¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190111
Ðû²¼Ê±¼ä 2019-01-11
FireEye·¢Ã÷Ò»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNSÐ®ÖÆÀ˳±£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£ÕâЩÓòÃûÊôÓÚÕþ¸®¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£ËäÈ»ÏÖÔÚÑо¿Ö°Ô±»¹Ã»Óн«´ËÔ˶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬µ«ÆðÔ´µÄÑо¿Åú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйء£¸Ã¹¥»÷Ô˶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂʱ´úÒ»Ö±´¦ÓÚ»îԾ״̬£¬²¢ÇÒ±£´æ¶à¸ö²»Öظ´µÄÓòÃû¡¢IPµØµã¼¯Èº¡£ÕâÒâζןù¥»÷Ô˶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕßµÄÔ˶¯¡£¹¥»÷ÕßµÄÊÖÒÕÖ÷񻃾¼°ÐÞ¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍÖØ¶¨Ïò¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html2¡¢TA505жñÒâÔ˶¯£¬·Ö·¢ServHelperºóÃźÍFlawedGrace RAT
Ñо¿Ö°Ô±·¢Ã÷·¸·¨ÍÅ»ïTA505ͨ¹ýÍøÂç´¹ÂÚÔ˶¯·Ö·¢ServHelperºóÃźÍFlawedGrace RAT¡£¹¥»÷Õß¼ÌÐøÃé×¼½ðÈÚºÍÁãÊÛÐÐÒµ£¬²¢Í¨¹ý¶ñÒâµÄMicrosoft Word¡¢PublisherºÍPDFÎļþѬȾÓû§¡£Æ¾Ö¤ProofpointµÄÑо¿£¬TA505ÒÑÔÚÍøÂç·¸·¨ÁìÓòÖÁÉÙ»îÔ¾ÁËËÄÄ꣬ÓëÖ®Ïà¹ØµÄ¶ñÒâÈí¼þ°üÀ¨ÒøÐÐľÂíDridex¡¢ÀÕË÷Èí¼þLocky¡¢PhiladelphiaºÍGlobeImposter¡£´Ë´Î¹¥»÷Ô˶¯Öй²·Ö·¢ÁËServHelperµÄÁ½ÖÖ±äÌå¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-servhelper-backdoor-and-flawedgrace-rat-pushed-by-necurs-botnet/3¡¢SystemdÈý¸öÌáȨÎó²î£¬Ó°Ïì´ó´ó¶¼Linux¿¯Ðаæ

QualysÇå¾²Ñо¿Ö°Ô±ÔÚSystemdÖз¢Ã÷Èý¸öÇå¾²Îó²î£¬ÕâЩÎó²î¿ÉÔÊÐíÎÞÌØÈ¨µÄÍâµØ¹¥»÷Õß»ò¶ñÒâ³ÌÐòÔÚÄ¿µÄϵͳÉÏ»ñµÃroot»á¼ûȨÏÞ¡£ÕâÈý¸öÎó²î£¨CVE-2018-16864¡¢CVE-2018-16865ºÍCVE-2018-16866£©±£´æÓÚsystemd-journald·þÎñÖУ¬¸Ã·þÎñÓÃÓÚÍøÂçÐÅÏ¢ºÍ½¨ÉèÈÕÖ¾¡£Ñо¿Ö°Ô±ÌåÏÖÕâЩÎó²îÓ°ÏìÁËËùÓлùÓÚsystemdµÄLinux¿¯Ðа棬°üÀ¨RedhatºÍDebian¡£µ«Ò²ÓÐһЩ¿¯Ðа棬ÀýÈçSUSE¡¢Fedora²»ÊÜÓ°Ïì¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÐÞ²¹³ÌÐò¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/linux-systemd-exploit.html4¡¢¹È¸èÐû²¼ÆäDNS·þÎñÖ§³ÖDNS-over-TLSÇå¾²ÐÒé
ÓÉÓÚDNSÅÌÎÊÊÇͨ¹ýUDP»òTCPÒÔÃ÷ÎÄÐÎʽ·¢Ë͵ģ¬Òò´Ë¸ÃÐÅÏ¢¿ÉÒÔй¶Óû§»á¼ûµÄÍøÕ¾£¬²¢ÇÒÒ×ÊÜÓÕÆ¹¥»÷¡£ÎªÏàʶ¾öÕâ¸öÎÊÌ⣬±¾ÖÜÈý¹È¸èÐû²¼Æä¹«¹²DNS·þÎñÖ§³ÖDNS-over-TLSÇå¾²ÐÒ飬ÕâÒâζ×ÅDNSÅÌÎʺÍÏìÓ¦½«Í¨¹ýTLS¼ÓÃܵÄTCPÅþÁ¬¾ÙÐÐͨѶ£¬¿ÉÒÔÓÐÓÃ×èÖ¹ÖÐÐÄÈ˹¥»÷¡£±ðµÄ£¬¹È¸èÒѾΪAndroid 9Óû§ÌṩÁËDNS-over-TLS£¬¸Ã²¿·ÖÓû§¿ÉÒÔÁ¬Ã¦Çл»µ½DNS-over-TLS¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/google-dns-over-tls-security.html5¡¢ÃÀ¹úÁè¼Ý80¸öÕþ¸®ÍøÕ¾µÄTLSÖ¤ÊéÓâÆÚ
¾ÝZDNet±¨µÀ£¬ÃÀ¹úÁè¼Ý80¸öÕþ¸®ÍøÕ¾µÄTLSÖ¤ÊéÒѾÓâÆÚ£¬²¢ÇÒûÓб»¸üУ¬²¿·ÖÍøÕ¾ÒѾÎÞ·¨»á¼û¡£¾ÝNetcraft³Æ£¬ÊÜÓ°ÏìµÄÕþ¸®»ú¹¹°üÀ¨NASA¡¢ÃÀ¹ú˾·¨²¿ºÍÃÀ¹úÁª°îÉÏËß·¨ÔºµÈ¡£²¿·ÖʵÑéÁËHSTSµÄÍøÕ¾ÓÉÓÚÖ¤ÊéÓâÆÚÒѾÎÞ·¨±»Óû§»á¼û£¬¶øÎ´ÊµÑéHSTSµÄÍøÕ¾½«ÔÚÓû§µÄä¯ÀÀÆ÷ÖÐÏÔʾHTTPS¹ýʧ¡£Ñо¿Ö°Ô±½«ÕâÒ»ÊÂÎñ¹é×ïÓÚÃÀ¹úÁª°îÕþ¸®µÄ¹Ø±Õ£¬´ó×ÚITºÍÍøÂçÇå¾²Ö°Ô±±»¿ª³ý£¬µ¼ÖÂûÓÐÈË¿ÉÒÔÐøÇ©ÕâЩ֤Êé¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/government-shutdown-tls-certificates-not-renewed-many-websites-are-down/6¡¢ÐÂ¹ã¸æÈí¼þICEPick-3PC£¬Ö÷ÒªÕë¶ÔAndroidÓû§

Media TrustÑо¿Ö°Ô±·¢Ã÷Ò»¸öÊ®·ÖÖØ´óµÄÐÂ¹ã¸æÈí¼þICEPick-3PC£¬Ñо¿Ö°Ô±ÒÔΪÆä±³ºóµÄÓÐ×éÖ¯·¸·¨ÍÅ»ïÕýÔÚ¿ªÕ¹Õë¶ÔAndroidÓû§µÄ´ó¹æÄ£¹¥»÷Ô˶¯¡£¹¥»÷Õß½«¶ñÒâ´úÂë×¢È뵽һЩµÚÈý·½¿âÖУ¬ÀýÈçGreenSock¶¯»Æ½Ì¨£¨GSAP£©-Ò»¸öHTML5¶¯»µÄJavaScript¿â¡£µ±Óû§µã»÷ÊÜѬȾµÄ¹ã¸æÊ±£¬¶ñÒâÈí¼þ»áÔÚÓû§×°±¸ºÍÔ¶³Ì×°±¸Ö®¼ä½¨ÉèRTC¶ÔµÈÅþÁ¬£¬²¢ÍøÂç×°±¸µÄÖ¸ÎÆÐÅÏ¢£¬°üÀ¨×°±¸µÄIPµØµã¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/icepick-adware-analysis/140722/ÉùÃ÷£º±¾×ÊѶÓÉ×ðÁú¿Ê±Î¬ËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ