Android 0day(CVE-2019-2215) PoC£»¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí

°ä²¼¹¦·ò 2019-10-18
1¡¢Android 0day(CVE-2019-2215)µÄPoC´úÂëÒѰ䲼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

±¾Ô³õ¹È¸è°²È«×êÑÐÔ±Maddie StoneÅû¶ÁËÒ»¸öAndroidÁãÈÕ·ì϶£¨CVE-2019-2215£©£¬Æäʱ¹È¸è°µÊ¾¸ÃÁãÈÕ·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓ᣽üÈÕ·ðÂÞÀï´ï´óѧGrant HernandezÔÚ²©¿ÍÖа䲼ÁËÒ»¸öеÄPoC¹¤¾ßQu1ckR00t£¬¹¥»÷Õß¿ÉÀûÓøù¤¾ß»ñµÃrootȨÏÞ²¢ÆëÈ«½ÚÔìÉ豸¡£¸Ã¹¤¾ßûÓÐ×÷Ϊ´ò°üµÄAPKÎļþ°ä²¼£¬¶øÊÇÒÔÔ´´úÂëµÄ´ó¾ÖÔÚGitHubÉϰ䲼¡£Hernandez°µÊ¾ËûÖ»ÔÚPixel 2ÊÖ»úÉϲâÊÔ¹ýQu1ckR00t£¬²¢ÖÒ¸æÃ»Óо­ÑéµÄÓû§²»Òª²âÊԸôúÂ룬²»È»»áÓÐϵͳ±äשºÍÊý¾ÝÃÔʧµÄ·çÏÕ¡£GoogleÒÑÔÚ2019Äê10ÔµÄAndroid°²È«²¼¸æ£¨°²È«²¹¶¡·¨Ê½¼¶±ð2019-10-06£©Öн¨²¹ÁËCVE-2019-2215 ¡£ÎªÁËÔ¤·À³öÏÖÎÊÌ⣬½¨ÒéÓû§×°ÖñØÒªµÄ²¹¶¡·¨Ê½¡£

   

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/security-researcher-publishes-proof-of-concept-code-for-recent-android-zero-day/

2¡¢Êý°ÙÍòÑÇÂíÑ·EchoºÍKindleÉ豸Ò×ÊÜWiFi KRACK¹¥»÷

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾ÝESETµÄÒ»·Ý»ã±¨£¬×êÑÐÈËÔ±·¢ÏÖAmazon Echo 1stºÍAmazon Kindle 8thÉ豸ÒÀÈ»Êܵ½WiFi KRACK·ì϶µÄÓ°Ï죬Õâ¿ÉÄÜÓ°ÏìÊý°ÙÍòÉ豸¡£KRACK·ì϶ÊÇWPA2ºÍ̸4´ÎÎÕÊÖÖеķì϶£¨CVE-2017-13077ºÍCVE-2017-13078£©£¬¸Ã·ì϶ÓÚ2017Äê10Ô±»¹«¿ª¡£Æ¾¾ÝESETµÄ±íÊö£¬ÕâЩ·ì϶¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐDoS¹¥»÷¡¢·ÛËéÍøÂçͨѶ»ò³Á²¥¹¥»÷£¬À¹½ØºÍ½âÃÜÓû§´«ÊäµÄÃÜÂë»ò»á»°µÈÃô¸ÐÐÅÏ¢£¬Î±ÔìÊý¾Ý°üÉõÖÁ×¢ÈëÐÂÊý¾Ý°üµÈ¡£ESETÓÚ2018Äê10ÔÂ23ÈÕ֪ͨÁËÑÇÂíÑ·£¬ÑÇÂíÑ·ÔÚ2019Äê1ÔÂÒÑÏòÊÜÓ°ÏìµÄÉè±¸ÍÆËÍÁËÓйؽ¨¸´²¹¶¡¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/millions-of-amazon-echo-and-kindle-devices-affected-by-wifi-bug/

3¡¢¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾

BlackBerry Cylance×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÔÚжñÒâ»î¶¯ÖÐÀûÓÃWAVÒôƵÎļþÔÚÖ¸±êϵͳÉϰµ²ØºóÃźͶñÒâ¿ó¹¤¡£¹ÌÈ»·¸×ï×é֯ʱʱÀûÓÃÒþдÊõÔÚJPEG»òPNGͼÏñÎļþÖÐ×¢Èëpayload£¬µ«ÔÚÀÄÓÃWAVÒôƵÎļþÉÏÉÐÊýµÚ¶þ´Î¡£×êÑÐÈËÔ±°µÊ¾£¬Ã¿¸öWAVÎļþ¶¼ÓëÒ»¸ö¼ÓÔØ·¨Ê½×é¼þ½áºÏÔÚһ·£¬ÓÃÓÚ½âÂëºÍÖ´Ðаµ²ØÔÚÒôƵÊý¾ÝÖеĶñÒâÄÚÈÝ¡£ÔÚ²¥·Åʱ£¬ÆäÖÐһЩWAVÎļþËù²úÉúµÄÒôÀÖûÓÐÏÔÖøµÄÖÊÁ¿ÎÊÌâ»òë´Ì£¬¶øÆäËüÎļþÒ²½ö²úÉú¾²Ì¬°×ÔëÉù¡£¹¥»÷ÕßÖØÒª·Ö·¢MetasploitºóÃźÍXMRig¿ó¹¤¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/attackers-hide-backdoors-and-cryptominers-in-wav-audio-files/

4¡¢×êÑлú¹¹·¢ÏÖ550¶à¸öÕë¶ÔÃÀ¹úÑ¡¾ÙµÄÐéαÓòÃû


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Digital ShadowsÔÚÒ»ÏîÐÂ×êÑÐÖз¢ÏÖ³¬¹ý550¸öÕë¶ÔÃÀ¹úÑ¡ÃñµÄÐéαѡ¾ÙÍøÕ¾¡£ÕâÐ©ÍøÕ¾¼Ù×°³É19¸öÃñÖ÷µ³ºÍ4¸ö¹²ºÍµ³×ÜͳºòÑ¡È˵ÄÑ¡¾ÙÓйØÍøÕ¾£¬ÆäÖдóÎÞÊýÍøÕ¾£¨68%£©Ö»Êǽ«Óû§³Á¶¨Ïòµ½ÁíÒ»¸öÓòÃûÉÏ£¨Í¨³£ÊǾºÕùµÐÊÖµÄÓòÃû£©¡£µ«Ò²ÓÐ8%µÄÍøÕ¾½«Óû§³Á¶¨ÏòÖÁ¿ÉÄܼӺ¦Ñ¡ÃñÒþÖÔ/´æÔÚ¶ñÒâÈí¼þµÄChrome²å¼þÉÏ¡£ÓÐ66¸öÓòÃûÍйÜÔÚͳһ¸öIPµØÖ·ÉÏ£¬²¢ÇÒÊÇͨ¹ýÒþÖÔ±£»¤·þÎñWhoisGuard×¢²áµÄ£¬ËüÃÇ¿ÉÄÜÊÇÓÉͳһ¸öÍŶÓÔÚÔËÓª¡£Digital ShadowsÎÞ·¨½«ÕâЩÐéαÓòÃû¹éÒòÓÚÌØ¶¨µÄÓ×ÎÒ»ò×éÖ¯¡£

Ô­ÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/over-550-fake-us-election-web/

5¡¢ÐÂÍÚ¿óÈ䳿GraboidÖØÒªÍ¨¹ýDockerÈÝÆ÷´«²¼

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Palo Alto NetworksµÄ×êÑÐÈËÔ±·¢ÏÖÖØÒªÕë¶ÔDockerÈÝÆ÷µÄÐÂÍÚ¿óÈ䳿Graboid¡£×êÑÐÈËÔ±´ÓGraboidµÄºÅÁîºÍ½ÚÔ죨C2£©·þÎñÆ÷Öз¢ÏÖÁËÒ»¸ö¾ç±¾£¬¸Ã¾ç±¾Ô̺¬Ò»¸öÓµÓÐ2000¶à¸öÖ¸±êIPµØÖ·µÄÁбí£¬Ä¿Ç°Éв»Ã÷ÏÔÆäÖÐÓм¸¶àÒѱ»Ï°È¾¡£ÔÚϰȾDocker·þÎñºó£¬¸ÃÈ䳿»á´ÓDocker HubÏÂÔØ¡° pocosow/centos¡± Docker¾µÏñ²¢²¿Êð£¬ÍÚ¿ó»î¶¯Í¨¹ý±»³ÆÎª¡°gakeaws/nginx¡±µÄµ¥¶ÀÈÝÆ÷½øÐС£¸ÃÈ䳿»¹»á´ÓÖ¸±êIPÁбíÖÐËæ»úÑ¡ÔñÏÂÒ»¸öÖ¸±ê¡£×ÜÌå¶øÑÔ£¬Æ¾¾ÝUnit 42µÄÊý¾Ý£¬×î³õµÄ¶ñÒâDocker¾µÏñÒѱ»ÏÂÔØÁË1Íò´ÎÒÔÉÏ£¬È䳿×ÔÉíÒѱ»ÏÂÔØÁË6500ÂŴΡ£

Ô­ÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unsecured-docker-hosts-attacked-by-new-graboid-cryptojacking-worm/

6¡¢Å·ÖÞij¹ú¼Ê»ú³¡50%ÒÔÉϵÄϵͳϰȾÍÚ¿óľÂí


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Cyberbit×êÑÐÈËÔ±·¢ÏÖÅ·ÖÞÒ»¸ö¹ú¼Ê»ú³¡µÄ50%ÒÔÉϵŤ×÷վϰȾÁËÃÅÂÞ±ÒÍÚ¿óľÂí¡£Cyberbit°µÊ¾£¬¸ÃÍÚ¿óľÂíÊÇÒ»Äê¶àÒÔǰÓÉZscaler·¢ÏÖµÄXMRigµÄÒ»¸ö±äÖÖ£¬¹¥»÷Õß¶ÔÆä½øÐÐÁ˸üÐÂÒÔÌӱܼì²â¡£¸Ã±äÖÖÔÚVirusTotalÉÏÖ»»ñµÃÁË16/73µÄ¼ì³öÂÊ¡£¸ÃľÂí¿ÉÄÜÒѾ­´æÔÚÁËÊýԵŦ·ò£¬Ä¿Ç°Éв»Ã÷ÏÔ¾ßÌåµÄϰȾý½é£¬µ«ºÃÐÂÎÅÊǸûú³¡µÄÔËӪûÓÐÊܵ½Ó°Ïì¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/european-airport-systems-infected-with-monero-mining-malware/