank-data-leak/

4¡¢RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRiskIQµÄÊý¾Ý£¬È¥ÄêÍøÂç·¸×ï·Ö×Óÿ·ÖÖÓ¸øÈ«Çò¾­¼ÃÔì³É290ÍòÃÀÔªµÄËðʧ£¬ÕûÄê×ܼÆÔì³É1.5ÍòÒÚÃÀÔªµÄËðʧ¡£ÆäËüÊý¾ÝÔ̺¬£¬¼ÓÃÜÇ®±ÒÂòÂôËùÿ·ÖÖÓµÄËðʧ´ï1930ÃÀÔª£»´¹µö¹¥»÷ÿ·ÖÖÓÔì³ÉµÄËðʧ´ï17700ÃÀÔª£»2019ÄêÈ«ÇòÀÕË÷Èí¼þÊÂÎñµÄÔ¤¼Æ³É±¾ÎªÃ¿·ÖÖÓ22184ÃÀÔª£»Ã¿·ÖÖÓй¶µÄÉí·ÝÊý¾ÝÌõÊýΪ8100Ìõ£»Ã¿·ÖÖÓ¼ì²âµ½µÄ¶ñÒâ³Á¶¨ÏòΪ7¸öµÈ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/external-threat-management/2019-evil-internet-minute/

5¡¢Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ǰÎ÷ÃÅ×ÓºÏͬ¹¤David TinleyÈÏ¿ÉÔÚΪ¹«Ë¾´´½¨µÄµç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯£¬Ëû½«Ãæ¶Ô×î¸ß10ÄêµÄ½ûïÀÒÔ¼°25ÍòÃÀÔªµÄ· £¿î¡£Æ¾¾ÝÓйط¨Í¥Îļþ£¬TinleyΪÎ÷ÃÅ×ÓµÄMonroeville PA´¦Ê´¦ÌṩÁ˽üÊ®ÄêµÄÈí¼þ·þÎñ£¬ËûÔÚ¸ø¹«Ë¾´´½¨ÓÃÓÚÖÎÀíÉ豸¶©µ¥µÄµç×Ó±í¸ñʱֲÈëÁËÂß¼­Õ¨µ¯£¬ÕâЩըµ¯»áÔÚÌØ¶¨ÈÕÆÚ´¥·¢£¬µ¼ÖÂÎļþ±ÀÀ£¡£Ã¿´Î±ÀÀ£Ê±Tinley³ÇÊÐÊÕÈ¡ÓöÈÀ´½¨¸´¸ÃÎļþ£¬Ö±µ½Á½ÄêºóÎ÷ÃÅ×Ó·¢ÏÖÁËÂß¼­Õ¨µ¯²¢Ìá³öÁËÖ¸¿Ø¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/siemens-contractor-pleads-guilty-to-planting-logic-bomb-in-company-spreadsheets/