ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ41ÖÜ
°ä²¼¹¦·ò 2021-10-11>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼°²È«·ì϶49¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓûؾø·þÎñ·ì϶£»Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´Ðзì϶£»Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´Ðзì϶£»Visual Tools DVR VX cgi-bin/slogin/login.pyºÅÁîÖ´Ðзì϶; Google chrome Safe BrowsingÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÓÉÓÚFirebaseÅäÖÃÃýÎó14¸öÀûÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢£»Facebook·ÓÉÅäÖÃÃýÎóµ¼ÖÂÈ«ÇòÁìÓòÄÚ·þÎñÖжϣ»Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÅäÖÃÃýÎóй¶10TBÊý¾Ý£»TwitchÒò·þÎñÆ÷ÅäÖÃÃýÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢£»Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£
>ÖØÒª°²È«·ì϶Áбí
1. Apache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓûؾø·þÎñ·ì϶
Apache HTTP Server´æÔÚĿ¼±éÀú·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎIJ鿴ϵͳÎļþÄÚÈÝ»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://httpd.apache.org/security/vulnerabilities_24.html
2. Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´Ðзì϶
Zoho ManageEngine ADManager Plus´æÔÚËÁÒâÎļþÉÏ´«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉÉÏ´«¶ñÒâÎļþ£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://www.manageengine.com/products/ad-manager/release-notes.html#7111
3. Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´Ðзì϶
Google Android¿ò¼Ü´æÔÚ°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂ룬£¬ÌáÉýȨÏÞ¡£¡£
https://source.android.com/security/bulletin/2021-10-01
4. Visual Tools DVR VX cgi-bin/slogin/login.pyºÅÁîÖ´Ðзì϶
Visual Tools DVR VX16 cgi-bin/slogin/login.py Uaer-Agent HTTP´¦ÖôæÔÚ°²È«·ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£
https://www.exploit-db.com/exploits/50098
5. Google chrome Safe BrowsingÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶
Google chrome Safe Browsing´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬ÓÕʹÓû§½âÎö£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òÕßʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html
>ÖØÒª°²È«ÊÂÎñ×ÛÊö
1¡¢¡¢¡¢ÓÉÓÚFirebaseÅäÖÃÃýÎó14¸öÀûÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢
9ÔÂ30ÈÕ£¬£¬ CyberNews ×êÑÐÔ± Martynas Vareikis °ä²¼»ã±¨³Æ£¬£¬ÓÉÓÚ Firebase Êý¾Ý¿âÅäÖÃÃýÎ󣬣¬µ¼ÖÂÊýÒÔǧ¼ÆµÄ iOS / Android ÀûÓ÷¨Ê½Ð¹Â¶Á˳¬¹ý1.4ÒÚÌõÐÅÏ¢¡£¡£Firebase ÊÇ Google ÌṩµÄ¡°ºó¶Ë¼´·þÎñ¡±²úÆ·£¬£¬ÆäÖÐÔ̺¬ÁË´óÁ¿·¢·þÎñ£¬£¬Ö¼ÔÚ·½±ãÒÆ¶¯¿ª·¢ÈËÔ±´´½¨»ùÓÚÕâЩ·þÎñµÄÒÆ¶¯»ò Web ÀûÓᣡ£
ÔÎÄÁ´½Ó£º
https://cybernews.com/security/research-popular-android-apps-with-142-5-million-collective-downloads-are-leaking-user-data/
2¡¢¡¢¡¢Facebook·ÓÉÅäÖÃÃýÎóµ¼ÖÂÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ
10ÔÂ4ÈÕ£¬£¬FacebookÆì϶à¸öƽ̨ºÍ·þÎñ£¬£¬Ô̺¬ Facebook¡¢¡¢¡¢Instagram¡¢¡¢¡¢MessengerºÍ WhatsAppµÈ£¬£¬Ïà¼Ì³öÏÖÑÏÖØ·þÎñÖжϡ£¡£Óû§ÎÞ·¨µÇÈ뷨ʽ£¬£¬·¨Ê½ÎÞ·¨Áª»úºÍ¸üУ¬£¬Ã»·¨ÊÕ·¢ÐÅÏ¢£¬£¬¾ÍÁ¬ÒÔ FacebookÕ˺ŵÇÈëµÄ·¨Ê½ºÍ·þÎñÒàÊܵ½ÖêÁ¬£¬£¬²»ÄÜÕý³£µÇÈë¡£¡£FacebookÆäºó·¢ÉêÃ÷Ö¸£¬£¬ÄÚ²¿Â·ÓÉÆ÷³öÏÖÎÊÌ⣬£¬Á¬Ëø·´Ó³µ¼Ö·þÎñÈ«ÃæÖжϣ¬£¬¹ÌÈ»·þÎñÒѻظ´£¬£¬µ«ÄÚ²¿ÈÔÔÚÈ«Á¦¸ÄÉÆÏµÍ³£¬£¬ÒԻظ´Õý³£¹¤×÷״̬¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/facebook-outage-caused-by-faulty-routing-configuration-changes/
3¡¢¡¢¡¢Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÅäÖÃÃýÎóй¶10TBÊý¾Ý
10ÔÂ6ÈÕ£¬£¬×êÑÐÔ± Bob Diachenko ·¢ÏÖÁËÒ»¸öÊôÓÚÓ¢¹ú±¨Ö½¡°µçѶ±¨¡±µÄδÊܱ£»¤µÄ 10 TB Êý¾Ý¿â¡£¡£²»°²È«µÄÊý¾Ý¿âÓÚ9 Ô 14 ÈÕ±»·¢ÏÖ£¬£¬ÆäÖÐÔ̺¬ÄÚ²¿ÈÕÖ¾ºÍ¶©ÔÄÕßÐÅÏ¢¡£¡£Êý¾Ý´æ´¢ÔÚ¶³öµÄ Elasticsearch ¼¯ÈºÉÏ£¬£¬´ó²¿ÃÅÊý¾Ý¶¼¾¹ý¼ÓÃÜ£¬£¬µ«ÖÁÉÙ 1,200 Ãû Telegraph ¶©ÔÄÕߺÍ×¢²áÕßµÄСÎÒ¾ßÌåÐÅÏ¢ÒÔ¼°´óÁ¿ÄÚ²¿·þÎñÆ÷ÈÕÖ¾¶¼ÒѾ¹ýÃ÷È·²âÊÔ¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123020/data-breach/the-telegraph-data-leak.html
4¡¢¡¢¡¢TwitchÒò·þÎñÆ÷ÅäÖÃÃýÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢
10ÔÂ6ÈÕ£¬£¬ºÚ¿ÍÔÚ4chan¹«¿ªÁËÔ̺¬125GBÊý¾ÝµÄtorrentÁ´½Ó£¬£¬³ÆÕâÊÇ´ÓԼĪ6000¸öÄÚ²¿Twitch Git´æ´¢¿âÖÐÇÔÈ¡µÄ£¬£¬Ô̺¬Ô´´úÂëºÍÖ§¸¶¼Í¼µÈÐÅÏ¢¡£¡£´ËÍ⣬£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˱êÇ©#DoBetterTwitch£¬£¬Ö¤Ã÷Õâ´Î¹¥»÷ÊÂÎñ¿ÉÄÜÖ¼ÔÚÕë¶ÔTwitch 8Ô·ÝûÓлØÓ¦ºÍÕмܶÔÖ÷²¥µÄ¹¥»÷»î¶¯¡£¡£TwitchÔÚ10ÔÂ7ÈÕÈ·ÈÏÆäÊý¾Ýй¶ÊÇÓÉÓÚ·þÎñÆ÷ÅäÖÃÃýÎóµ¼Öµģ¬£¬Ã»ÓеǼʹ´¦ºÍÐÅÓþ¿¨ºÅй¶¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/twitch-no-credentials-or-card-numbers-exposed-in-data-breach/
5¡¢¡¢¡¢Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯
Cyberint·¢ÏÖ¶ñÒâÈí¼þVidarÔÚÐÂÒ»ÂÖ¹¥»÷»î¶¯Öлع顣¡£Vidar×Ô2018Äê10ÔÂÒÔÀ´ÆðÍ·»îÔ¾£¬£¬Ö¼ÔÚ´ÓÖ¸±êϵͳÖÐÇÔÈ¡µç×ÓÓʼþÍ´´¦¡¢¡¢¡¢Ì¸ÌìÕÊ»§¾ßÌåÐÅÏ¢¡¢¡¢¡¢cookieµÈÊý¾Ý¡£¡£Õâ´Î»î¶¯ÖУ¬£¬¹¥»÷ÕßÊ×ÏȳÉÁ¢MastodonÕ˺ţ¬£¬²¢ÔÚСÎÒ×ÊÁÏÃèÊö²¿ÃÅÔö³¤¶ñÒâÈí¼þʹÓõÄC2µÄIP¡£¡£Æä»¹Ê¹ÓÃÁËÁíÒ»ÖÖ·Ö·¢²½Ö裬£¬Ö±½ÓÔÚÉ罻ýÌåÆ½Ì¨ÉÏ·¢ËÍÐÂÎÅ£¬£¬»òÕßÊÇÀûÓÃÆÆ½âÓÎÏ·µÄtorrent¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2-configuration/


¾©¹«Íø°²±¸11010802024551ºÅ