ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ47ÖÜ

Ðû²¼Ê±¼ä 2020-11-23

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼Çå¾²Îó²î61¸ö£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIí§ÒâÎļþÖ´ÐÐÎó²î£»£»£»£»£»Google Go CVE-2020-28366´úÂë×¢ÈëÎó²î£»£»£»£»£»Paradox IP150 CVE-2020-25189»º³åÇøÒç³öÎó²î£»£»£»£»£»QNAP QTS CVE-2020-2492ÏÂÁî×¢ÈëÎó²î£»£»£»£»£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç³öÎó²î¡£¡£ ¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǺڿÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»£»£»£»£»Snow SoftwareÐû²¼2021ÄêÓйØITÖÎÀíµÄÆÊÎö±¨¸æ£»£»£»£»£»Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ£»£»£»£»£»Google NestЧÀÍÖÐÖ¹µ¼ÖÂÎ÷Å·Óû§ÖÇÄܼҾÓʧÁ飻£»£»£»£»Ñо¿Ö°Ô±·¢Ã÷ÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢¡£¡£ ¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1.Aviatrix Systems Controller APIí§ÒâÎļþÖ´ÐÐÎó²î


Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ±£´æÎ´ÊÚȨÎó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐдúÂë¡£¡£ ¡£¡£¡£

https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/


2.Google Go CVE-2020-28366´úÂë×¢ÈëÎó²î


Google Go±£´æÇå¾²Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿É×¢Èë´úÂë²¢ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐС£¡£ ¡£¡£¡£

https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html



3.Paradox IP150 CVE-2020-25189»º³åÇøÒç³öÎó²î


Paradox IP150±£´æÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë»òʹӦÓóÌÐòÍ߽⡣¡£ ¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02


4.QNAP QTS CVE-2020-2492ÏÂÁî×¢ÈëÎó²î


QNAP QTS±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£¡£¡£

https://www.qnap.com/en/security-advisory/qsa-20-09


5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç³öÎó²î


Real Time Automation 499ES EtherNet/IP±£´æÕ»»º³åÇøÒç³öÎó²î£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë»òʹӦÓóÌÐòÍ߽⡣¡£ ¡£¡£¡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ºÚ¿ÍÔÚ°µÍø¹ûÕæ320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬£¬£¬ £¬ºÚ¿ÍÔÚ°µÍø¹ûÕæÁ˰üÀ¨320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â¡£¡£ ¡£¡£¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬£¬£¬ £¬Ð¹Â¶Êý¾Ý°üÀ¨Óû§Ãû¡¢µç×ÓÓʼþµØµã¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢×°±¸Æ½Ì¨ºÍIPµØµã¡£¡£ ¡£¡£¡£ºÚ¿ÍÉù³Æ´Ë´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬£¬£¬ £¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰй¶µÄ£¬£¬£¬ £¬×îмͼÊÇÔÚ2018Äê10ÔÂ12ÈÕ½¨ÉèµÄ¡£¡£ ¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬Pluto TVÉÐδ֤ʵÊÇ·ñ±¬·¢ÁËÊý¾Ýй¶£¬£¬£¬ £¬½öÌåÏÖËûÃÇÕýÔÚÊÓ²ìÖС£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2¡¢Snow SoftwareÐû²¼2021ÄêÓйØITÖÎÀíµÄÆÊÎö±¨¸æ


2.png


Snow SoftwareÐû²¼2021ÄêÓйØITÖÎÀíµÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£±¨¸æÏÔʾ£¬£¬£¬ £¬63£¥µÄÊÜ·ÃÕß³ÆÊÖÒÕÖÎÀí±äµÃÔ½À´Ô½ÄÑÌ⣬£¬£¬ £¬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵÄÊÖÒÕÖ§³öÖÜÈ«ÔöÌí¡£¡£ ¡£¡£¡£87£¥µÄITÏòµ¼ÕßÌåÏÖ£¬£¬£¬ £¬ÒÑÍùÒ»ÄêÖÐËûÃÇÒѾ­ÓÉMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©Ó¦É̵ÄÉ󼯣¬£¬£¬ £¬Ö»ÓÐ51£¥µÄÈ˵£ÐÄÏÂÒ»ÄêµÄÉ󼯡£¡£ ¡£¡£¡£±ðµÄ£¬£¬£¬ £¬Ç¿Ê¢µÄÊÖÒÕÇ鱨ʹITÏòµ¼ÕßÄܸüÓÐÓõؽâ¾öËûÃǵÄÖ÷ҪʹÃü£¬£¬£¬ £¬µ«Ö»ÓÐ14%µÄITÏòµ¼ÕßµÖ´ïÁ˳ÉÊìÊÖÒÕÖÇÄܵıê×¼¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report


3¡¢Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ


3.png


Intel 471Ðû²¼ÁËÓйذµÍøÖеÄ25ÖÖÖ÷ÒªRaaS²úÆ·µÄÆÊÎö±¨¸æ¡£¡£ ¡£¡£¡£Intel 471ÌåÏÖ£¬£¬£¬ £¬Ëüƾ֤RaaSµÄÅÓºéˮƽ¡¢¹¦Ð§ºÍÀúÊ·½«ÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öÌõÀí¡£¡£ ¡£¡£¡£µÚÒ»²ãΪµ±½ñ×îÖøÃûµÄÀÕË÷Èí¼þ£¬£¬£¬ £¬°üÀ¨REvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk¡£¡£ ¡£¡£¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÌìϵÄÐÂÐË´ú±í£¬£¬£¬ £¬°üÀ¨Avaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos¡£¡£ ¡£¡£¡£µÚÈý²ãΪÐÂÐû²¼µÄRaaS²úÆ·£¬£¬£¬ £¬°üÀ¨CVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


4¡¢Google NestЧÀÍÖÐÖ¹µ¼ÖÂÎ÷Å·Óû§ÖÇÄܼҾÓʧÁé


4.png


±¾ÖܶþGoogle NestЧÀÍ´ó¹æÄ£ÖÐÖ¹£¬£¬£¬ £¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé¡£¡£ ¡£¡£¡£ÖܶþÆÆÏþ£¬£¬£¬ £¬¹È¸è×ܲ¿Ðû²¼ÐÂÎųÆ£¬£¬£¬ £¬Æä·¢Ã÷Ò»¸öÎÊÌâ»áÓ°Ïì¹È¸èNest×°±¸ºÍNestÓ¦Óᣡ£ ¡£¡£¡£¸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬£¬£¬ £¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úԢĿÊÓÆµÖ±²¥£¬£¬£¬ £¬ÎÞ·¨µ÷½âºãοØÖÆÆ÷£¬£¬£¬ £¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÆ·»¥¶¯£¬£¬£¬ £¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó¡£¡£ ¡£¡£¡£×Åʵ£¬£¬£¬ £¬¸ÃЧÀÍÔÚ2ÔÂÒ²±¬·¢ÁËÀàËÆµÄÖÐÖ¹£¬£¬£¬ £¬Ò»Á¬ÁË16¸öСʱ¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/11/17/google_nest_outage/


5¡¢Ñо¿Ö°Ô±·¢Ã÷ÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÊØÐÅÏ¢


5.png


Palo Alto NetworksÑо¿Ö°Ô±·¢Ã÷ÁË16¸ö²î±ðAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬£¬£¬ £¬¿É±»ÀÄÓÃÀ´»ñÊØÐÅÏ¢¡£¡£ ¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»á×Ô¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄÕ½ÂÔËùµ¼ÖµÄ¡£¡£ ¡£¡£¡£ÈôÊÇÕ½ÂÔÖаüÀ¨²»±£´æµÄÉí·Ý£¬£¬£¬ £¬Ôò½¨Éè»ò¸üÐÂÕ½ÂÔµÄAPIŲÓý«Ê§°Ü£¬£¬£¬ £¬¹¥»÷Õß¿ÉÒÔÀÄÓô˹¦Ð§À´¼ì²éAWSÕË»§ÖеÄÏÖÓÐÉí·Ý¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±³Æ£¬£¬£¬ £¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϾÙÐУ¬£¬£¬ £¬Ò×Êܹ¥»÷µÄAWSЧÀͰüÀ¨AWS S3¡¢AWS KMSºÍAWS SQS¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data