Amcrest¼ÒÓÃÉãÏñÍ·ÑϳÁ·ì϶£»±¾ÌïÒâ±íй¶40GBÊý¾Ý£»DHSÖÒ¸æÓ×ÐÍ·É»úCAN×ÜÏßÑϳÁ·ì϶

°ä²¼¹¦·ò 2019-08-01
1¡¢±±¿¨ÂÞÀ´ÄÉÖÝÔâBECڲƭ¹¥»÷£¬Ëðʧ170ÍòÃÀÔª


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±±¿¨ÂÞÀ´ÄÉÖÝ¿¨°ÍÂ³Ë¹ÏØ£¨Cabarrus County£©ÔâBECÚ¿Æ­£¬Ëðʧ³¬170ÍòÃÀÔª ¡£¹¥»÷Õß¼Ù×°³É¸ÃÏØÐ¸ßÖеĹ¹Öþ³Ð°üÉÌ£¬Í¨¹ýÓʼþ·î¸æÆäÒøÐÐÕË»§ÒѾ­¸ü¸Ä£¬¸ÃÏØÒò¶øÏòÚ¿Æ­ÕßµÄÕË»§Ö§¸¶ÁË250ÍòÃÀÔª ¡£Ö±µ½Èý¸öÐÇÆÚºó³Ð°üÉÌѯÎÊÇ·¿îµÄÎÊÌ⣬¸ÃÏØ²Å·¢ÏÖÔâµ½Ú¿Æ­£¬´ËÊ±ÒøÐÐÖ»ÄÜ×·»Ø77ÍòÃÀÔªµÄ×ʽð ¡£FinCEN×î½üµÄÒ»·Ý»ã±¨Ö¸³ö£¬BECڲƭ´Ó2016ÄêµÄÿÔ¾ùÔÈ1.1ÒÚÃÀÔªÔö³¤µ½ÁË2018ÄêµÄÿÔÂ3.01ÒÚÃÀÔª ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/north-carolina-county-lost-17-million-in-bec-scam/


2¡¢±¾ÌïÒâ±íй¶40GBÊý¾Ý£¬Ô̺¬È«Çò30ÍòÔ±¹¤ÒþÖÔÐÅÏ¢


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÔ±Justin Paine·¢ÏÖ±¾ÌïµÄÒ»¸öElasticSearchÊý¾Ý¿âûÓÐÃÜÂë±£»¤£¬µ¼ÖÂ40GBÄÚ²¿ÎĵµÐ¹Â¶ ¡£¸ÃÊý¾Ý¿âÔ̺¬Ô¼1.34ÒÚ·ÝÎĵµ£¬²»½öй¶ÁË30ÍòÔ±¹¤µÄÓ×ÎÒÐÅÏ¢£¨ÐÕÃû¡¢µç×ÓÓʼþµÈ£©£¬»¹Ð¹Â¶Á˱¾ÌïÄÚ²¿ÍøÂçµÄÓйØÐÅÏ¢£¬ÀýÈçÖ÷»úÃû¡¢MACµØÖ·¡¢ÄÚ²¿IP¡¢²Ù×÷ϵͳ°æ±¾¡¢ÒÑÀûÓõIJ¹¶¡ÒÔ¼°Öն˰²È«Èí¼þµÄ״̬µÈ ¡£¸ÃÊý¾Ý¿âÔÚ¹«ÍøÉ϶³öÁËÔ¼6ÌìµÄ¹¦·ò£¬ÔÚ½Óµ½»ã±¨ºó±¾ÌïÒѾ­¶ÔÊý¾Ý¿â½øÐÐÁ˱£»¤ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/unsecured-database-exposes-security-risks-in-hondas-network/


3¡¢À¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý1.2ÍòѧÉúÐÅÏ¢±»µÁ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¸ñÀ¼Î÷±±²¿µÄÀ¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ£¬Ñ§ÉúÒþÖÔÐÅÏ¢±»µÁ ¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ7ÔÂ19ÈÕ£¬Ó°ÏìÁË1.2ÍòÖÁ2ÍòѧÉú£¬Ð¹Â¶µÄÐÅÏ¢Ô̺¬ÐÕÃû¡¢µØÖ·¡¢µç×ÓÓʼþµØÖ·ºÍµç»°ºÅÂë ¡£²¿ÃÅѧÉúÊÕµ½ÁËڲƭÐÔµÄÖ§¸¶ÒªÇ󣬾ݱ¨Â·ÒÑÓÐ6ÃûѧÉúÊÜÆ­ ¡£¸Ã´óѧÒѾ­³·ÏúÁËÊÜÓ°ÏìѧÉúÕË»§¶ÔÒµÎñϵͳµÄ½Ó¼ûȨÏÞ£¬²¢²ÉÈ¡´ëÊ©¼ÓǿϵͳµÄ°²È«ÐÔ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.theregister.co.uk/2019/07/31/lancaster_uni/


4¡¢DHSÖÒ¸æÓ×ÐÍ·É»úCAN×ÜÏßÑϳÁ·ì϶£¬¿Éµ¼Ö·ɻúʧ¿Ø


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úºÓɽ°²È«Êý°ä²¼ÁËÒ»·Ý°²È«¾¯±¨£¬ÖÒ¸æÓ×ÐÍ·É»ú¿ÉÄÜÊܵ½CAN×ÜÏßÖеÄÑϳÁ·ì϶µÄÓ°Ïì ¡ £¿ÉÎïÀí½Ó¼û·É»úµÄ¹¥»÷ÕßÄܹ»½«É豸Ïνӵ½CAN×ÜÏߣ¬×¢ÈëÐéαÊý¾ÝÔì³Éµç×ÓÉ豸µÄ¶ÁÊý²»ÕýÈ·£¬×îÖÕ¿ÉÄܵ¼Ö·ÉÐÐÔ±×ö³öÃýÎóµÄÅжÏÒÔ¼°×¹»úµÈÑϳÁºó¹û ¡£¹¥»÷ÕßÄܹ»´Û¸ÄµÄÊý¾ÝÔ̺¬·¢Æð»úÒ£²â¶ÁÊý¡¢Ö¸ÄÏÕëºÍ·ÉÐÐ×ËÊÆÊý¾Ý¡¢º£°Î¸ß¶È¡¢·ÉÐпìÂÊÒÔ¼°AoAÊý¾ÝµÈ ¡£ÃÀ¹úCISAÔÚ¶½´Ù·É»úÔì×÷ÉÌÝÓÈÆCAN×ÜÏßϵͳִÐб£»¤£¬²¢¾¡¿ÉÄÜÑϸñÏÞ¶ÈÆä¶Ô·É»úµÄ½Ó¼û ¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/airplane-can-bus-hacking.html


5¡¢Î÷²¿Êý¾ÝSSD¹¤¾ß°ü´æÔÚÁ½¸ö·ì϶£¬¿Éµ¼ÖÂMitM¹¥»÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Åû¶Î÷²¿Êý¾ÝÉÁµÏSSD¹¤¾ß°üÖеÄÁ½¸ö·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓÃÕâÁ½¸ö·ì϶ִÐÐÖÐÑëÈ˹¥»÷ ¡£¸Ã¹¤¾ß°üÓÃÓÚÔ®ÊÖÓû§¼à¿ØSSD»úÄÜ£¬²¢Õï¶ÏÎÊÌâºÍÍøÂç¹ÊÕÏÐÅÏ¢ ¡£Trustwave×êÑÐÈËÔ±Martin Rakhmanov°µÊ¾£¬ºÚ¿ÍÄܹ»Í¨¹ýMitM¹¥»÷À´ÇÔȡϵͳÐÅÏ¢»òͨ¹ý´¥·¢ÀûÓ÷¨Ê½¸üÐÂÀ´·Ö·¢¶ñÒâÈí¼þ ¡£±¾Ô³õÎ÷Êý°ä²¼Èí¼þ¸üн¨¸´ÁËÕâÁ½¸ö·ì϶ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trivial-bugs-in-western-digital-ssd-utility-puts-owners-at-risk/


6¡¢Amcrest¼ÒÓÃÉãÏñÍ·ÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«³§ÉÌTenable·¢ÏÖAmcrest IP2M-841B¼ÒÓÃÉãÏñÍ·´æÔÚÒ»¸öÑϳÁ·ì϶£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ýHTTPÔ¶³Ì¼àÌýÉãÏñÍ·µÄÒôƵÊäÈë ¡£¸Ã·ì϶±»ÏóÕ÷ΪCVE-2019-3948£¬Ó°ÏìÁËÉãÏñÍ·¹Ì¼þ°æ±¾V2.520.AC00.18.R£¬²¢ÇÒÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉÀûÓà ¡£´Ë±í£¬¸Ã²úÆ·Ò²Ò×ÊÜÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¨CVE-2017-7927£©¹¥»÷ ¡£AmcrestÒѾ­°ä²¼Óйؽ¨¸´²¹¶¡ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/iot-home-security-camera-allows-hackers-to-listen-in-over-http/