¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180703

Ðû²¼Ê±¼ä 2018-07-03

¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯


PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬ £¬£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬ £¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£¡£¡£¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£×î½ü£¬£¬ £¬£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÐµÄDiameterµç»°Ð­ÒéÓëSS7Ò»ÑùÒ×Êܹ¥»÷


Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬£¬ £¬£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä±ê×¼Ò»ÆðʹÓõÄDiameterЭÒéÈÝÒ×Êܵ½Óë¾ÉµÄµç»°±ê×¼£¨Èç3G£¬£¬ £¬£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7±ê×¼ÏàͬÀàÐ͵ÄÎó²îµÄ¹¥»÷£¬£¬ £¬£¬SS7ÊÇÔÚ20ÊÀ¼Í70ÄêÔ¿ª·¢µÄ£¬£¬ £¬£¬¿ìÒª¶þÊ®Äê֤ʵÆä±£´æ²»Çå¾²ÒòËØ¡£¡£¡£¡£¡£¡£¡£¡£ÕýÓÉÓÚÔÆÔÆ£¬£¬ £¬£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂç×îÏÈ£¬£¬ £¬£¬SS7±»DiameterЭÒéËùÈ¡´ú£¬£¬ £¬£¬DiameterЭÒéÊÇÒ»ÖÖˢеÄÍø¼äºÍÍøÄÚÐÅÁîЭÒ飬£¬ £¬£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G±ê×¼¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/


¡¾Çå¾²²¥±¨¡¿ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬ £¬£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£¡£¡£¡£¡£Ô­×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬ £¬£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬ £¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬ £¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/


¡¾Çå¾²²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ

FacebookÒѾ­ÈϿɣ¬£¬ £¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬ £¬£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬ £¬£¬FacebookÌåÏÖ£¬£¬ £¬£¬ËüÒѾ­ÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬ £¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html


¡¾Çå¾²²¥±¨¡¿ÈýÐDz¿·ÖϵÁÐÊÖ»ú±£´æbug£¬£¬ £¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË


×îа汾µÄÈýÐǶÌÐŶÌÐÅÓ¦ÓóÌÐò±£´æbug£¬£¬ £¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬ £¬£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬ £¬£¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬ £¬£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬ £¬£¬Óöµ½bugµÄÓû§Ëµ£¬£¬ £¬£¬ËûÃDz»ÖªµÀÊÖ»úÒѾ­·¢ËÍÁËÕÕÆ¬£¬£¬ £¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£¡£¡£¡£¡£Ö»Óе±ÕâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬ £¬£¬ËûÃDzŷ¢Ã÷¡£¡£¡£¡£¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÓ¦ÓóÌÐòÖ±µ½ÈýÐÇÐÞ¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/


¡¾Îó²î²¹¶¡¡¿VMwareÐû²¼Çå¾²¸üУ¬£¬ £¬£¬ÐÞ²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄÎó²î


VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬ £¬£¬ÆäÐÞ²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬ £¬£¬WorkstationºÍFusion²úÆ·ÖзºÆð¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¡£¡£¡£¡£¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓÃÇå¾²Îó²î»ñÊØÐÅÏ¢»òʹÐéÄâ»úÍ߽⡣¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²î±»ÁÐΪÖ÷Òª£¬£¬ £¬£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£¡£¡£¡£¡£Cisco TalosµÄÑо¿Ö°Ô±·¢Ã÷ÁËCVE-2018-6965¡£¡£¡£¡£¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱÏÝ»áÓ°ÏìÔÚÈÎºÎÆ½Ì¨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬ £¬£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬ £¬£¬²¢ÒÑÐû²¼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄÐÞ²¹³ÌÐòºÍ¸üС£¡£¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion