ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ51ÖÜ
°ä²¼¹¦·ò 2018-12-24
2018Äê12ÔÂ17ÈÕ23ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇWordPress two-factor-authentication²å¼þ¿çÕ¾ÒªÇóαÔì·ì϶£»ABB GATE-E1ºÍGATE-E2ÑéÖ¤ÈÆ¹ý·ì϶£»Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç¶Âí½Å£»DedeCMS uploads/include/dialog/select_images_post.phpËÁÒâ´úÂëÖ´Ðзì϶£»TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç¶Âí½Å¡£
³ÁÒª°²È«·ì϶Áбí
1. WordPress two-factor-authentication²å¼þ¿çÕ¾ÒªÇóαÔì·ì϶
WordPress two-factor-authentication²å¼þ´æÔÚ¿çÕ¾ÒªÇóαÔì·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶¹¹½¨¶ñÒâURI£¬ÓÕʹҪÇó£¬Äܹ»Ö¸±êÓû§¸ßµÍÎÄÖ´ÐжñÒâ²Ù×÷¡£
https://wordpress.org/plugins/two-factor-authentication/#developers2. ABB GATE-E1ºÍGATE-E2ÑéÖ¤ÈÆ¹ý·ì϶
ABB GATE-E1ºÍGATE-E2ÔÚÖÎÀítelnet»òweb½Ó¿ÚÖдæÔÚÑéÖ¤ÅäÖ÷ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɳÁÖÃÉ豸¡¢¶ÁÈ¡»òÅú¸Ä×¢²á±í¡¢Åú¸ÄIPµØÖ·µÈ¡£
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-013. Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç¶Âí½Å
Advantech WebAccess/SCADA´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-024. DedeCMS uploads/include/dialog/select_images_post.phpËÁÒâ´úÂëÖ´Ðзì϶
DedeCMS uploads/include/dialog/select_images_post.php´æÔÚÊäÈëÑéÖ¤ ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄË«³ÁÀ©´ó¼°Åú¸ÄµÄ.php×Ó×Ö·û´®ÒªÇ󣬿ÉÉÏ´«ËÁÒâÎļþ²¢Ö´ÐС£
http://www.iwantacve.cn/index.php/archives/88/5. TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç¶Âí½Å
TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
http://packetstormsecurity.com/files/150693/TRENDnet-Command-Injection-Buffer-Overflow-Cross-Site-Scripting.html³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀDoD³ÆÆäµ¯Â·µ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂ簲ȫÉó¼Æ
ƾ¾ÝÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý»ã±¨£¬ÃÀ¹úµÄµ¯Â·µ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂ簲ȫÉ󼯡£¸Ã»ã±¨Ö¸³öBMDSÉèʩδÄÜÖ´ÐÐÓ¦Óеݲȫ½ÚÔì´ëÊ©£¬Ô̺¬¶à³É·ÖÉí·ÝÈÏÖ¤¡¢·ì϶ÆÀ¹À»ººÍ½â¡¢·þÎñÆ÷»ú¼Ü°²È«¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵĻúÃÜÊý¾Ý±£»¤ºÍ¼¼ÊõÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£´Ë±í£¬Ò»Ð©ÎïÀí°²È«´ëʩҲûÓе½Î»£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚ±ØÒª×°ÖõĵØÎ»¡£¼à²ì³¤°ì¹«ÊÒÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý»ã±¨¡£
ÔÎÄÁ´½Ó£º
https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF
2¡¢Å·ÖÞÒé»áºÍÀíÊ»á°ä²¼¡¶Å·Ã˵ç×ÓͨѶ¹æ·¶£¨EECC£©¡·
Å·ÖÞÒé»áºÍÀíÊ»á°ä²¼¡¶Å·Ã˵ç×ÓͨѶ¹æ·¶£¨EECC£©¡·£¬¸Ã¹æ·¶ÊǶÔ2009Äê°ä²¼µÄÏÖÓеç×ÓͨѶÁ¢·¨¿ò¼ÜµÄ³Áж©Õý¡£Å·Ã˳ÉÔ±¹ú½«ÓÐÁ½ÄêµÄ¹¦·ò½«¸Ã¹æ·¶µÄÓйØÌõ¿îת»»Îª±¾¹úµÄ˾·¨¡¢ÂÉÀýºÍÐÐÕþ»®¶¨£¬ÕâÒ»×îºóÆÚÏÞÊÇ2020Äê12Ô¡£¸Ã¹æ·¶µÄÕûÌåÖ¸±êÊÇ¡°Ê¹Å·ÃËÔÚ2025ÄêÕ¾ÔÚ»¥ÁªÍøÏνӵÄ×îÇ°ÑØ-´´½¨Ò»¸öǧÕ×Éç»á¡±¡£¸Ã¹æ·¶»¹Ô̺¬¶Ô°²È«µÄ»®¶¨Ìõ¿î£ºµç×ÓÍ¨Ñ¶ÍøÂç·þÎñÉ̱ØÒª²ÉÈ¡ÏàÓ¦µÄ¼¼ÊõºÍ»úÔ죬ÒÔ×î´óÏ޶ȵØÏ÷¼õ°²È«ÊÂÎñ¡£
ÔÎÄÁ´½Ó£º
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018L1972
3¡¢Elasticsearch Kibana½ÚÔį̀ÎļþÔ̺¬·ì϶£¬PoC´úÂëÒѰ䲼
KibanaÊÇElasticsearchµÄÊý¾Ý¿ÉÊÓ»¯¹¤¾ß£¬ÆäConsole²å¼þ´æÔÚ±¾µØÎļþÔ̺¬£¨LFI£©·ì϶£¬×êÑÐÈËÔ±°ä²¼Á˸÷ì϶µÄPoC´úÂë¡£¸Ã·ì϶£¨CVE-2018-17246£©Ó°ÏìÁË6.4.3ºÍ5.6.13֮ǰµÄKibana°æ±¾£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ElasticÒÑÔÚ×îа汾µÄKibanaÖн¨¸´Á˸÷ì϶£¬ÈôÊÇÓû§ÁÙʱÎÞ·¨¸üУ¬Ò²Äܹ»ÔÚÅäÖÃÎļþÖнûÓøÃConsole²å¼þÀ´¶ã±ÜÕâÒ»ÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/file-inclusion-bug-in-kibana-console-for-elasticsearch-gets-exploit-code/
4¡¢NASAÅû¶Êý¾Ýй¶ÊÂÎñ£¬²¿ÃÅÔ±¹¤µÄPIIÐÅÏ¢±»µÁ
NASA±»ºÚ£¬Æ¾¾Ý¸Ã»ú¹¹µÄ˵·¨£¬NASAÔÚ10ÔÂ23ÈÕ·¢ÏÖÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬ÆäÒ»¸ö´æ´¢Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄ·þÎñÆ÷Ôâµ½ºÚ¿ÍÈëÇÖ£¬2006Äê7ÔÂÖÁ2018Äê10ÔÂÆÚ¼ä²ÎÓëNASAµÄÔ±¹¤µÄPIIÐÅϢй¶£¬Ô̺¬È¥Ö°»òµ÷Ö°µÄÔ±¹¤¡£NASAĿǰռÓÐÔ¼17300ÃûÔ±¹¤¡£¸Ã»ú¹¹°µÊ¾Ã»ÓÐÌ«¿Õ¹¤×÷Êܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/nasa-hack-data-breach.html
5¡¢SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δ½¨¸´µÄWindows 0day
×êÑÐÈËÔ±SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δ½¨¸´µÄWindows 0day£¬²¢ÇÒ°ä²¼ÁËÓйØPoC¡£Õâ¸öеķì϶´æÔÚÓÚWindowsµÄMsiAdvertiseProductÖ°ÄÜÖУ¬Æ¾¾Ý¸Ã×êÑÐÈËÔ±µÄ˵·¨£¬ÓÉÓÚûÓÐÕýÈ·ÑéÖ¤£¬¹¥»÷Õß¿ÉÀûÓøÃÖ°ÄÜвÆÈ×°Ö÷þÎñÒÔSYSTEMȨÏÞ¸´ÔìËÁÒâÎļþ²¢¶ÁÈ¡ÆäÄÚÈÝ£¬´Ó¶øµ¼ÖÂËÁÒâÎļþ¶ÁÈ¡·ì϶¡£SandboxEscaper»¹ÔÚGithubÉϰ䲼Á˸÷ì϶µÄPoC£¬µ«¸ÃGithubÕË»§Ä¿Ç°Òѱ»É¾³ý¡£SandboxEscaperÔøÔÚ2018Äê8Ô·ݺÍ10Ô·ݱðÀëÔÚTwitterÉÏÅû¶ÁËÁ½¸öWindows 0day¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/windows-zero-day-exploit.html
ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ