¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180723
Ðû²¼Ê±¼ä 2018-07-23¡¾ÍþвÇ鱨¡¿Ñо¿»ú¹¹ÖÒÑÔ³ÆÔ¼5ÒÚIoT×°±¸Ò×ÊÜDNSÖØÐ°󶨹¥»÷µÄÓ°Ïì
Armis¹«Ë¾ÖÒÑÔ³ÆÔ¼5ÒÚ¸öIoT×°±¸Ò×ÊÜDNSÖØÐ°󶨹¥»÷µÄÓ°Ïì¡£¡£¡£¡£¡£DNSÖØÐ°󶨹¥»÷ÊÇÖ¸¹¥»÷ÕßÓÕÆÓû§µÄä¯ÀÀÆ÷»ò×°±¸°ó¶¨ÖÁ¶ñÒâµÄDNSЧÀÍÆ÷µÄ¹¥»÷·½·¨¡£¡£¡£¡£¡£ArmisÆÊÎöÁËÕâÖÖ¹¥»÷¶ÔIoT×°±¸µÄÓ°Ï죬£¬£¬£¬£¬£¬£¬³ÆÏÕЩËùÓÐÀàÐ͵ÄÖÇÄÜ×°±¸¶¼Ò×ÊÜ´ËÀ๥»÷£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÖÇÄܵçÊÓ¡¢Â·ÓÉÆ÷¡¢´òÓ¡»ú¡¢¼àÊÓÆ÷¡¢IPµç»°µÈ¡£¡£¡£¡£¡£ÐÞ¸´ËùÓеÄ×°±¸¿ÉÄÜÊÇÒ»ÏîÎÞ·¨Íê³ÉµÄʹÃü£¬£¬£¬£¬£¬£¬£¬µ«½«IoT×°±¸¼¯³Éµ½Çå¾²¼à¿Ø²úÆ·ÖпÉÄÜÊÇ×î¼òÆÓÓÐÓõĽâ¾ö¼Æ»®¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/half-a-billion-iot-devices-vulnerable-to-dns-rebinding-attacks/
¡¾ÍþвÇ鱨¡¿Ñо¿ÍŶӷ¢Ã÷ÓÃÓÚ·Ö·¢FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯
ProofpointÑо¿ÍŶӷ¢Ã÷Ò»¸öÓÃÓÚÈö²¥FlawedAmmyy RATµÄ´ó¹æÄ£À¬»øÓʼþ»î¶¯¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸Ã»î¶¯±³ºóµÄ¹¥»÷ÕßÊÇ·¸·¨ÍÅ»ïTA505¡£¡£¡£¡£¡£´¹ÂÚÓʼþµÄ¸½¼þÊÇÒ»¸ö°üÀ¨¶ñÒâ.SettingContent-msÎļþµÄPDFÎļþ£¬£¬£¬£¬£¬£¬£¬µ±Óû§·¿ª´Ë¸½¼þʱ£¬£¬£¬£¬£¬£¬£¬½«Ö´ÐÐSettingContent-msÎļþµÄDeepLink±êÇ©ÖеÄPowerShellÏÂÁî¡£¡£¡£¡£¡£ÕâÖÖ¶ñÒâµÄSettingContent-msÎļþ¿ÉÒÔÈÆ¹ýWindows 10µÄÇå¾²»úÖÆ£¬£¬£¬£¬£¬£¬£¬ÀýÈçASR¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74639/hacking/settingcontent-ms-flawedammyy-rat.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÒ»³ÉÈËÍøÕ¾Õ©ÆÕßÔÚÒ»ÖÜÄÚÆÈ¡Áè¼Ý5ÍòÃÀÔª
Çå¾²Ñо¿Ö°Ô±SecGuru³ÆÒ»¸öʹÓóÉÈËÍøÕ¾¾ÙÐÐթƵĹ¥»÷ÕßÔÚÒ»ÖÜÄÚÆÈ¡ÁËÁè¼Ý5ÍòÃÀÔª¡£¡£¡£¡£¡£¸Ã¹¥»÷ÕßÏòÓû§·¢Óʼþ³ÆÆäÈëÇÖÁËÒ»¸ö³ÉÈËÍøÕ¾£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÔÚÓû§»á¼û´ËÍøÕ¾Ê±Í¨¹ý¶ñÒâÈí¼þѬȾÁËÓû§µÄÅÌËã»úºÍÅÄÉãÁËÊÓÆµ¡£¡£¡£¡£¡£µ«ÏÖʵÉÏÕâÖ»ÊÇÒ»ÖÖÚ²ÆÐÐΪ£¬£¬£¬£¬£¬£¬£¬²¢Ã»ÓжñÒâÈí¼þ±»ÏÖʵװÖᣡ£¡£¡£¡£SecGuru¼ì²éÁËÕ©ÆÕßµÄ42¸ö±ÈÌØ±ÒµØµã£¬£¬£¬£¬£¬£¬£¬·¢Ã÷30ÃûÊܺ¦ÕßÒѾ֧¸¶ÁËÊê½ð£¬£¬£¬£¬£¬£¬£¬×ܼÆÁè¼Ý5ÍòÃÀÔª¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/adult-site-blackmail-spammers-made-over-50k-in-one-week/
¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±·¢Ã÷΢ÈíTranslator Hub±£´æÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂËùÓÐÏîÄ¿±»É¾³ý
΢ÈíÐÞ¸´ÁËMicrosoft Translator HubÖеÄÒ»¸öÑÏÖØÎó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²î¿É±»¹¥»÷ÕßʹÓÃÒÔɾ³ý¸ÃЧÀÍÉÏÍйܵÄÈκÎÏîÄ¿¡£¡£¡£¡£¡£Microsoft Translator Hub¿ÉÒÔ×ÊÖúÆóÒµºÍÉçÇø¹¹½¨¡¢ÑµÁ·ºÍ°²ÅŶ¨ÖÆ»¯µÄ×Ô¶¯ÓïÑÔ·Òëϵͳ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±Haider MahmoodÔÚ2018Äê2ÔÂβ·¢Ã÷Á˸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬Mahmood³Æ¹¥»÷Õß¿Éͨ¹ýÐÞ¸ÄHTTPÇëÇóÖеIJÎÊýprojectidÀ´É¾³ýí§ÒâµÄÏîÄ¿¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74633/security/microsoft-translator-hub-flaw.html
¡¾Îó²î²¹¶¡¡¿Ñо¿ÍŶÓÅû¶Ë÷ÄáIPELA EÏà»úÖеĶà¸öÇå¾²Îó²î
˼¿ÆTalosÑо¿ÍŶÓÅû¶Ë÷ÄáIPELA EϵÁÐÏà»úÖеĶà¸öÇå¾²Îó²î¡£¡£¡£¡£¡£¸ÃÏà»úµÄmeasurementBitrateExecÒªÁìÖеÄÏÂÁî×¢ÈëÎó²î£¨CVE-2018-3937£©£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâGETÇëÇó´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂí§ÒâÏÂÁîÖ´ÐС£¡£¡£¡£¡£¸ÃÏà»úµÄ802dot1xclientcert.cgi±£´æ»º³åÇøÒç³öÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¶ñÒâPOSTÇëÇó´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ°æ±¾ÊÇIPELA EϵÁÐG5¹Ì¼þ1.87.00£¬£¬£¬£¬£¬£¬£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/07/sony-ipela-vulnerability-spotlight-multiple.html
¡¾Çå¾²²¥±¨¡¿Ñо¿Ö°Ô±³ÆÎ¢ÈíEdgeä¯ÀÀÆ÷ÖеÄXSS Filter·ºÆðbug
PortSwiggerµÄÇå¾²Ñо¿Ö°Ô±Gareth Heyes³ÆÎ¢ÈíµÄEdgeä¯ÀÀÆ÷Öи½´øµÄXSS FilterÇå¾²¹¦Ð§Ëƺõ·ºÆð¹ÊÕÏ¡£¡£¡£¡£¡£XSS FilterÓÃÓÚ×èÖ¹ä¯ÀÀÆ÷ÄÚ²¿µÄXSS¹¥»÷£¬£¬£¬£¬£¬£¬£¬¸Ã¹¦Ð§ÔÚĬÈÏÇéÐÎÏÂÆôÓᣡ£¡£¡£¡£µ«Heyes·¢Ã÷EdgeÖÐĬÈÏÇéÐÎϸù¦Ð§´¦ÓڹرÕ״̬£¬£¬£¬£¬£¬£¬£¬×ÝȻͨ¹ýX-XSS-Protection: 1ÏÂÁîÒ²ÎÞ·¨ÆôÓøù¦Ð§£¬£¬£¬£¬£¬£¬£¬¶øÔÚIEÖиù¦Ð§´¦ÓÚÕý³£×´Ì¬¡£¡£¡£¡£¡£Î¢Èí»òEdgeÍŶÓûÓÐÐû²¼Èκιٷ½ÉùÃ÷£¬£¬£¬£¬£¬£¬£¬Òò´ËÕâ¿ÉÄÜÊÇÒ»¸öbug¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/microsoft-edges-xss-filter-appears-to-be-broken/


¾©¹«Íø°²±¸11010802024551ºÅ