GA»Æ½ð¼×

¡°¼«¼ò¡±»ÀР¡¤ È«ÓòÖÇÁª Ø­ GA»Æ½ð¼×м«¼òÁ캽ÏÂÒ»´úÐ£Ô°Íø½¨Éè×êÑлá
date
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

°²È«¹«¸æ|ChromeÓÖ±¬Ò»Ã¶ÐÂ0Day·ì϶

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ °ä²¼¹¦·ò£º2021-04-16
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

2021Äê4ÔÂ14ÈÕ£¬GA»Æ½ð¼×ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶӼà²âµ½¹ú±í×êÑÐÔ±ÔÚ»¥ÁªÍøÉϹ«¿ªÁËÒ»·ÝChromeÔ¶³Ì´úÂëÖ´ÐÐ0day·ì϶POC£¬¾­²âÊÔ£¬¹¥»÷Õß¿Éͨ¹ý»ú¹ØÌض¨WebÒ³ÃæÓÕµ¼Êܺ¦Õß½Ó¼û£¬µ¼Ö´˷ì϶»ñµÃÔ¶³Ì´úÂëÖ´ÐС£

·ìϼûèÊö

Google ChromeÊÇÓÉGoogle¿ª·¢µÄÃâ·ÑÍøÒ³ä¯ÀÀÆ÷£¬ºÜ¶àµÚÈý·½ä¯ÀÀÆ÷ʹÓÃChromiumÄںˡ£¸Ã·ì϶ÒѾ­Ó°ÏìÁËChrome×îÐÂÕýʽ°æ£¨90.0.4430.72£©ÒÔ¼°»ùÓÚChromiumÄں˵ÄMicrosoft EdgeÕýʽ°æ£¨89.0.774.77£©¡£±ØÒª×¢Ã÷µÄÊÇ£¬´Ëö·ì϶Óë4ÔÂ13ÈÕµÄChrome 0Day·ì϶²¢²»ÊÇͳһ¸ö·ì϶¡£¼øÓڸ÷ì϶Ŀǰ´¦ÓÚ0Day·ì϶״̬£¬Ç¿ÁÒ½¨Òé¿Í»§¾¡¿ì²Éȡһʱ½â¾ö¹æ»®ÒÔÔ¤·ÀÊÜ´Ë·ì϶ӰÏì¡£

2021Äê4ÔÂ14ÈÕ£¬Chrome×îÐÂÕýʽ°æ£¨89.0.4389.128£©¸üÐÂÔ̺¬2¸ö°²È«½¨¸´·¨Ê½:

[1196781] High CVE-2021-21206: Use after free in Blink

[1196683] High CVE-2021-21220: Insufficient validation of untrusted input in V8 for x86_64.

ÆäÖÐCVE-2021-21220Ϊ4ÔÂ13ÈÕ±¬³öµÄChromeÔ¶³Ì´úÂëÖ´Ðзì϶¡£

¶øÓÚ4ÔÂ14ÈÕÍíÉÏ8µã×óÓÒ»¥ÁªÍøÓÖ±¬³öÁ˱¾ÎÄÌá¼°µÄChromeÔ¶³Ì´úÂëÖ´Ðзì϶¡£

Ó°ÏìÁìÓò

Google:Chrome: <=90.0.4430.72

ÍþвµÈ¼¶

¸ßΣ

POC״̬

µ±Ç°·ì϶POCÒѹ«¿ª

·ì϶¸´ÏÖ

1.ÔÚChrome 89.0.4389.128Õýʽ°æ±¾Öзì϶¸´ÏÖ£º

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

 

2.ÔÚChrome 90.0.4430.72Õýʽ°æ±¾Öзì϶¸´ÏÖ£º

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

 

´ëÖý¨Òé

¼øÓڸ÷ì϶Ŀǰ´¦ÓÚ0Day·ì϶״̬£¬ÎÞÏàÓ¦µÄ·ì϶²¹¶¡£¬Óû§²ÉÈ¡ÈçÏÂһʱ½â¾ö¹æ»®ÒÔÔ¤·ÀÊÜ·ì϶Ëùµ¼Ö·çÏÕÓ°Ï죺

1. É÷³Á´ò¿ªÆðÔ´²»Ã÷µÄÎļþ»òÍøÒ³Á´½Ó¡£

2. ÁÙʱÖÕ³¡Ê¹ÓÃV8ÓйØÒýÇæµÄä¯ÀÀÆ÷£¬ÈçChrome¡¢»ùÓÚChromiumÄں˵ÄMicrosoft Edge£¬»»FirefoxµÈä¯ÀÀÆ÷¡£

²úÆ·½â¾ö¹æ»®

RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳ

RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳÊÇGA»Æ½ð¼×ÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢°²È«·À»¤¡¢ÉÏÍøÐÐΪÖÎÀíµÈ¼¼Êõ½áºÏµÄÈëÇÖ¼ì²â·ÀÓùϵͳÉ豸¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ½øÐÐÕýÈ·µÄ·ÖÎöÅжÏ£¬×Ô¶¯ÓÐЧµÄ± £»¤ÍøÂ簲ȫ¡£RG—IDPϵͳÈëÇÖ¼ì²â·ÀÓùϵͳÒÑÖ§³Ö¶Ô¸Ã·ì϶µÄ¼ì²â¡£

RG-ScanϵÁзì϶ÆÀ¹Àϵͳ

GA»Æ½ð¼×RG-Scanͨ¹ý¶Ôϵͳ·ì϶¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢Èë·ì϶ÒÔ¼°¿çÕ¾¾ç±¾µÈ¹¥»÷¼¿Á©¶àÄêµÄ×êÑжѼ¯£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢ÏÖ¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈ¼¼Êõ£¬Äܹ»Í¨¹ýÖÇÄܱéÀú¹æ¶¨¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄ¼¿Á©£¬Éî¿ÌÕýÈ·µÄ¼ì²â³öϵͳºÍÍøÕ¾ÖдæÔڵķì϶ºÍÈõµã¡£

RG-WALL ÏµÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽ

RG-WALLϵÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽÔÚ°²È«ÄÜÁ¦ÉÏ£¬²»½öÖ§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ´«Í³°²È«Ö°ÄÜ£¬Í¬Ê±£¬Ò²Ö§³Ö·á˶µÄÀûÓü¶°²È«Ö°ÄÜ£¬Ô̺¬²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵È¡£Ìṩ¶àά¶ÈµÄÀûÓòã¼à¿ØÓë·ÖÎö£¬Ô®ÊÖÓû§°ÑÎÕ·çÏÕ£¬¾«×¼Ô¤¾¯¡£Í¬Ê±Ö§³ÖÓëÔÆ°²È«ÖÐÐĵÄÁª¶¯£¬ÌṩÁËÁ¢ÌåÓÐЧµÄδ֪Íþв·À»¤¹æ»®¡£

Õë¶Ôchromeä¯ÀÀÆ÷Ô¶³Ì´úÂëÖ´ÐУ¬Çëʵʱ¹Ø×¢ÓйزúÆ·Éý¼¶°ü¸üÐÂÇé¿ö¡£ÊµÊ±Éý¼¶°ü¼ì²âÓë·À»¤Éý¼¶°ü¡£

 

²Î¿¼Á´½Ó

https://twitter.com/frust93717815/status/1382301769577861123

ÍŶӽéÉÜ

GA»Æ½ð¼×ÍøÂçCERT°²È«Ó¦¼±ÏìÓ¦ÍŶÓ£¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬Õë¶Ô×îа²È«·ì϶£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ٺͷÖÎö £»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐЧµÄ°²È«·À»¤Õ½ÊõÓë½â¾ö¹æ»®¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

GA»Æ½ð¼×“ÍøÂç+°²È«”Ö÷ÕŽ«ÍøÂçÉ豸µÄ°²È«ÄÜÁ¦³ä·Ö²ûÑï£¬ÍøÂçÉ豸¡¢°²È«É豸Ó밲ȫƽ̨ÖÇÄÜÁª¶¯£¬ÎÕ±ð°²È«¹Âµº£¬×é³ÉÕûÍøÁª¶¯µÄ°²È«±£ÏÕϵͳ£¬ÊµÏÖ·À»¤¡¢°²È«Ô¤²â¡¢·ÖÎöºÍÏìÓ¦µÈ°²È«ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì¹Ø»·¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ÈçÄú±ØÒªGA»Æ½ð¼×°²È«£¬ÇëÁôÏÂÄúµÄÁªÏµ·½Ê½

 

¹Ø×¢GA»Æ½ð¼×
gfwx_logo
¹Ø×¢GA»Æ½ð¼×¹ÙÍøÎ¢ÐÅ
ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµAI¸±ÊÖ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
ev-close
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
Äú²»ÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
ÄúÊÇ·ñ»¹ÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁ˼±¾ç½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬ÄúÄܹ»ÁôÏÂÁªÏµ·½Ê½
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿