ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥(Õ÷ÇóÒâ¼û¸å)£»£»£»£»£»ºÚ¿ÍÔÚÍøÉÏÐû²¼¿ªÂüÒøÐеÄ2TBÊý¾Ý£»£»£»£»£»DockerÌÓÒÝÎó²î

Ðû²¼Ê±¼ä 2019-11-21
1¡¢ÍøÐŰìÐû²¼¡¶ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥(Õ÷ÇóÒâ¼û¸å)¡·

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ΪÓÐÓÃÓ¦¶ÔÍøÂçÇå¾²ÍþвºÍΣº¦£¬£¬£¬£¬£¬°ü¹ÜÍøÂçÔËÐÐÇå¾²£¬£¬£¬£¬£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ20Èվ͡¶ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÕæÕ÷ÇóÉç»áÒâ¼û£¬£¬£¬£¬£¬¶ÔÐû²¼ÍøÂçÇå¾²ÍþвÐÅÏ¢µÄÐÐΪ×÷³ö¹æ·¶¡£¡£¡£Æ¾Ö¤Õ÷ÇóÒâ¼û¸å£¬£¬£¬£¬£¬ÍøÂçÇå¾²ÍþвÐÅÏ¢°üÀ¨(Ò»)¶Ô¿ÉÄÜÍþÐ²ÍøÂçÕý³£ÔËÐеÄÐÐΪ£¬£¬£¬£¬£¬ÓÃÓÚÐÎòÆäÒâͼ¡¢ÒªÁì¡¢¹¤¾ß¡¢Àú³Ì¡¢Ð§¹ûµÈµÄÐÅÏ¢£»£»£»£»£»(¶þ)¿ÉÄÜÌ»Â¶ÍøÂçųÈõÐÔµÄÐÅÏ¢¡£¡£¡£Õ÷ÇóÒâ¼û¸åÃ÷È·£¬£¬£¬£¬£¬Ðû²¼ÍøÂçÇå¾²ÍþвÐÅÏ¢£¬£¬£¬£¬£¬Ó¦ÒÔά»¤ÍøÂçÇå¾²¡¢Ôö½øÍøÂçÇå¾²ÒâʶÌáÉý¡¢½»Á÷ÍøÂçÇå¾²·À»¤ÊÖÒÕ֪ʶΪĿµÄ£¬£¬£¬£¬£¬²»µÃΣº¦¹ú¼ÒÇå¾²ºÍÉç»á¹«¹²ÀûÒæ£¬£¬£¬£¬£¬²»µÃÇÖÕ¼¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄÕýµ±È¨Òæ¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2019-11/20/c_1575785387932969.htm

2¡¢ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬CLI×°Öðü±»Ì滻Ϊ¶ñÒâÈí¼þ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬¹Ù·½Linux CLI¶þ½øÖÆÎļþ±»Ì滻ΪÇÔÈ¡Óû§×ʽðµÄ¶ñÒâÈí¼þ¡£¡£¡£¸ÃÊÂÎñ±¬·¢ÔÚ11ÔÂ18ÈÕ£¬£¬£¬£¬£¬Ò»ÃûÓû§ÔÚGithubÉϱ¨¸æÁ˸ÃÎÊÌ⣬£¬£¬£¬£¬ÃÅÂÞ±ÒÍŶÓËæºó¾ÙÐÐÁËÈ·ÈÏ¡£¡£¡£½¨ÒéÔÚ18ºÅ2:30 AM UTCÖÁ4:30 PM UTCÖ®¼äÏÂÔØÁËCLIÇ®°üµÄÓû§¼ì²éÆä¶þ½øÖÆÎļþµÄ¹þÏ£Öµ£¬£¬£¬£¬£¬ÈôÊÇÓë¹ÙÍøÉϵĹþÏ£Öµ²»Æ¥Å䣬£¬£¬£¬£¬Ôò²»ÒªÔËÐиÃÈí¼þ²¢É¾³ýËü¡£¡£¡£Ä¿½ñÃÅÂÞ±ÒÍŶÓÌåÏÖÈÔÔÚÊӲ칥»÷ÕßÔõÑùÈëÇÖÆäÏÂÔØÐ§ÀÍÆ÷£¬£¬£¬£¬£¬ÏÖÔÚÉв»ÇåÎúÓм¸¶àÓû§ÔÚÕâ´ÎºÚ¿Í¹¥»÷ÖÐËðʧÁË×ʽ𡣡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/official-monero-website-compromised-with-malware-that-steals-funds/

3¡¢GateHubºÍEpicBotµÄ220ÍòÓû§Êý¾ÝÔÚÍøÉϹûÕæ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Çå¾²Ñо¿Ô±Troy HuntÌåÏÖ¼ÓÃÜÇ®±ÒÇ®°üЧÀÍGateHubºÍÓÎÏ·ÍøÕ¾EpicBotµÄ220Óû§ÕË»§Êý¾ÝÔÚÍøÉϹûÕæ¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨140Íò¸öGateHubÕÊ»§ºÍ80Íò¸öEpicBotÕÊ»§µÄÐÅÏ¢£¬£¬£¬£¬£¬Èçµç×ÓÓʼþµØµãºÍ¾­ÓÉbcrypt´¦Öóͷ£µÄ¹þÏ£ÃÜÂë¡£¡£¡£GateHubÈÏ¿ÉÔÚÑ×ÌìÔâµ½ºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬µ«ÆäʱÌåÏÖ½öÓÐ18473¸ö¿Í»§ÕË»§±»²»·¨»á¼û£¬£¬£¬£¬£¬ÏÖÔÚ¿´À´ÕâÒ»¹æÄ£Òª´óµÃ¶à¡£¡£¡£EpicBotÏÖÔÚÉÐδÈÏ¿ÉËüÒѱ»ºÚ¿ÍÈëÇÖ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-dump-2-2m-gaming-cryptocurrency-passwords-online/150451/

4¡¢PayMyTabÒâÍâй¶ÊýǧÃûÃÀ¹ú²Í¹ÝÖ÷¹ËÊý¾Ý

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÒÆ¶¯Ö§¸¶Ð§ÀÍÉÌPayMyTabÒòδ×ñÕÕAWSµÄÇ徲ЭÒ飬£¬£¬£¬£¬µ¼ÖÂÊýǧÃû²Í¹ÝÖ÷¹ËµÄÊý¾Ýй¶¡£¡£¡£¸Ã¹«Ë¾×Ô2018Äê7ÔÂ2ÈÕÆðûÓн«´æ´¢¿Í»§Êý¾ÝµÄAWS S3´æ´¢Í°¸ü¸ÄΪ˽ÓУ¬£¬£¬£¬£¬Ê¹µÃÈκÎÈ˶¼¿ÉÒÔ»á¼ûʹÓÃPayMyTabЧÀ͵IJÍÌüÖ÷¹ËÊý¾Ý£¬£¬£¬£¬£¬°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨ºóËÄλ¡¢¾Í²ÍÂÄÀúµÈÐÅÏ¢¡£¡£¡£Æ¾Ö¤vpnMentorµÄ˵·¨£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â̻¶Á˳¤´ï16¸öÔµÄʱ¼ä£¬£¬£¬£¬£¬ËäȻûÓÐй¶µÄÊý¾ÝÁ¿»ò¿Í»§ÊýÄ¿¼òÖ±ÇÐÊý×Ö£¬£¬£¬£¬£¬µ«ÊýǧÃû¿Í»§¿ÉÄÜÒò´ËÊܵ½ÔÚÏßڲƭ»ò¹¥»÷¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/paymytab-data-leak-exposes-personal-information-belonging-to-mobile-diners/

5¡¢ºÚ¿ÍÔÚÍøÉÏÐû²¼¿ªÂüÒøÐеÄ2TBÊý¾Ý


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ºÚ¿Í´Ó¿ªÂüÒøÐÐÇÔÈ¡ÁË2TBµÄÊý¾Ý²¢Ðû²¼ÔÚÍøÉÏ¡£¡£¡£¾Ý³ÆÕâЩÊý¾ÝÊÇÓɺڿͻòºÚ¿ÍÍÅ»ïPhineas FisherÇÔÈ¡µÄ£¬£¬£¬£¬£¬²¢Í¨¹ýDistributed Denial of SecretsÏîÄ¿Ðû²¼¡£¡£¡£Êý¾Ý¼¯ÖаüÀ¨¿ªÂüÒøÐÐΪÆäÈ«Çò¿Í»§ÖÎÀíµÄÁè¼Ý3800¼Ò¹«Ë¾¡¢ÐÅÍкÍСÎÒ˽¼ÒÕË»§µÄÏêϸ²ÆÎñÐÅÏ¢£¬£¬£¬£¬£¬ÉõÖÁ°üÀ¨ÕË»§Óà¶î¡£¡£¡£¿£¿£¿£¿£¿£¿£¿ªÂüÒøÐв¢Î´ÈÏ¿ÉÊý¾Ýй¶£¬£¬£¬£¬£¬µ«Ç徲ר¼Ò×¢ÖØµ½ÆäÐí¶àЧÀÍÓÚ11ÔÂ17ÈÕÒò¡°ÖØ´óÉý¼¶ºÍά»¤¡±¶ø´¦ÓÚ²»¿ÉÓÃ״̬¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94136/data-breach/cayman-national-bank-data-leak.html

6¡¢DockerÌÓÒÝÎó²î(CVE-2019-14271) PoCÐû²¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ñо¿Ö°Ô±Ðû²¼DockerÌÓÒÝÎó²î£¨CVE-2019-14271£©µÄPoC£¬£¬£¬£¬£¬²¢´ß´ÙÓû§Éý¼¶µ½×îа汾¡£¡£¡£¸ÃÎó²îÔÚ7Ô·ݵÄDocker°æ±¾19.03.1ÖÐÐÞ¸´£¬£¬£¬£¬£¬µ«ÈôÊÇδ´ò²¹¶¡£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜ»áͨ¹ý¶ñÒâÈÝÆ÷¾µÏñÔÚÓû§µÄËÞÖ÷»úÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£¡£¡£Palo Alto NetworksÇå¾²Ñо¿Ô±Yuval Avrahami±Þ²ßDocker¿ª·¢Ö°Ô±Í¨¹ý½öÔËÐÐÊÜÐÅÈεľµÏñÀ´ïÔÌ­¹¥»÷Ãæ£¬£¬£¬£¬£¬²¢½¨ÒéÔÚ²»ÐèÒªrootµÄÇéÐÎÏÂÒÔ·ÇrootÓû§Éí·ÝÔËÐÐÈÝÆ÷¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/researchers-public-poc-docker/