Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ±»¹¥ÆÆ£»£»£»£»2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼

Ðû²¼Ê±¼ä 2019-11-08
1¡¢Pwn2OwnÊ×ÈÕÑÇÂíÑ·Echo¼°ÈýÐÇË÷ÄáµçÊÓ¾ù±»¹¥ÆÆ

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

ÔÚPwn2Own Tokyo 2019ºÚ¿Í´óÈüµÄµÚÒ»Ì죬£¬£¬£¬£¬ÑÇÂíÑ·EchoÖÇÄÜÒôÏä¡¢ÈýÐǺÍË÷ÄáµÄÖÇÄܵçÊÓ¡¢Ð¡Ã×9ÊÖ»úÒÔ¼°NetgearºÍTP-Link·ÓÉÆ÷¾ù±»²ÎÈüÕß¹¥ÆÆ¡£¡£¡£¡£¡£±¾´Î´óÈüÊÇÓÉZero Day Initiative×éÖ¯µÄ£¬£¬£¬£¬£¬Ä¿µÄ×°±¸°üÀ¨17¿î£¬£¬£¬£¬£¬¹²ÔÊÐíÌṩÁè¼Ý75ÍòÃÀÔªµÄÏÖ½ðºÍ½±Æ·¡£¡£¡£¡£¡£ÕâÒ²ÊÇÊ×´ÎPwn2Own½«FacebookµÄPortalÖÇÄÜÏÔʾÆ÷ºÍOculus Quest VRÍ·¿øÁÐÈëÄ¿µÄ¡£¡£¡£¡£¡£ÔÚ´óÈüÊ×ÈÕ²ÎÈüÕßÒѾ­»ñµÃÁË19.5ÍòÃÀÔªµÄ½±Àø£¬£¬£¬£¬£¬ÊÕ»ñ×î¶àµÄÊÇFluoroacetateÍŶӣ¬£¬£¬£¬£¬¸ÃÍŶӻ®·Ö¹¥ÆÆÁËË÷ÄáX800GµçÊÓ¡¢ÑÇÂíÑ·Echo¡¢ÈýÐÇQ60µçÊÓ¡¢Ð¡Ã×9ºÍGalaxy S10¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/facebook-portal-survives-pwn2own-hacking-contest-amazon-echo-got-hacked/

2¡¢ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏ·ÖÏí7¸ö¶ñÒâÑù±¾


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹úÍøÂç˾ÁÔÚVirusTotalÉÏÐû²¼ÁË7¸öеĶñÒâÈí¼þÑù±¾£¬£¬£¬£¬£¬ÍøÂçÇå¾²ºÍ»ù´¡ÉèÊ©Çå¾²¾Ö£¨CISA£©ÃãÀøÓû§Éó²éÕâЩÑù±¾²¢»á¼ûCISAµÄ¶ñÒâ´úÂë·À»¤Êµ¼ù¡£¡£¡£¡£¡£ÓÐÑо¿Ö°Ô±ÔÚTwitterÉϻظ´³ÆÕâЩÑù±¾¿ÉÄÜÓëAPT28Óйء£¡£¡£¡£¡£¸Ã»ú¹¹ÉÏÒ»´Î¹²Ïí¶ñÒâÑù±¾ÊÇÔÚÁ½¸öÔÂǰ£¬£¬£¬£¬£¬ÆäÊ±ÍøÂç˾ÁÐû²¼ÁË11¸öÓ볯ÏÊAPT×éÖ¯LazarusÓйصÄÑù±¾¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2019/11/06/us-cyber-command-shares-seven-new-malware-samples

3¡¢Magento 1.x½«×èÖ¹¸üУ¬£¬£¬£¬£¬20¶àÍò¸öÍøÕ¾ÃæÁÙΣº¦

ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø

Magento 1.x·ÖÖ§½«ÔÚ2020Äê6ÔµִïÉúÃüÖÜÆÚ£¨EOL£©£¬£¬£¬£¬£¬½ìʱ»ùÓÚ¸ÃÆ½Ì¨µÄÔÚÏßÊÐËÁ½«ÎÞ·¨ÊÕµ½Çå¾²¸üУ¬£¬£¬£¬£¬ÕâÒâζ×ÅËüÃǽ«ÃæÁÙÍøÕ¾±»ºÚ¿ÍÈëÇÖ»òѬȾ¶ñÒâ´úÂ루ÈçMagecart£©µÄΣº¦¡£¡£¡£¡£¡£¾Ýͳ¼ÆÏÖÔÚÊÜÓ°ÏìµÄÔÚÏßÊÐËÁÊýÄ¿ÔÚ20Íòµ½24ÍòÖ®¼ä£¬£¬£¬£¬£¬ÕâЩÊÐËÁÐèÒªÔÚδÀ´9¸öÔÂÄÚ¶ÔØÊºó¶Ëƽ̨¾ÙÐÐÉý¼¶£¬£¬£¬£¬£¬ºÃ±ÈǨáãµ½Magento 2.x·ÖÖ§¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/between-200000-and-240000-magento-online-stores-will-reach-eol-next-year/

4¡¢¼ÓÀû¸£ÄáÑÇÖÝDMVй¶¼ÝʻԱÊý¾Ý³¤´ïËÄÄêʱ¼ä


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖÝÆû³µÖÎÀí²¿·Ö£¨DMV£©Ð¹Â¶ÊýǧÃû¼ÝʻԱµÄÊý¾Ý³¤´ï4ÄêµÄʱ¼ä¡£¡£¡£¡£¡£¹²ÓÐ3200Ãû¼ÝʻԱ±»Éæ¼°£¬£¬£¬£¬£¬ËûÃǵÄÐÅÏ¢±»Î¥¹æ·ÖÏí¸ø7¸ö»ú¹¹£¬£¬£¬£¬£¬°üÀ¨San DiegoºÍSanta ClaraÏØµÄµØÇøÉó²é¹Ù¡¢Ð¡ÐÍÆóÒµÖÎÀí¾Ö¡¢¹ú˰¾ÖµÈ²¿·Ö¡£¡£¡£¡£¡£¾Ý¡¶Âåɼí¶Ê±±¨±¨µÀ¡·£¬£¬£¬£¬£¬ÕâЩ»ú¹¹¿ÉÔÚ·¸·¨»î¶¯ÊÓ²ì»ò˰·¨ÊÓ²ìÖÐÎ¥¹æ»á¼ûDMV̻¶µÄÊý¾Ý£¬£¬£¬£¬£¬µ«Êý¾ÝûÓÐ̻¶¸øÐ¡ÎÒ˽¼Ò¡£¡£¡£¡£¡£ÔÚ8ÔÂ2ÈÕ·¢Ã÷Î¥¹æÐÐΪºó²»¾ÃDMV¼´ÏÞÖÆÁ˶ÔÊý¾ÝµÄ»á¼û¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/california-dmv-exposes-drivers/

5¡¢2019ÄêÇï¼¾´¹ÂÚ¹¥»÷»î¶¯ÔöÌíÖÁÈýÄêÀ´×î¸ß¼Í¼


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


ƾ֤APWGµÄͳ¼ÆÊý¾Ý£¬£¬£¬£¬£¬2019ÄêÇï¼¾ÍøÂç´¹ÂÚ¹¥»÷ÔöÌíÖÁÈýÄêÀ´µÄ×î¸ß¼Í¼¡£¡£¡£¡£¡£ÔÚ2019Äê7ÔÂÖÁ9ÔÂʱ´ú¼ì²âµ½µÄ´¹ÂÚÍøÕ¾×ÜÊýΪ266387£¬£¬£¬£¬£¬±È2019ÄêµÚ¶þ¼¾¶ÈµÄ182465ÔöÌíÁË46%£¬£¬£¬£¬£¬ÏÕЩÊÇ2018ÄêµÚËÄÐò¶ÈµÄ138328µÄÁ½±¶¡£¡£¡£¡£¡£³ýÁË´¹ÂÚÍøÕ¾ÊýÄ¿µÄÔöÌíÖ®Í⣬£¬£¬£¬£¬2019ÄêµÚÈý¼¾¶ÈÊÜ´¹ÂÚ¹¥»÷µÄÆ·ÅÆÊýĿҲÏÔ×ÅÔöÌí£¬£¬£¬£¬£¬Æ½¾ùÿÔÂÓÐ400¶à¸öÆ·ÅÆÊܵ½¹¥»÷£¬£¬£¬£¬£¬¶øµÚ¶þ¼¾¶ÈΪ313¸ö¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.helpnetsecurity.com/2019/11/07/phishing-attacks-levels-rise/

6¡¢ÑÇÂíÑ·°²·ÀÃÅÁåRing Video DoorbellÒ×ÔâMitm¹¥»÷


ÈËÉú¾ÍÊDz©-×ðÁú¿­Ê±Öйú¹ÙÍø


BitdefenderÇå¾²Ñо¿Ö°Ô±·¢Ã÷ÑÇÂíÑ·µÄRing Video Doorbell Pro×°±¸Öб£´æ¸ßΣÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îʵÑéÖÐÐÄÈ˹¥»÷²¢ÇÔÈ¡Óû§µÄWi-FiÃÜÂë¡£¡£¡£¡£¡£Ring Video DoorbellÊÇÒ»¸ö´øÉãÏñÍ·µÄÖÇÄÜÎÞÏß°²·ÀÃÅÁ壬£¬£¬£¬£¬Ñо¿Ö°Ô±·¢Ã÷¸Ã×°±¸ÓëAPPµÄͨѶΪ²»Çå¾²µÄHTTP´«Ê䣬£¬£¬£¬£¬¹¥»÷Õß¿ÉÓÕÆ­Óû§ÖØÐÂÉèÖøÃ×°±¸²¢Ðá̽ÆäÃÜÂ룬£¬£¬£¬£¬½ø¶ø¿ÉÒÔÌᳫÖÖÖÖ¶ñÒâ»î¶¯£¬£¬£¬£¬£¬°üÀ¨Óë¼ÒÍ¥ÍøÂçÖеÄ×°±¸½»»¥¡¢»á¼ûÍâµØNAS¡¢ÈëÇÖÆäËü×°±¸µÈ¡£¡£¡£¡£¡£¸Ã¹«Ë¾ÔÚ9ÔÂ5ÈÕÐû²¼ÁËÐÞ¸´²¹¶¡¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/11/ring-doorbell-wifi-password.html