¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181224

°ä²¼¹¦·ò 2018-12-24
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬³¬¹ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹µö¹¥»÷£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄ¹¤×÷ÈËԱʹ´¦½Ó¼ûÁ˸ÃÑ§ÇøµÄÍøÂç·þÎñ£¬³¬¹ý50ÍòѧÉú¡¢¸¸Ä¸ÒÔ¼°¹¤×÷ÈËÔ±µÄÐÅϢй¶¡£SDUSD³Æ¸ÃδÊÚȨ½Ó¼û³ÖÐøÁ˽«½üÒ»ÄêµÄ¹¦·ò£¨2018Äê1Ôµ½11Ô£©£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ÒäÖÁ2008ÖÁ2009ѧÄ꣬Ô̺¬Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢µ®ÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ´¹Î£ÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄ¹¤×ÊÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢Ð¼¼ÊõÖ§³¶à¿Æ­Ò³Ã潫µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



Google ChromeµÄbug»ã±¨ÖÐÅû¶ÁËÒ»¸öеļ¼ÊõÖ§³¶à¿Æ­»î¶¯£¬¸ÃÚ¿Æ­ÍøÒ³½«Ê¹ÓÃJavaScriptÑ­»·ºÄ¾¡ÍÆËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¸ÃÍøÒ³µÄ±êÌâΪ¡°³ÁÒªÐÅÏ¢¡±£¬¼Ù×°³ÉÌáÐÑϰȾµÄWindowsÃýÎ󾯱¨£¬´ËÒ³ÃæÔ̺¬µÄJavaScript½«ÊÓίÀÀÆ÷³Á¸´Ìø×ªÖÁ# URL£¬²¢À´»Øµã»÷ºóÍ˺Íǰ½ø°´Å¥£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£Óû§¿Éͨ¹ýɱËÀChrome¹ý³ÌÀ´ÊµÏÖ¿¨ËÀÇé¿ö¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/


3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹µö¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¹ú¼ÊÌØÉâ×éÖ¯µÄ»ã±¨£¬¸Ã×éÖ¯·¢ÏÖÁ½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÓòµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹µö»î¶¯¡£ÕâЩ´¹µö»î¶¯¼Ù×°³ÉÕË»§¾¯±¨£¬ÖØÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤²½ÖèµÄGmailºÍYahooÕÊ»§¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþ·þÎñ£¬ÀýÈçProtonMailºÍTutanota£¬Ö»¹ÜËüÃÇĬÈÏѡȡÁ˸ü¸ß¼¶´ËÍⰲȫÐÔºÍÒþÖÔÐÔ¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»³É¹¦Èƹý£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½ÇÖº¦¡£

 

 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/


4¡¢Õë¶ÔOrangeµ÷Ôì½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Bad Packets LLC×êÑÐÈËÔ±Troy Mursch·¢ÏÖ¹¥»÷ÕßÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷Ôì½âµ÷Æ÷¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎåÆðÍ·£¬¹¥»÷ÕßÀûÓÃOrange LiveBoxÉ豸Öеķì϶£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£×êÑÐÈËÔ±·¢ÏÖ½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷Ôì½âµ÷Æ÷£¬¾ø´óÎÞÊýλÓÚ·¨¹úºÍÎ÷°àÑÀ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/


5¡¢×êÑÐÈËÔ±Åû¶Facebookµã»÷½Ù³Ö·ì϶£¬µ«Facebook²»³ïË㽨¸´

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


²¨À¼°²È«×êÑÐÈËÔ±·¢ÏÖFacebookµÄAndroidÒÆ¶¯°æ±¾´æÔÚÒ»¸öµã»÷½Ù³Ö·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ýiframe±êÇ©ÀûÓø÷ì϶ÔÚÓû§µÄFacebookÉϰ䲼Á´½Ó¡£×êÑÐÈËÔ±ÒÔΪ¸Ã·ì϶ÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·ÓйØ£¬¸Ã±êÍ·Äܹ»Í¨Öªä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¹¥»÷ÕßÄܹ»½«ÍøÒ³¼ÓÔØµ½µö¶üÍøÒ³µÄ¶¥²ãÖУ¨²»Ë½¼ûµÄiFrame£©£¬Óû§½«¿´¼ûµö¶üÍøÒ³£¬µ«ÏÖʵÉÏÓë¸ÃiFrame½øÐн»»¥¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸ö°²È«ÎÊÌ⣬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÆëÈ«ÐÔ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/


6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬UberÔÙ±»·¨¹úÊý¾Ý±£»¤»ú¹¹·£¿î40ÍòÅ·Ôª

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


2016ÄêUberÔâ·êÊý¾Ýй¶ÊÂÎñ£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄÓ×ÎÒÊý¾Ýй¶£¬µ«Ö±µ½Ò»Äê¶àÒÔÀ´µÄ2017Äê11Ô¸ù«Ë¾²ÅÏò±í½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£2018Äê9Ô£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄºÍ½â½ð¡£2018Äê11Ô£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£»¤»ú¹¹±ðÀëÏòUber·£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿î¡£´Ë¿Ì£¬·¨¹úµÄÊý¾Ý±£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿î40ÍòÅ·Ôª¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.html


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù