ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ16ÖÜ

Ðû²¼Ê±¼ä 2019-04-22

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö



2019Äê4ÔÂ15ÈÕÖÁ21ÈÕ±¾ÖÜ

¹²ÊÕ¼Çå¾²Îó²î46¸ö£¬£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇAtlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀúÎó²î£»£»£»£»£»£»£»£»Sangfor Sundray WLAN ControllerȨÏÞÌáÉýÎó²î; GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉýÎó²î£»£»£»£»£»£»£»£»Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³öÎó²î£»£»£»£»£»£»£»£»Cloud Foundry Cloud Controller APIÑéÖ¤Îó²î¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄOutLookÕÊ»§ÐÅϢй¶£»£»£»£»£»£»£»£»Gnosticplayers³öÊÛµÚÎåÅúÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬°üÀ¨6500¶àÍò¸öÕ˺ţ»£»£»£»£»£»£»£»³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬£¬£¬£¬ £¬Ð®ÖÆ5ÒÚiOSÓû§»á»°£»£»£»£»£»£»£»£»JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢£»£»£»£»£»£»£»£»FacebookÐÂÊý¾Ý³óÎÅ£¬£¬£¬£¬£¬£¬ £¬Î´¾­Óû§ÔÊÐíÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£



Ö÷ÒªÇå¾²Îó²îÁбí



1. Atlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú©
Atlassian Confluence ServerºÍAtlassian Data Center downloadallattachments×ÊÔ´±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉó²éϵͳÎļþÄÚÈÝ¡£¡£¡£¡£¡£¡£
https://jira.atlassian.com/browse/CONFSERVER-58102

2. Sangfor Sundray WLAN ControllerȨÏÞÌáÉýÎó²î
Sundray WLAN Controller nginx_webconsole.php±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ £¬¿É¶ÁÈ¡adminÃÜÂ룬£¬£¬£¬£¬£¬ £¬»ñȡȨÏÞ¡£¡£¡£¡£¡£¡£
https://nvd.nist.gov/vuln/detail/CVE-2019-9161

3. GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉýÎó²î
GitLab impersonate user¹¦Ð§±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ £¬ÌáÉýÓû§È¨ÏÞ¡£¡£¡£¡£¡£¡£
https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/

4. Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç³öÎó²î
Delta Electronics Delta Industrial Automation CNCSoft±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ £¬¿ÉÖ´ÐÐí§Òâ´úÂë»ò¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£

https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01


5. Cloud Foundry Cloud Controller APIÑéÖ¤Îó²î
Cloud Foundry Cloud Controller APIÑé֤ʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬ £¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£
https://www.cloudfoundry.org/blog/cve-2019-3798


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬ £¬²¿·ÖÓû§µÄOutLookÕÊ»§ÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

΢Èí֤ʵ1ÔÂ1ÈÕÖÁ3ÔÂ29ÈÕʱ´ú¹¥»÷ÕßÈëÇÖÁËÒ»¸ö¿Í»§Ö§³ÖÊðÀíÕË»§£¬£¬£¬£¬£¬£¬ £¬²¢Ê¹ÓøÃÕË»§»á¼ûÁ˿ͻ§Ö§³ÖÃÅ»§ÍøÕ¾¼°²¿·ÖOutLookÓû§µÄÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢°üÀ¨µç×ÓÓʼþµØµã¡¢Îļþ¼ÐÃû³Æ¡¢ÓʼþÖ÷Ìâ¼°ÁªÏµÈ˵ç×ÓÓʼþµØµã£¬£¬£¬£¬£¬£¬ £¬µ«²»°üÀ¨Óʼþ¼°¸½¼þµÄÄÚÈÝ¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷µÄÏêϸϸ½Ú£¬£¬£¬£¬£¬£¬ £¬µ«Î¢ÈíÌåÏÖÒѾ­½ûÓÃÁ˸ÃÊðÀíÕË»§µÄƾ֤£¬£¬£¬£¬£¬£¬ £¬²¢Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§¡£¡£¡£¡£¡£¡£Î¢ÈíҲûÓÐ͸¶ÊÜÓ°ÏìµÄÓû§×ÜÊý¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/microsoft-outlook-email-hack.html

2¡¢Gnosticplayers³öÊÛµÚÎåÅúÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬°üÀ¨6500¶àÍò¸öÕ˺Å

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ºÚ¿ÍGnosticplayersÔÚ°µÍøÂÛ̳DreamMarketÉϳöÊÛµÚÎåÅú±»µÁµÄÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬ £¬ÕâÅúÊý¾Ý°üÀ¨Áè¼Ý6500Íò¸öÓû§ÕË»§£¬£¬£¬£¬£¬£¬ £¬ÊÛ¼ÛΪ0.8463±ÈÌØ±Ò£¨4350ÃÀÔª£©¡£¡£¡£¡£¡£¡£ÕâÅú±»µÁµÄÓû§¼Í¼ÊôÓÚÁù¼Òй«Ë¾£¬£¬£¬£¬£¬£¬ £¬°üÀ¨ÓÎϷƽ̨Mindjolt£¨2800Íò£©¡¢ÔÚÏß¹ºÎïÉçÇøWanelo£¨2300Íò£©¡¢Æ»¹ûάÐÞÖÐÐÄiCracked£¨150Íò£©¡¢ÂÃÓι«Ë¾Yanolja£¨150Íò£©¡¢µç×ÓÔ¼ÇëЧÀÍEvite£¨1000Íò£©ºÍÅ®×ÓʱװµêModa Operandi£¨150Íò£©¡£¡£¡£¡£¡£¡£ÏÖÔÚΪֹGnosticplayers³öÊ۵ı»µÁÓû§¼Í¼×ÜÊýÒÑ´ï9.32ÒÚÌõ¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/gnosticplayers-hacker-returns-with-fifth-dataset-containing-over-65-million-user-accounts-for-sale-95450e99

3¡¢³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬£¬£¬£¬ £¬Ð®ÖÆ5ÒÚiOSÓû§»á»°


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌConfiant·¢Ã÷·¸·¨ÍÅ»ïeGobblerÌᳫÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¹ã¸æ»î¶¯£¬£¬£¬£¬£¬£¬ £¬ÒÑÐ®ÖÆ5ÒÚiOSÓû§µÄ»á»°¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕ×îÏÈ£¬£¬£¬£¬£¬£¬ £¬Ò»Á¬ÁË6ÌìµÄʱ¼ä£¬£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃÁË8¸ö²î±ðµÄ¶ñÒâ¹ã¸æÏµÁкÍ30¶à¸öÐéα¹ã¸æ£¬£¬£¬£¬£¬£¬ £¬Ã¿¸öÐéα¹ã¸æÏµÁеÄÉúÃüÖÜÆÚΪ24-48Сʱ֮¼ä¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖ÷ÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬£¬£¬£¬£¬£¬ £¬²¢ÔÚ¹¥»÷ÖÐʹÓÃÁËChromeä¯ÀÀÆ÷ÖеÄÎó²îÒÔÈÆ¹ýɳºÐ¼ì²â¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹ÂÚÍøÕ¾£¬£¬£¬£¬£¬£¬ £¬¾­ÓɶÌÔݵÄÍ£ÁôÖ®ºó£¬£¬£¬£¬£¬£¬ £¬ÓÖתÏò.siteÓòÃûµÄ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬£¬£¬£¬£¬£¬ £¬ÕâЩ´¹ÂÚÍøÕ¾Ò»Ö±´¦ÓÚ»îԾ״̬¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

4¡¢JustDial APIй¶Áè¼Ý1ÒÚÓ¡¶ÈÓû§µÄСÎÒ˽¼ÒÐÅÏ¢

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ô±Rajshekhar Rajaharia·¢Ã÷Ó¡¶ÈÍâµØËÑË÷ЧÀ͹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ£»£»£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬ £¬¿É±»ÈκÎÈËʹÓÃÒÔ¼ìË÷Áè¼Ý100ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý°üÀ¨Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÊÖ»úºÅÂë¡¢ÆÜÉíµØµã¡¢ÐԱ𡢳öÉúÈÕÆÚ¡¢ÕÕÆ¬¡¢¾ÍÖ°¹«Ë¾µÈ¡£¡£¡£¡£¡£¡£ËäÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬ £¬µ«Éв»ÇåÎúÊÇ·ñÒÑÓÐÈËʹÓÃËüÀ´ÍøÂçJustDialÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

5¡¢FacebookÐÂÊý¾Ý³óÎÅ£¬£¬£¬£¬£¬£¬ £¬Î´¾­Óû§ÔÊÐíÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚÖÜÈýÐû²¼µÄÒ»·ÝÉùÃ÷ÖУ¬£¬£¬£¬£¬£¬ £¬FacebookÌåÏÖ×Ô2016Äê5ÔÂÒÔÀ´¸Ã¹«Ë¾¡°ÎÞÒâ¼ä¡±ÔÚδ¾­Óû§ÔÊÐíµÄÇéÐÎÏÂÏòЧÀÍÆ÷ÉÏ´«Á˶à´ï150ÍòÓû§µÄµç×ÓÓʼþÁªÏµÈË¡£¡£¡£¡£¡£¡£ÕâÊÇFacebook½üÆÚÃæÁÙµÄһϵÁÐÒþ˽Ïà¹ØÎÊÌâºÍÕùÒéÖеÄ×îÐÂÊÂÎñ¡£¡£¡£¡£¡£¡£FacebookÌåÏÖÒÑÔÚÒ»¸öÔÂǰ×èÖ¹ÁË¿ÉÒɵĵç×ÓÓʼþÑéÖ¤Àú³Ì£¬£¬£¬£¬£¬£¬ £¬²¢ÏòÓû§°ü¹Üδ·ÖÏíÕâЩÁªÏµÈËÐÅÏ¢¼°ÒѾ­×îÏÈɾ³ýÕâЩÁªÏµÈË¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/facebook-email-database.html