ʨ×Óº½¿Õ¹«Ë¾ÊýÍòÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶£»£»£»£»£»£»£»Ñо¿Ö°Ô±ÔÚ13¿î·ÓÉÆ÷ºÍNAS×°±¸Öз¢Ã÷125¸öÎó²î
Ðû²¼Ê±¼ä 2019-09-181.Ñо¿Ö°Ô±ÔÚ13¿î·ÓÉÆ÷ºÍNAS×°±¸Öз¢Ã÷125¸öÎó²î
Ñо¿Ö°Ô±ÔÚ13¿îSOHO·ÓÉÆ÷ºÍNAS×°±¸Öз¢Ã÷125¸öÐÂÎó²î£¬£¬£¬¸ÃÑо¿ÊÇSOHOpelessly Broken 2.0ÏîÄ¿µÄÒ»²¿·Ö¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷µÄÎó²îÇåµ¥°üÀ¨ÊÚÈ¨ÈÆ¹ý¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢»º³åÇøÒç³ö¡¢ÏÂÁî×¢Èë¡¢SQL×¢È루SQLi£©¡¢XSS¡¢CSRFºÍ·¾¶±éÀúÎó²î¡£¡£¡£ÊÜÓ°ÏìµÄÆ·ÅÆ°üÀ¨Buffalo¡¢ÈºêÍ¡¢TerraMaster¡¢Zyxel¡¢Drobo¡¢»ªË¶¼°Æä×ÓÆ·ÅÆAsustor¡¢Ï£½Ý¡¢QNAP¡¢åÚÏë¡¢Íø¼þ¡¢Ð¡Ã׺ÍZioncom£¨TOTOLINK£©¡£¡£¡£Ñо¿Ö°Ô±ÏòÊÜÓ°ÏìµÄ¹©Ó¦ÉÌÅû¶ÁËÕâЩÎó²î£¬£¬£¬´ó´ó¶¼¹©Ó¦ÉÌѸËÙ»ØÓ¦²¢ÐÞ¸´ÁËÎó²î£¬£¬£¬µ«Drobo¡¢BuffaloºÍZioncomÉÐδ¾ÙÐлØÓ¦¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/hacking-soho-routers.html
2.3S-SmartÐÞ¸´CODESYS¹¤Òµ²úÆ·ÖеĶà¸öÎó²î
ÃÀ¹úCISAÐû²¼Á˹ØÓڵ¹ú3S-Smart³§ÉÌÖÆÔìµÄCODESYS¹¤Òµ²úÆ·Öжà¸öÎó²îµÄÇå¾²×Éѯ£¬£¬£¬ÆäÖÐÐí¶àÎó²î¿É±»ÓÃÓÚÌᳫԶ³Ì´úÂëÖ´ÐС¢DoS¹¥»÷µÈ¡£¡£¡£ÊÜÓ°ÏìµÄÈí¼þ±»Ðí¶àµÚÈý·½¹©Ó¦ÉÌÓÃÓÚÊý°ÙÖÖ¹¤Òµ²úÆ·ÖС£¡£¡£Îó²î°üÀ¨CODESYS ENIЧÀÍÆ÷ÖеĻº³åÇøÒç³öÎó²î£¬£¬£¬¸ÃÎó²î¿É±»µÍÊÖÒÕˮƽµÄ¹¥»÷ÕßÔ¶³ÌʹÓÃÒÔÌᳫ´úÂëÖ´ÐлòDoS¹¥»÷£»£»£»£»£»£»£»CODESYS V3×Ô¶¯»¯Æ½Ì¨µÄÍø¹Ø×é¼þÖеÄDoSÎó²î£»£»£»£»£»£»£»WebЧÀÍÆ÷×é¼þÖеĿÉÓÃÓÚ»á¼ûÎļþ¡¢´¥·¢Ð§ÀÍÆ÷±ÀÀ£»£»£»£»£»£»£»òÖ´ÐÐí§Òâ´úÂëµÄÎó²îµÈ¡£¡£¡£3S-SmartÌåÏÖÉÐδ·¢Ã÷ÈκÎÕë¶ÔÕâЩÎó²îµÄ¹ûÕæÊ¹Ó㬣¬£¬µ«ÖÁÉÙÓÐÒ»¸öÇå¾²Îó²îÓÐ×ã¹»µÄ¹ûÕæÐÅÏ¢¿ÉÓÃÓÚ¿ª·¢Îó²îʹÓᣡ£¡£ËùÓÐÎó²î¶¼ÒÑͨ¹ýÈí¼þ¸üоÙÐÐÐÞ¸´£¬£¬£¬Ö»ÓÐÒ»¸öÎó²îÔ¤¼Æ½«ÔÚ2020Äê2Ô¸üÐÂÐÞ¸´¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/serious-flaws-codesys-products-expose-industrial-systems-remote-attacks
3.ʨ×Óº½¿Õ¹«Ë¾ÊýÍòÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶
ʨ×Óº½¿ÕÆìÏÂÁ½¼Òº½¿Õ¹«Ë¾µÄÊýÍòÍòÌõÓοͼͼÔÚ°µÍøÂÛ̳ÉÏй¶¡£¡£¡£ÕâЩÊý¾Ý´æ´¢ÔڿɹûÕæ»á¼ûµÄAmazon´æ´¢Í°ÖУ¬£¬£¬¹²ÓÐÁ½¸öÊý¾Ý¿â£¬£¬£¬Ò»¸ö°üÀ¨2100ÍòÌõ¼Í¼£¬£¬£¬ÁíÒ»¸ö°üÀ¨1400ÍòÌõ¼Í¼£¬£¬£¬¸ÃĿ¼Ï»¹°üÀ¨2019Äê5Ô·ݽ¨ÉèµÄ±¸·ÝÎļþ£¬£¬£¬Ö÷ÒªÊôÓÚMalindo AirºÍThai Lion Air¡£¡£¡£ÁíÒ»¸ö±¸·ÝÎļþµÄÃû³ÆÊÇBatik Air£¬£¬£¬¸Ã¹«Ë¾µÄĸ¹«Ë¾Ò²ÊÇʨ×Óº½¿Õ¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨Óο͵ÄÔ¤¶©ID¡¢ÆÜÉíµØµã¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£ÏÖÔÚ»¹²»ÇåÎúÕâЩÊý¾ÝÊ×´Îй¶µÄʱ¼ä£¬£¬£¬µ«¾Ý³ÆÖÁÉÙ´Ó8ÔÂ10ÈÕÆð¸ÃÊý¾Ý¿âÒÑÔÚÂÛ̳ÉÏÁ÷ͨ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-lion-air-passenger-records-exposed-and-exchanged-on-forums/
4.ÊýǧÃûÓû§µÄ¹È¸èÈÕÀúÒòÉèÖùýʧ̻¶Ãô¸ÐÐÅÏ¢
Ó¡¶ÈÇå¾²Ñо¿Ô±Avinash Jain·¢Ã÷ÊýÒÔǧ¼ÆµÄ¹È¸èÓû§ÒâÍâ¹ûÕæÁËÆä¹È¸èÈÕÀú£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¸ÃÎÊÌâÊÇÓɹýʧÉèÖõĹȸèÈÕÀúµ¼Öµģ¬£¬£¬¿É¹ûÕæ»á¼ûÒâζ×Å¿Éͨ¹ý¹«¹²ÒýÇæ¾ÙÐÐËÑË÷£¨°üÀ¨¹È¸è£©£¬£¬£¬ÔÊÐíÈκÎÈË»á¼ûÆäÖеÄÒþ˽»òÊÇʹÓöñÒâÐÅÏ¢»òÁ´½ÓÌí¼ÓÐÂÊÂÎñ¡£¡£¡£Jain·¢Ã÷ÓÐÁè¼Ý8000¸ö¹È¸èÈÕÀú¿É¹ûÕæ»á¼û£¬£¬£¬ÆäÖÐ200¶à¸ö̻¶ÁË´ó×ÚÒþ˽ÐÅÏ¢£¬£¬£¬ÀýÈçµç×ÓÓʼþID¡¢»î¶¯Ãû³Æ¡¢»î¶¯ÏêÇ顢λÖá¢zoom¾Û»áÁ´½Ó¡¢ÄÚ²¿ÑÝʾÁ´½ÓµÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/google-calendar-search.html
5.Ñо¿Ö°Ô±·¢Ã÷2430Íò»¼ÕßµÄÒ½ÁÆÓ°ÏñÐÅÏ¢ÔÚÍøÉÏ̻¶
Greenbone NetworksÑо¿Ö°Ô±·¢Ã÷ÊýÍòÍò»¼ÕßµÄXÉäÏß¡¢CTºÍMRIɨÃèͼÏñÔÚÈ«ÇòÒ½ÁÆÐ§ÀÍ»ú¹¹µÄÊý°Ų̀ЧÀÍÆ÷ÉÏ̻¶¡£¡£¡£Æ¾Ö¤¸ÃÍŶÓÔÚÒÑÍùÁ½¸öÔµÄÑо¿£¬£¬£¬È«Çò2300¸öÒ½ÁÆÓ°Ïñ´æµµÏµÍ³ÖÐÓÐ590¸ö¿É¹ûÕæ»á¼û£¬£¬£¬ÆäÖаüÀ¨52¸ö²î±ð¹ú¼ÒµÄ2430ÍòÃû»¼Õ߼ͼ¡£¡£¡£Ì»Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼ì²éÈÕÆÚ¡¢Ö÷ÖÎÒ½ÉúÒÔ¼°Óйؼì²éÄ¿µÄµÄһЩҽÁÆÐÅÏ¢¡£¡£¡£±ðµÄ£¬£¬£¬1370ÍòÌõ¼Í¼ÖаüÀ¨ÃÀ¹ú»¼ÕßµÄÉç»áÇå¾²ºÅÂë¡£¡£¡£»£»£»£»£»£»£»¼Õ߼ͼÖйØÁªµÄÒ½ÁÆÓ°ÏñÁè¼Ý7.37ÒÚ¸ö£¬£¬£¬ÆäÖÐÔ¼4ÒÚ¸ö¿Éͨ¹ý»¥ÁªÍøÏÂÔØ¡£¡£¡£ÔÚijЩÇéÐÎÏ£¬£¬£¬Ð§ÀÍÆ÷ÉõÖÁÔÊÐíͨ¹ýδ¼ÓÃܵÄHTTPÅþÁ¬ÏÂÔØ»¼ÕßÊý¾Ý¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.grahamcluley.com/medical-images-and-details-of-24-3-million-patients-left-exposed-on-the-internet/
6.¶ñÒâÈí¼þGootkitÒòÉèÖùýʧµ¼ÖÂÊý¾Ý¿âÔÚÍøÉÏ̻¶
¶ñÒâÈí¼þGootkit±³ºóµÄ·¸·¨ÍÅ»ïÒâÍ⽫MongoDBÊý¾Ý¿âÅþÁ¬µ½»¥ÁªÍø¶øÃ»ÓÐÉèÖÃÃÜÂ룬£¬£¬ÕâʹµÃÇå¾²Ñо¿Ô±Bob DiachenkoÄܹ»ÏÂÔØÕâЩÊý¾ÝºÍÉîÈëÆÊÎöÆä¹¥»÷»î¶¯¡£¡£¡£GootkitµÄÖ÷Òª¹¦Ð§ÊÇ´Óä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬£¬£¬°üÀ¨ÀúÊ·ä¯ÀÀ¼Í¼¡¢ÃÜÂë¡¢cookieÎļþ¡¢ÐÅÓÿ¨ÐÅÏ¢µÈ£¬£¬£¬ËüÖ§³Ö¶àÖÖÖ÷Á÷ä¯ÀÀÆ÷¡£¡£¡£7Ô·ݸöñÒâÈí¼þµÄÁ½¸öC2ЧÀÍÆ÷¿É¹ûÕæ»á¼û£¬£¬£¬²¢Ò»Á¬ÁËÒ»ÖܵÄʱ¼ä£¬£¬£¬ÏÖÔÚ»¹²»ÇåÎúÊǸÃÍÅ»ïÒÅÍüÉèÖÃÃÜÂëÕÕ¾ÉЧÀÍÆ÷·À»ðǽ·ºÆð¹ÊÕÏ¡£¡£¡£ÕâÁ½Ì¨Ð§ÀÍÆ÷¶¼ÔËÐÐMongoDB£¬£¬£¬ÆäÄÚÈÝËÆºõ¾ÛºÏÁËÈý¸öGootkit×Ó½©Ê¬ÍøÂçµÄÊý¾Ý£¬£¬£¬º¸Ç×ܹ²38653¸öÊÜѬȾµÄÖ÷»ú¡£¡£¡£Êý¾Ý¿âÖаüÀ¨¸Ã¶ñÒâÈí¼þÇÔÈ¡µÄÐÅÓÿ¨ÐÅÏ¢¡¢Óû§ÃûºÍƾ֤¡¢ÊÜѬȾÖ÷»úµÄÉèÖÃÎļþ¡¢cookieÎļþ¡¢Óû§ÆÁÄ»½ØÍ¼µÈ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/gootkit-malware-crew-left-their-database-exposed-online-without-a-password/


¾©¹«Íø°²±¸11010802024551ºÅ