ÖÐÎÄ
½»Á÷»ú
Ô°ÇøÍø½»Á÷»ú
Êý¾ÝÖÐÐÄÓëÔÆÅÌËã½»Á÷»ú
ÐÐÒµ¾«Ñ¡½»Á÷ϵÁÐ
¹¤Òµ½»Á÷»ú
Åä¼þ
ËùÓÐÊÖÒÕ½â¾ö¼Æ»®
·ÓÉÆ÷
»ã¾Û·ÓÉÆ÷
ÐÐÒµ¾«Ñ¡Â·ÓÉÆ÷ϵÁÐ
ËùÓÐÊÖÒÕ½â¾ö¼Æ»®
ÎÞÏß
·Å×°ÐÍÎÞÏß½ÓÈëµã
Ç½ÃæÐÍÎÞÏß½ÓÈëµã
ÖÇ·ÖÎÞÏß½ÓÈëµã
ÊÒÍâÎÞÏß½ÓÈëµã
³¡¾°»¯ÎÞÏß
ÎÞÏß¿ØÖÆÆ÷
ÐÐÒµ¾«Ñ¡ÎÞÏßϵÁÐ
ÎÞÏß¹ÜÀíÓëÓ¦ÓÃ
ÔÆ×ÀÃæ
ÔÆÖÕ¶ËϵÁÐ
ÔÆÖ÷»úϵÁÐ
ÔÆ×ÀÃæÈí¼þϵÁÐ
Åä¼þϵÁÐ
·þÎñ²úÆ·
Çå¾²
´óÊý¾ÝÇ徲ƽ̨
ÏÂÒ»´ú·À»ðǽ
Çå¾²Íø¹Ø
¼ì²â¹ÜÀíÇå¾²
ËùÓÐÊÖÒÕ½â¾ö¼Æ»®
Èí¼þ
Éí·Ý¹ÜÀí
·þÎñ²úÆ·
»ù´¡Î¬»¤·þÎñ
ÔËά¹ÜÀí·þÎñ
Çå¾²·þÎñ
±¸¼þÓëÀ©ÈÝ·þÎñ
ÅàѵÓëÈÏÖ¤·þÎñ
2021Äê4ÔÂ14ÈÕ£¬97¹ú¼ÊÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶӼà²âµ½ÍâÑóÑо¿Ô±ÔÚ»¥ÁªÍøÉϹûÕæÁËÒ»·ÝChromeÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²îPOC£¬¾²âÊÔ£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹Ìض¨WebÒ³ÃæÓÕµ¼Êܺ¦Õß»á¼û£¬µ¼Ö´ËÎó²î»ñµÃÔ¶³Ì´úÂëÖ´ÐС£
Google ChromeÊÇÓÉGoogle¿ª·¢µÄÃâ·ÑÍøÒ³ä¯ÀÀÆ÷£¬Ðí¶àµÚÈý·½ä¯ÀÀÆ÷ʹÓÃChromiumÄںˡ£¸ÃÎó²îÒѾӰÏìÁËChrome×îÐÂÕýʽ°æ£¨90.0.4430.72£©ÒÔ¼°»ùÓÚChromiumÄں˵ÄMicrosoft EdgeÕýʽ°æ£¨89.0.774.77£©¡£ÐèҪ˵Ã÷µÄÊÇ£¬´ËöÎó²îÓë4ÔÂ13ÈÕµÄChrome 0DayÎó²î²¢²»ÊÇͳһ¸öÎó²î¡£¼øÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0DayÎó²î״̬£¬Ç¿ÁÒ½¨Òé¿Í»§¾¡¿ì½ÓÄÉÔÝʱ½â¾ö¼Æ»®ÒÔ×èÖ¹ÊÜ´ËÎó²îÓ°Ïì¡£
2021Äê4ÔÂ14ÈÕ£¬Chrome×îÐÂÕýʽ°æ£¨89.0.4389.128£©¸üаüÀ¨2¸öÇå¾²ÐÞ¸´³ÌÐò:
[1196781] High CVE-2021-21206: Use after free in Blink
[1196683] High CVE-2021-21220: Insufficient validation of untrusted input in V8 for x86_64.
ÆäÖÐCVE-2021-21220Ϊ4ÔÂ13ÈÕ±¬³öµÄChromeÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
¶øÓÚ4ÔÂ14Èջƻè8µã×óÓÒ»¥ÁªÍøÓÖ±¬³öÁ˱¾ÎÄÌá¼°µÄChromeÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£
¸ßΣ
Ä¿½ñÎó²îPOCÒѹûÕæ
Îó²î¸´ÏÖ
1.ÔÚChrome 89.0.4389.128Õýʽ°æ±¾ÖÐÎó²î¸´ÏÖ£º
2.ÔÚChrome 90.0.4430.72Õýʽ°æ±¾ÖÐÎó²î¸´ÏÖ£º
¼øÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0DayÎó²î״̬£¬ÎÞÏìÓ¦µÄÎó²î²¹¶¡£¬Óû§½ÓÄÉÈçÏÂÔÝʱ½â¾ö¼Æ»®ÒÔ×èÖ¹ÊÜÎó²îËùµ¼ÖÂΣº¦Ó°Ï죺
1. ÎÈÖØ·¿ªÈªÔ´²»Ã÷µÄÎļþ»òÍøÒ³Á´½Ó¡£
2. ÔÝʱ×èֹʹÓÃV8Ïà¹ØÒýÇæµÄä¯ÀÀÆ÷£¬ÈçChrome¡¢»ùÓÚChromiumÄں˵ÄMicrosoft Edge£¬»»FirefoxµÈä¯ÀÀÆ÷¡£
RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳ
RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳÊÇ97¹ú¼ÊÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢Çå¾²·À»¤¡¢ÉÏÍøÐÐΪ¹ÜÀíµÈÊÖÒÕÍŽáµÄÈëÇÖ¼ì²â·ÀÓùϵͳװ±¸¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ¾ÙÐÐ׼ȷµÄÆÊÎöÅжϣ¬×Ô¶¯ÓÐÓõı£»¤ÍøÂçÇå¾²¡£RG—IDPϵͳÈëÇÖ¼ì²â·ÀÓùϵͳÒÑÖ§³Ö¶Ô¸ÃÎó²îµÄ¼ì²â¡£
RG-ScanϵÁÐÎó²îÆÀ¹Àϵͳ
97¹ú¼ÊRG-Scanͨ¹ý¶ÔϵͳÎó²î¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢ÈëÎó²îÒÔ¼°¿çÕ¾¾ç±¾µÈ¹¥»÷ÊֶζàÄêµÄÑо¿»ýÀÛ£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢Ã÷¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈÊÖÒÕ£¬¿ÉÒÔͨ¹ýÖÇÄܱéÀú¹æÔò¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄÊֶΣ¬ÉîÈë׼ȷµÄ¼ì²â³öϵͳºÍÍøÕ¾Öб£´æµÄÎó²îºÍÈõµã¡£
RG-WALL ϵÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽ
RG-WALLϵÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽÔÚÇå¾²ÄÜÁ¦ÉÏ£¬²»µ«Ö§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ¹Å°åÇå¾²¹¦Ð§£¬Í¬Ê±£¬Ò²Ö§³Ö¸»ºñµÄÓ¦Óü¶Çå¾²¹¦Ð§£¬°üÀ¨²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵ȡ£Ìṩ¶àά¶ÈµÄÓ¦Óòã¼à¿ØÓëÆÊÎö£¬×ÊÖúÓû§ÕÆÎÕΣº¦£¬¾«×¼Ô¤¾¯¡£Í¬Ê±Ö§³ÖÓëÔÆÇå¾²ÖÐÐĵÄÁª¶¯£¬ÌṩÁËÁ¢ÌåÓÐÓõÄδ֪Íþв·À»¤¼Æ»®¡£
Õë¶Ôchromeä¯ÀÀÆ÷Ô¶³Ì´úÂëÖ´ÐУ¬Çëʵʱ¹Ø×¢Ïà¹Ø²úÆ·Éý¼¶°ü¸üÐÂÇéÐΡ£ÊµÊ±Éý¼¶°ü¼ì²âÓë·À»¤Éý¼¶°ü¡£
https://twitter.com/frust93717815/status/1382301769577861123
97¹ú¼ÊÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶӣ¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬Õë¶Ô×îÐÂÇå¾²Îó²î£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ÙºÍÆÊÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐÓõÄÇå¾²·À»¤Õ½ÂÔÓë½â¾ö¼Æ»®¡£
97¹ú¼Ê“ÍøÂç+Çå¾²”Ö÷ÕŽ«ÍøÂç×°±¸µÄÇå¾²ÄÜÁ¦³ä·ÖÑéÕ¹£¬ÍøÂç×°±¸¡¢Çå¾²×°±¸ÓëÇ徲ƽ̨ÖÇÄÜÁª¶¯£¬Àë±ðÇå¾²¹Âµº£¬×é³ÉÕûÍøÁª¶¯µÄÇå¾²°ü¹Üϵͳ£¬ÊµÏÖ·À»¤¡¢Çå¾²Õ¹Íû¡¢ÆÊÎöºÍÏìÓ¦µÈÇå¾²ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£
ÈçÄúÐèÒª97¹ú¼ÊÇå¾²£¬ÇëÁôÏÂÄúµÄÁªÏµ·½·¨