¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190111
°ä²¼¹¦·ò 2019-01-11
FireEye·¢ÏÖÒ»²¨Õë¶ÔÈ«ÇòµÄ´ó¹æÄ£DNS½Ù³Öº£³±£¬£¬£¬£¬£¬£¬£¬£¬Ó°ÏìÁËÖж«¡¢±±·Ç¡¢Å·Ö޺ͱ±ÃÀµÄÊýÊ®¸öÓòÃû¡£¡£¡£¡£¡£¡£ÕâЩÓòÃûÊôÓÚµ±¾Ö¡¢µçÐźͻ¥ÁªÍø»ù´¡ÉèÊ©µÈ¡£¡£¡£¡£¡£¡£¹ÌȻĿǰ×êÑÐÈËÔ±»¹Ã»Óн«´Ë»î¶¯ÓëÈκι¥»÷×éÖ¯¹ØÁªÆðÀ´£¬£¬£¬£¬£¬£¬£¬£¬µ«³õ²½µÄ×êÑÐÅú×¢¹¥»÷ÕßÒÉÓëÒÁÀÊÓйء£¡£¡£¡£¡£¡£¸Ã¹¥»÷»î¶¯µÄ¶à¸ö¼¯ÈºÔÚ2017Äê1ÔÂÖÁ2019Äê1ÔÂÆÚ¼äÒ»Ïò´¦ÓÚ»îԾ״̬£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒ´æÔÚ¶à¸ö²»³Á¸´µÄÓòÃû¡¢IPµØÖ·¼¯Èº¡£¡£¡£¡£¡£¡£ÕâÒâζןù¥»÷»î¶¯¿ÉÄܲ¢²»Êǵ¥¸ö¹¥»÷ÕߵĻ¡£¡£¡£¡£¡£¡£¹¥»÷Õߵļ¼ÊõÖØÒªÉæ¼°Åú¸ÄDNS A¼Í¼¡¢NS¼Í¼ºÍ³Á¶¨Ïò¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.fireeye.com/blog/threat-research/2019/01/global-dns-hijacking-campaign-dns-record-manipulation-at-scale.html2¡¢TA505жñÒâ»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬·Ö·¢ServHelperºóÃźÍFlawedGrace RAT
×êÑÐÈËÔ±·¢ÏÖ·¸×ïÍÅ»ïTA505ͨ¹ýÍøÂç´¹µö»î¶¯·Ö·¢ServHelperºóÃźÍFlawedGrace RAT¡£¡£¡£¡£¡£¡£¹¥»÷Õß³ÖÐø¶Ô×¼½ðÈÚºÍÁãÊÛÐÐÒµ£¬£¬£¬£¬£¬£¬£¬£¬²¢Í¨¹ý¶ñÒâµÄMicrosoft Word¡¢PublisherºÍPDFÎļþϰȾÓû§¡£¡£¡£¡£¡£¡£Æ¾¾ÝProofpointµÄ×êÑУ¬£¬£¬£¬£¬£¬£¬£¬TA505ÒÑÔÚÍøÂç·¸×ïÁìÓòÖÁÉÙ»îÔ¾ÁËËÄÄ꣬£¬£¬£¬£¬£¬£¬£¬ÓëÖ®ÓйصĶñÒâÈí¼þÔ̺¬ÒøÐÐľÂíDridex¡¢ÀÕË÷Èí¼þLocky¡¢PhiladelphiaºÍGlobeImposter¡£¡£¡£¡£¡£¡£Õâ´Î¹¥»÷»î¶¯Öй²·Ö·¢ÁËServHelperµÄÁ½ÖÖ±äÌå¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-servhelper-backdoor-and-flawedgrace-rat-pushed-by-necurs-botnet/3¡¢SystemdÈý¸öÌáȨ·ì϶£¬£¬£¬£¬£¬£¬£¬£¬Ó°Ïì´óÎÞÊýLinux¿¯Ðаæ

Qualys°²È«×êÑÐÈËÔ±ÔÚSystemdÖз¢ÏÖÈý¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÔÊÐíÎÞÌØÈ¨µÄ±¾µØ¹¥»÷Õß»ò¶ñÒⷨʽÔÚÖ¸±êϵͳÉÏ»ñµÃroot½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£¡£ÕâÈý¸ö·ì϶£¨CVE-2018-16864¡¢CVE-2018-16865ºÍCVE-2018-16866£©´æÔÚÓÚsystemd-journald·þÎñÖУ¬£¬£¬£¬£¬£¬£¬£¬¸Ã·þÎñÓÃÓÚÍøÂçÐÅÏ¢ºÍ´´½¨ÈÕÖ¾¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾ÕâЩ·ì϶ӰÏìÁËËùÓлùÓÚsystemdµÄLinux¿¯Ðа棬£¬£¬£¬£¬£¬£¬£¬Ô̺¬RedhatºÍDebian¡£¡£¡£¡£¡£¡£µ«Ò²ÓÐһЩ¿¯Ðа棬£¬£¬£¬£¬£¬£¬£¬ÀýÈçSUSE¡¢Fedora²»ÊÜÓ°Ïì¡£¡£¡£¡£¡£¡£½¨ÒéÓû§¾¡¿ì×°Öý¨²¹·¨Ê½¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/linux-systemd-exploit.html4¡¢¹È¸è°ä·¢ÆäDNS·þÎñÖ§³ÖDNS-over-TLS°²È«ºÍ̸
ÓÉÓÚDNS²éÎÊÊÇͨ¹ýUDP»òTCPÒÔÃ÷ÎÄ´ó¾Ö·¢Ë͵쬣¬£¬£¬£¬£¬£¬£¬Òò¶ø¸ÃÐÅÏ¢Äܹ»Ð¹Â¶Óû§½Ó¼ûµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÒ×ÊܺýŪ¹¥»÷¡£¡£¡£¡£¡£¡£ÎªÏàʶ¾öÕâ¸öÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬±¾ÖÜÈý¹È¸è°ä·¢Æä¹«¹²DNS·þÎñÖ§³ÖDNS-over-TLS°²È«ºÍ̸£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅDNS²éÎʺÍÏìÓ¦½«Í¨¹ýTLS¼ÓÃܵÄTCPÏνӽøÐÐͨѶ£¬£¬£¬£¬£¬£¬£¬£¬Äܹ»ÓÐЧԤ·ÀÖÐÑëÈ˹¥»÷¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬£¬£¬£¬¹È¸èÒѾΪAndroid 9Óû§ÌṩÁËDNS-over-TLS£¬£¬£¬£¬£¬£¬£¬£¬¸Ã²¿ÃÅÓû§Äܹ»Á¢¿ÌÇл»µ½DNS-over-TLS¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/google-dns-over-tls-security.html5¡¢ÃÀ¹ú³¬¹ý80¸öµ±¾ÖÍøÕ¾µÄTLSÖ¤Êé¹ýÆÚ
¾ÝZDNet±¨Â·£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú³¬¹ý80¸öµ±¾ÖÍøÕ¾µÄTLSÖ¤ÊéÒѾ¹ýÆÚ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓб»¸üУ¬£¬£¬£¬£¬£¬£¬£¬²¿ÃÅÍøÕ¾ÒѾÎÞ·¨½Ó¼û¡£¡£¡£¡£¡£¡£¾ÝNetcraft³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìÈ·µ±¾Ö»ú¹¹Ô̺¬NASA¡¢ÃÀ¹ú˾·¨²¿ºÍÃÀ¹úÁª¹úÉÏËß·¨ÔºµÈ¡£¡£¡£¡£¡£¡£²¿ÃÅÖ´ÐÐÁËHSTSµÄÍøÕ¾ÓÉÓÚÖ¤Êé¹ýÆÚÒѾÎÞ·¨±»Óû§½Ó¼û£¬£¬£¬£¬£¬£¬£¬£¬¶øÎ´Ö´ÐÐHSTSµÄÍøÕ¾½«ÔÚÓû§µÄä¯ÀÀÆ÷ÖÐÏÔʾHTTPSÃýÎ󡣡£¡£¡£¡£¡£×êÑÐÈËÔ±½«ÕâÒ»ÊÂÎñ¹é×ïÓÚÃÀ¹úÁª¹úµ±¾ÖµÄ¹Ø¹Ø£¬£¬£¬£¬£¬£¬£¬£¬´óÁ¿ITºÍÍøÂ簲ȫÈËÔ±±»¿ª³ý£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂûÓÐÈËÄܹ»ÐøÇ©ÕâЩ֤Êé¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/government-shutdown-tls-certificates-not-renewed-many-websites-are-down/6¡¢Ð¸æ°×Èí¼þICEPick-3PC£¬£¬£¬£¬£¬£¬£¬£¬ÖØÒªÕë¶ÔAndroidÓû§

Media Trust×êÑÐÈËÔ±·¢ÏÖÒ»¸ö¼«¶È¸´ÔÓµÄиæ°×Èí¼þICEPick-3PC£¬£¬£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±ÒÔΪÆä±³ºóµÄÓÐ×éÖ¯·¸×ïÍÅ»ïÔÚ·¢Õ¹Õë¶ÔAndroidÓû§µÄ´ó¹æÄ£¹¥»÷»î¶¯¡£¡£¡£¡£¡£¡£¹¥»÷Õß½«¶ñÒâ´úÂë×¢È뵽һЩµÚÈý·½¿âÖУ¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçGreenSock¶¯»Æ½Ì¨£¨GSAP£©-Ò»¸öHTML5¶¯»µÄJavaScript¿â¡£¡£¡£¡£¡£¡£µ±Óû§µã»÷ÊÜϰȾµÄ¸æ°×ʱ£¬£¬£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áÔÚÓû§É豸ºÍÔ¶³ÌÉ豸֮¼ä³ÉÁ¢RTC¶ÔµÈÏνӣ¬£¬£¬£¬£¬£¬£¬£¬²¢ÍøÂçÉ豸µÄÖ¸ÎÆÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬£¬Ô̺¬É豸µÄIPµØÖ·¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/icepick-adware-analysis/140722/ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ