Ñо¿ÍŶӳÆNTLMÖм̹¥»÷DFSCoerce¿ÉÐ®ÖÆWindowsÓò

Ðû²¼Ê±¼ä 2022-06-22
1¡¢Ñо¿ÍŶӳÆNTLMÖм̹¥»÷DFSCoerce¿ÉÐ®ÖÆWindowsÓò

      

¾Ý6ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬Ñо¿ÍŶӷ¢Ã÷ÁËÃûΪDFSCoerceµÄÐÂNTLMÖм̹¥»÷£¬£¬£¬£¬£¬ £¬£¬¿ÉʹÓÃMicrosoftµÄÂþÑÜʽÎļþϵͳMS-DFSNMÀ´ÍêÈ«¿ØÖÆWindowsÓò¡£¡£¡£¡£¡£¡£¡£DFSCoerceµÄ¾ç±¾»ùÓÚPetitPotamµÄÎó²îʹÓ㬣¬£¬£¬£¬ £¬£¬²¢Ê¹ÓÃÁËMS-DFSNM¶ø·ÇMS-EFSRPC£¬£¬£¬£¬£¬ £¬£¬ÕâÊÇÒ»ÖÖ¿ÉÒÔͨ¹ýRPC½Ó¿ÚÖÎÀíWindowsÂþÑÜʽÎļþϵͳ(DFS)µÄЭÒé¡£¡£¡£¡£¡£¡£¡£¾­ÓɲâÊÔ£¬£¬£¬£¬£¬ £¬£¬ÕâÖÖеÄNTLMÖм̹¥»÷ºÜÈÝÒ×ÈöÔWindowsÓò¾ßÓлá¼ûȨÏÞµÄÓû§³ÉΪÓòÖÎÀíÔ±¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬µÖÓù´ËÀ๥»÷µÄ×î¼ÑÒªÁìÊÇ×ñÕÕ΢ÈíÐû²¼µÄ¹ØÓÚ»º½âPetitPotam NTLMÖм̹¥»÷µÄ½¨Òé¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/new-dfscoerce-ntlm-relay-attack-allows-windows-domain-takeover/


2¡¢CloudflareÍøÂçÉèÖùýʧµ¼ÖÂÊý¾ÝÖÐÐĺÍЧÀÍ´ó¹æÄ£ÖÐÖ¹

      

¾Ý±¨µÀ£¬£¬£¬£¬£¬ £¬£¬CloudflareÔÚ6ÔÂ21ÈÕ±¬·¢ÁË´ó¹æÄ£µÄÖÐÖ¹£¬£¬£¬£¬£¬ £¬£¬Ó°ÏìÁËÊ®¶à¸öÊý¾ÝÖÐÐĺÍÊý°Ù¸öÔÚÏ߯½Ì¨ºÍЧÀÍ¡£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖ£¬£¬£¬£¬£¬ £¬£¬´Ë´ÎÖÐÖ¹ÊÇÐÞ¸ÄÍøÂçÉèÖõ¼ÖµÄ£¬£¬£¬£¬£¬ £¬£¬´Ë¾Ù±¾ÒâÊÇÌá¸ßÍøÂ絯ÐÔ¡£¡£¡£¡£¡£¡£¡£ÖÐÖ¹×îÏÈÓÚ06:27 UTC£¬£¬£¬£¬£¬ £¬£¬Óû§ÔÚ»á¼ûÕâÐ©ÍøÕ¾Ê±»áÊÕµ½500 errorsÌáÐÑ¡£¡£¡£¡£¡£¡£¡£µÚÒ»¸öÊý¾ÝÖÐÐÄÔÚ06:58 UTCÖØÐÂÉÏÏߣ¬£¬£¬£¬£¬ £¬£¬µ½07:42 UTCËùÓÐÊý¾ÝÖÐÐͼ»Ö¸´Õý³£ÊÂÇé¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄµØÇø½öÕ¼CloudflareËùÓÐÍøÂçµÄ4%£¬£¬£¬£¬£¬ £¬£¬µ«Ó°ÏìÁËCloudflare´¦Öóͷ£µÄËùÓÐHTTPÇëÇóµÄÔ¼50%£¬£¬£¬£¬£¬ £¬£¬Éæ¼°Amazon¡¢Twitch¡¢Steam¡¢Telegram¡¢DiscordºÍGitlabµÈÍøÕ¾¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/technology/massive-cloudflare-outage-caused-by-network-configuration-error/


3¡¢GoogleÅû¶Apple SafariÎó²îCVE-2022-22620µÄϸ½Ú

      

6ÔÂ14ÈÕ£¬£¬£¬£¬£¬ £¬£¬Google Project ZeroÅû¶ÁËApple SafariÖÐÒѱ»Ê¹ÓõÄÎó²îµÄϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÕâÊÇWebKit×é¼þÖеÄÒ»¸öÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ £¬£¬×·×ÙΪCVE-2022-22620£¬£¬£¬£¬£¬ £¬£¬¿Éͨ¹ýÌØÖÆµÄWebÄÚÈÝʹÓò¢µ¼ÖÂí§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÔçÔÚ2013Äê¾ÍÒѱ»ÐÞ¸´£¬£¬£¬£¬£¬ £¬£¬µ«ÔÚ2016ÄêµÄ´ó¹æÄ£Öع¹ÊÂÇéÖÐÔٴα»ÒýÈë¡£¡£¡£¡£¡£¡£¡£Ö±µ½2022Äê2ÔÂÉÏÑ®£¬£¬£¬£¬£¬ £¬£¬AppleÐû²¼Á˸ÃÎó²îµÄ²¹¶¡£¬£¬£¬£¬£¬ £¬£¬²¢È·¶¨Æä¿ÉÄÜÒѱ»Æð¾¢Ê¹Óᣡ£¡£¡£¡£¡£¡£


https://googleprojectzero.blogspot.com/2022/06/an-autopsy-on-zombie-in-wild-0-day.html


4¡¢ZScaler·¢Ã÷Õë¶ÔÃÀ¹ú¾üÊ¡¢ITºÍÒ½ÁƵÈÐÐÒµµÄ´¹ÂÚ¹¥»÷

      

ýÌå6ÔÂ20ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬ÐÂÒ»ÂÖ´¹ÂڻһֱÔÚÕë¶ÔÃÀ¹úµÄ¾üÊ¡¢IT¡¢ÖÆÔ칩ӦÁ´¡¢Ò½ÁƱ£½¡ºÍÖÆÒ©µÈÁìÓòµÄ×éÖ¯£¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÇÔÈ¡Microsoft Office 365ºÍOutlookƾ֤¡£¡£¡£¡£¡£¡£¡£ZScaler³Æ£¬£¬£¬£¬£¬ £¬£¬´Ë´Î»î¶¯Óë2020Äê7Ô·¢Ã÷µÄÁíÒ»´Î»î¶¯µÄÕ½ÂÔ¡¢ÊÖÒպͳÌÐò(TTP)¸ß¶ÈÖØµþ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓÃÁËÈÕ±¾µÄµç×ÓÓʼþЧÀÍÀ´·¢ËÍÓʼþ£¬£¬£¬£¬£¬ £¬£¬²¢Î±Ôì·¢¼þÈ˵ĵصã¡£¡£¡£¡£¡£¡£¡£Óʼþ°üÀ¨Ò»¸öHTML¸½¼þ£¬£¬£¬£¬£¬ £¬£¬½«Ä¿µÄÖØ¶¨Ïòµ½´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£¡£Ö®ºó»áÊ×ÏȶÔÄ¿µÄ¾ÙÐÐCAPTCHA¼ì²é£¬£¬£¬£¬£¬ £¬£¬Ö¼ÔÚÈÆ¹ý¼ì²â²¢Ê¹Æä¿´ÆðÀ´¸üÕýµ±£¬£¬£¬£¬£¬ £¬£¬ÕâÒ»ÒªÁìÒ²ÔøÓÃÓÚ2020ÄêµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-365-credentials-targeted-in-new-fake-voicemail-campaign/


5¡¢Resecurity³Æ½üÆÚʹÓÃMicrosoft AFDµÄ´¹Âڻ¼¤Ôö 

      

ýÌå6ÔÂ21Èճƣ¬£¬£¬£¬£¬ £¬£¬Í¨¹ý΢ÈíÌṩµÄÔÆCDNЧÀÍAzure Front Door(AFD)µÄ´¹Âڻ¼¤Ôö¡£¡£¡£¡£¡£¡£¡£´ó´ó¶¼´¹ÂڻÖ÷ÒªÕë¶ÔSendGrid¡¢DocusignºÍAmazon£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°ÆäËû¼¸¼ÒÈÕ±¾ºÍÖж«ÔÚÏßЧÀÍÌṩÉ̺͹«Ë¾¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓñ»ÈëÇֵįóÒµºÍСÎÒ˽¼ÒµÄÓʼþÕÊ»§À´·Ö·¢°üÀ¨´¹ÂÚÁ´½ÓµÄÀ¬»øÓʼþ£¬£¬£¬£¬£¬ £¬£¬ÕâЩÁ´½ÓÖ¸ÏòÍйÜÔÚAzure Front DoorÉϵÄÐéαweb×ÊÔ´¡£¡£¡£¡£¡£¡£¡£ResecurityÏÈÈÝ£¬£¬£¬£¬£¬ £¬£¬´ËÀ๥»÷Õ½ÂÔÕ¹ÏÖÁ˹¥»÷ÕßÔõÑùʹÓÃÔÆÐ§ÀÍÒ»Ö±ÔöÇ¿ÆäÕ½ÂԺͳÌÐò£¬£¬£¬£¬£¬ £¬£¬ÒÔÈÆ¹ý´¹ÂÚ¹¥»÷µÄ¼ì²â¡£¡£¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/132458/cyber-crime/azure-front-door-phishing.html


6¡¢Î¢Èí½ôÆÈ¸üÐÂÐÞ¸´Arm×°±¸µÄMicrosoft 365µÇ¼ÎÊÌâ

      

΢ÈíÔÚ6ÔÂ20ÈÕÐû²¼´øÍâ(OOB)¸üУ¬£¬£¬£¬£¬ £¬£¬ÒÔÐÞ¸´×°ÖÃ6Ô²¹¶¡ºóµ¼ÖµÄArmÉè±¹ØÁ¬ÄAzure Active DirectoryºÍMicrosoft 365µÇ¼ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£Î¢ÈíÚ¹ÊͳÆ£¬£¬£¬£¬£¬ £¬£¬¸ÃÎÊÌâ½öÓ°Ïì»ùÓÚWindows ArmµÄ×°±¸£¬£¬£¬£¬£¬ £¬£¬µ¼ÖÂÎÞ·¨¾ÙÐÐAADµÇ¼£¬£¬£¬£¬£¬ £¬£¬Í¬Ê±Ò²»áÓ°ÏìʹÓÃAADµÇ¼µÄÓ¦ÓúÍЧÀÍ£¬£¬£¬£¬£¬ £¬£¬ÈçVPNÅþÁ¬¡¢Microsoft TeamsºÍOutlookµÈ¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì°æ±¾°üÀ¨Windows 11 21H2¡¢Windows 10 21H2¡¢Windows 10 21H1ºÍWindows 10 20H2¡£¡£¡£¡£¡£¡£¡£±¾Ôµĸüл¹µ¼ÖÂÁËWindows Serverϵͳ·ºÆðÎÊÌ⣬£¬£¬£¬£¬ £¬£¬Óû§ÎÞ·¨Ê¹ÓÃVSS±¸·ÝÊý¾Ý¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/windows-emergency-update-fixes-microsoft-365-issues-on-arm-devices/