ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ01ÖÜ

°ä²¼¹¦·ò 2020-01-06

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2019Äê12ÔÂ30ÈÕÖÁ2020Äê01ÔÂ05ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶; Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶£»£»£»£»£»£»ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶£»£»£»£»£»£»Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶£»£»£»£»£»£»Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶ ¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©£»£»£»£»£»£»ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû£»£»£»£»£»£»ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢£»£»£»£»£»£»°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ£»£»£»£»£»£»ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³ ¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. Apache Solr VelocityÄ£°å´úÂë×¢Èë·ì϶


Apache Solr VelocityÄ£°åVelocityResponseWriter´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Í¨¹ý½ç˵һ¸ö½«¸ÃÅäÖÃÉèÖÃΪ "true" µÄÏìӦдÈëÆ÷À´ÆôÓà "parms .resource.loader. loader¡±£¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£

https://issues.apache.org/jira/browse/SOLR-13971


2. Tencent WeChatÓû§ÃûºÅÁî×¢Èë·ì϶


Tencent WeChat½âÎöusernames´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐÖ´ÐÐËÁÒâ´úÂë ¡£¡£¡£¡£¡£

https://www.zerodayinitiative.com/advisories/ZDI-19-1035/


3. ALE Alcatel-Lucent Omnivista 4760´úÂëÖ´Ðзì϶


ALE Alcatel-Lucent OmnivistaʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»SYSTEMÓû§Éí·ÝÖ´ÐдúÂë ¡£¡£¡£¡£¡£

https://packetstormsecurity.com/files/155595/Alcatel-Lucent-Omnivista-8770-Remote-Code-Execution.html


4. Nagios XI schedulereport.php SHELLºÅÁî×¢Èë·ì϶


Nagios XI schedulereport.php´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâSHELLºÅÁî ¡£¡£¡£¡£¡£

https://code610.blogspot.com/2019/12/postauth-rce-in-latest-nagiosxi.html


5. Cisco Data Center Network Manager SOAP API OSºÅÁî×¢Èë·ì϶


Cisco Data Center Network Manager SOAP API´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬ÔÊÐíͨ¹ýÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬¿É×¢ÈëËÁÒâOSºÅÁî²¢Ö´ÐÐ ¡£¡£¡£¡£¡£

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20200102-dcnm-comm-inject


>³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Nagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Nagios XIÊÇÃÀ¹úNagios¹«Ë¾µÄÒ»Ì×IT»ù´¡ÉèÊ©¼à¿Ø½â¾ö¹æ»® ¡£¡£¡£¡£¡£¸Ã¹æ»®Ö§³Ö¶ÔÀûÓᢷþÎñ¡¢²Ù×÷ϵͳµÈ½øÐÐ¼à¿ØºÍÔ¤¾¯ ¡£¡£¡£¡£¡£@Cody SixteenÔÚTwitter°ä²¼ÁËÓйØNagios XIÔ¶³ÌºÅÁîÖ´Ðзì϶£¨CVE-2019-20197£©µÄÓйØÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶ӰÏìÁËNagios XI 5.6.9°æ±¾£¬£¬£¬£¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄÓû§Äܹ»Í¨¹ýÏòschedulereport.phpÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®id¡¯²ÎÊý£¬£¬£¬£¬£¬£¬£¬ÔÚWeb·þÎñÆ÷Óû§ÕÊ»§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ²Ù×÷ϵͳºÅÁî ¡£¡£¡£¡£¡£Ä¿Ç°³§ÉÌÔÝδ°ä²¼½¨¸´´ëÊ© ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201912-1534


2¡¢ÃÀ·¨ÔºÊÚȨ΢ÈíÊÕÊܳ¯ÏÊAPT37½ÚÔìµÄ50¸öÓòÃû


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


΢Èí³É¹¦ÊÕÊÜÁËÓɳ¯ÏʺڿÍ×éÖ¯APT37½ÚÔìµÄ50¸öÓòÃû£¬£¬£¬£¬£¬£¬£¬ÕâЩÓòÃû±»¸Ã×éÖ¯ÓÃÀ´ÌáÒéÍøÂç¹¥»÷£¬£¬£¬£¬£¬£¬£¬Ô̺¬·¢ËÍ´¹µöÓʼþºÍÍйܴ¹µöÒ³ÃæµÈ ¡£¡£¡£¡£¡£Î¢Èí°µÊ¾ÆäÊý×Ö·¸×ﲿÃÅ£¨DCU£©ºÍÍþвµý±¨ÖÐÐÄ£¨MSTIC£©ÒѾ­¼à¶½APT37³¤´ïÊýԵŦ·ò£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ12ÔÂ18ÈÕÔÚ¸¥¼ªÄáÑÇÖÝ·¨Ôº¶Ô¸Ã×éÖ¯Ìá¸æ×´ËÏ ¡£¡£¡£¡£¡£¸Ã·¨ÔºÊÚÓè΢ÈíȨÏÞÒÔÊÕÊÜAPT37ÔÚ·¸×ï»î¶¯ÖÐʹÓõÄ50¸öÓòÃû ¡£¡£¡£¡£¡£Î¢Èí¸ß¹Ü°µÊ¾¸Ã×éÖ¯µÄ´óÎÞÊýÖ¸±ê¶¼Î»ÓÚÃÀ¹ú¡¢ÈÕ±¾ÒÔ¼°º«¹ú ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/microsoft-takes-down-50-domains-operated-by-north-korean-hackers/


3¡¢ÎïÁªÍø¹©¸øÉÌWyzeÒâ±íй¶Լ240Íò¿Í»§ÐÅÏ¢


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÎïÁªÍø¹©¸øÉÌWyzeÈ·ÈÏÆäÒ»¸öElasticsearch·þÎñÆ÷й¶ÁËÔ¼240ÍòÓû§µÄ¾ßÌåÐÅÏ¢ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â²¢²»Êdzö²úϵͳ£¬£¬£¬£¬£¬£¬£¬µ«´æ´¢ÁËÓÐЧµÄÓû§Êý¾Ý£¬£¬£¬£¬£¬£¬£¬Ô̺¬ÓÃÓÚ´´½¨WyzeÕÊ»§µÄµç×ÓÓʼþµØÖ·¡¢·ÖÅ䏸ÆäWyze°²È«ÉãÏñ»úµÄÓû§êdzơ¢WiFiÍøÂç±êʶ·ûSSIDÒÔ¼°2.4ÍòÓû§µÄAlexaÁîÅÆµÈ ¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÓÚ12ÔÂ4ÈÕ±»ÃýÎóµØÂ¶³öÔÚ¹«ÍøÉÏ£¬£¬£¬£¬£¬£¬£¬°²È«¹«Ë¾Twelve SecurityÓÚ12ÔÂ26ÈÕ·¢ÏÖÁ˸ÃÊý¾Ý¿â²¢Í¨ÖªÁËWyze£¬£¬£¬£¬£¬£¬£¬WyzeËæºó¶ÔÊý¾Ý¿â½øÐÐÁ˱£»£»£»£»£»£»¤ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/iot-vendor-wyze-confirms-server-leak/


4¡¢°®¶ûÀ¼µ±¾Ö°ä²¼2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°®¶ûÀ¼µ±¾Ö°ä²¼ÁË¡¶2019-2024¹ú¶ÈÍøÂ簲ȫսÊõ¡·£¬£¬£¬£¬£¬£¬£¬ÕâÊǸùúÓÚ2015Äê°ä²¼µÄÊ׸ö°²È«Õ½ÊõµÄ¸üа汾 ¡£¡£¡£¡£¡£¸ÃÕ½Êõ»ã±¨¸ÅÊöÁ˵±¾Ö½«ÈôºÎ³ÖÐøÍÆ½ø¸Ã¹úÍÆËã»úÍøÂçºÍÓйػù´¡ÉèÊ©µÄ°²È« ¡£¡£¡£¡£¡£»ã±¨ÖвûÁËÈ»µ±¾Ö¶Ô°²È«ºÍ¿¿µÃסµÄÍøÂç¿Õ¼äµÄÔ¸¾°ÒÔ¼°½«²ÉÈ¡µÄÐж¯£¬£¬£¬£¬£¬£¬£¬Ô̺¬³ÖÐøÌá¸ß¹Ø¼ü»ù´¡¼Ü¹¹ºÍ¹«¹²·þÎñÖеÄÍøÂ絯ÐÔ£»£»£»£»£»£»Ìá¸ßÆóÒµºÍ¹«Ãñ¶ÔÍøÂ簲ȫ³ÁÒªÐÔµÄÒâʶ£»£»£»£»£»£»Í¨¹ýÓë½ÌÓýϵͳ¡¢ÐÐÒµºÍѧÊõ½çµÄºÏ×÷£¬£¬£¬£¬£¬£¬£¬½øÒ»²½·¢Õ¹È«Éç»áµÄÍøÂ簲ȫÎÄ»¯£»£»£»£»£»£»³ÖÐø¼áÈͰ®¶ûÀ¼×÷Ϊ¼¼ÊõºÍÐÅÏ¢°²È«ÖÐÐĵÄÈ«ÇòÃûÓþ£¬£¬£¬£¬£¬£¬£¬²¢Ô®ÊÖÍÆ½ø°®¶ûÀ¼³ÉΪICTÆóÒµµÄÊ×Ñ¡µØÖ· ¡£¡£¡£¡£¡£¸Ã»ã±¨»¹¶½ÍƽøÐж¦ÐÂÒÔ±£»£»£»£»£»£»¤¹Ø¼ü»ù´¡¼Ü¹¹ÃâÊܳÁ´óÍøÂçÍþвµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬Í¬Ê±»¹ÖÒ¸æ³Æ±í¹ú¿ÉÄÜ»á¹ýÎʰ®¶ûÀ¼µÄÑ¡¾Ù ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95825/laws-and-regulations/irish-national-cyber-security-strategy.html


5¡¢ÐǰͿËÔ±¹¤ÉÏ´«APIÃÜÔ¿µ½GitHubÉÏ£¬£¬£¬£¬£¬£¬£¬¿É½Ó¼ûÄÚ²¿ÏµÍ³


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×¨¼ÒVinoth KumarÔÚÒ»¸ö¹«¿ª¿ÉÓõÄGithub´æ´¢¿âÖз¢ÏÖÐǰͿ˵ÄÒ»¸öAPIÃÜÔ¿ÔÚÏß¶³ö£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀûÓøÃÃÜÔ¿À´½Ó¼û¹«Ë¾µÄÄÚ²¿ÏµÍ³²¢´Û¸ÄÊÚȨÓû§ÁÐ±í ¡£¡£¡£¡£¡£¸ÃÃÜÔ¿¿ÉÓÃÓÚ½Ó¼ûÐǰͿËJumpCloud API£¬£¬£¬£¬£¬£¬£¬JumpCloudÊÇÒ»¸öActive DirectoryÖÎÀíÆ½Ì¨£¬£¬£¬£¬£¬£¬£¬ÌṩÓû§ÖÎÀí¡¢WebÀûÓ÷¨Ê½µ¥µãµÇ¼£¨SSO£©½Ó¼û½ÚÔìºÍÇáÐÍĿ¼½Ó¼ûºÍ̸£¨LDAP£©·þÎñ ¡£¡£¡£¡£¡£Kumar»¹ÌṩÁ˸ÃÎÊÌâµÄPoC´úÂ룬£¬£¬£¬£¬£¬£¬ÑÝʾÁËÈôºÎÁгöϵͳºÍÓû§¡¢½ÚÔìAWSÕÊ»§¡¢ÔÚϵͳÉÏÖ´ÐкÅÁîÒÔ¼°Ôö³¤»òɾ³ýÓÐȨ½Ó¼ûÄÚ²¿ÏµÍ³µÄÓû§ ¡£¡£¡£¡£¡£ÐǰͿËÈ·ÈÏÁËÕâÒ»ÎÊÌⲢѸËÙ³·ÏúÁ˸ÃÃÜÔ¿ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95826/security/starbucks-api-key-exposed-online.html