2019-05-22
°ä²¼¹¦·ò 2019-05-22ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_APT×éÖ¯_MuddyWater_Ô¶³Ì·þÎñÆ÷ÏÎ½Ó |
|
ÊÂÎñ¼¶±ð£º |
¸ß¼¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ä¾ÂíºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuddyWater×éÖ¯ÀûÓõĺóÃÅ¡£ MuddyWaterÊÇÒ»¸öÖØÒªÕë¶ÔÒÁÀ¿ËºÍÉ³ÌØ°¢À²®È·µ±¾Ö»ú¹¹µÄAPT×éÖ¯£¬¸ÃAPT×éÖ¯±³ºóµÄÍŶÓͬÑùÕë¶ÔÖж«Å·ÖÞºÍÃÀ¹úµÈÆäËû¹ú¶È¡£ÆäÖØÒªÀûÓÃPowershell½øÐÐËûÃǵĶñÒâÐÐΪ£¬ÔÚһϵÁÐÐж¯ÖÐÑÜÉú³öÁËËûÃǵÄרÓÐľÂíPOWERSTATS¡£¸Ã×éÖ¯µÄ¹¥»÷Ö¸±êÖØÒª¼¯ÖÐÔÚµ±¾Ö£¬Í¨Ñ¶ÓëʯÓÍÁìÓò£¬¸Ã×éÖ¯ÒÉËÆÀ´×ÔÓÚÒÁÀÊ¡£¸ÃÊÂÎñÅú×¢MuddyWater×éÖ¯ÀûÓúóÃÅÓëÔ¶³Ì·þÎñÆ÷ÏνӲ¢½Ó¹ÜºÅÁîÖ´ÐС£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_KPot.Stealer_ÏÎ½Ó |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKPot¡£
KPotÊÇÒ»¸öÇÔÃÜľÂí£¬Äܹ»ÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢Skype¡¢Steam¡¢FTPµÈ¿Í»§¶Ë±£ÁôµÄÕ˺ÅÃÜÂë¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_Jenkins_GitLab²å¼þÐÅϢй¶·ì϶[CVE-2019-10300] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÔÚÀûÓÃGitLab²å¼þÐÅϢй¶µÄ·ì϶½øÐй¥»÷µÄÐÐΪ¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_Jenkins_ScriptSecurityPluginÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-1003005] |
|
ÊÂÎñ¼¶±ð£º |
¸ß¼¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Jenkins_ScriptSecurityPluginÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
TCP_SpringDataCommon_SPEL_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-1273] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃTCP_SpringDataCommon_SPEL_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_NUUO_NVRMini2Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2018-14933] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
×¢Èë¹¥»÷ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_NUUO_NVRMini2Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_NUUO_NVRMini2Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2018-15716] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
×¢Èë¹¥»÷ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_NUUO_NVRMini2Ô¶³ÌºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
TCP_SpringOAuth2_SPEL_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-1260] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃTCP_SpringOAuth2_SPEL_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_°²È«·ì϶_Spring_Cloud_Config_Serverõè¾¶´©Ô½ÓëËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2019-3799] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Spring Cloud Config Serverõè¾¶´©Ô½ÓëËÁÒâÎļþ¶ÁÈ¡·ì϶¡£ Pivotal Software Spring Cloud ConfigÊÇÃÀ¹úPivotal Software¹«Ë¾µÄÒ»Ì×É¢²¼Ê½ÏµÍ³µÄÅäÖÃÖÎÀí½â¾ö¹æ»®¡£¸Ã²úÆ·ÖØÒªÎªÉ¢²¼Ê½ÏµÍ³ÖÐµÄ±í²¿ÅäÖÃÌṩ·þÎñÆ÷ºÍ¿Í»§¶ËÖ§³Ö¡£ Spring Cloud ConfigÖдæÔÚĿ¼±éÀú·ì϶£¬¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδÄÜÕýÈ·µØ¹ýÂË×ÊÔ´»òÎļþõè¾¶ÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÊÜÏÞĿ¼֮±íµÄÃô¸ÐÎļþ£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_°²È«·ì϶_Ruby_on_Railsõè¾¶´©Ô½ÓëËÁÒâÎļþ¶ÁÈ¡·ì϶[CVE-2019-5418] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
Ruby on RailsÊÇÒ»¸ö Web ÀûÓ÷¨Ê½¿ò¼Ü,ÊÇÒ»¸öÏà¶Ô½ÏÐ嵀 Web ÀûÓ÷¨Ê½¿ò¼Ü£¬¹¹½¨ÔÚ Ruby ˵»°Ö®ÉÏ¡£ ¸Ã·ì϶ÊÇAction ViewÖдæÔÚ°²È«·ì϶¡£ÓÉÓÚÍøÕ¾Ê¹ÓÃÁËΪָ¶¨²ÎÊýµÄrender fileÀ´äÖȾÀûÓÃÖ®±íµÄÊÓͼ£¬Í¨¹ý¡°../../../../¡±À´´ïµ½õè¾¶´©Ô½µÄÖ÷ÕÅ£¬ÇÒͨ¹ý¡°{{¡±À´½øÐÐÄ£°å²éÎÊõè¾¶µÄ¹ØºÏ£¬Ê¹µÃËùÒª½Ó¼ûµÄÎļþ±»µ±×ö±í²¿Ä£°åÀ´½âÎö¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶й¶ÎļþÄÚÈÝ¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_°²È«·ì϶_Ruby_On_Railsõè¾¶´©Ô½·ì϶[CVE-2018-3760] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
SprocketsÊÇÈí¼þ¿ª·¢ÕßSam StephensonºÍJoshua Peek¹²Í¬Ñз¢µÄÒ»¸öRuby¿â£¬ËüÖØÒªÓÃÓÚ²é³JavaScriptÎļþµÄÏ໥ÒÀÀµ¹ØÏµ£¬ÒÔ¼°ÓÅ»¯ÍøÒ³ÖÐÒýÈëµÄJSÎļþ£¬¿ÉÔ¤·À¼ÓÔØ²»ÓÃÒªµÄJSÎļþ£¬¼Ó¿ìÍøÒ³½Ó¼û¿ìÂÊ¡£ Sprockets 4.0.0.beta7¼°Ö®Ç°°æ±¾¡¢3.7.1¼°Ö®Ç°°æ±¾ºÍ2.12.4¼°Ö®Ç°°æ±¾ÖдæÔÚÐÅϢй¶·ì϶¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÔìµÄÒªÇóÀûÓø÷ì϶½Ó¼ûÎļþϵͳÉϵÄÀûÓ÷¨Ê½rootĿ¼֮±íµÄÎļþ¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
HTTP_°²È«·ì϶_ZTE_ZXV10_H108L_Router_Ô¶³ÌºÅÁîÖ´Ðзì϶ |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
°²È«·ì϶ |
|
ÊÂÎñÃèÊö£º |
ZTE ZXV10 H108L RouterÊÇÖйúÖÐÐËͨѶ£¨ZTE£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£Ê¹ÓÃWIND Hellas°æ±¾¹Ì¼þµÄZXV10 H108L·ÓÉÆ÷ÖдæÔÚϵͳºÅÁî×¢Èë·ì϶£¬Ô¶³Ì¹¥»÷ÕßÄܹ»Ê¹ÓÃrootȨÏÞÖ´ÐÐϵͳºÅÁî¡£ |
|
¸üй¦·ò£º |
20190522 |
|
ĬÈÏ×÷Ϊ£º |
Åׯú |
|
ÊÂÎñÃû³Æ£º |
TCP_΢ÈíÔ¶³Ì×ÀÃæ·þÎñÔ¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-0708] |
|
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
|
°²È«ÀàÐÍ£º |
»º³åÒç³ö |
|
ÊÂÎñÃèÊö£º |
¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃTCP_RDPÔ¶³Ì´úÂëÒç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ |
|
¸üй¦·ò£º |
|
|
ĬÈÏ×÷Ϊ£º |
ͨ¹ý |
Åú¸ÄÊÂÎñ
ÎÞ


¾©¹«Íø°²±¸11010802024551ºÅ