¶à¸öÔ¼»áAPPÊý¾Ý¿âÎÞÃÜÂëµ¼Ö½ü4250ÍòÓû§¼Í¼й¶£»£»£»£»£»£»PyramidÒâÍâй¶¶à¼ÒÂùݵÄ85GBÇå¾²Éó¼ÆÈÕÖ¾

Ðû²¼Ê±¼ä 2019-05-31
1¶à¸öÔ¼»áAPPÊý¾Ý¿âÎÞÃÜÂëµ¼Ö½ü4250ÍòÓû§¼Í¼й¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±Jeremiah Fowler·¢Ã÷Ò»¸öδÉèÃÜÂëµÄElasticÊý¾Ý¿â£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨¶à¸öÔ¼»áappµÄ½ü4250ÍòÓû§¼Í¼¡£¡£¡£Êܵ½Ó°ÏìµÄÔ¼»áapp°üÀ¨Cougardating¡¢Christiansfinder¡¢Mingler¡¢FwbsºÍTS£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢´ó´ó¶¼ÊôÓÚÃÀ¹úÓû§£¬£¬£¬£¬£¬°üÀ¨Óû§Ãû¡¢ÄêËꡢλÖúÍIPµØµãµÈÐÅÏ¢¡£¡£¡£Ö»¹ÜÕâЩԼ»áappʹÓÃÁËͳһ¸öÊý¾Ý¿â£¬£¬£¬£¬£¬µ«ËüÃÇÉù³ÆÏ໥֮¼äÊÇ×ÔÁ¦µÄ¹«Ë¾»òСÎÒ˽¼Ò¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/unprotected-database-exposes-almost-425-million-records-from-chinese-dating-apps-bb4950a4

2Checkers²ÍÌüPoSϵͳ±»Ö²Èë¶ñÒâ´úÂ룬£¬£¬£¬£¬¿Í»§Ö§¸¶ÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÁ¬Ëø²ÍÒûµêCheckers and Rally'sÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÆäPoSϵͳÉÏÖ²ÈëÁ˶ñÒâÈí¼þ£¬£¬£¬£¬£¬µ¼Ö²¿·Ö¿Í»§µÄÖ§¸¶ÐÅÏ¢±»ÇÔ¡£¡£¡£Æ¾Ö¤CheckersÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬£¬¸ÃÊÂÎñÓ°ÏìÁË102¸öCheckers²ÍÌü£¬£¬£¬£¬£¬Ô¼Õ¼ÆäËùÓвÍÌüµÄ15%¡£¡£¡£¸Ã¹«Ë¾ÁгöÁËÿ¸ö²ÍÌüÊܶñÒâÈí¼þÓ°ÏìµÄʱ¼ä¶Î£¬£¬£¬£¬£¬´ó´ó¶¼Ñ¬È¾±¬·¢ÔÚ2018ÄêÖÁ2019ÄêÖ®¼ä£¬£¬£¬£¬£¬Ò²ÓÐÉÙÊýѬȾ±¬·¢ÔÚ2016ºÍ2017Äê¡£¡£¡£¹¥»÷ÕßÖ²ÈëµÄ¶ñÒâÈí¼þÖ¼ÔÚ´ÓÒøÐп¨´ÅÌõÖÐÇÔÊØÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨³Ö¿¨ÈËÐÕÃû¡¢ÒøÐп¨ºÅ¡¢ÑéÖ¤ÂëºÍµ½ÆÚÈÕÆÚµÈ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/checkers-drive-in-restaurants-suffered-malware-attack-impacting-102-checkers-and-rallys-locations-f31199f1

3PyramidÒâÍâй¶¶à¼ÒÂùݵÄ85GBÇå¾²Éó¼ÆÈÕÖ¾

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

VpnMentorÑо¿Ö°Ô±Noam RotemºÍRan Locar·¢Ã÷ÂùݺͶȼٴåÖÎÀí¹«Ë¾Pyramid Hotel GroupµÄÒ»¸öElasticsearchÊý¾Ý¿âδÉèÃÜÂ룬£¬£¬£¬£¬µ¼Ö¶à¼ÒÂùݵÄ85GBÇå¾²Éó¼ÆÈÕ־й¶¡£¡£¡£ÊÜÓ°ÏìµÄÂùݰüÀ¨ÍòºÀ¡¢ÑÅÀÖÐù¡¢ÈøÀ­Ë÷ËþµÈ£¬£¬£¬£¬£¬Ð¹Â¶µÄÐÅÏ¢¿É×·ËÝÖÁ2019Äê4ÔÂ19ÈÕ£¬£¬£¬£¬£¬°üÀ¨Ð§ÀÍÆ÷APIÃÜÔ¿ºÍÃÜÂë¡¢×°±¸Ãû³Æ¡¢´«ÈëÅþÁ¬µÄIPµØµã¡¢·À»ðǽ¡¢¿ª·Å¶Ë¿ÚÊý¾Ý¡¢¶ñÒâÈí¼þ¾¯±¨¡¢µÇ¼ʵÑé¼Í¼µÈ¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/unsecured-database-exposes-security-logs-of-major-hotel-chains/

4WordPress²å¼þConvert PlusÐÂÎó²î£¬£¬£¬£¬£¬¿É½¨ÉèÖÎÀíÔ±ÕË»§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


DefiantÑо¿Ö°Ô±·¢Ã÷WordPress²å¼þConvert Plus±£´æÒ»¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß½¨Éè¾ßÓÐÖÎÀíԱȨÏÞµÄÕË»§¡£¡£¡£¸ÃÎó²îÔ´ÓÚͨ¹ý²å¼þ±íµ¥´¦Öóͷ£ÐÂÓû§¶©ÔÄʱȱÉÙ¹ýÂË¡£¡£¡£ÔÚ²»¹ýÂËж©ÔĵÄÇéÐÎÏ£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÌá½»±íµ¥²¢ÐÞ¸Äcp_set_user×Ö¶ÎÖµ£¨½«ÆäÉèÖÃΪadministrator£©£¬£¬£¬£¬£¬´Ó¶øÔÚÍøÕ¾ÉϽ¨ÉèÐÂÖÎÀíÔ±ÕË»§¡£¡£¡£Ð½¨ÉèµÄÕË»§¾ßÓÐËæ»úµÄÃÜÂ룬£¬£¬£¬£¬µ«¹¥»÷Õß¿ÉÒÔÇëÇóÖØÖÃÃÜÂë¡£¡£¡£¸ÃÎó²îÓ°ÏìÁË3.4.2¼°Ö®Ç°µÄËùÓа汾£¬£¬£¬£¬£¬½¨ÒéÓû§¸üÐÂÖÁ°æ±¾3.4.3¡£¡£¡£¸Ã²å¼þµÄ×°ÖÃÁ¿Ô¼Îª10Íò´Î¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/convert-plus-plugin-flaw-lets-attackers-become-a-wordpress-admin/

5жñÒâÈí¼þHiddenWasp£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔLinuxϵͳ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Intezer LabsÇå¾²Ñо¿Ô±Nacho Sanmillan·¢Ã÷ÐÂLinux¶ñÒâÈí¼þHiddenWasp£¬£¬£¬£¬£¬¸Ã¶ñÒâÈí¼þÓÉÓû§Ä£Ê½rootkit¡¢Ä¾ÂíºÍ³õʼ°²Åž籾×é³É¡£¡£¡£Ñо¿Ö°Ô±³ÆHiddenWaspÓëÁíÒ»¸ö½üÆÚ·¢Ã÷µÄLinux¶ñÒâÈí¼þWennti¾ßÓÐÏàËÆµÄ½á¹¹£¬£¬£¬£¬£¬²¢ÇÒʹÓÃÁ˲¿·ÖChinaZ¡¢Adore-ng¼°MiraiµÄ´úÂë¡£¡£¡£HiddenWasp±»ÓÃ×÷µÚ¶þ½×¶Îpayload£¬£¬£¬£¬£¬µ«¹¥»÷µÄ³õÊ¼Ñ¬È¾ÔØÌåÉв»ÇåÎú¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-hiddenwasp-malware-found-targeting-linux-systems/

6APT×éÖ¯Turlaй¥»÷»î¶¯£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ESETÑо¿Ö°Ô±·¢Ã÷APT×éÖ¯TurlaµÄй¥»÷»î¶¯£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃеÄTTPÕë¶Ô¶«Å·µØÇøµÄÍâ½»»ú¹¹¡£¡£¡£¹¥»÷ÕßʹÓûùÓÚPowerShellµÄй¤¾ßÀ´ÊµÑéÎÞÎļþ¹¥»÷£¬£¬£¬£¬£¬ÆäÊͷŵÄpayload°üÀ¨»ùÓÚRPCµÄºóÃźÍʹÓÃOneDrive×÷ΪC&CЧÀÍÆ÷µÄºóÃÅ¡£¡£¡£ESETÑо¿Ô±Matthieu FaouÒÔΪÕâЩÊÖÒÕÕý±»¸Ã×éÖ¯ÓÃÓÚ¹¥»÷È«Çò¹æÄ£ÄÚµÄTurlaÄ¿µÄ¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/eset-exposes-turla-malware-1/