Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢£»2.6Íò¸öKibanaÊ·ý£»1.35Íò¸öiSCSI´æ´¢¼¯Èº

°ä²¼¹¦·ò 2019-04-03
1.×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄ·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬Ö¼ÔÚʵʱ³½ÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£´óÎÞÊý¶³öµÄÊ·ý¶¼Ã»ÓÐÊܵ½±£»¤£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§½Ó¼ûÒDZíÅÌ¡£ÕâЩÊ·ýÊôÓÚµç×Ó½ø½¨Æ½Ì¨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬ÃÀ¹ú£¨8311¸ö£©ÊǶ³öÊ·ý×î¶àµÄ¹ú¶È£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£´Ë±í£¬ºÜ¶àÊ·ý¶¼ÔËÐйýÆÚµÄÈí¼þ°æ±¾£¨´æÔÚËÁÒâÎļþÔ̺¬·ì϶£©¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/kibana-data-security.html

2.³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±A Shadow·¢ÏÖ³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö¡£ÕâЩ¼¯ÈºÒòδÆôÓÃÉí·ÝÑéÖ¤£¬µ¼Ö·¸×ï·Ö×ÓÄܹ»Í¨¹ý»¥ÁªÍø½Ó¼ûÕâЩ´ÅÅÌÕóÁкÍNASÉ豸£¬Ê¹µÃÆóÒµµÄÃô¸ÐÊý¾ÝÃæ¶Ô·çÏÕ¡£ÕâЩiSCSI¼¯ÈºÊôÓÚ˽Ӫ¹«Ë¾¡¢µ±¾Ö»ú¹¹¡¢´óѧºÍ×êÑлú¹¹µÈ£¬ÊÇÍøÂç·¸×OÍŵÄÃÎÏë¹¥»÷Ö¸±ê¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-13k-iscsi-storage-clusters-left-exposed-online-without-a-password/

3.ŦԼÊ׸®°Â¶û°ÍÄáÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬ËðʧÈÔÔÚÆÀ¹ÀÖÐ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ÃÀ¹úŦԼÖÝÊ׸®°Â¶û°ÍÄáÊÐÓÚ3ÔÂ30ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ±Ç°ÈÔ²»Ã÷ÏÔÆäÍÆËã»úϵͳµÄÊÜËðˮƽ£¬µ«Æ¾¾Ý¸ÃÊйÙÍø°ä²¼µÄÐÂΟ壬ËùÓеijÇÊзþÎñ¶¼ÒÑ¿ÉÓ㬵«µ®ÉúÖ¤Ã÷¡¢éæÃüÖ¤Ã÷ºÍ³É»éÖ¤Êé·þÎñÖ®±í¡£Ã»ÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÊý¾ÝÊÜË𣬵«³ÇÊеÄн×Ê·þÎñÊܵ½Ó°Ï죬²»ÄÜÈ·¶¨¸ÃÊÐÊÇ·ñ»áÖ§¸¶Êê½ð¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/

4.Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


3Ô³õSecurity DiscoveryµÄ°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖÓ¡¶È±±²¿Ò»¸öÖÝÈ·µ±¾ÖÒ½ÁƲ¿ÃÅÒâ±íй¶³¬¹ý1250Íò·ÝÔи¾µÄÒ½ÁƼͼ£¬ÕâЩ¼Í¼Ô̺¬ÐÕÃû¡¢µØÖ·¡¢´ºÇï¡¢µç»°¡¢Õï¶ÏºÍ¼²²¡ÐÅÏ¢¡¢»³Ì¥Çé¿ö¡¢»³Ì¥²¢·¢Ö¢¡¢USG/ÑòĤ´©´Ì/»ùÒò¼ì²âÐÅÏ¢¡¢º¢×ӵĸ¸Ç×ÐÕÃûµÈ¡£ÕâЩ¼Í¼×îÔç¿É×·ÒäÖÁ2014Äê¡£¸ÃÊý¾Ý¿âÔÚδÉèÃÜÂëµÄÇé¿öÏÂÏνӵ½»¥ÁªÍø£¬²¢ÔÚÍøÂçÉ϶³öÁ˳¬¹ý3ÖܵŦ·ò¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/indian-govt-agency-left-details-of-millions-of-pregnant-women-exposed-online/

5¡£Google°ä²¼4ÔÂAndroid°²È«¸üУ¬½¨¸´¶à¸ö·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Google°ä²¼4ÔÂAndroid°²È«¸üУ¬ÔÚ°²È«²¹¶¡¼¶±ð2019-04-01ÖУ¬Google½¨¸´ÁËÁ½¸ö¸ßΣRCE·ì϶ºÍ9¸öÌáȨ£¨EoP£©¼°ÐÅϢй¶£¨ID£©·ì϶¡£ÕâÁ½¸öRCE·ì϶ÊÇýÌå¿ò¼Ü×é¼þÖеķì϶£¨CVE-2019-2027ºÍCVE-2019-2028£©£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬Android 7.0¼°Ö®ºóµÄ°æ±¾¶¼ÊÜÓ°Ïì¡£ÁíÒ»¸ö°²È«²¹¶¡¼¶±ðÊÇ2019-04-05£¬½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fixes-two-critical-android-code-execution-vulnerabilities/

6.Apache°ä²¼Ð°汾2.4.39£¬½¨¸´¶à¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Apache HTTP Server 2.4.39Öн¨¸´Á˶à¸ö°²È«·ì϶£¬×îΪÑϳÁµÄ·ì϶ÊÇÌáȨ·ì϶£¨CVE-2019-0211£©£¬¸Ã·ì϶ӰÏìÁË2.4.17µ½2.4.38Ö®¼äµÄËùÓа汾£¬ÔÊÐíÓµÓо籾дÈëºÍÔËÐÐȨÏÞµÄÓû§»ñµÃrootȨÏÞ²¢Ö´ÐÐËÁÒâ´úÂë¡£´Ë±í£¬¸Ã°æ±¾»¹½¨¸´Á˽Ӽû½ÚÔìÈÆ¹ý·ì϶£¨CVE-2019-0217ºÍCVE-2019-0215£©¡¢¿ÉÄܵ¼Ö±ÀÀ£µÄ·ì϶£¨CVE-2019-0197£©¡¢read-after-free·ì϶£¨CVE-2019-0196£©ºÍURL¹æ·¶»¯²»Ò»Ö·ì϶£¨CVE-2019-0220£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apache-bug-lets-normal-users-gain-root-access-via-scripts/