LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾£»£»£»BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ

Ðû²¼Ê±¼ä 2019-12-18



1.LightInTheBoxй¶1.3TB WebЧÀÍÆ÷ÈÕÖ¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


vpnMentorÑо¿Ö°Ô±·¢Ã÷ÔÚÏßÁãÊÛÉÌLightInTheBoxµÄElasticsearchÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬ £¬£¬£¬ÆäÖаüÀ¨1.3TB WebЧÀÍÆ÷ÈÕÖ¾¡£¡£¡£¡£LightInTheBoxרעÓÚСÅä¼þ¡¢´ò°çºÍÅäÊεÄÏúÊÛ£¬£¬£¬£¬ £¬£¬£¬Æä´ó²¿·Ö¿Í»§Î»ÓÚ±±ÃÀºÍÅ·ÖÞ¡£¡£¡£¡£Ñо¿Ö°Ô±ÔÚ11ÔÂÏÂÑ®·¢Ã÷Á˸ÃÊý¾Ý¿â£¬£¬£¬£¬ £¬£¬£¬Êý¾Ý¿âÖеļͼ×ܼÆÁè¼Ý15ÒÚÌõ£¬£¬£¬£¬ £¬£¬£¬»¹°üÀ¨Æä×ÓÍøÕ¾MiniInTheBox.comµÄÊý¾Ý¡£¡£¡£¡£ÈÕÖ¾°üÀ¨8ÔÂ9ÈÕÖÁ10ÔÂ11ÈÕÖ®¼äµÄÍøÕ¾»î¶¯£¬£¬£¬£¬ £¬£¬£¬°üÀ¨µç×ÓÓʼþµØµã¡¢IPµØµã¡¢ÆÜÉí¹ú¼Ò/µØÇøÒÔ¼°Ã¿¸ö·Ã¿Í»á¼ûµÄÒ³ÃæµÈÐÅÏ¢¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/95231/data-breach/lightinthebox-data-leak.html


2.¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÉÌLifeLabsй¶1500Íò¿Í»§ÐÅÏ¢


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¼ÓÄôóÁÙ´²ÊµÑéÊÒЧÀÍÌṩÉÌLifeLabsй¶¶à´ï1500Íò¼ÓÄÃÖÁ¹«ÃñµÄСÎÒ˽¼ÒÐÅÏ¢¡£¡£¡£¡£Æ¾Ö¤ÆäÐû²¼µÄÊý¾Ýй¶֪ͨ£¬£¬£¬£¬ £¬£¬£¬Î´¾­ÊÚȨµÄ¹¥»÷Õß»á¼ûÁË1500Íò¿Í»§µÄÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþ¡¢µÇ¼Ãû¡¢ÃÜÂë¡¢³öÉúÈÕÆÚºÍÒ½ÁÆ¿¨ºÅÂë¡£¡£¡£¡£ÆäÖÐÔ¼8.5Íò¿Í»§µÄʵÑéÊÒЧ¹ûÒ²Ôâй¶¡£¡£¡£¡£¾Ý±¨µÀй¶µÄÊý¾ÝÖ÷ҪΪ2016Ä꼰֮ǰµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬Éæ¼°µÄ¿Í»§¾ø´ó´ó¶¼À´×ÔÓÚ±°Ê«Ê¡ºÍ°²¼òªʡ¡£¡£¡£¡£ÔÚ·¢Ã÷й¶ºó£¬£¬£¬£¬ £¬£¬£¬LifeLabs´ÓºÚ¿ÍÄÇÀﹺÖÃÁ˱»µÁµÄÊý¾Ý£¬£¬£¬£¬ £¬£¬£¬µ«²»ÖªµÀËûÃÇΪ´ËÖ§¸¶Á˼¸¶àÊê½ð¡£¡£¡£¡£LifeLabs½«ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÃâ·ÑÉí·Ý͵ÇÔ±£»£»£»¤Ð§ÀÍ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/lifelabs-data-breach-exposes-personal-info-of-15-million-customers/


3.Ó¢ÌØ¶û¿ìËÙ´æ´¢Èí¼þÖб£´æDLLÐ®ÖÆÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ó¢ÌØ¶û¿ìËÙ´æ´¢ÊÖÒÕ£¨Intel RST£©Èí¼þÖб£´æÒ»¸öDLLÐ®ÖÆÎó²î£¬£¬£¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÔÊÐí¶ñÒâ³ÌÐòÏÔʾΪÊÜÐÅÈγÌÐò£¬£¬£¬£¬ £¬£¬£¬´Ó¶øÈƹý·À²¡¶¾ÒýÇæ¡£¡£¡£¡£SafeBreachµÄÑо¿Ö°Ô±·¢Ã÷IAStorDataMgrSvc.exe½«ÊµÑé´ÓC:\Program Files\Intel\Intel(R) Rapid Storage Technology\Îļþ¼ÐϼÓÔØ4¸öDLL£¨IoctlLog.dll¡¢IoctlNet.dll¡¢IoctlSim.dll¡¢DriverSim.dll£©£¬£¬£¬£¬ £¬£¬£¬µ«ÕâЩDLLÔڸ÷¾¶Ï²¢²»±£´æ£¬£¬£¬£¬ £¬£¬£¬Òò´ËÑо¿Ö°Ô±¿ÉÒÔ½¨Éè×Ô¼ºµÄDLLʹIAStorDataMgrSvc.exeÔÚÆô¶¯Ê±¼ÓÔØ£¬£¬£¬£¬ £¬£¬£¬¸ÃDLL½«ÒÔSYSTEMÌØÈ¨¼ÓÔØ²¢ÊµÖÊÉϾßÓжÔÅÌËã»úµÄÍêÈ«»á¼ûȨÏÞ¡£¡£¡£¡£Ó¢ÌضûÒÑÓÚ12ÔÂ10ÈÕÐû²¼ÁË¿ìËÙ´æ´¢Èí¼þµÄ¸üаæÔ­À´½â¾ö¸ÃÎó²î¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/update-intels-rapid-storage-app-to-fix-bug-letting-malware-evade-av/


4.˼¿ÆTalosÅû¶WAGO PLCÖеĶà¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


˼¿ÆTalosÑо¿Ö°Ô±ÔÚWAGOÖÆÔìµÄ¿É±à³ÌÂß¼­¿ØÖÆÆ÷£¨PLC£©Öз¢Ã÷¶à¸öÑÏÖØÎó²î£¬£¬£¬£¬ £¬£¬£¬ÕâЩÎó²î¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐС¢¾Ü¾øÐ§À͹¥»÷»ò»ñȡװ±¸µÄµÇ¼ƾ֤¡£¡£¡£¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨WAGO PFC200ºÍPFC100¿ØÖÆÆ÷£¬£¬£¬£¬ £¬£¬£¬ËüÃDZ»ÆÕ±éÓÃÓÚÆû³µ¡¢Ìú·¡¢µçÁ¦¹¤³Ì¡¢ÖÆÔìºÍÐÞ½¨ÎïÖÎÀíµÈÐÐÒµÖС£¡£¡£¡£Õâ9¸öÎó²î£¨CVE-2019-5073~CVE-2019-5075£¬£¬£¬£¬ £¬£¬£¬CVE-2019-5077~CVE-2019-5082£©µÄ»ù´¡Ôµ¹ÊÔ­ÓÉÔÚÓÚ¿ØÖÆÆ÷ʹÓõÄÊäÈë/Êä³ö¼ì²éÉèÖÃЧÀ͵ÄЭÒé´¦Öóͷ£´úÂëÖб£´æÎÊÌâ¡£¡£¡£¡£TalosÌåÏÖûÓÐÖ¤¾ÝÅú×¢ÕâЩÎó²îÒÑÔÚÒ°ÍⱻʹÓᣡ£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/several-critical-vulnerabilities-found-wago-controllers


5.F-SecureÔÚClickShareÎÞÏßÑÝʾϵͳÖз¢Ã÷¶à¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


F-SecureÑо¿Ö°Ô±·¢Ã÷°Í¿É£¨Barco£©¹«Ë¾ClickShareÎÞÏßÑÝʾϵͳ±£´æ¶à¸ö¿É±»Ê¹ÓõÄÇå¾²Îó²î£¬£¬£¬£¬ £¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²ºÍ¸Ä¶¯ÑÝʾÀú³ÌÖеÄÐÅÏ¢¡¢ÇÔÈ¡ÃÜÂëµÈÉñÃØÐÅÏ¢ÒÔ¼°×°ÖúóÃÅºÍÆäËü¶ñÒâÈí¼þµÈ¡£¡£¡£¡£ÕâЩÎó²îµÄCVE IDΪCVE-2017-7936¡¢CVE-2017-7932ÒÔ¼°CVE-2019-18824~CVE-2019-18833¡£¡£¡£¡£Ñо¿Ö°Ô±ÓÚ10ÔÂ9ÈÕÓë°Í¿É·ÖÏíÁËÕâЩ·¢Ã÷£¬£¬£¬£¬ £¬£¬£¬°Í¿ÉÒÑÔÚÆäÍøÕ¾ÉÏÐû²¼Á˹̼þ°æÔ­À´»º½â²¿·ÖÎó²î£¬£¬£¬£¬ £¬£¬£¬ÁíÒ»Ð©Éæ¼°ÎïÀíά»¤µÄÓ²¼þ×é¼þÖеÄÎó²î¿ÉÄܲ»»á±»ÐÞ¸´¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/wireless-presentation-system-vulnerabilities/


6.BitglassÐû²¼2019Äê½ðÈÚÐÐÒµÊý¾Ýй¶±¨¸æ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


¾ÝBitglass³Æ£¬£¬£¬£¬ £¬£¬£¬2019ÄêËùÓÐÊý¾Ýй¶ÊÂÎñÖÐÖ»ÓÐ6£¥Éæ¼°µ½½ðÈÚЧÀ͹«Ë¾£¬£¬£¬£¬ £¬£¬£¬¿ÉÊÇÓëÆäËûÐÐÒµÏà±È£¬£¬£¬£¬ £¬£¬£¬ÕâЩÊÂÎñËðº¦Á˸ü¶àµÄ¼Í¼¡£¡£¡£¡£2019ÄêËùÓÐ×ß©¼Í¼ÖÐ×ܼÆÓÐ60£¥ÒÔÉÏÊÇÓɽðÈÚЧÀÍ»ú¹¹Ð¹Â¶µÄ£¬£¬£¬£¬ £¬£¬£¬ÕâÖÁÉÙ²¿·ÖÓëCapital OneÌØ´óÊý¾Ýй¶ÊÂÎñÓйأ¬£¬£¬£¬ £¬£¬£¬¸ÃÊÂÎñй¶ÁËÁè¼Ý1ÒÚÌõ¼Í¼¡£¡£¡£¡£2019ÄêºÚ¿ÍºÍ¶ñÒâÈí¼þÈÔÈ»ÊǽðÈÚЧÀÍÊý¾Ýй¶µÄÖ÷ÒªÔµ¹ÊÔ­ÓÉ£¬£¬£¬£¬ £¬£¬£¬Õ¼74.5£¥£¨ÂÔ¸ßÓÚ2018ÄêµÄ73.5£¥£©¡£¡£¡£¡£ÄÚ²¿Íþв´Ó2018ÄêµÄ2.9£¥ÔöÌíµ½½ñÄêµÄ5.5£¥£¬£¬£¬£¬ £¬£¬£¬¶øÒâÍâй¶´Ó14.7£¥ÔöÌíµ½18.2£¥¡£¡£¡£¡£ÔÚÒÑÍù¼¸ÄêÖУ¬£¬£¬£¬ £¬£¬£¬½ðÈÚЧÀÍÆ½¾ùÿÌõй¶¼Í¼µÄ±¾Ç®ÓÐËùÔöÌí£¨210ÃÀÔª£©£¬£¬£¬£¬ £¬£¬£¬Áè¼ÝÁËÒ½ÁƱ£½¡ÐÐÒµ£¨429ÃÀÔª£©Ö®ÍâµÄËùÓÐÆäËüÐÐÒµ¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2019/12/17/data-breaches-financial-services/