ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ41ÖÜ
Ðû²¼Ê±¼ä 2021-10-11>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾Öܹ²ÊÕ¼Çå¾²Îó²î49¸ö£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache HTTP Server HTTP/2ÆÊÎö¿ÕÖ¸ÕëÒýÓþܾøÐ§ÀÍÎó²î£»£»£»£»£»£»Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐÐÎó²î£»£»£»£»£»£»Visual Tools DVR VX cgi-bin/slogin/login.pyÏÂÁîÖ´ÐÐÎó²î; Google chrome Safe BrowsingÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÓÉÓÚFirebaseÉèÖùýʧ14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢£»£»£»£»£»£»Facebook·ÓÉÉèÖùýʧµ¼ÖÂÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹£»£»£»£»£»£»Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÉèÖùýʧй¶10TBÊý¾Ý£»£»£»£»£»£»TwitchÒòЧÀÍÆ÷ÉèÖùýʧй¶125GBÔ´´úÂëµÈÐÅÏ¢£»£»£»£»£»£»Cyberint·¢Ã÷VidarʹÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯¡£¡£¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£
>Ö÷ÒªÇå¾²Îó²îÁбí
1. Apache HTTP Server HTTP/2ÆÊÎö¿ÕÖ¸ÕëÒýÓþܾøÐ§ÀÍÎó²î
Apache HTTP Server±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÉó²éϵͳÎļþÄÚÈÝ»òÕßÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://httpd.apache.org/security/vulnerabilities_24.html
2. Zoho ManageEngine ADManager Plus CVE-2021-37931ÎļþÉÏ´«´úÂëÖ´ÐÐÎó²î
Zoho ManageEngine ADManager Plus±£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬£¬ÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.manageengine.com/products/ad-manager/release-notes.html#7111
3. Google Android¿ò¼ÜCVE-2021-0652´úÂëÖ´ÐÐÎó²î
Google Android¿ò¼Ü±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬£¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£
https://source.android.com/security/bulletin/2021-10-01
4. Visual Tools DVR VX cgi-bin/slogin/login.pyÏÂÁîÖ´ÐÐÎó²î
Visual Tools DVR VX16 cgi-bin/slogin/login.py Uaer-Agent HTTP´¦Öóͷ£±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£
https://www.exploit-db.com/exploits/50098
5. Google chrome Safe BrowsingÄÚ´æ¹ýʧÒýÓôúÂëÖ´ÐÐÎó²î
Google chrome Safe Browsing±£´æÊͷźóʹÓÃÎó²î£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÒ³ÇëÇ󣬣¬£¬£¬£¬ÓÕʹÓû§ÆÊÎö£¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë»òÕßʹӦÓóÌÐòÍ߽⡣¡£¡£¡£¡£
https://chromereleases.googleblog.com/2021/09/stable-channel-update-for-desktop_30.html
>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÓÉÓÚFirebaseÉèÖùýʧ14¸öÓ¦ÓÿÉÄÜй¶1.4ÒÚÓû§ÐÅÏ¢
9ÔÂ30ÈÕ£¬£¬£¬£¬£¬ CyberNews Ñо¿Ô± Martynas Vareikis Ðû²¼±¨¸æ³Æ£¬£¬£¬£¬£¬ÓÉÓÚ Firebase Êý¾Ý¿âÉèÖùýʧ£¬£¬£¬£¬£¬µ¼ÖÂÊýÒÔǧ¼ÆµÄ iOS / Android Ó¦ÓóÌÐòй¶ÁËÁè¼Ý1.4ÒÚÌõÐÅÏ¢¡£¡£¡£¡£¡£Firebase ÊÇ Google ÌṩµÄ¡°ºó¶Ë¼´Ð§ÀÍ¡±²úÆ·£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÁË´ó×Ú·¢Ð§ÀÍ£¬£¬£¬£¬£¬Ö¼ÔÚÀû±ãÒÆ¶¯¿ª·¢Ö°Ô±½¨Éè»ùÓÚÕâЩЧÀ͵ÄÒÆ¶¯»ò Web Ó¦Óᣡ£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cybernews.com/security/research-popular-android-apps-with-142-5-million-collective-downloads-are-leaking-user-data/
2¡¢Facebook·ÓÉÉèÖùýʧµ¼ÖÂÈ«Çò¹æÄ£ÄÚЧÀÍÖÐÖ¹
10ÔÂ4ÈÕ£¬£¬£¬£¬£¬FacebookÆì϶à¸öƽ̨ºÍЧÀÍ£¬£¬£¬£¬£¬°üÀ¨ Facebook¡¢Instagram¡¢MessengerºÍ WhatsAppµÈ£¬£¬£¬£¬£¬Ïà¼Ì·ºÆðÑÏÖØÐ§ÀÍÖÐÖ¹¡£¡£¡£¡£¡£Óû§ÎÞ·¨µÇÈë³ÌÐò£¬£¬£¬£¬£¬³ÌÐòÎÞ·¨Áª»úºÍ¸üУ¬£¬£¬£¬£¬Ã»·¨ÊÕ·¢ÐÅÏ¢£¬£¬£¬£¬£¬¾ÍÁ¬ÒÔ FacebookÕ˺ŵÇÈëµÄ³ÌÐòºÍЧÀÍÒàÊܵ½Ç£Á¬£¬£¬£¬£¬£¬²»¿ÉÕý³£µÇÈë¡£¡£¡£¡£¡£FacebookØÊºó·¢ÉùÃ÷Ö¸£¬£¬£¬£¬£¬ÄÚ²¿Â·ÓÉÆ÷·ºÆðÎÊÌ⣬£¬£¬£¬£¬Á¬Ëø·´Ó¦µ¼ÖÂЧÀÍÖÜÈ«ÖÐÖ¹£¬£¬£¬£¬£¬ËäȻЧÀÍÒѻظ´£¬£¬£¬£¬£¬µ«ÄÚ²¿ÈÔÔÚÈ«Á¦¸ÄÉÆÏµÍ³£¬£¬£¬£¬£¬ÒԻظ´Õý³£ÊÂÇé״̬¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/technology/facebook-outage-caused-by-faulty-routing-configuration-changes/
3¡¢Ó¢¹úÖðÈÕµçѶ±¨ElasticsearchÉèÖùýʧй¶10TBÊý¾Ý
10ÔÂ6ÈÕ£¬£¬£¬£¬£¬Ñо¿Ô± Bob Diachenko ·¢Ã÷ÁËÒ»¸öÊôÓÚÓ¢¹ú±¨Ö½¡°µçѶ±¨¡±µÄδÊܱ£»£»£»£»£»£»¤µÄ 10 TB Êý¾Ý¿â¡£¡£¡£¡£¡£²»Çå¾²µÄÊý¾Ý¿âÓÚ9 Ô 14 ÈÕ±»·¢Ã÷£¬£¬£¬£¬£¬ÆäÖаüÀ¨ÄÚ²¿ÈÕÖ¾ºÍ¶©ÔÄÕßÐÅÏ¢¡£¡£¡£¡£¡£Êý¾Ý´æ´¢ÔÚ̻¶µÄ Elasticsearch ¼¯ÈºÉÏ£¬£¬£¬£¬£¬´ó²¿·ÖÊý¾Ý¶¼¾ÓɼÓÃÜ£¬£¬£¬£¬£¬µ«ÖÁÉÙ 1,200 Ãû Telegraph ¶©ÔÄÕߺÍ×¢²áÕßµÄСÎÒ˽¼ÒÏêϸÐÅÏ¢ÒÔ¼°´ó×ÚÄÚ²¿Ð§ÀÍÆ÷ÈÕÖ¾¶¼ÒѾÓÉÃ÷È·²âÊÔ¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/123020/data-breach/the-telegraph-data-leak.html
4¡¢TwitchÒòЧÀÍÆ÷ÉèÖùýʧй¶125GBÔ´´úÂëµÈÐÅÏ¢
10ÔÂ6ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ4chan¹ûÕæÁ˰üÀ¨125GBÊý¾ÝµÄtorrentÁ´½Ó£¬£¬£¬£¬£¬³ÆÕâÊÇ´ÓԼĪ6000¸öÄÚ²¿Twitch Git´æ´¢¿âÖÐÇÔÈ¡µÄ£¬£¬£¬£¬£¬°üÀ¨Ô´´úÂëºÍÖ§¸¶¼Í¼µÈÐÅÏ¢¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃÁ˱êÇ©#DoBetterTwitch£¬£¬£¬£¬£¬Ö¤Êµ´Ë´Î¹¥»÷ÊÂÎñ¿ÉÄÜÖ¼ÔÚÕë¶ÔTwitch 8Ô·ÝûÓлØÓ¦ºÍµÖÓù¶ÔÖ÷²¥µÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£TwitchÔÚ10ÔÂ7ÈÕÈ·ÈÏÆäÊý¾Ýй¶ÊÇÓÉÓÚЧÀÍÆ÷ÉèÖùýʧµ¼Öµģ¬£¬£¬£¬£¬Ã»ÓеǼƾ֤ºÍÐÅÓÿ¨ºÅй¶¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/twitch-no-credentials-or-card-numbers-exposed-in-data-breach/
5¡¢Cyberint·¢Ã÷VidarʹÓÃMastodonµÄÐÂÒ»ÂÖ¹¥»÷»î¶¯
Cyberint·¢Ã÷¶ñÒâÈí¼þVidarÔÚÐÂÒ»ÂÖ¹¥»÷»î¶¯Öлع顣¡£¡£¡£¡£Vidar×Ô2018Äê10ÔÂÒÔÀ´×îÏÈ»îÔ¾£¬£¬£¬£¬£¬Ö¼ÔÚ´ÓÄ¿µÄϵͳÖÐÇÔÈ¡µç×ÓÓʼþƾ֤¡¢Ì¸ÌìÕÊ»§ÏêϸÐÅÏ¢¡¢cookieµÈÊý¾Ý¡£¡£¡£¡£¡£´Ë´Î»î¶¯ÖУ¬£¬£¬£¬£¬¹¥»÷ÕßÊ×ÏȽ¨ÉèMastodonÕ˺ţ¬£¬£¬£¬£¬²¢ÔÚСÎÒ˽¼Ò×ÊÁÏÐÎò²¿·ÖÌí¼Ó¶ñÒâÈí¼þʹÓõÄC2µÄIP¡£¡£¡£¡£¡£Æä»¹Ê¹ÓÃÁËÁíÒ»ÖÖ·Ö·¢ÒªÁ죬£¬£¬£¬£¬Ö±½ÓÔÚÉ罻ýÌåÆ½Ì¨ÉÏ·¢ËÍÐÂÎÅ£¬£¬£¬£¬£¬»òÕßÊÇʹÓÃÆÆ½âÓÎÏ·µÄtorrent¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/vidar-stealer-abuses-mastodon-to-silently-get-c2-configuration/