OpenSMTPDÐÂRCEÎó²î £¬£¬ £¬£¬£¬£¬£¬Ó°Ïì¶à¸öLinux¿¯Ðаæ£» £»£»ÃÀ¹úµçÁ¦¹©Ó¦ÉÌRMLDÔâÀÕË÷Èí¼þ¹¥»÷

Ðû²¼Ê±¼ä 2020-02-26

1.OpenSMTPDÐÂRCEÎó²î £¬£¬ £¬£¬£¬£¬£¬Ó°Ïì¶à¸öLinux¿¯Ðаæ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±ÔÚÓʼþЧÀÍÆ÷OpenSMTPDÖз¢Ã÷Ò»¸öеÄÑÏÖØÎó²î£¨CVE-2020-8794£© £¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔ¶³ÌʹÓøÃÎó²îÒÔrootÓû§Éí·ÝÔËÐÐShellÏÂÁî¡£¡£¡£¡£¡£¡£¡£OpenSMTPDÓ¦ÓÃÔÚ¶à¸ö»ùÓÚUnixµÄϵͳÉÏ £¬£¬ £¬£¬£¬£¬£¬°üÀ¨FreeBSD¡¢NetBSD¡¢macOS¡¢Linux£¨Alpine¡¢Arch¡¢Debian¡¢Fedora¡¢CentOS£©¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËOpenSMTPDµÄĬÈÏ×°Öà £¬£¬ £¬£¬£¬£¬£¬QualysÑо¿Ö°Ô±Ö¸³ö¸ÃÎÊÌâÊÇÔÚ2015Äê12ÔÂÒýÈëµÄ £¬£¬ £¬£¬£¬£¬£¬µ«Ö»ÓÐÔÚ2018Äê5ÔÂÖ®ºóÐû²¼µÄOpenSMTPD°æ±¾ÉϲſÉÒÔʹÓÃËüÒÔrootÌØÈ¨Ö´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£OpenSMTPD 6.6.4p1ÖÐÒѾ­ÐÞ¸´Á˸ÃÎó²î £¬£¬ £¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüС£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-critical-rce-bug-in-openbsd-smtp-server-threatens-linux-distros/


2.¹È¸èÐÞ¸´ChromeÖеÄÀàÐÍ»ìÏý0day £¬£¬ £¬£¬£¬£¬£¬ÒÑÔÚÒ°ÍâʹÓÃ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÐÞ¸´ChromeÖеÄÒ»¸öÒÑÔÚÒ°ÍâʹÓõÄ0day£¨CVE-2020-6418£© £¬£¬ £¬£¬£¬£¬£¬ÕâÊÇÒÑÍùÒ»ÄêÖеÚÈý¸ö±»·¢Ã÷ÔÚÒ°ÍâʹÓõÄChrome 0day¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»ÐÎòΪV8ÒýÇæÖеÄÀàÐÍ»ìÏýÎó²î £¬£¬ £¬£¬£¬£¬£¬Ïà¹ØÏêϸÐÅÏ¢ÉÐδ¹ûÕæ¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄÐÞ¸´²¹¶¡×÷ΪChrome°æ±¾80.0.3987.122µÄÒ»²¿·ÖÐû²¼ £¬£¬ £¬£¬£¬£¬£¬Õâ¸ö¸üÐÂÊÊÓÃÓÚWindows¡¢MacºÍLinuxÓû§ £¬£¬ £¬£¬£¬£¬£¬µ«²»ÊÊÓÃÓÚChrome OS¡¢iOSºÍAndroidÓû§¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-patches-chrome-zero-day-under-active-attacks/


3.Å·ÖÞÍøÂçÓëÐÅÏ¢Çå¾²¾ÖÐû²¼Ò½ÔºÍøÂçÇå¾²²É¹ºÖ¸ÄÏ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Å·ÖÞÍøÂçÓëÐÅÏ¢Çå¾²¾Ö£¨ENISA£©Ðû²¼Ò½ÔºÍøÂçÇå¾²²É¹ºÖ¸ÄÏ¡£¡£¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×ÊÖúÒ½ÔºÔڲɹºÐÂ×ʲúʱ֪×ãÐÅÏ¢Çå¾²·½ÃæµÄÒªÇó £¬£¬ £¬£¬£¬£¬£¬ÌṩÁ˽«ÍøÂçÇå¾²×÷ΪҽԺ²É¹ºÀú³ÌÖÐÒ»Ïî»®¶¨µÄÓÅÒìʵ¼ùºÍ½¨Òé £¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÏÈÈÝÁËÒ½Ôº×ʲúÜöÝÍÒÔ¼°ÓëÖ®Ïà¹ØµÄ×îÍ»³öÍøÂçÇå¾²Íþв¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ÷ÒªÕë¶ÔÔÚÒ½Ôºµ£µ±ÊÖÒÕÖ°ÎñµÄÒ½ÁƱ£½¡×¨ÒµÖ°Ô±£¨CIO £¬£¬ £¬£¬£¬£¬£¬CISO £¬£¬ £¬£¬£¬£¬£¬CTO £¬£¬ £¬£¬£¬£¬£¬ITÍŶÓÒÔ¼°Ò½ÁƱ£½¡×éÖ¯ÖеIJɹºÖ°Ô±£© £¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ¿ÉÒÔΪҽÁÆ×°±¸ÖÆÔìÉÌÌṩ²Î¿¼¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/02/25/cybersecurity-procurement-hospitals/


4.¿¨°Í˹»ùÐû²¼2019ÄêÒÆ¶¯¶ñÒâÈí¼þÑݱ䱨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ùÐû²¼2019ÄêÒÆ¶¯¶ñÒâÈí¼þÑݱ䱨¸æ £¬£¬ £¬£¬£¬£¬£¬±¨¸æÖ¸³öÊÜstalkerware£¨¸ú×ÙÈí¼þ£©Ñ¬È¾µÄÓû§ÊýÄ¿´Ó2018ÄêµÄ40386ÈËÔöÌíµ½2019ÄêµÄ67500ÈË £¬£¬ £¬£¬£¬£¬£¬ÔÚ2019ÄêÔöÌíÁ˽ü40£¥¡£¡£¡£¡£¡£¡£¡£±¨¸æ»¹·¢Ã÷£º×Ô2018ÄêÒÔÀ´ £¬£¬ £¬£¬£¬£¬£¬¿¨°Í˹»ù¼ì²âµ½µÄ¹ã¸æÈí¼þ×°ÖðüÊýÄ¿ÏÕЩ·­ÁËÒ»·¬£» £»£»ÒÁÀÊÊÇÓµÓÐ×î¶àAndroid¶ñÒâÈí¼þ¾¯±¨µÄ¹ú¼Ò £¬£¬ £¬£¬£¬£¬£¬¿¨°Í˹»ùµÄËùÓÐÒÁÀÊÓû§ÖÐÓÐ60£¥ÔÚ2019ÄêÔÚÆäÊÖ»úÉÏ×°ÖÃÁ˶ñÒâÓ¦Óã» £»£»HiddenAd¹ã¸æÈí¼þ¼Ò×åÊÇ2019Äê×îÊ¢ÐеĶñÒâÈí¼þÍþв¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/mobile-malware-evolution-2019/96280/


5.µÏ¿¨Ù¯ElasticsearchЧÀÍÆ÷й¶1.23Òڼͼ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


·¨¹úÌåÓýÁãÊÛ¾ÞÍ·µÏ¿¨Ù¯Ð¹Â¶Áè¼Ý1.23ÒÚÌõ¿Í»§ºÍÔ±¹¤ÐÅÏ¢¼Í¼¡£¡£¡£¡£¡£¡£¡£2ÔÂ12ÈÕvpnMentorÑо¿ÍŶÓÔڸù«Ë¾µÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄElasticsearchЧÀÍÆ÷ÉÏ·¢Ã÷ÁËÕâЩÊý¾Ý £¬£¬ £¬£¬£¬£¬£¬Êý¾Ý¿âµÄ×ܾÞϸΪ9GB £¬£¬ £¬£¬£¬£¬£¬°üÀ¨µÏ¿¨Ù¯Î÷°àÑÀ·ÖµêÒÔ¼°¿ÉÄÜÊÇÓ¢¹ú·ÖµêµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£×ß©µÄÊý¾Ý°üÀ¨Ô±¹¤Óû§Ãû¡¢Î´¼ÓÃܵÄÃÜÂëÒÔ¼°Ð¡ÎÒ˽¼ÒÉí·ÝÐÅÏ¢£¨PII£© £¬£¬ £¬£¬£¬£¬£¬ÀýÈçÉç»áÇå¾²ºÅÂë¡¢ÐÕÃû¡¢µØµã¡¢ÊÖ»úºÅÂëºÍ³öÉúÈÕÆÚ £¬£¬ £¬£¬£¬£¬£¬»¹°üÀ¨Î´¼ÓÃܵĿͻ§µç×ÓÓʼþºÍµÇ¼ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£µÏ¿¨Ù¯ÔÚ2ÔÂ17ÈչرÕÁ˶ÔÊý¾Ý¿âµÄ¹«¹²»á¼û¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/sports-giant-decathlon-leaks-123/


6.ÃÀ¹úµçÁ¦¹©Ó¦ÉÌRMLDÔâÀÕË÷Èí¼þ¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÂíÈøÖîÈûÖݵçÁ¦¹©Ó¦ÉÌRMLDÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬£¬ £¬£¬£¬£¬£¬Æä¹ÙÍøhttp://rmld.comÏÖÔÚ²»¿ÉÓà £¬£¬ £¬£¬£¬£¬£¬²¢ÇÒÎÞ·¨Ô¤¼ÆÏêϸµÄ»Ö¸´Ê±¼ä¡£¡£¡£¡£¡£¡£¡£RMLDÌåÏÖµçÁ¦Ð§ÀͲ¢Î´Êܵ½¹¥»÷µÄÓ°Ïì £¬£¬ £¬£¬£¬£¬£¬µçÍøÈÔÈ»Çå¾² £¬£¬ £¬£¬£¬£¬£¬²¢ÇÒûÓм£ÏóÅú×¢¿Í»§µÄ²ÆÎñÊý¾ÝÊܵ½Ë𺦠£¬£¬ £¬£¬£¬£¬£¬µ«¹¥»÷ÖпÉÄÜ̻¶µÄ¿Í»§Êý¾Ý°üÀ¨ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãÒÔ¼°µçÁ¿Ê¹Óüͼ¡£¡£¡£¡£¡£¡£¡£RMLDÉÐδȷÈÏÀÕË÷Èí¼þÔõÑù½øÈëÆäÅÌËã»úϵͳ £¬£¬ £¬£¬£¬£¬£¬Ò²Ã»ÓÐ˵Ã÷¹¥»÷ÕßÒªÇ󼸶àÊê½ð £¬£¬ £¬£¬£¬£¬£¬µ«ÌåÏ־ܾøÖ§¸¶Êê½ð¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/ransomware-attack-at-us-power/