ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ6ÖÜ
Ðû²¼Ê±¼ä 2021-02-08> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2021Äê02ÔÂ01ÈÕÖÁ02ÔÂ07ÈÕ¹²ÊÕ¼Çå¾²Îó²î66¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Shiro»á¼ûÈÆ¹ýÎó²î£»£»£»Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»Siemens Comfort Panel TelnetЧÀÍÎÞÑéÖ¤´úÂëÖ´ÐÐÎó²î£»£»£»Sonicwall SMA100 SQL×¢ÈëÎó²î£»£»£»Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇCiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿±¨¸æ£»£»£»Azure FunctionsÖб£´æÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»£»£»NCC Group¼ì²âµ½Ê¹ÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯£»£»£»Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»£»£»»õÔ˹«Ë¾Forward AirѬȾHades£¬£¬£¬£¬£¬£¬£¬£¬Ëðʧ´ï750ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£¡£¡£¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Apache Shiro»á¼ûÈÆ¹ýÎó²î
Apache ShiroʹÓÃspring±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûЧÀÍ¡£¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E
2.Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
Apache Dubbo decodeBody´¦Öóͷ£±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔЧÀÍÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-128/
3.Siemens Comfort Panel TelnetЧÀÍÎÞÑéÖ¤´úÂëÖ´ÐÐÎó²î
Siemens Comfort Panel TelnetЧÀÍÎÞÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-033-02
4.Sonicwall SMA100 SQL×¢ÈëÎó²î
Sonicwall SMA100 WEB½Ó¿Ú±£´æSQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001
5.Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐÐÎó²î
Apple macOS CoreText TTFÆÊÎö±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-21-149/
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢CiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿±¨¸æ

CiscoÐû²¼ÁË2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿±¨¸æ¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿ÊÓ²ìÁËÀ´×Ô25¸ö¹ú¼ÒºÍµØÇøµÄ4400¶à¸ö×éÖ¯£¬£¬£¬£¬£¬£¬£¬£¬²¢Ì½ÌÖÁËËûÃǶÔÒþ˽¹æÔòµÄ̬¶È¡£¡£¡£¡£¡£¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬£¬£¬£¬£¬£¬60£¥µÄ×é֯ûÓÐΪԶ³ÌÊÂÇéËùÉæ¼°µÄÒþ˽ºÍÇå¾²ÒªÇó×öºÃ×¼±¸£¬£¬£¬£¬£¬£¬£¬£¬93£¥µÄ×é֯ͨ¹ýÒþ˽±£»£»£»¤ÍŶÓÀ´Ó¦¶ÔÕâЩÌôÕ½£¬£¬£¬£¬£¬£¬£¬£¬87£¥µÄСÎÒ˽¼Òµ£ÐÄËûÃÇËùʹÓõÄÔ¶³Ì¹¤¾ßµÄÒþ˽±£»£»£»¤ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÏÖÒÑÓÐ140¶à¸ö˾·¨Í³ÁìÇøÖÆ¶©ÁËÒþ˽±£»£»£»¤·¨£¬£¬£¬£¬£¬£¬£¬£¬½ü80£¥µÄÊÜ·ÃÕßÒÔΪÕâЩִ·¨¾ßÓÐÆð¾¢Ó°Ïì¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blogs.cisco.com/security/privacy-comes-of-age-during-the-pandemic
2¡¢Azure FunctionsÖб£´æÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú

Intezer LabµÄÑо¿Ö°Ô±Åû¶ÁËMicrosoft Azure FunctionsÖÐδÐÞ¸´µÄÌáȨÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£¡£¡£¡£¡£¡£¡£¡£Azure Functions¿ÉÒÔÓÉHTTPÇëÇó´¥·¢£¬£¬£¬£¬£¬£¬£¬£¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÊÇ´úÂëûÓб»Çå¾²Ö§½â£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄܱ»ÀÄÓÃÀ´»á¼ûµ×²ãÇéÐΡ£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷¿ÉÒÔͨ¹ý½¨ÉèÒ»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÎÞÌØÈ¨µÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏÞµÄÀú³Ì½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html
3¡¢NCC Group¼ì²âµ½Ê¹ÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯

ÍøÂçÇå¾²¹«Ë¾NCC GroupÖÜÈճƣ¬£¬£¬£¬£¬£¬£¬£¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂç×°±¸ÖÐÁãÈÕÎó²îµÄ×Ô¶¯Ê¹ÓÃʵÑé¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú´ËÎó²îÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄÎó²îÏàͬ£¬£¬£¬£¬£¬£¬£¬£¬µ«NCCÒÔΪÕâÊǼ«ÓпÉÄܵġ£¡£¡£¡£¡£¡£¡£¡£SonicWallÔÚÆäSMA 100Ç徲ͨ¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢Ã÷µÄÁãÈÕÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÁгöÁËÊÜÓ°ÏìµÄ×°±¸ÐͺŲ¢ÌåÏÖ»áÔÚ2ÔÂ2ÈÕ֮ǰÐû²¼²¹¶¡³ÌÐò¡£¡£¡£¡£¡£¡£¡£¡£ÓйØÎó²îµÄϸ½Ú²¢Î´¹ûÕæ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ±ÜÃâÆäËû¹¥»÷Õß¶ÔÆä¾ÙÐÐÑо¿²¢·¢¶¯¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/
4¡¢Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â

SophosÑо¿Ö°Ô±·¢Ã÷ÌØ¹¤Èí¼þAgent TeslaʵÑé¸Ä¶¯Î¢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬£¬£¬£¬£¬£¬£¬£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍÆÊÎö¡£¡£¡£¡£¡£¡£¡£¡£Agent TeslaÓÚ2014ÄêÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄÉÌÒµRAT¡£¡£¡£¡£¡£¡£¡£¡£SophosÌåÏÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÕýÔÚÒ»Ö±¿ª·¢ÖУ¬£¬£¬£¬£¬£¬£¬£¬Æä.NETÏÂÔØ³ÌÐò¿ÉŲÓò¢ÏÂÔØÍйÜÔÚÕýµ±ÍøÕ¾ÉϵĶñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚÀֳɸ͝AMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇéÐÎÏÂÍêÕû°²ÅÅ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÈÓ¦Óᣡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/
5¡¢»õÔ˹«Ë¾Forward AirѬȾHades£¬£¬£¬£¬£¬£¬£¬£¬Ëðʧ´ï750ÍòÃÀÔª

»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷ÊÂÎñ±¬·¢ÔÚÈ¥Äê12ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬ÒòѬȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ¡£¡£¡£¡£¡£¡£¡£¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡ÐëÒªµÄÎļþÒÔͨ¹ýº£¹ØÇ幨ÔËÊ䣬£¬£¬£¬£¬£¬£¬£¬ÆäÔËÓªÊܵ½ÑÏÖØÆÆË𡣡£¡£¡£¡£¡£¡£¡£Ö»¹ÜForward AirÌåÏÖÆäÒÑÀֳɵشӹ¥»÷Öлָ´£¬£¬£¬£¬£¬£¬£¬£¬µ«ÕÕ¾ÉÖ§¸¶Á˼«ÖؼÛÇ®£¬£¬£¬£¬£¬£¬£¬£¬ÆäÔÚµÚËÄÐò¶ÈµÄ²ÆÎñÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/


¾©¹«Íø°²±¸11010802024551ºÅ