ÐÅÏ¢°²È«Öܱ¨-2019ÄêµÚ16ÖÜ

°ä²¼¹¦·ò 2019-04-22

±¾Öܰ²È«Ì¬ÊÆ×ÛÊö



2019Äê4ÔÂ15ÈÕÖÁ21ÈÕ±¾ÖÜ

¹²ÊÕ¼°²È«·ì϶46¸ö£¬£¬£¬ £¬£¬ÖµµÃ¹Ø×¢µÄÊÇAtlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú·ì϶£»£»£»£»£»£»£» £»Sangfor Sundray WLAN ControllerȨÏÞÌáÉý·ì϶; GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý·ì϶£»£»£»£»£»£»£» £»Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£» £»Cloud Foundry Cloud Controller APIÑéÖ¤·ì϶¡£¡£¡£¡£ ¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ΢ÈíÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬²¿ÃÅÓû§µÄOutLookÕÊ»§ÐÅϢй¶£»£»£»£»£»£»£» £»GnosticplayersÏúÊÛµÚÎåÅúÓû§Êý¾Ý£¬£¬£¬ £¬£¬Ô̺¬6500¶àÍò¸öÕ˺ţ»£»£»£»£»£»£» £»³¬´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬ £¬£¬½Ù³Ö5ÒÚiOSÓû§»á»°£»£»£»£»£»£»£» £»JustDial APIй¶³¬¹ý1ÒÚÓ¡¶Å×û§µÄÓ×ÎÒÐÅÏ¢£»£»£»£»£»£»£» £»FacebookÐÂÊý¾Ý³óÎÅ£¬£¬£¬ £¬£¬Î´¾­Óû§Ðí¿ÉÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË¡£¡£¡£¡£ ¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£ ¡£



³ÁÒª°²È«·ì϶Áбí



1. Atlassian Confluence ServerºÍAtlassian Data CenterĿ¼±éÀú©
Atlassian Confluence ServerºÍAtlassian Data Center downloadallattachments×ÊÔ´´æÔÚõè¾¶±éÀú·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬Äܹ»ÀûÓ÷¨Ê½¸ßµÍÎIJ鿴ϵͳÎļþÄÚÈÝ¡£¡£¡£¡£ ¡£
https://jira.atlassian.com/browse/CONFSERVER-58102

2. Sangfor Sundray WLAN ControllerȨÏÞÌáÉý·ì϶
Sundray WLAN Controller nginx_webconsole.php´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿É¶ÁÈ¡adminÃÜÂ룬£¬£¬ £¬£¬»ñȡȨÏÞ¡£¡£¡£¡£ ¡£
https://nvd.nist.gov/vuln/detail/CVE-2019-9161

3. GitLab CVE-2019-9485Óû§È¨ÏÞÌáÉý·ì϶
GitLab impersonate userÖ°ÄÜ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬ÌáÉýÓû§È¨ÏÞ¡£¡£¡£¡£ ¡£
https://about.gitlab.com/2019/03/04/security-release-gitlab-11-dot-8-dot-1-released/

4. Delta Electronics Delta Industrial Automation CNCSoft CVE-2019-10949»º³åÇøÒç¶Âí½Å
Delta Electronics Delta Industrial Automation CNCSoft´æÔÚÔ½½çд·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿ÉÖ´ÐÐËÁÒâ´úÂë»ò½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£ ¡£

https://ics-cert.us-cert.gov/advisories/ICSA-19-106-01


5. Cloud Foundry Cloud Controller APIÑéÖ¤·ì϶
Cloud Foundry Cloud Controller APIÑé֤ʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬¿ÉÌáÉýȨÏÞ¡£¡£¡£¡£ ¡£
https://www.cloudfoundry.org/blog/cve-2019-3798


 ³ÁÒª°²È«ÊÂÎñ×ÛÊö



1¡¢Î¢ÈíÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬²¿ÃÅÓû§µÄOutLookÕÊ»§ÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

΢Èí֤ʵ1ÔÂ1ÈÕÖÁ3ÔÂ29ÈÕÆÚ¼ä¹¥»÷ÕßÈëÇÖÁËÒ»¸ö¿Í»§Ö§³Ö´úÀíÕË»§£¬£¬£¬ £¬£¬²¢ÀûÓøÃÕË»§½Ó¼ûÁ˿ͻ§Ö§³ÖÃÅ»§ÍøÕ¾¼°²¿ÃÅOutLookÓû§µÄÓйØÐÅÏ¢¡£¡£¡£¡£ ¡£ÕâЩÐÅÏ¢Ô̺¬µç×ÓÓʼþµØÖ·¡¢Îļþ¼ÐÃû³Æ¡¢ÓʼþÖ÷Ìâ¼°ÁªÏµÈ˵ç×ÓÓʼþµØÖ·£¬£¬£¬ £¬£¬µ«²»Ô̺¬Óʼþ¼°¸½¼þµÄÄÚÈÝ¡£¡£¡£¡£ ¡£Ä¿Ç°Éв»Ã÷ÏÔ¹¥»÷µÄ¾ßÌåϸ½Ú£¬£¬£¬ £¬£¬µ«Î¢Èí°µÊ¾ÒѾ­½ûÓÃÁ˸ôúÀíÕË»§µÄÍ´´¦£¬£¬£¬ £¬£¬²¢Í¨ÖªËùÓÐÊÜÓ°ÏìµÄÓû§¡£¡£¡£¡£ ¡£Î¢ÈíҲûÓÐй©ÊÜÓ°ÏìµÄÓû§×ÜÊý¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/microsoft-outlook-email-hack.html

2¡¢GnosticplayersÏúÊÛµÚÎåÅúÓû§Êý¾Ý£¬£¬£¬ £¬£¬Ô̺¬6500¶àÍò¸öÕ˺Å

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ºÚ¿ÍGnosticplayersÔÚ°µÍøÂÛ̳DreamMarketÉÏÏúÊÛµÚÎåÅú±»µÁµÄÓû§Êý¾Ý£¬£¬£¬ £¬£¬ÕâÅúÊý¾ÝÔ̺¬³¬¹ý6500Íò¸öÓû§ÕË»§£¬£¬£¬ £¬£¬ÊÛ¼ÛΪ0.8463±ÈÌØ±Ò£¨4350ÃÀÔª£©¡£¡£¡£¡£ ¡£ÕâÅú±»µÁµÄÓû§¼Í¼ÊôÓÚÁù¼Òй«Ë¾£¬£¬£¬ £¬£¬Ô̺¬ÓÎϷƽ̨Mindjolt£¨2800Íò£©¡¢ÔÚÏß¹ºÎïÉçÇøWanelo£¨2300Íò£©¡¢Æ»¹ûά½¨ÖÐÐÄiCracked£¨150Íò£©¡¢ÓÎÀÀ¹«Ë¾Yanolja£¨150Íò£©¡¢µç×ÓÔ¼Çë·þÎñEvite£¨1000Íò£©ºÍÅ®×ÓʱװµêModa Operandi£¨150Íò£©¡£¡£¡£¡£ ¡£Ä¿Ç°ÎªÖ¹GnosticplayersÏúÊ۵ı»µÁÓû§¼Í¼×ÜÊýÒÑ´ï9.32ÒÚÌõ¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/gnosticplayers-hacker-returns-with-fifth-dataset-containing-over-65-million-user-accounts-for-sale-95450e99

3¡¢³¬´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬ £¬£¬½Ù³Ö5ÒÚiOSÓû§»á»°


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«³§ÉÌConfiant·¢ÏÖ·¸×ïÍÅ»ïeGobblerÌáÒéÕë¶ÔiOSÓû§µÄ³¬´ó¹æÄ£¶ñÒâ¸æ°×»î¶¯£¬£¬£¬ £¬£¬ÒѽٳÖ5ÒÚiOSÓû§µÄ»á»°¡£¡£¡£¡£ ¡£¸Ã¹¥»÷»î¶¯´Ó4ÔÂ6ÈÕÆðÍ·£¬£¬£¬ £¬£¬³ÖÐøÁË6ÌìµÄ¹¦·ò£¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃÁË8¸ö·ÖÆçµÄ¶ñÒâ¸æ°×ϵÁкÍ30¶à¸öÐéα¸æ°×£¬£¬£¬ £¬£¬Ã¿¸öÐéα¸æ°×ϵÁеÄÐÔÃüÖÜÆÚΪ24-48Ó×ʱ֮¼ä¡£¡£¡£¡£ ¡£¹¥»÷ÕßÖØÒªÕë¶ÔÃÀ¹úºÍÅ·Ã˵ÄiOSÓû§£¬£¬£¬ £¬£¬²¢ÔÚ¹¥»÷ÖÐÀûÓÃÁËChromeä¯ÀÀÆ÷Öеķì϶ÒÔÈÆ¹ýɳºÐ¼ì²â¡£¡£¡£¡£ ¡£¹¥»÷ÕßʹÓÃÁË.worldÓòÃûÍйܵĴ¹µöÍøÕ¾£¬£¬£¬ £¬£¬¾­¹ý¶ÌÔݵĸédz֮ºó£¬£¬£¬ £¬£¬ÓÖתÏò.siteÓòÃûµÄ´¹µöÍøÕ¾¡£¡£¡£¡£ ¡£×Ô4ÔÂ14ÈÕÒÔÀ´£¬£¬£¬ £¬£¬ÕâЩ´¹µöÍøÕ¾Ò»Ïò´¦ÓÚ»îԾ״̬¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/malvertising-campaign-abused-chrome-to-hijack-500-million-ios-user-sessions/

4¡¢JustDial APIй¶³¬¹ý1ÒÚÓ¡¶Å×û§µÄÓ×ÎÒÐÅÏ¢

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


°²È«×êÑÐÔ±Rajshekhar Rajaharia·¢ÏÖÓ¡¶È±¾µØËÑË÷·þÎñ¹«Ë¾JustDialµÄÒ»¸öAPIδÊܱ£»£»£»£»£»£»£» £»¤£¬£¬£¬ £¬£¬¿É±»ÈκÎÈËÀûÓÃÒÔ¼ìË÷³¬¹ý100ÍòÓû§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Óû§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢ÊÖ»úºÅÂë¡¢¾ÓסµØÖ·¡¢ÐԱ𡢵®ÉúÈÕÆÚ¡¢ÕÕÆ¬¡¢¾ÍÖ°¹«Ë¾µÈ¡£¡£¡£¡£ ¡£¹ÌÈ»¸ÃAPIÖÁÉÙ´Ó2015ÄêÆð¾Í¿É¹«¿ª½Ó¼û£¬£¬£¬ £¬£¬µ«Éв»Ã÷ÏÔÊÇ·ñÒÑÓÐÈËÀûÓÃËüÀ´ÍøÂçJustDialÓû§µÄÓ×ÎÒÐÅÏ¢¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/justdial-hacked-data-breach.html

5¡¢FacebookÐÂÊý¾Ý³óÎÅ£¬£¬£¬ £¬£¬Î´¾­Óû§Ðí¿ÉÉÏ´«150ÍòÓû§ÓʼþÁªÏµÈË


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÔÚÖÜÈý°ä²¼µÄÒ»·ÝÉêÃ÷ÖУ¬£¬£¬ £¬£¬Facebook°µÊ¾×Ô2016Äê5ÔÂÒÔÀ´¸Ã¹«Ë¾¡°ÎÞÒâ¼ä¡±ÔÚδ¾­Óû§Ðí¿ÉµÄÇé¿öÏÂÏò·þÎñÆ÷ÉÏ´«Á˶à´ï150ÍòÓû§µÄµç×ÓÓʼþÁªÏµÈË¡£¡£¡£¡£ ¡£ÕâÊÇFacebook½üÆÚÃæ¶ÔµÄһϵÁÐÒþÖÔÓйØÎÊÌâºÍÕùÒéÖеÄ×îÐÂÊÂÎñ¡£¡£¡£¡£ ¡£Facebook°µÊ¾ÒÑÔÚÒ»¸öÔÂǰÖÕ³¡ÁË¿ÉÒɵĵç×ÓÓʼþÑéÖ¤¹ý³Ì£¬£¬£¬ £¬£¬²¢ÏòÓû§±£ÕÏδ·ÖÏíÕâЩÁªÏµÈËÐÅÏ¢¼°ÒѾ­Æðͷɾ³ýÕâЩÁªÏµÈË¡£¡£¡£¡£ ¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/04/facebook-email-database.html