ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ47ÖÜ

°ä²¼¹¦·ò 2020-11-23

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶£»Google Go CVE-2020-28366´úÂë×¢Èë·ì϶£»Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å£»QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨£»Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨£»Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


³ÁÒª°²È«·ì϶Áбí


1.Aviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶


Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ´æÔÚδÊÚȨ·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐдúÂë¡£

https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/


2.Google Go CVE-2020-28366´úÂë×¢Èë·ì϶


Google Go´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿É×¢Èë´úÂë²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐС£

https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html



3.Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å


Paradox IP150´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02


4.QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶


QNAP QTS´æÔÚÊäÈëÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî¡£

https://www.qnap.com/en/security-advisory/qsa-20-09


5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å


Real Time Automation 499ES EtherNet/IP´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÔ̺¬320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ·¡£ºÚ¿ÍÐû³ÆÕâ´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ¡£Ä¿Ç°£¬Pluto TVÉÐδ֤ʵÊÇ·ñ²úÉúÁËÊý¾Ýй¶£¬½ö°µÊ¾ËûÃÇÔÚµ÷²éÖС£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2¡¢Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨


2.png


Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨¡£»ã±¨ÏÔʾ£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼ÊõÖÎÀí±äµÃÔ½À´Ô½ÄÑÌ⣬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö³¤¡£87£¥µÄIT¸¨µ¼Õß°µÊ¾£¬´ÓǰһÄêÖÐËûÃÇÒѾ­¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©¸øÉ̵ÄÉ󼯣¬Ö»ÓÐ51£¥µÄÈ˲»°²ÏÂÒ»ÄêµÄÉ󼯡£´Ë±í£¬×³´óµÄ¼¼Êõµý±¨Ê¹IT¸¨µ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×Òª¹¤×÷£¬µ«Ö»ÓÐ14%µÄIT¸¨µ¼Õß´ïµ½Á˳ÉÊì¼¼ÊõÖÇÄܵij߶È¡£


Ô­ÎÄÁ´½Ó£º

https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report


3¡¢Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨


3.png


Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨¡£Intel 471°µÊ¾£¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ£¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ·£¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


4¡¢Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁé


4.png


±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£ÖжÏ£¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé¡£ÖܶþÁ賿£¬¹È¸è×ܲ¿°ä²¼ÐÂÎųÆ£¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÀûÓ᣸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÅÔ¹ÛÊÓÆµÖ±²¥£¬ÎÞ·¨µ÷ÕûºãνÚÔìÆ÷£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó¡£Æäʵ£¬¸Ã·þÎñÔÚ2ÔÂÒ²²úÉúÁËÀàËÆµÄÖжÏ£¬³ÖÐøÁË16¸öÓ×ʱ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/11/17/google_nest_outage/


5¡¢×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢


5.png


Palo Alto Networks×êÑÐÈËÔ±·¢ÏÖÁË16¸ö·ÖÆçAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬¿É±»ÀÄÓÃÀ´»ñÊØÐÅÏ¢¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»á×Ô¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄÕ½ÊõËùµ¼ÖµÄ¡£ÈôÊÇÕ½ÊõÖÐÔ̺¬²»´æÔÚµÄÉí·Ý£¬Ôò´´½¨»ò¸üÐÂÕ½ÊõµÄAPIŲÓý«Ê§°Ü£¬¹¥»÷ÕßÄܹ»ÀÄÓôËÖ°ÄÜÀ´²é³­AWSÕË»§ÖеÄÏÖÓÐÉí·Ý¡£×êÑÐÈËÔ±³Æ£¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϽøÐУ¬Ò×Êܹ¥»÷µÄAWS·þÎñÔ̺¬AWS S3¡¢AWS KMSºÍAWS SQS¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data