ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ14ÖÜ
°ä²¼¹¦·ò 2019-04-08±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼°²È«·ì϶45¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspËÁÒâOSºÅÁîÖ´Ðзì϶£»£»£»£»£»£»£»£»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´Ðзì϶; Fortinet FortiOS¶ÑÒç¶Âí½Å£»£»£»£»£»£»£»£»TONGDA Office Anywhere SQL×¢Èë·ì϶£»£»£»£»£»£»£»£»Advantech WebAccess/SCADAºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
D-Link DSL-3782 Acl.asp´¦ÖÃScrIPaddrEndTXT²ÎÊý´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Äܹ»Ö´ÐÐËÁÒâosºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/
2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´Ðзì϶
VMware Workstation/Fusion e1000Ðé¹¹Íø¿¨ÊµÏÖ´æÔÚÔ½½çд·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
3. Fortinet FortiOS¶ÑÒç¶Âí½Å
Fortinet FortiOS´æÔÚ¶ÑÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://fortiguard.com/psirt/FG-IR-18-388
4. TONGDA Office Anywhere SQL×¢Èë·ì϶
TONGDA Office Anywhere´æÔÚsql×¢Èë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬣¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf
5. Advantech WebAccess/SCADAºÅÁî×¢Èë·ì϶
Advantech WebAccess/SCADA´æÔÚ±í²¿ÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´Ðз¸·¨ºÅÁî¡£¡£¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01
³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢SonicWallл㱨³Æ2018ÄêIoT¹¥»÷Ôö³¤217.5£¥
ƾ¾ÝSonicWallµÄÄê¶ÈÍøÂçÍþв»ã±¨£¨2019°æ£©£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ1030Íò´ÎÔö³¤ÁË217.5£¥¡£¡£¡£¡£¡£¡£¡£ÕâÒ»Ôö³¤µÄÔÒòÊÇIoTÉ豸Ôì×÷ÉÌδÄÜÖ´ÐÐÊʵ±µÄ°²È«½ÚÔì¡£¡£¡£¡£¡£¡£¡£È«Çò³¬¹ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØÖ·Ô´ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨13%£©¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬±È2017Äê½µÂä4.1£¥¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/
2¡¢ÒøÐÐľÂíAnubis£¬£¬£¬£¬£¬£¬×Ô2017ÄêÀ´ÒÑϰȾ300¶à¼Ò½ðÈÚ»ú¹¹
AndroidÒøÐÐľÂíAnubisÖØÒªÍ¨¹ýGoogle Play Store·Ö·¢£¬£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬AnubisÒѾϰȾÁËÈ«Çò³¬¹ý300¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£¡£¡£Anubisͨ³£¼Ù×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊµÓÃÓ×¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬£¬£¬£¬£¬£¬ÆäÖØÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£¡£¡£¡£¡£¡£¡£2019Äê3Ô£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67
3¡¢×êÑÐÈËÔ±·¢ÏÖ³¬¹ý2.6Íò¸öKibanaÊ·ýÔÚÍøÉ϶³ö
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html
4¡¢Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/
5¡¢JS-SnifferϰȾȫÇò2440¸öÍøÕ¾£¬£¬£¬£¬£¬£¬ÖØÒªÇÔÊØÐÅÓþ¿¨ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html


¾©¹«Íø°²±¸11010802024551ºÅ