CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬ £¬£¬£¬£¬ £¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ

Ðû²¼Ê±¼ä 2024-11-28

1. CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬ £¬£¬£¬£¬ £¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ


11ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ £¬»¥ÁªÍø»ù´¡ÉèÊ©¾ÞÍ·CloudflareÔÚ11ÔÂ14ÈÕÔâÓöÁËÒ»´ÎÑÏÖØµÄЧÀÍÖÐÖ¹£¬£¬ £¬£¬£¬£¬ £¬µ¼ÖÂÁè¼ÝÒ»°ëµÄÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ¡£¡£¡£¡£¡£¡£´Ë´ÎʹÊÔ´ÓÚÒ»´ÎÈí¼þ¸üзºÆð¹ÊÕÏ£¬£¬ £¬£¬£¬£¬ £¬Ê¹CloudflareµÄÈÕ־ЧÀÍ̱»¾3.5Сʱ£¬£¬ £¬£¬£¬£¬ £¬ÎÞ·¨Îª¿Í»§ÌṩҪº¦Êý¾Ý¡£¡£¡£¡£¡£¡£ÈÕ־ЧÀͶÔÍøÂçÔËÓªÖÁ¹ØÖ÷Òª£¬£¬ £¬£¬£¬£¬ £¬Äܹ»×ÊÖúÆóÒµÆÊÎöÁ÷Á¿Ä£Ê½¡¢½â¾öÎÊÌâ²¢¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¡£¡£¶øCloudflareµÄÈÕ־ЧÀÍÒÀÀµÃûΪLogpushµÄ¹¤¾ßÀ´´¦Öóͷ£²¢×ª´ï´ó×ÚÊý¾Ý¡£¡£¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬ £¬£¬£¬£¬ £¬µ±ÈÕµÄLogpush¸üÐÂÖб£´æÑÏÖØ¹ýʧ£¬£¬ £¬£¬£¬£¬ £¬µ¼ÖÂÍøÂçµ½µÄÈÕ־δ±»×¼È·×ª·¢²¢×îÖÕ±»ÓÀÊÀɾ³ý¡£¡£¡£¡£¡£¡£CloudflareÔÚ±¨¸æÖÐÖ¸³ö£¬£¬ £¬£¬£¬£¬ £¬¹ýʧÉèÖõ¼ÖÂÁËϵͳµÄ¼¶Áª¹ýÔØ£¬£¬ £¬£¬£¬£¬ £¬ÈôÊÇÄܹ»×¼È·ÉèÖ㬣¬ £¬£¬£¬£¬ £¬¼´¿É×èÖ¹ÈÕ־ɥʧ¡£¡£¡£¡£¡£¡£Ö»¹Ü¹¤³ÌʦѸËÙ·¢Ã÷ÎÊÌâ²¢»Ø¹öÁ˸üУ¬£¬ £¬£¬£¬£¬ £¬µ«´Ë¾ÙÒý·¢ÁËÁ¬Ëø¹ÊÕÏ£¬£¬ £¬£¬£¬£¬ £¬´ó×ÚÈÕÖ¾Êý¾ÝÓ¿Èëϵͳ£¬£¬ £¬£¬£¬£¬ £¬°üÀ¨Î´ÉèÖÃLogpushµÄÓû§Êý¾Ý£¬£¬ £¬£¬£¬£¬ £¬¼Ó¾çÁËÎÊÌâ¡£¡£¡£¡£¡£¡£CloudflareÒѶԴ˴ÎÊÂÎñºÍÊý¾ÝɥʧÖÂǸ£¬£¬ £¬£¬£¬£¬ £¬²¢ÔÊÐíÖÆ¶©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñÔٴα¬·¢£¬£¬ £¬£¬£¬£¬ £¬µ«ÏÖÔÚÕâЩ²½·¥ÈÔÔÚÖÆ¶©ÖС£¡£¡£¡£¡£¡£


https://securityonline.info/cloudflare-logs-suffer-critical-failure-losing-55-of-user-data/


2. ÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þ¹¥»÷MagentoÍøÕ¾


11ÔÂ28ÈÕ£¬£¬ £¬£¬£¬£¬ £¬½üÆÚ£¬£¬ £¬£¬£¬£¬ £¬Ò»ÖÖÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þÕë¶Ô Magento µç×ÓÉÌÎñÍøÕ¾Ìᳫ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þÄÜÔÚ½áÕËÒ³Ãæ¶¯Ì¬ÇÔÈ¡¸¶¿îÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâÒ»·¢Ã÷ÓÉÍøÂçÇå¾²¹«Ë¾ Sucuri µÄÑо¿Ö°Ô± Weston Henry ÔÚÐþÉ«ÐÇÆÚÎåǰϦ½ÒÆÆ¡£¡£¡£¡£¡£¡£¶ñÒâÈí¼þÒÔ JavaScript ×¢ÈëÐÎʽ±£´æ£¬£¬ £¬£¬£¬£¬ £¬¾ßÓжà¸ö±äÌ壬£¬ £¬£¬£¬£¬ £¬Í¨¹ý½¨ÉèÐéαÐÅÓÿ¨±íµ¥»òÖ±½ÓÌáȡ֧¸¶×Ö¶ÎÊý¾ÝÁ½ÖÖ·½·¨ÇÔÊØÐÅÏ¢¡£¡£¡£¡£¡£¡£Æä¶¯Ì¬ÒªÁìºÍ¼ÓÃÜ»úÖÆÔöÌíÁ˼ì²âÄѶÈ£¬£¬ £¬£¬£¬£¬ £¬Êý¾Ý±»¼ÓÃܺóй¶ÖÁ¹¥»÷Õß¿ØÖƵÄÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Magento ÍøÕ¾ÒòÆÕ±éʹÓÃÇÒ´¦Öóͷ£Ãô¸Ð¿Í»§Êý¾Ý¶ø³ÉÎªÍøÂç·¸·¨·Ö×ÓÄ¿µÄ¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬ £¬£¬£¬£¬ £¬¶ñÒâ¾ç±¾±»Òþ²ØÔÚ XML ÎļþµÄÌØ¶¨Ö¸ÁîÄÚ£¬£¬ £¬£¬£¬£¬ £¬ÄÚÈݱ»»ìÏýÒÔ×èÖ¹±»·¢Ã÷£¬£¬ £¬£¬£¬£¬ £¬½öÔÚ°üÀ¨¡°checkout¡±¶ø²»º¬¡°cart¡±µÄ URL Ò³ÃæÉϼ¤»î£¬£¬ £¬£¬£¬£¬ £¬ÒÔÌáÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£Ëæºó£¬£¬ £¬£¬£¬£¬ £¬¸Ã¶ñÒâÈí¼þ»¹Í¨¹ý Magento API ÍøÂçÓû§µÄÆäËûÊý¾Ý¡£¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓöàÖÖ·´¼ì²âÊÖÒÕÒþ²Ø»î¶¯£¬£¬ £¬£¬£¬£¬ £¬°üÀ¨½«Êý¾Ý¼ÓÃÜ¡¢±àÂ룬£¬ £¬£¬£¬£¬ £¬²¢Í¨¹ýÐűêÊÖÒÕÒþÃØ´«ÊäÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Îª±£»£»£»£»£» £»¤µç×ÓÉÌÎñÍøÕ¾ÃâÊÜ´ËÀ๥»÷£¬£¬ £¬£¬£¬£¬ £¬Sucuri¸ø³öÁËÏà¹Ø½¨Òé¡£¡£¡£¡£¡£¡£


https://www.darkreading.com/application-security/sneaky-skimmer-malware-magento-sites-black-friday


3. »ô²©¿ÏÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬Õþ¸®°ì¹«Êҹرղ¢Ô¤¾¯Ð§ÀÍÖÐÖ¹


11ÔÂ28ÈÕ£¬£¬ £¬£¬£¬£¬ £¬»ô²©¿ÏÊÐÔÚ27ÈÕÆÆÏþÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬µ¼ÖÂÕþ¸®°ì¹«ÊÒ±»ÆÈ¹Ø±Õ£¬£¬ £¬£¬£¬£¬ £¬²¢Òý·¢ÁËһϵÁÐЧÀͺͻµÄÖÐÖ¹¡£¡£¡£¡£¡£¡£¹ÙÔ±ÃÇѸËÙͨ¹ýÊÐÕþ¸®ÍøÕ¾ºÍÉ罻ýÌåÏòÍâµØ×¡Ãñ·¢³öÖÒÑÔ£¬£¬ £¬£¬£¬£¬ £¬Ö¸³ö¸Ð¶÷½Ú¼ÙÆÚǰϦ½«·ºÆðÍ£µçºÍЧÀÍÖÐÖ¹µÄÇéÐΡ£¡£¡£¡£¡£¡£ÊÐÕþÌü¡¢ÊÐÕþ·¨ÔººÍ½ÖµÀÇåɨÊÂÇé±»×÷·Ï£¬£¬ £¬£¬£¬£¬ £¬µ«Í£³µÖ´·¨ÊÂÇéÈÔÔÚ¼ÌÐø¡£¡£¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬ £¬£¬£¬£¬ £¬À¬»øÍøÂçºÍÓéÀֻÈÔ°´ÍýÏë¾ÙÐС£¡£¡£¡£¡£¡£»£»£»£»£» £»ô²©¿Ï¾¯Ô±¾ÖÕýÔÚÓëÊÐÕþ¸®ºÍIT²¿·ÖÏàÖú£¬£¬ £¬£¬£¬£¬ £¬ÊÓ²ì´Ë´ÎÏ®»÷ÊÂÎñ£¬£¬ £¬£¬£¬£¬ £¬²¢Ñ°ÕÒ×î¼ÑµÄÇå¾²»Ö¸´Ð§ÀÍÒªÁì¡£¡£¡£¡£¡£¡£ÏÖÔÚÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÈϿɶԴ˴ι¥»÷ÈÏÕæ¡£¡£¡£¡£¡£¡£»£»£»£»£» £»ô²©¿ÏÊÐ×÷ΪÐÂÔóÎ÷ÖݵÄÒ»¸öÖ÷Òª¶¼»á£¬£¬ £¬£¬£¬£¬ £¬½üÄêÀ´¸ÃÖÝÒÑÓжàËù»ú¹¹ÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬£¬ £¬°üÀ¨ÐÂÔóÎ÷¶¼»á´óѧÔÚ7ÔÂÔâµ½µÄRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷¡£¡£¡£¡£¡£¡£


https://therecord.media/hoboken-closes-city-hall-ransomware


4. GodLoader¶ñÒâÈí¼þʹÓÃGodotÓÎÏ·ÒýÇæÌӱܼì²âѬȾÉÏÍòϵͳ


11ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ £¬ºÚ¿ÍʹÓÃеÄGodLoader¶ñÒâÈí¼þ£¬£¬ £¬£¬£¬£¬ £¬Í¨¹ýÆÕ±éʹÓõÄGodotÓÎÏ·ÒýÇæµÄ¹¦Ð§À´Ìӱܼì²âϵͳ£¬£¬ £¬£¬£¬£¬ £¬²¢Ôڶ̶ÌÈý¸öÔÂÄÚѬȾÁËÁè¼Ý17,000¸öϵͳ¡£¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»¹¥»÷ËùÓÐÖ÷Ҫƽ̨µÄÓÎÏ·Íæ¼Ò£¬£¬ £¬£¬£¬£¬ £¬²¢Ê¹ÓÃGodotµÄÎÞаÐÔºÍGDScript¾ç±¾ÓïÑÔ¹¦Ð§Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£Ò»µ©¼ÓÔØ£¬£¬ £¬£¬£¬£¬ £¬¶ñÒâÎļþ¾Í»áÔÚÊܺ¦Õß×°±¸ÉÏ´¥·¢¶ñÒâ´úÂ룬£¬ £¬£¬£¬£¬ £¬Ê¹¹¥»÷ÕßÄܹ»ÇÔȡƾ֤»òÏÂÔØÆäËûÓÐÓøºÔØ£¬£¬ £¬£¬£¬£¬ £¬ÈçXMRig¼ÓÃÜÍÚ¿ó³ÌÐò¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ýStargazers Ghost NetworkÈö²¥GodLoader£¬£¬ £¬£¬£¬£¬ £¬ÕâÊÇÒ»ÖÖ¶ñÒâÈí¼þ·Ö·¢¼´Ð§ÀÍ£¨DaaS£©£¬£¬ £¬£¬£¬£¬ £¬Ê¹Óÿ´ËÆÕýµ±µÄGitHub´æ´¢¿âÑÚÊÎÆä»î¶¯¡£¡£¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷»î¶¯ÖУ¬£¬ £¬£¬£¬£¬ £¬Check Point¼ì²âµ½Á˶ನÕë¶Ô¿ª·¢Ö°Ô±ºÍÓÎÏ·Íæ¼ÒµÄ×ÔÁ¦¹¥»÷¡£¡£¡£¡£¡£¡£ËäȻֻ·¢Ã÷ÁËÕë¶ÔWindowsϵͳµÄGodLoaderÑù±¾£¬£¬ £¬£¬£¬£¬ £¬µ«Ñо¿Ö°Ô±»¹¿ª·¢ÁËGDScript¿´·¨ÑéÖ¤Îó²î´úÂ룬£¬ £¬£¬£¬£¬ £¬Õ¹Ê¾Á˸öñÒâÈí¼þ¿ÉÒÔÇáËɹ¥»÷LinuxºÍmacOSϵͳ¡£¡£¡£¡£¡£¡£Godot Engineά»¤ÕßÌåÏÖ£¬£¬ £¬£¬£¬£¬ £¬¸ÃÎó²î²¢·ÇGodotËùÌØÓУ¬£¬ £¬£¬£¬£¬ £¬ÃãÀøÈËÃÇÖ»Ö´ÐÐÀ´×Ô¿ÉÐÅȪԴµÄÈí¼þ¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/new-godloader-malware-infects-thousands-of-gamers-using-godot-scripts/


5. ProjectSendÉí·ÝÑéÖ¤Îó²îÖÂЧÀÍÆ÷ÃæÁÙÔ¶³Ì»á¼ûÍþв


11ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ £¬ÍþвÐÐΪÕßÕýÔÚʹÓÃProjectSendÖеÄÑÏÖØÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-11680£©À´»ñȡЧÀÍÆ÷µÄÔ¶³Ì»á¼ûȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìProjectSend r1720֮ǰµÄ°æ±¾£¬£¬ £¬£¬£¬£¬ £¬ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇó¸ü¸ÄÓ¦ÓóÌÐòÉèÖᣡ£¡£¡£¡£¡£Ö»¹Ü¸ÃÎó²îÒÑÓÚ2023Äê5ÔÂÐÞ¸´£¬£¬ £¬£¬£¬£¬ £¬µ«Ö±µ½×î½ü²Å±»·ÖÅÉCVE±àºÅ£¬£¬ £¬£¬£¬£¬ £¬µ¼ÖÂÓû§Î´ÊµÊ±¸üС£¡£¡£¡£¡£¡£¾ÝVulnCheck³Æ£¬£¬ £¬£¬£¬£¬ £¬99%µÄProjectSendʵÀýÈÔÔÚÔËÐб£´æÎó²îµÄ°æ±¾¡£¡£¡£¡£¡£¡£ProjectSendÊÇÒ»¸öÊ¢ÐеĿªÔ´Îļþ¹²ÏíÍøÂçÓ¦ÓóÌÐò£¬£¬ £¬£¬£¬£¬ £¬±»Ðí¶à×éÖ¯ÓÃÓÚÇå¾²¡¢Ë½ÃܵÄÎļþ´«Êä¡£¡£¡£¡£¡£¡£Censys±¨¸æ³Æ£¬£¬ £¬£¬£¬£¬ £¬Ô¼ÓÐ4000¸öÔÚÏßʵÀý£¬£¬ £¬£¬£¬£¬ £¬ÆäÖдó´ó¶¼±£´æÎó²î¡£¡£¡£¡£¡£¡£×Ô2024Äê9ÔÂMetasploitºÍNucleiÐû²¼¹ûÕæÎó²îʹÓÃÒÔÀ´£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷»î¶¯ÓÐËùÔöÌí¡£¡£¡£¡£¡£¡£VulnCheck·¢Ã÷£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õß²»µ«Ê¹ÓÃÎó²î»ñȡδ¾­ÊÚȨµÄ»á¼û£¬£¬ £¬£¬£¬£¬ £¬»¹¸ü¸ÄϵͳÉèÖᢰ²ÅÅwebshellÒÔ¿ØÖÆÊÜѬȾЧÀÍÆ÷¡£¡£¡£¡£¡£¡£GreyNoiseÁгöÁËÓë´Ë»î¶¯Ïà¹ØµÄ121¸öIP£¬£¬ £¬£¬£¬£¬ £¬Åú×¢ÕâÊÇÒ»´ÎÆÕ±éʵÑé¡£¡£¡£¡£¡£¡£VulnCheckÖÒÑԳƣ¬£¬ £¬£¬£¬£¬ £¬Webshell´æ´¢ÔÚÌØ¶¨Ä¿Â¼ÖУ¬£¬ £¬£¬£¬£¬ £¬¿ÉÖ±½Óͨ¹ýÍøÂçЧÀÍÆ÷»á¼û£¬£¬ £¬£¬£¬£¬ £¬Åú×¢±£´æ×Ô¶¯¹¥»÷¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Ç¿µ÷£¬£¬ £¬£¬£¬£¬ £¬¾¡¿ìÉý¼¶µ½ProjectSend°æ±¾r1750ÖÁ¹ØÖ÷Òª£¬£¬ £¬£¬£¬£¬ £¬ÒÔÌá·ÀÆÕ±éÈö²¥µÄ¹¥»÷¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-projectsend-flaw-to-backdoor-exposed-servers/


6. SL Data ServicesÊý¾Ý¿âÔâй¶£¬£¬ £¬£¬£¬£¬ £¬60ÓàÍòÃô¸ÐÎļþÆØ¹â


11ÔÂ27ÈÕ£¬£¬ £¬£¬£¬£¬ £¬¾ÝÇå¾²Ñо¿Ö°Ô±±¨µÀ£¬£¬ £¬£¬£¬£¬ £¬Êý¾Ý¾­¼Í¹«Ë¾SL Data ServicesµÄÒ»¸öδÊÜÃÜÂë±£»£»£»£»£» £»¤µÄAmazon S3´æ´¢Í°ÖУ¬£¬ £¬£¬£¬£¬ £¬Ì»Â¶ÁËÁè¼Ý600,000¸öÃô¸ÐÎļþ£¬£¬ £¬£¬£¬£¬ £¬°üÀ¨ÊýǧÈ˵폷¨ÀúÊ·¡¢Åä¾°ÊӲ졢³µÁ¾ºÍ¹¤Òµ¼Í¼µÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£ÕâЩÎļþ×ܾÞϸΪ713.1 GB£¬£¬ £¬£¬£¬£¬ £¬ÇÒδ¼ÓÃÜ¡£¡£¡£¡£¡£¡£ÐÅÏ¢Ç徲ר¼ÒJeremiah FowlerÔÚ10Ô·ݷ¢Ã÷´ËÎÊÌâºó£¬£¬ £¬£¬£¬£¬ £¬¶à´Îͨ¹ýµç»°ºÍµç×ÓÓʼþÏòÊý¾ÝÍøÂ繫˾±¨¸æ£¬£¬ £¬£¬£¬£¬ £¬µ«Î´ÊÕµ½»Ø¸´¡£¡£¡£¡£¡£¡£Ö»¹Ü×îÖÕ¸ÃÐÅϢЧÀÍÌṩÉ̹رÕÁËS3´æ´¢Í°£¬£¬ £¬£¬£¬£¬ £¬µ«ÒÑ̻¶µÄÐÅÏ¢¿ÉÄܻᱻÓÃÓÚÍøÂç´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷µÈ¶ñÒâÐÐΪ¡£¡£¡£¡£¡£¡£SL Data ServicesÉù³ÆÌṩ¹¤Òµ±¨¸æµÈЧÀÍ£¬£¬ £¬£¬£¬£¬ £¬µ«Fowler·¢Ã÷¸Ã¹«Ë¾ËƺõÔËÓª×ÅÖÁÉÙ16¸ö²î±ðµÄÍøÕ¾£¬£¬ £¬£¬£¬£¬ £¬Ìṩ°üÀ¨·¸·¨¼Í¼¼ì²é¡¢ÎÞа³µÖÎÀí²¿·Ö¼Í¼µÈһϵÁÐÊý¾Ý¡£¡£¡£¡£¡£¡£Ëû½¨Òé×é֯ʹÓÃËæ»úÇÒÉ¢ÁеÄΨһ±êʶ·ûÃüÃûÎļþ£¬£¬ £¬£¬£¬£¬ £¬²¢¼à¿Ø»á¼ûÈÕÖ¾ÒÔʶ±ðÒ쳣ģʽ£¬£¬ £¬£¬£¬£¬ £¬Í¬Ê±Ê¹ÓÃÃÜÂëºÍ¼ÓÃܱ£»£»£»£»£» £»¤Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£


https://www.theregister.com/2024/11/27/600k_sensitive_files_exposed/