΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©£»£»£»£»£»Å·ÖÞµçÁ¦ÔËÓªÉÌÁªÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ

°ä²¼¹¦·ò 2020-03-11

1.΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©£¬£¬£¬£¬£¬ÉÐÎÞ½¨¸´²¹¶¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢ÈíSMBv3È䳿¼¶0day£¨CVE-2020-0796£©µÄÐÅÏ¢ÔÚÍøÉÏÒâ±íй¶£¬£¬£¬£¬£¬Ä¿Ç°ÉÐδ°ä²¼¸Ã·ì϶µÄÈκμ¼Êõϸ½Ú£¬£¬£¬£¬£¬µ«Cisco TalosºÍFortinetµÄÍøÕ¾ÉÏÒѰ䲼Á˸÷ì϶µÄ¼ò¶Ì¸ÅÊö¡£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶δÔ̺¬ÔÚ3Եݲȫ¸üÐÂÖУ¬£¬£¬£¬£¬²¢ÇÒÉв»Ã÷ÏÔºÎʱ½¨¸´¡£¡£ ¡£¡£¡£¡£¡£Æ¾¾ÝFortinetµÄ˵·¨£¬£¬£¬£¬£¬¸Ã·ì϶±»ÃèÊöΪ¡°Microsoft SMB·þÎñÆ÷ÖеĻº³åÇøÒç¶Âí½Å¡±£¬£¬£¬£¬£¬²¢»ñµÃÁË×î¸ßÑϳÁµÈ¼¶£¬£¬£¬£¬£¬¡°Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓô˷ì϶ÔÚÀûÓ÷¨Ê½µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£¡£¡±Ë¼¿ÆTalos°µÊ¾¸Ã·ì϶ʹϵͳÒ×Ôâ¡°È䳿»¯¡±¹¥»÷£¬£¬£¬£¬£¬ÕâÒâζ×ÅÔÚÊܺ¦ÕßÖ®¼äµÄ×ªÒÆºÜÈÝÒס£¡£ ¡£¡£¡£¡£¡£¸Ã·ì϶½öÓ°ÏìSMBv3£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄϵͳÔ̺¬Windows 10 v1903¡¢Windows 10 v1909¡¢Windows Server v1903ºÍWindows Server v1909¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-about-new-smb-wormable-bug-leak-in-microsoft-patch-tuesday-snafu/


2.Å·ÖÞµçÁ¦ÔËÓªÉÌÁªÃËENTSO-E°ì¹«ÍøÂçÔâºÚ¿ÍÈëÇÖ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Å·ÖÞµçÁ¦ÔËÓªÉÌÁªÃË£¨ENTSO-E£©ÔÚÒ»·Ý¼ò¶ÌµÄÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬½üÆÚÆä°ì¹«ÍøÂçÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£ ¡£¡£¡£¡£¡£ÓÉÓÚ¸Ã°ì¹«ÍøÂ粢δÏνӵ½ÈκÎÔËÓªÖеĵçÁ¦´«Êäϵͳ£¬£¬£¬£¬£¬ÕâÒâζ׏¥»÷½öÏÞÓÚITϵͳ£¬£¬£¬£¬£¬Ã»ÓÐÓ°Ïì¹Ø¼ü½ÚÔìϵͳ¡£¡£ ¡£¡£¡£¡£¡£ENTSO-E×ܲ¿Î»ÓÚ²¼Â³Èû¶û£¬£¬£¬£¬£¬ÓÉ35¸öÅ·ÖÞ¹ú¶ÈµÄ42¼ÒµçÍøÔËÓªÉÌ×é³É¡£¡£ ¡£¡£¡£¡£¡£ENTSO-E°µÊ¾ÒѾ­½øÐÐÁË·çÏÕÆÀ¹ÀºÍÔì¶©ÁËÓ¦¼±´òË㣬£¬£¬£¬£¬ÒÔÏ÷¼õ½øÒ»²½¹¥»÷µÄ·çÏÕºÍÓ°Ï죬£¬£¬£¬£¬µ«Ã»ÓÐй©ÓëÈëÇÖºÎʱÆðÍ·ÒÔ¼°Ë­¿ÉÄܶԹ¥»÷ÕÆ¹ÜÓйصľßÌåÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.cyberscoop.com/european-entso-breach-fingrid/


3.¶ñÒâÈí¼þбäÖÖ¿ÉÈÆ¹ýChrome 80ÖеÄcookie¼ÓÃÜËã·¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸èÓÚ2Ô³õÍÆ³öÁËChrome 80£¬£¬£¬£¬£¬²¢ÔÚÆäÖжÔcookieºÍÃÜÂëÔö³¤ÁËAES-256¼ÓÃÜËã·¨½øÐб£»£»£»£»£»¤£¬£¬£¬£¬£¬Ä¿Ç°ÒÑÓÐÖÁÉÙËĸö¶ñÒâÈí¼þÍÆ³öÁË¿ÉÈÆ¹ý¸Ã¼ÓÃܵÄбäÖÖ£¬£¬£¬£¬£¬Ô̺¬ÐÅÏ¢ÇÔȡľÂíKPot¡¢Raccoon¡¢RedlineÒÔ¼°AZORult¡£¡£ ¡£¡£¡£¡£¡£ÔÚChrome 80֮ǰ£¬£¬£¬£¬£¬cookieºÍÃÜÂë¶¼ÊÇͨ¹ýWindows DPAPI½øÐмÓÃÜ£¬£¬£¬£¬£¬ÔÚChrome 80Ö®ºó£¬£¬£¬£¬£¬Êý¾ÝÊ×ÏÈͨ¹ýAES¼ÓÃÜ£¬£¬£¬£¬£¬¶øºóÀûÓÃCrypProtectData DPAPI¶ÔÃÜÔ¿½øÐмÓÃÜ£¬£¬£¬£¬£¬Òò¶ø¿Éͨ¹ýCryptUnprotectDataÄæ×ª¸Ã¹ý³Ì»ñµÃAES-256µÄÃÜÔ¿¡£¡£ ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/malware-unfazed-by-google-chromes-new-password-cookie-encryption/


4.¹¥»÷ÕßÀûÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ç÷Ïò¿Æ¼¼°²È«×êÑÐÈËÔ±¹Û²ìµ½¹¥»÷ÕßÀûÓÃÒøÐÐľÂíGeost¹¥»÷¶íÂÞ˹½ðÈÚ»ú¹¹¡£¡£ ¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒªÒÀ¸½´øÓÐËæ»úÌìÉúµÄ·þÎñÆ÷Ö÷»úÃûµÄ·Ç¹Ù·½ÍøÒ³À´·Ö·¢¸ÃÒøÐÐľÂí£¬£¬£¬£¬£¬¸Ã¹¥»÷»î¶¯ÖØÒªÕë¶ÔÎÞ·¨½Ó¼ûGoogle PlayÉ̵êµÄAndroidÓû§ÒÔ¼°ÄÇЩƫ²îÓÚËÑË÷Google¹Ù·½AndroidÊг¡Éϲ»³ÉÓÃAPPµÄÓû§¡£¡£ ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÃûΪ¡°§å§ã§ä§Ñ§ß§à§Ó§Ü§Ñ¡±£¨¶íÓï¡°ÉèÖá±£©£¬£¬£¬£¬£¬Ê¹ÓÃGoogle Play logoÓÕʹÓû§ÏÂÔØºÍ×°Ö㬣¬£¬£¬£¬ËüÒªÇóÊܺ¦ÕßÊÚÓèÆäÖÎÀíÔ±ÌØÈ¨£¬£¬£¬£¬£¬Ô̺¬½Ó¼ûSMS¶ÌÐŵÄÄÜÁ¦ÒÔ´Ó¶íÂÞË¹ÒøÐзþÎñ½Ó¹ÜÈ·È϶ÌÐÅ¡£¡£ ¡£¡£¡£¡£¡£Geost³õ´Î³öÏÖÓÚ2019Äê10Ô£¬£¬£¬£¬£¬Æäʱ¸ÃľÂíϰȾÁ˳¬¹ý80ÍòÃûÊܺ¦Õß¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityintelligence.com/news/geost-banking-trojan-targets-russian-banks-via-unofficial-webpages/?web_view=true


5.˼¿ÆTalosÅû¶WAGO e!COCKPITÖеĶà¸ö·ì϶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


˼¿ÆTalosÅû¶WAGO e!COCKPIT²úÆ·ÖеĶà¸ö·ì϶¡£¡£ ¡£¡£¡£¡£¡£e!COCKPITÊÇÒ»¸ö¼¯³É¿ª·¢»·¾³£¬£¬£¬£¬£¬Ö¼ÔÚ¼Ó¿ì×Ô¶¯»¯¹¤×÷ÒÔ¼°»úеºÍÏîÖ÷ÕÅÆô¶¯ËÙ¶È¡£¡£ ¡£¡£¡£¡£¡£e!COCKPITÈí¼þÓë·ÖÆçµÄ×Ô¶¯»¯½ÚÔìÆ÷£¨Ô̺¬PFC100ºÍPFC200£©´æÔÚ½Ó¿Ú£¬£¬£¬£¬£¬ËüÃÇÖеķì϶ÔÊÐíÔ¶³Ì¹¥»÷Õß½øÐи÷Àà¶ñÒâ»î¶¯£¬£¬£¬£¬£¬Ô̺¬ºÅÁî×¢Èë¡¢ÐÅϢй¶ºÍÔ¶³Ì´úÂëÖ´ÐС£¡£ ¡£¡£¡£¡£¡£ÆëÈ«·ì϶ºÍÊÜÓ°Ïì¹Ì¼þ°æ±¾ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2020/03/wago-vulnerability-spotlight-march-2020.html


6.ÃÀComcast Xfinityй¶½ü20Íò¸¶·Ñ¿Í»§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úComcast XfinityÔÚ¹«Ë¾µÄÔÚÏßĿ¼ÖÐй¶Á˽ü20Íò¿Í»§µÄ¾ßÌåÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£ÕâЩ¿Í»§ÏòComcast XfinityÖ§¸¶ÁËÓöȣ¬£¬£¬£¬£¬ÒÔ½«ÆäÐÕÃû¡¢µç»°ºÅÂëºÍµØÖ·µÈÓ×ÎÒ¾ßÌåÐÅÏ¢´æ´¢ÔÚ¹«¹²Êý¾Ý¿âÖ®±í£¬£¬£¬£¬£¬µ«ComcastÔÚÆäecolisting.comÍøÕ¾ÉÏ»¹ÊÇÁгöÁËËûÃǵÄÐÅÏ¢¡£¡£ ¡£¡£¡£¡£¡£ComcastÔÚ2ÔÂ5ÈÕ°µÊ¾£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚÒâʶµ½ÃýÎóºóÁ¢¿Ìɾ³ýÁËÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬²¢ÇÒÕâЩÐÅÏ¢ÔÚÍøÉ϶³öµÄ¹¦·òÓ×ÓÚÒ»¸öÔ¡£¡£ ¡£¡£¡£¡£¡£Ä¿Ç°¸ÃÍøÕ¾ÏÔʾXfinityÓïÒô·þÎñ½«²»ÔÙÌṩĿ¼ÁбíÖ°ÄÜ¡£¡£ ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.grahamcluley.com/comcast-xfinity-200000-customers-privacy/