CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬£¬£¬£¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ
Ðû²¼Ê±¼ä 2024-11-281. CloudflareÈÕ־ЧÀÍÑÏÖØÖÐÖ¹£¬£¬£¬£¬£¬³¬°ëÊýÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ
11ÔÂ27ÈÕ£¬£¬£¬£¬£¬»¥ÁªÍø»ù´¡ÉèÊ©¾ÞÍ·CloudflareÔÚ11ÔÂ14ÈÕÔâÓöÁËÒ»´ÎÑÏÖØµÄЧÀÍÖÐÖ¹£¬£¬£¬£¬£¬µ¼ÖÂÁè¼ÝÒ»°ëµÄÈÕÖ¾Êý¾ÝÓÀÊÀɥʧ¡£¡£¡£¡£´Ë´ÎʹÊÔ´ÓÚÒ»´ÎÈí¼þ¸üзºÆð¹ÊÕÏ£¬£¬£¬£¬£¬Ê¹CloudflareµÄÈÕ־ЧÀÍ̱»¾3.5Сʱ£¬£¬£¬£¬£¬ÎÞ·¨Îª¿Í»§ÌṩҪº¦Êý¾Ý¡£¡£¡£¡£ÈÕ־ЧÀͶÔÍøÂçÔËÓªÖÁ¹ØÖ÷Òª£¬£¬£¬£¬£¬Äܹ»×ÊÖúÆóÒµÆÊÎöÁ÷Á¿Ä£Ê½¡¢½â¾öÎÊÌâ²¢¼ì²â¶ñÒâ»î¶¯¡£¡£¡£¡£¶øCloudflareµÄÈÕ־ЧÀÍÒÀÀµÃûΪLogpushµÄ¹¤¾ßÀ´´¦Öóͷ£²¢×ª´ï´ó×ÚÊý¾Ý¡£¡£¡£¡£²»ÐÒµÄÊÇ£¬£¬£¬£¬£¬µ±ÈÕµÄLogpush¸üÐÂÖб£´æÑÏÖØ¹ýʧ£¬£¬£¬£¬£¬µ¼ÖÂÍøÂçµ½µÄÈÕ־δ±»×¼È·×ª·¢²¢×îÖÕ±»ÓÀÊÀɾ³ý¡£¡£¡£¡£CloudflareÔÚ±¨¸æÖÐÖ¸³ö£¬£¬£¬£¬£¬¹ýʧÉèÖõ¼ÖÂÁËϵͳµÄ¼¶Áª¹ýÔØ£¬£¬£¬£¬£¬ÈôÊÇÄܹ»×¼È·ÉèÖ㬣¬£¬£¬£¬¼´¿É×èÖ¹ÈÕ־ɥʧ¡£¡£¡£¡£Ö»¹Ü¹¤³ÌʦѸËÙ·¢Ã÷ÎÊÌâ²¢»Ø¹öÁ˸üУ¬£¬£¬£¬£¬µ«´Ë¾ÙÒý·¢ÁËÁ¬Ëø¹ÊÕÏ£¬£¬£¬£¬£¬´ó×ÚÈÕÖ¾Êý¾ÝÓ¿Èëϵͳ£¬£¬£¬£¬£¬°üÀ¨Î´ÉèÖÃLogpushµÄÓû§Êý¾Ý£¬£¬£¬£¬£¬¼Ó¾çÁËÎÊÌâ¡£¡£¡£¡£CloudflareÒѶԴ˴ÎÊÂÎñºÍÊý¾ÝɥʧÖÂǸ£¬£¬£¬£¬£¬²¢ÔÊÐíÖÆ¶©Ô¤·À²½·¥×èÖ¹ÀàËÆÊÂÎñÔٴα¬·¢£¬£¬£¬£¬£¬µ«ÏÖÔÚÕâЩ²½·¥ÈÔÔÚÖÆ¶©ÖС£¡£¡£¡£
https://securityonline.info/cloudflare-logs-suffer-critical-failure-losing-55-of-user-data/
2. ÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þ¹¥»÷MagentoÍøÕ¾
11ÔÂ28ÈÕ£¬£¬£¬£¬£¬½üÆÚ£¬£¬£¬£¬£¬Ò»ÖÖÐÂÐÍÐÅÓÿ¨µÁË¢¶ñÒâÈí¼þÕë¶Ô Magento µç×ÓÉÌÎñÍøÕ¾Ìᳫ¹¥»÷£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÄÜÔÚ½áÕËÒ³Ãæ¶¯Ì¬ÇÔÈ¡¸¶¿îÐÅÏ¢¡£¡£¡£¡£ÕâÒ»·¢Ã÷ÓÉÍøÂçÇå¾²¹«Ë¾ Sucuri µÄÑо¿Ö°Ô± Weston Henry ÔÚÐþÉ«ÐÇÆÚÎåǰϦ½ÒÆÆ¡£¡£¡£¡£¶ñÒâÈí¼þÒÔ JavaScript ×¢ÈëÐÎʽ±£´æ£¬£¬£¬£¬£¬¾ßÓжà¸ö±äÌ壬£¬£¬£¬£¬Í¨¹ý½¨ÉèÐéαÐÅÓÿ¨±íµ¥»òÖ±½ÓÌáȡ֧¸¶×Ö¶ÎÊý¾ÝÁ½ÖÖ·½·¨ÇÔÊØÐÅÏ¢¡£¡£¡£¡£Æä¶¯Ì¬ÒªÁìºÍ¼ÓÃÜ»úÖÆÔöÌíÁ˼ì²âÄѶȣ¬£¬£¬£¬£¬Êý¾Ý±»¼ÓÃܺóй¶ÖÁ¹¥»÷Õß¿ØÖƵÄÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Magento ÍøÕ¾ÒòÆÕ±éʹÓÃÇÒ´¦Öóͷ£Ãô¸Ð¿Í»§Êý¾Ý¶ø³ÉÎªÍøÂç·¸·¨·Ö×ÓÄ¿µÄ¡£¡£¡£¡£´Ë´Î¹¥»÷ÖУ¬£¬£¬£¬£¬¶ñÒâ¾ç±¾±»Òþ²ØÔÚ XML ÎļþµÄÌØ¶¨Ö¸ÁîÄÚ£¬£¬£¬£¬£¬ÄÚÈݱ»»ìÏýÒÔ×èÖ¹±»·¢Ã÷£¬£¬£¬£¬£¬½öÔÚ°üÀ¨¡°checkout¡±¶ø²»º¬¡°cart¡±µÄ URL Ò³ÃæÉϼ¤»î£¬£¬£¬£¬£¬ÒÔÌáÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£Ëæºó£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þ»¹Í¨¹ý Magento API ÍøÂçÓû§µÄÆäËûÊý¾Ý¡£¡£¡£¡£¹¥»÷ÕßʹÓöàÖÖ·´¼ì²âÊÖÒÕÒþ²Ø»î¶¯£¬£¬£¬£¬£¬°üÀ¨½«Êý¾Ý¼ÓÃÜ¡¢±àÂ룬£¬£¬£¬£¬²¢Í¨¹ýÐűêÊÖÒÕÒþÃØ´«ÊäÖÁÔ¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Îª±£»£»£»£»£»£»¤µç×ÓÉÌÎñÍøÕ¾ÃâÊÜ´ËÀ๥»÷£¬£¬£¬£¬£¬Sucuri¸ø³öÁËÏà¹Ø½¨Òé¡£¡£¡£¡£
https://www.darkreading.com/application-security/sneaky-skimmer-malware-magento-sites-black-friday
3. »ô²©¿ÏÊÐÔâÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬Õþ¸®°ì¹«Êҹرղ¢Ô¤¾¯Ð§ÀÍÖÐÖ¹
11ÔÂ28ÈÕ£¬£¬£¬£¬£¬»ô²©¿ÏÊÐÔÚ27ÈÕÆÆÏþÔâÓöÁËÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬µ¼ÖÂÕþ¸®°ì¹«ÊÒ±»ÆÈ¹Ø±Õ£¬£¬£¬£¬£¬²¢Òý·¢ÁËһϵÁÐЧÀͺͻµÄÖÐÖ¹¡£¡£¡£¡£¹ÙÔ±ÃÇѸËÙͨ¹ýÊÐÕþ¸®ÍøÕ¾ºÍÉ罻ýÌåÏòÍâµØ×¡Ãñ·¢³öÖÒÑÔ£¬£¬£¬£¬£¬Ö¸³ö¸Ð¶÷½Ú¼ÙÆÚǰϦ½«·ºÆðÍ£µçºÍЧÀÍÖÐÖ¹µÄÇéÐΡ£¡£¡£¡£ÊÐÕþÌü¡¢ÊÐÕþ·¨ÔººÍ½ÖµÀÇåɨÊÂÇé±»×÷·Ï£¬£¬£¬£¬£¬µ«Í£³µÖ´·¨ÊÂÇéÈÔÔÚ¼ÌÐø¡£¡£¡£¡£Ö»¹ÜÔÆÔÆ£¬£¬£¬£¬£¬À¬»øÍøÂçºÍÓéÀֻÈÔ°´ÍýÏë¾ÙÐС£¡£¡£¡£»£»£»£»£»£»ô²©¿Ï¾¯Ô±¾ÖÕýÔÚÓëÊÐÕþ¸®ºÍIT²¿·ÖÏàÖú£¬£¬£¬£¬£¬ÊÓ²ì´Ë´ÎÏ®»÷ÊÂÎñ£¬£¬£¬£¬£¬²¢Ñ°ÕÒ×î¼ÑµÄÇå¾²»Ö¸´Ð§ÀÍÒªÁì¡£¡£¡£¡£ÏÖÔÚÉÐδÓÐÈκÎÀÕË÷Èí¼þÍÅ»ïÈϿɶԴ˴ι¥»÷ÈÏÕæ¡£¡£¡£¡£»£»£»£»£»£»ô²©¿ÏÊÐ×÷ΪÐÂÔóÎ÷ÖݵÄÒ»¸öÖ÷Òª¶¼»á£¬£¬£¬£¬£¬½üÄêÀ´¸ÃÖÝÒÑÓжàËù»ú¹¹ÔâÊÜÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬£¬°üÀ¨ÐÂÔóÎ÷¶¼»á´óѧÔÚ7ÔÂÔâµ½µÄRhysidaÀÕË÷Èí¼þÍÅ»ïµÄ¹¥»÷¡£¡£¡£¡£
https://therecord.media/hoboken-closes-city-hall-ransomware
4. GodLoader¶ñÒâÈí¼þʹÓÃGodotÓÎÏ·ÒýÇæÌӱܼì²âѬȾÉÏÍòϵͳ
11ÔÂ27ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃеÄGodLoader¶ñÒâÈí¼þ£¬£¬£¬£¬£¬Í¨¹ýÆÕ±éʹÓõÄGodotÓÎÏ·ÒýÇæµÄ¹¦Ð§À´Ìӱܼì²âϵͳ£¬£¬£¬£¬£¬²¢Ôڶ̶ÌÈý¸öÔÂÄÚѬȾÁËÁè¼Ý17,000¸öϵͳ¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þÄܹ»¹¥»÷ËùÓÐÖ÷Ҫƽ̨µÄÓÎÏ·Íæ¼Ò£¬£¬£¬£¬£¬²¢Ê¹ÓÃGodotµÄÎÞаÐÔºÍGDScript¾ç±¾ÓïÑÔ¹¦Ð§Ö´ÐÐí§Òâ´úÂë¡£¡£¡£¡£Ò»µ©¼ÓÔØ£¬£¬£¬£¬£¬¶ñÒâÎļþ¾Í»áÔÚÊܺ¦Õß×°±¸ÉÏ´¥·¢¶ñÒâ´úÂ룬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»ÇÔȡƾ֤»òÏÂÔØÆäËûÓÐÓøºÔØ£¬£¬£¬£¬£¬ÈçXMRig¼ÓÃÜÍÚ¿ó³ÌÐò¡£¡£¡£¡£¹¥»÷Õßͨ¹ýStargazers Ghost NetworkÈö²¥GodLoader£¬£¬£¬£¬£¬ÕâÊÇÒ»ÖÖ¶ñÒâÈí¼þ·Ö·¢¼´Ð§ÀÍ£¨DaaS£©£¬£¬£¬£¬£¬Ê¹Óÿ´ËÆÕýµ±µÄGitHub´æ´¢¿âÑÚÊÎÆä»î¶¯¡£¡£¡£¡£ÔÚÕû¸ö¹¥»÷»î¶¯ÖУ¬£¬£¬£¬£¬Check Point¼ì²âµ½Á˶ನÕë¶Ô¿ª·¢Ö°Ô±ºÍÓÎÏ·Íæ¼ÒµÄ×ÔÁ¦¹¥»÷¡£¡£¡£¡£ËäȻֻ·¢Ã÷ÁËÕë¶ÔWindowsϵͳµÄGodLoaderÑù±¾£¬£¬£¬£¬£¬µ«Ñо¿Ö°Ô±»¹¿ª·¢ÁËGDScript¿´·¨ÑéÖ¤Îó²î´úÂ룬£¬£¬£¬£¬Õ¹Ê¾Á˸öñÒâÈí¼þ¿ÉÒÔÇáËɹ¥»÷LinuxºÍmacOSϵͳ¡£¡£¡£¡£Godot Engineά»¤ÕßÌåÏÖ£¬£¬£¬£¬£¬¸ÃÎó²î²¢·ÇGodotËùÌØÓУ¬£¬£¬£¬£¬ÃãÀøÈËÃÇÖ»Ö´ÐÐÀ´×Ô¿ÉÐÅȪԴµÄÈí¼þ¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/new-godloader-malware-infects-thousands-of-gamers-using-godot-scripts/
5. ProjectSendÉí·ÝÑéÖ¤Îó²îÖÂЧÀÍÆ÷ÃæÁÙÔ¶³Ì»á¼ûÍþв
11ÔÂ27ÈÕ£¬£¬£¬£¬£¬ÍþвÐÐΪÕßÕýÔÚʹÓÃProjectSendÖеÄÑÏÖØÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2024-11680£©À´»ñȡЧÀÍÆ÷µÄÔ¶³Ì»á¼ûȨÏÞ¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìProjectSend r1720֮ǰµÄ°æ±¾£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇó¸ü¸ÄÓ¦ÓóÌÐòÉèÖᣡ£¡£¡£Ö»¹Ü¸ÃÎó²îÒÑÓÚ2023Äê5ÔÂÐÞ¸´£¬£¬£¬£¬£¬µ«Ö±µ½×î½ü²Å±»·ÖÅÉCVE±àºÅ£¬£¬£¬£¬£¬µ¼ÖÂÓû§Î´ÊµÊ±¸üС£¡£¡£¡£¾ÝVulnCheck³Æ£¬£¬£¬£¬£¬99%µÄProjectSendʵÀýÈÔÔÚÔËÐб£´æÎó²îµÄ°æ±¾¡£¡£¡£¡£ProjectSendÊÇÒ»¸öÊ¢ÐеĿªÔ´Îļþ¹²ÏíÍøÂçÓ¦ÓóÌÐò£¬£¬£¬£¬£¬±»Ðí¶à×éÖ¯ÓÃÓÚÇå¾²¡¢Ë½ÃܵÄÎļþ´«Êä¡£¡£¡£¡£Censys±¨¸æ³Æ£¬£¬£¬£¬£¬Ô¼ÓÐ4000¸öÔÚÏßʵÀý£¬£¬£¬£¬£¬ÆäÖдó´ó¶¼±£´æÎó²î¡£¡£¡£¡£×Ô2024Äê9ÔÂMetasploitºÍNucleiÐû²¼¹ûÕæÎó²îʹÓÃÒÔÀ´£¬£¬£¬£¬£¬¹¥»÷»î¶¯ÓÐËùÔöÌí¡£¡£¡£¡£VulnCheck·¢Ã÷£¬£¬£¬£¬£¬¹¥»÷Õß²»µ«Ê¹ÓÃÎó²î»ñȡδ¾ÊÚȨµÄ»á¼û£¬£¬£¬£¬£¬»¹¸ü¸ÄϵͳÉèÖᢰ²ÅÅwebshellÒÔ¿ØÖÆÊÜѬȾЧÀÍÆ÷¡£¡£¡£¡£GreyNoiseÁгöÁËÓë´Ë»î¶¯Ïà¹ØµÄ121¸öIP£¬£¬£¬£¬£¬Åú×¢ÕâÊÇÒ»´ÎÆÕ±éʵÑé¡£¡£¡£¡£VulnCheckÖÒÑԳƣ¬£¬£¬£¬£¬Webshell´æ´¢ÔÚÌØ¶¨Ä¿Â¼ÖУ¬£¬£¬£¬£¬¿ÉÖ±½Óͨ¹ýÍøÂçЧÀÍÆ÷»á¼û£¬£¬£¬£¬£¬Åú×¢±£´æ×Ô¶¯¹¥»÷¡£¡£¡£¡£Ñо¿Ö°Ô±Ç¿µ÷£¬£¬£¬£¬£¬¾¡¿ìÉý¼¶µ½ProjectSend°æ±¾r1750ÖÁ¹ØÖ÷Òª£¬£¬£¬£¬£¬ÒÔÌá·ÀÆÕ±éÈö²¥µÄ¹¥»÷¡£¡£¡£¡£
https://www.bleepingcomputer.com/news/security/hackers-exploit-projectsend-flaw-to-backdoor-exposed-servers/
6. SL Data ServicesÊý¾Ý¿âÔâй¶£¬£¬£¬£¬£¬60ÓàÍòÃô¸ÐÎļþÆØ¹â
11ÔÂ27ÈÕ£¬£¬£¬£¬£¬¾ÝÇå¾²Ñо¿Ö°Ô±±¨µÀ£¬£¬£¬£¬£¬Êý¾Ý¾¼Í¹«Ë¾SL Data ServicesµÄÒ»¸öδÊÜÃÜÂë±£»£»£»£»£»£»¤µÄAmazon S3´æ´¢Í°ÖУ¬£¬£¬£¬£¬Ì»Â¶ÁËÁè¼Ý600,000¸öÃô¸ÐÎļþ£¬£¬£¬£¬£¬°üÀ¨ÊýǧÈ˵폷¨ÀúÊ·¡¢Åä¾°ÊӲ졢³µÁ¾ºÍ¹¤Òµ¼Í¼µÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£ÕâЩÎļþ×ܾÞϸΪ713.1 GB£¬£¬£¬£¬£¬ÇÒδ¼ÓÃÜ¡£¡£¡£¡£ÐÅÏ¢Ç徲ר¼ÒJeremiah FowlerÔÚ10Ô·ݷ¢Ã÷´ËÎÊÌâºó£¬£¬£¬£¬£¬¶à´Îͨ¹ýµç»°ºÍµç×ÓÓʼþÏòÊý¾ÝÍøÂ繫˾±¨¸æ£¬£¬£¬£¬£¬µ«Î´ÊÕµ½»Ø¸´¡£¡£¡£¡£Ö»¹Ü×îÖÕ¸ÃÐÅϢЧÀÍÌṩÉ̹رÕÁËS3´æ´¢Í°£¬£¬£¬£¬£¬µ«ÒÑ̻¶µÄÐÅÏ¢¿ÉÄܻᱻÓÃÓÚÍøÂç´¹ÂÚºÍÉç»á¹¤³Ì¹¥»÷µÈ¶ñÒâÐÐΪ¡£¡£¡£¡£SL Data ServicesÉù³ÆÌṩ¹¤Òµ±¨¸æµÈЧÀÍ£¬£¬£¬£¬£¬µ«Fowler·¢Ã÷¸Ã¹«Ë¾ËƺõÔËÓª×ÅÖÁÉÙ16¸ö²î±ðµÄÍøÕ¾£¬£¬£¬£¬£¬Ìṩ°üÀ¨·¸·¨¼Í¼¼ì²é¡¢ÎÞа³µÖÎÀí²¿·Ö¼Í¼µÈһϵÁÐÊý¾Ý¡£¡£¡£¡£Ëû½¨Òé×é֯ʹÓÃËæ»úÇÒÉ¢ÁеÄΨһ±êʶ·ûÃüÃûÎļþ£¬£¬£¬£¬£¬²¢¼à¿Ø»á¼ûÈÕÖ¾ÒÔʶ±ðÒ쳣ģʽ£¬£¬£¬£¬£¬Í¬Ê±Ê¹ÓÃÃÜÂëºÍ¼ÓÃܱ£»£»£»£»£»£»¤Ãô¸ÐÊý¾Ý¡£¡£¡£¡£
https://www.theregister.com/2024/11/27/600k_sensitive_files_exposed/


¾©¹«Íø°²±¸11010802024551ºÅ