ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ36ÖÜ
°ä²¼¹¦·ò 2019-09-16> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶£»Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶£»Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶£»Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶£»Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇDealer LeadsÒâ±íй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼£»ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý£»ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å£»ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô£»Telestar±»ÆØTelnetºóÃÅ·ì϶ӰÏì100¶àÍòIoTÉ豸¡£
> ³ÁÒª°²È«·ì϶Áбí
1. Dabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶
https://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
2. Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶
https://www.kb.cert.org/vuls/id/672565/
3. Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶
https://www.auscert.org.au/bulletins/ESB-2019.3469/
4. Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶
https://www.zerodayinitiative.com/advisories/ZDI-19-818/
5. Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1264
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë±£»¤£¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉ϶³ö¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÖ¸±êÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬°²È«×êÑÐÔ±Jeremiah Fowler°µÊ¾ÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µ×êÑÐÐÅÏ¢ºÍ·ÖÀà¸æ°×£¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý¡£¸Ã¶³öµÄÊý¾Ý¿â×ܹ²Ô̺¬413GBÐÅÏ¢£¬Ô̺¬Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢IPµØÖ·ÒÔ¼°´û¿îºÍ²ÆÕþÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/198m-car-buyer-records-exposed-online/148231/
2¡¢ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý
×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖеIJàÐÅ·¹¥»÷£¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´Ôì×÷µÄËùÓÐÏÖ´úÓ¢ÌØ¶û·þÎñÆ÷´¦ÖÃÆ÷¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/O¼¼Êõ£¨DDIO£©Óйأ¬DDIOÔÚ×îеÄÓ¢ÌØ¶û·þÎñÆ÷¼¶´¦ÖÃÆ÷ÖÐĬÈÏ´ò¿ª£¬Ô̺¬Intel Xeon E5¡¢E7ºÍSP´¦ÖÃÆ÷ϵÁС£¸Ã·ì϶£¨CVE-2019-11184£©µÄÀûÓÃÄѶȽϸߣ¬¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬²¢ÇÒ±ØÒªÓëÖ¸±êϵͳ³ÉÁ¢Ö±½ÓÍøÂçÏνӡ£Ó¢Ìضû½«¸Ã·ì϶µÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMAÖ°ÄÜ£¬»òÏÞ¶È´Ó±í²¿²»ÊÜÐÅÀµµÄÍøÂçÖ±½Ó½Ó¼ûÒ×Êܹ¥»÷µÄϵͳ¡£¶î±íµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÿÉÄֿܵ¹°´Ê±¹¥»÷µÄÈí¼þÄ£¿é»òʹÓú㰴¹¦·òÐÎ×´µÄ´úÂë¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/netcat-intel-side-channel.html
3¡¢ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å
ÔÎÄÁ´½Ó£º
https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/4¡¢ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô
±±ÃÀµçÁ¦¿¿µÃסÐÔ¹«Ë¾£¨NERC£©ÉÏÖܰµÊ¾½ñÄêÔçЩʱ³½Ó°ÏìÃÀ¹úµçÍøÊµÌåµÄÍøÂ簲ȫÊÂÎñ²¢Ã»ÓÐ×î³õÉèÏëµÄÄÇÑùΣÏÕ¡£NERCÔÚÒ»·Ý»ã±¨ÖÐÖ¸³ö£¬ºÚ¿ÍÔÚ2019Äê3ÔÂ5ÈÕÀûÓÃDoS·ì϶µ¼ÖµçÍø·À»ðǽÔÚ10Ó×ʱÄÚ·´¸´³ÁÆô£¬¸ÃÊÂÎñÖ»Ó°ÏìÁËһЩµÍÓ°Ïì¼¶·¢µçÕ¾µãµÄÍøÂç±íΧ·À»ðǽ£¬²¢Ã»ÓÐÔì³ÉµçÁ¦¹©¸øµÄÈκÎÖжϡ£ËæºóµÄ·ÖÎöÈ·¶¨³ÁÆôÊÇÓÉÀûÓÃÒÑÖª·À»ðǽ·ì϶µÄ±í²¿ÊµÌåÌáÒéµÄ£¬ÔËÓªÉÌ×îÖÕ·¢ÏÖËûÃÇδÄÜΪÊܵ½¹¥»÷µÄ·À»ðǽÀûÓù̼þ¸üУ¬ÔÚ²Ù×÷Ô±²¿ÊðÊʵ±µÄ²¹¶¡ºó£¬·À»ðǽ²»ÔÙ³ÁÆô¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cyber-security-incident-at-us-power-grid-entity-linked-to-unpatched-firewalls/
https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/


¾©¹«Íø°²±¸11010802024551ºÅ