ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ2ÖÜ

Ðû²¼Ê±¼ä 2019-01-14

±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2019Äê1ÔÂ07ÈÕÖÁ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î63¸ö £¬ÖµµÃ¹Ø×¢µÄÊÇCisco Identity Services Engine CVE-2018-15456ÃÜÂë»Ö¸´Îó²î£»Imperva SecureSphereÌí¼Óí§ÒâsshÃÜÔ¿Îó²î£»Juniper Junos OS BGP¾Ü¾ø·þÎñÎó²î£»Microsoft Visual Studio CVE-2019-0546í§Òâ´úÂëÖ´ÐÐÎó²î£»Microsoft Exchange ServerÔ¶³ÌÐÅϢй¶Îó²î ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂDNSЮÖÆÀ˳±Ï¯¾íÈ«Çò £¬ÒÉΪÒÁÀʺڿÍËùΪ£»Google PlayϼÜ85¸ö¹ã¸æapp £¬Ñ¬È¾Ô¼900ÍòAndroidÓû§£»Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆع⣻AvastÐû²¼2019ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ£»IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß ¡£

ƾ֤ÒÔÉÏ×ÛÊö £¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Cisco Identity Services Engine CVE-2018-15456ÃÜÂë»Ö¸´Îó²î
Cisco Identity Services Engine Admin Portal²»×¼È·ÉúÑÄÃÜÂëÐÅÏ¢ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬Éó²éÃ÷ÎÄÃÜÂëÐÅÏ¢ £¬Î´ÊÚȨ»á¼û ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190109-ise-passwd

2. Imperva SecureSphereÌí¼Óí§ÒâsshÃÜÔ¿Îó²î
Imperva SecureSphere±£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿ÉÏòÖÎÀíÔ±Óû§µÄauthorized_keysÌí¼Óí§ÒâsshÃÜÔ¿ ¡£
https://www.exploit-db.com/exploits/45130

3. Juniper Junos OS BGP¾Ü¾ø·þÎñÎó²î
Juniper Junos OS´¦Öóͷ£BGPÐÂÎű£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿É¾ÙÐоܾø·þÎñ¹¥»÷ ¡£
https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10912&actp=METADATA

4. Microsoft Visual Studio CVE-2019-0546í§Òâ´úÂëÖ´ÐÐÎó²î
Microsoft Visual StudioÔÚC++±àÒëÆ÷δ׼ȷ´¦Öóͷ£C++½á¹¹Ìض¨×éºÏ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó £¬ÓÕʹÓû§ÆÊÎö £¬¿ÉÒÔÓ¦Óù¦Ð§³ÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë ¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0546

5. Microsoft Exchange ServerÔ¶³ÌÐÅϢй¶Îó²î
Microsoft Exchange Server PowerShell APIÔÚcalendar contributorsȨÏÞÖÎÀíÖб£´æÇå¾²Îó²î £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó £¬¿É»ñÈ¡Ãô¸ÐÈÕÀúµÈÃô¸ÐÐÅÏ¢ ¡£
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0588


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÐÂDNSЮÖÆÀ˳±Ï¯¾íÈ«Çò £¬ÒÉΪÒÁÀʺڿÍËùΪ

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢


FireEye·¢Ã÷Ò»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNSЮÖÆÀ˳± £¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû ¡£ÕâЩÓòÃûÊôÓÚÕþ¸®¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ ¡£ËäÈ»ÏÖÔÚÑо¿Ö°Ô±»¹Ã»Óн«´ËÔ˶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´ £¬µ«ÆðÔ´µÄÑо¿Åú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйØ ¡£¸Ã¹¥»÷Ô˶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂʱ´úÒ»Ö±´¦ÓÚ»îԾ״̬ £¬²¢ÇÒ±£´æ¶à¸ö²»Öظ´µÄÓòÃû¡¢IPµØµã¼¯Èº ¡£ÕâÒâζןù¥»÷Ô˶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕßµÄÔ˶¯ ¡£¹¥»÷ÕßµÄÊÖÒÕÖ÷ÒªÉæ¼°ÐÞ¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍÖض¨Ïò ¡£

Ô­ÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html

2¡¢Google PlayϼÜ85¸ö¹ã¸æapp £¬Ñ¬È¾Ô¼900ÍòAndroidÓû§

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



Ç÷ÊƿƼ¼µÄÑо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁ·¢Ã÷85¸ö¹ã¸æÓ¦Óà £¬Ô¼900ÍòAndroidÓû§Êܵ½Ñ¬È¾ ¡£ÕâЩappαװ³ÉÓÎÏ·¡¢Á÷ýÌåµçÊÓºÍÄ£ÄâÒ£¿ØÆ÷µÈ £¬ÔÚ×°±¸ºǫ́¾²Ä¬ÔËÐÐ £¬²¢Ã¿¸ô15»ò30·ÖÖÓʹÓÃÈ«ÆÁ¹ã¸æºäÕ¨Óû§×°±¸ ¡£Ñо¿Ö°Ô±·¢Ã÷ÕâЩappÀ´×ÔÓÚ²î±ðµÄ¿ª·¢Ö°Ô± £¬²¢ÇÒÓµÓвî±ðµÄAPKÖ¤Ê鹫Կ £¬µ«ËüÃǵĴúÂëºÍÃüÃû·½·¨¶¼Ê®·ÖÏàËÆ ¡£Google PlayÔÚ½Óµ½Í¨ÖªºóÒÑϼÜÁËÕâЩӦÓà ¡£


Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/android-adware-malware.html

3¡¢Ó¡¶ÈÁè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êÔÚÆعâ

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



Çå¾²Ñо¿Ô±Justin Paine·¢Ã÷Ò»¸öδÉèÃÜÂëµÄElasticSearch·þÎñÆ÷ £¬¸Ã·þÎñÆ÷°üÀ¨À´×Ô27¼ÒÓ¡¶È¹úÓÐÔËÊä»ú¹¹µÄÊý¾Ý £¬ÆäÖаüÀ¨Áè¼Ý1.1ÍòÁ¾¹«¹²Æû³µµÄʵʱGPS×ø±êºÍõ辶ÐÅÏ¢ ¡£²î±ðÔËÊä»ú¹¹µÄÊý¾Ý²¢²»Ïàͬ £¬ÔÚijЩ°¸ÀýÖÐ £¬»¹°üÀ¨Âÿ͵ÄÓû§ÃûºÍµç×ÓÓʼþµØµã ¡£¸Ã·þÎñÆ÷ÖÁÉÙÒÑÔÚ»¥ÁªÍøÉÏÆعâÁËÈýÖܵÄʱ¼ä ¡£ÔÚPaine֪ͨӡ¶ÈCERTºó £¬¸Ã·þÎñÆ÷»ñµÃ±£»¤ £¬µ«CERT¾Ü¾ø͸¶¸Ã·þÎñÆ÷µÄËùÓÐÕß ¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/real-time-location-data-for-over-11000-indian-buses-left-exposed-online/

4¡¢AvastÐû²¼2019ÄêÍøÂçÍþв̬ÊƵÄÕ¹Íû±¨¸æ

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



AvastµÄ2019ÄêÍþв̬ÊÆÕ¹Íû±¨¸æÖ¸³ö £¬ÔÚ2019Äê¶Ô¿¹ÐÔAI½«Ó­À´ÀèÃ÷ ¡£Ñо¿Ö°Ô±Õ¹ÍûDeepAttacks¹¥»÷½«¸üƵÈԵطºÆð£¨ÕâÀ๥»÷ͨ³£Ê¹ÓÃAIÌìÉúµÄÄÚÈÝÀ´ÌÓ±ÜAIÇå¾²¿ØÖƲ½·¥£© ¡£±ðµÄ £¬ÎïÁªÍøÍþв½«±äµÃÔ½·¢ÖØ´ó £¬Â·ÓÉÆ÷Ò²½«Ô½À´Ô½¶àµØ³ÉΪ¹¥»÷Ä¿µÄ £¬¹ã¸æ¡¢´¹ÂÚºÍÐéαӦÓý«¼ÌÐøÖ÷µ¼Òƶ¯ÍþвÁìÓò ¡£


Ô­ÎÄÁ´½Ó£º
https://cdn2.hubspot.net/hubfs/486579/Avast_Threat_Landscape_Report_2019.pdf

5¡¢IBM TWCÌìÆøÓ¦ÓÃÒò³öÊÛÓû§Êý¾ÝÔâµ½ÆðËß

ÓÅ·¢¹ú¼Ê¡¤ËæÓŶø¶¯Ò»´¥¼´·¢



Âåɼí¶ÊÐÏò¼ÓÀû¸£ÄáÑÇÖÝ·¨ÔºÌáÆðËßËÏ £¬¿ØËßIBM×Ó¹«Ë¾TWCµÄÌìÆøÓ¦Óã¨Weather Channel£©ÍÚ¾òÓû§µÄÒþ˽Êý¾Ý²¢½«ÕâЩÐÅÏ¢³öÊÛ¸øµÚÈý·½ £¬°üÀ¨¹ã¸æ¹«Ë¾ ¡£Âåɼí¶Êз½ÃæÌåÏÖ £¬Weather ChannelÔÚÐí¶àÓû§²»ÖªÇéµÄÇéÐÎϸú×ÙÓû§µÄµØÀíλÖÃÊý¾Ý £¬²¢½«ÕâЩÊý¾ÝÓÃÓÚÓëÌìÆøÔ¤¸æÍêÈ«Î޹صĹã¸æµÈÉÌÒµÓÃ; ¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/city-of-la-sues-weather-channel-app-for-sharing-location-data-with-advertisers/


ÉùÃ÷£º±¾×ÊѶÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøάËûÃüÇ徲С×é·­ÒëºÍÕûÀí