¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180910
°ä²¼¹¦·ò 2018-09-1001
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨£¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£©£¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨£¬µ«¸ÃÓʼþÁбíÒѹýÆÚ£¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ±£¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£
ÔÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf
02
×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢
GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý£¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐеģ¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É£¬µ«ÎÊÌâÔÚÓÚ£¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí£¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍ¿ìÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ìÂʼÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html
03
×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷
Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ã棬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ£¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢£¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõȡ£
ÔÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/
04
×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶
EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£BMCÔڵײãÔËÐУ¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ£¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔ죬ҲûÓв鳹̼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html
05
Google°ä²¼9ÔÂAndroid°²È«¸üУ¬¹²½¨¸´50¶à¸ö·ì϶
9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ£¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶£¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ£¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01
06
Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹
ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨£¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£Haya Shulman²©Ê¿°µÊ¾£¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ£¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Ê飬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/
1¡¢ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨£¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£©£¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨£¬µ«¸ÃÓʼþÁбíÒѹýÆÚ£¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ±£¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£
ÔÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf
2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢
GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý£¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐеģ¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É£¬µ«ÎÊÌâÔÚÓÚ£¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí£¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍ¿ìÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ìÂʼÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£
ÔÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html
3¡¢×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷
Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ã棬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ£¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢£¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõȡ£
ÔÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/
4¡¢×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶
EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶£¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£BMCÔڵײãÔËÐУ¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ£¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔ죬ҲûÓв鳹̼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html
5¡¢Google°ä²¼9ÔÂAndroid°²È«¸üУ¬¹²½¨¸´50¶à¸ö·ì϶
9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ£¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶£¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ£¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01
6¡¢Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹
ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨£¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£Haya Shulman²©Ê¿°µÊ¾£¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ£¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Ê飬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/


¾©¹«Íø°²±¸11010802024551ºÅ