ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ15ÖÜ
Ðû²¼Ê±¼ä 2021-04-13> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2021Äê04ÔÂ05ÈÕÖÁ04ÔÂ11ÈÕ¹²ÊÕ¼Çå¾²Îó²î41¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇCisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î£»LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î£»OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î£»SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î£»Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day£»KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌع¤Ô˶¯£»Ð¼Óƹ¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢£»Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚÊÓ²ìÖУ»ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
> Ö÷ÒªÇå¾²Îó²îÁбí
1.Cisco RV345P Dual WAN Gigabit VPN Routers CVE-2021-1414í§Òâ´úÂëÖ´ÐÐÎó²î
CCisco RV345P Dual WAN Gigabit VPN Routers WEBÖÎÀí½Ó¿Ú±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÌáÉýȨÏÞ¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sb-rv34x-rce-8bfG2h6b
2.LiteSpeed Technologies OpenLiteSpeed web serverȨÏÞÌáÉýÎó²î
LiteSpeed Technologies OpenLiteSpeed web server±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÔÚÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁî¡£
https://github.com/litespeedtech/openlitespeed/issues/217
3.OpenIAM Groovy Script´úÂëÖ´ÐÐÎó²î
OpenIAM Groovy Script±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/Accenture/AARO-Bugs/blob/master/AARO-CVE-List.md
4.SonicWall GMSÔ¶³ÌȨÏÞÌáÉýÎó²î
SonicWall GMS±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTȨÏÞÖ´ÐÐí§Òâ´úÂë¡£
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0009
5.Skyworth Digital Technology RN510»º³åÇøÒç³öÎó²î
Skyworth Digital Technology RN510 /cgi-bin/app-staticIP.asp»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://s3curityb3ast.github.io/KSA-Dev-011.md
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢TIMÍŶÓÅû¶CA Technologies²úÆ·ÖеĶà¸ö0day
CA TechnologiesÊÇÃÀ¹úÒ»¼ÒרעÓÚB2BÈí¼þµÄ¿ç¹ú¹«Ë¾£¬ÏúÊÛ½ü200ÖÖ²úÆ·£¬Éæ¼°ÂþÑÜʽÅÌËã¡¢ÔÆÅÌËã¡¢DevOpsºÍÅÌËã»úÇå¾²Èí¼þÒÔ¼°Òƶ¯×°±¸¡£TIMµÄRed Team ResearchÍŶÓÅû¶ÁËCA eHealth Performance Manager²úÆ·ÖеÄ5¸öÐÂÎó²î¡£»®·ÖΪÌáȨÎó²î£¨CVE-2021-28246ºÍCVE-2021-28249£©¡¢¿çÕ¾µã¾ç±¾Îó²î£¨CVE-2021-28247£©¡¢Í¨¹ýSUID/GUIDÎļþµÄÌáȨÎó²î£¨CVE-2021-28250£©ºÍÉí·ÝÑéÖ¤Îó²î£¨CVE-2021-28248£©¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/116268/security/ca-ehealth-performance-manager-flaws.html
2¡¢KasperskyÅû¶Õë¶ÔÔ½Ä϶à¸ö×éÖ¯µÄÍøÂçÌع¤Ô˶¯
KasperskyÅû¶ÁËAPT×éÖ¯CycldekÕë¶ÔÔ½ÄÏÕþ¸®ºÍ¾üÊÂ×éÖ¯µÄÍøÂçÌع¤Ô˶¯¡£¸ÃÔ˶¯Ê¹ÓÃÁËÃûΪFoundCoreµÄ¶ñÒâÈí¼þ£¬¿É¾ÙÐÐÎļþϵͳʹÓá¢Àú³ÌʹÓá¢ÆÁÄ»½Øͼ²¶»ñºÍí§ÒâÏÂÁîÖ´ÐС£±ðµÄ£¬Kaspersky³Æ¸Ã×éÖ¯ÔÚÖØ´óÐÔ·½ÃæÈ¡µÃÁËÖØ´óÇ°½ø£¬ÀýÈ磬ÆäpayloadµÄ±êÍ·£¨´úÂëµÄÄ¿µÄºÍÔ´£©±»ÍêÈ«°þÀ룬ʣϵÄÉÙÊý²¿·ÖµÄÖµÊDz»Á¬¹áµÄ£¬Õâ´ó´óÔöÌíÁËÑо¿Ö°Ô±¶ÔÆä¾ÙÐÐÆÊÎöµÄÄѶȡ£
ÔÎÄÁ´½Ó£º
https://threatpost.com/spy-operations-vietnam-rat/165243/
3¡¢Ð¼Óƹ¤»áe2iÔâµ½´¹ÂÚ¹¥»÷£¬Ð¹Â¶ÊýÍò¹«ÃñµÄÐÅÏ¢
мÓÆÂÌìϹ¤»á´ú±í´ó»á¾ÍÒµÓë¾ÍÒµÑо¿Ëù£¨e2i£©ÔÚ±¾ÖÜÒ»£¨4ÔÂ5ÈÕ£©Ðû²¼ÉùÃ÷³Æ£¬¹¥»÷Õß¿ÉÄÜÒѾ»á¼ûÆäÓû§µÄСÎÒ˽¼ÒÐÅÏ¢¡£´Ë´Î鶵ÄÐÅÏ¢°üÀ¨Óû§µÄÐÕÃû¡¢½ÌÓý×ʸñºÍNRIC¡¢ÁªÏµ·½·¨ºÍ¾Íҵϸ½ÚµÈ¡£ÊÂÎñ±¬·¢ÔÚ3ÔÂ12ÈÕ£¬ÆäµÚÈý·½¹©Ó¦ÉÌ¡ª¡ªÁªÂçÖÐÐÄÕÛÎñ¹«Ë¾i-vic InternationalÔ±¹¤µÄÓÊÏäÔâµ½´¹ÂÚ¹¥»÷£¬¸ÃÓÊÏäµÄÔƶ˰üÀ¨ÁËÔ¼3Íò¸ö¼ÓÈëÁËe2iÔ˶¯µÄÓû§ÐÅÏ¢£¬¿ÉÊǸûú¹¹¾Ü¾ø͸¶×ܹ²Óм¸¶àÈËÔøʹÓùýe2iµÄ·þÎñ¡£
ÔÎÄÁ´½Ó£º
https://www.straitstimes.com/tech/tech-news/personal-data-of-30000-people-who-use-ntucs-e2i-services-may-have-been-breached
4¡¢Å·Ã˳ÆÆä¶à¸ö»ú¹¹ÔÚÉÏÖÜÔâµ½¹¥»÷£¬ÊÂÎñÈÔÔÚÊÓ²ìÖÐ
Å·ÃËίԱ»á½²»°È˳ƣ¬°üÀ¨Î¯Ô±»áÔÚÄڵĶà¸öÅ·ÃË×éÖ¯ÔÚÉÏÖÜÔâµ½ÁËÍøÂç¹¥»÷¡£ÏÖÔÚ¶Ô¸ÃÊÂÎñµÄÈ¡Ö¤ÆÊÎöÈÔ´¦ÓÚ³õÆڽ׶Σ¬ÉÐδ¼ì²âµ½±£´æÐÅϢй¶ÎÊÌâ¡£Åí²©ÉçÌåÏÖ£¬´Ë´ÎÊÂÎñ±ÈÅ·ÃËÒÔÍùÔâµ½µÄ¹¥»÷¸üΪÑÏÖØ£¬Å·ÃËij¹ÙÔ±»¹Í¸Â¶£¬ÆäÊÂÇéÖ°Ô±½üÆÚÊÕµ½ÁËÓйØÕë¶ÔÅ·Ã˵Ĵ¹ÂÚ¹¥»÷Ô¤¾¯¡£ÏÖÔÚ£¬Å·ÃËÈÔδ¹ûÕæÓйش˴ÎÊÂÎñµÄÐÔ×Ó»òÆä±³ºóµÄ¹¥»÷ÕßÉí·ÝµÄÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bloomberg.com/news/articles/2021-04-06/european-institutions-were-targeted-in-a-cyber-attack-last-week
5¡¢ESETÅû¶Õë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÒøÐÐľÂíJaneleiro
ESETµÄÑо¿Ö°Ô±Åû¶ÁËÕë¶ÔÀ¶¡ÃÀÖÞµØÇøÓû§µÄÐÂÐÍÒøÐÐľÂíJaneleiro¡£¸ÃľÂíÖÁÉÙ´Ó2019ÄêÒÔÀ´¾Í×îÏÈÕë¶Ô°ÍÎ÷µÄÆóÒµ£¬Éæ¼°¹¤³Ì¡¢Ò½ÁƱ£½¡¡¢ÁãÊÛ¡¢ÖÆÔìÒµ¡¢½ðÈÚ¡¢ÔËÊäºÍÕþ¸®µÈ¸÷¸öÁìÓò¡£Janeleiroͨ¹ýαÔì´óÐÍÒøÐÐÍøÕ¾£¨SantanderºÍBanco do BrasilµÈ£©µÄµ¯´°À´ÓÕ»óÄ¿µÄ£¬ÕâЩµ¯´°°üÀ¨ÐéαµÄ±í¸ñÀ´ÓÕʹĿµÄÊäÈëÒøÐÐƾ֤ºÍСÎÒ˽¼ÒÐÅÏ¢¡£±ðµÄ£¬JaneleiroÊÇÓÉVisual Basic .NET±àдµÄ£¬ÕâÓë¸ÃµØÇøµÄºÚ¿ÍËùϲ»¶µÄDelphiÓкܴóµÄÊÕÖ§¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/04/experts-uncover-new-banking-trojan.html