ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ41ÖÜ

°ä²¼¹¦·ò 2021-10-11

>±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼°²È«·ì϶49¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓûؾø·þÎñ·ì϶ £»£»£»£»£»Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´Ðзì϶ £»£»£»£»£»Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´Ðзì϶ £»£»£»£»£»Visual Tools DVR VX cgi-bin/slogin/login.pyºÅÁîÖ´Ðзì϶; Google chrome Safe BrowsingÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶¡£¡£ ¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇÓÉÓÚFirebaseÅäÖÃÃýÎó14¸öÀûÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢ £»£»£»£»£»Facebook·ÓÉÅäÖÃÃýÎóµ¼ÖÂÈ«ÇòÁìÓòÄÚ·þÎñÖÐ¶Ï £»£»£»£»£»Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÅäÖÃÃýÎóй¶10TBÊý¾Ý £»£»£»£»£»TwitchÒò·þÎñÆ÷ÅäÖÃÃýÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢ £»£»£»£»£»Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£ ¡£¡£¡£¡£


>³ÁÒª°²È«·ì϶Áбí


1. Apache HTTP Server HTTP/2½âÎö¿ÕÖ¸ÕëÒýÓûؾø·þÎñ·ì϶


Apache HTTP Server´æÔÚĿ¼±éÀú·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎIJ鿴ϵͳÎļþÄÚÈÝ»òÕßÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£


https://httpd.apache.org/security/vulnerabilities_24.html


2. Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´Ðзì϶


Zoho ManageEngine ADManager Plus´æÔÚËÁÒâÎļþÉÏ´«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£


https://www.manageengine.com/products/ad-manager/release-notes.html#7111


3. Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´Ðзì϶


Google Android¿ò¼Ü´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂ룬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£ ¡£¡£¡£¡£


https://source.android.com/security/bulletin/2021-10-01


4. Visual Tools DVR VX cgi-bin/slogin/login.pyºÅÁîÖ´Ðзì϶


Visual Tools DVR VX16  cgi-bin/slogin/login.py Uaer-Agent HTTP´¦ÖôæÔÚ°²È«·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£ ¡£¡£¡£¡£


https://www.exploit-db.com/exploits/50098


5. Google chrome Safe BrowsingÄÚ´æÃýÎóÒýÓôúÂëÖ´Ðзì϶


Google chrome Safe Browsing´æÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄWEBÒ³ÒªÇ󣬣¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬£¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë»òÕßʹÀûÓ÷¨Ê½±ÀÀ£¡£¡£ ¡£¡£¡£¡£


https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html


 >³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢ÓÉÓÚFirebaseÅäÖÃÃýÎó14¸öÀûÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢


9ÔÂ30ÈÕ£¬£¬£¬£¬£¬ CyberNews ×êÑÐÔ± Martynas Vareikis °ä²¼»ã±¨³Æ£¬£¬£¬£¬£¬ÓÉÓÚ Firebase Êý¾Ý¿âÅäÖÃÃýÎ󣬣¬£¬£¬£¬µ¼ÖÂÊýÒÔǧ¼ÆµÄ iOS / Android ÀûÓ÷¨Ê½Ð¹Â¶Á˳¬¹ý1.4ÒÚÌõÐÅÏ¢¡£¡£ ¡£¡£¡£¡£Firebase ÊÇ Google ÌṩµÄ¡°ºó¶Ë¼´·þÎñ¡±²úÆ·£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÁË´óÁ¿·¢·þÎñ£¬£¬£¬£¬£¬Ö¼ÔÚ·½±ãÒÆ¶¯¿ª·¢ÈËÔ±´´½¨»ùÓÚÕâЩ·þÎñµÄÒÆ¶¯»ò Web ÀûÓᣡ£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cybernews.com/security/research-popular-android-apps-with-142-5-million-collective-downloads-are-leaking-user-data/


2¡¢Facebook·ÓÉÅäÖÃÃýÎóµ¼ÖÂÈ«ÇòÁìÓòÄÚ·þÎñÖжÏ


10ÔÂ4ÈÕ£¬£¬£¬£¬£¬FacebookÆì϶à¸öƽ̨ºÍ·þÎñ£¬£¬£¬£¬£¬Ô̺¬ Facebook¡¢Instagram¡¢MessengerºÍ WhatsAppµÈ£¬£¬£¬£¬£¬Ïà¼Ì³öÏÖÑϳÁ·þÎñÖжϡ£¡£ ¡£¡£¡£¡£Óû§ÎÞ·¨µÇÈ뷨ʽ£¬£¬£¬£¬£¬·¨Ê½ÎÞ·¨Áª»úºÍ¸üУ¬£¬£¬£¬£¬Ã»·¨ÊÕ·¢ÐÅÏ¢£¬£¬£¬£¬£¬¾ÍÁ¬ÒÔ FacebookÕ˺ŵÇÈëµÄ·¨Ê½ºÍ·þÎñÒàÊܵ½ÖêÁ¬£¬£¬£¬£¬£¬²»ÄÜÕý³£µÇÈë¡£¡£ ¡£¡£¡£¡£FacebookÆäºó·¢ÉêÃ÷Ö¸£¬£¬£¬£¬£¬ÄÚ²¿Â·ÓÉÆ÷³öÏÖÎÊÌ⣬£¬£¬£¬£¬Á¬Ëø·´Ó³µ¼Ö·þÎñÈ«ÃæÖжϣ¬£¬£¬£¬£¬¹ÌÈ»·þÎñÒѻظ´£¬£¬£¬£¬£¬µ«ÄÚ²¿ÈÔÔÚÈ«Á¦¸ÄÉÆÏµÍ³£¬£¬£¬£¬£¬ÒԻظ´Õý³£¹¤×÷״̬¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/facebook-outage-caused-by-faulty-routing-configuration-changes/


3¡¢Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÅäÖÃÃýÎóй¶10TBÊý¾Ý


10ÔÂ6ÈÕ£¬£¬£¬£¬£¬×êÑÐÔ± Bob Diachenko ·¢ÏÖÁËÒ»¸öÊôÓÚÓ¢¹ú±¨Ö½¡°µçѶ±¨¡±µÄδÊܱ £»£»£»£»£»¤µÄ 10 TB Êý¾Ý¿â¡£¡£ ¡£¡£¡£¡£²»°²È«µÄÊý¾Ý¿âÓÚ9 Ô 14 ÈÕ±»·¢ÏÖ£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬ÄÚ²¿ÈÕÖ¾ºÍ¶©ÔÄÕßÐÅÏ¢¡£¡£ ¡£¡£¡£¡£Êý¾Ý´æ´¢ÔÚ¶³öµÄ Elasticsearch ¼¯ÈºÉÏ£¬£¬£¬£¬£¬´ó²¿ÃÅÊý¾Ý¶¼¾­¹ý¼ÓÃÜ£¬£¬£¬£¬£¬µ«ÖÁÉÙ 1,200 Ãû Telegraph ¶©ÔÄÕߺÍ×¢²áÕßµÄÓ×ÎÒ¾ßÌåÐÅÏ¢ÒÔ¼°´óÁ¿ÄÚ²¿·þÎñÆ÷ÈÕÖ¾¶¼ÒѾ­¹ýÃ÷È·²âÊÔ¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/123020/data-breach/the-telegraph-data-leak.html


4¡¢TwitchÒò·þÎñÆ÷ÅäÖÃÃýÎóй¶125GBÔ´´úÂëµÈÐÅÏ¢


10ÔÂ6ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ4chan¹«¿ªÁËÔ̺¬125GBÊý¾ÝµÄtorrentÁ´½Ó£¬£¬£¬£¬£¬³ÆÕâÊÇ´ÓԼĪ6000¸öÄÚ²¿Twitch Git´æ´¢¿âÖÐÇÔÈ¡µÄ£¬£¬£¬£¬£¬Ô̺¬Ô´´úÂëºÍÖ§¸¶¼Í¼µÈÐÅÏ¢¡£¡£ ¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˱êÇ©#DoBetterTwitch£¬£¬£¬£¬£¬Ö¤Ã÷Õâ´Î¹¥»÷ÊÂÎñ¿ÉÄÜÖ¼ÔÚÕë¶ÔTwitch 8Ô·ÝûÓлØÓ¦ºÍÕмܶÔÖ÷²¥µÄ¹¥»÷»î¶¯¡£¡£ ¡£¡£¡£¡£TwitchÔÚ10ÔÂ7ÈÕÈ·ÈÏÆäÊý¾Ýй¶ÊÇÓÉÓÚ·þÎñÆ÷ÅäÖÃÃýÎóµ¼Öµģ¬£¬£¬£¬£¬Ã»ÓеǼʹ´¦ºÍÐÅÓþ¿¨ºÅй¶¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/twitch-no-credentials-or-card-numbers-exposed-in-data-breach/


5¡¢Cyberint·¢ÏÖVidarÀûÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯


Cyberint·¢ÏÖ¶ñÒâÈí¼þVidarÔÚÐÂÒ»ÂÖ¹¥»÷»î¶¯Öлع顣¡£ ¡£¡£¡£¡£Vidar×Ô2018Äê10ÔÂÒÔÀ´ÆðÍ·»îÔ¾£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÖ¸±êϵͳÖÐÇÔÈ¡µç×ÓÓʼþÍ´´¦¡¢Ì¸ÌìÕÊ»§¾ßÌåÐÅÏ¢¡¢cookieµÈÊý¾Ý¡£¡£ ¡£¡£¡£¡£Õâ´Î»î¶¯ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȳÉÁ¢MastodonÕ˺ţ¬£¬£¬£¬£¬²¢ÔÚÓ×ÎÒ×ÊÁÏÃèÊö²¿ÃÅÔö³¤¶ñÒâÈí¼þʹÓõÄC2µÄIP¡£¡£ ¡£¡£¡£¡£Æä»¹Ê¹ÓÃÁËÁíÒ»ÖÖ·Ö·¢²½Ö裬£¬£¬£¬£¬Ö±½ÓÔÚÉ罻ýÌåÆ½Ì¨ÉÏ·¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬»òÕßÊÇÀûÓÃÆÆ½âÓÎÏ·µÄtorrent¡£¡£ ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2-configuration/