¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181106

Ðû²¼Ê±¼ä 2018-11-06
1¡¢»ôÄáΤ¶ûÐû²¼¹ØÓÚ¹¤ÒµÉèÊ©ÖеÄUSBÍþвµÄÆÊÎö±¨¸æ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤»ôÄáΤ¶ûÐû²¼µÄÒ»·Ýб¨¸æ£¬£¬£¬£¬£¬USB×°±¸ÊÇÕë¶Ô¹¤ÒµÉèÊ©µÄ¶ñÒâÈí¼þ¹¥»÷µÄÖ÷ҪǰÑÔ¡£¡£¡£¡£¡£¡£¸Ã±¨¸æÊÇ»ùÓÚ»ôÄáΤ¶ûµÄÇ徲ýÌå½»Á÷£¨SMX£©ÊÖÒÕÍøÂçµÄÊý¾Ý£¬£¬£¬£¬£¬º­¸ÇÁËÄÜÔ´¡¢Ê¯ÓͺÍ×ÔÈ»Æø¡¢»¯Ñ§¡¢Ö½ÕÅÖÆÔìµÈÐÐÒµ¡£¡£¡£¡£¡£¡£Êý¾ÝÅú×¢£¬£¬£¬£¬£¬26%µÄÍþв¿ÉÄܵ¼Ö¹¤ÒµÆóҵʧȥICSÇéÐεĿɼûÐÔ»ò¿ØÖÆÈ¨£¬£¬£¬£¬£¬´Ó¶øÔì³ÉÖØ´óÖÐÖ¹¡£¡£¡£¡£¡£¡£16%µÄÍþвרÃÅÕë¶ÔICSºÍIoTϵͳ£¬£¬£¬£¬£¬ÆäÖаüÀ¨¶ñÒâÈí¼þMirai£¨6£¥£©¡¢Stuxnet£¨2£¥£©¡¢Triton£¨2£¥£©ºÍWannaCry£¨1£¥£©¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://honeywellprocess.blob.core.windows.net/public/Support/Customer/Honeywell-USB-Threat-Report.pdf


2¡¢ÃÀ»ã·áÒøÐÐÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬²¿·Ö¿Í»§×ÊÁϱ»ÇÔ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤ÃÀ¹ú»ã·áÒøÐÐ11ÔÂ2ÈÕÏò¿Í»§·¢Ë͵ÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬²¿·Ö¿Í»§µÄÔÚÏßÕË»§ÓÚ2018Äê10ÔÂ4ÈÕÖÁ14ÈÕʱ´úÔ⵽δÊÚȨ»á¼û£¬£¬£¬£¬£¬±»ÇÔµÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢×¡Ö·¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢Õ˺š¢ÕË»§ÀàÐÍ¡¢ÕË»§Óà¶î¡¢ÀúÊ·ÉúÒâ¼Í¼¡¢ÊÕ¿îÈËÕË»§ÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡ £»£»£»£»£»£»ã·áÒøÐÐÌåÏÖËùÓÐÊÜÓ°ÏìµÄ¿Í»§¶¼½«»ñµÃÃâ·ÑµÄÐÅÓÃ¼à¿ØºÍÉí·Ý͵ÇÔ± £»£»£»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/hsbc-bank-breached-again-suspends-online-access-to-affected-accounts-523620.shtml


3¡¢Ñо¿Ö°Ô±ÖÒÑÔ³ÆICS×°±¸Ò×ÊܱßÐŵÀ¹¥»÷µÄÓ°Ïì

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±Demos AndreouÔÚICSÍøÂçÇå¾²´ó»áÉÏÖÒÑԳƱßÐŵÀ¹¥»÷¿ÉÄܶÔICSϵͳ×é³ÉÑÏÖØµÄÍþв¡£¡£¡£¡£¡£¡£Æ¾Ö¤Andreou¶ÔÅäµçϵͳ³£Óõı £»£»£»£»£»£»¤×°±¸µÄÑо¿£¬£¬£¬£¬£¬¾ßÓÐÎïÆÊÎö¼ûȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýʾ²¨Æ÷ºÍÔËÐпªÔ´Èí¼þµÄרÓÃÓ²¼þ×°±¸À´»ñÈ¡¼ÓÃÜÃÜÔ¿£¬£¬£¬£¬£¬´ËÀ๥»÷ËùÐèµÄÓ²¼þ±¾Ç®Ô¼Îª300ÃÀÔª¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Èý¼ÒÖ÷Òª¹©Ó¦É̵Ä×°±¸¶¼±£´æÎ£º¦£¬£¬£¬£¬£¬ÓÉÓÚÕâЩװ±¸ÓÃÓÚ± £»£»£»£»£»£»¤µçÍø£¬£¬£¬£¬£¬Òò´ËÕâÖÖ¹¥»÷¿ÉÄÜ»áÔì³ÉÑÏÖØµÄЧ¹û¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/ics-devices-vulnerable-side-channel-attacks-researcher


4¡¢Ñо¿Ö°Ô±ÖÒÑÔÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾µÄ´¹ÂÚÍøÕ¾VOTE411.com

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Ñо¿Ö°Ô±Amanda RousseauºÍLukas Stefanko·¢Ã÷ÓÃÓÚÄ£ÄâÑ¡¾ÙÐÅÏ¢ÍøÕ¾VOTE411.orgµÄ´¹ÂÚÕ©Æ­ÍøÕ¾vote411[.]com¡£¡£¡£¡£¡£¡£Ëæ×ÅÃÀ¹úÖÐÆÚÑ¡¾ÙµÄÁÚ½ü£¬£¬£¬£¬£¬·¸·¨·Ö×ÓÔ½À´Ô½¶àµØÕë¶ÔÑ¡Ãñ¾ÙÐд¹ÂÚ¹¥»÷¡£¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾»á½«macOSºÍiOSƽ̨µÄÓû§Öض¨ÏòÖÁÒ»¸öÐéαµÄ¶ñÒâÈí¼þѬȾ¾¯±¨Ò³Ã棬£¬£¬£¬£¬ÕâÊÇÒ»¸öµä·¶µÄÊÖÒÕÖ§³ÖȦÌ×£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÓÕʹÓû§¶©ÔĶÌÐÅЧÀÍ»òÆ­ÊØÐÅÓÿ¨ÐÅÏ¢¡£¡£¡£¡£¡£¡£ÈôÊÇ´ÓWindows»òAndroid»á¼û¸ÃÍøÕ¾£¬£¬£¬£¬£¬Ôò»á±»Öض¨ÏòÖÁ²î±ðµÄ´¹ÂÚÍøÕ¾¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/scammers-ride-on-voter-info-website-popularity-to-push-scareware-alerts/


5¡¢¿ªÔ´Á÷ýÌåЧÀÍÆ÷IcecastÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ¸´Ò»¸öRCEÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±·¢Ã÷¿ªÔ´Á÷ýÌåЧÀÍÆ÷Icecast±£´æÒ»¸öÎó²î£¬£¬£¬£¬£¬¿ÉÄܵ¼Ö»ùÓÚ¸ÃÈí¼þµÄÍøÂç¹ã²¥µç̨Í߽⡣¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-18820£©ÊÇÒ»¸öÓësprintfº¯ÊýÓйصĻº³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜʹÓöñÒâµÄ³¬³¤HTTPÍ·´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´Ðлò¾Ü¾øÐ§ÀÍ¡£¡£¡£¡£¡£¡£IcecastÔÚ11ÔÂ1ÈÕÐû²¼µÄа汾2.4.4ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/security-bug-puts-online-radio-stations-at-risk/


6¡¢Ñо¿ÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÍŶÓÅû¶Sophos HitmanPro.AlertÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£HitmanPro.AlertÊÇÒ»¸ö¶ñÒâÈí¼þ¼ì²âºÍ·À»¤¹¤¾ß£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷µÄÎó²îÓëÊäÈëÊä³ö¿ØÖÆ£¨IOCTL£©ÐÂÎÅ´¦Öóͷ£Àú³ÌÓйØ£¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3970£©¿ÉÔÊÐí¹¥»÷Õß¶ÁÈ¡ÄÚºËÄÚ´æÖеÄÄÚÈÝ£¬£¬£¬£¬£¬Îó²î£¨CVE-2018-3971£©¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐкÍÌáȨ¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÑÝʾÁËÔõÑùʹÓøÃÎó²î¹¹½¨exploitÀ´»ñÈ¡ÍâµØSYSTEMȨÏÞ¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.talosintelligence.com/2018/11/TALOS-2018-0636.html


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí