ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý £»£» £»£»£»£»£»¹È¸è½«ÔÚChrome 78ÖвâÊÔ»ùÓÚHTTPSµÄDNSÖ°ÄÜ £»£» £»£»£»£»£»

°ä²¼¹¦·ò 2019-09-12

1.¹È¸è½«ÔÚChrome 78ÖвâÊÔ»ùÓÚHTTPSµÄDNSÖ°ÄÜ


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


¹È¸èÒѾ­°ä·¢´òËãÔÚ½ñÄê10ÔÂÏÂÑ®°ä²¼µÄChrome v78°æ±¾ÖÐÕýʽ²âÊÔеÄDNS-over-HTTPS£¨DoH£©ºÍ̸ ¡£¡£¡£¡£¡£DoHµÄDNSÒªÇó×÷Ϊ¼ÓÃܵÄHTTPSÁ÷Á¿Í¨¹ý¶Ë¿Ú443·¢ËÍ£¬ £¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇͨ¹ý¶Ë¿Ú53ÒÔÃ÷ÎÄ·¢ËÍ ¡£¡£¡£¡£¡£ÕâÄܹ»×èÖ¹µÚÈý·½¹Û²ìÕßͨ¹ý¼Í¼ºÍ²é¿´Î´¼ÓÃܵÄDNSÊý¾ÝÀ´¸ú×ÙÓû§µÄä¯ÀÀº¹Çà¼Í¼ ¡£¡£¡£¡£¡£¶ÔÓÚ³õ²½²âÊÔ£¬ £¬£¬£¬£¬£¬£¬£¬¹È¸è°µÊ¾Ö»»áΪÉÙÊýDNSÌṩÉÌÇл»µ½DoH£¬ £¬£¬£¬£¬£¬£¬£¬Ö§³ÖµÄDNSÌṩÉÌÁбíÔ̺¬Cleanbrowsing¡¢Cloudflare¡¢DNS.SB¡¢Google¡¢OpenDNSºÍQuad9 ¡£¡£¡£¡£¡£Mozilla֮ǰҲ°ä·¢´òËãÔÚ±¾ÔÂÍíЩʱ³½ÎªÃÀ¹úµÄÒ»Óײ¿ÃÅÓû§Öð²½ÆôÓÃDoH ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/chrome-dns-over-https.html


2.Dealer LeadsÒâ±íй¶1.98ÒÚÆû³µÂò¼Ò¼Í¼


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Dealer LeadsµÄElasticsearchÊý¾Ý¿âδÊÜÃÜÂë± £»£» £»£»£»£»£»¤£¬ £¬£¬£¬£¬£¬£¬£¬µ¼ÖÂ1.98ÒÚÆû³µÂò¼Ò¼Í¼ÔÚÍøÉ϶³ö ¡£¡£¡£¡£¡£Dealer Leadsͨ¹ýSEOÓÅ»¯µÄÖ¸±êÍøÕ¾ÍøÂçÍøÂçÓйØÇ±ÔÚÂò¼ÒµÄÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬£¬°²È«×êÑÐÔ±Jeremiah Fowler°µÊ¾ÕâÐ©ÍøÕ¾Îª·Ã¿ÍÌṩ¹º³µ×êÑÐÐÅÏ¢ºÍ·ÖÀà¸æ°×£¬ £¬£¬£¬£¬£¬£¬£¬ÍøÂçµÄÐÅÏ¢±»·¢Ë͸øÆû³µ¾­ÏúÉÌ×÷ΪÏúÊÛÊý¾Ý ¡£¡£¡£¡£¡£¸Ã¶³öµÄÊý¾Ý¿â×ܹ²Ô̺¬413GBÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬Ç±ÔÚ¹º³µÕßµÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢µç»°ºÅÂë¡¢ÎïÀíµØÖ·¡¢IPµØÖ·ÒÔ¼°´û¿îºÍ²ÆÕþÊý¾Ý¡¢³µÁ¾ÐÅÏ¢µÈ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/198m-car-buyer-records-exposed-online/148231/


3.ÐÂNetCAT¹¥»÷¿É´ÓÓ¢ÌØ¶ûCPUÖÐÇÔÈ¡Êý¾Ý


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


×êÑÐÈËÔ±·¢ÏÖÒ»ÖÖеIJàÐÅ·¹¥»÷£¬ £¬£¬£¬£¬£¬£¬£¬ËüÓ°ÏìÁË×Ô2012ÄêÒÔÀ´Ôì×÷µÄËùÓÐÏÖ´úÓ¢ÌØ¶û·þÎñÆ÷´¦ÖÃÆ÷ ¡£¡£¡£¡£¡£¸Ã¹¥»÷±»³ÆÎªNetCAT£¨ÍøÂ绺´æ¹¥»÷£©£¬ £¬£¬£¬£¬£¬£¬£¬ÓëÓ¢ÌØ¶ûµÄÊý¾ÝÖ±½ÓI/O¼¼Êõ£¨DDIO£©Óйأ¬ £¬£¬£¬£¬£¬£¬£¬DDIOÔÚ×îеÄÓ¢ÌØ¶û·þÎñÆ÷¼¶´¦ÖÃÆ÷ÖÐĬÈÏ´ò¿ª£¬ £¬£¬£¬£¬£¬£¬£¬Ô̺¬Intel Xeon E5¡¢E7ºÍSP´¦ÖÃÆ÷ϵÁÐ ¡£¡£¡£¡£¡£¸Ã·ì϶£¨CVE-2019-11184£©µÄÀûÓÃÄѶȽϸߣ¬ £¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß±ØÒª½øÐÐÉí·ÝÑéÖ¤£¬ £¬£¬£¬£¬£¬£¬£¬²¢ÇÒ±ØÒªÓëÖ¸±êϵͳ³ÉÁ¢Ö±½ÓÍøÂçÏÎ½Ó ¡£¡£¡£¡£¡£Ó¢Ìضû½«¸Ã·ì϶µÄCVSSÆÀ·ÖÈ·¶¨Îª2.6·Ö£¬ £¬£¬£¬£¬£¬£¬£¬²¢½¨ÒéÔÚÊÜÓ°ÏìµÄCPUÉϽûÓÃDDIOºÍRDMAÖ°ÄÜ£¬ £¬£¬£¬£¬£¬£¬£¬»òÏÞ¶È´Ó±í²¿²»ÊÜÐÅÀµµÄÍøÂçÖ±½Ó½Ó¼ûÒ×Êܹ¥»÷µÄϵͳ ¡£¡£¡£¡£¡£¶î±íµÄ»º½â´ëÊ©Ô̺¬Ê¹ÓÿÉÄֿܵ¹°´Ê±¹¥»÷µÄÈí¼þÄ£¿£¿£¿£¿£¿£¿é»òʹÓú㰴¹¦·òÐÎ×´µÄ´úÂë ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/netcat-intel-side-channel.html


4.D-LinkºÍComba·ÓÉÆ÷·ì϶¿Éµ¼ÖÂÃ÷ÎÄÃÜÂëй¶


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

Trustwave×êÑÐÈËÔ±·¢ÏÖD-LinkºÍComba TelecomµÄWiFi·ÓÉÆ÷´æÔÚ¶à¸ö·ì϶ ¡£¡£¡£¡£¡£ËùÓÐÕâЩ·ì϶¶¼Éæ¼°²»°²È«µÄÍ´´¦´æ´¢£¬ £¬£¬£¬£¬£¬£¬£¬ÆäÖÐÈý¸ö·ì϶¿Éµ¼ÖÂÃ÷ÎÄÃÜÂëй¶ ¡£¡£¡£¡£¡£Simon Kenin°µÊ¾ÔÚD-Link DSLµ÷Ôì½âµ÷Æ÷Öз¢ÏÖÁ½¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬¶øÔÚComba Telecom WiFiÉ豸Öз¢ÏÖÈý¸ö·ì϶£¬ £¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÔÊÐí¹¥»÷Õ߸ü¸ÄÉ豸ÉèÖá¢ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡¢Ö´ÐÐMitM¹¥»÷ÒÔ¼°³Á¶¨ÏòÖÁ´¹µöÍøÕ¾µÈ ¡£¡£¡£¡£¡£D-LinkÔÚ9ÔÂ6ÈÕ°ä²¼Á˹̼þ½¨¸´²¹¶ ¡£¡£¡£¡£¡£¬ £¬£¬£¬£¬£¬£¬£¬µ«CombaÉÐ佨¸´ÕâЩ·ì϶ ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/09/router-password-hacking.html


5.Î÷ÃÅ×ÓÍÆ³öDejaBlue¡¢Urgent/11ºÍSACK Panic·ì϶µÄ½¨¸´²¹¶¡


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±¾ÖܶþÎ÷ÃÅ×Ó°ä²¼¼¸·Ý°²È«²¼¸æ£¬ £¬£¬£¬£¬£¬£¬£¬ÍƳö×î½üµÄDejaBlue¡¢Urgent/11ºÍSACK Panic·ì϶µÄ½¨¸´²¹¶¡ ¡£¡£¡£¡£¡£Î÷ÃÅ×Ó°µÊ¾£¬ £¬£¬£¬£¬£¬£¬£¬Î¢ÈíÔÚ8Ô·ݽ¨²¹µÄËĸöWindowsÔ¶³Ì×ÀÃæ·þÎñ·ì϶ӰÏìÁ˲¿ÃÅHealthineers²úÆ·£¬ £¬£¬£¬£¬£¬£¬£¬µ«´óÎÞÊýÒ½ÁƲúƷδÊÜÓ°Ïì ¡£¡£¡£¡£¡£ÕâЩ·ì϶±»×·×ÙΪDejaBlue£¬ £¬£¬£¬£¬£¬£¬£¬Óë΢ÈíÔÚ5Ô·ݽ¨¸´µÄBlueKeepÀàËÆ ¡£¡£¡£¡£¡£Î÷ÃÅ×Ó»¹·î¸æ¿Í»§ÆäºÜ¶à²úÆ·Êܵ½×î½üÅû¶µÄLinuxÄں˷ì϶£¨SACK Panic£©µÄÓ°Ï죬 £¬£¬£¬£¬£¬£¬£¬ÆäÖÐ×îÑϳÁµÄÒ»¸ö·ì϶Ϊ¿Éµ¼ÖÂDoSµÄ·ì϶£¨CVE-2019-11477£© ¡£¡£¡£¡£¡£´Ë±í£¬ £¬£¬£¬£¬£¬£¬£¬Î÷ÃÅ×ÓRUGGEDCOM WIN²úÆ·Êܵ½×î½üÅû¶µÄWind River VxWorks·ì϶£¨Urgent/11£©Ó°Ïì ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.securityweek.com/siemens-issues-advisories-dejablue-sack-panic-vulnerabilities


6.ÃÀ¹úÔì×÷É̳ÉΪLokiBot¶ñÒâ»î¶¯µÄ×îй¥»÷Ö¸±ê


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ÃÀ¹úÒ»¼ÒδÅû¼ûû³ÆµÄ´óÐÍÔì×÷¹«Ë¾³ÉΪLokiBotľÂíµÄ×îй¥»÷Ö¸±ê ¡£¡£¡£¡£¡£×êÑÐÈËÔ±ÓÚ8ÔÂ21ÈÕ³õ´Î¹Û²ìµ½¸Ã¹¥»÷»î¶¯£¬ £¬£¬£¬£¬£¬£¬£¬¸ÃÀ¬»øÓʼþÊÇ´Ó¿ÉÄÜÔâµ½ÉøÈëµÄ¡°¿ÉÐÅ¡±·¢¼þÈË·¢Ë͸øÖ¸±êÆóÒµµÄÏúÊÛ²¿ÃÅ ¡£¡£¡£¡£¡£Óʼþ¼Ù×°³É±¨¼ÛÒªÇó£¬ £¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏ·Ö·¢LokiBotľÂí ¡£¡£¡£¡£¡£Æ¾¾ÝFortinet×êÑÐÈËÔ±µÄ·ÖÎö£¬ £¬£¬£¬£¬£¬£¬£¬Õâ´ÎLokiBotÑù±¾µÄÎļþ´óÓ×Ϊ286KB£¬ £¬£¬£¬£¬£¬£¬£¬×î½ü±àÒ빦·òΪ8ÔÂ21ÈÕ£¬ £¬£¬£¬£¬£¬£¬£¬¸ÕºÃÓëÀ¬»øÓʼþµÄ·¢ËÍÈÕÆÚÒ»Ñù ¡£¡£¡£¡£¡£Õâ´Î¹¥»÷µÄIPµØÖ·×¢²áµ½ÑÇÀûÉ£ÄÇÖÝ·ï»Ë³ÇµÄÒ»¼ÒÍøÕ¾ÍйܷþÎñÌṩÉÌ£¨Ãû³ÆÎªLeaseWeb USA£©£¬ £¬£¬£¬£¬£¬£¬£¬´ËÇ°ÔøÔÚ6Ô·ݲúÉúµÄÀ¬»øÓʼþ¹¥»÷ÖÐʹÓùýÁ½´Î ¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/u-s-manufacturer-most-recent-target-of-lokibot-malspam-campaign/148153/