¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190315

°ä²¼¹¦·ò 2019-03-15
1¡¢Wordpress CSRF·ì϶ £¬¿Éµ¼ÖÂÖ´ÐÐËÁÒâ´úÂë

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


RIPS×êÑÐÈËÔ±Simon Scannell·¢ÏÖWordpress 5.1ÖдæÔÚÒ»¸öCSRF·ì϶ £¬¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õßͨ¹ýºýÅªÍøÕ¾ÖÎÀíÔ±½Ó¼ûÔ̺¬·ì϶ÀûÓôúÂëµÄ¶ñÒâÍøÕ¾ £¬Äܹ»ÏòÖ¸±êWordPressÍøÕ¾×¢Èë´æ´¢ÐÍXSS payload £¬²¢ÀûÓøÃpayloadÆëÈ«½ÚÔì¸ÃÍøÕ¾¡£±¾ÖÜÈýWordPressÍŶӰ䲼ÁËа汾WordPress 5.1.1ÒÔ½¨¸´¸Ã·ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/hack-wordpress-websites.html

2¡¢Ë¼¿Æ°ä²¼°²È«¸üР£¬½¨¸´CSPCÈí¼þÖеĺóÃÅÕË»§·ì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


˼¿Æ½¨¸´ÁËͨ³£·þÎñÆ½Ì¨ÍøÂçÆ÷£¨CSPC£©Èí¼þÖеÄÒ»¸öºóÃÅÕË»§·ì϶ £¬¸Ã·ì϶£¨CVE-2019-1723£©Ô̺¬Ò»¸ö´øÓо²Ì¬ÃÜÂëµÄĬÈÏÕË»§ £¬¹ÌÈ»¸ÃÕË»§Ã»ÓÐÖÎÀíԱȨÏÞ £¬µ«Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶»ñµÃϵͳµÄ½Ó¼ûȨÏÞ¡£Æ¾¾Ý˼¿ÆµÄ˵·¨ £¬¸Ã·ì϶ӰÏìÁËCSPC°æ±¾2.7.2µ½2.7.4.5ÒÔ¼°ËùÓеÄ2.8.x°æ±¾ £¬²¢ÒÑÔÚ°æ±¾2.7.4.6ºÍ2.8.1.2Öеõ½½¨¸´¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82391/security/common-services-platform-collector-flaw.html

3¡¢°Í»ùË¹Ì¹ÒÆÃñ¾Ö¹ÙÍøÔâºÚ¿ÍÈëÇÖ £¬±»Ö²Èë¼üÅ̼ͼľÂí

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

°Í»ùË¹Ì¹ÒÆÃñÓ뻤ÕվֵĹÙÍøtracking.dgip.gov[.]pkÔâºÚ¿ÍÈëÇÖ £¬¹¥»÷ÕßÔÚÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔ¸ú×ÙÓû§¡£±»Ö²ÈëµÄpayloadÊÇScanBox £¬¸Ã±äÖÖÄܹ»ÍøÂçÍøÕ¾½Ó¼ûÕßµÄϵͳÐÅÏ¢²¢½øÐмüÅ̼ͼ¡£´Ë±í £¬¸Ã±äÖÖ»¹ÊÔͼ¼ì²â½Ó¼ûÕßÊÇ·ñ×°ÖÃÁËÌØ¶¨µÄ°²È«²úÆ·¡¢½âѹËõ¹¤¾ßºÍÐé¹¹»ú¹¤¾ßµÈ £¬Õâ¸öÁÐ±í³¤´ï77Ïî £¬¸ÃÐÐΪ¿ÉÄÜÊÇÕë¶ÔÌØ¶¨Ö¸±êȺÌåµÄË®¿Ó¹¥»÷µÄÒ»²¿ÃÅ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pakistani-government-site-compromised-logs-visitor-keystrokes/

4¡¢SteamÉÏ39£¥µÄCS 1.6·þÎñÆ÷ÏòÍæ¼Ò·Ö·¢BelonardľÂí

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÔÚDr.WebµÄÒ»·Ýл㱨ÖÐ £¬×êÑÐÈËÔ±·¢ÏÖSteam¹Ù·½¿Í»§¶ËÉϵÄÔ¼5000¸öCS 1.6·þÎñÆ÷ÖÐÓÐ1951¸ö·þÎñÆ÷£¨39%£©ÏòÍæ¼Ò·Ö·¢BelonardľÂí¡£¹¥»÷ÕßÀûÓÃÕâÖÖ·½Ê½´´½¨ÁËBelonard½©Ê¬ÍøÂç £¬µ±Íæ¼ÒÏνӵ½¶ñÒâ·þÎñÆ÷ʱ £¬Belonard½©Ê¬ÍøÂçÀûÓÃCS 1.6¿Í»§¶ËÖеÄRCE·ì϶½øÐÐϰȾ¡£ÓÉÓÚCS 1.6ÊÇValve°ä²¼µÄ¸ÃÓÎÏ·×îºóÒ»¸ö°æ±¾ £¬Òò¶ø¿Í»§¶ËÖеÄRCE·ì϶²»»áµÃµ½½¨¸´ £¬ËùÓÐÍæ¼Ò¶¼¿ÉÄܳÉΪDZÔÚµÄÊܺ¦Õß¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/39-percent-of-all-counter-strike-16-servers-used-to-infect-players/

5¡¢ÐÂCryptoSinkÍÚ¿ó¹¥»÷ £¬ÖØÒªÕë¶ÔElasticsearch·þÎñÆ÷

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


F5 Networks×êÑÐÍŶӷ¢ÏÖÒ»¸öÕë¶ÔElasticsearch·þÎñÆ÷µÄжñÒâ»î¶¯CryptoSink £¬¹¥»÷ÕßÀûÓÃ2014ÄêµÄ·ì϶£¨CVE-2014-3120£©À´´«²¼ÃÅÂޱҿ󹤡£ÔÚLinuxÉÏ £¬¹¥»÷ÕßʹÓÃÁËһЩÒÔǰδ֪µÄ¶ñÒâÈí¼þ£¨Ô̺¬ÏÂÔØ·¨Ê½ºÍľÂí£© £¬·À²¡¶¾½â¾ö¹æ»®ÎÞ·¨¼ì²âµ½ËüÃÇ¡£¹¥»÷Õß»¹»á½«ÆäËüÁ÷Á¿µ¼Èë127.1.1.1À´É±ËÀÆäËüµÄ¾ºÕù¿ó¹¤¡£ÆäÓµÓжà¸öC&C·þÎñÆ÷ £¬µ±Ç°»îÔ¾µÄC&C·þÎñÆ÷λÓÚÖйú¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.f5.com/labs/articles/threat-intelligence/-cryptosink--campaign-deploys-a-new-miner-malware

6¡¢PoS¶ñÒâÈí¼þDMSniff £¬×Ô2016ÄêÀ´Ò»Ö¹Øë¶ÔÖÐÓ×ÐÍÆóÒµ

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Flashpoint×êÑÐÍŶӷ¢ÏÖPoS¶ñÒâÈí¼þDMSniff×Ô2016ÄêÆðÍ·Ò»Ïò»îÔ¾ £¬ËüÖØÒªÕë¶ÔÖÐÓ×ÐÍÆóÒµ £¬Ô̺¬²Í¹Ý¡¢¾çÔºÒÔ¼°ÆäËüÓéÀÖ³¡ËùµÈ¡£DMSniffÖØÒªÇÔÊØÐÅÓþ¿¨Êý¾Ý £¬Ëü»á²»ÐÝä¯ÀÀ¹ý³ÌÁбí £¬²¢´ÓÄÚ´æÖнâÎöÐÅÓþ¿¨ºÅ £¬¶øºó½«ÕâЩÐÅÏ¢·¢ËÍÖÁC&C·þÎñÆ÷¡£DMSniff×Ô2016ÄêÒÔÀ´ÖÁÉÙʹÓùý11ÖÖDGAËã·¨±äÌå £¬ÕâÒâζ×ÅÆäÖÁÉÙ²¿Êð¹ý11¸ö°æ±¾¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dmsniff-point-of-sale-malware-silently-attacked-smbs-for-years/

ÉêÃ÷£º±¾×ÊѶÓɱ¦ÔËÀ³¹Ù·½ÍøÕ¾Î¬ËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù