¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181224

Ðû²¼Ê±¼ä 2018-12-24
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬ £¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬ £¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬ £¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬ £¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢ÐÂÊÖÒÕÖ§³ÖÕ©Æ­Ò³Ãæ½«µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨



Google ChromeµÄbug±¨¸æÖÐÅû¶ÁËÒ»¸öеÄÊÖÒÕÖ§³ÖÕ©Æ­»î¶¯£¬£¬£¬ £¬£¬¸ÃÕ©Æ­ÍøÒ³½«Ê¹ÓÃJavaScriptÑ­»·ºÄ¾¡ÅÌËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¡£¡£¡£¡£¸ÃÍøÒ³µÄÎÊÌâΪ¡°Ö÷ÒªÐÅÏ¢¡±£¬£¬£¬ £¬£¬Î±×°³ÉÌáÐÑѬȾµÄWindows¹ýʧ¾¯±¨£¬£¬£¬ £¬£¬´ËÒ³Ãæ°üÀ¨µÄJavaScript½«Ê¹ä¯ÀÀÖØÊÓ¸´Ìø×ªÖÁ# URL£¬£¬£¬ £¬£¬²¢Íù·µµã»÷ÍËÈ´ºÍǰ½ø°´Å¥£¬£¬£¬ £¬£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýɱËÀChromeÀú³ÌÀ´¿¢Ê¿¨ËÀÇéÐΡ£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/


3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹ÂÚ¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ£¬£¬£¬ £¬£¬¸Ã×éÖ¯·¢Ã÷Á½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÇøµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹Âڻ¡£¡£¡£¡£¡£ÕâЩ´¹Âڻαװ³ÉÕË»§¾¯±¨£¬£¬£¬ £¬£¬Ö÷ÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤ÒªÁìµÄGmailºÍYahooÕÊ»§¡£¡£¡£¡£¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþЧÀÍ£¬£¬£¬ £¬£¬ÀýÈçProtonMailºÍTutanota£¬£¬£¬ £¬£¬Ö»¹ÜËüÃÇĬÈϽÓÄÉÁׯü¸ß¼¶±ðµÄÇå¾²ÐÔºÍÒþ˽ÐÔ¡£¡£¡£¡£¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»ÀÖ³ÉÈÆ¹ý£¬£¬£¬ £¬£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½Ë𺦡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/


4¡¢Õë¶ÔOrangeµ÷ÖÆ½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬£¬£¬ £¬£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Bad Packets LLCÑо¿Ö°Ô±Troy Mursch·¢Ã÷¹¥»÷ÕßÕýÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷ÖÆ½âµ÷Æ÷¡£¡£¡£¡£¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎå×îÏÈ£¬£¬£¬ £¬£¬¹¥»÷ÕßʹÓÃOrange LiveBox×°±¸ÖеÄÎó²î£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷ÖÆ½âµ÷Æ÷£¬£¬£¬ £¬£¬¾ø´ó´ó¶¼Î»ÓÚ·¨¹úºÍÎ÷°àÑÀ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/


5¡¢Ñо¿Ö°Ô±Åû¶Facebookµã»÷Ð®ÖÆÎó²î£¬£¬£¬ £¬£¬µ«Facebook²»ÍýÏëÐÞ¸´

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


²¨À¼Çå¾²Ñо¿Ö°Ô±·¢Ã÷FacebookµÄAndroidÒÆ¶¯°æ±¾±£´æÒ»¸öµã»÷Ð®ÖÆÎó²î£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýiframe±êǩʹÓøÃÎó²îÔÚÓû§µÄFacebookÉÏÐû²¼Á´½Ó¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÎó²îÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·ÓйØ£¬£¬£¬ £¬£¬¸Ã±êÍ·¿ÉÒÔ֪ͨä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«ÍøÒ³¼ÓÔØµ½ÓÕ¶üÍøÒ³µÄ¶¥²ãÖУ¨²»¿É¼ûµÄiFrame£©£¬£¬£¬ £¬£¬Óû§½«Íû¼ûÓÕ¶üÍøÒ³£¬£¬£¬ £¬£¬µ«ÏÖʵÉÏÓë¸ÃiFrame¾ÙÐн»»¥¡£¡£¡£¡£¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬ £¬£¬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÍêÕûÐÔ¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/


6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬£¬£¬ £¬£¬UberÔÙ±»·¨¹úÊý¾Ý± £»£»£»¤»ú¹¹·£¿£¿£¿î40ÍòÅ·Ôª

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2016ÄêUberÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬ £¬£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬ £¬£¬µ«Ö±µ½Ò»Äê¶àÒÔºóµÄ2017Äê11Ô¸ù«Ë¾²ÅÏòÍâ½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£2018Äê9Ô£¬£¬£¬ £¬£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£¡£¡£2018Äê11Ô£¬£¬£¬ £¬£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý± £»£»£»¤»ú¹¹»®·ÖÏòUber·£¿£¿£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿î¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬ £¬£¬·¨¹úµÄÊý¾Ý± £»£»£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿£¿£¿î40ÍòÅ·Ôª¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.html


ÉùÃ÷£º±¾×ÊѶÓɼøºÚµ£±£ÍøÎ¬ËûÃüÇ徲С×é·­ÒëºÍÕûÀí