ÐÅÏ¢Çå¾²Öܱ¨-2019ÄêµÚ9ÖÜ

Ðû²¼Ê±¼ä 2019-03-04

±¾ÖÜÇå¾²Ì¬ÊÆ×ÛÊö


2019Äê2ÔÂ25ÈÕÖÁ3ÔÂ03ÈÕ¹²ÊÕ¼Çå¾²Îó²î42¸ö£¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇApache Airflow AirflowÔªÊý¾Ý¿âí§Òâ´úÂëÖ´ÐÐÎó²î £»£»£»£»F5 BIG-IPÑéÖ¤SSLÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²î; Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î £»£»£»£»Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶ÁдÎó²î £»£»£»£»OpenSSLÇå¾²ÈÆ¹ýÐÅϢй¶Îó²î¡£ ¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊǽü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ £¬£¬£¬£¬£¬ÊÛ¼Û½ü350ÍòÃÀÔª £»£»£»£»Èý¸ö4G/5GÎó²î£¬ £¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½ÂÔ £»£»£»£»Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»È¦Ì×£¬ £¬£¬£¬£¬£¬Õ©Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷ £»£»£»£»Chrome 0dayÎó²î£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢ £»£»£»£»CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬 £¬£¬£¬£¬£¬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ¡£ ¡£¡£

ƾ֤ÒÔÉÏ×ÛÊö£¬ £¬£¬£¬£¬£¬±¾ÖÜÇå¾²ÍþвΪÖС£ ¡£¡£

Ö÷ÒªÇå¾²Îó²îÁбí


1. Apache Airflow AirflowÔªÊý¾Ý¿âí§Òâ´úÂëÖ´ÐÐÎó²î
Apache Airflow±à¼­AirflowÔªÊý¾Ý¿âÖй¤¾ßµÄ״̬±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓ¦ÓóÌÐòÉÏÏÂÎÄÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£
https://lists.apache.org/thread.html/f656fddf9c49293b3ec450437c46709eb01a12d1645136b2f1b8573b@%3Cdev.airflow.apache.org%3E

2. F5 BIG-IPÑéÖ¤SSLÔ¶³Ì¾Ü¾øÐ§ÀÍÎó²î
F5 BIG-IPÑéÖ¤SSL±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷¡£ ¡£¡£
https://support.f5.com/csp/article/K54167061

3. Cisco RV110W/RV130W/RV215W Routers CVE-2019-1663Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Cisco?RV110W Wireless-N VPN Firewall¡¢RV130W Wireless-N Multifunction VPN RouterºÍRV215W Wireless-N VPN Router WEB½Ó¿Ú±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190227-rmi-cmd-ex

4. Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cÔ½½ç¶ÁдÎó²î
Linux kernel net/ipv4/netfilter/nf_nat_snmp_basic_main.cûÓгä·Ö¼ì²éASN.1³¤¶È£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬¿É¾ÙÐоܾøÐ§À͹¥»÷»òÖ´ÐÐí§Òâ´úÂë¡£ ¡£¡£
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c4c07b4d6fa1f11880eab8e076d3d060ef3f55fc

5. OpenSSLÇå¾²ÈÆ¹ýÐÅϢй¶Îó²î
OpenSSL±£´æÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ £¬£¬£¬£¬£¬¿ÉÈÆ¹ýÇå¾²ÏÞÖÆ£¬ £¬£¬£¬£¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£ ¡£¡£
https://www.openssl.org/news/secadv/20190226.txt

 Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö


1¡¢½ü7ÍòÕŰͻùË¹Ì¹ÒøÐп¨ÐÅÏ¢ÔÚ°µÍø³öÊÛ£¬ £¬£¬£¬£¬£¬ÊÛ¼Û½ü350ÍòÃÀÔª

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾

Group-IBÑо¿Ö°Ô±·¢Ã÷69189ÕŰͻùË¹Ì¹ÒøÐп¨µÄÐÅÏ¢ÔÚ°µÍøÉϳöÊÛ¡£ ¡£¡£ÕâÅúÊý¾Ý·ÖΪÁ½¸öÊý¾Ý¿â£¬ £¬£¬£¬£¬£¬×ÜÊÛ¼ÛԼΪ350ÍòÃÀÔª¡£ ¡£¡£µÚÒ»¸öÊý¾Ý¿âÊÇ1ÔÂβÔÚJoker's StashÉÏÐû²¼µÄ£¬ £¬£¬£¬£¬£¬¹²°üÀ¨1535ÕÅÒøÐп¨ÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÆäÖÐ96£¥µÄÒøÐп¨¶¼ÓëMeezan BankÓйØ¡£ ¡£¡£µÚ¶þ¸öÊý¾Ý¿âÊÇ1ÔÂ30ÈÕÔÚJoker's StashÉÏÐû²¼µÄ£¬ £¬£¬£¬£¬£¬°üÀ¨67654ÕÅÒøÐп¨ÐÅÏ¢£¬ £¬£¬£¬£¬£¬Í¬ÑùÓÐ96£¥µÄÒøÐп¨ÓëMeezan BankÓйØ¡£ ¡£¡£ÕâЩÊý¾Ý¿ÉÄÜÅú×¢Îú¸ÃµØÇøÕë¶Ô½ðÈÚ»ú¹¹µÄ¹¥»÷ÕߵĻ¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/81579/cyber-crime/pakistani-banks-cards-darkweb.html

2¡¢Èý¸ö4G/5GÎó²î£¬ £¬£¬£¬£¬£¬¿Éµ¼Ö¹¥»÷ÕßÈÆ¹ýÆä·À»¤Õ½ÂÔ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ÔÚ2019ÄêNDSS×êÑлáÉÏ£¬ £¬£¬£¬£¬£¬Ò»¸öÑо¿ÍŶÓÅû¶ÁËÔÚ4GºÍ5G LTEЭÒé·äÎÑÍøÂçÖз¢Ã÷µÄÈý¸öÐÂÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²î×èµ²Óû§Í¨»°ºÍ×·×ÙÓû§Î»Öᣠ¡£¡£Ñо¿Ö°Ô±Åû¶µÄµÚÒ»ÖÖ¹¥»÷ÒªÁìÊÇTorpedo¹¥»÷£¬ £¬£¬£¬£¬£¬ËüʹÓÃÁËѰºôЭÒéÖеÄÎó²î£¬ £¬£¬£¬£¬£¬ÔÚ¶Ìʱ¼äÄÚ·¢³öºÍ×÷·Ï¶à¸öµç»°¿ÉÒÔ´¥·¢Ñ°ºôÐÂÎÅ£¬ £¬£¬£¬£¬£¬¶ø²»»áÏòÄ¿µÄ×°±¸·¢³öÀ´µç¾¯±¨¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔ¸ú×ÙÄ¿µÄµÄλÖ㬠£¬£¬£¬£¬£¬Ð®ÖÆÑ°ºôÐŵÀºÍ×¢ÈëαÔìµÄѰºôÐÂÎÅÀ´ÌᳫDoS¹¥»÷¡£ ¡£¡£±ðµÄ£¬ £¬£¬£¬£¬£¬ToRPEDO¹¥»÷»¹ÎªÁíÍâÁ½ÖÖ¹¥»÷-PIERCERºÍIMSI-Cracking¹¥»÷-ÌṩÁË¿ÉÄÜ£¬ £¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒÔ»ñÈ¡Óû§µÄIMSI¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2019/02/location-tracking-imsi-catchers.html

3¡¢Õë¶ÔInstagramÓû§µÄ¿ìËÙÖ¸»È¦Ì×£¬ £¬£¬£¬£¬£¬Õ©Æ­½ð¶îÀۼƸߴï300ÍòÓ¢°÷

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ó¢¹ú¹ú¼ÒڲƭºÍÍøÂç·¸·¨Í³¼ÆÖÐÐÄAction FraudÌåÏÖ£¬ £¬£¬£¬£¬£¬Ò»¸öÕë¶ÔInstagramÓû§µÄ¡°¿ìËÙÖ¸»¡±È¦Ì×ÒѾ­ÀÛ¼ÆÕ©Æ­Á˸ߴï300ÍòÓ¢°÷µÄ½ð¶î¡£ ¡£¡£¸ÃÕ©Æ­»î¶¯Ö÷ÒªÕë¶Ô20ÖÁ30ËêµÄÄêÇáÈË£¬ £¬£¬£¬£¬£¬×Ô2018Äê10ÔÂÒÔÀ´£¬ £¬£¬£¬£¬£¬ÒÑÓÐ356ÆðÏà¹ØÊÂÎñµÄ±¨¸æ£¬ £¬£¬£¬£¬£¬Êܺ¦Õ߯½¾ùÿÈËËðʧ8900Ó¢°÷¡£ ¡£¡£¸ÃÕ©Æ­»î¶¯ÏòÓû§ÔÊÔÊÐíÔÚ24СʱÄÚ»ñµÃ¸ß¶î»Ø±¨£¬ £¬£¬£¬£¬£¬µ«±ØÐèÏÈͶ×Ê600Ó¢°÷£¬ £¬£¬£¬£¬£¬µ±Êܺ¦ÕßתÕ˺ó£¬ £¬£¬£¬£¬£¬Ú²Æ­Õß»áÏòËûÃÇ·¢ËÍÒ»¸öÆÁÄ»½ØÍ¼£¬ £¬£¬£¬£¬£¬ÏÔʾÆäÕË»§ÒÑÊÕÈëÊýǧӢ°÷¡£ ¡£¡£µ«µ±Êܺ¦ÕßÒªÇóÌáÏÖʱ£¬ £¬£¬£¬£¬£¬Ú²Æ­Õ߾ͻá×èÖ¹ÁªÏµ¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/new-get-rich-quick-scheme-costs-instagram-users-over-3-million-61d5d384

4¡¢Chrome 0dayÎó²î£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýPDFÍøÂçÓû§ÐÅÏ¢

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


EdgeSpotÑо¿Ö°Ô±ÊӲ쵽ʹÓÃChromeÁãÈÕÎó²îÇÔÈ¡Óû§ÐÅÏ¢µÄ¶ñÒâPDFÎļþ¡£ ¡£¡£µ±Óû§Í¨¹ýChromeµÄPDFÉó²éÆ÷·­¿ª¸Ã¶ñÒâÎļþʱ£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÎó²îÍøÂçÓû§µÄÐÅÏ¢£¬ £¬£¬£¬£¬£¬²¢·¢ËÍÖÁÔ¶³ÌЧÀÍÆ÷¡£ ¡£¡£ÕâЩÐÅÏ¢°üÀ¨ÏµÍ³µÄÏêϸÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÀýÈçIPµØµã¡¢²Ù×÷ϵͳ°æ±¾ºÅ¡¢Chrome°æ±¾ºÅ¡¢PDFÎļþ·¾¶µÈ¡£ ¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ £¬£¬£¬£¬£¬¶ñÒâPDFÎļþÔÚAdobe ReaderÖв»»áÖ´ÐÐÈκζñÒâ»î¶¯¡£ ¡£¡£GoogleÈ·ÈÏÁËÕâÒ»Îó²î£¬ £¬£¬£¬£¬£¬²¢ÔÊÐí½«ÔÚ4ÔÂβ¾ÙÐÐÐÞ¸´¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/google-chrome-zero-day-vulnerability-could-allow-attackers-to-collect-user-information-via-pdf-files-01b8df3d

5¡¢CoinomiÇ®°üÃ÷ÎÄ´«ÊäÓû§ÃÜÂ룬 £¬£¬£¬£¬£¬µ¼ÖÂÔ¼7ÍòÃÀÔª±»ÇÔ

918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


¼ÓÃÜÇ®±ÒÇ®°üCoinomiÔÚÇ®°üÉèÖÃÀú³ÌÖлὫÓû§µÄÃ÷ÎÄÃÜÂëͨ¹ýHTTP·¢ËÍÖÁ¹È¸èµÄƴд¼ì²é³ÌÐò£¬ £¬£¬£¬£¬£¬µ¼ÖÂÓû§µÄÕË»§ºÍ×ʽðÒ×ÊÜÖÐÐÄÈË£¨MiTM£©¹¥»÷¡£ ¡£¡£¹¥»÷Õß¿ÉÒÔʹÓÃ×èµ²µ½µÄÃÜÂëµÇÈÎÃü»§µÄÕË»§²¢Çå¿ÕÆä×ʽð¡£ ¡£¡£Ò»¸öÓû§Al MaawaliÌåÏÖ£¬ £¬£¬£¬£¬£¬ÆäÕË»§ÖеÄ×ʽðÒò´ËËðʧÁË90%£¬ £¬£¬£¬£¬£¬¼ÛÖµÔ¼7ÍòÃÀÔª¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://cyware.com/news/cryptocurrency-wallet-coinomi-sends-users-passwords-to-googles-spellchecker-in-plain-text-3b3b794c

ÉùÃ÷£º±¾×ÊѶÓÉ918²©ÌìÌÃάËûÃüÇ徲С×é·­ÒëºÍÕûÀí