ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ22ÖÜ
Ðû²¼Ê±¼ä 2018-06-04
Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2018Äê05ÔÂ28ÈÕÖÁ06ÔÂ01ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´53¸ö£¬ÖµµÃ¹Ø×¢µÄÊǶà¿îTP-LINK²úÎïÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý©¶´£»strongSwan CVE-2018-5388»º³åÇøÒç³ö©¶´£»BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÍŶӷ¢ÏÖÀûÓÃAndroidÔÉúwebÊÓͼµÄеöÓã»î¶¯£»Ñо¿ÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯£»¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄÊý¾Ýй¶£»Ñо¿ÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷ÆÆ»µHDDºÍµ¼ÖÂϵͳÍ߽⣻±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖôíÎ󣬵¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢¶à¿îTP-LINK²úÎïÔ¶³Ì´úÂëÖ´ÐЩ¶´
¶à¿îTP-LINK²úÎïÖеÄ/usr/lib/lua/luci/torchlight/validator.luaÎļþ´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄJSONÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCE
2¡¢Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´ÐЩ¶´
Git ÔÚÓÃgit cloneʱûÓжÔsubmoduleµÄÎļþ¼ÐÃüÃû×ö×ã¹»µÄÑéÖ¤£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»¶ñÒâµÄ.gitmodulesÎļþ£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://git-scm.com
3¡¢Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý©¶´
Huawei 1288H V5ºÍ2288H V5´æÔÚJSON×¢Èë©¶´£¬ÔÊÐíµ±µØ¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬Ð޸ĹÜÀíÔ±ÃÜÂ룬»ñȡϵͳµÄ¹ÜÀíȨÏÞ¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en
4¡¢strongSwan CVE-2018-5388»º³åÇøÒç³ö©¶´
strongSwan´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ɺľ¡×ÊÔ´£¬½øÐоܾø·þÎñ¹¥»÷¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.strongswan.org/blog
5¡¢BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶©¶´
BeaconMedaes TotalAlert Scroll Medical Air Systems WEB·þÎñÆ÷´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-144-01
Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃAndroidÔÉúwebÊÓͼµÄеöÓã»î¶¯

RiskIQÑо¿ÍŶӷ¢ÏÖÕë¶ÔMyEtherWalletµÄÒ»¸öеöÓã»î¶¯¡£¹¥»÷Õßͨ¹ý½¨Á¢Ò»¸öαװ³ÉMyEtherWalletÖ§³ÖÍŶӵÄTelegramÁÄÌìȺ×éÀ´·Ö·¢¶ñÒâMyEtherWallet¿Í»§¶Ë¡£¸Ã¶ñÒⷨʽͨ¹ýGoNative.io½«WebÓ¦ÓÃ×÷Ϊµ±µØÓ¦ÓÃÐû²¼£¬ÓÃÓÚÇÔÈ¡Óû§µÄƾ¾Ý¡£Ñо¿ÈËÔ±Ðû²¼ÁËÏà¹ØIoC¡£
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/myetherwallet-android/
2¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯

FireEyeÑо¿ÍŶӷ¢ÏÖÀûÓÃRIG Exploit Kit£¨EK£©Á÷´«Ä¾ÂíGrobiosµÄ¶ñÒâ¹¥»÷»î¶¯£¬¸Ã»î¶¯´Ó2018Äê3ÔÂ10ÈÕ¿ªÊ¼¡£GrobiosʹÓÃÁ˶àÖÖÌӱܼì²â¼¼Êõ£¬²¢Í¨¹ý¶à¸ö±¸·ÝºÍ´´½¨×Ô¶¯ÔËÐÐ×¢²á±íÏî¼°¼Æ»®ÈÎÎñÀ´ÊµÏÖ³Ö¾ÃÐÔ¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72954/malware/rig-exploit-kit-grobios-campaign.html
3¡¢¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬²¿Ãſͻ§µÄÊý¾Ýй¶

¼ÓÄôóµÄÁ½¼ÒÒøÐÐSimplii FinancialºÍÃÉÌØÀû¶ûÒøÐÐÔÚÖÜÒ»·¢±íÉùÃ÷³Æ·¢ÉúÍøÂçÄþ¾²Ê¼þ£¬Simplii FinancialÌåÏÖ£¬ËüÔÚÉÏÖÜÄ©·¢ÏÖ¹¥»÷Õß·ÃÎÊÁËÔ¼4ÍòÃûSimplii¿Í»§µÄÕË»§ÐÅÏ¢¡£µ«ÊÇSimplii FinancialÔÊÐí100£¥·µ»¹ËùÊÜÓ°ÏìµÄÕË»§µÄËðʧ¡£ÔÚSimplii·¢±íÉùÃ÷һСʱºó£¬ÃÉÌØÀû¶ûÒøÐÐÒ²Ðû²¼ÁËÀàËÆµÄÉùÃ÷¡£¸ÃÒøÐÐÌåÏÖ£¬ºÚ¿Í×Ô¼ºÔÚÉÏÖÜÈÕÁªÏµÁËËûÃÇ£¬Éù³ÆÓµÓпͻ§Êý¾Ý¡£ÃÉÌØÀû¶ûÒøÐÐûÓÐ͸¶Óм¸¶à¿Í»§µÄÐÅϢй¶£¬µ«ÌåÏÖËûÃÇÏàÐÅÒѾ¹Ø±ÕÁ˺ڿͽøÈëÆäϵͳµÄÈë¿Úµã¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/two-canadian-banks-announce-hacks-over-the-weekend/
4¡¢Ñо¿ÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷ÆÆ»µHDDºÍµ¼ÖÂϵͳÍß½â

À´×ÔÃÜЪ¸ù´óѧºÍÕã½´óѧµÄÒ»¸öÑо¿Ð¡×鳯¿Éͨ¹ýÉù²¨/³¬Éù²¨¹¥»÷À´ÆÆ»µÓ²ÅÌ£¨HDD£©µÄ¶ÁÈ¡¡¢Ð´ÈëºÍ´æ´¢¹¦Ð§ÒÔ¼°µ¼Ö²Ù×÷ϵͳÍ߽⡣Ñо¿ÈËÔ±ÌåÏÖÕâÖÖ¹¥»÷¿ÉÒÔͨ¹ý×ÔÖÆµĄ̈ʽµçÄÔ»òÌõ¼Ç±¾µçÄÔµÄÑïÉùÆ÷½øÐУ¬Ò»ÖÖ¿ÉÄܵĹ¥»÷³¡¾°ÊÇ£¬Óû§·ÃÎÊÁ˶ñÒâÍøÕ¾²¢²¥·ÅÁ˾ßÓÐÆÆ»µÐԵĶñÒâÉù²¨¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/sonic-tone-attacks-damage-hard-disk-drives-crashes-os/132343/
5¡¢±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖôíÎ󣬵¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶

ƾ¾ÝKromtech SecurityµÄ³ÂËߣ¬±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄ2¸öAmazon S3¿É¹ûÈ»·ÃÎÊ£¬µ¼ÖÂÁè¼Ý5ÍòÃûÓû§µÄÐÅϢй¶¡£Õâ2¸öAWS bucket°üÂÞ±¾ÌïÒÆ¶¯Ó¦ÓÃHonda ConnectµÄÓû§µÄÏêϸÐÅÏ¢£¬ÀýÈçÐÕÃû¡¢ÐÔ±ð¡¢Óû§¼°Æä¿ÉÐÅÁªÏµÈ˵ĵ绰ºÅÂëºÍµç×ÓÓʼþµØÖ·¡¢ÕË»§ÃÜÂë¡¢Æû³µVINÂëºÍÆû³µConnect IDµÈ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/honda-india-left-details-of-50-000-customers-exposed-on-an-aws-s3-server/