¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180814

°ä²¼¹¦·ò 2018-08-14

¡¾Íþвµý±¨¡¿°²È«×êÑÐÈËÔ±·¢ÏÖVIA C3 x86´¦ÖÃÆ÷´æÔÚºóÃÅ»úÔì


°²È«×êÑÐÈËÔ±Christopher Domas·¢ÏÖVIA C3 x86´¦ÖÃÆ÷ÖдæÔÚºóÃÅ»úÔ죬£¬£¬ £¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß´ÓÓû§Ä£Ê½ÌáȨµ½OSÄÚºËģʽ¡£¡£¡£¡£¡£¡£¡£¸Ã´¦ÖÃÆ÷ÊÇÓĘ́ÍåVIA Technologies IncÓÚ2001ÄêÖÁ2003Äê¼ä³ö²úºÍÏúÊÛµÄCPUϵÁУ¬£¬£¬ £¬£¬£¬£¬£¬³£²¿ÊðÔÚPOS»ú¡¢ÖÇÄܵ绰ͤ¡¢ATM¡¢ÓÎÏ·É豸¡¢Ò½ÁÆÉ豸ÒÔ¼°¹¤Òµ×Ô¶¯»¯É豸ÉÏ¡£¡£¡£¡£¡£¡£¡£Domas½«¸ÃºóÃÅ»úÔì³ÆÎªRosenbridge£¬£¬£¬ £¬£¬£¬£¬£¬µ«Ò²ÓÐ×êÑÐÈËÔ±ÒÔΪ¸Ã»úÔì²¢²»ÊÇÒ»¸öÕæÕýµÄºóÃÅ£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚVIA¹Ù·½ÎĵµÔøÌáµ½¸Ã»úÔì¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/backdoor-mechanism-discovered-in-via-c3-x86-processors/


¡¾Íþвµý±¨¡¿×êÑÐÍŶÓÌá³öÕë¶ÔAndroid appµÄÐÂÐÍMan-in-the-Disk¹¥»÷


Check Point×êÑÐÍŶӷ¢ÏÖAndroid appµÄй¥»÷Ãæ£¬£¬£¬ £¬£¬£¬£¬£¬ÕâÖÖÃûΪMan-in-the-DiskµÄ¹¥»÷³¡¾°ÔÊÐí¹¥»÷Õß½Ó¼ûºÍ´Û¸Ä±í²¿´æ´¢ÉϵÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£Man-in-the-Disk¹¥»÷»ùÓÚÁ½¸öÊÂʵ£¬£¬£¬ £¬£¬£¬£¬£¬Ê×ÏÈ£¬£¬£¬ £¬£¬£¬£¬£¬ÈκÎÀûÓö¼Äܹ»´Û¸ÄÆäËüÀûÓÃµÄ±í²¿´æ´¢Êý¾Ý£¬£¬£¬ £¬£¬£¬£¬£¬Æä´Î£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÏÕЩËùÓÐapp¶¼ÒªÇó´ËȨÏÞ£¬£¬£¬ £¬£¬£¬£¬£¬Óû§Í¨³£» £»£»£»£»£»á²»¼ÓÒɻ󵨴ÍÓë´ËȨÏÞ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ËûÃÇÄܹ»Ö´ÐÐÁ½ÖÖÀàÐ͵Ĺ¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹ÆäËüapp±ÀÀ£» £»£»£»£»£»ò½«ÆäËüapp¸üÐÂΪ¶ñÒâ°æ±¾¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.checkpoint.com/2018/08/12/man-in-the-disk-a-new-attack-surface-for-android-apps/


¡¾·ì϶²¹¶¡¡¿Oracle¿ª·¢ÍŶӰ䲼°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´¸ßΣ·ì϶£¨CVE-2018-3110£©


Oracle½¨¸´ÆäÊý¾Ý¿â²úÆ·ÖеÄÒ»¸ö¸ßΣ·ì϶£¨CVE-2018-3110£©£¬£¬£¬ £¬£¬£¬£¬£¬¾­¹ýÔ¶³ÌÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÀûÓø÷ì϶ÊÕÊÜÊý¾Ý¿â²¢³ÉÁ¢¶Ôµ×²ã·þÎñÆ÷µÄshell½Ó¼û¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶´æÔÚÓÚOracle Database ServerµÄJava VM×é¼þÖУ¬£¬£¬ £¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄ°æ±¾Ô̺¬WindowsÉϵÄ11.2.0.4¡¢12.2.0.1ºÍ12.1.0.2ÒÔ¼°Unix»òLinuxÉϵÄ12.1.0.2¡£¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì½øÐиüС£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75310/hacking/cve-2018-3110-oracle-database.html


¡¾·ì϶²¹¶¡¡¿×êÑÐÈËÔ±Åû¶macOSÖеÄÐÂ0 day£¬£¬£¬ £¬£¬£¬£¬£¬¿Éͨ¹ýÄ£ÄâÊó±êµã»÷¼ÓÔØÄÚºËÀ©´ó


Digita Security×êÑÐÈËÔ±Patrick Wardle·¢ÏÖmacOSÖеÄÒ»¸öÁãÈÕ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÄ£ÄâÊó±êµã»÷ÈÆ¹ýϵͳµÄ°²È«»úÔ죬£¬£¬ £¬£¬£¬£¬£¬¼ÓÔØÏµÍ³ÄÚºËÀ©´ó¡£¡£¡£¡£¡£¡£¡£Æ»¹ûÔÚHigh SierraÖÐÍÆ³ö¡°Óû§ºË×¼ÄÚºËÀ©´ó¼ÓÔØ¡±µÄȫа²È«Ö°ÄÜÀ´¼ÓÇ¿macOSµÄ°²È«ÐÔ£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÖ°ÄÜÒªÇóÓû§ÔÚ°²È«ÉèÖýçÃæÊÖ¶¯µã»÷¡°ÔÊÐí¡±°´Å¥À´ºË×¼¼ÓÔØÈκÎÄÚºËÀ©´ó¡£¡£¡£¡£¡£¡£¡£µ«Patrick·¢ÏÖÁ½´Î¡°°´Ï¡±Êó±ê°´Å¥µÄÊÂÎñ»á±»ÏµÍ³Îó¼ø±ðΪ¡°°´Ï¡±ºÍ¡°·ÅËÉ¡¹ØâÒ»ÆëÈ«µÄµã»÷²Ù×÷£¬£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÍ»ÆÆÆä°²È«»úÔì¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/75293/hacking/synthetic-mouse-click-attack.html


¡¾·ì϶²¹¶¡¡¿Ë¼¿Æ°ä²¼IOSºÍIOS XEµÄ°²È«¸üУ¬£¬£¬ £¬£¬£¬£¬£¬½¨¸´Õë¶ÔIKEºÍ̸µÄ·ì϶


˼¿Æ½¨¸´ÁËÆäIOSºÍIOS XEÖеݲȫ·ì϶£¨CVE-2018-0131£©£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÊÇÕë¶ÔIKE£¨InternetÃÜÔ¿»¥»»£©ºÍ̸µÄÐÂBleichenbacher oracle¼ÓÃܹ¥»÷µÄËĸö·ì϶֮һ£¬£¬£¬ £¬£¬£¬£¬£¬ÆäÓàÈý¸ö·ì϶ÊÇ»ªÎª£¨CVE-2017-17305£©¡¢Clavister£¨CVE-2018-8753£©ºÍZyXEL£¨CVE-2018-9129£©¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ý˼¿ÆµÄ˵·¨£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß»ñÈ¡IKEv1»á»°µÄ¼ÓÃÜËæ»úÊý£¬£¬£¬ £¬£¬£¬£¬£¬½ø¶ø¸´Ô­Í¨¹ýIPsec·¢Ë͵ÄÊý¾Ý¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/cisco-patches-its-operating-systems-against-new-ike-crypto-attack/


¡¾¶ñÒâÈí¼þ¡¿°²È«×êÑÐÍŶӰ䲼¹ØÓÚÀÕË÷Èí¼þKeyPassµÄ·ÖÎö»ã±¨


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¹ØÓÚÀÕË÷Èí¼þKeyPassµÄ·ÖÎö»ã±¨£¬£¬£¬ £¬£¬£¬£¬£¬¸ÃÀÕË÷Èí¼þÔÚ8Ô·ݻý¼«½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¸ÃÑù±¾Ê¹ÓÃC++±àд£¬£¬£¬ £¬£¬£¬£¬£¬²¢Í¨¹ýMS Visual Studio½øÐбàÒ룬£¬£¬ £¬£¬£¬£¬£¬ÆäÀûÓÃÁËÀà¿âMFC¡¢BoostºÍCrypto ++£¬£¬£¬ £¬£¬£¬£¬£¬Ñù±¾µÄPEÍ·ÖÐÔ̺¬ÁË×î½üµÄ±àÒëÈÕÆÚ¡£¡£¡£¡£¡£¡£¡£Ã¿Ò»¸ö¼ÓÃܵÄÎļþ³ÇÊб»Ôö³¤.KEYPASSÀ©´óÃû¡£¡£¡£¡£¡£¡£¡£Æä¼ÓÃÜËã·¨ÊÇAES-256£¬£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃCFBģʽ²¢ÇÒIVΪ0£¬£¬£¬ £¬£¬£¬£¬£¬ËùÓÐÎļþµÄ¼ÓÃÜÃÜÔ¿¶¼ÎªÒ»ÑùµÄ32×Ö½ÚÃÜÔ¿¡£¡£¡£¡£¡£¡£¡£ÆäÓëC£¦C·þÎñÆ÷µÄͨѶÊÇͨ¹ýHTTPÒÔJSONµÄ´ó¾Ö´«ÊäµÄ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://securelist.com/keypass-ransomware/87412/