ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ49ÖÜ
Ðû²¼Ê±¼ä 2021-12-06>±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇDell Emc Streaming Data Platform sql×¢ÈëÎó²î£»EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î£»ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î£»Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î£»Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î£»IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ£»ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ£»°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ£»KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄÔ˶¯¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Dell Emc Streaming Data Platform sql×¢ÈëÎó²î
Dell Emc Streaming Data Platform±£´æsql×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£
https://www.dell.com/support/kbdoc/zh-cn/000193697/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities
2. EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î
EFM ipTIME C200 IP CameraÓëipTIME NASͬ²½Ê±±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
http://iptime.com/iptime/?page_id=126&diffid=&dfsid=19&dftid=541
3. ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î
ohmyzsh rand-quoteºÍhitokoto²å¼þ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/ohmyzsh/ohmyzsh/commit/72928432
4. Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î
Open Solutions For Education openSIS GetStuListFnc.php±£´æsql×¢ÈëÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/OS4ED/openSIS-Classic/issues/202
5. Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î
Sunnet eHRDδ׼ȷÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´»á¼û£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£
https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢TP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î
ResecurityÑо¿Ö°Ô±TP-LinkµÄ×°±¸Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ÊÜÓ°Ïì×°±¸µÄÐͺÅΪTL-XVR1800L£¬ÊÇÆóÒµ¼¶AX1800˫ƵǧÕ×Wi-Fi 6ÎÞÏßVPN·ÓÉÆ÷¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÍêÈ«¿ØÖÆ×°±¸»òÇÔÈ¡Ãô¸ÐÊý¾Ý£¬Ëü¿ÉÄÜ»¹±£´æÓÚͳһϵÁеÄÆäËû×°±¸ÖС£ResecurityÔÚ10ÔÂÉÏÑ®·¢Ã÷ÁËÕë¶Ô¸Ã×°±¸µÄ¹¥»÷Ô˶¯£¬²¢ÓÚ11ÔÂ19ÈÕ֪ͨÁËTP-Link£¬TP-LinkÔÚµÚ¶þÌìÈ·ÈÏÁ˸ÃÎó²î²¢ÔÊÐí»áÔÚÒ»ÖÜÄÚÐû²¼²¹¶¡¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html
2¡¢IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ
IEEEÔÚ½üÆÚÐû²¼ÁËδÀ´Òªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ¡£±¨¸æÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢Öйú¡¢Ó¡¶ÈºÍ°ÍÎ÷µÄ350λCTO¡¢CIOºÍIT×ܼ࣬չÍûÁË2022Äê×îÖ÷ÒªµÄÊÖÒÕ¡¢À´ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµÒÔ¼°Î´À´Ê®ÄêµÄÊÖÒÕÇ÷ÊÆ¡£21%µÄÊÜ·ÃÕßÒÔΪÈ˹¤ÖÇÄܺͻúеѧϰ½«³ÉΪÃ÷Äê×îÖ÷ÒªµÄÊÖÒÕ£¬Æä´ÎΪÔÆÅÌËã(20%)ºÍ5G(17%)£»25%µÄÈËÒÔΪÖÆÔìÒµ»áÊÇ2022ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµ£¬Æä´ÎΪ½ðÈÚ·þÎñ(19%)¡¢Ò½ÁƱ£½¡(16%)ºÍÄÜÔ´(13%)ÐÐÒµ¡£
ÔÎÄÁ´½Ó£º
https://transmitter.ieee.org/impact-of-technology-2022/
3¡¢ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ
ÈÕ±¾¿ç¹ú¹«Ë¾ËÉÏÂPanasonicÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷£¬È·ÈÏÆ䲿·ÖÊý¾ÝÒѾй¶¡£¹¥»÷±¬·¢ÔÚ6ÔÂ22ÈÕ£¬µ«Ö±µ½11ÔÂ11Èղű»·¢Ã÷¡£¾ÓÉÄÚ²¿ÊÓ²ìÈ·¶¨£¬¹¥»÷ÕßÒÑÔÚÕâ4¸öÔÂÖлá¼ûÁË·þÎñÆ÷ÉϵIJ¿·ÖÊý¾Ý¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÆäËüÏêϸÐÅÏ¢£¬µ«ÈÕ±¾ÐÂÎÅÍøÕ¾MainichiºÍNHK±¨µÀ³Æ£¬¹¥»÷ÕßÒѾ»ñµÃÁ˹«Ë¾ÊÖÒÕ¡¢ÏàÖúͬ°é¼°¹«Ë¾Ô±¹¤µÈÏà¹ØÐÅÏ¢¡£ÔçÔÚ2020Äê11Ô£¬ËÉÏÂÓ¡¶È·Ö¹«Ë¾ÔøÒòÍøÂç¹¥»÷й¶Á˲ÆÎñµÈÏà¹ØÐÅÏ¢¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/
4¡¢°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ
2021Äê11ÔÂ23ÈÕ£¬°µÍøÊг¡CannazonµÄÖÎÀíÔ±Ðû²¼½«ÓÀÊÀ¹Ø±Õ¸ÃÍøÕ¾¡£¾ÝϤ£¬¸ÃÍøÕ¾ÔÚ11Ô³õÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷£¬ÖÎÀíԱͨ¹ýïÔ̶©µ¥ÊýÄ¿ºÍ¹Ø±Õ²¿·ÖϵͳÒÔ»º½âÎÊÌâ¡£µ«ÕâÔÚÉçÇøÖÐÒýÆðÁ˾ª¶¯£¬Óû§µ£ÐÄÕâÊÇÒ»³¡Í˳öȦÌס£ÖÎÀíÔ±ÔÚÐû²¼¹Ø±Õͨ¸æʱ£¬¹ØÓÚÕâÖÖ´¦Öóͷ£ÒªÁìÌåÏÖǸÒ⣬³ÆûÓйûÕæ¹¥»÷Ô˶¯ÊÇΪÁ˱£»¤Óû§ºÍÉçÇø£¬ÒÔ±ÜÃ⹩ӦÉÌÊÔͼ·¢¶¯¼ÓÃÜÇ®±ÒÍ˳öȦÌס£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/
5¡¢KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄÔ˶¯
KasperskyÔÚ11ÔÂ29ÈÕÅû¶³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖ³ÆScarCruft»òTemp.Reaper£©ÔÚ½üÆڵĹ¥»÷Ô˶¯¡£ScarCruft´Ó2012Äê×îÏÈ»îÔ¾£¬Ö÷ÒªÕë¶Ôº«¹úµÄ¹Ù·½»ú¹¹»ò¹«Ë¾¡£´Ë´ÎÔ˶¯×îÏÈÓÚ2021Äê8Ô£¬³õʼѬȾǰÑÔÊÇÓã²æʽ´¹ÂÚÔ˶¯£¬Ö®ºóʹÓÃIEä¯ÀÀÆ÷ÖеÄÁ½¸öÎó²îÔÚº«¹úµÄÍøÕ¾ÖÐ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þBLUELIGHT£¬Ìᳫˮ¿Ó¹¥»÷¡£Ô˶¯»¹Ê¹ÓÃÁ˶ñÒâÈí¼þChinotto£¬Ëü¾ßÓÐÕë¶ÔPowerShell¡¢WindowsºÍAndroidµÄ¶à¸ö±äÌå¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/