ÍøÂ簲ȫÍþвÐÅÏ¢°ä²¼ÖÎÀí·¨×Ó(Õ÷Ç󶨼û¸å)£»ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý£»DockerÌÓÒÝ·ì϶

°ä²¼¹¦·ò 2019-11-21
1¡¢ÍøÐŰì°ä²¼¡¶ÍøÂ簲ȫÍþвÐÅÏ¢°ä²¼ÖÎÀí·¨×Ó(Õ÷Ç󶨼û¸å)¡·

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

ΪÓÐЧӦ¶ÔÍøÂ簲ȫÍþв΢·çÏÕ £¬±£ÏÕÍøÂçÔËÐа²È« £¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ20Èվ͡¶ÍøÂ簲ȫÍþвÐÅÏ¢°ä²¼ÖÎÀí·¨×Ó£¨Õ÷Ç󶨼û¸å£©¡·¹«¿ªÕ÷ÇóÉç»á¶¨¼û £¬¶Ô°ä²¼ÍøÂ簲ȫÍþвÐÅÏ¢µÄÐÐΪ×÷³ö¹æ·¶¡£Æ¾¾ÝÕ÷Ç󶨼û¸å £¬ÍøÂ簲ȫÍþвÐÅÏ¢Ô̺¬(Ò»)¶Ô¿ÉÄÜÍþÐ²ÍøÂçÕý³£ÔËÐеÄÐÐΪ £¬ÓÃÓÚÃèÊöÆäÒâͼ¡¢²½Öè¡¢¹¤¾ß¡¢¹ý³Ì¡¢Á˾ֵȵÄÐÅÏ¢£»(¶þ)¿ÉÄܶ³öÍøÂç´àÈõÐÔµÄÐÅÏ¢¡£Õ÷Ç󶨼û¸åÃ÷È· £¬°ä²¼ÍøÂ簲ȫÍþвÐÅÏ¢ £¬Ó¦ÒÔÊØ»¤ÍøÂ簲ȫ¡¢ÍƽøÍøÂ簲ȫÒâʶÌáÉý¡¢»¥»»ÍøÂ簲ȫ·À»¤¼¼Êõ֪ʶΪÖ÷ÕÅ £¬²»µÃ·çÏÕ¹ú¶È°²È«ºÍÉç»á¹«¹²ÀûÒæ £¬²»µÃ¼Óº¦¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄºÏ·¨È¨Àû¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2019-11/20/c_1575785387932969.htm

2¡¢ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿Í¹¥»÷ £¬CLI×°Öðü±»´úÌæÎª¶ñÒâÈí¼þ


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿ÍÈëÇÖ £¬¹Ù·½Linux CLI¶þ½øÔìÎļþ±»´úÌæÎªÇÔÈ¡Óû§×ʽðµÄ¶ñÒâÈí¼þ¡£¸ÃÊÂÎñ²úÉúÔÚ11ÔÂ18ÈÕ £¬Ò»ÃûÓû§ÔÚGithubÉϻ㱨Á˸ÃÎÊÌâ £¬ÃÅÂÞ±ÒÍŶÓËæºó½øÐÐÁËÈ·ÈÏ¡£½¨ÒéÔÚ18ºÅ2:30 AM UTCÖÁ4:30 PM UTCÖ®¼äÏÂÔØÁËCLIÇ®°üµÄÓû§²é³­Æä¶þ½øÔìÎļþµÄ¹þÏ£Öµ £¬ÈôÊÇÓë¹ÙÍøÉϵĹþÏ£Öµ²»Æ¥Åä £¬Ôò²»ÒªÔËÐиÃÈí¼þ²¢É¾³ýËü¡£µ±Ç°ÃÅÂÞ±ÒÍŶӰµÊ¾ÈÔÔÚµ÷²é¹¥»÷ÕßÈôºÎÈëÇÔìäÏÂÔØ·þÎñÆ÷ £¬Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶àÓû§ÔÚÕâ´ÎºÚ¿Í¹¥»÷ÖÐËðʧÁË×ʽð¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/official-monero-website-compromised-with-malware-that-steals-funds/

3¡¢GateHubºÍEpicBotµÄ220ÍòÓû§Êý¾ÝÔÚÍøÉϹ«¿ª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°²È«×êÑÐÔ±Troy Hunt°µÊ¾¼ÓÃÜÇ®±ÒÇ®°ü·þÎñGateHubºÍÓÎÏ·ÍøÕ¾EpicBotµÄ220Óû§ÕË»§Êý¾ÝÔÚÍøÉϹ«¿ª¡£¸ÃÊý¾Ý¿âÔ̺¬140Íò¸öGateHubÕÊ»§ºÍ80Íò¸öEpicBotÕÊ»§µÄÐÅÏ¢ £¬Èçµç×ÓÓʼþµØÖ·ºÍ¾­¹ýbcrypt´¦ÖõĹþÏ£ÃÜÂë¡£GateHubÈÏ¿ÉÔÚÏÄÌìÔâµ½ºÚ¿ÍÈëÇÖ £¬µ«Æäʱ°µÊ¾½öÓÐ18473¸ö¿Í»§ÕË»§±»·¸·¨½Ó¼û £¬´Ë¿Ì¿´À´ÕâÒ»ÁìÓòÒª´óµÃ¶à¡£EpicBotĿǰÉÐδÈÏ¿ÉËüÒѱ»ºÚ¿ÍÈëÇÖ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-dump-2-2m-gaming-cryptocurrency-passwords-online/150451/

4¡¢PayMyTabÒâ±íй¶ÊýǧÃûÃÀ¹ú²Í¹Ý¹Ë¿ÍÊý¾Ý

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÃÀ¹úÒÆ¶¯Ö§¸¶·þÎñÉÌPayMyTabÒòδ×ñÑ­AWSµÄ°²È«ºÍ̸ £¬µ¼ÖÂÊýǧÃû²Í¹Ý¹Ë¿ÍµÄÊý¾Ýй¶¡£¸Ã¹«Ë¾×Ô2018Äê7ÔÂ2ÈÕÆðûÓн«´æ´¢¿Í»§Êý¾ÝµÄAWS S3´æ´¢Í°¸ü¸ÄΪ˽ÓÐ £¬Ê¹µÃÈκÎÈ˶¼Äܹ»½Ó¼ûʹÓÃPayMyTab·þÎñµÄ²ÍÌü¹Ë¿ÍÊý¾Ý £¬Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÐÅÓþ¿¨ºóËÄλ¡¢¾Í²Í¾­ÀúµÈÐÅÏ¢¡£Æ¾¾ÝvpnMentorµÄ˵·¨ £¬¸ÃÊý¾Ý¿â¶³öÁ˳¤´ï16¸öԵŦ·ò £¬¹ÌȻûÓÐй¶µÄÊý¾ÝÁ¿»ò¿Í»§ÊýÁ¿¼òÖ±ÇÐÊý×Ö £¬µ«ÊýǧÃû¿Í»§¿ÉÄÜÒò¶øÊܵ½ÔÚÏßڲƭ»ò¹¥»÷¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/paymytab-data-leak-exposes-personal-information-belonging-to-mobile-diners/

5¡¢ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ºÚ¿Í´Ó¿ªÂüÒøÐÐÇÔÈ¡ÁË2TBµÄÊý¾Ý²¢°ä²¼ÔÚÍøÉÏ¡£¾Ý³ÆÕâЩÊý¾ÝÊÇÓɺڿͻòºÚ¿ÍÍÅ»ïPhineas FisherÇÔÈ¡µÄ £¬²¢Í¨¹ýDistributed Denial of SecretsÏîÄ¿°ä²¼¡£Êý¾Ý¼¯ÖÐÔ̺¬¿ªÂüÒøÐÐΪÆäÈ«Çò¿Í»§ÖÎÀíµÄ³¬¹ý3800¼Ò¹«Ë¾¡¢ÐÅÈκÍÓ×ÎÒÕË»§µÄ¾ßÌ岯ÕþÐÅÏ¢ £¬ÉõÖÁÔ̺¬ÕË»§Óà¶î¡ £¿ªÂüÒøÐв¢Î´ÈÏ¿ÉÊý¾Ýй¶ £¬µ«°²È«×¨¼Ò°ÑÎȵ½ÆäºÜ¶à·þÎñÓÚ11ÔÂ17ÈÕÒò¡°³Á´óÉý¼¶ºÍÊØ»¤¡±¶ø´¦ÓÚ²»³ÉÓÃ״̬¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94136/data-breach/cayman-national-bank-data-leak.html

6¡¢DockerÌÓÒÝ·ì϶(CVE-2019-14271) PoC°ä²¼


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±°ä²¼DockerÌÓÒÝ·ì϶£¨CVE-2019-14271£©µÄPoC £¬²¢¶½´ÙÓû§Éý¼¶µ½×îа汾¡£¸Ã·ì϶ÔÚ7Ô·ݵÄDocker°æ±¾19.03.1Öн¨¸´ £¬µ«ÈôÊÇδ´ò²¹¶¡ £¬¹¥»÷Õß¿ÉÄÜ»áͨ¹ý¶ñÒâÈÝÆ÷¾µÏñÔÚÓû§µÄËÞÖ÷»úÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£Palo Alto Networks°²È«×êÑÐÔ±Yuval Avrahami¶½´ÙDocker¿ª·¢ÈËԱͨ¹ý½öÔËÐÐÊÜÐÅÀµµÄ¾µÏñÀ´Ï÷¼õ¹¥»÷Ãæ £¬²¢½¨ÒéÔÚ²»±ØÒªrootµÄÇé¿öÏÂÒÔ·ÇrootÓû§Éí·ÝÔËÐÐÈÝÆ÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/researchers-public-poc-docker/