97¹ú¼Ê

¹¤³§ÑÐѧ Ø­ 97¹ú¼ÊÍøÂçÊý×Ö»¯ÖÇÄܹ¤³§¡°ºÚ¿Æ¼¼¡±´ó½ÒÃØ
Ô¤Ô¼Ö±²¥
ÀÖÏíÓªÒµ°ü¹Ü·þÎñ Ø­ ÊØ»¤Ò½ÁÆÓªÒµÒ»Á¬ÎȹÌ
Ô¤Ô¼Ö±²¥
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¼Æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¼Æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷»ï°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/ÓïÑÔ
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

Ç徲ͨ¸æ|ChromeÓÖ±¬Ò»Ã¶ÐÂ0DayÎó²î

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾ Ðû²¼Ê±¼ä£º2021-04-16
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

2021Äê4ÔÂ14ÈÕ£¬97¹ú¼ÊÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶӼà²âµ½ÍâÑóÑо¿Ô±ÔÚ»¥ÁªÍøÉϹûÕæÁËÒ»·ÝChromeÔ¶³Ì´úÂëÖ´ÐÐ0dayÎó²îPOC£¬¾­²âÊÔ£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹Ìض¨WebÒ³ÃæÓÕµ¼Êܺ¦Õß»á¼û£¬µ¼Ö´ËÎó²î»ñµÃÔ¶³Ì´úÂëÖ´ÐС£

Îó²îÐÎò

Google ChromeÊÇÓÉGoogle¿ª·¢µÄÃâ·ÑÍøÒ³ä¯ÀÀÆ÷£¬Ðí¶àµÚÈý·½ä¯ÀÀÆ÷ʹÓÃChromiumÄںˡ£¸ÃÎó²îÒѾ­Ó°ÏìÁËChrome×îÐÂÕýʽ°æ£¨90.0.4430.72£©ÒÔ¼°»ùÓÚChromiumÄں˵ÄMicrosoft EdgeÕýʽ°æ£¨89.0.774.77£©¡£ÐèҪ˵Ã÷µÄÊÇ£¬´ËöÎó²îÓë4ÔÂ13ÈÕµÄChrome 0DayÎó²î²¢²»ÊÇͳһ¸öÎó²î¡£¼øÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0DayÎó²î״̬£¬Ç¿ÁÒ½¨Òé¿Í»§¾¡¿ì½ÓÄÉÔÝʱ½â¾ö¼Æ»®ÒÔ×èÖ¹ÊÜ´ËÎó²îÓ°Ïì¡£

2021Äê4ÔÂ14ÈÕ£¬Chrome×îÐÂÕýʽ°æ£¨89.0.4389.128£©¸üаüÀ¨2¸öÇå¾²ÐÞ¸´³ÌÐò:

[1196781] High CVE-2021-21206: Use after free in Blink

[1196683] High CVE-2021-21220: Insufficient validation of untrusted input in V8 for x86_64.

ÆäÖÐCVE-2021-21220Ϊ4ÔÂ13ÈÕ±¬³öµÄChromeÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£

¶øÓÚ4ÔÂ14Èջƻè8µã×óÓÒ»¥ÁªÍøÓÖ±¬³öÁ˱¾ÎÄÌá¼°µÄChromeÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£

Ó°Ïì¹æÄ£

Google:Chrome: <=90.0.4430.72

ÍþвƷ¼¶

¸ßΣ

POC״̬

Ä¿½ñÎó²îPOCÒѹûÕæ

Îó²î¸´ÏÖ

1.ÔÚChrome 89.0.4389.128Õýʽ°æ±¾ÖÐÎó²î¸´ÏÖ£º

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

 

2.ÔÚChrome 90.0.4430.72Õýʽ°æ±¾ÖÐÎó²î¸´ÏÖ£º

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

 

´¦Öóͷ£½¨Òé

¼øÓÚ¸ÃÎó²îÏÖÔÚ´¦ÓÚ0DayÎó²î״̬£¬ÎÞÏìÓ¦µÄÎó²î²¹¶¡£¬Óû§½ÓÄÉÈçÏÂÔÝʱ½â¾ö¼Æ»®ÒÔ×èÖ¹ÊÜÎó²îËùµ¼ÖÂΣº¦Ó°Ï죺

1. ÎÈÖØ·­¿ªÈªÔ´²»Ã÷µÄÎļþ»òÍøÒ³Á´½Ó¡£

2. ÔÝʱ×èֹʹÓÃV8Ïà¹ØÒýÇæµÄä¯ÀÀÆ÷£¬ÈçChrome¡¢»ùÓÚChromiumÄں˵ÄMicrosoft Edge£¬»»FirefoxµÈä¯ÀÀÆ÷¡£

²úÆ·½â¾ö¼Æ»®

RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳ

RG-IDPϵÁÐÈëÇÖ¼ì²â·ÀÓùϵͳÊÇ97¹ú¼ÊÍøÂçÍÆ³öµÄ½«Éî¶ÈÄÚÈݼì²â¡¢Çå¾²·À»¤¡¢ÉÏÍøÐÐΪ¹ÜÀíµÈÊÖÒÕÍŽáµÄÈëÇÖ¼ì²â·ÀÓùϵͳװ±¸¡£Í¨¹ý¶ÔÍøÂçÖÐÉî²ã¹¥»÷ÐÐΪ¾ÙÐÐ׼ȷµÄÆÊÎöÅжÏ£¬×Ô¶¯ÓÐÓõı£»¤ÍøÂçÇå¾²¡£RG—IDPϵͳÈëÇÖ¼ì²â·ÀÓùϵͳÒÑÖ§³Ö¶Ô¸ÃÎó²îµÄ¼ì²â¡£

RG-ScanϵÁÐÎó²îÆÀ¹Àϵͳ

97¹ú¼ÊRG-Scanͨ¹ý¶ÔϵͳÎó²î¡¢·þÎñºóÃÅ¡¢ÍøÒ³¹ÒÂí¡¢SQL×¢ÈëÎó²îÒÔ¼°¿çÕ¾¾ç±¾µÈ¹¥»÷ÊֶζàÄêµÄÑо¿»ýÀÛ£¬×ܽá³öÁËÖÇÄÜÖ÷»ú·þÎñ·¢Ã÷¡¢ÖÇÄÜ»¯ÅÀ³æºÍSQL×¢Èë״̬¼ì²âµÈÊÖÒÕ£¬¿ÉÒÔͨ¹ýÖÇÄܱéÀú¹æÔò¿âºÍ¶àÖÖɨÃèÑ¡Ïî×éºÏµÄÊֶΣ¬ÉîÈë׼ȷµÄ¼ì²â³öϵͳºÍÍøÕ¾Öб£´æµÄÎó²îºÍÈõµã¡£

RG-WALL ÏµÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽ

RG-WALLϵÁÐÈ«ÐÂÏÂÒ»´ú·À»ðǽÔÚÇå¾²ÄÜÁ¦ÉÏ£¬²»µ«Ö§³ÖNAT¡¢ACL¡¢DDoS·ÀÓùµÈ¹Å°åÇå¾²¹¦Ð§£¬Í¬Ê±£¬Ò²Ö§³Ö¸»ºñµÄÓ¦Óü¶Çå¾²¹¦Ð§£¬°üÀ¨²¡¶¾²éɱ¡¢ÈëÇÖ¼ì²â¡¢APP¼ì²â¡¢Îļþ¹ýÂË¡¢¶ñÒâURL¹ýÂ˵È¡£Ìṩ¶àά¶ÈµÄÓ¦Óòã¼à¿ØÓëÆÊÎö£¬×ÊÖúÓû§ÕÆÎÕΣº¦£¬¾«×¼Ô¤¾¯¡£Í¬Ê±Ö§³ÖÓëÔÆÇå¾²ÖÐÐĵÄÁª¶¯£¬ÌṩÁËÁ¢ÌåÓÐÓõÄδ֪Íþв·À»¤¼Æ»®¡£

Õë¶Ôchromeä¯ÀÀÆ÷Ô¶³Ì´úÂëÖ´ÐУ¬Çëʵʱ¹Ø×¢Ïà¹Ø²úÆ·Éý¼¶°ü¸üÐÂÇéÐΡ£ÊµÊ±Éý¼¶°ü¼ì²âÓë·À»¤Éý¼¶°ü¡£

 

²Î¿¼Á´½Ó

https://twitter.com/frust93717815/status/1382301769577861123

ÍŶÓÏÈÈÝ

97¹ú¼ÊÍøÂçCERTÇå¾²Ó¦¼±ÏìÓ¦ÍŶÓ£¬¸ú×Ù×îл¥ÁªÍøÍþвÊÂÎñ£¬Õë¶Ô×îÐÂÇå¾²Îó²î£¬APT¹¥»÷ÒÔ¼°½©Ê¬ÍøÂç¼Ò×å×öʵʱ¸ú×ÙºÍÆÊÎö£»Îª²úÆ·¡¢¿Í»§Ìṩʵʱ¡¢ÓÐÓõÄÇå¾²·À»¤Õ½ÂÔÓë½â¾ö¼Æ»®¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

97¹ú¼Ê“ÍøÂç+Çå¾²”Ö÷ÕŽ«ÍøÂç×°±¸µÄÇå¾²ÄÜÁ¦³ä·ÖÑéÕ¹£¬ÍøÂç×°±¸¡¢Çå¾²×°±¸ÓëÇ徲ƽ̨ÖÇÄÜÁª¶¯£¬Àë±ðÇå¾²¹Âµº£¬×é³ÉÕûÍøÁª¶¯µÄÇå¾²°ü¹Üϵͳ£¬ÊµÏÖ·À»¤¡¢Çå¾²Õ¹Íû¡¢ÆÊÎöºÍÏìÓ¦µÈÇå¾²ÎÊÌâ×Ô¶¯»¯È«Á÷³Ì±Õ»·¡£

97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

ÈçÄúÐèÒª97¹ú¼ÊÇå¾²£¬ÇëÁôÏÂÄúµÄÁªÏµ·½·¨

 

¹Ø×¢97¹ú¼Ê
¹Ø×¢97¹ú¼Ê¹ÙÍøÎ¢ÐÅ
ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÎĵµÆÀ¼Û
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌâ £¿
Äú¶ÔÄ¿½ñÒ³ÃæµÄÖª×ã¶ÈÔõÑù £¿
²»Õ¦µÎ
ºÜÊǺÃ
ÄúÖª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
Äú²»Öª×ãµÄÔµ¹ÊÔ­ÓÉÊÇ£¨¶àÑ¡£© £¿
ÄúÊÇ·ñÉÐÓÐÆäËûÎÊÌâ»ò½¨Òé £¿
ΪÁË¿ìËÙ½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬Äú¿ÉÒÔÁôÏÂÁªÏµ·½·¨
ÓÊÏä
ÊÖ»úºÅ
ллÄúµÄ·´À¡£¡
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
97¹ú¼Ê¡¤(ÖйúÇø)¼¯ÍŹٷ½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø±Õ×Éѯҳ
ÊÛǰ×Éѯ ÊÛǰ×Éѯ
ÊÛǰ×Éѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
Òâ¼û·´Ïì Òâ¼û·´Ïì
Òâ¼û·´Ïì
¸ü¶àÁªÏµ·½·¨
ÍøÕ¾µØÍ¼