CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷

Ðû²¼Ê±¼ä 2021-11-17

ÍøÐŰìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·


ÍøÐŰìÐû²¼¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·.png


¹ú¼ÒÍøÐŰìÓÚ11ÔÂ14ÈÕÐû²¼ÁË¡¶ÍøÂçÊý¾ÝÇå¾²ÖÎÀíÌõÀý£¨Õ÷ÇóÒâ¼û¸å£©¡·µÄ¹ûÕæÕ÷ÇóÒâ¼û֪ͨ¡£¡£¡£¡£¡£¡£¡£×èÖ¹½ñÄê6Ô£¬ £¬£¬£¬£¬£¬ÎÒ¹úÍøÃñ¹æÄ£´ï10.11ÒÚ£¬ £¬£¬£¬£¬£¬Óɴ˱¬·¢µÄÍøÂçÊý¾ÝÁ¿¸üÊÇÌìÎÄÊý×Ö¡£¡£¡£¡£¡£¡£¡£¸ÃÌõÀý¹æ·¶ÍøÂçÊý¾Ý´¦Öóͷ£»î¶¯£¬ £¬£¬£¬£¬£¬±£»£»£»£»£»£»£»¤Ð¡ÎÒ˽¼Ò¡¢×éÖ¯ÔÚÍøÂç¿Õ¼äµÄÕýµ±È¨Ò棬 £¬£¬£¬£¬£¬Î¬»¤¹ú¼ÒÇå¾²ºÍ¹«¹²ÀûÒæ¡£¡£¡£¡£¡£¡£¡£Öйú»¥ÁªÍøÐ­»á·¨¹¤Î¯¸±ÃØÊ鳤ºú¸ÖÖ¸³ö£¬ £¬£¬£¬£¬£¬ÕâÊÇÐÂʱ´ú¹æ·¶»¥ÁªÍøÆ½Ì¨ÆóÒµ£¬ £¬£¬£¬£¬£¬Ç¿»¯·´Â¢¶ÏºÍ×ÊÔ´ÎÞÐòÀ©ÕŵÄÓ¦ÓÐÖ®Ò壬 £¬£¬£¬£¬£¬Ò²ÊÇά»¤¹ú¼ÒÇå¾²¡¢±£»£»£»£»£»£»£»¤Éç»á¹«¹²ÀûÒæµÄÐèÒª¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2021-11/14/c_1638501991577898.htm


VMwareÐÞ¸´TanzuÖеÄDoSÎó²îCVE-2021-22101


VMwareÐÞ¸´TanzuÖеÄDoSÎó²îCVE-2021-22101.png


VMwareÔÚ11ÔÂ11ÈÕÐû²¼²¹¶¡£¡£¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬ÐÞ¸´ÁËTanzu Application ServiceÖеÄÎó²îCVE-2021-22101¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚCloud FoundryµÄÔÆ¿ØÖÆÆ÷(CAPI)£¬ £¬£¬£¬£¬£¬CVSSv3ÆÀ·ÖΪ7.5¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßʹÓôËÎó²îʱ£¬ £¬£¬£¬£¬£¬¿ÉÒÔͨ¹ýʹÓÃREST HTTPÇëÇóÌìÉú´ó×ÚµÄSQLÅÌÎʵ¼ÖÂÊý¾Ý¿â(ccdb)²»¿ÉÓ㬠£¬£¬£¬£¬£¬À´´¥·¢¾Ü¾øÐ§ÀÍ״̬¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ncas/current-activity/2021/11/12/vmware-releases-security-update-tanzu-application-service-vms


CISAÅû¶¶à¸öDDS¹©Ó¦É̵Ä×°±¸ÖÐ13¸öÎó²îµÄϸ½Ú


CISAÅû¶¶à¸öDDS¹©Ó¦É̵Ä×°±¸ÖÐ13¸öÎó²îµÄϸ½Ú.png


CISAÔÚ11ÔÂ11ÈÕÐû²¼ÁËÒ»ÌõICS×Éѯ£¬ £¬£¬£¬£¬£¬Åû¶ÁË6¸ö´ó¶¼¾Ý·Ö·¢Ð§ÀÍ(DDS)¹©Ó¦É̵Ä×°±¸Öб£´æµÄ13¸öÎó²îµÄϸ½Ú¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²îÉæ¼°µ½Eclipse¡¢eProsimaºÍGurumNetworksµÈ¹«Ë¾£¬ £¬£¬£¬£¬£¬Éæ¼°µ½µÄ×°±¸°üÀ¨CycloneDDS¡¢FastDDS¡¢GurumDDSºÍOpenDDSµÈ¡£¡£¡£¡£¡£¡£¡£ÆäÖнÏΪÑÏÖØµÄÎó²îΪGurumDDSÖлùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-38439£©£¬ £¬£¬£¬£¬£¬OCI OpenDDSÖеÄDoSÎó²î£¨CVE-2021-38447£©ºÍ¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍÌõ¼þºÍÐÅϢй¶µÄÎó²î£¨CVE-2021-38429£©µÈ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://us-cert.cisa.gov/ics/advisories/icsa-21-315-02


CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷


CloudflareÐû²¼ÆäµÖÓùÁ˸ߴï2 TbpsµÄDDoS¹¥»÷.png


ÃÀ¹úÍøÂçÇå¾²¹«Ë¾CloudflareÔÚ11ÔÂ15ÈÕÐû²¼ÆäµÖÓùÁËÆù½ñΪֹÓöµ½µÄ×î´ó¹¥»÷DDoS¹¥»÷£¬ £¬£¬£¬£¬£¬·åÖµÂÔµÍÓÚ2 Tbps¡£¡£¡£¡£¡£¡£¡£´Ë´Î¹¥»÷»î¶¯ÊÇÁ¬ÏµÁËDNS·Å´ó¹¥»÷ºÍUDP·ººéµÄ¶àÏòÁ¿¹¥»÷£¬ £¬£¬£¬£¬£¬Õû¸öÀú³ÌÖ»Ò»Á¬ÁËÒ»·ÖÖÓ£¬ £¬£¬£¬£¬£¬À´×ÔÔ¼15000¸ö»úеÈË×é³ÉµÄ½©Ê¬ÍøÂçMirai±äÖÖ¡£¡£¡£¡£¡£¡£¡£Cloudflare±¨¸æ³ÆµÚÈý¼¾¶ÈÍøÂç²ãDDoS¹¥»÷»î¶¯±ÈÉÏÒ»¼¾¶ÈÔöÌíÁË44%£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ8ÔµÖÓùÁËÿÃë1720Íò´ÎÇëÇóµÄDDoS¹¥»÷£¬ £¬£¬£¬£¬£¬Î¢ÈíÔÚ10ÔÂ³ÆÆäÔÆÐ§ÀÍAzureµÖÓùÁË2.4 TbpsµÄDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/124634/security/cloudflare-mitigated-ddos-2-tbps.html


IvantiÐû²¼2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ


IvantiÐû²¼2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ.png


IvantiÓÚ11ÔÂ9ÈÕÐû²¼ÁË2021ÄêQ3ÀÕË÷¹¥»÷Ì¬ÊÆµÄÆÊÎö±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬µÚÈý¼¾¶ÈÓëÀÕË÷Èí¼þÏà¹ØµÄÎó²î½ÏÖ®ÉÏÒ»¼¾¶ÈÔöÌíÁË4.5%£¬ £¬£¬£¬£¬£¬×ÜÊýµÖ´ï278¸ö£»£»£»£»£»£»£»ÀÕË÷Èí¼þ¼Ò×åÔöÌíÁË3.4%£¬ £¬£¬£¬£¬£¬×ÜÊýµÖ´ï151¸ö¡£¡£¡£¡£¡£¡£¡£±¨¸æ»¹·¢Ã÷ÀÕË÷ÔËÓªÍÅ»ïÈÔÔÚÆð¾¢Ê¹ÓÃÁãÈÕÎó²î£»£»£»£»£»£»£»¹¥»÷ÖÐʹÓõÄÊÖÒÕÒ²±äµÃÔ½À´Ô½ÖØ´ó£¬ £¬£¬£¬£¬£¬ÀýÈçdropper as-a-service£»£»£»£»£»£»£»ÓÐ3¸ö¿É×·Ëݵ½2020Äê»ò¸üÔçµÄÎó²îÓëÕâÒ»¼¾¶ÈµÄÐÂÀÕË÷Èí¼þÓйØ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ivanti.com/lp/security/reports/2021-q3-ransomware-index-spotlight-report


Check PointÐû²¼2021Äê10ÔÂÈ«ÇòÍþвָÊý±¨¸æ


Check PointÐû²¼2021Äê10ÔÂÈ«ÇòÍþвָÊý±¨¸æ.png


Check PointÔÚ½üÆÚÐû²¼ÁË2021Äê10ÔÂÈ«ÇòÍþвָÊý±¨¸æ¡£¡£¡£¡£¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬£¬TrickbotÈÔλ¾Ó¶ñÒâÈí¼þ°ñµ¥Ö®Ê×£¬ £¬£¬£¬£¬£¬Ó°ÏìÁËÈ«Çò4%µÄ×éÖ¯£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇXMRig£¨3%£©ºÍRemcos£¨2%£©£»£»£»£»£»£»£»½ÌÓýºÍÑо¿ÐÐÒµÊÇÈ«ÇòÊܹ¥»÷×î¶àµÄÐÐÒµ£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇͨѶÐÐÒµ£¬ £¬£¬£¬£¬£¬ÒÔ¼°Õþ¸®ºÍ¾üÊÂ×éÖ¯£»£»£»£»£»£»£»×î³£¼ûµÄÎó²îÊÇWebЧÀÍÆ÷URLĿ¼±éÀúÎó²î£¬ £¬£¬£¬£¬£¬°üÀ¨CVE-2010-4598ºÍCVE-2011-2474µÈ£»£»£»£»£»£»£»xHelper ÈÔÈ»ÊÇ×î³£¼ûµÄÒÆ¶¯¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬£¬Æä´ÎÊÇAlienBotºÍXLoader¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2021/11/11/october-2021s-most-wanted-malware-trickbot-takes-top-spot-for-fifth-time/