ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ01ÖÜ
°ä²¼¹¦·ò 2020-01-06>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶; Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶£»Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶£»Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©£»ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû£»ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢£»°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
>³ÁÒª°²È«·ì϶Áбí
1. Apache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶
Apache Solr VelocityÄ£°åVelocityResponseWriter´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÅäÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://issues.apache.org/jira/browse/SOLR-13971
2. Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶
Tencent WeChat½âÎöusernames´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐÖ´ÐÐËÁÒâ´úÂë¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-1035/
3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶
ALE Alcatel-Lucent OmnivistaʵÏÖ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»SYSTEMÓû§Éí·ÝÖ´ÐдúÂë¡£
https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html
4. Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶
Nagios XI schedulereport.php´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî¡£
https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html
5. Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶
Cisco Data Center Network Manager SOAP API´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢ÈëËÁÒâOSºÅÁî²¢Ö´ÐС£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject
>³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©
Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»®¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯¡£@Cody SixteenÔÚTwitter°ä²¼ÁËÓйØNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©µÄÓйØÐÅÏ¢£¬¸Ã·ì϶ӰÏìÁËNagios XI 5.6.9°æ±¾£¬¾¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»Í¨¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁĿǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©¡£
ÔÎÄÁ´½Ó£º
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534
2¡¢ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû
΢Èí³É¹¦ÊÕÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37½ÚÔìµÄ50¸öÓòÃû£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌáÒéÍøÂç¹¥»÷£¬Ô̺¬·¢ËÍ´¹µöÓʼþºÍÍйܴ¹µöÒ³ÃæµÈ¡£Î¢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÒѾ¼à¶½APT37³¤´ïÊýԵŦ·ò£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯Ìá¸æ×´ËÏ¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔÊÕÊÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû¡£Î¢Èí¸ß¹Ü°µÊ¾¸Ã×éÖ¯µÄ´óÎÞÊýÖ¸±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/
3¡¢ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢
ÎïÁªÍø¹©¸øÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄ¾ßÌåÐÅÏ¢¡£¸ÃÊý¾Ý¿â²¢²»Êdzö²úϵͳ£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬Ô̺¬ÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅ䏸ÆäWyze°²È«ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»ÃýÎóµØÂ¶³öÔÚ¹«ÍøÉÏ£¬°²È«¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/
4¡¢°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ
°®¶ûÀ¼µ±¾Ö°ä²¼ÁË¡¶2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ¡·£¬ÕâÊǸùúÓÚ2015Äê°ä²¼µÄÊ׸ö°²È«Õ½ÊõµÄ¸üа汾¡£¸ÃÕ½Êõ»ã±¨¸ÅÊöÁ˵±¾Ö½«ÈôºÎ³ÖÐøÍÆ½ø¸Ã¹úÍÆËã»úÍøÂçºÍÓйػù´¡ÉèÊ©µÄ°²È«¡£»ã±¨ÖвûÁËÈ»µ±¾Ö¶Ô°²È«ºÍ¿¿µÃסµÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«²ÉÈ¡µÄÐж¯£¬Ô̺¬³ÖÐøÌá¸ß¹Ø¼ü»ù´¡¼Ü¹¹ºÍ¹«¹²·þÎñÖеÄÍøÂ絯ÐÔ£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂ簲ȫ³ÁÒªÐÔµÄÒâʶ£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄºÏ×÷£¬½øÒ»²½·¢Õ¹È«Éç»áµÄÍøÂ簲ȫÎÄ»¯£»³ÖÐø¼áÈͰ®¶ûÀ¼×÷Ϊ¼¼ÊõºÍÐÅÏ¢°²È«ÖÐÐĵÄÈ«ÇòÃûÓþ£¬²¢Ô®ÊÖÍÆ½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡µØÖ·¡£¸Ã»ã±¨»¹¶½ÍƽøÐж¦ÐÂÒÔ±£»¤¹Ø¼ü»ù´¡¼Ü¹¹ÃâÊܳÁ´óÍøÂçÍþвµÄÓ°Ï죬ͬʱ»¹ÖÒ¸æ³Æ±í¹ú¿ÉÄÜ»á¹ýÎʰ®¶ûÀ¼µÄÑ¡¾Ù¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html
5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³
°²È«×¨¼ÒVinoth KumarÔÚÒ»¸ö¹«¿ª¿ÉÓõÄGithub´æ´¢¿âÖз¢ÏÖÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß¶³ö£¬¹¥»÷ÕßÄܹ»ÀûÓøÃÃÜÔ¿À´½Ó¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢´Û¸ÄÊÚȨÓû§ÁÐ±í¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ½Ó¼ûÐǰͿËJumpCloud API£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬ÌṩÓû§ÖÎÀí¡¢WebÀûÓ÷¨Ê½µ¥µãµÇ¼£¨SSO£©½Ó¼û½ÚÔìºÍÇáÐÍĿ¼½Ó¼ûºÍ̸£¨LDAP£©·þÎñ¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬ÑÝʾÁËÈôºÎÁгöϵͳºÍÓû§¡¢½ÚÔìAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐкÅÁîÒÔ¼°Ôö³¤»òɾ³ýÓÐȨ½Ó¼ûÄÚ²¿ÏµÍ³µÄÓû§¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸ¿ì³·ÏúÁ˸ÃÃÜÔ¿¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html


¾©¹«Íø°²±¸11010802024551ºÅ