ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ22ÖÜ
°ä²¼¹¦·ò 2018-06-04
Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
2018Äê05ÔÂ28ÈÕÖÁ06ÔÂ01ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö£¬£¬£¬£¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊǶà¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£»£»strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶¡£¡£¡£¡£¡£¡£
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔÉúwebÊÓͼµÄд¹µö»î¶¯£»£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯£»£»£»£»£»£»£»£»¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÊý¾Ýй¶£»£»£»£»£»£»£»£»×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ££»£»£»£»£»£»£»£»±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£
ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬£¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£¡£
¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢¶à¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶
¶à¿îTP-LINK²úÆ·ÖеÄ/usr/lib/lua/luci/torchlight/validator.luaÎļþ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄJSONÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCE
2¡¢Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶
Git ÔÚÓÃgit cloneʱûÓжÔsubmoduleµÄÎļþ¼Ð¶¨Ãû×ö×ã¹»µÄÑéÖ¤£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá·´Ä¿ÒâµÄ.gitmodulesÎļþ£¬£¬£¬£¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://git-scm.com
3¡¢Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶
Huawei 1288H V5ºÍ2288H V5´æÔÚJSON×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬Åú¸ÄÖÎÀíÔ±ÃÜÂ룬£¬£¬£¬£¬£¬£¬£¬»ñȡϵͳµÄÖÎÀíȨÏÞ¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en
4¡¢strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å
strongSwan´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿ÉºÄ¾¡×ÊÔ´£¬£¬£¬£¬£¬£¬£¬£¬½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.strongswan.org/blog
5¡¢BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶
BeaconMedaes TotalAlert Scroll Medical Air Systems WEB·þÎñÆ÷´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬£¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£
Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-144-01
Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔÉúwebÊÓͼµÄд¹µö»î¶¯

RiskIQ×êÑÐÍŶӷ¢ÏÖÕë¶ÔMyEtherWalletµÄÒ»¸öд¹µö»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý³ÉÁ¢Ò»¸ö¼Ù×°³ÉMyEtherWalletÖ§³ÖÍŶӵÄTelegram̸ÌìȺ×éÀ´·Ö·¢¶ñÒâMyEtherWallet¿Í»§¶Ë¡£¡£¡£¡£¡£¡£¸Ã¶ñÒⷨʽͨ¹ýGoNative.io½«WebÀûÓÃ×÷Ϊ±¾µØÀûÓð䲼£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡Óû§µÄÍ´´¦¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°ä²¼ÁËÓйØIoC¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/myetherwallet-android/
2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯

FireEye×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG Exploit Kit£¨EK£©´«²¼Ä¾ÂíGrobiosµÄ¶ñÒâ¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¸Ã»î¶¯´Ó2018Äê3ÔÂ10ÈÕÆðÍ·¡£¡£¡£¡£¡£¡£GrobiosʹÓÃÁ˶àÖÖÌӱܼì²â¼¼Êõ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý¶à¸ö±¸·ÝºÍ´´½¨×Ô¶¯ÔËÐÐ×¢²á±íÏî¼°´òË㹤×÷À´ÊµÏÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72954/malware/rig-exploit-kit-grobios-campaign.html
3¡¢¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬²¿Ãſͻ§µÄÊý¾Ýй¶

¼ÓÄôóµÄÁ½¼ÒÒøÐÐSimplii FinancialºÍÃÉÌØÀû¶ûÒøÐÐÔÚÖÜÒ»°ä·¢ÉêÃ÷³Æ²úÉúÍøÂ簲ȫÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬Simplii Financial°µÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ËüÔÚÉÏÖÜÄ©·¢ÏÖ¹¥»÷Õß½Ó¼ûÁËÔ¼4ÍòÃûSimplii¿Í»§µÄÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£¡£µ«ÊÇSimplii Financial³Ðŵ100£¥·µ»¹ËùÊÜÓ°ÏìµÄÕË»§µÄËðʧ¡£¡£¡£¡£¡£¡£ÔÚSimplii°ä·¢ÉêÃ÷Ò»Ó×ʱºó£¬£¬£¬£¬£¬£¬£¬£¬ÃÉÌØÀû¶ûÒøÐÐÒ²°ä²¼ÁËÀàËÆµÄÉêÃ÷¡£¡£¡£¡£¡£¡£¸ÃÒøÐаµÊ¾£¬£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í×Ô¼ºÔÚÉÏÖÜÈÕÁªÏµÁËËûÃÇ£¬£¬£¬£¬£¬£¬£¬£¬Ðû³ÆÕ¼Óпͻ§Êý¾Ý¡£¡£¡£¡£¡£¡£ÃÉÌØÀû¶ûÒøÐÐûÓÐй©Óм¸¶à¿Í»§µÄÐÅϢй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«°µÊ¾ËûÃÇÏàÐÅÒѾ¹Ø¹ØÁ˺ڿͽøÈëÆäϵͳµÄÈë¿Úµã¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/two-canadian-banks-announce-hacks-over-the-weekend/
4¡¢×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ£

À´×ÔÃÜЪ¸ù´óѧºÍÕã½´óѧµÄÒ»¸ö×êÑÐÓ××鳯¿Éͨ¹ýÉù²¨/³¬Éù²¨¹¥»÷À´·ÛËéÓ²ÅÌ£¨HDD£©µÄ¶ÁÈ¡¡¢Ð´ÈëºÍ´æ´¢Ö°ÄÜÒÔ¼°µ¼Ö²Ù×÷ϵͳ±ÀÀ£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ÕâÖÖ¹¥»÷Äܹ»Í¨¹ý±ãÒ˵Ą̈ʽµçÄÔ»ò±Ê¼Ç±¾µçÄÔµÄÑïÉùÆ÷½øÐУ¬£¬£¬£¬£¬£¬£¬£¬Ò»ÖÖ¿ÉÄܵĹ¥»÷³¡¾°ÊÇ£¬£¬£¬£¬£¬£¬£¬£¬Óû§½Ó¼ûÁ˶ñÒâÍøÕ¾²¢²¥·ÅÁËÓµÓзÛËéÐԵĶñÒâÉù²¨¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://threatpost.com/sonic-tone-attacks-damage-hard-disk-drives-crashes-os/132343/
5¡¢±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶

ƾ¾ÝKromtech SecurityµÄ»ã±¨£¬£¬£¬£¬£¬£¬£¬£¬±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄ2¸öAmazon S3¿É¹«¿ª½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö³¬¹ý5ÍòÃûÓû§µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£Õâ2¸öAWS bucketÔ̺¬±¾ÌïÒÆ¶¯ÀûÓÃHonda ConnectµÄÓû§µÄ¾ßÌåÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÐÔ±ð¡¢Óû§¼°Æä¿ÉÐÅÁªÏµÈ˵ĵ绰ºÅÂëºÍµç×ÓÓʼþµØÖ·¡¢ÕË»§ÃÜÂë¡¢Æû³µVINÂëºÍÆû³µConnect IDµÈ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/honda-india-left-details-of-50-000-customers-exposed-on-an-aws-s3-server/


¾©¹«Íø°²±¸11010802024551ºÅ