Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢ £»£»£»£»£»£»£»2.6Íò¸öKibanaÊ·ý £»£»£»£»£»£»£»1.35Íò¸öiSCSI´æ´¢¼¯Èº

°ä²¼¹¦·ò 2019-04-03
1.×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö¡£¡£¡£¡£¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄ·ÖÎöºÍ¿ÉÊÓ»¯Æ½Ì¨£¬£¬ £¬£¬£¬£¬Ö¼ÔÚʵʱ³½ÎöElasticsearchÊý¾Ý¿âÖеÄÊý¾Ý¡£¡£¡£¡£¡£´óÎÞÊý¶³öµÄÊ·ý¶¼Ã»ÓÐÊܵ½± £»£»£»£»£»£»£»¤£¬£¬ £¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§½Ó¼ûÒDZíÅÌ¡£¡£¡£¡£¡£ÕâЩÊ·ýÊôÓÚµç×Ó½ø½¨Æ½Ì¨¡¢ÒøÐÐϵͳ¡¢Í£³µÖÎÀíϵͳ¡¢Ò½ÔººÍ´óѧµÈ´óÐÍ»ú¹¹£¬£¬ £¬£¬£¬£¬ÃÀ¹ú£¨8311¸ö£©ÊǶ³öÊ·ý×î¶àµÄ¹ú¶È£¬£¬ £¬£¬£¬£¬Æä´ÎÊÇÖйú£¨7282£©¡¢µÂ¹ú£¨1709£©ºÍ·¨¹ú£¨1152£©¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬ºÜ¶àÊ·ý¶¼ÔËÐйýÆÚµÄÈí¼þ°æ±¾£¨´æÔÚËÁÒâÎļþÔ̺¬·ì϶£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/04/kibana-data-security.html

2.³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÈËÔ±A Shadow·¢ÏÖ³¬¹ý1.35Íò¸öiSCSI´æ´¢¼¯ÈºÒòÅäÖÃÃýÎóÔÚÍøÉ϶³ö¡£¡£¡£¡£¡£ÕâЩ¼¯ÈºÒòδÆôÓÃÉí·ÝÑéÖ¤£¬£¬ £¬£¬£¬£¬µ¼Ö·¸×ï·Ö×ÓÄܹ»Í¨¹ý»¥ÁªÍø½Ó¼ûÕâЩ´ÅÅÌÕóÁкÍNASÉ豸£¬£¬ £¬£¬£¬£¬Ê¹µÃÆóÒµµÄÃô¸ÐÊý¾ÝÃæ¶Ô·çÏÕ¡£¡£¡£¡£¡£ÕâЩiSCSI¼¯ÈºÊôÓÚ˽Ӫ¹«Ë¾¡¢µ±¾Ö»ú¹¹¡¢´óѧºÍ×êÑлú¹¹µÈ£¬£¬ £¬£¬£¬£¬ÊÇÍøÂç·¸×OÍŵÄÃÎÏë¹¥»÷Ö¸±ê¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-13k-iscsi-storage-clusters-left-exposed-online-without-a-password/

3.ŦԼÊ׸®°Â¶û°ÍÄáÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ËðʧÈÔÔÚÆÀ¹ÀÖÐ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

ÃÀ¹úŦԼÖÝÊ׸®°Â¶û°ÍÄáÊÐÓÚ3ÔÂ30ÈÕÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬µ±Ç°ÈÔ²»Ã÷ÏÔÆäÍÆËã»úϵͳµÄÊÜËðˮƽ£¬£¬ £¬£¬£¬£¬µ«Æ¾¾Ý¸ÃÊйÙÍø°ä²¼µÄÐÂΟ壬£¬ £¬£¬£¬£¬ËùÓеijÇÊзþÎñ¶¼ÒÑ¿ÉÓ㬣¬ £¬£¬£¬£¬µ«µ®ÉúÖ¤Ã÷¡¢éæÃüÖ¤Ã÷ºÍ³É»éÖ¤Êé·þÎñÖ®±í¡£¡£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅú×¢Ó×ÎÒÊý¾ÝÊÜË𣬣¬ £¬£¬£¬£¬µ«³ÇÊеÄн×Ê·þÎñÊܵ½Ó°Ï죬£¬ £¬£¬£¬£¬²»ÄÜÈ·¶¨¸ÃÊÐÊÇ·ñ»áÖ§¸¶Êê½ð¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/

4.Ó¡¶Èµ±¾Ö»ú¹¹Òâ±íй¶1250Íò»³ÔÐÅ®ÐÔµÄÒ½ÁÆÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


3Ô³õSecurity DiscoveryµÄ°²È«×êÑÐÔ±Bob Diachenko·¢ÏÖÓ¡¶È±±²¿Ò»¸öÖÝÈ·µ±¾ÖÒ½ÁƲ¿ÃÅÒâ±íй¶³¬¹ý1250Íò·ÝÔи¾µÄÒ½ÁƼͼ£¬£¬ £¬£¬£¬£¬ÕâЩ¼Í¼Ô̺¬ÐÕÃû¡¢µØÖ·¡¢´ºÇï¡¢µç»°¡¢Õï¶ÏºÍ¼²²¡ÐÅÏ¢¡¢»³Ì¥Çé¿ö¡¢»³Ì¥²¢·¢Ö¢¡¢USG/ÑòĤ´©´Ì/»ùÒò¼ì²âÐÅÏ¢¡¢º¢×ӵĸ¸Ç×ÐÕÃûµÈ¡£¡£¡£¡£¡£ÕâЩ¼Í¼×îÔç¿É×·ÒäÖÁ2014Äê¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÔÚδÉèÃÜÂëµÄÇé¿öÏÂÏνӵ½»¥ÁªÍø£¬£¬ £¬£¬£¬£¬²¢ÔÚÍøÂçÉ϶³öÁ˳¬¹ý3ÖܵŦ·ò¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/indian-govt-agency-left-details-of-millions-of-pregnant-women-exposed-online/

5¡£¡£¡£¡£¡£Google°ä²¼4ÔÂAndroid°²È«¸üУ¬£¬ £¬£¬£¬£¬½¨¸´¶à¸ö·ì϶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Google°ä²¼4ÔÂAndroid°²È«¸üУ¬£¬ £¬£¬£¬£¬ÔÚ°²È«²¹¶¡¼¶±ð2019-04-01ÖУ¬£¬ £¬£¬£¬£¬Google½¨¸´ÁËÁ½¸ö¸ßΣRCE·ì϶ºÍ9¸öÌáȨ£¨EoP£©¼°ÐÅϢй¶£¨ID£©·ì϶¡£¡£¡£¡£¡£ÕâÁ½¸öRCE·ì϶ÊÇýÌå¿ò¼Ü×é¼þÖеķì϶£¨CVE-2019-2027ºÍCVE-2019-2028£©£¬£¬ £¬£¬£¬£¬¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬Android 7.0¼°Ö®ºóµÄ°æ±¾¶¼ÊÜÓ°Ïì¡£¡£¡£¡£¡£ÁíÒ»¸ö°²È«²¹¶¡¼¶±ðÊÇ2019-04-05£¬£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖÃÕâЩ¸üС£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-fixes-two-critical-android-code-execution-vulnerabilities/

6.Apache°ä²¼Ð°汾2.4.39£¬£¬ £¬£¬£¬£¬½¨¸´¶à¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Apache HTTP Server 2.4.39Öн¨¸´Á˶à¸ö°²È«·ì϶£¬£¬ £¬£¬£¬£¬×îΪÑϳÁµÄ·ì϶ÊÇÌáȨ·ì϶£¨CVE-2019-0211£©£¬£¬ £¬£¬£¬£¬¸Ã·ì϶ӰÏìÁË2.4.17µ½2.4.38Ö®¼äµÄËùÓа汾£¬£¬ £¬£¬£¬£¬ÔÊÐíÓµÓо籾дÈëºÍÔËÐÐȨÏÞµÄÓû§»ñµÃrootȨÏÞ²¢Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬¸Ã°æ±¾»¹½¨¸´Á˽Ӽû½ÚÔìÈÆ¹ý·ì϶£¨CVE-2019-0217ºÍCVE-2019-0215£©¡¢¿ÉÄܵ¼Ö±ÀÀ£µÄ·ì϶£¨CVE-2019-0197£©¡¢read-after-free·ì϶£¨CVE-2019-0196£©ºÍURL¹æ·¶»¯²»Ò»Ö·ì϶£¨CVE-2019-0220£©¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/apache-bug-lets-normal-users-gain-root-access-via-scripts/