¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190111

Ðû²¼Ê±¼ä 2019-01-11
1¡¢ÐÂDNSÐ®ÖÆÀ˳±Ï¯¾íÈ«Çò£¬ £¬£¬£¬£¬ÒÉΪÒÁÀʺڿÍËùΪ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

FireEye·¢Ã÷Ò»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNSÐ®ÖÆÀ˳±£¬ £¬£¬£¬£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£¡£¡£ ¡£¡£¡£ÕâЩÓòÃûÊôÓÚÕþ¸®¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£¡£¡£ ¡£¡£¡£ËäÈ»ÏÖÔÚÑо¿Ö°Ô±»¹Ã»Óн«´Ë»î¶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬ £¬£¬£¬£¬µ«ÆðÔ´µÄÑо¿Åú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйØ¡£¡£¡£ ¡£¡£¡£¸Ã¹¥»÷»î¶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂʱ´úÒ»Ö±´¦ÓÚ»îԾ״̬£¬ £¬£¬£¬£¬²¢ÇÒ±£´æ¶à¸ö²»Öظ´µÄÓòÃû¡¢IPµØµã¼¯Èº¡£¡£¡£ ¡£¡£¡£ÕâÒâζןù¥»÷»î¶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕߵĻ¡£¡£¡£ ¡£¡£¡£¹¥»÷ÕßµÄÊÖÒÕÖ÷񻃾¼°ÐÞ¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍÖØ¶¨Ïò¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html


2¡¢TA505жñÒâ»î¶¯£¬ £¬£¬£¬£¬·Ö·¢ServHelperºóÃźÍFlawedGrace RAT

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±·¢Ã÷·¸·¨ÍÅ»ïTA505ͨ¹ýÍøÂç´¹Âڻ·Ö·¢ServHelperºóÃźÍFlawedGrace RAT¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß¼ÌÐøÃé×¼½ðÈÚºÍÁãÊÛÐÐÒµ£¬ £¬£¬£¬£¬²¢Í¨¹ý¶ñÒâµÄMicrosoft Word¡¢PublisherºÍPDFÎļþѬȾÓû§¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤ProofpointµÄÑо¿£¬ £¬£¬£¬£¬TA505ÒÑÔÚÍøÂç·¸·¨ÁìÓòÖÁÉÙ»îÔ¾ÁËËÄÄ꣬ £¬£¬£¬£¬ÓëÖ®Ïà¹ØµÄ¶ñÒâÈí¼þ°üÀ¨ÒøÐÐľÂíDridex¡¢ÀÕË÷Èí¼þLocky¡¢PhiladelphiaºÍGlobeImposter¡£¡£¡£ ¡£¡£¡£´Ë´Î¹¥»÷»î¶¯Öй²·Ö·¢ÁËServHelperµÄÁ½ÖÖ±äÌå¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-servhelper-backdoor-and-flawedgrace-rat-pushed-by-necurs-botnet/


3¡¢SystemdÈý¸öÌáȨÎó²î£¬ £¬£¬£¬£¬Ó°Ïì´ó´ó¶¼Linux¿¯Ðаæ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

QualysÇå¾²Ñо¿Ö°Ô±ÔÚSystemdÖз¢Ã÷Èý¸öÇå¾²Îó²î£¬ £¬£¬£¬£¬ÕâЩÎó²î¿ÉÔÊÐíÎÞÌØÈ¨µÄÍâµØ¹¥»÷Õß»ò¶ñÒâ³ÌÐòÔÚÄ¿µÄϵͳÉÏ»ñµÃroot»á¼ûȨÏÞ¡£¡£¡£ ¡£¡£¡£ÕâÈý¸öÎó²î£¨CVE-2018-16864¡¢CVE-2018-16865ºÍCVE-2018-16866£©±£´æÓÚsystemd-journaldЧÀÍÖУ¬ £¬£¬£¬£¬¸ÃЧÀÍÓÃÓÚÍøÂçÐÅÏ¢ºÍ½¨ÉèÈÕÖ¾¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖÕâЩÎó²îÓ°ÏìÁËËùÓлùÓÚsystemdµÄLinux¿¯Ðаæ£¬ £¬£¬£¬£¬°üÀ¨RedhatºÍDebian¡£¡£¡£ ¡£¡£¡£µ«Ò²ÓÐһЩ¿¯Ðаæ£¬ £¬£¬£¬£¬ÀýÈçSUSE¡¢Fedora²»ÊÜÓ°Ïì¡£¡£¡£ ¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÐÞ²¹³ÌÐò¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/linux-systemd-exploit.html


4¡¢¹È¸èÐû²¼ÆäDNSЧÀÍÖ§³ÖDNS-over-TLSÇ徲ЭÒé

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

ÓÉÓÚDNSÅÌÎÊÊÇͨ¹ýUDP»òTCPÒÔÃ÷ÎÄÐÎʽ·¢Ë͵Ä£¬ £¬£¬£¬£¬Òò´Ë¸ÃÐÅÏ¢¿ÉÒÔй¶Óû§»á¼ûµÄÍøÕ¾£¬ £¬£¬£¬£¬²¢ÇÒÒ×ÊÜÓÕÆ­¹¥»÷¡£¡£¡£ ¡£¡£¡£ÎªÏàʶ¾öÕâ¸öÎÊÌ⣬ £¬£¬£¬£¬±¾ÖÜÈý¹È¸èÐû²¼Æä¹«¹²DNSЧÀÍÖ§³ÖDNS-over-TLSÇ徲ЭÒ飬 £¬£¬£¬£¬ÕâÒâζ×ÅDNSÅÌÎʺÍÏìÓ¦½«Í¨¹ýTLS¼ÓÃܵÄTCPÅþÁ¬¾ÙÐÐͨѶ£¬ £¬£¬£¬£¬¿ÉÒÔÓÐÓÃ×èÖ¹ÖÐÐÄÈ˹¥»÷¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬¹È¸èÒѾ­ÎªAndroid 9Óû§ÌṩÁËDNS-over-TLS£¬ £¬£¬£¬£¬¸Ã²¿·ÖÓû§¿ÉÒÔÁ¬Ã¦Çл»µ½DNS-over-TLS¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/google-dns-over-tls-security.html


5¡¢ÃÀ¹úÁè¼Ý80¸öÕþ¸®ÍøÕ¾µÄTLSÖ¤ÊéÓâÆÚ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

¾ÝZDNet±¨µÀ£¬ £¬£¬£¬£¬ÃÀ¹úÁè¼Ý80¸öÕþ¸®ÍøÕ¾µÄTLSÖ¤ÊéÒѾ­ÓâÆÚ£¬ £¬£¬£¬£¬²¢ÇÒûÓб»¸üУ¬ £¬£¬£¬£¬²¿·ÖÍøÕ¾ÒѾ­ÎÞ·¨»á¼û¡£¡£¡£ ¡£¡£¡£¾ÝNetcraft³Æ£¬ £¬£¬£¬£¬ÊÜÓ°ÏìµÄÕþ¸®»ú¹¹°üÀ¨NASA¡¢ÃÀ¹ú˾·¨²¿ºÍÃÀ¹úÁª°îÉÏËß·¨ÔºµÈ¡£¡£¡£ ¡£¡£¡£²¿·ÖʵÑéÁËHSTSµÄÍøÕ¾ÓÉÓÚÖ¤ÊéÓâÆÚÒѾ­ÎÞ·¨±»Óû§»á¼û£¬ £¬£¬£¬£¬¶øÎ´ÊµÑéHSTSµÄÍøÕ¾½«ÔÚÓû§µÄä¯ÀÀÆ÷ÖÐÏÔʾHTTPS¹ýʧ¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±½«ÕâÒ»ÊÂÎñ¹é×ïÓÚÃÀ¹úÁª°îÕþ¸®µÄ¹Ø±Õ£¬ £¬£¬£¬£¬´ó×ÚITºÍÍøÂçÇå¾²Ö°Ô±±»¿ª³ý£¬ £¬£¬£¬£¬µ¼ÖÂûÓÐÈË¿ÉÒÔÐøÇ©ÕâЩ֤Êé¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/government-shutdown-tls-certificates-not-renewed-many-websites-are-down/


6¡¢ÐÂ¹ã¸æÈí¼þICEPick-3PC£¬ £¬£¬£¬£¬Ö÷ÒªÕë¶ÔAndroidÓû§

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Media TrustÑо¿Ö°Ô±·¢Ã÷Ò»¸öÊ®·ÖÖØ´óµÄÐÂ¹ã¸æÈí¼þICEPick-3PC£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±ÒÔΪÆä±³ºóµÄÓÐ×éÖ¯·¸·¨ÍÅ»ïÕýÔÚ¿ªÕ¹Õë¶ÔAndroidÓû§µÄ´ó¹æÄ£¹¥»÷»î¶¯¡£¡£¡£ ¡£¡£¡£¹¥»÷Õß½«¶ñÒâ´úÂë×¢È뵽һЩµÚÈý·½¿âÖУ¬ £¬£¬£¬£¬ÀýÈçGreenSock¶¯»­Æ½Ì¨£¨GSAP£©-Ò»¸öHTML5¶¯»­µÄJavaScript¿â¡£¡£¡£ ¡£¡£¡£µ±Óû§µã»÷ÊÜѬȾµÄ¹ã¸æÊ±£¬ £¬£¬£¬£¬¶ñÒâÈí¼þ»áÔÚÓû§×°±¸ºÍÔ¶³Ì×°±¸Ö®¼ä½¨ÉèRTC¶ÔµÈÅþÁ¬£¬ £¬£¬£¬£¬²¢ÍøÂç×°±¸µÄÖ¸ÎÆÐÅÏ¢£¬ £¬£¬£¬£¬°üÀ¨×°±¸µÄIPµØµã¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/icepick-adware-analysis/140722/


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí