ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ22ÖÜ

°ä²¼¹¦·ò 2018-06-04

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ28ÈÕÖÁ06ÔÂ01ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö £¬ÖµµÃ¹Ø×¢µÄÊǶà¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶£»Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶£»Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶£»strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å£»BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶ ¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄд¹µö»î¶¯£»×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯£»¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷ £¬²¿Ãſͻ§µÄÊý¾Ýй¶£»×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ££»±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎó £¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶ ¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö £¬±¾Öܰ²È«ÍþвΪÖÐ ¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢¶à¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶

        ¶à¿îTP-LINK²úÆ·ÖеÄ/usr/lib/lua/luci/torchlight/validator.luaÎļþ´æÔÚÊäÈëÑéÖ¤·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄJSONÒªÇó £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCE
2¡¢Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶

        Git ÔÚÓÃgit cloneʱûÓжÔsubmoduleµÄÎļþ¼Ð¶¨Ãû×ö×ã¹»µÄÑéÖ¤ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá·´Ä¿ÒâµÄ.gitmodulesÎļþ £¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://git-scm.com
3¡¢Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶

        Huawei 1288H V5ºÍ2288H V5´æÔÚJSON×¢Èë·ì϶ £¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬Åú¸ÄÖÎÀíÔ±ÃÜÂë £¬»ñȡϵͳµÄÖÎÀíȨÏÞ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en
4¡¢strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å

        strongSwan´æÔÚ»º³åÇøÒç¶Âí½Å £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿ÉºÄ¾¡×ÊÔ´ £¬½øÐлؾø·þÎñ¹¥»÷ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.strongswan.org/blog
5¡¢BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶

        BeaconMedaes TotalAlert Scroll Medical Air Systems WEB·þÎñÆ÷´æÔÚ°²È«·ì϶ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-144-01


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄд¹µö»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        RiskIQ×êÑÐÍŶӷ¢ÏÖÕë¶ÔMyEtherWalletµÄÒ»¸öд¹µö»î¶¯ ¡£¹¥»÷Õßͨ¹ý³ÉÁ¢Ò»¸ö¼Ù×°³ÉMyEtherWalletÖ§³ÖÍŶӵÄTelegram̸ÌìȺ×éÀ´·Ö·¢¶ñÒâMyEtherWallet¿Í»§¶Ë ¡£¸Ã¶ñÒⷨʽͨ¹ýGoNative.io½«WebÀûÓÃ×÷Ϊ±¾µØÀûÓð䲼 £¬ÓÃÓÚÇÔÈ¡Óû§µÄÍ´´¦ ¡£×êÑÐÈËÔ±°ä²¼ÁËÓйØIoC ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/myetherwallet-android/

2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        FireEye×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG Exploit Kit£¨EK£©´«²¼Ä¾ÂíGrobiosµÄ¶ñÒâ¹¥»÷»î¶¯ £¬¸Ã»î¶¯´Ó2018Äê3ÔÂ10ÈÕÆðÍ· ¡£GrobiosʹÓÃÁ˶àÖÖÌӱܼì²â¼¼Êõ £¬²¢Í¨¹ý¶à¸ö±¸·ÝºÍ´´½¨×Ô¶¯ÔËÐÐ×¢²á±íÏî¼°´òË㹤×÷À´ÊµÏÖÓÆ¾ÃÐÔ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72954/malware/rig-exploit-kit-grobios-campaign.html

3¡¢¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷ £¬²¿Ãſͻ§µÄÊý¾Ýй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ¼ÓÄôóµÄÁ½¼ÒÒøÐÐSimplii FinancialºÍÃÉÌØÀû¶ûÒøÐÐÔÚÖÜÒ»°ä·¢ÉêÃ÷³Æ²úÉúÍøÂ簲ȫÊÂÎñ £¬Simplii Financial°µÊ¾ £¬ËüÔÚÉÏÖÜÄ©·¢ÏÖ¹¥»÷Õß½Ó¼ûÁËÔ¼4ÍòÃûSimplii¿Í»§µÄÕË»§ÐÅÏ¢ ¡£µ«ÊÇSimplii Financial³Ðŵ100£¥·µ»¹ËùÊÜÓ°ÏìµÄÕË»§µÄËðʧ ¡£ÔÚSimplii°ä·¢ÉêÃ÷Ò»Ó×ʱºó £¬ÃÉÌØÀû¶ûÒøÐÐÒ²°ä²¼ÁËÀàËÆµÄÉêÃ÷ ¡£¸ÃÒøÐаµÊ¾ £¬ºÚ¿Í×Ô¼ºÔÚÉÏÖÜÈÕÁªÏµÁËËûÃÇ £¬Ðû³ÆÕ¼Óпͻ§Êý¾Ý ¡£ÃÉÌØÀû¶ûÒøÐÐûÓÐй©Óм¸¶à¿Í»§µÄÐÅϢй¶ £¬µ«°µÊ¾ËûÃÇÏàÐÅÒѾ­¹Ø¹ØÁ˺ڿͽøÈëÆäϵͳµÄÈë¿Úµã ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/two-canadian-banks-announce-hacks-over-the-weekend/

4¡¢×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ£

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        À´×ÔÃÜЪ¸ù´óѧºÍÕã½­´óѧµÄÒ»¸ö×êÑÐÓ××鳯¿Éͨ¹ýÉù²¨/³¬Éù²¨¹¥»÷À´·ÛËéÓ²ÅÌ£¨HDD£©µÄ¶ÁÈ¡¡¢Ð´ÈëºÍ´æ´¢Ö°ÄÜÒÔ¼°µ¼Ö²Ù×÷ϵͳ±ÀÀ£ ¡£×êÑÐÈËÔ±°µÊ¾ÕâÖÖ¹¥»÷Äܹ»Í¨¹ý±ãÒ˵Ą̈ʽµçÄÔ»ò±Ê¼Ç±¾µçÄÔµÄÑïÉùÆ÷½øÐÐ £¬Ò»ÖÖ¿ÉÄܵĹ¥»÷³¡¾°ÊÇ £¬Óû§½Ó¼ûÁ˶ñÒâÍøÕ¾²¢²¥·ÅÁËÓµÓзÛËéÐԵĶñÒâÉù²¨ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/sonic-tone-attacks-damage-hard-disk-drives-crashes-os/132343/

5¡¢±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎó £¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

        ƾ¾ÝKromtech SecurityµÄ»ã±¨ £¬±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄ2¸öAmazon S3¿É¹«¿ª½Ó¼û £¬µ¼Ö³¬¹ý5ÍòÃûÓû§µÄÐÅϢй¶ ¡£Õâ2¸öAWS bucketÔ̺¬±¾ÌïÒÆ¶¯ÀûÓÃHonda ConnectµÄÓû§µÄ¾ßÌåÐÅÏ¢ £¬ÀýÈçÐÕÃû¡¢ÐÔ±ð¡¢Óû§¼°Æä¿ÉÐÅÁªÏµÈ˵ĵ绰ºÅÂëºÍµç×ÓÓʼþµØÖ·¡¢ÕË»§ÃÜÂë¡¢Æû³µVINÂëºÍÆû³µConnect IDµÈ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/honda-india-left-details-of-50-000-customers-exposed-on-an-aws-s3-server/