ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ30ÖÜ
°ä²¼¹¦·ò 2018-07-30Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑлú¹¹ÖÒ¸æ³ÆÔ¼5ÒÚIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ï죻³¬¹ý100¼ÒÆû³µ³§É̵ĻúÃÜÊý¾Ýй¶£¬·áÌï¡¢ÌØË¹ÀµÈ¾ùÊÜÓ°Ï죻×êÑÐÈËÔ±·¢ÏÖÕë¶ÔOracle WebLogic·þÎñÆ÷µÄй¥»÷»î¶¯£»¸¥¼ªÄáÑÇÒøÐÐ8¸öÔÂÄÚ2´ÎÔâºÚ¿ÍÈëÇÖ£¬¹²ËðʧԼ240ÍòÃÀÔª£»ÖÐÔ¶º£ÔËÃÀ¹ú·Ö¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾¹ÙÍøÒṈ̃»¾¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢ASUS HG100ºÅÁîÖ´Ðа²È«·ì϶
ASUS HG100´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâÌØÊâÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://jenkins.io/security/advisory/2018-07-18/
2¡¢Cisco SD-WAN Configuration and Management DatabaseÔ¶³Ì´úÂëÖ´Ðзì϶
Cisco SD-WAN Configuration and Management DatabaseÔ¶´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔvmanageÓû§¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180718-sdwan-cx
3¡¢Intel Converged Security Management EngineËÁÒâ´úÂëÖ´Ðзì϶
Intel Converged Security Management EngineÔ¶³ÌÖÎÀí¹æ»®ÔÚʵÏÖÉÏ´æÔÚÂß¼·ì϶£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Ö´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00118.html
4¡¢McAfee Web GatewayÖÎÀí½çÃæËÁÒâ´úÂëÖ´Ðзì϶
McAfee Web GatewayÖÎÀí½çÃæ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
https://kc.mcafee.com/corporate/index?page=content&id=SB10245
5¡¢Dell EMC RSA Archer REST APIȨÏÞÌáÉý·ì϶
Dell EMC RSA Archer REST API´æÔÚÊÚÈ¨ÈÆ¹ý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ÌáÉýȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£º
http://seclists.org/fulldisclosure/2018/Jul/69
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑлú¹¹ÖÒ¸æ³ÆÔ¼5ÒÚIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì
Armis¹«Ë¾ÖÒ¸æ³ÆÔ¼5ÒÚ¸öIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì¡£DNS³Áа󶨹¥»÷ÊÇÖ¸¹¥»÷ÕߺýŪÓû§µÄä¯ÀÀÆ÷»òÉ豸°ó¶¨ÖÁ¶ñÒâµÄDNS·þÎñÆ÷µÄ¹¥»÷·½Ê½¡£Armis·ÖÎöÁËÕâÖÖ¹¥»÷¶ÔIoTÉ豸µÄÓ°Ï죬³ÆÏÕЩËùÓÐÀàÐ͵ÄÖÇÄÜÉ豸¶¼Ò×ÊÜ´ËÀ๥»÷£¬Ô̺¬ÖÇÄܵçÊÓ¡¢Â·ÓÉÆ÷¡¢´òÓ¡»ú¡¢¼à¶½Æ÷¡¢IPµç»°µÈ¡£½¨¸´ËùÓеÄÉ豸¿ÉÄÜÊÇÒ»ÏîÎÞ·¨ÊµÏֵŤ×÷£¬µ«½«IoTÉ豸¼¯³Éµ½°²È«¼à¿Ø²úÆ·ÖпÉÄÜÊÇ×îµ¥Ò»ÓÐЧµÄ½â¾ö¹æ»®¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/half-a-billion-iot-devices-vulnerable-to-dns-rebinding-attacks/
2¡¢³¬¹ý100¼ÒÆû³µ³§É̵ĻúÃÜÊý¾Ýй¶£¬·áÌï¡¢ÌØË¹ÀµÈ¾ùÊÜÓ°Ïì
UpGuard×êÑÐÈËÔ±Chris Vickery·¢ÏÖ¹©¸øÉÌLevel OneµÄ²»°²È«Êý¾Ý¿â£¬ÆäÖÐÔ̺¬½ü47000·ÝÎļþ£¬º¸Ç¶à¼ÒÆû³µ³§É̵ĽüÊ®ÄêµÄ¾ßÌåÀ¶Í¼¡¢¹¤³§µÀÀíͼ¡¢¿Í»§×ÊÁÏ£¨ÈçºÏͬ¡¢·¢Æ±ºÍ¹¤×÷´òËãµÈ£©£¬ÒÔ¼°¸÷Àà±£ÃܺÍ̸ÎļþµÈ¡£Ð¹Â¶µÄÊý¾Ý×ÜÁ¿´ï157GB£¬¸£ÌØ¡¢·áÌͨÓúÍÌØË¹ÀµÈ¾ùÊÜÓ°Ï졣й¶µÄÔÒòÊÇLevel One¹«Ë¾µÄÓÃÓÚ±¸·ÝÊý¾ÝµÄÎļþ´«ÊäºÍ̸rsync±»ÅäÖÃΪ¿É¹«¿ª½Ó¼û£¬²¢ÇÒ²»±ØÒªÈκÎÃÜÂë¡£
ÔÎÄÁ´½Ó£ºhttps://www.grahamcluley.com/robotics-suppliers-sloppy-security-leaks-ten-years-worth-of-data-from-major-car-manufacturers/
3¡¢×êÑÐÈËÔ±·¢ÏÖÕë¶ÔOracle WebLogic·þÎñÆ÷µÄй¥»÷»î¶¯
×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔOracle WebLogic·þÎñÆ÷µÄ¹¥»÷»î¶¯£¬ÕâЩ¹¥»÷»î¶¯ÖØÒªÀûÓ÷ì϶£¨CVE-2018-2893£©½øÐй¥»÷¡£OracleÔÚ7ÔÂ18ÈÕ°ä²¼Á˸÷ì϶µÄÓйز¹¶¡£¬7ÔÂ21ÈÕÆäÓйØPoC±»Åû¶¡£×êÑÐÈËÔ±·¢ÏÖÖÁÉÙ2¸ö×éÖ¯ÔÚÀûÓø÷ì϶½øÐй¥»÷£¬½¨Ò黹δ¸üеÄÓû§¾¡¿ì½øÐÐÉý¼¶¡£Ò×Êܹ¥»÷µÄ°æ±¾Ô̺¬10.3.6.0¡¢12.1.3.0¡¢12.2.1.2ºÍ12.2.1.3¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/attacks-on-oracle-weblogic-servers-detected-after-publication-of-poc-code/
4¡¢¸¥¼ªÄáÑÇÒøÐÐ8¸öÔÂÄÚ2´ÎÔâºÚ¿ÍÈëÇÖ£¬¹²ËðʧԼ240ÍòÃÀÔª
¾Ý¼ÇÕßBrian Krebs±¨Â·£¬ÃÀ¸¥¼ªÄáÑǹú¶ÈÒøÐÐÓÚ2016Äê5ÔÂÏÂÑ®ºÍ2017Äê1ÔÂÁ½´ÎÔâµ½´¹µöÓʼþµÄ¹¥»÷£¬¹²ËðʧԼ240ÍòÃÀÔª¡£µÚÒ»´Î¹¥»÷Öй¥»÷Õßͨ¹ý¶ñÒâÈí¼þϰȾÁËÒ»Ì¨ÍÆËã»ú£¬²¢¿ÉÄܽӼûÒøÐÐÄÚÍøºÍÈÆ¹ýPINÂë¡¢ÖðÈÕÈ¡¿îÏÞ¶ÈÒÔ¼°·´Ú²Æ´ëÊ©µÈ¡£µÚ¶þ´Î¹¥»÷µÄģʽÓëµÚÒ»´Î¹¥»÷ÀàËÆ¡£SynopsysÊ×ϯÕÕ·÷Chandu KetkarÒÔΪ£¬ÕâЩÊÂÎñÊÇÆä°²È«ÒâʶÅàѵ¡¢¼à¿ØºÍÓ¦¼±ÏìÓ¦µÈÕ½ÊõµÄʧ°Ü¡£
ÔÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/virginian-bank-robbed-twice-in/
5¡¢ÖÐÔ¶º£ÔËÃÀ¹ú·Ö¹«Ë¾ÔâÀÕË÷Èí¼þ¹¥»÷£¬¹«Ë¾¹ÙÍøÒṈ̃»¾
ÖÐÔ¶º£Ô˵ÄÃÀ¹ú·Ö¹«Ë¾Ôâµ½ÀÕË÷Èí¼þµÄ¹¥»÷£¬Æä¹«Ë¾ÍøÂçÒÑÏÝÈë̱»¾¡£¸ÃÊÂÎñ²úÉúÔÚ7ÔÂ24ÈÕÐÇÆÚ¶þ£¬µ«Ä¿Ç°¸Ã¹«Ë¾ÃÀ¹úµØÓòµÄIT»ù´¡ÉèÊ©ÈÔ´¦ÓڹعØÖ®ÖУ¬Ô̺¬µç×ÓÓʼþ·þÎñÆ÷ºÍµç»°ÍøÂçµÈ£¬Æä¹ÙÍøÒ²´¦ÓڹعØ×´Ì¬¡£Ï°È¾¸Ã¹«Ë¾ÍøÂçµÄÀÕË÷Èí¼þÀàÐÍÒÀȻδ֪£¬Ä¿Ç°¸Ã¹«Ë¾Ò²Î´×÷³ö¸ü¶à»ØÓ¦¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/ransomware-infection-cripples-shipping-giant-coscos-american-network/


¾©¹«Íø°²±¸11010802024551ºÅ