¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20190129

Ðû²¼Ê±¼ä 2019-01-29
1¡¢Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾ÖENISAÐû²¼2018ÄêÍøÂçÍþв¾°¹Û±¨¸æ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Å·ÖÞÍøÂçÐÅÏ¢Çå¾²¾Ö£¨ENISA£©Ðû²¼2018ÄêÍþв¾°¹Û±¨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬¸Ã±¨¸æÖصãÏÈÈÝÁË2018ÄêµÄÍøÂçÍþвÇ÷ÊÆ×ª±ä£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨µç×ÓÓʼþºÍ´¹ÂÚ¶ÌÐÅÒѾ­³ÉΪÖ÷ÒªµÄ¶ñÒâÈí¼þѬȾǰÑÔ£»£»£»¶ñÒâ¿ó¹¤³ÉΪ·¸·¨·Ö×ÓµÄÖ÷Ҫ׬ǮÊֶΣ»£»£»¹ú¼Ò×ÊÖúµÄ·¸·¨ÍÅ»ïÔ½À´Ô½¶àµØÃé×¼ÒøÐУ»£»£»ÓÉÓÚȱ°±ÉͶËÎïÁªÍø×°±¸ºÍЧÀ͵ı£»£»£»¤»úÖÆ£¬ £¬£¬£¬£¬£¬£¬£¬¶ÔͨÓÃÎïÁªÍø±£»£»£»¤¼Ü¹¹/ÓÅÒìʵ¼ùµÄÐèÇóÈÔÈ»ÊÇÒ»¸ö½ôÆÈµÄÎÊÌ⣻£»£»ÍþвÇ鱨ÐèҪʹÓÃеÄ×Ô¶¯»¯¹¤¾ßºÍÒªÁìÀ´Ó¦¶Ô×Ô¶¯»¯µÄ¹¥»÷£»£»£»Çå¾²ÁìÓòÓ¦¸ÃÖØµã¹Ø×¢È˲źÍÊÖÒÕµÄÅàѵ¡£¡£¡£¡£¡£¸Ã±¨¸æ»¹´ÓÕþ²ß¡¢ÆóÒµÒÔ¼°ÊÖÒÕ¡¢Ñо¿ºÍ½ÌÓý·½ÃæÌá³öÁ˽¨Òé¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.enisa.europa.eu/publications/enisa-threat-landscape-report-2018/


2¡¢LocalBitcoinsµÚÈý·½Èí¼þÇå¾²Îó²î£¬ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ2.8ÍòÃÀÔª±ÈÌØ±Ò±»ÇÔ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


¼ÓÃÜÇ®±ÒÉúÒâËùLocalBitcoinsÔâµ½´¹ÂÚ¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß½«Óû§Öض¨Ïòµ½´¹ÂÚÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬£¬ÇÔÈ¡Óû§µÄLocalBitcoinsµÇ¼ƾ֤£¬ £¬£¬£¬£¬£¬£¬£¬Ëæºó´ÓÁù¸öÕË»§ÖÐÇÔÈ¡ÁËÔ¼8¸ö±ÈÌØ±Ò£¨¼ÛÖµÔ¼2.8ÍòÃÀÔª£©¡£¡£¡£¡£¡£LocalBitcoinsÔÚ1ÔÂ26ÈÕ·¢Ã÷ÁËÕâÒ»ÊÂÎñ£¬ £¬£¬£¬£¬£¬£¬£¬²¢×èÖ¹ÁËÆ½Ì¨ÉϵÄËùÓÐÉúÒâÒÔ×èÖ¹½øÒ»²½µÄ¹¥»÷¡£¡£¡£¡£¡£Æ¾Ö¤LocalBitcoinsµÄÊӲ챨¸æ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñÓëµÚÈý·½Èí¼þÖеÄÇå¾²Îó²îÓйء£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/localbitcoins-blames-security-breach-on-forum-third-party-software/


3¡¢¹¥»÷ÕßÃé׼˼¿ÆRV320/RV325·ÓÉÆ÷£¬ £¬£¬£¬£¬£¬£¬£¬Áè¼Ý9ǧ̨װ±¸ÔÚÏß̻¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÔÚÑо¿Ö°Ô±Ðû²¼ÁËÁ½¸öÐÂÎó²îµÄPoC´úÂëºó£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÕýÔÚÆð¾¢Ê¹ÓÃÕâÁ½¸öÎó²îÃé׼˼¿ÆRV320/RV325·ÓÉÆ÷¡£¡£¡£¡£¡£ÕâÁ½¸öÎó²î»®·ÖÊÇÏÂÁî×¢ÈëÎó²î£¨CVE-2019-1652£©ºÍÐÅϢй¶Îó²î£¨CVE-2019-1653£©£¬ £¬£¬£¬£¬£¬£¬£¬µÚÒ»¸öÎó²îÓ°ÏìÁ˹̼þ°æ±¾1.4.2.15µ½1.4.2.19µÄ×°±¸£¬ £¬£¬£¬£¬£¬£¬£¬µÚ¶þ¸öÎó²îÓ°ÏìÁ˹̼þ°æ±¾1.4.2.15ºÍ1.4.2.17¡£¡£¡£¡£¡£Bad PacketsµÄÑо¿Ö°Ô±ÌåÏÖ£¬ £¬£¬£¬£¬£¬£¬£¬ËûÃÇ·¢Ã÷È«ÇòÖÁÉÙÓÐ9657¸ö˼¿ÆÂ·ÓÉÆ÷£¨°üÀ¨6247¸öRV320ºÍ3410¸öRV325£©ÔÚÏß̻¶£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖд󲿷ÖλÓÚÃÀ¹ú¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/01/hacking-cisco-routers.html


4¡¢ÊÓÆµ·ÖÏíÆ½Ì¨DailyMotionÔâײ¿â¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬²¿·ÖÓû§Êܵ½Ó°Ïì

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÊÓÆµ·ÖÏíÆ½Ì¨DailyMotionÔÚ1ÔÂ25ÈÕÐû²¼Ô⵽ײ¿â¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß»ñµÃÁ˲¿·ÖÓû§ÕË»§µÄ»á¼ûȨÏÞ¡£¡£¡£¡£¡£DailyMotionÒѾʹËÊÂÎñ֪ͨÁËÊÜÓ°ÏìµÄÓû§£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÒªÇóËûÃǾÙÐÐÃÜÂëÖØÖᣡ£¡£¡£¡£DailyMotionÔÚÈ«Çò¹²ÓÐ18ÖÖÓïÑԵİ汾£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÔÚAlexaÁ÷Á¿ÅÅÃûÖÐÅÅÔÚµÚ134λ¡£¡£¡£¡£¡£Æ¾Ö¤DailyMotionÐû²¼µÄ֪ͨ£¬ £¬£¬£¬£¬£¬£¬£¬×²¿â¹¥»÷±¬·¢ÔÚ1ÔÂ19ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÆ¾Ö¤GDPR֪ͨÁËCNIL¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dailymotion-resets-passwords-after-credential-stuffing-attack/


5¡¢WordPress²å¼þTotal DonationsÁãÈÕÎó²î£¬ £¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÍøÕ¾±»½ÓÊÜ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


DefiantµÄÑо¿Ö°Ô±Mikey Veenstra·¢Ã÷¹¥»÷ÕßÕýÔÚʹÓÃWordPress²å¼þTotal DonationsÖеÄÁãÈÕÎó²îÀ´ÈëÇÖWordPressÍøÕ¾¡£¡£¡£¡£¡£¸Ã²å¼þÓÃÓÚÍøÂçºÍÖÎÀíÓû§µÄ¾èÔù£¬ £¬£¬£¬£¬£¬£¬£¬µ«²å¼þÖеÄÎó²î£¨CVE-2019-6703£©¿ÉÔÊÐí¹¥»÷Õß½ÓÊÜÍøÕ¾¡£¡£¡£¡£¡£ÓÉÓÚ²å¼þ¿ª·¢ÕßµÄÍøÕ¾×Ô2018Äê5ÔÂÒÔÀ´ÒÑʧЧ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îûÓÐÐÞ¸´²¹¶¡£¬ £¬£¬£¬£¬£¬£¬£¬Òò´ËÓû§Ó¦¸Ã¾¡¿ìɾ³ý´Ë²å¼þ¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/zero-day-vulnerability-in-total-donations-plugin-could-allow-attackers-to-take-over-wordpress-sites-2a0f5714


6¡¢FBI¼°Å·ÖÞÓйØÕþ¸®²é·â°µÍøÊг¡xDedic£¬ £¬£¬£¬£¬£¬£¬£¬¾Ð²¶ÈýÃûÏÓ·¸

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


1ÔÂ24ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬FBI¼°Å·ÖÞÓйØÕþ¸®²é·âÁ˰µÍøÊг¡xDedicµÄÓòÃûºÍЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÔÚÎÚ¿ËÀ¼¾Ð²¶ÁËÈýÃûÏÓ·¸¡£¡£¡£¡£¡£xDedicÖ÷ÒªÓÃÓÚ³öÊÛ»ò¹ºÖñ»ºÚ¿ÍÈëÇÖµÄЧÀÍÆ÷£¬ £¬£¬£¬£¬£¬£¬£¬Í¨³£ÊÇÊÜËðµÄRDPЧÀÍÕË»§¡£¡£¡£¡£¡£¸ÃÍøÕ¾×Ô2014ÄêÒÔÀ´Ò»Ö±±£´æ£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÊܺ¦Õ߱鲼Ììϸ÷µØµÄÖÖÖÖÐÐÒµ£¬ £¬£¬£¬£¬£¬£¬£¬°üÀ¨µØ·½¡¢ÖݺÍÁª°îÕþ¸®µÄ»ù´¡ÉèÊ©¡¢Ò½Ôº¡¢½»Í¨ÖÎÀí»ú¹¹¡¢»á¼ÆºÍ״ʦÊÂÎñÒÔÊǼ°´óѧµÈ¡£¡£¡£¡£¡£Õþ¸®ÒÔΪ¸ÃÍøÕ¾ÎªÚ²Æ­ÕßÌṩÁËÁè¼Ý6800ÍòÃÀÔªµÄ×ʽ𡣡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/authorities-shut-down-xdedic-marketplace-for-buying-hacked-servers/


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí