¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181224

Ðû²¼Ê±¼ä 2018-12-24
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢ÐÂÊÖÒÕÖ§³ÖÕ©Æ­Ò³Ãæ½«µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



Google ChromeµÄbug±¨¸æÖÐÅû¶ÁËÒ»¸öеÄÊÖÒÕÖ§³ÖÕ©Æ­»î¶¯£¬£¬£¬£¬£¬£¬£¬¸ÃÕ©Æ­ÍøÒ³½«Ê¹ÓÃJavaScriptÑ­»·ºÄ¾¡ÅÌËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¡£¡£¸ÃÍøÒ³µÄÎÊÌâΪ¡°Ö÷ÒªÐÅÏ¢¡±£¬£¬£¬£¬£¬£¬£¬Î±×°³ÉÌáÐÑѬȾµÄWindows¹ýʧ¾¯±¨£¬£¬£¬£¬£¬£¬£¬´ËÒ³Ãæ°üÀ¨µÄJavaScript½«Ê¹ä¯ÀÀÖØÊÓ¸´Ìø×ªÖÁ# URL£¬£¬£¬£¬£¬£¬£¬²¢Íù·µµã»÷ÍËÈ´ºÍǰ½ø°´Å¥£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£¡£¡£Óû§¿Éͨ¹ýɱËÀChromeÀú³ÌÀ´¿¢Ê¿¨ËÀÇéÐΡ£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/


3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹ÂÚ¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯·¢Ã÷Á½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÇøµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹Âڻ¡£¡£¡£ÕâЩ´¹Âڻαװ³ÉÕË»§¾¯±¨£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤ÒªÁìµÄGmailºÍYahooÕÊ»§¡£¡£¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþЧÀÍ£¬£¬£¬£¬£¬£¬£¬ÀýÈçProtonMailºÍTutanota£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËüÃÇĬÈϽÓÄÉÁׯü¸ß¼¶±ðµÄÇå¾²ÐÔºÍÒþ˽ÐÔ¡£¡£¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»ÀÖ³ÉÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½Ë𺦡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/


4¡¢Õë¶ÔOrangeµ÷ÖÆ½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬£¬£¬£¬£¬£¬£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Bad Packets LLCÑо¿Ö°Ô±Troy Mursch·¢Ã÷¹¥»÷ÕßÕýÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷ÖÆ½âµ÷Æ÷¡£¡£¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎå×îÏÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃOrange LiveBox×°±¸ÖеÄÎó²î£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷ÖÆ½âµ÷Æ÷£¬£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼Î»ÓÚ·¨¹úºÍÎ÷°àÑÀ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/


5¡¢Ñо¿Ö°Ô±Åû¶Facebookµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬µ«Facebook²»ÍýÏëÐÞ¸´

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


²¨À¼Çå¾²Ñо¿Ö°Ô±·¢Ã÷FacebookµÄAndroidÒÆ¶¯°æ±¾±£´æÒ»¸öµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýiframe±êǩʹÓøÃÎó²îÔÚÓû§µÄFacebookÉÏÐû²¼Á´½Ó¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÎó²îÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·Óйأ¬£¬£¬£¬£¬£¬£¬¸Ã±êÍ·¿ÉÒÔ֪ͨä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«ÍøÒ³¼ÓÔØµ½ÓÕ¶üÍøÒ³µÄ¶¥²ãÖУ¨²»¿É¼ûµÄiFrame£©£¬£¬£¬£¬£¬£¬£¬Óû§½«Íû¼ûÓÕ¶üÍøÒ³£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓë¸ÃiFrame¾ÙÐн»»¥¡£¡£¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÍêÕûÐÔ¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/


6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬£¬£¬£¬£¬£¬£¬UberÔÙ±»·¨¹úÊý¾Ý±£»£»£»£»¤»ú¹¹·£¿£¿£¿£¿£¿î40ÍòÅ·Ôª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


2016ÄêUberÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½Ò»Äê¶àÒÔºóµÄ2017Äê11Ô¸ù«Ë¾²ÅÏòÍâ½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£2018Äê9Ô£¬£¬£¬£¬£¬£¬£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£2018Äê11Ô£¬£¬£¬£¬£¬£¬£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£»£»£»£»¤»ú¹¹»®·ÖÏòUber·£¿£¿£¿£¿£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿î¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬·¨¹úµÄÊý¾Ý±£»£»£»£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿£¿£¿£¿£¿î40ÍòÅ·Ôª¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.html


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí