ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ8ÖÜ

Ðû²¼Ê±¼ä 2021-02-22

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ15ÈÕÖÁ02ÔÂ21ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´58¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇEFM ipTIME C200 IP Camera CVE-2020-7848ÃüÁî×¢È멶´£»Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐЩ¶´£»DJI Mavic 2¹Ì¼þÉý¼¶ÃüÁî×¢È멶´£»McAfee Web Gateway troubleshootingÒ³ÌØȨÌáÉý©¶´£»Bloodhound objectId×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊǼÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬Ð¹Â¶120GBÊý¾Ý£»·¨¹úºÍÎÚ¿ËÀ¼ÁªºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©£»°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCE©¶´£¬ÏÂÔس¬10ÒڴΣ»Cyble·¢ÏÖÀûÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂçµöÓã¹¥»÷»î¶¯£»Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Ä꿪ʼ»îÔ¾¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.EFM ipTIME C200 IP Camera CVE-2020-7848ÃüÁî×¢È멶´


EFM ipTIME C200 IP Camera /login.cgi?logout=1´æÔÚÊäÈ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýCOOKIEÖµÖ´ÐÐÈÎÒâOSÃüÁî¡£

https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=35905


2.Google Chrome Data TransferÕ»Òç³ö´úÂëÖ´ÐЩ¶´


Google Chrome Data Transfer´æÔÚÕ»Òç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄWEBÒ³£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_16.html


3.DJI Mavic 2¹Ì¼þÉý¼¶ÃüÁî×¢È멶´


DJI Mavic 2 Remote Controller dji_sysδ¹ýÂËÎļþÖÐÌØÊâÊôÐÔ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇó£¬Í¨¹ý¹Ì¼þÉý¼¶°üÖ´ÐдúÂë¡£

http://kth.diva-portal.org/smash/get/diva2:1463784/FULLTEXT01.pdf


4.McAfee Web Gateway troubleshootingÒ³ÌØȨÌáÉý©¶´


McAfee Web Gateway troubleshootingÒ³´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿Éͨ¹ýÓû§½Ó¿ÚÖ´ÐÐÈÎÒâÃüÁÌáÉýȨÏÞ¡£

https://kc.mcafee.com/corporate/index?page=content&id=SB10349


5.Bloodhound objectId×¢È멶´


Bloodhound objectId²ÎÊý´¦ÖôæÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢Èë¶ñÒâÃüÁî²¢Ö´ÐС£

https://github.com/BloodHoundAD/BloodHound/issues/338


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢¼ÓÄôó×â³µ¹«Ë¾Ñ¬È¾DarkSide£¬Ð¹Â¶120GBÊý¾Ý


1.jpg


¼ÓÄôóÁìÏȵÄÆû³µºÍ¿¨³µ×âÁÞ¹«Ë¾Canadian Discount Car and Truck RentalsÊܵ½DarkSideÀÕË÷Èí¼þ¹¥»÷£¬ºÚ¿ÍÉù³ÆÒÑÇÔÈ¡ÁË120GBµÄÊý¾Ý£¬°üÂÞ½ðÈÚ¡¢Êг¡ÓªÏú¡¢ÒøÐС¢ÕÊ»§ºÍ¼ÓÃËÉÌÊý¾Ý¡£Õⳡ¹¥»÷ÖжÏÁ˸ù«Ë¾ÔÚdiscountcar.comÉϵÄÔÚÏß×âÁÞ·þÎñ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/leading-canadian-rental-car-company-hit-by-darkside-ransomware/


2¡¢·¨¹úºÍÎÚ¿ËÀ¼ÁªºÏµ·»ÙÀÕË÷ÍÅ»ïEgregorµÄ»ù´¡ÉèÊ©


2.jpg


·¨¹úºÍÎÚ¿ËÀ¼Ö´·¨²¿ÃŵÄÁªºÏÐж¯´þ²¶ÁËÎÚ¿ËÀ¼µÄEgregorÀÕË÷Èí¼þµÄ¼¸Ãû³ÉÔ±£¬ÕâЩ³ÉÔ±µÄÊÂÇéÊÇÈëÇÖ¹«Ë¾ÍøÂç²¢²¿ÊðÀÕË÷Èí¼þ¡£¾Ý±¨µÀ£¬¸ÃÐж¯ÊÇÔÚÈ¥ÄêÇïÌìÊÕµ½°ÍÀèÀÕË÷Èí¼þ·¸×ïÍÅ»ïµÄͶËߺó£¬ÓÉ°ÍÀè´óÉó·¨ÔºÆô¶¯µÄ¡£Ä¿Ç°£¬EgregorµÄTorÍøÕ¾´¦ÓÚÀëÏß״̬¡£ÓÉÓÚÎÞ·¨·ÃÎÊTor¸¶¿îÕ¾µã£¬Êܺ¦ÕßÎÞ·¨ÁªÏµµ½ÀÕË÷Õߣ¬Ò²ÎÞ·¨Ö§¸¶Êê½ð»òÏÂÔؽâÃÜÆ÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/egregor-ransomware-members-arrested-by-ukrainian-french-police/


3¡¢°²×¿Ó¦ÓÃSHAREitÖÐδÐÞ¸´µÄRCE©¶´£¬ÏÂÔس¬10ÒÚ´Î


3.png


Ò»¸ö±»ÏÂÔØÁè¼Ý 10 ÒÚ´ÎµÄ Android Ó¦Ó÷¨Ê½°üÂÞÁËδÐÞ²¹µÄ©¶´£¬¶øÕâ¸ö°üÂÞ©¶´µÄÓ¦Ó÷¨Ê½µÄÐÞ¸´Ê±¼äÒѾ­Áè¼ÝÁËÈý¸öÔ¡£ÕâЩ©¶´Ó°ÏìÁË Android °æ±¾µÄ SHAREit£¬Ò»¸öÔÊÐíÓû§ÓëÅóÓÑ»ò¸öÈËÉ豸¹²ÏíÎļþµÄÒƶ¯Ó¦Ó÷¨Ê½¡£Trend MicroµÄÒƶ¯Íþв·ÖÎöʦEcho DuanÔÚÒ»·Ý³ÂËßÖÐ˵£¬¿ÉÒÔÀûÓÃÕâЩ©¶´ÔÚ°²×°ÁËSHAREitÓ¦Ó÷¨Ê½µÄÖÇÄÜÊÖ»úÉÏÔËÐжñÒâ´úÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-bugs-left-unpatched-in-android-app-with-one-billion-downloads/


4¡¢Cyble·¢ÏÖÀûÓÃNgrokƽ̨µÄÐÂÒ»ÂÖÍøÂçµöÓã¹¥»÷»î¶¯


4.png


ÍþвÇ鱨¹«Ë¾CybleµÄÑо¿ÈËÔ±·¢ÏÖÁËÕë¶Ô¶à¸öÀÄÓÃngrokƽ̨µÄ×éÖ¯µÄÐÂÒ»²¨ÍøÂçµöÓã¹¥»÷£¬ngrokƽ̨ÊÇͨÍùµ±ÌïÖ÷»úµÄÒ»¸öÄþ¾²ÇÒ¿É×ÔÊ¡µÄËíµÀ¡£ngrokÊÇÒ»¸ö¿çƽ̨ӦÓ÷¨Ê½£¬ÓÃÓÚ½«µ±µØ¿ª·¢·þÎñÆ÷¹ûÈ»µ½Internet£¬Í¨¹ý´´½¨µ½µ±ÌïÖ÷»úµÄ³¤Á´½ÓTCPËíµÀ£¬¸Ã·þÎñÆ÷ËƺõÍйÜÔÚngrokµÄ×ÓÓò£¨ÀýÈç4f421deb219c[.]ngrok[.]io£©ÉÏ¡£×¨¼ÒÃÇÖ¸³ö£¬ngrok·þÎñÆ÷Èí¼þÔËÐÐÔÚVPS»òרÓ÷þÎñÆ÷ÉÏ£¬¿ÉÒÔÈƹýNATÓ³ÉäºÍ·À»ðǽÏÞÖÆ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114644/cyber-crime/ngrok-phishing-attacks.html


5¡¢Unit42³Æ½©Ê¬ÍøÂçWatchDog×Ô2019Ä꿪ʼ»îÔ¾


5.png


WatchDog¼ÓÃÜÍÚ¿ó½©Ê¬ÍøÂçÓÉPalo Alto NetworksµÄÍþвÇ鱨²¿ÃÅ42²¿ÃÅ·¢ÏÖ£¬¸Ã½©Ê¬ÍøÂç×Ô2019Äê1ÔÂÒÔÀ´Ò»Ö±»îÔ¾¡£Ñо¿ÈËÔ±ÌåÏÖ£¬WatchDogÓÉGoÓïÑÔ±àд¶ø³É¡£Æ¾¾ÝUnit 42ÍŶӶÔWatchDog¶ñÒâÈí¼þµÄ·ÖÎö£¬Ñо¿ÈËÔ±Ô¤¼Æ¸Ã½©Ê¬ÍøÂçÒѹ¥»÷500µ½1000¸öÄ¿±ê¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/windows-and-linux-servers-targeted-by-new-watchdog-botnet-for-almost-two-years/