¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20190315

°ä²¼¹¦·ò 2019-03-15
1¡¢Wordpress CSRF·ì϶£¬¿Éµ¼ÖÂÖ´ÐÐËÁÒâ´úÂë

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


RIPS×êÑÐÈËÔ±Simon Scannell·¢ÏÖWordpress 5.1ÖдæÔÚÒ»¸öCSRF·ì϶£¬¿ÉÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâ´úÂë¡£¹¥»÷Õßͨ¹ýºýÅªÍøÕ¾ÖÎÀíÔ±½Ó¼ûÔ̺¬·ì϶ÀûÓôúÂëµÄ¶ñÒâÍøÕ¾£¬Äܹ»ÏòÖ¸±êWordPressÍøÕ¾×¢Èë´æ´¢ÐÍXSS payload£¬²¢ÀûÓøÃpayloadÆëÈ«½ÚÔì¸ÃÍøÕ¾¡£±¾ÖÜÈýWordPressÍŶӰ䲼ÁËа汾WordPress 5.1.1ÒÔ½¨¸´¸Ã·ì϶¡£

   

Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2019/03/hack-wordpress-websites.html

2¡¢Ë¼¿Æ°ä²¼°²È«¸üУ¬½¨¸´CSPCÈí¼þÖеĺóÃÅÕË»§·ì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


˼¿Æ½¨¸´ÁËͨ³£·þÎñÆ½Ì¨ÍøÂçÆ÷£¨CSPC£©Èí¼þÖеÄÒ»¸öºóÃÅÕË»§·ì϶£¬¸Ã·ì϶£¨CVE-2019-1723£©Ô̺¬Ò»¸ö´øÓо²Ì¬ÃÜÂëµÄĬÈÏÕË»§£¬¹ÌÈ»¸ÃÕË»§Ã»ÓÐÖÎÀíԱȨÏÞ£¬µ«Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶»ñµÃϵͳµÄ½Ó¼ûȨÏÞ¡£Æ¾¾Ý˼¿ÆµÄ˵·¨£¬¸Ã·ì϶ӰÏìÁËCSPC°æ±¾2.7.2µ½2.7.4.5ÒÔ¼°ËùÓеÄ2.8.x°æ±¾£¬²¢ÒÑÔÚ°æ±¾2.7.4.6ºÍ2.8.1.2Öеõ½½¨¸´¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/82391/security/common-services-platform-collector-flaw.html

3¡¢°Í»ùË¹Ì¹ÒÆÃñ¾Ö¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬±»Ö²Èë¼üÅ̼ͼľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

°Í»ùË¹Ì¹ÒÆÃñÓ뻤ÕվֵĹÙÍøtracking.dgip.gov[.]pkÔâºÚ¿ÍÈëÇÖ£¬¹¥»÷ÕßÔÚÍøÕ¾ÉÏÖ²ÈëÁ˶ñÒâ´úÂëÒÔ¸ú×ÙÓû§¡£±»Ö²ÈëµÄpayloadÊÇScanBox£¬¸Ã±äÖÖÄܹ»ÍøÂçÍøÕ¾½Ó¼ûÕßµÄϵͳÐÅÏ¢²¢½øÐмüÅ̼ͼ¡£´Ë±í£¬¸Ã±äÖÖ»¹ÊÔͼ¼ì²â½Ó¼ûÕßÊÇ·ñ×°ÖÃÁËÌØ¶¨µÄ°²È«²úÆ·¡¢½âѹËõ¹¤¾ßºÍÐé¹¹»ú¹¤¾ßµÈ£¬Õâ¸öÁÐ±í³¤´ï77Ï¸ÃÐÐΪ¿ÉÄÜÊÇÕë¶ÔÌØ¶¨Ö¸±êȺÌåµÄË®¿Ó¹¥»÷µÄÒ»²¿ÃÅ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/pakistani-government-site-compromised-logs-visitor-keystrokes/

4¡¢SteamÉÏ39£¥µÄCS 1.6·þÎñÆ÷ÏòÍæ¼Ò·Ö·¢BelonardľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÔÚDr.WebµÄÒ»·Ýл㱨ÖУ¬×êÑÐÈËÔ±·¢ÏÖSteam¹Ù·½¿Í»§¶ËÉϵÄÔ¼5000¸öCS 1.6·þÎñÆ÷ÖÐÓÐ1951¸ö·þÎñÆ÷£¨39%£©ÏòÍæ¼Ò·Ö·¢BelonardľÂí¡£¹¥»÷ÕßÀûÓÃÕâÖÖ·½Ê½´´½¨ÁËBelonard½©Ê¬ÍøÂ磬µ±Íæ¼ÒÏνӵ½¶ñÒâ·þÎñÆ÷ʱ£¬Belonard½©Ê¬ÍøÂçÀûÓÃCS 1.6¿Í»§¶ËÖеÄRCE·ì϶½øÐÐϰȾ¡£ÓÉÓÚCS 1.6ÊÇValve°ä²¼µÄ¸ÃÓÎÏ·×îºóÒ»¸ö°æ±¾£¬Òò¶ø¿Í»§¶ËÖеÄRCE·ì϶²»»áµÃµ½½¨¸´£¬ËùÓÐÍæ¼Ò¶¼¿ÉÄܳÉΪDZÔÚµÄÊܺ¦Õß¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/39-percent-of-all-counter-strike-16-servers-used-to-infect-players/

5¡¢ÐÂCryptoSinkÍÚ¿ó¹¥»÷£¬ÖØÒªÕë¶ÔElasticsearch·þÎñÆ÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


F5 Networks×êÑÐÍŶӷ¢ÏÖÒ»¸öÕë¶ÔElasticsearch·þÎñÆ÷µÄжñÒâ»î¶¯CryptoSink£¬¹¥»÷ÕßÀûÓÃ2014ÄêµÄ·ì϶£¨CVE-2014-3120£©À´´«²¼ÃÅÂޱҿ󹤡£ÔÚLinuxÉÏ£¬¹¥»÷ÕßʹÓÃÁËһЩÒÔǰδ֪µÄ¶ñÒâÈí¼þ£¨Ô̺¬ÏÂÔØ·¨Ê½ºÍľÂí£©£¬·À²¡¶¾½â¾ö¹æ»®ÎÞ·¨¼ì²âµ½ËüÃÇ¡£¹¥»÷Õß»¹»á½«ÆäËüÁ÷Á¿µ¼Èë127.1.1.1À´É±ËÀÆäËüµÄ¾ºÕù¿ó¹¤¡£ÆäÓµÓжà¸öC&C·þÎñÆ÷£¬µ±Ç°»îÔ¾µÄC&C·þÎñÆ÷λÓÚÖйú¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.f5.com/labs/articles/threat-intelligence/-cryptosink--campaign-deploys-a-new-miner-malware

6¡¢PoS¶ñÒâÈí¼þDMSniff£¬×Ô2016ÄêÀ´Ò»Ö¹Øë¶ÔÖÐÓ×ÐÍÆóÒµ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Flashpoint×êÑÐÍŶӷ¢ÏÖPoS¶ñÒâÈí¼þDMSniff×Ô2016ÄêÆðÍ·Ò»Ïò»îÔ¾£¬ËüÖØÒªÕë¶ÔÖÐÓ×ÐÍÆóÒµ£¬Ô̺¬²Í¹Ý¡¢¾çÔºÒÔ¼°ÆäËüÓéÀÖ³¡ËùµÈ¡£DMSniffÖØÒªÇÔÊØÐÅÓþ¿¨Êý¾Ý£¬Ëü»á²»ÐÝä¯ÀÀ¹ý³ÌÁбí£¬²¢´ÓÄÚ´æÖнâÎöÐÅÓþ¿¨ºÅ£¬¶øºó½«ÕâЩÐÅÏ¢·¢ËÍÖÁC&C·þÎñÆ÷¡£DMSniff×Ô2016ÄêÒÔÀ´ÖÁÉÙʹÓùý11ÖÖDGAËã·¨±äÌ壬ÕâÒâζ×ÅÆäÖÁÉÙ²¿Êð¹ý11¸ö°æ±¾¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/dmsniff-point-of-sale-malware-silently-attacked-smbs-for-years/

ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù