{"id":2661,"date":"2023-02-06T11:56:08","date_gmt":"2023-02-06T03:56:08","guid":{"rendered":"http:\/\/0.0.0.0:8801\/?p=2661"},"modified":"2023-02-14T11:57:32","modified_gmt":"2023-02-14T03:57:32","slug":"%e9%a7%ad%e4%be%b5%e5%9c%98%e9%ab%94%e6%94%bb%e6%93%8a%e5%8d%b0%e5%ba%a6%e6%9f%90%e9%86%ab%e7%99%82%e3%80%81%e8%83%bd%e6%ba%90%e7%a0%94%e7%a9%b6%e9%a0%98%e5%9f%9f%e8%88%87%e4%be%9b%e6%87%89%e9%8f%88","status":"publish","type":"post","link":"https:\/\/aict.nkust.edu.tw\/digitrans\/?p=2661","title":{"rendered":"\u99ed\u4fb5\u5718\u9ad4\u653b\u64ca\u5370\u5ea6\u67d0\u91ab\u7642\u3001\u80fd\u6e90\u7814\u7a76\u9818\u57df\u8207\u4f9b\u61c9\u93c8\u4ee5\u7aca\u53d6\u60c5\u5831"},"content":{"rendered":"\n<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC <br>\u66f4\u65b0\u65e5\u671f:2023-02-06<\/p>\n\n\n\n<p>\u8cc7\u5b89\u5ee0\u5546 WithSecure \u65e5\u524d\u767c\u8868\u7814\u7a76\u5831\u544a\uff0c\u6307\u51fa\u8a72\u516c\u53f8\u65d7\u4e0b\u7684\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\uff0c\u767c\u73fe Lazarus \u99ed\u4fb5\u5718\u9ad4\u6d89\u5acc\u65bc 2022 \u5e74\u7b2c\u56db\u5b63\u91dd\u5c0d\u5370\u5ea6\u516c\u79c1\u7acb\u91ab\u7642\u3001\u79d1\u6280\u8207\u80fd\u6e90\u7814\u7a76\u55ae\u4f4d\u548c\u5176\u4f9b\u61c9\u93c8\u767c\u52d5\u99ed\u4fb5\u76e3\u63a7\u653b\u64ca\uff0c\u5176\u4e3b\u8981\u76ee\u7684\u63a8\u5b9a\u70ba\u60c5\u5831\u6536\u96c6\u5206\u6790\u3002<\/p>\n\n\n\n<p>\u5831\u544a\u8a73\u7d30\u63cf\u8ff0 WithSecure \u89c0\u5bdf\u5230\u7684\u99ed\u4fb5\u7a0b\u5e8f\uff1b\u9996\u5148\u662f\u4ee5 Zimbra mail server \u8edf\u9ad4\u4e2d\u5df2\u77e5\u7684\u6f0f\u6d1e CVE-2022-27925 \u548c CVE-2022-37042 \u4fb5\u5165\u53d7\u99ed\u55ae\u4f4d\u7684\u5167\u90e8\u7db2\u8def\uff0c\u4e26\u5229\u7528\u53e6\u4e00\u500b\u5df2\u77e5\u6f0f\u6d1e\u300cpwnkit\u300d CVE-2021-4034 \u4f86\u63d0\u5347\u81ea\u6211\u57f7\u884c\u6b0a\u9650\u5230 root \u7b49\u7d1a\u3002<\/p>\n\n\n\n<p>\u63a5\u8457\u99ed\u4fb5\u8005\u5229\u7528 shelf webshell \u548c\u81ea\u88fd\u99ed\u4fb5\u5de5\u5177\u4f86\u5b89\u88dd proxy\u3001tunnel \u548c\u9023\u7dda\u4e2d\u7e7c\u5de5\u5177\uff0c\u4e26\u5229\u7528\u53d7\u99ed\u8005 Windows \u7db2\u57df\u4e2d\u4f7f\u7528\u8001\u820a\u4f5c\u696d\u7cfb\u7d71 Windows XP \u7684\u4e3b\u6a5f\u4f86\u9032\u4e00\u6b65\u5b89\u88dd\u5176\u4ed6\u99ed\u4fb5\u5de5\u5177\u5982 Grease\u3001Minikatz \u548c Cobalt Strike \u7b49\u3002\u99ed\u4fb5\u8005\u6700\u5f8c\u53d6\u5f97\u7d04 100GB \u8cc7\u6599\u50b3\u9001\u5230\u5176\u8a2d\u7acb\u7684\u63a7\u5236\u4f3a\u670d\u5668\uff0c\u4f46\u6c92\u6709\u9032\u884c\u4efb\u4f55\u7834\u58de\u884c\u70ba\u3002<\/p>\n\n\n\n<p>\u8cc7\u6599\u4f86\u6e90\uff1a<a href=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-6914-b9b8c-1.html\" data-type=\"URL\" data-id=\"https:\/\/www.twcert.org.tw\/tw\/cp-104-6914-b9b8c-1.html\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.twcert.org.tw\/tw\/cp-104-6914-b9b8c-1.html<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u767c\u5e03\u55ae\u4f4d:TWCERT\/CC \u66f4\u65b0\u65e5\u671f:2023-02-06 \u8cc7\u5b89\u5ee0\u5546 WithSecure \u65e5\u524d\u767c\u8868\u7814\u7a76\u5831\u544a\uff0c\u6307\u51fa\u8a72\u516c\u53f8\u65d7\u4e0b\u7684\u8cc7\u5b89\u7814\u7a76\u4eba\u54e1\uff0c\u767c\u73fe Lazarus \u99ed\u4fb5\u5718\u9ad4\u6d89\u5acc\u65bc &hellip;<\/p>\n","protected":false},"author":9,"featured_media":2662,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[352],"tags":[204],"class_list":["post-2661","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-information-security","tag-204"],"gutentor_comment":0,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/aict.nkust.edu.tw\/digitrans\/wp-content\/uploads\/2023\/02\/CS-8.png?fit=359%2C244&ssl=1","jetpack-related-posts":[],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2661","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2661"}],"version-history":[{"count":1,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2661\/revisions"}],"predecessor-version":[{"id":2663,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/posts\/2661\/revisions\/2663"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=\/wp\/v2\/media\/2662"}],"wp:attachment":[{"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2661"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2661"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aict.nkust.edu.tw\/digitrans\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2661"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}