ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ8ÖÜ

°ä²¼¹¦·ò 2021-02-22

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ15ÈÕÖÁ02ÔÂ21ÈÕ¹²ÊÕ¼°²È«·ì϶58¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇEFM ipTIME C200 IP Camera CVE-2020-7848ºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´Ðзì϶£»£»£»£»£»£»DJI Mavic 2¹Ì¼þÉý¼¶ºÅÁî×¢Èë·ì϶£»£»£»£»£»£»McAfee Web Gateway troubleshootingÒ³ÌØÈ¨ÌáÉý·ì϶£»£»£»£»£»£»Bloodhound objectId×¢Èë·ì϶¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǼÓÄôó×â³µ¹«Ë¾Ï°È¾DarkSide£¬£¬£¬£¬£¬£¬Ð¹Â¶120GBÊý¾Ý£»£»£»£»£»£»·¨¹úºÍÎÚ¿ËÀ¼½áºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©£»£»£»£»£»£»°²×¿ÀûÓÃSHAREitÖÐ佨¸´µÄRCE·ì϶£¬£¬£¬£¬£¬£¬ÏÂÔØ³¬10ÒڴΣ»£»£»£»£»£»Cyble·¢ÏÖÀûÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹µö¹¥»÷»î¶¯£»£»£»£»£»£»Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019ÄêÆðÍ·»îÔ¾¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£


> ³ÁÒª°²È«·ì϶Áбí


1.EFM ipTIME C200 IP Camera CVE-2020-7848ºÅÁî×¢Èë·ì϶


EFM ipTIME C200 IP Camera /login.cgi?logout=1´æÔÚÊäÈë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éͨ¹ýCOOKIEÖµÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£¡£¡£

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35905


2.Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´Ðзì϶


Google Chrome Data Transfer´æÔÚÕ»Òç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³£¬£¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html


3.DJI Mavic 2¹Ì¼þÉý¼¶ºÅÁî×¢Èë·ì϶


DJI Mavic 2 Remote Controller dji_sysδ¹ýÂËÎļþÖÐÌØÊâÊôÐÔ£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Í¨¹ý¹Ì¼þÉý¼¶°üÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdf


4.McAfee Web Gateway troubleshootingÒ³ÌØÈ¨ÌáÉý·ì϶


McAfee Web Gateway troubleshootingÒ³´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿Éͨ¹ýÓû§½Ó¿ÚÖ´ÐÐËÁÒâºÅÁ£¬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£¡£

https://kc.mcafee.com/corporate/index?page=content&id=SB10349


5.Bloodhound objectId×¢Èë·ì϶


Bloodhound objectId²ÎÊý´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿É×¢Èë¶ñÒâºÅÁî²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£

https://github.com/BloodHoundAD/BloodHound/issues/338


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢¼ÓÄôó×â³µ¹«Ë¾Ï°È¾DarkSide£¬£¬£¬£¬£¬£¬Ð¹Â¶120GBÊý¾Ý


1.jpg


¼ÓÄôóµ±ÏÈµÄÆû³µºÍ¿¨³µ×âÁÞ¹«Ë¾Canadian Discount Car and Truck RentalsÊܵ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬£¬ºÚ¿ÍÐû³ÆÒÑÇÔÈ¡ÁË120GBµÄÊý¾Ý£¬£¬£¬£¬£¬£¬Ô̺¬½ðÈÚ¡¢Êг¡ÓªÏú¡¢ÒøÐÓ×¢ÕÊ»§ºÍ¼ÓÃËÉÌÊý¾Ý¡£¡£¡£¡£¡£¡£Õⳡ¹¥»÷ÖжÏÁ˸ù«Ë¾ÔÚdiscountcar.comÉϵÄÔÚÏß×âÁÞ·þÎñ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/leading-canadian-rental-car-company-hit-by-darkside-ransomware/


2¡¢·¨¹úºÍÎÚ¿ËÀ¼½áºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©


2.jpg


·¨¹úºÍÎÚ¿ËÀ¼·¨Âɲ¿ÃŵĽáºÏÐж¯¿ÛÁôÁËÎÚ¿ËÀ¼µÄEgregorÀÕË÷Èí¼þµÄ¼¸Ãû³ÉÔ±£¬£¬£¬£¬£¬£¬ÕâЩ³ÉÔ±µÄ¹¤×÷ÊÇÈëÇÖ¹«Ë¾ÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¡£¾Ý±¨Â·£¬£¬£¬£¬£¬£¬¸ÃÐж¯ÊÇÔÚÈ¥ÄêÇïÌìÊÕµ½°ÍÀèÀÕË÷Èí¼þ·¸×ïÍÅ»ïµÄͶËߺ󣬣¬£¬£¬£¬£¬ÓɰÍÀè´óÉó·¨ÔºÆô¶¯µÄ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬£¬EgregorµÄTorÍøÕ¾´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£¡£ÓÉÓÚÎÞ·¨½Ó¼ûTor¸¶¿îÕ¾µã£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÎÞ·¨ÁªÏµµ½ÀÕË÷Õߣ¬£¬£¬£¬£¬£¬Ò²ÎÞ·¨Ö§¸¶Êê½ð»òÏÂÔØ½âÃÜÆ÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/egregor-ransomware-members-arrested-by-ukrainian-french-police/


3¡¢°²×¿ÀûÓÃSHAREitÖÐ佨¸´µÄRCE·ì϶£¬£¬£¬£¬£¬£¬ÏÂÔØ³¬10ÒÚ´Î


3.png


Ò»¸ö±»ÏÂÔØ³¬¹ý 10 ÒÚ´ÎµÄ Android ÀûÓ÷¨Ê½Ô̺¬ÁË佨²¹µÄ·ì϶£¬£¬£¬£¬£¬£¬¶øÕâ¸öÔ̺¬·ì϶µÄÀûÓ÷¨Ê½µÄ½¨¸´¹¦·òÒѾ­³¬¹ýÁËÈý¸öÔ¡£¡£¡£¡£¡£¡£ÕâЩ·ì϶ӰÏìÁË Android °æ±¾µÄ SHAREit£¬£¬£¬£¬£¬£¬Ò»¸öÔÊÐíÓû§Óë°é»òÓ×ÎÒÉ豸¹²ÏíÎļþµÄÒÆ¶¯ÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£Trend MicroµÄÒÆ¶¯Íþв·ÖÎöʦEcho DuanÔÚÒ»·Ý»ã±¨ÖÐ˵£¬£¬£¬£¬£¬£¬Äܹ»ÀûÓÃÕâЩ·ì϶ÔÚ×°ÖÃÁËSHAREitÀûÓ÷¨Ê½µÄÖÇÄÜÊÖ»úÉÏÔËÐжñÒâ´úÂë ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-bugs-left-unpatched-in-android-app-with-one-billion-downloads/


4¡¢Cyble·¢ÏÖÀûÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹µö¹¥»÷»î¶¯


4.png


Íþвµý±¨¹«Ë¾CybleµÄ×êÑÐÈËÔ±·¢ÏÖÁËÕë¶Ô¶à¸öÀÄÓÃngrokƽ̨µÄ×éÖ¯µÄÐÂÒ»²¨ÍøÂç´¹µö¹¥»÷£¬£¬£¬£¬£¬£¬ngrokƽ̨ÊÇͨÍù±¾µØÖ÷»úµÄÒ»¸ö°²È«ÇÒ¿É×ÔÊ¡µÄËí·¡£¡£¡£¡£¡£¡£ngrokÊÇÒ»¸ö¿çƽ̨ÀûÓ÷¨Ê½£¬£¬£¬£¬£¬£¬ÓÃÓÚ½«±¾µØ¿ª·¢·þÎñÆ÷¹«¿ªµ½Internet£¬£¬£¬£¬£¬£¬Í¨¹ý´´½¨µ½±¾µØÖ÷»úµÄ³¤Á´½ÓTCPËí·£¬£¬£¬£¬£¬£¬¸Ã·þÎñÆ÷ËÆºõÍйÜÔÚngrokµÄ×ÓÓò£¨ÀýÈç4f421deb219c[.]ngrok[.]io£©ÉÏ¡£¡£¡£¡£¡£¡£×¨¼ÒÃÇÖ¸³ö£¬£¬£¬£¬£¬£¬ngrok·þÎñÆ÷Èí¼þÔËÐÐÔÚVPS»òרÓ÷þÎñÆ÷ÉÏ£¬£¬£¬£¬£¬£¬Äܹ»ÈƹýNATÓ³ÉäºÍ·À»ðǽÏÞ¶È¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114644/cyber-crime/ngrok-phishing-attacks.html


5¡¢Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019ÄêÆðÍ·»îÔ¾


5.png


WatchDog¼ÓÃÜÍÚ¿ó½©Ê¬ÍøÂçÓÉPalo Alto NetworksµÄÍþвµý±¨²¿ÃÅ42²¿ÃÅ·¢ÏÖ£¬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2019Äê1ÔÂÒÔÀ´Ò»Ïò»îÔ¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬WatchDogÓÉGo˵»°±àд¶ø³É¡£¡£¡£¡£¡£¡£Æ¾¾ÝUnit 42ÍŶӶÔWatchDog¶ñÒâÈí¼þµÄ·ÖÎö£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±¹À¼Æ¸Ã½©Ê¬ÍøÂçÒѹ¥»÷500µ½1000¸öÖ¸±ê¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/windows-and-linux-servers-targeted-by-new-watchdog-botnet-for-almost-two-years/