×êÑÐÍŶӳÆNTLMÖм̹¥»÷DFSCoerce¿É½Ù³ÖWindowsÓò

°ä²¼¹¦·ò 2022-06-22
1¡¢×êÑÐÍŶӳÆNTLMÖм̹¥»÷DFSCoerce¿É½Ù³ÖWindowsÓò

      

¾Ý6ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬×êÑÐÍŶӷ¢ÏÖÁËÃûΪDFSCoerceµÄÐÂNTLMÖм̹¥»÷£¬£¬£¬£¬£¬¿ÉÀûÓÃMicrosoftµÄÉ¢²¼Ê½ÎļþϵͳMS-DFSNMÀ´ÆëÈ«½ÚÔìWindowsÓò¡£¡£¡£¡£¡£DFSCoerceµÄ¾ç±¾»ùÓÚPetitPotamµÄ·ì϶ÀûÓ㬣¬£¬£¬£¬²¢Ê¹ÓÃÁËMS-DFSNM¶ø·ÇMS-EFSRPC£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖÄܹ»Í¨¹ýRPC½Ó¿ÚÖÎÀíWindowsÉ¢²¼Ê½Îļþϵͳ(DFS)µÄºÍ̸¡£¡£¡£¡£¡£¾­¹ý²âÊÔ£¬£¬£¬£¬£¬ÕâÖÖеÄNTLMÖм̹¥»÷ºÜÈÝÒ×ÈöÔWindowsÓòÓµÓнӼûȨÏÞµÄÓû§³ÉΪÓòÖÎÀíÔ±¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬ÕмܴËÀ๥»÷µÄ×î¼Ñ²½ÖèÊÇ×ñѭ΢Èí°ä²¼µÄ¹ØÓÚ»º½âPetitPotam NTLMÖм̹¥»÷µÄ½¨Òé¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/new-dfscoerce-ntlm-relay-attack-allows-windows-domain-takeover/


2¡¢CloudflareÍøÂçÅäÖÃÃýÎóµ¼ÖÂÊý¾ÝÖÐÐĺͷþÎñ´ó¹æÄ£ÖжÏ

      

¾Ý±¨Â·£¬£¬£¬£¬£¬CloudflareÔÚ6ÔÂ21ÈÕ²úÉúÁË´ó¹æÄ£µÄÖжÏ£¬£¬£¬£¬£¬Ó°ÏìÁËÊ®¶à¸öÊý¾ÝÖÐÐĺÍÊý°Ù¸öÔÚÏ߯½Ì¨ºÍ·þÎñ¡£¡£¡£¡£¡£¸Ã¹«Ë¾°µÊ¾£¬£¬£¬£¬£¬Õâ´ÎÖжÏÊÇÅú¸ÄÍøÂçÅäÖõ¼ÖµÄ£¬£¬£¬£¬£¬´Ë¾Ù±¾ÒâÊÇÌá¸ßÍøÂ絯ÐÔ¡£¡£¡£¡£¡£ÖÐ¶ÏÆðÍ·ÓÚ06:27 UTC£¬£¬£¬£¬£¬Óû§ÔÚ½Ó¼ûÕâÐ©ÍøÕ¾Ê±»áÊÕµ½500 errorsÌáÐÑ¡£¡£¡£¡£¡£µÚÒ»¸öÊý¾ÝÖÐÐÄÔÚ06:58 UTC³ÁÐÂÉÏÏߣ¬£¬£¬£¬£¬µ½07:42 UTCËùº±¼û¾ÝÖÐÐͼ¸´Ô­Õý³£¹¤×÷¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄµØÓò½öÕ¼CloudflareÈ«ÊýÍøÂçµÄ4%£¬£¬£¬£¬£¬µ«Ó°ÏìÁËCloudflare´¦ÖõÄËùÓÐHTTPÒªÇóµÄÔ¼50%£¬£¬£¬£¬£¬Éæ¼°Amazon¡¢Twitch¡¢Steam¡¢Telegram¡¢DiscordºÍGitlabµÈÍøÕ¾¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/massive-cloudflare-outage-caused-by-network-configuration-error/


3¡¢GoogleÅû¶Apple Safari·ì϶CVE-2022-22620µÄϸ½Ú

      

6ÔÂ14ÈÕ£¬£¬£¬£¬£¬Google Project ZeroÅû¶ÁËApple SafariÖÐÒѱ»ÀûÓõķì϶µÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£ÕâÊÇWebKit×é¼þÖеÄÒ»¸ö¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬×·×ÙΪCVE-2022-22620£¬£¬£¬£¬£¬¿Éͨ¹ýÌØÔìµÄWebÄÚÈÝÀûÓò¢µ¼ÖÂËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¸Ã·ì϶ÔçÔÚ2013Äê¾ÍÒѱ»½¨¸´£¬£¬£¬£¬£¬µ«ÔÚ2016ÄêµÄ´ó¹æÄ£³Á¹¹¹¤×÷ÖÐÔٴα»ÒýÈë¡£¡£¡£¡£¡£Ö±µ½2022Äê2ÔÂÉÏÑ®£¬£¬£¬£¬£¬Apple°ä²¼Á˸÷ì϶µÄ²¹¶¡£¬£¬£¬£¬£¬²¢È·¶¨Æä¿ÉÄÜÒѱ»»ý¼«ÀûÓᣡ£¡£¡£¡£


https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html


4¡¢ZScaler·¢ÏÖÕë¶ÔÃÀ¹ú¾üÊ¡¢ITºÍÒ½ÁƵÈÐÐÒµµÄ´¹µö¹¥»÷

      

ýÌå6ÔÂ20ÈÕ±¨Â·£¬£¬£¬£¬£¬ÐÂÒ»ÂÖ´¹µö»î¶¯Ò»ÏòÔÚÕë¶ÔÃÀ¹úµÄ¾üÊ¡¢IT¡¢Ôì×÷¹©¸øÁ´¡¢Ò½ÁƱ£½¡ºÍÔìÒ©µÈÁìÓòµÄ×éÖ¯£¬£¬£¬£¬£¬Ö¼ÔÚÇÔÈ¡Microsoft Office 365ºÍOutlookÍ´´¦¡£¡£¡£¡£¡£ZScaler³Æ£¬£¬£¬£¬£¬Õâ´Î»î¶¯Óë2020Äê7Ô·¢ÏÖµÄÁíÒ»´Î»î¶¯µÄÕ½Êõ¡¢¼¼ÊõºÍ·¨Ê½(TTP)¸ß¶È³Áµþ¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓÃÁËÈÕ±¾µÄµç×ÓÓʼþ·þÎñÀ´·¢ËÍÓʼþ£¬£¬£¬£¬£¬²¢Î±Ôì·¢¼þÈ˵ĵØÖ·¡£¡£¡£¡£¡£ÓʼþÔ̺¬Ò»¸öHTML¸½¼þ£¬£¬£¬£¬£¬½«Ö¸±ê³Á¶¨Ïòµ½´¹µöÍøÕ¾¡£¡£¡£¡£¡£Ö®ºó»áÊ×ÏȶÔÖ¸±ê½øÐÐCAPTCHA²é³­£¬£¬£¬£¬£¬Ö¼ÔÚÈÆ¹ý¼ì²â²¢Ê¹Æä¿´ÆðÀ´¸üºÏ·¨£¬£¬£¬£¬£¬ÕâÒ»²½ÖèÒ²ÔøÓÃÓÚ2020ÄêµÄ»î¶¯¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-365-credentials-targeted-in-new-fake-voicemail-campaign/


5¡¢Resecurity³Æ½üÆÚÀûÓÃMicrosoft AFDµÄ´¹µö»î¶¯¼¤Ôö 

      

ýÌå6ÔÂ21Èճƣ¬£¬£¬£¬£¬Í¨¹ý΢ÈíÌṩµÄÔÆCDN·þÎñAzure Front Door(AFD)µÄ´¹µö»î¶¯¼¤Ôö¡£¡£¡£¡£¡£´óÎÞÊý´¹µö»î¶¯ÖØÒªÕë¶ÔSendGrid¡¢DocusignºÍAmazon£¬£¬£¬£¬£¬ÒÔ¼°ÆäËû¼¸¼ÒÈÕ±¾ºÍÖж«ÔÚÏß·þÎñÌṩÉ̺͹«Ë¾¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓñ»ÈëÇֵįóÒµºÍÓ×ÎÒµÄÓʼþÕÊ»§À´·Ö·¢Ô̺¬´¹µöÁ´½ÓµÄÀ¬»øÓʼþ£¬£¬£¬£¬£¬ÕâЩÁ´½ÓÖ¸ÏòÍйÜÔÚAzure Front DoorÉϵÄÐéαweb×ÊÔ´¡£¡£¡£¡£¡£Resecurity½éÉÜ£¬£¬£¬£¬£¬´ËÀ๥»÷Õ½Êõ½ÒʾÁ˹¥»÷ÕßÈôºÎÀûÓÃÔÆ·þÎñ²»ÐݼÓÇ¿ÆäÕ½ÊõºÍ·¨Ê½£¬£¬£¬£¬£¬ÒÔÈÆ¹ý´¹µö¹¥»÷µÄ¼ì²â¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132458/cyber-crime/azure-front-door-phishing.html


6¡¢Î¢Èí´¹Î£¸üн¨¸´ArmÉ豸µÄMicrosoft 365µÇ¼ÎÊÌâ

      

΢ÈíÔÚ6ÔÂ20ÈÕ°ä²¼´ø±í(OOB)¸üУ¬£¬£¬£¬£¬ÒÔ½¨¸´×°ÖÃ6Ô²¹¶¡ºóµ¼ÖµÄArmÉ豸ÉϵÄAzure Active DirectoryºÍMicrosoft 365µÇ¼ÎÊÌâ¡£¡£¡£¡£¡£Î¢ÈíÚ¹ÊͳÆ£¬£¬£¬£¬£¬¸ÃÎÊÌâ½öÓ°Ïì»ùÓÚWindows ArmµÄÉ豸£¬£¬£¬£¬£¬µ¼ÖÂÎÞ·¨½øÐÐAADµÇ¼£¬£¬£¬£¬£¬Í¬Ê±Ò²»áÓ°ÏìʹÓÃAADµÇ¼µÄÀûÓúͷþÎñ£¬£¬£¬£¬£¬ÈçVPNÏνӡ¢Microsoft TeamsºÍOutlookµÈ¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾Ô̺¬Windows 11 21H2¡¢Windows 10 21H2¡¢Windows 10 21H1ºÍWindows 10 20H2¡£¡£¡£¡£¡£±¾Ôµĸüл¹µ¼ÖÂÁËWindows Serverϵͳ³öÏÖÎÊÌ⣬£¬£¬£¬£¬Óû§ÎÞ·¨Ê¹ÓÃVSS±¸·ÝÊý¾Ý¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/