¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180612

Ðû²¼Ê±¼ä 2018-06-12
¡¾ÆÊÎö±¨¸æ¡¿Ñо¿ÍŶÓÐû²¼5Gʱ´úIoT×°±¸¼°ÎÀÐǵÄÇ徲Σº¦±¨¸æ


Ëæ×Å5G·äÎÑÍøÂçÊÖÒÕºÍIoTµÄÒ»Ö±À©Õ¹£¬£¬ £¬£¬£¬ £¬£¬ÎÀÐÇÒѾ­³ÉΪÎïÁªÍøºÍ»¥ÁªÍøÒªº¦»ù´¡ÉèÊ©µÄÖ÷Òª×é³É²¿·Ö£¬£¬ £¬£¬£¬ £¬£¬È·ÊØÎÀÐǵÄÇå¾²¾ßÓÐÖ÷ÒªµÄÒâÒå¡£¡£¡£¡£ ¡£¡£¡£Õë¶ÔÎÀÐǵĹ¥»÷ÏòÁ¿¿ÉÒÔÊÇÌì¿ÕºÍµØÃæÖ®¼ä£¬£¬ £¬£¬£¬ £¬£¬Ò²¿ÉÒÔÊǵØÃæÖÁÎÀÐÇÔÙÈö²¥ÖÁÆäËüÎÀÐÇ£¬£¬ £¬£¬£¬ £¬£¬»òÕßÎÀÐÇÖÁµØÃæÔÙÈö²¥ÖÁÆäËüµØ·½¡£¡£¡£¡£ ¡£¡£¡£³£¼ûµÄ¹¥»÷ÀàÐͰüÀ¨µçÐÅڲƭ¡¢¿çÎÀÐǹ¥»÷¡¢ÀÄÓÃÎÀÐǵ绰µÈ£¬£¬ £¬£¬£¬ £¬£¬¹¥»÷³¡¾°°üÀ¨ÐéαµØÇò»ùÕ¾¡¢Î±×°³ÉÎÀÐǵÄͨѶ¡¢Ê¹ÓÃÎÀÐÇÍøÂç¼äµÄÐÅÈεȡ£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/attack-vectors-in-orbit-need-for-satellite-security-in-5g-iot/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý1.5Íò¸öAndroid×°±¸µÄADBµ÷ÊÔ¶Ë¿Ú̻¶


Ñо¿Ö°Ô±Kevin Beaumont³ÆÁè¼Ý1.5Íò¸öAndroid×°±¸µÄADB¶Ë¿Ú̻¶£¬£¬ £¬£¬£¬ £¬£¬ADB£¨Android Debug Bridge£©ÊÇAndroidϵͳµÄÒ»¸ö¹ÊÕÏɨ³ý¹¤¾ß£¬£¬ £¬£¬£¬ £¬£¬Ëü»¹¿ÉÒÔÊÚȨÓû§»á¼ûһЩÃô¸Ð¹¤¾ß£¨°üÀ¨Unix shell£©¡£¡£¡£¡£ ¡£¡£¡£ÎÊÌâÔÚÓÚһЩ¹©Ó¦É̽«ÆôÓÃÁËADB over WiFi¹¦Ð§µÄ×°±¸½»¸¶¸øÓû§Ê¹Ó㬣¬ £¬£¬£¬ £¬£¬ÕâʹµÃÔÚÓû§²»ÖªÇéµÄÇéÐÎÏ£¬£¬ £¬£¬£¬ £¬£¬Æä×°±¸¿Éͨ¹ýTCP¶Ë¿Ú5555Ô¶³Ì»á¼û£¬£¬ £¬£¬£¬ £¬£¬²¿·Ö×°±¸Òò´ËѬȾÃÅÂÞ±Ò¿ó¹¤ADB.Miner¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/tens-of-thousands-of-android-devices-are-exposing-their-debug-port/


¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӳƹ¥»÷Õß´Ó²»Çå¾²µÄÒÔÌ«·»½ÚµãÖÐÇÔÈ¡Áè¼Ý2000ÍòÃÀÔª


Çå¾²Ñо¿Ö°Ô±ÖÒÑÔ³ÆÒ»¸öÍøÂç·¸·¨×é֯ͨ¹ýÐ®ÖÆÍøÉÏ̻¶µÄ²»Çå¾²ÉèÖõÄÒÔÌ«·»½Úµã£¬£¬ £¬£¬£¬ £¬£¬ÔÚÒÑÍù¼¸¸öÔÂÄÚÇÔÈ¡ÁË38642¸öÒÔÌ«±Ò£¬£¬ £¬£¬£¬ £¬£¬¼ÛÖµÁè¼Ý2000ÍòÃÀÔª¡£¡£¡£¡£ ¡£¡£¡£Ò»Ð©ÒÔÌ«·»½ÚµãʹÓÃGeth¿Í»§¶Ë£¬£¬ £¬£¬£¬ £¬£¬²¢ÇÒ¿ª·ÅÁËJSON-RPC¶Ë¿Ú8545¡£¡£¡£¡£ ¡£¡£¡£Í¨¹ýJSON-RPCÓû§¿ÉÒÔÔ¶³Ì»á¼ûÒÔÌ«·»Çø¿éÁ´ºÍ½ÚµãµÄ¹¦Ð§£¬£¬ £¬£¬£¬ £¬£¬°üÀ¨´ÓÒѽâËøÕË»§·¢ËÍÉúÒâ¡£¡£¡£¡£ ¡£¡£¡£¹¥»÷Õßͨ¹ýɨÃ軥ÁªÍøÉÏ¿ª·ÅµÄ8545¶Ë¿ÚÇÔÈ¡Óû§µÄ×ʽ𡣡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/ethereum-geth-hacking.html


¡¾¹¥»÷ÊÂÎñ¡¿º«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿ÍÈëÇÖ£¬£¬ £¬£¬£¬ £¬£¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª


ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÉúÒâËùCoinrailÔâºÚ¿Í¹¥»÷£¬£¬ £¬£¬£¬ £¬£¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿·ÖICO´ú±Ò£¬£¬ £¬£¬£¬ £¬£¬ÉúÒâËùûÓÐÅû¶Ïà¹Ø±»µÁ×ʽðµÄÏêϸÊý×Ö£¬£¬ £¬£¬£¬ £¬£¬µ«ÓÐÓû§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØµã£¬£¬ £¬£¬£¬ £¬£¬ÒÔΪÏà¹Ø±»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä£¬£¬ £¬£¬£¬ £¬£¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£¡£¡£¡£ ¡£¡£¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ÏàÖúÒÔ¶³½á±»µÁµÄ´ú±Ò¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷Ò»¼Ó6ÊÖ»ú±£´æÇå¾²Îó²î£¬£¬ £¬£¬£¬ £¬£¬¿ÉÔÊÐí¹¥»÷Õß½ÓÊÜ×°±¸


Edge SecurityÇå¾²Ñо¿Ö°Ô±Jason Donenfeld·¢Ã÷Ò»¼Ó6ÊÖ»úÉϵÄbootloader²¢Î´ÍêÈ«Ëø¶¨£¬£¬ £¬£¬£¬ £¬£¬¿ÉÔÊÐí¹¥»÷ÕßдÈë¶ñÒâ¾µÏñºÍÍêÈ«½ÓÊÜ×°±¸¡£¡£¡£¡£ ¡£¡£¡£¸ÃÎó²îµÄʹÓÃÐèÒª¶Ô×°±¸µÄÎïÆÊÎö¼û¡£¡£¡£¡£ ¡£¡£¡£ÔÚÑÝʾÊÓÆµÖУ¬£¬ £¬£¬£¬ £¬£¬Ñо¿Ö°Ô±Ö»ÆÆ·ÑÁ˼¸·ÖÖӾͽ«¶ñÒâ¾µÏñͨ¹ýADBµÄ¿ìËÙÖ¸µ¼ÏÂÁîдÈë×°±¸¡£¡£¡£¡£ ¡£¡£¡£Ò»¼ÓÒѾ­È·ÈÏÁ˸ÃÎÊÌ⣬£¬ £¬£¬£¬ £¬£¬²¢ÔÊÐí½«Ðû²¼Ïà¹ØÈí¼þ¸üС£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/oneplus6-bootloader-root.html


¡¾Çå¾²Îó²î¡¿Ñо¿Ö°Ô±·¢Ã÷ABBÃŽûϵͳ±£´æ¶à¸öÇå¾²Îó²î


ERNWÑо¿Ö°Ô±Maxim RuppºÍFlorian GrunowÔÚÈðÊ¿ABB¹«Ë¾µÄÃŽûÖÎÀíϵͳÖз¢Ã÷¶à¸öÇå¾²Îó²î£¬£¬ £¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄ×é¼þÊǹ̼þ°æ±¾3.39¼°Ö®Ç°µÄABB IPÍø¹Ø¡£¡£¡£¡£ ¡£¡£¡£Îó²î¹æÄ£°üÀ¨ÈÏÖ¤ÈÆ¹ýÎó²î£¨CVE-2017-7931£©¡¢Ã÷ÎÄÃÜÂëй¶Îó²î£¨CVE-2017-7933£©¡¢¿çÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î£¨CVE-2017-7906£©ºÍÒ»¸öÔ¶³Ì´úÂë×¢ÈëÎó²î¡£¡£¡£¡£ ¡£¡£¡£ABBÔڹ̼þ°æ±¾3.40ÖÐÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£¡£ ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-flaws-expose-abb-door-communication-systems-attacks