TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬ £¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª;µÂ¹úCanyon BicyclesÔâºÚ¿ÍÈëÇÖ

Ðû²¼Ê±¼ä 2020-01-08


1.Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾SQL×¢ÈëÎó²î£¬ £¬£¬£¬£¬£¬¿É¸Ä¶¯Ö´·¨Îļþ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾ÖеÄÒ»¸öSQL×¢ÈëÎó²î¿ÉÄܵ¼Ö¹¥»÷Õ߸͝¸ÃµØÖ´·¨ÎļþµÄÕýÊ½ÍøÂç°æ±¾¡£¡£¡£¡£¡£¡£¡£Çå¾²Ñо¿Ô±Ax SharmaÔÚÑо¿Ö±²¼ÂÞÍÓÁìÍÁºÍº£°¶¾¯ÎÀ¶ÓÍøÕ¾µÄǩ֤»®×¼Ê±·¢Ã÷ÁËÕâ¸öÎó²î£¬ £¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉʹÓÃÕþ¸®ÍøÕ¾ÉÏ̻¶µÄÐÅÏ¢¸Ä¶¯Ö±²¼ÂÞÍÓÖ´·¨µÄ¹Ù·½ÔÚÏß´æ´¢¿â£¬ £¬£¬£¬£¬£¬°üÀ¨É¾³ý»òÉÏ´«PDFÎļþ¡£¡£¡£¡£¡£¡£¡£Ê¹ÓÿªÔ´¹¤¾ßsqlmap£¬ £¬£¬£¬£¬£¬SharmaÄܹ»Éó²éΪִ·¨ÎļþÍйÜÕ¾µãÌṩ֧³ÖµÄËùÓбíºÍÊý¾Ý¿âÐÅÏ¢£¬ £¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÃûΪgiblaws_giblaws.userµÄ±í°üÀ¨ÁËÊÂÇéÖ°Ô±µÄÐÕÃû¡¢Óû§ÃûºÍÃÜÂëÕªÒªµÈ¡£¡£¡£¡£¡£¡£¡£SharmaʹÓÃsqlmapµÄÄÚÖÃͻ񻮮½â¹¤¾ß²»µ½1Ãë¾ÍÆÆ½âÁËÆäÖÐÒ»¸öÃÜÂ룬 £¬£¬£¬£¬£¬ÕâʹµÃÆä¿ÉÒԵǼ²¢Ê¹ÓøÃÕË»§µÄȨÏÞÀ´±à¼­ÍøÕ¾ÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£Ö±²¼ÂÞÍÓÕþ¸®½²»°ÈËÈ·ÈÏÁËÕâÒ»Îó²î£¬ £¬£¬£¬£¬£¬²¢ÌåÏÖÒѽ«ÊÜÓ°ÏìµÄÍøÒ³ÀëÏß¡£¡£¡£¡£¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/01/07/gibraltar_sql_vuln_allowed_law_editing/


2.µÂ¹úCanyon Bicycles ÔâºÚ¿ÍÈëÇÖ£¬ £¬£¬£¬£¬£¬Ð§ÀÍÆ÷ºÍÈí¼þ±»¼ÓÃÜ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¹ú×ÔÐгµÖÆÔìÉÌCanyon Bicycles GmbGÈ·ÈÏÔÚÐÂÄê¼ÙÆÚʱ´úÔâÓöÇå¾²ÊÂÎñ£¬ £¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©±»·¸·¨·Ö×ÓËø¶¨¡£¡£¡£¡£¡£¡£¡£¸Ã³§ÉÌÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÐÂÄê֮ǰ¾ÍÈëÇÖÁËÆäITϵͳ£¬ £¬£¬£¬£¬£¬ÆäÈí¼þºÍЧÀÍÆ÷±»¼ÓÃܺÍËø¶¨¡£¡£¡£¡£¡£¡£¡£Ëü»¹ÌåÏÖÍøÕ¾²»ÊÜÓ°Ï죬 £¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§¿ÉÒÔÕý³£Ï´ïÔÚÏß¶©µ¥£¬ £¬£¬£¬£¬£¬²¢ÇҸù«Ë¾Ä¿½ñÒѾ­È·¶¨²¢×èÖ¹Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£CanyonÊ×´´È˼æÊ×ϯִÐйÙRoman ArnoldÌåÏÖ£º¡°´Ë´Î¹¥»÷ÏÔʾ³ö´ó¹æÄ£µÄ·¸·¨Òâͼ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚIT»ù´¡¼Ü¹¹±»¼ÓÃÜ£¬ £¬£¬£¬£¬£¬µ¼ÖÂÊÂÇéºÍÓªÒµÁ÷³ÌÔÝʱÊܵ½ÁËÖØ´óÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡±Î÷µÂ¿Æ²¼Â×´Ä×ܲ¿ºÍÏÕЩËùÓйú¼ÊÓªÒµ¶¼Êܵ½Ö±½ÓÓ°Ï죬 £¬£¬£¬£¬£¬µ«ÃÀ¹ú×Ó¹«Ë¾²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£Arnold²¢Î´Ìá¼°ÏêϸµÄÀÕË÷Èí¼þ£¬ £¬£¬£¬£¬£¬ÒÔ¼°·¸·¨·Ö×ÓÊÇ·ñÒªÇóÁËÊê½ð¡¢Êê½ð½ð¶î»òÊÇÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/01/07/hackers_canyon_bicycles/


3.ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraÔâµ½MageCart¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraµÄÍøÕ¾ÓÚÈ¥ÄêÄêµ×Ôâµ½MageCart¹¥»÷£¬ £¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÒþ²Ø¶ñÒâÁ÷Á¿£¬ £¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁË¡°zdsassets.com¡±ÓòÃû£¬ £¬£¬£¬£¬£¬¸ÃÓòÃûÄ£ÄâÁËZenDeskµÄÕýµ±ÓòÃû¡°zdassets.com¡±¡£¡£¡£¡£¡£¡£¡£Juniper NetworksÇå¾²Ñо¿Ô±Mounir HahadÔÚ12ÔÂÏÂÑ®·¢Ã÷Á˶ñÒâ¾ç±¾£¬ £¬£¬£¬£¬£¬¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþ¡¢¿Í»§ÐÕÃû¡¢µØµã£¨Õ˵¥ºÍÔËÊ䣩¡¢µç»°ºÅÂë¼°Ö§¸¶¿¨ÏêϸÐÅÏ¢£¨ºÅÂë¡¢ÓÐÓÃÆÚ¡¢CVVÂ룩¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤DNSÒ£²âÊý¾Ý£¬ £¬£¬£¬£¬£¬¸ÃC&CÓòÃûÒѱ»ÆÊÎö905´Î£¬ £¬£¬£¬£¬£¬Õâ¿ÉÄÜÅú×¢ÎúÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/magecart-attackers-steal-card-info-from-focus-camera-shoppers/


4.TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬ £¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×ÔÍâ»ã¹«Ë¾TravelexÔâµ½ÍøÂç¹¥»÷ÒѾ­ÒÑÍùÁËÁùÌìµÄʱ¼ä£¬ £¬£¬£¬£¬£¬BleepingComputerÄܹ»È·Èϸù«Ë¾Ñ¬È¾µÄ¶ñÒâÈí¼þΪÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚ12ÔÂ31ÈÕ£¬ £¬£¬£¬£¬£¬¸Ã¹«Ë¾½ÓÄÉÁËÔ¤·À²½·¥½«ËùÓеÄÅÌËã»úϵͳÍÑ»ú£¬ £¬£¬£¬£¬£¬Ê¹µÃ¿Í»§ÎÞ·¨ÔÙʹÓÃÍøÂç»òAPP¾ÙÐÐÉúÒâ»òÔÚÈ«ÇòÁè¼Ý1500¼ÒµêËÁÖÐʹÓÃÐÅÓÿ¨£¨½è¼Ç¿¨£©¸¶¿î¡£¡£¡£¡£¡£¡£¡£TravelexÉÐδÌṩÓйػָ´Ð§Àͽø¶ÈµÄ×îÐÂÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£BleepingComputerÊÕµ½ÐÂÎųÆTravelexȷʵÊܵ½SodinokibiµÄѬȾ£¬ £¬£¬£¬£¬£¬ÆäÀ©Õ¹ÃûÀàËÆÓÚ.u3i7y74¡£¡£¡£¡£¡£¡£¡£Sodinokibi¹¥»÷Õß»¹³Æ¶ÔÕû¸öTravelexÍøÂç¾ÙÐÐÁ˼ÓÃÜ£¬ £¬£¬£¬£¬£¬²¢¸´ÖÆÁËÁè¼Ý5GBµÄСÎÒ˽¼ÒÊý¾Ý£¬ £¬£¬£¬£¬£¬ÆäÖаüÀ¨³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢µÈ£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßË÷ÒªµÄÊê½ðΪ300ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-hits-travelex-demands-3-million/


5.3¸ö¶ñÒâAPPʹÓÃCVE-2019-2215£¬ £¬£¬£¬£¬£¬»òÓëSideWinder APTÓйØ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁÖз¢Ã÷3¸ö¶ñÒâAPP£¬ £¬£¬£¬£¬£¬ËüÃÇ¿ÉÒÔЭͬÊÂÇ鯯ËðÊܺ¦ÕßµÄ×°±¸²¢ÍøÂçÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÃûΪCameroµÄAPPʹÓÃÁËBinder£¨AndroidÖÐÖ÷ÒªµÄÀú³Ì¼äͨѶϵͳ£©ÖеÄuse-after-freeÎó²î£¨CVE-2019-2215£©£¬ £¬£¬£¬£¬£¬ÕâÊÇÒÑÖªµÄÊ׸öʹÓøÃÎó²îµÄÒ°Íâ¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚ½øÒ»³ÌÐò²éÖУ¬ £¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÕâÈý¸ö¶ñÒâAPP¿ÉÄÜÓë·¸·¨ÍÅ»ïSideWinder APTÓйØ¡£¡£¡£¡£¡£¡£¡£SideWinder×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬ £¬£¬£¬£¬£¬¾Ý±¨µÀËüÖ÷ÒªÃé×¼¾üÊ»ú¹¹µÄWindowsÅÌËã»ú¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÍƲâÕâÈý¸ö¶ñÒâAPP×Ô2019Äê3ÔÂÒÔÀ´Ò»Ö±´¦Óڻ״̬£¬ £¬£¬£¬£¬£¬Ä¿½ñËüÃÇÒѱ»Google PlayϼÜ¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/


6.¹È¸èÐû²¼2020Äê1ÔÂAndroidÇå¾²¸üУ¬ £¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê1ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö£º2020-01-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËFramework¡¢Media¿ò¼ÜºÍϵͳ×é¼þÖеÄ7¸öÎó²î£»£»£»2020-01-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËÄںˡ¢¸ßͨ×é¼þºÍ¸ßͨ±ÕÔ´×é¼þÖеÄ33¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¡£±»±êΪcritical£¨ÑÏÖØ£©¼¶±ðµÄÎó²îΪMedia¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0002£©£¬ £¬£¬£¬£¬£¬Ëü¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î½öÔÚAndroid 8.0¡¢8.1 ºÍ9°æ±¾Öб»ÒÔΪÊÇÑÏÖØ¼¶±ð£¬ £¬£¬£¬£¬£¬µ«ÔÚAndroid 10ÖÐΪÖÐΣ¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑÏÖØÎó²îÊÇRealtek rtlwifiÇý¶¯³ÌÐòÖеÄRCEÎó²î£¨CVE-2019-17666£©¡£¡£¡£¡£¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/androids-january-2020-update-patches-40-vulnerabilities