¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190117
Ðû²¼Ê±¼ä 2019-01-17
ÒÔÉ«ÁÐÇå¾²Ñо¿Ô±Noam Rotem·¢Ã÷»úƱԤ¶©ÏµÍ³Amadeus±£´æÒ»¸öÑÏÖØµÄÇå¾²Îó²î£¬£¬£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶ºÍÕË»§¸ü¸Ä¡£¡£¡£RotemÔÚÒÔÉ«Áк½¿Õ¹«Ë¾ELALÔ¤¶©»úƱʱ·¢Ã÷ÁËÕâÒ»ÎÊÌ⣬£¬£¬£¬£¬ÔÚÔ¤¶©º½°àºó£¬£¬£¬£¬£¬ÓοͻáÊÕµ½PNRºÅÂëºÍÓÃÓÚÉó²éÔ¤¶©ÐÅÏ¢µÄÁ´½Ó¡£¡£¡£Rotem·¢Ã÷ͨ¹ý½«¸ÃÁ´½ÓÉϵÄRULE_SOURCE_1_ID²ÎÊýÐÞ¸ÄΪÆäËüÈ˵ÄPNRºÅÂë¼´¿ÉÉó²éËûÈ˵ÄÔ¤¶©ÐÅÏ¢£¬£¬£¬£¬£¬¹¥»÷Õß»¹¿ÉʹÓÃÕâЩÐÅÏ¢»á¼ûELALÃÅ»§ÍøÕ¾²¢¸ü¸ÄÊܺ¦ÕßµÄÕË»§ÐÅÏ¢£¬£¬£¬£¬£¬°üÀ¨¶Ò»»Àï³Ì¡¢¸ü¸ÄÓʼþµØµãºÍµç»°ºÅÂëµÈ¡£¡£¡£ÓÉÓÚAmadeus¿ª·¢µÄ»úƱԤ¶©ÏµÍ³±»È«ÇòÖÁÉÙ141¼Òº½¿Õ¹«Ë¾Ê¹Ó㨰üÀ¨ÃÀ¹úÁªºÏº½¿Õ¹«Ë¾¡¢µÂ¹úººÉ¯º½¿Õ¹«Ë¾ºÍ¼ÓÄô󺽿չ«Ë¾µÈ£©£¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²î¿ÉÄÜÓ°ÏìÁËÊýÒÚÓο͡£¡£¡£ÏÖÔÚAmadeusÒѾÐÞ¸´Á˸ÃÎÊÌâ¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/airlines-flight-hacking.html2¡¢OVH¡¢DreamhostµÈÎå´óÍйÜЧÀÍÉ̱£´æ¶à¸öÇå¾²Îó²î
Çå¾²Ñо¿Ö°Ô±Paulos Yibelo·¢Ã÷È«ÇòÎå´óÍйÜЧÀÍÉÌ£¨Bluehost¡¢Dreamhost¡¢HostGator¡¢OVHºÍiPage£©±£´æ¶à¸öÇå¾²Îó²î£¬£¬£¬£¬£¬Ê¹µÃËüÃǵĿͻ§ºÍÍйܵÄÍøÕ¾ÃæÁٺڿ͹¥»÷µÄΣº¦¡£¡£¡£ÕâЩЧÀÍÉÌ»òÐíÍйÜÁË700Íò¸öÍøÕ¾¡£¡£¡£Yibelo¹²·¢Ã÷ÁËÔ¼12¸öÎó²î£¬£¬£¬£¬£¬°üÀ¨CORSÉèÖò»µ±µ¼ÖµÄÐÅϢй¶¡¢ÕË»§½ÓÊÜ¡¢ÖÐÐÄÈ˹¥»÷¡¢XSS¡¢APIÉèÖùýʧºÍCSPÈÆ¹ýµÈ¡£¡£¡£YibeloÏòÕâЩЧÀÍÉ̱¨¸æÁËËûµÄÊÓ²ìЧ¹û£¬£¬£¬£¬£¬ÏÖÔÚ³ýÁËOVHÉÐδ¾ÙÐлØÓ¦Ö®Í⣬£¬£¬£¬£¬ÆäËüЧÀÍÉÌÒѾÐÞ¸´ÁËÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/web-hosting-server-security.html3¡¢Ñо¿ÍŶÓÅû¶¥Óî×Ô¶¯»¯ÏµÍ³BASÖеÄ6¸ö0day
ForeScoutÑо¿ÍŶӷ¢Ã÷Â¥Óî×Ô¶¯»¯ÏµÍ³£¨BAS£©ÖеÄ6¸ö0day¡£¡£¡£ÕâЩÎó²î±£´æÓÚBASµÄPLCºÍÍø¹ØÐÒéµÈ×é¼þÖУ¬£¬£¬£¬£¬Îó²î¹æÄ£°üÀ¨XSS¡¢Â·¾¶±éÀú¡¢í§ÒâÎļþɾ³ýºÍÉí·ÝÑéÖ¤ÈÆ¹ý£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÕâЩÎó²îÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢»á¼û»òɾ³ýÒªº¦ÎļþºÍÖ´ÐжñÒâ²Ù×÷µÈ¡£¡£¡£Ñо¿Ö°Ô±Í¨¹ýShodanºÍCensys·¢Ã÷ÁËÁè¼Ý9000¸öÒ×Êܹ¥»÷µÄ×°±¸£¬£¬£¬£¬£¬±ðµÄÉÐÓÐÁè¼Ý1Íò¸öIPÉãÏñ»úÒ×Êܹ¥»÷¡£¡£¡£BASϵͳ²»µ«ÓÃÓÚסլºÍÉÌÒµÐÞ½¨ÖУ¬£¬£¬£¬£¬»¹±£´æÓÚÒ½Ôº¡¢»ú³¡¡¢Ñ§Ð£ºÍÊý¾ÝÖÐÐĵȡ£¡£¡£½¨ÒéÓû§¾¡¿ì×°ÖÃÐÞ¸´²¹¶¡¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/zero-day-vulnerabilities-leave-smart-buildings-open-to-cyber-attacks/4¡¢±¤ÀÝÖ®Ò¹¶à¸öÎó²î¿ÉÔÊÐí¹¥»÷Õß½ÓÊÜÍæ¼ÒÕË»§
Check PointÑо¿Ö°Ô±·¢Ã÷Fortnite£¨±¤ÀÝÖ®Ò¹£©ÖеĶà¸öÇå¾²Îó²î£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÎó²î¿Éµ¼ÖÂÔ¶³Ì¹¥»÷ÕßÍêÈ«½ÓÊÜÍæ¼ÒµÄÕ˺𣡣¡£Æ¾Ö¤Ñо¿Ö°Ô±µÄ˵·¨£¬£¬£¬£¬£¬Îó²îµÄ¹æÄ£°üÀ¨SQL×¢Èë¡¢XSS¡¢WAFÈÆ¹ýÒÔ¼°ÕË»§½ÓÊÜ¡£¡£¡£Ñо¿Ö°Ô±³ÆEpic Games×ÓÓòÉϵÄxssºÍ¶ñÒâÖØ¶¨ÏòÎÊÌâÔÊÐí¹¥»÷Õßͨ¹ýÓÕÆÓû§µã»÷¶ñÒâÁ´½ÓÀ´ÇÔÈ¡Óû§µÄÉí·ÝÑéÖ¤ÁîÅÆ¡£¡£¡£FortniteÔÚÈ«ÇòÓµÓÐ8000ÍòÍæ¼Ò£¬£¬£¬£¬£¬ÕâЩÓû§¶¼¿ÉÄÜÊܵ½Ó°Ïì¡£¡£¡£Epic GamesÒÑÔÚ2018Äê12ÔÂÖÐÑ®ÐÞ¸´ÁËÕâЩÎó²î¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/fortnite-account-hacked.html5¡¢VoIPЧÀÍÉÌVOIPOÒâÍâй¶ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý
Ñо¿Ö°Ô±Justin Paineͨ¹ýShodan·¢Ã÷Ò»¸ö¿É¹ûÕæ»á¼ûµÄElasticSearchÊý¾Ý¿â£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿âÊôÓÚVoIPЧÀÍÉÌVOIPO£¬£¬£¬£¬£¬ÆäÖаüÀ¨Á˸ù«Ë¾ÒÑÍùËÄÄêµÄ¿Í»§Êý¾Ý¡£¡£¡£Æ¾Ö¤PaineµÄ˵·¨£¬£¬£¬£¬£¬¸ÃÊý¾Ý¿â°üÀ¨¿É×·ËÝÖÁ2017Äê7ÔµÄ670ÍòÌõͨ»°¼Í¼¡¢¿É×·ËÝÖÁ2015Äê12ÔµÄ600ÍòÌõ¶ÌÐÅ/²ÊÐÅÈÕÖ¾ÒÔ¼°100ÍòÌõ°üÀ¨ÄÚ²¿ÏµÍ³API KEYµÄÈÕÖ¾¡£¡£¡£Ñо¿Ö°Ô±ÓÚ1ÔÂ8ÈÕÏòVOIPOת´ïÁËÕâÒ»·¢Ã÷£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚͳһÌ콫Êý¾Ý¿â¾ÙÐÐÁËÍÑ»ú±£»£»£»£»£»£»¤¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/voip-service-database-hacking.html6¡¢Magecart Group 12ͨ¹ý¹©Ó¦Á´¹¥»÷ѬȾ277¸öµç×ÓÉÌÎñÍøÕ¾
ƾ֤RiskIQºÍÇ÷ÊÆ¿Æ¼¼µÄ±¨¸æ£¬£¬£¬£¬£¬Ò»¸öеÄMagecart·¸·¨ÍŻMagecart Group 12£©Í¨¹ý¹©Ó¦Á´¹¥»÷ÀÖ³ÉѬȾÁ˽ü277¸öµç×ÓÉÌÎñÍøÕ¾¡£¡£¡£Ôâµ½Magecart Group 12¹¥»÷µÄÊÇ·¨¹úÔÚÏß¹ã¸æ¹«Ë¾AdverlineÌṩµÄJavaScript¿â¡£¡£¡£Å·ÖÞÊý°Ù¸öµç×ÓÉÌÎñÍøÕ¾¶¼Ê¹ÓÃAdverlineµÄЧÀÍÀ´Õ¹Ê¾¹ã¸æ¡£¡£¡£ÔÚ½Óµ½Í¨Öªºó£¬£¬£¬£¬£¬AdverlineÁ¬Ã¦´ÓÆäJavaScript¿âÖÐɾ³ýÁ˶ñÒâ´úÂë¡£¡£¡£Ñо¿Ö°Ô±ÔÚ±¨¸æÖл¹Ðû²¼ÁËÓëMagecart Group 12Ïà¹ØµÄIoC¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/magecart-hacking-credit-cards.htmlÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ