RapperBot»Ø¹éͨ¹ýÎïÁªÍø×°±¸DDoS¹¥»÷ÓÎϷЧÀÍÆ÷

Ðû²¼Ê±¼ä 2022-11-18
1¡¢RapperBot»Ø¹éͨ¹ýÎïÁªÍø×°±¸DDoS¹¥»÷ÓÎϷЧÀÍÆ÷


FortinetÔÚ11ÔÂ15ÈÕ³ÆÆä·¢Ã÷ÁËRapperBotµÄÐÂÑù±¾£¬£¬£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔÓÎϷЧÀÍÆ÷Ö´ÐÐDDoS¹¥»÷¡£ ¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÓÚÈ¥Äê8Ô±»·¢Ã÷£¬£¬£¬£¬£¬ £¬£¬ÆäʱËüʹÓÃSSH±©Á¦¹¥»÷ÔÚLinuxЧÀÍÆ÷ÉÏ·Ö·¢¡£ ¡£¡£¡£¡£¡£Í¨¹ý×·×ÙÆä»î¶¯£¬£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±·¢Ã÷RapperBot×Ô2021Äê5ÔÂÒÔÀ´Ò»Ö±ÔÚÔËÐУ¬£¬£¬£¬£¬ £¬£¬µ«ÆäÄ¿µÄºÜÊÇÄ£ºý¡£ ¡£¡£¡£¡£¡£×î½üµÄ±äÌåʹÓÃÁËTelnet×ÔÎÒÈö²¥»úÖÆ£¬£¬£¬£¬£¬ £¬£¬Õâ¸ü¿¿½üÓÚԭʼMirai¶ñÒâÈí¼þµÄÒªÁì¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬Ä¿½ñ»î¶¯µÄÄ¿µÄÔ½·¢ÏÔ×Å£¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚ×îбäÌåÖеÄDoSÏÂÁîÊÇרΪ¹¥»÷ÍйÜÔÚÏßÓÎÏ·µÄЧÀÍÆ÷¶øÉè¼Æ¡£ ¡£¡£¡£¡£¡£


https://www.fortinet.com/blog/threat-research/new-rapperbot-campaign-ddos-attacks

2¡¢Sansec³ÆÕë¶ÔMagento 2ÍøÕ¾µÄTrojanOrders¹¥»÷¼¤Ôö


¾ÝýÌå11ÔÂ16ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬Çå¾²¹«Ë¾Sansec·¢Ã÷TrojanOrders¹¥»÷»î¶¯´ó¹æÄ£¼¤Ôö£¬£¬£¬£¬£¬ £¬£¬½ü40%µÄMagento 2ÍøÕ¾Ôâµ½´ËÀ๥»÷¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬×ܽáÒÑÍù¼¸ÖܵĹ¥»÷ÊÂÎñ·¢Ã÷ÓÐ7¸ö²î±ðµÄ¹¥»÷ÔØÌ壬£¬£¬£¬£¬ £¬£¬ÕâÒâζ×ÅÏÖÔÚÖÁÉÙÓÐ7¸öºÚ¿ÍÕûÌåÔÚʵÑéÖ´ÐÐTrojanOrders¹¥»÷¡£ ¡£¡£¡£¡£¡£TrojanOrdersÊÇÒ»ÖÖʹÓÃMagento 2Îó²î£¨CVE-2022-24086£©µÄ¹¥»÷·½·¨£¬£¬£¬£¬£¬ £¬£¬¿É±»Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÓÃÀ´Ö´ÐдúÂë²¢ÔÚÍøÕ¾ÉÏ×°ÖÃRAT¡£ ¡£¡£¡£¡£¡£AdobeÔÚ2022Äê2ÔÂÐÞ¸´Á˸ÃÎó²î£¬£¬£¬£¬£¬ £¬£¬µ«Ðí¶àMagentoÍøÕ¾ÈÔδװÖò¹¶¡¡£ ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/magento-stores-targeted-in-massive-surge-of-trojanorders-attacks/

3¡¢Mitiga·¢Ã÷Êý°Ù¸öAmazon RDSʵÀýй¶Óû§µÄPIIÊý¾Ý

11ÔÂ16ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬MitigaµÄÐÂÑо¿ÏÔʾAmazon Relational Database Service(Amazon RDS)ÉϵÄÊý°Ù¸öÊý¾Ý¿âй¶ÁËÓû§µÄСÎÒ˽¼ÒÉí·ÝÐÅÏ¢¡£ ¡£¡£¡£¡£¡£Ð¹Â¶Ô´ÓÚÒ»¸öÃûΪ¹«¹²RDS¿ìÕյĹ¦Ð§£¬£¬£¬£¬£¬ £¬£¬¸Ã¹¦Ð§ÔÊÐí½¨ÉèÒ»¸öÔÚÔÆÖÐÔËÐеÄÕû¸öÊý¾Ý¿âÇéÐεı¸·Ý£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒËü¿ÉÒÔ±»ËùÓÐAWSÕË»§»á¼û¡£ ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±´Ó2022Äê9ÔÂ21ÈÕµ½10ÔÂ20ÈÕ·¢Ã÷ÁË810¸ö¹ûÕæµÄ¿ìÕÕ£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐÁè¼Ý250¸öÒѾ­Ì»Â¶ÁË30Ì죬£¬£¬£¬£¬ £¬£¬ÕâÅú×¢ËüÃǺܿÉÄܱ»ÒÅÍüÁË¡£ ¡£¡£¡£¡£¡£

https://thehackernews.com/2022/11/researchers-discover-hundreds-of-amazon.html

4¡¢F5Ðû²¼Çå¾²¸üÐÂÐÞ¸´Æä²úÆ·ÖеÄ2¸öÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¾Ý11ÔÂ16ÈÕ±¨µÀ£¬£¬£¬£¬£¬ £¬£¬Rapid7·¢Ã÷ÁËF5 BIG-IPºÍBIG-IQÖеĶà¸öÎó²î¡£ ¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÊÇͨ¹ýiControl SOAPµÄCSRFÎó²î£¨CVE-2022-41622£©£¬£¬£¬£¬£¬ £¬£¬¿Éµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£ ¡£¡£¡£¡£¡£ÒÔ¼°£¬£¬£¬£¬£¬ £¬£¬Í¨¹ýפÁôÔÚ×°±¸Ä£Ê½iControl RESTÖеÄRPM¹æ·¶×¢ÈëµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2022-41800£©£¬£¬£¬£¬£¬ £¬£¬¿ÉÓÃÀ´ÈƹýApplianceģʽÏÞÖÆ¡£ ¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬ £¬£¬F5ÒÑÐÞ¸´ÕâЩÎó²î¡£ ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬ £¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷Á˼¸¸öÈÆ¹ýÇå¾²¿ØÖƵÄÒªÁ죬£¬£¬£¬£¬ £¬£¬µ«F5²¢Î´½«Æäʶ±ðΪ¿ÉʹÓõÄÎó²î¡£ ¡£¡£¡£¡£¡£

https://securityaffairs.co/wordpress/138631/security/2-rce-f5-products.html

5¡¢Î¢ÈíÅû¶DEV-0569·Ö·¢RoyalºÍ¶à¸öpayloadµÄÐÂÒªÁì

΢ÈíÔÚ11ÔÂ17ÈÕÐû²¼±¨¸æ³Æ£¬£¬£¬£¬£¬ £¬£¬Æä½üÆÚ·¢Ã÷ÁËDEV-0569·Ö·¢¶à¸öpayloadµÄ»î¶¯£¬£¬£¬£¬£¬ £¬£¬²¢×îÖÕ×°ÖÃÀÕË÷Èí¼þRoyal¡£ ¡£¡£¡£¡£¡£DEV-0569Ö÷ÒªÒÀÀµ¶ñÒâ¹ã¸æºÍÖ¸Ïò¶ñÒâÈí¼þÏÂÔØ³ÌÐòµÄ´¹ÂÚÁ´½Ó¾ÙÐзַ¢£¬£¬£¬£¬£¬ £¬£¬ÔÚ×î½ü¼¸¸öÔÂÀ£¬£¬£¬£¬ £¬£¬Î¢Èí·¢Ã÷¸ÃÍÅ»ïµÄ·Ö·¢ÒªÁìÓÐÁ˵÷½â£ºÔÚÄ¿µÄÍøÕ¾ÉÏʹÓÃÁªÏµ±í¸ñ·Ö·¢´¹ÂÚÁ´½Ó£¬£¬£¬£¬£¬ £¬£¬ÔÚ¿´ÆðÀ´Õýµ±µÄÈí¼þÏÂÔØÍøÕ¾ºÍ×ÊÔ´¿âÉÏÍйÜαÔìµÄ×°ÖÃÎļþ£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°Ê¹ÓÃGoogle AdsÀ´À©Õ¹ËûÃǵĶñÒâ¹ã¸æÊÖÒÕ¡£ ¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹¹ûÕæÁËDEV-0569µÄTTPÒÔ¼°×éÖ¯¿ÉÒÔ½ÓÄɵķÀÓù²½·¥¡£ ¡£¡£¡£¡£¡£

https://www.microsoft.com/en-us/security/blog/2022/11/17/dev-0569-finds-new-ways-to-deliver-royal-ransomware-various-payloads/

6¡¢Unit 42Ðû²¼2022Äê5ÖÁ7ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ

11ÔÂ16ÈÕ£¬£¬£¬£¬£¬ £¬£¬Unit 42Ðû²¼ÁË2022Äê5ÖÁ7ÔÂÍøÂçÇå¾²Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£ ¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬£¬£¬£¬£¬ £¬£¬ÔÚÕâÈý¸öÔÂÖУ¬£¬£¬£¬£¬ £¬£¬¹²×¢²áÁË5976¸öеÄCVE±àºÅ£¬£¬£¬£¬£¬ £¬£¬ÆäÖÐ23.5%±»¹éÀàΪÍâµØÎó²î£¬£¬£¬£¬£¬ £¬£¬ÆäÓà76.5%ÊÇÔ¶³ÌÎó²î¡£ ¡£¡£¡£¡£¡£¿£¿£¿£¿çÕ¾¾ç±¾Îó²îÈÔÊDZ¨¸æ×î¶àµÄÎó²î£¬£¬£¬£¬£¬ £¬£¬SQL×¢ÈëÎó²îÒ²ÓÐËùÔöÌí¡£ ¡£¡£¡£¡£¡£¹¥»÷Õß¾­³£Ê¹ÓýüÆÚÅû¶µÄÎó²î£¬£¬£¬£¬£¬ £¬£¬ÓÈÆäÊÇ2021-2022ÄêµÄÎó²î¡£ ¡£¡£¡£¡£¡£°´¹¥»÷ÀàÐÍ·Ö£¬£¬£¬£¬£¬ £¬£¬×î¶àµÄÊÇÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬ £¬£¬Æä´ÎÊÇÐÅϢй¶ºÍ±éÀú¹¥»÷¡£ ¡£¡£¡£¡£¡£´ó´ó¶¼¹¥»÷ËÆºõ¶¼À´×ÔÃÀ¹ú£¬£¬£¬£¬£¬ £¬£¬Æä´ÎÊǵ¹úºÍºÉÀ¼¡£ ¡£¡£¡£¡£¡£

https://unit42.paloaltonetworks.com/network-security-trends-update/