TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª;µÂ¹úCanyon BicyclesÔâºÚ¿ÍÈëÇÖ

Ðû²¼Ê±¼ä 2020-01-08


1.Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾SQL×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬£¬¿É¸Ä¶¯Ö´·¨Îļþ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ö±²¼ÂÞÍÓÕþ¸®ÍøÕ¾ÖеÄÒ»¸öSQL×¢ÈëÎó²î¿ÉÄܵ¼Ö¹¥»÷Õ߸͝¸ÃµØÖ´·¨ÎļþµÄÕýÊ½ÍøÂç°æ±¾¡£¡£¡£ ¡£¡£¡£Çå¾²Ñо¿Ô±Ax SharmaÔÚÑо¿Ö±²¼ÂÞÍÓÁìÍÁºÍº£°¶¾¯ÎÀ¶ÓÍøÕ¾µÄǩ֤»®×¼Ê±·¢Ã÷ÁËÕâ¸öÎó²î£¬£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉʹÓÃÕþ¸®ÍøÕ¾ÉÏ̻¶µÄÐÅÏ¢¸Ä¶¯Ö±²¼ÂÞÍÓÖ´·¨µÄ¹Ù·½ÔÚÏß´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬°üÀ¨É¾³ý»òÉÏ´«PDFÎļþ¡£¡£¡£ ¡£¡£¡£Ê¹ÓÿªÔ´¹¤¾ßsqlmap£¬£¬£¬£¬£¬£¬£¬SharmaÄܹ»Éó²éΪִ·¨ÎļþÍйÜÕ¾µãÌṩ֧³ÖµÄËùÓбíºÍÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÃûΪgiblaws_giblaws.userµÄ±í°üÀ¨ÁËÊÂÇéÖ°Ô±µÄÐÕÃû¡¢Óû§ÃûºÍÃÜÂëÕªÒªµÈ¡£¡£¡£ ¡£¡£¡£SharmaʹÓÃsqlmapµÄÄÚÖÃͻ񻮮½â¹¤¾ß²»µ½1Ãë¾ÍÆÆ½âÁËÆäÖÐÒ»¸öÃÜÂ룬£¬£¬£¬£¬£¬£¬ÕâʹµÃÆä¿ÉÒԵǼ²¢Ê¹ÓøÃÕË»§µÄȨÏÞÀ´±à¼­ÍøÕ¾ÉϵÄÄÚÈÝ¡£¡£¡£ ¡£¡£¡£Ö±²¼ÂÞÍÓÕþ¸®½²»°ÈËÈ·ÈÏÁËÕâÒ»Îó²î£¬£¬£¬£¬£¬£¬£¬²¢ÌåÏÖÒѽ«ÊÜÓ°ÏìµÄÍøÒ³ÀëÏß¡£¡£¡£ ¡£¡£¡£


  Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/01/07/gibraltar_sql_vuln_allowed_law_editing/


2.µÂ¹úCanyon Bicycles ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬Ð§ÀÍÆ÷ºÍÈí¼þ±»¼ÓÃÜ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


µÂ¹ú×ÔÐгµÖÆÔìÉÌCanyon Bicycles GmbGÈ·ÈÏÔÚÐÂÄê¼ÙÆÚʱ´úÔâÓöÇå¾²ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¿·Ö»ù´¡ÉèÊ©±»·¸·¨·Ö×ÓËø¶¨¡£¡£¡£ ¡£¡£¡£¸Ã³§ÉÌÔÚÒ»·ÝÉùÃ÷ÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÐÂÄê֮ǰ¾ÍÈëÇÖÁËÆäITϵͳ£¬£¬£¬£¬£¬£¬£¬ÆäÈí¼þºÍЧÀÍÆ÷±»¼ÓÃܺÍËø¶¨¡£¡£¡£ ¡£¡£¡£Ëü»¹ÌåÏÖÍøÕ¾²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§¿ÉÒÔÕý³£Ï´ïÔÚÏß¶©µ¥£¬£¬£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾Ä¿½ñÒѾ­È·¶¨²¢×èÖ¹Á˹¥»÷¡£¡£¡£ ¡£¡£¡£CanyonÊ×´´È˼æÊ×ϯִÐйÙRoman ArnoldÌåÏÖ£º¡°´Ë´Î¹¥»÷ÏÔʾ³ö´ó¹æÄ£µÄ·¸·¨Òâͼ¡£¡£¡£ ¡£¡£¡£ÓÉÓÚIT»ù´¡¼Ü¹¹±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÊÂÇéºÍÓªÒµÁ÷³ÌÔÝʱÊܵ½ÁËÖØ´óÓ°Ïì¡£¡£¡£ ¡£¡£¡£¡±Î÷µÂ¿Æ²¼Â×´Ä×ܲ¿ºÍÏÕЩËùÓйú¼ÊÓªÒµ¶¼Êܵ½Ö±½ÓÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«ÃÀ¹ú×Ó¹«Ë¾²»ÊÜÓ°Ïì¡£¡£¡£ ¡£¡£¡£Arnold²¢Î´Ìá¼°ÏêϸµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°·¸·¨·Ö×ÓÊÇ·ñÒªÇóÁËÊê½ð¡¢Êê½ð½ð¶î»òÊÇÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2020/01/07/hackers_canyon_bicycles/


3.ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraÔâµ½MageCart¹¥»÷


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraµÄÍøÕ¾ÓÚÈ¥ÄêÄêµ×Ôâµ½MageCart¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£ ¡£¡£¡£ÎªÁËÒþ²Ø¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁË¡°zdsassets.com¡±ÓòÃû£¬£¬£¬£¬£¬£¬£¬¸ÃÓòÃûÄ£ÄâÁËZenDeskµÄÕýµ±ÓòÃû¡°zdassets.com¡±¡£¡£¡£ ¡£¡£¡£Juniper NetworksÇå¾²Ñо¿Ô±Mounir HahadÔÚ12ÔÂÏÂÑ®·¢Ã÷Á˶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢°üÀ¨µç×ÓÓʼþ¡¢¿Í»§ÐÕÃû¡¢µØµã£¨Õ˵¥ºÍÔËÊ䣩¡¢µç»°ºÅÂë¼°Ö§¸¶¿¨ÏêϸÐÅÏ¢£¨ºÅÂë¡¢ÓÐÓÃÆÚ¡¢CVVÂ룩¡£¡£¡£ ¡£¡£¡£Æ¾Ö¤DNSÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¸ÃC&CÓòÃûÒѱ»ÆÊÎö905´Î£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÅú×¢ÎúÊÜÓ°ÏìµÄ¿Í»§ÊýÄ¿¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/magecart-attackers-steal-card-info-from-focus-camera-shoppers/


4.TravelexѬȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


×ÔÍâ»ã¹«Ë¾TravelexÔâµ½ÍøÂç¹¥»÷ÒѾ­ÒÑÍùÁËÁùÌìµÄʱ¼ä£¬£¬£¬£¬£¬£¬£¬BleepingComputerÄܹ»È·Èϸù«Ë¾Ñ¬È¾µÄ¶ñÒâÈí¼þΪÀÕË÷Èí¼þSodinokibi¡£¡£¡£ ¡£¡£¡£¹¥»÷ÊÂÎñ±¬·¢ÔÚ12ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾½ÓÄÉÁËÔ¤·À²½·¥½«ËùÓеÄÅÌËã»úϵͳÍÑ»ú£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¿Í»§ÎÞ·¨ÔÙʹÓÃÍøÂç»òAPP¾ÙÐÐÉúÒâ»òÔÚÈ«ÇòÁè¼Ý1500¼ÒµêËÁÖÐʹÓÃÐÅÓÿ¨£¨½è¼Ç¿¨£©¸¶¿î¡£¡£¡£ ¡£¡£¡£TravelexÉÐδÌṩÓйػָ´Ð§Àͽø¶ÈµÄ×îÐÂÐÅÏ¢¡£¡£¡£ ¡£¡£¡£BleepingComputerÊÕµ½ÐÂÎųÆTravelexȷʵÊܵ½SodinokibiµÄѬȾ£¬£¬£¬£¬£¬£¬£¬ÆäÀ©Õ¹ÃûÀàËÆÓÚ.u3i7y74¡£¡£¡£ ¡£¡£¡£Sodinokibi¹¥»÷Õß»¹³Æ¶ÔÕû¸öTravelexÍøÂç¾ÙÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬²¢¸´ÖÆÁËÁè¼Ý5GBµÄСÎÒ˽¼ÒÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨³öÉúÈÕÆÚ¡¢Éç»áÇå¾²ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßË÷ÒªµÄÊê½ðΪ300ÍòÃÀÔª¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-hits-travelex-demands-3-million/


5.3¸ö¶ñÒâAPPʹÓÃCVE-2019-2215£¬£¬£¬£¬£¬£¬£¬»òÓëSideWinder APTÓйØ


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


Ç÷ÊÆ¿Æ¼¼Ñо¿Ö°Ô±ÔÚGoogle PlayÊÐËÁÖз¢Ã÷3¸ö¶ñÒâAPP£¬£¬£¬£¬£¬£¬£¬ËüÃÇ¿ÉÒÔЭͬÊÂÇ鯯ËðÊܺ¦ÕßµÄ×°±¸²¢ÍøÂçÓû§ÐÅÏ¢¡£¡£¡£ ¡£¡£¡£ÆäÖÐÃûΪCameroµÄAPPʹÓÃÁËBinder£¨AndroidÖÐÖ÷ÒªµÄÀú³Ì¼äͨѶϵͳ£©ÖеÄuse-after-freeÎó²î£¨CVE-2019-2215£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒÑÖªµÄÊ׸öʹÓøÃÎó²îµÄÒ°Íâ¹¥»÷¡£¡£¡£ ¡£¡£¡£ÔÚ½øÒ»³ÌÐò²éÖУ¬£¬£¬£¬£¬£¬£¬Ñо¿Ö°Ô±»¹·¢Ã÷ÕâÈý¸ö¶ñÒâAPP¿ÉÄÜÓë·¸·¨ÍÅ»ïSideWinder APTÓйء£¡£¡£ ¡£¡£¡£SideWinder×Ô2012ÄêÒÔÀ´Ò»Ö±»îÔ¾£¬£¬£¬£¬£¬£¬£¬¾Ý±¨µÀËüÖ÷ÒªÃé×¼¾üÊ»ú¹¹µÄWindowsÅÌËã»ú¡£¡£¡£ ¡£¡£¡£Ñо¿Ö°Ô±ÍƲâÕâÈý¸ö¶ñÒâAPP×Ô2019Äê3ÔÂÒÔÀ´Ò»Ö±´¦Óڻ״̬£¬£¬£¬£¬£¬£¬£¬Ä¿½ñËüÃÇÒѱ»Google Playϼܡ£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/


6.¹È¸èÐû²¼2020Äê1ÔÂAndroidÇå¾²¸üУ¬£¬£¬£¬£¬£¬£¬ÐÞ¸´40¸öÎó²î


¼øºÚµ£±£Íø(jhdbw)¡¤×î¾ßȨÍþΨһάȨµ£±£Æ½Ì¨


2020Äê1ÔµÄAndroidÇå¾²¸üаüÀ¨Á½¸ö²¿·Ö£º2020-01-01Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËFramework¡¢Media¿ò¼ÜºÍϵͳ×é¼þÖеÄ7¸öÎó²î£»£»£»£»£»£»2020-01-05Çå¾²²¹¶¡³ÌÐò¼¶±ðÐÞ¸´ÁËÄںˡ¢¸ßͨ×é¼þºÍ¸ßͨ±ÕÔ´×é¼þÖеÄ33¸öÇå¾²Îó²î¡£¡£¡£ ¡£¡£¡£±»±êΪcritical£¨ÑÏÖØ£©¼¶±ðµÄÎó²îΪMedia¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2020-0002£©£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓöñÒâÎļþÔÚÌØÈ¨Àú³ÌµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ ¡£¡£¡£¸ÃÎó²î½öÔÚAndroid 8.0¡¢8.1 ºÍ9°æ±¾Öб»ÒÔΪÊÇÑÏÖØ¼¶±ð£¬£¬£¬£¬£¬£¬£¬µ«ÔÚAndroid 10ÖÐΪÖÐΣ¡£¡£¡£ ¡£¡£¡£ÁíÒ»¸öÑÏÖØÎó²îÊÇRealtek rtlwifiÇý¶¯³ÌÐòÖеÄRCEÎó²î£¨CVE-2019-17666£©¡£¡£¡£ ¡£¡£¡£


 Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/androids-january-2020-update-patches-40-vulnerabilities