΢ÈíÐû²¼Õë¶ÔPetitPotam NTLMÖм̹¥»÷µÄ»º½â²½·¥£»£»£»ºÚ¿ÍÔÚ°µÍøÉϳöÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë

Ðû²¼Ê±¼ä 2021-07-26
1.΢ÈíÐû²¼Õë¶ÔPetitPotam NTLMÖм̹¥»÷µÄ»º½â²½·¥


1.jpg


΢ÈíÐû²¼Õë¶ÔеÄPetitPotam NTLMÖм̹¥»÷µÄ»º½â²½·¥¡£¡£¡£ ¡£¡£¡£PetitPotamÊÇÓÉ·¨¹úÑо¿Ö°Ô±Gilles Lionel·¢Ã÷µÄÐÂNTLMÖм̹¥»÷£¬ £¬£¬£¬£¬Ê¹ÓÃÁËMicrosoft¼ÓÃÜÎļþϵͳԶ³ÌЭÒé( EFSRPC)À´Ç¿ÖÆ×°±¸ÏòÓɺڿͿØÖƵÄÔ¶³ÌNTLMÖмÌÉí·ÝÑéÖ¤£¬ £¬£¬£¬£¬¸Ã¹¥»÷¿ÉÓÃÀ´½ÓÊÜÓò¿ØÖÆÆ÷»òÆäËûWindowsЧÀÍÆ÷¡£¡£¡£ ¡£¡£¡£Î¢Èí½¨ÒéÔÚ²»ÐèÒªµÄµØ·½½ûÓÃNTLM£¬ £¬£¬£¬£¬»òÕ߯ôÓÃÉí·ÝÑéÖ¤»úÖÆµÄÀ©Õ¹±£»£»£»¤£»£»£»²¢½¨ÒéÔÚÆôÓÃÁËNTLMµÄÍøÂçÉÏ£¬ £¬£¬£¬£¬ÔÊÐíNTLMÉí·ÝÑé֤ʹÓÃÊðÃû¹¦Ð§µÄЧÀÍ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcompter.com/news/security/microsoft-shares-mitigations-for-new-petitpotam-ntlm-relay-attack/


2.΢Èí³ÆÆä7Ô·ÝÇå¾²¸üпÉÄÜÓ°Ï첿·ÖϵͳµÄ´òÓ¡¹¦Ð§


2.jpg


΢ÈíÌåÏÖ£¬ £¬£¬£¬£¬ÔÚÓò¿ØÖÆÆ÷(DC)ÉÏ×°ÖÃ2021Äê7ÔÂWindows 10Çå¾²¸üÐÂºó£¬ £¬£¬£¬£¬Ê¹ÓÃÖÇÄÜ¿¨(PIV)Éí·ÝÑéÖ¤µÄ×°±¸µÄ´òÓ¡ºÍɨÃ蹦Ч¿ÉÄ᷺ܻÆðÎÊÌâ¡£¡£¡£ ¡£¡£¡£¸ÃÎÊÌâÊÇÓÉÓÚÕë¶ÔÇå¾²Îó²îCVE-2021-33764µÄ¼Ó¹ÌËùµ¼Öµģ¬ £¬£¬£¬£¬Ó°ÏìÁËÔÚKerberosASÇëÇóʱ´ú²»Ö§³ÖDH»òÖ§³Ödes-ede3-cbc£¨ÈýÖØDES£©µÄÖÇÄÜ¿¨ÑéÖ¤´òÓ¡»ú¡¢É¨ÃèÒǺͶ๦Чװ±¸¡£¡£¡£ ¡£¡£¡£Î¢Èí½¨ÒéÊÜÓ°ÏìµÄ¿Í»§ÁªÏµ×°±¸µÄÖÆÔìÉ̲¢ÒªÇó¾ÙÐÐÉèÖøü¸Ä»ò¸üУ¬ £¬£¬£¬£¬ÒÔÇкÏCVE-2021-33764µÄÇå¾²¸üС£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/microsoft/windows-10-july-security-updates-break-printing-on-some-systems/


3.Ñо¿ÍŶÓÅû¶ÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ


3.jpg


Çå¾²¹«Ë¾MBSDÅû¶ÁËÒÔ°ÂÔË»áΪÖ÷ÌâÕë¶ÔÈÕ±¾µÄwiper¶ñÒâÈí¼þ¡£¡£¡£ ¡£¡£¡£¸Ã¶ñÒâÈí¼þÊÇÔÚÉÏÖÜÎå¾ÙÐеÄ2021Äê¶«¾©°ÂÔ˻ῪĻʽǰÁ½Ìì·¢Ã÷µÄ£¬ £¬£¬£¬£¬Ëü²»µ«ÄÜɾ³ýµçÄÔÉϵÄËùÓÐÊý¾Ý£¬ £¬£¬£¬£¬»¹ÄÜËÑË÷λÓÚC:/Users/<username>/µÄÓû§Ð¡ÎÒ˽¼ÒÎļþ¼ÐÖеÄÌØ¶¨ÎļþÀàÐÍ¡£¡£¡£ ¡£¡£¡£ÆäÖУ¬ £¬£¬£¬£¬Microsoft OfficeÎļþÊÇÒª¸Ã¶ñÒâÈí¼þɾ³ýµÄÖ÷ҪĿµÄ£¬ £¬£¬£¬£¬±ðµÄÉÐÓÐTXT¡¢LOGºÍCSVÎļþ£¬ £¬£¬£¬£¬ÓÉÓÚÕâЩÎļþÓÐʱ»á´æ´¢ÈÕÖ¾¡¢Êý¾Ý¿â»òÃÜÂëÐÅÏ¢µÈ¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬¸Ãwiper»¹Õë¶ÔʹÓÃÁËIchitaroÈÕÓïÎÄ×Ö´¦Öóͷ£Æ÷½¨ÉèµÄÎļþ£¬ £¬£¬£¬£¬Õâ֤ʵËü¿ÉÄÜרÃÅÕë¶ÔÈÕ±¾¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://therecord.media/wiper-malware-targeting-japanese-pcs-discovered-ahead-of-tokyo-olympics-opening/


4.AvananÅû¶ʹÓÃЭ×÷Ó¦ÓÃMilanoteÈÆ¹ýSEGµÄ´¹Âڻ


4.jpg


AvananÑо¿Ö°Ô±Åû¶ÁËʹÓÃЭ×÷Ó¦ÓÃMilanoteÈÆ¹ýSEGµÄ´¹Âڻ¡£¡£¡£ ¡£¡£¡£Avanan³Æ£¬ £¬£¬£¬£¬½üÆÚ´ËÀàÍøÂç´¹ÂÚ¹¥»÷µÄÊýÄ¿¼±¾çÔöÌí£¬ £¬£¬£¬£¬ËûÃÇÔÚÍ¨Ñ¶ÍøÂçÖÐÆÊÎöÁË1430·â°üÀ¨MilanoteÁ´½ÓµÄÓʼþ£¬ £¬£¬£¬£¬ÆäÖÐ1367·âÊÇÍøÂç´¹ÂڻµÄÒ»²¿·Ö£¨¸ß´ï95.5%£©¡£¡£¡£ ¡£¡£¡£´Ë´Î»î¶¯Ê¹ÓÃÁËÒÔÏîÄ¿Ìá°¸·¢Æ±ÎªÖ÷ÌâµÄ´¹ÂÚÓʼþ£¬ £¬£¬£¬£¬ÓÕʹĿµÄ·­¿ªÅþÁ¬ÖеÄÎĵµ²¢±»Öض¨Ïòµ½MilanoteÖеÄÒ³Ãæ¡£¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýÕâÖÖ·½·¨½«payloadǶÌ×ÔÚÕýµ±Ð§ÀÍÖÐÀ´ÈƹýÕâЩ¼ì²â»úÖÆ£¬ £¬£¬£¬£¬°üÀ¨¾²Ì¬É¨ÃèÆ÷¡£¡£¡£ ¡£¡£¡£ 


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2021/07/hacker-employ-milanote-app-for.html


5.ºÚ¿ÍÔÚ°µÍøÉϳöÊÛ38ÒÚ¸öClubhouseÓû§µÄµç»°ºÅÂë


5.jpg


ºÚ¿ÍÔÚ°µÍøÉϳöÊÛÁËClubhouse°üÀ¨38ÒÚ¸öµç»°ºÅÂëµÄÊý¾Ý¿â¡£¡£¡£ ¡£¡£¡£ÂôÃÅ·ç³Æ¸ÃÊý¾Ý¿â°üÀ¨38ÒÚ¸öµç»°ºÅÂ룬 £¬£¬£¬£¬°üÀ¨ÊÖ»ú¡¢Àο¿µç»°¡¢Ë½È˵绰ºÍרҵµç»°£¬ £¬£¬£¬£¬²¢ÇÒÿ¸öºÅÂë¶¼°´Ìض¨µÄ·ÖÊý£¨Ôڵ绰²¾ÖÐÓµÓд˵绰ºÅÂëµÄ»áËùÓû§ÊýÄ¿£©¾ÙÐÐÁËÅÅÃû¡£¡£¡£ ¡£¡£¡£ºÚ¿Í»¹Ðû²¼Á˸ÃÊý¾Ý¿âµÄÑù±¾µÄ£¬ £¬£¬£¬£¬°üÀ¨Áè¼Ý8350Íò¸öÈÕ±¾Óû§µÄµç»°ºÅÂë¡£¡£¡£ ¡£¡£¡£ÔçÔÚ2021Äê4Ô£¬ £¬£¬£¬£¬Cyber NewsµÄÑо¿Ö°Ô±Ôø·¢Ã÷ÁË130Íò¸öClubhouseÓû§µÄСÎÒ˽¼ÒÐÅϢй¶¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/120553/hacking/threat-actor-offers-clubhouse-secret-database-containing-3-8b-phone-numbers.html


6.KasperskyÐû²¼2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)±¨¸æ


6.jpg


KasperskyÐû²¼ÁË2020ÄêQ4Íйܼì²âºÍÏìÓ¦(MDR)µÄÆÊÎö±¨¸æ¡£¡£¡£ ¡£¡£¡£±¨¸æÖ¸³ö£¬ £¬£¬£¬£¬ÔÚ2020ÄêµÚËÄÐò¶È£¬ £¬£¬£¬£¬´Óһ̨Ö÷»úÍøÂçµÄԭʼÊÂÎñµÄƽ¾ùÊýĿԼΪ15000¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤MDRÊÂÎñÑÏÖØÐÔ·ÖÀ࣬ £¬£¬£¬£¬¸ßÑÏÖØÐÔÊÂÎñÓë¾ßÓиßÓ°ÏìµÄÈËΪ¹¥»÷»ò¶ñÒâÈí¼þÓйأ¬ £¬£¬£¬£¬ÆäÖдËÀàÊÂÎñµÄÓÕÒò¿ÉÄÜΪ£ºAPT--Õë¶ÔÐÔ¹¥»÷¡¢½ø¹¥ÐԻ¡¢Ó°ÏìÑÏÖØµÄ¶ñÒâÈí¼þ¡¢¿É±»Ê¹ÓõÄÎó²î¡¢DDOS/DOS¡¢ÄÚ²¿Íþв£¨Ú²Æ­µÈ£©ÒÔ¼°Éç»á¹¤³Ì¹¥»÷µÈ¡£¡£¡£ ¡£¡£¡£±ðµÄ£¬ £¬£¬£¬£¬ÏÕЩËùÓбÊÖ±ÐÐÒµ¶¼ÓÐÊܺ¦Õߣ¬ £¬£¬£¬£¬¶øÇ°3ÃûΪITÐÐÒµ¡¢Õþ¸®×éÖ¯ºÍ¹¤Òµ¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securelist.com/managed-detection-and-response-in-q4-2020/103387/