ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ5ÖÜ

Ðû²¼Ê±¼ä 2021-02-01

> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö


2021Äê01ÔÂ25ÈÕÖÁ01ÔÂ31ÈÕ¹²ÊÕ¼Çå¾²Îó²î59¸ö  £¬ÖµµÃ¹Ø×¢µÄÊÇGoogle AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´ÐÐÎó²î£»Bosch FSM-2500 serverÃÜÂëй¶Îó²î£»Rust SmallVec::insert_many¶ÑÒç³öÎó²î£»SonicWall SSL-VPN User-AgentÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£»Mozilla Firefox CVE-2021-23964ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇSonicWallÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷Ô˶¯£»ºÚ¿Í¹ûÕæ¼ÓÃÜÇ®±ÒÉúÒâËùBuyucoinÓû§µÄÊý¾Ý£»AppleÇå¾²¸üР £¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚҰʹÓõÄ0day£»SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ£»È«ÇòÖ´·¨²¿·ÖÍŽáÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©¡£


ƾ֤ÒÔÉÏ×ÛÊö  £¬±¾ÖÜÇå¾²ÍþвΪÖС£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.Google AndroidÔËÐÐʱCVE-2020-0267´úÂëÖ´ÐÐÎó²î


Google AndroidÔËÐÐʱ±£´æÇå¾²Îó²î  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó  £¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://source.android.com/security/bulletin/android-11


2.Bosch FSM-2500 serverÃÜÂëй¶Îó²î


Bosch FSM-2500 serverʹÓõÄÃÜÂë¹þÏ£²»·ó½áʵ  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó  £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

https://psirt.bosch.com/security-advisories/BOSCH-SA-332072-BT.html


3.Rust SmallVec::insert_many¶ÑÒç³öÎó²î


Rust SmallVec::insert_many±£´æ¶ÑÒç³öÎó²î  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó  £¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://github.com/servo/rust-smallvec/issues/252


4.SonicWall SSL-VPN User-AgentÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î


Sonicwall ssl-vpn CGI³ÌÐò´¦Öóͷ£±£´æÂß¼­Îó²î  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄUser-AgentÇëÇó  £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://darrenmartyn.ie/2021/01/24/visualdoor-sonicwall-ssl-vpn-exploit/


5.Mozilla Firefox CVE-2021-23964ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î


Mozilla Firefox´¦Öóͷ£WEBÒ³±£´æÄÚ´æÆÆËðÎó²î  £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²î¹¹½¨¶ñÒâWEBÒ³  £¬ÓÕʹÓû§ÆÊÎö  £¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£

https://www.auscert.org.au/bulletins/ESB-2021.0291/


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢SonicWallÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷Ô˶¯


1.jpg


Çå¾²³§ÉÌSonicWallÐû²¼½ôÆÈ֪ͨ  £¬ÖÒÑÔʹÓÃÆäVPN²úÆ·ÖÐ0dayµÄ¹¥»÷Ô˶¯¡£¸ÃÎó²îλÓÚSecure Mobile Access£¨SMA£©VPN×°±¸¼°NetExtender VPN¿Í»§¶ËÖÐ  £¬¿É±»ÓÃÀ´¶Ô¹«Ë¾µÄÄÚ²¿ÏµÍ³¾ÙÐÐЭͬ¹¥»÷¡£SonicWallÉÐδÐû²¼ÓйظÃÎó²îµÄÏêϸÐÅÏ¢  £¬µ«Æ¾Ö¤»º½â²½·¥ÅÐ¶Ï  £¬Æä¿ÉÄÜÊÇÊÇÉí·ÝÑéÖ¤Îó²î  £¬¿É±»ÓÃÀ´ÔڿɹûÕæ»á¼ûµÄ×°±¸ÉÏÔ¶³ÌʹÓá£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sonicwall-firewall-maker-hacked-using-zero-day-in-its-vpn-device/


2¡¢ºÚ¿Í¹ûÕæ¼ÓÃÜÇ®±ÒÉúÒâËùBuyucoinÓû§µÄÊý¾Ý


2.png


ShinyHuntersÔÚ°µÍøÉϹûÕæÓ¡¶È¼ÓÃÜÇ®±ÒÉúÒâËùBuyucoinÓû§µÄÊý¾Ý¡£´Ë´Î×ܹ²Ð¹Â¶ÁËÈý¸öMongoDBÊý¾Ý¿â  £¬ÕâЩÊý¾Ý¿â¾ùÒÔʱ¼äÃüÃû  £¬»®·ÖΪ2020Äê6ÔÂ1ÈÕ¡¢2020Äê7ÔÂ14ÈÕºÍ2020Äê9ÔÂ5ÈÕ¡£Ð¹Â¶Êý¾Ý°üÀ¨Óû§¼Í¼¡¢¼ÓÃÜÇ®±ÒÉÌÒµÉúÒâ¡¢Óû§Á´½ÓµÄÒøÐÐÕÊ»§ÐÅÏ¢ÒÔ¼°ÉúÒâËùÄÚ²¿Ê¹ÓõÄÆäËû±í  £¬ÆäÖÐÓû§¼Í¼±í´æ´¢ÁË161487¸ö³ÉÔ±µÄÐÅÏ¢  £¬°üÀ¨µç×ÓÓʼþµØµã¡¢¹ú¼Ò/µØÇø¡¢¹þÏ£ÃÜÂë¡¢ÊÖ»úºÅÂëºÍGoogleµÇ¼ÁîÅƵÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/data-breach-at-buyucoin-crypto-exchange-leaks-user-info-trades/


3¡¢AppleÇå¾²¸üР £¬ÐÞ¸´iOSÖÐ3¸öÒѱ»ÔÚҰʹÓõÄ0day


3.png


AppleÐû²¼ÁËÕë¶ÔiOSµÄÇå¾²¸üР £¬ÐÞ¸´ÁË3¸öÒѱ»ÔÚҰʹÓõÄ0day¡£µÚÒ»¸öΪӰÏìiOS²Ù×÷ϵͳÄں˵ľºÕùÌõ¼þÎó²î£¨CVE-2021-1782£©  £¬Ëü¿ÉÒÔʹ¹¥»÷ÕßÌáÉýÆä¹¥»÷´úÂëµÄȨÏÞ¡£ÁíÍâÁ½¸öΪӰÏìWebKitä¯ÀÀÆ÷ÒýÇæµÄÂß¼­Îó²î£¨CVE-2021-1870ºÍCVE-2021-1871£©  £¬¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÔÚÓû§µÄSafariä¯ÀÀÆ÷ÖÐÖ´ÐжñÒâ´úÂë¡£ÔÚÎó²îʹÓÃÁ´ÖÐ  £¬Óû§±»ÒýÓÕµ½Ò»¸ö¶ñÒâÍøÕ¾  £¬¸ÃÍøվʹÓÃWebKitÎó²îÔËÐдúÂë  £¬ËæºóÉý¼¶ÆäÔËÐÐϵͳ¼¶´úÂëµÄȨÏÞ  £¬Î£¼°²Ù×÷ϵͳ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/apple-fixes-another-three-ios-zero-days-exploited-in-the-wild/


4¡¢SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ


4.png


Çå¾²Éó¼Æ¹«Ë¾Qualys·¢Ã÷SudoÎó²îBaronSameditÎÞÐèÃÜÂë¿ÉÌáȨÖÁrootȨÏÞ  £¬ÒÑÓнüÊ®ÄêµÄÀúÊ·¡£¸ÃÎó²îÊÇÓÉÓÚsudo¹ýʧµØÔÚ²ÎÊýÖÐתÒåÁË·´Ð±¸Üµ¼Ö»ùÓڶѵĻº³åÇøÒç³öÎó²î  £¬±»×·×ÙΪCVE-2021-3156  £¬ÔÊÐíÈκÎÍâµØÓû§£¨ÎÞÂÛÊÇ·ñÔÚsudoersÎļþÖУ©ÎÞÐè¾ÙÐÐÉí·ÝÑéÖ¤»ñµÃrootȨÏÞ¡£ÔÚÒÑÍùÁ½ÄêÖз¢Ã÷ÁËÁíÍâÁ½¸öSudoÎó²î£¨CVE-2019-14287ºÍCVE-2019-18634£©  £¬¿ÉÊÇ´Ë´ÎÅû¶µÄÎó²îÊÇÈýÆäÖÐ×îΣÏÕµÄÒ»¸ö¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/10-years-old-sudo-bug-lets-linux-users-gain-root-level-access/


5¡¢È«ÇòÖ´·¨²¿·ÖÍŽáÆÆ»ñEmotet½©Ê¬ÍøÂçµÄ»ù´¡ÉèÊ©


5.png


ÓÉÅ·ÖÞÐ̾¯×éÖ¯£¨Europol£©Ïòµ¼µÄÈ«ÇòÖ´·¨Ðж¯ÆÆ»ñÁËÖøÃû½©Ê¬ÍøÂçEmotetµÄ»ù´¡ÉèÊ©¡£EmotetÖÁÉÙ´Ó2014Äê×îÏÈ»îÔ¾  £¬ÓëºÚ¿Í×éÖ¯TA542ÓйØ¡£Europol³Æ  £¬´Ë´ÎÐж¯±»³ÆΪOperation Ladybird  £¬ÓɺÉÀ¼¡¢µÂ¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢·¨¹ú¡¢Á¢ÌÕÍð¡¢¼ÓÄôóºÍÎÚ¿ËÀ¼Õþ¸®ÅäºÏÏàÖú  £¬ÆÆËð²¢½ÓÊÜÁËλÓÚ90¶à¸ö¹ú¼ÒµÄEmotetµÄC&C  £¬²¢¾Ð²¶Á˶àÁ½ÃûÍøÂç·¸·¨·Ö×Ó¡£¾ÝºÉÀ¼¾¯·½³Æ  £¬Emotet×ܼÆÔì³ÉÁËÊýÒÚÃÀÔªµÄËðʧ  £¬¶øÎÚ¿ËÀ¼Ö´·¨²¿·ÖËðʧ¶îÔ¤¼ÆΪ25ÒÚÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/113933/cyber-crime/emotet-global-takedown.html