ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ3ÖÜ

°ä²¼¹¦·ò 2019-01-21

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇBrocade Network Advisor CVE-2018-6443Ó²±àÂëÆ¾Ö¤·ì϶£»£»£»£»£»£»systemd-journaldÕ»»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£»£»£»£»£»IDenticard PremisysÊý¾Ý¿âĬÈÏÆ¾Ö¤·ì϶£»£»£»£»£»£»LCDS LAquis SCADAδÊÚȨ½Ó¼û·ì϶¡£¡£¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ»úƱԤԼϵͳAmadeusÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾;ÃÀOklahomaÖݵ±¾Ö·þÎñÆ÷ÒⱩ¶³ö3TBÃô¸ÐÊý¾Ý;Ó¢¹úBSIA°ä²¼»¥Áª°²Õûϵͳ×î¼Ñʵ¼ÊÖ¸ÄÏ;VoIP·þÎñÉÌVOIPOÒâ±íй¶´ÓǰËÄÄêµÄ¿Í»§Êý¾Ý;ESÎļþä¯ÀÀÆ÷Á½¸ö·ì϶ʹµÃ³¬¹ý1ÒÚAndroidÓû§Ãæ¶Ô·çÏÕ¡£¡£¡£¡£¡£¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1. Brocade Network Advisor CVE-2018-6443Ó²±àÂëÆ¾Ö¤·ì϶
Brocade Network Advisor´æÔÚÓ²±àÂë·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉµÇ¼µ½JBoss Administration½çÃæ²¢×°ÖÃÆäËûJEEÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£¡£
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743

2. systemd-journaldÕ»»º³åÇøÒç¶Âí½Å
systemd-journaldʵÏÖ´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Ê¹systemd-journald±ÀÀ£»£»£»£»£»£»òÒÔjournaldȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864

3. SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´Ðзì϶
SAS Web Infrastructure PlatformµÄ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://support.sas.com/kb/63/391.html

4. IDenticard PremisysÊý¾Ý¿âĬÈÏÆ¾Ö¤·ì϶
IDenticard Premisys Identicard·þÎñÔÚ×°ÖÃʱʹÓÃĬÈϵÄÊý¾Ý¿âÓû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬Î´ÊÚȨ½Ó¼ûÊý¾Ý¿âȨÏÞ¡£¡£¡£¡£¡£¡£¡£
http://www.securityfocus.com/bid/106552

5. LCDS LAquis SCADAδÊÚȨ½Ó¼û·ì϶
LCDS LAquis SCADAʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢»úƱԤԼϵͳAmadeusÑϳÁ·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÒÔÉ«Áа²È«×êÑÐÔ±Noam Rotem·¢ÏÖ»úƱԤԼϵͳAmadeus´æÔÚÒ»¸öÑϳÁµÄ°²È«·ì϶£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£¡£¡£¡£¡£¡£¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤Ô¼»úƱʱ·¢ÏÖÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬ÔÚÔ¤Ô¼º½°àºó£¬£¬£¬£¬£¬£¬´î¿Í»áÊÕµ½PNRºÅÂëºÍÓÃÓڲ鿴ԤԼÐÅÏ¢µÄÁ´½Ó¡£¡£¡£¡£¡£¡£¡£Rotem·¢ÏÖͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÅú¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿É²é¿´ËûÈ˵ÄÔ¤Ô¼ÐÅÏ¢£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉÀûÓÃÕâЩÐÅÏ¢½Ó¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬£¬Ô̺¬¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤԼϵͳ±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Óã¨Ô̺¬ÃÀ¹ú½áºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶¿ÉÄÜÓ°ÏìÁËÊýÒÚ´î¿Í¡£¡£¡£¡£¡£¡£¡£Ä¿Ç°AmadeusÒѾ­½¨¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html



2¡¢ÃÀOklahomaÖݵ±¾Ö·þÎñÆ÷ÒⱩ¶³ö3TBÃô¸ÐÊý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



UpGuard×êÑÐÈËÔ±Greg Pollock·¢ÏÖÊôÓÚÃÀ¹ú¶í¿ËÀ­ºÉÂíÖÝ֤ȯ²¿ODSµÄһ̨·þÎñÆ÷¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ̺¬Êý°ÙÍòÃô¸ÐÎļþµÄÔ¼3TBµÐÔÖÊý¾Ý¶³ö¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÔ̺¬Ö¤È¯Î¯Ô±»áÊýÊ®ÄêµÄ»úÃÜÎļþºÍºÜ¶àÃô¸ÐµÄFBIµ÷²éÎļþ£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô¼1ÍòÃû¹ÉƱ¾­¼ÍÈ˵ĵç×ÓÓʼþ¡¢Éç»á°²È«ºÅÂë¡¢ÐÕÃûºÍµØÖ·ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£ShodanÏÔʾ¸Ã·þÎñÆ÷ÖÁÉÙ´Ó2018Äê11ÔÂ30ÈÕÆðÍ·¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬Ô¼Ò»ÖܺóODSÊÕµ½Í¨Öª²¢¶Ô¸Ã·þÎñÆ÷Ö´ÐÐÁ˱£»£»£»£»£»£»¤´ëÊ©¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/oklahoma-fbi-data-leak.html


3¡¢Ó¢¹úBSIA°ä²¼»¥Áª°²Õûϵͳ×î¼Ñʵ¼ÊÖ¸ÄÏ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



Ó¢¹ú°²·ÀÐÐҵЭ»á£¨BSIA£©°ä²¼»¥Áª°²Õûϵͳ×î¼Ñʵ¼ÊÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×î´óÏ޶ȵØÏ÷¼õµç×Ó°²ÕûϵͳÖеÄÍøÂçÏνÓÉ豸¡¢Èí¼þºÍϵͳµÄÊý×ÔìÆ»µ·çÏÕ¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÒÔÐÐÒµµÄ×î¼Ñ¹ú¼Êʵ¼ÊΪ»ù´¡£¡£¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬²¢²Î¿¼¹«ÈϵĹú¼ÊÖ¸ÄϺͳ߶ȣ¬£¬£¬£¬£¬£¬Äܹ»Ô®ÊÖ»¥Áª°²Õûϵͳ¹©¸øÁ´ÖеÄÉè¼ÆÕß¡¢Ôì×÷ÉÌ¡¢×°ÖÃÈËÔ±¡¢ÊØ»¤ÈËÔ±¡¢·þÎñÌṩÉ̺ÍÓû§ÌáÉý°²È«ÏνӵÄÐÅÐÄ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/


4¡¢VoIP·þÎñÉÌVOIPOÒâ±íй¶´ÓǰËÄÄêµÄ¿Í»§Êý¾Ý

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



×êÑÐÈËÔ±Justin Paineͨ¹ýShodan·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticSearchÊý¾Ý¿â£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚVoIP·þÎñÉÌVOIPO£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Á˸ù«Ë¾´ÓǰËÄÄêµÄ¿Í»§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝPaineµÄ˵·¨£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÔ̺¬¿É×·ÒäÖÁ2017Äê7ÔµÄ670ÍòÌõͨ»°¼Í¼¡¢¿É×·ÒäÖÁ2015Äê12ÔµÄ600ÍòÌõ¶ÌÐÅ/²ÊÐÅÈÕÖ¾ÒÔ¼°100ÍòÌõÔ̺¬ÄÚ²¿ÏµÍ³API KEYµÄÈÕÖ¾¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ1ÔÂ8ÈÕÏòVOIPO´«µÝÁËÕâÒ»·¢ÏÖ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚͳһÌ콫Êý¾Ý¿â½øÐÐÁËÍÑ»ú±£»£»£»£»£»£»¤¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html



5¡¢ESÎļþä¯ÀÀÆ÷Á½¸ö·ì϶ʹµÃ³¬¹ý1ÒÚAndroidÓû§Ãæ¶Ô·çÏÕ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



°²È«×êÑÐÔ±Robert BaptisteÔÚESÎļþä¯ÀÀÆ÷Öз¢ÏÖÒ»¸öʼÖÕÔÚºó¶ÜÔËÐеݵ²ØWeb·þÎñÆ÷£¨¶Ë¿Ú59777£©£¬£¬£¬£¬£¬£¬ÓëÊܺ¦Õß´¦ÓÚͳһ±¾µØÍøÂçµÄ¹¥»÷Õ߿ɻñÈ¡Êܺ¦ÕßÊÖ»úµÄ´óÁ¿ÓÐЧÐÅÏ¢£¨Ô̺¬É豸ÐÅÏ¢¡¢app×°ÖÃÐÅÏ¢¡¢ÎļþµÈ)£¬£¬£¬£¬£¬£¬ÉõÖÁÄܹ»Ô¶³ÌÆô¶¯app¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2019-6447£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹°ä²¼ÁËPOC¾ç±¾¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬ESET×êÑÐÈËÔ±Lukas Stefanko·¢ÏÖÁËÁíÒ»¸öÖÐÑëÈË£¨MitM£©¹¥»÷·ì϶£¬£¬£¬£¬£¬£¬Ó°ÏìÁË4.1.9.7.4¼°Ö®Ç°µÄ°æ±¾¡£¡£¡£¡£¡£¡£¡£ESÎļþä¯ÀÀÆ÷¿ª·¢ÍŶӰµÊ¾½¨¸´²¹¶¡½«ÔÚԼĪÁ½ÌìºóÍÆ³ö¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/es-file-explorer-flaws-put-100-million-users-data-at-risk-fix-promised/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù