ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ36ÖÜ
°ä²¼¹¦·ò 2019-09-16> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2019Äê9ÔÂ09ÈÕÖÁ13ÈÕ¹²ÊÕ¼°²È«·ì϶48¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶£»£»£»£»£»£»Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶£»£»£»£»£»£»Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶£»£»£»£»£»£»Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇDealer LeadsÒâ±íй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼£»£»£»£»£»£»ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý£»£»£»£»£»£»ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å£»£»£»£»£»£»ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô£»£»£»£»£»£»Telestar±»ÆØTelnetºóÃÅ·ì϶ӰÏì100¶àÍòIoTÉ豸¡£¡£¡£¡£¡£¡£
> ³ÁÒª°²È«·ì϶Áбí
1. Dabman & Imperial Web Radio Devices telnetºóÃÅ·ì϶
https://packetstormsecurity.com/files/154416/Dabman-And-Imperial-Web-Radio-Devices-Undocumented-Telnet-Backdoor.html
2. Exim³õʼTLSÎÕÊÖËÁÒâ´úÂëÖ´Ðзì϶
https://www.kb.cert.org/vuls/id/672565/
3. Apache OFBiz template×¢Èë´úÂëÖ´Ðзì϶
https://www.auscert.org.au/bulletins/ESB-2019.3469/
4. Adobe Flash Player PSDKÄÚ´æÃýÎóÒýÓ÷ì϶
https://www.zerodayinitiative.com/advisories/ZDI-19-818/
5. Microsoft OfficeÄÚ´æ·ÛËé´úÂëÖ´Ðзì϶
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-1264
> ³ÁÒª°²È«ÊÂÎñ×ÛÊö
Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë±£»£»£»£»£»£»¤£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉ϶³ö¡£¡£¡£¡£¡£¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÖ¸±êÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬°²È«×êÑÐÔ±Jeremiah Fowler°µÊ¾ÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µ×êÑÐÐÅÏ¢ºÍ·ÖÀà¸æ°×£¬£¬£¬£¬£¬£¬£¬£¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý¡£¡£¡£¡£¡£¡£¸Ã¶³öµÄÊý¾Ý¿â×ܹ²Ô̺¬413GBÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢IPµØÖ·ÒÔ¼°´û¿îºÍ²ÆÕþÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/198m-car-buyer-records-exposed-online/148231/
2¡¢ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý
×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖеIJàÐÅ·¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´Ôì×÷µÄËùÓÐÏÖ´úÓ¢ÌØ¶û·þÎñÆ÷´¦ÖÃÆ÷¡£¡£¡£¡£¡£¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬£¬£¬£¬£¬£¬£¬£¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/O¼¼Êõ£¨DDIO£©Óйأ¬£¬£¬£¬£¬£¬£¬£¬DDIOÔÚ×îеÄÓ¢ÌØ¶û·þÎñÆ÷¼¶´¦ÖÃÆ÷ÖÐĬÈÏ´ò¿ª£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬Intel Xeon E5¡¢E7ºÍSP´¦ÖÃÆ÷ϵÁС£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-11184£©µÄÀûÓÃÄѶȽϸߣ¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ±ØÒªÓëÖ¸±êϵͳ³ÉÁ¢Ö±½ÓÍøÂçÏνӡ£¡£¡£¡£¡£¡£Ó¢Ìضû½«¸Ã·ì϶µÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬£¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMAÖ°ÄÜ£¬£¬£¬£¬£¬£¬£¬£¬»òÏÞ¶È´Ó±í²¿²»ÊÜÐÅÀµµÄÍøÂçÖ±½Ó½Ó¼ûÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£¡£¶î±íµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÿÉÄֿܵ¹°´Ê±¹¥»÷µÄÈí¼þÄ£¿£¿£¿£¿£¿é»òʹÓú㰴¹¦·òÐÎ×´µÄ´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/netcat-intel-side-channel.html
3¡¢ÃÀ¹ú¹ú¶È³ß¶ÈÓë¼¼Êõ×êÑÐÔº°ä²¼ÒþÖÔ¿ò¼Ü³õ¸å
ÔÎÄÁ´½Ó£º
https://www.executivegov.com/2019/09/nist-issues-preliminary-draft-of-privacy-framework/4¡¢ºÚ¿ÍÀûÓÃDoS·ì϶µ¼ÖÂÃÀ¹úµçÍø·À»ðǽ·´¸´³ÁÆô
±±ÃÀµçÁ¦¿¿µÃסÐÔ¹«Ë¾£¨NERC£©ÉÏÖܰµÊ¾½ñÄêÔçЩʱ³½Ó°ÏìÃÀ¹úµçÍøÊµÌåµÄÍøÂ簲ȫÊÂÎñ²¢Ã»ÓÐ×î³õÉèÏëµÄÄÇÑùΣÏÕ¡£¡£¡£¡£¡£¡£NERCÔÚÒ»·Ý»ã±¨ÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ2019Äê3ÔÂ5ÈÕÀûÓÃDoS·ì϶µ¼ÖµçÍø·À»ðǽÔÚ10Ó×ʱÄÚ·´¸´³ÁÆô£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÖ»Ó°ÏìÁËһЩµÍÓ°Ïì¼¶·¢µçÕ¾µãµÄÍøÂç±íΧ·À»ðǽ£¬£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓÐÔì³ÉµçÁ¦¹©¸øµÄÈκÎÖжϡ£¡£¡£¡£¡£¡£ËæºóµÄ·ÖÎöÈ·¶¨³ÁÆôÊÇÓÉÀûÓÃÒÑÖª·À»ðǽ·ì϶µÄ±í²¿ÊµÌåÌáÒéµÄ£¬£¬£¬£¬£¬£¬£¬£¬ÔËÓªÉÌ×îÖÕ·¢ÏÖËûÃÇδÄÜΪÊܵ½¹¥»÷µÄ·À»ðǽÀûÓù̼þ¸üУ¬£¬£¬£¬£¬£¬£¬£¬ÔÚ²Ù×÷Ô±²¿ÊðÊʵ±µÄ²¹¶¡ºó£¬£¬£¬£¬£¬£¬£¬£¬·À»ðǽ²»ÔÙ³ÁÆô¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/cyber-security-incident-at-us-power-grid-entity-linked-to-unpatched-firewalls/
https://www.zdnet.com/article/critical-vulnerabilities-impact-over-a-million-iot-radio-devices/


¾©¹«Íø°²±¸11010802024551ºÅ