¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181101

Ðû²¼Ê±¼ä 2018-11-01
1¡¢¹«°²»ú¹Ø»¥ÁªÍøÇå¾²¼àÊÓ¼ì²é»®¶¨½ñÈÕ×îÏÈÖ´ÐÐ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¡¶¹«°²»ú¹Ø»¥ÁªÍøÇå¾²¼àÊÓ¼ì²é»®¶¨¡·ÒѾ­ÓÚ2018Äê9ÔÂ5ÈÕ¹«°²²¿²¿³¤°ì¹«¾Û»áͨ¹ý£¬£¬£¬£¬£¬ £¬£¬£¬×Ô2018Äê11ÔÂ1ÈÕÆðÊ©ÐÐ ¡£¡£¡£¡£±¾»®¶¨ÊÊÓÃÓÚ¹«°²»ú¹ØÒÀ·¨¶Ô»¥ÁªÍøÐ§ÀÍÌṩÕߺÍÁªÍøÊ¹Óõ¥Î»ÍÆÐÐÖ´·¨¡¢ÐÐÕþ¹æÔò»®¶¨µÄÍøÂçÇå¾²ÒåÎñÇéÐξÙÐеÄÇå¾²¼àÊÓ¼ì²é ¡£¡£¡£¡£»£»£»£»£»£» £»£»¥ÁªÍøÇå¾²¼àÊÓ¼ì²éÊÂÇéÓÉÏØ¼¶ÒÔÉϵط½ÈËÃñÕþ¸®¹«°²»ú¹ØÍøÂçÇå¾²ÊØÎÀ²¿·Ö×é֯ʵÑé ¡£¡£¡£¡£¹«°²»ú¹Ø¶Ô»¥ÁªÍøÇå¾²¼àÊÓ¼ì²éÊÂÇéÖз¢Ã÷µÄ¿ÉÄÜΣº¦¹ú¼ÒÇå¾²¡¢¹«¹²Çå¾²¡¢Éç»áÖÈÐòµÄÍøÂçÇ徲Σº¦£¬£¬£¬£¬£¬ £¬£¬£¬Ó¦µ±ÊµÊ±×ª´ïÓйØÖ÷¹Ü²¿·ÖºÍµ¥Î» ¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.mps.gov.cn/n2254314/n2254409/n4904353/c6263180/content.html


2¡¢Ñо¿ÍŶÓÐû²¼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¿¨°Í˹»ùÐû²¼2018ÄêµÚÈý¼¾¶ÈDDoS¹¥»÷Ç÷ÊÆµÄÆÊÎö±¨¸æ£¬£¬£¬£¬£¬ £¬£¬£¬±¨¸æµÄÖ÷Òª·¢Ã÷°üÀ¨£ºÍ¨¹ý½©Ê¬ÍøÂçÌᳫµÄDDoS¹¥»÷ÊýÄ¿ÔÚ8Ô·ݵִïá۷壬£¬£¬£¬£¬ £¬£¬£¬×îµÍ¹È·ºÆðÔÚ7Ô³õ£»£»£»£»£»£» £»£»Ò»Á¬ÐÔDDoS¹¥»÷µÄÊýÄ¿ÓÐËùϽµ£¬£¬£¬£¬£¬ £¬£¬£¬È»¶øÒ»Á¬Ê±¼ä¶ÌÓÚ4СʱµÄ¹¥»÷ÔöÌíÁË17.5¸ö°Ù·Öµã£¬£¬£¬£¬£¬ £¬£¬£¬´ï86.94%£»£»£»£»£»£» £»£»SYN·ººé¹¥»÷ÈÔÈ»ÅÅÔÚµÚһ루83.2%£©£»£»£»£»£»£» £»£»ÖйúÈÔÈ»Êǹ¥»÷ÊýÄ¿×î¶àµÄµØÇø£¨78%£© ¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/ddos-report-in-q3-2018/88617/


3¡¢Windows 10ÐÂÎó²îÔÊÐíUWPÓ¦Óûá¼ûËùÓÐÎļþϵͳ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ͨÓÃWindowsƽ̨£¨UWP£©Ó¦ÓÃÔÊÐíÓ¦ÓóÌÐòÔÚÈκÎWindows 10×°±¸ÉÏÔËÐУ¬£¬£¬£¬£¬ £¬£¬£¬°üÀ¨Ì¨Ê½»ú¡¢Xbox¡¢ÎïÁªÍø×°±¸ºÍSurface HubµÈ ¡£¡£¡£¡£Î¢ÈíΪUWPÓ¦ÓÃÌṩÁËÒ»¸öAPIÀ´»á¼ûÎļþϵͳ£¬£¬£¬£¬£¬ £¬£¬£¬Õý³£ÇéÐÎϸÃAPI»áµ¯³ö¶Ô»°¿òÉêÇëÓû§µÄȨÏÞÔÊÐí£¬£¬£¬£¬£¬ £¬£¬£¬µ«Ñо¿Ö°Ô±·¢Ã÷¸ÃAPI±£´æÖÂÃüÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬¶ñÒâµÄUWPÓ¦ÓÿÉÈÆ¹ýÓû§µÄȨÏÞÇëÇó»á¼ûÍêÕûµÄÎļþϵͳ ¡£¡£¡£¡£Î¢ÈíÒѾ­ÔÚWindows 10°æ±¾1809ÖÐÐÞ¸´Á˸ÃÎó²î ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/windows10-uwp-apps.html


4¡¢Ñо¿Ö°Ô±ÔÚÐÂÐû²¼µÄiOS 12.1Öз¢Ã÷ÃÜÂëÈÆ¹ýÎó²î


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÔÚAppleÐû²¼iOS 12.1µÄ¼¸¸öСʱÄÚ£¬£¬£¬£¬£¬ £¬£¬£¬Î÷°àÑÀÑо¿Ö°Ô±Jose Rodriguez·¢Ã÷ÁËÒ»¸öеÄÃÜÂëÈÆ¹ýÎó²î ¡£¡£¡£¡£¸ÃÎó²îÓëiOS 12.1ÖеÄй¦Ð§Group FaceTimeÓйØ£¬£¬£¬£¬£¬ £¬£¬£¬Ñо¿Ö°Ô±Åû¶ÁËÏà¹ØPoCÊÓÆµ ¡£¡£¡£¡£¸ÃÎó²îËÆºõÊÊÓÃÓÚËùÓеÄiPhoneÐͺÅ£¬£¬£¬£¬£¬ £¬£¬£¬°üÀ¨iPhone XºÍXS ¡£¡£¡£¡£ÓÉÓÚÏÖÔÚûÓÐÔÝʱ½â¾ö¸ÃÎÊÌâµÄworkaround£¬£¬£¬£¬£¬ £¬£¬£¬½¨ÒéÓû§ÆÚ´ýAppleµÄ¸üР¡£¡£¡£¡£ÕâÒѾ­ÊÇRodriguez½üÆÚµÚÈý´ÎѸËÙ·¢Ã÷iOS 12ÖеÄÃÜÂëÈÆ¹ýÎó²îÁË ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/10/iphone-ios-passcode-bypass.html


5¡¢Ë¼¿ÆÅû¶ASAºÍFTD²úÆ·ÖеÄÐÂ0day£¬£¬£¬£¬£¬ £¬£¬£¬¿Éµ¼Ö¾ܾøÐ§ÀÍ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


˼¿ÆÇå¾²ÍŶÓÅû¶Æä×Ô˳ӦÇå¾²×°±¸£¨ASA£©ºÍFirepowerÍþв·ÀÓùÈí¼þ£¨FTD£©ÖеĻỰ³õʼ»¯Ð­Ò飨SIP£©¼ì²éÒýÇæ±£´æÒ»¸ö¿Éµ¼Ö¾ܾøÐ§À͵ÄÁãÈÕÎó²î ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý·¢ËͶñÒâSIPÇëÇóÀ´´¥·¢¸ÃÎó²î£¬£¬£¬£¬£¬ £¬£¬£¬µ¼ÖÂDoS ¡£¡£¡£¡£¸ÃÎó²î£¨CVE-2018-15454£©Ó°ÏìÔËÐÐASA 9.4+ºÍFTD 6.0+µÄ×°±¸£¬£¬£¬£¬£¬ £¬£¬£¬°üÀ¨¶à¸öÐͺŵĹ¤ÒµÇå¾²×°±¸ºÍ·À»ðǽµÈ²úÆ· ¡£¡£¡£¡£ÏÖÔÚ»¹Ã»ÓиÃÎó²îµÄÐÞ¸´²¹¶¡ºÍworkaround£¬£¬£¬£¬£¬ £¬£¬£¬µ«¿ÉÒÔ½ÓÄÉһЩ»º½â²½·¥×èÖ¹Ô¶³Ì¹¥»÷Õ߯ÆËðÆä×°±¸ ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181031-asaftd-sip-dos


6¡¢Ñо¿»ú¹¹Ðû²¼¹ØÓÚÀÕË÷Èí¼þ¼´Ð§ÀÍKraken CryptorµÄÆÊÎö±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Insikt GroupÓëMcAfeeÅäºÏÐû²¼¹ØÓÚÀÕË÷Èí¼þKraken CryptorµÄÆÊÎö±¨¸æ ¡£¡£¡£¡£KrakenÓÚ2018Äê8ÔÂÊ×´ÎÔÚÒ°Íâ·ºÆð£¬£¬£¬£¬£¬ £¬£¬£¬ÓÉ»îÔ¾ÔÚ¶íÂÞ˹·¸·¨ÂÛ̳ÉϵÄÍÅ»ïThisWasKraken¾ÙÐзַ¢ ¡£¡£¡£¡£KrakenÊÇÒ»¸öÀÕË÷Èí¼þ¼´Ð§ÀÍ£¨RaaS£©µÄ»áÔ±ÖÆÏúÊÛÍýÏ룬£¬£¬£¬£¬ £¬£¬£¬ÓÉThisWasKrakenÈÏտı»®£¬£¬£¬£¬£¬ £¬£¬£¬ÆäÖ÷Òª·Ö·¢·½·¨ÊÇFallout EK ¡£¡£¡£¡£Ñо¿Ö°Ô±»¹·¢Ã÷ThisWasKrakenʹÓÃÔÚÏ߶ij¡BitcoinPenguinÀ´Ï´Ç® ¡£¡£¡£¡£Insikt GroupÐÅÐÄÊ®×ãµØÒÔΪThisWasKrakenÍŶӵijÉÔ±ÆÜÉíÔÚÒÁÀÊ¡¢°ÍÎ÷»òǰËÕÁª¹ú¼Ò ¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.recordedfuture.com/kraken-cryptor-ransomware/


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí