¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190123

°ä²¼¹¦·ò 2019-01-23
1¡¢Linux°üÖÎÀíÆ÷apt/apt-getÔ¶³Ì´úÂëÖ´Ðзì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Max Justicz·¢ÏÖLinux°üÖÎÀíÆ÷apt/apt-get´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¸Ã·ì϶£¨CVE-2019-3462£©ÔÊÐí¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷²¢»ñÈ¡rootȨÏÞÖ´ÐÐËÁÒâ´úÂë ¡£¸Ã·ì϶µÄÆðÒòÊÇaptĬÈÏʹÓÃHTTPͨѶ£¬¶øÆätransport²½ÖèÖд¦ÖÃHTTP³Á¶¨ÏòµÄ´úÂëûÓÐÕýÈ·²é³­Ä³Ð©²ÎÊý£¬¹¥»÷Õß¿Éͨ¹ýÖÐÑëÈ˹¥»÷ʹÓÃαÔìÊðÃûÆ­¹ý¸Ã²é³­£¬½ø¶øÔÚÓû§Ö÷»úÉÏ×°ÖÃËÁÒⷨʽ ¡£ÓÉÓÚapt×ÔÉíÒѾ­»ñÈ¡ÁËrootȨÏÞ£¬¸Ã¶ñÒⷨʽ¿ÉÔÚrootȨÏÞÏÂÖ´ÐÐ ¡£¸Ã·ì϶ӰÏìÁìÓò¼«Îª¿í·º£¬ËùÓÐʹÓÃÀϰ汾aptµÄÖ÷»ú¶¼Êܵ½Ó°Ïì ¡£apt¿ª·¢ÈËÔ±ÒÑÔÚ°æ±¾1.4.9Öн¨¸´Á˸÷ì϶ ¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/linux-apt-http-hacking.html


2¡¢Check Point°ä²¼2019ÍøÂ簲ȫ»ã±¨£¬³Áµã·ÖÎöÍøÂç¹¥»÷Ç÷Ïò

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



ÒÔÉ«Áа²È«³§ÉÌCheck Point°ä²¼2019ÍøÂ簲ȫ»ã±¨£¬»ØÊ×ÁË2018ÄêµÄÍþвÇ÷Ïò£¬Ô̺¬´ó¹æÄ£Êý¾Ýй¶¡¢ÀÕË÷Èí¼þ¹¥»÷¡¢¶ñÒâÍÚ¿ó¹¥»÷ºÍAPT¹¥»÷µÈ ¡£ÔÚ2018Äê£¬ÍøÂçÍþв¾ÖÊÆ¸ü¾ßÌôÕ½ÐÔ£¬¹¥»÷Õß²»ÐݸĽøÆäÍøÂç±øÆ÷¡¢Ñ¡È¡ÐµĹ¥»÷²½ÖèºÍÊÊÓ¦ÐÂÐ˼¼Êõ ¡£2018ÄêµÄÍøÂç¹¥»÷Äܹ»±»¶¨ÐÔΪ¸ü¾ßÕë¶ÔÐÔ£¬ÆäÖ÷ÕÅÊÇÔì³É¸ü´óµÄ·ÛË飬ԽÀ´Ô½¶àµÄ¹¥»÷Ôì³ÉÁËÕû¸ö×éÖ¯µÄ¹Ø¹Ø»ò¹ú¼ÊÊÂÎñµÄÇÖÈÅ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2019/01/21/threat-trends-analysis-report/


3¡¢ÐÂÀÕË÷Èí¼þPhobosÀûÓÃRDP·þÎñ´«²¼£¬Õë¶ÔÈ«ÇòÆóÒµ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


CoveWare×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÈ«ÇòÆóÒµµÄÐÂÀÕË÷Èí¼þPhobos£¬Phobos³öÏÖÓÚ2018Äê12Ô·Ý£¬²¢ÇÒÓëÀÕË÷Èí¼þDharma´æÔںܶàÀàËÆÖ®´¦ ¡£ÓëDharmaÒ»Ñù£¬PhobosÀûÓÃÊ¢¿ªµÄ»ò°²È«ÐԽϲîµÄRDP¶Ë¿Ú½øÐÐÈëÇÖ ¡£±»¼ÓÃܵÄÎļþ»á±»Ôö³¤.phobosÀ©´óÃû ¡£PhobosÒªÇóÒÔ±ÈÌØ±ÒµÄ·½Ê½Ö§¸¶Êê½ð£¬ÆäÀÕË÷µ¥¾ÝÉϵÄ×ÖÌåºÍÎı¾ÓëDharmaÆëȫһÑù ¡£×êÑÐÈËÔ±»¹³ÆPhobosµÄ´ó²¿ÃÅ´úÂëÒ²ÓëDharmaÒ»Ö ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world/


4¡¢ÀÕË÷Èí¼þSTOPбäÖÖRumba£¬ÖØÒªÍ¨¹ýµÁ°æÈí¼þ´«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÀÕË÷Èí¼þSTOPµÄбäÖÖRumbaÔÚ´Óǰ30ÌìÄÚ»ý¼«½øÐзַ¢£¬¸Ã±äÌ彫.rumbaÀ©´óÃû¸½¼Óµ½¼ÓÃÜÎļþºó£¬ÖØÒª°ó¸¿ÔÚ¸æ°×Èí¼þ°üºÍÆÆ½â°æÈí¼þÖд«²¼ ¡£¾Ý±¨Â·£¬ÕâЩµÁ°æÈí¼þÔ̺¬Windows¼¤»î¹¤¾ß£¨ÀýÈçKMSPico£©¡¢Cubase¡¢PhotoshopÒÔ¼°ÆäËüÊ¢ÐÐÈí¼þµÄÆÆ½â°æµÈ ¡£ºÃÐÂÎÅÊÇ£¬×êÑÐÍŶÓÒѾ­°ä²¼ÁËSTOPµÄÃâ·Ñ½âÃܹ¤¾ß£¬Êܵ½Ï°È¾µÄÓû§Äܹ»ÏÂÔØ¸Ã¹¤¾ß½øÐнâÃÜ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-rumba-stop-ransomware-being-installed-by-software-cracks/


5¡¢ÇàÄêѧÉú×éÖ¯AIESECÒâ±íй¶400¶àÍòʵϰÉúÉêÇëÊé


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



AIESECÊÇÒ»¼Ò·ÇͶ»úµÄÇàÄêѧÉú×éÖ¯£¬1ÔÂ11ÈÕ×êÑÐÈËÔ±Bob Diachenko·¢ÏÖ¸Ã×éÖ¯µÄÒ»¸öElasticsearchÊý¾Ý¿âδÊܱ£»¤£¬µ¼ÖÂ400¶àÍò·ÝʵϰÉúÉêÇëÊéй¶ ¡£ÕâЩÉêÇëÊéÔ̺¬ÉêÇëÈ˵ÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚÒÔ¼°ÉêÇëÔ­ÒòµÈÓ×ÎÒÃô¸ÐÐÅÏ¢ ¡£AEISECÈ«Çò¸±×ܲÃLaurin Stahl֤ʵÁËÕâһй¶ÊÂÎñ£¬µ«Ðû³ÆÖ»Óв»µ½40ÃûÓû§Êܵ½Ó°Ïì ¡£

  

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/01/21/aiesec-data-leak/


6¡¢ÃÀ¹ú¶à¼Ò´ò¶ÄÍøÕ¾Ð¹Â¶1.08ÒÚ´ò¶ÄÐÅÏ¢£¬Ô̺¬Óû§Ö§¸¶Êý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



¾ÝZDNet±¨Â·£¬°²È«×êÑÐÈËÔ±Justin Paine·¢ÏÖÒ»¸öÍøÂç´ò¶Ä¼¯ÍŵÄElasticSearch·þÎñÆ÷δÉèÃÜÂ룬µ¼Ö³¬¹ý1.08ÒÚ´ò¶ÄÐÅϢй¶ ¡£¸Ã·þÎñÆ÷ÉÏй¶µÄÓû§ÐÅÏ¢Ô̺¬¿Í»§µÄÕæÊµÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÍøÕ¾Óû§Ãû¡¢ÕÊ»§Óà¶î¡¢IPµØÖ·¡¢ä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳÐÅÏ¢ÒÔ¼°ÉϴεǼÐÅÏ¢µÈ ¡£´Ë±í£¬Paine»¹·¢ÏÖ1.08ÒÚÌõ´ò¶ÄÐÅÏ¢£¬ÆäÖÐÔ̺¬¿Í»§µÄ´æ¿î¡¢È¡¿îÒÔ¼°Ö§¸¶ÐÅÏ¢ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù