Android 0day(CVE-2019-2215) PoC£»£»£»£»£» £»¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí

°ä²¼¹¦·ò 2019-10-18
1¡¢Android 0day(CVE-2019-2215)µÄPoC´úÂëÒѰ䲼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

±¾Ô³õ¹È¸è°²È«×êÑÐÔ±Maddie StoneÅû¶ÁËÒ»¸öAndroidÁãÈÕ·ì϶£¨CVE-2019-2215£©£¬ £¬£¬£¬£¬£¬£¬Æäʱ¹È¸è°µÊ¾¸ÃÁãÈÕ·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓà ¡£¡£¡£¡£¡£¡£¡£½üÈÕ·ðÂÞÀï´ï´óѧGrant HernandezÔÚ²©¿ÍÖа䲼ÁËÒ»¸öеÄPoC¹¤¾ßQu1ckR00t£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓøù¤¾ß»ñµÃrootȨÏÞ²¢ÆëÈ«½ÚÔìÉ豸 ¡£¡£¡£¡£¡£¡£¡£¸Ã¹¤¾ßûÓÐ×÷Ϊ´ò°üµÄAPKÎļþ°ä²¼£¬ £¬£¬£¬£¬£¬£¬¶øÊÇÒÔÔ´´úÂëµÄ´ó¾ÖÔÚGitHubÉϰ䲼 ¡£¡£¡£¡£¡£¡£¡£Hernandez°µÊ¾ËûÖ»ÔÚPixel 2ÊÖ»úÉϲâÊÔ¹ýQu1ckR00t£¬ £¬£¬£¬£¬£¬£¬²¢ÖÒ¸æÃ»Óо­ÑéµÄÓû§²»Òª²âÊԸôúÂ룬 £¬£¬£¬£¬£¬£¬²»È»»áÓÐϵͳ±äשºÍÊý¾ÝÃÔʧµÄ·çÏÕ ¡£¡£¡£¡£¡£¡£¡£GoogleÒÑÔÚ2019Äê10ÔµÄAndroid°²È«²¼¸æ£¨°²È«²¹¶¡·¨Ê½¼¶±ð2019-10-06£©Öн¨²¹ÁËCVE-2019-2215 ¡£¡£¡£¡£¡£¡£¡£ÎªÁËÔ¤·À³öÏÖÎÊÌ⣬ £¬£¬£¬£¬£¬£¬½¨ÒéÓû§×°ÖñØÒªµÄ²¹¶¡·¨Ê½ ¡£¡£¡£¡£¡£¡£¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-researcher-publishes-proof-of-concept-code-for-recent-android-zero-day/

2¡¢Êý°ÙÍòÑÇÂíÑ·EchoºÍKindleÉ豸Ò×ÊÜWiFi KRACK¹¥»÷

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


ƾ¾ÝESETµÄÒ»·Ý»ã±¨£¬ £¬£¬£¬£¬£¬£¬×êÑÐÈËÔ±·¢ÏÖAmazon Echo 1stºÍAmazon Kindle 8thÉ豸ÒÀÈ»Êܵ½WiFi KRACK·ì϶µÄÓ°Ï죬 £¬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÓ°ÏìÊý°ÙÍòÉ豸 ¡£¡£¡£¡£¡£¡£¡£KRACK·ì϶ÊÇWPA2ºÍ̸4´ÎÎÕÊÖÖеķì϶£¨CVE-2017-13077ºÍCVE-2017-13078£©£¬ £¬£¬£¬£¬£¬£¬¸Ã·ì϶ÓÚ2017Äê10Ô±»¹«¿ª ¡£¡£¡£¡£¡£¡£¡£Æ¾¾ÝESETµÄ±íÊö£¬ £¬£¬£¬£¬£¬£¬ÕâЩ·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐDoS¹¥»÷¡¢·ÛËéÍøÂçͨѶ»ò³Á²¥¹¥»÷£¬ £¬£¬£¬£¬£¬£¬À¹½ØºÍ½âÃÜÓû§´«ÊäµÄÃÜÂë»ò»á»°µÈÃô¸ÐÐÅÏ¢£¬ £¬£¬£¬£¬£¬£¬Î±ÔìÊý¾Ý°üÉõÖÁ×¢ÈëÐÂÊý¾Ý°üµÈ ¡£¡£¡£¡£¡£¡£¡£ESETÓÚ2018Äê10ÔÂ23ÈÕ֪ͨÁËÑÇÂíÑ·£¬ £¬£¬£¬£¬£¬£¬ÑÇÂíÑ·ÔÚ2019Äê1ÔÂÒÑÏòÊÜÓ°ÏìµÄÉè±¸ÍÆËÍÁËÓйؽ¨¸´²¹¶¡ ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-amazon-echo-and-kindle-devices-affected-by-wifi-bug/

3¡¢¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

BlackBerry Cylance×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÔÚжñÒâ»î¶¯ÖÐÀûÓÃWAVÒôƵÎļþÔÚÖ¸±êϵͳÉϰµ²ØºóÃźͶñÒâ¿ó¹¤ ¡£¡£¡£¡£¡£¡£¡£¹ÌÈ»·¸×ï×é֯ʱʱÀûÓÃÒþдÊõÔÚJPEG»òPNGͼÏñÎļþÖÐ×¢Èëpayload£¬ £¬£¬£¬£¬£¬£¬µ«ÔÚÀÄÓÃWAVÒôƵÎļþÉÏÉÐÊýµÚ¶þ´Î ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬ £¬£¬£¬£¬£¬£¬Ã¿¸öWAVÎļþ¶¼ÓëÒ»¸ö¼ÓÔØ·¨Ê½×é¼þ½áºÏÔÚһ·£¬ £¬£¬£¬£¬£¬£¬ÓÃÓÚ½âÂëºÍÖ´Ðаµ²ØÔÚÒôƵÊý¾ÝÖеĶñÒâÄÚÈÝ ¡£¡£¡£¡£¡£¡£¡£ÔÚ²¥·Åʱ£¬ £¬£¬£¬£¬£¬£¬ÆäÖÐһЩWAVÎļþËù²úÉúµÄÒôÀÖûÓÐÏÔÖøµÄÖÊÁ¿ÎÊÌâ»òë´Ì£¬ £¬£¬£¬£¬£¬£¬¶øÆäËüÎļþÒ²½ö²úÉú¾²Ì¬°×ÔëÉù ¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÖØÒª·Ö·¢MetasploitºóÃźÍXMRig¿ó¹¤ ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/attackers-hide-backdoors-and-cryptominers-in-wav-audio-files/

4¡¢×êÑлú¹¹·¢ÏÖ550¶à¸öÕë¶ÔÃÀ¹úÑ¡¾ÙµÄÐéαÓòÃû


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Digital ShadowsÔÚÒ»ÏîÐÂ×êÑÐÖз¢ÏÖ³¬¹ý550¸öÕë¶ÔÃÀ¹úÑ¡ÃñµÄÐéαѡ¾ÙÍøÕ¾ ¡£¡£¡£¡£¡£¡£¡£ÕâÐ©ÍøÕ¾¼Ù×°³É19¸öÃñÖ÷µ³ºÍ4¸ö¹²ºÍµ³×ÜͳºòÑ¡È˵ÄÑ¡¾ÙÓйØÍøÕ¾£¬ £¬£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýÍøÕ¾£¨68%£©Ö»Êǽ«Óû§³Á¶¨Ïòµ½ÁíÒ»¸öÓòÃûÉÏ£¨Í¨³£ÊǾºÕùµÐÊÖµÄÓòÃû£© ¡£¡£¡£¡£¡£¡£¡£µ«Ò²ÓÐ8%µÄÍøÕ¾½«Óû§³Á¶¨ÏòÖÁ¿ÉÄܼӺ¦Ñ¡ÃñÒþÖÔ/´æÔÚ¶ñÒâÈí¼þµÄChrome²å¼þÉÏ ¡£¡£¡£¡£¡£¡£¡£ÓÐ66¸öÓòÃûÍйÜÔÚͳһ¸öIPµØÖ·ÉÏ£¬ £¬£¬£¬£¬£¬£¬²¢ÇÒÊÇͨ¹ýÒþÖÔ±£»£»£»£»£» £»¤·þÎñWhoisGuard×¢²áµÄ£¬ £¬£¬£¬£¬£¬£¬ËüÃÇ¿ÉÄÜÊÇÓÉͳһ¸öÍŶÓÔÚÔËÓª ¡£¡£¡£¡£¡£¡£¡£Digital ShadowsÎÞ·¨½«ÕâЩÐéαÓòÃû¹éÒòÓÚÌØ¶¨µÄÓ×ÎÒ»ò×éÖ¯ ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/over-550-fake-us-election-web/

5¡¢ÐÂÍÚ¿óÈ䳿GraboidÖØÒªÍ¨¹ýDockerÈÝÆ÷´«²¼

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Palo Alto NetworksµÄ×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔDockerÈÝÆ÷µÄÐÂÍÚ¿óÈ䳿Graboid ¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±´ÓGraboidµÄºÅÁîºÍ½ÚÔ죨C2£©·þÎñÆ÷Öз¢ÏÖÁËÒ»¸ö¾ç±¾£¬ £¬£¬£¬£¬£¬£¬¸Ã¾ç±¾Ô̺¬Ò»¸öÓµÓÐ2000¶à¸öÖ¸±êIPµØÖ·µÄÁбí£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔÆäÖÐÓм¸¶àÒѱ»Ï°È¾ ¡£¡£¡£¡£¡£¡£¡£ÔÚϰȾDocker·þÎñºó£¬ £¬£¬£¬£¬£¬£¬¸ÃÈ䳿»á´ÓDocker HubÏÂÔØ¡° pocosow/centos¡± Docker¾µÏñ²¢²¿Ê𣬠£¬£¬£¬£¬£¬£¬ÍÚ¿ó»î¶¯Í¨¹ý±»³ÆÎª¡°gakeaws/nginx¡±µÄµ¥¶ÀÈÝÆ÷½øÐÐ ¡£¡£¡£¡£¡£¡£¡£¸ÃÈ䳿»¹»á´ÓÖ¸±êIPÁбíÖÐËæ»úÑ¡ÔñÏÂÒ»¸öÖ¸±ê ¡£¡£¡£¡£¡£¡£¡£×ÜÌå¶øÑÔ£¬ £¬£¬£¬£¬£¬£¬Æ¾¾ÝUnit 42µÄÊý¾Ý£¬ £¬£¬£¬£¬£¬£¬×î³õµÄ¶ñÒâDocker¾µÏñÒѱ»ÏÂÔØÁË1Íò´ÎÒÔÉÏ£¬ £¬£¬£¬£¬£¬£¬È䳿×ÔÉíÒѱ»ÏÂÔØÁË6500ÂÅ´Î ¡£¡£¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unsecured-docker-hosts-attacked-by-new-graboid-cryptojacking-worm/

6¡¢Å·ÖÞij¹ú¼Ê»ú³¡50%ÒÔÉϵÄϵͳϰȾÍÚ¿óľÂí


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Cyberbit×êÑÐÈËÔ±·¢ÏÖÅ·ÖÞÒ»¸ö¹ú¼Ê»ú³¡µÄ50%ÒÔÉϵŤ×÷վϰȾÁËÃÅÂÞ±ÒÍÚ¿óľÂí ¡£¡£¡£¡£¡£¡£¡£Cyberbit°µÊ¾£¬ £¬£¬£¬£¬£¬£¬¸ÃÍÚ¿óľÂíÊÇÒ»Äê¶àÒÔǰÓÉZscaler·¢ÏÖµÄXMRigµÄÒ»¸ö±äÖÖ£¬ £¬£¬£¬£¬£¬£¬¹¥»÷Õß¶ÔÆä½øÐÐÁ˸üÐÂÒÔÌӱܼì²â ¡£¡£¡£¡£¡£¡£¡£¸Ã±äÖÖÔÚVirusTotalÉÏÖ»»ñµÃÁË16/73µÄ¼ì³öÂÊ ¡£¡£¡£¡£¡£¡£¡£¸ÃľÂí¿ÉÄÜÒѾ­´æÔÚÁËÊýԵŦ·ò£¬ £¬£¬£¬£¬£¬£¬Ä¿Ç°Éв»Ã÷ÏÔ¾ßÌåµÄϰȾý½é£¬ £¬£¬£¬£¬£¬£¬µ«ºÃÐÂÎÅÊǸûú³¡µÄÔËӪûÓÐÊܵ½Ó°Ïì ¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/european-airport-systems-infected-with-monero-mining-malware/