ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2020-03-10> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐЩ¶´; Rubetek SmartHome²¨¶ÎÉè¼Æ©¶´£»Envoy²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´£»Qualcomm MDM9206 WLAN»º³åÇøÒç³ö©¶´£»Google Chrome mediaÄþ¾²Èƹý©¶´¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Ê飻CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡·£»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î£»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÄþ¾²Ö¸ÄÏ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£
>ÖØÒªÄþ¾²Â©¶´Áбí
1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐЩ¶´
FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ´æÔÚºÚÃûµ¥Èƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://github.com/FasterXML/jackson-databind/issues/2631
2. Rubetek SmartHome²¨¶ÎÉè¼Æ©¶´
Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î½øÐÐͨÐÅ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢»ò½øÐоܾø·þÎñ¹¥»÷¡£
https://pastebin.com/CckKKJcM
3. Envoy²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´
EnvoyʹÓÃSDS´æÔÚ²»ÕýÈ··ÃÎÊ¿ØÖÆ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÊÜÏÞ×ÊÔ´¡£
https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
4. Qualcomm MDM9206 WLAN»º³åÇøÒç³ö©¶´
Qualcomm MDM9206 WLAN´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɽøÐоܾø·þÎñ¹¥»÷»ò¿ÉÖ´ÐÐÈÎÒâ´úÂë¡£
https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin
5. Google Chrome mediaÄþ¾²Èƹý©¶´
Google Chrome media´¦ÖÃÄþ¾²¼Æı´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉÈƹýÄþ¾²ÏÞÖÆ£¬Î´ÊÚȨ·ÃÎÊ¡£
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html
> ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶
TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶Ê¼þ£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼Æ¾«ÃÜÁã¼þµÄÖÆÔìÉÌ¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖУ¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÄþ¾²·¸×ïʼþ£¨°üÂÞ·ÃÎʺÍ͵ÇÔÊý¾Ý£©µÄÄ¿±ê¡±¡£¸Ã¹«Ë¾·¢ÑÔÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷½øÐÐÈ«ÃæÊӲ죬¶øÇÒÒµÎñÔËÐÐÕý³£¡±¡£TechCrunchÑо¿ÈËÔ±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/03/01/visser-breach/
2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug£¬Let's EncryptÏîÄ¿¼Æ»®´ÓÊÀ½ç³ß¶Èʱ¼ä2020Äê3ÔÂ4ÈÕ00:00¿ªÊ¼È¡ÏûÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¾ßÌåÀ´Ëµ£¬¸ÃbugÓ°ÏìÁËBoulder£¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé·¢±í»ú¹¹ÊÚȨ£©¹æ·¶µÄʵʩ£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÂÞN¸öÐèÒª½øÐÐCAAÖØмì²éµÄÓòÃûʱ£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£Õâʵ¼ÊÉÏÒâζ×ÅÈç¹ûÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬¶øÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Ç¼ÔÊÐíLet's Encrypt¿¯ÐУ¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÂÞ¸ÃÓòÃûµÄÖ¤Ê飬¼´Ê¹Ö®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ°²×°Á˽ûÖ¹Let's Encrypt¿¯ÐеÄCAA¼Ç¼¡±¡£ÔÚÕâ300Íò¸öÈ¡ÏûµÄÖ¤ÊéÖУ¬ÓÐ100Íò¸öÊÇͬһÓò/×ÓÓòµÄÖظ´ÏÒò´ËÊÜÓ°ÏìÖ¤ÊéµÄʵ¼ÊÊýÁ¿Ô¼Îª200Íò¸ö¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Ê鶼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦Ó÷¨Ê½ÖеĴíÎó£¬ÓòÃûËùÓÐÕß½«±ØÐëÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв³ÂËß¡·¶Ô¹ýÈ¥Ò»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊƽøÐÐÁËÉîÈë·ÖÎö£¬¸Ã³ÂËßµÄÒªµã°üÂÞ£º´óÐ͹¥»÷»î¶¯£¨BGH£©²»Í£Éý¼¶£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬¶øÇÒÔì³É¼«´óµÄÆÆ»µ£»ÍøÂç·¸×ï·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬ÒÔÔö¼Ó¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»eCrimeÉú̬ϵͳ²»Í£Éú³¤£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½²»Í£Ìá¸ß£»ÔÚBGHÖ®Í⣬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔö¼Ó£»³¯ÏòÎÞ¶ñÒâÈí¼þ¼ÆıµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬´Ù½øÉçÇøÄÚ²¿µÄÆÆÁÑ£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕߵĺÏ×÷¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
4¡¢Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940Íò´î¿ÍÊý¾Ýй¶Ê¼þ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£¸Ã¹¥»÷ÒÉËÆ·¢ÉúÔÚ2018Äê3Ô·ݣ¬²¢ÓÚ5Ô·ݵõ½È·ÈÏ£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦Æƽ⹥»÷¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÊÕ¼¯Àà¶ñÒâÈí¼þµÄÓ°Ï죬²¢·¢ÏÖ¹úÌ©ÔÚÄþ¾²ÐÔ·½ÃæµÄһЩ²»×㣬°üÂÞ²»ÊÜÃÜÂë±£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»¤µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÄþ¾²Ö¸ÄÏ
°Ä´óÀûÑÇÍøÂçÄþ¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ±£»¤CMSϵͳµÄÍøÂçÄþ¾²Ö¸ÄÏ£¬¸ÃÖ¸ÄϸÅÊöÁËÈçºÎÔÚweb·þÎñÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚ·çÏյļÆı£¬ÆäÄ¿±êÊÜÖÚÊÇÂôÁ¦Ê¹ÓÃCMS¿ª·¢ºÍ±£»¤ÍøÕ¾»òWebÓ¦Ó÷¨Ê½µÄÈË¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÄþ¾²Â©¶´¡£Ò»µ©CMS±»ÈëÇÖ£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦Ó÷¨Ê½µÄÑéÖ¤ÇøÓòºÍÌØȨÇøÓòµÄ·ÃÎÊȨÏÞ£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì·ÃÎÊ£¬ÀýÈçÉÏ´«Web Shell»òRAT£»ÔںϷ¨ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWeb·þÎñÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿ÃÅ£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£ACSC½¨Òé½ÓÄɵĻº½â´ëÊ©°üÂÞ£ºÊ¹ÓÃCMSÍйܷþÎñ£»Á¼ºÃµÄ²¹¶¡¹ÜÀí£»Â©¶´ÆÀ¹À£»ÕË»§¹ÜÀí£»¼ÓÇ¿CMS°²×°µÄÄþ¾²ÐÔ¿ØÖÆ´ëÊ©£»¼à¿ØCMS°²×°É϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.cyber.gov.au/publications/securing-content-management-systems