Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飻£»£»£»£»×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶

°ä²¼¹¦·ò 2020-09-22

1.Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊé


1.jpg


Pradeo°ä²¼ÁË¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飬£¬£¬£¬ £¬ £¬£¬½éÉÜÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ë¾·¨¿ò¼Ü¡¢·çÏÕÒÔ¼°±£»£»£»£»£»¤Òƶ¯ÒøÐÐÀûÓ÷¨Ê½°²È«µÄ½â¾ö¹æ»®£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£ ¡£ÆäÖÐд·£¬£¬£¬£¬ £¬ £¬£¬Òƶ¯ÒøÐзþÎñѸËÙÊܵ½Ïû·ÑÕßµÄϲ»¶£¬£¬£¬£¬ £¬ £¬£¬µ½2019Äêµ×£¬£¬£¬£¬ £¬ £¬£¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒÆ¶¯É豸À´ÖÎÀíÆä²ÆÕþ¡£¡£¡£¡£¡£ ¡£µ«ÊÇ×êÑÐÅú×¢£¬£¬£¬£¬ £¬ £¬£¬ÊÖ»úÒøÐÐÀûÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇô°²È«£¬£¬£¬£¬ £¬ £¬£¬¾ÝRSAµÄڲƭ΢·çÏÕµý±¨ÍŶÓ×î½üÍøÂçµÄÊý¾Ý·ÖÎöÏÔʾ£¬£¬£¬£¬ £¬ £¬£¬ÓëÊÖ»úÀûÓÃÓйصÄڲƭÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·­ÁËÒ»·¬¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention/


2.F-Secure°ä²¼2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨


2.jpg


F-Secureµ÷²éÁ˽ñÄêÉϰëÄêÍøÂçÍþвµÄ·¢Õ¹Çé¿ö£¬£¬£¬£¬ £¬ £¬£¬²¢°ä²¼ÁË2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨¡£¡£¡£¡£¡£ ¡£»ã±¨ÏÔʾ£¬£¬£¬£¬ £¬ £¬£¬´Ó½ñÄê3ÔÂÆðÍ·£¬£¬£¬£¬ £¬ £¬£¬ÀûÓø÷ÀàCOVID-19ÎÊÌâµÄ¶ñÒâµç×ÓÓʼþÏÔ×ÅÔö³¤£¬£¬£¬£¬ £¬ £¬£¬ÒÔÓÕʹÓû§Â¶³öÓÚ¸÷Ààµç×ÓÓʼþ¹¥»÷ºÍڲƭÖУ¬£¬£¬£¬ £¬ £¬£¬ÆäÖÐÓÐËÄ·ÖÖ®ÈýµÄµç×ÓÓʼþÖи½¼þÖÐÔ̺¬ÐÅÏ¢ÇÔÈ¡Æ÷¡£¡£¡£¡£¡£ ¡£´Ë±í£¬£¬£¬£¬ £¬ £¬£¬ÔÚ´¹µöÓʼþÖУ¬£¬£¬£¬ £¬ £¬£¬½ðÈÚÒµÊÇ×î³£±»ºýŪµÄÐÐÒµ£¬£¬£¬£¬ £¬ £¬£¬µç×ÓÓʼþÊÇ´«²¼¶ñÒâÈí¼þ×îÊ¢Ðеķ½Ê½£¬£¬£¬£¬ £¬ £¬£¬Õ¼ËùÓÐϰȾý½éµÄÒ»°ëÒÔÉÏ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.f-secure.com/en/press/p/covid-19-spam--phishing-emails--plagued-users-in-first-half-of-2


3.ר¼Ò·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯


3.jpg


×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯£¬£¬£¬£¬ £¬ £¬£¬²¢²»Ò×±»ÆóÒµ°²È«²úÆ·¼ì²âµ½¡£¡£¡£¡£¡£ ¡£Google App EngineÊÇÒ»¸ö»ùÓÚÔÆµÄ·þÎñƽ̨£¬£¬£¬£¬ £¬ £¬£¬ÓÃÓÚÔÚGoogleµÄ·þÎñÆ÷ÉÏ¿ª·¢ºÍÍйÜWebÀûÓᣡ£¡£¡£¡£ ¡£Google App EngineÔÚÌìÉú×ÓÓòʱÈκÎ×Ö¶ÎÃýÎó¶¼²»»áÏÔʾ404δÕÒµ½Ò³Ã棬£¬£¬£¬ £¬ £¬£¬¶øÊÇÏÔʾÆäĬÈÏÒ³Ãæ¡£¡£¡£¡£¡£ ¡£Òò¶ø£¬£¬£¬£¬ £¬ £¬£¬ºÚ¿Í¿ÉÀûÓøÃÖ°ÄÜ´´½¨ÎÞÏÞ¸ö¶ñÒâ´¹µöÍøÕ¾£¬£¬£¬£¬ £¬ £¬£¬ÕâÒ²Ôö³¤ÁËϵͳÖÎÀíÔ±×èÖ¹¸Ã¶ñÒâ»î¶¯µÄÄѶÈ¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-app-engine-feature-abused-to-create-unlimited-phishing-pages/


4.×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶£¬£¬£¬£¬ £¬ £¬£¬ÉÐδ±»ÔÚÒ°ÀûÓÃ


4.jpg


×êÑÐÈËÔ±Åû¶ÁËAction ViewÖеÄXSS·ì϶£¬£¬£¬£¬ £¬ £¬£¬ÆäÊÇÒ»ÖÖÊ¢ÐеÄRuby Gem£¬£¬£¬£¬ £¬ £¬£¬Äܹ»ÔÚRails WebÀûÓ÷¨Ê½¿ò¼ÜÖд¦ÖÃWebÒªÇ󣬣¬£¬£¬ £¬ £¬£¬Ä¿Ç°¸Ã·ì϶ÉÐδ±»ÔÚÒ°ÀûÓᣡ£¡£¡£¡£ ¡£¸Ã·ì϶λÓÚAction ViewÓÃÀ´·­ÒëÓû§ÊäÈëµÄ·­Ò븱ÊÖÖУ¬£¬£¬£¬ £¬ £¬£¬µ±Ò»¸öhtml²»°²È«µÄ×Ö·û´®×÷Ϊȱʡֵ´«µÝ¸øÒ»¸öÃûΪhtml»òÒÔ_html½áβµÄ©Òë¼üʱ£¬£¬£¬£¬ £¬ £¬£¬Ä¬ÈÏ×Ö·û´®½«±»ÃýÎóµØÏóÕ÷Ϊhtml°²È«ÇÒûÓÐתÒ壬£¬£¬£¬ £¬ £¬£¬ÕâÒâζ׏¥»÷ÕßÄܹ»ÊäÈë¼Ù×°³ÉºÏ·¨µÄ¶ñÒâ´úÂë¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/action-view-xss-bug-discovered-in-popular-ruby-gem


5.ÃÀ¹úNewhallÑ§ÇøÏ°È¾ÀÕË÷Èí¼þµ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø


5.jpg


ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄNewhallÑ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬£¬£¬£¬ £¬ £¬£¬µ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø£¬£¬£¬£¬ £¬ £¬£¬Ó°ÏìÁË10Ëù·ÖÆç´°Ð£µÄËùÓÐÔ¶³Ì½ÌÓý¡£¡£¡£¡£¡£ ¡£¸ÃÑ§ÇøµÄÕÆ¹ÜÈ˰µÊ¾£¬£¬£¬£¬ £¬ £¬£¬ºÚ¿ÍµÄ¹¥»÷´ÓÖÜÖçÒ¹¼ä³ÖÐøµ½ÖÜÒ»ÔçÉÏ£¬£¬£¬£¬ £¬ £¬£¬ËûÔÚÊÔͼ½Ó¼ûOutlookºÍµç×ÓÓʼþʱÊÕµ½ÃýÎóÐÅÏ¢¶ø°ÑÎȵ½¸ÃÎÊÌâ¡£¡£¡£¡£¡£ ¡£ÓÐȤµÄÊÇ£¬£¬£¬£¬ £¬ £¬£¬ºÚ¿Í²¢Ã»ÓÐÌá³öڲƭÀÕË÷µÄÐèÒª¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/california-elementary-kids-online-learning-ransomware/159319/


6.ArbiterSportsϰȾÀÕË÷Èí¼þ£¬£¬£¬£¬ £¬ £¬£¬54Íò»áÔ±ÐÅÏ¢±»µÁ


6.jpg


ArbiterSports°µÊ¾£¬£¬£¬£¬ £¬ £¬£¬ËüÒÑÓÚ½ñÄê7ÔÂÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£ ¡£ArbiterSportsÊÇÒ»¼ÒΪÌåÓýÁªÈüÌṩÈí¼þÀ´ÖÎÀí²ÃÅкͽÇÖð¹ÙÔ±µÄ¹«Ë¾£¬£¬£¬£¬ £¬ £¬£¬Õâ´ÎÊÂÎñÉæ¼°µ½ÆäÔ¼54ÍòÃû×¢²á»áÔ±£¬£¬£¬£¬ £¬ £¬£¬ÆäÖÐÔ̺¬²ÃÅÓ×¢ÁªÈü¹ÙÔ±ºÍѧÌôú±í¡£¡£¡£¡£¡£ ¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§µÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬ £¬ £¬£¬ÀýÈçÕÊ»§Óû§Ãû¡¢ÃÜÂë¡¢ÕæÊµÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍÉç»á°²È«ºÅÂë¡£¡£¡£¡£¡£ ¡£Ä¿Ç°£¬£¬£¬£¬ £¬ £¬£¬ ¸Ã¹«Ë¾°µÊ¾ÆäÒѾ­Ö§¸¶ÁËÊê½ð£¬£¬£¬£¬ £¬ £¬£¬²¢È·ÈϺڿÍ×éÖ¯ÒÑɾ³ý±»µÁÊý¾Ý¡£¡£¡£¡£¡£ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-of-540000-sports-referees-taken-in-failed-ransomware-attack/