ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ36ÖÜ

Ðû²¼Ê±¼ä 2018-09-10

 ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö

 

2018Äê09ÔÂ03ÈÕÖÁ09ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco Cloud Services Platform 2100 ÃüÁî×¢Èë©¶´£»Opto22 PAC Control»º³åÇøÒç³ö©¶´£»ThinkPHP SQL×¢Èë©¶´£»Tenda AC9ºÍAC10 OSÃüÁî×¢Èë©¶´£»Foxit Reader PDFÎļþ´¦ÖÃÀàÐÍ»ìÏý©¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÑо¿ÈËÔ±·¢ÏÖFiservƽ̨´æÔÚÄþ¾²Â©¶´£¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÓû§ÐÅϢй¶£»Ñо¿ÈËÔ±·¢ÏÖÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄƾ¾ÝÔÚÂÛ̳³öÊÛ£»Ñо¿ÍŶӷ¢ÏÖÀûÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯£»½©Ê¬ÍøÂçNecursÔÚ5ÔÂÖÁ7ÔÂÆÚ¼ä·¢³öÁË78Íò·âÀ¬»øÓʼþ£»¿¨°Í˹»ùÐû²¼2018ÄêÉϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³µÄÍþв¾°¹Û³ÂËß ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí

1. Cisco Cloud Services Platform 2100 ÃüÁî×¢Èë©¶´

Cisco Cloud Services Platform 2100 WEB½Ó¿Ú´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔWEBÉÏÏÂ

ÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180905-csp2100-injection


2. Opto22 PAC Control»º³åÇøÒç³ö©¶´

Opto22 PAC Control´æÔÚ»ùÓÚÕ»µÄ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬽øÐоܾø·þÎñ¹¥»÷»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë ¡£
https://ics-cert.us-cert.gov/advisories/ICSA-18-247-01


3. ThinkPHP SQL×¢Èë©¶´

ThinkPHP public/index/index/test/index²éѯ×Ö·û´®ÖдæÔÚSQL×¢Èë©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë ¡£
https://github.com/top-think/framework/issues/1375


4. Tenda AC9ºÍAC10 OSÃüÁî×¢Èë©¶´

Tenda AC9ºÍAC10´¦ÖÃPOSTÇëÇóÖеÄ'mcc'²ÎÊý´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬Ö´ÐÐÈÎÒâOSÃüÁî ¡£
https://github.com/zsjevilhex/iot/blob/master/route/tenda/tenda-04/tenda.md


5. Foxit Reader PDFÎļþ´¦ÖÃÀàÐÍ»ìÏý©¶´

Foxit Reader´¦ÖÃPDFÎļþ´æÔÚÀàÐÍ»ìÏý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÖ´ÐÐÈÎÒâ´úÂë ¡£
https://www.foxitsoftware.com/support/security-bulletins.php


 ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Ñо¿ÈËÔ±·¢ÏÖFiservƽ̨´æÔÚÄþ¾²Â©¶´£¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÓû§ÐÅϢй¶


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Äþ¾²Ñо¿ÈËÔ±Kristian Erik Hermansen·¢ÏÖ½ðÈÚ»ú¹¹¼¼Êõ·þÎñÌṩÉÌFiservµÄÍøÂçÆ½Ì¨´æÔÚ©¶´£¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÊý¾Ýй¶ ¡£FiservûÓÐÃ÷ȷ˵Ã÷Óм¸¶à½ðÈÚ»ú¹¹¿ÉÄÜÊܵ½Ó°Ï죬µ«¾Ý±¨µÀĿǰÓÐ1700¼ÒÒøÐÐÕýÔÚʹÓÃFiservƽ̨ ¡£Fiserv·¢ÑÔÈ˳Ƹù«Ë¾ÔÚÊÕµ½³ÂËߺó24СʱÄÚ¿ª·¢ÁËÐÞ¸´²¹¶¡²¢½øÐÐÁ˲¿Êð ¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/hundreds-of-banks-exposed-from/


2¡¢Ñо¿ÈËÔ±·¢ÏÖÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄƾ¾ÝÔÚÂÛ̳³öÊÛ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


Äþ¾²Ñо¿ÈËÔ±Adam Davies·¢ÏÖÊôÓÚÔ¼57ÍòMortal OnlineÓÎÏ·Íæ¼ÒµÄÕË»§ÐÅÏ¢ÔÚÂÛ̳ÉϳöÊÛ ¡£2018Äê6ÔÂ17ÈÕδ¾­ÊÚȨµÄµÚÈý·½·ÃÎÊÁ˸ÃÓÎÏ·µÄÂÛ̳ºÍÉ̵êÊý¾Ý¿âµÄ·þÎñÆ÷²¢ÇÔÈ¡ÁËÓû§µÄÊý¾Ý ¡£¹¥»÷Õß»¹»ñÈ¡ÁËÓû§ÃÜÂëµÄMD5¹þÏ£Öµ£¬ÕâЩ¹þÏ£ÖµËÆºõÒѱ»ÆÆ½â ¡£¸ÃÊý¾Ý¿âĿǰÒѱ»Ìí¼Óµ½Have I Been PwnedÍøÕ¾ÖÐ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/cracked-logins-of-570-000-mortal-online-players-sold-on-forums/


3¡¢Ñо¿ÍŶӷ¢ÏÖÀûÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯


×ðÁú¶¶È¦ - Ϊdu¶øÉú


ZscalerµÄÑо¿ÈËÔ±·¢ÏÖÀûÓÃ.tkÓòÃûµÄ´ó¹æÄ£¹ã¸æÕ©Æ­»î¶¯ ¡£×Ô2018Äê5ÔÂÒÔÀ´£¬¸Ã¶ñÒâ»î¶¯Ò»Ö±´¦ÓÚ»îԾ״̬ ¡£¹¥»÷Õß½«Óû§Öض¨ÏòÖÁÐé¼ÙµÄ²©¿ÍÍøÕ¾£¬ÕâÐ©ÍøÕ¾ÉÏµÄ¹ã¸æÊÕÈëÿÔ´ï2ÍòÃÀÔªÒÔÉÏ ¡£²¿ÃÅ.tkÓòÃû»¹±»ÓÃÓÚ¼¼ÊõÖ§³ÖÕ©Æ­ ¡£.tkÓòÃûÊÇÒ»¸ö¹ú¼Ò/µØÓò¼¶µÄ¶¥¼¶ÓòÃû£¬Ëü´ú±íÁËÁ¥ÊôÓÚÐÂÎ÷À¼µÄµº¹úTokelau ¡£¸ÃÓòÃûÊÇÃâ·ÑµÄ£¬ÕâÒýÆðÁ˹¥»÷ÕßµÄÐËȤ ¡£Ñо¿ÈËÔ±×ܹ²·¢ÏÖÁËÓë¸Ã¶ñÒâ»î¶¯ÓйصÄ3804¸ö.tkÓòÃû ¡£

Ô­ÎÄÁ´½Ó£º
https://www.zscaler.com/blogs/research/spam-campaigns-leveraging-tk-domains


4¡¢½©Ê¬ÍøÂçNecursÔÚ5ÔÂÖÁ7ÔÂÆÚ¼ä·¢³öÁË78Íò·âÀ¬»øÓʼþ


×ðÁú¶¶È¦ - Ϊdu¶øÉú


IBM X-ForceÑо¿ÍŶӷ¢ÏÖ½©Ê¬ÍøÂçNecursÔÚ5ÔÂÖÁ7ÔÂÆÚ¼ä¹²·¢³öÁËÁè¼Ý78Íò·âÀ¬»øÓʼþ ¡£ÕâЩÀ¬»øÓʼþ¶¼°üÂÞ¶ñÒâµÄIQYÎļþ£¬ÓÃÓÚ·Ö·¢¶ñÒâÈí¼þFlawedAmmyy RAT¡¢MarapºÍQuant Loader ¡£Ñо¿ÈËÔ±¹²ÊӲ쵽5¸ö¹¥»÷À˳±£¬5ÔÂ25ÈÕNecurs·¢ËÍÁËÁè¼Ý30Íò·âÀ¬»øÓʼþ£¬6ÔÂ7ÈÕÓÖ·¢ËÍÁËÔ¼20Íò·â ¡£ËæºóµÄ6ÔÂ13ÈÕ·¢ËÍÁËÁè¼Ý15Íò·â£¬7ÔÂ13ÈÕ²»µ½10Íò·âÒÔ¼°7ÔÂ17ÈÕµÄÉÙÓÚ5Íò·â ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/necurs-spews-780-000-emails-with-weaponized-iqy-files/


5¡¢¿¨°Í˹»ùÐû²¼2018ÄêÉϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³µÄÍþв¾°¹Û³ÂËß


×ðÁú¶¶È¦ - Ϊdu¶øÉú


¿¨°Í˹»ùʵÑéÊÒICS CERTÐû²¼¹ØÓÚ2018ÄêÉϰëÄ깤ҵ×Ô¶¯»¯ÏµÍ³µÄÍþв¾°¹ÛµÄ·ÖÎö³ÂËß ¡£Óë2017ÄêϰëÄêÏà±È£¬2018ÄêÉϰëÄêÔâµ½¹¥»÷µÄICS¼ÆËã»úµÄ±ÈÀýÔö³¤ÁË3.5¸ö°Ù·Öµã£¬µ½´ïÁË41.2% ¡£Í¬±ÈÔòÊÇÔö³¤ÁË4.6¸ö°Ù·Öµã ¡£·ÇÖÞ¡¢ÑÇÖÞºÍÀ­¶¡ÃÀÖÞµÄICS¼ÆËã»úÔâµ½¹¥»÷µÄ±ÈÀýÔ¶µÍÓÚÅ·ÖÞ¡¢±±ÃÀºÍ°Ä´óÀûÑÇ ¡£¶«Å·µÄÊý×ÖÒ²Ô¶´óÓÚÎ÷Å·µÄÊý×Ö ¡£ÄÏÅ·Ôâµ½¹¥»÷µÄICS¼ÆËã»úµÄ±ÈÀýÒª¸ßÓÚ±±Å·ºÍÎ÷Å· ¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/threat-landscape-for-industrial-automation-systems-in-h1-2018/87913/