CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬£¬ £¬£¬£¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ

Ðû²¼Ê±¼ä 2024-11-28

1. CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬£¬ £¬£¬£¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ


11ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬»¥ÁªÍø»ù´¡ÉèÊ©¾ÞÍ·CloudflareÔÚ11ÔÂ14ÈÕÔâÓöÁËÒ»´ÎÑÏÖØµÄЧÀÍÖÐÖ¹£¬£¬£¬ £¬£¬£¬µ¼ÖÂÁè¼ÝÒ»°ëµÄÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ¡£¡£¡£ ¡£¡£´Ë´ÎʹÊÔ´ÓÚÒ»´ÎÈí¼þ¸üзºÆð¹ÊÕÏ£¬£¬£¬ £¬£¬£¬Ê¹CloudflareµÄÈÕ־ЧÀÍ̱»¾3.5Сʱ£¬£¬£¬ £¬£¬£¬ÎÞ·¨Îª¿Í»§ÌṩҪº¦Êý¾Ý¡£¡£¡£ ¡£¡£ÈÕ־ЧÀͶÔÍøÂçÔËÓªÖÁ¹ØÖ÷Òª£¬£¬£¬ £¬£¬£¬Äܹ»×ÊÖúÆóÒµÆÊÎöÁ÷Á¿Ä£Ê½¡¢½â¾öÎÊÌâ²¢¼ì²â¶ñÒâ»î¶¯¡£¡£¡£ ¡£¡£¶øCloudflareµÄÈÕ־ЧÀÍÒÀÀµÃûΪLogpushµÄ¹¤¾ßÀ´´¦Öóͷ£²¢×ª´ï´ó×ÚÊý¾Ý¡£¡£¡£ ¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬ £¬£¬£¬µ±ÈÕµÄLogpush¸üÐÂÖб£´æÑÏÖØ¹ýʧ£¬£¬£¬ £¬£¬£¬µ¼ÖÂÍøÂçµ½µÄÈÕ־δ±»×¼È·×ª·¢²¢×îÖÕ±»ÓÀÊÀɾ³ý¡£¡£¡£ ¡£¡£CloudflareÔÚ±¨¸æÖÐÖ¸³ö£¬£¬£¬ £¬£¬£¬¹ýʧÉèÖõ¼ÖÂÁËϵͳµÄ¼¶Áª¹ýÔØ£¬£¬£¬ £¬£¬£¬ÈôÊÇÄܹ»×¼È·ÉèÖ㬣¬£¬ £¬£¬£¬¼´¿É×èÖ¹ÈÕ־ɥʧ¡£¡£¡£ ¡£¡£Ö»¹Ü¹¤³ÌʦѸËÙ·¢Ã÷ÎÊÌâ²¢»Ø¹öÁ˸üУ¬£¬£¬ £¬£¬£¬µ«´Ë¾ÙÒý·¢ÁËÁ¬Ëø¹ÊÕÏ£¬£¬£¬ £¬£¬£¬´ó×ÚÈÕÖ¾Êý¾ÝÓ¿Èëϵͳ£¬£¬£¬ £¬£¬£¬°üÀ¨Î´ÉèÖÃLogpushµÄÓû§Êý¾Ý£¬£¬£¬ £¬£¬£¬¼Ó¾çÁËÎÊÌâ¡£¡£¡£ ¡£¡£CloudflareÒѶԴ˴ÎÊÂÎñºÍÊý¾ÝɥʧÖÂǸ£¬£¬£¬ £¬£¬£¬²¢ÔÊÐíÖÆ¶©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñÔٴα¬·¢£¬£¬£¬ £¬£¬£¬µ«ÏÖÔÚÕâЩ²½·¥ÈÔÔÚÖÆ¶©ÖС£¡£¡£ ¡£¡£


https://securityonline.info/cloudflare-logs-suffer-critical-failure-losing-55-of-user-data/


2. ÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þ¹¥»÷MagentoÍøÕ¾


11ÔÂ28ÈÕ£¬£¬£¬ £¬£¬£¬½üÆÚ£¬£¬£¬ £¬£¬£¬Ò»ÖÖÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þÕë¶Ô Magento µç×ÓÉÌÎñÍøÕ¾Ìᳫ¹¥»÷£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þÄÜÔÚ½áÕËÒ³Ãæ¶¯Ì¬ÇÔÈ¡¸¶¿îÐÅÏ¢¡£¡£¡£ ¡£¡£ÕâÒ»·¢Ã÷ÓÉÍøÂçÇå¾²¹«Ë¾ Sucuri µÄÑо¿Ö°Ô± Weston Henry ÔÚÐþÉ«ÐÇÆÚÎåǰϦ½ÒÆÆ¡£¡£¡£ ¡£¡£¶ñÒâÈí¼þÒÔ JavaScript ×¢ÈëÐÎʽ±£´æ£¬£¬£¬ £¬£¬£¬¾ßÓжà¸ö±äÌ壬£¬£¬ £¬£¬£¬Í¨¹ý½¨ÉèÐéαÐÅÓÿ¨±íµ¥»òÖ±½ÓÌáȡ֧¸¶×Ö¶ÎÊý¾ÝÁ½ÖÖ·½·¨ÇÔÊØÐÅÏ¢¡£¡£¡£ ¡£¡£Æä¶¯Ì¬ÒªÁìºÍ¼ÓÃÜ»úÖÆÔöÌíÁ˼ì²âÄѶÈ£¬£¬£¬ £¬£¬£¬Êý¾Ý±»¼ÓÃܺóй¶ÖÁ¹¥»÷Õß¿ØÖƵÄÔ¶³ÌЧÀÍÆ÷¡£¡£¡£ ¡£¡£Magento ÍøÕ¾ÒòÆÕ±éʹÓÃÇÒ´¦Öóͷ£Ãô¸Ð¿Í»§Êý¾Ý¶ø³ÉÎªÍøÂç·¸·¨·Ö×ÓÄ¿µÄ¡£¡£¡£ ¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬ £¬£¬£¬¶ñÒâ¾ç±¾±»Òþ²ØÔÚ XML ÎļþµÄÌØ¶¨Ö¸ÁîÄÚ£¬£¬£¬ £¬£¬£¬ÄÚÈݱ»»ìÏýÒÔ×èÖ¹±»·¢Ã÷£¬£¬£¬ £¬£¬£¬½öÔÚ°üÀ¨¡°checkout¡±¶ø²»º¬¡°cart¡±µÄ URL Ò³ÃæÉϼ¤»î£¬£¬£¬ £¬£¬£¬ÒÔÌáÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£ ¡£¡£Ëæºó£¬£¬£¬ £¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹Í¨¹ý Magento API ÍøÂçÓû§µÄÆäËûÊý¾Ý¡£¡£¡£ ¡£¡£¹¥»÷ÕßʹÓöàÖÖ·´¼ì²âÊÖÒÕÒþ²Ø»î¶¯£¬£¬£¬ £¬£¬£¬°üÀ¨½«Êý¾Ý¼ÓÃÜ¡¢±àÂ룬£¬£¬ £¬£¬£¬²¢Í¨¹ýÐűêÊÖÒÕÒþÃØ´«ÊäÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£ ¡£¡£Îª±£»£» £»£»£»£»¤µç×ÓÉÌÎñÍøÕ¾ÃâÊÜ´ËÀ๥»÷£¬£¬£¬ £¬£¬£¬Sucuri¸ø³öÁËÏà¹Ø½¨Òé¡£¡£¡£ ¡£¡£


https://www.darkreading.com/application-security/sneaky-skimmer-malware-magento-sites-black-friday


3. »ô²©¿ÏÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬Õþ¸®°ì¹«Êҹرղ¢Ô¤¾¯Ð§ÀÍÖÐÖ¹


11ÔÂ28ÈÕ£¬£¬£¬ £¬£¬£¬»ô²©¿ÏÊÐÔÚ27ÈÕÆÆÏþÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬µ¼ÖÂÕþ¸®°ì¹«ÊÒ±»ÆÈ¹Ø±Õ£¬£¬£¬ £¬£¬£¬²¢Òý·¢ÁËһϵÁÐЧÀͺͻµÄÖÐÖ¹¡£¡£¡£ ¡£¡£¹ÙÔ±ÃÇѸËÙͨ¹ýÊÐÕþ¸®ÍøÕ¾ºÍÉ罻ýÌåÏòÍâµØ×¡Ãñ·¢³öÖÒÑÔ£¬£¬£¬ £¬£¬£¬Ö¸³ö¸Ð¶÷½Ú¼ÙÆÚǰϦ½«·ºÆðÍ£µçºÍЧÀÍÖÐÖ¹µÄÇéÐΡ£¡£¡£ ¡£¡£ÊÐÕþÌü¡¢ÊÐÕþ·¨ÔººÍ½ÖµÀÇåɨÊÂÇé±»×÷·Ï£¬£¬£¬ £¬£¬£¬µ«Í£³µÖ´·¨ÊÂÇéÈÔÔÚ¼ÌÐø¡£¡£¡£ ¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬ £¬£¬£¬À¬»øÍøÂçºÍÓéÀֻÈÔ°´ÍýÏë¾ÙÐС£¡£¡£ ¡£¡£»£» £»£»£»£»ô²©¿Ï¾¯Ô±¾ÖÕýÔÚÓëÊÐÕþ¸®ºÍIT²¿·ÖÏàÖú£¬£¬£¬ £¬£¬£¬ÊÓ²ì´Ë´ÎÏ®»÷ÊÂÎñ£¬£¬£¬ £¬£¬£¬²¢Ñ°ÕÒ×î¼ÑµÄÇå¾²»Ö¸´Ð§ÀÍÒªÁì¡£¡£¡£ ¡£¡£ÏÖÔÚÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÈϿɶԴ˴ι¥»÷ÈÏÕæ¡£¡£¡£ ¡£¡£»£» £»£»£»£»ô²©¿ÏÊÐ×÷ΪÐÂÔóÎ÷ÖݵÄÒ»¸öÖ÷Òª¶¼»á£¬£¬£¬ £¬£¬£¬½üÄêÀ´¸ÃÖÝÒÑÓжàËù»ú¹¹ÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬ £¬£¬£¬°üÀ¨ÐÂÔóÎ÷¶¼»á´óѧÔÚ7ÔÂÔâµ½µÄRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷¡£¡£¡£ ¡£¡£


https://therecord.media/hoboken-closes-city-hall-ransomware


4. GodLoader¶ñÒâÈí¼þʹÓÃGodotÓÎÏ·ÒýÇæÌӱܼì²âѬȾÉÏÍòϵͳ


11ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬ºÚ¿ÍʹÓÃеÄGodLoader¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬Í¨¹ýÆÕ±éʹÓõÄGodotÓÎÏ·ÒýÇæµÄ¹¦Ð§À´Ìӱܼì²âϵͳ£¬£¬£¬ £¬£¬£¬²¢Ôڶ̶ÌÈý¸öÔÂÄÚѬȾÁËÁè¼Ý17,000¸öϵͳ¡£¡£¡£ ¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»¹¥»÷ËùÓÐÖ÷Ҫƽ̨µÄÓÎÏ·Íæ¼Ò£¬£¬£¬ £¬£¬£¬²¢Ê¹ÓÃGodotµÄÎÞаÐÔºÍGDScript¾ç±¾ÓïÑÔ¹¦Ð§Ö´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£Ò»µ©¼ÓÔØ£¬£¬£¬ £¬£¬£¬¶ñÒâÎļþ¾Í»áÔÚÊܺ¦Õß×°±¸ÉÏ´¥·¢¶ñÒâ´úÂ룬£¬£¬ £¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÇÔȡƾ֤»òÏÂÔØÆäËûÓÐÓøºÔØ£¬£¬£¬ £¬£¬£¬ÈçXMRig¼ÓÃÜÍÚ¿ó³ÌÐò¡£¡£¡£ ¡£¡£¹¥»÷Õßͨ¹ýStargazers Ghost NetworkÈö²¥GodLoader£¬£¬£¬ £¬£¬£¬ÕâÊÇÒ»ÖÖ¶ñÒâÈí¼þ·Ö·¢¼´Ð§ÀÍ£¨DaaS£©£¬£¬£¬ £¬£¬£¬Ê¹Óÿ´ËÆÕýµ±µÄGitHub´æ´¢¿âÑÚÊÎÆä»î¶¯¡£¡£¡£ ¡£¡£ÔÚÕû¸ö¹¥»÷»î¶¯ÖУ¬£¬£¬ £¬£¬£¬Check Point¼ì²âµ½Á˶ನÕë¶Ô¿ª·¢Ö°Ô±ºÍÓÎÏ·Íæ¼ÒµÄ×ÔÁ¦¹¥»÷¡£¡£¡£ ¡£¡£ËäȻֻ·¢Ã÷ÁËÕë¶ÔWindowsϵͳµÄGodLoaderÑù±¾£¬£¬£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±»¹¿ª·¢ÁËGDScript¿´·¨ÑéÖ¤Îó²î´úÂ룬£¬£¬ £¬£¬£¬Õ¹Ê¾Á˸öñÒâÈí¼þ¿ÉÒÔÇáËɹ¥»÷LinuxºÍmacOSϵͳ¡£¡£¡£ ¡£¡£Godot Engineά»¤ÕßÌåÏÖ£¬£¬£¬ £¬£¬£¬¸ÃÎó²î²¢·ÇGodotËùÌØÓУ¬£¬£¬ £¬£¬£¬ÃãÀøÈËÃÇÖ»Ö´ÐÐÀ´×Ô¿ÉÐÅȪԴµÄÈí¼þ¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/new-godloader-malware-infects-thousands-of-gamers-using-godot-scripts/


5. ProjectSendÉí·ÝÑéÖ¤Îó²îÖÂЧÀÍÆ÷ÃæÁÙÔ¶³Ì»á¼ûÍþв


11ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬ÍþвÐÐΪÕßÕýÔÚʹÓÃProjectSendÖеÄÑÏÖØÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-11680£©À´»ñȡЧÀÍÆ÷µÄÔ¶³Ì»á¼ûȨÏÞ¡£¡£¡£ ¡£¡£¸ÃÎó²îÓ°ÏìProjectSend r1720֮ǰµÄ°æ±¾£¬£¬£¬ £¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇó¸ü¸ÄÓ¦ÓóÌÐòÉèÖᣡ£¡£ ¡£¡£Ö»¹Ü¸ÃÎó²îÒÑÓÚ2023Äê5ÔÂÐÞ¸´£¬£¬£¬ £¬£¬£¬µ«Ö±µ½×î½ü²Å±»·ÖÅÉCVE±àºÅ£¬£¬£¬ £¬£¬£¬µ¼ÖÂÓû§Î´ÊµÊ±¸üС£¡£¡£ ¡£¡£¾ÝVulnCheck³Æ£¬£¬£¬ £¬£¬£¬99%µÄProjectSendʵÀýÈÔÔÚÔËÐб£´æÎó²îµÄ°æ±¾¡£¡£¡£ ¡£¡£ProjectSendÊÇÒ»¸öÊ¢ÐеĿªÔ´Îļþ¹²ÏíÍøÂçÓ¦ÓóÌÐò£¬£¬£¬ £¬£¬£¬±»Ðí¶à×éÖ¯ÓÃÓÚÇå¾²¡¢Ë½ÃܵÄÎļþ´«Êä¡£¡£¡£ ¡£¡£Censys±¨¸æ³Æ£¬£¬£¬ £¬£¬£¬Ô¼ÓÐ4000¸öÔÚÏßʵÀý£¬£¬£¬ £¬£¬£¬ÆäÖдó´ó¶¼±£´æÎó²î¡£¡£¡£ ¡£¡£×Ô2024Äê9ÔÂMetasploitºÍNucleiÐû²¼¹ûÕæÎó²îʹÓÃÒÔÀ´£¬£¬£¬ £¬£¬£¬¹¥»÷»î¶¯ÓÐËùÔöÌí¡£¡£¡£ ¡£¡£VulnCheck·¢Ã÷£¬£¬£¬ £¬£¬£¬¹¥»÷Õß²»µ«Ê¹ÓÃÎó²î»ñȡδ¾­ÊÚȨµÄ»á¼û£¬£¬£¬ £¬£¬£¬»¹¸ü¸ÄϵͳÉèÖᢰ²ÅÅwebshellÒÔ¿ØÖÆÊÜѬȾЧÀÍÆ÷¡£¡£¡£ ¡£¡£GreyNoiseÁгöÁËÓë´Ë»î¶¯Ïà¹ØµÄ121¸öIP£¬£¬£¬ £¬£¬£¬Åú×¢ÕâÊÇÒ»´ÎÆÕ±éʵÑé¡£¡£¡£ ¡£¡£VulnCheckÖÒÑԳƣ¬£¬£¬ £¬£¬£¬Webshell´æ´¢ÔÚÌØ¶¨Ä¿Â¼ÖУ¬£¬£¬ £¬£¬£¬¿ÉÖ±½Óͨ¹ýÍøÂçЧÀÍÆ÷»á¼û£¬£¬£¬ £¬£¬£¬Åú×¢±£´æ×Ô¶¯¹¥»÷¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±Ç¿µ÷£¬£¬£¬ £¬£¬£¬¾¡¿ìÉý¼¶µ½ProjectSend°æ±¾r1750ÖÁ¹ØÖ÷Òª£¬£¬£¬ £¬£¬£¬ÒÔÌá·ÀÆÕ±éÈö²¥µÄ¹¥»÷¡£¡£¡£ ¡£¡£


https://www.bleepingcomputer.com/news/security/hackers-exploit-projectsend-flaw-to-backdoor-exposed-servers/


6. SL Data ServicesÊý¾Ý¿âÔâй¶£¬£¬£¬ £¬£¬£¬60ÓàÍòÃô¸ÐÎļþÆØ¹â


11ÔÂ27ÈÕ£¬£¬£¬ £¬£¬£¬¾ÝÇå¾²Ñо¿Ö°Ô±±¨µÀ£¬£¬£¬ £¬£¬£¬Êý¾Ý¾­¼Í¹«Ë¾SL Data ServicesµÄÒ»¸öδÊÜÃÜÂë±£»£» £»£»£»£»¤µÄAmazon S3´æ´¢Í°ÖУ¬£¬£¬ £¬£¬£¬Ì»Â¶ÁËÁè¼Ý600,000¸öÃô¸ÐÎļþ£¬£¬£¬ £¬£¬£¬°üÀ¨ÊýǧÈ˵폷¨ÀúÊ·¡¢Åä¾°ÊӲ졢³µÁ¾ºÍ¹¤Òµ¼Í¼µÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£ ¡£¡£ÕâЩÎļþ×ܾÞϸΪ713.1 GB£¬£¬£¬ £¬£¬£¬ÇÒδ¼ÓÃÜ¡£¡£¡£ ¡£¡£ÐÅÏ¢Ç徲ר¼ÒJeremiah FowlerÔÚ10Ô·ݷ¢Ã÷´ËÎÊÌâºó£¬£¬£¬ £¬£¬£¬¶à´Îͨ¹ýµç»°ºÍµç×ÓÓʼþÏòÊý¾ÝÍøÂ繫˾±¨¸æ£¬£¬£¬ £¬£¬£¬µ«Î´ÊÕµ½»Ø¸´¡£¡£¡£ ¡£¡£Ö»¹Ü×îÖÕ¸ÃÐÅϢЧÀÍÌṩÉ̹رÕÁËS3´æ´¢Í°£¬£¬£¬ £¬£¬£¬µ«ÒÑ̻¶µÄÐÅÏ¢¿ÉÄܻᱻÓÃÓÚÍøÂç´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷µÈ¶ñÒâÐÐΪ¡£¡£¡£ ¡£¡£SL Data ServicesÉù³ÆÌṩ¹¤Òµ±¨¸æµÈЧÀÍ£¬£¬£¬ £¬£¬£¬µ«Fowler·¢Ã÷¸Ã¹«Ë¾ËƺõÔËÓª×ÅÖÁÉÙ16¸ö²î±ðµÄÍøÕ¾£¬£¬£¬ £¬£¬£¬Ìṩ°üÀ¨·¸·¨¼Í¼¼ì²é¡¢ÎÞа³µÖÎÀí²¿·Ö¼Í¼µÈһϵÁÐÊý¾Ý¡£¡£¡£ ¡£¡£Ëû½¨Òé×é֯ʹÓÃËæ»úÇÒÉ¢ÁеÄΨһ±êʶ·ûÃüÃûÎļþ£¬£¬£¬ £¬£¬£¬²¢¼à¿Ø»á¼ûÈÕÖ¾ÒÔʶ±ðÒ쳣ģʽ£¬£¬£¬ £¬£¬£¬Í¬Ê±Ê¹ÓÃÃÜÂëºÍ¼ÓÃܱ£»£» £»£»£»£»¤Ãô¸ÐÊý¾Ý¡£¡£¡£ ¡£¡£


https://www.theregister.com/2024/11/27/600k_sensitive_files_exposed/