˼¿Æ½¨¸´·¢ÏÖºÍ̸£¨CDP£©ÖÐÎå¸ö¸ßΣ·ì϶£¬Ó°ÏìÊý°ÙÍòÉ豸£»×êÑÐÈËÔ±Åû¶º£Ë¼Ð¾Æ¬ÖÐÉÐ佨¸´µÄºóÃÅ·ì϶¼°PoC

°ä²¼¹¦·ò 2020-02-07

1.˼¿Æ½¨¸´·¢ÏÖºÍ̸£¨CDP£©ÖÐÎå¸ö¸ßΣ·ì϶£¬Ó°ÏìÊý°ÙÍòÉ豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÎïÁªÍø°²È«¹«Ë¾ArmisÔÚ˼¿Æ·¢ÏÖºÍ̸£¨CDP£©Öз¢ÏÖÎå¸ö¸ßΣ·ì϶£¬Ó°ÏìÊý°ÙÍòÉ豸 ¡£CDPÊÇ˼¿ÆÉ豸ʹÓõÄרÓеÚ2²ã£¨Êý¾ÝÁ´Â·²ã£©ºÍ̸£¬ÓÃÓÚ·¢ÏÖ±¾µØÍøÂçÉÏµÄÆäËü˼¿ÆÉ豸 ¡£Ä¬ÈÏÇé¿öÏ£¬ÏÕЩËùÓÐ˼¿Æ²úÆ·£¨Ô̺¬Â·ÓÉÆ÷¡¢»¥»»»úÒÔ¼°IPµç»°ºÍÉãÏñ»ú£©¾ùÆôÓô˺Í̸ ¡£ÕâÎå¸ö·ì϶±»³ÆÎªCDPwn£¬Ô̺¬ËĸöÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-3110¡¢CVE-2020-3111¡¢CVE-2020-3118¡¢CVE-2020-3119£©ºÍÒ»¸ö»Ø¾ø·þÎñ·ì϶£¨CVE-2020-3120£© ¡£´ÓǰʮÄêÖа䲼µÄ˼¿Æ¹Ì¼þ°æ±¾¾ùÊܵ½ÕâЩ·ì϶µÄÓ°Ï죬ÕâЩ·ì϶¿ÉÄÜÊ¹ÉøÈëµ½ÆóÒµÍøÂçÖеı¾µØ¹¥»÷Õß¿ÉÄÜÖ´ÐÐÖÐÑëÈ˹¥»÷¡¢¼à¶½ÓïÒô»òÊÓÆµºô½Ó×¢ÍøÂçºÍй©Êý¾ÝÒÔ¼°·ÛËéÍøÂç·Ö¶Î ¡£Ä¿Ç°Ë¼¿ÆÒѾ­°ä²¼ÁËÓйزúÆ·µÄ¹Ì¼þ¸üÐÂÀ´½¨¸´ÕâЩ·ì϶ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-patches-critical-cdp-flaws-affecting-millions-of-devices/


2.×êÑÐÈËÔ±Åû¶º£Ë¼Ð¾Æ¬ÖÐÉÐ佨¸´µÄºóÃÅ·ì϶¼°PoC



GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÂÞ˹°²È«×¨¼ÒVladislav Yarmak°ä²¼ÁËËûÔÚº£Ë¼Ð¾Æ¬Öз¢ÏֵĺóÃÅ»úÔìµÄ¼¼Êõϸ½Ú£¬²¢°µÊ¾ÓÉÓÚ¶Ô¹©¸øÉ̲»×ãÐÅÀµ£¬ËûûÓÐÏòº£Ë¼Åû¶¸Ã·ì϶ ¡£¸ÃºóÃÅ»úÔìÄܹ»Ê¹¹¥»÷Õß»ñµÃroot shell½Ó¼ûȨÏÞ²¢ÆëÈ«½ÚÔìÉ豸£¬¾ßÌåÀ´Ëµ£¬¹¥»÷Õß¿ÉÄÜÀûÓà ºóÃÅͨ¹ýÔÚTCP¶Ë¿Ú9530ÉÏÏò»ùÓÚº£Ë¼Ð¾Æ¬µÄÉ豸·¢ËÍһϵÁкÅÁÕâЩºÅÁîÔÊÐí¹¥»÷ÕßÔÚÉ豸ÉÏÆôÓÃTelnet·þÎñ£¬¶øºó¹¥»÷ÕßÄܹ»Ê¹ÓÃÁù¸öTelnetÍ´´¦Ö®Ò»µÇ¼£¬²¢»ñµÃ¶ÔrootÕÊ»§µÄ½Ó¼ûȨÏÞ ¡£Yarmak»¹ÔÚgithubÉϰ䲼Á˸÷ì϶µÄPoC´úÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/97367/hacking/hisilicon-chips-backdoor.html


3.×êÑÐÈËÔ±·¢ÏÖÃÀ¹ú¹ú·À²¿£¨DOD£©ÍøÕ¾ÔËÐÐÃÅÂÞ±ÒÍÚ¿ó·þÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±ÉϸöÔ·¢ÏÖÃÀ¹ú¹ú·À²¿£¨DOD£©ÔËÓªµÄWeb·þÎñÆ÷ÖÐϰȾÁ˼ÓÃÜÇ®±ÒÍÚ¿ó½©Ê¬ÍøÂç ¡£Ó¡¶È°²È«×êÑÐÔ±Nitesh Suranaͨ¹ý¹ú·À²¿µÄ¹Ù·½·ì϶Éͽð´òËã·¢ÏÖ²¢»ã±¨ÁË´ËÎÊÌâ ¡£×î³õ£¬·ì϶»ã±¨ÊÇÕë¶ÔÓëDODÓò¹ØÁªµÄAWS·þÎñÆ÷ÉÏÔËÐеÄÅäÖÃÃýÎóµÄJenkins×Ô¶¯»¯·þÎñÆ÷Ìá½»µÄ£¬Surana·¢ÏÖÈκÎÈ˶¼Äܹ»ÔÚûÓеǼʹ´¦µÄÇé¿öϽӼûJenkins·þÎñÆ÷ ¡£ºóÀ´SuranaÒâʶµ½¸ÃJenkins·þÎñÆ÷ÔÚËû·¢ÏÖ֮ǰÒѾ­Ï°È¾ÁËÃÅÂÞ±ÒÍÚ¿ó½©Ê¬ÍøÂç ¡£ÀûÓÃXMRHunter·þÎñ£¬×êÑÐÈËÔ±·¢ÏÖ½©Ê¬ÍøÂçµÄÃÅÂÞ±ÒµØÖ·µ±Ç°³ÖÓÐ35.4¸öÃÅÂÞ±Ò£¬¼ÛÖµÂÔ¸ßÓÚ2700ÃÀÔª£¬µ«Õâ²¢²»ÄÜÕýÈ·¹À¼Æ¸Ã½©Ê¬ÍøÂçµÄÔËÐÐÇé¿ö ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/bug-hunter-finds-cryptocurrency-mining-botnet-on-dod-network/


4.ÂíË¹ÌØÀïºÕÌØ´óѧÏòÀÕË÷Èí¼þ¹¥»÷ÕßÖ§¸¶30±ÈÌØ±ÒÊê½ð


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÂíË¹ÌØÀïºÕÌØ´óѧ°µÊ¾ÔÚÔâµ½ÀÕË÷Èí¼þ¹¥»÷ºó£¬ËüÖ§¸¶ÁË30±ÈÌØ±ÒµÄÊê½ðÒÔ¸´Ô­ÆäÍÆËã»úϵͳ ¡£¸Ã´óѧ¸±Ð£³¤Äá¿Ë¡¤²©Ë¹£¨Nick Bos£©ÔÚÐÂÎŰ䲼»áÉÏ·ÖÏíÁËÕâÒ»Êý×Ö ¡£BosÖ¸³ö£¬¸ÃÊÂÎñʼÓÚ2019Äê11Ô£¬´¹µö¹¥»÷ÕßÈëÇÖÁËÒ»Ãû´óѧԱ¹¤µÄµç×ÓÓʼþÕÊ»§£¬¶øºóÔÚ12ÔÂ24ÈÕͨ¹ýÀÕË÷Èí¼þÏ°È¾Ëø¶¨ÁË´óѧµÄÍÆËã»úϵͳ£¬µ¼ÖÂÔ±¹¤ÎÞ·¨½Ó¼ûÆäµç×ÓÓʼþ»ò¹¤×÷Õ¾ ¡£Æ¾¾ÝÊý×Ö°²È«¹«Ë¾Fox-ITµÄµ÷²é£¬¸Ã¹¥»÷ÊÂÎñÓë·¸×ïÍÅ»ïTA505ÓйØ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.tripwire.com/state-of-security/security-data-protection/university-of-maastricht-paid-30-bitcoins-to-ransomware-attackers/


5.ÈÕ±¾¹ú·À³Ð°üÉÌPascoºÍKobelco±ðÀëÅû¶ºÚ¿ÍÈëÇÖÊÂÎñ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÈÕ±¾¹ú·À³Ð°üÉÌPasco Corporation£¨Pasco£©ºÍKobe Steel£¨Kobelco£©±ðÀëÅû¶ÁË2018Äê5ÔºÍ2015Äê6ÔÂ/2016Äê8Ô²úÉúµÄºÚ¿ÍÈëÇÖÊÂÎñ ¡£KobelcoÊÇÈÕ±¾×ÔÎÀ¶Ó£¨SDF£©Ç±Í§Áã¼þµÄ³ÛÃû¹©¸øÉÌ£¬¶øPascoÊÇÎÀÐÇÊý¾ÝµÄÌṩÉÌ£¬¶þÕß»¹È·ÈÏÁËÁ½´ÎÊÂÎñÆÚ¼äÆäÄÚ²¿ÍøÂç¾ùÔ⵽δÊÚȨ½Ó¼ûÒÔ¼°ÔÚ¹¥»÷ºóÆäÍÆËã»úϵͳÔâµ½¶ñÒâÈí¼þϰȾ ¡£Æ¾¾ÝPasco°ä·¢µÄ¹Ù·½ÉêÃ÷£¬µ½Ä¿Ç°ÎªÖ¹µ÷²éÖÐûÓз¢ÏÖÖîÈçÐÅϢй©֮ÀàµÄÇÖº¦ ¡£µ«Ö»¹ÜKobelcoµÄ¹Ù·½ÉêÃ÷ûÓÐÌá¼°£¬¡¶ÈÕ¾­ÐÂÎÅ¡· ±¨Â·¸Ã¹«Ë¾µÄ250¸öÔ̺¬Óë¹ú·À²¿ºÍÓ×ÎÒÐÅÏ¢ÓйصÄÊý¾ÝÎļþÔâµ½ÇÖº¦ ¡£Á½¼Ò¹«Ë¾ÊÇ2016ÄêÖÁ2019ÄêÆÚ¼äÈÕ±¾±»ºÚ¿ÍÈëÇÖµÄËļÒÓë¹ú·ÀÓйصĹ«Ë¾ÖеÄ×îºóÁ½¼Ò£¬Áí±íÁ½¼ÒÊÇÈýÁâµç»úºÍNEC£¬ËüÃDZðÀëÔÚ1ÔÂ20ÈÕºÍ1ÔÂ30ÈÕ°ä²¼µÄÉêÃ÷ÖÐ֤ʵÆäϵͳÔâµ½ÈëÇÖ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/japanese-defense-contractors-kobe-steel-pasco-disclose-breaches/


6.¶íÀÕ¸ÔÖÝÒ½Áƹ©¸øÉÌHealth Shareй¶65.4Íò»¼ÕßÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¶íÀÕ¸ÔÖÝÒ½ÁƲ¹ÖúЭµ÷×éÖ¯£¨CCO£©µÄHealth ShareÅû¶һÏîÊý¾Ýй¶ÊÂÎñ£¬ÔÚÔËÊ乩¸øÉÌGridWorks ICµÄ±Ê¼Ç±¾µçÄÔ±»µÁºó¹²ÓÐ654362Ãû»¼ÕßµÄÐÅϢй¶ ¡£¸ÃÊÂÎñ²úÉúÔÚ2019Äê11ÔÂ18ÈÕ£¬±»µÁµÄ±Ê¼Ç±¾µçÄÔÔ̺¬¼¸ÖÖÀàÐ͵ϼÕßÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç»°ºÅÂë¡¢µ®ÉúÈÕÆÚ¡¢Éç»á±£ÏպźÍÒ½ÁƲ¹ÖúIDºÅ ¡£Æ¾¾ÝHealth ShareµÄÉêÃ÷£¬¸ÃÊÂÎñ²¢Î´Â¶³ö»¼ÕßµÄÒ½Áƺ¹Çà¼Í¼ ¡£Health Share½«ÎªÊÜÓ°ÏìµÄ»¼ÕßÌṩ1ÄêµÄÃâ·ÑÉí·Ý¼à¿Ø·þÎñ£¬Ô̺¬ÐÅÓþ¼à¿Ø¡¢Ú²Æ­Õ÷ѯºÍÉí·Ý͵ÇÔ¸´Ô­ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/medicaid-cco-vendor-breach-exposes-health-personal-info-of-654k/