ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý£» £»£»£»¹È¸è½«ÔÚChrome 78ÖвâÊÔ»ùÓÚHTTPSµÄDNS¹¦Ð§£» £»£»£»

Ðû²¼Ê±¼ä 2019-09-12

1.¹È¸è½«ÔÚChrome 78ÖвâÊÔ»ùÓÚHTTPSµÄDNS¹¦Ð§


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¹È¸èÒѾ­Ðû²¼ÍýÏëÔÚ½ñÄê10ÔÂÏÂÑ®Ðû²¼µÄChrome v78°æ±¾ÖÐÕýʽ²âÊÔеÄDNS-over-HTTPS£¨DoH£©Ð­Òé¡£¡£¡£¡£¡£DoHµÄDNSÇëÇó×÷Ϊ¼ÓÃܵÄHTTPSÁ÷Á¿Í¨¹ý¶Ë¿Ú443·¢ËÍ£¬£¬£¬ £¬ £¬¶ø²»ÊÇͨ¹ý¶Ë¿Ú53ÒÔÃ÷ÎÄ·¢ËÍ¡£¡£¡£¡£¡£Õâ¿ÉÒÔ×èÖ¹µÚÈý·½ÊÓ²ìÕßͨ¹ý¼Í¼ºÍÉó²éδ¼ÓÃܵÄDNSÊý¾ÝÀ´¸ú×ÙÓû§µÄä¯ÀÀÀúÊ·¼Í¼¡£¡£¡£¡£¡£¹ØÓÚÆðÔ´²âÊÔ£¬£¬£¬ £¬ £¬¹È¸èÌåÏÖÖ»»áΪÉÙÊýDNSÌṩÉÌÇл»µ½DoH£¬£¬£¬ £¬ £¬Ö§³ÖµÄDNSÌṩÉÌÁбí°üÀ¨Cleanbrowsing¡¢Cloudflare¡¢DNS.SB¡¢Google¡¢OpenDNSºÍQuad9¡£¡£¡£¡£¡£Mozilla֮ǰҲÐû²¼ÍýÏëÔÚ±¾ÔÂÍíЩʱ¼äΪÃÀ¹úµÄһС²¿·ÖÓû§Öð²½ÆôÓÃDoH¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/chrome-dns-over-https.html


2.Dealer LeadsÒâÍâй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë±£» £»£»£»¤£¬£¬£¬ £¬ £¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉÏ̻¶¡£¡£¡£¡£¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÄ¿µÄÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬£¬£¬ £¬ £¬Çå¾²Ñо¿Ô±Jeremiah FowlerÌåÏÖÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µÑо¿ÐÅÏ¢ºÍ·ÖÀà¹ã¸æ£¬£¬£¬ £¬ £¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾­ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý¡£¡£¡£¡£¡£¸Ã̻¶µÄÊý¾Ý¿â×ܹ²°üÀ¨413GBÐÅÏ¢£¬£¬£¬ £¬ £¬°üÀ¨Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÎïÀíµØµã¡¢IPµØµãÒÔ¼°´û¿îºÍ²ÆÎñÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/198m-car-buyer-records-exposed-online/148231/


3.ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±·¢Ã÷Ò»ÖÖеIJàÐŵÀ¹¥»÷£¬£¬£¬ £¬ £¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´ÖÆÔìµÄËùÓÐÏÖ´úÓ¢ÌØ¶ûЧÀÍÆ÷´¦Öóͷ£Æ÷¡£¡£¡£¡£¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬£¬£¬ £¬ £¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/OÊÖÒÕ£¨DDIO£©ÓйØ£¬£¬£¬ £¬ £¬DDIOÔÚ×îеÄÓ¢ÌØ¶ûЧÀÍÆ÷¼¶´¦Öóͷ£Æ÷ÖÐĬÈÏ·­¿ª£¬£¬£¬ £¬ £¬°üÀ¨Intel Xeon E5¡¢E7ºÍSP´¦Öóͷ£Æ÷ϵÁС£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2019-11184£©µÄʹÓÃÄѶȽϸߣ¬£¬£¬ £¬ £¬¹¥»÷ÕßÐèÒª¾ÙÐÐÉí·ÝÑéÖ¤£¬£¬£¬ £¬ £¬²¢ÇÒÐèÒªÓëÄ¿µÄϵͳ½¨ÉèÖ±½ÓÍøÂçÅþÁ¬¡£¡£¡£¡£¡£Ó¢Ìضû½«¸ÃÎó²îµÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬£¬£¬ £¬ £¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMA¹¦Ð§£¬£¬£¬ £¬ £¬»òÏÞÖÆ´ÓÍⲿ²»ÊÜÐÅÈεÄÍøÂçÖ±½Ó»á¼ûÒ×Êܹ¥»÷µÄϵͳ¡£¡£¡£¡£¡£ÌØÁíÍ⻺½â²½·¥°üÀ¨Ê¹ÓÃÄܹ»¶Ô¿¹×¼Ê±¹¥»÷µÄÈí¼þÄ£¿£¿£¿£¿£¿é»òʹÓúã׼ʱ¼äÑùʽµÄ´úÂë¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/netcat-intel-side-channel.html


4.D-LinkºÍComba·ÓÉÆ÷Îó²î¿Éµ¼ÖÂÃ÷ÎÄÃÜÂëй¶


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

TrustwaveÑо¿Ö°Ô±·¢Ã÷D-LinkºÍComba TelecomµÄWiFi·ÓÉÆ÷±£´æ¶à¸öÎó²î¡£¡£¡£¡£¡£ËùÓÐÕâЩÎó²î¶¼Éæ¼°²»Çå¾²µÄƾ֤´æ´¢£¬£¬£¬ £¬ £¬ÆäÖÐÈý¸öÎó²î¿Éµ¼ÖÂÃ÷ÎÄÃÜÂëй¶¡£¡£¡£¡£¡£Simon KeninÌåÏÖÔÚD-Link DSLµ÷ÖÆ½âµ÷Æ÷Öз¢Ã÷Á½¸öÎó²î£¬£¬£¬ £¬ £¬¶øÔÚComba Telecom WiFi×°±¸Öз¢Ã÷Èý¸öÎó²î£¬£¬£¬ £¬ £¬ÕâЩÎó²î¿ÉÔÊÐí¹¥»÷Õ߸ü¸Ä×°±¸ÉèÖá¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐÐMitM¹¥»÷ÒÔ¼°Öض¨ÏòÖÁ´¹ÂÚÍøÕ¾µÈ¡£¡£¡£¡£¡£D-LinkÔÚ9ÔÂ6ÈÕÐû²¼Á˹̼þÐÞ¸´²¹¶¡£¬£¬£¬ £¬ £¬µ«CombaÉÐδÐÞ¸´ÕâЩÎó²î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/router-password-hacking.html


5.Î÷ÃÅ×ÓÍÆ³öDejaBlue¡¢Urgent/11ºÍSACK PanicÎó²îµÄÐÞ¸´²¹¶¡


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


±¾ÖܶþÎ÷ÃÅ×ÓÐû²¼¼¸·ÝÇ徲ͨ¸æ£¬£¬£¬ £¬ £¬ÍƳö×î½üµÄDejaBlue¡¢Urgent/11ºÍSACK PanicÎó²îµÄÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£Î÷ÃÅ×ÓÌåÏÖ£¬£¬£¬ £¬ £¬Î¢ÈíÔÚ8Ô·ÝÐÞ²¹µÄËĸöWindowsÔ¶³Ì×ÀÃæÐ§ÀÍÎó²îÓ°ÏìÁ˲¿·ÖHealthineers²úÆ·£¬£¬£¬ £¬ £¬µ«´ó´ó¶¼Ò½ÁƲúƷδÊÜÓ°Ïì¡£¡£¡£¡£¡£ÕâЩÎó²î±»×·×ÙΪDejaBlue£¬£¬£¬ £¬ £¬Óë΢ÈíÔÚ5Ô·ÝÐÞ¸´µÄBlueKeepÀàËÆ¡£¡£¡£¡£¡£Î÷ÃÅ×Ó»¹¼û¸æ¿Í»§ÆäÐí¶à²úÆ·Êܵ½×î½üÅû¶µÄLinuxÄÚºËÎó²î£¨SACK Panic£©µÄÓ°Ï죬£¬£¬ £¬ £¬ÆäÖÐ×îÑÏÖØµÄÒ»¸öÎó²îΪ¿Éµ¼ÖÂDoSµÄÎó²î£¨CVE-2019-11477£©¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬ £¬Î÷ÃÅ×ÓRUGGEDCOM WIN²úÆ·Êܵ½×î½üÅû¶µÄWind River VxWorksÎó²î£¨Urgent/11£©Ó°Ïì¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-issues-advisories-dejablue-sack-panic-vulnerabilities


6.ÃÀ¹úÖÆÔìÉ̳ÉΪLokiBot¶ñÒâ»î¶¯µÄ×îй¥»÷Ä¿µÄ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÒ»¼ÒδÅû¶Ãû³ÆµÄ´óÐÍÖÆÔ칫˾³ÉΪLokiBotľÂíµÄ×îй¥»÷Ä¿µÄ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ8ÔÂ21ÈÕÊ×´ÎÊӲ쵽¸Ã¹¥»÷»î¶¯£¬£¬£¬ £¬ £¬¸ÃÀ¬»øÓʼþÊÇ´Ó¿ÉÄÜÔâµ½ÉøÍ¸µÄ¡°¿ÉÐÅ¡±·¢¼þÈË·¢Ë͸øÄ¿µÄÆóÒµµÄÏúÊÛ²¿·Ö¡£¡£¡£¡£¡£Óʼþαװ³É±¨¼ÛÇëÇ󣬣¬£¬ £¬ £¬µ«ÏÖʵÉÏ·Ö·¢LokiBotľÂí¡£¡£¡£¡£¡£Æ¾Ö¤FortinetÑо¿Ö°Ô±µÄÆÊÎö£¬£¬£¬ £¬ £¬´Ë´ÎLokiBotÑù±¾µÄÎļþ¾ÞϸΪ286KB£¬£¬£¬ £¬ £¬×î½ü±àÒëʱ¼äΪ8ÔÂ21ÈÕ£¬£¬£¬ £¬ £¬Ç¡Ç¡ÓëÀ¬»øÓʼþµÄ·¢ËÍÈÕÆÚÏàͬ¡£¡£¡£¡£¡£´Ë´Î¹¥»÷µÄIPµØµã×¢²áµ½ÑÇÀûÉ£ÄÇÖÝ·ï»Ë³ÇµÄÒ»¼ÒÍøÕ¾ÍйÜЧÀÍÌṩÉÌ£¨Ãû³ÆÎªLeaseWeb USA£©£¬£¬£¬ £¬ £¬´ËÇ°ÔøÔÚ6Ô·ݱ¬·¢µÄÀ¬»øÓʼþ¹¥»÷ÖÐʹÓùýÁ½´Î¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/u-s-manufacturer-most-recent-target-of-lokibot-malspam-campaign/148153/