ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ10ÖÜ
°ä²¼¹¦·ò 2020-03-10> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼°²È«·ì϶52¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´Ðзì϶; Rubetek SmartHome²¨¶ÎÉè¼Æ·ì϶£»£»£»£»£»£»£»£»Envoy²»ÕýÈ·½Ó¼û½ÚÔì·ì϶£»£»£»£»£»£»£»£»Qualcomm MDM9206 WLAN»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»Google Chrome media°²È«Èƹý·ì϶¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»£»£»£»£»£»£»£»Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Ê飻£»£»£»£»£»£»£»CrowdStrike°ä²¼¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·£»£»£»£»£»£»£»£»Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿î£»£»£»£»£»£»£»£»°Ä´óÀûÑÇACSC°ä²¼CMSϵͳ°²È«Ö¸ÄÏ¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£
>³ÁÒª°²È«·ì϶Áбí
1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´Ðзì϶
FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ´æÔÚºÚÃûµ¥Èƹý·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://github.com/FasterXML/jackson-databind/issues/2631
2. Rubetek SmartHome²¨¶ÎÉè¼Æ·ì϶
Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î½øÐÐͨѶ£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£
https://pastebin.com/CckKKJcM
3. Envoy²»ÕýÈ·½Ó¼û½ÚÔì·ì϶
EnvoyʹÓÃSDS´æÔÚ²»ÕýÈ·½Ó¼û½ÚÔì·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉδÊÚȨ½Ó¼ûÊÜÏÞ×ÊÔ´¡£¡£¡£¡£¡£
https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
4. Qualcomm MDM9206 WLAN»º³åÇøÒç¶Âí½Å
Qualcomm MDM9206 WLAN´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É½øÐлؾø·þÎñ¹¥»÷»ò¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£
https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin
5. Google Chrome media°²È«Èƹý·ì϶
Google Chrome media´¦Öð²È«Õ½Êõ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉÈÆ¹ý°²È«ÏÞ¶È£¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼û¡£¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶
TeslaºÍSpaceXµÄÁã¼þÔì×÷ÉÌVisserÈ·ÈÏÔâ·êÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼Æ¾«ÃÜÁã¼þµÄÔì×÷ÉÌ¡£¡£¡£¡£¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉêÃ÷ÖУ¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂ簲ȫ·¸×ïÊÂÎñ£¨Ô̺¬½Ó¼ûºÍ͵ÇÔÊý¾Ý£©µÄÖ¸±ê¡±¡£¡£¡£¡£¡£¸Ã¹«Ë¾½²»°È˰µÊ¾½«¡°³ÖÐø¶Ô¸Ã¹¥»÷½øÐÐÈ«Ãæµ÷²é£¬£¬£¬£¬£¬²¢ÇÒÒµÎñÔËÐÐÕý³£¡±¡£¡£¡£¡£¡£TechCrunch×êÑÐÈËÔ±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/03/01/visser-breach/
2¡¢4Let's Encrypt³·»Ø³¬¹ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢ÏÖÁËÒ»¸öbug£¬£¬£¬£¬£¬Let's EncryptÏîÄ¿´òËã´ÓÊÀ½ç±ê¶¨¹¦·ò2020Äê3ÔÂ4ÈÕ00:00ÆðÍ·³·Ïú³¬¹ý300Íò¸öTLSÖ¤Êé¡£¡£¡£¡£¡£¾ßÌåÀ´Ëµ£¬£¬£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬£¬£¬£¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤ÊéÐû¸æ»ú¹¹ÊÚȨ£©¹æ·¶µÄÖ´ÐУ¬£¬£¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÒªÇóÔ̺¬N¸ö±ØÒª½øÐÐCAA³Áв鳵ÄÓòÃûʱ£¬£¬£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢²é³N´Î¡£¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚ¹¦·òXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚ¹¦·òXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬£¬£¬£¬Ôò¸ÃÓû§Äܹ»ÔÚX+30ÌìµÄ¹¦·òÀ￯ÐÐÔ̺¬¸ÃÓòÃûµÄÖ¤Ê飬£¬£¬£¬£¬¼´±ãÖ®ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁ˲»ÈÝLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£¡£¡£ÔÚÕâ300Íò¸ö³·ÏúµÄÖ¤ÊéÖУ¬£¬£¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄ³Á¸´Ï£¬£¬£¬£¬Òò¶øÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýÁ¿Ô¼Îª200Íò¸ö¡£¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÀûÓ÷¨Ê½ÖеÄÃýÎ󣬣¬£¬£¬£¬ÓòÃûËùÓÐÕß½«±Ø±ØÒªÇóеÄTLSÖ¤Êé²¢´úÌæ¾ÉµÄTLSÖ¤Êé¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
3¡¢CrowdStrike°ä²¼¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв»ã±¨¡·¶Ô´ÓǰһÄêÖж¥¼¶ÍøÂçÍþвÇ÷Ïò½øÐÐÁËÉî¿Ì·ÖÎö£¬£¬£¬£¬£¬¸Ã»ã±¨µÄÖØµãÔ̺¬£º´óÐ͹¥»÷»î¶¯£¨BGH£©²»ÐÝÉý¼¶£¬£¬£¬£¬£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬£¬£¬£¬£¬²¢ÇÒÔì³É¼«´óµÄ·ÛË飻£»£»£»£»£»£»£»ÍøÂç·¸×ï·Ö×ÓÔÚʹÃô¸ÐÊý¾Ý±øÆ÷»¯£¬£¬£¬£¬£¬ÒÔÔö³¤¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»£»£»£»£»£»eCrimeÉú̬ϵͳ²»ÐÝ·¢Õ¹£¬£¬£¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½²»ÐÝÌá¸ß£»£»£»£»£»£»£»£»ÔÚBGHÖ®±í£¬£¬£¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔö³¤£»£»£»£»£»£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÊõµÄÇ÷ÏòÔڼӿ죻£»£»£»£»£»£»£»¹ú¶ÈÔÞÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ³ÖÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùµý±¨£¬£¬£¬£¬£¬ÍƽøÉçÇøÄÚ²¿µÄ¸îÁÑ£¬£¬£¬£¬£¬²¢¹Û²ìµ½ÁËÓëÏȽøeCrime¹¥»÷ÕߵĺÏ×÷¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
4¡¢Ó¢¹úÊý¾Ý¼à¹Ü»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940Íò³Ë¿ÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ²úÉúÔÚ2018Äê3Ô·ݣ¬£¬£¬£¬£¬²¢ÓÚ5Ô·ݵõ½È·ÈÏ£¬£¬£¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£¡£ICOµ÷²é³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬£¬£¬²¢·¢ÏÖ¹úÌ©ÔÚ°²È«ÐÔ·½ÃæµÄһЩ²»¼°£¬£¬£¬£¬£¬Ô̺¬²»ÊÜÃÜÂë±£»£»£»£»£»£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýÆÚµÄ²Ù×÷ϵͳºÍ²»×ã·À²¡¶¾±£»£»£»£»£»£»£»£»¤µÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5¡¢°Ä´óÀûÑÇACSC°ä²¼CMSϵͳ°²È«Ö¸ÄÏ
°Ä´óÀûÑÇÍøÂ簲ȫÖÐÐÄ£¨ACSC£©°ä²¼Ò»·ÝÓÃÓÚ±£»£»£»£»£»£»£»£»¤CMSϵͳµÄÍøÂ簲ȫָÄÏ£¬£¬£¬£¬£¬¸ÃÖ¸ÄϸÅÊöÁËÈôºÎÔÚweb·þÎñÆ÷Éϼø±ðºÍ×îÓ×»¯Ç±ÔÚ·çÏÕµÄÕ½Êõ£¬£¬£¬£¬£¬ÆäÖ¸±êÊܶàÊÇÕÆ¹ÜʹÓÃCMS¿ª·¢ºÍ±£»£»£»£»£»£»£»£»¤ÍøÕ¾»òWebÀûÓ÷¨Ê½µÄÈË¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Ê¹ÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵݲȫ·ì϶¡£¡£¡£¡£¡£Ò»µ©CMS±»ÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓÃÆäȨÏÞÀ´£º»ñµÃWebÀûÓ÷¨Ê½µÄÑéÖ¤ÇøÓòºÍÌØÈ¨ÇøÓòµÄ½Ó¼ûȨÏÞ£»£»£»£»£»£»£»£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì½Ó¼û£¬£¬£¬£¬£¬ÀýÈçÉÏ´«Web Shell»òRAT£»£»£»£»£»£»£»£»ÔںϷ¨ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¡£¹¥»÷Õß»¹Äܹ»½«ÊÜϰȾµÄWeb·þÎñÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿ÃÅ£¬£¬£¬£¬£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£¡£ACSC½¨Òé²ÉÈ¡µÄ»º½â´ëÊ©Ô̺¬£ºÊ¹ÓÃCMSÍйܷþÎñ£»£»£»£»£»£»£»£»ÓÅÁ¼µÄ²¹¶¡ÖÎÀí£»£»£»£»£»£»£»£»·ì϶ÆÀ¹À£»£»£»£»£»£»£»£»ÕË»§ÖÎÀí£»£»£»£»£»£»£»£»¼ÓÇ¿CMS×°ÖõݲȫÐÔ½ÚÔì´ëÊ©£»£»£»£»£»£»£»£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyber.gov.au/publications/securing-content-management-systems


¾©¹«Íø°²±¸11010802024551ºÅ