ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ27ÖÜ

°ä²¼¹¦·ò 2019-07-15

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ08ÈÕÖÁ14ÈÕ¹²ÊÕ¼°²È«·ì϶54¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFastjsonËÁÒâ´úÂëÖ´Ðзì϶£»Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶£»Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç¶Âí½Å£»Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´Ðзì϶£»Microsoft SQL Server CVE-2019-1068ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶¡£



±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǸæ°×Èí¼þAgent SmithϰȾԼ2500Íǫ̀AndroidÉ豸£»Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷£¬DNS¼Í¼±»´Û¸Ä£»ÍòºÀÒòÊý¾Ýй¼ûæ¶ÔÓ¢¹ú¼à¹Ü»ú¹¹1.23ÒÚÃÀÔª·£¿î£»ÊÓÆµ»áÒéÈí¼þZoom RCE·ì϶£¬¿É½Ù³ÖMacÉãÏñÍ·£»Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£



³ÁÒª°²È«·ì϶Áбí



1. FastjsonËÁÒâ´úÂëÖ´Ðзì϶


Fastjson autotype´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/alibaba/fastjson/wiki/update_faq_20190722

2. Apache Solr·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶


Apache Solr Config API´¦ÖÃPOSTÒªÇóÅäÖÃJMX·þÎñÆ÷´æÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£
https://seclists.org/oss-sec/2019/q1/169

3. Cesanta Mongoose ¡®mq_parse_http¡¯ º¯Êý»º³åÇøÒç¶Âí½Å


Cesanta Mongoose mongoose.cÎļþµÄ¡®mq_parse_http¡¯ º¯Êý´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐËÁÒâ´úÂë¡£
https://github.com/cesanta/mongoose/pull/1035

4. Microsoft Azure DevOps Server CVE-2019-1072´úÂëÖ´Ðзì϶


Microsoft Azure DevOps Server´¦ÖÃÌØÊâÎļþ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»TFS ·þÎñÕÊ»§µÄ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1072

5. Microsoft SQL Server CVE-2019-1068ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Microsoft SQL ServerÄÚ²¿º¯Êý´¦ÖôæÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ» SQL ServerÊý¾Ý¿âÒýÇæ·þÎñÕË»§¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1068


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢¸æ°×Èí¼þAgent SmithϰȾԼ2500Íǫ̀AndroidÉ豸


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check Point×êÑÐÈËÔ±·¢ÏÖԼĪÓÐ2500Íǫ̀AndroidÉ豸Òѱ»Ð¸æ°×Èí¼þAgent SmithϰȾ¡£¸Ã¶ñÒâÈí¼þÓÃÓÚÏòÓû§µÄÊÖ»úÍÆË͸æ°×£¬µ«¹¥»÷ÕßÒ²¿ÉÄܽ«ÆäÓÃÓÚ¸ü¶ñÒâµÄÖ÷ÕÅ£¬ÀýÈçÇÔÈ¡ÒøÐÐÍ´´¦¡£ÎªÁËʵÏÖ¸üÐÂ×°Öùý³Ì£¬¸Ã¶ñÒâÈí¼þÀûÓÃÁËJanus·ì϶£¬ÒÔÈÆ¹ýÀûÓ÷¨Ê½µÄÊðÃû²¢ÏòÆäÔö³¤ËÁÒâ´úÂë¡£ÊÜϰȾÉ豸ÊýÁ¿×î¶àµÄ¹ú¶ÈÊÇÓ¡¶È£¨³¬¹ý1500Íǫ̀£©£¬Æä´ÎÊÇÃϼÓÀ­¹ú£¨³¬¹ý250Íǫ̀£©ºÍ°Í»ù˹̹£¨½ü170Íǫ̀£©¡£Æ¾¾ÝCheck PointµÄµ÷²éÁ˾Ö£¬Agent Smith×îÔçÓÚ2016ËêÊׯðÍ·»î¶¯£¬Á½ÄêÀ´ËüÖØÒªÍ¨¹ýµÚÈý·½ÀûÓÃÉ̵ê9apps.com´«²¼¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/25-million-android-devices-infected-by-agent-smith-malware/

2¡¢Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷£¬DNS¼Í¼±»´Û¸Ä


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ï£À°¶¥¼¶ÓòÃû×¢²áÉÌICS-ForthÔâºÚ¿Í¹¥»÷¡£ICS-ForthÕÆ¹ÜÖÎÀíÏ£À°µÄ¶¥¼¶ÓòÃû.grºÍ.el£¬¸Ã×é֯ȷÈÏÔâµ½ºÚ¿ÍÈëÇÖ¡£¹¥»÷ÕßÓë˼¿ÆTalos4Ô·ݵĻ㱨ÖÐÃèÊöµÄ×éÖ¯Ò»Ñù£¬¼´·¸×ïÍÅ»ïSea Turtle¡£¸Ã×é֯ʹÓÃÒ»ÖÖÏà¶Ô½ÏеIJ½Öè¹¥»÷Ö¸±ê£¬ËûÃDz»»áÖ±½ÓÕë¶ÔÖ¸±ê£¬¶øÊÇÈëÇÖÓòÃû×¢²áÉÌ»òDNSÍйܷþÎñÉ̵ÄÕË»§£¬Åú¸ÄÖ¸±ê¹«Ë¾µÄDNSÉèÖ㬴Ӷø½«Ö¸±ê¹«Ë¾µÄÀûÓ÷¨Ê½»òµç×ÓÓʼþµÄÁ÷Á¿³Á¶¨ÏòÖÁ¹¥»÷ÕߵķþÎñÆ÷£¬Ö´ÐÐÖÐÑëÈ˹¥»÷²¢À¹½ØµÇ¼ʹ´¦¡£ÕâÖÖ¹¥»÷³ÖÐø¹¦·ò½Ï¶Ì£¬ÔÚÊýÓ×ʱÖÁÊýÌìÖ®¼ä£¬ÓÉÓÚ´óÎÞÊý¹«Ë¾Ã»ÓйØ×¢DNSÉèÖõĸü¸Ä£¬Òò¶øÕâÖÖ¹¥»÷ÄÑÒÔ±»¾õ²ì¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/hackers-breached-greeces-top-level-domain-registrar/

3¡¢ÍòºÀÒòÊý¾Ýй¼ûæ¶ÔÓ¢¹ú¼à¹Ü»ú¹¹1.23ÒÚÃÀÔª·£¿î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÊý¾Ý±£»¤»ú¹¹Öܶþ°µÊ¾½«ÏòÍòºÀ´¦ÒÔ9900ÍòÓ¢°÷£¨ºÏ1.23ÒÚÃÀÔª£©µÄ·£¿î£¬Ô­ÒòÊÇ2018Äê11ÔÂÍòºÀÆìÏÂϲ´ïÎݾƵêµÄ»áÔ±Êý¾Ýй¶ÊÂÎñ¡£¾ÝÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©³Æ£¬Å·ÖÞ31¸ö¹ú¶ÈµÄ½ü3000Íò¾ÓÃñºÍ700ÍòÓ¢¹ú¾ÓÃñÊܵ½ÍòºÀÊý¾Ýй¶µÄÓ°Ïì¡£ÕâÊÇ´ÓǰÁ½ÌìÄÚ²úÉúµÄµÚ¶þÆðÕë¶ÔÊý¾Ýй¶µÄ³Á´ó·£¿î֪ͨ¡£ÍòºÀ°µÊ¾¶ÔÐÅϢרԱ°ì¹«Êҵľö¶¨¸ÐÓ¦¾øÍû£¬ÔÚ±»´¦ÒÔ·£¿î֮ǰ£¬Ëü¡°ÓÐȨ×ö³ö»ØÓ¦¡±£¬²¢¡°³ïËã×ö³ö»ØÓ¦ÇÒ»ý¼«±£ÎÀ¡±×Ô¼ºµÄ̬¶È¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/marriott-data-breach-gdpr.html

4¡¢ÊÓÆµ»áÒéÈí¼þZoom RCE·ì϶£¬¿É½Ù³ÖMacÉãÏñÍ·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Jonathan LeitschuhÅû¶ÊÓÆµ»áÒéÈí¼þZoomÖеÄÒ»¸öRCE·ì϶£¬¸Ã·ì϶ӰÏìÁËMacƽ̨ÉϵÄZoom app°æ±¾4.4.4£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÓû§½Ó¼ûÍøÕ¾Ê±ÊÕÊÜÍøÂçÉãÏñÍ·¡£Æ¾¾ÝLeitschuhµÄ˵·¨£¬³¬¹ý400ÍòÓû§Ãæ¶Ô·çÏÕ¡£¸Ã·ì϶ÀûÓÃÁËZoomÈí¼þµÄµã»÷²ÎÓëÖ°ÄÜ£¬¼´Ö»Ðèµã»÷Ô¼ÇëÁ´½Ó¼´¿É×Ô¶¯¼¤»îϵͳÉÏ×°ÖõÄÀûÓ÷¨Ê½²¢Í¨¹ýWebä¯ÀÀÆ÷²ÎÓëÊÓÆµ»áÒé¡£¹¥»÷Õß¿Éͨ¹ý´¹µöÓʼþ·Ö·¢ÕâÖÖ¶ñÒâÁ´½Ó¡£Leitschuh»¹°µÊ¾ZoomµÄ½¨¸´Ö»ÊÇ×èÖ¹¹¥»÷Õß´ò¿ªÓû§µÄÉãÏñÍ·£¬¹¥»÷ÕßÈÔÄܹ»Í¨¹ý¶ñÒâÁ´½ÓÓÕʹÓû§²ÎÓë»áÒé¡£


Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/88147/hacking/zoom-mac-software-flaw.html

5¡¢Ó¢¹úº½¿Õ¹«Ë¾ÒòÊý¾Ýй¼ûæ¶Ô1.83ÒÚÓ¢°÷·£¿î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾µØ¹¦·ò7ÔÂ8ÈÕ£¬Ó¢¹úÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©°ä·¢£¬½«¶ÔÓ¢¹úº½¿Õ¹«Ë¾2018ÄêÊý¾Ýй¶ÊÂÎñ¿ª³ö1.83ÒÚÓ¢°÷¾Þ¶î·£µ¥¡£ÕâÊÇ×Ô¡¶Í¨ÓÃÊý¾Ý±£»¤ÌõÀý¡·£¨GDPR£©Ö´ÐÐÒÔÀ´×î´óµÄÒ»±Ê·£µ¥£¬Ò²ÊǵÚÒ»¸öƾ¾Ýй涨°ä²¼µÄ·£µ¥¡£Ó¢¹úº½¿Õ¹«Ë¾¸ß²ã¶ÔÕâ¸ö¾ö¶¨¸ÐÓ¦Õ𾪡£1.83ÒÚÓ¢°÷ÊÇÆ¾¾Ý¸Ã¹«Ë¾2017²ÆÄêÈ«Çò½»Ò×¶îµÄ1.5%ÍÆËãµÃÀ´£¬Æ¾¾ÝGDPR£¬ÕâÒ»´¦·£±ÈÀý×î¸ß¿É´ï4%¡£ÔÚ´Ë֮ǰ£¬ICO×î¸ßµÄ·£¿î¶îÊÇ50ÍòÓ¢°÷£¬2018ÄêFacebook½£ÇÅÊý¾Ý³óÎźÍ2017ÄêEquifax´ó¹æÄ£Êý¾Ýй¶¾ù±»´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/british-airways-breach-gdpr-fine.html