Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ±»¹¥ÆÆ£» £»£»2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼

Ðû²¼Ê±¼ä 2019-11-08
1¡¢Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ¾ù±»¹¥ÆÆ

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

ÔÚPwn2Own Tokyo 2019ºÚ¿Í´óÈüµÄµÚÒ»Ì죬£¬£¬£¬£¬£¬£¬ÑÇÂíÑ·EchoÖÇÄÜÒôÏä¡¢ÈýÐǺÍË÷ÄáµÄÖÇÄܵçÊÓ¡¢Ð¡Ã×9ÊÖ»úÒÔ¼°NetgearºÍTP-Link·ÓÉÆ÷¾ù±»²ÎÈüÕß¹¥ÆÆ¡£¡£¡£¡£¡£±¾´Î´óÈüÊÇÓÉZero Day Initiative×éÖ¯µÄ£¬£¬£¬£¬£¬£¬£¬Ä¿µÄ×°±¸°üÀ¨17¿î£¬£¬£¬£¬£¬£¬£¬¹²ÔÊÐíÌṩÁè¼Ý75ÍòÃÀÔªµÄÏÖ½ðºÍ½±Æ·¡£¡£¡£¡£¡£ÕâÒ²ÊÇÊ×´ÎPwn2Own½«FacebookµÄPortalÖÇÄÜÏÔʾÆ÷ºÍOculus Quest VRÍ·¿øÁÐÈëÄ¿µÄ¡£¡£¡£¡£¡£ÔÚ´óÈüÊ×ÈÕ²ÎÈüÕßÒѾ­»ñµÃÁË19.5ÍòÃÀÔªµÄ½±Àø£¬£¬£¬£¬£¬£¬£¬ÊÕ»ñ×î¶àµÄÊÇFluoroacetateÍŶӣ¬£¬£¬£¬£¬£¬£¬¸ÃÍŶӻ®·Ö¹¥ÆÆÁËË÷ÄáX800GµçÊÓ¡¢ÑÇÂíÑ·Echo¡¢ÈýÐÇQ60µçÊÓ¡¢Ð¡Ã×9ºÍGalaxy S10¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-portal-survives-pwn2own-hacking-contest-amazon-echo-got-hacked/

2¡¢ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏ·ÖÏí7¸ö¶ñÒâÑù±¾


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏÐû²¼ÁË7¸öеĶñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬£¬£¬ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÃãÀøÓû§Éó²éÕâЩÑù±¾²¢»á¼ûCISAµÄ¶ñÒâ´úÂë·À»¤Êµ¼ù¡£¡£¡£¡£¡£ÓÐÑо¿Ö°Ô±ÔÚTwitterÉϻظ´³ÆÕâЩÑù±¾¿ÉÄÜÓëAPT28ÓйØ¡£¡£¡£¡£¡£¸Ã»ú¹¹ÉÏÒ»´Î¹²Ïí¶ñÒâÑù±¾ÊÇÔÚÁ½¸öÔÂǰ£¬£¬£¬£¬£¬£¬£¬ÆäÊ±ÍøÂç˾ÁÐû²¼ÁË11¸öÓ볯ÏÊAPT×éÖ¯LazarusÓйصÄÑù±¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2019/11/06/us-cyber-command-shares-seven-new-malware-samples

3¡¢Magento 1.x½«×èÖ¹¸üУ¬£¬£¬£¬£¬£¬£¬20¶àÍò¸öÍøÕ¾ÃæÁÙΣº¦

¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨

Magento 1.x·ÖÖ§½«ÔÚ2020Äê6ÔµִïÉúÃüÖÜÆÚ£¨EOL£©£¬£¬£¬£¬£¬£¬£¬½ìʱ»ùÓÚ¸ÃÆ½Ì¨µÄÔÚÏßÊÐËÁ½«ÎÞ·¨ÊÕµ½Çå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃǽ«ÃæÁÙÍøÕ¾±»ºÚ¿ÍÈëÇÖ»òѬȾ¶ñÒâ´úÂ루ÈçMagecart£©µÄΣº¦¡£¡£¡£¡£¡£¾Ýͳ¼ÆÏÖÔÚÊÜÓ°ÏìµÄÔÚÏßÊÐËÁÊýÄ¿ÔÚ20Íòµ½24ÍòÖ®¼ä£¬£¬£¬£¬£¬£¬£¬ÕâЩÊÐËÁÐèÒªÔÚδÀ´9¸öÔÂÄÚ¶ÔØÊºó¶Ëƽ̨¾ÙÐÐÉý¼¶£¬£¬£¬£¬£¬£¬£¬ºÃ±ÈǨáãµ½Magento 2.x·ÖÖ§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/between-200000-and-240000-magento-online-stores-will-reach-eol-next-year/

4¡¢¼ÓÀû¸£ÄáÑÇÖÝDMVй¶¼ÝʻԱÊý¾Ý³¤´ïËÄÄêʱ¼ä


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝÆû³µÖÎÀí²¿·Ö£¨DMV£©Ð¹Â¶ÊýǧÃû¼ÝʻԱµÄÊý¾Ý³¤´ï4ÄêµÄʱ¼ä¡£¡£¡£¡£¡£¹²ÓÐ3200Ãû¼ÝʻԱ±»Éæ¼°£¬£¬£¬£¬£¬£¬£¬ËûÃǵÄÐÅÏ¢±»Î¥¹æ·ÖÏí¸ø7¸ö»ú¹¹£¬£¬£¬£¬£¬£¬£¬°üÀ¨San DiegoºÍSanta ClaraÏØµÄµØÇøÉó²é¹Ù¡¢Ð¡ÐÍÆóÒµÖÎÀí¾Ö¡¢¹ú˰¾ÖµÈ²¿·Ö¡£¡£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨±¨µÀ¡·£¬£¬£¬£¬£¬£¬£¬ÕâЩ»ú¹¹¿ÉÔÚ·¸·¨»î¶¯ÊÓ²ì»ò˰·¨ÊÓ²ìÖÐÎ¥¹æ»á¼ûDMV̻¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬µ«Êý¾ÝûÓÐ̻¶¸øÐ¡ÎÒ˽¼Ò¡£¡£¡£¡£¡£ÔÚ8ÔÂ2ÈÕ·¢Ã÷Î¥¹æÐÐΪºó²»¾ÃDMV¼´ÏÞÖÆÁ˶ÔÊý¾ÝµÄ»á¼û¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/california-dmv-exposes-drivers/

5¡¢2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ƾ֤APWGµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬£¬2019ÄêÇï¼¾ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂʱ´ú¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýΪ266387£¬£¬£¬£¬£¬£¬£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465ÔöÌíÁË46%£¬£¬£¬£¬£¬£¬£¬ÏÕЩÊÇ2018ÄêµÚËÄÐò¶ÈµÄ138328µÄÁ½±¶¡£¡£¡£¡£¡£³ýÁË´¹ÂÚÍøÕ¾ÊýÄ¿µÄÔöÌíÖ®Í⣬£¬£¬£¬£¬£¬£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹ÂÚ¹¥»÷µÄÆ·ÅÆÊýĿҲÏÔ×ÅÔöÌí£¬£¬£¬£¬£¬£¬£¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬£¬£¬£¬£¬£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/

6¡¢ÑÇÂíÑ·°²·ÀÃÅÁåRing Video DoorbellÒ×ÔâMitm¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


BitdefenderÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÑÇÂíÑ·µÄRing Video Doorbell Pro×°±¸Öб£´æ¸ßΣÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÑéÖÐÐÄÈ˹¥»÷²¢ÇÔÈ¡Óû§µÄWi-FiÃÜÂë¡£¡£¡£¡£¡£Ring Video DoorbellÊÇÒ»¸ö´øÉãÏñÍ·µÄÖÇÄÜÎÞÏß°²·ÀÃÅÁ壬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸ÓëAPPµÄͨѶΪ²»Çå¾²µÄHTTP´«Ê䣬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕÆ­Óû§ÖØÐÂÉèÖøÃ×°±¸²¢Ðá̽ÆäÃÜÂ룬£¬£¬£¬£¬£¬£¬½ø¶ø¿ÉÒÔÌᳫÖÖÖÖ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬°üÀ¨Óë¼ÒÍ¥ÍøÂçÖеÄ×°±¸½»»¥¡¢»á¼ûÍâµØNAS¡¢ÈëÇÖÆäËü×°±¸µÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ9ÔÂ5ÈÕÐû²¼ÁËÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html