ºÚ¿ÍÔÚ°µÍøÐ¹Â¶³¬¹ý50Íǫ̀É豸µÄTelnetÍ´´¦ £»Citrix°ä²¼´úÂëÖ´Ðзì϶CVE-2019-19781µÄ½¨¸´²¹¶¡

°ä²¼¹¦·ò 2020-01-20


1.ºÚ¿ÍÔÚ°µÍøÐ¹Â¶³¬¹ý50Íǫ̀É豸µÄTelnetÍ´´¦


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿ÍÔÚÒ»¸ö°µÍøÂÛ̳ÉÏй¶Á˳¬¹ý51.5Íǫ̀·þÎñÆ÷¡¢¼ÒÓ÷ÓÉÆ÷ºÍIoTÉ豸µÄTelnetÍ´´¦Áбí£¬ÁбíÖÐÔ̺¬Ã¿¸öÉ豸µÄIPµØÖ·ÒÔ¼°ÆäTelnet·þÎñµÄÓû§ÃûºÍÃÜÂë¡£ÕâÊÇÆù½ñΪֹÒÑÖªµÄ×î´óTelnetÃÜÂëй©¡£¾ÝZDNetÏàʶ£¬¸ÃÁбíÊÇÓÉDDoS³ö×â·þÎñµÄÔËÓªÕßÔÚÏß°ä²¼µÄ£¬¹¥»÷Õßͨ¹ýɨÃèÕû¸öInternetÀ´²éÕÒTelnet¶Ë¿Ú¶³öµÄÉ豸£¬²¢ÇÒ³¢ÊÔʹÓã¨1£©³ö³§ÉèÖõÄĬÈÏÓû§ÃûºÍÃÜÂë»ò£¨2£©×Ô½ç˵µ«Ò×Óڲ²âµÄÃÜÂë×éºÏ½øÐб¬ÆÆ¼ÙÔìÁ˸ÃÁбí¡£ÁбíÖÐËùÓÐÌõ¿î±êÈÕÆÚΪ2019Äê10ÔÂÖÁ11Ô£¬ÆäÖÐһЩÉ豸¿ÉÄÜÒѾ­¸ü»»ÁËIPµØÖ·»òÍ´´¦¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/hacker-leaks-passwords-for-more-than-500000-servers-routers-and-iot-devices/


2.ÎÚ¿ËÀ¼µ±¾Ö¹¤×÷ÃÅ»§ÍøÕ¾Ð¹Â¶²¿ÃŹ«ÃñµÄÓ×ÎÒÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý·͸É籨·£¬ÎÚ¿ËÀ¼¹ú¶È×î¸ß°²È«»ú¹¹ÉÏÖÜÎåÈϿɲ¿ÃŹ«ÃñµÄÓ×ÎÒÊý¾ÝÔÚµ±¾Ö¹¤×÷ÃÅ»§ÍøÕ¾ÖÐй¶¡£¹ú¶È°²È«ºÍ¹ú·ÀίԱ»áûÓÐ֤ʵй©ÊÇ·ñÊÇÍøÂç¹¥»÷µÄÁ˾Ö£¬Ò²Ã»ÓÐй©Óм¸¶àÊý¾ÝÊܵ½Ó°ÏìºÍÊÂÎñÓÉË­ÕÆ¹Ü£¬µ«°µÊ¾ÒѾ­¡°È·¶¨ÁË·ì϶¡±²¢ÇÒÃÅ»§ÍøÕ¾ÒѾ­µÃµ½± £»¤¡£Ä¿Ç°ÉÐÎÞ¸ü¶àϸ½ÚÅû¶¡£


 Ô­ÎÄÁ´½Ó£º

https://in.reuters.com/article/ukraine-cyber-leak/ukraine-says-personal-data-leaked-from-government-jobs-portal-idINKBN1ZG1OP


3.Õë¶Ô±±´ï¿ÆËûÖݵ±¾ÖµÄÍøÂç¹¥»÷¼¤ÔöÖÁÿÔÂ1500Íò´Î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾Ý¡¶Grand Forks Herald¡·±¨Â·£¬2019ÄêÕë¶Ô±±´ï¿ÆËûÖݵ±¾ÖµÄÍøÂç¹¥»÷³¢ÊÔÏÕЩ·­ÁËÈý±¶¡£±±´ï¿ÆËûÖÝÊ×ϯÐÅÏ¢¹Ù¼æÐÅÏ¢¼¼Êõ²¿ÃÅÕÆ¹ÜÈËФ¶÷¡¤À·û£¨Shawn Riley£©°µÊ¾£¬2019ÄêÿÔÂÓг¬¹ý1500Íò´ÎÕë¶Ô¸ÃÖݵ±¾ÖµÄÍøÂç¹¥»÷£¬×Ô2018ÄêÒÔÀ´Ôö³¤ÁË300£¥¡£ÔÚ2018Ä꣬ÿÔÂÔ¼ÓÐ500Íò´ÎδËìµÄÍøÂç¹¥»÷¡£È«¹ú¸÷µØµÄ´¦Ëùµ±¾Ö¶¼·¢ÏÖÍøÂç¹¥»÷ÓÐËùÔö³¤£¬µ«±±´ï¿ÆËûÖݵÄÇ÷ÏòÒª±ÈÆäËü×éÖ¯ÑϳÁһЩ£¬×ÜÌå¶øÑÔ£¬Ôö³¤Ï൱¿É¹Û¡£


 Ô­ÎÄÁ´½Ó£º

https://thehill.com/policy/cybersecurity/478936-cyber-attacks-against-north-dakota-state-government-skyrocket-to-15m-a


4.µç×ÓÉÌÎñƽ̨Zen Cart×¢Èë¹¥»÷£¬ÇÔÈ¡PayPalÕÊ»§ÃÜÂë


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Christopher Morrow½üÈÕ·¢ÏÖÕë¶Ô¿ªÔ´µç×ÓÉÌÎñƽ̨Zen CartµÄ×¢Èë¹¥»÷£¬¹¥»÷ÕßÖØÒªÇÔÈ¡Óû§µÄPayPalÕË»§ºÍÃÜÂë¡£Zen Cart×ÔÉíÊǾɰæOsCommerceµÄ·ÖÖ§£¬¸Ãƽ̨ºÜÉÙÔâµ½ÐÅÓþ¿¨Æ²ÔüÆ÷µÄ¹¥»÷£¬ÓÉÓÚÆ¾¾ÝW3µÄ×îÐÂÊý¾Ý£¬Ïà±ÈMagento£¨0.8£¥£©»òPrestashop£¨0.6£¥£©µÈÆäËû¿ªÔ´Æ½Ì¨£¬Zen CartµÄÓû§ÈººÜС£¨0.1£¥£©¡£×êÑÐÈËÔ±·¢ÏֵĶñÒâ´úÂë×¢Èëµ½Zen CartµÄPHPÎļþÖУ¬ËüרÃÅÕë¶ÔPayPal Payments Pro¸¶¿îÄ£¿é£¬²¶»ñÓû§µÄÓ×ÎÒÉí·ÝÐÅÏ¢£¨PII£©ºÍÖ§¸¶¿¨¾ßÌåÐÅÏ¢¡£


 Ô­ÎÄÁ´½Ó£º

https://blog.sucuri.net/2020/01/zen-cart-paypal-skimmer.html


5.×êÑÐÍŶӰ䲼Êý¾Ý²Á³ýÆ÷DustmanµÄ·ÖÎö»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2019Äê12Ô£¬IBM X-ForceÍŶӰ䲼ÁËÓйØÕë¶ÔÖж«µØÓòµÄ·ÛËéÐÔ¹¥»÷ÖеÄÊý¾Ý²Á³ý¶ñÒâÈí¼þZeroCleareµÄ·ÖÎö»ã±¨£¬Ô¼Ò»¸öÔºóÉ³ÌØ¹ú¶ÈÍøÂ簲ȫ¾Ö£¨NCA£©»ã±¨ÁËÕë¶ÔͳһµØÓòµÄZeroCleare±äÌ壬¸Ã±äÌå±»³ÆÎªDustman¡£DustmanµÄ×é¼þÓëZeroCleareʹÓõÄ×é¼þÀàËÆ£¬ÕâÔ̺¬Æä´úÂë¿âºÍ¶ÔTurlaÇý¶¯·¨Ê½µÄʹÓã¬ÒÔ¼°ÓÃÓÚ²Á³ýÊÜϰȾ»úе´ÅÅ̵ÄEldoS RawDiskÇý¶¯·¨Ê½ºÍÒ»ÑùµÄEldoSÈí¼þÐí¿ÉÖ¤ÃÜÔ¿¡£ZeroCleareºÍDustmanÖ®¼äµÄÇø±ðÔÚÓÚÎļþÃûºÍ²¿ÊðÁ÷³ÌµÄ΢Óױ䶯¡£


 Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/posts/enter-dustman-new-wiper-takes-after-zerocleare-targets-organizations-in-saudi-arabia/


6.Citrix°ä²¼´úÂëÖ´Ðзì϶CVE-2019-19781µÄ½¨¸´²¹¶¡


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CitrixÕë¶ÔÒѱ»»ý¼«ÀûÓõÄCVE-2019-19781·ì϶°ä²¼ÓÀÔ¶½¨¸´²¹¶¡£¬¸Ã·ì϶ӰÏìÁËCitrix Application Delivery Controller£¨ADC£©¡¢CitrixÍø¹ØºÍCitrix SD-WAN WANOPÉ豸£¬²¢ÇÒÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£CitrixÒѾ­°ä²¼ÁËADC°æ±¾11.1ºÍ12.0µÄÓÀÔ¶½¨¸´·¨Ê½£¬ÕâЩ²¹¶¡»¹ºÏÓÃÓÚÍйÜÔÚESX¡¢Hyper-V¡¢KVM¡¢XenServer¡¢Azure¡¢AWS¡¢GCP»òCitrix ADC·þÎñ½»¸¶É豸£¨SDX£©ÉϵÄCitrix ADCºÍCitrix GatewayÐé¹¹É豸£¨VPX£©¡£SDXÉϵÄSVM²»±ØÒª¸üС£³ý´ËÖ®±í£¬Citrix»¹¼Ó¿ìÁ˽«¸Ã²¹¶¡ÍÆË͵½ÆäËüADC°æ±¾ºÍSD-WAN WANOPµÄ¹ý³Ì£¬ÐµĹ̼þ½«ÔÚ1ÔÂ24ÈÕ°ä²¼¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/citrix-patches-cve-2019-19781-flaw-in-citrix-adc-111-and-120/