ÐÅÏ¢°²È«Öܱ¨-2018ÄêµÚ22ÖÜ

°ä²¼¹¦·ò 2018-06-04

Ò»¡¢±¾Öܰ²È«Ì¬ÊÆ×ÛÊö
        2018Äê05ÔÂ28ÈÕÖÁ06ÔÂ01ÈÕ¹²ÊÕ¼°²È«·ì϶53¸ö£¬£¬£¬ £¬£¬£¬£¬£¬ÖµµÃ¹Ø×¢µÄÊǶà¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶£»£»£»£»£»£»£»£»Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶£»£»£»£»£»£»£»£»strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å£»£»£»£»£»£»£»£»BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶¡£¡£¡£¡£¡£ ¡£

        ±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂ簲ȫÊÂÎñÊÇ×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄд¹µö»î¶¯£»£»£»£»£»£»£»£»×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯£»£»£»£»£»£»£»£»¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬²¿Ãſͻ§µÄÊý¾Ýй¶£»£»£»£»£»£»£»£»×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ££»£»£»£»£»£»£»£»±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎ󣬣¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶¡£¡£¡£¡£¡£ ¡£

        ƾ¾ÝÒÔÉÏ×ÛÊö£¬£¬£¬ £¬£¬£¬£¬£¬±¾Öܰ²È«ÍþвΪÖС£¡£¡£¡£¡£ ¡£


¶þ¡¢³ÁÒª°²È«·ì϶Áбí
1¡¢¶à¿îTP-LINK²úÆ·Ô¶³Ì´úÂëÖ´Ðзì϶

        ¶à¿îTP-LINK²úÆ·ÖеÄ/usr/lib/lua/luci/torchlight/validator.luaÎļþ´æÔÚÊäÈëÑéÖ¤·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄJSONÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCE
2¡¢Git 'git clone ¨Crecurse-submodules'Ô¶³Ì´úÂëÖ´Ðзì϶

        Git ÔÚÓÃgit cloneʱûÓжÔsubmoduleµÄÎļþ¼Ð¶¨Ãû×ö×ã¹»µÄÑéÖ¤£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá·´Ä¿ÒâµÄ.gitmodulesÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬ÒÔÀûÓ÷¨Ê½¸ßµÍÎÄÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://git-scm.com
3¡¢Huawei 1288H V5ºÍ2288H V5 CVE-2018-7904ȨÏÞÌáÉý·ì϶

        Huawei 1288H V5ºÍ2288H V5´æÔÚJSON×¢Èë·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐí±¾µØ¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬Åú¸ÄÖÎÀíÔ±ÃÜÂ룬£¬£¬ £¬£¬£¬£¬£¬»ñȡϵͳµÄÖÎÀíȨÏÞ¡£¡£¡£¡£¡£ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180523-01-json-en
4¡¢strongSwan CVE-2018-5388»º³åÇøÒç¶Âí½Å

        strongSwan´æÔÚ»º³åÇøÒç¶Âí½Å£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬¿ÉºÄ¾¡×ÊÔ´£¬£¬£¬ £¬£¬£¬£¬£¬½øÐлؾø·þÎñ¹¥»÷¡£¡£¡£¡£¡£ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttp://www.strongswan.org/blog
5¡¢BeaconMedaes TotalAlert Scroll Medical Air SystemsÐÅϢй¶·ì϶

        BeaconMedaes TotalAlert Scroll Medical Air Systems WEB·þÎñÆ÷´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓ÷ì϶Ìá½»ÌØÊâµÄÒªÇ󣬣¬£¬ £¬£¬£¬£¬£¬¿É»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£ ¡£

        Óû§¿É²Î¿¼Èçϳ§ÉÌÌṩµÄ°²È«²¹¶¡ÒÔ½¨¸´¸Ã·ì϶£ºhttps://ics-cert.us-cert.gov/advisories/ICSMA-18-144-01


Èý¡¢³ÁÒª°²È«ÊÂÎñ×ÛÊö
1¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃAndroidÔ­ÉúwebÊÓͼµÄд¹µö»î¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        RiskIQ×êÑÐÍŶӷ¢ÏÖÕë¶ÔMyEtherWalletµÄÒ»¸öд¹µö»î¶¯¡£¡£¡£¡£¡£ ¡£¹¥»÷Õßͨ¹ý³ÉÁ¢Ò»¸ö¼Ù×°³ÉMyEtherWalletÖ§³ÖÍŶӵÄTelegram̸ÌìȺ×éÀ´·Ö·¢¶ñÒâMyEtherWallet¿Í»§¶Ë¡£¡£¡£¡£¡£ ¡£¸Ã¶ñÒⷨʽͨ¹ýGoNative.io½«WebÀûÓÃ×÷Ϊ±¾µØÀûÓð䲼£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚÇÔÈ¡Óû§µÄÍ´´¦¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±°ä²¼ÁËÓйØIoC¡£¡£¡£¡£¡£ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/labs/myetherwallet-android/

2¡¢×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG EK·Ö·¢Ä¾ÂíGrobiosµÄ¹¥»÷»î¶¯

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        FireEye×êÑÐÍŶӷ¢ÏÖÀûÓÃRIG Exploit Kit£¨EK£©´«²¼Ä¾ÂíGrobiosµÄ¶ñÒâ¹¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã»î¶¯´Ó2018Äê3ÔÂ10ÈÕÆðÍ·¡£¡£¡£¡£¡£ ¡£GrobiosʹÓÃÁ˶àÖÖÌӱܼì²â¼¼Êõ£¬£¬£¬ £¬£¬£¬£¬£¬²¢Í¨¹ý¶à¸ö±¸·ÝºÍ´´½¨×Ô¶¯ÔËÐÐ×¢²á±íÏî¼°´òË㹤×÷À´ÊµÏÖÓÆ¾ÃÐÔ¡£¡£¡£¡£¡£ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/72954/malware/rig-exploit-kit-grobios-campaign.html

3¡¢¼ÓÄôóµÄÁ½¼ÒÒøÐÐÔâºÚ¿Í¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬²¿Ãſͻ§µÄÊý¾Ýй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ¼ÓÄôóµÄÁ½¼ÒÒøÐÐSimplii FinancialºÍÃÉÌØÀû¶ûÒøÐÐÔÚÖÜÒ»°ä·¢ÉêÃ÷³Æ²úÉúÍøÂ簲ȫÊÂÎñ£¬£¬£¬ £¬£¬£¬£¬£¬Simplii Financial°µÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ËüÔÚÉÏÖÜÄ©·¢ÏÖ¹¥»÷Õß½Ó¼ûÁËÔ¼4ÍòÃûSimplii¿Í»§µÄÕË»§ÐÅÏ¢¡£¡£¡£¡£¡£ ¡£µ«ÊÇSimplii Financial³Ðŵ100£¥·µ»¹ËùÊÜÓ°ÏìµÄÕË»§µÄËðʧ¡£¡£¡£¡£¡£ ¡£ÔÚSimplii°ä·¢ÉêÃ÷Ò»Ó×ʱºó£¬£¬£¬ £¬£¬£¬£¬£¬ÃÉÌØÀû¶ûÒøÐÐÒ²°ä²¼ÁËÀàËÆµÄÉêÃ÷¡£¡£¡£¡£¡£ ¡£¸ÃÒøÐаµÊ¾£¬£¬£¬ £¬£¬£¬£¬£¬ºÚ¿Í×Ô¼ºÔÚÉÏÖÜÈÕÁªÏµÁËËûÃÇ£¬£¬£¬ £¬£¬£¬£¬£¬Ðû³ÆÕ¼Óпͻ§Êý¾Ý¡£¡£¡£¡£¡£ ¡£ÃÉÌØÀû¶ûÒøÐÐûÓÐй©Óм¸¶à¿Í»§µÄÐÅϢй¶£¬£¬£¬ £¬£¬£¬£¬£¬µ«°µÊ¾ËûÃÇÏàÐÅÒѾ­¹Ø¹ØÁ˺ڿͽøÈëÆäϵͳµÄÈë¿Úµã¡£¡£¡£¡£¡£ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/two-canadian-banks-announce-hacks-over-the-weekend/

4¡¢×êÑÐÈËÔ±³Æ¿Éͨ¹ýÉù²¨¹¥»÷·ÛËéHDDºÍµ¼ÖÂϵͳ±ÀÀ£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        À´×ÔÃÜЪ¸ù´óѧºÍÕã½­´óѧµÄÒ»¸ö×êÑÐÓ××鳯¿Éͨ¹ýÉù²¨/³¬Éù²¨¹¥»÷À´·ÛËéÓ²ÅÌ£¨HDD£©µÄ¶ÁÈ¡¡¢Ð´ÈëºÍ´æ´¢Ö°ÄÜÒÔ¼°µ¼Ö²Ù×÷ϵͳ±ÀÀ£¡£¡£¡£¡£¡£ ¡£×êÑÐÈËÔ±°µÊ¾ÕâÖÖ¹¥»÷Äܹ»Í¨¹ý±ãÒ˵Ą̈ʽµçÄÔ»ò±Ê¼Ç±¾µçÄÔµÄÑïÉùÆ÷½øÐУ¬£¬£¬ £¬£¬£¬£¬£¬Ò»ÖÖ¿ÉÄܵĹ¥»÷³¡¾°ÊÇ£¬£¬£¬ £¬£¬£¬£¬£¬Óû§½Ó¼ûÁ˶ñÒâÍøÕ¾²¢²¥·ÅÁËÓµÓзÛËéÐԵĶñÒâÉù²¨¡£¡£¡£¡£¡£ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://threatpost.com/sonic-tone-attacks-damage-hard-disk-drives-crashes-os/132343/

5¡¢±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄAWS S3ÅäÖÃÃýÎ󣬣¬£¬ £¬£¬£¬£¬£¬µ¼ÖÂ5Íò¶àÃûÓû§µÄÐÅϢй¶

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

        ƾ¾ÝKromtech SecurityµÄ»ã±¨£¬£¬£¬ £¬£¬£¬£¬£¬±¾ÌïÆû³µÓ¡¶È·Ö¹«Ë¾µÄ2¸öAmazon S3¿É¹«¿ª½Ó¼û£¬£¬£¬ £¬£¬£¬£¬£¬µ¼Ö³¬¹ý5ÍòÃûÓû§µÄÐÅϢй¶¡£¡£¡£¡£¡£ ¡£Õâ2¸öAWS bucketÔ̺¬±¾ÌïÒÆ¶¯ÀûÓÃHonda ConnectµÄÓû§µÄ¾ßÌåÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬ÀýÈçÐÕÃû¡¢ÐÔ±ð¡¢Óû§¼°Æä¿ÉÐÅÁªÏµÈ˵ĵ绰ºÅÂëºÍµç×ÓÓʼþµØÖ·¡¢ÕË»§ÃÜÂë¡¢Æû³µVINÂëºÍÆû³µConnect IDµÈ¡£¡£¡£¡£¡£ ¡£

        Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/honda-india-left-details-of-50-000-customers-exposed-on-an-aws-s3-server/