SOS Online Backupй¶1.35ÒÚÌõ¼Í¼£»£»£»£»£»GoDaddyÔ±¹¤Ôâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§ÓòÉèÖÃȨÏÞ±»¸Ä¶¯

Ðû²¼Ê±¼ä 2020-04-02

1.½©Ê¬ÍøÂçVollgarʹÓÃMSSQLЧÀÍÆ÷Íڿ󣬣¬£¬£¬£¬£¬£¬ÒÑ»îÔ¾½üÁ½Äê


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


GuardicoreÑо¿Ö°Ô±·¢Ã÷×Ô2018Äê5ÔÂÒÔÀ´£¬£¬£¬£¬£¬£¬£¬½©Ê¬ÍøÂçVollgarÒ»Ö±ÔÚÕë¶ÔMicrosoft SQL£¨MSSQL£©Êý¾Ý¿âÌᳫ±©Á¦¹¥»÷£¬£¬£¬£¬£¬£¬£¬ÊÔͼ½ÓÊÜЧÀÍÆ÷²¢×°ÖÃMoneroºÍVollar¿ó¹¤¡£¡£¡£ ¡£¡£VollgarÔÚÒÑÍù¼¸ÖÜÄÚÌìÌìÀÖ³ÉѬȾÁ˽ü2000-3000̨Êý¾Ý¿âЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬Ç±ÔÚµÄÊܺ¦Õß»®·ÖÀ´×ÔÖйú¡¢Ó¡¶È¡¢ÃÀ¹ú¡¢º«¹úºÍÍÁ¶úÆäµÄÒ½ÁƱ£½¡¡¢º½¿Õ¡¢IT&µçÐÅÒÔ¼°¸ßµÈ½ÌÓýÐÐÒµ¡£¡£¡£ ¡£¡£¹¥»÷ÕßµÄÓÐÓúÉÔØÊÇSQLAGENTIDC.exe»òSQLAGENTVDC.exe£¬£¬£¬£¬£¬£¬£¬ËüÊ×ÏÈɱËÀÒ»³¤´®Àú³Ì£¬£¬£¬£¬£¬£¬£¬ÒÔÈ·±£Õ¼ÓÐ×î´óÊýÄ¿µÄϵͳ×ÊÔ´ºÍÏû³ýÆäËü¹¥»÷ÕߵĻ£¬£¬£¬£¬£¬£¬£¬Ëü»¹³äµ±²î±ðRATÒÔ¼°»ùÓÚXMRigµÄ¼ÓÃܿ󹤵ÄͶµÝÆ÷¡£¡£¡£ ¡£¡£Ñо¿Ö°Ô±»¹Ðû²¼ÁËÒ»¸ö¾ç±¾£¬£¬£¬£¬£¬£¬£¬ÒÔ×ÊÖúϵͳÖÎÀíÔ±¼ì²âÆäMSSQLЧÀÍÆ÷ÊÇ·ñÒÑѬȾ´ËÍþв¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/backdoor-.html


2.GoDaddyÔ±¹¤Ôâ´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§ÓòÉèÖÃȨÏÞ±»¸Ä¶¯


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤KrebsOnSecurityµÄ±¨µÀ£¬£¬£¬£¬£¬£¬£¬È«Çò×î´óµÄÓòÃû×¢²áÉÌGoDaddy.comµÄÒ»Ãû¿Í»§Ð§ÀÍÔ±¹¤Ôâµ½´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñʹ¹¥»÷ÕßÄܹ»Éó²éºÍÐÞ¸ÄÒªº¦¿Í»§µÄ¼Í¼£¬£¬£¬£¬£¬£¬£¬°üÀ¨6Ãû¿Í»§£¨ÀýÈçÉúÒâ¾­¼ÍÍøÕ¾escrow.com£©µÄÓòÉèÖûá¼ûȨÏÞ¡£¡£¡£ ¡£¡£escrow.comÊ×ϯִÐйÙMatt BarrieÌåÏÖ£¬£¬£¬£¬£¬£¬£¬ÔÚÊÂÎñ±¬·¢Ê±´úºÚ¿Í½«escrow.comµÄDNS¼Í¼¸ü¸ÄΪָÏòµÚÈý·½WebЧÀÍÆ÷¡£¡£¡£ ¡£¡£escrow.com½«ÔÚδÀ´¼¸ÌìÄÚ¹²ÏíÓë´ËÊÂÎñÓйصĸü¶àÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬µ«BarrieÇ¿µ÷´ËÊÂÎñûÓÐÆÆËðescrow.comϵͳ£¬£¬£¬£¬£¬£¬£¬Ò²²»»áË𻵿ͻ§Êý¾Ý¡¢×ʽð»òÓòÃû¡£¡£¡£ ¡£¡£GoDaddyÈϿɹ«Ë¾ÓÚ3ÔÂ30ÈÕÊÕµ½Óйؿͻ§ÓòÃûÔâÓöÇå¾²ÊÂÎñµÄ¾¯±¨£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÁíÍâ5Ãû¿Í»§Êܵ½¡°Ç±ÔÚ¡±Ó°Ï죬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐ͸¶¸ü¶àÏêϸÐÅÏ¢¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://krebsonsecurity.com/2020/03/phish-of-godaddy-employee-jeopardized-escrow-com-among-others/


3.Ñо¿Ö°Ô±Ðû²¼SMBGhostÎó²î£¨CVE-2020-0796£©µÄPoC


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±Ðû²¼Õë¶ÔWindows SMBGhostÎó²î£¨CVE-2020-0796£©µÄPoC£¬£¬£¬£¬£¬£¬£¬¿ÉʹÓøÃÎó²î¾ÙÐÐÍâµØÌØÈ¨Éý¼¶¡£¡£¡£ ¡£¡£Æ¾Ö¤Çå¾²³§ÉÌZecOpsµÄÐÎò£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÊÇÕûÊýÒçÍÉ»¯Î󣬣¬£¬£¬£¬£¬£¬Ëü±¬·¢ÔÚsrv2.sys SMBЧÀÍÆ÷Çý¶¯³ÌÐòµÄSrv2DecompressDataº¯ÊýÖУ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±Ðû²¼µÄPoC¿ÉʹÓøÃÎó²î½«ÌØÈ¨Éý¼¶µ½SYSTEM¡£¡£¡£ ¡£¡£ÐèÒª×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îʹÓýöÏÞÓÚÖеÈÍêÕûÐÔ¼¶±ð£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÒÀÀµÓڽϵÍÍêÕûÐÔ¼¶±ð²»¿ÉÓõÄAPIŲÓᣡ£¡£ ¡£¡£Î¢ÈíÐû²¼ÁËÕë¶ÔWindows 10°æ±¾1903ºÍ1909ºÍWindows Server 2019°æ±¾1903ºÍ1909µÄKB4551762¸üÐÂÀ´ÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ìÓ¦ÓøøüС£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/100882/hacking/cve-2020-0796-poc-rce.html


4.Rank Math SEO²å¼þÎó²îÓ°ÏìÁè¼Ý20Íò¸öWordPressÍøÕ¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



Çå¾²³§ÉÌDefiant±¨¸æ³Æ£¬£¬£¬£¬£¬£¬£¬Rank Math SEO²å¼þÖеÄÒ»¸öÒªº¦Îó²î¿ÉÄÜÔÊÐí¹¥»÷Õß½«ÖÎÀíÔ±Ëø¶¨ÔÚ×Ô¼ºµÄÍøÕ¾Ö®Íâ¡£¡£¡£ ¡£¡£¸ÃÎó²îµÄCVSSÆÀ·ÖΪ10·Ö£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁ˲å¼þ¸üÐÂÌû×ÓÔªÊý¾ÝµÄ¹¦Ð§¡£¡£¡£ ¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þ×¢²áÁËÒ»¸öREST-API¶Ëµã£¨rankmath/v1/updateMeta£©£¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚȱ·¦ÓÃÓÚ¹¦Ð§¼ì²éµÄPermission_callback£¬£¬£¬£¬£¬£¬£¬Ê¹Æä̻¶¸ø¹¥»÷Õß¡£¡£¡£ ¡£¡£¶ËµãʹÓÃupdate_metadataº¯Êýɾ³ý»ò¸üÐÂÌû×Ó¡¢Ì¸ÂÛºÍÊõÓïµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«Ò²¿ÉÒÔΪÓû§¸üÐÂÔªÊý¾Ý£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼Ö´ËÎó²î¡£¡£¡£ ¡£¡£WordPressÖеÄÓû§È¨ÏÞ´æ´¢ÔÚusermeta±íÖУ¬£¬£¬£¬£¬£¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉʹÓôËÎó²îÊÚÓèÈκÎÒÑ×¢²áÓû§ÖÎÀíȨÏÞ£¬£¬£¬£¬£¬£¬£¬ÉõÖÁÍêÈ«µõÏúÏÖÓÐÖÎÀíÔ±µÄÌØÈ¨¡£¡£¡£ ¡£¡£¸Ã²å¼þµÄ×°ÖÃÁ¿Áè¼Ý20Íò£¬£¬£¬£¬£¬£¬£¬¿ª·¢ÍŶÓÒѾ­ÔÚа汾10.0.41ÖÐÐÞ¸´ÁËÎó²î£¬£¬£¬£¬£¬£¬£¬Ç¿ÁÒ½¨ÒéÓû§¸üС£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/critical-flaw-seo-plugin-exposes-many-wordpress-sites-attacks


5.Zoom¿Í»§¶ËÒ×ÊÜUNC·¾¶×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿ÉÇÔÈ¡Windowsƾ֤


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Zoom Windows¿Í»§¶ËµÄ̸Ì칦ЧÒ×ÊÜUNC·¾¶×¢Èë¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓôËÎó²îÇÔÈ¡Óû§µÄWindowsƾ֤¡£¡£¡£ ¡£¡£ÔÚʹÓÃZoom¿Í»§¶Ëʱ£¬£¬£¬£¬£¬£¬£¬Óë»áÖ°Ô±¿ÉÒÔͨ¹ý̸Ìì½çÃæ·¢ËÍÎı¾ÐÂÎÅÀ´Ï໥½»Á÷£¬£¬£¬£¬£¬£¬£¬µ«ËùÓз¢Ë͵ÄURL¶¼½«×ª»»Îª³¬Á´½Ó£¬£¬£¬£¬£¬£¬£¬ÒÔ±ãÆäËû³ÉÔ±¿ÉÒÔµ¥»÷ËüÃÇÔÚÆäĬÈÏä¯ÀÀÆ÷Öз­¿ªÍøÒ³¡£¡£¡£ ¡£¡£ÎÊÌâÊÇÇå¾²Ñо¿Ô±@_g0dmode·¢Ã÷Zoom¿Í»§¶Ë»¹½«WindowsÍøÂçUNC·¾¶Ò²×ª»»Îª¿Éµ¥»÷Á´½Ó£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÓû§µ¥»÷¸ÃÁ´½Ó£¬£¬£¬£¬£¬£¬£¬ÔòWindows½«ÊµÑéʹÓÃSMBÎļþ¹²ÏíЭÒéÅþÁ¬µ½Ô¶³ÌÕ¾µã£¬£¬£¬£¬£¬£¬£¬²¢ÔÚĬÈÏÇéÐÎÏ·¢ËÍÓû§µÄµÇ¼ÃûºÍËûÃǵÄNTLMÃÜÂë¹þÏ££¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÆÆ½â¸Ã¹þÏ£»£»£»£»£»ñÈ¡Óû§µÄÃÜÂë¡£¡£¡£ ¡£¡£³ýÁËÇÔÈ¡Windowsƾ֤Í⣬£¬£¬£¬£¬£¬£¬UNC×¢ÈëÒ²¿ÉÓÃÓÚÔÚÍâµØÅÌËã»úÉÏÆô¶¯³ÌÐò¡£¡£¡£ ¡£¡£ZoomÌåÏÖÒѾ­ÊÕµ½´ËÎó²îµÄ֪ͨ£¬£¬£¬£¬£¬£¬£¬µ«ÓÉÓÚ´ËÎó²îÉÐδÐÞ¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§Ê¹ÓÃÌæ»»µÄÊÓÆµ¾Û»áÈí¼þ»òÔÚWebä¯ÀÀÆ÷ÖÐʹÓÃZoomÈ¡´úʹÓÿͻ§¶Ë¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2020/04/zoom-windows-password.html


6.ÔÚÏß±¸·Ý¹«Ë¾SOS Online Backupй¶1.35ÒÚÌõ¼Í¼


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


vpnMentor·¢Ã÷¼ÓÀû¸£ÄáÑÇÖÝÔÚÏß±¸·Ý¹«Ë¾SOS Online BackupµÄÒ»¸ö¿É¹ûÕæ»á¼ûµÄÊý¾Ý¿âй¶Áè¼Ý1.35ÒÚÌõ¼Í¼¡£¡£¡£ ¡£¡£¸ÃÊý¾Ý¿âÖаüÀ¨½ü70GBÓëÓû§ÕÊ»§Ïà¹ØµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬£¬Õâ°üÀ¨½á¹¹¡¢²Î¿¼¡¢ÐÎòÐÔºÍÖÎÀíÐÔÔªÊý¾Ý£¬£¬£¬£¬£¬£¬£¬º­¸ÇÁËSOSÔÆÐ§À͵ÄÐí¶à·½Ãæ¡£¡£¡£ ¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Ì»Â¶µÄÊý¾Ý¿âÖл¹°üÀ¨Ð¡ÎÒ˽¼Òʶ±ðÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢µç×ÓÓʼþ¡¢µç»°ºÅÂë¡¢ÓªÒµÏêϸÐÅÏ¢£¨Õë¶Ô¹«Ë¾¿Í»§£©ºÍÓû§Ãû¡£¡£¡£ ¡£¡£¹¥»÷Õß¿ÉÄÜʹÓÃÕâЩÊý¾ÝÕë¶ÔSOS¼°Æä¿Í»§ÌᳫÖÖÖÖڲƭ¹¥»÷¡£¡£¡£ ¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/secure-backup-company-leaks-135/