Òâ´óÀûCSIRT³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½DDoS¹¥»÷

Ðû²¼Ê±¼ä 2022-05-16
1¡¢Òâ´óÀûCSIRT³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾Ôâµ½DDoS¹¥»÷


5ÔÂ13ÈÕ£¬£¬£¬£¬ £¬£¬£¬Òâ´óÀûÅÌËã»úÇå¾²ÊÂÎñÏìӦС×é(CSIRT)³ÆÆä¶à¸ö¹Ù·½×éÖ¯µÄÍøÕ¾ÔÚ×î½ü¼¸ÌìÔâµ½DDoS¹¥»÷¡£¡£¡£¡£CSIRTÚ¹ÊÍ˵£¬£¬£¬£¬ £¬£¬£¬´Ó5ÔÂ11ÈÕ×îÏÈ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¶ÔÆäÕþ¸®¡¢²¿Î¯¡¢Òé»áÉõÖÁ¾ü¶ÓµÄÍøÕ¾¾ÙÐÐÁËËùνµÄ¡°Slow HTTP¡±DDoS¹¥»÷¡£¡£¡£¡£ÕâÖÖÀàÐ͵Ĺ¥»÷ÔÚʹÓÃPOSTÇëÇóµÄÇéÐÎϸüÓÐÓ㬣¬£¬£¬ £¬£¬£¬ÓÉÓÚËüÃÇ»¹ÓÃÓÚÏòWebЧÀÍÆ÷·¢ËÍ´ó×ÚÊý¾Ý¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬¸Ã»ú¹¹»¹ÌṩÁË»º½â´ËÀ๥»÷µÄÒªÁì¡£¡£¡£¡£ºÚ¿ÍÍÅ»ïKillnetÉù³Æ¶Ô´Ë´Î¹¥»÷ÈÏÕæ£¬£¬£¬£¬ £¬£¬£¬ËûÃÇ»¹¶ÔÂÞÂíÄáÑÇÃÅ»§ÍøÕ¾ºÍÃÀ¹ú²¼À­µÂÀû»ú³¡¾ÙÐÐÁËÀàËÆ¹¥»÷µÄ¡£¡£¡£¡£


https://securityaffairs.co/wordpress/131256/hacktivism/pro-russian-hacktivists-target-italy.html


2¡¢2¸öÉèÖùýʧµÄESЧÀÍÆ÷й¶Լ3.59ÒÚÌõ¼Í¼


ýÌå5ÔÂ12Èճƣ¬£¬£¬£¬ £¬£¬£¬2¸öÉèÖùýʧµÄElasticSearchЧÀÍÆ÷йÁ˶Լ359019902Ìõ¼Í¼¡£¡£¡£¡£¾ÝÑо¿Ö°Ô±³Æ£¬£¬£¬£¬ £¬£¬£¬ÕâÁ½Ð©ESЧÀÍÆ÷¾ùÊôÓÚÒ»¸ö×éÖ¯£¬£¬£¬£¬ £¬£¬£¬°üÀ¨Ô¼579.4 GBµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬Éæ¼°ÍÆ¼öÈËÒ³Ãæ¡¢Ê±¼ä´ÁIP¡¢µØÀíλÖÃÊý¾Ý¡¢»á¼ûµÄÍøÒ³¡¢ºÍÓû§ÊðÀíÊý¾ÝµÈ¡£¡£¡£¡£ÆäÖеÚһ̨ЧÀÍÆ÷°üÀ¨2021Äê9ÔÂ2ÈÕÖÁ10ÔÂ1ÈÕʱ´úÍøÂçµÄ242728328Ìõ¼Í¼£¬£¬£¬£¬ £¬£¬£¬Áíһ̨°üÀ¨2021Äê12ÔÂ1ÈÕÖÁ12ÔÂ27ÈÕÍøÂçµÄ116291574Ìõ¼Í¼¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬£¬ £¬£¬£¬Ô¼ÓÐ1500ÍòÓû§ÊÜ´ËÊÂÎñµÄÓ°Ïì¡£¡£¡£¡£


https://www.hackread.com/misconfigured-elasticsearch-servers-user-website-activity/


3¡¢´ó×Ú¶íÂÞ˹AndroidÓû§·´Ó¦ÎÞ·¨×°ÖÃChrome¸üÐÂ


¾ÝýÌå5ÔÂ13ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬£¬¶íÂÞ˹ԽÀ´Ô½¶àµÄAndroid ChromeÓû§·´Ó¦ÔÚ×°ÖøüÐÂʱ±¨¸æ¹ýʧ¡£¡£¡£¡£Æ¾Ö¤Óû§Ì¸ÂÛ£¬£¬£¬£¬ £¬£¬£¬ÎÊÌâʼÓÚ2022Äê5ÔÂ9ÈÕ£¬£¬£¬£¬ £¬£¬£¬ËûÃÇÔÚÊÔͼװÖÃChrome°æ±¾101ʱÊÕµ½ÁËÒ»Ìõ¹ýʧÐÂÎÅ¡°ÎÞ·¨×°ÖÃGoogle Chrome¡±¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬¹ýʧÐÂÎŲ¢Î´ËµÃ÷¸üÐÂʧ°ÜµÄÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬ £¬£¬£¬GoogleµÄÖ§³ÖÊðÀí½¨ÒéÓû§ÔÚÖ§³ÖÉçÇøÌÖÂÛÖвéÕÒ½â¾ö¼Æ»®¡£¡£¡£¡£Í¶ËßµÄÊýÄ¿ÌìÌì¶¼ÔÚÔöÌí£¬£¬£¬£¬ £¬£¬£¬µ«µ½ÏÖÔÚΪֹ£¬£¬£¬£¬ £¬£¬£¬ÎÊÌâµÄÔµ¹ÊÔ­ÓÉÈÔȻδ֪£¬£¬£¬£¬ £¬£¬£¬Ò²Î´½â¾ö¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/google-chrome-updates-failing-on-android-devices-in-russia/


4¡¢Windows 5Ô·ݵĸüпÉÄܻᵼÖÂADÉí·ÝÑé֤ʧ°Ü

¾Ý5ÔÂ12ÈÕ±¨µÀ£¬£¬£¬£¬ £¬£¬£¬Î¢ÈíÕýÔÚÊÓ²ì2022Äê5ÔµÄÖܶþ²¹¶¡µ¼ÖµÄWindowsЧÀÍÉí·ÝÑé֤ʧ°ÜµÄÎÊÌâ¡£¡£¡£¡£Óû§³ÆËûÃÇÔÚ×°ÖøüкóÊÕµ½Á˹ýʧÐÂÎÅ¡°ÓÉÓÚÓû§Æ¾Ö¤²»Æ¥Å䣬£¬£¬£¬ £¬£¬£¬Éí·ÝÑé֤ʧ°Ü¡£¡£¡£¡£ÌṩµÄÓû§ÃûδӳÉäµ½ÏÖÓÐÕÊ»§»òÃÜÂ벻׼ȷ¡£¡£¡£¡£¡±Î¢ÈíÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬Ö»ÓÐÔÚÓÃ×÷Óò¿ØÖÆÆ÷µÄЧÀÍÆ÷ÉÏ×°Öøüкó²Å»á´¥·¢ÎÊÌ⣬£¬£¬£¬ £¬£¬£¬´ËÉí·ÝÑéÖ¤ÎÊÌâÊÇÓÉÐÞ¸´ÁËWindows KerberosºÍActive DirectoryÓòЧÀÍÖеÄÁ½¸öÌáȨÎó²î£¨CVE-2022-26931ºÍCVE-2022-26923£©ÒýÆðµÄ¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-may-windows-updates-cause-ad-authentication-failures/


5¡¢Î¢Èí·¢Ã÷Sysrv-KʹÓöà¸öÐÂÎó²î×°ÖöñÒâ¿ó¹¤µÄ»î¶¯


ýÌå5ÔÂ13Èճƣ¬£¬£¬£¬ £¬£¬£¬Î¢Èí·¢Ã÷½©Ê¬ÍøÂç±äÌåSysrv-KÕýÔÚʹÓÃеÄÎó²î£¬£¬£¬£¬ £¬£¬£¬ÔÚWindowsºÍLinuxЧÀÍÆ÷ÉÏ×°ÖüÓÃܶñÒâÈí¼þ¡£¡£¡£¡£´Ë´ÎʹÓõÄÎó²î¾ùÒѱ»ÐÞ¸´£¬£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨WordPress²å¼þÖеÄCVE-2022-22947µÈ½ÏеÄÎó²î£¬£¬£¬£¬ £¬£¬£¬ÒÔ¼°Spring Cloud Gateway¿âÖеĴúÂë×¢ÈëÎó²î£¨CVE-2022-22947£©¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬ £¬£¬£¬Sysrv-K±äÌ廹ÔöÌíÁËй¦Ð§£¬£¬£¬£¬ £¬£¬£¬ÀýÈçɨÃèWordPressÉèÖÃÎļþ¼°Æä±¸·ÝÒÔÇÔÈ¡Êý¾Ý¿âƾ֤£¬£¬£¬£¬ £¬£¬£¬ÓÃÓÚ½ÓÊÜÍøÂçЧÀÍÆ÷¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/microsoft-sysrv-botnet-targets-windows-linux-servers-with-new-exploits/


6¡¢SecureworksÅû¶COBALT MIRAGEÕë¶Ô¶à¹úµÄ¹¥»÷»î¶¯


5ÔÂ12ÈÕ£¬£¬£¬£¬ £¬£¬£¬SecureworksÐû²¼±¨¸æÅû¶ÁËCOBALT MIRAGEÍÅ»ï½üÆÚ¹¥»÷»î¶¯µÄϸ½Ú¡£¡£¡£¡£¸ÃÍÅ»ï´Ó2020Äê6ÔÂ×îÏÈ»îÔ¾£¬£¬£¬£¬ £¬£¬£¬ÓëÒÁÀÊCOBALT ILLUSION£¨ÓÖ³ÆAPT35£©ÓйØÁª£¬£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÒÔÉ«ÁС¢ÃÀ¹ú¡¢Å·Ö޺ͰĴóÀûÑÇ¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ £¬£¬£¬¹¥»÷ÕßʹÓÃÁËÁ½ÖÖ²î±ðµÄÈëÇÖ·½·¨£¬£¬£¬£¬ £¬£¬£¬ÆäÖÐÒ»ÖÖʹÓÃBitLockerºÍDiskCryptor¾ÙÐÐÀÕË÷¹¥»÷£¬£¬£¬£¬ £¬£¬£¬ÒÔ»ñÈ¡¾­¼ÃÀûÒæ£» £»£»£»£»£»ÁíÒ»ÖÖ¸ü¾ßÕë¶ÔÐÔ£¬£¬£¬£¬ £¬£¬£¬Ö÷ҪĿµÄÊÇ»ñÈ¡»á¼ûȨÏÞºÍÍøÂçÇ鱨£¬£¬£¬£¬ £¬£¬£¬µ«ÓÐʱҲ»áʹÓÃÀÕË÷Èí¼þ¡£¡£¡£¡£


https://www.secureworks.com/blog/cobalt-mirage-conducts-ransomware-operations-in-us