ÐÅÏ¢Äþ¾²Öܱ¨-2020ÄêµÚ47ÖÜ

Ðû²¼Ê±¼ä 2020-11-23

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê11ÔÂ16ÈÕÖÁ11ÔÂ22ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´61¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇAviatrix Systems Controller APIÈÎÒâÎļþÖ´ÐЩ¶´£»Google Go CVE-2020-28366´úÂë×¢È멶´£»Paradox IP150 CVE-2020-25189»º³åÇøÒç³ö©¶´£»QNAP QTS CVE-2020-2492ÃüÁî×¢È멶´£»Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç³ö©¶´ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǺڿÍÔÚ°µÍø¹ûÈ»320Íò¸öPluto TVÓû§µÄÐÅÏ¢£»Snow SoftwareÐû²¼2021ÄêÓйØIT¹ÜÀíµÄ·ÖÎö³ÂËߣ»Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÎïµÄ·ÖÎö³ÂËߣ»Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁ飻Ñо¿ÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÈ¡ÐÅÏ¢ ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖÐ ¡£


ÖØÒªÄþ¾²Â©¶´Áбí


1.Aviatrix Systems Controller APIÈÎÒâÎļþÖ´ÐЩ¶´


Aviatrix Systems Controller APIʵÏֵĿÉÖ´ÐÐÎļþ´æÔÚδÊÚȨ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐдúÂë ¡£

https://www.criticalstart.com/multiple-vulnerabilities-discovered-in-aviatrix/


2.Google Go CVE-2020-28366´úÂë×¢È멶´


Google Go´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢Èë´úÂë²¢ÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐ ¡£

https://www.vuxml.org/freebsd/db4b2f27-252a-11eb-865c-00155d646400.html



3.Paradox IP150 CVE-2020-25189»º³åÇøÒç³ö©¶´


Paradox IP150´æÔÚÕ»»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë»òʹӦÓ÷¨Ê½Í߽⠡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-02


4.QNAP QTS CVE-2020-2492ÃüÁî×¢È멶´


QNAP QTS´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâÃüÁî ¡£

https://www.qnap.com/en/security-advisory/qsa-20-09


5.Real Time Automation 499ES EtherNet/IPÕ»»º³åÇøÒç³ö©¶´


Real Time Automation 499ES EtherNet/IP´æÔÚÕ»»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë»òʹӦÓ÷¨Ê½Í߽⠡£

https://us-cert.cisa.gov/ics/advisories/icsa-20-324-03


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢ºÚ¿ÍÔÚ°µÍø¹ûÈ»320Íò¸öPluto TVÓû§µÄÐÅÏ¢


1.png


ÉÏÖÜÈý£¬ºÚ¿ÍÔÚ°µÍø¹ûÈ»ÁË°üÂÞ320Íò¸öPluto TVÓû§ÐÅÏ¢µÄÊý¾Ý¿â ¡£Í¨¹ýÊý¾Ý¿âÑù±¾¿ÉÖª£¬Ð¹Â¶Êý¾Ý°üÂÞÓû§Ãû¡¢µç×ÓÓʼþµØÖ·¡¢bcrypt¹þÏ£ÃÜÂë¡¢ÉúÈÕ¡¢É豸ƽ̨ºÍIPµØÖ· ¡£ºÚ¿ÍÉù³Æ´Ë´ÎÊý¾Ýй¶ÊÇÓÉShinyHuntersµ¼ÖµÄ£¬¶ø¸ÃÊý¾Ý¿â¿ÉÄÜÊÇÁ½Äêǰ鶵Ä£¬×îмǼÊÇÔÚ2018Äê10ÔÂ12ÈÕ´´½¨µÄ ¡£Ä¿Ç°£¬Pluto TVÉÐδ֤ʵÊÇ·ñ·¢ÉúÁËÊý¾Ýй¶£¬½öÌåÏÖËûÃÇÕýÔÚÊÓ²ìÖÐ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-shares-32-million-pluto-tv-accounts-for-free-on-forum/


2¡¢Snow SoftwareÐû²¼2021ÄêÓйØIT¹ÜÀíµÄ·ÖÎö³ÂËß


2.png


Snow SoftwareÐû²¼2021ÄêÓйØIT¹ÜÀíµÄ·ÖÎö³ÂËß ¡£³ÂËßÏÔʾ£¬63£¥µÄÊÜ·ÃÕ߳Ƽ¼Êõ¹ÜÀí±äµÃÔ½À´Ô½À§ÄÑ£¬ÆóÒµÔÚÈí¼þ¡¢Ó²¼þ¡¢SaaSºÍÔÆÉϵļ¼ÊõÖ§³öÈ«ÃæÔö¼Ó ¡£87£¥µÄITÁìµ¼ÕßÌåÏÖ£¬¹ýÈ¥Ò»ÄêÖÐËûÃÇÒѾ­¹ýMicrosoft¡¢IBM¡¢Oracle¡¢AdobeºÍSAPµÈÈí¼þ¹©Ó¦É̵ÄÉó¼Æ£¬Ö»ÓÐ51£¥µÄÈ˵£ÓÇÏÂÒ»ÄêµÄÉó¼Æ ¡£´ËÍ⣬ǿ´óµÄ¼¼ÊõÇ鱨ʹITÁìµ¼ÕßÄܸüÓÐЧµØ½â¾öËûÃǵÄÊ×ÒªÈÎÎñ£¬µ«Ö»ÓÐ14%µÄITÁìµ¼Õßµ½´ïÁ˳ÉÊì¼¼ÊõÖÇÄÜµÄ³ß¶È ¡£


Ô­ÎÄÁ´½Ó£º

https://www.snowsoftware.com/company/news/cios-face-competing-and-complex-priorities-2021-finds-new-snow-software-report


3¡¢Intel 471Ðû²¼°µÍøÖÐ25ÖÖÖ÷ÒªRaaS²úÎïµÄ·ÖÎö³ÂËß


3.png


Intel 471Ðû²¼ÁËÓйذµÍøÖеÄ25ÖÖÖ÷ÒªRaaS²úÎïµÄ·ÖÎö³ÂËß ¡£Intel 471ÌåÏÖ£¬Ëüƾ¾ÝRaaSµÄÅÓ´óˮƽ¡¢¹¦Ð§ºÍÀúÊ·½«ÕâЩÀÕË÷Èí¼þ·ÖΪÈý¸öÌõÀí ¡£µÚÒ»²ãΪµ±½ñ×îÖøÃûµÄÀÕË÷Èí¼þ£¬°üÂÞREvil¡¢Netwalker¡¢DopplePaymer¡¢Egregor£¨Maze£©ºÍRyuk ¡£µÚ¶þ²ãΪÀÕË÷Èí¼þÊÀ½çµÄÐÂÐË´ú±í£¬°üÂÞAvaddon¡¢Conti¡¢Clop¡¢DarkSide¡¢Mespinoza£¨Pysa£©¡¢RagnarLocker¡¢Ranzy£¨Ako£©¡¢SunCryptºÍThanos ¡£µÚÈý²ãΪÐÂÐû²¼µÄRaaS²úÎ°üÂÞCVartek.u45¡¢Exorcist¡¢Gothmog¡¢Lolkek¡¢Muchlove¡¢Nemty¡¢Rush¡¢Wally¡¢Xinof¡¢ZeoticusºÍZagreuS ¡£


Ô­ÎÄÁ´½Ó£º

https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/


4¡¢Google Nest·þÎñÖжϵ¼ÖÂÅ·ÃÀÓû§ÖÇÄܼҾÓʧÁé


4.png


±¾ÖܶþGoogle Nest·þÎñ´ó¹æÄ£ÖжÏ£¬µ¼Ö±±ÃÀºÍÅ·ÖÞÓû§ÖÇÄܼҾÓʧÁé ¡£ÖܶþÁ賿£¬¹È¸è×ܲ¿Ðû²¼ÏûÏ¢³Æ£¬Æä·¢ÏÖÒ»¸öÎÊÌâ»áÓ°Ïì¹È¸èNestÉ豸ºÍNestÓ¦Óà ¡£¸ÃÎÊÌâµ¼ÖÂÖÇÄܼҾÓÓû§ÎÞ·¨µÇ¼ÆäÕË»§£¬ÎÞ·¨Ê¹ÓÃÖÇÄÜÊÖ»úԢĿÊÓƵֱ²¥£¬ÎÞ·¨µ÷ÕûºãοØÖÆÆ÷£¬Ò²ÎÞ·¨ÓëNestµÄÈκÎϵÁвúÎﻥ¶¯£¬ÆäÖб±ÃÀºÍ±±Å·µÄÓû§Êܵ½µÄÓ°Ïì×î´ó ¡£Æäʵ£¬¸Ã·þÎñÔÚ2ÔÂÒ²·¢ÉúÁËÀàËƵÄÖжÏ£¬Á¬ÐøÁË16¸öСʱ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.com/2020/11/17/google_nest_outage/


5¡¢Ñо¿ÈËÔ±·¢ÏÖÊýÊ®¸öAWS API¿É±»ÓÃÀ´ÇÔÈ¡ÐÅÏ¢


5.png


Palo Alto NetworksÑо¿ÈËÔ±·¢ÏÖÁË16¸ö²îÒìAmazon Web Services£¨AWS£©ÖеÄ22¸öAPI£¬¿É±»ÀÄÓÃÀ´»ñÈ¡ÐÅÏ¢ ¡£¸ÃÎÊÌâÊÇÓÉÓÚAWSºó¶Ë»áÖ÷¶¯ÑéÖ¤¸½¼Óµ½×ÊÔ´µÄËùÓлùÓÚ×ÊÔ´µÄ¼ÆıËùµ¼Ö嵀 ¡£Èç¹û¼ÆıÖаüÂÞ²»´æÔÚµÄÉí·Ý£¬Ôò´´½¨»ò¸üмÆıµÄAPIµ÷Óý«Ê§°Ü£¬¹¥»÷Õß¿ÉÒÔÀÄÓô˹¦Ð§À´¼ì²éAWSÕË»§ÖеÄÏÖÓÐÉí·Ý ¡£Ñо¿ÈËÔ±³Æ£¬¸Ã¹¥»÷¿ÉÔÚaws¡¢aws-us-govºÍaws-cn·ÖÇøÉϽøÐУ¬Ò×Êܹ¥»÷µÄAWS·þÎñ°üÂÞAWS S3¡¢AWS KMSºÍAWS SQS ¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/researchers-find-tens-aws-apis-leaking-sensitive-data