Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©£»Õë¶ÔFPGA-CPU»ìºÏƽ̨µÄJackHammer¹¥»÷

°ä²¼¹¦·ò 2020-01-03


1.È«Çò8.15ÒÚÖÇÄÜÑïÉùÆ÷ÖÐÓÐÒ»°ëʹÓû§ÒþÖÔÃæ¶Ô·çÏÕ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¹ú¼ÊÊý¾Ý¹«Ë¾£¨IDC£©½øÐеÄÒ»Ïîµ÷²éÏÔʾ£¬ÔÚÈ«ÇòÔËÓªµÄ8.15ÒÚ¸öÖÇÄÜÑïÉùÆ÷ÖУ¬ÏÕЩÓÐÒ»°ëÔÚÍþвÓû§µÄÒþÖÔ¡£ÕâÊÇIDC¶ÔÈ«Çò8.15ÒÚ¸öÖÇÄÜÑïÉùÆ÷¡¢¼à¿ØÉãÏñÍ·ÒÔ¼°ÆäËûÖÇÄÜÉ豸£¨ÀýÈçÖÇÄܵçÊÓ£©½øÐÐ×êÑÐʱ·¢Ïֵġ£Ò»¸ö¸üÓÐȤµÄ·¢ÏÖÊÇ£¬ÕâЩÉ豸´óÎÞÊý¶¼ÊÇ×÷ΪÀñÎïÏúÊ۵ġ£ÈôÊÇÓû§³ïËãʹÓÃÕâЩÉ豸£¬½¨ÒéËûÃǰ´²½Öè²Ù×÷ÒÔ×î´óˮƽµØ½µµÍÆäÇÔÌýÄÜÁ¦¡£ÊÜÓ°ÏìµÄÉ豸ÀàÐÍ¿ÉÄÜÔ̺¬ÖÇÄÜÑïÉùÆ÷»òÖÇÄÜÍó±í¡¢°²È«ÉãÏñÍ·»ò±£Ä·ÉãÏñÍ·¡¢ÖÇÄÜÃÅËø¡¢ÖÇÄܵçÊÓÒÔ¼°ÖÇÄÜÍæ¾ß¡£


Ô­ÎÄÁ´½Ó£º

https://www.cybersecurity-insiders.com/half-of-the-global-815-million-smart-speakers-are-putting-users-privacy-at-risk/


2.×êÑÐÈËÔ±ÑÝʾÕë¶ÔFPGA-CPU»ìºÏƽ̨µÄJackHammer¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚ2019Äê12ÔÂ31ÈÕ°ä²¼µÄһƪÐÂÂÛÎÄÖУ¬Ò»ÈºÃÀ¹úºÍµÂ¹ú´âÕßÑÝʾÁËÈôºÎÀûÓÃÏÖ³¡¿É±à³ÌÃÅÕóÁУ¨FPGA£©¿¨À´ÌáÒé¸ü¿ìºÍ¸ü¿¿µÃסµÄJackHammer¹¥»÷¡£FPGAÊÇÄܹ»Ôö³¤µ½ÍÆËã»úϵͳ£¨Ì¨Ê½»ú»ò·þÎñÆ÷£©µÄ¸½¼Ó¿¨£¬½üÄêÀ´FPGAÒѾ­³ÉÎªÔÆÍÆËã»·¾³ÖеÄÒ»ÖÖ³£¼û²úÆ·£¬°¢ÀïÔÆºÍAWS¾ù¿ÉΪ¿Í»§Ìṩ»ùÓÚFPGAµÄ·þÎñÆ÷Ê·ý£¬Î¢Èí»¹ÖÂÁ¦ÓÚÔÚAzureÄÚ²¿¼¯³É»ùÓÚFPGAµÄ¼¼Êõ¡£×êÑÐÈËÔ±·¢ÏÖµ±´ÓÓû§ÅäÖõÄFPGAÖÐÆô¶¯¹¥»÷´úÂëʱ£¬Óë´ÓCPU¹¥»÷Ïà±ÈÄܹ»¸üÓÐЧµØÒýÆðλ·­×ª²¢ÒÔ¸ü¿ìµÄ¿ìÂʽøÐвÙ×÷£¬ÕâÊÇÓÉÓÚFPGA¿¨Ö±½ÓÏνÓËÄ´¦ÖÃÆ÷µÄ×ÜÏߣ¬´Ó¶øÄܹ»Ö±½Ó²»ÊÜÏ޶ȵؽӼûCPU»º´æºÍRAM´æ´¢Æ÷£¬´Ë±íFPGA²»Óô¦Öù̼þºÍOSÈí¼þ£¬´Ó¶øÊ¹ÆäÔËÐдúÂëµÄ¿ìÂʱÈͨ³£CPU¸ü¿ì¡£WolfSSLÔÚ12ÔÂ20ÈÕ°ä²¼µÄ4.3.0°æ±¾ÖÐÔ̺¬ÁËÒ»¸ö·ì϶£¨CVE-2019-19962£©µÄ½¨¸´·¨Ê½£¬ÓÃÓÚÔ¤·À»ººÍ½âJackHammer¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/fpga-cards-can-be-abused-for-faster-and-more-reliable-rowhammer-attacks/


3.²ÍÒûÓéÀÖ¹«Ë¾LandryϰȾ¶ñÒâÈí¼þ£¬¿Í»§Ö§¸¶ÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹ú²ÍÒû¡¢×¡ËÞ¼°ÓéÀÖ¹«Ë¾Landry֪ͨ¿Í»§ÆäÖ§¸¶¿¨Êý¾Ý¿ÉÄÜÔÚ°²È«ÊÂÎñÖÐй¶¡£Æ¾¾ÝÆäÍøÕ¾Éϰ䲼µÄ֪ͨ£¬¸Ã¹«Ë¾°µÊ¾¶ñÒâÈí¼þÖØÒª´ÓÆä¾Æ°ÉºÍ·¹µêÍøÂçÖ§¸¶¿¨Êý¾Ý¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê3ÔÂ13ÈÕµ½2019Äê10ÔÂ17ÈÕÆÚ¼ä£¬ÓÐ63¸ö¾Æ°ÉºÍ²ÍÌüÆ·ÅÆÊܵ½Ó°Ïì¡£Landry°µÊ¾ÔÚ2016Äê²úÉúÖ§¸¶¿¨Ð¹Â¶ÊÂÎñÖ®ºó£¬ËûÃÇÖ´ÐÐÁËÒ»ÖÖ°²È«½â¾ö¹æ»®£¬Í¨¹ý¶Ëµ½¶Ë¼ÓÃÜÀ´°µ²Ø¿Í»§µÄÖ§¸¶¿¨Êý¾Ý¡£µ«¸Ã°²È«Ö°ÄܽöºÏÓÃÓÚPoSÖÕ¶Ë£¬¶Ô¾Æ°ÉºÍ²ÍÌüµÄ¶©µ¥ÊäÈëϵͳûÓÐÓ°Ïì¡£Landry°µÊ¾ÊÂÎñµÄÔ­Òò¿ÉÄÜÊÇ·þÎñÔ±ÃýÎóµØÔÚ¶©µ¥ÊäÈëϵͳÉÏË¢Á˿ͻ§µÄÖ§¸¶¿¨£¬Òò¶ø¸Ã¹«Ë¾ÒÔΪֻÓÐÉÙÊýÓû§Êܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/landrys-notifies-customers-of-payment-card-incident/


4.¿ÆÂÞÀ­¶àÖݰÂÂÞÀ­ÊÐË®Îñ²¿ÃÅй¶²¿Ãſͻ§ÒþÖÔÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿ÆÂÞÀ­¶àÖݰÂÂÞÀ­ÊÐË®Îñ²¿ÃųƲ¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢¿ÉÄÜÒòÊý¾Ýй¶¶øÊܵ½ÇÖº¦£¬ÊÜÓ°ÏìµÄ¿Í»§ÎªÔÚ2019Äê8ÔÂ30ÈÕÖÁ10ÔÂ14ÈÕÆÚ¼äʹÓÃClick2GovÖ§¸¶ÏµÍ³½øÐÐÒ»´ÎÐÔ¸¶¿î»òÉèÖö¨ÆÚ¸¶¿îµÄ¿Í»§¡£Æ¾¾Ý¸ÃÊеĵ÷²é£¬Î´¾­ÊÚȨµÄ¹¥»÷ÕßÅú¸ÄÁËClick2GovÈí¼þµÄÒ»¶ÎÍÆËã»ú´úÂ룬ÓÃÓÚÇÔÈ¡ÐÕÃû¡¢Õ˵¥µØÖ·¡¢Ö§¸¶¿¨ÀàÐÍ¡¢Ö§¸¶¿¨ºÅ¡¢ÑéÖ¤ÂëÒÔ¼°µ½ÆÚÈÕÆÚµÈÐÅÏ¢£¬µ«²»Ô̺¬Éç»á°²È«ºÅÂë»òµ±¾ÖÐû¸æµÄIDºÅÂë¡£¸ÃÊÐË®Îñ²¿ÃÅÒѾ­ÆôÓÃÁËÒ»¸öÃûΪPaymentusµÄÐÂÖ§¸¶ÏµÍ³²¢ÔÚÆëÈ«¹ý¶Éµ½¸ÃÐÂϵͳ£¬¸ÃϵͳûÓÐÊܵ½Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://www.9news.com/article/news/local/aurora-water-data-breach/73-4a717e74-9827-4a05-bab9-25782737dda6


5.Big Monitoring Fabric°ä²¼°²È«¸üУ¬½¨¸´Á½¸ö·ì϶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Big Monitoring FabricÀûÓ÷¨Ê½½¨¸´ÁËÁ½¸ö¸ßΣ·ì϶£¬Ô̺¬XSS·ì϶£¨CVE-2019-19632£©ºÍÃô¸ÐÐÅϢй¶·ì϶£¨CVE-2019-19631£©¡£ÓÉBig Switch Networks¿ª·¢µÄBig Monitoring FabricÊÇÒ»ÖÖ»ìºÏµÄÔÆ¿É¼ûÐԺͰ²È«ÐÔ½â¾ö¹æ»®£¬Ö¼ÔÚΪ¿Í»§Ìṩͨ¹ýµ¥¸öÒDZí°å¼à¶½ÎïÀí¡¢Ðé¹¹ºÍÔÆ»·¾³µÄÄÜÁ¦¡£µÚÒ»¸öXSS·ì϶λÓÚ/loginÒ³ÃæÖУ¬ËüÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÔڵǼ¹ý³ÌÖÐÌá½»JavaScript XSSÓÐЧÄÚÈÝ×÷ΪÓû§Ãû£¬´Ó¶ø»ñµÃ¶ÔBig Monitoring FabricÀûÓ÷¨Ê½µÄÖÎÀí½Ó¼ûÒÔ¼°¶ÔÊÜÓ°ÏìϵͳµÄSSH½ÚÔį̀½Ó¼û¡£µÚ¶þ¸ö·ì϶ÔÊÐíµÍȨÏÞÖ»¶ÁÓû§»ñµÃÖÎÀíȨÏÞ£¬²¢Í¨¹ýSSH½ÚÔį̀½Ó¼ûÊÜÓ°ÏìµÄϵͳ£¬¾ßÌåÀ´Ëµ£¬Ö»¶Á»òÖÎÀíÔ±×éÖеÄÓû§Äܹ»Í¨¹ýAPI /api/v1/export½Ó¼ûSSH RSA˽ԿºÍÓÐЧµÄÓû§»á»°cookie£¨Ô̺¬ÖÎÀíÔ±µÄcookie£©¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/high-risk-vulnerabilities-addressed-big-monitoring-fabric


6.Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»®¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯¡£@Cody SixteenÔÚTwitter°ä²¼ÁËÓйØNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©µÄÓйØÐÅÏ¢£¬¸Ã·ì϶ӰÏìÁËNagios XI 5.6.9°æ±¾£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»Í¨¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁĿǰ³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ©¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534