¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180703

°ä²¼¹¦·ò 2018-07-03

¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖÀûÓÃPROPagate´úÂë×¢Èë¼¼ÊõµÄ¶ñÒâ¹¥»÷»î¶¯


PROPagate´úÂë×¢Èë¼¼Êõ×îÔçÓÚ2017Äê11ÔÂÓÉHexacorn°²È«×êÑÐÈËÔ±·¢ÏÖ£¬£¬£¬£¬£¬£¬ £¬£¬¸Ã×êÑÐÈËÔ±Ö¤Ã÷ËüÄܹ»ÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬£¬£¬ £¬£¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÀûÓ÷¨Ê½¡£¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõĺϷ¨GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÀûÓ÷¨Ê½ÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬£¬£¬ £¬£¬FireEyeµÄר¼Ò·¢ÏÖÁËÒ»¸öÀûÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢Èë¼¼Êõ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±³ÆÐµÄDiameterµç»°ºÍ̸ÓëSS7Ò»ÑùÒ×Êܹ¥»÷


°²È«×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä³ß¶Èһ·ʹÓõÄDiameterºÍ̸ÈÝÒ×Êܵ½Óë¾ÉµÄµç»°³ß¶È£¨Èç3G£¬£¬£¬£¬£¬£¬ £¬£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7³ß¶ÈÒ»ÑùÀàÐ͵ķì϶µÄ¹¥»÷£¬£¬£¬£¬£¬£¬ £¬£¬SS7ÊÇÔÚ20ÊÀ¼Í70Äê´ú¿ª·¢µÄ£¬£¬£¬£¬£¬£¬ £¬£¬½«½ü¶þÊ®ÄêÖ¤Ã÷Æä´æÔÚ²»°²È«³É·Ö¡£¡£¡£¡£¡£¡£ÕýÓÉÓÚÈç´Ë£¬£¬£¬£¬£¬£¬ £¬£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂçÆðÍ·£¬£¬£¬£¬£¬£¬ £¬£¬SS7±»DiameterºÍ̸ËùÈ¡´ú£¬£¬£¬£¬£¬£¬ £¬£¬DiameterºÍ̸ÊÇÒ»ÖָĽøµÄÍø¼äºÍÍøÄÚÐÅÁîºÍ̸£¬£¬£¬£¬£¬£¬ £¬£¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G³ß¶È¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/


¡¾°²È«²¥±¨¡¿ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼


ÃÀ¹ú¹ú¶È°²È«¾Ö£¨NSA£©ÉÏÖܰ䷢£¬£¬£¬£¬£¬£¬ £¬£¬ËüÔÚ´óÁ¿É¾³ýÊýÒÚÌõ¿É×·Òäµ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£¡£¡£Ô­×ÓÄÜ»ú¹¹°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬ÔÚÃÀ¹ú¹ú¶È°²È«¾Ö·ÖÎöÈËÔ±·¢ÏÖ¡°´ÓµçÕÛ·þÎñÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý´æÔÚ¼¼ÊõÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬£¬£¬ £¬£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬£¬£¬ £¬£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/


¡¾°²È«²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ

FacebookÒѾ­ÈϿɣ¬£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÀûÓÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ½Ó¼ûȨÏÞ£¬£¬£¬£¬£¬£¬ £¬£¬ÔÚ½ñÄê3Ô°䲼µÄCambridge Analytica³óÎÅÆÚ¼ä£¬£¬£¬£¬£¬£¬ £¬£¬Facebook°µÊ¾£¬£¬£¬£¬£¬£¬ £¬£¬ËüÒѾ­ÔÚ2015Äê5ÔÂÖÕ³¡Á˵ÚÈý·½½Ó¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚ°ä²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬£¬£¬ £¬£¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó³ÖÐøÓë61¼ÒÓ²¼þºÍÈí¼þÔì×÷ÉÌÒÔ¼°ÀûÓÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html


¡¾°²È«²¥±¨¡¿ÈýÐDz¿ÃÅϵÁÐÊÖ»ú´æÔÚbug£¬£¬£¬£¬£¬£¬ £¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË


×îа汾µÄÈýÐǶÌÐŶÌÐÅÀûÓ÷¨Ê½´æÔÚbug£¬£¬£¬£¬£¬£¬ £¬£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬£¬£¬ £¬£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬£¬£¬£¬£¬ £¬£¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬£¬£¬£¬£¬ £¬£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬ £¬£¬Óöµ½bugµÄÓû§Ëµ£¬£¬£¬£¬£¬£¬ £¬£¬ËûÃDz»ÖªÂ·ÊÖ»úÒѾ­·¢ËÍÁËÕÕÆ¬£¬£¬£¬£¬£¬£¬ £¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£¡£¡£Ö»Óе¹ØâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬£¬£¬£¬£¬ £¬£¬ËûÃDzŷ¢ÏÖ¡£¡£¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÀûÓ÷¨Ê½Ö±µ½ÈýÐǽ¨¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/


¡¾·ì϶²¹¶¡¡¿VMware°ä²¼°²È«¸üУ¬£¬£¬£¬£¬£¬ £¬£¬½¨²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄ·ì϶


VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬£¬£¬£¬£¬ £¬£¬Æä½¨²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬£¬£¬£¬£¬ £¬£¬WorkstationºÍFusion²úÆ·ÖгöÏֻؾø·þÎñ£¨DoS£©»òÐÅϢй¶µÄ·ì϶¡£¡£¡£¡£¡£¡£ÓµÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉÀûÓð²È«·ì϶»ñÊØÐÅÏ¢»òʹÐé¹¹»ú±ÀÀ£¡£¡£¡£¡£¡£¡£¸Ã·ì϶±»ÁÐΪ³ÁÒª£¬£¬£¬£¬£¬£¬ £¬£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£¡£¡£Cisco TalosµÄ×êÑÐÈËÔ±·¢ÏÖÁËCVE-2018-6965¡£¡£¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱµã»áÓ°ÏìÔÚÖ°ºÎƽ̨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬£¬£¬£¬£¬ £¬£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬£¬£¬£¬£¬ £¬£¬²¢ÒѰ䲼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄ½¨²¹·¨Ê½ºÍ¸üС£¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion