¿ªÔ´Â·ÓÉÆ÷OPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£© £»£»£»£»£»£»£»libmicrodns¿â¶à¸öRCEºÍDoSÎó²î

Ðû²¼Ê±¼ä 2020-03-26

1.¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDE RCEÎó²î£¨CVE-2020-7982£©


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±Åû¶¿ªÔ´Â·ÓÉÆ÷¿¯ÐаæOPENWRT/LEDEÖеÄÒªº¦RCEÎó²î£¨CVE-2020-7982£©µÄÊÖÒÕϸ½ÚºÍPoC¡£¡£¡£¡£ ¡£¡£¸ÃÎó²î±£´æÓÚOpenWrtµÄOPKGÈí¼þ°ü¹ÜÀíÆ÷ÖУ¬£¬£¬OPKG¶ÔÏÂÔØµÄÈí¼þ°üÖ´ÐÐÍêÕûÐÔ¼ì²éʱ£¬£¬£¬ÈôÊÇSHA-256УÑéºÍ°üÀ¨ÈκÎǰµ¼¿Õ¸ñ£¬£¬£¬OPKG»áÌø¹ýÍêÕûÐÔ¼ì²é¼ÌÐøÖ´ÐÐ×°ÖÃʹÃü¡£¡£¡£¡£ ¡£¡£¸ÃÎó²î¿ÉÄÜʹԶ³ÌMitM¹¥»÷ÕßÄܹ»ÓÕÆ­ÏµÍ³×°ÖÃδÂÄÀúÖ¤µÄ¶ñÒâÈí¼þ°ü»òÈí¼þ¸üУ¬£¬£¬´Ó¶ø×赲ĿµÄ×°±¸µÄͨѶºÍÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ ¡£¡£OpenWrt°æ±¾18.06.0ÖÁ18.06.6ºÍ19.07.0ÒÔ¼°LEDE 17.01.0ÖÁ17.01.7¾ùÊܵ½Ó°Ïì¡£¡£¡£¡£ ¡£¡£½¨ÒéÊÜÓ°ÏìµÄÓû§½«Æä×°±¸¹Ì¼þÉý¼¶µ½×îÐÂOpenWrt°æ±¾18.06.7ºÍ19.07.1¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/03/openwrt-rce-vulnerability.html


2.Adobe´øÍâÇå¾²¸üУ¬£¬£¬ÐÞ¸´Creative CloudÖеÄí§ÒâÎļþɾ³ýÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


AdobeÐû²¼´øÍâÇå¾²¸üУ¬£¬£¬ÐÞ¸´Windows°æCreative Cloud×ÀÃæÓ¦ÓóÌÐòÖеÄÒ»¸öÑÏÖØÎó²î¡£¡£¡£¡£ ¡£¡£¸ÃÎó²î£¨CVE-2020-3808£©Ô´×ÔTOCTOU¾ºÕùÌõ¼þ£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õßɾ³ýÄ¿µÄϵͳÉϵÄí§ÒâÎļþ¡£¡£¡£¡£ ¡£¡£µ«Adobe²¢Î´ÌṩÓйع¥»÷µÄ¸ü¶àÏêϸÐÅÏ¢£¬£¬£¬ÀýÈç¹¥»÷ÕßÊÇ·ñÐèÒªÔÚÍâµØÕվɿÉÔ¶³ÌʹÓ㬣¬£¬»òÕßÊÇ·ñÐèÒªÉí·ÝÑéÖ¤¡£¡£¡£¡£ ¡£¡£Adobe½¨ÒéÓû§Æ¾Ö¤Ç徲ͨ¸æÖеÄ˵Ã÷½«Æä²úÆ·¸üе½×îа汾¡£¡£¡£¡£ ¡£¡£ÕâÊÇÈýÔ·ÝAdobeÐû²¼µÄµÚ¶þ¸ö´øÍâ¸üС£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-adobe-flaw-out-of-band-security-update/154075/


3.˼¿ÆTalosÅû¶libmicrodns¿âÖеĶà¸öRCEºÍDoSÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


˼¿ÆTalosµÄÇå¾²Ñо¿Ö°Ô±Åû¶VideolabsµÄlibmicrodns¿âÖеĶà¸öDoSºÍ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£ ¡£¡£VideolabsÓÉVideoLAN³ÉÔ±½¨É裬£¬£¬ÊÇVLCÒÆ¶¯Ó¦ÓóÌÐòµÄÄ¿½ñ±à¼­Õߣ¬£¬£¬Ò²ÊÇVLCýÌå²¥·ÅÆ÷µÄÖ÷ҪТ˳Õß¡£¡£¡£¡£ ¡£¡£libmicrodnsÊÇ¿çÆ½Ì¨µÄmDNSÆÊÎöÆ÷¿â£¬£¬£¬ÔÚVLCýÌå²¥·ÅÆ÷ÖÐÓÃÓÚmDNSЧÀÍ·¢Ã÷¡£¡£¡£¡£ ¡£¡£×îÑÏÖØµÄÒ»¸öÎó²îÊÇÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-6072£©£¬£¬£¬ÆäCVSS·ÖÊýΪ9.8¡£¡£¡£¡£ ¡£¡£ÆäÓàÎó²îµÄCVSSÆÀ·Ö¾ùΪ7.5£¬£¬£¬µ«ËüÃÇÓ°ÏìÁË¿âÖеIJî±ð×é¼þ£¬£¬£¬°üÀ¨×ÊÔ´¼Í¼ÆÊÎö¹¦Ð§ÖеÄDoSÎó²î£¨CVE-2020-6071£©¡¢TXT¼Í¼ÆÊÎö¹¦Ð§ÖеÄDoSÎó²î£¨CVE-2020-6073£©¡¢ÐÂÎÅÆÊÎö¹¦Ð§ÖеÄDoSÎó²î£¨CVE-2020-6077£©µÈ¡£¡£¡£¡£ ¡£¡£ÕâЩÎó²îÓ°ÏìÁËlibmicrodns¿â°æ±¾0.1.0£¬£¬£¬¹©Ó¦ÉÌÓÚ3ÔÂ20ÈÕÐû²¼ÁËÐÞ¸´°æ±¾0.1.1¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/03/vuln-spotlight-videolabs-microdns.html


4.FireEyeÐû²¼APT41¹¥»÷»î¶¯±¨¸æ£¬£¬£¬Ê¹ÓöàÖÖÎó²îÈëÇÖÈ«ÇòÆóÒµ


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÔÚ1ÔÂ20ÈÕÖÁ3ÔÂ11ÈÕÖ®¼ä£¬£¬£¬FireEyeÊӲ쵽APT41ÊÔͼʹÓÃCitrix NetScaler/ADC¡¢Cisco·ÓÉÆ÷ºÍZoho ManageEngine Desktop CentralÖеÄÎó²î¹¥»÷Áè¼Ý75¸ö¿Í»§¡£¡£¡£¡£ ¡£¡£ÆäÄ¿µÄÐÐÒµ°üÀ¨ÒøÐÐ/½ðÈÚ¡¢ÐÞ½¨¡¢¹ú·À¹¤Òµ»ùµØ¡¢Õþ¸®¡¢Ò½ÁÆ¡¢¸ß¿Æ¼¼¡¢¸ßµÈ½ÌÓý¡¢Ö´·¨¡¢ÖÆÔìÒµ¡¢Ã½Ìå¡¢·ÇÓªÀû¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢Ê¯»¯¡¢ÖÆÒ©¡¢·¿µØ²ú¡¢µçÐÅ¡¢ÔËÊä¡¢ÂÃÓκ͹«ÓÃÊÂÒµ¡£¡£¡£¡£ ¡£¡£Ä¿µÄ¹ú¼Ò°üÀ¨°Ä´óÀûÑÇ¡¢¼ÓÄô󡢵¤Âó¡¢·ÒÀ¼¡¢·¨¹ú¡¢Ó¡¶È¡¢Òâ´óÀû¡¢ÈÕ±¾¡¢ÂíÀ´Î÷ÑÇ¡¢Ä«Î÷¸ç¡¢·ÆÂɱö¡¢²¨À¼¡¢¿¨Ëþ¶û¡¢É³Ìذ¢À­²®¡¢ÐÂ¼ÓÆÂ¡¢Èðµä¡¢ÈðÊ¿¡¢°¢ÁªÇõ¡¢Ó¢¹úºÍÃÀ¹ú¡£¡£¡£¡£ ¡£¡£ÏÖÔÚÉв»ÇåÎúAPT41ÊÇɨÃ軥ÁªÍø²¢ÊÔͼÌᳫ´ó¹æÄ£¹¥»÷»î¶¯ÕվɽöÕë¶ÔÌØ¶¨×éÖ¯µÄ×Ó¼¯£¬£¬£¬µ«¿´ÆðÀ´¸üÏñÊÇÕë¶ÔÐÔ¹¥»÷¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html


5.TrickBotÍÅ»ïʹÓöñÒâAPP TrickMoÈÆ¹ýÒøÐÐË«ÒòËØÈÏÖ¤


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


IBM X-ForceÑо¿Ö°Ô±·¢Ã÷TrickBotÍÅ»ïÕýÔÚʹÓöñÒâAPP TrickMoÈÆ¹ýÒøÐеÄË«ÒòËØÉí·ÝÑéÖ¤£¨2FA£©± £»£»£»£»£»£»£»¤¡£¡£¡£¡£ ¡£¡£ÔÚÊܺ¦Õß½«TrickMo×°Öõ½ËûÃǵÄAndroid×°±¸ÉÏÖ®ºó£¬£¬£¬¸ÃAPP¿ÉÒÔ×èµ²ÖÖÖÖÉúÒâÑéÖ¤Â루TAN£©£¬£¬£¬°üÀ¨Ò»´ÎÐÔÑéÖ¤Â루OTP£©¡¢Òƶ¯TAN£¨mTAN£©ºÍpushTANÑéÖ¤Â룬£¬£¬²¢×ª·¢¸øTrickBot¹¥»÷Õߣ¬£¬£¬ºóÕßËæºó¿ÉÒÔʹÓÃËüÃǾÙÐÐڲƭÐÔÉúÒâ¡£¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ú¹ÊÍ£¬£¬£¬TrickMoÖ¼ÔÚÍ»ÆÆ×îеÄOTPÒªÁ죬£¬£¬ÓÈÆäÊÇÍ»ÆÆµÂ¹ú¾­³£Ê¹ÓõÄTANÑéÖ¤Âë¡£¡£¡£¡£ ¡£¡£³ý´ËÖ®Í⣬£¬£¬TrickMoµÄÖ÷Òª¹¦Ð§»¹°üÀ¨ÇÔȡСÎÒ˽¼Ò×°±¸ÐÅÏ¢¡¢×èµ²SMSÐÂÎÅ¡¢Ëø¶¨ÊÖ»ú¡¢ÇÔȡװ±¸ÖеÄͼƬºÍ×Ô»Ù/ɾ³ý»úÖÆ¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/trickbot-bypasses-online-banking-2fa-protection-via-mobile-app/


6.ÃÀ¹úÌØ°Ù»Ý¹ÙÍøÔâºÚ¿ÍÈëÇÖ²¢Ñ¬È¾Magecart¾ç±¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ºÚ¿Í¹¥»÷ÁËÃÀ¹úÌØ°Ù»Ý¹«Ë¾£¨Tupperware£©µÄ¹ÙÍø£¬£¬£¬²¢Ö²ÈëÁËÓÃÓÚÇÔÈ¡¿Í»§ÐÅÓÿ¨ÐÅÏ¢µÄ¶ñÒâ¾ç±¾£¨±»³ÆÎªskimmer»òMagecart£©¡£¡£¡£¡£ ¡£¡£Æ¾Ö¤MalwarebytesµÄÒ»·Ý±¨¸æ£¬£¬£¬¸Ã¶ñÒâ´úÂëÒѾ­ÔÚTupperwareÖ÷Ò³ÉÏÔËÐÐÁËÖÁÉÙÎåÌì¡£¡£¡£¡£ ¡£¡£ÏÖÔÚTupperwareÒѾ­´ÓÆäЧÀÍÆ÷ÉÑþ³ØýÁ˶ñÒâ¾ç±¾£¬£¬£¬µ«ÉÐδÐû²¼ÕýʽµÄ»ØÓ¦»òÉùÃ÷¡£¡£¡£¡£ ¡£¡£MalwarebytesÌåÏָöñÒâ´úÂëÔÚÿ´ÎÓû§¸¶¿îʱ½¨ÉèÒ»¸öƯ¸¡µÄiframe£¬£¬£¬²¢ÏÔʾһ¸öÄ£ÄâVISA CyberSource¸¶¿îÐÎʽµÄ±íµ¥£¬£¬£¬¸Ã±íµ¥»áÍøÂçÓû§ÊäÈëµÄÊý¾Ý£¬£¬£¬ÀýÈçÐÕÃû¡¢Õ˵¥µØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨ºÅÂë¡¢µ½ÆÚÈÕÆÚºÍCVVÂ룬£¬£¬È»ºó½«Æä·¢Ë͵½Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£ ¡£¡£TupperwareµÄÍâµØ»¯Ò³ÃæÒ²Ñ¬È¾Á˸þ籾£¬£¬£¬µ«ºÜÈÝÒ×ʶ±ð³öÀ´£¬£¬£¬ÓÉÓÚÍâµØÒ³ÃæÏÔʾµÄ¶¼ÊÇÍâµØÓïÑÔ£¬£¬£¬¶ø¶ñÒâ±íµ¥ÊÇÓ¢Óï¡£¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/tupperware-website-hacked-and-infected-with-payment-card-skimmer/