ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ49ÖÜ

Ðû²¼Ê±¼ä 2021-12-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬£¬£¬£¬ £¬ÖµµÃ¹Ø×¢µÄÊÇDell Emc Streaming Data Platform sql×¢ÈëÎó²î£»£»£»£»£»£»EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î£»£»£»£»£»£»Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ£»£»£»£»£»£»ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ£»£»£»£»£»£»°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ£»£»£»£»£»£»KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬ £¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Dell Emc Streaming Data Platform sql×¢ÈëÎó²î


Dell Emc Streaming Data Platform±£´æsql×¢ÈëÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬ £¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬ £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


https://www.dell.com/support/kbdoc/zh-cn/000193697/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities


2. EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î


EFM ipTIME C200 IP CameraÓëipTIME NASͬ²½Ê±±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


http://iptime.com/iptime/?page_id=126&diffid=&dfsid=19&dftid=541


3. ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î


ohmyzsh rand-quoteºÍhitokoto²å¼þ±£´æÇå¾²Îó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


https://github.com/ohmyzsh/ohmyzsh/commit/72928432


4. Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î


Open Solutions For Education openSIS GetStuListFnc.php±£´æsql×¢ÈëÎó²î£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬£¬£¬£¬ £¬²Ù×÷Êý¾Ý¿â£¬£¬£¬£¬£¬ £¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


https://github.com/OS4ED/openSIS-Classic/issues/202


5. Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î


Sunnet eHRDδ׼ȷÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´»á¼û£¬£¬£¬£¬£¬ £¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬£¬£¬ £¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£


https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î


ResecurityÑо¿Ö°Ô±TP-LinkµÄ×°±¸Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ÊÜÓ°Ïì×°±¸µÄÐͺÅΪTL-XVR1800L£¬£¬£¬£¬£¬ £¬ÊÇÆóÒµ¼¶AX1800˫ƵǧÕ×Wi-Fi 6ÎÞÏßVPN·ÓÉÆ÷¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÍêÈ«¿ØÖÆ×°±¸»òÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ £¬Ëü¿ÉÄÜ»¹±£´æÓÚͳһϵÁÐµÄÆäËû×°±¸ÖС£¡£¡£ResecurityÔÚ10ÔÂÉÏÑ®·¢Ã÷ÁËÕë¶Ô¸Ã×°±¸µÄ¹¥»÷»î¶¯£¬£¬£¬£¬£¬ £¬²¢ÓÚ11ÔÂ19ÈÕ֪ͨÁËTP-Link£¬£¬£¬£¬£¬ £¬TP-LinkÔÚµÚ¶þÌìÈ·ÈÏÁ˸ÃÎó²î²¢ÔÊÐí»áÔÚÒ»ÖÜÄÚÐû²¼²¹¶¡¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html


2¡¢IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ


IEEEÔÚ½üÆÚÐû²¼ÁËδÀ´Òªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ¡£¡£¡£±¨¸æÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢Öйú¡¢Ó¡¶ÈºÍ°ÍÎ÷µÄ350λCTO¡¢CIOºÍIT×ܼ࣬£¬£¬£¬£¬ £¬Õ¹ÍûÁË2022Äê×îÖ÷ÒªµÄÊÖÒÕ¡¢À´ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµÒÔ¼°Î´À´Ê®ÄêµÄÊÖÒÕÇ÷ÊÆ¡£¡£¡£21%µÄÊÜ·ÃÕßÒÔΪÈ˹¤ÖÇÄܺͻúеѧϰ½«³ÉΪÃ÷Äê×îÖ÷ÒªµÄÊÖÒÕ£¬£¬£¬£¬£¬ £¬Æä´ÎÎªÔÆÅÌËã(20%)ºÍ5G(17%)£»£»£»£»£»£»25%µÄÈËÒÔÎªÖÆÔìÒµ»áÊÇ2022ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµ£¬£¬£¬£¬£¬ £¬Æä´ÎΪ½ðÈÚЧÀÍ(19%)¡¢Ò½ÁƱ£½¡(16%)ºÍÄÜÔ´(13%)ÐÐÒµ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://transmitter.ieee.org/impact-of-technology-2022/


3¡¢ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ


ÈÕ±¾¿ç¹ú¹«Ë¾ËÉÏÂPanasonicÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷£¬£¬£¬£¬£¬ £¬È·ÈÏÆä²¿·ÖÊý¾ÝÒѾ­Ð¹Â¶¡£¡£¡£¹¥»÷±¬·¢ÔÚ6ÔÂ22ÈÕ£¬£¬£¬£¬£¬ £¬µ«Ö±µ½11ÔÂ11Èղű»·¢Ã÷¡£¡£¡£¾­ÓÉÄÚ²¿ÊÓ²ìÈ·¶¨£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒÑÔÚÕâ4¸öÔÂÖлá¼ûÁËЧÀÍÆ÷ÉϵIJ¿·ÖÊý¾Ý¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÆäËüÏêϸÐÅÏ¢£¬£¬£¬£¬£¬ £¬µ«ÈÕ±¾ÐÂÎÅÍøÕ¾MainichiºÍNHK±¨µÀ³Æ£¬£¬£¬£¬£¬ £¬¹¥»÷ÕßÒѾ­»ñµÃÁ˹«Ë¾ÊÖÒÕ¡¢ÏàÖúͬ°é¼°¹«Ë¾Ô±¹¤µÈÏà¹ØÐÅÏ¢¡£¡£¡£ÔçÔÚ2020Äê11Ô£¬£¬£¬£¬£¬ £¬ËÉÏÂÓ¡¶È·Ö¹«Ë¾ÔøÒòÍøÂç¹¥»÷й¶Á˲ÆÎñµÈÏà¹ØÐÅÏ¢¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/


4¡¢°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ


2021Äê11ÔÂ23ÈÕ£¬£¬£¬£¬£¬ £¬°µÍøÊг¡CannazonµÄÖÎÀíÔ±Ðû²¼½«ÓÀÊÀ¹Ø±Õ¸ÃÍøÕ¾¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬ £¬¸ÃÍøÕ¾ÔÚ11Ô³õÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷£¬£¬£¬£¬£¬ £¬ÖÎÀíԱͨ¹ýïÔÌ­¶©µ¥ÊýÄ¿ºÍ¹Ø±Õ²¿·ÖϵͳÒÔ»º½âÎÊÌâ¡£¡£¡£µ«ÕâÔÚÉçÇøÖÐÒýÆðÁ˾ª¶¯£¬£¬£¬£¬£¬ £¬Óû§µ£ÐÄÕâÊÇÒ»³¡Í˳öȦÌס£¡£¡£ÖÎÀíÔ±ÔÚÐû²¼¹Ø±Õͨ¸æÊ±£¬£¬£¬£¬£¬ £¬¹ØÓÚÕâÖÖ´¦Öóͷ£ÒªÁìÌåÏÖǸÒ⣬£¬£¬£¬£¬ £¬³ÆÃ»ÓйûÕæ¹¥»÷»î¶¯ÊÇΪÁ˱£»£»£»£»£»£»¤Óû§ºÍÉçÇø£¬£¬£¬£¬£¬ £¬ÒÔ±ÜÃ⹩ӦÉÌÊÔͼ·¢¶¯¼ÓÃÜÇ®±ÒÍ˳öȦÌס£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/


5¡¢KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯


KasperskyÔÚ11ÔÂ29ÈÕÅû¶³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖ³ÆScarCruft»òTemp.Reaper£©ÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£¡£¡£ScarCruft´Ó2012Äê×îÏÈ»îÔ¾£¬£¬£¬£¬£¬ £¬Ö÷ÒªÕë¶Ôº«¹úµÄ¹Ù·½»ú¹¹»ò¹«Ë¾¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ2021Äê8Ô£¬£¬£¬£¬£¬ £¬³õʼѬȾǰÑÔÊÇÓã²æÊ½´¹Âڻ£¬£¬£¬£¬£¬ £¬Ö®ºóʹÓÃIEä¯ÀÀÆ÷ÖеÄÁ½¸öÎó²îÔÚº«¹úµÄÍøÕ¾ÖÐ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þBLUELIGHT£¬£¬£¬£¬£¬ £¬Ìᳫˮ¿Ó¹¥»÷¡£¡£¡£»£»£»£»£»£»î¶¯»¹Ê¹ÓÃÁ˶ñÒâÈí¼þChinotto£¬£¬£¬£¬£¬ £¬Ëü¾ßÓÐÕë¶ÔPowerShell¡¢WindowsºÍAndroidµÄ¶à¸ö±äÌå¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/