Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ±»¹¥ÆÆ£»£»£»£»£»£»2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼

Ðû²¼Ê±¼ä 2019-11-08
1¡¢Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ¾ù±»¹¥ÆÆ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

ÔÚPwn2Own Tokyo 2019ºÚ¿Í´óÈüµÄµÚÒ»Ì죬£¬ £¬£¬£¬£¬£¬ÑÇÂíÑ·EchoÖÇÄÜÒôÏä¡¢ÈýÐǺÍË÷ÄáµÄÖÇÄܵçÊÓ¡¢Ð¡Ã×9ÊÖ»úÒÔ¼°NetgearºÍTP-Link·ÓÉÆ÷¾ù±»²ÎÈüÕß¹¥ÆÆ¡£¡£¡£¡£±¾´Î´óÈüÊÇÓÉZero Day Initiative×éÖ¯µÄ£¬£¬ £¬£¬£¬£¬£¬Ä¿µÄ×°±¸°üÀ¨17¿î£¬£¬ £¬£¬£¬£¬£¬¹²ÔÊÐíÌṩÁè¼Ý75ÍòÃÀÔªµÄÏÖ½ðºÍ½±Æ·¡£¡£¡£¡£ÕâÒ²ÊÇÊ×´ÎPwn2Own½«FacebookµÄPortalÖÇÄÜÏÔʾÆ÷ºÍOculus Quest VRÍ·¿øÁÐÈëÄ¿µÄ¡£¡£¡£¡£ÔÚ´óÈüÊ×ÈÕ²ÎÈüÕßÒѾ­»ñµÃÁË19.5ÍòÃÀÔªµÄ½±Àø£¬£¬ £¬£¬£¬£¬£¬ÊÕ»ñ×î¶àµÄÊÇFluoroacetateÍŶÓ£¬£¬ £¬£¬£¬£¬£¬¸ÃÍŶӻ®·Ö¹¥ÆÆÁËË÷ÄáX800GµçÊÓ¡¢ÑÇÂíÑ·Echo¡¢ÈýÐÇQ60µçÊÓ¡¢Ð¡Ã×9ºÍGalaxy S10¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-portal-survives-pwn2own-hacking-contest-amazon-echo-got-hacked/

2¡¢ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏ·ÖÏí7¸ö¶ñÒâÑù±¾


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏÐû²¼ÁË7¸öеĶñÒâÈí¼þÑù±¾£¬£¬ £¬£¬£¬£¬£¬ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÃãÀøÓû§Éó²éÕâЩÑù±¾²¢»á¼ûCISAµÄ¶ñÒâ´úÂë·À»¤Êµ¼ù¡£¡£¡£¡£ÓÐÑо¿Ö°Ô±ÔÚTwitterÉϻظ´³ÆÕâЩÑù±¾¿ÉÄÜÓëAPT28ÓйØ¡£¡£¡£¡£¸Ã»ú¹¹ÉÏÒ»´Î¹²Ïí¶ñÒâÑù±¾ÊÇÔÚÁ½¸öÔÂǰ£¬£¬ £¬£¬£¬£¬£¬ÆäÊ±ÍøÂç˾ÁÐû²¼ÁË11¸öÓ볯ÏÊAPT×éÖ¯LazarusÓйصÄÑù±¾¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2019/11/06/us-cyber-command-shares-seven-new-malware-samples

3¡¢Magento 1.x½«×èÖ¹¸üУ¬£¬ £¬£¬£¬£¬£¬20¶àÍò¸öÍøÕ¾ÃæÁÙΣº¦

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Magento 1.x·ÖÖ§½«ÔÚ2020Äê6ÔµִïÉúÃüÖÜÆÚ£¨EOL£©£¬£¬ £¬£¬£¬£¬£¬½ìʱ»ùÓÚ¸ÃÆ½Ì¨µÄÔÚÏßÊÐËÁ½«ÎÞ·¨ÊÕµ½Çå¾²¸üУ¬£¬ £¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃǽ«ÃæÁÙÍøÕ¾±»ºÚ¿ÍÈëÇÖ»òѬȾ¶ñÒâ´úÂ루ÈçMagecart£©µÄΣº¦¡£¡£¡£¡£¾Ýͳ¼ÆÏÖÔÚÊÜÓ°ÏìµÄÔÚÏßÊÐËÁÊýÄ¿ÔÚ20Íòµ½24ÍòÖ®¼ä£¬£¬ £¬£¬£¬£¬£¬ÕâЩÊÐËÁÐèÒªÔÚδÀ´9¸öÔÂÄÚ¶ÔØÊºó¶Ëƽ̨¾ÙÐÐÉý¼¶£¬£¬ £¬£¬£¬£¬£¬ºÃ±ÈǨáãµ½Magento 2.x·ÖÖ§¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/between-200000-and-240000-magento-online-stores-will-reach-eol-next-year/

4¡¢¼ÓÀû¸£ÄáÑÇÖÝDMVй¶¼ÝʻԱÊý¾Ý³¤´ïËÄÄêʱ¼ä


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝÆû³µÖÎÀí²¿·Ö£¨DMV£©Ð¹Â¶ÊýǧÃû¼ÝʻԱµÄÊý¾Ý³¤´ï4ÄêµÄʱ¼ä¡£¡£¡£¡£¹²ÓÐ3200Ãû¼ÝʻԱ±»Éæ¼°£¬£¬ £¬£¬£¬£¬£¬ËûÃǵÄÐÅÏ¢±»Î¥¹æ·ÖÏí¸ø7¸ö»ú¹¹£¬£¬ £¬£¬£¬£¬£¬°üÀ¨San DiegoºÍSanta ClaraÏØµÄµØÇøÉó²é¹Ù¡¢Ð¡ÐÍÆóÒµÖÎÀí¾Ö¡¢¹ú˰¾ÖµÈ²¿·Ö¡£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨±¨µÀ¡·£¬£¬ £¬£¬£¬£¬£¬ÕâЩ»ú¹¹¿ÉÔÚ·¸·¨»î¶¯ÊÓ²ì»ò˰·¨ÊÓ²ìÖÐÎ¥¹æ»á¼ûDMV̻¶µÄÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬µ«Êý¾ÝûÓÐ̻¶¸øÐ¡ÎÒ˽¼Ò¡£¡£¡£¡£ÔÚ8ÔÂ2ÈÕ·¢Ã÷Î¥¹æÐÐΪºó²»¾ÃDMV¼´ÏÞÖÆÁ˶ÔÊý¾ÝµÄ»á¼û¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/california-dmv-exposes-drivers/

5¡¢2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ƾ֤APWGµÄͳ¼ÆÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬2019ÄêÇï¼¾ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂʱ´ú¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýΪ266387£¬£¬ £¬£¬£¬£¬£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465ÔöÌíÁË46%£¬£¬ £¬£¬£¬£¬£¬ÏÕЩÊÇ2018ÄêµÚËÄÐò¶ÈµÄ138328µÄÁ½±¶¡£¡£¡£¡£³ýÁË´¹ÂÚÍøÕ¾ÊýÄ¿µÄÔöÌíÖ®Í⣬£¬ £¬£¬£¬£¬£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹ÂÚ¹¥»÷µÄÆ·ÅÆÊýĿҲÏÔ×ÅÔöÌí£¬£¬ £¬£¬£¬£¬£¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬ £¬£¬£¬£¬£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/

6¡¢ÑÇÂíÑ·°²·ÀÃÅÁåRing Video DoorbellÒ×ÔâMitm¹¥»÷


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


BitdefenderÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÑÇÂíÑ·µÄRing Video Doorbell Pro×°±¸Öб£´æ¸ßΣÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÑéÖÐÐÄÈ˹¥»÷²¢ÇÔÈ¡Óû§µÄWi-FiÃÜÂë¡£¡£¡£¡£Ring Video DoorbellÊÇÒ»¸ö´øÉãÏñÍ·µÄÖÇÄÜÎÞÏß°²·ÀÃÅÁ壬£¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸ÓëAPPµÄͨѶΪ²»Çå¾²µÄHTTP´«Ê䣬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕÆ­Óû§ÖØÐÂÉèÖøÃ×°±¸²¢Ðá̽ÆäÃÜÂ룬£¬ £¬£¬£¬£¬£¬½ø¶ø¿ÉÒÔÌᳫÖÖÖÖ¶ñÒâ»î¶¯£¬£¬ £¬£¬£¬£¬£¬°üÀ¨Óë¼ÒÍ¥ÍøÂçÖеÄ×°±¸½»»¥¡¢»á¼ûÍâµØNAS¡¢ÈëÇÖÆäËü×°±¸µÈ¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ9ÔÂ5ÈÕÐû²¼ÁËÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html