Äê¹Ø½«ÖÁ£¡2018£¡

°ä²¼¹¦·ò 2019-01-25
ÈȵãÊÂÎñ·ÖÎöÔ¤¾¯

¡¾·ì϶Ԥ¾¯¡¿WebLogic CVE-2018-2628·´ÐòÁл¯·ì϶¸´ÏÖ


¡¾Ô­´´·ì϶¡¿WebLogic·´ÐòÁл¯·ì϶CVE-2018-2893Ô¤¾¯


¡¾Ô­´´·ì϶¡¿Weblogic·´ÐòÁл¯·ì϶CVE-2018-3245Ô¤¾¯


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab·¢ÏÖWebLogic´æÔÚÉÏÊö·´ÐòÁл¯·ì϶ £¬·ì϶ӰÏìWebLogic 10.3.6.0¡¢12.1.3.0¡¢12.2.1.2¡¢12.2.1.3¶à¸ö°æ±¾¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔÚ·ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷ £¬²¢¿É»ñȡָ±êϵͳËùÓÐȨÏÞ¡£


¡¾·ì϶Ԥ¾¯¡¿ºáºÓµç»úSTARDOM½ÚÔìÆ÷´æÔÚ¸ßΣ·ì϶


¶«·½µçÆø-±¦ÔËÀ³¹Ù·½ÍøÕ¾¹¤¿ØÐÅÏ¢°²È«½áºÏ³¢ÊÔÊÒ£¨VDLab£©·¢ÏÖ¹¤Òµ×Ô¶¯»¯½ÚÔìºÍÐÅϢϵÍÂäìµ¼ÆóÒµÈÕ±¾ºáºÓµç»úSTARDOM½ÚÔìÆ÷´æÔÚ¸ßΣ·ì϶¡£·ì϶ӰÏìºáºÓµç»úµÄSTARDOM¶à¿î½ÚÔìÆ÷ £¬²¢¶ÔÀûÓÃÆä½ÚÔìÆ÷µÄÄÜÔ´¡¢¹Ø¼üÔì×÷¡¢Ê³Æ·ºÍũҵµÈÐÐÒµÔì³ÉÑϳÁ·çÏÕ £¬Ó°Ï켫Ϊ¿í·º¡£

¡¾·ì϶Ԥ¾¯¡¿LinuxÄں˴æÔÚTCP°²È«·ì϶£¨CVE-2018-5390£©


·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÎÞÐèÈκÎȨÏÞÔÚÊÜÓ°ÏìµÄLinuxÉ豸Éϵ¼ÖÂÔ¶³Ì»Ø¾ø·þÎñ¡£ÄÚºË4.9¼°ÒÔÉϵÄLinux°æ±¾¾ùÊÜ·ì϶ӰÏì £¬ÊÜÓ°ÏìµÄÉ豸Ô̺¬×°ÖÃÁËÉÏÊöÄں˵ÄÍÆËã»úƽ̨¼°LinuxǶÈëʽÉ豸¡£


¡¾·ì϶Ԥ¾¯¡¿Apache Struts2Ô¶³Ì´úÂëÖ´Ðзì϶£¨S2-057£©


Apache Struts2´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¨S2-057£© £¬¿ÉÓ°ÏìApache Struts 2.3 - Struts 2.3.34 £¬Apache Struts 2.5 - Struts 2.5.16°æ±¾¡£

¡¾·ì϶Ԥ¾¯¡¿Win10 ´æÔÚ±¾µØÌáȨ0day·ì϶


Windows 10ϵͳÖÐÒ»¸ö±¾µØÌáȨ0day·ì϶ £¬´æÔÚÓÚWindowsµÄ¹¤×÷µ÷¶È·þÎñÖÐ £¬ÔÊÐí¹¥»÷Õß´ÓUSERȨÏÞÌáȨµ½SYSTEMȨÏÞ¡£·ì϶¿ÉÓ°ÏìWindows 10ºÍWindows Server 2016¡£


¡¾·ì϶Ԥ¾¯¡¿Adobe ColdFusion ·´ÐòÁл¯·ì϶


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab·¢ÏÖAdobe Coldfusion´æÔÚ·´ÐòÁл¯·ì϶CVE-2018-15958ºÍCVE-2018-15959¡£·ì϶¿ÉÓ°ÏìColdFusion 11 Update 14¼°Ö®Ç°°æ±¾¡¢2016.0 Update 6¼°Ö®Ç°°æ±¾¡£

ÎïÁªÍø×¨Ìâ·ÖÎö

ÖÇÄÜÃÅËøÍøÂ簲ȫ·ÖÎö»ã±¨


2017ÄêÖÇÄÜÃÅËø²úÖµ³¬¹ý°ÙÒÚÔª £¬Êг¡¹æÄ£¿¿½ü800Íò°Ñ £¬Ô¤¼Æ2020ÄêÖÇÄÜÃÅËøÊг¡¹æÄ£½«´ïµ½4000Íò°Ñ¡£ ÖÇÄÜÃÅËøµÄ°²È«½«»áÖ±½Óµ¼ÖÂÓ×ÎҺͼÒÍ¥µÄÐÔÃü²Æ¸»°²È« £¬±¾»ã±¨³Áµã¹Ø×¢ÖÇÄÜÃÅËøµÄÍøÂ簲ȫÎÊÌâ¡£


VPNFilter£ºÎ£¼°È«Çò¹¤¿ØÉ豸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв


VPNFilterÊÇһ·ÒÔÈëÇÖÎïÁªÍøÎªÔØÌå´ÓÊ¿ÉÄÜÓɹú¶ÈÌáÒéµÄÈ«ÇòÐԸ߼¶¶ñÒâÈí¼þ¹¥»÷ £¬ÖÁÉÙÓÐ50Íǫ̀É豸Ôâ·êϰȾ¡£±¾»ã±¨¶ÔΣ¼°¹¤¿Ø¼°°ì¹«ÍøÂçµÄÎïÁªÍø¼äµýÈí¼þVPNFilter½øÐÐÉî¿Ì·ÖÎö £¬ÏêÊöC&C±»¶¯»ñÈ¡µÄSYNËí·¼¼Êõ¡£


ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLabÔڳ־õĽ©Ê¬Éú̬×êÑзÖÎöÖз¢ÏÖÒ»¿îÎïÁªÍø½©Ê¬±»¿í·ºµØÖ²ÈëÁ˺Úȸ £¬Í¨¹ýËÝÔ´·ÖÎöÈ·ÈÏÊÇÒ»ÖÖÖ§³Ö¶àCPUƽ̨µÄDdostf½©Ê¬ÍøÂç¼Ò×å±äÖÖ¡£±¾»ã±¨³Áµã½éÉÜÆäºÚȸ¹¥»÷µÄµÀÀíÒÔ¼°¡°¶¾ÉϼӶ¾¡±µÄ¾°Ïó¡£


ÐÛÂõ¶à¸öÉãÏñÍ··ì϶Ԥ¾¯¼°½¨¸´£¨¸½¹¤¾ß£©


ÐÛÂõ²úÆ·´æÔÚ¶à¸ö°²È«·ì϶ £¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýÄÚ±íÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢×°ÖöñÒâ´úÂë¡¢ÌáÒé´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab¾ùÔÚÓйØÐͺŵÄ×îй̼þ°æ±¾ÉϽøÐÐÁËÑéÖ¤¡£ÊÜÓ°ÏìµÄÔÚÍøÉ豸ÊýÁ¿ÔÚ°ÙÍòÒÔÉÏ¡£

ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö

¶ãÔÚP2PÈä³æÍøÂç±³ºóµÄ¹í»ê£ºDridexÈ䳿ÐÂÐͱäÖÖÌ½ÃØ£¨¸½×¨É±¹¤¾ß£©


DridexÒÑÐγɼ¯È䳿¡¢½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÀÕË÷Èí¼þ¡¢P2P´úÀíÓÚÒ»ÉíµÄ»ìºÏÐÍÈ䳿²¡¶¾¡£ÔÚÇÔÃÜÖ°ÄÜÉÏ £¬Ëü²»½ö¿ÉÇÔÈ¡¸÷ÀàÖ÷Á÷Óʼþ¿Í»§¶ËÒÔ¼°ä¯ÀÀÆ÷±£ÁôµÄµÇ¼ƾ֤ £¬»¹»áÍøÂçÒøÐÓ×¢ÐÅÓþ¿¨µÈµÇ¼ºÍÖ§¸¶Æ¾Ö¤ £¬·çÏÕ¼«´ó¡£


Ê׿îÀûÓÃFirebaseÔÆÐÂÎÅ´«µÝ»úÔìµÄ¸ß¼¶¼äµýÈí¼þ


¸Ã¼äµýÈí¼þÊÇĿǰAndroidƽ̨ÉÏ×îΪ׳´óµÄ¶ñÒâÀûÓÃÖ®Ò» £¬¿ÉʵÏÖÔ¶³ÌrootÌáÉýµ½×î¸ßȨÏÞ £¬²¢ÇÒʵÏÖÁËAndroid²ãµÄÃô¸ÐÐÅÏ¢ÇÔÈ¡ £¬ÉõÖÁʵÏÖÁËLinux²ãÃæµÄ¡°·´µ¯Shell¡±ÒÔ´ïµ½Æä¶ÔÖ¸±êÉ豸µÄÆëÈ«½ÚÔì¡£±¾ÎijÁµã·Ö½âÑù±¾Android¶ËµÄ¸÷¸ö·þÎñºÍ½ÚÔìµÄÂß¼­²¿ÃÅ¡£


Crysis¼Ò×åÀÕË÷²¡¶¾×îбäÖÖ·ÖÎö


Crysis¼Ò×åбäÖÖ×åÖØÒªÍ¨¹ý´¹µöÓʼþºÍÀûÓÃRDP±¬ÆÆ½øÐд«²¼ £¬ÆäʹÓüÓÃܵÄshellcode £¬ÔÚshellcodeÖÐÀûÓû»Ìå¼¼Êõ¶Ô·¨Ê½µØÖ·¿Õ¼ä½øÐÐÅú¸Ä £¬ÒÔ´ïµ½×ÌÈÅɱ¶¾Èí¼þµÄ²éɱºÍÆ¥µÐ¶þ½øÔì·ÖÎöµÄÖ÷ÕÅ¡£


ÐÂÐÍÀÕË÷²¡¶¾BadCkat¼Ù×°³É·¨Ôº´«Æ±½øÐй¥»÷


BadCkatÊÇÒ»¿îÀûÓá°EDA2¡±¿ªÔ´ÀÕË÷ÏîĿˢжø³ÉµÄÀÕË÷²¡¶¾ £¬ÔÚÊÀ½çÁìÓòÄÚ½øÐÐ¿í·ºµÄ¹¥»÷»î¶¯¡£¸ÃÀÕË÷²¡¶¾½ö¶ÔÎļþÍ·µÄ²¿ÃÅÊý¾Ý½øÐмÓÃÜ £¬Òò¶ø¼ÓÃÜËٶȼ«¿ì £¬Í¬Ê±´ïµ½ÁË·ÛË鷨ʽÕý³£ÔËÐÐ £¬Îĵµ¼ÓÃܲ»ÄÜ´ò¿ªµÄÖ÷ÕÅ¡£


Ê׿ÀÕË÷¡¢¼äµý¡¢ÒøÐÐľÂíÓÚÒ»ÌåµÄÐÂÐÍ×ÛºÏÐÍAndroid²¡¶¾Éî¶È·ÖÎö


ÐÂÐͲ¡¶¾ÊµÏÖÁ˼ÓÃÜÀÕË÷¡¢¼üÅ̼ͼ¡¢Ô¶³Ì½Ó¼ûľÂí¡¢¶ÌÐÅÀ¹½Ø¡¢ºô½Ð×ªÒÆºÍËø¶¨ÆÁÄ»µÈÖ°ÄÜ £¬¿É½Ù³ÖÏÕЩº­¸ÇÊÀ½ç¸÷´ó½ðÈÚ»ú¹¹µÄÊÖ»úAPP £¬×ÜÊýÓÐ300¶à¸ö £¬Éæ¼°Öйú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸ÛµÈ40¶à¸ö¹ú¶ÈºÍµØÓò¡£


¾¯Ì裺´óÁ¿³ÛÃûÈí¼þ×°Öðü±»Ö²Èë¡°×°Öùí»ê¡±Íڿ󲡶¾
±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab·¢ÏÖ´óÁ¿³ÛÃûÈí¼þ×°Ö÷¨Ê½±»Ö²Èë¡°×°Öùí»ê¡±Íڿ󲡶¾ £¬¸Ã²¡¶¾±³ºóµÄºÚ¿ÍÊÔͼͨ¹ýÈí¼þ¹²ÏíÂÛ̳µÈÇþ·°ä²¼°ó¸¿Óиò¡¶¾µÄÊ¢ÐÐÀûÓÃµÄÆÆ½â°æ±¾ £¬Éæ¼°ÀûÓù²¼Æ26ÖÖ £¬Á¬Í¬·ÖÆçµÄ°æ±¾¹²°ä²¼ÓÐ99¸öÖ®¶à¡£

°²È«·ì϶·ÖÎö

 CPU¡°¹í»ê¡±·ì϶·ÖÎöÓëÑéÖ¤


CPUµ×²ã·ì϶°²È«ÊÂÎñÒѲ¨¼°È«ÇòÏÕЩËùÓеÄÊÖ»ú¡¢µçÄÔ¡¢ÔÆÍÆËã²úÆ·¡£¡°¹í»ê¡±·ì϶¿ÉÔì³ÉÊܱ£»¤µÄÃÜÂë¡¢Ãô¸ÐÐÅϢй¶¡£±¾ÎijÁµã¶Ô¡°¹í»ê¡±µÄ·ì϶µÀÀí¡¢·ì϶ÑéÖ¤¡¢·çÏÕ¼°·À»¤½øÐнéÉÜ¡£


WPA2¡°KRACK¡±·ì϶¼ò½éÓë³ÁÏÖ


ÎÞÏßÍøÂçºÍ̸WPA2´æÔÚ¸ßΣ·ì϶ £¬·ì϶ÔÊÐí¹¥»÷Õß¼àÌýAPºÍ½ÓÈëµãSTAÖ®¼ä´«ÊäµÄWi-FiÊý¾ÝÁ÷Á¿ £¬ÀíÂÛÉÏËùÓÐÖ§³ÖWPA2µÄ¿Í»§¶Ë¶¼½«Êܵ½¡°KRACK¡±¹¥»÷µÄÓ°Ïì¡£±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLabͨ¹ý¶ÔÈ«ÁãÃÜÔ¿·ì϶µÄ·ÖÎö³É¹¦³ÁÏÖ¡°KRACK¡±¹¥»÷¡£


DrupalÔ¶³Ì´úÂëÖ´Ðзì϶(CVE-2018-7600)·ÖÎöÓëÑéÖ¤

                           

Drupal 6.x¡¢7.x¡¢8.x¶à¸ö×Ó°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ·ì϶ £¬¹¥»÷ÕßÀûÓô˷ì϶¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë £¬²¢½ÚÔìʹÓÃDrupalµÄÕ¾µã¡£·ì϶´æÔÚÓÚÓû§×¢ÊéÒ³Ãæ £¬ËùÒÔÈκÎÄäÃû¹¥»÷Õß¶¼Äܹ»´¥·¢ £¬·çÏÕˮƽ½Ï¸ß¡£


WebKitä¯ÀÀÆ÷·ìϼûæÃæ¹Û


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab¶ÔWebKitÒýÇæ½øÐзì϶ÍÚ¾òºÍ´úÂëÉó¼ÆÊ± £¬·¢ÏÖWebkit´æÔÚ¶à¸ö°²È«·ì϶¡£±¾ÎľßÌå·ÖÎöWebKit¸÷Ä£¿éµÄ·ì϶°¸Àý £¬¶Ô WebKitä¯ÀÀÆ÷·ìϼûæ½øÐÐÈ«ÃæÂÛÊö¡£


AndroidÀ¶ÑÀ×é¼þ·ì϶Á¬Á¬¿´ 


AndroidϵͳÖÐ £¬À¶ÑÀ×é¼þÄܹ»ËµÊǰ²È«·ì϶³ÁÔÖÇø¡£±¾ÎijÁµã½éÉÜÀ¶ÑÀºÍ̸ջÖеÄL2CAPºÍ̸ºÍSMPºÍ̸ £¬²¢¶ÔCVE-2018-9359ºÍCVE-2018-9365ÕâÁ½¸ö·ì϶°¸Àý½øÐоßÌå·ÖÎö¡£


ThinkPHP5Ô¶³Ì´úÂëÖ´Ðзì϶·ÖÎö


·ì϶ÊÇÓÉÓÚ·ÓɽâÎöȱµãËùµ¼Ö £¬·çÏÕˮƽ¼«¶È¸ß £¬Ä¬ÈÏ»·¾³ÅäÖü´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¾­¹ý±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab¶ÔThinkPHPµÄ56¸öÓ×°æ±¾µÄÔ´Âë·ÖÎöºÍÑéÖ¤ £¬È·¶¨¾ßÌåÊÜÓ°ÏìµÄ°æ±¾ÎªThinkPHP 5.0.5-5.0.22¡¢5.1.0-5.1.30¡£


ChakraÒýÇæÖÐJIT±àÒëÓÅ»¯¹ý³ÌÖеÄÊý×éÀàÐÍ»ìºÏ·ì϶·ÖÎö


ChakraÊÇÒ»¸öÓÉ΢ÈíΪMicrosoft Edgeä¯ÀÀÆ÷¿ª·¢µÄJavaScriptÒýÇæ¡£ËüÔÚÒ»¸ö¶ÀÁ¢µÄCPUÖ÷ÌâÉϼ´Ê±±àÒë¾ç±¾ £¬Óëä¯ÀÀÆ÷²¢ÐС£±¾ÎÄÖØÒª¶ÔChakraÒýÇæÖÐJIT±àÒëÓÅ»¯¹ý³ÌÖеÄÊý×éÀàÐÍ»ìºÏ·ì϶½øÐзÖÎö¡£

Çø¿éÁ´×¨Ìâ·ÖÎö

¾¯ÌèÖÇÄܺÏÔ¼·ì϶£ºÇø¿éÁ´Éϵġ°¿ÕÆø¡±±Ò


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab½üÄêÀ´³ÖÐø¹Ø×¢Çø¿éÁ´¼¼Êõ°²È«ÎÊÌâ £¬Í¨¹ý¶ÔÒÔÌ«·»Ö÷Á´ÖÇÄܺÏÔ¼½øÐÐ×êÑÐ £¬·¢ÏÖÁË400¶à¸öCVE·ì϶¡£ÀûÓÃÖÇÄܺÏÔ¼·ì϶¹¥»÷Õ߿ɽÚÔìÊг¡ÉϵÄÇ®±Ò×ÜÁ¿»òËÁÒâÕË»§µÄÇ®±ÒÁ¿ £¬Ê¹Õý±¾¾ÍÎÞêµÄÇ®±Ò³¹µ×ʧȥÐÅÓþ £¬³ÉΪ¡°¿ÕÆø¡±±Ò¡£


Ê׸öÇø¿éÁ´tokenµÄ×Ô¶¯»¯Þ¶Ñòë¹¥»÷·ÖÎö


±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab½áºÏµç×ӿƼ¼´óѧ³ÂÌü¸±½ÌÊÚ×·×Ùµ½ÒÔÌ«·»tokenÖеÄÊ׸ö×Ô¶¯»¯Þ¶Ñòë¹¥»÷ÊÂÎñ¡£tokenÃû³ÆÎªSimoleon (SIM) £¬Óп¿½ü57ÍòÕË»§³ÖÓиúÏÔ¼µÄtoken¡£¹¥»÷Õßͨ¹ý²¿Êð¹¥»÷ºÏÔ¼»ñµÃÁ˳¬¹ý700ÍòµÄtoken £¬Ò»¾Ù³ÉΪ¸ÃºÏÔ¼tokenµÄµÚËÄ´ó³ÖÓÐÕß¡£


´Ósolidity˵»°¸öÐÔÉî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏÔ¼·ì϶µÀÀíºÍ¹¥»÷ÀûÓÃ


ÖÇÄܺÏÔ¼µÄ¿ª·¢Ëµ»°¡¢Éè¼ÆÄ£Ê½¡¢ÔËÐлúÔì¶¼Ó봫ͳÀûÓÃÓнϴó²î¾à¡£±¾»ã±¨ÒÔWCTF2018µÄһ·ÖÇÄܺÏÔ¼·ì϶ÈüÌâΪÀý £¬´Ósolidity˵»°¸öÐÔÆô³Ì £¬Éî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏÔ¼·ì϶µÀÀíºÍ¹¥»÷ÀûÓá£


God.GameÖÇÄܺÏÔ¼¹¥»÷ÊÂÎñ·ÖÎö


2018Äê8Ô £¬God.GameÔÚÒÔÌ«·»Çø¿éÁ´Éϲ¿ÊðÆäºÏÔ¼ºóµÚ¶þÌì±ã±»µÁÈ¡ÁË243¸öÒÔÌ«±Ò £¬¼ÛÖµ³¬¹ý6ÍòÃÀÔª¡£¾­±¦ÔËÀ³¹Ù·½ÍøÕ¾ADLab¾ßÌå·ÖÎöºÍ³ÁÏÖ £¬·¢ÏÖ¹¥»÷ÕßÊÇͨ¹ýÂŴδ¥·¢GodºÏÔ¼µÄ·ÖÆçÒµÎñÂß¼­×îÖÕÔì³ÉÕûÊýÒç³ö¡£


ÒÔÌ«·»ÖÇÄܺÏÔ¼¶à¸ö¹¥»÷°¸Àý·ÖÎö


ÔÚ¶à¶àÖÇÄܺÏÔ¼¹¥»÷°¸ÀýÖÐ £¬ÓÐЩ·ì϶³ÉÒò»ò¹¥»÷ģʽÉÙÓÐ×êÑÐÉæ¼° £¬Ò²³öÏÖÁËһЩ±ÈÁ¦Òñ±ÎµÄ¹¥»÷Á´¡£±¾ÎijÁµã´ÓʹÓÃOraclize·þÎñµÄºöÂÔ¡¢ÅÓÊÏ´ú±ÒºÏÔ¼·ì϶¡¢SafeMathʹÓò»µ±µÈ³ÉÒòÈëÊÔìÊÎöºÚ¿Í¹¥»÷ÐÐΪ¡£


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾