Windows¼Çʱ¾´úÂëÖ´Ðзì϶£»Docker¾ºÕùǰÌá·ì϶ £¬Ó°ÏìËùÓÐDocker°æ±¾£»DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷

°ä²¼¹¦·ò 2019-05-30
1Docker佨¸´µÄ¾ºÕùǰÌá·ì϶ £¬Ó°ÏìËùÓÐDocker°æ±¾


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±Åû¶DockerÖÐ佨¸´µÄ¾ºÕùǰÌá·ì϶ £¬¸Ã·ì϶ӰÏìÁËËùÓеÄDocker°æ±¾¡£¸Ã·ì϶ÀàËÆÓÚCVE-2018-15664 £¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶ £¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ £¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷¡£×êÑÐÈËÔ±ÒѾ­°ä²¼ÁËPoC´úÂë¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/

2DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷ £¬×°ÖÃÁ¿´ï500Íò´Î


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


°²È«×êÑÐÈËÔ±Dhiraj Mishra·¢ÏÖAndroid¿ªÔ´ä¯ÀÀÆ÷DuckDuckGo´æÔÚÒ»¸öURLºýŪ·ì϶£¨CVE-2019-12329£© £¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ºýŪÓû§ÏàÐŽӼûµÄÊÇ¿ÉÐÅÍøÕ¾¡£¸Ã·ì϶ÔÊÐíʹÓÃJavaScriptºýŪä¯ÀÀÆ÷µÄµØÖ·À¸ £¬Í¨¹ýsetIntervalº¯Êýÿ10µ½50ºÁÃë³ÁмÓÔØÒ»¸öURL¡£DuckDuckGo°²È«ÍŶÓÒÔΪ¸Ã·ì϶²»±ØÒª½¨¸´¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/duckduckgo-android-browser-vulnerable-to-url-spoofing-attacks/

3¹È¸è×êÑÐÈËÔ±ÔÚWindows¼Çʱ¾Öз¢ÏÖ´úÂëÖ´Ðзì϶

±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾

Google Project Zero×êÑÐÔ±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶ £¬OrmandyÒÑÏò΢Èí»ã±¨Á˸ÃÎÊÌâ¡£·ì϶µÄϸ½ÚÉÐδÅû¶ £¬µ«OrmandyÔ¤¼Æ¸Ã·ì϶ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶ £¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÈôºÎÔÚ¼Çʱ¾Öе¯³öshell¡£Æ¾¾Ý¹È¸èµÄ·ì϶Åû¶Õþ²ß £¬Ormandy½«ÔÚ90Ììºó»ò΢Èí°ä²¼½¨¸´²¹¶¡ºóÅû¶¸ü¶à·ì϶ϸ½Ú¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html

4жñÒâÍڿ󺣳±Nansh0u £¬ÒÑϰȾ5Íǫ̀·þÎñÆ÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ƾ¾ÝGuardicore LabsµÄ»ã±¨ £¬Ò»¸öеĶñÒâÍÚ¿ó»î¶¯Nansh0uÒѾ­Ï°È¾Á˶à´ï5Íǫ̀·þÎñÆ÷¡£¸ÃÍڿ󺣳±×Ô2ÔÂÒÔÀ´Ò»Ïò»îÔ¾ £¬Êܺ¦Õß´óÎÞÊýλÓÚÖйú¡¢ÃÀ¹úºÍÓ¡¶È £¬¹²¸²¸ÇÁË90¸ö¹ú¶È¡£Êܵ½¹¥»÷µÄÐÐÒµÔ̺¬Ò½ÁƱ£½¡¡¢µçÐÅ¡¢Ã½ÌåºÍITÁìÓò¡£Êܵ½Ï°È¾ºó £¬¹¥»÷Õß»áÔÚÖ¸±ê·þÎñÆ÷ÉÏ×°ÖüÓÃܿ󹤺ÍÄÚºËģʽrootkit £¬ÒÔÍÚ¾ò¿ªÔ´¼ÓÃÜÇ®±ÒTurtleCoin¡£ÔÚ4Ô·Ý £¬×êÑÐÈËÔ±¹Û²ìµ½Èý´ÎÀàËÆµÄ¹¥»÷ £¬ËùÓеÄÔ´IPµØÖ·¶¼À´×ÔÄÏ·Ç £¬ÇÒʹÓÃÒ»ÑùµÄ¹¥»÷¹ý³ÌºÍ¹¥»÷²½Öè¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/50k-servers-infected-with-cryptomining-malware-in-nansh0u-campaign/145140/

5ÐÂÎ÷À¼²ÆÕþ²¿ÔâºÚ¿ÍÈëÇÖ £¬²ÆÕþÔ¤ËãÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÐÂÎ÷À¼²ÆÕþ²¿³¤Gabriel Makhlouf°µÊ¾²ÆÕþ²¿ÒÑÈ·ÈÏÔâµ½ºÚ¿Í¹¥»÷ £¬²ÆÕþÔ¤ËãÐÅÏ¢¿ÉÄÜй¶¡£Makhlouf°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢ÓÐÈκÎÓ×ÎÒÐÅϢй¶¡£²ÆÕþ²¿ÒÑÆ¾¾Ý¹ú¶ÈÍøÂ簲ȫÖÐÐĵĽ¨Ò齫´ËÊ»㱨¸ø¾¯·½ £¬²¢Á¢¼´²ÉÈ¡´ëÊ©¼ÓÇ¿ËùÓÐÓëÔ¤ËãÓйصÄÐÅÏ¢µÄ°²È«ÐÔ £¬²ÆÕþ²¿»¹´òËã¶ÔÐÅÏ¢°²È«Á÷³Ì½øÐÐÈ«ÃæÉó²é¡£

 

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/new-zealand-treasury-hacked-and-budget-information-leaked-2fceb79b

6Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingÔâºÚ¿ÍÈëÇÖ £¬¿Í»§ÐÅϢй¶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingµÄÀñÎï¿¨ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ £¬µ¼Ö¿ͻ§Êý¾Ýй¶¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ID¡¢¼ÓÃܵÄÃÜÂë¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÀñÎ│¶©µ¥ºÅ £¬µ«²»Ô̺¬ÈκÎÒøÐп¨Ï¸½Ú»òÖ§¸¶ÐÅÏ¢¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ2019Äê5ÔÂ14ÈÕ £¬¸Ã¹«Ë¾ÒÑÏòÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¼°Æä¿Í»§´«µÝÁËй¶ÊÂÎñ £¬Ä¿Ç°ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Î´Öª¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/uk-pub-chain-greene-king-suffers-data-breach-following-hack-on-its-gift-card-website-1aec5c69