ÐÅÏ¢Äþ¾²Öܱ¨-2018ÄêµÚ42ÖÜ

Ðû²¼Ê±¼ä 2018-10-22

Ò»¡¢±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2018Äê10ÔÂ15ÈÕÖÁ21ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´57¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇLibssh CVE-2018-10933·þÎñÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý©¶´£»Pivotal Spring Security OAuthȨÏÞÌáÉý©¶´£»Dell EMC Secure Remote ServicesȨÏÞÌáÉý©¶´£»Opto 22 PAC Control CVE-2018-14807»º³åÇøÒç³ö©¶´£»HPE Intelligent Management Center PLAT´úÂëÖ´ÐЩ¶´¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄÂÃÐмǼй¶£»ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷£»Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Ç¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ£»±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬FBIÒѽéÈëÊӲ죻Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼ÄÜÔ´¹«Ë¾µÄÐÂAPT×éÖ¯GreyEnergy¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£

¶þ¡¢ÖØÒªÄþ¾²Â©¶´Áбí


1. Libssh CVE-2018-10933·þÎñÆ÷Éí·ÝÑéÖ¤ÈÆ¹ý©¶´


Libsshͨ¹ýÏò·þÎñÆ÷ÌṩSSH2_MSG_USERAUTH_SUCCESSÏûÏ¢À´È¡´ú·þÎñÆ÷Õý³£Æô¶¯Éí·ÝÑéÖ¤µÄSSH2_MSG_USERAUTH_REQUESTÏûϢʱ´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÎÞÐèÑé֤δÊÚȨ·ÃÎÊ¡£


https://www.libssh.org/2018/10/16/libssh-0-8-4-and-0-7-6-security-and-bugfix-release/

2. Pivotal Spring Security OAuthȨÏÞÌáÉý©¶´


Pivotal Spring Security OAuth´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÌáÉýȨÏÞ¡£

https://pivotal.io/security/cve-2018-15758

3. Dell EMC Secure Remote ServicesȨÏÞÌáÉý©¶´


Dell EMC Secure Remote Services°üÂÞ¶à¸ö¾ßÓÐÈ«¾Ö¿É¶ÁȨÏÞµÄÅäÖÃÎļþ£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇó£¬ÌáÉýȨÏÞ¡£


https://www.dellemc.com/

4. Opto 22 PAC Control CVE-2018-14807»º³åÇøÒç³ö©¶´

Opto 22 PAC Control´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½»òÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.opto22.com/support/resources-tools/knowledgebase/kb87547

5. HPE Intelligent Management Center PLAT´úÂëÖ´ÐЩ¶´


HPE Intelligent Management Center PLAT´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓé¶´Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐÈÎÒâ´úÂë¡£


https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03901en_us

Èý¡¢ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ÃÀ¹ú·À²¿£¨Îå½Ç´óÂ¥£©Ô¼3ÍòÃûÔ±¹¤µÄÂÃÐмǼй¶

×ðÁú¶¶È¦ - Ϊdu¶øÉú

ÃÀ¹ú¹ú·À²¿£¨Îå½Ç´óÂ¥£©µÄ²¿Ãžü·½ºÍÎÄÖ°ÈËÔ±µÄ¸öÈËÐÅÏ¢ºÍÐÅÓÿ¨Êý¾Ýй¶£¬Ô¼3ÍòÈËÊܵ½Ó°Ïì¡£ÕâÒ»Êý¾Ýй¶Ê¼þ¿ÉÄÜ·¢ÉúÔÚ¼¸¸öÔÂǰ£¬µ«Ö±µ½×î½ü²Å±»·¢ÏÖ¡£¸ÃʼþÉæ¼°µ½Ò»¼ÒΪ¹ú·À²¿Ìṩ·þÎñµÄµÚÈý·½¹©Ó¦ÉÌ£¬Ä¿Ç°¸Ã¹©Ó¦É̵ÄÉí·ÝÈÔÈ»²»Ã÷È·¡£ÕâһʼþÈÔÈ»ÔÚ½øÒ»²½µÄÊÓ²ìÖ®ÖУ¬µ«Ã»ÓÐÈκλúÃÜÐÅÏ¢Ô⵽й¶¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77097/data-breach/pentagon-travel-records-data-breach.html

2¡¢ÎÚ¿ËÀ¼Õþ¸®»ú¹¹ÔÙÔâAPT×éÖ¯BlackEnergyÏ®»÷

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ÎÚ¿ËÀ¼Äþ¾²¾Ö£¨SBU£©ÌåÏÖ×î½ü¶íÂÞ˹APT×éÖ¯BlackEnergyÔÙ´ÎÕë¶ÔÎÚ¿ËÀ¼Õþ¸®»ú¹¹µÄÐÅϢϵͳºÍµçÐÅϵͳÌᳫ¹¥»÷¡£SBUר¼ÒÖ¸³ö£¬¹¥»÷ÕßʹÓÃÁËеĶñÒâÈí¼þ£¬Æä¹¦Ð§°üÂÞÔ¶³Ì¹ÜÀí²Ù×÷ϵͳÒÔ¼°Îļþ¸´ÖÆ¡¢¼à¿ØÓû§ÐÐΪºÍÀ¹½ØÃÜÂëµÈ¡£Æ¾¾ÝSBUºÍÒ»¸öÄþ¾²³§É̵ÄÊӲ죬¹¥»÷ÖÐÉæ¼°µ½µÄ¶ñÒâÈí¼þÊÇIndustroyerºóÃŵÄбäÌå¡£´ËÍ⣬SBU»¹·¢ÏÖÁËÊôÓÚ¸ÃAPT×éÖ¯µÄ¶ÀÕ¼¹¤¾ß¡£


Ô­ÎÄÁ´½Ó£º
https://www.ukrinform.net/rubric-crime/2557323-russian-hackers-mount-cyberattack-on-ukraines-state-bodies.html

3¡¢Áè¼Ý3500ÍòÃÀ¹úÑ¡ÃñµÄ¼Ç¼ÔÚºÚ¿ÍÂÛ̳ÉϳöÊÛ

×ðÁú¶¶È¦ - Ϊdu¶øÉú


±¾ÖÜÒ»Anomali LabsºÍIntel 471µÄÑо¿ÈËÔ±ÔÚ°µÍøÂÛ̳ÉÏ·¢ÏÖÒ»¸ö°üÂÞ´óÁ¿Ñ¡ÃñÊý¾ÝµÄÊý¾Ý¿âÕýÔÚ³öÊÛ¡£¸ÃÊý¾Ý¿â°üÂÞÀ´×Ô19¸öÖݵĶà´ï3500ÍòÌõÑ¡Ãñ¼Ç¼¡£ÕâЩ¼Ç¼°üÂÞÐÕÃû¡¢µç»°ºÅÂ롢סַ¡¢Í¶Æ±ÀúÊ·ºÍÆäËüͶƱÊý¾ÝµÈ¡£Ñо¿ÈËÔ±¶Ô¸ÃÊý¾Ý¿âµÄÑù±¾½øÐÐÁËÉó²é£¬È·ÈÏÕâЩÊý¾ÝÓÐЧ¶øÇÒ¸ÃÊý¾Ý¿â¾ßÓи߶ȵĿÉÐŶÈ¡£¼øÓÚÃÀ¹ú2018ÄêµÄÖÐÆÚÑ¡¾Ù¼´½«µ½À´£¬ÕâЩй¶µÄÊý¾Ý¿ÉÄܱ»¹¥»÷ÕßÓÃÀ´ÆÆ»µÑ¡¾Ù»ò½øÐÐÉí·Ý͵ÇԵȶñÒâ»î¶¯¡£


Ô­ÎÄÁ´½Ó£º
https://threatpost.com/up-to-35-million-2018-voter-records-for-sale-on-hacking-forum/138295/

4¡¢±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳÔâÀÕË÷Èí¼þ¹¥»÷£¬FBIÒѽéÈëÊÓ²ì

×ðÁú¶¶È¦ - Ϊdu¶øÉú


±¾ÖÜÒ»ONWASA£¨°ºË¹Â幩ˮºÍÎÛË®¹ÜÀí¾Ö£©Ðû²¼ÏûÏ¢³Æ£¬±±¿¨ÂÞÀ´ÄÉÖÝË®ÎñϵͳµÄÄÚ²¿¼ÆËã»úϵͳ£¨°üÂÞ·þÎñÆ÷ºÍ¸öÈ˵çÄÔ£©Ôâµ½ÀÕË÷Èí¼þEmotet¹¥»÷¡£ONWASAûÓÐÅû¶¾ßÌåµÄÊê½ð½ð¶î¡£¸Ã¹¥»÷·¢ÉúÔÚ10ÔÂ4ÈÕ£¬Çé¿öËæºóÒѵõ½¿ØÖÆ¡£ËäȻûÓпͻ§ÐÅÏ¢Ôڴ˴ι¥»÷ÖÐÊܵ½Ó°Ï죬µ«Ðí¶àÊý¾Ý¿âÐèÒªÖØ½¨¡£Ä¿Ç°FBI¡¢¹úÍÁÄþ¾²²¿ºÍ±±¿¨ÂÞÀ´ÄÉÖÝÕþ¸®ÒѽéÈëÊӲ졣


Ô­ÎÄÁ´½Ó£º
https://www.securityweek.com/feds-investigate-after-hackers-attack-water-utility

5¡¢Ñо¿ÍŶӷ¢ÏÖÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼ÄÜÔ´¹«Ë¾µÄÐÂAPT×éÖ¯GreyEnergy

×ðÁú¶¶È¦ - Ϊdu¶øÉú


ESETÑо¿ÍŶӷ¢ÏÖÒ»¸öеÄAPT×éÖ¯GreyEnergy£¬¸ÃAPT×éÖ¯±»ÈÏΪÊÇBlackEnergyµÄ¼Ì³ÐÕß¡£ÔÚ¹ýÈ¥ÈýÄêÄÚ£¬GreyEnergyÖ÷ÒªÕë¶ÔÎÚ¿ËÀ¼ºÍ²¨À¼µÄÄÜÔ´¹«Ë¾µÈ¸ß¼ÛֵĿ±ê¡£GreyEnergyµÄ¶ñÒâÈí¼þ¿ò¼ÜÓëBlackEnergy¾ßÓкܶàÏàËÆÖ®´¦¡£Ñо¿ÈËÔ±²¢Ã»ÓÐÊӲ쵽רÃÅÕë¶ÔICSµÄ¶ñÒâÈí¼þÄ£¿é£¬µ«GreyEnergyµÄ¹¥»÷¼ÆÄ±Ò»Ö±ÊÇÕë¶ÔÒªº¦»ù´¡ÉèÊ©ÖеÄSCADAÊÂÇéÕ¾ºÍ·þÎñÆ÷µÈ¡£


Ô­ÎÄÁ´½Ó£º
https://www.welivesecurity.com/2018/10/17/greyenergy-updated-arsenal-dangerous-threat-actors/


ÉùÃ÷£º±¾×ÊѶÓɶ¶È¦Îª¶Ä¶øÉúάËûÃüÄþ¾²Ð¡×é·­ÒëºÍÕûÀí