ÐÅÏ¢°²È«Öܱ¨-2020ÄêµÚ47ÖÜ

°ä²¼¹¦·ò 2020-11-23

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼°²È«·ì϶61¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶£» £»£»£»£»Google Go CVE-2020-28366´úÂë×¢Èë·ì϶£» £»£»£»£»Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å£» £»£»£»£»QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶£» £»£»£»£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å ¡£¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊǺڿÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢£» £»£»£»£»Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨£» £»£»£»£»Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨£» £»£»£»£»Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻 £»£»£»£»×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢ ¡£¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÐ ¡£¡£¡£¡£¡£¡£


³ÁÒª°²È«·ì϶Áбí


1.Aviatrix Systems Controller APIËÁÒâÎļþÖ´Ðзì϶


Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ´æÔÚδÊÚȨ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐдúÂë ¡£¡£¡£¡£¡£¡£

https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/


2.Google Go CVE-2020-28366´úÂë×¢Èë·ì϶


Google Go´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É×¢Èë´úÂë²¢ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐ ¡£¡£¡£¡£¡£¡£

https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html



3.Paradox IP150 CVE-2020-25189»º³åÇøÒç¶Âí½Å


Paradox IP150´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£ ¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02


4.QNAP QTS CVE-2020-2492ºÅÁî×¢Èë·ì϶


QNAP QTS´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâºÅÁî ¡£¡£¡£¡£¡£¡£

https://www.qnap.com/en/security-advisory/qsa-20-09


5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç¶Âí½Å


Real Time Automation 499ES EtherNet/IP´æÔÚÕ»»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òʹÀûÓ÷¨Ê½±ÀÀ£ ¡£¡£¡£¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ºÚ¿ÍÔÚ°µÍø¹«¿ª320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍø¹«¿ªÁËÔ̺¬320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â ¡£¡£¡£¡£¡£¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬£¬£¬£¬£¬Ð¹Â¶Êý¾ÝÔ̺¬Óû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ· ¡£¡£¡£¡£¡£¡£ºÚ¿ÍÐû³ÆÕâ´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬£¬£¬£¬£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬£¬£¬£¬£¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ ¡£¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬£¬Pluto TVÉÐδ֤ʵÊÇ·ñ²úÉúÁËÊý¾Ýй¶£¬£¬£¬£¬£¬½ö°µÊ¾ËûÃÇÔÚµ÷²éÖÐ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2¡¢Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨


2.png


Snow Software°ä²¼2021ÄêÓйØITÖÎÀíµÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼ÊõÖÎÀí±äµÃÔ½À´Ô½ÄÑÌ⣬£¬£¬£¬£¬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö³¤ ¡£¡£¡£¡£¡£¡£87£¥µÄIT¸¨µ¼Õß°µÊ¾£¬£¬£¬£¬£¬´ÓǰһÄêÖÐËûÃÇÒѾ­¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©¸øÉ̵ÄÉ󼯣¬£¬£¬£¬£¬Ö»ÓÐ51£¥µÄÈ˲»°²ÏÂÒ»ÄêµÄÉó¼Æ ¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬×³´óµÄ¼¼Êõµý±¨Ê¹IT¸¨µ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×Òª¹¤×÷£¬£¬£¬£¬£¬µ«Ö»ÓÐ14%µÄIT¸¨µ¼Õß´ïµ½Á˳ÉÊì¼¼ÊõÖÇÄÜµÄ³ß¶È ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report


3¡¢Intel 471°ä²¼°µÍøÖÐ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨


3.png


Intel 471°ä²¼ÁËÓйذµÍøÖеÄ25ÖÖÖØÒªRaaS²úÆ·µÄ·ÖÎö»ã±¨ ¡£¡£¡£¡£¡£¡£Intel 471°µÊ¾£¬£¬£¬£¬£¬Ëüƾ¾ÝRaaSµÄ¸´ÔÓˮƽ¡¢Ö°Äܺͺ¹ÇཫÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öµµ´Î ¡£¡£¡£¡£¡£¡£µÚÒ»²ãΪµ±½ñ×î³ÛÃûµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬Ô̺¬REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk ¡£¡£¡£¡£¡£¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬£¬£¬£¬£¬Ô̺¬Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos ¡£¡£¡£¡£¡£¡£µÚÈý²ãΪа䲼µÄRaaS²úÆ·£¬£¬£¬£¬£¬Ô̺¬CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


4¡¢Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁé


4.png


±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£ÖжÏ£¬£¬£¬£¬£¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé ¡£¡£¡£¡£¡£¡£ÖܶþÁ賿£¬£¬£¬£¬£¬¹È¸è×ܲ¿°ä²¼ÐÂÎųÆ£¬£¬£¬£¬£¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÀûÓà ¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬£¬£¬£¬£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úÅÔ¹ÛÊÓÆµÖ±²¥£¬£¬£¬£¬£¬ÎÞ·¨µ÷ÕûºãνÚÔìÆ÷£¬£¬£¬£¬£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬£¬£¬£¬£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó ¡£¡£¡£¡£¡£¡£Æäʵ£¬£¬£¬£¬£¬¸Ã·þÎñÔÚ2ÔÂÒ²²úÉúÁËÀàËÆµÄÖжÏ£¬£¬£¬£¬£¬³ÖÐøÁË16¸öÓ×ʱ ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/11/17/google_nest_outage/


5¡¢×êÑÐÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢


5.png


Palo Alto Networks×êÑÐÈËÔ±·¢ÏÖÁË16¸ö·ÖÆçAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬£¬£¬£¬£¬¿É±»ÀÄÓÃÀ´»ñÊØÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»á×Ô¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄÕ½ÊõËùµ¼Ö嵀 ¡£¡£¡£¡£¡£¡£ÈôÊÇÕ½ÊõÖÐÔ̺¬²»´æÔÚµÄÉí·Ý£¬£¬£¬£¬£¬Ôò´´½¨»ò¸üÐÂÕ½ÊõµÄAPIŲÓý«Ê§°Ü£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÀÄÓôËÖ°ÄÜÀ´²é³­AWSÕË»§ÖеÄÏÖÓÐÉí·Ý ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±³Æ£¬£¬£¬£¬£¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϽøÐУ¬£¬£¬£¬£¬Ò×Êܹ¥»÷µÄAWS·þÎñÔ̺¬AWS S3¡¢AWS KMSºÍAWS SQS ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data