MacOS 0day¿ÉÄ£ÄâÊó±êµã»÷ÒÔÖ´ÐжñÒâ´úÂ룻£»£»£»£» £»£»SUPRAÖÇÄܵçÊÓÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂ×°±¸±»Ð®ÖÆ

Ðû²¼Ê±¼ä 2019-06-04
1MacOS 0day¿ÉÄ£ÄâÊó±êµã»÷ÒÔÖ´ÐжñÒâ´úÂë


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Digita SecurityÑо¿Ö°Ô±Patrick WardleÅû¶macOSÖеÄÒ»¸ö0day£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷Õßͨ¹ýÄ£ÄâÊó±êµã»÷ÒÔÈÆ¹ýmacOSµÄÇå¾²²½·¥²¢Ö´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓëmacOSÑéÖ¤Ó¦ÓóÌÐòµÄ·½·¨Óйأ¬£¬£¬£¬£¬£¬£¬Ò»Ð©Ó¦ÓóÌÐòÔÚ×°ÖÃ֮ǰ²»ÐèÒªÈκΡ°ÔÊÐí¡±»ò¡°¾Ü¾ø¡±Çå¾²¶Ô»°¿ò£¬£¬£¬£¬£¬£¬£¬ÀýÈçVLCýÌå²¥·ÅÆ÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâ°æ±¾µÄVLCÀ´Ö´ÐжñÒâÐÐΪ£¬£¬£¬£¬£¬£¬£¬ÀýÈç·­¿ªÂó¿Ë·ç»òÇÔÈ¡GPD×ø±êÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/macos-zero-day-malicious-code/145259/

2SUPRAÖÇÄܵçÊÓÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂ×°±¸±»Ð®ÖÆ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±Dhiraj Mishra·¢Ã÷SUPRAÖÇÄܵçÊÓÊܵ½Î´ÐÞ²¹µÄÔ¶³ÌÎļþ°üÀ¨Îó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-12477£©¿ÉÔÊÐíWiFi¹¥»÷ÕßÔÚδ¾­Éí·ÝÑéÖ¤µÄÇéÐÎÏÂÐ®ÖÆµçÊÓÆÁÄ»²¥·ÅÐéαÊÓÆµ¡£¡£¡£¡£¡£¡£SUPRAÊÇÒ»¸ö¶íÂÞ˹µç×ÓÆ·ÅÆ£¬£¬£¬£¬£¬£¬£¬Æä²úÆ·Ö÷ÒªÔÚ¶íÂÞ˹¡¢ÖйúºÍ°¢ÁªÇõÏúÊÛ¡£¡£¡£¡£¡£¡£¸ÃÎó²î±£´æÓÚSupra Smart Cloud TVµÄ¡°openLiveURL¡±¹¦Ð§ÖУ¬£¬£¬£¬£¬£¬£¬ËäÈ»¸ÃÎó²îÒÑ»ñµÃCVE ID£¬£¬£¬£¬£¬£¬£¬µ«¿ÉÄܲ»»á»ñµÃÐÞ²¹¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/06/supra-smart-tv-hack.html

3QuestÐÞ¸´Kace K1000×°±¸ÖеĶà¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤¿¨ÄÚ»ù÷¡´óѧCERT/CCÐû²¼µÄÒ»·Ý±¨¸æ£¬£¬£¬£¬£¬£¬£¬Quest¹«Ë¾µÄKace K1000×°±¸Êܵ½¶à¸öÎó²îµÄÓ°Ï죬£¬£¬£¬£¬£¬£¬°üÀ¨SQLäעÎó²î£¨CVE-2018-5404£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Ãô¸ÐÐÅÏ¢£©¡¢JavaScript´úÂë×¢ÈëÎó²î£¨CVE-2018-5405£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¹¥»÷ÕßÐ®ÖÆÖÎÀíÔ±»á»°£©ÒÔ¼°¿ÉÔÊÐí¹¥»÷ÕßÌí¼ÓÖÎÀíÔ±ÕË»§»ò¸ü¸Ä×°±¸ÉèÖÃÐÅÏ¢µÄÎó²î£¨CVE-2018-5406£©µÈ¡£¡£¡£¡£¡£¡£QuestÒÑÔÚ9.0.270¼°¸ü¸ß°æ±¾ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/serious-vulnerabilities-found-kace-k1000-appliance

4ºÚ¿Íͨ¹ýÈõÃÜÂëÈëÇÖÊý°ÙÃû°£Èû¶í±ÈÑÇÌØ¹¤ÓÊÏä


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


°£Èû¶í±ÈÑÇÐÅÏ¢ÍøÂçÇå¾²¾Ö£¨INSA£©µÄÊý°ÙÃûÌØ¹¤µÄµç×ÓÓÊÏäÒòʹÓÃÈõÃÜÂë±»ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£Æ¾Ö¤Safety DetectiveÑо¿Ö°Ô±µÄÊӲ죬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ×ÓÚÍÆ²âµÄÓû§ÃûºÍÃÜÂë»ñµÃÁ˶ÔÕâÐ©ÌØ¹¤ÓÊÏäµÄδÊÚȨ»á¼û¡£¡£¡£¡£¡£¡£ÔÚÊÜËðµÄ300¸öƾ֤ÖУ¬£¬£¬£¬£¬£¬£¬ÓÐ142¸öʹÓÃÁËÈõÃÜÂë¡°p@$$w0rd¡±£¬£¬£¬£¬£¬£¬£¬±ðµÄ£¬£¬£¬£¬£¬£¬£¬ÓÐ62¸öÃÜÂë°üÀ¨¡°123¡±ÐòÁС£¡£¡£¡£¡£¡£²¢ÇÒINSA²¢Î´¶ÔÃÜÂë¾ÙÐмÓÑκ͹þÏ£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/emails-of-hundreds-of-ethiopias-information-network-security-agency-agents-hacked-due-to-predictable-passwords-40bbc358

5AMCAÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ1190ÍòQuest Diagnostics»¼ÕßÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÕ˵¥Ð§À͹«Ë¾AMCAÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂѪҺ¼ì²â¹«Ë¾Quest DiagnosticsµÄ1190Íò»¼ÕßÐÅϢй¶¡£¡£¡£¡£¡£¡£Æ¾Ö¤AMCAµÄͨ¸æ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñ±¬·¢ÔÚ2018Äê8ÔÂ1ÈÕÖÁ2019Äê3ÔÂ30ÈÕʱ´ú£¬£¬£¬£¬£¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁËAMCAµÄϵͳ£¬£¬£¬£¬£¬£¬£¬¸Ãϵͳ°üÀ¨Quest DiagnosticsµÄ»¼ÕßÐÅÏ¢¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÒøÐÐÕË»§Êý¾ÝºÍÐÅÓÿ¨ºÅµÈ²ÆÎñÐÅÏ¢ÒÔ¼°Ò½ÁÆÐÅÏ¢ºÍÉç»áÇå¾²ºÅÂëµÈСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£¡£¡£QuestºÍAMCAÕýÔÚ¶Ô´ËÊÂÎñ¾ÙÐÐÊӲ졣¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/billing-details-for-119m-quest-diagnostics-clients-exposed/

6ÃÀLewes¹«¹²¹¤³ÌίԱ»áÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬¿Í»§ÐÅϢй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤ÃÀ¹úÁìÍÁÇå¾²²¿µÄÖÒÑÔ£¬£¬£¬£¬£¬£¬£¬Lewes¹«¹²¹¤³ÌίԱ»áÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬²¿·Ö¿Í»§ÐÅϢй¶¡£¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢ÐÅÓÿ¨ÐÅÏ¢¡¢ÒøÐÐÕË»§ÏêϸÐÅÏ¢¡¢Õ˺𢯾֤ºÍµ½ÆÚÈÕÆÚ¡£¡£¡£¡£¡£¡£¸ÃίԱ»áÔÚ5ÔÂ28ÈÕ·¢Ã÷ÁËÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¢Á¬Ã¦¸ôÀëÁ˿ͻ§ÐÅϢϵͳºÍ֪ͨÏà¹ØÈí¼þ¹©Ó¦ÉÌ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÕýÔÚ½øÒ»²½µÄÊÓ²ìÖ®ÖС£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/lewes-board-of-public-works-notifies-customers-of-potential-data-breach-b5f45004