Windows¼Çʱ¾´úÂëÖ´Ðзì϶£»Docker¾ºÕùǰÌá·ì϶£¬Ó°ÏìËùÓÐDocker°æ±¾£»DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷

°ä²¼¹¦·ò 2019-05-30
1Docker佨¸´µÄ¾ºÕùǰÌá·ì϶£¬Ó°ÏìËùÓÐDocker°æ±¾


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


×êÑÐÈËÔ±Åû¶DockerÖÐ佨¸´µÄ¾ºÕùǰÌá·ì϶£¬¸Ã·ì϶ӰÏìÁËËùÓеÄDocker°æ±¾ ¡£¸Ã·ì϶ÀàËÆÓÚCVE-2018-15664£¬¿ÉÔÊÐí¹¥»÷ÕßÔÚÖ¸¶¨µÄ·¨Ê½¶Ô×ÊÔ´½øÐвÙ×÷֮ǰÅú¸Ä×ÊÔ´õè¾¶£¬´Ó¶ø¿ÉÄÜ»ñµÃËÁÒâÎļþµÄ¶Áд½Ó¼ûȨÏÞ£¬Õâ±»³ÆÎªTOCTOUÀàÐ͵Äbug ¡£¸Ã·ì϶µÄÖ÷ÌâÔ´ÓÚFollowSymlinkInScopeÖ°ÄÜÒ×ÊÜTOCTOU¹¥»÷ ¡£×êÑÐÈËÔ±ÒѾ­°ä²¼ÁËPoC´úÂë ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/unpatched-flaw-affects-all-docker-versions-exploits-ready/

2DuckDuckGoÒ×ÊÜURLºýŪ¹¥»÷£¬×°ÖÃÁ¿´ï500Íò´Î


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


°²È«×êÑÐÈËÔ±Dhiraj Mishra·¢ÏÖAndroid¿ªÔ´ä¯ÀÀÆ÷DuckDuckGo´æÔÚÒ»¸öURLºýŪ·ì϶£¨CVE-2019-12329£©£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ºýŪÓû§ÏàÐŽӼûµÄÊÇ¿ÉÐÅÍøÕ¾ ¡£¸Ã·ì϶ÔÊÐíʹÓÃJavaScriptºýŪä¯ÀÀÆ÷µÄµØÖ·À¸£¬Í¨¹ýsetIntervalº¯Êýÿ10µ½50ºÁÃë³ÁмÓÔØÒ»¸öURL ¡£DuckDuckGo°²È«ÍŶÓÒÔΪ¸Ã·ì϶²»±ØÒª½¨¸´ ¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/duckduckgo-android-browser-vulnerable-to-url-spoofing-attacks/

3¹È¸è×êÑÐÈËÔ±ÔÚWindows¼Çʱ¾Öз¢ÏÖ´úÂëÖ´Ðзì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

Google Project Zero×êÑÐÔ±Tavis OrmandyÔÚ΢ÈíµÄWindows¼Çʱ¾Öз¢ÏÖÒ»¸ö´úÂëÖ´Ðзì϶£¬OrmandyÒÑÏò΢Èí»ã±¨Á˸ÃÎÊÌâ ¡£·ì϶µÄϸ½ÚÉÐδÅû¶£¬µ«OrmandyÔ¤¼Æ¸Ã·ì϶ÊÇÒ»¸öÄÚ´æ°Ü»µ·ì϶£¬ËûÔÚTwitterÉÏ·ÖÏíµÄͼƬÑÝʾÁËÈôºÎÔÚ¼Çʱ¾Öе¯³öshell ¡£Æ¾¾Ý¹È¸èµÄ·ì϶Åû¶Õþ²ß£¬Ormandy½«ÔÚ90Ììºó»ò΢Èí°ä²¼½¨¸´²¹¶¡ºóÅû¶¸ü¶à·ì϶ϸ½Ú ¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/86297/hacking/code-execution-flaw-notepad.html

4жñÒâÍڿ󺣳±Nansh0u£¬ÒÑϰȾ5Íǫ̀·þÎñÆ÷


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝGuardicore LabsµÄ»ã±¨£¬Ò»¸öеĶñÒâÍÚ¿ó»î¶¯Nansh0uÒѾ­Ï°È¾Á˶à´ï5Íǫ̀·þÎñÆ÷ ¡£¸ÃÍڿ󺣳±×Ô2ÔÂÒÔÀ´Ò»Ïò»îÔ¾£¬Êܺ¦Õß´óÎÞÊýλÓÚÖйú¡¢ÃÀ¹úºÍÓ¡¶È£¬¹²¸²¸ÇÁË90¸ö¹ú¶È ¡£Êܵ½¹¥»÷µÄÐÐÒµÔ̺¬Ò½ÁƱ£½¡¡¢µçÐÅ¡¢Ã½ÌåºÍITÁìÓò ¡£Êܵ½Ï°È¾ºó£¬¹¥»÷Õß»áÔÚÖ¸±ê·þÎñÆ÷ÉÏ×°ÖüÓÃܿ󹤺ÍÄÚºËģʽrootkit£¬ÒÔÍÚ¾ò¿ªÔ´¼ÓÃÜÇ®±ÒTurtleCoin ¡£ÔÚ4Ô·Ý£¬×êÑÐÈËÔ±¹Û²ìµ½Èý´ÎÀàËÆµÄ¹¥»÷£¬ËùÓеÄÔ´IPµØÖ·¶¼À´×ÔÄÏ·Ç£¬ÇÒʹÓÃÒ»ÑùµÄ¹¥»÷¹ý³ÌºÍ¹¥»÷²½Öè ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/50k-servers-infected-with-cryptomining-malware-in-nansh0u-campaign/145140/

5ÐÂÎ÷À¼²ÆÕþ²¿ÔâºÚ¿ÍÈëÇÖ£¬²ÆÕþÔ¤ËãÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ÐÂÎ÷À¼²ÆÕþ²¿³¤Gabriel Makhlouf°µÊ¾²ÆÕþ²¿ÒÑÈ·ÈÏÔâµ½ºÚ¿Í¹¥»÷£¬²ÆÕþÔ¤ËãÐÅÏ¢¿ÉÄÜй¶ ¡£Makhlouf°µÊ¾Ã»ÓÐÖ¤¾ÝÅú×¢ÓÐÈκÎÓ×ÎÒÐÅϢй¶ ¡£²ÆÕþ²¿ÒÑÆ¾¾Ý¹ú¶ÈÍøÂ簲ȫÖÐÐĵĽ¨Ò齫´ËÊ»㱨¸ø¾¯·½£¬²¢µ±¼´²ÉÈ¡´ëÊ©¼ÓÇ¿ËùÓÐÓëÔ¤ËãÓйصÄÐÅÏ¢µÄ°²È«ÐÔ£¬²ÆÕþ²¿»¹´òËã¶ÔÐÅÏ¢°²È«Á÷³Ì½øÐÐÈ«ÃæÉó²é ¡£

 

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/new-zealand-treasury-hacked-and-budget-information-leaked-2fceb79b

6Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingÔâºÚ¿ÍÈëÇÖ£¬¿Í»§ÐÅϢй¶


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Ó¢¹úÁ¬Ëø¾Æ°ÉGreene KingµÄÀñÎï¿¨ÍøÕ¾ÔâºÚ¿ÍÈëÇÖ£¬µ¼Ö¿ͻ§Êý¾Ýй¶ ¡£Ð¹Â¶µÄÐÅÏ¢Ô̺¬¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØÖ·¡¢Óû§ID¡¢¼ÓÃܵÄÃÜÂë¡¢µØÖ·¡¢ÓÊÕþ±àÂëºÍÀñÎ│¶©µ¥ºÅ£¬µ«²»Ô̺¬ÈκÎÒøÐп¨Ï¸½Ú»òÖ§¸¶ÐÅÏ¢ ¡£ÕâÒ»ÊÂÎñ²úÉúÔÚ2019Äê5ÔÂ14ÈÕ£¬¸Ã¹«Ë¾ÒÑÏòÐÅϢרԱ°ì¹«ÊÒ£¨ICO£©¼°Æä¿Í»§´«µÝÁËй¶ÊÂÎñ£¬Ä¿Ç°ÊÜÓ°ÏìµÄ¿Í»§ÊýÁ¿Î´Öª ¡£

  

Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/uk-pub-chain-greene-king-suffers-data-breach-following-hack-on-its-gift-card-website-1aec5c69