¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180910

Ðû²¼Ê±¼ä 2018-09-10

01

ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒGAOÐû²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ×±¨¸æ


ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒ£¨GAO£©Ðû²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ×±¨¸æ £¬£¬£¬ £¬£¬ £¬±¨¸æÖÐÏêϸ˵Ã÷ÎúEquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇéÐÎÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ±¬·¢Ê±´úºÍÖ®ºóµÄÏìÓ¦¡£¡£¡£ ¡£2017Äê3ÔÂ8ÈÕApacheÐÞ¸´ÁËStruts Java¿ò¼ÜÖеÄÎó²î£¨CVE-2017-5638£© £¬£¬£¬ £¬£¬ £¬Í³Ò»ÌìUS-CERTÕë¶Ô¸ÃÎó²îÐû²¼ÁËÇå¾²¾¯±¨¡£¡£¡£ ¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´ËÎó²î¾¯±¨ £¬£¬£¬ £¬£¬ £¬µ«¸ÃÓʼþÁбíÒѹýʱ £¬£¬£¬ £¬£¬ £¬²¢Ã»ÓаüÀ¨ËùÓеÄϵͳÖÎÀíÔ± £¬£¬£¬ £¬£¬ £¬Õâ¼ä½Óµ¼ÖÂÁËЧÀÍÆ÷µÄ²¹¶¡ÐÞ¸´ÊÂÇé²»ÍêÕû¡£¡£¡£ ¡£

   Ô­ÎÄÁ´½Ó£º

https://www.gao.gov/assets/700/694158.pdf


02

Ñо¿ÍŶӷ¢Ã÷ÊýÊ®¸öiOSÓ¦ÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÓû§µÄλÖÃÐÅÏ¢


GuardianAppÑо¿ÍŶӷ¢Ã÷ÊýÊ®¸öiOSÓ¦ÓÃÍøÂçÓû§µÄλÖÃÊý¾Ý £¬£¬£¬ £¬£¬ £¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£¡£¡£ ¡£ÕâЩÊý¾ÝÍøÂç²»ÊÇÉñÃØ¾ÙÐÐµÄ £¬£¬£¬ £¬£¬ £¬ËùÓеÄÓ¦Óö¼»áÒªÇóÓû§µÄÔÊÐí £¬£¬£¬ £¬£¬ £¬µ«ÎÊÌâÔÚÓÚ £¬£¬£¬ £¬£¬ £¬ÕâЩӦÓúÜÉÙ»ò»ù´¡Ã»ÓÐÌá¼°»á½«Î»ÖÃÊý¾ÝÓëµÚÈý·½¹²Ïí £¬£¬£¬ £¬£¬ £¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÄ¿µÄ¡£¡£¡£ ¡£´ó´ó¶¼ÇéÐÎÏÂÕâЩӦÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØµã£©Êý¾Ý¡£¡£¡£ ¡£»£»£»£» £ÉÐÓÐһЩӦÓûáÍøÂçGPS¸ß¶ÈºÍËÙÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼ÓËÙÂʼÆÐÅÏ¢ºÍIDFA¹ã¸æ±êʶ·ûµÈÊý¾Ý¡£¡£¡£ ¡£

  Ô­ÎÄÁ´½Ó£º

https://guardianapp.com/ios-app-location-report-sep2018.html


03

Ñо¿Ö°Ô±³Æ¿É¹ûÕæ»á¼ûµÄ.GitĿ¼µ¼ÖÂÁè¼Ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷


Lynt ServicesµÄÑо¿Ö°Ô±Vladim¨ªrSmitka·¢Ã÷¿É¹ûÕæ»á¼ûµÄ.gitĿ¼µ¼ÖÂÁè¼Ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£¡£¡£ ¡£Ðí¶àWeb¿ª·¢Ö°Ô±Ê¹ÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ãæ £¬£¬£¬ £¬£¬ £¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É»á¼û²¿·Ö £¬£¬£¬ £¬£¬ £¬ÉõÖÁ°üÀ¨Ò»Ð©Ö÷ÒªµÄÐÅÏ¢ £¬£¬£¬ £¬£¬ £¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõÈ¡£¡£¡£ ¡£

  Ô­ÎÄÁ´½Ó£º

https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/


04

Ñо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆ±£´æÎó²î


EclypsiumµÄÑо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆ±£´æÇå¾²Îó²î £¬£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÄÜʹÓøÃÎó²î×°Öó¤ÆÚÐÔ¶ñÒâÈí¼þ»òÕßÍêÈ«²Á³ý²¢ÖØÐÂ×°ÖòÙ×÷ϵͳ¡£¡£¡£ ¡£BMCÔڵײãÔËÐÐ £¬£¬£¬ £¬£¬ £¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ £¬£¬£¬ £¬£¬ £¬Òò´ËÍùÍù³ÉΪ¹¥»÷ÕßµÄÄ¿µÄ¡£¡£¡£ ¡£Ñо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆÃ»ÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÖÆ £¬£¬£¬ £¬£¬ £¬Ò²Ã»Óмì²é¹Ì¼þÊÇ·ñÊÇ´ÓÕýµ±ÈªÔ´ÏÂÔØµÄ¡£¡£¡£ ¡£

  Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html


05

GoogleÐû²¼9ÔÂAndroidÇå¾²¸üР£¬£¬£¬ £¬£¬ £¬¹²ÐÞ¸´50¶à¸öÎó²î


9ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö £¬£¬£¬ £¬£¬ £¬ÆäÖÐÇå¾²²¹¶¡¼¶±ð2018-09-01ÐÞ¸´ÁË24¸öÎó²î £¬£¬£¬ £¬£¬ £¬Çå¾²²¹¶¡¼¶±ð2018-09-05ÐÞ¸´ÁË35¸öÎó²î¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄ×é¼þ°üÀ¨Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£¡£¡£ ¡£ÑÏÖØÐԽϸߵÄÎó²î°üÀ¨Èý¸öSystemÌØÈ¨ÌáÉýÎó²îºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£Google»¹Ðû²¼ÁË2018Äê9ÔµÄPixel/NexusÇ徲ͨ¸æ £¬£¬£¬ £¬£¬ £¬ÐÞ¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸öÇå¾²Îó²î¡£¡£¡£ ¡£

  Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2018-09-01


06

Fraunhofer SITÑо¿Ö°Ô±ÑÝʾÔõÑùÓÕÆ­Ö¤Êé½ÒÏþ»ú¹¹


ƾ֤The RegisterµÄÒ»·Ý±¨¸æ £¬£¬£¬ £¬£¬ £¬µÂ¹úFraunhoferÇå¾²ÐÅÏ¢ÊÖÒÕÑо¿Ëù£¨SIT£©µÄÑо¿Ö°Ô±ÑÝʾÔõÑùÓÕÆ­Ö¤Êé½ÒÏþ»ú¹¹¡£¡£¡£ ¡£Haya Shulman²©Ê¿ÌåÏÖ £¬£¬£¬ £¬£¬ £¬ËûÃÇ¿ÉÒÔͨ¹ýDNS»º´æÖж¾¹¥»÷½«CAÖØ¶¨ÏòÖÁ¹¥»÷ÕßµÄÅÌËã»ú¡£¡£¡£ ¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤Êé¿ÉÒÔ±»ÓÕÆ­ £¬£¬£¬ £¬£¬ £¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸üÇå¾²µÄÒªÁìÑéÖ¤µÄÖ¤Êé £¬£¬£¬ £¬£¬ £¬ÀýÈçÀ©Õ¹ÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£¡£¡£ ¡£

  Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/


1¡¢ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒGAOÐû²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ×±¨¸æ

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÕþ¸®ÎÊÔð°ì¹«ÊÒ£¨GAO£©Ðû²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ×±¨¸æ £¬£¬£¬ £¬£¬ £¬±¨¸æÖÐÏêϸ˵Ã÷ÎúEquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇéÐÎÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ±¬·¢Ê±´úºÍÖ®ºóµÄÏìÓ¦¡£¡£¡£ ¡£2017Äê3ÔÂ8ÈÕApacheÐÞ¸´ÁËStruts Java¿ò¼ÜÖеÄÎó²î£¨CVE-2017-5638£© £¬£¬£¬ £¬£¬ £¬Í³Ò»ÌìUS-CERTÕë¶Ô¸ÃÎó²îÐû²¼ÁËÇå¾²¾¯±¨¡£¡£¡£ ¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´ËÎó²î¾¯±¨ £¬£¬£¬ £¬£¬ £¬µ«¸ÃÓʼþÁбíÒѹýʱ £¬£¬£¬ £¬£¬ £¬²¢Ã»ÓаüÀ¨ËùÓеÄϵͳÖÎÀíÔ± £¬£¬£¬ £¬£¬ £¬Õâ¼ä½Óµ¼ÖÂÁËЧÀÍÆ÷µÄ²¹¶¡ÐÞ¸´ÊÂÇé²»ÍêÕû¡£¡£¡£ ¡£

   Ô­ÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf


2¡¢Ñо¿ÍŶӷ¢Ã÷ÊýÊ®¸öiOSÓ¦ÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÓû§µÄλÖÃÐÅÏ¢

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


GuardianAppÑо¿ÍŶӷ¢Ã÷ÊýÊ®¸öiOSÓ¦ÓÃÍøÂçÓû§µÄλÖÃÊý¾Ý £¬£¬£¬ £¬£¬ £¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£¡£¡£ ¡£ÕâЩÊý¾ÝÍøÂç²»ÊÇÉñÃØ¾ÙÐÐµÄ £¬£¬£¬ £¬£¬ £¬ËùÓеÄÓ¦Óö¼»áÒªÇóÓû§µÄÔÊÐí £¬£¬£¬ £¬£¬ £¬µ«ÎÊÌâÔÚÓÚ £¬£¬£¬ £¬£¬ £¬ÕâЩӦÓúÜÉÙ»ò»ù´¡Ã»ÓÐÌá¼°»á½«Î»ÖÃÊý¾ÝÓëµÚÈý·½¹²Ïí £¬£¬£¬ £¬£¬ £¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÄ¿µÄ¡£¡£¡£ ¡£´ó´ó¶¼ÇéÐÎÏÂÕâЩӦÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØµã£©Êý¾Ý¡£¡£¡£ ¡£»£»£»£» £ÉÐÓÐһЩӦÓûáÍøÂçGPS¸ß¶ÈºÍËÙÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼ÓËÙÂʼÆÐÅÏ¢ºÍIDFA¹ã¸æ±êʶ·ûµÈÊý¾Ý¡£¡£¡£ ¡£
  Ô­ÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html

 

3¡¢Ñо¿Ö°Ô±³Æ¿É¹ûÕæ»á¼ûµÄ.GitĿ¼µ¼ÖÂÁè¼Ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Lynt ServicesµÄÑо¿Ö°Ô±Vladim¨ªrSmitka·¢Ã÷¿É¹ûÕæ»á¼ûµÄ.gitĿ¼µ¼ÖÂÁè¼Ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£¡£¡£ ¡£Ðí¶àWeb¿ª·¢Ö°Ô±Ê¹ÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ãæ £¬£¬£¬ £¬£¬ £¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É»á¼û²¿·Ö £¬£¬£¬ £¬£¬ £¬ÉõÖÁ°üÀ¨Ò»Ð©Ö÷ÒªµÄÐÅÏ¢ £¬£¬£¬ £¬£¬ £¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõÈ¡£¡£¡£ ¡£
  Ô­ÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/

 

4¡¢Ñо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆ±£´æÎó²î

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


EclypsiumµÄÑо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆ±£´æÇå¾²Îó²î £¬£¬£¬ £¬£¬ £¬¹¥»÷Õß¿ÉÄÜʹÓøÃÎó²î×°Öó¤ÆÚÐÔ¶ñÒâÈí¼þ»òÕßÍêÈ«²Á³ý²¢ÖØÐÂ×°ÖòÙ×÷ϵͳ¡£¡£¡£ ¡£BMCÔڵײãÔËÐÐ £¬£¬£¬ £¬£¬ £¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ £¬£¬£¬ £¬£¬ £¬Òò´ËÍùÍù³ÉΪ¹¥»÷ÕßµÄÄ¿µÄ¡£¡£¡£ ¡£Ñо¿Ö°Ô±·¢Ã÷SupermicroЧÀÍÆ÷µÄBMC¸üлúÖÆÃ»ÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÖÆ £¬£¬£¬ £¬£¬ £¬Ò²Ã»Óмì²é¹Ì¼þÊÇ·ñÊÇ´ÓÕýµ±ÈªÔ´ÏÂÔØµÄ¡£¡£¡£ ¡£
  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html


5¡¢GoogleÐû²¼9ÔÂAndroidÇå¾²¸üР£¬£¬£¬ £¬£¬ £¬¹²ÐÞ¸´50¶à¸öÎó²î

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


9ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö £¬£¬£¬ £¬£¬ £¬ÆäÖÐÇå¾²²¹¶¡¼¶±ð2018-09-01ÐÞ¸´ÁË24¸öÎó²î £¬£¬£¬ £¬£¬ £¬Çå¾²²¹¶¡¼¶±ð2018-09-05ÐÞ¸´ÁË35¸öÎó²î¡£¡£¡£ ¡£ÊÜÓ°ÏìµÄ×é¼þ°üÀ¨Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£¡£¡£ ¡£ÑÏÖØÐԽϸߵÄÎó²î°üÀ¨Èý¸öSystemÌØÈ¨ÌáÉýÎó²îºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£ ¡£Google»¹Ðû²¼ÁË2018Äê9ÔµÄPixel/NexusÇ徲ͨ¸æ £¬£¬£¬ £¬£¬ £¬ÐÞ¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸öÇå¾²Îó²î¡£¡£¡£ ¡£
  Ô­ÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01


6¡¢Fraunhofer SITÑо¿Ö°Ô±ÑÝʾÔõÑùÓÕÆ­Ö¤Êé½ÒÏþ»ú¹¹

 

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤The RegisterµÄÒ»·Ý±¨¸æ £¬£¬£¬ £¬£¬ £¬µÂ¹úFraunhoferÇå¾²ÐÅÏ¢ÊÖÒÕÑо¿Ëù£¨SIT£©µÄÑо¿Ö°Ô±ÑÝʾÔõÑùÓÕÆ­Ö¤Êé½ÒÏþ»ú¹¹¡£¡£¡£ ¡£Haya Shulman²©Ê¿ÌåÏÖ £¬£¬£¬ £¬£¬ £¬ËûÃÇ¿ÉÒÔͨ¹ýDNS»º´æÖж¾¹¥»÷½«CAÖØ¶¨ÏòÖÁ¹¥»÷ÕßµÄÅÌËã»ú¡£¡£¡£ ¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤Êé¿ÉÒÔ±»ÓÕÆ­ £¬£¬£¬ £¬£¬ £¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸üÇå¾²µÄÒªÁìÑéÖ¤µÄÖ¤Êé £¬£¬£¬ £¬£¬ £¬ÀýÈçÀ©Õ¹ÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£¡£¡£ ¡£
  Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/