ÐÅÏ¢°²È«Öܱ¨-2021ÄêµÚ6ÖÜ

°ä²¼¹¦·ò 2021-02-08

> ±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2021Äê02ÔÂ01ÈÕÖÁ02ÔÂ07ÈÕ¹²ÊÕ¼°²È«·ì϶66¸ö£¬ÖµµÃ¹Ø×¢µÄÊÇApache Shiro½Ó¼ûÈÆ¹ý·ì϶£»Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´Ðзì϶£»Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´Ðзì϶£»Sonicwall SMA100 SQL×¢Èë·ì϶£»Apple macOS CoreText TTFÔ½½çд´úÂëÖ´Ðзì϶¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇCisco°ä²¼2021ÄêÊý¾ÝÒþÖÔ»ù×¼µÄ×êÑл㱨£»Azure FunctionsÖдæÔÚÌáȨ·ì϶£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú£»NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯£»Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â£»»õÔ˹«Ë¾Forward AirϰȾHades£¬Ëðʧ´ï750ÍòÃÀÔª¡£


ƾ¾ÝÒÔÉÏ×ÛÊö£¬±¾Öܰ²È«ÍþвΪÖС£


> ³ÁÒª°²È«·ì϶Áбí


1.Apache Shiro½Ó¼ûÈÆ¹ý·ì϶


Apache ShiroʹÓÃspring´æÔÚ°²È«·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉδÊÚȨ½Ó¼û·þÎñ¡£

https://lists.apache.org/thread.html/rce5943430a6136d37a1f2fc201d245fe094e2727a0bc27e3b2d43a39%40%3Cdev.shiro.apache.org%3E


2.Apache Dubbo decodeBody·´ÐòÁл¯´úÂëÖ´Ðзì϶


Apache Dubbo decodeBody´¦ÖôæÔÚ·´ÐòÁл¯·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»·þÎñ¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-128/


3.Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤´úÂëÖ´Ðзì϶


Siemens Comfort Panel Telnet·þÎñÎÞÑéÖ¤·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇó£¬Äܹ»ROOT¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://us-cert.cisa.gov/ics/advisories/icsa-21-033-02


4.Sonicwall SMA100 SQL×¢Èë·ì϶


Sonicwall SMA100 WEB½Ó¿Ú´æÔÚSQL×¢Èë·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄSQLÒªÇ󣬲Ù×÷Êý¾Ý¿â£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐËÁÒâ´úÂë¡£

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0001


5.Apple macOS CoreText TTFÔ½½çд´úÂëÖ´Ðзì϶


Apple macOS CoreText TTF½âÎö´æÔÚÔ½½çд·ì϶£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬿ÉʹÀûÓ÷¨Ê½±ÀÀ£»òÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£

https://www.zerodayinitiative.com/advisories/ZDI-21-149/


> ³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢Cisco°ä²¼2021ÄêÊý¾ÝÒþÖÔ»ù×¼µÄ×êÑл㱨


1.png


Cisco°ä²¼ÁË2021ÄêÊý¾ÝÒþÖÔ»ù×¼µÄ×êÑл㱨¡£×êÑе÷²éÁËÀ´×Ô25¸ö¹ú¶ÈºÍµØÓòµÄ4400¶à¸ö×éÖ¯£¬²¢Ì½ÇóÁËËûÃǶÔÒþÖÔÂÉÀýµÄ̬¶È¡£»ã±¨ÏÔʾ£¬60£¥µÄ×é֯ûÓÐΪԶ³Ì¹¤×÷ËùÉæ¼°µÄÒþÖԺͰ²È«ÒªÇó×öºÃ³ï±¸£¬93£¥µÄ×é֯ͨ¹ýÒþÖÔ±£»¤ÍŶÓÀ´Ó¦¶ÔÕâЩÌôÕ½£¬87£¥µÄÓ×ÎÒ²»°²ËûÃÇËùʹÓõÄÔ¶³Ì¹¤¾ßµÄÒþÖÔ±£»¤ÎÊÌâ¡£´Ë±í£¬ÏÖÒÑÓÐ140¶à¸ö˾·¨¹ÜÏ½ÇøÔì¶©ÁËÒþÖÔ±£»¤·¨£¬½ü80£¥µÄÊÜ·ÃÕßÒÔΪÕâЩ˾·¨ÓµÓлý¼«Ó°Ïì¡£


Ô­ÎÄÁ´½Ó£º

https://blogs.cisco.com/security/privacy-comes-of-age-during-the-pandemic


2¡¢Azure FunctionsÖдæÔÚÌáȨ·ì϶£¬¿ÉÌÓÒÝÖÁDockerÖ÷»ú


2.png


Intezer LabµÄ×êÑÐÈËÔ±Åû¶ÁËMicrosoft Azure FunctionsÖÐ佨¸´µÄÌáȨ·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÀ´ÌÓÒÝÖÁDockerÖ÷»ú¡£Azure FunctionsÄܹ»ÓÉHTTPÒªÇó´¥·¢£¬Óû§µÄ´úÂëÔÚAzureÍйܵÄÈÝÆ÷ÉÏÔËÐУ¬µ«ÊÇ´úÂëûÓб»°²È«Ô׸²¢ÇÒ¿ÉÄܱ»ÀÄÓÃÀ´½Ó¼ûµ×²ã»·¾³¡£×êÑÐÈËÔ±·¢ÏÖÄܹ»Í¨¹ý´´½¨Ò»¸öHTTP´¥·¢Æ÷À´Ö´ÐÐshell£¬ÒÔÎÞÌØÈ¨µÄappÓû§Éí·ÝÔÚÈÝÆ÷²éÕÒÊôÓÚrootȨÏ޵Ĺý³Ì½Ó¿Ú¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/114061/hacking/azure-functions-escape-docker.html


3¡¢NCC Group¼ì²âµ½ÀûÓÃSonicWallÖÐ0dayµÄ¹¥»÷»î¶¯


3.png


ÍøÂ簲ȫ¹«Ë¾NCC GroupÖÜÈճƣ¬ËüÒѼì²âµ½Õë¶ÔSonicWallÍøÂçÉ豸ÖÐÁãÈÕ·ì϶µÄ×Ô¶¯ÀûÓó¢ÊÔ¡£Ä¿Ç°Éв»Ã÷ÏÔ´Ë·ì϶ÊÇ·ñÓëSonicWallÔÚ1ÔÂ23ÈÕÅû¶µÄ·ì϶һÑù£¬µ«NCCÒÔΪÕâÊǼ«ÓпÉÄܵÄ¡£SonicWallÔÚÆäSMA 100°²È«²¼¸æµÄ¸üÐÂÖÐÒÑÈ·ÈÏÁËNCC Group·¢ÏÖµÄÁãÈÕ·ì϶£¬ÁгöÁËÊÜÓ°ÏìµÄÉ豸ÐͺŲ¢°µÊ¾»áÔÚ2ÔÂ2ÈÕ֮ǰ°ä²¼²¹¶¡·¨Ê½¡£Óйطì϶µÄϸ½Ú²¢Î´¹«¿ª£¬ÒÔÔ¤·ÀÆäËû¹¥»÷Õß¶ÔÆä½øÐÐ×êÑв¢·¢Æð¹¥»÷¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/sonicwall-zero-day-exploited-in-the-wild/


4¡¢Agent Tesla³¢ÊÔ´Û¸Ä΢ÈíAMSIÀ´Èƹýɱ¶¾Èí¼þ¼ì²â


4.png


Sophos×êÑÐÈËÔ±·¢ÏÖ¼äµýÈí¼þAgent Tesla³¢ÊÔ´Û¸Ä΢Èí·À¶ñÒâÈí¼þÈí¼þ½Ó¿Ú£¨AMSI£©£¬À´Èƹýɱ¶¾Èí¼þµÄɨÃèºÍ·ÖÎö¡£Agent TeslaÓÚ2014Äê³õ´Î±»·¢ÏÖ£¬ÊÇÒ»ÖÖÓÃ.NET±àдµÄóÒ×RAT¡£Sophos°µÊ¾£¬¸Ã¶ñÒâÈí¼þÔÚ²»ÐÝ¿ª·¢ÖУ¬Æä.NETÏÂÔØ·¨Ê½¿ÉŲÓò¢ÏÂÔØÍйÜÔںϷ¨ÍøÕ¾ÉϵĶñÒâ´úÂë¡£Ôڳɹ¦´Û¸ÄAMSIºó¸Ã¶ñÒâÈí¼þ¿ÉÔÚûÓÐÈκÎ×ÌÈŵÄÇé¿öÏÂÆëÈ«ÊýÊð£¬ÒÔÇÔÈ¡Êý¾Ý£¬ÖØÒªÕë¶ÔOpera¡¢Chromium¡¢Chrome¡¢Firefox¡¢OpenVPNºÍOutlookµÅצÓá£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/agent-tesla-ramps-up-its-game-in-bypassing-security-walls-attacks-endpoint-protection/


5¡¢»õÔ˹«Ë¾Forward AirϰȾHades£¬Ëðʧ´ï750ÍòÃÀÔª


5.png


»õÔ˹«Ë¾Forward AirÔâµ½ÁËHadesÀÕË÷Èí¼þ¹¥»÷£¬Ôì³ÉµÄËðʧ´ï750ÍòÃÀÔª¡£¸Ã¹¥»÷ÊÂÎñ²úÉúÔÚÈ¥Äê12ÔÂ15ÈÕ£¬ÒòϰȾHadesµ¼Ö¸ù«Ë¾½«ËùÓÐITϵͳÍÑ»úÒÔÓ¦¶ÔÈëÇÖ¡£µ¼Ö¼ÝʻԱºÍÔ±¹¤ÎÞ·¨»ñÈ¡±ØÒªµÄÎļþÒÔͨ¹ýº£¹ØÇ幨ÔËÊ䣬ÆäÔËÓªÊܵ½ÑϳÁ·ÛËé¡£Ö»¹ÜForward Air°µÊ¾ÆäÒѳɹ¦µØ´Ó¹¥»÷Öи´Ô­£¬µ«»¹ÊÇÖ§³öÁ˳Á³Á¼ÛÖµ£¬ÆäÔÚµÚËÄʱ¶ÈµÄ²ÆÕþÒµ¼¨ÖеÄËðʧ¸ß´ï750ÍòÃÀÔª¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/trucking-company-forward-air-said-its-ransomware-incident-cost-it-7-5-million/