¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180910

°ä²¼¹¦·ò 2018-09-10

01

ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨


640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨 £¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£© £¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨ £¬µ«¸ÃÓʼþÁбíÒѹýÆÚ £¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ± £¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£

   Ô­ÎÄÁ´½Ó£º

https://www.gao.gov/assets/700/694158.pdf


02

×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢


640?wx_fmt=png&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý £¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐеÄ £¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É £¬µ«ÎÊÌâÔÚÓÚ £¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí £¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍ¿ìÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ìÂʼÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£

  Ô­ÎÄÁ´½Ó£º

https://guardianapp.com/ios-app-location-report-sep2018.html


03

×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷


640?wx_fmt=jpeg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ãæ £¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ £¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢ £¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõÈ¡£

  Ô­ÎÄÁ´½Ó£º

https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/


04

×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶


640?wx_fmt=jpeg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶ £¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£BMCÔڵײãÔËÐÐ £¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ £¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔì £¬Ò²Ã»Óв鳭¹Ì¼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£

  Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html


05

Google°ä²¼9ÔÂAndroid°²È«¸üР£¬¹²½¨¸´50¶à¸ö·ì϶


640?wx_fmt=jpeg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ £¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶ £¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ £¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£

  Ô­ÎÄÁ´½Ó£º

https://source.android.com/security/bulletin/2018-09-01


06

Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹


640?wx_fmt=jpeg&tp=webp&wxfrom=5&wx_lazy=1&wx_co=1

ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨ £¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£Haya Shulman²©Ê¿°µÊ¾ £¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ £¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Êé £¬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£

  Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/


1¡¢ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨 £¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£© £¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨ £¬µ«¸ÃÓʼþÁбíÒѹýÆÚ £¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ± £¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£

   Ô­ÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf


2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý £¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐеÄ £¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É £¬µ«ÎÊÌâÔÚÓÚ £¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí £¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍ¿ìÂÊÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ìÂʼÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£
  Ô­ÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html

 

3¡¢×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ãæ £¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ £¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢ £¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõÈ¡£
  Ô­ÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/

 

4¡¢×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶ £¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£BMCÔڵײãÔËÐÐ £¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ £¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔì £¬Ò²Ã»Óв鳭¹Ì¼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£
  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html


5¡¢Google°ä²¼9ÔÂAndroid°²È«¸üР£¬¹²½¨¸´50¶à¸ö·ì϶

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ £¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶ £¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ £¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£
  Ô­ÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01


6¡¢Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹

 

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨ £¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£Haya Shulman²©Ê¿°µÊ¾ £¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ £¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Êé £¬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£
  Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/