ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ29ÖÜ

Ðû²¼Ê±¼ä 2018-07-23

Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2018Äê07ÔÂ16ÈÕÖÁ22ÈÕ¹²ÊÕ¼Çå¾²Îó²î44¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇPivotal Spring FrameworkÔ¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐÏÂÁî×¢ÈëÎó²î£»£»£»£»£»£»ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Dasan GPONÏÂÁî×¢ÈëÎó²î¡£¡£ ¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÒøÐÐľÂíDorkbot¾íÍÁÖØÀ´£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%£»£»£»£»£»£»¶íÂÞ˹ÔÚÌìϱ­Ê±´úÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷£»£»£»£»£»£»Telefonica¹ÙÍøÎó²î¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶£»£»£»£»£»£»ÃÀѪҺ¼ì²âʵÑéÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ï죻£»£»£»£»£»¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª¡£¡£ ¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£ ¡£


¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí


1¡¢Pivotal Spring FrameworkÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Spring FrameworkʹÓÃspring-messagingÄ£¿£¿£¿ £¿£¿£¿£¿éÀ´ÊµÏÖSTOMPÊðÀíʱ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÐÂÎÅ£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.exploit-db.com/exploits/44796/


2¡¢Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐÏÂÁî×¢ÈëÎó²î

Cisco IP Phone 6800¡¢7800ºÍ8800ϵÁÐWEB UI±£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬×¢Èëí§ÒâSHELLÏÂÁî²¢Ö´ÐС£¡£ ¡£


 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180711-phone-webui-inject


3¡¢ManageEngine Exchange Reporter Plus ¡®ADSHACluster¡¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î


 ManageEngine Exchange Reporter Plus Java servlet ¡®ADSHACluster¡¯ÔÚÖ´ÐС®bcp.exe¡¯Îļþ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâ¡®BCP_EXE¡¯²ÎÊýÇëÇ󣬣¬£¬£¬£¬Ö´ÐÐí§Òâ´úÂë¡£¡£ ¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.manageengine.com/products/exchange-reports/release-notes.html


4¡¢Adobe Flash Player CVE-2018-5007ÀàÐÍ»ìÏý´úÂëÖ´ÐÐÎó²î

Adobe Flash Player´¦Öóͷ£SWFÎļþ±£´æÀàÐÍ»ìÏýÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâÎļþÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£ ¡£

Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-24.html


5¡¢Dasan GPONÏÂÁî×¢ÈëÎó²î

Dasan GPON GponForm/diag_Form URI±£´æÉè¼ÆÎó²î£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄ'dest_host¡¯²ÎÊýµÄdiag_action=pingÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§ÒâÏÂÁî¡£¡£ ¡£

 Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÇå¾²²¹¶¡ÒÔÐÞ¸´¸ÃÎó²î£ºhttps://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/

Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢ÒøÐÐľÂíDorkbot¾íÍÁÖØÀ´£¬£¬£¬£¬£¬Õ¼ÒøÐжñÒâÈí¼þÊг¡µÄ25%


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

 Æ¾Ö¤Check PointµÄ×îÐÂÊý¾Ý£¬£¬£¬£¬£¬ÒøÐÐľÂíDorkbotÔÚ2018Äê¾íÍÁÖØÀ´£¬£¬£¬£¬£¬³ÉΪһ¸öÑÏÖØµÄÍþв¡£¡£ ¡£Dorkbot×îÔç¿ÉÒÔ×·Ëݵ½2012Ä꣬£¬£¬£¬£¬ÆäÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÒøÐеǼƾ֤¡£¡£ ¡£ÔÚ2018ÄêÉϰëÄ꣬£¬£¬£¬£¬È«ÇòÒøÐжñÒâÈí¼þÊг¡Õ¼ÓÐǰÈýλµÄ»®·ÖÊÇRamnit£¨27£¥£©¡¢Dorkbot£¨25£¥£©ºÍZeus£¨13£¥£©¡£¡£ ¡£DorkbotÒѳÉΪ2018ÄêµÚ¶þ´óÁîÈËÍ·ÌÛµÄÒøÐжñÒâÈí¼þ¡£¡£ ¡£

 Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/threatlist-6-year-old-dorkbot-banking-malware-resurfaces-as-big-threat/133898/

2¡¢¶íÂÞ˹ÔÚÌìϱ­Ê±´úÔâµ½Ô¼2500Íò´ÎÍøÂç¹¥»÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ī˹¿ÆÊ±±¨±¨µÀ³Æ£¬£¬£¬£¬£¬¶íÂÞ˹×ÜͳÆÕ¾©¸ß¶ÈÔÞÑïÁ˸ùúµÄÍøÂçÇå¾²²¿·Ö£¬£¬£¬£¬£¬¸Ã²¿·ÖÔÚÌìϱ­Ê±´ú¹²×èÖ¹ÁËÔ¼2500Íò´ÎÍøÂç¹¥»÷ºÍÆäËü·¸·¨»î¶¯£¬£¬£¬£¬£¬È·±£Á˽ÇÖðµÄÇå¾²¡£¡£ ¡£FireEyeÄÏÅ·ÊÖÒÕ×ܼàDavid GroutÌåÏÖËäÈ»ÕâÒ»Êý×ֺܸߣ¬£¬£¬£¬£¬µ«²¢²»³öÈËÒâÁÏ¡£¡£ ¡£ÕâЩ¹¥»÷¿ÉÄܰüÀ¨ÔÚ½ÇÖðǰ¼¸ÖܾÍ×îÏȵÄÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬ÀýÈçµÍ¼Û»úƱ¡¢Ó®µÃ¶íÂÞ˹֮ÂÃÒÔ¼°ÓëÌìϱ­Ö÷ÌâÏà¹ØµÄ´ÙÏú»î¶¯£¨Èç¹ú¼Ò¶ÓÇòÒ£©µÈ¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/russia-fends-off-25-million-world/

3¡¢Telefonica¹ÙÍøÎó²î¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Î÷°àÑÀµçÐŹ«Ë¾TelefonicaµÄ¹Ì»°¡¢¿í´ø¼°¸¶·ÑµçÊÓÓªÒµMovistarµÄ¹ÙÍø±£´æÎó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÊý°ÙÍòÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£ ¡£Movistar¹ÙÍøÉÏÓÃÓÚÉó²é·¢Æ±µÄÒ³ÃæµÄURLÖаüÀ¨ÁË·¢Æ±µÄID£¬£¬£¬£¬£¬ÈκÎÓû§¶¼¿ÉÒÔͨ¹ýÐ޸ĴËIDÀ´Éó²éÆäËüÕË»§µÄÊý¾Ý¡£¡£ ¡£Æ¾Ö¤ÐµÄGDPR»®¶¨£¬£¬£¬£¬£¬¸Ã¹«Ë¾¿ÉÄÜÃæÁÙ1000Íò~2000ÍòÅ·Ôª»òÏ൱ÓÚÆäÄêÓªÒµ¶î2%~4%µÄ·£¿£¿£¿ £¿£¿£¿£¿î¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/telefonica-spain-exposed-the-personal-details-of-millions-of-customers/

4¡¢ÃÀѪҺ¼ì²âʵÑéÊÒLabCorpÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§ÒÉÊÜÓ°Ïì


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

±¾ÖÜÒ»ÃÀ¹ú×î´óµÄѪҺ¼ì²âʵÑéÊÒLabCorpÐû²¼ÆäÔÚÖÜĩʱ´úÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£ ¡£LabCorp¹Ø±ÕÁ˲¿·ÖϵͳÒÔ¿ØÖƸÃÈëÇֻ£¬£¬£¬£¬£¬ÏÖÔÚ¸÷ϵͳ¹¦Ð§ÕýÔÚ»Ö¸´ÖС£¡£ ¡£¸Ã¹«Ë¾ÌåÏÖûÓÐÖ¤¾ÝÅú×¢±¬·¢Á˶ÔÊý¾ÝµÄδÊÚȨ»á¼û£¬£¬£¬£¬£¬µ«Ã»ÓÐÅû¶¸ü¶àÏà¹ØÏ¸½Ú¡£¡£ ¡£ÓйØÕþ¸®ÕýÔÚ¾ÙÐÐÊÓ²ìÖ®ÖС£¡£ ¡£LabCorpÔÚÈ«ÇòÓµÓнü6ÍòÃûÔ±¹¤£¬£¬£¬£¬£¬ÆäÿÖܲâÊԵϼÕßÑù±¾Áè¼Ý250Íò¸ö£¬£¬£¬£¬£¬Òò´ËÊý¾Ýй¶µÄDZÔÚЧ¹û¿ÉÄÜÊÇÖØ´óµÄ£¬£¬£¬£¬£¬Êý°ÙÍòÓû§µÄÃô¸ÐÐÅÏ¢¿ÉÄÜÃæÁÙΣº¦¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-network-of-labcorp-us-biggest-blood-testing-laboratories/

5¡¢¶íÂÞ˹PIRÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬ËðʧԼ100ÍòÃÀÔª

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

 Æ¾Ö¤¶íÂÞ˹Çå¾²³§ÉÌGroup-IBµÄ±¨¸æ£¬£¬£¬£¬£¬ºÚ¿ÍÍÅ»ïMoneyTakerͨ¹ý·ÓÉÆ÷ÈëÇÖÁ˶íÂÞ˹PIRÒøÐеÄÍøÂ磬£¬£¬£¬£¬²¢ÇÔÈ¡ÁËÔ¼100ÍòÃÀÔªµÄ×ʽ𡣡£ ¡£Group-IBÈ·ÈϹ¥»÷ʼÓÚ2018Äê5ÔÂÏÂÑ®£¬£¬£¬£¬£¬¹¥»÷ÕßµÄÈë¿ÚÊǹýʱµÄ·ÓÉÆ÷£¬£¬£¬£¬£¬¸Ã·ÓÉÆ÷ÓÐËíµÀ£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÖ±½Ó»á¼ûÒøÐеÄÍâµØÍøÂç¡£¡£ ¡£¹¥»÷±¬·¢ÔÚ7ÔÂ3ÈÕ£¬£¬£¬£¬£¬PIRÒøÐеÄÔ±¹¤ÔÚÒ»ÌìºóµÄ7ÔÂ4ÈÕ·¢Ã÷ÁË´ó±ÊδÊÚȨµÄÉúÒ⣬£¬£¬£¬£¬µ«ÎªÊ±ÒÑÍí¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/hackers-breach-russian-bank-and-steal-1-million-due-to-outdated-router/