Prometheus·þÎñÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв£¬ÐèÔöÇ¿·À»¤

Ðû²¼Ê±¼ä 2024-12-16

1. Prometheus·þÎñÆ÷ÃæÁÙ¶àÖØÇå¾²Íþв£¬ÐèÔöÇ¿·À»¤


12ÔÂ12ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ö°Ô±·¢³öÖÒÑÔ£¬Ö¸³öÍÐ¹Ü Prometheus ¼à¿ØºÍ¾¯±¨¹¤¾ß°üµÄÊýǧ̨·þÎñÆ÷ÃæÁÙÖØ´óÇ徲Σº¦¡£ÕâЩ·þÎñÆ÷ÓÉÓÚȱ·¦Êʵ±µÄÉí·ÝÑéÖ¤£¬ÈÝÒ×ÔâÊÜÐÅϢй¶¡¢¾Ü¾ø·þÎñ£¨DoS£©ºÍÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©¹¥»÷¡£¾ÝÔ¤¼Æ£¬ÓÐÊýÊ®Íǫ̀ Prometheus ʵÀýºÍ·þÎñÆ÷¿Éͨ¹ý»¥ÁªÍø¹ûÕæ»á¼û£¬ÐγÉÁËÒ»¸öÖØ´óµÄ¹¥»÷Ã棬¿ÉÄÜʹÊý¾ÝºÍ·þÎñÊܵ½Íþв¡£¹¥»÷Õß¿ÉÒÔÇáËɵØÍøÂçÃô¸ÐÐÅÏ¢£¬Èçƾ֤ºÍAPIÃÜÔ¿£¬²¢Ö±½ÓÅÌÎÊÄÚ²¿Êý¾Ý£¬Ì»Â¶ÉñÃØ£¬½ø¶øÔÚ×éÖ¯ÖлñµÃÆðԴפ×ãµã¡£±ðµÄ£¬¡°/debug/pprof¡±¶ËµãµÄ̻¶¿ÉÄܳÉΪDoS¹¥»÷µÄÔØÌ壬µ¼Ö·þÎñÆ÷Í߽⡣AquaÇå¾²¹«Ë¾»¹·¢Ã÷¹©Ó¦Á´Íþв£¬°üÀ¨Ê¹ÓûعºÐ®ÖÆÊÖÒÕÒýÈë¶ñÒâµÄµÚÈý·½³ö¿ÚÉÌ£¬Prometheus¹Ù·½ÎĵµÖÐÁгöµÄ°Ë¸öµ¼³öÆ÷Ò×Êܴ˹¥»÷¡£×Ô2024Äê9ÔÂÆð£¬PrometheusÇå¾²ÍŶÓÒѽâ¾öÕâЩÎÊÌâ¡£Ñо¿Ö°Ô±½¨Òé×éÖ¯½ÓÄÉÊʵ±µÄÉí·ÝÑéÖ¤ÒªÁì±£»¤Prometheus·þÎñÆ÷ºÍµ¼³öÆ÷£¬ÏÞÖƹûÕæÆع⣬²¢¼à¿Ø¡°/debug/pprof¡±¶ËµãÊÇ·ñÓÐÒì³£Ô˶¯£¬ÒÔ×èÖ¹Ç徲Σº¦¡£


https://thehackernews.com/2024/12/296000-prometheus-instances-exposed.html


2. Î÷°àÑÀÃس¾¯·½ÁªÊÖ¹¥»÷´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©Æ­


12ÔÂ12ÈÕ£¬Î÷°àÑÀ¾¯·½ÓëÃس¾¯·½ÏàÖú£¬Àֳɹ¥»÷ÁËÒ»¸ö´ó¹æÄ£ÓïÒôÍøÂç´¹ÂÚÕ©Æ­ÍŻÁ½¹ú¹²¾Ð²¶ÁË83Ãû·¸·¨ÏÓÒÉÈË¡£ÆäÖУ¬35ÈËÔÚÎ÷°àÑÀ¸÷µØ±»²¶£¬°üÀ¨ÂíµÂÀï¡¢°ÍÈûÂÞÄǵȵØ£¬ÉÐÓÐ48ÈËÔÚÃسÂäÍø¡£ÔÚÐж¯ÖУ¬¾¯·½»¹×¥»ñÁ˸÷¸·¨ÍÅ»ïµÄÍ·Ä¿£¬²¢½É»ñÁË´ó×ÚÏÖ½ð¡¢ÊÖ»ú¡¢µçÄÔºÍÎļþ¡£¸ÃÍÅ»ïı»®×Å´óÐͺô½ÐÖÐÐÄ£¬¹ÍÓ¶ÁË50ÃûÔ±¹¤£¬Í¨¹ýð³äÒøÐпͷþ£¬Ê¹ÓÃÇÔÈ¡µÄÊý¾Ý¿âºÍÔ¤ÉèµÄÉç»á¹¤³Ìѧ¾ç±¾£¬ÓÕÆ­ÖÁÉÙ10,000ÈËй¶Ãô¸ÐÒøÐÐÐÅÏ¢£¬²¢»ñÈ¡ÁË300ÍòÅ·Ôª£¨315ÍòÃÀÔª£©µÄÊÕÒæ¡£ËûÃÇʹÓÃÀ´µçÓÕÆ­ÊÖÒÕÔöÌí¿ÉÐŶÈ£¬ÒÔδ¾­ÊÚȨµÄATMÈ¡¿î¾¯±¨ÎªÓÕ¶ü£¬Ö¸µ¼Êܺ¦Õßй¶һ´ÎÐÔÃÜÂë¡£ÏÖ½ðÌáÈ¡ºó£¬²¿·Ö»á±»ÔËÓªÉ̱£´æ£¬ÆäÓàÔòËÍÍùÃسµÄ×éÖ¯¡£¾¯·½Ç¿µ÷£¬·¸·¨·Ö×ÓʹÓÃÑÕÉ«´úÂëʶ±ðÒøÐÐ×éÖ¯£¬ÊèÉ¢Ìع¤µ½²î±ð¶¼»áÒÔÔöÌí×·×ÙÄѶÈ¡£Îª±ÜÃâÕ©Æ­£¬¾¯·½½¨Òé½öÔÚÈ·ÈÏÓëÕæÕýÒøÐÐÊðÀíÈËÅÊ̸ºó²ÅÌṩСÎÒ˽¼ÒÐÅÏ¢£¬²¢¼Ç×ÅÒøÐоø²»»áÒªÇó͸¶¿¨¡¢Éí·ÝÖ¤¡¢Óû§Ãû¡¢ÕË»§ÃÜÂëºÍÒ»´ÎÐÔÃÜÂëµÈÃô¸ÐÐÅÏ¢¡£


https://www.bleepingcomputer.com/news/security/spain-busts-voice-phishing-ring-for-defrauding-10-000-bank-customers/


3. ¶íÂÞ˹ÍøÂçÌع¤×éÖ¯GamaredonʹÓÃAndroidÌع¤Èí¼þÇÔÈ¡Êý¾Ý


12ÔÂ13ÈÕ£¬¶íÂÞ˹ÍøÂçÌع¤×éÖ¯Gamaredon±»·¢Ã÷ʹÓÃÃûΪ¡°BoneSpy¡±ºÍ¡°PlainGnome¡±µÄAndroidÌع¤Èí¼þϵÁУ¬Õë¶ÔÇ°ËÕÁª¹ú¼ÒµÄ¶íÓïÈËÊ¿¾ÙÐмàÊÓºÍÇÔÈ¡Òƶ¯×°±¸Êý¾Ý¡£BoneSpy×Ô2021ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬Í¨¹ýľÂíTelegramÓ¦ÓóÌÐò»òð³äÈýÐÇKnoxÈö²¥£¬¾ßÓÐÍøÂç¶ÌÐÅ¡¢Â¼Òô¡¢¶¨Î»¡¢ÕÕÏàµÈ¶àÖÖ¹¦Ð§¡£¶øPlainGnomeÊÇÒ»¿î½ÏеĶ¨ÖÆAndroid¼à¿Ø¶ñÒâÈí¼þ£¬½ÓÄÉÁ½½×¶Î×°ÖÃÀú³Ì£¬Ô½·¢ÒþÃØÇÒÓÃ;Æձ飬¾ßÓÐÓëBoneSpyÏàËƵÄÊý¾ÝÍøÂ繦Ч£¬²¢¼¯³ÉÁ×Æß¼¶¹¦Ð§ÒÔ½µµÍ¼ì²âΣº¦¡£Á½Õß¾ùδÔÚGoogle PlayÉÏ·¢Ã÷£¬ºÜ¿ÉÄÜÊÇͨ¹ýÉç½»¹¤³ÌÖ¸µ¼Êܺ¦ÕßÏÂÔصÄ¡£Ñо¿Ö°Ô±Ö¸³ö£¬ÕâÏÔʾÁËGamaredon¶ÔAndroid×°±¸µÄÈÕÒæ¹Ø×¢£¬²¢½«Æä¼à¿ØÄÜÁ¦À©Õ¹µ½Òƶ¯×°±¸¡£¹È¸èÒÑÈ·ÈÏ£¬Google Play Protect¿ÉÒÔ×Ô¶¯·ÀÓù¸Ã¶ñÒâÈí¼þµÄÒÑÖª°æ±¾¡£


https://www.bleepingcomputer.com/news/security/russian-cyberspies-target-android-users-with-new-spyware/


4. Æû³µÁ㲿¼þ¾ÞÍ·LKQ¼ÓÄôóÓªÒµ²¿·ÖÔâºÚ¿Í¹¥»÷


12ÔÂ13ÈÕ£¬Æû³µÁ㲿¼þ¾ÞÍ·LKQ¹«Ë¾£¬Ò»¼ÒÔÚ25¸ö¹ú¼ÒÓµÓÐ45,000ÃûÔ±¹¤µÄÃÀ¹úÉÏÊй«Ë¾£¬×¨ÃÅ´ÓÊÂÆû³µÌæ»»Áã¼þ¡¢²¿¼þ¼°Î¬ÐÞ±£Ñø·þÎñ£¬Æä¼ÓÄôóÓªÒµ²¿·Ö½üÆÚÔâÓöºÚ¿Í¹¥»÷¡£LKQÔÚÌá½»¸øÃÀ¹ú֤ȯÉúÒâίԱ»áµÄFORM 8-KÎļþÖÐ͸¶£¬11ÔÂ13ÈÕ£¬¹«Ë¾¼ì²âµ½Æä¼ÓÄôóÒ»ÓªÒµ²¿·ÖµÄITϵͳÔâÊÜÁËδ¾­ÊÚȨµÄ»á¼û£¬µ¼ÖÂÓªÒµÔËÓªÖÐÖ¹¡£LKQѸËÙ½ÓÄÉÐж¯£¬°üÀ¨Æô¶¯Çå¾²ÊÂÎñÏìÓ¦ÍýÏë¡¢ÓëÈ¡Ö¤ÊÓ²ìÔ±ÏàÖú£¬²¢Í¨ÖªÖ´·¨²¿·Ö¡£¾­ÆÊÎö£¬¹«Ë¾ÒÔΪÒÑÓÐÓÃ×èÖ¹Íþв£¬ÇÒ³ý¸ÃÓªÒµ²¿·ÖÍ⣬ÆäËûӪҵδÊÜÓ°Ï죬ÏÖÔڸò¿·ÖÒÑ¿¿½üÂú¸ººÉÔËת¡£LKQÔ¤¼Æ´Ë´ÎÊÂÎñ²»»á¶Ô±¾²ÆÄêÊ£Óàʱ¼äµÄ²ÆÎñ»òÔËÓªÔì³ÉÖØ´óÓ°Ï죬²¢½«ÏòÍøÂç°ü¹Ü¹«Ë¾×·ÇóÅâ³¥¡£Ö»¹ÜÏÖÔÚÉÐδÓÐÀÕË÷Èí¼þÍÅ»ï»òÆäËûÍþвÐÐΪÕßÉù³Æ¶Ô´Ë´ÎÏ®»÷ÈÏÕ棬µ«LKQÖÒÑԳƣ¬ÊÜÓ°ÏìµÄÓªÒµÔÚ¼¸ÖÜÄÚ·ºÆðÖÐÖ¹£¬ÏÖÒѻָ´ÔËÓª¡£


https://www.bleepingcomputer.com/news/security/auto-parts-giant-lkq-says-cyberattack-disrupted-canadian-business-unit/


5. Care1Êý¾Ý¿âÔâй¶£¬480Íò»¼ÕßÐÅÏ¢Æعâ


12ÔÂ13ÈÕ£¬ÍøÂçÇå¾²Ñо¿Ô±Jeremiah Fowler½üÆÚ½ÒÆÆÁËÒ»¸öÖØ´óÇå¾²Òþ»¼£¬Ëû·¢Ã÷¼ÓÄôóÒ½ÁÆÊÖÒÕ¹«Ë¾Care1µÄÒ»¸öδÊܱ£»¤Êý¾Ý¿â̻¶ÁËÁè¼Ý480ÍòÌõ»¼ÕßÃô¸ÐÐÅÏ¢£¬°üÀ¨ÐÕÃû¡¢µØµã¡¢²¡Ê·¼°Ð¡ÎÒ˽¼Ò¿µ½¡ºÅÂ루PHN£©µÈ£¬×ÜÊý¾ÝÁ¿´ï2.2TB¡£Care1×÷ΪרҵµÄÑÛ¿ÆÕչ˻¤Ê¿AIÈí¼þ½â¾ö¼Æ»®ÌṩÉÌ£¬ÓµÓÐ170¶àÃûÏàÖúÑé¹âʦ£¬ÖÎÀí×ÅÁè¼Ý15Íò´Î»¼Õß¾ÍÕï¡£´Ë´Î鶵ÄÊý¾Ý²»µ«°üÀ¨ÏêϸµÄÑۿƼì²é±¨¸æ£¬ÉÐÓÐCSVºÍXLSµç×Ó±í¸ñ£¬ÆäÖÐÁгöÁË»¼ÕߵļÒͥסַ¡¢PHNµÈÒªº¦ÐÅÏ¢¡£PHNÔÚ¼ÓÄôóÊÇ»¼ÕßµÄΨһ¿µ½¡±êʶ·û£¬Ëä²»Ö±½ÓÒý·¢½ðÈÚڲƭ£¬µ«¿ÉÄÜΪ·¸·¨·Ö×ÓÌṩ¹¹½¨Ð¡ÎÒ˽¼ÒÖÜÈ«µµ°¸µÄÖ÷ÒªÐÅÏ¢¡£ÏÖÔÚÉв»ÇåÎúÊý¾Ý¿âµÄÏêϸÖÎÀí·½¼°Ð¹Â¶Ò»Á¬Ê±¼ä£¬µ«FowlerÒÑÏòCare1·¢ËÍÁËÈÏÕæÈεÄÅû¶֪ͨ£¬²¢´ÙʹÆäѸËÙÏÞÖÆÁ˹«ÖÚ»á¼û¡£Ëæ×ÅÒ½ÁƱ£½¡ÁìÓòÊý×Ö»¯Àú³Ì¼ÓËÙ£¬Êý¾Ýй¶Σº¦ÈÕÒæ͹ÏÔ£¬¸ø»¼Õß´øÀ´ÖØ´óÒþ˽Íþв¡£ÀàËÆCare1ÕâÑùµÄ¹«Ë¾Ðè¸ß¶ÈÖØÊÓÍøÂçÇå¾²£¬½ÓÄÉÇ¿¼ÓÃÜ¡¢ÑÏ¿á»á¼û¿ØÖƺͰ´ÆÚÇå¾²Éó¼ÆµÈ²½·¥£¬È·±£»¼ÕßÐÅÏ¢µÄÇå¾²¡£


https://hackread.com/canadian-eyecare-firm-care1-exposes-patient-records/


6. µÂ¹úBSIÆÆËð3Íǫ̀Android IoT×°±¸ÖÐBadBox¶ñÒâÈí¼þ


12ÔÂ13ÈÕ£¬µÂ¹úÁª°îÐÅÏ¢Çå¾²¾Ö£¨BSI£©ÒѽÓÄÉÐж¯£¬ÆÆËðÁËÔڸùúÏúÊÛµÄ30,000¶ą̀Android IoT×°±¸ÖÐԤװµÄBadBox¶ñÒâÈí¼þ¡£BadBoxÊÇÒ»ÖÖÓÃÓÚÇÔÈ¡Êý¾Ý¡¢×°ÖÃÆäËû¶ñÒâÈí¼þ»òÔÊÐíÔ¶³Ì»á¼ûµÄAndroid¶ñÒâÈí¼þ£¬Ö÷ÒªÓ°ÏìÊýÂëÏà¿ò¡¢Ã½Ìå²¥·ÅÆ÷ºÍÁ÷ýÌå×°±¸µÈ¡£BSIͨ¹ý³Á¶´´¦Öóͷ££¨Sinkholing£©×èÖ¹ÁËBadBoxÓëÆäÏÂÁîºÍ¿ØÖÆ·þÎñÆ÷µÄͨѶ£¬´Ó¶øÓÐÓÃ×èÖ¹Á˶ñÒâÈí¼þµÄÔËÐС£ÊÜѬȾװ±¸µÄËùÓÐÕß½«Æ¾Ö¤IPµØµãÊÕµ½Í¨Öª£¬²¢Ó¦Á¬Ã¦¶Ï¿ª×°±¸ÓëÍøÂçµÄÅþÁ¬»ò×èֹʹÓ㬲¢Í˻ػòÑïÆú¸Ã×°±¸¡£BSIÖÒÑԳƣ¬ËùÓÐÊÜÓ°ÏìµÄ×°±¸¶¼ÔËÐÐ׏ýʱµÄAndroid°æ±¾ºÍ¾É¹Ì¼þ£¬Òò´Ë×ÝÈ»ÒÑÌá·ÀBadBox£¬Ò²ÈÝÒ×Êܵ½ÆäËû½©Ê¬ÍøÂç¶ñÒâÈí¼þµÄ¹¥»÷¡£ÏûºÄÕßÓ¦Ö»¹ºÖÃÀ´×ÔÐÅÓþÓÅÒìµÄÖÆÔìÉ̵ÄÖÇÄÜ×°±¸£¬²¢Ñ°ÕÒÌṩºã¾ÃÇå¾²Ö§³ÖµÄ²úÆ·¡£


https://www.bleepingcomputer.com/news/security/germany-blocks-badbox-malware-loaded-on-30-000-android-devices/