CDATA OLTÖдæÔÚ¶à¸ö0day £¬¿Éͨ¹ýtelnet½Ó¼ûºóÃÅ£»È¥Äê14.8£¥µÄAndroid¶ñÒâÈí¼þ²»³Éɾ³ý

°ä²¼¹¦·ò 2020-07-08

1.CDATA OLTÖдæÔÚ¶à¸ö0day £¬¿Éͨ¹ýtelnet½Ó¼ûºóÃÅ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CDATA OLTÖдæÔÚ¶à¸ö·ì϶ £¬¶Ô²úÆ·µÄ¶à¸ö°æ±¾¶¼ÓÐÓ°Ïì ¡£Õâ´Î·¢ÏÖµÄÖØÒª·ì϶Ô̺¬¿ÉʹÓÃtelnet½Ó¼ûºóÃÅ £¬¹¥»÷ÕßÄܹ»´ÓWAN½Ó¿ÚºÍFTTH LAN½Ó¿Ú½Ó¼ûtelnet·þÎñ £¬»ñµÃÖÎÀíÔ±CLI½Ó¼ûȨÏÞ£»Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÌåʽƾ֤£¨telnet£© £¬¹¥»÷Õß¿ÉÔÚCLIÖÐÔËÐкÅÁî»ñÈ¡ÖÎÀíԱʹ´¦£»ÓµÓÐrootÌØÈ¨µÄEscape Shell £¬CLIÖÐÓкÅÁî×¢ÈëÖ°ÄÜ £¬¹¥»÷ÕßÄܹ»ÒÔrootÓû§Éí·ÝÖ´ÐкÅÁԤÈÏÖ¤Ô¶³ÌDoS £¬¹¥»÷ÕßÄܹ»Ê¹ÓûùÓÚIA¡¢»úе½ø½¨ºÍshawarmaµÄÍÌͼ¼Êõ £¬³ÁÆôËùÓÐOLT£»Æ¾Ö¤ÐÅϢй©ºÍÃ÷ÎÄÆ¾Ö¤£¨HTTP£© £¬¹¥»÷Õß¿ÉÌáÈ¡Web¡¢Telnetƾ֤ºÍsnmp¹²Í¬Ì壨¶Áд£©£»Èõ¼ÓÃÜËã·¨£»ÖÎÀí½çÃæ²»°²È« £¬Ö»ÄÜʹÓÃHTTP¡¢telnetºÍSNMPÔ¶³ÌÖÎÀíÉ豸 £¬²»Ö§³ÖHTTP»òSSHµÄSSL / TLS £¬¹¥»÷ÕßÄܹ»À¹½ØÒÔÃ÷ÎÄ´ó¾Ö·¢Ë͵ÄÃÜÂë £¬²¢Í¨¹ýMITMÀ´½Ù³ÖÉ豸 ¡£


Ô­ÎÄÁ´½Ó£º

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html


2.Kaspersky·¢ÏÖÈ¥Äê14.8£¥µÄAndroid¶ñÒâÈí¼þ²»³Éɾ³ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Kaspersky×êÑÐÈËÔ±·¢ÏÖ £¬È¥ÄêÓÐ14.8£¥µÄAndroid¶ñÒâÈí¼þ²»³Éɾ³ý ¡£È¥Äê £¬ÊܵÃÊÖ»ú¶ñÒâÈí¼þ»òÊÖ»ú¸æ°×Èí¼þ¹¥»÷µÄ°²×¿Óû§ÖÐ £¬ÓÐ14.8£¥µÄÓû§ÏµÍ³·ÖÇøÔâµ½ÁËϰȾ ¡£Kaspersky°µÊ¾ £¬ÏµÍ³·ÖÇøÏ°È¾»á¸øÊܺ¦Õß´øÀ´ºÜ¸ßµÄ·çÏÕ £¬ÓÉÓÚ°²È«½â¾ö¹æ»®ÎÞ·¨½Ó¼ûϵͳĿ¼ £¬ÕâÒâζ×ÅËüÎÞ·¨É¾³ý¶ñÒâÎļþ £¬¶øÕâЩ¶ñÒâÈí¼þÄܹ»ÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂ×°ÖúÍÔËÐÐÀûÓ÷¨Ê½ ¡£Kaspersky·¢ÏÖ £¬ÔÚAndroidÖÇÄÜÊÖ»úµÄϵͳ·ÖÇøÖÐ×î³£¼ûµÄ¶ñÒâÈí¼þΪLezokºÍTriadaľÂí ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/android-users-undeletable-adware/157189/


3.OnePlus½¨¸´ÆäϵͳÖзì϶ £¬¿Éµ¼ÖÂÓû§Ó×ÎÒÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÖйúÊÖ»úÔì×÷ÉÌOnePlus·¢ÏÔì䷢ƱϵͳÖдæÔÚÒ»¸ö·ì϶ £¬¸Ã·ìÏ¶Éæ¼°ÃÀ¹úÉ豸µÄ±£½¨ÆÚ±íά½¨ £¬Ð¹Â¶Á˿ͻ§µÄ¾ßÌåÐÅÏ¢ £¬ÆäÖÐÔ̺¬ÐÕÃû¡¢µç»°ºÅÂë¡¢µçÓʵØÖ·¡¢IMEIºÅÂëºÍÎïÀíµØÖ· ¡£Æ¾¾ÝOnePlus·¢Õ¹µÄÄÚ²¿Éó¼ÆÏÔʾ £¬Ã»ÓÐÖ¤¾ÝÅú×¢¸Ã·ìÏ¶Ôø±»ÀûÓùý ¡£Ä¿Ç° £¬¼ø±ðϸ½ÚÒÑ´Ó·¢Æ±ÏµÍ³ÖÐɾ³ý £¬¸Ã·ì϶ÒѾ­±»½¨¸´ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.itsecurityguru.org/2020/07/06/oneplus-fixes-vulnerability-that-could-have-exposed-customer-personal-data/?utm_source=rss&utm_medium=rss&utm_campaign=oneplus-fixes-vulnerability-that-could-have-exposed-customer-personal-data


4.CybernewsÏóÕ÷ÖйúµÄÁ½¼Ò¹«Ë¾µÄÊý¾Ý¿â¿ÉÔÚÏß½Ó¼û


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CybernewsµÄ×êÑÐÈËÔ±·¢ÏÖÁËÁ½¸ö²»°²È«µÄÊý¾Ý¿âй¶ÁËÊý°ÙÍò±Ê¼Í¼ £¬ÕâÁ½¸öÊý¾Ý¿â±ðÀëÊôÓÚÖйú¹«Ë¾Ð¢ÐÅͨºÍÉϺ£ÑÓ»ªÖÇÄܿƼ¼ ¡£ÆäÖÐТÐÅͨµÄÊý¾Ý¿âÓг¬¹ý34Íò±Ê¼Í¼ £¬Ô̺¬ÊÖ»úºÅÂë¡¢µØÖ·ºÍGPSµØÎ»¡¢Óû§Ç×ÊôºÍÆäËû¼à»¤È˵ÄÊÖ»úºÅÂëºÍÐÕÃû¡¢µØÎ»¹ì¼££¨Ô̺¬µØÖ·ºÍGPS×ø±ê£©¡¢¹þÏ£ÃÜÂë¡¢SOS¼Í¼ºÍSOS¼Í¼µØÎ»¡¢Ó×ÎÒIDµÈ ¡£ÉϺ£ÑÓ»ªÐ¹Â¶Á˸ü¶àÃô¸ÐµÄÊý¾Ý £¬ÀýÈçÒ×ÓÚ½âÂëµÄÒôƵÎļþ¡¢ÐÕÃû¡¢Ô±¹¤IDºÅ¡¢ÐÄÂÊ¡¢ÑõÆøË®Æ½¡¢GPSµØÎ»µÈ ¡£Ä¿Ç° £¬ÕâÁ½¸öÊý¾Ý¿â¶¼ÒѹعØ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105609/data-breach/chinese-companies-data-leak.html?utm_source=rss&utm_medium=rss&utm_campaign=chinese-companies-data-leak


5.DXC×Ó¹«Ë¾XchangingϰȾÀÕË÷²¡¶¾ £¬ÉÐÔÚµ÷²éÖÐ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



È«ÇòIT·þÎñºÍ½â¾ö¹æ»®ÌṩÉÌDXC TechnologyµÄ×Ó¹«Ë¾XchangingµÄÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷ ¡£¸Ã¹«Ë¾ÓÚ7ÔÂ5ÈÕÅû¶Á˰²È«·ì϶ £¬µ«Éв»Ã÷ÏÔºÎʱ·¢ÏÖÕâ´Î¹¥»÷ÊÂÎñ ¡£¸Ã¹«Ë¾ÉÐδ͸©ÓйØÍøÂç¹¥»÷µÄ¾ßÌåÐÅÏ¢ £¬Ö»ÊÇÅú×¢ÊÇÀÕË÷Èí¼þϰȾÁËÆäϵͳ ¡£Æ¾¾ÝXchangingµÄ˵·¨ £¬Ö»Óп϶¨ÊýÁ¿µÄ¿Í»§Êܵ½ÍøÂç¹¥»÷µÄÓ°Ïì £¬DXCĿǰÒѽ«ÊÂÎñ»ã±¨¸ø·¨Âɲ¿ÃÅ £¬²¢ÔÚÓëÊÜÓ°ÏìµÄ¿Í»§ºÏ×÷ÒÔ¸´Ô­¶ÔÆäϵͳµÄ½Ó¼û ¡£´Ë±í £¬DXC°µÊ¾Ä¿Ç°Ã»ÓÐÈκμ£ÏóÅú×¢Êý¾ÝÒѱ»·ÛËé»òÃÔʧ ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105601/hacking/xchanging-ransomware-attack.html?utm_source=rss&utm_medium=rss&utm_campaign=xchanging-ransomware-attack


6.WatchGuard°ä²¼2020ÄêQ1»¥ÁªÍø°²È«»ã±¨


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


WatchGuard°ä²¼ÁË¡¶2020ÄêµÚÒ»¼¾¶È»¥ÁªÍø°²È«»ã±¨¡· £¬Ç¿µ÷Á˼ÓÃܶñÒâÈí¼þµÄΣÏÕ £¬ÌṩÁ˹ØÓÚCOVID-19µÄ°²È«Ó°ÏìµÄϸ½ÚµÈ ¡£Watchguard°µÊ¾ £¬ÔÚ2020ÄêµÚÒ»¼¾¶È½»¸¶µÄËùÓжñÒâÈí¼þÖÐ £¬ÓÐÈý·ÖÖ®¶þÒѼÓÃÜ £¬ÎÞ·¨²é³­´ËÀàÁ÷Á¿µÄ°²Õûϵͳ½«¶Ô´óÎÞÊý¶ñÒâÈí¼þ³¨¿ª´óÃÅ ¡£¸Ã»ã±¨ÐÅÏ¢À´×ÔÈ«ÇòÔ¼4.4Íò¸ö°²È«É豸µÄÄäÃûÊý¾Ý £¬ÕâЩÉ豸×èÖ¹ÁËԼĪ3200Íò¸ö¶ñÒâÈí¼þ±äÌåºÍԼĪ170Íò´ÎÍøÂç¹¥»÷ ¡£»ã±¨Ëµ £¬»ùÓÚÒ»ÑùµÄÊý¾Ý £¬¸ÃʱÆÚÄÚ72£¥µÄ¼ÓÃܶñÒâÈí¼þ±»¹éÀàΪ0day £¬Ã»Óв¹¶¡»ò¸üР¡£


Ô­ÎÄÁ´½Ó£º

https://www.globenewswire.com/news-release/2020/06/24/2052424/0/en/WatchGuard-Technologies-Report-Finds-Two-Thirds-of-Malware-is-Encrypted-Invisible-Without-HTTPS-Inspection.html