¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180612

Ðû²¼Ê±¼ä 2018-06-12
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼5Gʱ´úIoT×°±¸¼°ÎÀÐǵÄÇ徲Σº¦±¨¸æ


Ëæ×Å5G·äÎÑÍøÂçÊÖÒÕºÍIoTµÄÒ»Ö±À©Õ¹£¬£¬£¬£¬ÎÀÐÇÒѾ­³ÉΪÎïÁªÍøºÍ»¥ÁªÍøÒªº¦»ù´¡ÉèÊ©µÄÖ÷Òª×é³É²¿·Ö£¬£¬£¬£¬È·ÊØÎÀÐǵÄÇå¾²¾ßÓÐÖ÷ÒªµÄÒâÒå¡£¡£¡£¡£ ¡£Õë¶ÔÎÀÐǵĹ¥»÷ÏòÁ¿¿ÉÒÔÊÇÌì¿ÕºÍµØÃæÖ®¼ä£¬£¬£¬£¬Ò²¿ÉÒÔÊǵØÃæÖÁÎÀÐÇÔÙÈö²¥ÖÁÆäËüÎÀÐÇ£¬£¬£¬£¬»òÕßÎÀÐÇÖÁµØÃæÔÙÈö²¥ÖÁÆäËüµØ·½¡£¡£¡£¡£ ¡£³£¼ûµÄ¹¥»÷ÀàÐͰüÀ¨µçÐÅڲƭ¡¢¿çÎÀÐǹ¥»÷¡¢ÀÄÓÃÎÀÐǵ绰µÈ£¬£¬£¬£¬¹¥»÷³¡¾°°üÀ¨ÐéαµØÇò»ùÕ¾¡¢Î±×°³ÉÎÀÐǵÄͨѶ¡¢Ê¹ÓÃÎÀÐÇÍøÂç¼äµÄÐÅÈεÈ¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/attack-vectors-in-orbit-need-for-satellite-security-in-5g-iot/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1.5Íò¸öAndroid×°±¸µÄADBµ÷ÊÔ¶Ë¿Ú̻¶


Ñо¿Ö°Ô±Kevin Beaumont³ÆÁè¼Ý1.5Íò¸öAndroid×°±¸µÄADB¶Ë¿Ú̻¶£¬£¬£¬£¬ADB£¨Android Debug Bridge£©ÊÇAndroidϵͳµÄÒ»¸ö¹ÊÕÏɨ³ý¹¤¾ß£¬£¬£¬£¬Ëü»¹¿ÉÒÔÊÚȨÓû§»á¼ûһЩÃô¸Ð¹¤¾ß£¨°üÀ¨Unix shell£©¡£¡£¡£¡£ ¡£ÎÊÌâÔÚÓÚһЩ¹©Ó¦É̽«ÆôÓÃÁËADB over WiFi¹¦Ð§µÄ×°±¸½»¸¶¸øÓû§Ê¹Ó㬣¬£¬£¬ÕâʹµÃÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ£¬£¬£¬£¬Æä×°±¸¿Éͨ¹ýTCP¶Ë¿Ú5555Ô¶³Ì»á¼û£¬£¬£¬£¬²¿·Ö×°±¸Òò´ËѬȾÃÅÂÞ±Ò¿ó¹¤ADB.Miner¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/tens-of-thousands-of-android-devices-are-exposing-their-debug-port/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӳƹ¥»÷Õß´Ó²»Çå¾²µÄÒÔÌ«·»½ÚµãÖÐÇÔÈ¡Áè¼Ý2000ÍòÃÀÔª


Çå¾²Ñо¿Ö°Ô±ÖÒÑÔ³ÆÒ»¸öÍøÂç·¸·¨×é֯ͨ¹ýÐ®ÖÆÍøÉÏ̻¶µÄ²»Çå¾²ÉèÖõÄÒÔÌ«·»½Úµã£¬£¬£¬£¬ÔÚÒÑÍù¼¸¸öÔÂÄÚÇÔÈ¡ÁË38642¸öÒÔÌ«±Ò£¬£¬£¬£¬¼ÛÖµÁè¼Ý2000ÍòÃÀÔª¡£¡£¡£¡£ ¡£Ò»Ð©ÒÔÌ«·»½ÚµãʹÓÃGeth¿Í»§¶Ë£¬£¬£¬£¬²¢ÇÒ¿ª·ÅÁËJSON-RPC¶Ë¿Ú8545¡£¡£¡£¡£ ¡£Í¨¹ýJSON-RPCÓû§¿ÉÒÔÔ¶³Ì»á¼ûÒÔÌ«·»Çø¿éÁ´ºÍ½ÚµãµÄ¹¦Ð§£¬£¬£¬£¬°üÀ¨´ÓÒѽâËøÕË»§·¢ËÍÉúÒâ¡£¡£¡£¡£ ¡£¹¥»÷Õßͨ¹ýɨÃ軥ÁªÍøÉÏ¿ª·ÅµÄ8545¶Ë¿ÚÇÔÈ¡Óû§µÄ×ʽ𡣡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/ethereum-geth-hacking.html


¡¾¹¥»÷ÊÂÎñ¡¿º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª


ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿·ÖICO´ú±Ò£¬£¬£¬£¬ÉúÒâËùûÓÐÅû¶Ïà¹Ø±»µÁ×ʽðµÄÏêϸÊý×Ö£¬£¬£¬£¬µ«ÓÐÓû§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØµã£¬£¬£¬£¬ÒÔΪÏà¹Ø±»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä£¬£¬£¬£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£¡£¡£¡£ ¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ÏàÖúÒÔ¶³½á±»µÁµÄ´ú±Ò¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷Ò»¼Ó6ÊÖ»ú±£´æÇå¾²Îó²î£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß½ÓÊÜ×°±¸


Edge SecurityÇå¾²Ñо¿Ö°Ô±Jason Donenfeld·¢Ã÷Ò»¼Ó6ÊÖ»úÉϵÄbootloader²¢Î´ÍêÈ«Ëø¶¨£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßдÈë¶ñÒâ¾µÏñºÍÍêÈ«½ÓÊÜ×°±¸¡£¡£¡£¡£ ¡£¸ÃÎó²îµÄʹÓÃÐèÒª¶Ô×°±¸µÄÎïÆÊÎö¼û¡£¡£¡£¡£ ¡£ÔÚÑÝʾÊÓÆµÖУ¬£¬£¬£¬Ñо¿Ö°Ô±Ö»ÆÆ·ÑÁ˼¸·ÖÖӾͽ«¶ñÒâ¾µÏñͨ¹ýADBµÄ¿ìËÙÖ¸µ¼ÏÂÁîдÈë×°±¸¡£¡£¡£¡£ ¡£Ò»¼ÓÒѾ­È·ÈÏÁ˸ÃÎÊÌ⣬£¬£¬£¬²¢ÔÊÐí½«Ðû²¼Ïà¹ØÈí¼þ¸üС£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/oneplus6-bootloader-root.html


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷ABBÃŽûϵͳ±£´æ¶à¸öÇå¾²Îó²î


ERNWÑо¿Ö°Ô±Maxim RuppºÍFlorian GrunowÔÚÈðÊ¿ABB¹«Ë¾µÄÃŽûÖÎÀíϵͳÖз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬£¬£¬ÊÜÓ°ÏìµÄ×é¼þÊǹ̼þ°æ±¾3.39¼°Ö®Ç°µÄABB IPÍø¹Ø¡£¡£¡£¡£ ¡£Îó²î¹æÄ£°üÀ¨ÈÏÖ¤ÈÆ¹ýÎó²î£¨CVE-2017-7931£©¡¢Ã÷ÎÄÃÜÂëй¶Îó²î£¨CVE-2017-7933£©¡¢¿çÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î£¨CVE-2017-7906£©ºÍÒ»¸öÔ¶³Ì´úÂë×¢ÈëÎó²î¡£¡£¡£¡£ ¡£ABBÔڹ̼þ°æ±¾3.40ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-flaws-expose-abb-door-communication-systems-attacks