¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181123

Ðû²¼Ê±¼ä 2018-11-23
1¡¢VMwareÐû²¼¸üУ¬£¬£¬ÐÞ¸´ÐéÄâ»úÌÓÒÝÎó²îCVE-2018-6983

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


VMwareÐÞ¸´Ì츮±­ÉÏÅû¶µÄÐéÄâ»úÌÓÒÝÎó²î£¨CVE-2018-6983£©£¬£¬£¬¸ÃÎó²îÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬£¬£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÐéÄâ»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨VMware Workstation¡¢VMware FusionµÈ£¬£¬£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2ÖÐÐÞ¸´Á˸ÃÎó²î£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.vmware.com/security/advisories/VMSA-2018-0030.html


2¡¢µÂ¹úÉí·ÝÖ¤RFIDоƬ±»ÆØ±£´æÎó²î£¬£¬£¬¿ÉÓÃÓÚαÔìÉí·Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²³§ÉÌSEC Consult±¾ÖÜÅû¶µÂ¹úRFIDоƬÉí·ÝÖ¤ÖеÄÒ»¸öÇå¾²Îó²î£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßαÔì×Ô¼ºµÄÉí·Ý¡£¡£¡£¡£µÂ¹ú´Ó2010Äê×îÏÈʹÓÃÕâÖÖ´øÓÐÉäÆµÊ¶±ð£¨RFID£©Ð¾Æ¬µÄÊý×ÖÉí·ÝÖ¤£¬£¬£¬²¢ÔÚоƬÖд洢¹«ÃñµÄÉí·ÝÊý¾Ý£¬£¬£¬°üÀ¨ÐÕÃû¡¢ÉúÈÕ¡¢ÕÕÆ¬µÈ£¬£¬£¬¿Éͨ¹ýÏìÓ¦µÄ¿Í»§¶ËÈí¼þ£¨eID client£©¶ÁȡоƬÊý¾Ý²¢¾ÙÐÐÏßÉÏÈÏÖ¤¡£¡£¡£¡£Ñо¿Ö°Ô±Wolfgang Ettlinger·¢Ã÷ÔÚÕâ¸öÀú³ÌÖпÉÒÔʹÓÃαÔìµÄÊý¾ÝÈÆ¹ýЧÀÍÆ÷µÄ±£»£» £»£»£»¤£¬£¬£¬´Ó¶ø±ä»»Éí·Ý¡£¡£¡£¡£GovernikusÒÑÔÚ2018Äê8Ô·ÝÐû²¼µÄAutent SDK 3.8.1.2ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/german-eid-authentication-flaw-lets-you-change-identity/


3¡¢Ñо¿ÍŶӷ¢Ã÷ÓÃÓÚ·Ö·¢AzorultľÂíµÄжñÒâ»î¶¯FindMyName

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Palo Alto NetworksµÄUnit42Ñо¿ÍŶӴÓ2018Äê10ÔÂ20ÈÕÆðÊӲ쵽ÓÃÓÚ·Ö·¢AzorultľÂíбäÌåµÄ¶ñÒâ»î¶¯FindMyName¡£¡£¡£¡£¸Ã»î¶¯µÃÃûÓÚÆäʹÓõÄÓòÃûfindmyname[.]pw¡£¡£¡£¡£¸ÃAzorult±äÌåͨ¹ýFallout EK¾ÙÐзַ¢£¬£¬£¬Ñо¿Ö°Ô±Í¨Ì«¹ýÎö·¢Ã÷¸Ã¶ñÒâÑù±¾Ê¹ÓÃÁ˸߼¶»ìÏýÊÖÒÕÒÔÌӱܼì²â¡£¡£¡£¡£±ðµÄ£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷AzorultÓÖÓÐËùÑݱ䣬£¬£¬ÆäÏÖÔÚÖ§³Ö´Ó¸ü¶àµÄä¯ÀÀÆ÷¡¢Ó¦ÓóÌÐòºÍ¼ÓÃÜÇ®±ÒÇ®°üÖÐÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://researchcenter.paloaltonetworks.com/2018/11/unit42-new-wine-old-bottle-new-azorult-variant-found-findmyname-campaign-using-fallout-exploit-kit/


4¡¢Çå¾²³§ÉÌ·¢Ã÷¿ÉÕë¶ÔLinuxЧÀÍÆ÷µÄMirai±äÌåBotmasters

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ArborµÄASERTÑо¿ÍŶӷ¢Ã÷Ò»¸öеÄMirai±äÌåÏÖÔÚ¿ÉÒÔѬȾLinuxЧÀÍÆ÷ÁË£¬£¬£¬¸Ã±äÌåÊÇBotmasters£¬£¬£¬Í¨¹ý½«¹¥»÷Ä¿µÄ´ÓIoT×°±¸×ª±äΪÉÌÓÃLinuxЧÀÍÆ÷£¬£¬£¬Botmasters²»ÔÙÐèҪΪ²î±ðµÄ¼Ü¹¹¾ÙÐвüô£¬£¬£¬¶øÊÇ¿ÉÒÔ¼Ù¶¨¹¥»÷Ä¿µÄΪx86ƽ̨¡£¡£¡£¡£Ò»Ð©¹¥»÷ÕßÕýÔÚʹÓö¨ÖƵŤ¾ßͨ¹ýHadoop YARNÎó²î·Ö·¢¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£ÓÉÓÚÉÌÓÃLinuxЧÀÍÆ÷µÄ´ø¿íÒª±ÈIoT×°±¸Òª´óµÃ¶à£¬£¬£¬Òò´Ë¸Ã¶ñÒâÈí¼þ¿É¹¹½¨Ð§Âʸü¸ßµÄDDoS½©Ê¬ÍøÂ磬£¬£¬ÆäΣº¦½ûֹСêï¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://asert.arbornetworks.com/mirai-not-just-for-iot-anymore/


5¡¢Ñо¿ÍŶӷ¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹µÄÐÂRotexyľÂí

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¿¨°Í˹»ùʵÑéÊÒ·¢Ã÷Ö÷ÒªÕë¶Ô¶íÂÞ˹µÄRotexyľÂíбäÌ壬£¬£¬ÔÚ2018Äê8ÔÂÖÁ10ÔµÄÈý¸öÔÂÄÚ£¬£¬£¬¸Ã±äÌå×ܹ²Ïò¶íÂÞ˹Óû§ÌᳫÁË7Íò¶à´Î¹¥»÷¡£¡£¡£¡£RotexyľÂí¼Ò×åµÄÒ»¸öÓÐÈ¤ÌØÕ÷ÊÇͬʱʹÓÃÁËÈýÖÖÏÂÁîÔ´£¬£¬£¬°üÀ¨¹È¸èÔÆÍÆËÍЧÀÍ£¨GCM£©-ÓÃÓÚ½«JSONÃûÌõÄÐÅÏ¢·¢ËÍÖÁÒÆ¶¯×°±¸¡¢C&CЧÀÍÆ÷ÒÔ¼°¶ÌÐÅ¡£¡£¡£¡£ÕâÊǸÃľÂí¼Ò×åµÄÒ»¸öÌØÉ«¡£¡£¡£¡£RotexyµÄбäÌå×ÛºÏÁËÒøÐÐľÂíºÍÀÕË÷Èí¼þµÄ¹¦Ð§£¬£¬£¬ËüÒÔAvitoPay.apkµÄÃû³ÆÈö²¥£¬£¬£¬´Óyoula9d6h.tk¡¢prodam8n9.tk¡¢prodamfkz.ml¡¢avitoe0ys.tkµÈÍøÕ¾ÏÂÔØ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securelist.com/the-rotexy-mobile-trojan-banker-and-ransomware/88893/


6¡¢Ñо¿ÍŶӷ¢Ã÷ÐÂÔöPoS¶ñÒâÄ£¿£¿£¿£¿ £¿£¿éµÄTrickBotбäÌå

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼µÄÑо¿ÍŶӷ¢Ã÷ÒøÐÐľÂíTrickBotÐÂÔöÁËÒ»¸öPoS¶ñÒâÄ£¿£¿£¿£¿ £¿£¿é£¬£¬£¬Ê¹Æä±äµÃÔ½·¢Î£ÏÕ¡£¡£¡£¡£¸ÃÄ£¿£¿£¿£¿ £¿£¿éÓÃÓÚɨÃèÊÜѬȾµÄÅÌËã»úÊÇ·ñÅþÁ¬µ½ÈκÎÖ§³ÖPoSЧÀ͵Ä×°±¸ºÍÍøÂ磬£¬£¬²¢ÍøÂçÏà¹ØÐÅÏ¢¡£¡£¡£¡£Ñо¿Ö°Ô±»¹ÔÚÊӲ칥»÷ÕßÔõÑùʹÓÃÕâЩÐÅÏ¢£¬£¬£¬µ«¿ÉÄܵÄÇéÐÎÊǹ¥»÷ÕßÕýÔÚÍøÂçÐÅÏ¢ÒÔΪδÀ´µÄÈëÇÖ×ö×¼±¸¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/trickbots-bigger-bag-of-tricks/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí