¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180919

Ðû²¼Ê±¼ä 2018-09-19

¡¾ÆÊÎö±¨¸æ¡¿¿¨°Í˹»ùʵÑéÊÒÐû²¼¹ØÓÚÎïÁªÍøÍþвÇ÷ÊÆµÄÆÊÎö±¨¸æ


ƾ֤±¾Öܶþ¿¨°Í˹»ùʵÑéÊÒÐû²¼µÄÎïÁªÍøÍþв±¨¸æ£¬£¬£¬ £¬£¬£¬£¬2018ÄêÉϰëÄ꿨°Í˹»ùÍøÂçµ½µÄIoT¶ñÒâÈí¼þÑù±¾µÄÊýÄ¿ÊÇ2017ÄêÕûÄêµÄÈý±¶£¬£¬£¬ £¬£¬£¬£¬¶ø2017ÄêµÄÊý×ÖÔòÊÇ2016ÄêµÄ10±¶¡£¡£¡£¡£¡£¡£¡£Ò×Êܹ¥»÷µÄIoT×°±¸°üÀ¨MikroTik·ÓÉÆ÷ÒÔ¼°TP-Link¡¢SonicWall¡¢CiscoºÍD-LinkµÄ×°±¸µÈ¡£¡£¡£¡£¡£¡£¡£×îÊܽӴýµÄ¹¥»÷ÏòÁ¿ÊÇTelnet¹¥»÷£¬£¬£¬ £¬£¬£¬£¬Õ¼ËùÓй¥»÷µÄ75.40%¡£¡£¡£¡£¡£¡£¡£ÔÚÉæ¼°µ½IoT¹¥»÷ʱ£¬£¬£¬ £¬£¬£¬£¬Mirai¼Ò×åÊÇ·¸·¨·Ö×ÓµÄÊ×Ñ¡¶ñÒâÈí¼þ£¬£¬£¬ £¬£¬£¬£¬ÆäÕ¼ÓÐÁËËùÓй¥»÷µÄ15.97%¡£¡£¡£¡£¡£¡£¡£


https://securelist.com/new-trends-in-the-world-of-iot-threats/87991/


¡¾ÆÊÎö±¨¸æ¡¿RiskIQÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ


RiskIQÑо¿ÍŶÓÐû²¼2018ÄêµÚ¶þ¼¾¶ÈµÄÒÆ¶¯ÍþÐ²Ì¬ÊÆ±¨¸æ£¬£¬£¬ £¬£¬£¬£¬ºÚÃûµ¥Ó¦Óü±¾çÔöÌí¡£¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬£¬£¬ £¬£¬£¬£¬RiskIQÔÚµÚ¶þ¼¾¶È¹²ÊӲ쵽52885¸öºÚÃûµ¥Ó¦Ó㬣¬£¬ £¬£¬£¬£¬Õ¼ËùÓÐÓ¦ÓõÄ4%£¬£¬£¬ £¬£¬£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁË2%¡£¡£¡£¡£¡£¡£¡£Ä¾ÂíºÍ¹ã¸æÈí¼þÊÇ×î³£¼ûµÄÍþв¡£¡£¡£¡£¡£¡£¡£Google PlayÖеĺÚÃûµ¥Ó¦ÓÃ×î¶à£¬£¬£¬ £¬£¬£¬£¬´ï28533¸ö£¬£¬£¬ £¬£¬£¬£¬±ÈµÚÒ»¼¾¶ÈÔöÌíÁËÔ¼20000¸ö¡£¡£¡£¡£¡£¡£¡£Ñо¿ÍŶӻ¹ÔÚÓ¦ÓÃÊÐËÁÖ®ÍâÊӲ쵽11288¸öºÚÃûµ¥Ó¦Óᣡ£¡£¡£¡£¡£¡£


https://www.riskiq.com/blog/external-threat-management/q2-2018-mobile-threat-landscape-report/


¡¾Êý¾Ýй¶¡¿MongoDBÉèÖùýʧµ¼ÖÂÔ¼1100Íòµç×ÓÓʼþ¼Í¼¿É¹ûÕæ»á¼û


Çå¾²Ñо¿Ö°Ô±Bob DiachenkoÔÚ»¥ÁªÍøÉÏ·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄMongoDB£¬£¬£¬ £¬£¬£¬£¬¸ÃÊý¾Ý¿âÖаüÀ¨Ô¼1100ÍòÌõµç×ÓÓʼþ¼Í¼¡£¡£¡£¡£¡£¡£¡£Êý¾Ý¿âµÄ¾ÞϸΪ43.5GB£¬£¬£¬ £¬£¬£¬£¬°üÀ¨ÁËÓû§µÄÑÅ»¢µç×ÓÓÊÏä¼Í¼ÒÔ¼°ÐÕÃû¡¢ÎïÀíµØµã¡¢ÓÊÕþ±àÂëºÍÆÜÉí¶¼»áµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿âÍйÜÔÚÃÀ¹úGrupo-SMSµÄ»ù´¡ÉèÊ©ÉÏ£¬£¬£¬ £¬£¬£¬£¬ÏÖÔÚ»¹²»ÖªµÀ¸ÃÊý¾Ý¿âµÄËùÓÐÕßµÄÉí·Ý¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/database-with-11-million-email-records-exposed/


¡¾Êý¾Ýй¶¡¿GovPayNet¹ÙÍø±£´æÎó²î£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý1400ÍòÓû§¼Í¼ÒÉй¶


ΪÃÀ¹úÖÝÕþ¸®ºÍµØ·½Õþ¸®ÌṩÔÚÏßÖ§¸¶Æ½Ì¨µÄGovPayNow.com±£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬£¬Áè¼Ý1400ÍòÓû§µÄСÎÒ˽¼ÒÐÅÏ¢ÒÉй¶¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÕ¾Îª36¸öÖݵÄ2000¶à¸öÕþ¸®»ú¹¹ÌṩЧÀÍ£¬£¬£¬ £¬£¬£¬£¬¹«Ãñ¿ÉÒÔͨ¹ýËüÀ´Ö§¸¶· £¿£¿£¿£¿î¡¢ÅÆÕշѺÍÕ˵¥µÈ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Brian KrebsµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬¸ÃÍøÕ¾µÄÔÚÏßÖ§¸¶ÊÕÌõÊǰ´Ë³Ðò±àºÅµÄ£¬£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸ÄURLÖеÄÊý×ÖÀ´Éó²éÆäËüÈ˵ļͼ¡£¡£¡£¡£¡£¡£¡£ÕâЩ¼Í¼°üÀ¨Óû§µÄÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¼°ÒøÐп¨ºóËÄλÊý×ֵȡ£¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÌåÏÖÒÑÔÚÖÜÄ©ÐÞ¸´ÁËÕâÒ»ÎÊÌâ¡£¡£¡£¡£¡£¡£¡£


https://www.infosecurity-magazine.com/news/government-payment-service-exposes/


¡¾Îó²î²¹¶¡¡¿AppleÐû²¼Ð°汾iOS12£¬£¬£¬ £¬£¬£¬£¬ÐÞ¸´¶à¿î²úÆ·ÖеÄÇå¾²Îó²î


Apple±¾ÖÜÕýʽÐû²¼iOS 12£¬£¬£¬ £¬£¬£¬£¬²¢ÐÞ¸´ÁËSafari¡¢watchOSºÍtvOSÖеĶà¸öÎó²î¡£¡£¡£¡£¡£¡£¡£iOS 12Öй²ÐÞ¸´ÁË16¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬iPhone 5s¼°Ö®ºóµÄ°æ±¾¡¢iPad Air¼°Ö®ºóµÄ°æ±¾ÒÔ¼°iPod touch 6Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£½ÏÑÏÖØµÄÎó²î°üÀ¨À¶ÑÀÖеÄÊäÈëÑéÖ¤Îó²î£¨CVE-2018-5383£©ÒÔ¼°SafariÖеÄÐÅϢй¶Îó²î£¨CVE-2018-4313£©µÈ¡£¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬£¬tvOS 12ÖÐÐÞ¸´ÁË5¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬£¬¶øwatchOS 5ÐÞ¸´ÁËÁíÍâµÄ4¸öÎó²î¡£¡£¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/ios-12-patches-memory-bugs-safari-12-fixes-data-leaks/


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÒÆ¶¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶Ô45¸ö¹ú¼ÒµÄÄ¿µÄ


ƾ֤Citizen LabµÄÒ»·Ýб¨¸æ£¬£¬£¬ £¬£¬£¬£¬ÒÑÍùÁ½ÄêÀ´Òƶ¯Ìع¤Èí¼þPegasus±»ÓÃÓÚÕë¶ÔÈ«Çò45¸ö¹ú¼ÒµÄÄ¿µÄ¡£¡£¡£¡£¡£¡£¡£PegasusÊÇÒÔÉ«Áй«Ë¾NSO¿ª·¢µÄÌØ¹¤Èí¼þ£¬£¬£¬ £¬£¬£¬£¬Ö¼ÔÚ¼à¿ØiPhoneºÍAndroid×°±¸µÄ»î¶¯£¬£¬£¬ £¬£¬£¬£¬¿ÉÓÃÓÚÍøÂçÓû§µÄ¶ÌÐÅ¡¢ÈÕÀú¡¢µç×ÓÓʼþ¡¢Î»Öá¢Âó¿Ë·çºÍÏà»úµÈÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£PegasusÖ»ÏòÕþ¸®ºÍÖ´·¨»ú¹¹³öÊÛ¡£¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÖ¸³ö36ÃûÔËÓªÉÌÒ»Ö±ÔÚʹÓÃPegasusÔÚ45¸ö¹ú¼ÒÄÚ¿ªÕ¹¼àÊÓÐж¯¡£¡£¡£¡£¡£¡£¡£NSO½²»°È˳Ƹù«Ë¾Ã»ÓÐÎ¥·´Èκιú¼ÒµÄÖ´·¨¡£¡£¡£¡£¡£¡£¡£


https://thehackernews.com/2018/09/android-ios-hacking-tool.html



¡¾¼øºÚµ£±£Íø¼¯ÍÅADLabÕûÀíÐû²¼¡¿