¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180703
°ä²¼¹¦·ò 2018-07-03¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÀûÓÃPROPagate´úÂë×¢Èë¼¼ÊõµÄ¶ñÒâ¹¥»÷»î¶¯
PROPagate´úÂë×¢Èë¼¼Êõ×îÔçÓÚ2017Äê11ÔÂÓÉHexacorn°²È«×êÑÐÈËÔ±·¢ÏÖ£¬¸Ã×êÑÐÈËÔ±Ö¤Ã÷ËüÄܹ»ÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÀûÓ÷¨Ê½¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõĺϷ¨GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÀûÓ÷¨Ê½ÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£×î½ü£¬FireEyeµÄר¼Ò·¢ÏÖÁËÒ»¸öÀûÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢Èë¼¼Êõ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÐµÄDiameterµç»°ºÍ̸ÓëSS7Ò»ÑùÒ×Êܹ¥»÷
°²È«×êÑÐÈËÔ±°µÊ¾£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä³ß¶Èһ·ʹÓõÄDiameterºÍ̸ÈÝÒ×Êܵ½Óë¾ÉµÄµç»°³ß¶È£¨Èç3G£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7³ß¶ÈÒ»ÑùÀàÐ͵ķì϶µÄ¹¥»÷£¬SS7ÊÇÔÚ20ÊÀ¼Í70Äê´ú¿ª·¢µÄ£¬½«½ü¶þÊ®ÄêÖ¤Ã÷Æä´æÔÚ²»°²È«³É·Ö¡£ÕýÓÉÓÚÈç´Ë£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂçÆðÍ·£¬SS7±»DiameterºÍ̸ËùÈ¡´ú£¬DiameterºÍ̸ÊÇÒ»ÖָĽøµÄÍø¼äºÍÍøÄÚÐÅÁîºÍ̸£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G³ß¶È¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/
¡¾°²È«²¥±¨¡¿ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼
ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢£¬ËüÔÚ´óÁ¿É¾³ýÊýÒÚÌõ¿É×·Òäµ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£Ô×ÓÄÜ»ú¹¹°µÊ¾£¬ÔÚÃÀ¹ú¹ú¶È°²È«¾Ö·ÖÎöÈËÔ±·¢ÏÖ¡°´ÓµçÕÛ·þÎñÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý´æÔÚ¼¼ÊõÎ¥¹æÐÐΪ¡±ºó£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/
¡¾°²È«²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ
FacebookÒѾÈϿɣ¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÀûÓÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ£¬ÔÚ½ñÄê3Ô°䲼µÄCambridge Analytica³óÎÅÆÚ¼ä£¬Facebook°µÊ¾£¬ËüÒѾÔÚ2015Äê5ÔÂÖÕ³¡Á˵ÚÈý·½½Ó¼ûÆäÓû§Êý¾Ý¡£È»¶øÔÚ½üÆÚ°ä²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó³ÖÐøÓë61¼ÒÓ²¼þºÍÈí¼þÔì×÷ÉÌÒÔ¼°ÀûÓÿª·¢É̹²ÏíÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html
¡¾°²È«²¥±¨¡¿ÈýÐDz¿ÃÅϵÁÐÊÖ»ú´æÔÚbug£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË
×îа汾µÄÈýÐǶÌÐŶÌÐÅÀûÓ÷¨Ê½´æÔÚbug£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£ºÃÐÂÎÅÊÇ£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬ÈçS9¡¢S9 PlusºÍNote 8£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬Óöµ½bugµÄÓû§Ëµ£¬ËûÃDz»ÖªÂ·ÊÖ»úÒѾ·¢ËÍÁËÕÕÆ¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£Ö»Óе¹ØâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬ËûÃDzŷ¢ÏÖ¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÀûÓ÷¨Ê½Ö±µ½ÈýÐǽ¨¸´ÕâЩÎÊÌâ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/
¡¾·ì϶²¹¶¡¡¿VMware°ä²¼°²È«¸üУ¬½¨²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄ·ì϶
VMwareÉÏÖÜ֪ͨ¿Í»§£¬Æä½¨²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬WorkstationºÍFusion²úÆ·ÖгöÏֻؾø·þÎñ£¨DoS£©»òÐÅϢй¶µÄ·ì϶¡£ÓµÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉÀûÓð²È«·ì϶»ñÊØÐÅÏ¢»òʹÐé¹¹»ú±ÀÀ£¡£¸Ã·ì϶±»ÁÐΪ³ÁÒª£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£Cisco TalosµÄ×êÑÐÈËÔ±·¢ÏÖÁËCVE-2018-6965¡£¾ÝVMware³ÆÕâЩȱµã»áÓ°ÏìÔÚÖ°ºÎƽ̨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬²¢ÒѰ䲼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄ½¨²¹·¨Ê½ºÍ¸üС£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion


¾©¹«Íø°²±¸11010802024551ºÅ