¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180723

°ä²¼¹¦·ò 2018-07-23

¡¾Íþвµý±¨¡¿×êÑлú¹¹ÖÒ¸æ³ÆÔ¼5ÒÚIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì


Armis¹«Ë¾ÖÒ¸æ³ÆÔ¼5ÒÚ¸öIoTÉ豸Ò×ÊÜDNS³Áа󶨹¥»÷µÄÓ°Ïì ¡£DNS³Áа󶨹¥»÷ÊÇÖ¸¹¥»÷ÕߺýŪÓû§µÄä¯ÀÀÆ÷»òÉ豸°ó¶¨ÖÁ¶ñÒâµÄDNS·þÎñÆ÷µÄ¹¥»÷·½Ê½ ¡£Armis·ÖÎöÁËÕâÖÖ¹¥»÷¶ÔIoTÉ豸µÄÓ°Ï죬³ÆÏÕЩËùÓÐÀàÐ͵ÄÖÇÄÜÉ豸¶¼Ò×ÊÜ´ËÀ๥»÷£¬Ô̺¬ÖÇÄܵçÊÓ¡¢Â·ÓÉÆ÷¡¢´òÓ¡»ú¡¢¼à¶½Æ÷¡¢IPµç»°µÈ ¡£½¨¸´ËùÓеÄÉ豸¿ÉÄÜÊÇÒ»ÏîÎÞ·¨ÊµÏֵŤ×÷£¬µ«½«IoTÉ豸¼¯³Éµ½°²È«¼à¿Ø²úÆ·ÖпÉÄÜÊÇ×îµ¥Ò»ÓÐЧµÄ½â¾ö¹æ»® ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/half-a-billion-iot-devices-vulnerable-to-dns-rebinding-attacks/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӷ¢ÏÖÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯


Proofpoint×êÑÐÍŶӷ¢ÏÖÒ»¸öÓÃÓÚ´«²¼FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯ ¡£×êÑÐÈËÔ±ÒÔΪ¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÊÇ·¸×ïÍÅ»ïTA505 ¡£´¹µöÓʼþµÄ¸½¼þÊÇÒ»¸öÔ̺¬¶ñÒâ.SettingContent-msÎļþµÄPDFÎļþ£¬µ±Óû§´ò¿ª´Ë¸½¼þʱ£¬½«Ö´ÐÐSettingContent-msÎļþµÄDeepLink±êÇ©ÖеÄPowerShellºÅÁî ¡£ÕâÖÖ¶ñÒâµÄSettingContent-msÎļþÄܹ»ÈƹýWindows 10µÄ°²È«»úÔ죬ÀýÈçASR ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74639/hacking/settingcontent-ms-flawedammyy-rat.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÒ»³ÉÈËÍøÕ¾Ú¿Æ­ÕßÔÚÒ»ÖÜÄÚÆ­È¡³¬¹ý5ÍòÃÀÔª


°²È«×êÑÐÈËÔ±SecGuru³ÆÒ»¸öÀûÓóÉÈËÍøÕ¾½øÐÐÚ¿Æ­µÄ¹¥»÷ÕßÔÚÒ»ÖÜÄÚÆ­È¡Á˳¬¹ý5ÍòÃÀÔª ¡£¸Ã¹¥»÷ÕßÏòÓû§·¢Óʼþ³ÆÆäÈëÇÖÁËÒ»¸ö³ÉÈËÍøÕ¾£¬²¢ÇÒÔÚÓû§½Ó¼û´ËÍøÕ¾Ê±Í¨¹ý¶ñÒâÈí¼þϰȾÁËÓû§µÄÍÆËã»úºÍÅÄÉãÁËÊÓÆµ ¡£µ«ÏÖʵÉÏÕâÖ»ÊÇÒ»ÖÔìÛÕ©ÐÐΪ£¬²¢Ã»ÓжñÒâÈí¼þ±»ÏÖʵװÖà ¡£SecGuru²é³­ÁËÚ¿Æ­ÕßµÄ42¸ö±ÈÌØ±ÒµØÖ·£¬·¢ÏÖ30ÃûÊܺ¦ÕßÒѾ­Ö§¸¶ÁËÊê½ð£¬×ܼƳ¬¹ý5ÍòÃÀÔª ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adult-site-blackmail-spammers-made-over-50k-in-one-week/


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±·¢ÏÖ΢ÈíTranslator Hub´æÔÚÑϳÁ·ì϶£¬¿Éµ¼ÖÂËùÓÐÏîÄ¿±»É¾³ý


΢Èí½¨¸´ÁËMicrosoft Translator HubÖеÄÒ»¸öÑϳÁ·ì϶£¬¸Ã·ì϶¿É±»¹¥»÷ÕßÀûÓÃÒÔɾ³ý¸Ã·þÎñÉÏÍйܵÄÈκÎÏîÄ¿ ¡£Microsoft Translator HubÄܹ»Ô®ÊÔìóÒµºÍÉçÇø¹¹½¨¡¢ÑµÁ·ºÍ²¿Êð¶¨Ô컯µÄ×Ô¶¯Ëµ»°·­Òëϵͳ ¡£×êÑÐÈËÔ±Haider MahmoodÔÚ2018Äê2Ôµ׷¢ÏÖÁ˸÷ì϶£¬Mahmood³Æ¹¥»÷Õß¿Éͨ¹ýÅú¸ÄHTTPÒªÇóÖеIJÎÊýprojectidÀ´É¾³ýËÁÒâµÄÏîÄ¿ ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74633/security/microsoft-translator-hub-flaw.html


¡¾·ì϶²¹¶¡¡¿×êÑÐÍŶÓÅû¶Ë÷ÄáIPELA EÏà»úÖеĶà¸ö°²È«·ì϶


˼¿ÆTalos×êÑÐÍŶÓÅû¶Ë÷ÄáIPELA EϵÁÐÏà»úÖеĶà¸ö°²È«·ì϶ ¡£¸ÃÏà»úµÄmeasurementBitrateExec²½ÖèÖеĺÅÁî×¢Èë·ì϶£¨CVE-2018-3937£©£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâGETÒªÇó´¥·¢¸Ã·ì϶£¬µ¼ÖÂËÁÒâºÅÁîÖ´ÐÐ ¡£¸ÃÏà»úµÄ802dot1xclientcert.cgi´æÔÚ»º³åÇøÒç¶Âí½Å£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâPOSTÒªÇó´¥·¢¸Ã·ì϶£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ ¡£ÊÜÓ°ÏìµÄ°æ±¾ÊÇIPELA EϵÁÐG5¹Ì¼þ1.87.00£¬½¨ÒéÓû§¾¡¿ì½øÐиüР¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/sony-ipela-vulnerability-spotlight-multiple.html


¡¾°²È«²¥±¨¡¿×êÑÐÈËÔ±³ÆÎ¢ÈíEdgeä¯ÀÀÆ÷ÖеÄXSS Filter³öÏÖbug


PortSwiggerµÄ°²È«×êÑÐÈËÔ±Gareth Heyes³ÆÎ¢ÈíµÄEdgeä¯ÀÀÆ÷Öи½´øµÄXSS Filter°²È«Ö°ÄÜËÆºõ³öÏÖ¹ÊÕÏ ¡£XSS FilterÓÃÓÚ×èÖÓίÀÀÆ÷ÄÚ²¿µÄXSS¹¥»÷£¬¸ÃÖ°ÄÜÔÚĬÈÏÇé¿öÏÂÆôÓà ¡£µ«Heyes·¢ÏÖEdgeÖÐĬÈÏÇé¿öϸÃÖ°ÄÜ´¦ÓڹعØ×´Ì¬£¬¼´±ãͨ¹ýX-XSS-Protection: 1ºÅÁîÒ²ÎÞ·¨ÆôÓøÃÖ°ÄÜ£¬¶øÔÚIEÖиÃÖ°ÄÜ´¦ÓÚÕý³£×´Ì¬ ¡£Î¢Èí»òEdgeÍŶÓûÓа䲼Èκιٷ½ÉêÃ÷£¬Òò¶øÕâ¿ÉÄÜÊÇÒ»¸öbug ¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/microsoft-edges-xss-filter-appears-to-be-broken/