¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180622

Ðû²¼Ê±¼ä 2018-06-22

¡¾Êý¾Ýй¶¡¿Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶


Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨ЧÀÍÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×ÙЧÀ͵Ĺ«Ë¾£¬£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ´Ë´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£¡£¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁ˰üÀ¨ÃÜÂëÖØÖÃÁ´½ÓµÄÓʼþ£¬£¬£¬£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html


¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û


Çå¾²Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öapp£¨°üÀ¨2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬£¬Áè¼Ý1ÒÚÌõÓû§ÐÅϢй¶£¨Áè¼Ý113GB£©¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢Î»ÖÃÒÔ¼°²¿·Ö²ÆÎñ¼Í¼£¨ÒøÐС¢¼ÓÃÜÇ®±ÒÉúÒ⣩µÈ¡£¡£¡£GoogleµÄFirebaseÊÇ×îÊܽӴýµÄÒÆ¶¯ºÍWebÓ¦Óõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬£¬£¬£¬ËüΪ¿ª·¢Ö°Ô±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬£¬£¬£¬²¢ÒÔJSONÃûÌô洢Êý¾Ý¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Ðí¶à¿ª·¢Ö°Ô±Î´Í×ÉÆ±£»£»£»£»¤ÆäFirebaseÊý¾Ý¿â£¬£¬£¬£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÌí¼Ó¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É»á¼ûÕâЩÊý¾Ý¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯


˼¿ÆTalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯£¬£¬£¬£¬FormBookÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬£¬°üÀ¨¼üÅ̼ͼ¡¢ÇÔÈ¡ÃÜÂ루ÍâµØÃÜÂëºÍweb±íµ¥ÖеÄÃÜÂ룩ÒÔ¼°½ØÆÁµÈ¹¦Ð§¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄй¥»÷»î¶¯ÔÚͳһ·â´¹ÂÚÓʼþÖÐʹÓÃÁË4¸ö²î±ðµÄ¶ñÒâÎĵµ£¨°üÀ¨PDFºÍWordÃûÌã©£¬£¬£¬£¬²¢Ê¹ÓÃÁ½¸ö¹ûÕæµÄOfficeÎó²îʹÓã¨CVE-2017-0199ºÍCVE-2017-11882£©·Ö·¢ÓÐÓúÉÔØ¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/06/my-little-formbook.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ѬȾÁè¼Ý6Íò¸öÊÖ»úµÄ¶ñÒâÈí¼þScammy


RiskIQÑо¿ÍŶӷ¢Ã÷Ò»¸öжñÒâapp Scammy£¬£¬£¬£¬ScammyÖ÷ÒªÓÃÓÚ×Ô¶¯µã»÷¹ã¸æºÍÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬£¬°üÀ¨IMEI¡¢µç»°ºÅÂë¡¢ÊÖ»úÐÍºÅºÍÆ·ÅÆ¡¢Î»Öõȡ£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þÖÁÉÙÒÑѬȾÁË6Íò¸öAndroidÊÖ»ú¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄIoCÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/interesting-crawls/battery-saving-mobile-scam-app/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±³ÆFireFoxºÍEdge±£´æÎó²îWavethrough£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶


GoogleÑо¿Ö°Ô±Jake Archibald·¢Ã÷ÏÖ´úä¯ÀÀÆ÷±£´æÇå¾²Îó²îWavethrough£¬£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÇÔÈ¡ÔÚ¸Ãä¯ÀÀÆ÷ÉϵǼ¹ýµÄÆäËüÍøÕ¾µÄÕË»§µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¸ÃÎó²îÓëä¯ÀÀÆ÷´¦Öóͷ£¶ÔÊÓÆµºÍÒôƵÎļþµÄ¿çÓòÇëÇóµÄ·½·¨ÓйØ£¬£¬£¬£¬ÉõÖÁ¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Óû§µÄGmail»òFacebook˽ÈËÐÂÎÅ¡£¡£¡£ChromeºÍSafari²»ÊÜÓ°Ï죬£¬£¬£¬FireFoxºÍEdgeÒ²ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/browser-cross-origin-vulnerability.html


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐÞ¸´FXOSºÍNX-OSÖеÄ24¸öÇå¾²Îó²î£¬£¬£¬£¬¶à¸öÐͺŵĽ»Á÷»úÊÜÓ°Ïì


±¾ÖÜÈý˼¿ÆÐû²¼FXOSºÍNX-OSµÄÇå¾²¸üУ¬£¬£¬£¬¹²ÐÞ¸´24¸öÇå¾²Îó²î£¬£¬£¬£¬ÆäÖаüÀ¨5¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеĸßΣÎó²î£¨CVE-2018-0301¡¢CVE-2018-0308¡¢CVE-2018-0304¡¢CVE-2018-0314ºÍCVE-2018-0312£©¡£¡£¡£Îó²î¹æÄ£°üÀ¨Î´ÊÚȨ»á¼û¡¢ÌáȨ¡¢í§Òâ´úÂëÖ´ÐС¢í§ÒâÏÂÁîÖ´ÐС¢Ãô¸ÐÐÅϢй¶ºÍDoS¡£¡£¡£Ë¼¿ÆÈ·ÈϳÆÕâЩÎó²îûÓÐÓ°ÏìCisco IOS»òIOS XE¡£¡£¡£ÏêϸÎó²îÁбíÇë»á¼ûÒÔÏÂÁ´½Ó¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770