ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ14ÖÜ
Ðû²¼Ê±¼ä 2019-04-08±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2019Äê4ÔÂ01ÈÕÖÁ07ÈÕ¹²ÊÕ¼Çå¾²Îó²î45¸ö£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇD-Link DSL-3782 Acl.aspí§ÒâOSÏÂÁîÖ´ÐÐÎó²î£»£»£»£»VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐÐÎó²î; Fortinet FortiOS¶ÑÒç³öÎó²î£»£»£»£»TONGDA Office Anywhere SQL×¢ÈëÎó²î£»£»£»£»Advantech WebAccess/SCADAÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
Ö÷ÒªÇå¾²Îó²îÁбí
D-Link DSL-3782 Acl.asp´¦Öóͷ£ScrIPaddrEndTXT²ÎÊý±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÒÔÖ´ÐÐí§ÒâosÏÂÁî¡£¡£¡£¡£¡£
https://c0mix.github.io/2019/D-Link-DIR-3782-SecAdvisory-OS-Command-Injection-and-Stored-XSS/
2. VMware Workstation/Fusion CVE-2019-5524Ô½½çд´úÂëÖ´ÐÐÎó²î
VMware Workstation/Fusion e1000ÐéÄâÍø¿¨ÊµÏÖ±£´æÔ½½çдÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://www.vmware.com/security/advisories/VMSA-2019-0005.html
3. Fortinet FortiOS¶ÑÒç³öÎó²î
Fortinet FortiOS±£´æ¶ÑÒç³öÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://fortiguard.com/psirt/FG-IR-18-388
4. TONGDA Office Anywhere SQL×¢ÈëÎó²î
TONGDA Office Anywhere±£´æsql×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬£¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
http://expzh.com/TONGDA-OA-SQL-Injection.pdf
5. Advantech WebAccess/SCADAÏÂÁî×¢ÈëÎó²î
Advantech WebAccess/SCADA±£´æÍⲿÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬¿ÉÖ´Ðв»·¨ÏÂÁî¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-19-092-01
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢SonicWallб¨¸æ³Æ2018ÄêIoT¹¥»÷ÔöÌí217.5£¥

ƾ֤SonicWallµÄÄê¶ÈÍøÂçÍþв±¨¸æ£¨2019°æ£©£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½3270Íò´ÎIoT¹¥»÷£¬£¬£¬£¬£¬£¬±È2017ÄêµÄ1030Íò´ÎÔöÌíÁË217.5£¥¡£¡£¡£¡£¡£ÕâÒ»ÔöÌíµÄÔµ¹ÊÔÓÉÊÇIoT×°±¸ÖÆÔìÉÌδÄÜʵÑéÊʵ±µÄÇå¾²¿ØÖÆ¡£¡£¡£¡£¡£È«ÇòÁè¼Ý46%µÄIoT½©Ê¬ÍøÂçÆäIPµØµãÔ´ÓÚÃÀ¹ú£¬£¬£¬£¬£¬£¬Æä´ÎÊÇÖйú£¨13%£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬2018ÄêSonicWall¹²¼ì²âµ½2600Íò´Î´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬±È2017ÄêϽµ4.1£¥¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/iot-attacks-escalating-with-a-2175-percent-increase-in-volume/
2¡¢ÒøÐÐľÂíAnubis£¬£¬£¬£¬£¬£¬×Ô2017ÄêÀ´ÒÑѬȾ300¶à¼Ò½ðÈÚ»ú¹¹
AndroidÒøÐÐľÂíAnubisÖ÷Ҫͨ¹ýGoogle Play Store·Ö·¢£¬£¬£¬£¬£¬£¬×Ô2017ÄêÒÔÀ´£¬£¬£¬£¬£¬£¬AnubisÒѾѬȾÁËÈ«ÇòÁè¼Ý300¼Ò½ðÈÚ»ú¹¹¡£¡£¡£¡£¡£Anubisͨ³£Î±×°³ÉÊÖ»úÓÎÏ·¡¢ÓʼþAPP¡¢ÊÊÓÃС¹¤¾ßÉõÖÁÊÇä¯ÀÀÆ÷ºÍ̸ÌìAPPµÈ£¬£¬£¬£¬£¬£¬ÆäÖ÷ÒªÕë¶ÔÅ·ÖÞ¡¢ÑÇÖÞºÍÃÀÖÞ¡£¡£¡£¡£¡£2019Äê3Ô£¬£¬£¬£¬£¬£¬Ò»¸öÃûΪAldesaµÄ¹¥»÷ÕßÔÚµØÏÂÂÛ̳ÉÏÏúÊÛ×îбäÌåAnubis 3¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/uncovering-the-capabilities-and-activities-of-anubis-android-banking-trojan-9e3d7e67
3¡¢Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý2.6Íò¸öKibanaʵÀýÔÚÍøÉÏ̻¶
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/kibana-data-security.html
4¡¢Facebook 5.4ÒÚÓû§¼Í¼ÔÚÑÇÂíÑ·ÔÆ´æ´¢ÖÐÆØ¹â
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/540-mllion-facebook-records-leaked-by-public-amazon-s3-buckets/
5¡¢JS-SnifferѬȾȫÇò2440¸öÍøÕ¾£¬£¬£¬£¬£¬£¬Ö÷ÒªÇÔÊØÐÅÓÿ¨ÐÅÏ¢
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/js-sniffers-credit-card-hacking.html