ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ26ÖÜ
°ä²¼¹¦·ò 2019-07-08±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê7ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼°²È«·ì϶46¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Mesos Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»TRENDnet TEW-827DRU apply.cgiºÅÁî×¢Èë·ì϶£»£»£»£»£»£»£»£»NLnet Labs Name Server Daemon CVE-2019-13207»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»Nortek Security£¦Control Linear eMerge E3-Series CVE-2019-7253Ŀ¼±éÀú·ì϶£»£»£»£»£»£»£»£»NetApp AFF A700s Baseboard Management Controller CVE-2019-5497ºÅÁî×¢Èë·ì϶¡£¡£¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
1. Apache Mesos Ô¶³Ì´úÂëÖ´Ðзì϶
Apache Mesos×é¼þ´æÔÚ¸²¸Ç·ì϶£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄDockerÓ³Ïñ£¬£¬£¬£¬£¬£¬¿É¸²¸Çinit helperÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£
https://lists.apache.org/thread.html/b162dd624dc088cd634292f0402282a1d1d0ce853baeae8205bc033c@%3Cdev.mesos.apache.org%3E
2. TRENDnet TEW-827DRU apply.cgiºÅÁî×¢Èë·ì϶
https://github.com/TeamSeri0us/pocs/blob/master/iot/trendnet/cmdinject678.jpg
3. NLnet Labs Name Server Daemon CVE-2019-13207»º³åÇøÒç¶Âí½Å
https://github.com/NLnetLabs/nsd/issues/20
4. Nortek Security£¦Control Linear eMerge E3-Series CVE-2019-7253Ŀ¼±éÀú·ì϶
https://www.applied-risk.com/resources/ar-2019-005
5. NetApp AFF A700s Baseboard Management Controller CVE-2019-5497ºÅÁî×¢Èë·ì϶
https://security.netapp.com/advisory/ntap-20190627-0001/
³ÁÒª°²È«ÊÂÎñ×ÛÊö
Ç÷Ïò¿Æ¼¼¹Û²ìµ½Ò»¸ö»îÔ¾µÄ¸æ°×Èí¼þ»î¶¯£¨AndroidOS_HiddenAd.HRXAAºÍAndroidOS_HiddenAd.GCLA£©£¬£¬£¬£¬£¬£¬¸Ã¸æ°×Èí¼þ°µ²ØÔÚ182¸öÄܹ»Ãâ·ÑÏÂÔØµÄÓÎÏ·ºÍÏà»úAPPÖУ¬£¬£¬£¬£¬£¬ÆäÖÐ111¸ö¿ÉÔÚGoogle PlayÉ̵êÖÐÕÒµ½£¬£¬£¬£¬£¬£¬ÆäËü¶ñÒâAPPÔòÔÚ9AppsºÍPP AssistantµÈµÚÈý·½ÀûÓÃÉ̵êÖгöÏÖ¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ±»Ï¼Ü֮ǰ£¬£¬£¬£¬£¬£¬ÕâЩ¶ñÒâAPPµÄ×ÜÏÂÔØÁ¿´ï934.9Íò´Î¡£¡£¡£¡£¡£¡£¡£¡£¸Ã¸æ°×Èí¼þÄܹ»°µ²Ø¶ñÒâAPPµÄͼ±ê£¬£¬£¬£¬£¬£¬ÏòÓû§ÍÆËÍÎÞ·¨Á¢¼´¹Ø¹Ø»òÍ˳öµÄÈ«ÆÁ¸æ°×£¬£¬£¬£¬£¬£¬»¹Äܹ»ÌÓ±ÜɳºÐµÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/adware-campaign-identified-from-182-game-and-camera-apps-on-google-play-and-third-party-stores-like-9apps/
2¡¢CloudflareÔٴη¢×÷¹ÊÕÏ£¬£¬£¬£¬£¬£¬´óÁ¿ÍøÕ¾å´»ú
CDN¼Ó¿ì·þÎñÉÌCloudflareÔÚ±±¾©¹¦·ò7ÔÂ2ÈÕÍí¼ä³öÏÖ´óÃæ»ýå´»ú£¬£¬£¬£¬£¬£¬Óû§½Ó¼ûʹÓÃÁËCloudflareµÄÍøÕ¾³öÏÖ502ÃýÎ󡣡£¡£¡£¡£¡£¡£¡£Õâ´Îå´»úÔÒòÊÇCloudflareÔÚеÄWebÀûÓòã·À»ðǽ(WAF£©Öв¿ÊðÁËÒ»¸öÅäÖÃÃýÎóµÄ¹æ¶¨£¬£¬£¬£¬£¬£¬ÇÒÕâЩ¹æ¶¨Ò»´ÎÐÔÔÚËùÓнڵãÉϲ¿Ê𣬣¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÁËÈ«Çò´óÃæ»ýå´»ú¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÃýÎóµÄ¹æ¶¨Ô̺¬Ò»¸öÕýÔò±í°×ʽ£¬£¬£¬£¬£¬£¬µ¼ÖÂCloudflare·þÎñÆ÷ÉϵÄCPUÕ¼ÓÃìÉýÖÁ100%¡£¡£¡£¡£¡£¡£¡£¡£ËæºóCloudflare»Ø¹öÁËÃýÎóµÄ¹æ¶¨£¬£¬£¬£¬£¬£¬Ä¿Ç°ÓйطþÎñÒѸ´ÔÕý³£¡£¡£¡£¡£¡£¡£¡£¡£ÕâÒѾÊÇCloundflare±¾Ôµڶþ´Î³öÏÖå´»úÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.cloudflare.com/cloudflare-outage/
3¡¢ÖÇÄܼҾӳ§ÉÌOrviboÒâ±íй¶³¬¹ý20ÒÚÌõÓû§¼Í¼
vpnMentor×êÑÐÈËÔ±·¢ÏÖÖÇÄܼҾӳ§ÉÌOrviboµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬ÆäÖÐй¶Á˳¬¹ý20ÒÚÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝÓû§ÈÕÖ¾£¬£¬£¬£¬£¬£¬ÐÅÏ¢±»Ð¹Â¶µÄÓû§À´×ÔÖйú¡¢ÈÕ±¾¡¢Ì©¹ú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢Ä«Î÷¸ç¡¢·¨¹ú¡¢°Ä´óÀûÑǺͰÍÎ÷¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢ÃÜÂë¡¢ÕÊ»§³ÁÖôúÂë¡¢¾«È·µÄµØÀíµØÎ»¡¢IPµØÖ·¡¢Óû§ÃûºÍÓû§ID¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÃÜÂëΪδ¼ÓÑεÄMD5¹þÏ£Ìåʽ¡£¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖл¹Ô̺¬¼ÒÍ¥ID¡¢¼ÒÍ¥Ãû³Æ¡¢¹ØÁªÖÇÄÜÉ豸ÐÅÏ¢ºÍ´òË㹤×÷µÈ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩÐÅÏ¢¿ÉÄܱ»ÓÃÀ´ÓÀÔ¶Ëø¶¨Óû§µÄÕË»§¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/unprotected-database-of-smart-home-vendor-exposes-billions-of-records-23f3a56b
4¡¢×êÑÐÈËÔ±·¢ÏÖÊ׸öÀÄÓÃDNS over HTTPSºÍ̸µÄ¶ñÒâÈí¼þGodlua
×êÑÐÈËÔ±·¢ÏÖÊ׸öÀÄÓÃDNS over HTTPS£¨DoH£©ºÍ̸µÄ¶ñÒâÈí¼þGodlua£¬£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÊÇÒ»¸öÓÃLua±àдµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬Æä×÷ÓÃÀàËÆÓÚºóÃÅ¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÀûÓ÷ì϶£¨CVE-2019-3396£©À´Ï°È¾Linux·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖµÄÁ½¸öGodluaÑù±¾¶¼Ê¹ÓÃDNS over HTTPSÒªÇóÀ´»ñÈ¡ÓòÃûTXT£¬£¬£¬£¬£¬£¬ÆäÖд洢ÁËC£¦C·þÎñÆ÷µÄURL¡£¡£¡£¡£¡£¡£¡£¡£ÕâÖÖ´ÓDNSÎı¾¼Í¼ÖмìË÷µÚ¶þ/µÚÈý½×¶ÎC£¦C·þÎñÆ÷URLµØÖ·µÄ¼¼Êõ²¢²»ÐÂÏÊ£¬£¬£¬£¬£¬£¬µ«Ê¹ÓÃDoHÒªÇó¶ø²»ÊÇ´«Í³µÄDNSÒªÇóΪ³õ´Î³öÏÖ¡£¡£¡£¡£¡£¡£¡£¡£DoH£¨DNS£©ÒªÇó¶ÔµÚÈý·½¹Û²ìÕß¼ÓÃÜÇÒ²»Ë½¼û£¬£¬£¬£¬£¬£¬ÕâÔ̺¬ÒÀÀµ±»¶¯DNS¼à¿ØÀ´×èÖ¹¶ÔÒÑÖª¶ñÒâÓòÒªÇóµÄÍøÂ簲ȫÈí¼þ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/first-ever-malware-strain-spotted-abusing-new-doh-dns-over-https-protocol/
5¡¢³¬¹ý30¸öVMware²úÆ·Êܵ½Linux SACK·ì϶ӰÏì
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/many-vmware-products-affected-sack-linux-vulnerabilities


¾©¹«Íø°²±¸11010802024551ºÅ