ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ8ÖÜ
Ðû²¼Ê±¼ä 2021-02-22> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê02ÔÂ15ÈÕÖÁ02ÔÂ21ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇEFM ipTIME C200 IP Camera CVE-2020-7848ÏÂÁî×¢ÈëÎó²î£»Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»DJI Mavic 2¹Ì¼þÉý¼¶ÏÂÁî×¢ÈëÎó²î£»McAfee Web Gateway troubleshootingÒ³ÌØȨÌáÉýÎó²î£»Bloodhound objectId×¢ÈëÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬Ð¹Â¶120GBÊý¾Ý£»·¨¹úºÍÎÚ¿ËÀ¼ÍŽᵷ»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©£»°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCEÎó²î£¬ÏÂÔس¬10ÒڴΣ»Cyble·¢Ã÷ʹÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹ÂÚ¹¥»÷Ô˶¯£»Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Äê×îÏÈ»îÔ¾¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.EFM ipTIME C200 IP Camera CVE-2020-7848ÏÂÁî×¢ÈëÎó²î
EFM ipTIME C200 IP Camera /login.cgi?logout=1±£´æÊäÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýCOOKIEÖµÖ´ÐÐí§ÒâOSÏÂÁî¡£
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35905
2.Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐÐÎó²î
Google Chrome Data Transfer±£´æÕ»Òç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html
3.DJI Mavic 2¹Ì¼þÉý¼¶ÏÂÁî×¢ÈëÎó²î
DJI Mavic 2 Remote Controller dji_sysδ¹ýÂËÎļþÖÐÌØÊâÊôÐÔ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬Í¨¹ý¹Ì¼þÉý¼¶°üÖ´ÐдúÂë¡£
http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdf
4.McAfee Web Gateway troubleshootingÒ³ÌØȨÌáÉýÎó²î
McAfee Web Gateway troubleshootingÒ³±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýÓû§½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁÌáÉýȨÏÞ¡£
https://kc.mcafee.com/corporate/index?page=content&id=SB10349
5.Bloodhound objectId×¢ÈëÎó²î
Bloodhound objectId²ÎÊý´¦Öóͷ£±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿É×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£
https://github.com/BloodHoundAD/BloodHound/issues/338
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢¼ÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬Ð¹Â¶120GBÊý¾Ý
¼ÓÄôóÁìÏȵÄÆû³µºÍ¿¨³µ×âÁÞ¹«Ë¾Canadian Discount Car and Truck RentalsÊܵ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÁË120GBµÄÊý¾Ý£¬°üÀ¨½ðÈÚ¡¢Êг¡ÓªÏú¡¢ÒøÐС¢ÕÊ»§ºÍ¼ÓÃËÉÌÊý¾Ý¡£Õⳡ¹¥»÷ÖÐÖ¹Á˸ù«Ë¾ÔÚdiscountcar.comÉϵÄÔÚÏß×âÁÞ·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/leading-canadian-rental-car-company-hit-by-darkside-ransomware/
2¡¢·¨¹úºÍÎÚ¿ËÀ¼ÍŽᵷ»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©
·¨¹úºÍÎÚ¿ËÀ¼Ö´·¨²¿·ÖµÄÍŽáÐж¯¾Ð²¶ÁËÎÚ¿ËÀ¼µÄEgregorÀÕË÷Èí¼þµÄ¼¸Ãû³ÉÔ±£¬ÕâЩ³ÉÔ±µÄÊÂÇéÊÇÈëÇÖ¹«Ë¾ÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¾Ý±¨µÀ£¬¸ÃÐж¯ÊÇÔÚÈ¥ÄêÇïÌìÊÕµ½°ÍÀèÀÕË÷Èí¼þ·¸·¨ÍÅ»ïµÄͶËߺó£¬ÓÉ°ÍÀè´óÉó·¨ÔºÆô¶¯µÄ¡£ÏÖÔÚ£¬EgregorµÄTorÍøÕ¾´¦ÓÚÀëÏß״̬¡£ÓÉÓÚÎÞ·¨»á¼ûTor¸¶¿îÕ¾µã£¬Êܺ¦ÕßÎÞ·¨ÁªÏµµ½ÀÕË÷Õߣ¬Ò²ÎÞ·¨Ö§¸¶Êê½ð»òÏÂÔؽâÃÜÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/egregor-ransomware-members-arrested-by-ukrainian-french-police/
3¡¢°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCEÎó²î£¬ÏÂÔس¬10ÒÚ´Î
Ò»¸ö±»ÏÂÔØÁè¼Ý 10 ÒÚ´ÎµÄ Android Ó¦ÓóÌÐò°üÀ¨ÁËδÐÞ²¹µÄÎó²î£¬¶øÕâ¸ö°üÀ¨Îó²îµÄÓ¦ÓóÌÐòµÄÐÞ¸´Ê±¼äÒѾÁè¼ÝÁËÈý¸öÔ¡£ÕâЩÎó²îÓ°ÏìÁË Android °æ±¾µÄ SHAREit£¬Ò»¸öÔÊÐíÓû§ÓëÅóÙ»òСÎÒ˽¼Ò×°±¸¹²ÏíÎļþµÄÒƶ¯Ó¦ÓóÌÐò¡£Trend MicroµÄÒƶ¯ÍþвÆÊÎöʦEcho DuanÔÚÒ»·Ý±¨¸æÖÐ˵£¬¿ÉÒÔʹÓÃÕâЩÎó²îÔÚ×°ÖÃÁËSHAREitÓ¦ÓóÌÐòµÄÖÇÄÜÊÖ»úÉÏÔËÐжñÒâ´úÂë ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-bugs-left-unpatched-in-android-app-with-one-billion-downloads/
4¡¢Cyble·¢Ã÷ʹÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹ÂÚ¹¥»÷Ô˶¯
ÍþвÇ鱨¹«Ë¾CybleµÄÑо¿Ö°Ô±·¢Ã÷ÁËÕë¶Ô¶à¸öÀÄÓÃngrokƽ̨µÄ×éÖ¯µÄÐÂÒ»²¨ÍøÂç´¹ÂÚ¹¥»÷£¬ngrokƽ̨ÊÇͨÍùµ±ÌïÖ÷»úµÄÒ»¸öÇå¾²ÇÒ¿É×ÔÊ¡µÄËíµÀ¡£ngrokÊÇÒ»¸ö¿çƽ̨ӦÓóÌÐò£¬ÓÃÓÚ½«ÍâµØ¿ª·¢·þÎñÆ÷¹ûÕæµ½Internet£¬Í¨¹ý½¨Éèµ½µ±ÌïÖ÷»úµÄ³¤Á´½ÓTCPËíµÀ£¬¸Ã·þÎñÆ÷ËƺõÍйÜÔÚngrokµÄ×ÓÓò£¨ÀýÈç4f421deb219c[.]ngrok[.]io£©ÉÏ¡£×¨¼ÒÃÇÖ¸³ö£¬ngrok·þÎñÆ÷Èí¼þÔËÐÐÔÚVPS»òרÓ÷þÎñÆ÷ÉÏ£¬¿ÉÒÔÈƹýNATÓ³ÉäºÍ·À»ðǽÏÞÖÆ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/114644/cyber-crime/ngrok-phishing-attacks.html
5¡¢Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Äê×îÏÈ»îÔ¾
WatchDog¼ÓÃÜÍÚ¿ó½©Ê¬ÍøÂçÓÉPalo Alto NetworksµÄÍþвÇ鱨²¿·Ö42²¿·Ö·¢Ã÷£¬¸Ã½©Ê¬ÍøÂç×Ô2019Äê1ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£Ñо¿Ö°Ô±ÌåÏÖ£¬WatchDogÓÉGoÓïÑÔ±àд¶ø³É¡£Æ¾Ö¤Unit 42ÍŶӶÔWatchDog¶ñÒâÈí¼þµÄÆÊÎö£¬Ñо¿Ö°Ô±Ô¤¼Æ¸Ã½©Ê¬ÍøÂçÒѹ¥»÷500µ½1000¸öÄ¿µÄ¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/windows-and-linux-servers-targeted-by-new-watchdog-botnet-for-almost-two-years/