Òâ´óÀûCSIRT³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½DDoS¹¥»÷

°ä²¼¹¦·ò 2022-05-16
1¡¢Òâ´óÀûCSIRT³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½DDoS¹¥»÷


5ÔÂ13ÈÕ£¬£¬ £¬£¬£¬£¬Òâ´óÀûÍÆËã»ú°²È«ÊÂÎñÏìÓ¦Ó××é(CSIRT)³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ×î½ü¼¸ÌìÔâµ½DDoS¹¥»÷¡£¡£¡£¡£¡£CSIRTÚ¹ÊÍ˵£¬£¬ £¬£¬£¬£¬´Ó5ÔÂ11ÈÕÆðÍ·£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¶ÔÆäµ±¾Ö¡¢²¿Î¯¡¢Òé»áÉõÖÁ¾ü¶ÓµÄÍøÕ¾½øÐÐÁËËùνµÄ¡°Slow HTTP¡±DDoS¹¥»÷¡£¡£¡£¡£¡£ÕâÖÖÀàÐ͵Ĺ¥»÷ÔÚʹÓÃPOSTÒªÇóµÄÇé¿öϸüÓÐЧ£¬£¬ £¬£¬£¬£¬ÓÉÓÚËüÃÇ»¹ÓÃÓÚÏòWeb·þÎñÆ÷·¢ËÍ´óÁ¿Êý¾Ý¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬¸Ã»ú¹¹»¹ÌṩÁË»º½â´ËÀ๥»÷µÄ²½Öè¡£¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïKillnetÐû³Æ¶ÔÕâ´Î¹¥»÷ÕÆ¹Ü£¬£¬ £¬£¬£¬£¬ËûÃÇ»¹¶ÔÂÞÂíÄáÑÇÃÅ»§ÍøÕ¾ºÍÃÀ¹ú²¼À­µÂÀû»ú³¡½øÐÐÁËÀàËÆ¹¥»÷µÄ¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/131256/hacktivism/pro-russian-hacktivists-target-italy.html


2¡¢2¸öÅäÖÃÃýÎóµÄES·þÎñÆ÷й¶Լ3.59Òڱʼͼ


ýÌå5ÔÂ12Èճƣ¬£¬ £¬£¬£¬£¬2¸öÅäÖÃÃýÎóµÄElasticSearch·þÎñÆ÷йÁ˶Լ359019902±Ê¼Í¼¡£¡£¡£¡£¡£¾Ý×êÑÐÈËÔ±³Æ£¬£¬ £¬£¬£¬£¬ÕâÁ½Ð©ES·þÎñÆ÷¾ùÊôÓÚÒ»¸ö×éÖ¯£¬£¬ £¬£¬£¬£¬Ô̺¬Ô¼579.4 GBµÄÊý¾Ý£¬£¬ £¬£¬£¬£¬Éæ¼°ÍÆ¼öÈËÒ³Ãæ¡¢¹¦·ò´ÁIP¡¢µØÀíµØÎ»Êý¾Ý¡¢½Ó¼ûµÄÍøÒ³¡¢ºÍÓû§´úÀíÊý¾ÝµÈ¡£¡£¡£¡£¡£ÆäÖеÚһ̨·þÎñÆ÷Ô̺¬2021Äê9ÔÂ2ÈÕÖÁ10ÔÂ1ÈÕÆÚ¼äÍøÂçµÄ242728328±Ê¼Í¼£¬£¬ £¬£¬£¬£¬Áíһ̨Ô̺¬2021Äê12ÔÂ1ÈÕÖÁ12ÔÂ27ÈÕÍøÂçµÄ116291574±Ê¼Í¼¡£¡£¡£¡£¡£¾Ý¹À¼Æ£¬£¬ £¬£¬£¬£¬Ô¼ÓÐ1500ÍòÓû§ÊÜ´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£


https://www.hackread.com/misconfigured-elasticsearch-servers-user-website-activity/


3¡¢´óÁ¿¶íÂÞ˹AndroidÓû§·´Ó³ÎÞ·¨×°ÖÃChrome¸üÐÂ


¾ÝýÌå5ÔÂ13ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬¶íÂÞ˹ԽÀ´Ô½¶àµÄAndroid ChromeÓû§·´Ó³ÔÚ×°ÖøüÐÂʱ»ã±¨ÃýÎ󡣡£¡£¡£¡£Æ¾¾ÝÓû§ÆÀÂÛ£¬£¬ £¬£¬£¬£¬ÎÊÌâʼÓÚ2022Äê5ÔÂ9ÈÕ£¬£¬ £¬£¬£¬£¬ËûÃÇÔÚÊÔͼװÖÃChrome°æ±¾101ʱÊÕµ½ÁËÒ»ÌõÃýÎóÐÂÎÅ¡°ÎÞ·¨×°ÖÃGoogle Chrome¡±¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬ÃýÎóÐÂÎŲ¢Î´×¢Ã÷¸üÐÂʧ°ÜµÄÔ­Òò£¬£¬ £¬£¬£¬£¬GoogleµÄÖ§³Ö´úÀí½¨ÒéÓû§ÔÚÖ§³ÖÉçÇø»áÉÌÖвéÕÒ½â¾ö¹æ»®¡£¡£¡£¡£¡£Í¶ËßµÄÊýÁ¿Ã¿Ìì¶¼ÔÚÔö³¤£¬£¬ £¬£¬£¬£¬µ«µ½Ä¿Ç°ÎªÖ¹£¬£¬ £¬£¬£¬£¬ÎÊÌâµÄÔ­ÒòÒÀȻδ֪£¬£¬ £¬£¬£¬£¬Ò²Î´½â¾ö¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chrome-updates-failing-on-android-devices-in-russia/


4¡¢Windows 5Ô·ݵĸüпÉÄܻᵼÖÂADÉí·ÝÑé֤ʧ°Ü

¾Ý5ÔÂ12ÈÕ±¨Â·£¬£¬ £¬£¬£¬£¬Î¢ÈíÔÚµ÷²é2022Äê5ÔµÄÖܶþ²¹¶¡µ¼ÖµÄWindows·þÎñÉí·ÝÑé֤ʧ°ÜµÄÎÊÌâ¡£¡£¡£¡£¡£Óû§³ÆËûÃÇÔÚ×°ÖøüкóÊÕµ½ÁËÃýÎóÐÂÎÅ¡°ÓÉÓÚÓû§Í´´¦²»Æ¥Å䣬£¬ £¬£¬£¬£¬Éí·ÝÑé֤ʧ°Ü¡£¡£¡£¡£¡£ÌṩµÄÓû§ÃûδӳÉäµ½ÏÖÓÐÕÊ»§»òÃÜÂë²»ÕýÈ·¡£¡£¡£¡£¡£¡±Î¢Èí°µÊ¾£¬£¬ £¬£¬£¬£¬Ö»ÓÐÔÚÓÃ×÷Óò½ÚÔìÆ÷µÄ·þÎñÆ÷ÉÏ×°Öøüкó²Å»á´¥·¢ÎÊÌ⣬£¬ £¬£¬£¬£¬´ËÉí·ÝÑéÖ¤ÎÊÌâÊÇÓɽ¨¸´ÁËWindows KerberosºÍActive DirectoryÓò·þÎñÖеÄÁ½¸öÌáȨ·ì϶£¨CVE-2022-26931ºÍCVE-2022-26923£©ÒýÆðµÄ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-may-windows-updates-cause-ad-authentication-failures/


5¡¢Î¢Èí·¢ÏÖSysrv-KÀûÓöà¸öзì϶װÖöñÒâ¿ó¹¤µÄ»î¶¯


ýÌå5ÔÂ13Èճƣ¬£¬ £¬£¬£¬£¬Î¢Èí·¢ÏÖ½©Ê¬ÍøÂç±äÌåSysrv-KÔÚÀûÓÃеķì϶£¬£¬ £¬£¬£¬£¬ÔÚWindowsºÍLinux·þÎñÆ÷ÉÏ×°ÖüÓÃܶñÒâÈí¼þ¡£¡£¡£¡£¡£Õâ´ÎÀûÓõķì϶¾ùÒѱ»½¨¸´£¬£¬ £¬£¬£¬£¬ÆäÖÐÔ̺¬WordPress²å¼þÖеÄCVE-2022-22947µÈ½Ïеķì϶£¬£¬ £¬£¬£¬£¬ÒÔ¼°Spring Cloud Gateway¿âÖеĴúÂë×¢Èë·ì϶£¨CVE-2022-22947£©¡£¡£¡£¡£¡£´Ë±í£¬£¬ £¬£¬£¬£¬Sysrv-K±äÌ廹Ôö³¤ÁËÐÂÖ°ÄÜ£¬£¬ £¬£¬£¬£¬ÀýÈçɨÃèWordPressÅäÖÃÎļþ¼°Æä±¸·ÝÒÔÇÔÈ¡Êý¾Ý¿âÍ´´¦£¬£¬ £¬£¬£¬£¬ÓÃÓÚÊÕÊÜÍøÂç·þÎñÆ÷¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-sysrv-botnet-targets-windows-linux-servers-with-new-exploits/


6¡¢SecureworksÅû¶COBALT MIRAGEÕë¶Ô¶à¹úµÄ¹¥»÷»î¶¯


5ÔÂ12ÈÕ£¬£¬ £¬£¬£¬£¬Secureworks°ä²¼»ã±¨Åû¶ÁËCOBALT MIRAGEÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¡£¸ÃÍÅ»ï´Ó2020Äê6ÔÂÆðÍ·»îÔ¾£¬£¬ £¬£¬£¬£¬ÓëÒÁÀÊCOBALT ILLUSION£¨ÓÖ³ÆAPT35£©ÓйØÁª£¬£¬ £¬£¬£¬£¬ÖØÒªÕë¶ÔÒÔÉ«ÁÓ×¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃÁËÁ½ÖÖ·ÖÆçµÄÈëÇÖ·½Ê½£¬£¬ £¬£¬£¬£¬ÆäÖÐÒ»ÖÖÀûÓÃBitLockerºÍDiskCryptor½øÐÐÀÕË÷¹¥»÷£¬£¬ £¬£¬£¬£¬ÒÔ»ñÈ¡¾­¼ÃÀûÒæ£»£»£» £»£»£»ÁíÒ»ÖÖ¸ü¾ßÕë¶ÔÐÔ£¬£¬ £¬£¬£¬£¬ÖØÒªÖ÷ÕÅÊÇ»ñÈ¡½Ó¼ûȨÏÞºÍÍøÂçµý±¨£¬£¬ £¬£¬£¬£¬µ«ÓÐʱҲ»áʹÓÃÀÕË÷Èí¼þ¡£¡£¡£¡£¡£


https://www.secureworks.com/blog/cobalt-mirage-conducts-ransomware-operations-in-us