Wi-FiÈÈÃŲéÕÒÆ÷й¶200ÍòWi-FiÃÜÂ룻£»£»£»£»¹ã¸æÈí¼þPreAMoÏÂÔØ´ï9000Íò´Î£»£»£»£»£»123456ÈÔÊÇ×î³£ÓÃÃÜÂë

Ðû²¼Ê±¼ä 2019-04-23
1.NCSCÐû²¼×î³£±»ºÚ¿ÍÈëÇÖµÄÃÜÂëÁÐ±í £¬£¬£¬123456ÈÔ±»Êý°ÙÍòÈËʹÓÃ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢¹ú¹ú¼ÒÍøÂçÇå¾²ÖÐÐÄ£¨NCSC£©Ðû²¼×î³£±»ºÚ¿ÍÈëÇÖµÄÃÜÂëÁÐ±í £¬£¬£¬ÒÔÃãÀøÓû§Ñ¡ÔñÇ¿ÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£Æ¾Ö¤ÕâÏîÑо¿ £¬£¬£¬È«ÇòÈÔÓÐ2320Íò¸öÕË»§Ê¹ÓÃ123456×÷ΪÃÜÂë £¬£¬£¬ÕâÒ²ÊÇʹÓÃÊýÄ¿×î¶àµÄÈõÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£µÚ¶þÃûÊÇ123456789 £¬£¬£¬ÓÐ770Íò¸öÕË»§Ê¹ÓÃÁ˸ÃÃÜÂë¡£¡£¡£¡£¡£¡£ ¡£È»ºóÊÇqwerty£¨380Íò£©¡¢password£¨360Íò£©ºÍ111111£¨310Íò£©¡£¡£¡£¡£¡£¡£ ¡£Óû§¿ÉÒÔ´ÓHave I Been PwnedÍøÕ¾Éϼì²â×Ô¼ºµÄÃÜÂëÔÚÁбíÖзºÆðµÄ´ÎÊý¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.digitaltrends.com/computing/online-passwords-research-confirms-millions-are-using-123456/

2.Google PlayÖÐ¹ã¸æÈí¼þPreAMo £¬£¬£¬ÏÂÔØÁ¿´ï9000Íò´Î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


CheckpointÑо¿Ö°Ô±ÔÚGoogle PlayÖз¢Ã÷¹ã¸æÈí¼þPreAMo £¬£¬£¬¸Ã¹ã¸æÈí¼þαװ³É6¸öAPP £¬£¬£¬×ÜÏÂÔØÁ¿Áè¼Ý9000Íò´Î¡£¡£¡£¡£¡£¡£ ¡£PreAMoÖ÷ÒªÕë¶ÔÈý¸ö¹ã¸æÊðÀíÉÌ - Presage¡¢AdmobºÍMopub¾ÙÐÐڲƭ £¬£¬£¬¹¥»÷ÕßÕë¶Ôÿ¸ö¹ã¸æÊðÀíÉÌʹÓòî±ðµÄ´¦Öóͷ£ÒªÁì £¬£¬£¬µ«Ê¹ÓÃÁËÏàͬµÄC£¦CЧÀÍÆ÷£¨res.mnexuscdn[.]com£© £¬£¬£¬ÓÃÓÚ·¢ËÍͳ¼ÆÐÅÏ¢ºÍÎüÊÕÉèÖÃÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£Google PlayÔÚ½Óµ½±¨¸æºóÒѾ­Ï¼ÜÁËÕâЩÊÜѬȾµÄAPP¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://research.checkpoint.com/preamo-a-clicker-campaign-found-on-google-play/

3.jQueryÐû²¼Ð°汾v3.4.0 £¬£¬£¬ÐÞ¸´prototype pollutionÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

jQueryÔÚа汾v3.4.0ÖÐÐÞ¸´ÁËÒ»¸ö±»³ÆÎª¡°Ô­ÐÍÎÛȾ£¨prototype pollution£©¡±µÄÇå¾²Îó²î¡£¡£¡£¡£¡£¡£ ¡£Ô­ÐÍÎÛȾÊÇÖ¸¹¥»÷Õßͨ¹ýijÖÖÊÖ¶ÎÐÞ¸ÄJavaScript¹¤¾ßµÄprototype £¬£¬£¬Í¨¹ý´¥·¢JavaScriptÒì³£µ¼Ö¾ܾøÐ§ÀÍ»ò¸Ä¶¯Ô´´úÂë¾ÙÐÐ×¢Èë £¬£¬£¬×îÖÕµ¼ÖÂÓ¦ÓóÌÐòÍ߽⻣»£»£»£»òÐ®ÖÆ¡£¡£¡£¡£¡£¡£ ¡£ËäÈ»Îó²îÑÏÖØÐÔ½Ï¸ß £¬£¬£¬µ«Ô­ÐÍÎÛȾ¹¥»÷²¢²»¿É±»´ó¹æÄ£Ê¹Óà £¬£¬£¬ÓÉÓÚ¹¥»÷´úÂë±ØÐèÕë¶Ô²î±ðµÄÄ¿µÄ¾ÙÐÐ΢µ÷¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/popular-jquery-javascript-library-impacted-by-prototype-pollution-flaw/

4.Wi-FiÈÈÃŲéÕÒÆ÷й¶200ÍòWi-FiÃÜÂë


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤TechCrunchµÄ±¨¸æ £¬£¬£¬Ò»¸öÃûΪWiFi FinderµÄAndroid APPй¶ÁËÁè¼Ý200Íò¸öWi-FiÍøÂçµÄÃÜÂë £¬£¬£¬ÆäÖÐÊýÍò¸öWi-FiÈÈÃÅλÓÚÃÀ¹ú¡£¡£¡£¡£¡£¡£ ¡£¸ÃAPPÓÃÓÚ×ÊÖúÓû§²éÕÒWi-FiÈÈÃÅ £¬£¬£¬ÆäÏÂÔØÁ¿´ïÊýǧ´Î¡£¡£¡£¡£¡£¡£ ¡£Ñо¿Ö°Ô±·¢Ã÷¸ÃAPPµÄÊý¾Ý¿â̻¶ÔÚÍøÉÏÇÒδÊܱ£»£»£»£»£»¤ £¬£¬£¬Êý¾Ý¿âÖеļͼ°üÀ¨Wi-FiÍøÂçµÄÃû³Æ¡¢×¼È·µÄµØÀíλÖá¢BSSIDºÍÃ÷ÎÄÃÜÂë £¬£¬£¬µ«²»°üÀ¨Wi-FiËùÓÐÕßµÄÁªÏµÐÅÏ¢¡£¡£¡£¡£¡£¡£ ¡£ÔÆÐ§À͹«Ë¾DigitalOceanÔÚ½Óµ½±¨¸æºóɾ³ýÁ˸ÃÊý¾Ý¿â¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/leaky_app_data/144029/

5.Steps To RecoveryÒ½ÁÆÖÐÐÄÒâÍâй¶14.6Íò»¼ÕßÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±öϦ·¨ÄáÑÇÖÝÒ½ÁÆÖÐÐÄSteps To RecoveryµÄÒ»¸öElasticSearchÊý¾Ý¿âÒòÉèÖùýʧ¶øÎ´Êܱ£»£»£»£»£»¤ £¬£¬£¬µ¼ÖÂ146316Ãû»¼ÕßµÄPIIÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£¸ÃÊý¾Ý¿â¾ÞϸΪ1.45GB £¬£¬£¬°üÀ¨491Íò¸öÏà¹ØÎĵµ¡£¡£¡£¡£¡£¡£ ¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨»¼ÕßµÄÄêËê¡¢³öÉúÈÕÆÚ¡¢Ä¿½ñµØµã¡¢ÒÑÍùµÄµØµã¡¢µç×ÓÓʼþµØµãÒÔ¼°»¼Õß¾ìÊôµÄÐÕÃûºÍµç»°ºÅÂë¡£¡£¡£¡£¡£¡£ ¡£¸ÃÒ½ÁÆÖÐÐÄÉÐδ֪ͨÊÜÓ°ÏìµÄ»¼Õß¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/misconfigured-elasticsearch-database-exposes-49-million-sensitive-documents-of-steps-to-recovery-treatment-center-1e460888

6.Bodybuilding.comÔâ´¹ÂÚ¹¥»÷ £¬£¬£¬²¿·ÖÔ±¹¤µÄÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Bodybuilding.comÐû²¼ÉùÃ÷³Æ¸Ã¹«Ë¾Ôâµ½´¹ÂÚ¹¥»÷ £¬£¬£¬²¿·ÖÔ±¹¤µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÔÚ4Ô·ݵÄÊÓ²ìÅú×¢ £¬£¬£¬´¹ÂÚ¹¥»÷±¬·¢ÔÚ2018Äê7Ô £¬£¬£¬¹¥»÷Õß¿ÉÄÜ»á¼ûÁ˲¿·ÖÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢ £¬£¬£¬°üÀ¨ÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢Õ˵¥/ËÍ»õµØµã¡¢µç»°ºÅÂë¡¢¶©µ¥ÀúÊ·µÈ £¬£¬£¬µ«²»°üÀ¨ÍêÕûµÄÐÅÓÿ¨»ò½è¼Ç¿¨ºÅÂë¡£¡£¡£¡£¡£¡£ ¡£¸Ã¹«Ë¾ÕýÔÚÓëÖ´·¨»ú¹¹ºÍÇ徲ר¼ÒÏàÖú½â¾ö¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.databreaches.net/bodybuilding-com-experiences-data-security-incident/