ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ51ÖÜ
°ä²¼¹¦·ò 2018-12-24
2018Äê12ÔÂ17ÈÕ23ÈÕ¹²ÊÕ¼°²È«·ì϶49¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇWordPress two-factor-authentication²å¼þ¿çÕ¾ÒªÇóαÔì·ì϶£»£»£»£»£»£»£»£»ABB GATE-E1ºÍGATE-E2ÑéÖ¤ÈÆ¹ý·ì϶£»£»£»£»£»£»£»£»Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»DedeCMS uploads/include/dialog/select_images_post.phpËÁÒâ´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç¶Âí½Å¡£¡£¡£¡£¡£¡£¡£
³ÁÒª°²È«·ì϶Áбí
1. WordPress two-factor-authentication²å¼þ¿çÕ¾ÒªÇóαÔì·ì϶
WordPress two-factor-authentication²å¼þ´æÔÚ¿çÕ¾ÒªÇóαÔì·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶¹¹½¨¶ñÒâURI£¬£¬£¬£¬£¬ÓÕʹҪÇ󣬣¬£¬£¬£¬Äܹ»Ö¸±êÓû§¸ßµÍÎÄÖ´ÐжñÒâ²Ù×÷¡£¡£¡£¡£¡£¡£¡£
https://wordpress.org/plugins/two-factor-authentication/#developers2. ABB GATE-E1ºÍGATE-E2ÑéÖ¤ÈÆ¹ý·ì϶
ABB GATE-E1ºÍGATE-E2ÔÚÖÎÀítelnet»òweb½Ó¿ÚÖдæÔÚÑéÖ¤ÅäÖ÷ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿É³ÁÖÃÉ豸¡¢¶ÁÈ¡»òÅú¸Ä×¢²á±í¡¢Åú¸ÄIPµØÖ·µÈ¡£¡£¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-013. Advantech WebAccess/SCADA CVE-2018-18999»º³åÇøÒç¶Âí½Å
Advantech WebAccess/SCADA´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-024. DedeCMS uploads/include/dialog/select_images_post.phpËÁÒâ´úÂëÖ´Ðзì϶
DedeCMS uploads/include/dialog/select_images_post.php´æÔÚÊäÈëÑéÖ¤ ·ì϶£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄË«³ÁÀ©´ó¼°Åú¸ÄµÄ.php×Ó×Ö·û´®ÒªÇ󣬣¬£¬£¬£¬¿ÉÉÏ´«ËÁÒâÎļþ²¢Ö´ÐÓ×£¡£¡£¡£¡£¡£¡£
http://www.iwantacve.cn/index.php/archives/88/5. TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi»º³åÇøÒç¶Âí½Å
TRENDnet TEW-632BRPºÍTEW-673GRU apply.cgi´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£
http://packetstormsecurity.com/files/150693/TRENDnet-Command-Injection-Buffer-Overflow-Cross-Site-Scripting.html³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢ÃÀDoD³ÆÆäµ¯Â·µ¼µ¯·ÀÓùϵͳδͨ¹ýÍøÂ簲ȫÉó¼Æ
ƾ¾ÝÃÀ¹ú¹ú·À²¿¼à²ì³¤µÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬ÃÀ¹úµÄµ¯Â·µ¼µ¯·ÀÓùϵͳ£¨BMDS£©Î´ÄÜͨ¹ýÍøÂ簲ȫÉ󼯡£¡£¡£¡£¡£¡£¡£¸Ã»ã±¨Ö¸³öBMDSÉèʩδÄÜÖ´ÐÐÓ¦Óеݲȫ½ÚÔì´ëÊ©£¬£¬£¬£¬£¬Ô̺¬¶à³É·ÖÉí·ÝÈÏÖ¤¡¢·ì϶ÆÀ¹À»ººÍ½â¡¢·þÎñÆ÷»ú¼Ü°²È«¡¢¿ÉÒÆ¶¯Ã½ÌåÉϵĻúÃÜÊý¾Ý±£»£»£»£»£»£»£»£»¤ºÍ¼¼ÊõÐÅÏ¢¼ÓÃÜ´«ÊäµÈ¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬Ò»Ð©ÎïÀí°²È«´ëʩҲûÓе½Î»£¬£¬£¬£¬£¬ÀýÈçÉãÏñÍ·ºÍ´«¸ÐÆ÷²¢Ã»ÓÐ×°ÖÃÔÚ±ØÒª×°ÖõĵØÎ»¡£¡£¡£¡£¡£¡£¡£¼à²ì³¤°ì¹«ÊÒÔÚÒªÇóÊ×ϯÐÅÏ¢¹Ù¡¢Ö¸»Ó¹ÙµÈÔÚ2019Äê1ÔÂ8ÈÕǰ»ØÓ¦¸Ã·Ý»ã±¨¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://media.defense.gov/2018/Dec/14/2002072642/-1/-1/1/DODIG-2019-034.PDF
2¡¢Å·ÖÞÒé»áºÍÀíÊ»á°ä²¼¡¶Å·Ã˵ç×ÓͨѶ¹æ·¶£¨EECC£©¡·
Å·ÖÞÒé»áºÍÀíÊ»á°ä²¼¡¶Å·Ã˵ç×ÓͨѶ¹æ·¶£¨EECC£©¡·£¬£¬£¬£¬£¬¸Ã¹æ·¶ÊǶÔ2009Äê°ä²¼µÄÏÖÓеç×ÓͨѶÁ¢·¨¿ò¼ÜµÄ³Áж©Õý¡£¡£¡£¡£¡£¡£¡£Å·Ã˳ÉÔ±¹ú½«ÓÐÁ½ÄêµÄ¹¦·ò½«¸Ã¹æ·¶µÄÓйØÌõ¿îת»»Îª±¾¹úµÄ˾·¨¡¢ÂÉÀýºÍÐÐÕþ»®¶¨£¬£¬£¬£¬£¬ÕâÒ»×îºóÆÚÏÞÊÇ2020Äê12Ô¡£¡£¡£¡£¡£¡£¡£¸Ã¹æ·¶µÄÕûÌåÖ¸±êÊÇ¡°Ê¹Å·ÃËÔÚ2025ÄêÕ¾ÔÚ»¥ÁªÍøÏνӵÄ×îÇ°ÑØ-´´½¨Ò»¸öǧÕ×Éç»á¡±¡£¡£¡£¡£¡£¡£¡£¸Ã¹æ·¶»¹Ô̺¬¶Ô°²È«µÄ»®¶¨Ìõ¿î£ºµç×ÓÍ¨Ñ¶ÍøÂç·þÎñÉ̱ØÒª²ÉÈ¡ÏàÓ¦µÄ¼¼ÊõºÍ»úÔ죬£¬£¬£¬£¬ÒÔ×î´óÏ޶ȵØÏ÷¼õ°²È«ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018L1972
3¡¢Elasticsearch Kibana½ÚÔį̀ÎļþÔ̺¬·ì϶£¬£¬£¬£¬£¬PoC´úÂëÒѰ䲼
KibanaÊÇElasticsearchµÄÊý¾Ý¿ÉÊÓ»¯¹¤¾ß£¬£¬£¬£¬£¬ÆäConsole²å¼þ´æÔÚ±¾µØÎļþÔ̺¬£¨LFI£©·ì϶£¬£¬£¬£¬£¬×êÑÐÈËÔ±°ä²¼Á˸÷ì϶µÄPoC´úÂë¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2018-17246£©Ó°ÏìÁË6.4.3ºÍ5.6.13֮ǰµÄKibana°æ±¾£¬£¬£¬£¬£¬³É¹¦ÀûÓø÷ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£ElasticÒÑÔÚ×îа汾µÄKibanaÖн¨¸´Á˸÷ì϶£¬£¬£¬£¬£¬ÈôÊÇÓû§ÁÙʱÎÞ·¨¸üУ¬£¬£¬£¬£¬Ò²Äܹ»ÔÚÅäÖÃÎļþÖнûÓøÃConsole²å¼þÀ´¶ã±ÜÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/file-inclusion-bug-in-kibana-console-for-elasticsearch-gets-exploit-code/
4¡¢NASAÅû¶Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬²¿ÃÅÔ±¹¤µÄPIIÐÅÏ¢±»µÁ
NASA±»ºÚ£¬£¬£¬£¬£¬Æ¾¾Ý¸Ã»ú¹¹µÄ˵·¨£¬£¬£¬£¬£¬NASAÔÚ10ÔÂ23ÈÕ·¢ÏÖÁËÕâÒ»Êý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬ÆäÒ»¸ö´æ´¢Ó×ÎÒÉí·ÝÐÅÏ¢£¨PII£©µÄ·þÎñÆ÷Ôâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬2006Äê7ÔÂÖÁ2018Äê10ÔÂÆÚ¼ä²ÎÓëNASAµÄÔ±¹¤µÄPIIÐÅϢй¶£¬£¬£¬£¬£¬Ô̺¬È¥Ö°»òµ÷Ö°µÄÔ±¹¤¡£¡£¡£¡£¡£¡£¡£NASAĿǰռÓÐÔ¼17300ÃûÔ±¹¤¡£¡£¡£¡£¡£¡£¡£¸Ã»ú¹¹°µÊ¾Ã»ÓÐÌ«¿Õ¹¤×÷Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/nasa-hack-data-breach.html
5¡¢SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δ½¨¸´µÄWindows 0day
×êÑÐÈËÔ±SandboxEscaperµÚÈý´ÎÔÚTwitterÉÏÅû¶δ½¨¸´µÄWindows 0day£¬£¬£¬£¬£¬²¢ÇÒ°ä²¼ÁËÓйØPoC¡£¡£¡£¡£¡£¡£¡£Õâ¸öеķì϶´æÔÚÓÚWindowsµÄMsiAdvertiseProductÖ°ÄÜÖУ¬£¬£¬£¬£¬Æ¾¾Ý¸Ã×êÑÐÈËÔ±µÄ˵·¨£¬£¬£¬£¬£¬ÓÉÓÚûÓÐÕýÈ·ÑéÖ¤£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓøÃÖ°ÄÜвÆÈ×°Ö÷þÎñÒÔSYSTEMȨÏÞ¸´ÔìËÁÒâÎļþ²¢¶ÁÈ¡ÆäÄÚÈÝ£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¡£¡£¡£¡£¡£¡£SandboxEscaper»¹ÔÚGithubÉϰ䲼Á˸÷ì϶µÄPoC£¬£¬£¬£¬£¬µ«¸ÃGithubÕË»§Ä¿Ç°Òѱ»É¾³ý¡£¡£¡£¡£¡£¡£¡£SandboxEscaperÔøÔÚ2018Äê8Ô·ݺÍ10Ô·ݱðÀëÔÚTwitterÉÏÅû¶ÁËÁ½¸öWindows 0day¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/12/windows-zero-day-exploit.html
ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ