ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ3ÖÜ

Ðû²¼Ê±¼ä 2019-01-21

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê1ÔÂ14ÈÕÖÁ20ÈÕ¹²ÊÕ¼Çå¾²Îó²î50¸ö£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇBrocade Network Advisor CVE-2018-6443Ó²±àÂëÆ¾Ö¤Îó²î£»£»£»£»£»£»systemd-journaldÕ»»º³åÇøÒç³öÎó²î£»£»£»£»£»£»SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»IDenticard PremisysÊý¾Ý¿âĬÈÏÆ¾Ö¤Îó²î£»£»£»£»£»£»LCDS LAquis SCADAδÊÚȨ»á¼ûÎó²î ¡£¡£¡£¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾;ÃÀOklahomaÖÝÕþ¸®Ð§ÀÍÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý;Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ;VoIPЧÀÍÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý;ESÎļþä¯ÀÀÆ÷Á½¸öÎó²îʹµÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙΣº¦ ¡£¡£¡£¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖÐ ¡£¡£¡£¡£¡£


Ö÷ÒªÇå¾²Îó²îÁбí


1. Brocade Network Advisor CVE-2018-6443Ó²±àÂëÆ¾Ö¤Îó²î
Brocade Network Advisor±£´æÓ²±àÂëÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉµÇ¼µ½JBoss Administration½çÃæ²¢×°ÖÃÆäËûJEEÓ¦ÓóÌÐò ¡£¡£¡£¡£¡£
https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2018-743

2. systemd-journaldÕ»»º³åÇøÒç³öÎó²î
systemd-journaldʵÏÖ±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Ê¹systemd-journald±ÀÀ£»£»£»£»£»£»òÒÔjournaldȨÏÞÖ´ÐдúÂë ¡£¡£¡£¡£¡£
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16864

3. SAS Web Infrastructure Platform·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
SAS Web Infrastructure PlatformµÄ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë ¡£¡£¡£¡£¡£
https://support.sas.com/kb/63/391.html

4. IDenticard PremisysÊý¾Ý¿âĬÈÏÆ¾Ö¤Îó²î
IDenticard Premisys IdenticardЧÀÍÔÚ×°ÖÃʱʹÓÃĬÈϵÄÊý¾Ý¿âÓû§ÃûºÍÃÜÂ룬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼ûÊý¾Ý¿âȨÏÞ ¡£¡£¡£¡£¡£
http://www.securityfocus.com/bid/106552

5. LCDS LAquis SCADAδÊÚȨ»á¼ûÎó²î
LCDS LAquis SCADAʵÏÖ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÈƹýÉí·ÝÑéÖ¤£¬£¬£¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-015-01


 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢»úƱԤ¶©ÏµÍ³AmadeusÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÒÔÉ«ÁÐÇå¾²Ñо¿Ô±Noam Rotem·¢Ã÷»úƱԤ¶©ÏµÍ³Amadeus±£´æÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä ¡£¡£¡£¡£¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤¶©»úƱʱ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÔÚÔ¤¶©º½°àºó£¬£¬£¬£¬£¬£¬£¬ÓοͻáÊÕµ½PNRºÅÂëºÍÓÃÓÚÉó²éÔ¤¶©ÐÅÏ¢µÄÁ´½Ó ¡£¡£¡£¡£¡£Rotem·¢Ã÷ͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÐÞ¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿ÉÉó²éËûÈ˵ÄÔ¤¶©ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉʹÓÃÕâЩÐÅÏ¢»á¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬°üÀ¨¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØµãºÍµç»°ºÅÂëµÈ ¡£¡£¡£¡£¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤ¶©ÏµÍ³±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Ó㨰üÀ¨ÃÀ¹úÁªºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬£¬£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²î¿ÉÄÜÓ°ÏìÁËÊýÒÚÓÎ¿Í ¡£¡£¡£¡£¡£ÏÖÔÚAmadeusÒѾ­ÐÞ¸´Á˸ÃÎÊÌâ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html



2¡¢ÃÀOklahomaÖÝÕþ¸®Ð§ÀÍÆ÷ÒâÍâ̻¶3TBÃô¸ÐÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



UpGuardÑо¿Ö°Ô±Greg Pollock·¢Ã÷ÊôÓÚÃÀ¹ú¶í¿ËÀ­ºÉÂíÖÝ֤ȯ²¿ODSµÄһ̨ЧÀÍÆ÷¿É¹ûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬µ¼Ö°üÀ¨Êý°ÙÍòÃô¸ÐÎļþµÄÔ¼3TBÕþ¸®Êý¾Ý̻¶ ¡£¡£¡£¡£¡£ÕâЩÊý¾Ý°üÀ¨Ö¤È¯Î¯Ô±»áÊýÊ®ÄêµÄÉñÃØÎļþºÍÐí¶àÃô¸ÐµÄFBIÊÓ²ìÎļþ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°Ô¼1ÍòÃû¹ÉƱ¾­¼ÍÈ˵ĵç×ÓÓʼþ¡¢Éç»áÇå¾²ºÅÂë¡¢ÐÕÃûºÍµØµãÐÅÏ¢µÈ ¡£¡£¡£¡£¡£ShodanÏÔʾ¸ÃЧÀÍÆ÷ÖÁÉÙ´Ó2018Äê11ÔÂ30ÈÕ×îÏȿɹûÕæ»á¼û£¬£¬£¬£¬£¬£¬£¬Ô¼Ò»ÖܺóODSÊÕµ½Í¨Öª²¢¶Ô¸ÃЧÀÍÆ÷ʵÑéÁ˱£»£»£»£»£»£»¤²½·¥ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/oklahoma-fbi-data-leak.html


3¡¢Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Ó¢¹ú°²·ÀÐÐҵЭ»á£¨BSIA£©Ðû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ ¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×î´óÏ޶ȵØïÔÌ­µç×ÓÇ徲ϵͳÖеÄÍøÂçÅþÁ¬×°±¸¡¢Èí¼þºÍϵͳµÄÊý×ÖÆÆËðΣº¦ ¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÒÔÐÐÒµµÄ×î¼Ñ¹ú¼Êʵ¼ùΪ»ù´ ¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬£¬²¢²Î¿¼¹«ÈϵĹú¼ÊÖ¸ÄϺͱê×¼£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ×ÊÖú»¥ÁªÇ徲ϵͳ¹©Ó¦Á´ÖеÄÉè¼ÆÕß¡¢ÖÆÔìÉÌ¡¢×°ÖÃÖ°Ô±¡¢Î¬»¤Ö°Ô±¡¢Ð§ÀÍÌṩÉ̺ÍÓû§ÌáÉýÇå¾²ÅþÁ¬µÄÐÅÐÄ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/


4¡¢VoIPЧÀÍÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Ñо¿Ö°Ô±Justin Paineͨ¹ýShodan·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚVoIPЧÀÍÉÌVOIPO£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨Á˸ù«Ë¾ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý ¡£¡£¡£¡£¡£Æ¾Ö¤PaineµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨¿É×·ËÝÖÁ2017Äê7ÔµÄ670ÍòÌõͨ»°¼Í¼¡¢¿É×·ËÝÖÁ2015Äê12ÔµÄ600ÍòÌõ¶ÌÐÅ/²ÊÐÅÈÕÖ¾ÒÔ¼°100ÍòÌõ°üÀ¨ÄÚ²¿ÏµÍ³API KEYµÄÈÕÖ¾ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ1ÔÂ8ÈÕÏòVOIPOת´ïÁËÕâÒ»·¢Ã÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚͳһÌ콫Êý¾Ý¿â¾ÙÐÐÁËÍÑ»ú±£»£»£»£»£»£»¤ ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html



5¡¢ESÎļþä¯ÀÀÆ÷Á½¸öÎó²îʹµÃÁè¼Ý1ÒÚAndroidÓû§ÃæÁÙΣº¦

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Çå¾²Ñо¿Ô±Robert BaptisteÔÚESÎļþä¯ÀÀÆ÷Öз¢Ã÷Ò»¸öʼÖÕÔÚºǫ́ÔËÐеÄÒþ²ØWebЧÀÍÆ÷£¨¶Ë¿Ú59777£©£¬£¬£¬£¬£¬£¬£¬ÓëÊܺ¦Õß´¦ÓÚͳһÍâµØÍøÂçµÄ¹¥»÷Õ߿ɻñÈ¡Êܺ¦ÕßÊÖ»úµÄ´ó×ÚÓÐÓÃÐÅÏ¢£¨°üÀ¨×°±¸ÐÅÏ¢¡¢app×°ÖÃÐÅÏ¢¡¢ÎļþµÈ)£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ¿ÉÒÔÔ¶³ÌÆô¶¯app ¡£¡£¡£¡£¡£¸ÃÎó²î±»¸ú×ÙΪCVE-2019-6447£¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹Ðû²¼ÁËPOC¾ç±¾ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬ESETÑо¿Ö°Ô±Lukas Stefanko·¢Ã÷ÁËÁíÒ»ÆäÖÐÐÄÈË£¨MitM£©¹¥»÷Îó²î£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁË4.1.9.7.4¼°Ö®Ç°µÄ°æ±¾ ¡£¡£¡£¡£¡£ESÎļþä¯ÀÀÆ÷¿ª·¢ÍŶÓÌåÏÖÐÞ¸´²¹¶¡½«ÔÚԼĪÁ½ÌìºóÍÆ³ö ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/es-file-explorer-flaws-put-100-million-users-data-at-risk-fix-promised/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí