ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ40ÖÜ

Ðû²¼Ê±¼ä 2021-10-08

>±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê09ÔÂ27ÈÕÖÁ10ÔÂ03ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´59¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇMicro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´£»Nagios XI repairmysql.sh²»ÕýȷȨÏÞÖ¸ÅÉ´úÂëÖ´ÐЩ¶´£»ECOA BAS controllerÃô¸ÐÐÅϢ鶩¶´£»Tenda AC9 httpd»º³åÇøÒç³ö©¶´£»Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇWindows WPBTÖеÄЩ¶´Ó°ÏìWin8¼°Ö®ºóËùÓÐϵͳ£»Å·ÖÞºô½ÐÖÐÐĹ©Ó¦ÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷£»ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷£»Î¢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb£»CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


>ÖØÒªÄþ¾²Â©¶´Áбí


1.Micro Focus ArcSight Enterprise Security ManagerÔ¶³Ì´úÂëÖ´ÐЩ¶´


Micro Focus ArcSight Enterprise Security Manager´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://portal.microfocus.com/s/article/KM000001960?language=en_US


2.Nagios XI repairmysql.sh²»ÕýȷȨÏÞÖ¸ÅÉ´úÂëÖ´ÐЩ¶´


Nagios XI repairmysql.sh´æÔÚ²»ÕýȷȨÏÞÖ¸ÅÉ©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://www.nagios.com/downloads/nagios-xi/change-log/



3.ECOA BAS controllerÃô¸ÐÐÅϢ鶩¶´


ECOA BAS controller´¦ÖÃHTTP GETÇëÇó´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢¡£


https://www.twcert.org.tw/tw/cp-132-5137-730a6-1.html



4.Tenda AC9 httpd»º³åÇøÒç³ö©¶´


Tenda AC9 httpd /goform/SetStaticRouteCfg´æÔÚ»º³åÇøÒç³ö©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://github.com/grapefruitvul/vulinfo/blob/master/tenda/vul1.md



5.Siemens Solid Edge OBJÎļþCVE-2021-41535ÄÚ´æ´íÎóÒýÓôúÂëÖ´ÐЩ¶´


Siemens Solid Edge SE2021 OBJÎļþ´æÔÚÊͷźóʹÓ鶴£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§½âÎö£¬¿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÕßÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£


https://cert-portal.siemens.com/productcert/pdf/ssa-728618.pdf



 >ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Windows WPBTÖеÄЩ¶´Ó°ÏìWin8¼°Ö®ºóËùÓÐϵͳ


Windows WPBTÖеÄЩ¶´Ó°ÏìWin8¼°Ö®ºóËùÓÐϵͳ.jpg


EclypsiumÑо¿ÍŶӷ¢ÏÖMicrosoft Windowsƽ̨¶þ½øÖƱí(WPBT)ÖдæÔÚÒ»¸ö©¶´£¬¿ÉÓÃÀ´ÔÚϵͳÉÏ°²×°Rootkit¡£¸Ã©¶´Ó°ÏìÁË2012ÄêÖ®ºó¿¯ÐеÄWindows 8¼°¸ü¸ß°æ±¾µÄËùÓÐϵͳ£¬¹¥»÷Õß¿ÉÀûÓø鶴ÔÚϵͳÆô¶¯Ê±ÒÔÄÚºËȨÏÞÔËÐжñÒâ´úÂ롣΢ÈíÌá³öµÄ»º½â´ëÊ©°üÂÞʹÓÃWindows DefenderÓ¦Ó÷¨Ê½¿ØÖÆ£¨WDAC£©¼ÆıÀ´¿ØÖÆÔÚϵͳÖÐÔËÐеĶþ½øÖÆÎļþ£¬»òʹÓÃAppLocker¼ÆıÀ´¿ØÖÆÔÊÐíÔËÐеÄÓ¦Óá£


Ô­ÎÄÁ´½Ó£º


https://www.bleepingcomputer.com/news/security/microsoft-wpbt-flaw-lets-hackers-install-rootkits-on-windows-devices/



2¡¢Å·ÖÞºô½ÐÖÐÐĹ©Ó¦ÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷


Å·ÖÞºô½ÐÖÐÐĹ©Ó¦ÉÌGSSÔâµ½ContiÍÅ»ïµÄÀÕË÷¹¥»÷.jpg


Covisian·¢ÑÔÈ˳Æ£¬ÆäÎ÷°àÑÀºÍÀ­¶¡ÃÀÖÞ·Ö²¿GSSÓÚ9ÔÂ18ÈÕÔâµ½ÁËContiÍÅ»ïµÄÀÕË÷¹¥»÷¡£CovisianÊÇÅ·ÖÞ×î´óµÄ¿Í»§·þÎñºÍºô½ÐÖÐÐĹ©Ó¦ÉÌÖ®Ò»£¬´Ë´Î¹¥»÷µ¼ÖÂÆä´ó²¿ÃÅϵͳÖжÏ£¬Ó°ÏìÁËVodafone Spain¡¢MasMovil ISP¡¢ÂíµÂÀïµÄ¹©Ë®¹«Ë¾ºÍµçÊǪ́µÈ¹«Ë¾ºÍ×éÖ¯¡£²»¾ÃÇ°£¬ÃÀ¹úµÄºô½ÐÖÐÐĺͿͻ§Ö§³Ö·þÎñ¹©Ó¦ÉÌTTECÒ²Ôâµ½ÁËÀÕË÷¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/122570/cyber-crime/gss-ransomware-attack.html



3¡¢ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷


ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔâµ½DDoS¹¥»÷.jpg


ÃÀ¹úVoIPÌṩÉÌBandwidth.comÔÚ½üÆÚÔâµ½ÁËDDoS¹¥»÷£¬µ¼Ö¹ýÈ¥¼¸ÌìÄÚÆäÔÚÈ«ÃÀµÄÓïÒô·þÎñÖжÏ¡£Bandwidth´ÓÃÀ¹ú¶«²¿Ê±¼ä9ÔÂ25ÈÕÏÂÎç3:31¿ªÊ¼³ÂËßÆäϵͳ·ºÆð¹ÊÕÏ£¬Ó°ÏìÁËÓïÒô¡¢ÔöÇ¿ÐÍ911(E911)·þÎñ¡¢ÏûÏ¢·¢Ëͺ͹ÙÍø·ÃÎÊ¡£Bandwidthδ¹ûÈ»·þÎñÖжϵÄÔ­Òò£¬µ«ÆäÔ±¹¤³ÆÊÇDDoS¹¥»÷µ¼ÖµÄ¡£±¾ÔÂVoIP.msÔøÔ⵽ΪÆÚÒ»ÖܵÄDDoS¹¥»÷²¢±»ÀÕË÷450ÍòÃÀÔª£¬Éв»Çå³þBandwidthÊÇ·ñÒ²Ôâµ½ÁËÀàËƵÄÀÕË÷¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/bandwidthcom-is-latest-victim-of-ddos-attacks-against-voip-providers/


4¡¢Î¢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb


΢Èí·¢ÏÖÖ¼ÔÚÇÔÈ¡AD FS¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb.jpg


΢ÈíÍþвÇ鱨ÖÐÐÄ(MSTIC)ÓÚ9ÔÂ27ÈÕÅû¶ÁËÖ¼ÔÚÇÔÈ¡Active DirectoryÁªºÏÉí·ÝÑéÖ¤·þÎñ(AD FS)¹ÜÀíԱƾ¾ÝµÄºóÃÅFoggyWeb¡£¸Ã¶ñÒâÈí¼þÓë¶íÂÞ˹Íâ¹úÇ鱨¾Ö(SVR)µÄºÚ¿ÍÍÅ»ïNobeliumÓйØ£¬ÀÄÓÃÁËSAMLÁîÅÆ¡£Ëü¿ÉÒÔΪ¹¥»÷Õß½ç˵µÄURIÅäÖÃHTTP¼àÌýÆ÷£¨ÕâЩURIÄ£·ÂÁËÄ¿±êAD FSʹÓõĺϷ¨URIµÄ½á¹¹£©£¬À´¼àÌý·¢Ë͵½AD FSµÄHTTP GETºÍPOSTÇëÇ󣬲¢À¹½ØÓë×Ô½ç˵URIģʽƥÅäµÄHTTPÇëÇó¡£


Ô­ÎÄÁ´½Ó£º

https://www.microsoft.com/security/blog/2021/09/27/foggyweb-targeted-nobelium-malware-leads-to-persistent-backdoor/



5¡¢CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ


CISAºÍNSAÁªºÏÐû²¼ÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ.jpg


ÃÀ¹úCISAºÍNSAÔÚ9ÔÂ28ÈÕÁªºÏÐû²¼ÁËÓйØÑ¡ÔñºÍ¼Ó¹ÌVPNµÄÄþ¾²Ö¸ÄÏ¡£Ö¸ÄÏÖ¸³ö£¬×éÖ¯Ó¦¸Ã´ÓÐÅÓþÁ¼ºÃµÄ¹©Ó¦ÉÌÄÇÀïÑ¡Ôñ²úÎÒòΪËûÃÇ»áÒÔ×î¿ìµÄËÙ¶ÈÐÞ¸´ÒÑ֪©¶´¡£Äþ¾²»ú¹¹³Æ£¬VPNÉ豸¿ÉÒÔÊÕ¼¯Æ¾Ö¤¡¢ÓÃÀ´Ô¶³ÌÖ´ÐдúÂë¡¢Ï÷Èõ¼ÓÃÜÁ÷Á¿»á»°µÄ¼ÓÃÜ¡¢½Ù³Ö»á»°ÒÔ¼°¶ÁÈ¡Ãô¸ÐÐÅÏ¢£¬½¨Òé×éÖ¯ÅäÖÃÇ¿¼ÓÃܺÍÉí·ÝÑéÖ¤¡¢½öÔËÐÐÐëÒªµÄ¹¦Ð§ÒÔ¼°±£»¤ºÍ¼à¿Ø¶ÔVPNµÄ·ÃÎÊ¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/09/28/cisa-and-nsa-release-guidance-selecting-and-hardening-vpns