¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190116
°ä²¼¹¦·ò 2019-01-16
Oracle°ä²¼2019Äê1ÔµijÁÒª²¹¶¡¸üУ¬£¬£¬£¬£¬£¬¹²½¨¸´ÁË284¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£ÆäÖÐÔ̺¬Ó°ÏìOracle Database ServerµÄRDBMS×é¼þµÄÁ½¸ö·ì϶£¨CVE-2019-2444¡¢CVE-2019-2406£©ºÍJava VM×é¼þµÄÒ»¸ö·ì϶£¨CVE-2019-2547£©¡£¡£¡£¡£¡£¡£Oracle CommunicationsÖн¨¸´ÁË33¸ö·ì϶£¬£¬£¬£¬£¬£¬ÆäÖÐ29¸ö¿Éͨ¹ýÍøÂçÔ¶³ÌÀûÓöøÎÞÐèÓû§Í´´¦¡£¡£¡£¡£¡£¡£ÆäËüÊÜÓ°ÏìµÄ²úÆ·»¹Ô̺¬E-BusinessÌ×¼þ¡¢ÆóÒµÖÎÀíÆ÷¡¢Financial Services¡¢FusionÖÐÑë¼þµÈ£¬£¬£¬£¬£¬£¬¾ßÌå·ì϶ÁбíÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html2¡¢ZDIÅû¶¿Éµ¼ÖÂRCEµÄWindows VCard 0day
°²È«×êÑÐÈËÔ±John Page£¨@hyp3rlinx£©·¢ÏÖWindows vCardÎļþÖеÄÒ»¸ö0day£¬£¬£¬£¬£¬£¬¸Ã·ì϶¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£ZDIÔÚ6¸öÔÂǰÏò΢Èí»ã±¨ÁË´Ë·ì϶£¬£¬£¬£¬£¬£¬µ«Î¢Èí°µÊ¾²»½øÐн¨¸´¡£¡£¡£¡£¡£¡£vCardÎļþÓÃÓÚ´æ´¢Ó×ÎÒ»òÆóÒµµÄÁªÏµÐÅÏ¢£¬£¬£¬£¬£¬£¬Æ¾¾Ý×êÑÐÈËÔ±µÄ˵·¨£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽ«ÎļþÖеÄÁªÏµÈËÍøÕ¾URLÖ¸Ïò±¾µØ¿ÉÖ´ÐÐÎļþ£¬£¬£¬£¬£¬£¬µ±Óû§µã»÷¸ÃURLʱ£¬£¬£¬£¬£¬£¬Windows½«Ö´ÐжñÒâ¿ÉÖ´ÐÐÎļþ¶ø²»ÏÔʾÈκÎÖÒ¸æÐÅÏ¢¡£¡£¡£¡£¡£¡£¸Ã·ì϶ÉÐδ±»·ÖÅäÈκÎCVE±àºÅ£¬£¬£¬£¬£¬£¬ÆäCVSS 3.0ÆÀ·ÖΪ7.8£¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±»¹°ä²¼ÁËÓйØPOC´úÂë¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/vcard-windows-hacking.html3¡¢SCPºÍ̸´æÔÚ4¸öÓµÓÐ36Ä꺹ÇàµÄ°²È«·ì϶
F-Secure×êÑÐÈËÔ±Harry Sintonen·¢ÏÖ°²È«¸´ÔìºÍ̸£¨SCP£©ÖдæÔÚ4¸öÓµÓÐ36Ä꺹ÇàµÄ°²È«·ì϶£¬£¬£¬£¬£¬£¬¶ñÒâ·þÎñÆ÷»òÖÐÑëÈ˹¥»÷Õß¿ÉÀûÓÃÕâЩ·ì϶¸²¸Ç¿Í»§¶ËϵͳÉϵÄËÁÒâÎļþ¡£¡£¡£¡£¡£¡£·ì϶ÓëSCP¿Í»§¶ËµÄÑéÖ¤²»µ±Óйأ¬£¬£¬£¬£¬£¬Ô̺¬Ä¿Â¼Ãû³ÆµÄ²»ÕýÈ·ÑéÖ¤£¨CVE-2018-20685£©¡¢½Ó¹Üµ½µÄ¶ÔÏóµÄÃû³ÆÑé֤ȱʧ£¨CVE-2019-6111£©¡¢¶ÔÏóÃû³ÆºýŪ£¨CVE-2019-6109£©ºÍstderrºýŪ£¨CVE-2019-6110£©¡£¡£¡£¡£¡£¡£ÓÉÓÚ·ì϶ӰÏìSCPºÍ̸µÄÖ´ÐУ¬£¬£¬£¬£¬£¬ËùÓÐSCP¿Í»§¶ËÀûÓ÷¨Ê½£¨Ô̺¬OpenSSH¡¢PuTTYºÍWinSCP£©³ÇÊÐÊܵ½Ó°Ï죬£¬£¬£¬£¬£¬½¨ÒéÓû§ÊµÊ±¹Ø×¢ÕâЩ²úÆ·µÄ°²È«¸üС£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://thehackernews.com/2019/01/scp-software-vulnerabilities.html
4¡¢ÃÀ¹ú·À²¿×îл㱨³ÆÎå½Ç´óÂ¥ÈÔ´æÔÚÍøÂ簲ȫ·çÏÕ
2019Äê1ÔÂ9ÈÕÃÀ¹ú¹ú·À²¿×ܼà²ì³¤°ì¹«ÊÒ°ä²¼ÁËÒ»·ÝÄê¶ÈÉó¼Æ»ã±¨£¬£¬£¬£¬£¬£¬Õâ·Ý»ã±¨Ö¸³öÎå½Ç´óÂ¥ÔÚ´¦ÖÃÕë¶ÔÍøÂ簲ȫ·çÏյĽ¨Òé·½ÃæÒÀÈ»²»¼°£¬£¬£¬£¬£¬£¬ÈÔÓÐ266Ïî´ý½â¾öµÄÍøÂ簲ȫÓйؽ¨Ò飬£¬£¬£¬£¬£¬ÕâЩ½¨Òé×îÔç¿É×·ÒäÖÁ2008Äê¡£¡£¡£¡£¡£¡£Õâ·Ý»ã±¨»¹Ô̺¬×ܼà²ì³¤°ì¹«ÊÒÉó¼ÆÁË2017Äê7ÔÂ1ÈÕÖÁ2018Äê6ÔÂ30ÈÕÆÚ¼äGAOºÍ¹ú·À²¿¼à¹Ü²¿ÃŰ䲼µÄ4·Ý»úÃܻ㱨ºÍ20·Ý·Ç»úÃܻ㱨µÄÁ˾֡£¡£¡£¡£¡£¡£Îå½Ç´óÂ¥Õë¶ÔÉÏÊö»ã±¨ÖÐÌá³öµÄ159ÏÒéÖеÄ19Ïî²ÉÈ¡ÁËÐж¯£¬£¬£¬£¬£¬£¬µ«ÈÔÓжà¶àÍøÂ簲ȫÎÊÌâ±ØÒª½â¾ö¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/hundreds-of-cybersecurity-risks-still-affecting-the-pentagon/5¡¢ÐÂÎ÷À¼¼ÓÃÜÇ®±ÒÂòÂôËùCryptopiaÔâºÚ¿ÍÈëÇÖ
ÐÂÎ÷À¼¼ÓÃÜÇ®±ÒÂòÂôËùCryptopia°ä·¢Ôâµ½ºÚ¿ÍÈëÇÖ²¢Ôâ·ê³Á´óËðʧ£¬£¬£¬£¬£¬£¬µ«¸ÃÂòÂôËù²¢Î´Åû¶ÈëÇÖÊÂÎñµÄÏêÇ飬£¬£¬£¬£¬£¬Ò²Ã»ÓÐÅû¶Êܵ½ËðʧµÄ¾ßÌå½ð¶î¡£¡£¡£¡£¡£¡£CryptopiaÐû³ÆÒѾ֪ͨÁËÓйص±²¿ÃÅÃÅ£¬£¬£¬£¬£¬£¬²¢ÇÒÔÝÍ£ÁËËùÓÐÂòÂô¡£¡£¡£¡£¡£¡£¸ÃÐÂÎÅÊÇÔÚTwitterÉϰ䲼µÄ£¬£¬£¬£¬£¬£¬1ÔÂ14ÈÕÏÂÎçCryptopia°ä²¼ÍÆÎijÆÂòÂôµØµã½øÐдòËã±íÊØ»¤£¬£¬£¬£¬£¬£¬²¢ÔÚÖÂÁ¦¾¡¿ì¸´Ô·þÎñ£¬£¬£¬£¬£¬£¬µ«µÚ¶þÌì¸ÃÂòÂôËù°ä²¼ÍÆÎijÆÔâµ½ºÚ¿ÍÈëÇÖ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://blokt.com/news/cryptopia-notifies-its-users-of-security-breach-with-substantial-losses6¡¢Ð´¹µö»î¶¯ÀûÓöñÒâRTFÎĵµ´«²¼HawkeyeľÂí
Ò»¸öеÄÍøÂç´¹µö»î¶¯ÀûÓöñÒâµÄRTFÎĵµ¸½¼þ·Ö·¢¼üÅ̼ͼľÂíHawkeye¡£¡£¡£¡£¡£¡£¸Ã»î¶¯ÖØÒªÕë¶ÔÖÐÓ×ÐÍÆóÒµ£¬£¬£¬£¬£¬£¬²¢ÀûÓÃOffice¹«Ê½±à×ëÆ÷·ì϶CVE-2017-1182½øÐд«²¼£¬£¬£¬£¬£¬£¬¶ñÒâÎĵµµÄ²¿ÃÅÒ³ÃæÊÇÓÉÔ½ÄÏÓï±àдµÄ¡£¡£¡£¡£¡£¡£µ±Êܺ¦Õß´ò¿ª¶ñÒâÎĵµÊ±£¬£¬£¬£¬£¬£¬¾Í»áÓëhttp[:]//bit[.]ly/2D1Ob77ͨѶ²¢´Óhttp[:]//aoiap[.]org/q.pngÏÂÔØHawkeyeľÂí¡£¡£¡£¡£¡£¡£¹ÌÈ»¸ÃÎļþ¿´ËÆÊÇÒ»¸öͼƬÎļþ£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÊÇÒ»¸öÅú¸ÄÁËÀ©´óÃûµÄexeÎļþ¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/malicious-rtf-docs-used-to-deliver-hawkeye-keylogger-trojan-in-a-new-phishing-campaign-03e71fd5ÉêÃ÷£º±¾×ÊѶÓÉ8827Ì«Ñô¼¯ÍÅάËûÃü°²È«Ó××é·ÒëºÍÕû¶Ù


¾©¹«Íø°²±¸11010802024551ºÅ