Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ±»¹¥ÆÆ£»£»£»2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼

Ðû²¼Ê±¼ä 2019-11-08
1¡¢Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ¾ù±»¹¥ÆÆ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÔÚPwn2Own Tokyo 2019ºÚ¿Í´óÈüµÄµÚÒ»Ì죬£¬£¬£¬£¬£¬ £¬ÑÇÂíÑ·EchoÖÇÄÜÒôÏä¡¢ÈýÐǺÍË÷ÄáµÄÖÇÄܵçÊÓ¡¢Ð¡Ã×9ÊÖ»úÒÔ¼°NetgearºÍTP-Link·ÓÉÆ÷¾ù±»²ÎÈüÕß¹¥ÆÆ¡£¡£¡£¡£¡£¡£±¾´Î´óÈüÊÇÓÉZero Day Initiative×éÖ¯µÄ£¬£¬£¬£¬£¬£¬ £¬Ä¿µÄ×°±¸°üÀ¨17¿î£¬£¬£¬£¬£¬£¬ £¬¹²ÔÊÐíÌṩÁè¼Ý75ÍòÃÀÔªµÄÏÖ½ðºÍ½±Æ·¡£¡£¡£¡£¡£¡£ÕâÒ²ÊÇÊ×´ÎPwn2Own½«FacebookµÄPortalÖÇÄÜÏÔʾÆ÷ºÍOculus Quest VRÍ·¿øÁÐÈëÄ¿µÄ¡£¡£¡£¡£¡£¡£ÔÚ´óÈüÊ×ÈÕ²ÎÈüÕßÒѾ­»ñµÃÁË19.5ÍòÃÀÔªµÄ½±Àø£¬£¬£¬£¬£¬£¬ £¬ÊÕ»ñ×î¶àµÄÊÇFluoroacetateÍŶÓ£¬£¬£¬£¬£¬£¬ £¬¸ÃÍŶӻ®·Ö¹¥ÆÆÁËË÷ÄáX800GµçÊÓ¡¢ÑÇÂíÑ·Echo¡¢ÈýÐÇQ60µçÊÓ¡¢Ð¡Ã×9ºÍGalaxy S10¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-portal-survives-pwn2own-hacking-contest-amazon-echo-got-hacked/

2¡¢ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏ·ÖÏí7¸ö¶ñÒâÑù±¾


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏÐû²¼ÁË7¸öеĶñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬£¬ £¬ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÃãÀøÓû§Éó²éÕâЩÑù±¾²¢»á¼ûCISAµÄ¶ñÒâ´úÂë·À»¤Êµ¼ù¡£¡£¡£¡£¡£¡£ÓÐÑо¿Ö°Ô±ÔÚTwitterÉϻظ´³ÆÕâЩÑù±¾¿ÉÄÜÓëAPT28Óйء£¡£¡£¡£¡£¡£¸Ã»ú¹¹ÉÏÒ»´Î¹²Ïí¶ñÒâÑù±¾ÊÇÔÚÁ½¸öÔÂǰ£¬£¬£¬£¬£¬£¬ £¬ÆäÊ±ÍøÂç˾ÁÐû²¼ÁË11¸öÓ볯ÏÊAPT×éÖ¯LazarusÓйصÄÑù±¾¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2019/11/06/us-cyber-command-shares-seven-new-malware-samples

3¡¢Magento 1.x½«×èÖ¹¸üУ¬£¬£¬£¬£¬£¬ £¬20¶àÍò¸öÍøÕ¾ÃæÁÙΣº¦

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Magento 1.x·ÖÖ§½«ÔÚ2020Äê6ÔµִïÉúÃüÖÜÆÚ£¨EOL£©£¬£¬£¬£¬£¬£¬ £¬½ìʱ»ùÓÚ¸ÃÆ½Ì¨µÄÔÚÏßÊÐËÁ½«ÎÞ·¨ÊÕµ½Çå¾²¸üУ¬£¬£¬£¬£¬£¬ £¬ÕâÒâζ×ÅËüÃǽ«ÃæÁÙÍøÕ¾±»ºÚ¿ÍÈëÇÖ»òѬȾ¶ñÒâ´úÂ루ÈçMagecart£©µÄΣº¦¡£¡£¡£¡£¡£¡£¾Ýͳ¼ÆÏÖÔÚÊÜÓ°ÏìµÄÔÚÏßÊÐËÁÊýÄ¿ÔÚ20Íòµ½24ÍòÖ®¼ä£¬£¬£¬£¬£¬£¬ £¬ÕâЩÊÐËÁÐèÒªÔÚδÀ´9¸öÔÂÄÚ¶ÔØÊºó¶Ëƽ̨¾ÙÐÐÉý¼¶£¬£¬£¬£¬£¬£¬ £¬ºÃ±ÈǨáãµ½Magento 2.x·ÖÖ§¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/between-200000-and-240000-magento-online-stores-will-reach-eol-next-year/

4¡¢¼ÓÀû¸£ÄáÑÇÖÝDMVй¶¼ÝʻԱÊý¾Ý³¤´ïËÄÄêʱ¼ä


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝÆû³µÖÎÀí²¿·Ö£¨DMV£©Ð¹Â¶ÊýǧÃû¼ÝʻԱµÄÊý¾Ý³¤´ï4ÄêµÄʱ¼ä¡£¡£¡£¡£¡£¡£¹²ÓÐ3200Ãû¼ÝʻԱ±»Éæ¼°£¬£¬£¬£¬£¬£¬ £¬ËûÃǵÄÐÅÏ¢±»Î¥¹æ·ÖÏí¸ø7¸ö»ú¹¹£¬£¬£¬£¬£¬£¬ £¬°üÀ¨San DiegoºÍSanta ClaraÏØµÄµØÇøÉó²é¹Ù¡¢Ð¡ÐÍÆóÒµÖÎÀí¾Ö¡¢¹ú˰¾ÖµÈ²¿·Ö¡£¡£¡£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨±¨µÀ¡·£¬£¬£¬£¬£¬£¬ £¬ÕâЩ»ú¹¹¿ÉÔÚ·¸·¨»î¶¯ÊÓ²ì»ò˰·¨ÊÓ²ìÖÐÎ¥¹æ»á¼ûDMV̻¶µÄÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬µ«Êý¾ÝûÓÐ̻¶¸øÐ¡ÎÒ˽¼Ò¡£¡£¡£¡£¡£¡£ÔÚ8ÔÂ2ÈÕ·¢Ã÷Î¥¹æÐÐΪºó²»¾ÃDMV¼´ÏÞÖÆÁ˶ÔÊý¾ÝµÄ»á¼û¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/california-dmv-exposes-drivers/

5¡¢2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤APWGµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬2019ÄêÇï¼¾ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂʱ´ú¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýΪ266387£¬£¬£¬£¬£¬£¬ £¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465ÔöÌíÁË46%£¬£¬£¬£¬£¬£¬ £¬ÏÕЩÊÇ2018ÄêµÚËÄÐò¶ÈµÄ138328µÄÁ½±¶¡£¡£¡£¡£¡£¡£³ýÁË´¹ÂÚÍøÕ¾ÊýÄ¿µÄÔöÌíÖ®Í⣬£¬£¬£¬£¬£¬ £¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹ÂÚ¹¥»÷µÄÆ·ÅÆÊýĿҲÏÔ×ÅÔöÌí£¬£¬£¬£¬£¬£¬ £¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬£¬£¬£¬£¬ £¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/

6¡¢ÑÇÂíÑ·°²·ÀÃÅÁåRing Video DoorbellÒ×ÔâMitm¹¥»÷


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


BitdefenderÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÑÇÂíÑ·µÄRing Video Doorbell Pro×°±¸Öб£´æ¸ßΣÎó²î£¬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÑéÖÐÐÄÈ˹¥»÷²¢ÇÔÈ¡Óû§µÄWi-FiÃÜÂë¡£¡£¡£¡£¡£¡£Ring Video DoorbellÊÇÒ»¸ö´øÉãÏñÍ·µÄÖÇÄÜÎÞÏß°²·ÀÃÅÁ壬£¬£¬£¬£¬£¬ £¬Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸ÓëAPPµÄͨѶΪ²»Çå¾²µÄHTTP´«Ê䣬£¬£¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉÓÕÆ­Óû§ÖØÐÂÉèÖøÃ×°±¸²¢Ðá̽ÆäÃÜÂ룬£¬£¬£¬£¬£¬ £¬½ø¶ø¿ÉÒÔÌᳫÖÖÖÖ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬£¬ £¬°üÀ¨Óë¼ÒÍ¥ÍøÂçÖеÄ×°±¸½»»¥¡¢»á¼ûÍâµØNAS¡¢ÈëÇÖÆäËü×°±¸µÈ¡£¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ9ÔÂ5ÈÕÐû²¼ÁËÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html