¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190115

Ðû²¼Ê±¼ä 2019-01-16
1¡¢Ó¢¹úBSIAÐû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹ú°²·ÀÐÐҵЭ»á£¨BSIA£©Ðû²¼»¥ÁªÇ徲ϵͳ×î¼Ñʵ¼ùÖ¸ÄÏ¡£¡£ ¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÖ¼ÔÚ×î´óÏ޶ȵØïÔÌ­µç×ÓÇ徲ϵͳÖеÄÍøÂçÅþÁ¬×°±¸¡¢Èí¼þºÍϵͳµÄÊý×ÖÆÆËðΣº¦¡£¡£ ¡£¡£¡£¡£¡£¸ÃÖ¸ÄÏÒÔÐÐÒµµÄ×î¼Ñ¹ú¼Êʵ¼ùΪ»ù´¡£¬£¬£¬£¬£¬²¢²Î¿¼¹«ÈϵĹú¼ÊÖ¸ÄϺͱê×¼£¬£¬£¬£¬£¬¿ÉÒÔ×ÊÖú»¥ÁªÇ徲ϵͳ¹©Ó¦Á´ÖеÄÉè¼ÆÕß¡¢ÖÆÔìÉÌ¡¢×°ÖÃÖ°Ô±¡¢Î¬»¤Ö°Ô±¡¢Ð§ÀÍÌṩÉ̺ÍÓû§ÌáÉýÇå¾²ÅþÁ¬µÄÐÅÐÄ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/bsia-guidelines-digital-sabotage/


2¡¢ETC51%¹¥»÷Õß½«¼ÛÖµ10ÍòÃÀÔªµÄETC·µ»¹¸øGate.io

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



ƾ֤Gate.ioµÄ˵·¨£¬£¬£¬£¬£¬2019Äê1ÔÂ10ÈÕETCÍøÂç51%¹¥»÷ÕßÍË»ØÁ˼ÛÖµ10ÍòÃÀÔªµÄETC¡£¡£ ¡£¡£¡£¡£¡£¸ú×Ù·¢Ã÷ÉÐÓиü¶à×ʽ𷵻ص½ÆäËüƽ̨¡£¡£ ¡£¡£¡£¡£¡£Gate.ioÊÔͼÓë¹¥»÷ÕßÈ¡µÃÁªÏµ£¬£¬£¬£¬£¬µ«ÉÐδÊÕµ½»Ø¸´¡£¡£ ¡£¡£¡£¡£¡£ÏÖÔÚÉв»ÇåÎú¹¥»÷Õß·¢¶¯Õë¶ÔETCµÄ51%¹¥»÷µÄÏêϸԵ¹ÊÔ­ÓÉ£¬£¬£¬£¬£¬ÈôÊDz»ÊÇΪÁË׬Ǯ£¬£¬£¬£¬£¬ÄÇôÆäÄ¿µÄÓпÉÄÜÊÇΪÁËÒýÆðÐÐÒµ¹ØÓÚÇø¿éÁ´¹²Ê¶Ëã·¨ºÍËãÁ¦±£»£»£»£»¤µÄÖØÊÓ¡£¡£ ¡£¡£¡£¡£¡£µ«¹¥»÷ÕßÈÔ±£´æÓмÛÖµÔ¼100ÍòÃÀÔªµÄ±»µÁ×ʽ𡣡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/51-percent-ethereum-hacker-returns-100000-in-stolen-cryptocurrency/


3¡¢Mozilla½«´ÓFirefox 69×îÏȽûÓÃAdobe Flash

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤Mozilla×îеIJå¼þõ辶ͼ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÍýÏëÔÚFirefox 69ÖнûÓÃAdobe Flash²å¼þ¡£¡£ ¡£¡£¡£¡£¡£¸Ã°æ±¾Ô¤¼Æ½«ÓÚ2019Äê9ÔÂ3ÈÕÐû²¼£¬£¬£¬£¬£¬ÕâÒâζ×Å´ÓÕâÒ»Ìì×îÏÈ£¬£¬£¬£¬£¬FlashÔÚFirefoxÉϵÄÀúÊ·½«»ù±¾Íê½á¡£¡£ ¡£¡£¡£¡£¡£½ûÓÃFlashÊÇΪÁËÅäºÏAdobe½«ÔÚ2020Äêµ××èÖ¹Ö§³ÖFlash²å¼þµÄÕþ²ß¡£¡£ ¡£¡£¡£¡£¡£ÔÚFirefox 69֮ǰ£¬£¬£¬£¬£¬Óû§Ò²¿ÉÒÔͨ¹ýÊÖ¶¯²Ù×÷½ûÓÃFlash²å¼þ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/software/mozilla-to-disable-flash-plugin-by-default-in-firefox-69/


4¡¢Neiman MarcusÊý¾Ýй¶ÊÂÎñ¸æ¿¢150ÍòÃÀԪϢÕùЭÒé

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÉÝ³ÞÆ·Á¬Ëø°Ù»õÊÐËÁNeiman MarcusÒѾ­Ô޳ɼ¨2014ÄêµÄÊý¾Ýй¶ÊÂÎñ¸æ¿¢150ÍòÃÀÔªµÄÏ¢ÕùЭÒé¡£¡£ ¡£¡£¡£¡£¡£¸Ãй¶ÊÂÎñ±¬·¢ÔÚ2014Äê7ÔÂ16ÈÕÖÁ10ÔÂ30ÈÕʱ´ú£¬£¬£¬£¬£¬Ô¼ÓÐ37ÍòÓû§µÄÐÅÓÿ¨ÐÅÏ¢±»ÇÔ£¬£¬£¬£¬£¬ÆäÖÐÖÁÉÙÓÐ9200ÕÅÐÅÓÿ¨ÒÑÔ⵽ڲƭʹÓᣡ£ ¡£¡£¡£¡£¡£Æ¾Ö¤µÂ¿ËÈøË¹ÖÝÉó²é³¤°ì¹«ÊÒµÄÉùÃ÷£¬£¬£¬£¬£¬Neiman MarcusÒÑÓë43¸öÖݸ濢ϢÕù£¬£¬£¬£¬£¬°üÀ¨µÂ¿ËÈøË¹ÖÝ¡¢°¢À­Ë¹¼ÓÖÝ¡¢¿ÆÂÞÀ­¶àÖÝ¡¢Å¦Ô¼ÖݺͻªÊ¢¶ÙÖݵÈ¡£¡£ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/neiman-marcus-agrees-to-1-5-million-data-breach-settlement/


5¡¢DX.ExchangeÉúÒâÍøÕ¾Îó²îµ¼ÖÂÓû§Êý¾Ýй¶

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤ÐÂÎÅÍøÕ¾Ars TechnicaµÄ±¨µÀ£¬£¬£¬£¬£¬Ò»ÃûÉúÒâÔ±·¢Ã÷DX.ExchangeÉúÒâÍøÕ¾Éϱ£´æÇå¾²Îó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§µÄÃô¸ÐÊý¾Ýй¶¡£¡£ ¡£¡£¡£¡£¡£¸ÃÉúÒâÔ±·¢Ã÷DX.ExchangeÍøÕ¾µÄHTTPÏìÓ¦ÖаüÀ¨ÆäËüÓû§µÄÉí·ÝÑéÖ¤ÁîÅÆºÍÃÜÂëÖØÖÃÁ´½Ó£¬£¬£¬£¬£¬¸ÃÉúÒâÔ±»¹¿Éͨ¹ýÆôÓÃAPI»á¼ûÀ´·­¿ªÓÀÊÀºóÃŽøÈëÊÜÓ°ÏìµÄÓû§ÕË»§¡£¡£ ¡£¡£¡£¡£¡£ÈôÊÇ¿ÉÒÔ½øÈë¾ßÓÐÖÎÀíȨÏÞµÄÕË»§£¬£¬£¬£¬£¬¹¥»÷Õß½«Äܹ»ÏÂÔØÕû¸öÊý¾Ý¿â¡¢×¢Èë¶ñÒâÈí¼þÉõÖÁ´ÓÓû§ÕË»§ÖÐ×ªÒÆ×ʽ𡣡£ ¡£¡£¡£¡£¡£DX.ExchangeÒѾ­ÐÞ¸´Á˸ÃÎó²î¡£¡£ ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2019/01/11/trading-site-dx-exchange-spills-gobs-of-user-data/


6¡¢Ê©Ä͵ÂÐÞ¸´EVlink³äµç×®ÖеÄÈý¸öÇå¾²Îó²î

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾



Ñо¿Ö°Ô±·¢Ã÷Ê©Ä͵ÂEVlink³äµç×®Öб£´æÈý¸öÇå¾²Îó²î£¨CVE-2018-7800¡¢CVE-2018-7801ºÍCVE-2018-7802£©£¬£¬£¬£¬£¬ÕâЩÎó²îÓ°ÏìÁËEVLink Parking v3.2.0-12_v1¼°¸üÔçµÄ°æ±¾¡£¡£ ¡£¡£¡£¡£¡£Ê©Ä͵ÂEVlink³äµç×®±»ÆÕ±éÓÃÓÚÂùݡ¢³¬ÊкÍÊÐÕþ¾ÖµÄÍ£³µ³¡ÖУ¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î»ñµÃ³äµç×®µÄ»á¼ûȨÏÞ£¬£¬£¬£¬£¬´Ó¶øÓ°Ïì³µÁ¾µÄ³äµçÀú³Ì¡£¡£ ¡£¡£¡£¡£¡£½¨ÒéÓû§Ö»¹ÜïÔÌ­ÕâЩװ±¸ÔÚ»¥ÁªÍøÉϵÄ̻¶ÇéÐΡ£¡£ ¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/three-flaws-in-schneider-electric/


ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí