ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ48ÖÜ
Ðû²¼Ê±¼ä 2021-11-29>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î50¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDell Networking X-Series firmwareÑéÖ¤ÈƹýÎó²î£»D-Link DWR-932C E1 debug_fcgi OSÏÂÁî×¢ÈëÎó²î£»Commvault CommCell AppStudioUploadHandlerí§ÒâÎļþÉÏ´«Îó²î£»HejHome GKW-IC052 IP CameraÓ²±àÂëÎó²î£»QNAP QVR²»×¼È·ÑéÖ¤Îó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇRedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿µÄÉæ¼°¸÷Ðи÷Òµ£»LinuxºóÃÅlinux_avp¿ÉÈƹýµçÉÌƽ̨µÄÇå¾²¼ì²â£»CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î£»AppGalleryÖжà¿îÓÎÏ·Ó¦Óñ£´æľÂí£¬ÒÑѬȾ900¶àÍò×°±¸£»KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©ÆÔ˶¯µÄÆÊÎö±¨¸æ¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Dell Networking X-Series firmwareÑéÖ¤ÈƹýÎó²î
Dell Networking X-Series firmware±£´æÑéÖ¤ÈƹýÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉЮÖƻỰ£¬Í¨¹ýαÔì»á»°id»á¼ûweb·þÎñÆ÷¡£
https://www.dell.com/support/kbdoc/en-us/000193230/dsa-2021-191-dell-networking-x-series-security-update-for-multiple-security-vulnerabilities
2. D-Link DWR-932C E1 debug_fcgi OSÏÂÁî×¢ÈëÎó²î
D-Link DWR-932C E1 debug_fcgi±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://supportannouncement.us.dlink.com/announcement/publication.aspx?name=SAP10246
3. Commvault CommCell AppStudioUploadHandlerí§ÒâÎļþÉÏ´«Îó²î
Commvault CommCell AppStudioUploadHandlerÀà±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉÏ´«Îļþ²¢Ö´ÐС£
https://www.zerodayinitiative.com/advisories/ZDI-21-1332/
4. HejHome GKW-IC052 IP CameraÓ²±àÂëÎó²î
HejHome GKW-IC052 IP Camera±£´æÓ²±àÂëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɿØÖÆϵͳδÊÚȨ¾ÙÐвÙ×÷¡£
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36359
5. QNAP QVR²»×¼È·ÑéÖ¤Îó²î
NAP QVR±£´æ²»×¼È·ÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼ûϵͳ¡£
https://www.qnap.com.cn/en/security-advisory/qsa-21-52
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢RedCurlÍÅ»ï»Ø¹é£¬ÐµĹ¥»÷Ä¿µÄÉæ¼°¸÷Ðи÷Òµ
Group-IBÔÚ11ÔÂ18ÈÕÅû¶Á˺ڿÍÍÅ»ïRedCurlµÄÐÂÔ˶¯¡£ÍøÂçÌع¤ºÚ¿Í×éÖ¯RedCurlÔÚ2018ÄêÖÁ2020Äêʱ´ú£¬ÌᳫÁËÖÁÉÙ26´Î¹¥»÷£¬Éæ¼°Ó¢¹ú¡¢µÂ¹ú¡¢¼ÓÄôó¡¢Å²Íþ¡¢¶íÂÞ˹ºÍÎÚ¿ËÀ¼µÈµØÇøµÄÐÞ½¨¡¢½ðÈÚ¡¢×Éѯ¡¢ÁãÊÛ¡¢°ü¹ÜºÍÖ´·¨ÐÐÒµµÄ¹«Ë¾¡£¸ÃÍÅ»ïÔÚÖÐÖ¹7¸öÔºó¾íÍÁÖØÀ´£¬×Ô2021ÄêÍ·ÒÔÀ´Õë¶Ô4¼Ò¹«Ë¾ÌᳫÁËÐµĹ¥»÷£¬ÆäÖаüÀ¨¶íÂÞ˹×î´óµÄÅú·¢ÊÐËÁ¡£Group-IB³Æ£¬RedCurlÔÚÿ´Î¹¥»÷Öж¼»áʹÓÃÆä×Ô½ç˵¶ñÒâÈí¼þÈƹý¼ì²â¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/red-curl-threat-report/
2¡¢LinuxºóÃÅlinux_avp¿ÉÈƹýµçÉÌƽ̨µÄÇå¾²¼ì²â
SansecÍþвÑо¿ÍŶÓÔÚ11ÔÂ18µÄ×îÐÂÑо¿·¢Ã÷ÁËLinuxºóÃÅlinux_avp¡£Ñо¿Ö°Ô±³Æ£¬¹¥»÷ÕßÔÚµçÉÌÍøÕ¾×¢ÈëÐÅÓÿ¨ÇÔÈ¡Æ÷ºó£¬»¹»áÔÚ±»ÈëÇֵķþÎñÆ÷ÉÏ×°ÖÃLinuxºóÃÅ¡£linux_avpÒ»µ©Æô¶¯£¬¾ÍÁ¬Ã¦½«×Ô¼º´Ó´ÅÅÌÖÐɾ³ý£¬Î±×°³Éps -efÀú³Ì£¬ÓÃÓÚ»ñÈ¡Ä¿½ñÕýÔÚÔËÐеÄÀú³ÌÁÐ±í²¢Èƹý¼ì²â¡£¸ÃÑù±¾ÓÚ10ÔÂ8ÈÕÊ×´ÎÉÏ´«£¬ÏÖÔÚVirusTotalµÄ·´¶ñÒâÈí¼þÒýÇæÈÔδ¼ì²âµ½Ëü¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hackers-deploy-linux-malware-web-skimmer-on-e-commerce-servers/
3¡¢CloudLinuxÐÞ¸´Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î
Cisco TaloÔÚ11ÔÂ22ÈÕÅû¶ÁËCloudLinuxµÄ²úÆ·Imunify360ÖеÄPHP·´ÐòÁл¯Îó²î¡£¸Ã²úÆ·ÊÇ»ùÓÚLinuxµÄWeb·þÎñÆ÷µÄÇ徲ƽ̨£¬Óû§¿ÉʹÓÃÆäͨ¹ýÖÖÖÖÉèÖÃÀ´ÊµÊ±ÑÚ»¤ÍøÕ¾ºÍWeb·þÎñÆ÷µÄÇå¾²¡£¸ÃÎó²î(CVE-2021-21956)CVSSÆÀ·ÖΪ8.2£¬±£´æÓÚAi-Bolit¹¦Ð§ÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ý¸ÃÎó²îÔÚÄ¿µÄϵͳÖÐÖ´ÐÐí§Òâ´úÂ룬»òÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ÏÖÔÚ£¬CloudLinuxÒÑÐÞ¸´¸ÃÎó²î¡£
ÔÎÄÁ´½Ó£º
https://blog.talosintelligence.com/2021/11/vulnerability-spotlight-php-deserialize.html
4¡¢AppGalleryÖжà¿îÓÎÏ·Ó¦Óñ£´æľÂí£¬ÒÑѬȾ900¶àÍò×°±¸
11ÔÂ23ÈÕ£¬Dr. WebµÄÑо¿Ö°Ô±Åû¶»ªÎªÓ¦ÓÃÊÐËÁAppGalleryÖеÄ190¿îÓÎÏ·Öб£´æľÂíAndroid.Cynos.7.origin£¬ÒÑ×°ÖÃÔ¼9300000´Î¡£¸ÃľÂíÊǶñÒâÈí¼þCynosµÄ±äÌ壬ּÔÚÍøÂçÓû§µÄÐÅÏ¢¡£ÕâЩÓÎÏ·Ö÷ҪʹÓöíÓï¡¢ÖÐÎĺÍÓ¢ÓÆäÖÐÓÎÏ·¡°¿ìµã¶ãÆðÀ´¡±µÄÏÂÔØÁ¿¸ß´ï2000000´Î¡£Ñо¿Ö°Ô±³Æ£¬¸ÃľÂí¿É·¢ËͺÍ×èµ²¶ÌÐÅ¡¢ÏÂÔغÍÆô¶¯ÆäËüÄ£¿é£¬ÒÔ¼°ÏÂÔغÍ×°ÖÃÆäËûÓ¦Óá£ÏÖÔÚ£¬»ªÎª¹«Ë¾Òѽ«ÕâЩÓÎϷϼܡ£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/124927/malware/android-cynos-7-origin-trojan-infections.html
5¡¢KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©ÆÔ˶¯µÄÆÊÎö±¨¸æ
11ÔÂ22ÈÕ£¬KasperskyÐû²¼2021ÄêºÚÎåʱ´úÕ©ÆÔ˶¯µÄÆÊÎö±¨¸æ¡£±¨¸æÖ÷ÒªÆÊÎöÁËÓëÈ«Çò»á¼ûÁ¿×î´óµÄÎå¸öÁãÊÛƽ̨£ºÎÖ¶ûÂê¡¢eBay¡¢ÑÇÂíÑ·¡¢°¢Àï°Í°ÍºÍ Mercado Libre¡£Ñо¿·¢Ã÷£¬2021ÄêÇ°10¸öÔ¼ì²âµ½40584415ÆðÕë¶ÔµçÉÌƽ̨ÒÔ¼°ÒøÐлú¹¹µÄ´¹ÂÚ¹¥»÷£»Õë¶Ôµç×ÓÖ§¸¶ÏµÍ³µÄ´¹ÂÚÔ˶¯ÔöÌíÁË208%£»10ÔÂ27ÈÕÖÁ11ÔÂ19ÈÕ·¢Ã÷ÁË221745·âÓëºÚÎåÓйصÄÓʼþ¡£±¨¸æÖ¸³ö£¬ÐþÉ«ÐÇÆÚÎå²»µ«¶Ô¹ºÎïÕßÀ´ËµÊÇÖ÷ÒªµÄÒ»Ì죬¶Ô¹¥»÷ÕßÀ´ËµÒ²ÊÇÔÆÔÆ¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/black-friday-2021/104915/