TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª;µÂ¹úCanyon BicyclesÔâºÚ¿ÍÈëÇÖ
Ðû²¼Ê±¼ä 2020-01-08
1.Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾SQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¿É¸Ä¶¯Ö´·¨Îļþ
Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾ÖеÄÒ»¸öSQL×¢ÈëÎó²î¿ÉÄܵ¼Ö¹¥»÷Õ߸͝¸ÃµØÖ´·¨ÎļþµÄÕýÊ½ÍøÂç°æ±¾¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Ax SharmaÔÚÑо¿Ö±²¼ÂÞÍÓÁìÍÁºÍº£°¶¾¯ÎÀ¶ÓÍøÕ¾µÄǩ֤»®×¼Ê±·¢Ã÷ÁËÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉʹÓÃÕþ¸®ÍøÕ¾ÉÏ̻¶µÄÐÅÏ¢¸Ä¶¯Ö±²¼ÂÞÍÓÖ´·¨µÄ¹Ù·½ÔÚÏß´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬°üÀ¨É¾³ý»òÉÏ´«PDFÎļþ¡£¡£¡£¡£¡£¡£Ê¹ÓÿªÔ´¹¤¾ßsqlmap£¬£¬£¬£¬£¬£¬£¬SharmaÄܹ»Éó²éΪִ·¨ÎļþÍйÜÕ¾µãÌṩ֧³ÖµÄËùÓбíºÍÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÃûΪgiblaws_giblaws.userµÄ±í°üÀ¨ÁËÊÂÇéÖ°Ô±µÄÐÕÃû¡¢Óû§ÃûºÍÃÜÂëÕªÒªµÈ¡£¡£¡£¡£¡£¡£SharmaʹÓÃsqlmapµÄÄÚÖÃͻ񻮮½â¹¤¾ß²»µ½1Ãë¾ÍÆÆ½âÁËÆäÖÐÒ»¸öÃÜÂ룬£¬£¬£¬£¬£¬£¬ÕâʹµÃÆä¿ÉÒԵǼ²¢Ê¹ÓøÃÕË»§µÄȨÏÞÀ´±à¼ÍøÕ¾ÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£¡£Ö±²¼ÂÞÍÓÕþ¸®½²»°ÈËÈ·ÈÏÁËÕâÒ»Îó²î£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÒѽ«ÊÜÓ°ÏìµÄÍøÒ³ÀëÏß¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/gibraltar_sql_vuln_allowed_law_editing/
2.µÂ¹úCanyon Bicycles ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ð§ÀÍÆ÷ºÍÈí¼þ±»¼ÓÃÜ
µÂ¹ú×ÔÐгµÖÆÔìÉÌCanyon Bicycles GmbGÈ·ÈÏÔÚÐÂÄê¼ÙÆÚʱ´úÔâÓöÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©±»·¸·¨·Ö×ÓËø¶¨¡£¡£¡£¡£¡£¡£¸Ã³§ÉÌÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÐÂÄê֮ǰ¾ÍÈëÇÖÁËÆäITϵͳ£¬£¬£¬£¬£¬£¬£¬ÆäÈí¼þºÍЧÀÍÆ÷±»¼ÓÃܺÍËø¶¨¡£¡£¡£¡£¡£¡£Ëü»¹ÌåÏÖÍøÕ¾²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§¿ÉÒÔÕý³£Ï´ïÔÚÏß¶©µ¥£¬£¬£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾Ä¿½ñÒѾȷ¶¨²¢×èÖ¹Á˹¥»÷¡£¡£¡£¡£¡£¡£CanyonÊ×´´È˼æÊ×ϯִÐйÙRoman ArnoldÌåÏÖ£º¡°´Ë´Î¹¥»÷ÏÔʾ³ö´ó¹æÄ£µÄ·¸·¨Òâͼ¡£¡£¡£¡£¡£¡£ÓÉÓÚIT»ù´¡¼Ü¹¹±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊÂÇéºÍÓªÒµÁ÷³ÌÔÝʱÊܵ½ÁËÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£¡±Î÷µÂ¿Æ²¼Â×´Ä×ܲ¿ºÍÏÕЩËùÓйú¼ÊÓªÒµ¶¼Êܵ½Ö±½ÓÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«ÃÀ¹ú×Ó¹«Ë¾²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£Arnold²¢Î´Ìá¼°ÏêϸµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°·¸·¨·Ö×ÓÊÇ·ñÒªÇóÁËÊê½ð¡¢Êê½ð½ð¶î»òÊÇÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/hackers_canyon_bicycles/
3.ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraÔâµ½MageCart¹¥»÷
ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraµÄÍøÕ¾ÓÚÈ¥ÄêÄêµ×Ôâµ½MageCart¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£ÎªÁËÒþ²Ø¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁË¡°zdsassets.com¡±ÓòÃû£¬£¬£¬£¬£¬£¬£¬¸ÃÓòÃûÄ£ÄâÁËZenDeskµÄÕýµ±ÓòÃû¡°zdassets.com¡±¡£¡£¡£¡£¡£¡£Juniper NetworksÇå¾²Ñо¿Ô±Mounir HahadÔÚ12ÔÂÏÂÑ®·¢Ã÷Á˶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþ¡¢¿Í»§ÐÕÃû¡¢µØµã£¨Õ˵¥ºÍÔËÊ䣩¡¢µç»°ºÅÂë¼°Ö§¸¶¿¨ÏêϸÐÅÏ¢£¨ºÅÂë¡¢ÓÐÓÃÆÚ¡¢CVVÂ룩¡£¡£¡£¡£¡£¡£Æ¾Ö¤DNSÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¸ÃC&CÓòÃûÒѱ»ÆÊÎö905´Î£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÅú×¢ÎúÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magecart-attackers-steal-card-info-from-focus-camera-shoppers/
4.TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª
×ÔÍâ»ã¹«Ë¾TravelexÔâµ½ÍøÂç¹¥»÷ÒѾÒÑÍùÁËÁùÌìµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬BleepingComputerÄܹ»È·Èϸù«Ë¾Ñ¬È¾µÄ¶ñÒâÈí¼þΪÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚ12ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½ÓÄÉÁËÔ¤·À²½·¥½«ËùÓеÄÅÌËã»úϵͳÍÑ»ú£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¿Í»§ÎÞ·¨ÔÙʹÓÃÍøÂç»òAPP¾ÙÐÐÉúÒâ»òÔÚÈ«ÇòÁè¼Ý1500¼ÒµêËÁÖÐʹÓÃÐÅÓÿ¨£¨½è¼Ç¿¨£©¸¶¿î¡£¡£¡£¡£¡£¡£TravelexÉÐδÌṩÓйػָ´Ð§Àͽø¶ÈµÄ×îÐÂÐÅÏ¢¡£¡£¡£¡£¡£¡£BleepingComputerÊÕµ½ÐÂÎųÆTravelexȷʵÊܵ½SodinokibiµÄѬȾ£¬£¬£¬£¬£¬£¬£¬ÆäÀ©Õ¹ÃûÀàËÆÓÚ.u3i7y74¡£¡£¡£¡£¡£¡£Sodinokibi¹¥»÷Õß»¹³Æ¶ÔÕû¸öTravelexÍøÂç¾ÙÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬²¢¸´ÖÆÁËÁè¼Ý5GBµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßË÷ÒªµÄÊê½ðΪ300ÍòÃÀÔª¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-hits-travelex-demands-3-million/
5.3¸ö¶ñÒâAPPʹÓÃCVE-2019-2215£¬£¬£¬£¬£¬£¬£¬»òÓëSideWinder APTÓйØ
Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁÖз¢Ã÷3¸ö¶ñÒâAPP£¬£¬£¬£¬£¬£¬£¬ËüÃÇ¿ÉÒÔÐͬÊÂÇ鯯ËðÊܺ¦ÕßµÄ×°±¸²¢ÍøÂçÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£ÆäÖÐÃûΪCameroµÄAPPʹÓÃÁËBinder£¨AndroidÖÐÖ÷ÒªµÄÀú³Ì¼äͨѶϵͳ£©ÖеÄuse-after-freeÎó²î£¨CVE-2019-2215£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒÑÖªµÄÊ׸öʹÓøÃÎó²îµÄÒ°Íâ¹¥»÷¡£¡£¡£¡£¡£¡£ÔÚ½øÒ»³ÌÐò²éÖУ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÕâÈý¸ö¶ñÒâAPP¿ÉÄÜÓë·¸·¨ÍÅ»ïSideWinder APTÓйء£¡£¡£¡£¡£¡£SideWinder×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬¾Ý±¨µÀËüÖ÷ÒªÃé×¼¾üÊ»ú¹¹µÄWindowsÅÌËã»ú¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲâÕâÈý¸ö¶ñÒâAPP×Ô2019Äê3ÔÂÒÔÀ´Ò»Ö±´¦Óڻ״̬£¬£¬£¬£¬£¬£¬£¬Ä¿½ñËüÃÇÒѱ»Google Playϼܡ£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/
6.¹È¸èÐû²¼2020Äê1ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î
2020Äê1ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö£º2020-01-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËFramework¡¢Media¿ò¼ÜºÍϵͳ×é¼þÖеÄ7¸öÎó²î£»£»£»£»£»£»2020-01-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËÄںˡ¢¸ßͨ×é¼þºÍ¸ßͨ±ÕÔ´×é¼þÖеÄ33¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£±»±êΪcritical£¨ÑÏÖØ£©¼¶±ðµÄÎó²îΪMedia¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0002£©£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚAndroid 8.0¡¢8.1 ºÍ9°æ±¾Öб»ÒÔΪÊÇÑÏÖØ¼¶±ð£¬£¬£¬£¬£¬£¬£¬µ«ÔÚAndroid 10ÖÐΪÖÐΣ¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑÏÖØÎó²îÊÇRealtek rtlwifiÇý¶¯³ÌÐòÖеÄRCEÎó²î£¨CVE-2019-17666£©¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/androids-january-2020-update-patches-40-vulnerabilities