¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180703

Ðû²¼Ê±¼ä 2018-07-03

¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯


PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÐµÄDiameterµç»°Ð­ÒéÓëSS7Ò»ÑùÒ×Êܹ¥»÷


Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä±ê×¼Ò»ÆðʹÓõÄDiameterЭÒéÈÝÒ×Êܵ½Óë¾ÉµÄµç»°±ê×¼£¨Èç3G£¬£¬£¬£¬£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7±ê×¼ÏàͬÀàÐ͵ÄÎó²îµÄ¹¥»÷£¬£¬£¬£¬£¬SS7ÊÇÔÚ20ÊÀ¼Í70ÄêÔ¿ª·¢µÄ£¬£¬£¬£¬£¬¿ìÒª¶þÊ®Äê֤ʵÆä±£´æ²»Çå¾²ÒòËØ¡£¡£¡£¡£ÕýÓÉÓÚÔÆÔÆ£¬£¬£¬£¬£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂç×îÏÈ£¬£¬£¬£¬£¬SS7±»DiameterЭÒéËùÈ¡´ú£¬£¬£¬£¬£¬DiameterЭÒéÊÇÒ»ÖÖˢеÄÍø¼äºÍÍøÄÚÐÅÁîЭÒ飬£¬£¬£¬£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G±ê×¼¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/


¡¾Çå¾²²¥±¨¡¿ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬£¬£¬£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£Ô­×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬£¬£¬£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/


¡¾Çå¾²²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ

FacebookÒѾ­ÈϿɣ¬£¬£¬£¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬£¬£¬£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬£¬£¬£¬FacebookÌåÏÖ£¬£¬£¬£¬£¬ËüÒѾ­ÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html


¡¾Çå¾²²¥±¨¡¿ÈýÐDz¿·ÖϵÁÐÊÖ»ú±£´æbug£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË


×îа汾µÄÈýÐǶÌÐŶÌÐÅÓ¦ÓóÌÐò±£´æbug£¬£¬£¬£¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬£¬£¬£¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬£¬£¬£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬£¬£¬£¬Óöµ½bugµÄÓû§Ëµ£¬£¬£¬£¬£¬ËûÃDz»ÖªµÀÊÖ»úÒѾ­·¢ËÍÁËÕÕÆ¬£¬£¬£¬£¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£Ö»Óе±ÕâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬£¬£¬£¬ËûÃDzŷ¢Ã÷¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÓ¦ÓóÌÐòÖ±µ½ÈýÐÇÐÞ¸´ÕâЩÎÊÌâ¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/


¡¾Îó²î²¹¶¡¡¿VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬£¬ÐÞ²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄÎó²î


VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬£¬£¬£¬ÆäÐÞ²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬£¬£¬£¬WorkstationºÍFusion²úÆ·ÖзºÆð¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓÃÇå¾²Îó²î»ñÊØÐÅÏ¢»òʹÐéÄâ»úÍ߽⡣¡£¡£¡£¸ÃÎó²î±»ÁÐΪÖ÷Òª£¬£¬£¬£¬£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£Cisco TalosµÄÑо¿Ö°Ô±·¢Ã÷ÁËCVE-2018-6965¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱÏÝ»áÓ°ÏìÔÚÈÎºÎÆ½Ì¨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬£¬£¬£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬£¬£¬£¬²¢ÒÑÐû²¼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄÐÞ²¹³ÌÐòºÍ¸üС£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion