ÐÅÏ¢Çå¾²Öܱ¨-2020ÄêµÚ10ÖÜ
Ðû²¼Ê±¼ä 2020-03-10> ±¾ÖÜÇ徲̬ÊÆ×ÛÊö
2020Äê03ÔÂ02ÈÕÖÁ08ÈÕ¹²ÊÕ¼Çå¾²Îó²î52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇFasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î; Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î£»Envoy²»×¼È·»á¼û¿ØÖÆÎó²î£»Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î£»Google Chrome mediaÇå¾²ÈƹýÎó²î¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶£»Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Ê飻CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·£»Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î£»°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. FasterXML jackson-databind CVE-2020-9548´úÂëÖ´ÐÐÎó²î
FasterXML jackson-databind ibatis-sqlmapÒÔ¼°anteros-core×é¼þ±£´æºÚÃûµ¥ÈƹýÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://github.com/FasterXML/jackson-databind/issues/2631
2. Rubetek SmartHome²¨¶ÎÉè¼ÆÎó²î
Rubetek SmartHomeʹÓÃÁËδ¼ÓÃܵÄ433 MHz²¨¶Î¾ÙÐÐͨѶ£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɻñÈ¡Ãô¸ÐÐÅÏ¢»ò¾ÙÐоܾø·þÎñ¹¥»÷¡£
https://pastebin.com/CckKKJcM
3. Envoy²»×¼È·»á¼û¿ØÖÆÎó²î
EnvoyʹÓÃSDS±£´æ²»×¼È·»á¼û¿ØÖÆÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ»á¼ûÊÜÏÞ×ÊÔ´¡£
https://github.com/envoyproxy/envoy/security/advisories/GHSA-3x9m-pgmg-xpx8
4. Qualcomm MDM9206 WLAN»º³åÇøÒç³öÎó²î
Qualcomm MDM9206 WLAN±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿ɾÙÐоܾø·þÎñ¹¥»÷»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://www.qualcomm.com/company/product-security/bulletins/march-2020-bulletin
5. Google Chrome mediaÇå¾²ÈƹýÎó²î
Google Chrome media´¦Öóͷ£Çå¾²Õ½ÂÔ±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÈƹýÇå¾²ÏÞÖÆ£¬Î´ÊÚȨ»á¼û¡£
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop.html
> Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâºÚ¿Í¹¥»÷ÇÒÊý¾Ýй¶
TeslaºÍSpaceXµÄÁã¼þÖÆÔìÉÌVisserÈ·ÈÏÔâÓöÊý¾Ýй¶ÊÂÎñ£¬¸Ã¹«Ë¾ÊÇÒ»¼ÒרÃÅΪ̫¿ÕºÍ¹ú·À³Ð°üÉÌÉè¼ÆϸÃÜÁã¼þµÄÖÆÔìÉÌ¡£ÔÚÒ»·Ý¼ò¶ÌµÄÉùÃ÷ÖУ¬¸Ã¹«Ë¾È·ÈÏÆä½üÆÚ³ÉΪ¡°ÍøÂçÇå¾²·¸·¨ÊÂÎñ£¨°üÀ¨»á¼ûºÍ͵ÇÔÊý¾Ý£©µÄÄ¿µÄ¡±¡£¸Ã¹«Ë¾½²»°ÈËÌåÏÖ½«¡°¼ÌÐø¶Ô¸Ã¹¥»÷¾ÙÐÐÖÜÈ«ÊӲ죬²¢ÇÒÓªÒµÔËÐÐÕý³£¡±¡£TechCrunchÑо¿Ö°Ô±³ÆÕâ´Î¹¥»÷ºÜÓпÉÄÜÊÇÓÉDoppelPaymerÀÕË÷Èí¼þÒýÆðµÄ¡£
ÔÎÄÁ´½Ó£º
https://techcrunch.com/2020/03/01/visser-breach/
2¡¢4Let's Encrypt³·»ØÁè¼Ý300Íò¸öTLSÖ¤Êé
ÓÉÓÚÔÚºó¶Ë´úÂëÖз¢Ã÷ÁËÒ»¸öbug£¬Let's EncryptÏîÄ¿ÍýÏë´ÓÌìϱê׼ʱ¼ä2020Äê3ÔÂ4ÈÕ00:00×îÏÈ×÷·ÏÁè¼Ý300Íò¸öTLSÖ¤Êé¡£ÏêϸÀ´Ëµ£¬¸ÃbugÓ°ÏìÁËBoulder£¬Let's EncryptÏîĿʹÓø÷þÎñÆ÷Èí¼þÔÚ¿¯ÐÐTLSÖ¤Êé֮ǰÑéÖ¤Óû§¼°ÆäÓò¡£¸ÃbugÓ°ÏìÁËBoulderÄÚ²¿CAA£¨Ö¤Êé½ÒÏþ»ú¹¹ÊÚȨ£©¹æ·¶µÄʵÑ飬¡°µ±Ò»¸öÖ¤ÊéÇëÇó°üÀ¨N¸öÐèÒª¾ÙÐÐCAAÖØмì²éµÄÓòÃûʱ£¬Boulder½«Ñ¡ÔñÒ»¸öÓòÃû²¢¼ì²éN´Î¡£ÕâÏÖʵÉÏÒâζ×ÅÈôÊÇÒ»¸öÓû§ÔÚʱ¼äXÑéÖ¤ÁËÒ»¸öÓòÃû£¬²¢ÇÒ¸ÃÓòÃûÔÚʱ¼äXµÄCAA¼Í¼ÔÊÐíLet's Encrypt¿¯ÐУ¬Ôò¸ÃÓû§¿ÉÒÔÔÚX+30ÌìµÄʱ¼äÀ￯ÐаüÀ¨¸ÃÓòÃûµÄÖ¤Ê飬×ÝȻ֮ºóÓÐÈËÔÚ¸ÃÓòÃûÉÏ×°ÖÃÁËեȡLet's Encrypt¿¯ÐеÄCAA¼Í¼¡±¡£ÔÚÕâ300Íò¸ö×÷·ÏµÄÖ¤ÊéÖУ¬ÓÐ100Íò¸öÊÇͳһÓò/×ÓÓòµÄÖظ´ÏÒò´ËÊÜÓ°ÏìÖ¤ÊéµÄÏÖʵÊýĿԼΪ200Íò¸ö¡£ÔÚ3ÔÂ4ÈÕ00:00Ö®ºóËùÓÐÊÜÓ°ÏìµÄÖ¤Ê鶼½«´¥·¢ä¯ÀÀÆ÷ºÍÆäËûÓ¦ÓóÌÐòÖеĹýʧ£¬ÓòÃûËùÓÐÕß½«±ØÐèÇëÇóеÄTLSÖ¤Êé²¢Ìæ»»¾ÉµÄTLSÖ¤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/lets-encrypt-to-revoke-3-million-certificates-on-march-4-due-to-bug/
3¡¢CrowdStrikeÐû²¼¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·
CrowdStrikeµÄ¡¶2020ÄêÈ«ÇòÍþв±¨¸æ¡·¶ÔÒÑÍùÒ»ÄêÖж¥¼¶ÍøÂçÍþвÇ÷ÊƾÙÐÐÁËÉîÈëÆÊÎö£¬¸Ã±¨¸æµÄÒªµã°üÀ¨£º´óÐ͹¥»÷Ô˶¯£¨BGH£©Ò»Ö±Éý¼¶£¬Êê½ðÒªÇóìÉýÖÁÊý°ÙÍò£¬²¢ÇÒÔì³É¼«´óµÄÆÆËð£»ÍøÂç·¸·¨·Ö×ÓÕýÔÚʹÃô¸ÐÊý¾ÝÎäÆ÷»¯£¬ÒÔÔöÌí¶ÔÀÕË÷Èí¼þÊܺ¦ÕßµÄѹÁ¦£»eCrimeÉú̬ϵͳһֱÉú³¤£¬±äµÃ³ÉÊìºÍרҵ»¯Ë®Æ½Ò»Ö±Ìá¸ß£»ÔÚBGHÖ®Í⣬Õë¶ÔÈ«Çò½ðÈÚ»ú¹¹µÄeCrimeÔ˶¯ÓÐËùÔöÌí£»³¯ÏòÎÞ¶ñÒâÈí¼þÕ½ÂÔµÄÇ÷ÊÆÕýÔÚ¼ÓËÙ£»¹ú¼Ò×ÊÖúµÄÓÐÕë¶ÔÐÔµÄÈëÇÖÔ˶¯¼ÌÐøÕë¶Ô֪ʶ²úȨ/¾ºÕùÇ鱨£¬Ôö½øÉçÇøÄÚ²¿µÄÆÆË飬²¢ÊӲ쵽ÁËÓëÏȽøeCrime¹¥»÷ÕßµÄÏàÖú¡£
ÔÎÄÁ´½Ó£º
https://www.crowdstrike.com/resources/reports/2020-crowdstrike-global-threat-report/
4¡¢Ó¢¹úÊý¾Ýî¿Ïµ»ú¹¹¶Ô¹úÌ©º½¿Õ´¦ÒÔ50ÍòÓ¢°÷·£¿î
Ó¢¹úÐÅϢרԱ°ì¹«ÊÒÒò2018Äê940ÍòÂÿÍÊý¾Ýй¶ÊÂÎñ¶Ô¹úÌ©º½¿Õ¹«Ë¾´¦ÒÔ50ÍòÓ¢°÷µÄ·£¿î¡£¸Ã¹¥»÷ÒÉËƱ¬·¢ÔÚ2018Äê3Ô·ݣ¬²¢ÓÚ5Ô·ݻñµÃÈ·ÈÏ£¬Æäʱ¹úÌ©º½¿ÕµÄÊý¾Ý¿âÔâµ½Á˱©Á¦Æƽ⹥»÷¡£ICOÊÓ²ì³Æ¹úÌ©µÄϵͳÊܵ½ÁËÊý¾ÝÍøÂçÀà¶ñÒâÈí¼þµÄÓ°Ï죬²¢·¢Ã÷¹úÌ©ÔÚÇå¾²ÐÔ·½ÃæµÄһЩȱ·¦£¬°üÀ¨²»ÊÜÃÜÂë±£»¤µÄ±¸·ÝÎļþ¡¢Î´´ò²¹¶¡µÄWeb·þÎñÆ÷¡¢ÒѹýʱµÄ²Ù×÷ϵͳºÍȱ·¦·À²¡¶¾±£»¤µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/03/04/ico_fines_cathay_pacific_500000/
5¡¢°Ä´óÀûÑÇACSCÐû²¼CMSϵͳÇå¾²Ö¸ÄÏ
°Ä´óÀûÑÇÍøÂçÇå¾²ÖÐÐÄ£¨ACSC£©Ðû²¼Ò»·ÝÓÃÓÚ±£»¤CMSϵͳµÄÍøÂçÇå¾²Ö¸ÄÏ£¬¸ÃÖ¸ÄϸÅÊöÁËÔõÑùÔÚweb·þÎñÆ÷ÉÏʶ±ðºÍ×îС»¯Ç±ÔÚΣº¦µÄÕ½ÂÔ£¬ÆäÄ¿µÄÊÜÖÚÊÇÈÏÕæʹÓÃCMS¿ª·¢ºÍ±£»¤ÍøÕ¾»òWebÓ¦ÓóÌÐòµÄÈË¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×Ô¶¯»¯¹¤¾ßɨÃèInternetÉϵÄÇå¾²Îó²î¡£Ò»µ©CMS±»ÈëÇÖ£¬¹¥»÷Õß¿ÉÒÔʹÓÃÆäȨÏÞÀ´£º»ñµÃWebÓ¦ÓóÌÐòµÄÑéÖ¤ÇøÓòºÍÌØȨÇøÓòµÄ»á¼ûȨÏÞ£»ÉÏ´«¶ñÒâÈí¼þÀ´»ñµÃÔ¶³Ì»á¼û£¬ÀýÈçÉÏ´«Web Shell»òRAT£»ÔÚÕýµ±ÍøÒ³ÉÏ×¢Èë¶ñÒâÄÚÈÝ¡£¹¥»÷Õß»¹¿ÉÒÔ½«ÊÜѬȾµÄWeb·þÎñÆ÷ÓÃ×÷¡°Ë®¿Ó¡±¹¥»÷µÄÒ»²¿·Ö£¬»òÓÃ×÷C&CµÄ»ù´¡ÉèÊ©¡£ACSC½¨Òé½ÓÄɵĻº½â²½·¥°üÀ¨£ºÊ¹ÓÃCMSÍйܷþÎñ£»ÓÅÒìµÄ²¹¶¡ÖÎÀí£»Îó²îÆÀ¹À£»ÕË»§ÖÎÀí£»ÔöÇ¿CMS×°ÖõÄÇå¾²ÐÔ¿ØÖƲ½·¥£»¼à¿ØCMS×°ÖÃÉ϶ÔÍйÜÄÚÈݵÄδÊÚȨ¸ü¸ÄµÈ¡£
ÔÎÄÁ´½Ó£º
https://www.cyber.gov.au/publications/securing-content-management-systems