ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ10ÖÜ

°ä²¼¹¦·ò 2020-03-10

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼°²È«·ì϶52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´Ðзì϶; Rubetek SmartHome²¨¶ÎÉè¼Æ·ì϶£»Envoy²»ÕýÈ·½Ó¼û½ÚÔì·ì϶£»Qualcomm MDM9206 WLAN»º³åÇøÒç¶Âí½Å£»Google Chrome media°²È«Èƹý·ì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Ê飻CrowdStrike°ä²¼¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·£»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷· £¿î£»°Ä´óÀûÑÇACSC°ä²¼CMSϵͳ°²È«Ö¸ÄÏ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


>³ÁÒª°²È«·ì϶Áбí


1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´Ðзì϶


FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ´æÔÚºÚÃûµ¥Èƹý·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉÖ´ÐÐËÁÒâ´úÂë¡£

https://github.com/FasterXML/jackson-databind/issues/2631


2. Rubetek SmartHome²¨¶ÎÉè¼Æ·ì϶


Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î½øÐÐͨѶ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢»ò½øÐлؾø·þÎñ¹¥»÷¡£

https://pastebin.com/CckKKJcM


3. Envoy²»ÕýÈ·½Ó¼û½ÚÔì·ì϶


EnvoyʹÓÃSDS´æÔÚ²»ÕýÈ·½Ó¼û½ÚÔì·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼ûÊÜÏÞ×ÊÔ´¡£

https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8


4. Qualcomm MDM9206 WLAN»º³åÇøÒç¶Âí½Å


Qualcomm MDM9206 WLAN´æÔÚ»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ɽøÐлؾø·þÎñ¹¥»÷»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£

https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin


5. Google Chrome media°²È«Èƹý·ì϶


Google Chrome media´¦Öð²È«Õ½Êõ´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬Î´ÊÚȨ½Ó¼û¡£

https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâ·êÊý¾Ýй¶ÊÂÎñ£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼Æ¾«ÃÜÁã¼þµÄÔì×÷ÉÌ¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉêÃ÷ÖУ¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂ簲ȫ·¸×ïÊÂÎñ£¨Ô̺¬½Ó¼ûºÍ͵ÇÔÊý¾Ý£©µÄÖ¸±ê¡±¡£¸Ã¹«Ë¾½²»°È˰µÊ¾½«¡°³ÖÐø¶Ô¸Ã¹¥»÷½øÐÐÈ«Ãæµ÷²é£¬²¢ÇÒÒµÎñÔËÐÐÕý³£¡±¡£TechCrunch×êÑÐÈËÔ±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£


Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2020/03/01/visser-breach/


2¡¢4Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Êé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug£¬Let's EncryptÏîÄ¿´òËã´ÓÊÀ½ç±ê¶¨¹¦·ò2020Äê3ÔÂ4ÈÕ00:00ÆðÍ·³·Ïú³¬¹ý300Íò¸öTLSÖ¤Êé¡£¾ßÌåÀ´Ëµ£¬¸ÃbugÓ°ÏìÁËBoulder£¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤ÊéÐû¸æ»ú¹¹ÊÚȨ£©¹æ·¶µÄÖ´ÐУ¬¡°µ±Ò»¸öÖ¤ÊéÒªÇóÔ̺¬N¸ö±ØÒª½øÐÐCAA³Áв鳭µÄÓòÃûʱ£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢²é³­N´Î¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚ¹¦·òXÑéÖ¤ÁËÒ»¸öÓòÃû£¬²¢ÇÒ¸ÃÓòÃûÔÚ¹¦·òXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬Ôò¸ÃÓû§Äܹ»ÔÚX+30ÌìµÄ¹¦·òÀ￯ÐÐÔ̺¬¸ÃÓòÃûµÄÖ¤Ê飬¼´±ãÖ®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁ˲»ÈÝLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£ÔÚÕâ300Íò¸ö³·ÏúµÄÖ¤ÊéÖУ¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄ³Á¸´ÏÒò¶øÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýÁ¿Ô¼Îª200Íò¸ö¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÀûÓ÷¨Ê½ÖеÄÃýÎó£¬ÓòÃûËùÓÐÕß½«±Ø±ØÒªÇóеÄTLSÖ¤Êé²¢´úÌæ¾ÉµÄTLSÖ¤Êé¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/


3¡¢CrowdStrike°ä²¼¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·¶Ô´ÓǰһÄêÖж¥¼¶ÍøÂçÍþвÇ÷Ïò½øÐÐÁËÉî¿Ì·ÖÎö£¬¸Ã»ã±¨µÄÖØµãÔ̺¬£º´óÐ͹¥»÷»î¶¯£¨BGH£©²»ÐÝÉý¼¶£¬Êê½ðÒªÇóì­ÉýÖÁÊý°ÙÍò£¬²¢ÇÒÔì³É¼«´óµÄ·ÛËé£»ÍøÂç·¸×ï·Ö×ÓÔÚʹÃô¸ÐÊý¾Ý±øÆ÷»¯£¬ÒÔÔö³¤¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»eCrimeÉú̬ϵͳ²»ÐÝ·¢Õ¹£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½²»ÐÝÌá¸ß£»ÔÚBGHÖ®±í£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔö³¤£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÊõµÄÇ÷ÏòÔڼӿ죻¹ú¶ÈÔÞÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ³ÖÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùµý±¨£¬ÍƽøÉçÇøÄÚ²¿µÄ¸îÁÑ£¬²¢¹Û²ìµ½ÁËÓëÏȽøeCrime¹¥»÷ÕߵĺÏ×÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/


4¡¢Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷· £¿î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940Íò³Ë¿ÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ· £¿î¡£¸Ã¹¥»÷ÒÉËÆ²úÉúÔÚ2018Äê3Ô·Ý£¬²¢ÓÚ5Ô·ݵõ½È·ÈÏ£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£ICOµ÷²é³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬²¢·¢ÏÖ¹úÌ©ÔÚ°²È«ÐÔ·½ÃæµÄһЩ²»¼°£¬Ô̺¬²»ÊÜÃÜÂë±£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýÆÚµÄ²Ù×÷ϵͳºÍ²»×ã·À²¡¶¾±£»¤µÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/


5¡¢°Ä´óÀûÑÇACSC°ä²¼CMSϵͳ°²È«Ö¸ÄÏ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©°ä²¼Ò»·ÝÓÃÓÚ±£»¤CMSϵͳµÄÍøÂ簲ȫָÄÏ£¬¸ÃÖ¸ÄϸÅÊöÁËÈôºÎÔÚweb·þÎñÆ÷Éϼø±ðºÍ×îÓ×»¯Ç±ÔÚ·çÏÕµÄÕ½Êõ£¬ÆäÖ¸±êÊܶàÊÇÕÆ¹ÜʹÓÃCMS¿ª·¢ºÍ±£»¤ÍøÕ¾»òWebÀûÓ÷¨Ê½µÄÈË¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵݲȫ·ì϶¡£Ò»µ©CMS±»ÈëÇÖ£¬¹¥»÷ÕßÄܹ»ÀûÓÃÆäȨÏÞÀ´£º»ñµÃWebÀûÓ÷¨Ê½µÄÑéÖ¤ÇøÓòºÍÌØÈ¨ÇøÓòµÄ½Ó¼ûȨÏÞ£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì½Ó¼û£¬ÀýÈçÉÏ´«Web Shell»òRAT£»ÔںϷ¨ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¹¥»÷Õß»¹Äܹ»½«ÊÜϰȾµÄWeb·þÎñÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿ÃÅ£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£ACSC½¨Òé²ÉÈ¡µÄ»º½â´ëÊ©Ô̺¬£ºÊ¹ÓÃCMSÍйܷþÎñ£»ÓÅÁ¼µÄ²¹¶¡ÖÎÀí£»·ì϶ÆÀ¹À£»ÕË»§ÖÎÀí£»¼ÓÇ¿CMS×°ÖõݲȫÐÔ½ÚÔì´ëÊ©£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.cyber.gov.au/publications/securing-content-management-systems