ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ29ÖÜ

°ä²¼¹¦·ò 2019-07-29

>  ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê7ÔÂ22ÈÕÖÁ28ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶£»£» £»£»£»£»£»Apple Webkit ¶à¸öÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶£»£» £»£»£»£»£»Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶£»£» £»£»£»£»£»Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶£»£» £»£»£»£»£»McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǶíÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬»úÃÜÏîÄ¿ÆØ¹â£»£» £»£»£»£»£»ProFTPD RCE·ì϶£¬£¬£¬£¬£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ï죻£» £»£»£»£»£»Ó¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢£»£» £»£»£»£»£»RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬£¬£¬£¬£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª£»£» £»£»£»£»£»Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯¡£¡£¡£¡£ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£ ¡£



>  ³ÁÒª°²È«·ì϶Áбí



1. ProFTPD SITE CPFR/CPTOËÁÒâ¶Áд·ì϶


ProFTPD SITE CPFR/CPTOûÓÐÕýÈ·´¦ÖúÍÅäÖ㬣¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ¶Áд²Ù×÷¡£¡£¡£¡£ ¡£

http://bugs.proftpd.org/show_bug.cgi?id=4372

2. Apple Webkit CVE-2019-8644ÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶


Apple iOSÔ̺¬µÄWebKit´æÔÚÄÚ´æ·ÛËé·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£» £»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£

https://support.apple.com/zh-cn/HT210356

3. Zeroshell http²ÎÊýºÅÁî×¢Èë·ì϶


Zeroshell´¦ÖÃhttp²ÎÊý´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt

4. Apache Storm·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Storm´¦Öò»³ÉÐÅÊý¾Ý´æÔÚ·´ÐòÁл¯·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£ ¡£
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E

5. McAfee Data Loss Prevention Endpoint ePOÀ©´óºÅÁî×¢Èë·ì϶


McAfee Data Loss Prevention Endpoint ePOÀ©´ó´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâOSºÅÁî¡£¡£¡£¡£ ¡£
https://kc.mcafee.com/corporate/index?page=content&id=SB10289



 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢¶íÂÞ˹Áª¹ú°²È«¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬»úÃÜÏîÄ¿ÆØ¹â


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¶íÂÞ˹Áª¹ú°²È«¾Ö£¨FSB£©µÄ³Ð°üÉÌSyTechÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÎªFSB¿ª·¢µÄ»úÃÜÏîÄ¿±»ÆØ¹â¡£¡£¡£¡£ ¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚ7ÔÂ13ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ï0v1ru$ÈëÇÖÁËSyTechµÄ·þÎñÆ÷£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË7.5TBµÄÊý¾Ý¡£¡£¡£¡£ ¡£ÕâЩÊý¾ÝËæºó±»·ÖÏí¸øºÚ¿ÍÍÅ»ïDigitalRevolution£¬£¬£¬£¬£¬ºóÕßÏòýÌå½øÐÐÁËÆØ¹â¡£¡£¡£¡£ ¡£ÕâЩ»úÃÜÏîÄ¿Ô̺¬Ö¼ÔÚ¸ôÀë¶íÂÞ˹»¥ÁªÍøµÄNadezhdaÏîÄ¿¡¢Ö¼ÔÚÍøÂçÉ罻ýÌåÓû§ÐÅÏ¢µÄNautilusÏîÄ¿ÒÔ¼°Ö¼ÔÚ¶ÔTorÍøÂçÓû§½øÐÐÈ¥ÄäÃû»¯µÄNautilus-SÏîÄ¿µÈ¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/

2¡¢ProFTPD RCE·ì϶£¬£¬£¬£¬£¬³¬¹ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



ProFTPD°ä²¼Ð°汾1.3.6£¬£¬£¬£¬£¬½¨¸´Ò»¸ö¿Éµ¼ÖÂRCEµÄ·ì϶¡£¡£¡£¡£ ¡£¸Ã·ì϶£¨CVE-2019- 12815£©ÓëProFTPDµÄmod_copyÄ£¿ £¿ £¿£¿£¿£¿£¿£¿éÓйØ£¬£¬£¬£¬£¬·ì϶ԭÒòÊÇmod_copyÄ£¿ £¿ £¿£¿£¿£¿£¿£¿éµÄ×Ô½ç˵SITE CPFRºÍSITE CPTOºÅÁîûÓа´Ô¤ÆÚÅäÖù¤×÷¡£¡£¡£¡£ ¡£ÖÎÀíÔ±¿Éͨ¹ý½ûÓÃmod_copyÄ£¿ £¿ £¿£¿£¿£¿£¿£¿éÀ´»º½â¸Ã·ì϶¡£¡£¡£¡£ ¡£Æ¾¾ÝShodanµÄËÑË÷Á˾Ö£¬£¬£¬£¬£¬Ä¿Ç°Óг¬¹ý100Íò¸öProFTPd·þÎñÆ÷ÉÐδÉý¼¶½¨¸´²¹¶¡¡£¡£¡£¡£ ¡£µÂ¹úCERT-BundÒ²Õë¶Ô¸Ã·ì϶ÏòÓû§·¢³ö¾¯±¨¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/

3¡¢Ó¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashÒâ±íй¶260ÍòÓû§ÂòÂôÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖÓ¡¶ÈÓ×¶îÐÅ´ûÒøÐÐJana CashµÄÒ»¸öÊý¾Ý¿âδÊÜÃÜÂë±£»£» £»£»£»£»£»¤£¬£¬£¬£¬£¬µ¼ÖÂÊý°ÙÍòÓû§µÄÂòÂôÐÅÏ¢¿É±»¹«¿ª½Ó¼û¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÃô¸ÐÐÅÏ¢Ô̺¬260ÍòÓû§µÄÂòÂô¼Í¼£¬£¬£¬£¬£¬ÒÔ¼°ËûÃǵÄKYC PIIÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÇ®°üID¡¢Óû§Ãû¡¢µç×ÓÓʼþ¡¢IPµØÖ·ºÍ¶Ë±êÓïµÈ¡£¡£¡£¡£ ¡£ÔÚ×êÑÐÈËÔ±´«µÝ¸Ã¹«Ë¾ºó£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒѶÔElasticÊý¾Ý¿â½øÐб£»£» £»£»£»£»£»¤¡£¡£¡£¡£ ¡£Ä¿Ç°Éв»Ã÷ÏÔ¸ÃÊý¾Ý¿â¶³öÁ˶೤¹¦·òÒÔ¼°ÊÇ·ñÒѱ»ÆäËûÈ˽Ӽû¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://securitydiscovery.com/jana-bank-data-leak/

4¡¢RiskIQ°ä²¼2019»¥ÁªÍø·¸×ï»ã±¨£¬£¬£¬£¬£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝRiskIQµÄÊý¾Ý£¬£¬£¬£¬£¬È¥ÄêÍøÂç·¸×ï·Ö×Óÿ·ÖÖÓ¸øÈ«Çò¾­¼ÃÔì³É290ÍòÃÀÔªµÄËðʧ£¬£¬£¬£¬£¬ÕûÄê×ܼÆÔì³É1.5ÍòÒÚÃÀÔªµÄËðʧ¡£¡£¡£¡£ ¡£ÆäËüÊý¾ÝÔ̺¬£¬£¬£¬£¬£¬¼ÓÃÜÇ®±ÒÂòÂôËùÿ·ÖÖÓµÄËðʧ´ï1930ÃÀÔª£»£» £»£»£»£»£»´¹µö¹¥»÷ÿ·ÖÖÓÔì³ÉµÄËðʧ´ï17700ÃÀÔª£»£» £»£»£»£»£»2019ÄêÈ«ÇòÀÕË÷Èí¼þÊÂÎñµÄÔ¤¼Æ³É±¾ÎªÃ¿·ÖÖÓ22184ÃÀÔª£»£» £»£»£»£»£»Ã¿·ÖÖÓй¶µÄÉí·ÝÊý¾ÝÌõÊýΪ8100Ìõ£»£» £»£»£»£»£»Ã¿·ÖÖÓ¼ì²âµ½µÄ¶ñÒâ³Á¶¨ÏòΪ7¸öµÈ¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/external-threat-management/2019-evil-internet-minute/

5¡¢Ç°Î÷ÃÅ×ÓºÏͬ¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ǰÎ÷ÃÅ×ÓºÏͬ¹¤David TinleyÈÏ¿ÉÔÚΪ¹«Ë¾´´½¨µÄµç×Ó±í¸ñÖÐÖ²ÈëÂß¼­Õ¨µ¯£¬£¬£¬£¬£¬Ëû½«Ãæ¶Ô×î¸ß10ÄêµÄ½ûïÀÒÔ¼°25ÍòÃÀÔªµÄ·£¿ £¿ £¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£ ¡£Æ¾¾ÝÓйط¨Í¥Îļþ£¬£¬£¬£¬£¬TinleyΪÎ÷ÃÅ×ÓµÄMonroeville PA´¦Ê´¦ÌṩÁ˽üÊ®ÄêµÄÈí¼þ·þÎñ£¬£¬£¬£¬£¬ËûÔÚ¸ø¹«Ë¾´´½¨ÓÃÓÚÖÎÀíÉ豸¶©µ¥µÄµç×Ó±í¸ñʱֲÈëÁËÂß¼­Õ¨µ¯£¬£¬£¬£¬£¬ÕâЩըµ¯»áÔÚÌØ¶¨ÈÕÆÚ´¥·¢£¬£¬£¬£¬£¬µ¼ÖÂÎļþ±ÀÀ£¡£¡£¡£¡£ ¡£Ã¿´Î±ÀÀ£Ê±Tinley³ÇÊÐÊÕÈ¡ÓöÈÀ´½¨¸´¸ÃÎļþ£¬£¬£¬£¬£¬Ö±µ½Á½ÄêºóÎ÷ÃÅ×Ó·¢ÏÖÁËÂß¼­Õ¨µ¯²¢Ìá³öÁËÖ¸¿Ø¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/siemens-contractor-pleads-guilty-to-planting-logic-bomb-in-company-spreadsheets/