¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190228

Ðû²¼Ê±¼ä 2019-02-28
1¡¢Android°æSHAREit±£´æ2¸öÎó²î£¬ £¬£¬£¬£¬Ó°Ïì5ÒÚ¶àÓû§

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±ÔÚSHAREitµÄAndroid APPÖз¢Ã÷Á½¸ö¸ßΣÎó²î£¬ £¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÈÆ¹ý×°±¸µÄÉí·ÝÑéÖ¤»úÖÆ²¢ÇÔÈ¡°üÀ¨Ãô¸ÐÐÅÏ¢µÄÎļþ¡£¡£¡£¡£¡£¡£¡£SHAREitÊÇÊÊÓÃÓÚAndroid¡¢iOS¡¢WindowsºÍMacµÄÊ¢ÐÐÎļþ¹²ÏíÓ¦Ó㬠£¬£¬£¬£¬Æ¾Ö¤RedForceÑо¿Ö°Ô±µÄ±íÊö£¬ £¬£¬£¬£¬Android°æSHAREit¾ßÓÐÁè¼Ý5ÒÚÓû§£¬ £¬£¬£¬£¬ÕâЩÓû§¶¼ÈÝÒ×Êܵ½¹¥»÷¡£¡£¡£¡£¡£¡£¡£SHAREitÒÑÔÚ2018Äê3ÔÂÐÞ¸´ÁËÕâЩÎó²î£¬ £¬£¬£¬£¬Ë¼Á¿µ½Îó²îµÄÓ°Ïì¹æÄ£Ì«¹ã£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±ÓÚ±¾ÖÜÒ»²ÅÅû¶ÁËÏà¹ØÏ¸½Ú¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/02/shareit-android-hacking.html

2¡¢À×µç½Ó¿ÚThunderclapÎó²îÔ¤¾¯£¬ £¬£¬£¬£¬¿É¶ÁÈ¡ÄÚ´æÃô¸ÐÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÔÚNDSS 2019Çå¾²¾Û»áÉÏ£¬ £¬£¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËÓ°ÏìÀ×µç½Ó¿ÚµÄThunderclapÎó²î£¬ £¬£¬£¬£¬¸ÃÎó²îÔÊÐí¶ñÒâ×°±¸Ö±½Ó´Ó²Ù×÷ϵͳµÄÄÚ´æÖÐÇÔÈ¡Êý¾Ý£¬ £¬£¬£¬£¬Õâ¿ÉÄܰüÀ¨¸ß¶ÈÃô¸ÐµÄÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£Windows¡¢Mac¡¢LinuxºÍFreeBSDϵͳ¶¼Êܵ½Ó°Ï죬 £¬£¬£¬£¬ÓÈÆäÊÇÆ»¹û×Ô2011ÄêµÄMacBook ProÌõ¼Ç±¾±ã×îÏȼÓÈëÀ×µç½Ó¿Ú£¬ £¬£¬£¬£¬ÏÖ¿îµÄÌõ¼Ç±¾¸üÊÇËùÓÐÅ䱸ÁËÀ×µç3½Ó¿Ú¡£¡£¡£¡£¡£¡£¡£Æ»¹ûÔÚ2016Äê±ãͨ¹ýmacOS 10.12.4¸üÐÂÐÞ¸´Á˸ÃÎó²î£¬ £¬£¬£¬£¬Windows 10Ò²ÔÚ1803Ö®ºóµÄ°æ±¾ÖмÓÈëÁËÀ×µç3½Ó¿ÚµÄÄÚºËDMA±£»£»£»£»£»£»£»¤£¬ £¬£¬£¬£¬±ðµÄ£¬ £¬£¬£¬£¬Ó¢ÌضûÒ²ÔÊÐí»áΪLinuxÄں˵ÄϵͳÌṩÐÞ²¹¶¡£¬ £¬£¬£¬£¬½«ÔÚ5.0ÄÚºËʱ·Å³ö¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/thunderclap-flaws-impact-how-windows-mac-linux-handle-thunderbolt-peripherals/

3¡¢NVIDIAÐû²¼GPUÇý¶¯³ÌÐòµÄÇå¾²¸üУ¬ £¬£¬£¬£¬ÐÞ¸´8¸öÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

NVIDIAÐû²¼ÆäGPUÇý¶¯³ÌÐòµÄÇå¾²¸üУ¬ £¬£¬£¬£¬ÐÞ¸´ÁËGeForce¡¢Quadro¡¢NVSºÍTeslaµÈ²úÆ·ÖеÄ8¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£ÕâЩÎó²î¿Éµ¼Ö´úÂëÖ´ÐС¢¾Ü¾øÐ§ÀÍ¡¢È¨ÏÞÌáÉý»òÐÅϢй¶µÈ£¬ £¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì×°ÖøüС£¡£¡£¡£¡£¡£¡£ÆäÖÐ5¸öÎó²îµÄCVSSÆÀ·ÖΪ8.8£¬ £¬£¬£¬£¬°üÀ¨3DÊÓ¾õ×é¼þÖеÄÎó²î£¨CVE?2019?5665£©ºÍÄÚºËģʽ²ãnvlddmkm.sysÖеÄËĸöÎó²î£¨CVE?2019?5666¡«CVE?2019?5669£©¡£¡£¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/nvidia-patches-high-risk-vulnerabilities-gpu-display-drivers

4¡¢Ë¼¿ÆWebEx MeetingsÐÂÎó²î£¬ £¬£¬£¬£¬¿ÉÌáȨÖÁSYSTEM

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ñо¿Ö°Ô±ÔÚ˼¿ÆWebex MeetingsµÄWindows×ÀÃæÓ¦ÓÃÖз¢Ã÷Ò»¸öÌáȨÎó²î£¬ £¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-1674£©¿ÉÔÊÐíÎÞÌØÈ¨µÄÍâµØ¹¥»÷ÕßÌáȨÖÁSYSTEMȨÏÞ²¢Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËWebEx°æ±¾33.6.4.15ÖÁ33.8.2.7£¬ £¬£¬£¬£¬Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬ £¬£¬£¬£¬¸ÃÎó²îÊÇ˼¿ÆÔÚÐÞ¸´DLLÐ®ÖÆÎó²î£¨CVE-2018-15442£©Ê±ÒýÈëµÄÒ»¸öÐÂÎó²î¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-elevation-of-privilege-vulnerability-found-in-cisco-webex-meetings/

5¡¢ÃϼÓÀ­´óʹ¹Ý¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬¹ÙÍø±»Ö²Èë¶ñÒâ´úÂë

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÃϼÓÀ­¹úפ¿ªÂÞ´óʹ¹ÝµÄ¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬µ±Óû§»á¼ûÈκÎÒ³ÃæÊ±£¬ £¬£¬£¬£¬½«»áÇ¿ÖÆÏÂÔØÃûΪConference_Details.docxµÄ¶ñÒâWordÎĵµ¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤TrustwaveµÄ±¨¸æ£¬ £¬£¬£¬£¬¸Ã¶ñÒâÎĵµÊ¹ÓÃÁËÎó²îCVE-2017-0261£¬ £¬£¬£¬£¬²¢ÏòÓû§×°ÖÃMSBuld.exeÎļþ¡£¡£¡£¡£¡£¡£¡£VirusTotalµÄ¼ì²âЧ¹ûÅú×¢ÕâÊÇÒ»¸öÃÜÂëÇÔȡľÂí¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚTrustwave²¢Î´ÄÜÓëÍøÕ¾ËùÓÐÕßÁªÏµÉÏ£¬ £¬£¬£¬£¬Òò´ËÄ¿½ñ¸ÃÍøÕ¾ÈÔ´¦ÓÚ±»Ñ¬È¾×´Ì¬¡£¡£¡£¡£¡£¡£¡£
  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/web-site-for-a-bangladesh-embassy-compromised-with-malicious-docs/

6¡¢ä¯ÀÀÆ÷ÍÚ¿ó¾ç±¾Coinhive½«ÓÚ3ÔÂ8ÈÕ×èֹЧÀÍ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CoinhiveÐû²¼½«ÓÚ3ÔÂ8ÈÕ×èֹЧÀÍ¡£¡£¡£¡£¡£¡£¡£CoinhiveÊÇÒ»¸öJavaScriptÍÚ¿ó¾ç±¾£¬ £¬£¬£¬£¬Ö¼ÔÚÔÊÐíÍøÕ¾Ê¹Óûá¼ûÕßµÄCPU×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£¡£¡£¡£¡£Æä¼´½«¹Ø±ÕµÄÔµ¹ÊÔ­ÓÉÊÇÃÅÂÞ±ÒµÄ×îºóÒ»¸öÓ²·Ö²æµ¼Ö¹þÏ£ÂÊϽµÁË50%£¬ £¬£¬£¬£¬ÒÔ¼°ÃÅÂÞ±ÒÔÚÒ»ÄêÄÚ±áÖµÁè¼Ý85%¡£¡£¡£¡£¡£¡£¡£ÔÚ2019Äê3ÔÂ8ÈÕÖ®ºó£¬ £¬£¬£¬£¬¸ÃÍÚ¿ó¾ç±¾½«×èֹЧÀÍ£¬ £¬£¬£¬£¬µ«Óû§ÈÔ¿ÉÒÔÔÚ4ÔÂ30ÈÕ֮ǰ»¨¹âÆäÓà¶î¡£¡£¡£¡£¡£¡£¡£ÕâÒ»ÐÂÎÅÒâζ×Å´ó×ÚʹÓÃCoinhive¾ç±¾µÄ¶ñÒâÍÚ¿ó»î¶¯Ò²½«×èÖ¹¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/technology/coinhive-in-browser-cryptomining-service-shuts-down-on-march-8/

ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí