¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190123

°ä²¼¹¦·ò 2019-01-23
1¡¢Linux°üÖÎÀíÆ÷apt/apt-getÔ¶³Ì´úÂëÖ´Ðзì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±Max Justicz·¢ÏÖLinux°üÖÎÀíÆ÷apt/apt-get´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¸Ã·ì϶£¨CVE-2019-3462£©ÔÊÐí¹¥»÷Õß½øÐÐÖÐÑëÈ˹¥»÷²¢»ñÈ¡rootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£¸Ã·ì϶µÄÆðÒòÊÇaptĬÈÏʹÓÃHTTPͨѶ £¬¶øÆätransport²½ÖèÖд¦ÖÃHTTP³Á¶¨ÏòµÄ´úÂëûÓÐÕýÈ·²é³­Ä³Ð©²ÎÊý £¬¹¥»÷Õß¿Éͨ¹ýÖÐÑëÈ˹¥»÷ʹÓÃαÔìÊðÃûÆ­¹ý¸Ã²é³­ £¬½ø¶øÔÚÓû§Ö÷»úÉÏ×°ÖÃËÁÒⷨʽ¡£ÓÉÓÚapt×ÔÉíÒѾ­»ñÈ¡ÁËrootȨÏÞ £¬¸Ã¶ñÒⷨʽ¿ÉÔÚrootȨÏÞÏÂÖ´ÐС£¸Ã·ì϶ӰÏìÁìÓò¼«Îª¿í·º £¬ËùÓÐʹÓÃÀϰ汾aptµÄÖ÷»ú¶¼Êܵ½Ó°Ïì¡£apt¿ª·¢ÈËÔ±ÒÑÔÚ°æ±¾1.4.9Öн¨¸´Á˸÷ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/linux-apt-http-hacking.html


2¡¢Check Point°ä²¼2019ÍøÂ簲ȫ»ã±¨ £¬³Áµã·ÖÎöÍøÂç¹¥»÷Ç÷Ïò

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



ÒÔÉ«Áа²È«³§ÉÌCheck Point°ä²¼2019ÍøÂ簲ȫ»ã±¨ £¬»ØÊ×ÁË2018ÄêµÄÍþвÇ÷Ïò £¬Ô̺¬´ó¹æÄ£Êý¾Ýй¶¡¢ÀÕË÷Èí¼þ¹¥»÷¡¢¶ñÒâÍÚ¿ó¹¥»÷ºÍAPT¹¥»÷µÈ¡£ÔÚ2018Äê £¬ÍøÂçÍþв¾ÖÊÆ¸ü¾ßÌôÕ½ÐÔ £¬¹¥»÷Õß²»ÐݸĽøÆäÍøÂç±øÆ÷¡¢Ñ¡È¡ÐµĹ¥»÷²½ÖèºÍÊÊÓ¦ÐÂÐ˼¼Êõ¡£2018ÄêµÄÍøÂç¹¥»÷Äܹ»±»¶¨ÐÔΪ¸ü¾ßÕë¶ÔÐÔ £¬ÆäÖ÷ÕÅÊÇÔì³É¸ü´óµÄ·ÛËé £¬Ô½À´Ô½¶àµÄ¹¥»÷Ôì³ÉÁËÕû¸ö×éÖ¯µÄ¹Ø¹Ø»ò¹ú¼ÊÊÂÎñµÄÇÖÈÅ¡£

  

Ô­ÎÄÁ´½Ó£º

https://blog.checkpoint.com/2019/01/21/threat-trends-analysis-report/


3¡¢ÐÂÀÕË÷Èí¼þPhobosÀûÓÃRDP·þÎñ´«²¼ £¬Õë¶ÔÈ«ÇòÆóÒµ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


CoveWare×êÑÐÈËÔ±·¢ÏÖÕë¶ÔÈ«ÇòÆóÒµµÄÐÂÀÕË÷Èí¼þPhobos £¬Phobos³öÏÖÓÚ2018Äê12Ô·Ý £¬²¢ÇÒÓëÀÕË÷Èí¼þDharma´æÔںܶàÀàËÆÖ®´¦¡£ÓëDharmaÒ»Ñù £¬PhobosÀûÓÃÊ¢¿ªµÄ»ò°²È«ÐԽϲîµÄRDP¶Ë¿Ú½øÐÐÈëÇÖ¡£±»¼ÓÃܵÄÎļþ»á±»Ôö³¤.phobosÀ©´óÃû¡£PhobosÒªÇóÒÔ±ÈÌØ±ÒµÄ·½Ê½Ö§¸¶Êê½ð £¬ÆäÀÕË÷µ¥¾ÝÉϵÄ×ÖÌåºÍÎı¾ÓëDharmaÆëȫһÑù¡£×êÑÐÈËÔ±»¹³ÆPhobosµÄ´ó²¿ÃÅ´úÂëÒ²ÓëDharmaÒ»Ö¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/new-phobos-ransomware-exploits-weak-security-to-hit-targets-around-the-world/


4¡¢ÀÕË÷Èí¼þSTOPбäÖÖRumba £¬ÖØÒªÍ¨¹ýµÁ°æÈí¼þ´«²¼

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÀÕË÷Èí¼þSTOPµÄбäÖÖRumbaÔÚ´Óǰ30ÌìÄÚ»ý¼«½øÐзַ¢ £¬¸Ã±äÌ彫.rumbaÀ©´óÃû¸½¼Óµ½¼ÓÃÜÎļþºó £¬ÖØÒª°ó¸¿ÔÚ¸æ°×Èí¼þ°üºÍÆÆ½â°æÈí¼þÖд«²¼¡£¾Ý±¨Â· £¬ÕâЩµÁ°æÈí¼þÔ̺¬Windows¼¤»î¹¤¾ß£¨ÀýÈçKMSPico£©¡¢Cubase¡¢PhotoshopÒÔ¼°ÆäËüÊ¢ÐÐÈí¼þµÄÆÆ½â°æµÈ¡£ºÃÐÂÎÅÊÇ £¬×êÑÐÍŶÓÒѾ­°ä²¼ÁËSTOPµÄÃâ·Ñ½âÃܹ¤¾ß £¬Êܵ½Ï°È¾µÄÓû§Äܹ»ÏÂÔØ¸Ã¹¤¾ß½øÐнâÃÜ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-rumba-stop-ransomware-being-installed-by-software-cracks/


5¡¢ÇàÄêѧÉú×éÖ¯AIESECÒâ±íй¶400¶àÍòʵϰÉúÉêÇëÊé


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



AIESECÊÇÒ»¼Ò·ÇͶ»úµÄÇàÄêѧÉú×éÖ¯ £¬1ÔÂ11ÈÕ×êÑÐÈËÔ±Bob Diachenko·¢ÏÖ¸Ã×éÖ¯µÄÒ»¸öElasticsearchÊý¾Ý¿âδÊܱ£»¤ £¬µ¼ÖÂ400¶àÍò·ÝʵϰÉúÉêÇëÊéй¶¡£ÕâЩÉêÇëÊéÔ̺¬ÉêÇëÈ˵ÄÐÕÃû¡¢ÐԱ𡢵®ÉúÈÕÆÚÒÔ¼°ÉêÇëÔ­ÒòµÈÓ×ÎÒÃô¸ÐÐÅÏ¢¡£AEISECÈ«Çò¸±×ܲÃLaurin Stahl֤ʵÁËÕâһй¶ÊÂÎñ £¬µ«Ðû³ÆÖ»Óв»µ½40ÃûÓû§Êܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://techcrunch.com/2019/01/21/aiesec-data-leak/


6¡¢ÃÀ¹ú¶à¼Ò´ò¶ÄÍøÕ¾Ð¹Â¶1.08ÒÚ´ò¶ÄÐÅÏ¢ £¬Ô̺¬Óû§Ö§¸¶Êý¾Ý

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾



¾ÝZDNet±¨Â· £¬°²È«×êÑÐÈËÔ±Justin Paine·¢ÏÖÒ»¸öÍøÂç´ò¶Ä¼¯ÍŵÄElasticSearch·þÎñÆ÷δÉèÃÜÂë £¬µ¼Ö³¬¹ý1.08ÒÚ´ò¶ÄÐÅϢй¶¡£¸Ã·þÎñÆ÷ÉÏй¶µÄÓû§ÐÅÏ¢Ô̺¬¿Í»§µÄÕæÊµÐÕÃû¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢µç×ÓÓʼþµØÖ·¡¢µ®ÉúÈÕÆÚ¡¢ÍøÕ¾Óû§Ãû¡¢ÕÊ»§Óà¶î¡¢IPµØÖ·¡¢ä¯ÀÀÆ÷ºÍ²Ù×÷ϵͳÐÅÏ¢ÒÔ¼°ÉϴεǼÐÅÏ¢µÈ¡£´Ë±í £¬Paine»¹·¢ÏÖ1.08ÒÚÌõ´ò¶ÄÐÅÏ¢ £¬ÆäÖÐÔ̺¬¿Í»§µÄ´æ¿î¡¢È¡¿îÒÔ¼°Ö§¸¶ÐÅÏ¢¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/online-casino-group-leaks-information-on-108-million-bets-including-user-details/


ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù