Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÏÖÒѱ»½¨¸´£»£» £»£»£»£» £»wolfSSLÖдæÔÚ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂMiTM¹¥»÷

°ä²¼¹¦·ò 2020-09-03

1.Cisco Jabber´æÔÚÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÏÖÒѱ»½¨¸´


1.jpg


WatchcomµÄOlav Sortland Thoresen·¢ÏÖWindows°æCisco JabberÖдæÔÚÑϳÁµÄ´úÂëÖ´Ðзì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÏÖÒѱ»½¨¸´¡£¡£¡£¡£¡£¸Ã·ì϶±»¸ú×ÙΪCVE-2020-3495£¬£¬£¬ £¬£¬£¬£¬£¬ CVSSΪ9.9·Ö£¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÓÚ´«ÈëÐÂÎÅÄÚÈݵÄÊäÈëÑéÖ¤²»ÕýÈ·ÒýÆðµÄ¡£¡£¡£¡£¡£¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»Ê¹ÓöñÒâµÄ¿ÉÀ©´óÐÂÎźÍ״̬ºÍ̸£¨XMPP£©ÐÂÎÅÀûÓø÷ì϶£¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓú󹥻÷Õß¿ÉÔÚÖ¸±êϵͳÉÏÖ´ÐÐËÁÒⷨʽ¡£¡£¡£¡£¡£Ë¼¿Æ²úÆ·°²È«ÊÂÎñÏìÓ¦Ó××飨PSIRT£©°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ĿǰÉÐδ±»¿í·ºÀûÓᣡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/cisco-fixes-critical-code-execution-bug-in-jabber-for-windows/


2.×êÑÐÈËÔ±·¢ÏÖwolfSSLÖдæÔÚ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂMiTM¹¥»÷


2.png


×êÑÐÈËÔ±G¨¦raldDoussotÓÚ2020Äê7Ô·¢ÏÖwolfSSLÖдæÔÚ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂMiTM¹¥»÷¡£¡£¡£¡£¡£¸Ã·ì϶±»×·×ÙΪCVE-2020-24613£¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÓÉÓÚTLS 1.3¿Í»§¶Ë״̬»úµÄÃýÎóʵÏÖ¶øµ¼ÖµÄ¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶À¹½Ø¿Í»§¶Ëͨ¹ýTLS 1.3Óë·þÎñÆ÷µÄÁªÏµ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÔÚTLSÎÕÊÖ½×¶ÎʹÓÃÎÞЧµÄ°ü½øÐÐÏìÓ¦¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß»¹Äܹ»Ä£ÄâÖ¸±ê·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬ÌáÒéÖÐÑëÈË£¨MiTM£©¹¥»÷¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬ £¬£¬£¬£¬£¬¹©¸øÉÌÒѰ䲼Õë¶Ô¸Ã·ì϶µÄ²¹¶¡·¨Ê½¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://latesthackingnews.com/2020/09/01/vulnerability-in-wolfssl-could-allow-mitm-attacks-patch-available/


3.MagentoµÄ²å¼þMagmi´æÔÚCSRFºÍÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶


3.png

µç×ÓÉÌÎñÍøÕ¾MagentoµÄµÚÈý·½²å¼þMagmi´æÔÚÁ½¸öÑϳÁµÄ·ì϶¡£¡£¡£¡£¡£µÚÒ»¸öΪ¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¨CVE-2020-5776£©Ó°ÏìÁËMagmi°æ±¾0.7.24£¬£¬£¬ £¬£¬£¬£¬£¬CVSSv2ÆÀ·ÖΪ6.8£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÓÉÓÚMagmiµÄGETºÍPOST¶ËµãδʵÏÖCSRF±£»£» £»£»£»£» £»¤¶øµ¼Öµģ¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓú󹥻÷Õ߿ɽٳÖÖÎÀíÔ±µÄ»á»°£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÔÚÍйÜMagmiµÄ·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£µÚ¶þ¸öÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2020-5777£©Ó°ÏìÁËMagento°æ±¾0.7.23¼°¸üµÍ°æ±¾£¬£¬£¬ £¬£¬£¬£¬£¬CVSSv2ÆÀ·ÖΪ6.8£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÊý¾Ý¿â»Ø¾ø·þÎñ(DB-DoS)¹¥»÷µ¼ÖÂÊý¾Ý¿âÏνÓʧ°Ü£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÔÚ·þÎñÆ÷ÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/magento-sites-vulnerable-to-rce-stemming-from-magmi-plugin-flaws/158864/


4.×êÑÐÈËÔ±·¢ÏÖºÚ¿Í¿Éͨ¹ý¸öÈ˵籨Ƶ·ÇÔÊØÐÅÓþ¿¨ÐÅÏ¢


4.png


×êÑÐÈËÔ±Affable Krautͨ¹ý¶ÈÎöºÚ¿ÍʹÓõĶñÒâJavaScript£¬£¬£¬ £¬£¬£¬£¬£¬·¢ÏÖºÚ¿Í¿Éͨ¹ý¸öÈ˵籨Ƶ·ÇÔÊØÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£¸Ã¾ç±¾ÏÈ´ÓËùÓÐÀàÐ͵ÄÊäÈë×Ö¶ÎÍøÂçÊý¾Ý²¢½«Æä·¢Ë͵½TelegramƵ·£¬£¬£¬ £¬£¬£¬£¬£¬ËùÓÐÐÅÏ¢¾ù»áʹÓù«¹²ÃÜÔ¿¼ÓÃÜ¡£¡£¡£¡£¡£¶øºó£¬£¬£¬ £¬£¬£¬£¬£¬Telegram»úеÈ˽«±»µÁÊý¾Ý×÷ΪÐÂÎŰ䲼ÔÚ̸ÌìÖС£¡£¡£¡£¡£´ÓÇ°Ò²ÔøÓкڿÍʹÓõ籨ÇÔÈ¡±»µÁÊý¾Ý£¬£¬£¬ £¬£¬£¬£¬£¬Õ°²©ÍøÂçÔÚÈ¥Äê·¢ÏÖÓкڿÍʹÓÃ̸ÌìÆ½Ì¨µÄÐÅÏ¢ÇÔÈ¡Æ÷Masad ClipperºÍStealer¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/credit-card-data-smuggled-via-private-telegram-channel/


5.Ó¢¹úµ±¾ÖÖÎÀíµÄ450¶à¸öÓòÃû±»·ÅÈëDNSµÄºÚÃûµ¥ÖÐ


5.png


GitHubÓû§tg12·¢ÏÖ£¬£¬£¬ £¬£¬£¬£¬£¬Ó¢¹úµ±¾ÖÖÎÀíµÄ450¶à¸öGOV.UKÓòÃû±»·ÅÈëÁËDNSµÄºÚÃûµ¥ÖУ¬£¬£¬ £¬£¬£¬£¬£¬Õâ¿ÉÔì³Éµç×ÓÓʼþͨѶÎÊÌâ¡£¡£¡£¡£¡£¶à¸öµ±¾Ö»ú¹¹¡¢ÀíÊ»áºÍ¹«Òæ»ú¹¹¶¼ÒÀÀµGOV.UKÓòÃûΪӢ¹ú¾ÓÃñÌṩÔÚÏß·þÎñ¡£¡£¡£¡£¡£Í¨³£Çé¿öÏ£¬£¬£¬ £¬£¬£¬£¬£¬ÊÕ¼þÈ˵ÄÓʼþÌṩÉÌ¿ÉÄÜ»á²éÕÒÓòÃûϵͳµÄºÚÃûµ¥ÁÐ±í£¨DNSBL£©£¬£¬£¬ £¬£¬£¬£¬£¬²¢½«ÇкÏÁбíµÄÓʼþÒÆ¶¯µ½À¬»øÓʼþÎļþ¼ÐÖС£¡£¡£¡£¡£Òò¶ø£¬£¬£¬ £¬£¬£¬£¬£¬ÕâÖÖÇé¿ö²»½ö»áÓ°Ïì×éÖ¯µÄÃûÓþ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒ»¹»áµ¼ÖºϷ¨µÄµç×ÓÓʼþ´«µÝ³öÏÖÎÊÌâ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/over-400-govuk-domains-found-on-spam-blacklists/


6.CISA½áºÏ¶à¸ö»ú¹¹°ä²¼¹ØÓÚ·¢ÏֺͲ¹¾È¶ñÒâ¹¥»÷»î¶¯µÄ½¨Òé


6.png

ÍøÂ簲ȫºÍ»ù´¡¼Ü¹¹°²È«¾Ö£¨CISA£©Óë°Ä´óÀûÑÇ¡¢¼ÓÄôó¡¢ÐÂÎ÷À¼ºÍÓ¢¹úµÄÍøÂ簲ȫ»ú¹¹ºÏ×÷°ä²¼ÁËÒ»·Ý½áºÏÍøÂ簲ȫÕ÷ѯ¡£¡£¡£¡£¡£¸Ã´«µÝ³Áµã½éÉÜÁË·¢ÏÖ¶ñÒâ»î¶¯µÄ¼¼Êõ²½Ö裬£¬£¬ £¬£¬£¬£¬£¬Ô̺¬¼ÓÇ¿ºÏ×÷ͬ°éºÍÍøÂçÖÎÀíÔ±Ö®¼äÊÂÎñÏìÓ¦µÄ²½Öè¡£¡£¡£¡£¡£¸Ã»ã±¨µÄÖ÷ÕÅÊǼÓÇ¿ºÏ×÷ͬ°éºÍÍøÂçÖÎÀíÔ±Ö®¼äµÄÊÂÎñÏìÓ¦ÄÜÁ¦£¬£¬£¬ £¬£¬£¬£¬£¬²¢³äÈÎÊÂÎñµ÷²éÊֲᡣ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/alerts/aa20-245a