¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180723
°ä²¼¹¦·ò 2018-07-23¡¾Íþвµý±¨¡¿×êÑлú¹¹ÖÒ¸æ³ÆÔ¼5ÒÚIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì
Armis¹«Ë¾ÖÒ¸æ³ÆÔ¼5ÒÚ¸öIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì¡£DNS³Áа󶨹¥»÷ÊÇÖ¸¹¥»÷ÕߺýŪÓû§µÄä¯ÀÀÆ÷»òÉ豸°ó¶¨ÖÁ¶ñÒâµÄDNS·þÎñÆ÷µÄ¹¥»÷·½Ê½¡£Armis·ÖÎöÁËÕâÖÖ¹¥»÷¶ÔIoTÉ豸µÄÓ°Ï죬³ÆÏÕЩËùÓÐÀàÐ͵ÄÖÇÄÜÉ豸¶¼Ò×ÊÜ´ËÀ๥»÷£¬Ô̺¬ÖÇÄܵçÊÓ¡¢Â·ÓÉÆ÷¡¢´òÓ¡»ú¡¢¼à¶½Æ÷¡¢IPµç»°µÈ¡£½¨¸´ËùÓеÄÉ豸¿ÉÄÜÊÇÒ»ÏîÎÞ·¨ÊµÏֵŤ×÷£¬µ«½«IoTÉ豸¼¯³Éµ½°²È«¼à¿Ø²úÆ·ÖпÉÄÜÊÇ×îµ¥Ò»ÓÐЧµÄ½â¾ö¹æ»®¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/half-a-billion-iot-devices-vulnerable-to-dns-rebinding-attacks/
¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯
Proofpoint×êÑÐÍŶӷ¢ÏÖÒ»¸öÓÃÓÚ´«²¼FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£×êÑÐÈËÔ±ÒÔΪ¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÊÇ·¸×ïÍÅ»ïTA505¡£´¹µöÓʼþµÄ¸½¼þÊÇÒ»¸öÔ̺¬¶ñÒâ.SettingContent-msÎļþµÄPDFÎļþ£¬µ±Óû§´ò¿ª´Ë¸½¼þʱ£¬½«Ö´ÐÐSettingContent-msÎļþµÄDeepLink±êÇ©ÖеÄPowerShellºÅÁî¡£ÕâÖÖ¶ñÒâµÄSettingContent-msÎļþÄܹ»ÈƹýWindows 10µÄ°²È«»úÔ죬ÀýÈçASR¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74639/hacking/settingcontent-ms-flawedammyy-rat.html
¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÒ»³ÉÈËÍøÕ¾Ú¿ÆÕßÔÚÒ»ÖÜÄÚÆÈ¡³¬¹ý5ÍòÃÀÔª
°²È«×êÑÐÈËÔ±SecGuru³ÆÒ»¸öÀûÓóÉÈËÍøÕ¾½øÐÐڿƵĹ¥»÷ÕßÔÚÒ»ÖÜÄÚÆÈ¡Á˳¬¹ý5ÍòÃÀÔª¡£¸Ã¹¥»÷ÕßÏòÓû§·¢Óʼþ³ÆÆäÈëÇÖÁËÒ»¸ö³ÉÈËÍøÕ¾£¬²¢ÇÒÔÚÓû§½Ó¼û´ËÍøÕ¾Ê±Í¨¹ý¶ñÒâÈí¼þϰȾÁËÓû§µÄÍÆËã»úºÍÅÄÉãÁËÊÓÆµ¡£µ«ÏÖʵÉÏÕâÖ»ÊÇÒ»ÖÔìÛÕ©ÐÐΪ£¬²¢Ã»ÓжñÒâÈí¼þ±»ÏÖʵװÖá£SecGuru²é³ÁËÚ¿ÆÕßµÄ42¸ö±ÈÌØ±ÒµØÖ·£¬·¢ÏÖ30ÃûÊܺ¦ÕßÒѾ֧¸¶ÁËÊê½ð£¬×ܼƳ¬¹ý5ÍòÃÀÔª¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adult-site-blackmail-spammers-made-over-50k-in-one-week/
¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖ΢ÈíTranslator Hub´æÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂËùÓÐÏîÄ¿±»É¾³ý
΢Èí½¨¸´ÁËMicrosoft Translator HubÖеÄÒ»¸öÑϳÁ·ì϶£¬¸Ã·ì϶¿É±»¹¥»÷ÕßÀûÓÃÒÔɾ³ý¸Ã·þÎñÉÏÍйܵÄÈκÎÏîÄ¿¡£Microsoft Translator HubÄܹ»Ô®ÊÔìóÒµºÍÉçÇø¹¹½¨¡¢ÑµÁ·ºÍ²¿Êð¶¨Ô컯µÄ×Ô¶¯Ëµ»°·Òëϵͳ¡£×êÑÐÈËÔ±Haider MahmoodÔÚ2018Äê2Ôµ׷¢ÏÖÁ˸÷ì϶£¬Mahmood³Æ¹¥»÷Õß¿Éͨ¹ýÅú¸ÄHTTPÒªÇóÖеIJÎÊýprojectidÀ´É¾³ýËÁÒâµÄÏîÄ¿¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74633/security/microsoft-translator-hub-flaw.html
¡¾·ì϶²¹¶¡¡¿×êÑÐÍŶÓÅû¶Ë÷ÄáIPELA EÏà»úÖеĶà¸ö°²È«·ì϶
˼¿ÆTalos×êÑÐÍŶÓÅû¶Ë÷ÄáIPELA EϵÁÐÏà»úÖеĶà¸ö°²È«·ì϶¡£¸ÃÏà»úµÄmeasurementBitrateExec²½ÖèÖеĺÅÁî×¢Èë·ì϶£¨CVE-2018-3937£©£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâGETÒªÇó´¥·¢¸Ã·ì϶£¬µ¼ÖÂËÁÒâºÅÁîÖ´ÐС£¸ÃÏà»úµÄ802dot1xclientcert.cgi´æÔÚ»º³åÇøÒç¶Âí½Å£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâPOSTÒªÇó´¥·¢¸Ã·ì϶£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÊÜÓ°ÏìµÄ°æ±¾ÊÇIPELA EϵÁÐG5¹Ì¼þ1.87.00£¬½¨ÒéÓû§¾¡¿ì½øÐиüС£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/sony-ipela-vulnerability-spotlight-multiple.html
¡¾°²È«²¥±¨¡¿×êÑÐÈËÔ±³ÆÎ¢ÈíEdgeä¯ÀÀÆ÷ÖеÄXSS Filter³öÏÖbug
PortSwiggerµÄ°²È«×êÑÐÈËÔ±Gareth Heyes³ÆÎ¢ÈíµÄEdgeä¯ÀÀÆ÷Öи½´øµÄXSS Filter°²È«Ö°ÄÜËÆºõ³öÏÖ¹ÊÕÏ¡£XSS FilterÓÃÓÚ×èÖÓίÀÀÆ÷ÄÚ²¿µÄXSS¹¥»÷£¬¸ÃÖ°ÄÜÔÚĬÈÏÇé¿öÏÂÆôÓᣵ«Heyes·¢ÏÖEdgeÖÐĬÈÏÇé¿öϸÃÖ°ÄÜ´¦ÓڹعØ×´Ì¬£¬¼´±ãͨ¹ýX-XSS-Protection: 1ºÅÁîÒ²ÎÞ·¨ÆôÓøÃÖ°ÄÜ£¬¶øÔÚIEÖиÃÖ°ÄÜ´¦ÓÚÕý³£×´Ì¬¡£Î¢Èí»òEdgeÍŶÓûÓа䲼Èκιٷ½ÉêÃ÷£¬Òò¶øÕâ¿ÉÄÜÊÇÒ»¸öbug¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/microsoft-edges-xss-filter-appears-to-be-broken/


¾©¹«Íø°²±¸11010802024551ºÅ