ÃÀ¹úGilletteÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷£»Magecart¶ñÒâÓòÃûÐÔÃüÖÜÆÚµÄ·ÖÎö»ã±¨
°ä²¼¹¦·ò 2019-09-231.TescoÍ£³µÀûÓôæÔÚ·ì϶µ¼ÖÂÊýǧÍò³µÅÆÍ¼Ïñй¶
ÔÚ±íýThe Register±¨Â·ÊýǧÍòÕÅANPR£¨³µÅÆ×Ô¶¯¼ø±ð£©Í¼ÏñÔÚMicrosoft AzureÖж³öÖ®ºó£¬TescoÒÑ¹Ø¹ØÆäÍ£³µÑéÖ¤WebÀûÓá£ÕâЩͼÏñÓÉÓ¢¹ú¸÷µØµÄ19¸öTescoÍ£³µ³¡ËùÅÄÉãµÄ½øÈëºÍÍÑÀëµÄÆû³µÕÕÆ¬×é³É£¬ÕÕÆ¬ÖÐ͹ÆðÏÔʾÁËÆû³µµÄ³µÅÆ£¬¹ÌÈ»ÓÉÓÚ·Ö±æÂʽϵͶø¿´²»µ½¼ÝʻԱ¡£ANPRͼÏñÒÔ´øÓй¦·ò´ÁµÄjpegÌåʽ±£ÁôÔÚAzure blobÖУ¬²¢ÇÒͼÏñÎļþÃûÒ²Ô̺¬¹¦·òÐÅÏ¢£¬´Ó¶øÊ¹µÃÈκÎÕýÈ·´§¶È³öËùÐèHTTP POSTÒªÇóÌåʽµÄÈËÄܹ»ÅúÁ¿»ñÈ¡ÕâЩͼÏñÒÔ¹©·¸·¨Ê¹Óá£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2019/09/20/tesco_parking_app_10s_millions_anpr_photos_exposed/
2.ÐÂÎ÷À¼³èÎïÁãÊÛÉÌAnimatesÔâºÚ¿ÍÇÔÈ¡2700Ãû¿Í»§ÐÅÏ¢
ÐÂÎ÷À¼³èÎïÁãÊÛÉÌAnimatesÔâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂ2700λ¿Í»§µÄÓ×ÎҺͲÆÕþÐÅϢй¶¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê6ÔÂ29ÈÕÖÁ9ÔÂ13ÈÕÖ®¼ä£¬ÊÂÎñÔÒòÊÇδ¾ÊÚȨµÄµÚÈý·½½Ó¼û¡£Animates°µÊ¾¿Í»§µÄÐÅÓþ¿¨/½è¼Ç¿¨Êý¾ÝÊǹ¥»÷ÕßµÄÖ¸±ê£¬Í¬Ê±¿Í»§µÄÓ×ÎÒÐÅÏ¢Ò²Ôâй¶£¬Ô̺¬µØÖ·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ÃûºÍÃÜÂë¡£¶ÔÓÚʹÓÃLayby»òPayPalÔÚÏß¹ºÎïµÄ¿Í»§£¬Æä¸¶¿îÐÅÏ¢²»ÊÜÓ°Ïì¡£Animates»¹È·ÈϳÆÊµÌåµêµÄÂòÂôδÊÜÓ°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.animates.co.nz/data-breach/
3.ÃÀ¹úGilletteÒ½ÔºÔâÀÕË÷Èí¼þ¹¥»÷µ¼Ö·þÎñÖжÏ
ƾ¾ÝÃÀ¹úÎÀÉú²¿·¢³öµÄ¾¯±¨£¬GilletteÒ½ÔºÔÚÉÏÖÜÎåÔâµ½ÀÕË÷Èí¼þ¹¥»÷¡£¸Ã¹¥»÷Ô¼²úÉúÔÚÖÜÎåÁ賿3µã£¬µ¼ÖÂÒ½ÔºÔâ·êÁËÑϳÁµÄÍÆËã»úÎÊÌâÒÔ¼°·þÎñÖжϡ£ÔÚÖÜÎå·Å¹¤¹¦·ò£¬¸ÃÒ½ÔºµÄµç»°ÏµÍ³ÒѳÁÐÂÉÏÏߣ¬µ«ÈÔ²»ÄܲÉÈ¡ÈκÎл¼Õߣ¬²¢ÇÒÆä³¢ÊÔÊÒ¡¢ºôÎüÒ½Öμ°·ÅÉä¿ÆÒ²²»ÄÜÌṩ²é³ºÍÒ½ÖηþÎñ¡£¸ÃÒ½ÔºÕý½«ÃÅÕï·þÎñ»ò¼¹Øï·þÎñµÄ»¼Õß·ÖÁ÷ÖÁÆäËüÒ½Ôº¡£ÎÀÉú²¿ÖÒ¸æÆäËüÒ½Ôº¼ì²âÆäIT·þÎñ£¬²¢ÔÚ·¢ÏÖÈκοÉÒÉÄÚÈÝʱÌáÐѵ±¾Ö¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/wy-gillette-hospital-targeted-in-ransomware-attack/
4.Atlassian½¨¸´Jira ServerºÍService DeskÖеÄÁ½¸ö·ì϶
Atlassian°ä²¼Jira ServerºÍService DeskµÄ°²È«¸üУ¬½¨¸´Á½¸ö°²È«·ì϶¡£µÚÒ»¸ö·ì϶ÊÇURLõè¾¶±éÀú·ì϶£¨CVE-2019-14994£©£¬¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶²é¿´Ö¸±êÊ·ýÖеÄËùÓÐJiraÏîÄ¿£¬Ô̺¬Service DeskÏîÄ¿¡¢Jira CoreÏîÄ¿ºÍJira SoftwareÏîÄ¿¡£Tenable×êÑÐÈËÔ±Satnam Narang»ã±¨³Æ2.5Íò¶à¸öÒ×Êܹ¥»÷µÄÊ·ýÔÚÍøÉ϶³ö£¬ËüÃÇÊôÓÚÒ½ÁÆ¡¢µ±¾Ö¡¢½ÌÓýºÍÔì×÷ÐÐÒµµÈ¡£µÚ¶þ¸ö·ì϶ÊÇJira Importers²å¼þÖеÄÄ£°å×¢Èë·ì϶£¨CVE-2019-15001£©£¬¸Ã·ì϶ӰÏìÁËJira ServerºÍJira Data CenterµÄ7.0.10°æ±¾£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶Զ³ÌÖ´ÐдúÂë¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/jira-server-and-service-desk-fix-critical-security-bugs/
5.VMware½¨¸´ESXi¡¢WorkstationµÈ²úÆ·ÖеÄÁ½¸ö·ì϶
VMware°ä²¼°²È«¸üУ¬½¨¸´¶à¸ö²úÆ·ÖеÄÁ½¸ö·ì϶¡£µÚÒ»¸ö·ì϶ÊÇESXi¡¢Workstation¡¢Fusion¡¢VMRCºÍHorizon ClientÖеÄuse-after-free·ì϶£¬¸Ã·ì϶£¨CVE-2019-5527£©µÄCVSS v3ÆÀ·ÖΪ8.5·Ö£¬ÊÇÒ»¸öÐé¹¹»úÌÓÒÝ·ì϶£¬¿Í»§»úÉÏÓµÓзÇÖÎÀíԱȨÏ޵ı¾µØ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£µÚ¶þ¸ö·ì϶ÊÇWorkstationºÍFusionÖеÄDoS·ì϶£¨CVE-2019-5535£©£¬¸Ã·ì϶µÄCVSS v3ÆÀ·ÖΪ4.7·Ö¡£¸Ã·ì϶ÓëVMNATµÄIPv6ģʽÓйأ¬¹¥»÷ÕßÄܹ»Í¨¹ý·¢ËͶñÒâIPv6Êý¾Ý°üÀ´²»ÈÝNATģʽÏ¿ͻ§»úÉϵÄÍøÂç½Ó¼û¡£
ÔÎÄÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2019-0014.html
6.×êÑÐÍŶӰ䲼Magecart¶ñÒâÓòÃûÐÔÃüÖÜÆÚµÄ·ÖÎö»ã±¨
ƾ¾ÝRiskIQµÄÒ»·ÝÐÂ×êÑУ¬·¸×ï·Ö×ÓÔÚ¶þ´ÎÀûÓÃMagecart¶ñÒâÓòÃû½øÐÐÆäËü¶ñÒâ»î¶¯¡£ÔÚMagecartÁ÷Á¿±»sinkhole»òÆäËü·½Ê½ÖÕ³¡»î¶¯ºó£¬·¸×ï·Ö×Ó»á²É°ìÕâЩÓòÃû£¬´Ó¶øÀûÓñ»MagecartÉøÈëµÄÍøÕ¾·Ö·¢¶ñÒâ¸æ°×»ò½øÐÐÆäËü¶ñÒâ»î¶¯¡£ÕâÊÇÓÉÓÚÍøÕ¾ËùÓÐÕßÍùÍùûÓйØ×¢ÆäÍøÕ¾ÉÏÔËÐеÄJavaScript¾ç±¾£¬Êý¾ÝÏÔʾMagecartƲÔüÆ÷ÔÚÍøÕ¾ÉϵľùÔÈÍ£¶Ù¹¦·ò³¬¹ýÁ½¸öÔ£¬²¢ÇÒÓкܶàÏÕЩÊÇÎÞÆÚÏÞµØÍ£¶ÙÔÚÄÇÀï¡£ÕâÖÖ²»Ë½¼ûÐÔÒâζ×ÅÒ»µ©¶ñÒâÓòÃû±»Ôٴμ¤»î£¬¹¥»÷ÕßÄܹ»½øÐÐÆäËü¶ñÒâ»î¶¯À´Í¶»ú¡£
ÔÎÄÁ´½Ó£º
https://www.riskiq.com/blog/labs/magecart-reused-domains/


¾©¹«Íø°²±¸11010802024551ºÅ