ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ8ÖÜ

Ðû²¼Ê±¼ä 2021-02-22

> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ15ÈÕÖÁ02ÔÂ21ÈÕ¹²ÊÕ¼Çå¾²Îó²î58¸ö£¬ £¬ £¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇEFM ipTIME C200 IP Camera CVE-2020-7848ÏÂÁî×¢ÈëÎó²î£»£»£»£»Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐÐÎó²î£»£»£»£»DJI Mavic 2¹Ì¼þÉý¼¶ÏÂÁî×¢ÈëÎó²î£»£»£»£»McAfee Web Gateway troubleshootingÒ³ÌØÈ¨ÌáÉýÎó²î£»£»£»£»Bloodhound objectId×¢ÈëÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǼÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬ £¬ £¬£¬£¬£¬Ð¹Â¶120GBÊý¾Ý£»£»£»£»·¨¹úºÍÎÚ¿ËÀ¼ÁªºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©£»£»£»£»°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCEÎó²î£¬ £¬ £¬£¬£¬£¬ÏÂÔØ³¬10ÒڴΣ»£»£»£»Cyble·¢Ã÷ʹÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹ÂÚ¹¥»÷»î¶¯£»£»£»£»Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Äê×îÏÈ»îÔ¾¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬ £¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


> Ö÷ÒªÇå¾²Îó²îÁбí


1.EFM ipTIME C200 IP Camera CVE-2020-7848ÏÂÁî×¢ÈëÎó²î


EFM ipTIME C200 IP Camera /login.cgi?logout=1±£´æÊäÈëÎó²î£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬ £¬£¬£¬£¬¿Éͨ¹ýCOOKIEÖµÖ´ÐÐí§ÒâOSÏÂÁî¡£¡£¡£¡£¡£

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35905


2.Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐÐÎó²î


Google Chrome Data Transfer±£´æÕ»Òç³öÎó²î£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³£¬ £¬ £¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬ £¬ £¬£¬£¬£¬¿ÉʹӦÓóÌÐò±ÀÀ£»£»£»£»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£

https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html


3.DJI Mavic 2¹Ì¼þÉý¼¶ÏÂÁî×¢ÈëÎó²î


DJI Mavic 2 Remote Controller dji_sysδ¹ýÂËÎļþÖÐÌØÊâÊôÐÔ£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬ £¬£¬£¬£¬Í¨¹ý¹Ì¼þÉý¼¶°üÖ´ÐдúÂë¡£¡£¡£¡£¡£

http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdf


4.McAfee Web Gateway troubleshootingÒ³ÌØÈ¨ÌáÉýÎó²î


McAfee Web Gateway troubleshootingÒ³±£´æÊäÈëÑéÖ¤Îó²î£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬ £¬£¬£¬£¬¿Éͨ¹ýÓû§½Ó¿ÚÖ´ÐÐí§ÒâÏÂÁ £¬ £¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£

https://kc.mcafee.com/corporate/index?page=content&id=SB10349


5.Bloodhound objectId×¢ÈëÎó²î


Bloodhound objectId²ÎÊý´¦Öóͷ£±£´æÇå¾²Îó²î£¬ £¬ £¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬ £¬£¬£¬£¬¿É×¢Èë¶ñÒâÏÂÁî²¢Ö´ÐС£¡£¡£¡£¡£

https://github.com/BloodHoundAD/BloodHound/issues/338


> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢¼ÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬ £¬ £¬£¬£¬£¬Ð¹Â¶120GBÊý¾Ý


1.jpg


¼ÓÄôóÁìÏÈµÄÆû³µºÍ¿¨³µ×âÁÞ¹«Ë¾Canadian Discount Car and Truck RentalsÊܵ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬ £¬ £¬£¬£¬£¬ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÁË120GBµÄÊý¾Ý£¬ £¬ £¬£¬£¬£¬°üÀ¨½ðÈÚ¡¢Êг¡ÓªÏú¡¢ÒøÐС¢ÕÊ»§ºÍ¼ÓÃËÉÌÊý¾Ý¡£¡£¡£¡£¡£Õⳡ¹¥»÷ÖÐÖ¹Á˸ù«Ë¾ÔÚdiscountcar.comÉϵÄÔÚÏß×âÁÞЧÀÍ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/leading-canadian-rental-car-company-hit-by-darkside-ransomware/


2¡¢·¨¹úºÍÎÚ¿ËÀ¼ÁªºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©


2.jpg


·¨¹úºÍÎÚ¿ËÀ¼Ö´·¨²¿·ÖµÄÁªºÏÐж¯¾Ð²¶ÁËÎÚ¿ËÀ¼µÄEgregorÀÕË÷Èí¼þµÄ¼¸Ãû³ÉÔ±£¬ £¬ £¬£¬£¬£¬ÕâЩ³ÉÔ±µÄÊÂÇéÊÇÈëÇÖ¹«Ë¾ÍøÂç²¢°²ÅÅÀÕË÷Èí¼þ¡£¡£¡£¡£¡£¾Ý±¨µÀ£¬ £¬ £¬£¬£¬£¬¸ÃÐж¯ÊÇÔÚÈ¥ÄêÇïÌìÊÕµ½°ÍÀèÀÕË÷Èí¼þ·¸·¨ÍÅ»ïµÄͶËߺó£¬ £¬ £¬£¬£¬£¬ÓɰÍÀè´óÉó·¨ÔºÆô¶¯µÄ¡£¡£¡£¡£¡£ÏÖÔÚ£¬ £¬ £¬£¬£¬£¬EgregorµÄTorÍøÕ¾´¦ÓÚÀëÏß״̬¡£¡£¡£¡£¡£ÓÉÓÚÎÞ·¨»á¼ûTor¸¶¿îÕ¾µã£¬ £¬ £¬£¬£¬£¬Êܺ¦ÕßÎÞ·¨ÁªÏµµ½ÀÕË÷Õߣ¬ £¬ £¬£¬£¬£¬Ò²ÎÞ·¨Ö§¸¶Êê½ð»òÏÂÔØ½âÃÜÆ÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/egregor-ransomware-members-arrested-by-ukrainian-french-police/


3¡¢°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCEÎó²î£¬ £¬ £¬£¬£¬£¬ÏÂÔØ³¬10ÒÚ´Î


3.png


Ò»¸ö±»ÏÂÔØÁè¼Ý 10 ÒÚ´ÎµÄ Android Ó¦ÓóÌÐò°üÀ¨ÁËδÐÞ²¹µÄÎó²î£¬ £¬ £¬£¬£¬£¬¶øÕâ¸ö°üÀ¨Îó²îµÄÓ¦ÓóÌÐòµÄÐÞ¸´Ê±¼äÒѾ­Áè¼ÝÁËÈý¸öÔ¡£¡£¡£¡£¡£ÕâЩÎó²îÓ°ÏìÁË Android °æ±¾µÄ SHAREit£¬ £¬ £¬£¬£¬£¬Ò»¸öÔÊÐíÓû§ÓëÅóÙ­»òСÎÒ˽¼Ò×°±¸¹²ÏíÎļþµÄÒÆ¶¯Ó¦ÓóÌÐò¡£¡£¡£¡£¡£Trend MicroµÄÒÆ¶¯ÍþвÆÊÎöʦEcho DuanÔÚÒ»·Ý±¨¸æÖÐ˵£¬ £¬ £¬£¬£¬£¬¿ÉÒÔʹÓÃÕâЩÎó²îÔÚ×°ÖÃÁËSHAREitÓ¦ÓóÌÐòµÄÖÇÄÜÊÖ»úÉÏÔËÐжñÒâ´úÂë ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-bugs-left-unpatched-in-android-app-with-one-billion-downloads/


4¡¢Cyble·¢Ã÷ʹÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂç´¹ÂÚ¹¥»÷»î¶¯


4.png


ÍþвÇ鱨¹«Ë¾CybleµÄÑо¿Ö°Ô±·¢Ã÷ÁËÕë¶Ô¶à¸öÀÄÓÃngrokƽ̨µÄ×éÖ¯µÄÐÂÒ»²¨ÍøÂç´¹ÂÚ¹¥»÷£¬ £¬ £¬£¬£¬£¬ngrokƽ̨ÊÇͨÍùµ±ÌïÖ÷»úµÄÒ»¸öÇå¾²ÇÒ¿É×ÔÊ¡µÄËíµÀ¡£¡£¡£¡£¡£ngrokÊÇÒ»¸ö¿çƽ̨ӦÓóÌÐò£¬ £¬ £¬£¬£¬£¬ÓÃÓÚ½«ÍâµØ¿ª·¢Ð§ÀÍÆ÷¹ûÕæµ½Internet£¬ £¬ £¬£¬£¬£¬Í¨¹ý½¨Éèµ½µ±ÌïÖ÷»úµÄ³¤Á´½ÓTCPËíµÀ£¬ £¬ £¬£¬£¬£¬¸ÃЧÀÍÆ÷ËÆºõÍйÜÔÚngrokµÄ×ÓÓò£¨ÀýÈç4f421deb219c[.]ngrok[.]io£©ÉÏ¡£¡£¡£¡£¡£×¨¼ÒÃÇÖ¸³ö£¬ £¬ £¬£¬£¬£¬ngrokЧÀÍÆ÷Èí¼þÔËÐÐÔÚVPS»òרÓÃЧÀÍÆ÷ÉÏ£¬ £¬ £¬£¬£¬£¬¿ÉÒÔÈÆ¹ýNATÓ³ÉäºÍ·À»ðǽÏÞÖÆ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114644/cyber-crime/ngrok-phishing-attacks.html


5¡¢Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Äê×îÏÈ»îÔ¾


5.png


WatchDog¼ÓÃÜÍÚ¿ó½©Ê¬ÍøÂçÓÉPalo Alto NetworksµÄÍþвÇ鱨²¿·Ö42²¿·Ö·¢Ã÷£¬ £¬ £¬£¬£¬£¬¸Ã½©Ê¬ÍøÂç×Ô2019Äê1ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬ £¬ £¬£¬£¬£¬WatchDogÓÉGoÓïÑÔ±àд¶ø³É¡£¡£¡£¡£¡£Æ¾Ö¤Unit 42ÍŶӶÔWatchDog¶ñÒâÈí¼þµÄÆÊÎö£¬ £¬ £¬£¬£¬£¬Ñо¿Ö°Ô±Ô¤¼Æ¸Ã½©Ê¬ÍøÂçÒѹ¥»÷500µ½1000¸öÄ¿µÄ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/windows-and-linux-servers-targeted-by-new-watchdog-botnet-for-almost-two-years/