ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ44ÖÜ
Ðû²¼Ê±¼ä 2018-11-05
Ò»¡¢±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇÐÂÀ¶ÑÀÎó²îBleedingBitµ¼ÖÂÊý°ÙÍò×°±¸±£´æÎ£º¦£»£»£»£»¼ÓÃÜÇ®±ÒÉúÒâËùMapleChangeÔâºÚ¿Í¹¥»÷£¬£¬£¬Ëðʧ913¸ö±ÈÌØ±Ò£»£»£»£»±ÈÀûʱµçÐŹ«Ë¾BelgacomÔâÊܹ¥»÷ÊÂÎñÒÉΪӢ¹úGCHQËùΪ£»£»£»£»¿¨°Í˹»ùÐû²¼2018Äê¹¤ÒµÍøÂçÇ徲״̬°×ƤÊ飻£»£»£»Ë¼¿ÆÅû¶ASAºÍFTD²úÆ·ÖеÄÐÂ0day£¬£¬£¬¿Éµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£
¶þ¡¢Ö÷ÒªÇå¾²Îó²îÁбí
1. Qualcomm Snapdragon¶à¸ö»º³åÇøÒç³öÎó²î
Qualcomm Snapdragon²úÆ·´¦Öóͷ£WMI_START_SCAN_CMDIDʱûÓÐ׼ȷ´¦Öóͷ£'remaining_len'£¬£¬£¬ÔÊÐíÍâµØ¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬¾ÙÐоܾøÐ§À͹¥»÷»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£
https://www.qualcomm.com/company/product-security/bulletins
2. Apache Tomcat JK (mod_jk) ConnectorĿ¼±éÀúÎó²î
Apache Tomcat JK£¨mod_jk£©Connector±£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬£¬Î´ÊÚȨ¶ÁȡϵͳÃô¸ÐÐÅÏ¢¡£¡£¡£
https://lists.apache.org/thread.html/6d564bb0ab73d6b3efdd1d6b1c075d1a2c84ecd84a4159d6122529ad@%3Cannounce.tomcat.apache.org%3E
3. OpenSSL²àÐŵÀ¹¥»÷ÐÅϢй¶Îó²î
OpenSSL DSAÊðÃûËã·¨±£´æ²àÐŵÀÎó²î£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îͨ¹ý»ñÈ¡ÊðÃûËã·¨ÀïµÄ±äÁ¿£¬£¬£¬»Ö¸´ÃØÔ¿ÐÅÏ¢¡£¡£¡£
https://www.openssl.org/news/secadv/20181030.txt
4. IBM WebSphere Commerce CVE-2018-1808´úÂë×¢ÈëÎó²î
Èý¡¢Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö
1¡¢ÐÂÀ¶ÑÀÎó²îBleedingBitµ¼ÖÂÊý°ÙÍò×°±¸±£´æÎ£º¦
ÒÔÉ«ÁÐÇå¾²¹«Ë¾ArmisµÄÑо¿Ö°Ô±·¢Ã÷µÂÖÝÒÇÆ÷£¨TI£©Éú²úµÄµÍ¹¦ºÄÀ¶ÑÀоƬ£¨BLE£©±£´æÁ½¸öÇå¾²Îó²î£¬£¬£¬Ë¼¿Æ¡¢MerakiºÍArubaµÈÖÆÔìÉ̵Ķà¸ö²úÏß¶¼Êܵ½Ó°Ïì¡£¡£¡£ÕâÁ½¸öÎó²î£¨CVE-2018-16986ºÍCVE-2018-7080£©±»³ÆÎªBleedingBit£¬£¬£¬ÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§Òâ´úÂë²¢ÍêÈ«½ÓÊÜ×°±¸¡£¡£¡£±¾ÖÜËĵÂÖÝÒÇÆ÷Ðû²¼ÁËÏà¹ØÐÞ¸´²¹¶¡£¬£¬£¬ÕâЩ²¹¶¡½«Í¨¹ý²î±ðµÄOEMÉÌÌṩӦÓû§¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2018/11/bluetooth-chip-hacking.html
2¡¢¼ÓÃÜÇ®±ÒÉúÒâËùMapleChangeÔâºÚ¿Í¹¥»÷£¬£¬£¬Ëðʧ913¸ö±ÈÌØ±Ò
¼ÓÃÜÇ®±ÒÉúÒâËùMapleChange³ÆÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬¹²Ëðʧ913¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼600ÍòÃÀÔª£©¡£¡£¡£¸Ãƽ̨¾Ý³ÆÊǼÓÄôóµÄÒ»¸öСÐÍÉúÒâËù¡£¡£¡£MapleChangeÔÚTwitterÉϳƾÓÉÏêϸµÄÊӲ죬£¬£¬¸ÃÉúÒâËùÎÞÁ¦¶ÔÓû§¾ÙÐÐÅ⸶£¬£¬£¬½«²»µÃ²»¹Ø±Õ£¬£¬£¬°üÀ¨¹Ø±ÕÆäTwitterÕË»§ºÍÍøÕ¾¡£¡£¡£ÕâÒ»ÊÂÎñѸËÙÒý·¢Á˶àÈËÏÓÒÉ£¬£¬£¬ÒÔΪ¸ÃСÐÍÉúÒâËù¿ÉÄÜÖ»ÊÇÒ»¸öȦÌ×£¬£¬£¬¸ÃÊÂÎñ¿ÉÄÜ»áÒý·¢ºóÐøµÄÐÌÊÂÊӲ졣¡£¡£
ÔÎÄÁ´½Ó£º
https://ethereumworldnews.com/maplechange-crypto-exchange-hacked-for-913-bitcoin-btc-exit-scam-likely/
3¡¢±ÈÀûʱµçÐŹ«Ë¾BelgacomÔâÊܹ¥»÷ÊÂÎñÒÉΪӢ¹úGCHQËùΪ
±ÈÀûʱ±¨Ö½De Standaard±¨µÀ³Æ£¬£¬£¬ÊÓ²ìÖ°Ô±ÒѾ֤ʵÕë±ÈÕÕÀûʱµçÐŹ«Ë¾Belgacom£¨ÏÖΪProximus¹«Ë¾£©µÄºÚ¿Í¹¥»÷ÊÇÓ¢¹úÇ鱨»ú¹¹GCHQËùΪ¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ2013Äê9Ô£¬£¬£¬BelgacomµÄIT»ù´¡ÉèÊ©Ôâµ½¶ñÒâÈí¼þ¹¥»÷¡£¡£¡£±¨µÀÖ¸³ö£¬£¬£¬Óë¹¥»÷BelgacomµÄÌØ¹¤Èí¼þ¾ÙÐÐͨѶµÄIPµØµãÖУ¬£¬£¬ÓÐÈý¸öIPÊôÓÚÒ»¼ÒÓ¢¹ú¹«Ë¾¡£¡£¡£¸Ã¹¥»÷ÊÇÓÉGCHQÌᳫµÄ£¬£¬£¬´úºÅΪOperation Socialist£¨Éç»áÖ÷ÒåÐж¯£©¡£¡£¡£Ó¢º£ÄÚÕþ²¿¾Ü¾øÓëÊÓ²ì×é¾ÙÐÐÏàÖú¡£¡£¡£ÈôÊDZ¨µÀÊôʵ£¬£¬£¬ÕâÒ»ÇéÐÎÓÈÆäÁîÈ˵£ÐÄ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/77430/intelligence/gchq-hacked-belgacom.html
4¡¢¿¨°Í˹»ùÐû²¼2018Äê¹¤ÒµÍøÂçÇ徲״̬°×ƤÊé
¿¨°Í˹»ù×î½üÐû²¼µÄ2018Äê¹¤ÒµÍøÂçÇ徲״̬°×ƤÊéÖ¸³ö£¬£¬£¬Ëæ×ÅÓëÍⲿÌìϵÄÅþÁ¬Ò»Ö±Ôö¶à£¬£¬£¬ÔÚ¹¤ÒµITºÍOTÍøÂçÖÐÇå¾²ÐÔÕýÔÚ³ÉΪ×îÖ÷ÒªµÄÖ÷ÌâÖ®Ò»¡£¡£¡£77%µÄ¹¤ÒµÇå¾²ÈËÊ¿ÒÔΪËûÃÇµÄÆóÒµºÜ¿ÉÄܳÉÎªÍøÂçÇå¾²ÊÂÎñµÄÄ¿µÄ£¬£¬£¬Í¬Ê±48%µÄÊÜ·ÃÕßÌåÏÖËûÃÇûÓÐרÃŵÄOT/ICSÊÂÎñÏìÓ¦ÍýÏë¡£¡£¡£ÒÑÍù12¸öÔÂÄÚÁè¼ÝÒ»°ëµÄÆóÒµÌåÏÖËûÃÇûÓÐÂÄÀú¹ýÈκÎÇå¾²ÊÂÎñ£¬£¬£¬µ«Ðí¶àÆóÒµÊÂʵÉÏ»ù´¡Ã»Óмì²â»ò¸ú×Ù¹ýÈκι¥»÷¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://ics.kaspersky.com/media/2018-Kaspersky-ICS-Whitepaper.pdf
5¡¢Ë¼¿ÆÅû¶ASAºÍFTD²úÆ·ÖеÄÐÂ0day£¬£¬£¬¿Éµ¼Ö¾ܾøÐ§ÀÍ
˼¿ÆÇå¾²ÍŶÓÅû¶Æä×Ô˳ӦÇå¾²×°±¸£¨ASA£©ºÍFirepowerÍþв·ÀÓùÈí¼þ£¨FTD£©ÖеĻỰ³õʼ»¯ÐÒ飨SIP£©¼ì²éÒýÇæ±£´æÒ»¸ö¿Éµ¼Ö¾ܾøÐ§À͵ÄÁãÈÕÎó²î¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSIPÇëÇóÀ´´¥·¢¸ÃÎó²î£¬£¬£¬µ¼ÖÂDoS¡£¡£¡£¸ÃÎó²î£¨CVE-2018-15454£©Ó°ÏìÔËÐÐASA 9.4+ºÍFTD 6.0+µÄ×°±¸£¬£¬£¬°üÀ¨¶à¸öÐͺŵĹ¤ÒµÇå¾²×°±¸ºÍ·À»ðǽµÈ²úÆ·¡£¡£¡£ÏÖÔÚ»¹Ã»ÓиÃÎó²îµÄÐÞ¸´²¹¶¡ºÍworkaround£¬£¬£¬µ«¿ÉÒÔ½ÓÄÉһЩ»º½â²½·¥×èÖ¹Ô¶³Ì¹¥»÷Õ߯ÆËðÆä×°±¸¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos
ÉùÃ÷£º±¾×ÊѶÓÉÄϹ¬NGÓéÀÖάËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ