TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª;µÂ¹úCanyon BicyclesÔâºÚ¿ÍÈëÇÖ
Ðû²¼Ê±¼ä 2020-01-08
1.Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾SQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¿É¸Ä¶¯Ö´·¨Îļþ
Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾ÖеÄÒ»¸öSQL×¢ÈëÎó²î¿ÉÄܵ¼Ö¹¥»÷Õ߸͝¸ÃµØÖ´·¨ÎļþµÄÕýÊ½ÍøÂç°æ±¾¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Ax SharmaÔÚÑо¿Ö±²¼ÂÞÍÓÁìÍÁºÍº£°¶¾¯ÎÀ¶ÓÍøÕ¾µÄǩ֤»®×¼Ê±·¢Ã÷ÁËÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉʹÓÃÕþ¸®ÍøÕ¾ÉÏ̻¶µÄÐÅÏ¢¸Ä¶¯Ö±²¼ÂÞÍÓÖ´·¨µÄ¹Ù·½ÔÚÏß´æ´¢¿â£¬£¬£¬£¬£¬£¬°üÀ¨É¾³ý»òÉÏ´«PDFÎļþ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÿªÔ´¹¤¾ßsqlmap£¬£¬£¬£¬£¬£¬SharmaÄܹ»Éó²éΪִ·¨ÎļþÍйÜÕ¾µãÌṩ֧³ÖµÄËùÓбíºÍÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÃûΪgiblaws_giblaws.userµÄ±í°üÀ¨ÁËÊÂÇéÖ°Ô±µÄÐÕÃû¡¢Óû§ÃûºÍÃÜÂëÕªÒªµÈ¡£¡£¡£¡£¡£¡£¡£SharmaʹÓÃsqlmapµÄÄÚÖÃͻ񻮮½â¹¤¾ß²»µ½1Ãë¾ÍÆÆ½âÁËÆäÖÐÒ»¸öÃÜÂ룬£¬£¬£¬£¬£¬ÕâʹµÃÆä¿ÉÒԵǼ²¢Ê¹ÓøÃÕË»§µÄȨÏÞÀ´±à¼ÍøÕ¾ÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£Ö±²¼ÂÞÍÓÕþ¸®½²»°ÈËÈ·ÈÏÁËÕâÒ»Îó²î£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÒѽ«ÊÜÓ°ÏìµÄÍøÒ³ÀëÏß¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/gibraltar_sql_vuln_allowed_law_editing/
2.µÂ¹úCanyon Bicycles ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬Ð§ÀÍÆ÷ºÍÈí¼þ±»¼ÓÃÜ
µÂ¹ú×ÔÐгµÖÆÔìÉÌCanyon Bicycles GmbGÈ·ÈÏÔÚÐÂÄê¼ÙÆÚʱ´úÔâÓöÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©±»·¸·¨·Ö×ÓËø¶¨¡£¡£¡£¡£¡£¡£¡£¸Ã³§ÉÌÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÐÂÄê֮ǰ¾ÍÈëÇÖÁËÆäITϵͳ£¬£¬£¬£¬£¬£¬ÆäÈí¼þºÍЧÀÍÆ÷±»¼ÓÃܺÍËø¶¨¡£¡£¡£¡£¡£¡£¡£Ëü»¹ÌåÏÖÍøÕ¾²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§¿ÉÒÔÕý³£Ï´ïÔÚÏß¶©µ¥£¬£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾Ä¿½ñÒѾȷ¶¨²¢×èÖ¹Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£CanyonÊ×´´È˼æÊ×ϯִÐйÙRoman ArnoldÌåÏÖ£º¡°´Ë´Î¹¥»÷ÏÔʾ³ö´ó¹æÄ£µÄ·¸·¨Òâͼ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚIT»ù´¡¼Ü¹¹±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬µ¼ÖÂÊÂÇéºÍÓªÒµÁ÷³ÌÔÝʱÊܵ½ÁËÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡±Î÷µÂ¿Æ²¼Â×´Ä×ܲ¿ºÍÏÕЩËùÓйú¼ÊÓªÒµ¶¼Êܵ½Ö±½ÓÓ°Ï죬£¬£¬£¬£¬£¬µ«ÃÀ¹ú×Ó¹«Ë¾²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Arnold²¢Î´Ìá¼°ÏêϸµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬ÒÔ¼°·¸·¨·Ö×ÓÊÇ·ñÒªÇóÁËÊê½ð¡¢Êê½ð½ð¶î»òÊÇÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/hackers_canyon_bicycles/
3.ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraÔâµ½MageCart¹¥»÷
ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraµÄÍøÕ¾ÓÚÈ¥ÄêÄêµ×Ôâµ½MageCart¹¥»÷£¬£¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÒþ²Ø¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁË¡°zdsassets.com¡±ÓòÃû£¬£¬£¬£¬£¬£¬¸ÃÓòÃûÄ£ÄâÁËZenDeskµÄÕýµ±ÓòÃû¡°zdassets.com¡±¡£¡£¡£¡£¡£¡£¡£Juniper NetworksÇå¾²Ñо¿Ô±Mounir HahadÔÚ12ÔÂÏÂÑ®·¢Ã÷Á˶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþ¡¢¿Í»§ÐÕÃû¡¢µØµã£¨Õ˵¥ºÍÔËÊ䣩¡¢µç»°ºÅÂë¼°Ö§¸¶¿¨ÏêϸÐÅÏ¢£¨ºÅÂë¡¢ÓÐÓÃÆÚ¡¢CVVÂ룩¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤DNSÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬¸ÃC&CÓòÃûÒѱ»ÆÊÎö905´Î£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÅú×¢ÎúÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magecart-attackers-steal-card-info-from-focus-camera-shoppers/
4.TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª
×ÔÍâ»ã¹«Ë¾TravelexÔâµ½ÍøÂç¹¥»÷ÒѾÒÑÍùÁËÁùÌìµÄʱ¼ä£¬£¬£¬£¬£¬£¬BleepingComputerÄܹ»È·Èϸù«Ë¾Ñ¬È¾µÄ¶ñÒâÈí¼þΪÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚ12ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½ÓÄÉÁËÔ¤·À²½·¥½«ËùÓеÄÅÌËã»úϵͳÍÑ»ú£¬£¬£¬£¬£¬£¬Ê¹µÃ¿Í»§ÎÞ·¨ÔÙʹÓÃÍøÂç»òAPP¾ÙÐÐÉúÒâ»òÔÚÈ«ÇòÁè¼Ý1500¼ÒµêËÁÖÐʹÓÃÐÅÓÿ¨£¨½è¼Ç¿¨£©¸¶¿î¡£¡£¡£¡£¡£¡£¡£TravelexÉÐδÌṩÓйػָ´Ð§Àͽø¶ÈµÄ×îÐÂÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£BleepingComputerÊÕµ½ÐÂÎųÆTravelexȷʵÊܵ½SodinokibiµÄѬȾ£¬£¬£¬£¬£¬£¬ÆäÀ©Õ¹ÃûÀàËÆÓÚ.u3i7y74¡£¡£¡£¡£¡£¡£¡£Sodinokibi¹¥»÷Õß»¹³Æ¶ÔÕû¸öTravelexÍøÂç¾ÙÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬²¢¸´ÖÆÁËÁè¼Ý5GBµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßË÷ÒªµÄÊê½ðΪ300ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-hits-travelex-demands-3-million/
5.3¸ö¶ñÒâAPPʹÓÃCVE-2019-2215£¬£¬£¬£¬£¬£¬»òÓëSideWinder APTÓйØ
Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁÖз¢Ã÷3¸ö¶ñÒâAPP£¬£¬£¬£¬£¬£¬ËüÃÇ¿ÉÒÔÐͬÊÂÇ鯯ËðÊܺ¦ÕßµÄ×°±¸²¢ÍøÂçÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÃûΪCameroµÄAPPʹÓÃÁËBinder£¨AndroidÖÐÖ÷ÒªµÄÀú³Ì¼äͨѶϵͳ£©ÖеÄuse-after-freeÎó²î£¨CVE-2019-2215£©£¬£¬£¬£¬£¬£¬ÕâÊÇÒÑÖªµÄÊ׸öʹÓøÃÎó²îµÄÒ°Íâ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚ½øÒ»³ÌÐò²éÖУ¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÕâÈý¸ö¶ñÒâAPP¿ÉÄÜÓë·¸·¨ÍÅ»ïSideWinder APTÓйء£¡£¡£¡£¡£¡£¡£SideWinder×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬¾Ý±¨µÀËüÖ÷ÒªÃé×¼¾üÊ»ú¹¹µÄWindowsÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲâÕâÈý¸ö¶ñÒâAPP×Ô2019Äê3ÔÂÒÔÀ´Ò»Ö±´¦Óڻ״̬£¬£¬£¬£¬£¬£¬Ä¿½ñËüÃÇÒѱ»Google Playϼܡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/
6.¹È¸èÐû²¼2020Äê1ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î
2020Äê1ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö£º2020-01-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËFramework¡¢Media¿ò¼ÜºÍϵͳ×é¼þÖеÄ7¸öÎó²î£»£»£»2020-01-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËÄںˡ¢¸ßͨ×é¼þºÍ¸ßͨ±ÕÔ´×é¼þÖеÄ33¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£±»±êΪcritical£¨ÑÏÖØ£©¼¶±ðµÄÎó²îΪMedia¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0002£©£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚAndroid 8.0¡¢8.1 ºÍ9°æ±¾Öб»ÒÔΪÊÇÑÏÖØ¼¶±ð£¬£¬£¬£¬£¬£¬µ«ÔÚAndroid 10ÖÐΪÖÐΣ¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑÏÖØÎó²îÊÇRealtek rtlwifiÇý¶¯³ÌÐòÖеÄRCEÎó²î£¨CVE-2019-17666£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/androids-january-2020-update-patches-40-vulnerabilities


¾©¹«Íø°²±¸11010802024551ºÅ