CNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·£»£»£»£»£»£»£»£»ÐÙÑÀÀûÒøÐк͵çÐÅÒµÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ

°ä²¼¹¦·ò 2020-09-28

1.CNCERT°ä²¼¡¶2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÍøÂ簲ȫ¼à²âÊý¾Ý·ÖÎö»ã±¨¡·


1.jpg


ÎªÈ«Ãæ·´Ó³2020ÄêÉϰëÄêÎÒ¹ú»¥ÁªÍøÔÚ¶ñÒⷨʽ´«²¼¡¢·ì϶·çÏÕ¡¢DDoS¹¥»÷¡¢ÍøÕ¾°²È«µÈ·½ÃæµÄÇé¿ö£¬£¬ £¬ £¬£¬CNCERT¶ÔÉϰëÄê¼à²âÊý¾Ý½øÐÐÁËÊáÀí£¬£¬ £¬ £¬£¬²¢Ðγɼà²âÊý¾Ý·ÖÎö»ã±¨¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬ £¬ £¬£¬2020ÄêÉϰëÄ꣬£¬ £¬ £¬£¬²¶»ñÍÆËã»ú¶ñÒⷨ״ò±¾ÊýÁ¿Ô¼1815Íò¸ö£¬£¬ £¬ £¬£¬ÈÕ¾ù´«²¼´ÎÊý´ï483ÍòÓà´Î£¬£¬ £¬ £¬£¬Éæ¼°ÍÆËã»ú¶ñÒⷨʽ¼Ò×åÔ¼1.1ÍòÓà¸ö¡£¡£¡£¡£¡£¡£ÒÀÕÕ´«²¼ÆðԴͳ¼Æ£¬£¬ £¬ £¬£¬¾³±í¶ñÒâ·¨Ê½ÖØÒªÀ´×ÔÃÀ¹ú¡¢ÈûÉà¶ûºÍ¼ÓÄôóµÈ£¬£¬ £¬ £¬£¬£»£»£»£»£»£»£»£»¾³ÄڵĶñÒâ·¨Ê½ÖØÒªÀ´×ÔÕã½­Ê¡¡¢¹ã¶«Ê¡ºÍ±±¾©ÊеÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.cert.org.cn/publish/main/46/2020/20200926085042652505447/20200926085042652505447_.html


2.ÐÙÑÀÀûÒøÐк͵çÐÅÒµÔâµ½DDoS¹¥»÷µ¼Ö·þÎñÁÙʱÖжÏ


2.jpg


Ò»³¡×³´óµÄDDoS¹¥»÷Ï®»÷ÁËÐÙÑÀÀûµÄÒ»Ð©ÒøÐк͵çÕÛ·þÎñ£¬£¬ £¬ £¬£¬µ¼ÖÂÆä·þÎñÖжÏ¡£¡£¡£¡£¡£¡£¾ÝMagyarµçÐŹ«Ë¾³Æ£¬£¬ £¬ £¬£¬Õâ´Î¹¥»÷²úÉúÔÚÖÜËÄ£¬£¬ £¬ £¬£¬¶íÂÞ˹ºÍÔ½ÄϵȹúµÄºÚ¿ÍÊÔͼ¶ÔÐÙÑÀÀû½ðÈÚ»ú¹¹ÌáÒéDDoS¹¥»÷£¬£¬ £¬ £¬£¬ËûÃÇͬʱҲ·ÛËéÁËMagyarµçÐŹ«Ë¾µÄÍøÂç¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬ £¬£¬Õâ´Î¹¥»÷ÖеÄÊý¾ÝÁ÷Á¿±Èͨ³£ÔÚDDoSÊÂÎñÖп´µ½µÄÁ÷Á¿¸ß10±¶£¬£¬ £¬ £¬£¬ÕâÒâζ×Å¾ÍÆä¹æÄ£ºÍ¸´ÔÓÐÔ¶øÑÔ£¬£¬ £¬ £¬£¬ÕâÊÇÐÙÑÀÀûÓÐÊ·ÒÔÀ´×î´óµÄºÚ¿Í¹¥»÷Ö®Ò»¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/108788/hacking/ddos-attack-hungarian-orgs.html


3.Tesorion·¢ÏÖThunderXÖзì϶£¬£¬ £¬ £¬£¬¿ÉÃâ·Ñ¸´Ô­±»ËøÎļþ


3.jpg


ÍøÂ簲ȫ¹«Ë¾Tesorion·¢ÏÖThunderXÖзì϶£¬£¬ £¬ £¬£¬ÒÔ´Ë¿ª·¢²¢°ä²¼ÁËThunderXÀÕË÷Èí¼þµÄ½âÃÜ·¨Ê½£¬£¬ £¬ £¬£¬Ê¹Êܺ¦ÕßÄܹ»Ãâ·Ñ¸´Ô­ÆäÎļþ¡£¡£¡£¡£¡£¡£¸Ã½âÃÜÆ÷Äܹ»½âÃÜÓµÓÐ.tx_lockedÀ©´óÃûµÄ±»¼ÓÃܵÄÎļþ£¬£¬ £¬ £¬£¬Ö»ÐèÉÏ´«Ò»·Ýreadme.txtÊê½ð×¢Ã÷µÄ¸±±¾ºÍÒ»¸ö¼ÓÃܵÄÎļþ£¬£¬ £¬ £¬£¬±ãÄܹ»ÌìÉú½âÃÜÃÜÔ¿¡£¡£¡£¡£¡£¡£Ö®ºó£¬£¬ £¬ £¬£¬ÏÂÔØTesorionµÄThunderX Ransomware½âÃÜ·¨Ê½±ãÄܹ»½øÐнâÃܲÙ×÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/thunderx-ransomware-silenced-with-release-of-a-free-decryptor/


4.³¬¹ý20Íò¸öʹÓÃFortinet VPNµÄÆóÒµÒ×ÊÜMitM¹¥»÷


4.png


ÍøÂ簲ȫƽ̨ÌṩÉÌ SAM Seamless Network³Æ£¬£¬ £¬ £¬£¬³¬¹ý20Íò¸öʹÓÃFortinet VPNµÄÆóÒµÒ×ÊÜMitM¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚFortigate VPNµÄĬÈÏÉèÖÃÖУ¬£¬ £¬ £¬£¬Fortigate SSL-VPN¿Í»§¶Ë½öÑéÖ¤CAÊÇÓÉFortigate»¹ÊÇÓÉÁíÒ»¸öÊÜÐÅÀµµÄCAÐû¸æµÄ£¬£¬ £¬ £¬£¬Õâʹ¹¥»÷ÕßÄܹ»³öʾÐû¸æ¸øÆäËûFortigate·ÓÉÆ÷µÄÖ¤ÊéÀ´Ö´ÐÐÖÐÑëÈ˹¥»÷¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬ £¬ £¬£¬Ä¿Ç°Fortinet²¢Ã»ÓдòËã½â¾ö¸Ã·ì϶£¬£¬ £¬ £¬£¬Ëü½¨ÒéÓû§ÊÖ¶¯´úÌæÄ¬ÈÏÖ¤Ê飬£¬ £¬ £¬£¬ÒÔÔ¤·ÀMitM¹¥»÷¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/108737/hacking/fortigate-vpn-attacks.html


5.TylerÖÒ¸æÆäÓû§Ô¶³Ì½Ó¼ûÃÜÂë»òÒѱ»ÀûÓ㬣¬ £¬ £¬£¬½¨ÒéÁ¢¼´Åú¸Ä


5.png


µ±¾ÐļÊõ·þÎñÌṩÉÌTyler TechnologiesÖÒ¸æÆäÓû§Ô¶³Ì½Ó¼ûÃÜÂë»òÒѱ»ºÚ¿ÍÀûÓ㬣¬ £¬ £¬£¬½¨ÒéÁ¢¼´Åú¸Ä¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾µÄCIO Matt Bieri°µÊ¾£¬£¬ £¬ £¬£¬Æä×î½ü·¢ÏÖÓÐÁ½¸ö¿Í»§¶Ë»ã±¨ÁËʹÓÃTylerÔ¶³Ì½Ó¼ûÍ´´¦½øÐеĿÉÒɵǼ¡£¡£¡£¡£¡£¡£Ä¿Ç°Éв»Ã÷ÏÔÕâЩ¿ÉÒɻÊÇ·ñÓëÆäÉÏÖÜÈÕÔâµ½µÄÀÕË÷Èí¼þ¹¥»÷Óйأ¬£¬ £¬ £¬£¬µ«ÊÇΪÁ˰²È«Æð¼û£¬£¬ £¬ £¬£¬ËûÃǽ¨ÒéÆä¿Í»§¸ü¸ÄTyler TechnologiesʹÓõÄÕÊ»§µÄËùÓÐÃÜÂë¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/tyler-technologies-warns-clients-to-change-remote-support-passwords/


6.Google´ÓPlayÉ̵êÖÐɾ³ý17ÖÖϰȾJokerµÄAndroidÀûÓÃ


6.png


Google±¾ÖÜ´Ó¹Ù·½PlayÉ̵êÖÐɾ³ýÁË17ÖÖϰȾÁËJokerµÄAndroidÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¼äµýÈí¼þJokerÖ¼ÔÚÇÔÈ¡SMSÐÂÎÅ¡¢ÁªÏµÁбíºÍÉ豸ÐÅÏ¢£¬£¬ £¬ £¬£¬²¢ÒÔ¾²Ä¬·½Ê½Ç©ÊðÊܺ¦Õߵĸ߼¶ÎÞÏßÀûÓúÍ̸£¨WAP£©·þÎñ¡£¡£¡£¡£¡£¡£Õâ17¸ö¶ñÒâÀûÓÃÓÚ±¾ÔÂÔÚPlayÉ̵êÉϼܣ¬£¬ £¬ £¬£¬ÔÚ±»·¢ÏÖ֮ǰÒÑÏÂÔØÁË12Íò´ÎÒÔÉÏ¡£¡£¡£¡£¡£¡£ÕâÒÑÊǽü¼¸¸öÔÂÄڹȸ谲ȫÍŶӽøÐеĵÚÈý´ÎÕë¶ÔϰȾJokerµÄÀûÓõĶϸù»î¶¯£¬£¬ £¬ £¬£¬ÔÚ±¾Ô³õ£¬£¬ £¬ £¬£¬¹È¸è¾Íɾ³ýÁË6¸ö´ËÀàÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-removes-17-android-apps-doing-wap-billing-fraud-from-the-play-store/