ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ47ÖÜ
°ä²¼¹¦·ò 2020-11-23> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶£»Google Go CVE-2020-28366´úÂë×¢Èë·ì϶£»Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å£»QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨£»Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨£»Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
> ³ÁÒª°²È«·ì϶Áбí
1.Aviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶
Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ´æÔÚδÊÚȨ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐдúÂë¡£
https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/
2.Google Go CVE-2020-28366´úÂë×¢Èë·ì϶
Google Go´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢Èë´úÂë²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£
https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html
3.Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å
Paradox IP150´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02
4.QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶
QNAP QTS´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
https://www.qnap.com/en/security-advisory/qsa-20-09
5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å
Real Time Automation 499ES EtherNet/IP´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢

ÉÏÖÜÈý£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÔ̺¬320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ·¡£ºÚ¿ÍÐû³ÆÕâ´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼Öµģ¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ¡£Ä¿Ç°£¬Pluto TVÉÐδ֤ʵÊÇ·ñ²úÉúÁËÊý¾Ýй¶£¬½ö°µÊ¾ËûÃÇÔÚµ÷²éÖС£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/
2¡¢Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨

Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼ÊõÖÎÀí±äµÃÔ½À´Ô½ÄÑÌ⣬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö³¤¡£87£¥µÄIT¸¨µ¼Õß°µÊ¾£¬´ÓǰһÄêÖÐËûÃÇÒѾ¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©¸øÉ̵ÄÉ󼯣¬Ö»ÓÐ51£¥µÄÈ˲»°²ÏÂÒ»ÄêµÄÉ󼯡£´Ë±í£¬×³´óµÄ¼¼Êõµý±¨Ê¹IT¸¨µ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×Òª¹¤×÷£¬µ«Ö»ÓÐ14%µÄIT¸¨µ¼Õß´ïµ½Á˳ÉÊì¼¼ÊõÖÇÄܵij߶ȡ£
ÔÎÄÁ´½Ó£º
https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report
3¡¢Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨

Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨¡£Intel 471°µÊ¾£¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ£¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ·£¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£
ÔÎÄÁ´½Ó£º
https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/
4¡¢Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁé

±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£Öжϣ¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé¡£ÖܶþÁ賿£¬¹È¸è×ܲ¿°ä²¼ÐÂÎųƣ¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÀûÓ᣸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÅÔ¹ÛÊÓÆµÖ±²¥£¬ÎÞ·¨µ÷ÕûºãνÚÔìÆ÷£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó¡£Æäʵ£¬¸Ã·þÎñÔÚ2ÔÂÒ²²úÉúÁËÀàËÆµÄÖжϣ¬³ÖÐøÁË16¸öÓ×ʱ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.com/2020/11/17/google_nest_outage/
5¡¢×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢

Palo Alto Networks×êÑÐÈËÔ±·¢ÏÖÁË16¸ö·ÖÆçAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬¿É±»ÀÄÓÃÀ´»ñÊØÐÅÏ¢¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»á×Ô¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄÕ½ÊõËùµ¼Öµġ£ÈôÊÇÕ½ÊõÖÐÔ̺¬²»´æÔÚµÄÉí·Ý£¬Ôò´´½¨»ò¸üÐÂÕ½ÊõµÄAPIŲÓý«Ê§°Ü£¬¹¥»÷ÕßÄܹ»ÀÄÓôËÖ°ÄÜÀ´²é³AWSÕË»§ÖеÄÏÖÓÐÉí·Ý¡£×êÑÐÈËÔ±³Æ£¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϽøÐУ¬Ò×Êܹ¥»÷µÄAWS·þÎñÔ̺¬AWS S3¡¢AWS KMSºÍAWS SQS¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data


¾©¹«Íø°²±¸11010802024551ºÅ