ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ29ÖÜ
Ðû²¼Ê±¼ä 2019-07-29> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2019Äê7ÔÂ22ÈÕÖÁ28ÈÕ¹²ÊÕ¼Çå¾²Îó²î49¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇProFTPD SITE CPFR/CPTOí§Òâ¶ÁдÎó²î£»Apple Webkit ¶à¸öÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î£»Zeroshell http²ÎÊýÏÂÁî×¢ÈëÎó²î£»Apache Storm·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î£»McAfee Data Loss Prevention Endpoint ePOÀ©Õ¹ÏÂÁî×¢ÈëÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǶíÂÞ˹Áª°îÇå¾²¾Ö³Ð°üÉÌÔâºÚ¿ÍÈëÇÖ£¬ÉñÃØÏîÄ¿Æع⣻ProFTPD RCEÎó²î£¬Áè¼Ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ï죻ӡ¶ÈС¶îÐÅ´ûÒøÐÐJana CashÒâÍâй¶260ÍòÓû§ÉúÒâÐÅÏ¢£»RiskIQÐû²¼2019»¥ÁªÍø·¸·¨±¨¸æ£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª£»Ç°Î÷ÃÅ×ÓÌõÔ¼¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯¡£
> Ö÷ÒªÇå¾²Îó²îÁбí
1. ProFTPD SITE CPFR/CPTOí§Òâ¶ÁдÎó²î
ProFTPD SITE CPFR/CPTOûÓÐ׼ȷ´¦Öóͷ£
2. Apple Webkit CVE-2019-8644ÄÚ´æÆÆËð´úÂëÖ´ÐÐÎó²î
Apple iOS°üÀ¨µÄWebKit±£´æÄÚ´æÆÆËðÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://support.apple.com/zh-cn/HT2103563. Zeroshell http²ÎÊýÏÂÁî×¢ÈëÎó²î
https://www.tarlogic.com/advisories/zeroshell-rce-root.txt
4. Apache Storm·´ÐòÁл¯´úÂëÖ´ÐÐÎó²î
https://lists.apache.org/thread.html/3e4f704c4bd9296405a07a0290b8cbb6cbf5046e277efe6d93280a98@%3Cuser.storm.apache.org%3E
5. McAfee Data Loss Prevention Endpoint ePOÀ©Õ¹ÏÂÁî×¢ÈëÎó²î
https://kc.mcafee.com/corporate/index?page=content&id=SB10289
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/russian-fsb-intel-agency-contractor-hacked-secret-projects-exposed/
2¡¢ProFTPD RCEÎó²î£¬Áè¼Ý100Íǫ̀·þÎñÆ÷ÊÜÓ°Ïì
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/
3¡¢Ó¡¶ÈС¶îÐÅ´ûÒøÐÐJana CashÒâÍâй¶260ÍòÓû§ÉúÒâÐÅÏ¢
ÔÎÄÁ´½Ó£ºhttps://securitydiscovery.com/jana-bank-data-leak/
4¡¢RiskIQÐû²¼2019»¥ÁªÍø·¸·¨±¨¸æ£¬Ã¿·ÖÖÓËðʧ290ÍòÃÀÔª
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/external-threat-management/2019-evil-internet-minute/
5¡¢Ç°Î÷ÃÅ×ÓÌõÔ¼¹¤ÈÏ¿ÉÔÚ¹«Ë¾µç×Ó±í¸ñÖÐÖ²ÈëÂß¼Õ¨µ¯
ÔÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/siemens-contractor-pleads-guilty-to-planting-logic-bomb-in-company-spreadsheets/