ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ4ÖÜ
°ä²¼¹¦·ò 2021-01-25> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2021Äê01ÔÂ18ÈÕÖÁ01ÔÂ24ÈÕ¹²ÊÕ¼°²È«·ì϶57¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇOracle E-Business Suite One-to-One Fulfillment CVE-2021-2101δÃ÷ËÁÒâ´úÂëÖ´Ðзì϶£»£»Netapp Clustered Data ONTAPËÁÒâÊý¾Ý¸²¸Ç·ì϶£»£»Delta Electronics ISPSoftÏîÄ¿Îļþ´¦ÖÃÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶£»£»Cisco SD-WAN vManage Software ºÅÁî×¢Èë·ì϶£»£»Google Chrome Cryptohome²»³ä·ÖÕ½ÊõÖ´Ðзì϶¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶíÂÞ˹Ìú·´æÔڿɽӼûÆä¼à¿ØÏµÍ³µÄ·ì϶£»£»FiberHome FTTH ONT·ÓÉÆ÷ÖдæÔÚ28¸öºóÃÅÕÊ»§£»£»JSOFÅû¶DnsmasqÖÐ7¸öͳ³ÆÎªDNSpooqµÄ·ì϶£»£»Malwarebytes³ÆSolarWindsºÚ¿ÍÒÑÈëÇÖÆäÓʼþϵͳ£»£»×êÑÐÍŶӷ¢ÏÖFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£
> ÖØÒª°²È«·ì϶Áбí
1.Oracle E-Business Suite One-to-One Fulfillment CVE-2021-2101δÃ÷ËÁÒâ´úÂëÖ´Ðзì϶
Oracle E-Business Suite One-to-One Fulfillment´æÔÚδÃ÷°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://www.oracle.com/security-alerts/cpujan2021.html
2.Netapp Clustered Data ONTAPËÁÒâÊý¾Ý¸²¸Ç·ì϶
Netapp Clustered Data ONTAP´æÔÚδÃ÷°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿É¸²¸ÇϵͳÊý¾Ý¡£¡£
https://security.netapp.com/advisory/ntap-20210119-0001/
3.Delta Electronics ISPSoftÏîÄ¿Îļþ´¦ÖÃÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Delta Electronics ISPSoftÏîÄ¿Îļþ´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://us-cert.cisa.gov/ics/advisories/icsa-21-021-01
4.Cisco SD-WAN vManage Software ºÅÁî×¢Èë·ì϶
Cisco SD-WAN vManage Software WEB½Ó¿Ú´æÔÚ°²È«·ì϶£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-cmdinjm-9QMSmgcn
5.Google Chrome Cryptohome²»³ä·ÖÕ½ÊõÖ´Ðзì϶
Google Chrome Cryptohome´æÔÚ²»³ä·ÖÕ½ÊõÖ´Ðзì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»òÄܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html
> ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢¡¢¶íÂÞ˹Ìú·´æÔڿɽӼûÆä¼à¿ØÏµÍ³µÄ·ì϶

¶íÂÞ˹Ìú·¹«Ë¾´æÔÚ·ì϶£¬£¬¿ÉÓÃÀ´½Ó¼ûÆä¼à¿ØÏµÍ³ºÍÄÚ²¿·þÎñ¡£¡£¸Ã·ì϶ÊÇÓÉÓÚĬÈÏÇé¿öÏÂMikroTik·ÓÉÆ÷ÉϵÄÃÜÂëδ¸ü¸ÄËùµ¼Öµģ¬£¬ºÚ¿Í¿ÉÀûÓø÷ì϶ÔÚÒ»ÖÜÄڹرÕÌú·ÉϵÄËùÓÐ¼à¿Ø£¬£¬¶ø¸´Ôϵͳ±ØÒªÖÁÉÙÒ»¸öԵŦ·ò£¬£¬ÆÆ·Ñ1.3ÒÚ¬²¼£¨180ÍòÃÀÔª£©¡£¡£Ä¿Ç°£¬£¬¸Ã·ì϶Òѱ»ÐÞ¸´£¬£¬µ«²»ÄÜÈ·¶¨ÊÇ·ñÓй¥»÷ÕßÀûÓÃÆä·¸·¨½Ó¼û¹ý¹«Ë¾µÄϵͳ¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.ehackingnews.com/2021/01/hackers-accessed-thousands-of.html
2¡¢¡¢¡¢FiberHome FTTH ONT·ÓÉÆ÷ÖдæÔÚ28¸öºóÃÅÕÊ»§

×êÑÐÈËÔ±Pierre Kim·¢ÏÖFiberHome FTTH ONT·ÓÉÆ÷ÖдæÔÚ28¸öºóÃÅÕÊ»§ºÍ¶à¸öÆäËû·ì϶¡£¡£¸Ã·ÓÉÆ÷ÖØÒª²¿ÊðÓÚÄÏÃÀºÍ¶«ÄÏÑÇ£¬£¬Í¨³£×°ÖÃÔÚÑ¡ÔñǧÕ×λµÄ¹«Ô¢Â¥ÄÚ¡¢¡¢¡¢¼ÒÍ¥»òÆóÒµÄÚ²¿¡£¡£Kim³ÆÆä·¢ÏÖ´óÁ¿¿É±»ÀÄÓÃÀ´ÊÕÊÜISPµÄºóÃźͷì϶£¬£¬ÀýÈçºóÃÅÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆµÄHTTPSÒªÇó[https£º£º// [ip]/telnet£¿£¿£¿enable=0£¦key=calculated£¨BR0_MAC£©]Óë·ÓÉÆ÷µÄTelnetÏνӣ¬£¬Web·þÎñÆ÷Ô̺¬22¸öÓÉ·ÖÆçµÄInternet·þÎñÌṩÉÌʹÓõÄÓ²±àÂëÍ´´¦µÈ¡£¡£
ÔÎÄÁ´½Ó£º£º
https://www.zdnet.com/article/multiple-backdoors-and-vulnerabilities-discovered-in-fiberhome-routers/
3¡¢¡¢¡¢JSOFÅû¶DnsmasqÖÐ7¸öͳ³ÆÎªDNSpooqµÄ·ì϶

JSOFµÄ×êÑÐÈËÔ±Åû¶ÁËDnsmasqÖеÄ7¸öDNSpooq·ì϶¡£¡£DnsmasqÊÇ»ùÓÚ*NIX²Ù×÷ϵͳµÄDNSת·¢¿Í»§¶Ë£¬£¬Í¨³£ÔÚ¸÷ÀàÍøÂçÉ豸µÄ¹Ì¼þÖС£¡£Õâ´Î×ܹ²Åû¶ÁË7¸ö·ì϶£¬£¬ËûÃDZ»Í³³ÆÎªDNSpooq£¬£¬ÆäÖÐ4¸öÊÇ»º³åÇøÒç³ö·ì϶£¬£¬¿ÉÄܵ¼ÖÂÔ¶³ÌÖ´ÐдúÂ룬£¬¶øÆäËû3¸ö·ì϶Ôò¿Éµ¼ÖÂDNS»º´æÖж¾¡£¡£JSOF³Æ¹¥»÷Õ߿ɽáºÏʹÓÃDNSpooqºÍ¾É°æDnsmasqÈí¼þ£¬£¬¶ÔÖ±½Ó¶³öÔÚInternetÉϵÄDnsmasq½øÐй¥»÷£¬£¬²¢ÇÒÊÜÓ°ÏìÉ豸Ëù´¦µÄÄÚÍøÉÏµÄÆäËüÉ豸Ҳ½«´¦ÓÚΣÏÕÖ®ÖС£¡£
ÔÎÄÁ´½Ó£º£º
https://www.zdnet.com/article/dnspooq-lets-attackers-poison-dns-cache-records/
4¡¢¡¢¡¢Malwarebytes³ÆSolarWindsºÚ¿ÍÒÑÈëÇÖÆäÓʼþϵͳ

°²È«¹«Ë¾Malwarebytes³ÆSolarWinds±³ºóµÄºÚ¿ÍÒÑÈëÇÖÆäÓʼþϵͳ¡£¡£¸Ã¹«Ë¾Ö¸³ö£¬£¬¹ÌÈ»ÆäûÓÐʹÓÃSolarWinds£¬£¬µ«ÓëÆäËû¹«Ë¾Ò»ÑùÔâµ½ÁËSolarWinds¹©¸øÁ´¹¥»÷¡£¡£¹¥»÷²úÉúÔÚÈ¥Ä꣬£¬ºÚ¿ÍÀûÓÃAzure Active DirectoryÖеķì϶ºÍ¶ñÒâOffice 365ÀûÓ÷¨Ê½£¬£¬¶Ô¹«Ë¾²¿ÃÅϵͳÌáÒéÁ˹¥»÷¡£¡£¾¹ýµ÷²é£¬£¬¸Ã¹«Ë¾È·¶¨¹¥»÷Õß½ö»ñµÃÁ˲¿ÃÅÄÚ²¿ÓʼþµÄ½Ó¼ûȨ£¬£¬ÆäÄÚ²¿³ö²ú»·¾³²¢Î´Êܵ½Ó°Ï죬£¬Ä¿Ç°ÈԿɰ²È«Ê¹ÓÃMalwarebytesÈí¼þ¡£¡£
ÔÎÄÁ´½Ó£º£º
https://securityaffairs.co/wordpress/113628/hacking/malwarebytes-solarwinds-attack.html
5¡¢¡¢¡¢×êÑÐÍŶӷ¢ÏÖFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯

×êÑÐÍŶӷ¢ÏÖ½©Ê¬ÍøÂçFreakOutÀûÓöà¸öзì϶µÄ¹¥»÷»î¶¯¡£¡£Õâ´Î¹¥»÷ÖØÒªÕë¶ÔTerraMaster²Ù×÷ϵͳ¡¢¡¢¡¢Zend FrameworkºÍLiferay Portal£¬£¬ÀûÓÃÁËCVE-2020-28188¡¢¡¢¡¢ CVE-2021-3007ºÍCVE-2020-7961·ì϶¡£¡£FreakOutÓµÓзþÎñ¶Ë¿ÚɨÃè¡¢¡¢¡¢ÍøÂçÐÅÏ¢¡¢¡¢¡¢ÍøÂçÐá̽»ò·¢ÆðÉ¢²¼Ê½»Ø¾ø·þÎñ(DDoS)¹¥»÷µÈÖ°ÄÜ£¬£¬¿ÉϰȾLinuxÉ豸£¬£¬²¢ÀûÓÃÆäÍÚ¼ÓÃÜÇ®±Ò¡¢¡¢¡¢ÔÚ¹«Ë¾ÍøÂçÉϺáÏò´«²¼»ò¼Ù×°³ÉÊÜÓ°ÏìµÄ¹«Ë¾¹¥»÷ÆäËûÖ¸±ê¡£¡£
ÔÎÄÁ´½Ó£º£º
https://research.checkpoint.com/2021/freakout-leveraging-newest-vulnerabilities-for-creating-a-botnet/


¾©¹«Íø°²±¸11010802024551ºÅ