Wi-FiÈȵã²éÕÒÆ÷й¶200ÍòWi-FiÃÜÂ룻¸æ°×Èí¼þPreAMoÏÂÔØ´ï9000Íò´Î£»123456ÈÔÊÇ×î³£ÓÃÃÜÂë
°ä²¼¹¦·ò 2019-04-23
Ó¢¹ú¹ú¶ÈÍøÂ簲ȫÖÐÐÄ£¨NCSC£©°ä²¼×î³£±»ºÚ¿ÍÈëÇÖµÄÃÜÂëÁÐ±í£¬ÒÔ¼¤ÀøÓû§Ñ¡ÔñÇ¿ÃÜÂ롣ƾ¾ÝÕâÏî×êÑУ¬È«ÇòÈÔÓÐ2320Íò¸öÕË»§Ê¹ÓÃ123456×÷ΪÃÜÂ룬ÕâÒ²ÊÇʹÓÃÊýÁ¿×î¶àµÄÈõÃÜÂë¡£µÚ¶þÃûÊÇ123456789£¬ÓÐ770Íò¸öÕË»§Ê¹ÓÃÁ˸ÃÃÜÂë¡£¶øºóÊÇqwerty£¨380Íò£©¡¢password£¨360Íò£©ºÍ111111£¨310Íò£©¡£Óû§Äܹ»´ÓHave I Been PwnedÍøÕ¾Éϼì²â×Ô¼ºµÄÃÜÂëÔÚÁбíÖгöÏֵĴÎÊý¡£
ÔÎÄÁ´½Ó£º
https://www.digitaltrends.com/computing/online-passwords-research-confirms-millions-are-using-123456/2.Google PlayÖиæ°×Èí¼þPreAMo£¬ÏÂÔØÁ¿´ï9000Íò´Î
Checkpoint×êÑÐÈËÔ±ÔÚGoogle PlayÖз¢ÏÖ¸æ°×Èí¼þPreAMo£¬¸Ã¸æ°×Èí¼þ¼Ù×°³É6¸öAPP£¬×ÜÏÂÔØÁ¿³¬¹ý9000Íò´Î¡£PreAMoÖØÒªÕë¶ÔÈý¸ö¸æ°×´úÀíÉÌ - Presage¡¢AdmobºÍMopub½øÐÐڲƣ¬¹¥»÷ÕßÕë¶Ôÿ¸ö¸æ°×´úÀíÉÌʹÓÃ·ÖÆçµÄ´¦Öò½Ö裬µ«Ê¹ÓÃÁËÒ»ÑùµÄC£¦C·þÎñÆ÷£¨res.mnexuscdn[.]com£©£¬ÓÃÓÚ·¢ËÍͳ¼ÆÐÅÏ¢ºÍ½Ó¹ÜÅäÏàÐÅÏ¢¡£Google PlayÔÚ½Óµ½»ã±¨ºóÒѾϼÜÁËÕâЩÊÜϰȾµÄAPP¡£
ÔÎÄÁ´½Ó£º
https://research.checkpoint.com/preamo-a-clicker-campaign-found-on-google-play/3.jQuery°ä²¼Ð°汾v3.4.0£¬½¨¸´prototype pollution·ì϶
jQueryÔÚа汾v3.4.0Öн¨¸´ÁËÒ»¸ö±»³ÆÎª¡°ÔÐÍ´«È¾£¨prototype pollution£©¡±µÄ°²È«·ì϶¡£ÔÐÍ´«È¾ÊÇÖ¸¹¥»÷Õßͨ¹ýijÖÖ¼¿Á©Åú¸ÄJavaScript¶ÔÏóµÄprototype£¬Í¨¹ý´¥·¢JavaScriptÒì³£µ¼Ö»ؾø·þÎñ»ò´Û¸ÄÔ´´úÂë½øÐÐ×¢È룬×îÖÕµ¼ÖÂÀûÓ÷¨Ê½±ÀÀ£»ò½Ù³Ö¡£¹ÌÈ»·ì϶ÑϳÁÐԽϸߣ¬µ«ÔÐÍ´«È¾¹¥»÷²¢²»Äܱ»´ó¹æÄ£ÀûÓã¬ÓÉÓÚ¹¥»÷´úÂë±ØÐëÕë¶Ô·ÖÆçµÄÖ¸±ê½øÐÐ΢µ÷¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/popular-jquery-javascript-library-impacted-by-prototype-pollution-flaw/4.Wi-FiÈȵã²éÕÒÆ÷й¶200ÍòWi-FiÃÜÂë
ƾ¾ÝTechCrunchµÄ»ã±¨£¬Ò»¸öÃûΪWiFi FinderµÄAndroid APPй¶Á˳¬¹ý200Íò¸öWi-FiÍøÂçµÄÃÜÂ룬ÆäÖÐÊýÍò¸öWi-FiÈȵãλÓÚÃÀ¹ú¡£¸ÃAPPÓÃÓÚÔ®ÊÖÓû§²éÕÒWi-FiÈȵ㣬ÆäÏÂÔØÁ¿´ïÊýǧ´Î¡£×êÑÐÈËÔ±·¢ÏÖ¸ÃAPPµÄÊý¾Ý¿â¶³öÔÚÍøÉÏÇÒδÊܱ£»¤£¬Êý¾Ý¿âÖеļͼÔ̺¬Wi-FiÍøÂçµÄÃû³Æ¡¢¾«È·µÄµØÀíµØÎ»¡¢BSSIDºÍÃ÷ÎÄÃÜÂ룬µ«²»Ô̺¬Wi-FiËùÓÐÕßµÄÁªÏµÐÅÏ¢¡£ÔÆ·þÎñ¹«Ë¾DigitalOceanÔÚ½Óµ½»ã±¨ºóɾ³ýÁ˸ÃÊý¾Ý¿â¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/leaky_app_data/144029/5.Steps To RecoveryÒ½ÁÆÖÐÐÄÒâ±íй¶14.6Íò»¼ÕßÐÅÏ¢
±öϦ·¨ÄáÑÇÖÝÒ½ÁÆÖÐÐÄSteps To RecoveryµÄÒ»¸öElasticSearchÊý¾Ý¿âÒòÅäÖÃÃýÎó¶øÎ´Êܱ£»¤£¬µ¼ÖÂ146316Ãû»¼ÕßµÄPIIÐÅϢй¶¡£¸ÃÊý¾Ý¿â´óÓ×Ϊ1.45GB£¬Ô̺¬491Íò¸öÓйØÎĵµ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬»¼ÕߵĴºÇï¡¢µ®ÉúÈÕÆÚ¡¢µ±Ç°µØÖ·¡¢´ÓǰµÄµØÖ·¡¢µç×ÓÓʼþµØÖ·ÒÔ¼°»¼Õß¾ìÊôµÄÐÕÃûºÍµç»°ºÅÂë¡£¸ÃÒ½ÁÆÖÐÐÄÉÐδ֪ͨÊÜÓ°ÏìµÄ»¼Õß¡£
ÔÎÄÁ´½Ó£º
https://cyware.com/news/misconfigured-elasticsearch-database-exposes-49-million-sensitive-documents-of-steps-to-recovery-treatment-center-1e4608886.Bodybuilding.comÔâ´¹µö¹¥»÷£¬²¿ÃÅÔ±¹¤µÄÐÅϢй¶
Bodybuilding.com°ä²¼ÉêÃ÷³Æ¸Ã¹«Ë¾Ôâµ½´¹µö¹¥»÷£¬²¿ÃÅÔ±¹¤µÄÐÅϢй¶¡£¸Ã¹«Ë¾ÔÚ4Ô·ݵĵ÷²éÅú×¢£¬´¹µö¹¥»÷²úÉúÔÚ2018Äê7Ô£¬¹¥»÷Õß¿ÉÄܽӼûÁ˲¿ÃÅÔ±¹¤µÄÓ×ÎÒÐÅÏ¢£¬Ô̺¬ÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Õ˵¥/ËÍ»õµØÖ·¡¢µç»°ºÅÂë¡¢¶©µ¥º¹ÇàµÈ£¬µ«²»Ô̺¬ÆëÈ«µÄÐÅÓþ¿¨»ò½è¼Ç¿¨ºÅÂë¡£¸Ã¹«Ë¾ÔÚÓë·¨ÂÉ»ú¹¹ºÍ°²È«×¨¼ÒºÏ×÷½â¾ö¸ÃÎÊÌâ¡£
ÔÎÄÁ´½Ó£º
https://www.databreaches.net/bodybuilding-com-experiences-data-security-incident/


¾©¹«Íø°²±¸11010802024551ºÅ