¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190123

Ðû²¼Ê±¼ä 2019-01-23
1¡¢Linux°ü¹ÜÀíÆ÷apt/apt-getÔ¶³Ì´úÂëÖ´ÐÐÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±Max Justicz·¢Ã÷Linux°ü¹ÜÀíÆ÷apt/apt-get±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¸ÃÎó²î£¨CVE-2019-3462£©ÔÊÐí¹¥»÷Õß¾ÙÐÐÖÐÐÄÈ˹¥»÷²¢»ñÈ¡rootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¸ÃÎó²îµÄÒòÓÉÊÇaptĬÈÏʹÓÃHTTPͨѶ£¬£¬£¬¶øÆätransportÒªÁìÖд¦Öóͷ£HTTPÖØ¶¨ÏòµÄ´úÂëûÓÐ׼ȷ¼ì²éijЩ²ÎÊý£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÖÐÐÄÈ˹¥»÷ʹÓÃαÔìÊðÃûÆ­¹ý¸Ã¼ì²é£¬£¬£¬½ø¶øÔÚÓû§Ö÷»úÉÏ×°ÖÃí§Òâ³ÌÐò¡£¡£¡£ÓÉÓÚapt×Ô¼ºÒѾ­»ñÈ¡ÁËrootȨÏÞ£¬£¬£¬¸Ã¶ñÒâ³ÌÐò¿ÉÔÚrootȨÏÞÏÂÖ´ÐС£¡£¡£¸ÃÎó²îÓ°Ïì¹æÄ£¼«ÎªÆÕ±é£¬£¬£¬ËùÓÐʹÓÃÀϰ汾aptµÄÖ÷»ú¶¼Êܵ½Ó°Ïì¡£¡£¡£apt¿ª·¢Ö°Ô±ÒÑÔÚ°æ±¾1.4.9ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/linux-apt-http-hacking.html


2¡¢Check PointÐû²¼2019ÍøÂçÇå¾²±¨¸æ£¬£¬£¬ÖصãÆÊÎöÍøÂç¹¥»÷Ç÷ÊÆ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



ÒÔÉ«ÁÐÇå¾²³§ÉÌCheck PointÐû²¼2019ÍøÂçÇå¾²±¨¸æ£¬£¬£¬»ØÊ×ÁË2018ÄêµÄÍþвÇ÷ÊÆ£¬£¬£¬°üÀ¨´ó¹æÄ£Êý¾Ýй¶¡¢ÀÕË÷Èí¼þ¹¥»÷¡¢¶ñÒâÍÚ¿ó¹¥»÷ºÍAPT¹¥»÷µÈ¡£¡£¡£ÔÚ2018Ä꣬£¬£¬ÍøÂçÍþвÐÎÊÆ¸ü¾ßÌôÕ½ÐÔ£¬£¬£¬¹¥»÷ÕßһֱˢÐÂÆäÍøÂçÎäÆ÷¡¢½ÓÄÉÐµĹ¥»÷ÒªÁìºÍ˳ӦÐÂÐËÊÖÒÕ¡£¡£¡£2018ÄêµÄÍøÂç¹¥»÷¿ÉÒÔ±»¶¨ÐÔΪ¸ü¾ßÕë¶ÔÐÔ£¬£¬£¬ÆäÄ¿µÄÊÇÔì³É¸ü´óµÄÆÆË𣬣¬£¬Ô½À´Ô½¶àµÄ¹¥»÷Ôì³ÉÁËÕû¸ö×éÖ¯µÄ¹Ø±Õ»ò¹ú¼ÊÊÂÎñµÄÈÅÂÒ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2019/01/21/threat-trends-analysis-report/


3¡¢ÐÂÀÕË÷Èí¼þPhobosʹÓÃRDPЧÀÍÈö²¥£¬£¬£¬Õë¶ÔÈ«ÇòÆóÒµ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CoveWareÑо¿Ö°Ô±·¢Ã÷Õë¶ÔÈ«ÇòÆóÒµµÄÐÂÀÕË÷Èí¼þPhobos£¬£¬£¬Phobos·ºÆðÓÚ2018Äê12Ô·ݣ¬£¬£¬²¢ÇÒÓëÀÕË÷Èí¼þDharma±£´æÐí¶àÏàËÆÖ®´¦¡£¡£¡£ÓëDharmaÒ»Ñù£¬£¬£¬PhobosʹÓÿª·ÅµÄ»òÇå¾²ÐԽϲîµÄRDP¶Ë¿Ú¾ÙÐÐÈëÇÖ¡£¡£¡£±»¼ÓÃܵÄÎļþ»á±»Ìí¼Ó.phobosÀ©Õ¹Ãû¡£¡£¡£PhobosÒªÇóÒÔ±ÈÌØ±ÒµÄ·½·¨Ö§¸¶Êê½ð£¬£¬£¬ÆäÀÕË÷Ʊ¾ÝÉϵÄ×ÖÌåºÍÎı¾ÓëDharmaÍêÈ«Ïàͬ¡£¡£¡£Ñо¿Ö°Ô±»¹³ÆPhobosµÄ´ó²¿·Ö´úÂëÒ²ÓëDharmaÒ»Ö¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world/


4¡¢ÀÕË÷Èí¼þSTOPбäÖÖRumba£¬£¬£¬Ö÷Ҫͨ¹ýµÁ°æÈí¼þÈö²¥

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÀÕË÷Èí¼þSTOPµÄбäÖÖRumbaÔÚÒÑÍù30ÌìÄÚÆð¾¢¾ÙÐзַ¢£¬£¬£¬¸Ã±äÌ彫.rumbaÀ©Õ¹Ãû¸½¼Óµ½¼ÓÃÜÎļþºó£¬£¬£¬Ö÷ÒªÀ¦°óÔÚ¹ã¸æÈí¼þ°üºÍÆÆ½â°æÈí¼þÖÐÈö²¥¡£¡£¡£¾Ý±¨µÀ£¬£¬£¬ÕâЩµÁ°æÈí¼þ°üÀ¨Windows¼¤»î¹¤¾ß£¨ÀýÈçKMSPico£©¡¢Cubase¡¢PhotoshopÒÔ¼°ÆäËüÊ¢ÐÐÈí¼þµÄÆÆ½â°æµÈ¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬Ñо¿ÍŶÓÒѾ­Ðû²¼ÁËSTOPµÄÃ⺬»ìÃܹ¤¾ß£¬£¬£¬Êܵ½Ñ¬È¾µÄÓû§¿ÉÒÔÏÂÔØ¸Ã¹¤¾ß¾ÙÐнâÃÜ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-rumba-stop-ransomware-being-installed-by-software-cracks/


5¡¢ÇàÄêѧÉú×éÖ¯AIESECÒâÍâй¶400¶àÍòʵϰÉúÉêÇëÊé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



AIESECÊÇÒ»¼Ò·ÇÓªÀûµÄÇàÄêѧÉú×éÖ¯£¬£¬£¬1ÔÂ11ÈÕÑо¿Ö°Ô±Bob Diachenko·¢Ã÷¸Ã×éÖ¯µÄÒ»¸öElasticsearchÊý¾Ý¿âδÊܱ£» £»£» £»£»¤£¬£¬£¬µ¼ÖÂ400¶àÍò·ÝʵϰÉúÉêÇëÊéй¶¡£¡£¡£ÕâЩÉêÇëÊé°üÀ¨ÉêÇëÈ˵ÄÐÕÃû¡¢ÐԱ𡢳öÉúÈÕÆÚÒÔ¼°ÉêÇëÔµ¹ÊÔ­ÓɵÈСÎÒ˽¼ÒÃô¸ÐÐÅÏ¢¡£¡£¡£AEISECÈ«Çò¸±×ܲÃLaurin Stahl֤ʵÁËÕâһй¶ÊÂÎñ£¬£¬£¬µ«Éù³ÆÖ»Óв»µ½40ÃûÓû§Êܵ½Ó°Ïì¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/01/21/aiesec-data-leak/


6¡¢ÃÀ¹ú¶à¼Ò¶Ä²©ÍøÕ¾Ð¹Â¶1.08ÒڶIJ©ÐÅÏ¢£¬£¬£¬°üÀ¨Óû§Ö§¸¶Êý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



¾ÝZDNet±¨µÀ£¬£¬£¬Çå¾²Ñо¿Ö°Ô±Justin Paine·¢Ã÷Ò»¸öÍøÂç¶Ä²©¼¯ÍŵÄElasticSearchЧÀÍÆ÷δÉèÃÜÂ룬£¬£¬µ¼ÖÂÁè¼Ý1.08ÒڶIJ©ÐÅϢй¶¡£¡£¡£¸ÃЧÀÍÆ÷ÉÏй¶µÄÓû§ÐÅÏ¢°üÀ¨¿Í»§µÄÕæÊµÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØµã¡¢³öÉúÈÕÆÚ¡¢ÍøÕ¾Óû§Ãû¡¢ÕÊ»§Óà¶î¡¢IPµØµã¡¢ä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳÐÅÏ¢ÒÔ¼°ÉϴεǼÐÅÏ¢µÈ¡£¡£¡£±ðµÄ£¬£¬£¬Paine»¹·¢Ã÷1.08ÒÚÌõ¶Ä²©ÐÅÏ¢£¬£¬£¬ÆäÖаüÀ¨¿Í»§µÄ´æ¿î¡¢È¡¿îÒÔ¼°Ö§¸¶ÐÅÏ¢¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí