Hyper-VÐéÄâ»úÌÓÒÝ·´ÏòRDPÎó²î£» £»£»£»£»Ñо¿Ö°Ô±Åû¶²¨Òô787ÄÚ²¿ÍøÂçÖеĶà¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2019-08-09
1¡¢Ñо¿Ö°Ô±Åû¶¿Éµ¼ÖÂHyper-VÐéÄâ»úÌÓÒݵķ´ÏòRDPÎó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Check PointÑо¿Ö°Ô±Eyal ItkinÔÚBlackHat USA 2019ÉÏÅû¶Á˿ɵ¼Ö·´ÏòRDP¹¥»÷µÄÒ»¸öÎó²î£¬£¬£¬£¬¸ÃÎó²î£¨CVE-2019-0887£©¿ÉÓÃÓÚÌÓÒÝHyper-VÐéÄâ»ú¡£¡£¡£¡£¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ±íÊö£¬£¬£¬£¬Hyper-VÖÎÀíÆ÷µÄÔöÇ¿»á»°Ä£Ê½Ê¹ÓÃÁËRDPÏàͬµÄʵÏÖ£¬£¬£¬£¬ÓÃÓÚÔÚÖ÷»úºÍÐéÄâ»úÖ®¼ä¹²Ïí×ÊÔ´£¬£¬£¬£¬ÀýÈç¼ôÌù°åµÈ¡£¡£¡£¡£¡£ÕâÒâζ×ÅHyper-VÖÎÀíÆ÷Ò²Êܵ½RDPÖеÄÎó²îÓ°Ïì¡£¡£¡£¡£¡£¶ñÒâRDPЧÀÍÆ÷¿Éͨ¹ýÏò¼ôÌù°å·¢ËͶñÒâÄÚÈÝ×îÖÕÔÚËÞÖ÷»úÉÏ´¥·¢Â·¾¶±éÀú¡£¡£¡£¡£¡£Î¢ÈíÔÚ7Ô·ÝÐû²¼µÄWindowsÇå¾²¸üÐÂÖо²Ä¬ÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/08/reverse-rdp-windows-hyper-v.html


2¡¢Ñо¿Ö°Ô±ÔÚ6ÖÖÆóÒµ´òÓ¡»úÖз¢Ã÷Áè¼Ý35¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

NCC GroupÑо¿Ö°Ô±ÔÚ6ÖÖÖ÷Á÷ÐÍºÅµÄÆóÒµ´òÓ¡»úÖз¢Ã÷ÖÁÉÙ35¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÕâЩÎó²îµÄÓ°Ïì¹æÄ£°üÀ¨´òÓ¡»úÍ߽⣨¾Ü¾øÐ§ÀÍ£©¡¢¼à¿Ø´òÓ¡×÷ÒµÒÔ¼°Î´ÊÚȨ·¢ËÍ´òÓ¡×÷ÒµµÈ¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ³§ÉÌÆ·ÅưüÀ¨»ÝÆÕ¡¢Àí¹â¡¢Xerox¡¢ÀûÃË¡¢KyoceraºÍBrother¡£¡£¡£¡£¡£ËùÓеÄÎó²îҪôÒѾ­±»ÐÞ¸´£¬£¬£¬£¬ÒªÃ´¼´½«Ðû²¼ÐÞ¸´²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬Ñо¿Ö°Ô±½«ÔÚÖÜÁùµÄDEF CON´ó»áÉÏÅû¶¸ü¶àÊÖÒÕϸ½Ú¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/office-printers-hackers-open-door/147083/


3¡¢Ñо¿Ö°Ô±Åû¶²¨Òô787ÄÚ²¿ÍøÂçÖеĶà¸öÇå¾²Îó²î

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

IOActiveÑо¿Ö°Ô±Ruben SantamartaÔÚBlack Hat´ó»áÉÏÅû¶Á˲¨Òô787ÃλÿͻúÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£ÕâЩÎó²îÓë·É»úµÄ³ÉÔ±ÐÅϢЧÀÍ/ά»¤ÏµÍ³£¨CIS/MS£©Óйأ¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÏò·É»úµÄÒªº¦Ç徲ϵͳ£¨ÀýÈçÒýÇæ¡¢Öƶ¯ÏµÍ³¡¢´«¸ÐÆ÷£©·¢ËͶñÒâÏÂÁî¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¹¥»÷Õß»¹¿Éͨ¹ýÈëÇÖ·É»úµÄÎÀÐÇ×°±¸¼°ÎÞÏßͨѶÇþµÀÏòά»¤¹¤³ÌʦÌṩ¹ýʧµÄϵͳÐÅÏ¢¡£¡£¡£¡£¡£²¨ÒôÉù³ÆÕâЩÎÊÌâ²»»á×é³ÉÍøÂçÍþв£¬£¬£¬£¬ÓÉÓÚÆä·À»¤²½·¥¿ÉÒÔ×èÖ¹´ËÀ๥»÷¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.wired.com/story/boeing-787-code-leak-security-flaws/?verso=true


4¡¢PearsonÊý¾Ýй¶²¨¼°Indian Prairie 204Ñ§Çø½ü5ÍòÃûѧÉú

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ƾ֤Indian Prairie 204Ñ§ÇøÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬Pearson¹«Ë¾ÔâÓöµÄÊý¾Ýй¶ÊÂÎñ²¨¼°µ½¸ÃÑ§ÇøµÄ4.9ÍòÃûѧÉúÒÔ¼°2300ÃûÔ±¹¤¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄѧÉúÊÇÔÚ2001ÖÁ2016ѧÄêʱ´ú×¢²áµÄѧÉú£¬£¬£¬£¬Ð¹Â¶µÄѧÉúÐÅÏ¢½ö°üÀ¨ÐÕÃûÒÔ¼°³öÉúÈÕÆÚ£¬£¬£¬£¬²»°üÀ¨ÈκÎЧ¹û¡¢Ñ§ºÅµÈÐÅÏ¢¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄÔ±¹¤ÐÅÏ¢Ôò°üÀ¨ÐÕÃû¼°Ñ§Ð£µç×ÓÓʼþµØµã¡£¡£¡£¡£¡£Pearson½«ÎªÊÜÓ°ÏìµÄѧÉúºÍÔ±¹¤ÌṩÃâ·ÑµÄÐÅÓñ£» £»£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttp://www.ipsd.org/news.aspx?id=104263


5¡¢SuperINNÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Áè¼Ý4.3Íò¿Í»§µÄÒþ˽ÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Sark Technologies¹«Ë¾¿ª·¢µÄÔ¤Ô¼ÖÎÀíÈí¼þSuperINN±£´æÎó²î£¬£¬£¬£¬µ¼ÖÂÆäÊý¾Ý¿â±»ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Áè¼Ý4.3ÍòÓû§µÄÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÓÚ2019Äê5ÔÂ26ÈÕ·¢Ã÷ÈëÇÖÊÂÎñ£¬£¬£¬£¬Æ¾Ö¤¸Ã¹«Ë¾µÄÊӲ죬£¬£¬£¬SuperINNµÄͼÏñÉÏ´«¹¦Ð§±£´æÎó²î£¬£¬£¬£¬µ¼Ö¹¥»÷ÕßÔÚ2018Äê9ÔÂ23ÈÕÉÏ´«ÁËPHP web shell£¬£¬£¬£¬²¢×îÖÕÓÚ2019Äê1ÔÂ1ÈÕÖÁ5ÔÂ30ÈÕʱ´ú»á¼ûÁËÓû§Êý¾Ý¿â¡£¡£¡£¡£¡£Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç»°ºÅÂë¡¢ÓʼþµØµã¡¢¼ÓÃܵÄÐÅÓÿ¨ºÅµÈ¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬¹¥»÷Õß»¹Ê¹ÓÃSuperINNÖеÄÒ»¸öSQL×¢ÈëÎó²îÇÔÈ¡Á˼ÓÃܵijֿ¨ÈËÐÅÏ¢¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://oag.ca.gov/system/files/Sark%20Notice%20of%20Data%20Security%20Incident%20%28California%29_1.PDF

6¡¢ÃÀ¹ú¹ú¼Ò°ôÇòÃûÈËÌùÙÍøÑ¬È¾MageCart¾ç±¾£¬£¬£¬£¬¿Í»§ÐÅÓÿ¨ÐÅÏ¢ÔâÇÔ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

λÓÚŦԼ¿â²®Ë¹¶ÙµÄÃÀ¹ú¹ú¼Ò°ôÇòÃûÈËÌÃ×î½üÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬ÒòÓÉÊÇÆä¹ÙÍø±»Ö²Èë¶ñÒâMageCart¾ç±¾£¬£¬£¬£¬µ¼ÖÂÔÚÍøÕ¾ÉϹºÎïµÄÏûºÄÕßÐÅÓÿ¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ2018Äê11ÔÂ15ÈÕÖÁ2019Äê5ÔÂ14ÈÕʱ´ú£¬£¬£¬£¬¸Ã¹«Ë¾ÓÚ2019Äê6ÔÂ18Èղŷ¢Ã÷ÎÊÌâ¡£¡£¡£¡£¡£±»ÇÔµÄÐÅÏ¢°üÀ¨ÏûºÄÕßµÄÐÕÃû¡¢µØµãÒÔ¼°ÐÅÓÿ¨/½è¼Ç¿¨ÐÅÏ¢£¬£¬£¬£¬°üÀ¨CVVÂë¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎúÏêϸµÄÊÜÓ°ÏìÈËÊý¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/national-baseball-hall-of-fame-hit-by-payment-card-stealing-attack/