¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180910
°ä²¼¹¦·ò 2018-09-1001
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨£¬£¬£¬£¬£¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£¡£¡£¡£¡£¡£¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£©£¬£¬£¬£¬£¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£¡£¡£¡£¡£¡£¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨£¬£¬£¬£¬£¬µ«¸ÃÓʼþÁбíÒѹýÆÚ£¬£¬£¬£¬£¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ±£¬£¬£¬£¬£¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf
02
×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢
GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐе쬣¬£¬£¬£¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É£¬£¬£¬£¬£¬µ«ÎÊÌâÔÚÓÚ£¬£¬£¬£¬£¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí£¬£¬£¬£¬£¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍËÙ¶ÈÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ì¶È¼ÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html
03
×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷
Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ã棬£¬£¬£¬£¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõȡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/
04
×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶
EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£BMCÔڵײãÔËÐУ¬£¬£¬£¬£¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ£¬£¬£¬£¬£¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔ죬£¬£¬£¬£¬Ò²Ã»Óв鳹̼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html
05
Google°ä²¼9ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬¹²½¨¸´50¶à¸ö·ì϶
9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ£¬£¬£¬£¬£¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶£¬£¬£¬£¬£¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£¡£¡£¡£¡£¡£¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01
06
Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹
ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£¡£¡£¡£¡£¡£¡£Haya Shulman²©Ê¿°µÊ¾£¬£¬£¬£¬£¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ£¬£¬£¬£¬£¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Ê飬£¬£¬£¬£¬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/
1¡¢ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒGAO°ä²¼¹ØÓÚEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨
ÃÀ¹úµ±¾ÖÎÊÔð°ì¹«ÊÒ£¨GAO£©°ä²¼¹ØÓÚ2017ÄêEquifaxÊý¾Ýй¶ÊÂÎñµÄ»ØÊ׻㱨£¬£¬£¬£¬£¬»ã±¨ÖоßÌå˵ÁËÈ»EquifaxÔâµ½ºÚ¿ÍÈëÇÖµÄÇé¿öÒÔ¼°¸Ã¹«Ë¾ÔÚÊÂÎñ²úÉúÆÚ¼äºÍÖ®ºóµÄÏìÓ¦¡£¡£¡£¡£¡£¡£¡£2017Äê3ÔÂ8ÈÕApache½¨¸´ÁËStruts Java¿ò¼ÜÖеķì϶£¨CVE-2017-5638£©£¬£¬£¬£¬£¬Í³Ò»ÌìUS-CERTÕë¶Ô¸Ã·ì϶°ä²¼Á˰²È«¾¯±¨¡£¡£¡£¡£¡£¡£¡£Equifax ITÖÎÀíÔ±ÏòÄÚ²¿ÓʼþÁбíת·¢ÁË´Ë·ì϶¾¯±¨£¬£¬£¬£¬£¬µ«¸ÃÓʼþÁбíÒѹýÆÚ£¬£¬£¬£¬£¬²¢Ã»ÓÐÔ̺¬ËùÓеÄϵͳÖÎÀíÔ±£¬£¬£¬£¬£¬Õâ¼ä½Óµ¼ÖÂÁË·þÎñÆ÷µÄ²¹¶¡½¨¸´¹¤×÷²»ÆëÈ«¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.gao.gov/assets/700/694158.pdf
2¡¢×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂç²¢ÓëµÚÈý·½¹²ÏíÊÜ»§µÄλÏàÐÅÏ¢
GuardianApp×êÑÐÍŶӷ¢ÏÖÊýÊ®¸öiOSÀûÓÃÍøÂçÓû§µÄµØÎ»Êý¾Ý£¬£¬£¬£¬£¬²¢½«ÕâЩÊý¾ÝÓëµÚÈý·½¹²Ïí¡£¡£¡£¡£¡£¡£¡£ÕâЩÊý¾ÝÍøÂç²»ÊǰÂÃØ½øÐе쬣¬£¬£¬£¬ËùÓеÄÀûÓóÇÊÐÒªÇóÓû§µÄÐí¿É£¬£¬£¬£¬£¬µ«ÎÊÌâÔÚÓÚ£¬£¬£¬£¬£¬ÕâЩÀûÓúÜÉÙ»òµ××ÓûÓÐÌá¼°»á½«µØÎ»Êý¾ÝÓëµÚÈý·½¹²Ïí£¬£¬£¬£¬£¬ÒÔÓÃÓÚÓëAPPÎ޹صÄÖ÷ÕÅ¡£¡£¡£¡£¡£¡£¡£´óÎÞÊýÇé¿öÏÂÕâЩÀûÓûáÍøÂçGPS×ø±ê¡¢À¶ÑÀLEÐűêÊý¾ÝÒÔ¼°Wi-Fi SSID£¨ÍøÂçÃû³Æ£©ºÍBSSID£¨ÍøÂçMACµØÖ·£©Êý¾Ý¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»¹ÓÐһЩÀûÓûáÍøÂçGPS¸ß¶ÈºÍËÙ¶ÈÐÅÏ¢¡¢µç³Ø³äµç״̬¡¢·äÎÑÍøÂçÃû³Æ¡¢¼Ó¿ì¶È¼ÆÐÅÏ¢ºÍIDFA¸æ°×±êʶ·ûµÈÊý¾Ý¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://guardianapp.com/ios-app-location-report-sep2018.html
3¡¢×êÑÐÈËÔ±³Æ¿É¹«¿ª½Ó¼ûµÄ.GitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷
Lynt ServicesµÄ×êÑÐÈËÔ±Vladim¨ªrSmitka·¢Ïֿɹ«¿ª½Ó¼ûµÄ.gitĿ¼µ¼Ö³¬¹ý39Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£¡£¡£¡£¡£¡£¡£ºÜ¶àWeb¿ª·¢ÈËԱʹÓÿªÔ´¹¤¾ßGitÀ´¹¹½¨Ò³Ã棬£¬£¬£¬£¬µ«ËûÃÇÍùÍù½«.gitÎļþ¼ÐÒÅÁôÔÚÍøÕ¾µÄ¹«¹²¿É½Ó¼û²¿ÃÅ£¬£¬£¬£¬£¬ÉõÖÁÔ̺¬Ò»Ð©³ÁÒªµÄÐÅÏ¢£¬£¬£¬£¬£¬ÀýÈçÍøÕ¾½á¹¹µÄÐÅÏ¢¡¢Êý¾Ý¿âÃÜÂë¡¢APIÃÜÔ¿¡¢¿ª·¢IDEÉèÖõȡ£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/open-git-directories-leave-390k-websites-vulnerable/137299/
4¡¢×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ·ì϶
EclypsiumµÄ×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔì´æÔÚ°²È«·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓø÷ì϶װÖÃÓÆ¾ÃÐÔ¶ñÒâÈí¼þ»òÕ߯ëÈ«²Á³ý²¢³ÁÐÂ×°ÖòÙ×÷ϵͳ¡£¡£¡£¡£¡£¡£¡£BMCÔڵײãÔËÐУ¬£¬£¬£¬£¬Æä¼¶±ðµÍÓÚÖ÷»úµÄ²Ù×÷ϵͳºÍϵͳ¹Ì¼þ£¬£¬£¬£¬£¬Òò¶øÍùÍù³ÉΪ¹¥»÷ÕßµÄÖ¸±ê¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖSupermicro·þÎñÆ÷µÄBMC¸üлúÔìûÓÐʵÏÖ´úÂëµÄÊðÃûÑéÖ¤»úÔ죬£¬£¬£¬£¬Ò²Ã»Óв鳹̼þÊÇ·ñÊǴӺϷ¨ÆðÔ´ÏÂÔØµÄ¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/75999/hacking/flaw-supermicro-servers.html
5¡¢Google°ä²¼9ÔÂAndroid°²È«¸üУ¬£¬£¬£¬£¬¹²½¨¸´50¶à¸ö·ì϶
9ÔµÄAndroid°²È«¸üÐÂÔ̺¬Á½¸ö²¿ÃÅ£¬£¬£¬£¬£¬ÆäÖа²È«²¹¶¡¼¶±ð2018-09-01½¨¸´ÁË24¸ö·ì϶£¬£¬£¬£¬£¬°²È«²¹¶¡¼¶±ð2018-09-05½¨¸´ÁË35¸ö·ì϶¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°ÏìµÄ×é¼þÔ̺¬Android runtime¡¢framework¡¢Library¡¢SystemºÍýÌå¿ò¼ÜµÈ¡£¡£¡£¡£¡£¡£¡£ÑϳÁÐԽϸߵķì϶Ô̺¬Èý¸öSystemÌØÈ¨ÌáÉý·ì϶ºÍÁ½¸öýÌå¿ò¼ÜÖеÄÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£¡£¡£¡£¡£Google»¹°ä²¼ÁË2018Äê9ÔµÄPixel/Nexus°²È«²¼¸æ£¬£¬£¬£¬£¬½¨¸´ÁËÄں˺͸ßͨ×é¼þÖеÄ15¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://source.android.com/security/bulletin/2018-09-01
6¡¢Fraunhofer SIT×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹
ƾ¾ÝThe RegisterµÄÒ»·Ý»ã±¨£¬£¬£¬£¬£¬µÂ¹úFraunhofer°²È«ÐÅÏ¢¼¼Êõ×êÑÐËù£¨SIT£©µÄ×êÑÐÈËÔ±ÑÝʾÈôºÎºýŪ֤ÊéÐû¸æ»ú¹¹¡£¡£¡£¡£¡£¡£¡£Haya Shulman²©Ê¿°µÊ¾£¬£¬£¬£¬£¬ËûÃÇÄܹ»Í¨¹ýDNS»º´æÖж¾¹¥»÷½«CA³Á¶¨ÏòÖÁ¹¥»÷ÕßµÄÍÆËã»ú¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ»ùÓÚÓòÑéÖ¤£¨DV£©µÄÖ¤ÊéÄܹ»±»ºýŪ£¬£¬£¬£¬£¬×éÖ¯Ó¦¸Ã×ªÒÆµ½Í¨¹ýÆäËü¸ü°²È«µÄ²½ÖèÑéÖ¤µÄÖ¤Ê飬£¬£¬£¬£¬ÀýÈçÀ©´óÑéÖ¤£¨EV£©»ò×éÖ¯ÑéÖ¤£¨OV£©¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/german-researchers-spoof-protected/


¾©¹«Íø°²±¸11010802024551ºÅ