ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2020-03-10> ±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î52¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î; Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î£»£»£»£»£»£»Envoy²»×¼È·»á¼û¿ØÖÆÎó²î£»£»£»£»£»£»Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î£»£»£»£»£»£»Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»£»£»£»£»£»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Ê飻£»£»£»£»£»CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»£»£»£»£»£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î£»£»£»£»£»£»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î
FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ±£´æºÚÃûµ¥ÈƹýÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://github.com/FasterXML/jackson-databind/issues/2631
2. Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î
Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î¾ÙÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¾ÙÐоܾøÐ§À͹¥»÷¡£¡£¡£¡£
https://pastebin.com/CckKKJcM
3. Envoy²»×¼È·»á¼û¿ØÖÆÎó²î
EnvoyʹÓÃSDS±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉδÊÚȨ»á¼ûÊÜÏÞ×ÊÔ´¡£¡£¡£¡£
https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
4. Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î
Qualcomm MDM9206 WLAN±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£
https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin
5. Google Chrome mediaÇå¾²ÈÆ¹ýÎó²î
Google Chrome media´¦Öóͷ£Çå¾²Õ½ÂÔ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬Î´ÊÚȨ»á¼û¡£¡£¡£¡£
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶
TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼ÆÏ¸ÃÜÁã¼þµÄÖÆÔìÉÌ¡£¡£¡£¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖУ¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÇå¾²·¸·¨ÊÂÎñ£¨°üÀ¨»á¼ûºÍ͵ÇÔÊý¾Ý£©µÄÄ¿µÄ¡±¡£¡£¡£¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷¾ÙÐÐÖÜÈ«ÊӲ죬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÓªÒµÔËÐÐÕý³£¡±¡£¡£¡£¡£TechCrunchÑо¿Ö°Ô±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/03/01/visser-breach/
2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬£¬£¬£¬£¬£¬£¬£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃbugÓ°ÏìÁËBoulder£¬£¬£¬£¬£¬£¬£¬£¬Let's EncryptÏîĿʹÓøÃЧÀÍÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¡£¡£¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬£¬£¬£¬£¬£¬£¬£¬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØÐ¼ì²éµÄÓòÃûʱ£¬£¬£¬£¬£¬£¬£¬£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£¡£¡£¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬£¬£¬£¬£¬£¬£¬£¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬£¬£¬£¬£¬£¬£¬£¬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£¡£¡£¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬£¬£¬£¬£¬£¬£¬£¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖØ¸´Ï£¬£¬£¬£¬£¬£¬£¬Òò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£¡£¡£¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Êé¶¼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬£¬£¬£¬£¬£¬£¬£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊÆ¾ÙÐÐÁËÉîÈëÆÊÎö£¬£¬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷»î¶¯£¨BGH£©Ò»Ö±Éý¼¶£¬£¬£¬£¬£¬£¬£¬£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔì³É¼«´óµÄÆÆË𣻣»£»£»£»£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»£»£»£»£»£»eCrimeÉú̬ϵͳһֱÉú³¤£¬£¬£¬£¬£¬£¬£¬£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»£»£»£»£»£»ÔÚBGHÖ®Í⣬£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrime»î¶¯ÓÐËùÔöÌí£»£»£»£»£»£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»£»£»£»£»£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇֻ¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬£¬£¬£¬£¬£¬£¬£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬£¬£¬£¬£¬£¬£¬£¬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
4¡¢Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿£¿£¿£¿£¿£¿£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¸Ã¹¥»÷ÒÉËÆ±¬·¢ÔÚ2018Äê3Ô·ݣ¬£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬£¬£¬£¬£¬£¬£¬£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦ÆÆ½â¹¥»÷¡£¡£¡£¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬£¬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨²»ÊÜÃÜÂë±£»£»£»£»£»£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWebЧÀÍÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»£»£»£»£»£»¤µÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ
°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ±£»£»£»£»£»£»¤CMSϵͳµÄÍøÂçÇå¾²Ö¸ÄÏ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÖ¸ÄϸÅÊöÁËÔõÑùÔÚwebЧÀÍÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚΣº¦µÄÕ½ÂÔ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÄ¿µÄÊÜÖÚÊÇÈÏÕæÊ¹ÓÃCMS¿ª·¢ºÍ±£»£»£»£»£»£»¤ÍøÕ¾»òWebÓ¦ÓóÌÐòµÄÈË¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÇå¾²Îó²î¡£¡£¡£¡£Ò»µ©CMS±»ÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦ÓóÌÐòµÄÑéÖ¤ÇøÓòºÍÌØÈ¨ÇøÓòµÄ»á¼ûȨÏÞ£»£»£»£»£»£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì»á¼û£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÉÏ´«Web Shell»òRAT£»£»£»£»£»£»ÔÚÕýµ±ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¡£¡£¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWebЧÀÍÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿·Ö£¬£¬£¬£¬£¬£¬£¬£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£¡£¡£¡£ACSC½¨Òé½ÓÄɵĻº½â²½·¥°üÀ¨£ºÊ¹ÓÃCMSÍйÜЧÀÍ£»£»£»£»£»£»ÓÅÒìµÄ²¹¶¡ÖÎÀí£»£»£»£»£»£»Îó²îÆÀ¹À£»£»£»£»£»£»ÕË»§ÖÎÀí£»£»£»£»£»£»ÔöÇ¿CMS×°ÖõÄÇå¾²ÐÔ¿ØÖƲ½·¥£»£»£»£»£»£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.cyber.gov.au/publications/securing-content-management-systems


¾©¹«Íø°²±¸11010802024551ºÅ