ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ41ÖÜ

Ðû²¼Ê±¼ä 2021-10-11

>±¾ÖÜÇ徲̬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache HTTP Server HTTP/2ÆÊÎö¿ÕÖ¸ÕëÒýÓþܾø·þÎñÎó²î £»Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐÐÎó²î £»Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐÐÎó²î £»Visual Tools DVR VX cgi-bin/slogin/login.pyÏÂÁîÖ´ÐÐÎó²î; Google chrome Safe BrowsingÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓÉÓÚFirebaseÉèÖùýʧ14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢ £»Facebook·ÓÉÉèÖùýʧµ¼ÖÂÈ«Çò¹æÄ£ÄÚ·þÎñÖÐÖ¹ £»Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÉèÖùýʧй¶10TBÊý¾Ý £»TwitchÒò·þÎñÆ÷ÉèÖùýʧй¶125GBÔ´´úÂëµÈÐÅÏ¢ £»Cyberint·¢Ã÷VidarʹÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷Ô˶¯¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache HTTP Server HTTP/2ÆÊÎö¿ÕÖ¸ÕëÒýÓþܾø·þÎñÎó²î


Apache HTTP Server±£´æĿ¼±éÀúÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉó²éϵͳÎļþÄÚÈÝ»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£


https://httpd.apache.org/security/vulnerabilities_24.html


2. Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐÐÎó²î


Zoho ManageEngine ADManager Plus±£´æí§ÒâÎļþÉÏ´«Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÉÏ´«¶ñÒâÎļþ£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£


https://www.manageengine.com/products/ad-manager/release-notes.html#7111


3. Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐÐÎó²î


Google Android¿ò¼Ü±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂ룬ÌáÉýȨÏÞ¡£


https://source.android.com/security/bulletin/2021-10-01


4. Visual Tools DVR VX cgi-bin/slogin/login.pyÏÂÁîÖ´ÐÐÎó²î


Visual Tools DVR VX16  cgi-bin/slogin/login.py Uaer-Agent HTTP´¦Öóͷ£±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§Òâ´úÂë¡£


https://www.exploit-db.com/exploits/50098


5. Google chrome Safe BrowsingÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î


Google chrome Safe Browsing±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë»òÕßʹӦÓóÌÐòÍ߽⡣


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html


 >Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÓÉÓÚFirebaseÉèÖùýʧ14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢


9ÔÂ30ÈÕ£¬ CyberNews Ñо¿Ô± Martynas Vareikis Ðû²¼±¨¸æ³Æ£¬ÓÉÓÚ Firebase Êý¾Ý¿âÉèÖùýʧ£¬µ¼ÖÂÊýÒÔǧ¼ÆµÄ iOS / Android Ó¦ÓóÌÐòй¶ÁËÁè¼Ý1.4ÒÚÌõÐÅÏ¢¡£Firebase ÊÇ Google ÌṩµÄ¡°ºó¶Ë¼´·þÎñ¡±²úÆ·£¬ÆäÖаüÀ¨ÁË´ó×Ú·¢·þÎñ£¬Ö¼ÔÚÀû±ãÒƶ¯¿ª·¢Ö°Ô±½¨Éè»ùÓÚÕâЩ·þÎñµÄÒƶ¯»ò Web Ó¦Óá£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/security/research-popular-android-apps-with-142-5-million-collective-downloads-are-leaking-user-data/


2¡¢Facebook·ÓÉÉèÖùýʧµ¼ÖÂÈ«Çò¹æÄ£ÄÚ·þÎñÖÐÖ¹


10ÔÂ4ÈÕ£¬FacebookÆì϶à¸öƽ̨ºÍ·þÎñ£¬°üÀ¨ Facebook¡¢Instagram¡¢MessengerºÍ WhatsAppµÈ£¬Ïà¼Ì·ºÆðÑÏÖØ·þÎñÖÐÖ¹¡£Óû§ÎÞ·¨µÇÈë³ÌÐò£¬³ÌÐòÎÞ·¨Áª»úºÍ¸üУ¬Ã»·¨ÊÕ·¢ÐÅÏ¢£¬¾ÍÁ¬ÒÔ FacebookÕ˺ŵÇÈëµÄ³ÌÐòºÍ·þÎñÒàÊܵ½Ç£Á¬£¬²»¿ÉÕý³£µÇÈë¡£FacebookØʺó·¢ÉùÃ÷Ö¸£¬ÄÚ²¿Â·ÓÉÆ÷·ºÆðÎÊÌ⣬Á¬Ëø·´Ó¦µ¼Ö·þÎñÖÜÈ«ÖÐÖ¹£¬ËäÈ»·þÎñÒѻظ´£¬µ«ÄÚ²¿ÈÔÔÚÈ«Á¦¸ÄÉÆϵͳ£¬ÒԻظ´Õý³£ÊÂÇé״̬¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/facebook-outage-caused-by-faulty-routing-configuration-changes/


3¡¢Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÉèÖùýʧй¶10TBÊý¾Ý


10ÔÂ6ÈÕ£¬Ñо¿Ô± Bob Diachenko ·¢Ã÷ÁËÒ»¸öÊôÓÚÓ¢¹ú±¨Ö½¡°µçѶ±¨¡±µÄδÊܱ £»¤µÄ 10 TB Êý¾Ý¿â¡£²»Çå¾²µÄÊý¾Ý¿âÓÚ9 Ô 14 ÈÕ±»·¢Ã÷£¬ÆäÖаüÀ¨ÄÚ²¿ÈÕÖ¾ºÍ¶©ÔÄÕßÐÅÏ¢¡£Êý¾Ý´æ´¢ÔÚ̻¶µÄ Elasticsearch ¼¯ÈºÉÏ£¬´ó²¿·ÖÊý¾Ý¶¼¾­ÓɼÓÃÜ£¬µ«ÖÁÉÙ 1,200 Ãû Telegraph ¶©ÔÄÕߺÍ×¢²áÕßµÄСÎÒ˽¼ÒÏêϸÐÅÏ¢ÒÔ¼°´ó×ÚÄÚ²¿·þÎñÆ÷ÈÕÖ¾¶¼ÒѾ­ÓÉÃ÷È·²âÊÔ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123020/data-breach/the-telegraph-data-leak.html


4¡¢TwitchÒò·þÎñÆ÷ÉèÖùýʧй¶125GBÔ´´úÂëµÈÐÅÏ¢


10ÔÂ6ÈÕ£¬ºÚ¿ÍÔÚ4chan¹ûÕæÁË°üÀ¨125GBÊý¾ÝµÄtorrentÁ´½Ó£¬³ÆÕâÊÇ´ÓԼĪ6000¸öÄÚ²¿Twitch Git´æ´¢¿âÖÐÇÔÈ¡µÄ£¬°üÀ¨Ô´´úÂëºÍÖ§¸¶¼Í¼µÈÐÅÏ¢¡£±ðµÄ£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˱êÇ©#DoBetterTwitch£¬Ö¤Êµ´Ë´Î¹¥»÷ÊÂÎñ¿ÉÄÜÖ¼ÔÚÕë¶ÔTwitch 8Ô·ÝûÓлØÓ¦ºÍµÖÓù¶ÔÖ÷²¥µÄ¹¥»÷Ô˶¯¡£TwitchÔÚ10ÔÂ7ÈÕÈ·ÈÏÆäÊý¾Ýй¶ÊÇÓÉÓÚ·þÎñÆ÷ÉèÖùýʧµ¼ÖµÄ£¬Ã»ÓеǼƾ֤ºÍÐÅÓÿ¨ºÅй¶¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/twitch-no-credentials-or-card-numbers-exposed-in-data-breach/


5¡¢Cyberint·¢Ã÷VidarʹÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷Ô˶¯


Cyberint·¢Ã÷¶ñÒâÈí¼þVidarÔÚÐÂÒ»ÂÖ¹¥»÷Ô˶¯Öлعé¡£Vidar×Ô2018Äê10ÔÂÒÔÀ´×îÏÈ»îÔ¾£¬Ö¼ÔÚ´ÓÄ¿µÄϵͳÖÐÇÔÈ¡µç×ÓÓʼþƾ֤¡¢Ì¸ÌìÕÊ»§ÏêϸÐÅÏ¢¡¢cookieµÈÊý¾Ý¡£´Ë´ÎÔ˶¯ÖУ¬¹¥»÷ÕßÊ×ÏȽ¨ÉèMastodonÕ˺Å£¬²¢ÔÚСÎÒ˽¼Ò×ÊÁÏÐÎò²¿·ÖÌí¼Ó¶ñÒâÈí¼þʹÓõÄC2µÄIP¡£Æ仹ʹÓÃÁËÁíÒ»ÖÖ·Ö·¢ÒªÁ죬ֱ½ÓÔÚÉ罻ýÌåƽ̨ÉÏ·¢ËÍÐÂÎÅ£¬»òÕßÊÇʹÓÃÆƽâÓÎÏ·µÄtorrent¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2-configuration/