ʨ×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶£»£»£»£»£»£»£»£»×êÑÐÈËÔ±ÔÚ13¿î·ÓÉÆ÷ºÍNASÉ豸Öз¢ÏÖ125¸ö·ì϶
°ä²¼¹¦·ò 2019-09-181.×êÑÐÈËÔ±ÔÚ13¿î·ÓÉÆ÷ºÍNASÉ豸Öз¢ÏÖ125¸ö·ì϶
×êÑÐÈËÔ±ÔÚ13¿îSOHO·ÓÉÆ÷ºÍNASÉ豸Öз¢ÏÖ125¸öзì϶£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×êÑÐÊÇSOHOpelessly Broken 2.0ÏîÖ÷ÕÅÒ»²¿ÃÅ¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢Ïֵķì϶Çåµ¥Ô̺¬ÊÚÈ¨ÈÆ¹ý¡¢Éí·ÝÑéÖ¤ÈÆ¹ý¡¢»º³åÇøÒç³ö¡¢ºÅÁî×¢Èë¡¢SQL×¢È루SQLi£©¡¢XSS¡¢CSRFºÍõè¾¶±éÀú·ì϶¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÆ·ÅÆÔ̺¬Buffalo¡¢ÈºêÍ¡¢TerraMaster¡¢Zyxel¡¢Drobo¡¢»ªË¶¼°Æä×ÓÆ·ÅÆAsustor¡¢Ï£½Ý¡¢QNAP¡¢åÚÏë¡¢Íø¼þ¡¢Ó×Ã׺ÍZioncom£¨TOTOLINK£©¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÏòÊÜÓ°ÏìµÄ¹©¸øÉÌÅû¶ÁËÕâЩ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬´óÎÞÊý¹©¸øÉÌѸËÙ»ØÓ¦²¢½¨¸´ÁË·ì϶£¬£¬£¬£¬£¬£¬£¬£¬µ«Drobo¡¢BuffaloºÍZioncomÉÐδ½øÐлØÓ¦¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/hacking-soho-routers.html
2.3S-Smart½¨¸´CODESYS¹¤Òµ²úÆ·ÖеĶà¸ö·ì϶
ÃÀ¹úCISA°ä²¼Á˹ØÓڵ¹ú3S-Smart³§ÉÌÔì×÷µÄCODESYS¹¤Òµ²úÆ·Öжà¸ö·ì϶µÄ°²È«Õ÷ѯ£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖкܶà·ì϶¿É±»ÓÃÓÚÌáÒéÔ¶³Ì´úÂëÖ´ÐÓ×¢DoS¹¥»÷µÈ¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÈí¼þ±»ºÜ¶àµÚÈý·½¹©¸øÉÌÓÃÓÚÊý°ÙÖÖ¹¤Òµ²úÆ·ÖС£¡£¡£¡£¡£¡£·ì϶Ô̺¬CODESYS ENI·þÎñÆ÷ÖеĻº³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿É±»µÍ¼¼ÊõˮƽµÄ¹¥»÷ÕßÔ¶³ÌÀûÓÃÒÔÌáÒé´úÂëÖ´ÐлòDoS¹¥»÷£»£»£»£»£»£»£»£»CODESYS V3×Ô¶¯»¯Æ½Ì¨µÄÍø¹Ø×é¼þÖеÄDoS·ì϶£»£»£»£»£»£»£»£»Web·þÎñÆ÷×é¼þÖеĿÉÓÃÓÚ½Ó¼ûÎļþ¡¢´¥·¢·þÎñÆ÷±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂëµÄ·ì϶µÈ¡£¡£¡£¡£¡£¡£3S-Smart°µÊ¾ÉÐδ·¢ÏÖÈκÎÕë¶ÔÕâЩ·ì϶µÄ¹«¿ªÀûÓ㬣¬£¬£¬£¬£¬£¬£¬µ«ÖÁÉÙÓÐÒ»¸ö°²È«·ì϶ÓÐ×ã¹»µÄ¹«¿ªÐÅÏ¢¿ÉÓÃÓÚ¿ª·¢·ì϶ÀûÓᣡ£¡£¡£¡£¡£ËùÓзì϶¶¼ÒÑͨ¹ýÈí¼þ¸üнøÐн¨¸´£¬£¬£¬£¬£¬£¬£¬£¬Ö»ÓÐÒ»¸ö·ì϶Ԥ¼Æ½«ÔÚ2020Äê2Ô¸üн¨¸´¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/serious-flaws-codesys-products-expose-industrial-systems-remote-attacks
3.ʨ×Óº½¿Õ¹«Ë¾ÊýǧÍòÓû§¼Í¼ÔÚ°µÍøÐ¹Â¶
ʨ×Óº½¿ÕÆìÏÂÁ½¼Òº½¿Õ¹«Ë¾µÄÊýǧÍòÌõ´î¿Í¼Í¼ÔÚ°µÍøÂÛ̳ÉÏй¶¡£¡£¡£¡£¡£¡£ÕâЩÊý¾Ý´æ´¢Ôڿɹ«¿ª½Ó¼ûµÄAmazon´æ´¢Í°ÖУ¬£¬£¬£¬£¬£¬£¬£¬¹²ÓÐÁ½¸öÊý¾Ý¿â£¬£¬£¬£¬£¬£¬£¬£¬Ò»¸öÔ̺¬2100Íò±Ê¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬ÁíÒ»¸öÔ̺¬1400Íò±Ê¼Í¼£¬£¬£¬£¬£¬£¬£¬£¬¸ÃĿ¼Ï»¹Ô̺¬2019Äê5Ô·ݴ´½¨µÄ±¸·ÝÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÊôÓÚMalindo AirºÍThai Lion Air¡£¡£¡£¡£¡£¡£ÁíÒ»¸ö±¸·ÝÎļþµÄÃû³ÆÊÇBatik Air£¬£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾µÄĸ¹«Ë¾Ò²ÊÇʨ×Óº½¿Õ¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬´î¿ÍµÄÔ¤Ô¼ID¡¢¾ÓסµØÖ·¡¢µç»°ºÅÂë¡¢ÓÊÏ䵨ַ¡¢ÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢»¤ÕÕºÅÂëºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£¡£¡£¡£Ä¿Ç°»¹²»Ã÷ÏÔÕâЩÊý¾Ý³õ´Îй¶µÄ¹¦·ò£¬£¬£¬£¬£¬£¬£¬£¬µ«¾Ý³ÆÖÁÉÙ´Ó8ÔÂ10ÈÕÆð¸ÃÊý¾Ý¿âÒÑÔÚÂÛ̳ÉÏÁ÷ͨ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-lion-air-passenger-records-exposed-and-exchanged-on-forums/
4.ÊýǧÃûÓû§µÄ¹È¸èÈÕÀúÒòÅäÖÃÃýÎó¶³öÃô¸ÐÐÅÏ¢
Ó¡¶È°²È«×êÑÐÔ±Avinash Jain·¢ÏÖÊýÒÔǧ¼ÆµÄ¹È¸èÓû§Òâ±í¹«¿ªÁËÆä¹È¸èÈÕÀú£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÃýÎóÅäÖõĹȸèÈÕÀúµ¼Öµģ¬£¬£¬£¬£¬£¬£¬£¬¿É¹«¿ª½Ó¼ûÒâζ×Å¿Éͨ¹ý¹«¹²ÒýÇæ½øÐÐËÑË÷£¨Ô̺¬¹È¸è£©£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÈκÎÈ˽ӼûÆäÖеÄÒþÖÔ»òÊÇʹÓöñÒâÐÅÏ¢»òÁ´½ÓÔö³¤ÐÂÊÂÎñ¡£¡£¡£¡£¡£¡£Jain·¢ÏÖÓг¬¹ý8000¸ö¹È¸èÈÕÀú¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ200¶à¸ö¶³öÁË´óÁ¿ÒþÖÔÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçµç×ÓÓʼþID¡¢»î¶¯Ãû³Æ¡¢»î¶¯ÏêÇé¡¢µØÎ»¡¢zoom»áÒéÁ´½Ó¡¢ÄÚ²¿ÑÝʾÁ´½ÓµÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/09/google-calendar-search.html
5.×êÑÐÈËÔ±·¢ÏÖ2430Íò»¼ÕßµÄÒ½ÁÆÓ°ÏñÐÅÏ¢ÔÚÍøÉ϶³ö
Greenbone Networks×êÑÐÈËÔ±·¢ÏÖÊýǧÍò»¼ÕßµÄXÉäÏß¡¢CTºÍMRIɨÃèͼÏñÔÚÈ«ÇòÒ½ÁÆ·þÎñ»ú¹¹µÄÊý°Ų̀·þÎñÆ÷É϶³ö¡£¡£¡£¡£¡£¡£Æ¾¾Ý¸ÃÍŶÓÔÚ´ÓǰÁ½¸öÔµÄ×êÑУ¬£¬£¬£¬£¬£¬£¬£¬È«Çò2300¸öÒ½ÁÆÓ°Ïñ´æµµÏµÍ³ÖÐÓÐ590¸ö¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬52¸ö·ÖÆç¹ú¶ÈµÄ2430ÍòÃû»¼Õ߼ͼ¡£¡£¡£¡£¡£¡£Â¶³öµÄÐÅÏ¢Ô̺¬»¼ÕßµÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢²é³ÈÕÆÚ¡¢Ö÷ÖÎÒ½ÉúÒÔ¼°Óйزé³Ö÷ÕŵÄһЩҽÁÆÐÅÏ¢¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬1370Íò±Ê¼Í¼ÖÐÔ̺¬ÃÀ¹ú»¼ÕßµÄÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»¼Õ߼ͼÖйØÁªµÄÒ½ÁÆÓ°Ïñ³¬¹ý7.37ÒÚ¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¼4ÒÚ¸ö¿Éͨ¹ý»¥ÁªÍøÏÂÔØ¡£¡£¡£¡£¡£¡£ÔÚijЩÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬£¬·þÎñÆ÷ÉõÖÁÔÊÐíͨ¹ýδ¼ÓÃܵÄHTTPÏνÓÏÂÔØ»¼ÕßÊý¾Ý¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.grahamcluley.com/medical-images-and-details-of-24-3-million-patients-left-exposed-on-the-internet/
6.¶ñÒâÈí¼þGootkitÒòÅäÖÃÃýÎóµ¼ÖÂÊý¾Ý¿âÔÚÍøÉ϶³ö
¶ñÒâÈí¼þGootkit±³ºóµÄ·¸×ïÍÅ»ïÒâ±í½«MongoDBÊý¾Ý¿âÏνӵ½»¥ÁªÍø¶øÃ»ÓÐÉèÖÃÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃ°²È«×êÑÐÔ±Bob Diachenko¿ÉÄÜÏÂÔØÕâЩÊý¾ÝºÍÉî¿Ì·ÖÎöÆä¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£GootkitµÄÖØÒªÖ°ÄÜÊÇ´Óä¯ÀÀÆ÷ÇÔÈ¡Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬º¹Çàä¯ÀÀ¼Í¼¡¢ÃÜÂë¡¢cookieÎļþ¡¢ÐÅÓþ¿¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬£¬ËüÖ§³Ö¶àÖÖÖ÷Á÷ä¯ÀÀÆ÷¡£¡£¡£¡£¡£¡£7Ô·ݸöñÒâÈí¼þµÄÁ½¸öC2·þÎñÆ÷¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬²¢³ÖÐøÁËÒ»ÖܵŦ·ò£¬£¬£¬£¬£¬£¬£¬£¬Ä¿Ç°»¹²»Ã÷ÏÔÊǸÃÍŻ。ÍüÉèÖÃÃÜÂ뻹ÊÇ·þÎñÆ÷·À»ðǽ³öÏÖ¹ÊÕÏ¡£¡£¡£¡£¡£¡£ÕâÁ½Ì¨·þÎñÆ÷¶¼ÔËÐÐMongoDB£¬£¬£¬£¬£¬£¬£¬£¬ÆäÄÚÈÝËÆºõ¾ÛºÏÁËÈý¸öGootkit×Ó½©Ê¬ÍøÂçµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬º¸Ç×ܹ²38653¸öÊÜϰȾµÄÖ÷»ú¡£¡£¡£¡£¡£¡£Êý¾Ý¿âÖÐÔ̺¬¸Ã¶ñÒâÈí¼þÇÔÈ¡µÄÐÅÓþ¿¨ÐÅÏ¢¡¢Óû§ÃûºÍÍ´´¦¡¢ÊÜϰȾÖ÷»úµÄÅäÖÃÎļþ¡¢cookieÎļþ¡¢Óû§ÆÁÄ»½ØÍ¼µÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/gootkit-malware-crew-left-their-database-exposed-online-without-a-password/


¾©¹«Íø°²±¸11010802024551ºÅ