ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ16ÖÜ

Ðû²¼Ê±¼ä 2018-04-25

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö
        2018Äê04ÔÂ16ÈÕÖÁ20ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´47¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇBelkin N750Õ»»º³åÇøÒç³ö©¶´£»Discuz! DiscuzX CVE-2018-10298¿çÕ¾½Å±¾Â©¶´£»Spring Data CommonsÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Oracle WebLogic Server·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´£»Adobe Flash PlayerÔ½½çдÈÎÒâ´úÂë©¶´¡£

       ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÌ©¹úÔËÓªÉÌTrueMove HµÄÓû§Êý¾Ýй¶£¬Ô¼4.6ÍòÓû§Êܵ½Ó°Ï죻×îеÄÑо¿ÏÔʾ´óÁ¿AndroidÓ¦ÓÃÎ¥¹æÊÕÂÞ¶ùͯµÄÒþ˽ÐÅÏ¢£»Ñо¿ÈËÔ±³ÆÊý°ÙÍò¸öAPPͨ¹ý¹ã¸æSDKй¶Óû§Êý¾Ý£»CCleaner APTÊÓ²ìºóÐø£º¹¥»÷Õßͨ¹ýTeamViewer½øÈëPiriformµÄÍøÂ磻Ñо¿ÈËÔ±·¢ÏÖÊý¾Ý¹«Ë¾LocalBloxµÄÔ¼4800ÍòÓû§Êý¾Ý¿É¹ûÈ»·ÃÎÊ¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí
1¡¢Belkin N750Õ»»º³åÇøÒç³ö©¶´

        Belkin N750´æÔÚ»ùÓÚÕ»µÄ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ïòproxy.cgi·¢ËÍHTTPÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://www.tenable.com/security/research/tra-2018-08
2¡¢Discuz! DiscuzX CVE-2018-10298¿çÕ¾½Å±¾Â©¶´

        Discuz! DiscuzX data/template/1_diy_portal_view.tpl.phpδÏÞÖÆÄÚÈÝ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´×¢Èë¶ñÒâ½Å±¾»òHTML´úÂ룬µ±¶ñÒâÊý¾Ý±»¼ì²ìʱ£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò½Ù³ÖÓû§»á»°¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://laworigin.github.io/2018/04/22/Discuz-x-portal-Stored-XSS/
3¡¢Spring Data CommonsÔ¶³Ì´úÂëÖ´ÐЩ¶´

        Spring Data Commons´¦ÖÃSPEL±í´ïʽ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÒÔWEBȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://pivotal.io/security/cve-2018-1273
4¡¢Oracle WebLogic Server·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´

        Oracle WebLogic Server´æÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâÇëÇó£¬ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
5¡¢Adobe Flash PlayerÔ½½çдÈÎÒâ´úÂë©¶´

        Adobe Flash Player´æÔÚÔ½½çд©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâÎļþ£¬ÓÕʹÓû§½âÎö£¬¿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄÄþ¾²²¹¶¡ÒÔÐÞ¸´¸Ã©¶´£ºhttps://helpx.adobe.com/security/products/flash-player/apsb18-08.html


Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö
1¡¢Ì©¹úÔËÓªÉÌTrueMove HµÄÓû§Êý¾Ýй¶£¬Ô¼4.6ÍòÓû§Êܵ½Ó°Ïì

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        Äþ¾²Ñо¿ÈËÔ±Niall Merrigan·¢ÏÖÌ©¹ú×î´óµÄ4GÒÆ¶¯ÔËÓªÉÌTrueMove HµÄÒ»¸öAmazon AWS S3¿É¹ûÈ»·ÃÎÊ£¬Ð¹Â¶µÄÊý¾Ý°üÂÞÓû§µÄ¼ÝʻִÕպͻ¤ÕÕµÈÉí·ÝÖ¤¼þµÄɨÃ裬Êý¾Ý×ÜÁ¿ÎªÔ¼4.6ÍòÌõ¼Ç¼£¬¹²32GB¡£¸ÃÊý¾Ý¿âÖ±µ½4ÔÂ12ÈÕ»¹¿É¼ÌÐø·ÃÎÊ£¬Ëæºó¸Ã¹«Ë¾ÏÞÖÆÁËÆä·ÃÎÊȨÏÞ¡£TrueMove HÉùÃ÷³ÆÊý¾Ýй¶Ê¼þÓ°ÏìµÄÊÇÆä×Ó¹«Ë¾I True Mart¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/71406/data-breach/truemove-h-data-leak.html

2¡¢×îеÄÑо¿ÏÔʾ´óÁ¿AndroidÓ¦ÓÃÎ¥¹æÊÕÂÞ¶ùͯµÄÒþ˽ÐÅÏ¢

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        À´×ÔÃÀ¹ú¶àËù´óѧµÄÒþ˽ר¼Ò·ÖÎöÁËGoogle PlayÉ̵êµÄ¡°Îª¼ÒÍ¥¶øÉè¼Æ¡±£¨DFF£©¼Æ»®µÄ5855¸öAndroid app£¬·¢ÏÖÁè¼Ý57%µÄapp¿ÉÄÜÎ¥·´Á˶ùͯÔÚÏßÒþ˽±£»¤·¨°¸£¨COPPA£©¡£Ô¼5%µÄappδ¾­Ðí¿ÉÊÕ¼¯Óû§µÄλÖúÍÁªÏµÈËÐÅÏ¢£¬Ô¼19%µÄappÓëµÚÈý·½¹²ÏíÃô¸ÐÐÅÏ¢£¬Ô¼40%µÄappÎ¥·´ÁËÖ¼ÔÚ±£»¤¶ùͯÒþ˽µÄGoogle·þÎñÌõ¿î¡£Ö÷ÒªÔ­ÒòÊÇ´ó¶àÊýappʹÓõÄSDKͨ³£×Ô¶¯ÊÕ¼¯Óû§ÐÅÏ¢¡£

        Ô­ÎÄÁ´½Ó£ºhttp://news.softpedia.com/news/thousands-of-android-apps-are-tracking-kids-without-parental-consent-520696.shtml

3¡¢Ñо¿ÈËÔ±³ÆÊý°ÙÍò¸öAPPͨ¹ý¹ã¸æSDKй¶Óû§Êý¾Ý

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        ¿¨°Í˹»ùʵÑéÊÒÄþ¾²Ñо¿Ô±Roman UnuchekÌåÏÖ£¬Êý°ÙÍò¸öAPPʹÓÃÁ˵ÚÈý·½µÄSDK£¬µ«²¢Ã»Óб£»¤ÕâЩ¹ã¸æSDK´«Ê䏸µÚÈý·½¹ã¸æÉ̵ÄÓû§Êý¾Ý¡£ÕâЩÊý¾Ý°üÂÞÓû§µÄ¸öÈËÉí·ÝÐÅÏ¢ÈçÐÕÃû¡¢ÄêÁä¡¢ÊÕÈëÉõÖÁµç»°ºÅÂëºÍµç×ÓÓʼþµØÖ·µÈ£¬ÕâЩÊý¾Ýͨ¹ýHTTPÒÔδ¼ÓÃܵķ½Ê½´«Ê䣬ºÜÈÝÒ×±»À¹½ØºÍÐ޸쬵¼Ö¶ñÒâÈí¼þѬȾºÍÀÕË÷µÈ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/millions-of-apps-leak-private-user-data-via-leaky-ad-sdks/131251/

4¡¢CCleaner APTÊÓ²ìºóÐø£º¹¥»÷Õßͨ¹ýTeamViewer½øÈëPiriformµÄÍøÂç

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        AvastÑо¿ÈËÔ±Ðû²¼CCleaner APTµÄºóÐøÊÓ²ì½á¹û¡£¹¥»÷ÕßÊ×ÏÈÔÚ2017Äê3ÔÂ11ÈÕͨ¹ýÒ»¸ö¿ª·¢ÈËÔ±ÊÂÇéÕ¾ÉϵÄTeamViewer½øÈëPiriform¹«Ë¾µÄÍøÂ磬ÆäÈçºÎ»ñÈ¡ÓÐЧµÄµÇ¼ƾ¾Ý»¹²»µÃ¶øÖª¡£Æ¾¾ÝÈÕÖ¾Îļþ£¬¹¥»÷ÕßÔÚµ±µØÊ±¼äÁ賿5µã½øÐÐÉøÍ¸£¬ÆäʹÓõÄÓÐЧºÉÔØÊÇΪ´Ë´Î¹¥»÷¶ø¶¨ÖƵÄShadowPad¡£

        Ô­ÎÄÁ´½Ó£ºhttps://blog.avast.com/update-ccleaner-attackers-entered-via-teamviewer

5¡¢Ñо¿ÈËÔ±·¢ÏÖÊý¾Ý¹«Ë¾LocalBloxµÄÔ¼4800ÍòÓû§Êý¾Ý¿É¹ûÈ»·ÃÎÊ

×ðÁú¶¶È¦ - Ϊdu¶øÉú

        UpGuardµÄÑо¿ÈËÔ±·¢ÏÖÊý¾Ý¹«Ë¾LocalBloxµÄÒ»¸öAWS S3¿É¹ûÈ»·ÃÎÊ£¬ÀïÃæ´æ´¢Á˸ù«Ë¾´ÓFacebook¡¢LinkedIn¡¢TwitterºÍ·¿µØ²ú¹«Ë¾ZillowµÈÍøÕ¾ÉÏÊÕ¼¯µÄÔ¼4800ÍòÓû§µÄ¹ûÈ»×ÊÁÏ¡£ÕâЩÊý¾Ý°üÂÞÓû§µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢Êµ¼ÊµØÖ·¡¢£¨LinkedIn£©ÊÂÇéÀúÊ·¼Ç¼¡¢²¿ÃÅÓû§µÄIPºÍµç×ÓÓʼþµØÖ·ÒÔ¼°²¿ÃÅÓû§µÄ¸öÈ˾»×ʲúµÈÐÅÏ¢¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/data-firm-left-profiles-of-48-million-users-on-a-publicly-accessible-aws-server/