ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ40ÖÜ

°ä²¼¹¦·ò 2021-10-08

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ27ÈÕÖÁ10ÔÂ03ÈÕ¹²ÊÕ¼°²È«·ì϶59¸ö£¬ £¬£¬£¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇMicro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»Nagios XI repairmysql.sh²»ÕýȷȨÏÞÖ¸ÅÉ´úÂëÖ´Ðзì϶£»£»£»£»£»ECOA BAS controllerÃô¸ÐÐÅϢй¶·ì϶£»£»£»£»£»Tenda AC9 httpd»º³åÇøÒç¶Âí½Å£»£»£»£»£»Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇWindows WPBTÖеÄзì϶ӰÏìWin8¼°Ö®ºóËùÓÐϵͳ£»£»£»£»£»Å·ÖÞºô½ÐÖÐÐĹ©¸øÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷£»£»£»£»£»ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷£»£»£»£»£»Î¢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FSÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb£»£»£»£»£»CISAºÍNSA½áºÏ°ä²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ¡£¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬ £¬£¬£¬ £¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1.Micro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´Ðзì϶


Micro Focus ArcSight Enterprise Security Manager´æÔÚ°²È«·ì϶£¬ £¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£


https://portal.microfocus.com/s/article/KM000001960?language=en_US


2.Nagios XI repairmysql.sh²»ÕýȷȨÏÞÖ¸ÅÉ´úÂëÖ´Ðзì϶


Nagios XI repairmysql.sh´æÔÚ²»ÕýȷȨÏÞÖ¸ÅÉ·ì϶£¬ £¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£


https://www.nagios.com/downloads/nagios-xi/change-log/



3.ECOA BAS controllerÃô¸ÐÐÅϢй¶·ì϶


ECOA BAS controller´¦ÖÃHTTP GETÒªÇó´æÔÚ°²È«·ì϶£¬ £¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£


https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html



4.Tenda AC9 httpd»º³åÇøÒç¶Âí½Å


Tenda AC9 httpd /goform/SetStaticRouteCfg´æÔÚ»º³åÇøÒç¶Âí½Å£¬ £¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£


https://github.com/grapefruitvul/vulinfo/blob/master/tenda/vul1.md



5.Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Siemens Solid Edge SE2021 OBJÎļþ´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬ £¬£¬£¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬ £¬£¬£¬ £¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£


https://cert-portal.siemens.com/productcert/pdf/ssa-728618.pdf



 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Windows WPBTÖеÄзì϶ӰÏìWin8¼°Ö®ºóËùÓÐϵͳ


Windows WPBTÖеÄзì϶ӰÏìWin8¼°Ö®ºóËùÓÐϵͳ.jpg


Eclypsium×êÑÐÍŶӷ¢ÏÖMicrosoft Windowsƽ̨¶þ½øÔì±í(WPBT)ÖдæÔÚÒ»¸ö·ì϶£¬ £¬£¬£¬ £¬£¬£¬£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ×°ÖÃRootkit¡£¡£¡£¡£¡£¸Ã·ì϶ӰÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬ £¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂë¡£¡£¡£¡£¡£Î¢ÈíÌá³öµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÃWindows DefenderÀûÓ÷¨Ê½½ÚÔ죨WDAC£©Õ½ÊõÀ´½ÚÔìÔÚϵͳÖÐÔËÐеĶþ½øÔìÎļþ£¬ £¬£¬£¬ £¬£¬£¬£¬»òʹÓÃAppLockerÕ½ÊõÀ´½ÚÔìÔÊÐíÔËÐеÄÀûÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º


https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/



2¡¢Å·ÖÞºô½ÐÖÐÐĹ©¸øÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷


Å·ÖÞºô½ÐÖÐÐĹ©¸øÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷.jpg


Covisian½²»°È˳ƣ¬ £¬£¬£¬ £¬£¬£¬£¬ÆäÎ÷°àÑÀºÍÀ­¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§·þÎñºÍºô½ÐÖÐÐĹ©¸øÉÌÖ®Ò»£¬ £¬£¬£¬ £¬£¬£¬£¬Õâ´Î¹¥»÷µ¼ÖÂÆä´ó²¿ÃÅϵͳÖжϣ¬ £¬£¬£¬ £¬£¬£¬£¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£¡£¡£¡£¡£²»¾Ãǰ£¬ £¬£¬£¬ £¬£¬£¬£¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³Ö·þÎñ¹©¸øÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html



3¡¢ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷


ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷.jpg


ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔÚ½üÆÚÔâµ½ÁËDDoS¹¥»÷£¬ £¬£¬£¬ £¬£¬£¬£¬µ¼Ö´Óǰ¼¸ÌìÄÚÆäÔÚÈ«ÃÀµÄÓïÒô·þÎñÖжϡ£¡£¡£¡£¡£Bandwidth´ÓÃÀ¹ú¶«²¿¹¦·ò9ÔÂ25ÈÕÏÂÎç3:31ÆðÍ·»ã±¨Æäϵͳ³öÏÖ¹ÊÕÏ£¬ £¬£¬£¬ £¬£¬£¬£¬Ó°ÏìÁËÓïÒô¡¢¼ÓÇ¿ÐÍ911(E911)·þÎñ¡¢ÐÂÎÅ·¢Ëͺ͹ÙÍø½Ó¼û¡£¡£¡£¡£¡£Bandwidthδ¹«¿ª·þÎñÖжϵÄÔ­Òò£¬ £¬£¬£¬ £¬£¬£¬£¬µ«ÆäÔ±¹¤³ÆÊÇDDoS¹¥»÷µ¼Öµġ£¡£¡£¡£¡£±¾ÔÂVoIP.msÔøÔ⵽ΪÆÚÒ»ÖܵÄDDoS¹¥»÷²¢±»ÀÕË÷450ÍòÃÀÔª£¬ £¬£¬£¬ £¬£¬£¬£¬Éв»Ã÷ÏÔBandwidthÊÇ·ñÒ²Ôâµ½ÁËÀàËÆµÄÀÕË÷¹¥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bandwidthcom-is-latest-victim-of-ddos-attacks-against-voip-providers/


4¡¢Î¢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FSÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb


΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FSÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвµý±¨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁª³ÆÉí·ÝÑéÖ¤·þÎñ(AD FS)ÖÎÀíԱʹ´¦µÄºóÃÅFoggyWeb¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹±í¹úµý±¨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйأ¬ £¬£¬£¬ £¬£¬£¬£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£¡£¡£¡£¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÅäÖÃHTTP¼àÌýÆ÷£¨ÕâЩURI·ÂÕÕÁËÖ¸±êAD FSʹÓõĺϷ¨URIµÄ½á¹¹£©£¬ £¬£¬£¬ £¬£¬£¬£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÒªÇó£¬ £¬£¬£¬ £¬£¬£¬£¬²¢À¹½ØÓë×Ô½ç˵URIģʽƥÅäµÄHTTPÒªÇ󡣡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



5¡¢CISAºÍNSA½áºÏ°ä²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ


CISAºÍNSA½áºÏ°ä²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ.jpg


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕ½áºÏ°ä²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄ°²È«Ö¸ÄÏ¡£¡£¡£¡£¡£Ö¸ÄÏÖ¸³ö£¬ £¬£¬£¬ £¬£¬£¬£¬×éÖ¯Ó¦¸Ã´ÓŵÑÔÓÅÁ¼µÄ¹©¸øÉÌÄÇÀïÑ¡Ôñ²úÆ·£¬ £¬£¬£¬ £¬£¬£¬£¬ÓÉÓÚËûÃÇ»áÒÔ×î¿ìµÄËٶȽ¨¸´ÒÑÖª·ì϶¡£¡£¡£¡£¡£°²È«»ú¹¹³Æ£¬ £¬£¬£¬ £¬£¬£¬£¬VPNÉ豸Äܹ»ÍøÂçÆ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢¼õÈõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢½Ù³Ö»á»°ÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬ £¬£¬£¬ £¬£¬£¬£¬½¨Òé×éÖ¯ÅäÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐбØÒªµÄÖ°ÄÜÒÔ¼°±£»£»£»£»£»¤ºÍ¼à¿Ø¶ÔVPNµÄ½Ó¼û¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns