ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ39ÖÜ

°ä²¼¹¦·ò 2018-10-03

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö


2018Äê09ÔÂ24ÈÕÖÁ30ÈÕ¹²ÊÕ¼°²È«·ì϶50¸ö£¬£¬£¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊÇFoxit Reader for Windows¶à¸ö¶ÔÏó¿ªÊͺóʹÓ÷ì϶£»£»£»£»£»Wecon LeviStudioU CVE-2018-10610»º³åÇøÒç¶Âí½Å£»£»£»£»£»Cisco Video Surveillance Manager ApplianceĬÈÏÃÜÂë·ì϶£»£»£»£»£»ISC BIND CVE-2018-5741°²È«ÏÞ¶ÈÈÆ¹ý·ì϶£»£»£»£»£»DedeCMS XML×¢ÈëËÁÒâ´úÂë·ì϶¡£¡£¡£¡£¡£ ¡£¡£

±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇFacebookÔâ0day·ì϶¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼5000ÍòÓû§µÄ½Ó¼ûÁîÅÆ±»ÇÔ£»£»£»£»£»°²È«×êÑÐÍŶӰ䲼¹ØÓÚUSBÍþв½ü¿öµÄ·ÖÎö»ã±¨£»£»£»£»£»¿¨°Í˹»ù°ä²¼¹ØÓÚICSϵͳÖеÄRAT·çÏյķÖÎö»ã±¨£»£»£»£»£»Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶£»£»£»£»£»ÔÆÍÆË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ó×ʱ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì¡£¡£¡£¡£¡£ ¡£¡£

ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖÓ×£¡£¡£¡£¡£ ¡£¡£



¶þ¡¢³ÁÒª°²È«·ì϶Áбí


1. Foxit Reader for Windows¶à¸ö¶ÔÏó¿ªÊͺóʹÓ÷ì϶


Foxit Reader for Windows CalculateÊÂÎñ´¦ÖôæÔÚ¿ªÊͺóʹÓ÷ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£


https://www.foxitsoftware.com/support/security-bulletins.php


2. Wecon LeviStudioU CVE-2018-10610»º³åÇøÒç¶Âí½Å


Wecon LeviStudioU TIFFͼÏñµÄ½âÎö´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬ÓÕʹÓû§½âÎö£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉʹÀûÓ÷¨Ê½±ÀÀ£»£»£»£»£»òÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£


https://www.zerodayinitiative.com/advisories/ZDI-18-1090/


3. Cisco Video Surveillance Manager ApplianceĬÈÏÃÜÂë·ì϶


Cisco Video Surveillance Manager Appliance ROOTÕË»§Ê¹ÓÃÓ²±àÂëÆ¾Ö¤£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬ÒÔrootÓû§Éí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£¡£¡£ ¡£¡£


https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180921-vsm


4. ISC BIND CVE-2018-5741°²È«ÏÞ¶ÈÈÆ¹ý·ì϶


ISC BINDʵÏÖ´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬Èƹý°²È«ÏÞ¶È£¬£¬£¬ £¬£¬£¬£¬£¬Ö´ÐÐδÊÚȨµÄ²Ù×÷¡£¡£¡£¡£¡£ ¡£¡£


https://kb.isc.org/docs/cve-2018-5741


5. DedeCMS XML×¢ÈëËÁÒâ´úÂë·ì϶


DedeCMS´¦ÖÃ<file type='file' name='../×Ö·û´®´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬Ö´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£¡£


https://github.com/ky-j/dedecms/issues/3




Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö


1¡¢FacebookÔâ0day·ì϶¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼5000ÍòÓû§µÄ½Ó¼ûÁîÅÆ±»ÇÔ

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

9ÔÂ28ÈÕFacebookÈ·ÈÏÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃ0day·ì϶ÇÔÈ¡Á˳¬¹ý5000ÍòÓû§µÄ½Ó¼ûÁîÅÆ¡£¡£¡£¡£¡£ ¡£¡£¸Ã·ì϶´æÔÚÓÚFacebookµÄView AsÖ°ÄÜÖУ¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷ÕßÇÔÈ¡Óû§µÄ½Ó¼ûÁîÅÆ²¢½Ó¼ûÓû§µÄ¸öÈËÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬¶øÎÞÐèÕË»§ÃÜÂë»òË«³É·ÖÑéÖ¤Âë¡£¡£¡£¡£¡£ ¡£¡£FacebookÒѲÉÈ¡´ëʩԮÊÖ½ü9000ÍòÓû§³ÁÖÃÁ˽ӼûÁîÅÆ£¬£¬£¬ £¬£¬£¬£¬£¬²¢½ûÓÃÁËView AsÖ°ÄÜ¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚµ÷²éÈÔ´¦ÓÚÔçÆÚ½×¶Î£¬£¬£¬ £¬£¬£¬£¬£¬FacebookÉÐδȷ¶¨ÊÇ·ñÓÐÈκÎÕË»§±»ÀÄÓûòÐÅÏ¢±»½Ó¼û¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://thehackernews.com/2018/09/facebook-account-hack.html


2¡¢°²È«×êÑÐÍŶӰ䲼¹ØÓÚUSBÍþв½ü¿öµÄ·ÖÎö»ã±¨

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚUSBÍþвÇé¿öµÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£»ã±¨µÄÖØÒª·¢ÏÖÔ̺¬£ºÖÁÉÙ´Ó2015ÄêÆðÍ·£¬£¬£¬ £¬£¬£¬£¬£¬USBÉ豸ºÍÆäËü¿ÉÒÆ¶¯Ã½Ìå±»ÓÃÓÚ´«²¼¶ñÒâÍÚ¿óÈí¼þ£»£»£»£»£»Í¨¹ýUSBÉ豸/¿ÉÒÆ¶¯Ã½Ìå´«²¼µÄÆäËü¶ñÒâÈí¼þ»¹Ô̺¬WindowsľÂí¼Ò×åLNK£»£»£»£»£»ÑÇÖÞ¡¢·ÇÖÞºÍÄÏÃÀÖÞµÈÐÂÐËÊг¡×îÈÝÒ×Êܵ½¿ÉÒÆ¶¯Ã½ÌåÍþвµÄϰȾ£¬£¬£¬ £¬£¬£¬£¬£¬µ«ÔÚÅ·Ö޺ͱ±ÃÀÒ²´æÔÚһЩ¹ÂÁ¢µÄ¹¥»÷ÊÂÎñ¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/usb-threats-from-malware-to-miners/87989/


3¡¢¿¨°Í˹»ù°ä²¼¹ØÓÚICSϵͳÖеÄRAT·çÏյķÖÎö»ã±¨


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚICSÖеÄRAT·çÏյķÖÎö»ã±¨¡£¡£¡£¡£¡£ ¡£¡£Ô¶³ÌÖÎÀí¹¤¾ß£¨RAT£©±»¿í·ºÓÃÓÚ¹¤ÒµÍøÂçÖ®ÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚ½øÐÐICS¼à²â¡¢½ÚÔìºÍÊØ»¤¡£¡£¡£¡£¡£ ¡£¡£Ô¶³Ì²Ù×÷ICSµÄÄÜÁ¦Äܹ»´ó´ó½µµÍÊØ»¤³É±¾£¬£¬£¬ £¬£¬£¬£¬£¬µ«²»ÊܽÚÔìµÄÔ¶³Ì½Ó¼û¡¢ÎÞ·¨100%µØÌṩԶ³Ì¿Í»§¶ËµÄºÏ·¨ÐÔÑéÖ¤ÒÔ¼°RAT´úÂëºÍÅäÖÃÖеķì϶¶¼´ó´óÔö³¤Á˹¥»÷Ãæ¡£¡£¡£¡£¡£ ¡£¡£Óë´Ëͬʱ£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔ½À´Ô½¶àµØÊ¹ÓÃRATºÍÆäËüºÏ·¨¹¤¾ßÀ´¸²¸ÇÆä¶ñÒâ»î¶¯£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹µÃ¶Ô¶ñÒâ»î¶¯½øÐйéÒòÔ½·¢ÄÑÌâ¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://securelist.com/threats-posed-by-using-rats-in-ics/88011/


4¡¢Ê±×°ÁãÊÛÉÌSHEINÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ʱװÁãÊÛÉÌSHEINÉÏÖÜÎå°ä·¢ÆäÔâµ½ºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼642ÍòÓû§µÄÐÅÏ¢¿ÉÄÜй¶¡£¡£¡£¡£¡£ ¡£¡£¹¥»÷ÊÂÎñ²úÉúÔÚÏÄÌ죬£¬£¬ £¬£¬£¬£¬£¬¼´6ÔµÄij¸öʱ³½£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß½Ó¼ûÁËÓû§µÄµç×ÓÓʼþµØÖ·ºÍ¼ÓÃܵÄÃÜÂë¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÓÚ8ÔÂ22ÈÕ·¢ÏÖÁËÕâÒ»ÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬£¬²¢ÔÚÁªÏµÊÜÓ°ÏìµÄÓû§Åú¸ÄÆäÃÜÂë¡£¡£¡£¡£¡£ ¡£¡£Ð¹Â¶µÄÊý¾ÝÖв»Ô̺¬ÈκÎÐÅÓþ¿¨ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£¡£¸Ã¹«Ë¾ÔÚ½øÇ°½øÒ»²½µÄµ÷²é¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/shein-fashion-retailer-announces-breach-affecting-6-42-million-users/


5¡¢ÔÆÍÆË㹫˾ZohoµÄÓòÃû±»½ûÓýüÁ½Ó×ʱ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼3000ÍòÓû§ÊÜÓ°Ïì


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Ó¡¶È³ÛÃûÔÆÍÆËã¿Æ¼¼¹«Ë¾ZohoµÄÓòÃû£¨zoho.com£©±»ÆäÓòÃû×¢²áÉÌTierraNet½ûÓýüÁ½¸öÓ×ʱ£¬£¬£¬ £¬£¬£¬£¬£¬ÔÚ´ËÆÚ¼äÓû§±»³Á¶¨ÏòÖÁÒ»¸ö¿ÕÈ±Ò³Ãæ£¬£¬£¬ £¬£¬£¬£¬£¬Ô¼3000ÍòÓû§Êܵ½Ó°Ïì¡£¡£¡£¡£¡£ ¡£¡£Æ¾¾ÝTierraNetµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÂÅ´ÎÊÕµ½¹ØÓÚÀûÓÃZohoÓʼþ·þÎñ·¢ËÍ´¹µöÓʼþµÄͶËߣ¬£¬£¬ £¬£¬£¬£¬£¬µ«ÔÚÊý´ÎÓëZoho¹µÍ¨ºó¸ÃÎÊÌâûÓеõ½½â¾ö£¬£¬£¬ £¬£¬£¬£¬£¬×îÖÕÒ»Ì××Ô¶¯»¯ÏµÍ³µ¼ÖÂÁË´ËÊÂÎñµÄ²úÉú¡£¡£¡£¡£¡£ ¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/domain-registrar-oversteps-taking-down-zoho-domain-impacts-over-30mil-users/


ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù