¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20180612

°ä²¼¹¦·ò 2018-06-12
¡¾·ÖÎö»ã±¨¡¿×êÑÐÍŶӰ䲼5GʱÆÚIoTÉ豸¼°ÎÀÐǵݲȫ·çÏջ㱨


Ëæ×Å5G·äÎÑÍøÂç¼¼ÊõºÍIoTµÄ²»ÐÝÀ©´ó £¬ÎÀÐÇÒѾ­³ÉΪÎïÁªÍøºÍ»¥ÁªÍø¹Ø¼ü»ù´¡ÉèÊ©µÄ³ÁÒª×é³É²¿ÃÅ £¬È·±£ÎÀÐǵݲȫӵÓгÁÒªµÄÒâ˼¡£Õë¶ÔÎÀÐǵĹ¥»÷ÏòÁ¿¿ÉËùÒÔÌì¿ÕºÍµØÃæÖ®¼ä £¬Ò²¿ÉËùÒÔµØÃæÖÁÎÀÐÇÔÙ´«²¼ÖÁÆäËüÎÀÐÇ £¬»òÕßÎÀÐÇÖÁµØÃæÔÙ´«²¼ÖÁÆäËü´¦Ëù¡£³£¼ûµÄ¹¥»÷ÀàÐÍÔ̺¬µçÐÅڲƭ¡¢¿çÎÀÐǹ¥»÷¡¢ÀÄÓÃÎÀÐǵ绰µÈ £¬¹¥»÷³¡¾°Ô̺¬ÐéαµØÇò»ùÕ¾¡¢¼Ù×°³ÉÎÀÐǵÄͨѶ¡¢ÀûÓÃÎÀÐÇÍøÂç¼äµÄÐÅÀµµÈ¡£


Ô­ÎÄÁ´½Ó£ºhttps://blog.trendmicro.com/trendlabs-security-intelligence/attack-vectors-in-orbit-need-for-satellite-security-in-5g-iot/


¡¾Íþвµý±¨¡¿×êÑÐÈËÔ±·¢ÏÖ³¬¹ý1.5Íò¸öAndroidÉ豸µÄADBµ÷ÊԶ˿ڶ³ö


×êÑÐÈËÔ±Kevin Beaumont³Æ³¬¹ý1.5Íò¸öAndroidÉ豸µÄADB¶Ë¿Ú¶³ö £¬ADB£¨Android Debug Bridge£©ÊÇAndroidϵͳµÄÒ»¸ö¹ÊÕÏÅųý¹¤¾ß £¬Ëü»¹Äܹ»ÊÚȨÓû§½Ó¼ûһЩÃô¸Ð¹¤¾ß£¨Ô̺¬Unix shell£©¡£ÎÊÌâÔÚÓÚһЩ¹©¸øÉ̽«ÆôÓÃÁËADB over WiFiÖ°ÄܵÄÉ豸½»¸¶¸øÓû§Ê¹Óà £¬ÕâʹµÃÔÚÓû§²»ÖªÇéµÄÇé¿öÏ £¬ÆäÉ豸¿Éͨ¹ýTCP¶Ë¿Ú5555Ô¶³Ì½Ó¼û £¬²¿ÃÅÉ豸Òò¶øÏ°È¾ÃÅÂÞ±Ò¿ó¹¤ADB.Miner¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/tens-of-thousands-of-android-devices-are-exposing-their-debug-port/


¡¾Íþвµý±¨¡¿×êÑÐÍŶӳƹ¥»÷Õß´Ó²»°²È«µÄÒÔÌ«·»½ÚµãÖÐÇÔÈ¡³¬¹ý2000ÍòÃÀÔª


°²È«×êÑÐÈËÔ±ÖÒ¸æ³ÆÒ»¸öÍøÂç·¸×ï×é֯ͨ¹ý½Ù³ÖÍøÉ϶³öµÄ²»°²È«ÅäÖõÄÒÔÌ«·»½Úµã £¬ÔÚ´Óǰ¼¸¸öÔÂÄÚÇÔÈ¡ÁË38642¸öÒÔÌ«±Ò £¬¼ÛÖµ³¬¹ý2000ÍòÃÀÔª¡£Ò»Ð©ÒÔÌ«·»½ÚµãʹÓÃGeth¿Í»§¶Ë £¬²¢ÇÒÊ¢¿ªÁËJSON-RPC¶Ë¿Ú8545¡£Í¨¹ýJSON-RPCÓû§Äܹ»Ô¶³Ì½Ó¼ûÒÔÌ«·»Çø¿éÁ´ºÍ½ÚµãµÄÖ°ÄÜ £¬Ô̺¬´ÓÒѽâËøÕË»§·¢ËÍÂòÂô¡£¹¥»÷Õßͨ¹ýɨÃ軥ÁªÍøÉÏÊ¢¿ªµÄ8545¶Ë¿ÚÇÔÈ¡Óû§µÄ×ʽð¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/ethereum-geth-hacking.html


¡¾¹¥»÷ÊÂÎñ¡¿º«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿ÍÈëÇÖ £¬ËðʧԼ3000ÍòÖÁ4000ÍòÃÀÔª


ÉÏÖÜÈÕº«¹ú¼ÓÃÜÇ®±ÒÂòÂôËùCoinrailÔâºÚ¿Í¹¥»÷ £¬ÈëÇÖÕßÇÔÈ¡ÁËPundi X£¨NPXS£©¡¢NPER£¨NPER£©ºÍAston£¨ATX£©µÄ²¿ÃÅICO´ú±Ò £¬ÂòÂôËùûÓÐÅû¶Óйر»µÁ×ʽðµÄ¾ßÌåÊý×Ö £¬µ«ÓÐЧ»§¸ú×ÙÁËÈëÇÖÕßµÄÕË»§µØÖ· £¬ÒÔΪÓйر»µÁ×ʽð¼ÛÖµÔÚ3000Íòµ½4000ÍòÃÀÔªÖ®¼ä £¬ÆäÖÐÔ¼Ò»°ëΪNPXS´ú±Ò¡£Coinrail³ÆÕýÓëÊÜÓ°ÏìµÄICO¹«Ë¾ºÏ×÷ÒÔ¶³½á±»µÁµÄ´ú±Ò¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/south-korean-cryptocurrency-exchange-coinrail-gets-hacked/


¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖÒ»¼Ó6ÊÖ»ú´æÔÚ°²È«·ì϶ £¬¿ÉÔÊÐí¹¥»÷ÕßÊÕÊÜÉ豸


Edge Security°²È«×êÑÐÈËÔ±Jason Donenfeld·¢ÏÖÒ»¼Ó6ÊÖ»úÉϵÄbootloader²¢Î´ÆëÈ«Ëø¶¨ £¬¿ÉÔÊÐí¹¥»÷ÕßдÈë¶ñÒâ¾µÏñºÍÆëÈ«ÊÕÊÜÉ豸¡£¸Ã·ì϶µÄÀûÓñØÒª¶ÔÉ豸µÄÎïÀí½Ó¼û¡£ÔÚÑÝʾÊÓÆµÖÐ £¬×êÑÐÈËÔ±Ö»ÆÆ·ÑÁ˼¸·ÖÖӾͽ«¶ñÒâ¾µÏñͨ¹ýADBµÄ¼±¾çÊèµ¼ºÅÁîдÈëÉ豸¡£Ò»¼ÓÒѾ­È·ÈÏÁ˸ÃÎÊÌâ £¬²¢³Ðŵ½«°ä²¼ÓйØÈí¼þ¸üС£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/oneplus6-bootloader-root.html


¡¾°²È«·ì϶¡¿×êÑÐÈËÔ±·¢ÏÖABBÃŽûϵͳ´æÔÚ¶à¸ö°²È«·ì϶


ERNW×êÑÐÈËÔ±Maxim RuppºÍFlorian GrunowÔÚÈðÊ¿ABB¹«Ë¾µÄÃŽûÖÎÀíϵͳÖз¢ÏÖ¶à¸ö°²È«·ì϶ £¬ÊÜÓ°ÏìµÄ×é¼þÊǹ̼þ°æ±¾3.39¼°Ö®Ç°µÄABB IPÍø¹Ø¡£·ì϶ÁìÓòÔ̺¬ÈÏÖ¤ÈÆ¹ý·ì϶£¨CVE-2017-7931£©¡¢Ã÷ÎÄÃÜÂëй¶·ì϶£¨CVE-2017-7933£©¡¢¿çÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¨CVE-2017-7906£©ºÍÒ»¸öÔ¶³Ì´úÂë×¢Èë·ì϶¡£ABBÔڹ̼þ°æ±¾3.40Öн¨¸´ÁËÕâЩ·ì϶¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/critical-flaws-expose-abb-door-communication-systems-attacks