JFrog·¢ÏÖClickHouse DBMSÖеÄ7¸öRCEºÍDoS©¶´

Ðû²¼Ê±¼ä 2022-03-21

JFrog·¢ÏÖClickHouse DBMSÖеÄ7¸öRCEºÍDoS©¶´


JFrogÑо¿ÍŶÓÔÚ3ÔÂ15ÈÕÐû²¼³ÂËߣ¬ÏêÊöÁË¿ªÔ´Êý¾Ý¿â¹ÜÀíϵͳClickHouseÖеÄ7¸ö©¶´ ¡£ÆäÖаüÂÞ¿ÉÒÔµ¼Ö´úÂëÖ´ÐеĶѻº³åÇøÒç³ö©¶´£¨CVE-2021-43304ºÍCVE-2021-43305£© £»¿Éµ¼Ö¾ܾø·þÎñ»òÐÅϢй¶µÄ¶ÑÔ½½ç©¶´£¨CVE-2021-42387ºÍCVE-2021-42388£© £»ÒÔ¼°DoS©¶´£¨CVE-2021-42389¡¢CVE-2021-42390ºÍCVE-2021-42391£© ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓöñÒâµÄѹËõÎļþÀûÓÃÉÏÊöÈÎÒâ©¶´£¬Ôì³ÉÊý¾Ý¿â·þÎñÆ÷Í߽⣬½¨ÒéÓû§Éý¼¶µ½v21.10.2.15-stable»ò¸ü¸ß°æ±¾ÒÔÐÞ¸´Â©¶´ ¡£


https://jfrog.com/blog/7-rce-and-dos-vulnerabilities-found-in-clickhouse-dbms/


Ñо¿ÈËÔ±Åû¶CRI-OÖЩ¶´cr8escapeµÄÏêϸÐÅÏ¢


3ÔÂ15ÈÕ£¬CrowdStrikeÍŶÓÅû¶ÁËCRI-OÖЩ¶´cr8escape£¨CVE-2022-0811£©µÄÏêϸÐÅÏ¢ ¡£CRI-OÊÇÒ»¸öÇáÁ¿¼¶µÄ£¬×¨ÃŶÔKubernetes½øÐÐÓÅ»¯µÄÈÝÆ÷ÔËÐÐʱ»·¾³ ¡£¸Ã©¶´µÄCVSSÆÀ·ÖΪ8.8£¬Ñо¿ÈËÔ±ÌåÏÖËü¿É±»ÓÃÀ´Èƹý± £»¤´ëÊ©²¢ÔÚÄ¿±êÖ÷»úÉÏÉèÖÃÈÎÒâÄں˲ÎÊý£¬ÈκÎÓÐȨÔÚʹÓÃCRI-OµÄKubernetesÉϲ¿ÊðpodµÄ¹¥»÷Õß¶¼¿ÉÒÔÀÄÓÃkernel.core_pattern²ÎÊý£¬ÔÚÈÎÒâ½ÚµãÉÏÒÔrootȨÏÞ½øÐÐÈÝÆ÷ÌÓÒݺÍÖ´ÐÐÈÎÒâ´úÂë ¡£¸Ã©¶´ÒÑÔÚ3ÔÂ15ÈÕÐû²¼µÄ1.23.2°æ±¾ÖÐÐÞ¸´ ¡£


https://thehackernews.com/2022/03/new-vulnerability-in-cri-o-engine-lets.html


Emotet»Ø¹é£¬Ã°³äÃÀ¹ú¹ú˰¾Ö·¢ËÍ´óÁ¿µöÓãÓʼþ


¾ÝýÌå3ÔÂ16Èճƣ¬ÓʼþÄþ¾²¹«Ë¾Cofense·¢ÏÖEmotetÐÂÒ»ÂֵĵöÓã»î¶¯ ¡£ÃÀ¹úĿǰÕýÖµ±¨Ë°¼¾£¬¹¥»÷Õßð³ä»¥ÁªÍøË°Îñ¾Ö(IRS.gov)£¬ÏòÄ¿±ê·¢ËÍ2021ÄêÄÉ˰É걨±í¡¢W-9±í¸ñºÍ±¨Ë°ÆÚ¼ä³£ÓÃµÄÆäËü˰ÎñÎļþ ¡£Ä¿±êÖ´Ðи½¼þÖаüÂÞ¶ñÒâºêµÄÓÕ¶üÎļþºó£¬»áÏÂÔØ²¢°²×°Emotet ¡£Ö®ºó£¬¸Ã¶ñÒâÈí¼þ»áÏÂÔØÌØ±ðµÄpayload£¬°üÂÞCobalt StrikeºÍÔ¶³Ì·ÃÎÊľÂíSystemBCµÈ ¡£´ËÍ⣬¸½¼þÖеÄzipÎļþÊÜÃÜÂë± £»¤£¬Òò´ËºÜÄѱ»Äþ¾²ÓʼþÍø¹Ø¼ì²âµ½ ¡£


https://www.cyberscoop.com/cofense-emotet-irs-phishing/


AhnLabÐû²¼CirenegRAT½üÆÚ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß


AhnLabÔÚ3ÔÂ16ÈÕÐû²¼Ò»·ÝгÂËߣ¬¸ÅÊöÁËGhostCringeÈçºÎÕë¶ÔÒ×Êܹ¥»÷µÄÊý¾Ý¿â·þÎñÆ÷ ¡£GhostCringeÒ²³ÆÎªCirenegRAT£¬ÊÇ»ùÓÚGh0st RATµÄ´úÂëµÄ¶ñÒâÈí¼þÖ®Ò»£¬ÓÚ2018Äê12ÔÂÊ״α»·¢ÏÖ£¬Í¨¹ýSMB©¶´½øÐзַ¢ ¡£´Ë´Î»î¶¯Ö÷ÒªÃé×¼MS-SQLºÍMySQL·þÎñÆ÷£¬¹¥»÷ÕßʹÓýø³Ìmysqld.exe¡¢mysqld-nt.exeºÍsqlserver.exe½«¶ñÒâµÄmcsql.exe¿ÉÖ´ÐÐÎļþдÈë´ÅÅÌ ¡£


https://asec.ahnlab.com/en/32572/


SophosÐû²¼¹ØÓÚCryptoRomÐÂÒ»ÂÖ¹¥»÷µÄ·ÖÎö³ÂËß


3ÔÂ16ÈÕ£¬SophosÐû²¼Á˹ØÓÚCryptoRomÕë¶ÔiPhoneºÍAndroidÓû§µÄ¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß ¡£CryptoRomÓÚ2021ÄêÊ״α»Åû¶£¬ÊÇÒ»¸öÔÚÑÇÖÞ¡¢ÃÀ¹úºÍÅ·ÖÞ»îÔ¾µÄ¹ú¼ÊÕ©Æ­ÍÅ»ï ¡£Ñо¿ÌåÏÖ£¬CryptoRomÒѾ­¸ïÐÂÁ˼¼Êõ£¬ËûÃÇÀûÓÃiOS¹¦Ð§TestFlightºÍWebClips£¬ÈƹýÑϸñµÄÉóÅúÁ÷³Ì½«¶ñÒâÓ¦Óð²×°ÔÚÄ¿±êµÄÊÖ»úÉÏ ¡£³ÂË߳ƣ¬ÀֳɵÄCryptoRom¹¥»÷»î¶¯¿ÉÄܸøÄ¿±êÔì³ÉÎåλÊý¡¢ÁùλÊýÉõÖÁÆßλÊýµÄËðʧ ¡£


https://news.sophos.com/en-us/2022/03/16/cryptorom-bitcoin-swindlers-continue-to-target-vulnerable-iphone-and-android-users/


»ªË¶³ÆÆä¶à¿î·ÓÉÆ÷Ò×ÊÜCyclops BlinkµÄ¹¥»÷


»ªË¶£¨ASUS£©ÔÚ3ÔÂ17ÈÕÐû²¼Äþ¾²Í¨¸æ£¬³ÆÆä¶à¿î·ÓÉÆ÷Ò×ÊÜCyclops BlinkµÄ¹¥»÷ ¡£Ç÷ÊÆ¿Æ¼¼ÌåÏָöñÒâÈí¼þÓÐÒ»¸öרÃÅÕë¶Ô»ªË¶Â·ÓÉÆ÷µÄÄ£¿é£¬¿É¶ÁÈ¡ÉÁ´æÀ´ÊÕ¼¯ÓйØÎļþ¡¢¿ÉÖ´ÐÐÎļþ¡¢Êý¾ÝºÍ¿âµÄÐÅÏ¢ ¡£È»ºó£¬Ëü»áÔÚÉÁ´æÖн¨Á¢³Ö¾Ã»¯£¬¼´Ê¹»Ö¸´³ö³§ÉèÖÃÒ²²»»áɾ³ý ¡£Ä¿Ç°£¬»ªË¶ÉÐδÐû²¼ÐµĹ̼þ¸üÐÂÒÔµÖÓùCyclops BlinkµÄ¹¥»÷£¬µ«Ðû²¼ÁËÓÃÓÚ± £»¤É豸µÄ»º½â´ëÊ© ¡£


https://www.bleepingcomputer.com/news/security/asus-warns-of-cyclops-blink-malware-attacks-targeting-routers/



Äþ¾²¹¤¾ß


RefleXXion


ÊÇÒ»¸öʵÓ÷¨Ê½£¬Ö¼ÔÚ×ÊÖúÈÆ¹ý AV/EPP/EDR µÈʹÓõÄÓû§Ä£Ê½hook ¡£


https://github.com/hlldz/RefleXXion


LDAP shell


Õâ¸ö´æ´¢¿â°üÂÞÒ»¸ö´Ó ldap_shell ¼Ì³ÐµÄС¹¤¾ß ¡£


https://github.com/z-Riocool/ldap_shell/


Viper


ÊÇÒ»¸öͼÐλ¯µÄÄÚÍøÉøÍ¸¹¤¾ß ¡£


https://github.com/FunnyWolf/Viper


Nivistealer 


ÓÃÓÚÇÔȡĿ±êͼÏñ¼òÖ±ÇÐλÖÃÉ豸ÐÅÏ¢µÈµÈ ¡£


https://github.com/swagkarna/Nivistealer




Äþ¾²·ÖÎö


¶íÂÞ˹ʹÓÃÎÚ¿ËÀ¼×ÜͳµÄdeepfakeÐû²¼Ðé¼ÙÐÅÏ¢


https://securityaffairs.co/wordpress/129124/intelligence/russia-deepfake-video-zelenskyy.html


΢ÈíÆô¶¯ 2022 Äê 3 Ô Windows 11 Bug Bash


https://news.softpedia.com/news/microsoft-kicks-off-the-march-2022-bug-bash-for-windows-11-535050.shtml


Cobalt Strike ·ÖÎöºÍ½Ì³Ì


https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/


αװ³É²úÎï½éÉܵĶñÒâWordÎļþ


https://asec.ahnlab.com/en/32609/


Ò»ÌìÄÚÊý°Ù¸öÍйÜÔÚGoDaddyµÄÍøÕ¾Ôâµ½ºóÃŹ¥»÷


https://www.wordfence.com/blog/2022/03/increase-in-malware-sightings-on-godaddy-managed-hosting/


Zimperium Ðû²¼ÁËÆäÄê¶ÈÒÆ¶¯Íþв³ÂËß


https://www.bleepingcomputer.com/news/security/2021-mobile-security-android-more-vulnerabilities-ios-more-zero-days/