¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190117

°ä²¼¹¦·ò 2019-01-17
1¡¢»úƱԤԼϵͳAmadeusÑϳÁ·ì϶£¬Ó°ÏìÈ«Çò141¼Òº½¿Õ¹«Ë¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÒÔÉ«Áа²È«×êÑÐÔ±Noam Rotem·¢ÏÖ»úƱԤԼϵͳAmadeus´æÔÚÒ»¸öÑϳÁµÄ°²È«·ì϶£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤Ô¼»úƱʱ·¢ÏÖÁËÕâÒ»ÎÊÌ⣬ÔÚÔ¤Ô¼º½°àºó£¬´î¿Í»áÊÕµ½PNRºÅÂëºÍÓÃÓڲ鿴ԤԼÐÅÏ¢µÄÁ´½Ó¡£Rotem·¢ÏÖͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÅú¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿É²é¿´ËûÈ˵ÄÔ¤Ô¼ÐÅÏ¢£¬¹¥»÷Õß»¹¿ÉÀûÓÃÕâЩÐÅÏ¢½Ó¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬Ô̺¬¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØÖ·ºÍµç»°ºÅÂëµÈ¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤԼϵͳ±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Óã¨Ô̺¬ÃÀ¹ú½áºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬Òò¶ø¸Ã·ì϶¿ÉÄÜÓ°ÏìÁËÊýÒÚ´î¿Í¡£Ä¿Ç°AmadeusÒѾ­½¨¸´Á˸ÃÎÊÌâ¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/airlines-flight-hacking.html


2¡¢OVH¡¢DreamhostµÈÎå´óÍйܷþÎñÉÌ´æÔÚ¶à¸ö°²È«·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



°²È«×êÑÐÈËÔ±Paulos Yibelo·¢ÏÖÈ«ÇòÎå´óÍйܷþÎñÉÌ£¨Bluehost¡¢Dreamhost¡¢HostGator¡¢OVHºÍiPage£©´æÔÚ¶à¸ö°²È«·ì϶£¬Ê¹µÃËüÃǵĿͻ§ºÍÍйܵÄÍøÕ¾Ãæ¶ÔºÚ¿Í¹¥»÷µÄ·çÏÕ¡£ÕâЩ·þÎñÉÌ»òÐíÍйÜÁË700Íò¸öÍøÕ¾¡£Yibelo¹²·¢ÏÖÁËÔ¼12¸ö·ì϶£¬Ô̺¬CORSÅäÖò»µ±µ¼ÖµÄÐÅϢй¶¡¢ÕË»§ÊÕÊÜ¡¢ÖÐÑëÈ˹¥»÷¡¢XSS¡¢APIÅäÖÃÃýÎóºÍCSPÈÆ¹ýµÈ¡£YibeloÏòÕâЩ·þÎñÉ̻㱨ÁËËûµÄµ÷²éÁ˾Ö£¬Ä¿Ç°³ýÁËOVHÉÐδ½øÐлØÓ¦Ö®±í£¬ÆäËü·þÎñÉÌÒѾ­½¨¸´ÁË·ì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/web-hosting-server-security.html


3¡¢×êÑÐÍŶÓÅû¶¥Óî×Ô¶¯»¯ÏµÍ³BASÖеÄ6¸ö0day

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ForeScout×êÑÐÍŶӷ¢ÏÖÂ¥Óî×Ô¶¯»¯ÏµÍ³£¨BAS£©ÖеÄ6¸ö0day¡£ÕâЩ·ì϶´æÔÚÓÚBASµÄPLCºÍÍø¹ØºÍ̸µÈ×é¼þÖУ¬·ì϶ÁìÓòÔ̺¬XSS¡¢õè¾¶±éÀú¡¢ËÁÒâÎļþɾ³ýºÍÉí·ÝÑéÖ¤ÈÆ¹ý£¬¹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢½Ó¼û»òɾ³ý¹Ø¼üÎļþºÍÖ´ÐжñÒâ²Ù×÷µÈ¡£×êÑÐÈËԱͨ¹ýShodanºÍCensys·¢ÏÖÁ˳¬¹ý9000¸öÒ×Êܹ¥»÷µÄÉ豸£¬´Ë±í»¹Óг¬¹ý1Íò¸öIPÉãÏñ»úÒ×Êܹ¥»÷¡£BASϵͳ²»½öÓÃÓÚסլºÍóÒ×¹¹ÖþÖУ¬»¹´æÔÚÓÚÒ½Ôº¡¢»ú³¡¡¢Ñ§ÌúÍÊý¾ÝÖÐÐĵÈ¡£½¨ÒéÓû§¾¡¿ì×°Öý¨¸´²¹¶¡¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/zero-day-vulnerabilities-leave-smart-buildings-open-to-cyber-attacks/


4¡¢µï±¤Ö®Ò¹¶à¸ö·ì϶¿ÉÔÊÐí¹¥»÷ÕßÊÕÊÜÍæ¼ÒÕË»§

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Check Point×êÑÐÈËÔ±·¢ÏÖFortnite£¨µï±¤Ö®Ò¹£©ÖеĶà¸ö°²È«·ì϶£¬ÆäÖÐÒ»¸ö·ì϶¿Éµ¼ÖÂÔ¶³Ì¹¥»÷Õ߯ëÈ«ÊÕÊÜÍæ¼ÒµÄÕ˺Å¡£Æ¾¾Ý×êÑÐÈËÔ±µÄ˵·¨£¬·ì϶µÄÁìÓòÔ̺¬SQL×¢Èë¡¢XSS¡¢WAFÈÆ¹ýÒÔ¼°ÕË»§ÊÕÊÜ¡£×êÑÐÈËÔ±³ÆEpic Games×ÓÓòÉϵÄxssºÍ¶ñÒâ³Á¶¨ÏòÎÊÌâÔÊÐí¹¥»÷Õßͨ¹ýºýŪÓû§µã»÷¶ñÒâÁ´½ÓÀ´ÇÔÈ¡Óû§µÄÉí·ÝÑéÖ¤ÁîÅÆ¡£FortniteÔÚÈ«ÇòÕ¼ÓÐ8000ÍòÍæ¼Ò£¬ÕâЩÓû§¶¼¿ÉÄÜÊܵ½Ó°Ïì¡£Epic GamesÒÑÔÚ2018Äê12ÔÂÖÐÑ®½¨¸´ÁËÕâЩ·ì϶¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/fortnite-account-hacked.html


5¡¢VoIP·þÎñÉÌVOIPOÒâ±íй¶´ÓǰËÄÄêµÄ¿Í»§Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Justin Paineͨ¹ýShodan·¢ÏÖÒ»¸ö¿É¹«¿ª½Ó¼ûµÄElasticSearchÊý¾Ý¿â£¬¸ÃÊý¾Ý¿âÊôÓÚVoIP·þÎñÉÌVOIPO£¬ÆäÖÐÔ̺¬Á˸ù«Ë¾´ÓǰËÄÄêµÄ¿Í»§Êý¾Ý¡£Æ¾¾ÝPaineµÄ˵·¨£¬¸ÃÊý¾Ý¿âÔ̺¬¿É×·ÒäÖÁ2017Äê7ÔµÄ670ÍòÌõͨ»°¼Í¼¡¢¿É×·ÒäÖÁ2015Äê12ÔµÄ600ÍòÌõ¶ÌÐÅ/²ÊÐÅÈÕÖ¾ÒÔ¼°100ÍòÌõÔ̺¬ÄÚ²¿ÏµÍ³API KEYµÄÈÕÖ¾¡£×êÑÐÈËÔ±ÓÚ1ÔÂ8ÈÕÏòVOIPO´«µÝÁËÕâÒ»·¢ÏÖ£¬¸Ã¹«Ë¾ÔÚͳһÌ콫Êý¾Ý¿â½øÐÐÁËÍÑ»ú± £»¤¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/voip-service-database-hacking.html


6¡¢Magecart Group 12ͨ¹ý¹©¸øÁ´¹¥»÷ϰȾ277¸öµç×ÓÉÌÎñÍøÕ¾

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝRiskIQºÍÇ÷Ïò¿Æ¼¼µÄ»ã±¨£¬Ò»¸öеÄMagecart·¸×ïÍŻMagecart Group 12£©Í¨¹ý¹©¸øÁ´¹¥»÷³É¹¦Ï°È¾Á˽ü277¸öµç×ÓÉÌÎñÍøÕ¾¡£Ôâµ½Magecart Group 12¹¥»÷µÄÊÇ·¨¹úÔÚÏ߸æ°×¹«Ë¾AdverlineÌṩµÄJavaScript¿â¡£Å·ÖÞÊý°Ù¸öµç×ÓÉÌÎñÍøÕ¾¶¼ÀûÓÃAdverlineµÄ·þÎñÀ´Õ¹Ê¾¸æ°×¡£ÔÚ½Óµ½Í¨Öªºó£¬AdverlineÂíÉÏ´ÓÆäJavaScript¿âÖÐɾ³ýÁ˶ñÒâ´úÂë¡£×êÑÐÈËÔ±Ôڻ㱨Öл¹°ä²¼ÁËÓëMagecart Group 12ÓйصÄIoC¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/magecart-hacking-credit-cards.html


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù