Ñо¿ÍŶÓɨÃè·¢ÏÖÁè¼Ý360Íǫ̻̀¶µÄMySQL·þÎñÆ÷

Ðû²¼Ê±¼ä 2022-06-02

1¡¢Ñо¿ÍŶÓɨÃè·¢ÏÖÁè¼Ý360Íǫ̻̀¶µÄMySQL·þÎñÆ÷


¾ÝýÌå5ÔÂ31ÈÕ±¨µÀ£¬Äþ¾²Ñо¿×éÖ¯Shadowserver FoundationÔÚÉÏÖܽøÐеÄɨÃèÖУ¬·¢ÏÖÁè¼Ý360Íǫ̻̀¶µÄMySQL·þÎñÆ÷ʹÓÃĬÈ϶˿ÚTCP¶Ë¿Ú3306¡£ÕâЩ·þÎñÆ÷ÔÚÍøÉϹûȻ̻¶²¢ÏìÓ¦²éѯ£¬¿ÉÄܳÉΪºÚ¿ÍºÍÀÕË÷¹¥»÷ÕßµÄÄ¿±ê¡£ÆäÖУ¬ÓÐ230Íǫ̀ͨ¹ýIPv4Á¬½Ó£¬130Íǫ̀É豸ͨ¹ýIPv6Á¬½Ó¡£×î¶àµÄ¹ú¼ÒÊÇÃÀ¹ú£¬ÓµÓÐÁè¼Ý120Íǫ̻̀¶µÄÉ豸£¬Æä´ÎÊǵ¹ú¡¢ÐÂ¼ÓÆÂ¡¢ºÉÀ¼ºÍ²¨À¼µÈ¹ú¡£²»Êʵ±µØ±£»¤MySQLÊý¾Ý¿â·þÎñÆ÷¿ÉÄܵ¼ÖÂÊý¾Ýй¶¡¢ÆÆ»µÐԵĹ¥»÷¡¢ÀÕË÷¹¥»÷ÒÔ¼°RATѬȾ¡£


https://www.bleepingcomputer.com/news/security/over-36-million-mysql-servers-found-exposed-on-the-internet/


2¡¢ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄ6.5 TBÊý¾Ýй¶


ýÌå5ÔÂ31Èճƣ¬ÍÁ¶úÆäº½¿Õ¹«Ë¾Pegasus AirlinesµÄAWS´æ´¢Í°ÅäÖôíÎó£¬Ð¹Â¶ÁË6.5 TBÊý¾Ý¡£Ñо¿ÈËÔ±ÔÚ2ÔÂ28ÈÕ·¢ÏÖÁËÒ»¸ö¿ª·ÅµÄ´æ´¢Í°£¬ÆäÖÐÓÐÔ¼2300Íò·ÝÎĵµ£¬Éæ¼°Áè¼Ý300Íò¸ö·ÉÐÐÊý¾ÝÎļþ£¨Èç·ÉÐÐͼ±í¡¢±£ÏÕÎļþºÍ»ú×éÂÖ°àÐÅÏ¢µÈ),Áè¼Ý160Íò·Ý»ú×éÈËÔ±µÄPIIÐÅÏ¢£¬ÒÔ¼°Pegasusº½¿Õ¹«Ë¾¿ª·¢µÄµç×Ó·ÉÐаü(EFB)Èí¼þµÄÔ´´úÂ롣Ŀǰ£¬¸Ã´æ´¢¿âÒѱ»±£»¤ÆðÀ´¡£


https://www.hackread.com/pegasus-airlines-leak-tb-data-aws-s3-bucket-mess-up/


3¡¢SideWinderÍÅ»ïÔÚ½üÁ½ÄêÖÐÒѽøÐÐ1000¶à´Î¹¥»÷»î¶¯


¾Ý5ÔÂ31ÈÕ±¨µÀ£¬×Ô2020Äê4ÔÂÒÔÀ´£¬ºÚ¿ÍÍÅ»ïSideWinderÒÑÌᳫÁËÁè¼Ý1000´Î¹¥»÷»î¶¯¡£KasperskyÌåÏÖ£¬¸ÃÍÅ»ïµÄ²¿ÃÅÌØÕ÷ʹÆäÍÑÓ±¶ø³ö£¬°üÂÞ¹¥»÷µÄÊýÁ¿¡¢ÆµÂʺͳ־ÃÐÔ£¬ÒÔ¼°ÔÚÆä»î¶¯ÖÐʹÓõĴóÁ¿¼ÓÃܺͻìÏý¶ñÒâ×é¼þ¡£ÔÚ¹ýÈ¥µÄÁ½ÄêÖУ¬¹¥»÷ÕßÒ»Ö±ÔËÓª×ÅÒ»¸öÓÉ400¶à¸öÓòºÍ×ÓÓò×é³ÉµÄ´óÐÍC2»ù´¡ÉèÊ©£¬À´ÍйܺͿØÖƶñÒâpayload¡£Ñо¿ÈËÔ±³Æ¸ÃÍÅ»ïʹÓÃÖÖÖÖѬȾý½éºÍÏȽøµÄ¼¼Êõ£¬¾ßÓнϸߵÄÅÓ´óÐÔ£¬½¨Òé×é֯ʹÓÃ×îа汾µÄMicrosoft Office»º½â´ËÀ๥»÷¡£


https://thehackernews.com/2022/05/sidewinder-hackers-launched-over-1000.html


4¡¢¶à¹úÖ´·¨²¿ÃÅÁªºÏÐж¯Àֳɵ·»ÙFluBotµÄ»ù´¡ÉèÊ©


Å·ÖÞÐ̾¯×éÖ¯ÔÚ6ÔÂ1ÈÕÐû²¼£¬ÒѾ­Àֳɵ·»ÙAndroid¶ñÒâÈí¼þFluBot¡£´Ë´ÎÖ´·¨Ðж¯Éæ¼°°Ä´óÀûÑÇ¡¢±ÈÀûʱ¡¢·ÒÀ¼¡¢ÐÙÑÀÀû¡¢°®¶ûÀ¼¡¢ÂÞÂíÄáÑÇ¡¢Î÷°àÑÀ¡¢Èðµä¡¢ÈðÊ¿¡¢ºÉÀ¼ºÍÃÀ¹ú¡£ÔçÔÚ2021Äê3Ô£¬Î÷°àÑÀ¾¯·½Ôø´þ²¶ÁË4ÃûÏÓÒÉÈË£¬ËûÃDZ»ÈÏΪÊÇFluBot»î¶¯µÄÖ÷Òª³ÉÔ±£¬µ«´Ë´ÎÖжÏÖ»ÊÇÔÝʱµÄ£¬¹¥»÷Õß²»¾Ãºó¿ªÊ¼Õë¶ÔÎ÷°àÑÀÖ®ÍâµÄ¹ú¼Ò¡£ÕâÒ»´Î£¬Å·ÖÞÐ̾¯×é֯ǿµ÷£¬FluBotµÄ»ù´¡ÉèÊ©ÒÑ´¦ÓÚÖ´·¨²¿ÃŵĿØÖÆÖ®Ï£¬Òò´Ë²»ÐÐÄÜÔÙËÀ»Ò¸´È¼¡£


https://www.bleepingcomputer.com/news/security/flubot-android-malware-operation-shutdown-by-law-enforcement/


5¡¢Check PointÐû²¼¹ØÓÚ½©Ê¬ÍøÂçXLoaderµÄ·ÖÎö³ÂËß


5ÔÂ31ÈÕ£¬Check PointÐû²¼¹ØÓÚа汾µÄ½©Ê¬ÍøÂçXLoaderµÄ·ÖÎö³ÂËß¡£XLoaderÊÇÒ»¸öÐÅÏ¢ÇÔÈ¡·¨Ê½£¬×î³õ»ùÓÚFormbook£¬Ö÷ÒªÕë¶ÔWindowsºÍmacOS£¬ËüÓÚ2021Äê1ÔÂÊ״α»¹ã·ºµØÀûÓá£×îа汾¶ÔC2ÀֳɵķÃÎÊÔ´ÓÚ¸ÅÂÊÂ۵ĴóÊý¶¨ÂÉ£¬Äþ¾²Ñо¿ÈËÔ±±ØÐë¾­¹ýÈß³¤µÄÄ£Äâ²ÅÆøµÃ³öʵ¼ÊµÄC2µØÖ·£¬ÕâÊÇÒ»ÖÖ²»³£¼ûµÄ×ö·¨£¬Ëü»áʹËùÓеÄ×Ô¶¯½Å±¾±äµÃºÁÎÞÓô¦¡£Ñо¿ÈËÔ±·¢ÏÖÔÚ2.6°æ±¾ÖУ¬XLoader´Ó64λµÄpayloadÖÐɾ³ýÁËÕâÒ»¹¦Ð§£¬Ã¿´Î¶¼ÊÐÁ¬½ÓÕæÕýµÄC2Óò£»µ«ÔÚ32λϵͳÖУ¨Ò²¾ÍÊÇÑо¿ÈËԱʹÓõÄɳºÐÖг£¼ûµÄϵͳ£©£¬±£ÁôÁËÕâ¸öеÄC2»ìÏý¹¦Ð§¡£


https://www.bleepingcomputer.com/news/security/new-xloader-botnet-uses-probability-theory-to-hide-its-servers/


6¡¢Unit 42Ðû²¼2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþвµÄ·ÖÎö³ÂËß


Unit 42ÔÚ5ÔÂ31ÈÕÐû²¼ÁË2021Äê11ÔÂÖÁ2022Äê1ÔÂÍøÂçÍþÐ²Ì¬ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬ÔÚÕâÈý¸öÔÂÖÐ×ܹ²·ºÆðÁË6443¸öЩ¶´£¬ÆäÖÐ31.3%Êǵ±µØÂ©¶´£¬¶øÊ£ÓàµÄ68.7%ÊÇÔ¶³Ì©¶´¡£×î³£¼ûµÄ©¶´ÀàÐÍÊÇ¿çÕ¾½Å±¾Â©¶´£¬Æä´ÎÊǾܾø·þÎñ©¶´¡¢»º³åÇøÒç³ö©¶´ºÍÌáȨ©¶´¡£×î³£¼ûµÄ¹¥»÷ÀàÐÍÊÇÔ¶³Ì´úÂëÖ´ÐУ¬Æä´ÎÊÇÐÅϢй¶ºÍ±éÀú¡£×î¶àµÄ¹¥»÷À´×ÔÀ´×ÔÃÀ¹ú£¬Ö®ºóÊǵ¹úºÍ¶íÂÞ˹£¬µ«¹¥»÷ÕßÓпÉÄÜʹÓÃÁËÊðÀíºÍVPNÀ´Òþ²ØÊµ¼ÊλÖá£


https://unit42.paloaltonetworks.com/network-security-trends-cross-site-scripting/