¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬£¬£¬ £¬£¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª£»£»£» £»£»£»£»Ê׸ö´ó¹æÄ£Ê¹ÓÃBlueKeepÎó²îµÄÍøÂç¹¥»÷»î¶¯

Ðû²¼Ê±¼ä 2019-11-04
1¡¢Ê׸ö´ó¹æÄ£Ê¹ÓÃBlueKeepÎó²îµÄÍøÂç¹¥»÷±»·¢Ã÷

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Ç徲ר¼ÒKevin BeaumontÔÚÖÜÁù·¢Ã÷Ê׸öʹÓÃBlueKeepÎó²îµÄ´ó¹æÄ£ºÚ¿Í¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬ÆäʱËûµÄ¶à¸öEternalPot RDPÃÛ¹ÞϵͳͻȻÍß½â²¢ÖØÆô¡£¡£¡£¡£¸Ã¹¥»÷Ö¼ÔÚÈö²¥ÃÅÂÞ±ÒÍÚ¿óľÂí¡£¡£¡£¡£Çå¾²Ñо¿Ö°Ô±Marcus HutchinsÆÊÎöÆäcrash dumpÎļþºóÈ·ÈÏÁËÕâÒ»·¢Ã÷£¬£¬£¬ £¬£¬£¬µ«ÌåÏָöñÒâ´úÂëÉв»¾ß±¸×ÔÎÒÈö²¥¹¦Ð§¡£¡£¡£¡£¹¥»÷ÕßËÆºõÊÇÏÈ´ÓInternetÉÏɨÃèÒ×Êܹ¥»÷µÄϵͳ£¬£¬£¬ £¬£¬£¬È»ºóÔÙ¹¥»÷ËüÃÇ¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú´Ë´Î¹¥»÷ÒѾ­Ñ¬È¾Á˼¸¶àϵͳ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/bluekeep-rdp-vulnerability.html

2¡¢Ñо¿Ö°Ô±Åû¶rConfigÖеÄÁ½¸öδÐÞ²¹RCEÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Çå¾²Ñо¿Ö°Ô±ÔÚrConfig¹¤¾ßÖз¢Ã÷Á½¸öδÐÞ¸´µÄÒªº¦RCEÎó²î£¬£¬£¬ £¬£¬£¬²¢Åû¶ÁËÏà¹ØPoC¡£¡£¡£¡£rConfigÊÇÓÃPHP±àдµÄ¿ªÔ´ÍøÂç×°±¸ÉèÖù¤¾ß£¬£¬£¬ £¬£¬£¬Æ¾Ö¤¸ÃÏîÄ¿µÄÍøÕ¾£¬£¬£¬ £¬£¬£¬rConfig±»ÓÃÓÚÖÎÀíÁè¼Ý330Íò¸öÍøÂç×°±¸¡£¡£¡£¡£ÕâÁ½¸öÎó²î°üÀ¨ajaxServerSettingsChk.phpÖÐδ¾­Éí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16662£©ºÍsearch.crud.phpÖо­ÓÉÉí·ÝÑéÖ¤µÄRCE£¨CVE-2019-16663£©¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýGET²ÎÊý»á¼ûÎļþ²¢ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£ËùÓа汾µÄrConfig¶¼ÊÜÓ°Ï죬£¬£¬ £¬£¬£¬°üÀ¨×îа汾3.9.2¡£¡£¡£¡£rConfigÏîĿά»¤ÕßÉÐδ¶ÔÎó²î¾ÙÐлØÓ¦£¬£¬£¬ £¬£¬£¬Òò´ËÄ¿½ñûÓпÉÓõÄÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/rConfig-network-vulnerability.html

3¡¢Å¦Ô¼²¼Â³¿ËÁÖÒ½ÔºÔâ¶ñÒâÈí¼þ¹¥»÷ÇÒÊý¾ÝÎÞ·¨»Ö¸´

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ŦԼ²¼Â³¿ËÁÖÒ½ÔºÖÐÐÄÐû²¼Êý¾Ýй¶֪ͨ³Æ£¬£¬£¬ £¬£¬£¬¸ÃÒ½ÔºÔÚ7ÔÂÏÂÑ®·¢Ã÷ЧÀÍÆ÷Éϱ£´æÄ³Ð©Òì³£»£»£» £»£»£»£»î¶¯£¬£¬£¬ £¬£¬£¬¾­ÓÉÊÓ²ì¸ÃҽԺȷ¶¨Ä³Ð©¼ÓÃÜÀà¶ñÒâÈí¼þÆÆËðÁËҽԺϵͳµÄÔËÐС£¡£¡£¡£Ã»ÓÐÖ¤¾ÝÅúעδ¾­ÊÚȨµÄȦÍâÈËÏÖʵ»á¼û»ò»ñÈ¡ÁËÊý¾Ý£¬£¬£¬ £¬£¬£¬µ«Ä³Ð©»¼ÕßÊý¾ÝÎÞ·¨»Ö¸´£¬£¬£¬ £¬£¬£¬°üÀ¨»¼ÕßµÄÐÕÃûºÍÐÄÔà¡¢ÑÀ³ÝͼÏñ¡£¡£¡£¡£¸ÃÒ½ÔºÉÐδ·¢Ã÷ÈκÎÏÖʵ»òÊÔͼ»á¼û¡¢ÀÄÓÃÒ½ÁÆÐÅÏ¢/СÎÒ˽¼ÒÐÅÏ¢µÄÇéÐΡ£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/brooklyn-hospital-center-notice-data-230000523.html

4¡¢Î¬¶û¾©ÈºµºWAPA³ÉΪClick2GovÊý¾Ýй¶µÄ×îÐÂÊܺ¦Õß

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úά¶û¾©ÈºµºË®µç¾Ö£¨WAPA£©³ÉΪÊÜClick2GovÊý¾Ýй¶²¨¼°µÄ×îÐÂÊܺ¦Õß¡£¡£¡£¡£Central Square TechnologiesÊÇWAPAÓÃÀ´´¦Öóͷ£ÐÅÓÿ¨¸¶¿îµÄµÚÈý·½¹©Ó¦ÉÌ£¬£¬£¬ £¬£¬£¬WAPAÌåÏÖËü×î³õÔÚ10ÔÂ18ÈÕµÃÖªÁË¿ÉÄܵÄÎ¥¹æÊÂÎñ£¬£¬£¬ £¬£¬£¬µ«CSTÆäʱȷÈϸ¶¿îÃÅ»§ÍøÕ¾²¢Î´Êܵ½Ë𺦣¬£¬£¬ £¬£¬£¬Ö±µ½µÚ¶þλ¿Í»§ÓÚ10ÔÂ22ÈÕ֪ͨWAPAÓйØÐÅÓÿ¨µÄÀàËÆÊÂÎñ£¬£¬£¬ £¬£¬£¬CST²ÅÈ·ÈÏÊܵ½Click2GovÊÂÎñµÄ²¨¼°¡£¡£¡£¡£ÏÖÔÚÊÜÓ°ÏìµÄWAPA¿Í»§ÊýĿδ֪¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://stcroixsource.com/2019/10/31/wapa-advises-customers-to-continue-monitoring-credit-card-accounts-for-fraudulent-charges/

5¡¢µÂ¿ËÈøË¹ÖÝÐÂÊý¾Ýй¶֪ͨ·¨°¸½«ÓÚ2020ÄêÆðʵÑé


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¿ËÈøË¹ÖݵÄÐÂÊý¾Ýй¶֪ͨ·¨°¸½«ÓÚ2020Äê1ÔÂ1ÈÕÆðʵÑé¡£¡£¡£¡£¸Ã·¨°¸ÐÞÕýÁË¡¶µÂ¿ËÈøË¹ÖÝÉí·Ý͵ÇÔÖ´·¨ºÍ±£»£»£» £»£»£»£»¤·¨¡·£¬£¬£¬ £¬£¬£¬ÒªÇóÆóÒµÔÚÈ·¶¨±¬·¢Êý¾ÝÎ¥¹æºóÔÚ60ÌìÄÚ֪ͨµÂ¿ËÈøË¹ÖÝסÃñ¡£¡£¡£¡£±ðµÄ£¬£¬£¬ £¬£¬£¬ÈôÊÇÎ¥¹æÊÂÎñÓ°ÏìÁËÁè¼Ý250ÃûµÂ¿ËÈøË¹ÖÝסÃñ£¬£¬£¬ £¬£¬£¬ÆóÒµ±ØÐèÔÚͳһʱ¼ä£¨60Ì죩ÄÚÏòÖÝ˾·¨²¿³¤ÌṩÊÂÎñ֪ͨ£¬£¬£¬ £¬£¬£¬¸Ã֪ͨӦ¸Ã°üÀ¨ÏêϸÊÂÎñÐÎò/ʹÓõÄÃô¸ÐÐÅÏ¢¡¢ÊÜÓ°ÏìµÄÈËÊý¡¢ÒѽÓÄɼ°½«Òª½ÓÄɵIJ½·¥ÒÔ¼°ÊÇ·ñÒÑִ֪ͨ·¨²¿·ÖµÈÐÅÏ¢¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.natlawreview.com/article/texas-updates-data-breach-notification-requirements

6¡¢¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÉúЧ£¬£¬£¬ £¬£¬£¬¿ÉÓëÈ«Çò»¥ÁªÍø¶Ï¿ª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¶íÂÞ˹¡°Ö÷Ȩ»¥ÁªÍø¡±Ö´·¨ÔÚÉÏÖÜÎåÉúЧ£¬£¬£¬ £¬£¬£¬Õ⽫ʹ¶íÂÞ˹Õþ¸®Äܹ»½«¸Ã¹úÓëÈ«Çò»¥ÁªÍø¶Ï¿ªÅþÁ¬¡£¡£¡£¡£ÕâÏîÖ´·¨ÓÉÆÕ¾©×ÜͳÔÚ5Ô·ÝÇ©Ê𣬣¬£¬ £¬£¬£¬ÒªÇóISP×°ÖÃÕþ¸®ÌṩµÄÊÖÒÕ×°±¸ÒÔ¾ÙÐÐÁ÷Á¿¼ì²é£¬£¬£¬ £¬£¬£¬Õâ¿ÉÄÜΪ´ó¹æÄ£¼àÊÓ·­¿ªÁË´óÃÅ¡£¡£¡£¡£Æ¾Ö¤¶íÂÞ˹Õþ¸®µÄ˵·¨£¬£¬£¬ £¬£¬£¬¸ÃÖ´·¨Ö¼ÔÚÈ·±£×ÝÈ»¶Ï¿ªÓëÈ«Çò»¥ÁªÍøµÄÅþÁ¬Ò²¿ÉÒÔ»á¼û¶íÂÞ˹վµã£¬£¬£¬ £¬£¬£¬ÒÔÓ¦¶ÔÓÉÍøÂç¹¥»÷»òÇå¾²ÊÂÎñµ¼ÖµÄÖÐÖ¹¡£¡£¡£¡£¸ÃÖ´·¨½«Ê¹¶íÂÞ˹Õþ¸®Äܹ»Éó²éÔÚÏßÄÚÈݲ¢¼àÊÓÍøÃñ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/93315/laws-and-regulations/russia-controversial-law-russia.html