ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ1ÖÜ

Ðû²¼Ê±¼ä 2021-01-04

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2020Äê12ÔÂ28ÈÕÖÁ2021Äê01ÔÂ03ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´52¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇKLog Server actions/authenticate.phpÃüÁî×¢È멶´ £»Solarwinds Orion Platform Request.PathInfoÄþ¾²Èƹý©¶´ £»Panasonic Security SystemÓ²±àÂ멶´ £»Netgear NMS300 CVE-2020-35789ÃüÁî×¢È멶´ £»NETGEAR D7800 CVE-2020-35791ÃüÁî×¢È멶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇApple iCloudÖжÏ36Сʱ£¬Éв»Çå³þ¹ÊÕÏÔ­Òò £»GoDaddyÏòÔ±¹¤·¢Ë͵öÓãÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³ £»Ð¶ñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike½Å±¾ £»ÈÕ±¾¾ü¹¤ÆóÒµ´¨ÆéÖع¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶ £»WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öСʱ¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


ÖØÒªÄþ¾²Â©¶´Áбí


1.KLog Server actions/authenticate.phpÃüÁî×¢È멶´


KLog Server actions/authenticate.php´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿É×¢ÈëÈÎÒâOSÃüÁî²¢Ö´ÐС£

https://github.com/mustgundogdu/Research/blob/main/KLOG_SERVER/Exploit_Code


2.Solarwinds Orion Platform Request.PathInfoÄþ¾²Èƹý©¶´


Solarwinds Orion Platform Request.PathInfo´æÔÚÑéÖ¤Èƹý©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÖ´ÐÐδÊÚȨµÄAPIÃüÁî¡£

https://www.kb.cert.org/vuls/id/843464


3.Panasonic Security SystemÓ²±àÂ멶´


Panasonic Security System´æÔÚlkjhgfdsaÓ²±àÂ멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸¡£

https://security.panasonic.com/products_technology/products/wv-s2231l/



4.Netgear NMS300 CVE-2020-35789ÃüÁî×¢È멶´


Netgear NMS300´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸¡£

https://kb.netgear.com/000062686/Security-Advisory-for-Post-Authentication-Command-Injection-on-NMS300-PSV-2020-0559


5.NETGEAR D7800 CVE-2020-35791ÃüÁî×¢È멶´


NETGEAR D7800´æÔÚÊäÈëÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊÉ豸¡£

https://kb.netgear.com/000062714/Security-Advisory-for-Post-Authentication-Command-Injection-on-Some-Routers-PSV-2019-0079


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢Apple iCloudÖжÏ36Сʱ£¬Éв»Çå³þ¹ÊÕÏÔ­Òò


1.jpg


Apple iCloud·þÎñ·ºÆð¹ÊÕÏ£¬Ê¹Óû§ÎÞ·¨µÇ¼¸Ã·þÎñ·ÃÎÊÎļþ»òÉèÖÃÐÂÉ豸¡£´Ë´ÎÖжϴÓÃÀ¹ú¶«²¿Ê±¼ä12ÔÂ25ÈÕÉÏÎç4:45¿ªÊ¼£¬Ö±µ½12ÔÂ26ÈÕÏÂÎç4:35²Å±»ÐÞ¸´£¬Àúʱ36Сʱ¡£ÖжÏÆڼ䣬AppleµÄϵͳ״̬ҳÉϽöÏÔʾ¡°Óû§¿ÉÄÜÓöµ½´Ë·þÎñµÄÎÊÌ⡱µÄÌáʾ£¬Ã»Óиü¶àÓйشËÖжϵÄÐÅÏ¢¡£Ä¿Ç°£¬Apple¹«Ë¾Ã»ÓÐÌṩÈκιÊÕÏÔ­Òò¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/apple/apple-icloud-outage-prevents-device-activations-access-to-data/


2¡¢GoDaddyÏòÔ±¹¤·¢Ë͵öÓãÓʼþ£¬²âÊÔÔ±¹¤µÄ·´Ó³


2.jpg


GoDaddyÏòÔ±¹¤·¢Ë͵öÓãÓʼþ£¬ÒÔ²âÊÔÔ±¹¤¶ÔÍøÂçµöÓã»î¶¯µÄ·´Ó³¡£¸Ã²âÊÔÓÚ12Ô½øÐУ¬ÓʼþÉù³Æ½«Ìṩ650ÃÀÔªµÄÊ¥µ®½Ú½±½ð£¬ÒÔ×ÊÖúÔ±¹¤Ó¦¶ÔÒòCOVID-19·¢×÷¶øµ¼Öµľ­¼ÃÎÊÌ⣬²¢ÒªÇóËûÃÇÌîд¸öÈËÐÅÏ¢±í¸ñ¡£Õâ´Î²âÊԻԼĪ500ÃûÔ±¹¤ÖÐÕУ¬ËûÃǽ«±»ÒªÇóÖØмÓÈëÉç»á¹¤³ÌÄþ¾²ÒâʶµÄÅàѵ¡£ÓÉÓÚ²âÊÔÖÐʹÓõÄÓÕ¶üºÍÄ£Äâʱ¼äµÄÑ¡Ôñ£¬¸ÃÒªÁìÊܵ½Á˲¿ÃÅÍøÂçÄþ¾²ÍÅÌåµÄÅúÆÀ¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112664/security/godaddy-phishing-test-employees.html


3¡¢Ð¶ñÒâÈí¼þ¿ÉÀûÓÃImgurÀ´½âÂëCobalt Strike½Å±¾


3.jpg


жñÒâÈí¼þ¿ÉÀûÓÃͼÏñÍйܷþÎñImgurÏÂÔغϷ¨µÄͼÏñ£¬À´½âÂëCobalt Strike½Å±¾¡£ÐµĶñÒâÈí¼þʹÓôøÓкêµÄWordÎļþ´ÓGitHubÏÂÔØPowerShell½Å±¾£¬¸Ã½Å±¾½«´ÓImgurÏÂÔØʵ¼ÊPNGÎļþ¡£Ö®ºó£¬ÀûÓÃÏñInvoke-PSImageÕâÑùµÄ¹¤¾ßÀ´Ê¹ÓÃPNGÎļþÖеÄÏñËØÖµ±àÂëPowerShell½Å±¾£¬²¢Éú³ÉÒ»ÐÐÃüÁîÀ´Ö´ÐÐpayload£¬×îÖÕ»ñµÃCobalt Strike½Å±¾¡£Ñо¿ÈËÔ±ÍƲâ´Ë¶ñÒâÈí¼þ¿ÉÄÜÓëÖ÷ÒªÕë¶ÔÖж«ÊµÌåµÄAPT×éÖ¯MuddyWaterÓйØ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/github-hosted-malware-calculates-cobalt-strike-payload-from-imgur-pic/


4¡¢ÈÕ±¾¾ü¹¤ÆóÒµ´¨ÆéÖع¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶


4.png


ÈÕ±¾¾ü¹¤ÆóÒµ´¨ÆéÖع¤Ôâµ½¹¥»÷£¬»ò½«µ¼ÖÂÊý¾Ýй¶¡£´¨ÆéÖع¤£¨Kawasaki£©³Æ£¬2020Äê6ÔÂ11ÈÕÓÐδ¾­ÊÚȨµÄµÚÈý·½´ÓÌ©¹ú·þÎñ´¦·ÃÎÊÁËÈÕ±¾µÄ·þÎñÆ÷£¬ÔÚ·¢ÏÖ¸ÃÎÊÌâºóÁ½¸öÕ¾µãÖ®¼äµÄËùÓÐͨÐŶ¼±»Í£Ö¹¡£Ëæºó£¬¸Ã¹«Ë¾ÓÖ·¢ÏÖÁËÆäËûº£ÍâÕ¾µã£¨Ó¡¶ÈÄáÎ÷ÑÇ¡¢·ÆÂɱöºÍÃÀ¹ú£©Î´¾­ÊÚȨ·ÃÎÊÈÕ±¾·þÎñÆ÷µÄÇé¿ö£¬²¢ÇжÏͨÐÅ¡£´¨Æé³Æ´Ë´Î¹¥»÷ʹÓÃÁËÏȽø¼¼Êõ¶øûÓÐÁôÏÂÈκκۼ£ºÍÖ¤¾Ý£¬µ«¹«Ë¾Êý¾Ý»òÐíÒѾ­Ð¹Â¶¡£ËùÓб»ÖÕÖ¹µÄͨÐÅÓÚ11ÔÂ30ÈÕ»Ö¸´Õý³£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/112765/data-breach/kawasaki-heavy-industries-cyber-attack.html


5¡¢WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öСʱ


5.png


WasabiÔÆ´æ´¢·þÎñÒòDNS½âÎöÎÊÌâµ¼ÖÂÖжÏ13¸öСʱ¡£12ÔÂ28ÈÕÏÂÎç2:30 ESTÓû§·¢ÏÖÎÞ·¨·ÃÎÊwasabisys.comÉϵĴ洢Ͱ£¬WasabiÔÚÖжϳÂËßÖгÆÊÇÓÉÓÚDNS½âÎöÎÊÌâµ¼Ö¡£¾ÝϤ£¬¸Ãƽ̨Óû§ÉÏ´«Á˶ñÒâÈí¼þ£¬ÆäÓòÃû³Æ×¢²áÉÌ·¢ÏÖºóÏëҪͨ¹ýµç×ÓÓʼþ֪ͨWasabi£¬È´°Ñ³ÂËßת·¢µ½ÁË´íÎóµÄµØÖ·£¬Ê¹µÃWasabiδµÃµ½Í¨Öª¡£¶ø¸Ã×¢²áÉÌÒòδµÃµ½»Ø¸´¶øÔÝÍ£Á˸ÃÓò£¬WasabiÔÚµÃÖª¸Ãʼþºóɾ³ýÁËÍйܶñÒâÈí¼þ²¢ÒªÇóÖØ줻î¸ÃÓò£¬Æ½Ì¨ÔÚ12ÔÂ29ÈÕÏÂÎç12:57 ESTÖÕÓڵõ½»Ö¸´¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/wasabi-cloud-storage-service-knocked-offline-for-hosting-malware/