ÐÅÏ¢Çå¾²Öܱ¨-2021ÄêµÚ49ÖÜ

Ðû²¼Ê±¼ä 2021-12-06

>±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


±¾Öܹ²ÊÕ¼Çå¾²Îó²î58¸ö£¬£¬ÖµµÃ¹Ø×¢µÄÊÇDell Emc Streaming Data Platform sql×¢ÈëÎó²î£»£»£»£»£»£»EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î£»£»£»£»£»£»Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î£»£»£»£»£»£»Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£


±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇTP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î£»£»£»£»£»£»IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ£»£»£»£»£»£»ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ£»£»£»£»£»£»°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ£»£»£»£»£»£»KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯¡£¡£¡£¡£¡£


ƾ֤ÒÔÉÏ×ÛÊö£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£¡£¡£¡£¡£


>Ö÷ÒªÇå¾²Îó²îÁбí


1. Dell Emc Streaming Data Platform sql×¢ÈëÎó²î


Dell Emc Streaming Data Platform±£´æsql×¢ÈëÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬²Ù×÷Êý¾Ý¿â£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


https://www.dell.com/support/kbdoc/zh-cn/000193697/dsa-2021-205-dell-emc-streaming-data-platform-security-update-for-third-party-vulnerabilities


2. EFM ipTIME C200 IP Cameraí§ÒâÏÂÁîÖ´ÐÐÎó²î


EFM ipTIME C200 IP CameraÓëipTIME NASͬ²½Ê±±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


http://iptime.com/iptime/?page_id=126&diffid=&dfsid=19&dftid=541


3. ohmyzsh rand-quoteºÍhitokoto²å¼þí§ÒâÏÂÁîÖ´ÐÐÎó²î


ohmyzsh rand-quoteºÍhitokoto²å¼þ±£´æÇå¾²Îó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


https://github.com/ohmyzsh/ohmyzsh/commit/72928432


4. Open Solutions For Education openSIS GetStuListFnc.php SQL×¢ÈëÎó²î


Open Solutions For Education openSIS GetStuListFnc.php±£´æsql×¢ÈëÎó²î£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄSQLÇëÇ󣬣¬²Ù×÷Êý¾Ý¿â£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢»òÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


https://github.com/OS4ED/openSIS-Classic/issues/202


5. Sunnet eHRD»á¼û¿ØÖÆ´úÂëÖ´ÐÐÎó²î


Sunnet eHRDδ׼ȷÏÞÖÆÀ´×ÔδÊÚȨ½ÇÉ«µÄ×ÊÔ´»á¼û£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬣¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£


https://www.twcert.org.tw/tw/cp-132-5354-0aac0-1.html


>Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢TP-LinkÐÞ¸´ÆäWi-Fi 6·ÓÉÆ÷ÖеĴúÂëÖ´ÐÐÎó²î


ResecurityÑо¿Ö°Ô±TP-LinkµÄ×°±¸Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¡£ÊÜÓ°Ïì×°±¸µÄÐͺÅΪTL-XVR1800L£¬£¬ÊÇÆóÒµ¼¶AX1800˫ƵǧÕ×Wi-Fi 6ÎÞÏßVPN·ÓÉÆ÷¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÍêÈ«¿ØÖÆ×°±¸»òÇÔÈ¡Ãô¸ÐÊý¾Ý£¬£¬Ëü¿ÉÄÜ»¹±£´æÓÚͳһϵÁÐµÄÆäËû×°±¸ÖС£¡£¡£¡£¡£ResecurityÔÚ10ÔÂÉÏÑ®·¢Ã÷ÁËÕë¶Ô¸Ã×°±¸µÄ¹¥»÷»î¶¯£¬£¬²¢ÓÚ11ÔÂ19ÈÕ֪ͨÁËTP-Link£¬£¬TP-LinkÔÚµÚ¶þÌìÈ·ÈÏÁ˸ÃÎó²î²¢ÔÊÐí»áÔÚÒ»ÖÜÄÚÐû²¼²¹¶¡¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/125016/hacking/0-day-tp-link-wi-fi-6.html


2¡¢IEEEÐû²¼2022Ä꼰δÀ´Ê®ÄêÒªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ


IEEEÔÚ½üÆÚÐû²¼ÁËδÀ´Òªº¦ÊÖÒÕµÄÕ¹Íû±¨¸æ¡£¡£¡£¡£¡£±¨¸æÊÓ²ìÁËÀ´×ÔÃÀ¹ú¡¢Ó¢¹ú¡¢Öйú¡¢Ó¡¶ÈºÍ°ÍÎ÷µÄ350λCTO¡¢CIOºÍIT×ܼ࣬£¬Õ¹ÍûÁË2022Äê×îÖ÷ÒªµÄÊÖÒÕ¡¢À´ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµÒÔ¼°Î´À´Ê®ÄêµÄÊÖÒÕÇ÷ÊÆ¡£¡£¡£¡£¡£21%µÄÊÜ·ÃÕßÒÔΪÈ˹¤ÖÇÄܺͻúеѧϰ½«³ÉΪÃ÷Äê×îÖ÷ÒªµÄÊÖÒÕ£¬£¬Æä´ÎÎªÔÆÅÌËã(20%)ºÍ5G(17%)£»£»£»£»£»£»25%µÄÈËÒÔÎªÖÆÔìÒµ»áÊÇ2022ÄêÊÜÊÖÒÕÓ°Ïì×î´óµÄÐÐÒµ£¬£¬Æä´ÎΪ½ðÈÚЧÀÍ(19%)¡¢Ò½ÁƱ£½¡(16%)ºÍÄÜÔ´(13%)ÐÐÒµ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://transmitter.ieee.org/impact-of-technology-2022/


3¡¢ÈÕ±¾µçÆ÷¹«Ë¾ËÉÏÂÈ·Èϳ¤´ï4¸öÔÂÖ®¾ÃÊý¾Ýй¶ÊÂÎñ


ÈÕ±¾¿ç¹ú¹«Ë¾ËÉÏÂPanasonicÔÚÉÏÖÜÎåÐû²¼ÉùÃ÷£¬£¬È·ÈÏÆä²¿·ÖÊý¾ÝÒѾ­Ð¹Â¶¡£¡£¡£¡£¡£¹¥»÷±¬·¢ÔÚ6ÔÂ22ÈÕ£¬£¬µ«Ö±µ½11ÔÂ11Èղű»·¢Ã÷¡£¡£¡£¡£¡£¾­ÓÉÄÚ²¿ÊÓ²ìÈ·¶¨£¬£¬¹¥»÷ÕßÒÑÔÚÕâ4¸öÔÂÖлá¼ûÁËЧÀÍÆ÷ÉϵIJ¿·ÖÊý¾Ý¡£¡£¡£¡£¡£¸Ã¹«Ë¾Ã»ÓÐÌṩÆäËüÏêϸÐÅÏ¢£¬£¬µ«ÈÕ±¾ÐÂÎÅÍøÕ¾MainichiºÍNHK±¨µÀ³Æ£¬£¬¹¥»÷ÕßÒѾ­»ñµÃÁ˹«Ë¾ÊÖÒÕ¡¢ÏàÖúͬ°é¼°¹«Ë¾Ô±¹¤µÈÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£ÔçÔÚ2020Äê11Ô£¬£¬ËÉÏÂÓ¡¶È·Ö¹«Ë¾ÔøÒòÍøÂç¹¥»÷й¶Á˲ÆÎñµÈÏà¹ØÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/panasonic-discloses-data-breach-after-network-hack/


4¡¢°µÍøÊг¡CannazonÔâµ½´ó¹æÄ£DDoS¹¥»÷ºóÓÀÊÀ¹Ø±Õ


2021Äê11ÔÂ23ÈÕ£¬£¬°µÍøÊг¡CannazonµÄÖÎÀíÔ±Ðû²¼½«ÓÀÊÀ¹Ø±Õ¸ÃÍøÕ¾¡£¡£¡£¡£¡£¾ÝϤ£¬£¬¸ÃÍøÕ¾ÔÚ11Ô³õÔâµ½ÁË´ó¹æÄ£DDoS¹¥»÷£¬£¬ÖÎÀíԱͨ¹ýïÔÌ­¶©µ¥ÊýÄ¿ºÍ¹Ø±Õ²¿·ÖϵͳÒÔ»º½âÎÊÌâ¡£¡£¡£¡£¡£µ«ÕâÔÚÉçÇøÖÐÒýÆðÁ˾ª¶¯£¬£¬Óû§µ£ÐÄÕâÊÇÒ»³¡Í˳öȦÌס£¡£¡£¡£¡£ÖÎÀíÔ±ÔÚÐû²¼¹Ø±Õͨ¸æÊ±£¬£¬¹ØÓÚÕâÖÖ´¦Öóͷ£ÒªÁìÌåÏÖǸÒ⣬£¬³ÆÃ»ÓйûÕæ¹¥»÷»î¶¯ÊÇΪÁ˱£»£»£»£»£»£»¤Óû§ºÍÉçÇø£¬£¬ÒÔ±ÜÃ⹩ӦÉÌÊÔͼ·¢¶¯¼ÓÃÜÇ®±ÒÍ˳öȦÌס£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dark-web-market-cannazon-shuts-down-after-massive-ddos-attack/


5¡¢KasperskyÅû¶APT37ʹÓÃChinotto¹¥»÷º«¹úµÄ»î¶¯


KasperskyÔÚ11ÔÂ29ÈÕÅû¶³¯ÏʺڿÍ×éÖ¯APT37£¨ÓÖ³ÆScarCruft»òTemp.Reaper£©ÔÚ½üÆÚµÄ¹¥»÷»î¶¯¡£¡£¡£¡£¡£ScarCruft´Ó2012Äê×îÏÈ»îÔ¾£¬£¬Ö÷ÒªÕë¶Ôº«¹úµÄ¹Ù·½»ú¹¹»ò¹«Ë¾¡£¡£¡£¡£¡£´Ë´Î»î¶¯×îÏÈÓÚ2021Äê8Ô£¬£¬³õʼѬȾǰÑÔÊÇÓã²æÊ½´¹Âڻ£¬£¬Ö®ºóʹÓÃIEä¯ÀÀÆ÷ÖеÄÁ½¸öÎó²îÔÚº«¹úµÄÍøÕ¾ÖÐ×°ÖÃ×Ô½ç˵¶ñÒâÈí¼þBLUELIGHT£¬£¬Ìᳫˮ¿Ó¹¥»÷¡£¡£¡£¡£¡£»£»£»£»£»£»î¶¯»¹Ê¹ÓÃÁ˶ñÒâÈí¼þChinotto£¬£¬Ëü¾ßÓÐÕë¶ÔPowerShell¡¢WindowsºÍAndroidµÄ¶à¸ö±äÌå¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/