Android 0day(CVE-2019-2215) PoC£»¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí
°ä²¼¹¦·ò 2019-10-18
±¾Ô³õ¹È¸è°²È«×êÑÐÔ±Maddie StoneÅû¶ÁËÒ»¸öAndroidÁãÈÕ·ì϶£¨CVE-2019-2215£©£¬Æäʱ¹È¸è°µÊ¾¸ÃÁãÈÕ·ì϶ÔÚÒ°±í±»»ý¼«ÀûÓ᣽üÈÕ·ðÂÞÀï´ï´óѧGrant HernandezÔÚ²©¿ÍÖа䲼ÁËÒ»¸öеÄPoC¹¤¾ßQu1ckR00t£¬¹¥»÷Õß¿ÉÀûÓøù¤¾ß»ñµÃrootȨÏÞ²¢ÆëÈ«½ÚÔìÉ豸¡£¸Ã¹¤¾ßûÓÐ×÷Ϊ´ò°üµÄAPKÎļþ°ä²¼£¬¶øÊÇÒÔÔ´´úÂëµÄ´ó¾ÖÔÚGitHubÉϰ䲼¡£Hernandez°µÊ¾ËûÖ»ÔÚPixel 2ÊÖ»úÉϲâÊÔ¹ýQu1ckR00t£¬²¢ÖÒ¸æÃ»ÓоÑéµÄÓû§²»Òª²âÊԸôúÂ룬²»È»»áÓÐϵͳ±äשºÍÊý¾ÝÃÔʧµÄ·çÏÕ¡£GoogleÒÑÔÚ2019Äê10ÔµÄAndroid°²È«²¼¸æ£¨°²È«²¹¶¡·¨Ê½¼¶±ð2019-10-06£©Öн¨²¹ÁËCVE-2019-2215 ¡£ÎªÁËÔ¤·À³öÏÖÎÊÌ⣬½¨ÒéÓû§×°ÖñØÒªµÄ²¹¶¡·¨Ê½¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/security-researcher-publishes-proof-of-concept-code-for-recent-android-zero-day/2¡¢Êý°ÙÍòÑÇÂíÑ·EchoºÍKindleÉ豸Ò×ÊÜWiFi KRACK¹¥»÷
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/millions-of-amazon-echo-and-kindle-devices-affected-by-wifi-bug/3¡¢¹¥»÷ÕßÔÚWAVÒôƵÎļþÖаµ²ØºóÃźÍÍÚ¿óľÂí
BlackBerry Cylance×êÑÐÈËÔ±·¢ÏÖ¹¥»÷ÕßÔÚжñÒâ»î¶¯ÖÐÀûÓÃWAVÒôƵÎļþÔÚÖ¸±êϵͳÉϰµ²ØºóÃźͶñÒâ¿ó¹¤¡£¹ÌÈ»·¸×ï×é֯ʱʱÀûÓÃÒþдÊõÔÚJPEG»òPNGͼÏñÎļþÖÐ×¢Èëpayload£¬µ«ÔÚÀÄÓÃWAVÒôƵÎļþÉÏÉÐÊýµÚ¶þ´Î¡£×êÑÐÈËÔ±°µÊ¾£¬Ã¿¸öWAVÎļþ¶¼ÓëÒ»¸ö¼ÓÔØ·¨Ê½×é¼þ½áºÏÔÚһ·£¬ÓÃÓÚ½âÂëºÍÖ´Ðаµ²ØÔÚÒôƵÊý¾ÝÖеĶñÒâÄÚÈÝ¡£ÔÚ²¥·Åʱ£¬ÆäÖÐһЩWAVÎļþËù²úÉúµÄÒôÀÖûÓÐÏÔÖøµÄÖÊÁ¿ÎÊÌâ»òë´Ì£¬¶øÆäËüÎļþÒ²½ö²úÉú¾²Ì¬°×ÔëÉù¡£¹¥»÷ÕßÖØÒª·Ö·¢MetasploitºóÃźÍXMRig¿ó¹¤¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/attackers-hide-backdoors-and-cryptominers-in-wav-audio-files/4¡¢×êÑлú¹¹·¢ÏÖ550¶à¸öÕë¶ÔÃÀ¹úÑ¡¾ÙµÄÐéαÓòÃû
Digital ShadowsÔÚÒ»ÏîÐÂ×êÑÐÖз¢ÏÖ³¬¹ý550¸öÕë¶ÔÃÀ¹úÑ¡ÃñµÄÐéαѡ¾ÙÍøÕ¾¡£ÕâÐ©ÍøÕ¾¼Ù×°³É19¸öÃñÖ÷µ³ºÍ4¸ö¹²ºÍµ³×ÜͳºòÑ¡È˵ÄÑ¡¾ÙÓйØÍøÕ¾£¬ÆäÖдóÎÞÊýÍøÕ¾£¨68%£©Ö»Êǽ«Óû§³Á¶¨Ïòµ½ÁíÒ»¸öÓòÃûÉÏ£¨Í¨³£ÊǾºÕùµÐÊÖµÄÓòÃû£©¡£µ«Ò²ÓÐ8%µÄÍøÕ¾½«Óû§³Á¶¨ÏòÖÁ¿ÉÄܼӺ¦Ñ¡ÃñÒþÖÔ/´æÔÚ¶ñÒâÈí¼þµÄChrome²å¼þÉÏ¡£ÓÐ66¸öÓòÃûÍйÜÔÚͳһ¸öIPµØÖ·ÉÏ£¬²¢ÇÒÊÇͨ¹ýÒþÖÔ±£»¤·þÎñWhoisGuard×¢²áµÄ£¬ËüÃÇ¿ÉÄÜÊÇÓÉͳһ¸öÍŶÓÔÚÔËÓª¡£Digital ShadowsÎÞ·¨½«ÕâЩÐéαÓòÃû¹éÒòÓÚÌØ¶¨µÄÓ×ÎÒ»ò×éÖ¯¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/over-550-fake-us-election-web/
5¡¢ÐÂÍÚ¿óÈ䳿GraboidÖØÒªÍ¨¹ýDockerÈÝÆ÷´«²¼
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/unsecured-docker-hosts-attacked-by-new-graboid-cryptojacking-worm/
6¡¢Å·ÖÞij¹ú¼Ê»ú³¡50%ÒÔÉϵÄϵͳϰȾÍÚ¿óľÂí
Cyberbit×êÑÐÈËÔ±·¢ÏÖÅ·ÖÞÒ»¸ö¹ú¼Ê»ú³¡µÄ50%ÒÔÉϵŤ×÷վϰȾÁËÃÅÂÞ±ÒÍÚ¿óľÂí¡£Cyberbit°µÊ¾£¬¸ÃÍÚ¿óľÂíÊÇÒ»Äê¶àÒÔǰÓÉZscaler·¢ÏÖµÄXMRigµÄÒ»¸ö±äÖÖ£¬¹¥»÷Õß¶ÔÆä½øÐÐÁ˸üÐÂÒÔÌӱܼì²â¡£¸Ã±äÖÖÔÚVirusTotalÉÏÖ»»ñµÃÁË16/73µÄ¼ì³öÂÊ¡£¸ÃľÂí¿ÉÄÜÒѾ´æÔÚÁËÊýԵŦ·ò£¬Ä¿Ç°Éв»Ã÷ÏÔ¾ßÌåµÄϰȾý½é£¬µ«ºÃÐÂÎÅÊǸûú³¡µÄÔËӪûÓÐÊܵ½Ó°Ïì¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/european-airport-systems-infected-with-monero-mining-malware/


¾©¹«Íø°²±¸11010802024551ºÅ