TravelexϰȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª;µÂ¹úCanyon BicyclesÔâºÚ¿ÍÈëÇÖ
°ä²¼¹¦·ò 2020-01-08
1.Ö±²¼ÂÞÍÓµ±¾ÖÍøÕ¾SQL×¢Èë·ì϶£¬£¬£¬£¬£¬£¬£¬¿É´Û¸Ä˾·¨Îļþ
Ö±²¼ÂÞÍÓµ±¾ÖÍøÕ¾ÖеÄÒ»¸öSQL×¢Èë·ì϶¿ÉÄܵ¼Ö¹¥»÷Õߴ۸ĸõØË¾·¨ÎļþµÄÕýÊ½ÍøÂç°æ±¾¡£¡£¡£¡£¡£¡£¡£¡£°²È«×êÑÐÔ±Ax SharmaÔÚ×êÑÐÖ±²¼ÂÞÍÓ±ßÚïºÍº£°¶¾¯ÎÀ¶ÓÍøÕ¾µÄǩ֤¹æ°´Ê±·¢ÏÖÁËÕâ¸ö·ì϶£¬£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÀûÓõ±¾ÖÍøÕ¾É϶³öµÄÐÅÏ¢´Û¸ÄÖ±²¼ÂÞÍÓ˾·¨µÄ¹Ù·½ÔÚÏß´æ´¢¿â£¬£¬£¬£¬£¬£¬£¬Ô̺¬É¾³ý»òÉÏ´«PDFÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÀûÓÿªÔ´¹¤¾ßsqlmap£¬£¬£¬£¬£¬£¬£¬Sharma¿ÉÄܲ鿴Ϊ˾·¨ÎļþÍйÜÕ¾µãÌṩ֧³ÖµÄËùÓбíºÍÊý¾Ý¿âÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÒ»¸öÃûΪgiblaws_giblaws.userµÄ±íÔ̺¬Á˹¤×÷ÈËÔ±µÄÐÕÃû¡¢Óû§ÃûºÍÃÜÂëÌáÒªµÈ¡£¡£¡£¡£¡£¡£¡£¡£SharmaÀûÓÃsqlmapµÄÄÚÖÃÌá񻮮½â¹¤¾ß²»µ½1Ãë¾ÍÆÆ½âÁËÆäÖÐÒ»¸öÃÜÂ룬£¬£¬£¬£¬£¬£¬ÕâʹµÃÆäÄܹ»µÇ¼²¢Ê¹ÓøÃÕË»§µÄȨÏÞÀ´±à×ëÍøÕ¾ÉϵÄÄÚÈÝ¡£¡£¡£¡£¡£¡£¡£¡£Ö±²¼ÂÞÍÓµ±¾Ö½²»°ÈËÈ·ÈÏÁËÕâÒ»·ì϶£¬£¬£¬£¬£¬£¬£¬²¢°µÊ¾Òѽ«ÊÜÓ°ÏìµÄÍøÒ³ÀëÏß¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/gibraltar_sql_vuln_allowed_law_editing/
2.µÂ¹úCanyon Bicycles ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬·þÎñÆ÷ºÍÈí¼þ±»¼ÓÃÜ
µÂ¹ú×ÔÐгµÔì×÷ÉÌCanyon Bicycles GmbGÈ·ÈÏÔÚÐÂÄê¼ÙÆÚÆÚ¼äÔâ·ê°²È«ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬²¿ÃÅ»ù´¡ÉèÊ©±»·¸×ï·Ö×ÓËø¶¨¡£¡£¡£¡£¡£¡£¡£¡£¸Ã³§ÉÌÔÚÒ»·ÝÉêÃ÷ÖаµÊ¾£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÐÂÄê֮ǰ¾ÍÈëÇÖÁËÆäITϵͳ£¬£¬£¬£¬£¬£¬£¬ÆäÈí¼þºÍ·þÎñÆ÷±»¼ÓÃܺÍËø¶¨¡£¡£¡£¡£¡£¡£¡£¡£Ëü»¹°µÊ¾ÍøÕ¾²»ÊÜÓ°Ï죬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓû§Äܹ»Õý³£Ï´ïÔÚÏß¶©µ¥£¬£¬£¬£¬£¬£¬£¬²¢ÇҸù«Ë¾µ±Ç°ÒѾȷ¶¨²¢×èÖ¹Á˹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£CanyonÊ×´´È˼æÊ×ϯִÐйÙRoman Arnold°µÊ¾£º¡°Õâ´Î¹¥»÷ÏÔʾ³ö´ó¹æÄ£µÄ·¸×ïÒâͼ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚIT»ù´¡¼Ü¹¹±»¼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¤×÷ºÍÒµÎñÁ÷³ÌÁÙʱÊܵ½Á˾޴óÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£¡±Î÷µÂ¿Æ²¼Â×´Ä×ܲ¿ºÍÏÕЩËùÓйú¼ÊÒµÎñ¶¼Êܵ½Ö±½ÓÓ°Ï죬£¬£¬£¬£¬£¬£¬µ«ÃÀ¹ú×Ó¹«Ë¾²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£¡£¡£Arnold²¢Î´Ìá¼°¾ßÌåµÄÀÕË÷Èí¼þ£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°·¸×ï·Ö×ÓÊÇ·ñÒªÇóÁËÊê½ð¡¢Êê½ð½ð¶î»òÊÇÊÇ·ñÖ§¸¶ÁËÊê½ð¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.theregister.co.uk/2020/01/07/hackers_canyon_bicycles/
3.ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraÔâµ½MageCart¹¥»÷
ÉãÓ°Æ÷²ÄÁãÊÛÉÌFocus CameraµÄÍøÕ¾ÓÚÈ¥ÄêÄêµ×Ôâµ½MageCart¹¥»÷£¬£¬£¬£¬£¬£¬£¬¿Í»§µÄÖ§¸¶¿¨ÐÅÏ¢±»ÇÔ¡£¡£¡£¡£¡£¡£¡£¡£ÎªÁ˰µ²Ø¶ñÒâÁ÷Á¿£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß×¢²áÁË¡°zdsassets.com¡±ÓòÃû£¬£¬£¬£¬£¬£¬£¬¸ÃÓòÃû·ÂÕÕÁËZenDeskµÄºÏ·¨ÓòÃû¡°zdassets.com¡±¡£¡£¡£¡£¡£¡£¡£¡£Juniper Networks°²È«×êÑÐÔ±Mounir HahadÔÚ12ÔÂÏÂÑ®·¢ÏÖÁ˶ñÒâ¾ç±¾£¬£¬£¬£¬£¬£¬£¬¸Ã¾ç±¾ÇÔÈ¡µÄÐÅÏ¢Ô̺¬µç×ÓÓʼþ¡¢¿Í»§ÐÕÃû¡¢µØÖ·£¨Õ˵¥ºÍÔËÊ䣩¡¢µç»°ºÅÂë¼°Ö§¸¶¿¨¾ßÌåÐÅÏ¢£¨ºÅÂë¡¢ÓÐЧÆÚ¡¢CVVÂ룩¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝDNSÒ£²âÊý¾Ý£¬£¬£¬£¬£¬£¬£¬¸ÃC&CÓòÃûÒѱ»½âÎö905´Î£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܽ²ÁËÈ»ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/magecart-attackers-steal-card-info-from-focus-camera-shoppers/
4.TravelexϰȾÀÕË÷Èí¼þSodinokibi£¬£¬£¬£¬£¬£¬£¬±»ÀÕË÷300ÍòÃÀÔª
×Ô±í»ã¹«Ë¾TravelexÔâµ½ÍøÂç¹¥»÷ÒѾ´ÓǰÁËÁùÌìµÄ¹¦·ò£¬£¬£¬£¬£¬£¬£¬BleepingComputer¿ÉÄÜÈ·Èϸù«Ë¾Ï°È¾µÄ¶ñÒâÈí¼þΪÀÕË÷Èí¼þSodinokibi¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÊÂÎñ²úÉúÔÚ12ÔÂ31ÈÕ£¬£¬£¬£¬£¬£¬£¬¸Ã¹«Ë¾²ÉÈ¡ÁËÔ¤·À´ëÊ©½«ËùÓеÄÍÆËã»úϵͳÍÑ»ú£¬£¬£¬£¬£¬£¬£¬Ê¹µÃ¿Í»§ÎÞ·¨ÔÙʹÓÃÍøÂç»òAPP½øÐÐÂòÂô»òÔÚÈ«Çò³¬¹ý1500¼ÒµêÆÌÖÐʹÓÃÐÅÓþ¿¨£¨½è¼Ç¿¨£©¸¶¿î¡£¡£¡£¡£¡£¡£¡£¡£TravelexÉÐδÌṩÓйظ´Ô·þÎñ½ø¶ÈµÄ×îÐÂÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£BleepingComputerÊÕµ½ÐÂÎųÆTravelexµÄÈ·Êܵ½SodinokibiµÄϰȾ£¬£¬£¬£¬£¬£¬£¬ÆäÀ©´óÃûÀàËÆÓÚ.u3i7y74¡£¡£¡£¡£¡£¡£¡£¡£Sodinokibi¹¥»÷Õß»¹³Æ¶ÔÕû¸öTravelexÍøÂç½øÐÐÁ˼ÓÃÜ£¬£¬£¬£¬£¬£¬£¬²¢¸´ÔìÁ˳¬¹ý5GBµÄÓ×ÎÒÊý¾Ý£¬£¬£¬£¬£¬£¬£¬ÆäÖÐÔ̺¬µ®ÉúÈÕÆÚ¡¢Éç»á°²È«ºÅÂë¡¢Ö§¸¶¿¨ÐÅÏ¢µÈ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßË÷ÒªµÄÊê½ðΪ300ÍòÃÀÔª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-hits-travelex-demands-3-million/
5.3¸ö¶ñÒâAPPÀûÓÃCVE-2019-2215£¬£¬£¬£¬£¬£¬£¬»òÓëSideWinder APTÓйØ
Ç÷Ïò¿Æ¼¼×êÑÐÈËÔ±ÔÚGoogle PlayÉ̵êÖз¢ÏÖ3¸ö¶ñÒâAPP£¬£¬£¬£¬£¬£¬£¬ËüÃÇÄܹ»Ðͬ¹¤×÷·ÛËéÊܺ¦ÕßµÄÉ豸²¢ÍøÂçÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£ÆäÖÐÃûΪCameroµÄAPPÀûÓÃÁËBinder£¨AndroidÖÐÖØÒªµÄ¹ý³Ì¼äͨѶϵͳ£©ÖеÄuse-after-free·ì϶£¨CVE-2019-2215£©£¬£¬£¬£¬£¬£¬£¬ÕâÊÇÒÑÖªµÄÊ׸öÀûÓø÷ì϶µÄÒ°±í¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£ÔÚ½øÒ»´ëÊ©²éÖУ¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹·¢ÏÖÕâÈý¸ö¶ñÒâAPP¿ÉÄÜÓë·¸×ïÍÅ»ïSideWinder APTÓйء£¡£¡£¡£¡£¡£¡£¡£SideWinder×Ô2012ÄêÒÔÀ´Ò»Ïò»îÔ¾£¬£¬£¬£¬£¬£¬£¬¾Ý±¨Â·ËüÖØÒª¶Ô×¼¾üÊ»ú¹¹µÄWindowsÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±´§Ä¦ÕâÈý¸ö¶ñÒâAPP×Ô2019Äê3ÔÂÒÔÀ´Ò»Ïò´¦Óڻ״̬£¬£¬£¬£¬£¬£¬£¬µ±Ç°ËüÃÇÒѱ»Google Playϼܡ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blog.trendmicro.com/trendlabs-security-intelligence/first-active-attack-exploiting-cve-2019-2215-found-on-google-play-linked-to-sidewinder-apt-group/
6.¹È¸è°ä²¼2020Äê1ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨¸´40¸ö·ì϶
2020Äê1ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ£º2020-01-01°²È«²¹¶¡·¨Ê½¼¶±ð½¨¸´ÁËFramework¡¢Media¿ò¼ÜºÍϵͳ×é¼þÖеÄ7¸ö·ì϶£»£»£»£»£»£»2020-01-05°²È«²¹¶¡·¨Ê½¼¶±ð½¨¸´ÁËÄںˡ¢¸ßͨ×é¼þºÍ¸ßͨ¹ØÔ´×é¼þÖеÄ33¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£±»±êΪcritical£¨ÑϳÁ£©¼¶´ËÍâ·ì϶ΪMedia¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶£¨CVE-2020-0002£©£¬£¬£¬£¬£¬£¬£¬ËüÄܹ»ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓöñÒâÎļþÔÚÌØÈ¨¹ý³ÌµÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£¡£¸Ã·ì϶½öÔÚAndroid 8.0¡¢8.1 ºÍ9°æ±¾Öб»ÒÔΪÊÇÑϳÁ¼¶±ð£¬£¬£¬£¬£¬£¬£¬µ«ÔÚAndroid 10ÖÐΪÖÐΣ¡£¡£¡£¡£¡£¡£¡£¡£ÁíÒ»¸öÑϳÁ·ì϶ÊÇRealtek rtlwifiÇý¶¯·¨Ê½ÖеÄRCE·ì϶£¨CVE-2019-17666£©¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.securityweek.com/androids-january-2020-update-patches-40-vulnerabilities


¾©¹«Íø°²±¸11010802024551ºÅ