ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ10ÖÜ

Ðû²¼Ê±¼ä 2019-03-11

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê3ÔÂ04ÈÕÖÁ10ÈÕ¹²ÊÕ¼Çå¾²Îó²î51¸ö£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇCisco NX-OS Software CLI CVE-2019-1610ÏÂÁî×¢ÈëÎó²î£»£»£»£» £»£»Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐÐÎó²î; Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈÆ¹ýÎó²î£»£»£»£» £»£»Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐÐÎó²î£»£»£»£» £»£»Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³öÎó²î¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ΢ÈíÐû²¼Çå¾²±¨¸æVolume 24£¬£¬£¬£¬2018Äê´¹ÂÚ¹¥»÷ÔöÌí250£¥£»£»£»£» £»£»Ñо¿Åú×¢2018Ä걬·¢12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬±È2017ÄêÔöÌí424%£»£»£»£» £»£»Dalil¹«Ë¾MongoDB¿É¹ûÕæ»á¼û£¬£¬£¬£¬500¶àÍòÓû§Êý¾Ýй¶£»£»£»£» £»£»2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬£¬£¬WordPressÕ¼90%£»£»£»£» £»£»Ñо¿ÍŶӷ¢Ã÷2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý¡£¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Cisco NX-OS Software CLI CVE-2019-1610ÏÂÁî×¢ÈëÎó²î
Cisco NX-OS Software CLIÑéÖ¤²ÎÊý±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ÌáÉýȨÏÞÖ´ÐÐí§ÒâosÏÂÁî¡£¡£¡£¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190306-nxos-cmdinj-1610

2. Google Chrome FileReaderÊͷźóʹÓôúÂëÖ´ÐÐÎó²î
Google Chrome FileReaderµÄʵÏÖ±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬¿ÉʹӦÓóÌÐòÍ߽⻣»£»£» £»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html

3. Adobe ColdFusion CVE-2019-7816ÎļþÉÏ´«ÏÞÖÆÈÆ¹ýÎó²î
Adobe ColdFusionÎļþÉÏ´«ÊµÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬ÉÏ´«í§ÒâÎļþ£¬£¬£¬£¬²¢Ö´ÐС£¡£¡£¡£¡£
https://helpx.adobe.com/security/products/coldfusion/apsb19-14.html

4. Samsung Galaxy S9Éí·ÝÑéÖ¤´úÂëÖ´ÐÐÎó²î
Samsung Galaxy S9 GameServiceReceiver¸üлúÖÆ±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.zerodayinitiative.com/advisories/ZDI-19-255/

5. Nokia Alcatel Lucent I-240W-Q GPON ONT CVE-2019-3922»º³åÇøÒç³öÎó²î
Nokia Alcatel Lucent I-240W-Q GPON ONT´¦Öóͷ£ÌØÊâµÄHTTP POSTÇëÇó±£´æÇå¾²Îó²î£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.tenable.com/security/research/tra-2019-09

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢Î¢ÈíÐû²¼Çå¾²±¨¸æVolume 24£¬£¬£¬£¬2018Äê´¹ÂÚ¹¥»÷ÔöÌí250£¥

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú

ƾ֤΢ÈíµÄÇå¾²Ç鱨±¨¸æ£¨SIR£©Volume 24£¬£¬£¬£¬ÔÚ2018Äê1ÔÂÖÁ12ÔÂʱ´ú£¬£¬£¬£¬ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÁË250%¡£¡£¡£¡£¡£¹¥»÷ÕßÔÚÔËÓªÍøÂç´¹Âڻʱ½ÓÄɶàÑù»¯µÄ»ù´¡ÉèÊ©£¬£¬£¬£¬°üÀ¨ÍйÜЧÀÍÆ÷ºÍ¹«¹²ÔƵÈ¡£¡£¡£¡£¡£ÁíÒ»·½Ã棬£¬£¬£¬2018Äêʱ´ú¶ñÒâÈí¼þµÄÊýĿϽµÁËÔ¼34%¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬Ëæ×Å2018ÄêÄêβ¼ÓÃÜÇ®±Ò¼ÛÇ®µÄϵø£¬£¬£¬£¬¶ñÒâÍÚ¿ó»î¶¯Ò²Ï½µÁË36%¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-sees-250-percent-phishing-increase-malware-decline-by-34-percent/

2¡¢Ñо¿Åú×¢2018Ä걬·¢12449ÆðÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬±È2017ÄêÔöÌí424%

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ƾ֤ÍþвÇ鱨¹«Ë¾4IQµÄÒ»·Ýб¨¸æ£¬£¬£¬£¬2018ÄêÒÑÈ·ÈϵÄÊý¾Ýй¶ÊÂÎñµÄÊýÄ¿´ï12449Æð£¬£¬£¬£¬Óë2017ÄêÏà±ÈÔöÌí424%£¬£¬£¬£¬ÆäÖÐ47%µÄÊÂÎñÓëÃÀ¹úºÍÖйúµÄ¹«Ë¾ÓйØ¡£¡£¡£¡£¡£¸Ã¹«Ë¾Í³¼ÆµÄÊÇÒÑÈ·ÈϵÄÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ËäÈ»ÊÂÎñµÄÊýÄ¿ÔÚ2018Äê´ó·ùÌáÉý£¬£¬£¬£¬µ«Æ½¾ùй¶¹æÄ£ÔòϽµÖÁ216884Ìõ¼Í¼£¬£¬£¬£¬±È2017ÄêҪС4.7±¶¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬2018ÄêÓÐ149ÒÚ±»µÁµÄԭʼÉí·Ý¼Í¼ÔÚ°µÍøÉϾÙÐÐÈö²¥£¬£¬£¬£¬µ«Ö»ÓÐ36ÒÚÊÇеĺÍÕæÊµµÄ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/12-449-data-breaches-confirmed-in-2018-a-424-percent-increase-over-the-previous-year/

3¡¢Dalil¹«Ë¾MongoDB¿É¹ûÕæ»á¼û£¬£¬£¬£¬500¶àÍòÓû§Êý¾Ýй¶

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


VPNMentorÑо¿ÍŶӷ¢Ã÷É³ÌØ°¢À­²®Í¨Ñ¶APP DalilµÄMongoDBÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬µ¼ÖÂÁè¼Ý500ÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£¡£¡£Dalilͨ¹ýÍøÂçÓû§ÐÅÏ¢£¬£¬£¬£¬¿ÉÒÔ×ÊÖúÓû§Ê¶±ðδ֪µÄµç»°ºÅÂ룬£¬£¬£¬´Ó¶ø×èֹɧÈŵ绰»òÍÆÏúµç»°µÈ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷ÆäMongoDBÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬ÕâÒâζÕß¹¥»÷ÕßÎÞÐèÉí·ÝÑéÖ¤¼´¿É»á¼ûÓû§µÄÊý¾Ý£¬£¬£¬£¬°üÀ¨ÊÖ»úºÅÂë¡¢IPµØµã¡¢×°±¸Ðͺš¢ÐòÁкš¢²Ù×÷ϵͳ¡¢IMEI¡¢SIM¿¨ÐÅÏ¢¡¢GPSÐÅÏ¢ÒÔ¼°ÓÊÏäÕË»§¡¢ÐÕÃû¡¢ÐÔ±ðºÍÖ°ÒµµÈ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.vpnmentor.com/blog/dalil-data-breach/

4¡¢2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾ÖУ¬£¬£¬£¬WordPressÕ¼90%

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


ƾ֤SucuriµÄÒ»·ÝÊӲ챨¸æ£¬£¬£¬£¬ÔÚ2018Äê±»ºÚ¿ÍÈëÇÖµÄÍøÕ¾µÄCMSÂþÑÜÖУ¬£¬£¬£¬WordPressÒ£Ò£ÁìÏÈ£¬£¬£¬£¬Õ¼90%£¬£¬£¬£¬¶þÈýËÄÃû»®·ÖÊÇMagento£¨4.6£¥£©¡¢Joomla£¨4.3£¥£©ºÍDrupal£¨3.7£¥£©¡£¡£¡£¡£¡£68%µÄÊÜÑ¬È¾ÍøÕ¾±»Ö²ÈëÁ˺óÃÅ£¬£¬£¬£¬56%µÄÊÜÑ¬È¾ÍøÕ¾ÍйÜÁËÆäËü¶ñÒâÈí¼þ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬51%µÄÊÜÑ¬È¾ÍøÕ¾±»°²ÅÅÁËSEOÀ¬»øÐÅÏ¢Ò³Ãæ£¬£¬£¬£¬2017ÄêÕâÒ»Êý×ÖÊÇ44%¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/wordpress-accounted-for-90-percent-of-all-hacked-cms-sites-in-2018/

5¡¢Ñо¿ÍŶӷ¢Ã÷2Ô·ÝÀÕË÷Èí¼þShadeµÄ¹¥»÷»î¶¯ì­Éý

c7c7ÓéÀÖÆ½Ì¨(ÖйúÓÎ)µÇ¼¹ÙÍøÈë¿Ú


Malwarebytes LabsÑо¿ÍŶӷ¢Ã÷ÀÕË÷Èí¼þTroldesh£¨ÓÖÃûShade£©ÔÚ2018ÄêQ4µ½2019ÄêQ1ʱ´úµÄ¼ì²âÊýÄ¿¼±¾çÔöÌí¡£¡£¡£¡£¡£Shadeͨ³£Í¨¹ý´¹ÂÚÓʼþ¾ÙÐÐÈö²¥£¬£¬£¬£¬Æä¸½¼þÊǰüÀ¨Javascript¾ç±¾µÄzipÎļþ¡£¡£¡£¡£¡£ShadeµÄÖ÷Òª¹¥»÷Ä¿µÄÊÇWindowsϵͳ£¬£¬£¬£¬Æä½ÓÄÉAES 256 CBCËã·¨¾ÙÐмÓÃÜ¡£¡£¡£¡£¡£²¿·ÖShadeµÄ±äÖÖ±£´æÃâ·ÑµÄ½âÃܹ¤¾ß£¬£¬£¬£¬Óû§¿ÉÔÚNoMoreRansom.orgÍøÕ¾ÉÏÕÒµ½ËüÃÇ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://blog.malwarebytes.com/threat-analysis/2019/03/spotlight-troldesh-ransomware-aka-shade/

ÉùÃ÷£º±¾×ÊѶÓÉc7c7ÓéÀÖÆ½Ì¨Î¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí