¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180917

Ðû²¼Ê±¼ä 2018-09-17
1¡¢Î¢ÈíÐÞ¸´¶à¸öWindows°æ±¾Öпɵ¼ÖÂDoSµÄFragmentSmackÎó²î



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


΢ÈíÐû²¼¹ØÓڿɵ¼ÖÂDoSµÄÇå¾²Îó²îFragmentSmackµÄÇ徲ͨ¸æ£¬£¬ £¬£¬£¬¸ÃÎó²î£¨CVE-2018-5391£©ÊÇÒ»ÖÖIPË鯬¹¥»÷£¨Teardrop¹¥»÷£©£¬£¬ £¬£¬£¬¿Éµ¼ÖÂÅÌËã»úµÄCPUµÖ´ï×î´óʹÓÃÂʲ¢ÇÒ²Ù×÷ϵͳÎÞÏìÓ¦¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËWindows 7¡¢8ºÍ10ÒÔ¼°Server 2008¡¢2012ºÍ2016ϵͳ¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÏìÓ¦µÄ¸üС£¡£¡£¡£¡£


   Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/windows-systems-vulnerable-to-fragmentsmack-90s-like-dos-bug/


2¡¢Ñо¿Ö°Ô±·¢Ã÷macOSÇå¾²Èí¼þWebroot SecureAnywhere±£´æÄں˼¶Îó²î



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


TrustwaveµÄÑо¿Ö°Ô±·¢Ã÷macOSÇå¾²Èí¼þWebroot SecureAnywhereÖб£´æÒ»¸ö¿É±»ÍâµØÊ¹ÓõÄÄں˼¶Îó²î¡£¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-16962£©ÊÇÓÉȱÉÙ¶ÔÓû§Ö¸ÕëµÄÑéÖ¤¶øµ¼ÖµÄ£¬£¬ £¬£¬£¬ÔÚijЩÇéÐÎÏ£¬£¬ £¬£¬£¬¸ÃÎó²î¿ÉÄÜÓëÆäËüÎó²îÁ¬ÏµÒÔ¾ÙÐÐÍâµØÌáȨ£¬£¬ £¬£¬£¬µ¼ÖÂÒÔÄں˼¶È¨ÏÞÖ´ÐжñÒâÈí¼þ¡£¡£¡£¡£¡£Webroot SecureAnywhere°æ±¾9.0.8.34ÖÐÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76220/hacking/webroot-secureanywhere-flaw.html


3¡¢Ñо¿Ö°Ô±ÑÝʾͨ¹ýCSSºÍHTMLÍøÒ³µ¼ÖÂiPhoneÖØÆôºÍMac¿¨ËÀµÄй¥»÷ÒªÁì



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


WireÇå¾²Ñо¿Ö°Ô±Sabri HaddoucheÉè¼Æ³öÒ»ÖÖͨ¹ýCSS&HTMLÍøÒ³¿ìËٺľ¡Æ»¹û×°±¸×ÊÔ´µÄ¹¥»÷ÒªÁì¡£¡£¡£¡£¡£¸Ã¹¥»÷¿É¿ìËÙÏûºÄËùÓеÄͼÐÎ×ÊÔ´²¢µ¼Ö²Ù×÷ϵͳ±ÀÀ£»£»£»£»£»ò¿¨ËÀ£¬£¬ £¬£¬£¬ËùÓÐʹÓÃWebKitäÖȾÒýÇæµÄiOSä¯ÀÀÆ÷ÒÔ¼°macOSÖеÄSafariºÍMail¶¼Êܵ½Ó°Ïì¡£¡£¡£¡£¡£¹ØÓÚiOS£¬£¬ £¬£¬£¬¸Ã¹¥»÷½«µ¼ÖÂÄÚºËÍß½â²¢ÖØÆô£»£»£»£»£»¹ØÓÚmacOS£¬£¬ £¬£¬£¬¸Ã¹¥»÷½«µ¼ÖÂSafari»á»°ÖØÆô¼°×°±¸¿¨ËÀ¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»Óв½·¥·À»¤´ËÀ๥»÷¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-css-attack-restarts-an-iphone-or-freezes-a-mac/


4¡¢Ñо¿ÍŶӷ¢Ã÷αװ³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄ´¹ÂÚÓʼþ¹¥»÷



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Malwarebytes LabsÑо¿ÍŶӷ¢Ã÷αװ³ÉÓ¢¹ú˰Îñ¾ÖHMRCµÄÍøÂç´¹Âڻ¡£¡£¡£¡£¡£¸Ã´¹ÂÚÓʼþµÄÖ÷ÌâÊÇ542.94Ó¢°÷µÄÍË˰£¬£¬ £¬£¬£¬ÓʼþÕýÎÄÖаüÀ¨ÓÃÓÚÍË˰µÄÍøÕ¾Á´½Ó¡£¡£¡£¡£¡£¸Ã´¹ÂÚÍøÕ¾µÄµÚÒ»¸öÈë¿ÚµãÊÇÐéαµÄOutlookµÇÂ¼Ò³Ãæ£¬£¬ £¬£¬£¬ÆäÍøÖ·ÊÇonlinehmrevnue(.)from-tx(.)com/webGBTxid/checkValidation(.)php£¬£¬ £¬£¬£¬Ò»µ©Óû§ÊäÈëÏà¹ØÆ¾Ö¤£¬£¬ £¬£¬£¬¾Í»áÌø×ªµ½Ò»¸öÓÃÓÚÍøÂçÐÕÃû¡¢µØµã¡¢µç»°ºÅÂëµÈÐÅÏ¢µÄÍøÒ³¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://blog.malwarebytes.com/cybercrime/2018/09/hmrc-phish-swipes-email-login-payment-details/


5¡¢Çå¾²Ñо¿Ö°Ô±·¢Ã÷ÀÕË÷Èí¼þDharmaµÄбäÌåBrrr



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±Jakub Kroustek·¢Ã÷ÀÕË÷Èí¼þDharma¼Ò×åµÄÒ»¸öбäÌ壬£¬ £¬£¬£¬¸Ã±äÌåÔÚ¼ÓÃܵÄÎļþºó¸½¼Ó.brrrÀ©Õ¹Ãû¡£¡£¡£¡£¡£Dharmaͨ¹ýRDPÅþÁ¬ÊÖ¶¯¾ÙÐзַ¢£¬£¬ £¬£¬£¬¹¥»÷Õßͨ¹ýɨÃ迪·ÅµÄTCP3389¶Ë¿Ú£¬£¬ £¬£¬£¬¶ÔÆä¾ÙÐб©Á¦ÆÆ½âÒÔ»ñµÃµÇ¼ƾ֤¡£¡£¡£¡£¡£¹¥»÷ÕßÒ²¿ÉÄÜ´ÓµØÏÂÂÛ̳¹ºÖÿɻá¼ûµÄRDPµÇ¼ƾ֤¡£¡£¡£¡£¡£Brrr»áÔÚ¼ÓÃܵÄÎļþºóÌí¼Ó.id-[id].[email].brrrÀ©Õ¹Ãû¡£¡£¡£¡£¡£ÏÖÔÚ»¹Ã»Óв½·¥Ã⺬»ìÃܸñäÌå¼ÓÃܵÄÎļþ¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-brrr-dharma-ransomware-variant-released/


6¡¢Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬º½°àÐÅÏ¢ÏÔʾÆÁÒÑ×èֹЧÀÍÁ½Ìì



918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹ú²¼Àï˹Íжû»ú³¡Ôâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬ £¬£¬£¬Æäº½°àÐÅÏ¢ÏÔʾÆÁÒÑ×èֹЧÀÍÁ½Ìì¡£¡£¡£¡£¡£¸Ã»ú³¡µÄ½²»°ÈËÌåÏÖº½°à²»ÊÜÓ°Ï죬£¬ £¬£¬£¬µ«±ØÐèʹÓÃÓ¦¼±²½·¥ºÍÊÖ¶¯µÄÁ÷³Ì£¬£¬ £¬£¬£¬°üÀ¨°×°åºÍ¼ÇºÅ±ÊµÈÀ´È¡´úÏÔʾÆÁ¡£¡£¡£¡£¡£¸Ã»ú³¡Ã»ÓÐÏò¹¥»÷ÕßÖ§¸¶Êê½ð¡£¡£¡£¡£¡£Õâ²»ÊÇÒ»´ÎÕë¶ÔÐԵĹ¥»÷£¬£¬ £¬£¬£¬¶øÊÇËæ»úµÄ¹¥»÷¡£¡£¡£¡£¡£¸Ã»ú³¡ÕýÔÚÈ·±£Æäº½°àÐÅϢϵͳÔÚÖØÐÂÉÏÏß֮ǰÊÇÇå¾²µÄ¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/76248/breaking-news/bristol-airport-cyber-attack.html


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí