ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢£»£»£»£»£»£»Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î

Ðû²¼Ê±¼ä 2019-07-18

1¡¢ÂùÝÖÎÀí¹«Ë¾AavGoÒâÍâй¶800Íò¿Í»§ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


WizcaseÇå¾²Ñо¿Ô±Daniel Brown·¢Ã÷ÂùÝÖÎÀíÉÌAavGoµÄÒ»¸öElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨800ÍòÌõ¿Í»§ÐÅÏ¢£¬£¬£¬°üÀ¨Ô¤¶©ÐÅÏ¢¡¢¿Í»§Í¶Ëß¡¢·¢Æ±¡¢¹¤µ¥¡¢Ô±¹¤±¸Íü¼ºÍÐÂÎÅ¡¢Âùݷ¿¼äͼƬ¡¢ÎïÆ·Ëð»µÍ¼Æ¬ÒÔ¼°¿Í»§µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨µã¡¢×¡Ö·¡¢»éÒö״̬¡¢µÇ¼ÐÅÏ¢ºÍ¸¶¿î·½·¨£©¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾Ý»¹°üÀ¨ÂùÝÖÎÀíÔ±µÄÏêϸµÇ¼ÐÅÏ¢£¬£¬£¬ÀýÈçÖÎÀíÃæ°å¡¢Ô¤¶©ÏµÍ³ºÍÄÚ²¿Êý¾Ý¿âµÄÓû§ÃûºÍÃÜÂë¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨The Row Hotel¡¢Stay Cal HotelsµÈÊ®¶à¼ÒÂùÝ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÒÑÔÚ7ÔÂ16ÈÕ¶ÔÊý¾Ý¿â½ÓÄÉÁ˱£»£»£»£»£»£»¤²½·¥¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/unprotected-elasticsearch-database-belonging-to-aavgo-exposed-8-million-records-of-guest-details-f5fb1eac


2¡¢CPL³Æ220Íò»¼ÕßÐÅÏ¢ÊÜAMCAÊý¾Ýй¶ÊÂÎñÓ°Ïì


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÁÙ´²²¡ÀíѧʵÑéÊÒ£¨CPL£©³ÉΪAMCAÊý¾Ýй¶ÊÂÎñµÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£¡£¡£AMCAÒÑÏò3.45ÍòCPL»¼Õß·¢ËÍÁËÊý¾Ýй¶֪ͨ£¬£¬£¬Æ¾Ö¤AMCAÌṩµÄÐÅÏ¢£¬£¬£¬CPLÔ¤¼ÆÉÐÓÐ220Íò»¼ÕßÊܵ½´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨CPL»¼ÕßµÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢³öÉúÈÕÆÚ¡¢Ð§ÀÍÈÕÆÚ¡¢Óà¶î¡¢ÐÅÓÿ¨ÐÅÏ¢ºÍÒ½ÉúÐÅÏ¢¡£¡£¡£¡£¡£¡£AMCAÈ·ÈÏ»¼ÕßµÄÉç»áÇå¾²ºÅÂëδÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://cyware.com/news/clinical-pathology-laboratories-notifies-patients-of-security-incident-caused-by-amca-data-breach-37f8382c


3¡¢Sprint³ÆºÚ¿Íͨ¹ýÈýÐÇÍøÕ¾ÈëÇÖÆä¿Í»§ÕË»§


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹úµçÐŹ«Ë¾SprintÌåÏÖºÚ¿ÍÏ뷨ʹÓÃÈýÐÇÍøÕ¾Samsung.comÉϵÄаìºÅÂë¡°Add a line¡±Ò³Ãæ×÷Ϊ¹¥»÷Ìø°å£¬£¬£¬ÈëÇÖÆä¿Í»§ÕË»§¡£¡£¡£¡£¡£¡£ÔÚ·¢¸ø¿Í»§µÄ֪ͨº¯ÖÐSprintÌåÏÖ¹²±¬·¢ÁËÁ½ÆðÎ¥¹æÐÐΪ£¬£¬£¬Ò»Æð±¬·¢ÔÚ6ÔÂ8ÈÕ£¬£¬£¬ÁíÒ»Æð±¬·¢ÔÚ6ÔÂ22ÈÕ¡£¡£¡£¡£¡£¡£ºÚ¿Í¿ÉÒÔ»á¼ûµÄ¿Í»§ÐÅÏ¢°üÀ¨Óû§ID¡¢Õʺš¢ÕÊ»§½¨ÉèÈÕÆÚ¡¢ÐÕÃû¡¢Õʵ¥µØµã¡¢µç»°ºÅÂë¡¢×°±¸ÀàÐÍ¡¢×°±¸ID¡¢Ã¿ÔÂÓöȵÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sprint-accounts-breached-by-hackers-using-samsung-site/


4¡¢Î¢ÈíÐÞ¸´PowerShell½¹µãÖеÄWDACÈÆ¹ýÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


΢ÈíÐû²¼Ð°汾PowerShell Core£¬£¬£¬ÐÞ¸´Ò»¸ö¿ÉÔÊÐíÍâµØ¹¥»÷ÕßÈÆ¹ýWindows DefenderÓ¦ÓóÌÐò¿ØÖÆ£¨WDAC£©µÄÎó²î£¬£¬£¬¸ÃÎó²î±»±ê¼ÇΪCVE-2019-1167¡£¡£¡£¡£¡£¡£ÔÚÆôÓÃWDACʱ£¬£¬£¬PowerShell½«×Ô¶¯½øÈëÔ¼ÊøÓïÑÔģʽÒÔÏÞÖÆ¶ÔijЩWindows APIµÄ»á¼û£¬£¬£¬µ«¸ÃÎó²î¿ÉÈÆ¹ýPowerShellÔ¼ÊøÓïÑÔģʽºÍWDAC¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË6.1.5֮ǰµÄËùÓÐPowerShell Core 6.0¡¢6.1°æ±¾ºÍ6.2.2֮ǰµÄPowerShell Core 6.2°æ±¾£¬£¬£¬½¨ÒéÓû§¾¡¿ì¸üС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/microsoft/microsoft-patches-powershell-core-security-bug-to-fix-wdac-bypass/


5¡¢LenovoEMC/Iomega NAS±»ÆØ±£´æÐÅϢй¶Îó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±ÖÒÑԳƣ¬£¬£¬LenovoEMC/IomegaÆ·ÅÆµÄNAS×°±¸Öб£´æÐÅϢй¶Îó²î£¬£¬£¬µ¼Ö´ó×ÚÃô¸ÐÊý¾ÝÔÚ¹«ÍøÉÏ̻¶¡£¡£¡£¡£¡£¡£LenovoEMCºÍIomegaµÄNAS²úÆ·Ö÷ÒªÃæÁÙÖÐСÐÍÆóÒµ¡£¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-6160£©Ô´ÓÚδÊܱ£»£»£»£»£»£»¤µÄAPIŲÓ㬣¬£¬ÈκÎÈ˶¼¿ÉÒÔͨ¹ýShodan²éÕÒÒ×Êܹ¥»÷µÄNAS×°±¸£¬£¬£¬È»ºóͨ¹ý·¢ËͶñÒâÇëÇóÏÂÔØÉè±¹ØÁ¬ÄÎļþ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚshodanÉÏ·¢Ã÷ÁË̻¶ÔÚ¹«ÍøµÄ36TBÊý¾Ý£¬£¬£¬Éæ¼°5114¸ö×°±¸¡£¡£¡£¡£¡£¡£¸ÃÎó²îÏÖÔÚ»¹Ã»ÓÐÐû²¼ÏêϸµÄÐÞ¸´Ê±¼ä¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.helpnetsecurity.com/2019/07/17/lenovoemc-nas-devices-flaw/


6¡¢Drupal CMSÐÞ¸´¿Éµ¼ÖÂÍøÕ¾±»½ÓÊܵÄÑÏÖØÎó²î


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Drupal CMS¿ª·¢ÍŶÓÐû²¼8.7.5°æ±¾£¬£¬£¬ÐÞ¸´»á¼ûÈÆ¹ýÎó²î£¨CVE-2019-6342£©¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËDrupal 8.7.4 ¡¢8.7.3¼°¸üÔç°æ±¾¡¢8.6.x¼°¸üÔç°æ±¾£¬£¬£¬¶øDrupal 7.x²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¸ÃÎó²îÉÐÎÞ¿ÉÓõÄexp£¬£¬£¬ÃÀ¹úCISAÒ²·¢³öÖÒÑÔ£¬£¬£¬±Þ²ßDrupalÖÎÀíÔ±ºÍÓû§Éý¼¶µ½Drupal 8.7.5°æ±¾¡£¡£¡£¡£¡£¡£Æ¾Ö¤Drupal CoreʹÓÃÇéÐÎͳ¼ÆÊý¾Ý£¬£¬£¬¹²ÓÐÔ¼29Íò¸öÍøÕ¾ÕýÔÚʹÓÃDrupal 8.x¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/drupal-patches-critical-bug-that-lets-hackers-take-over-sites/