΢ÈíAzure App Serviceй¶²¿ÃÅÓû§Ô´´úÂ볤´ï4Äê
Ðû²¼Ê±¼ä 2021-12-23Ñо¿ÍŶÓÔÚAuerswald VoIPϵͳÖмì²âµ½2¸öÒþ²ØºóÃÅ
RedTeam PentestingÔÚ12ÔÂ20ÈÕ͸¶µÂ¹úµçÐÅÓ²¼þÖÆÔìÉÌAuerswaldʹÓõĻ¥ÁªÍøÐÒéÓïÒô(VoIP)ϵͳÖдæÔÚ2¸öÒþ²ØºóÃÅ¡£Ñо¿ÈËÔ±³ÆËûÃÇÔÚCOMpact 5500R PBXµÄ¹Ì¼þÖз¢ÏÖÁËÕâ2¸öºóÃŵÄÃÜÂ룬һ¸öÊôÓÚÃØÃÜÓû§Schandelah£¬ÁíÒ»¸öÊôÓÚ¹ÜÀíÔ±admin£¬Ä¿Ç°Ã»Óз¢ÏÖ½ûÓÃÕâЩºóÃŵÄÒªÁì¡£¸Ã©¶´×·×ÙΪCVE-2021-40859£¬CVSSΪ9.8£¬ÓÚ9ÔÂ10ÈÕ±»¹ûÈ»£¬AuerswaldÔÚ11ÔµĹ̼þ¸üУ¨8.2B°æ£©ÖÐÐÞ¸´ÁËÕâһ©¶´¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2021/12/secret-backdoors-found-in-german-made.html
еĽ©Ê¬ÍøÂçAbcbotÖ÷ÒªÕë¶ÔÖйúµÄÔÆ·þÎñÌṩÉÌ
12ÔÂ21ÈÕ£¬Cado Security·¢ÏÖн©Ê¬ÍøÂçAbcbotÔÚ¹ýÈ¥¼¸¸öÔÂÖ÷ÒªÕë¶ÔÖйúÔÆ·þÎñÌṩÉÌ£¬°üÂÞ°¢ÀïÔÆ¡¢°Ù¶È¡¢ÌÚѶºÍ»ªÎªÔƵȡ£AbcbotÊ×ÏȻᰲװһ¸öLinux bash½Å±¾£¬À´½ûÓÃSELinuxÄþ¾²±£»¤£¬²¢´´½¨ºóÃÅ¡£È»ºóɨÃèÄ¿±êÖ÷»úÖÐÊÇ·ñ´æÔÚÆäËü¶ñÒâÈí¼þ£¬Èç¹û·¢ÏÖÔò»áɾ³ýÆäËü¶ñÒâÈí¼þµÄÏà¹Ø½ø³Ì¡£³ý´ËÖ®Í⣬Abcbot»¹»áɾ³ýSSHÃÜÔ¿²¢½ö±£Áô×Ô¼ºµÄÃÜÔ¿£¬ÒÔ±£Ö¤Æä¶ÔÄ¿±êÖ÷»úµÄ¶ÀÕ¼·ÃÎÊ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/125872/malware/abcbot-botnet-chinese-providers.html
Ç÷ÊÆ¿Æ¼¼·¢ÏÖTropic TrooperÕë¶ÔÔËÊäÐÐÒµµÄ¹¥»÷»î¶¯
Ç÷ÊÆ¿Æ¼¼ÔÚ12ÔÂ14ÈÕ·¢ÏÖ¼äµý×éÖ¯Tropic Trooper£¨Ò²³ÆEarth Centaur£©Õë¶ÔÔËÊäÐÐÒµµÄ¹¥»÷»î¶¯¡£´Ë´Î»î¶¯Ê¼ÓÚ2020Äê7Ô£¬Ãé×¼ÁËÔËÊäÐÐÒµµÄ¹«Ë¾ºÍ¹Ù·½»ú¹¹¡£Ñо¿ÈËÔ±½«ÈëÇÖ¹ý³Ì·ÖΪ¶à¸ö½×¶Î£º¹¥»÷´æÔÚ©¶´µÄIIS·þÎñÆ÷ºÍExchange²¢°²×°shell£»ÀûÓøÃshell°²×°.NET¼ÓÔØ·¨Ê½NerapackºÍµÚÒ»½×¶ÎºóÃÅQuasar£»È»ºó£¬Æ¾¾ÝÊܺ¦ÕßÀàÐÍ·Ö·¢µÚ¶þ½×¶ÎºóÃÅ£¬°üÂÞChiserClientºÍSmileSvrµÈ£»×îºó£¬»¹»áÊÔÍ¼ÆÆ»µÄÚÍø¡¢×ª´¢Æ¾¾Ý²¢Çå³ýÈÕÖ¾¡£
ÔÎÄÁ´½Ó£º
https://www.trendmicro.com/en_us/research/21/l/collecting-in-the-dark-tropic-trooper-targets-transportation-and-government-organizations.html
Group-IB³Æ´ó¹æÄ£Õ©Æ»î¶¯Ã¿ÔÂÔì³ÉÔ¼8000ÍòÃÀÔªËðʧ
12ÔÂ21ÈÕ£¬Group-IB·¢ÏÖÒ»³¡Õë¶ÔÈ«Çò90¶à¸ö¹ú¼Ò/µØÓòµÄÓû§µÄթƻ¡£Ñо¿ÈËÔ±³Æ£¬Ä¿Ç°ÒѼì²âµ½ÖÁÉÙ60¸ö²îÒìµÄÕ©ÆÍøÂ磬ÔËÐÐÓÐÕë¶ÔÐÔµÄÁ´½Ó£¬Æ½¾ùÿ¸öÍøÂçʹÓÃÁË70¸ö²îÒìµÄÓòÃû¡£´Ë´Î»î¶¯Ã°³ä121¸öÆ·ÅÆ£¬ÒªÇóÓû§¼ÓÈëÊӲ첢»î¶¯ÔùÆ·£¬ÆäÖе¥¸öÕ©ÆÍøÂçµÄDZÔÚÄ¿±êԼΪ1000ÍòÈË¡£Í¨¹ý·ÖÎö·ÃÎÊÕßµÄÀ´Ô´·¢ÏÖ£¬Ö÷ÒªÁ÷Á¿À´×ÔÓ¡¶È£¨42.2%£©¡¢Ì©¹ú£¨7%£©ºÍÓ¡¶ÈÄáÎ÷ÑÇ£¨4.4%£©µÈ¡£
ÔÎÄÁ´½Ó£º
https://www.group-ib.com/media/target-links-2021/
΢ÈíAzure App Serviceй¶²¿ÃÅÓû§Ô´´úÂ볤´ï4Äê
12ÔÂ21ÈÕ£¬Wiz.io³ÆÎ¢ÈíAzure App Serviceƽ̨´æÔÚ©¶´£¬Ð¹Â¶Á˽ü4ÄêËùÓÐʹÓÃPHP¡¢Node¡¢Python¡¢RubyºÍJava¿ª·¢µÄÓ¦ÓõÄÔ´´úÂë¡£¸Ãƽ̨Ö÷ÒªÓÃÓÚ¹¹½¨ºÍÍйÜWebÓ¦Ó÷¨Ê½£¬ÓÉÓÚÓû§ÎÞÒâÖÐÅäÖÃÐèÒªÔÚÄÚÈݸùĿ¼Öд´½¨µÄ.gitÎļþ¼Ðµ¼ÖÂÐÅϢй¶¡£Ñо¿ÈËÔ±½«Â©¶´Ï·³ÆÎªNotLegit£¬³ÆÆä×Ô2017Äê9Ô¾ÍÒ»Ö±´æÔÚ£¬¿ÉÄÜÒѱ»ÔÚÒ°ÀûÓá£12ÔÂ22ÈÕ£¬Î¢ÈíÐû²¼Í¨¸æ³ÆÎÊÌâÒѽâ¾ö¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/microsoft-azure-app-service-flaw-exposed-customer-source-code/
Unit 42Ðû²¼2021ÄêµÚÈý¼¾¶ÈÍøÂçÄþ¾²Ç÷ÊÆµÄ·ÖÎö³ÂËß
Unit 42ÔÚ12ÔÂ21ÈÕÐû²¼ÁË2021ÄêµÚÈý¼¾¶ÈÍøÂçÄþ¾²Ç÷ÊÆµÄ·ÖÎö³ÂËß¡£³ÂËßÖ¸³ö£¬µÚÈý¼¾¶È×ܹ²ÓÐ7064¸öеÄCVE£¬ÆäÖÐ594¸öÊôÓÚ¸ßΣ©¶´£¬Õ¼±È13.6%£¬1965¸ö¸ßÑÏÖØÐÔ©¶´£¨45.1%£©ºÍ2542ÆäÖеÈÑÏÖØÐÔ©¶´£¨41.3%£©£»ÆäÖÐ25.6%Êǵ±µØÂ©¶´£¬ÆäÓàµÄ74.4%ÊÇÔ¶³Ì©¶´£»×î³£¼û©¶´ÀàÐÍΪ¿çÕ¾½Å±¾¡¢¾Ü¾ø·þÎñºÍÐÅϢй¶©¶´£¬×î³£¼ûµÄ¹¥»÷ÀàÐÍΪÐÅϢй¶¡¢´úÂëÖ´ÐкÍĿ¼±éÀú¡£
ÔÎÄÁ´½Ó£º
https://unit42.paloaltonetworks.com/network-attacks-trends-august-october-2021/