ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ14ÖÜ

Ðû²¼Ê±¼ä 2019-04-08

 ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼Çå¾²Îó²î45¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspí§ÒâOSÏÂÁîÖ´ÐÐÎó²î£»£»£»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐÐÎó²î; Fortinet FortiOS¶ÑÒç³öÎó²î£»£»£»TONGDA Office Anywhere SQL×¢ÈëÎó²î£»£»£»Advantech WebAccess/SCADAÏÂÁî×¢ÈëÎó²î¡£¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSonicWallб¨¸æ³Æ2018ÄêIoT¹¥»÷ÔöÌí217.5£¥£»£»£»ÒøÐÐľÂíAnubis£¬£¬£¬£¬£¬£¬£¬£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹£»£»£»Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶£»£»£»Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â£»£»£»JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£ ¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí



1. D-Link DSL-3782 Acl.aspí§ÒâOSÏÂÁîÖ´ÐÐÎó²î
D-Link DSL-3782 Acl.asp´¦Öóͷ£ScrIPaddrEndTXT²ÎÊý±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÖ´ÐÐí§ÒâosÏÂÁî¡£¡£ ¡£¡£¡£¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/

2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐÐÎó²î
VMware Workstation/Fusion e1000ÐéÄâÍø¿¨ÊµÏÖ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£ ¡£¡£¡£¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html

3. Fortinet FortiOS¶ÑÒç³öÎó²î
Fortinet FortiOS±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£
https://fortiguard.com/psirt/FG-IR-18-388

4. TONGDA Office Anywhere SQL×¢ÈëÎó²î
TONGDA Office Anywhere±£´æsql×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£¡£¡£¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf

5. Advantech WebAccess/SCADAÏÂÁî×¢ÈëÎó²î
Advantech WebAccess/SCADA±£´æÍⲿÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´Ðв»·¨ÏÂÁî¡£¡£ ¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01



 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢SonicWallб¨¸æ³Æ2018ÄêIoT¹¥»÷ÔöÌí217.5£¥


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ƾ֤SonicWallµÄÄê¶ÈÍøÂçÍþв±¨¸æ£¨2019°æ£©£¬£¬£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ1030Íò´ÎÔöÌíÁË217.5£¥¡£¡£ ¡£¡£¡£¡£ÕâÒ»ÔöÌíµÄÔµ¹ÊÔ­ÓÉÊÇIoT×°±¸ÖÆÔìÉÌδÄÜʵÑéÊʵ±µÄÇå¾²¿ØÖÆ¡£¡£ ¡£¡£¡£¡£È«ÇòÁè¼Ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØµãÔ´ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨13%£©¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬±È2017ÄêϽµ4.1£¥¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/

2¡¢ÒøÐÐľÂíAnubis£¬£¬£¬£¬£¬£¬£¬£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


AndroidÒøÐÐľÂíAnubisÖ÷Ҫͨ¹ýGoogle Play Store·Ö·¢£¬£¬£¬£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬£¬£¬AnubisÒѾ­Ñ¬È¾ÁËÈ«ÇòÁè¼Ý300¼Ò½ðÈÚ»ú¹¹¡£¡£ ¡£¡£¡£¡£Anubisͨ³£Î±×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊÊÓÃС¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£¡£ ¡£¡£¡£¡£2019Äê3Ô£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67

3¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶¡£¡£ ¡£¡£¡£¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄÆÊÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚʵʱÆÊÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£¡£ ¡£¡£¡£¡£´ó´ó¶¼Ì»Â¶µÄʵÀý¶¼Ã»ÓÐÊܵ½±£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§»á¼ûÒDZíÅÌ¡£¡£ ¡£¡£¡£¡£ÕâЩʵÀýÊôÓÚµç×Óѧϰƽ̨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú£¨8311¸ö£©ÊÇ̻¶ʵÀý×î¶àµÄ¹ú¼Ò£¬£¬£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£¡£ ¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬Ðí¶àʵÀý¶¼ÔËÐйýʱµÄÈí¼þ°æ±¾£¨±£´æí§ÒâÎļþ°üÀ¨Îó²î£©¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html

4¡¢Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


UpGuardÑо¿ÍŶӷ¢Ã÷Á½¸öµÚÈý·½Ó¦ÓõÄÑÇÂíÑ·S3´æ´¢¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖд洢ÁËÁè¼Ý5.4ÒÚFacebookÓû§µÄ¼Í¼¡£¡£ ¡£¡£¡£¡£ÕâЩÓû§Êý¾Ý°üÀ¨µÚÈý·½Ó¦ÓõÄÃ÷ÎÄÃÜÂë¡¢FacebookÕË»§Ãû³Æ¡¢Óû§ID¡¢Ì¸ÂÛ¡¢ÐËȤ¡¢¹ØÏµ×´Ì¬µÈ¡£¡£ ¡£¡£¡£¡£Ò»¸öÊý¾Ý¿âÊôÓÚÄ«Î÷¸çýÌ幫˾Cultura Colectiva£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÃûΪcc-datalake£¬£¬£¬£¬£¬£¬£¬£¬¾ÞϸΪ146GB£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ô¼5.4ÒÚÓû§¼Í¼¡£¡£ ¡£¡£¡£¡£ÁíÒ»¸öÊý¾Ý¿âÊôÓÚµÚÈý·½Ó¦ÓÃAt the Pool£¬£¬£¬£¬£¬£¬£¬£¬Ö»°üÀ¨2.2ÍòÓû§¼Í¼¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/

5¡¢JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÊØÐÅÓÿ¨ÐÅÏ¢


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤Çå¾²³§ÉÌGroup-IBµÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬½ü38¸ö²î±ðµÄJS-SnifferѬȾÁËÈ«Çò2440¸öµç×ÓÉÌÎñÍøÕ¾¡£¡£ ¡£¡£¡£¡£JS-SnifferÊÇÒ»ÖÖJavaScript¶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬£¬£¬Ö¼ÔÚ×èµ²²¢ÇÔÈ¡Óû§ÊäÈëµÄÒøÐп¨ºÅ¡¢ÐÕÃû¡¢µØµã¡¢µÇ¼ÐÅÏ¢ºÍÃÜÂëµÈ¡£¡£ ¡£¡£¡£¡£Æ¾Ö¤Ô¤¼Æ£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩJS-sniffer¿ª·¢ÕßµÄÊÕÒæ¿É´ïÿÔÂÊýÊ®ÍòÃÀÔª¡£¡£ ¡£¡£¡£¡£ÔÚÕâЩJS-Sniffer¼Ò×åÖУ¬£¬£¬£¬£¬£¬£¬£¬ÖÁÉÙÓÐ8¸ö֮ǰ´Óδ±»ÊÓ²ì¹ý¡£¡£ ¡£¡£¡£¡£ÔÚÊÜѬȾµÄÍøÕ¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬Áè¼ÝÒ»°ëµÄ¹¥»÷ÊÇÓÉJS-sniffer¼Ò×åMagentoNameÌᳫµÄ£¬£¬£¬£¬£¬£¬£¬£¬¶øÁè¼Ý13%µÄ¹¥»÷ÊÇÓÉWebRank¼Ò×åÌᳫµÄ¡£¡£ ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html