ÐÅÏ¢Äþ¾²Öܱ¨-2021ÄêµÚ6ÖÜ

Ðû²¼Ê±¼ä 2021-02-08

> ±¾ÖÜÄþ¾²Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ01ÈÕÖÁ02ÔÂ07ÈÕ¹²ÊÕ¼Äþ¾²Â©¶´66¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Shiro·ÃÎÊÈƹý©¶´£»Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐЩ¶´£»Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´ÐЩ¶´£»Sonicwall SMA100 SQL×¢È멶´£»Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐЩ¶´¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÄþ¾²Ê¼þÊÇCiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËߣ»Azure FunctionsÖдæÔÚÌáȨ©¶´£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯£»Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»»õÔ˹«Ë¾Forward AirѬȾHades£¬Ëðʧ´ï750ÍòÃÀÔª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾ÖÜÄþ¾²ÍþвΪÖС£


> ÖØÒªÄþ¾²Â©¶´Áбí


1.Apache Shiro·ÃÎÊÈƹý©¶´


Apache ShiroʹÓÃspring´æÔÚÄþ¾²Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉδÊÚȨ·ÃÎÊ·þÎñ¡£

https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E


2.Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´ÐЩ¶´


Apache Dubbo decodeBody´¦ÖôæÔÚ·´ÐòÁл¯Â©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔ·þÎñÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-128/


3.Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´ÐЩ¶´


Siemens Comfort Panel Telnet·þÎñÎÞÑé֤©¶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉÒÔROOTÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-033-02


4.Sonicwall SMA100 SQL×¢È멶´


Sonicwall SMA100 WEB½Ó¿Ú´æÔÚSQL×¢È멶´£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔÀûÓ鶴Ìá½»ÌØÊâµÄSQLÇëÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐÈÎÒâ´úÂë¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001


5.Apple macOS CoreText TTFÔ½½çд´úÂëÖ´ÐЩ¶´


Apple macOS CoreText TTF½âÎö´æÔÚÔ½½ç䩶´£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ鶴Ìá½»ÌØÊâµÄÇëÇ󣬿ÉʹӦÓ÷¨Ê½±ÀÀ£»òÒÔÓ¦Ó÷¨Ê½ÉÏÏÂÎÄÖ´ÐÐÈÎÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-149/


> ÖØÒªÄþ¾²Ê¼þ×ÛÊö


1¡¢CiscoÐû²¼2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËß


1.png


CiscoÐû²¼ÁË2021ÄêÊý¾ÝÒþ˽»ù×¼µÄÑо¿³ÂËß¡£Ñо¿ÊÓ²ìÁËÀ´×Ô25¸ö¹ú¼ÒºÍµØÓòµÄ4400¶à¸ö×éÖ¯£¬²¢Ì½ÌÖÁËËûÃǶÔÒþ˽¹æÔòµÄ̬¶È¡£³ÂËßÏÔʾ£¬60£¥µÄ×é֯ûÓÐΪԶ³ÌÊÂÇéËùÉæ¼°µÄÒþ˽ºÍÄþ¾²ÒªÇó×öºÃ×¼±¸£¬93£¥µÄ×é֯ͨ¹ýÒþ˽±£»¤ÍŶÓÀ´Ó¦¶ÔÕâЩÌôÕ½£¬87£¥µÄ¸öÈ˵£ÓÇËûÃÇËùʹÓõÄÔ¶³Ì¹¤¾ßµÄÒþ˽±£»¤ÎÊÌâ¡£´ËÍ⣬ÏÖÒÑÓÐ140¶à¸ö˾·¨¹ÜϽÇøÖƶ¨ÁËÒþ˽±£»¤·¨£¬½ü80£¥µÄÊÜ·ÃÕßÈÏΪÕâЩִ·¨¾ßÓлý¼«Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://blogs.cisco.com/security/privacy-comes-of-age-during-the-pandemic


2¡¢Azure FunctionsÖдæÔÚÌáȨ©¶´£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú


2.png


Intezer LabµÄÑо¿ÈËÔ±Åû¶ÁËMicrosoft Azure FunctionsÖÐδÐÞ¸´µÄÌáȨ©¶´£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£Azure Functions¿ÉÒÔÓÉHTTPÇëÇó´¥·¢£¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐУ¬µ«ÊÇ´úÂëûÓб»Äþ¾²Ö§½â£¬¶øÇÒ¿ÉÄܱ»ÀÄÓÃÀ´·ÃÎʵײ㻷¾³¡£Ñо¿ÈËÔ±·¢ÏÖ¿ÉÒÔͨ¹ý´´½¨Ò»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell£¬ÒÔÎÞÌØȨµÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏ޵Ľø³Ì½Ó¿Ú¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html


3¡¢NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯


3.png


ÍøÂçÄþ¾²¹«Ë¾NCC GroupÖÜÈճƣ¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂçÉ豸ÖÐÁãÈÕ©¶´µÄÖ÷¶¯ÀûÓÃʵÑ顣ĿǰÉв»Çå³þ´Ë©¶´ÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄ©¶´Ïàͬ£¬µ«NCCÈÏΪÕâÊǼ«ÓпÉÄܵÄ¡£SonicWallÔÚÆäSMA 100Äþ¾²Í¨¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢ÏÖµÄÁãÈÕ©¶´£¬ÁгöÁËÊÜÓ°ÏìµÄÉ豸ÐͺŲ¢ÌåÏÖ»áÔÚ2ÔÂ2ÈÕ֮ǰÐû²¼²¹¶¡·¨Ê½¡£ÓйØ©¶´µÄϸ½Ú²¢Î´¹ûÈ»£¬ÒÔ·ÀÖ¹ÆäËû¹¥»÷Õ߶ÔÆä½øÐÐÑо¿²¢·¢¶¯¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/


4¡¢Agent TeslaʵÑé¸Ä¶¯Î¢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â


4.png


SophosÑо¿ÈËÔ±·¢ÏÖ¼äµýÈí¼þAgent TeslaʵÑé¸Ä¶¯Î¢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍ·ÖÎö¡£Agent TeslaÓÚ2014ÄêÊ״α»·¢ÏÖ£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄÉÌÒµRAT¡£SophosÌåÏÖ£¬¸Ã¶ñÒâÈí¼þÕýÔÚ²»Í£¿ª·¢ÖУ¬Æä.NETÏÂÔØ·¨Ê½¿Éµ÷Óò¢ÏÂÔØÍйÜÔںϷ¨ÍøÕ¾ÉϵĶñÒâ´úÂë¡£ÔÚÀֳɸĶ¯AMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇé¿öÏÂÍêÕû²¿Êð£¬ÒÔÇÔÈ¡Êý¾Ý£¬Ö÷ÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÈÓ¦Óá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/


5¡¢»õÔ˹«Ë¾Forward AirѬȾHades£¬Ëðʧ´ï750ÍòÃÀÔª


5.png


»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª¡£¸Ã¹¥»÷ʼþ·¢ÉúÔÚÈ¥Äê12ÔÂ15ÈÕ£¬ÒòѬȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡ÐëÒªµÄÎļþÒÔͨ¹ýº£¹ØÇå¹ØÔËÊ䣬ÆäÔËÓªÊܵ½ÑÏÖØÆÆ»µ¡£¾¡¹ÜForward AirÌåÏÖÆäÒÑÀֳɵشӹ¥»÷Öлָ´£¬µ«»¹ÊÇÖ§¸¶Á˼«ÖØ´ú¼Û£¬ÆäÔÚµÚËļ¾¶ÈµÄ²ÆÕþÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/