ÍøÂ簲ȫÍþвÐÅÏ¢°ä²¼ÖÎÀí·¨×Ó(Õ÷Ç󶨼û¸å)£»ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý£»DockerÌÓÒÝ·ì϶
°ä²¼¹¦·ò 2019-11-21
ΪÓÐЧӦ¶ÔÍøÂ簲ȫÍþв΢·çÏÕ£¬±£ÏÕÍøÂçÔËÐа²È«£¬¹ú¶È»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ20Èվ͡¶ÍøÂ簲ȫÍþвÐÅÏ¢°ä²¼ÖÎÀí·¨×Ó£¨Õ÷Ç󶨼û¸å£©¡·¹«¿ªÕ÷ÇóÉç»á¶¨¼û£¬¶Ô°ä²¼ÍøÂ簲ȫÍþвÐÅÏ¢µÄÐÐΪ×÷³ö¹æ·¶¡£Æ¾¾ÝÕ÷Ç󶨼û¸å£¬ÍøÂ簲ȫÍþвÐÅÏ¢Ô̺¬(Ò»)¶Ô¿ÉÄÜÍþÐ²ÍøÂçÕý³£ÔËÐеÄÐÐΪ£¬ÓÃÓÚÃèÊöÆäÒâͼ¡¢²½Öè¡¢¹¤¾ß¡¢¹ý³Ì¡¢Á˾ֵȵÄÐÅÏ¢£»(¶þ)¿ÉÄܶ³öÍøÂç´àÈõÐÔµÄÐÅÏ¢¡£Õ÷Ç󶨼û¸åÃ÷È·£¬°ä²¼ÍøÂ簲ȫÍþвÐÅÏ¢£¬Ó¦ÒÔÊØ»¤ÍøÂ簲ȫ¡¢ÍƽøÍøÂ簲ȫÒâʶÌáÉý¡¢»¥»»ÍøÂ簲ȫ·À»¤¼¼Êõ֪ʶΪÖ÷ÕÅ£¬²»µÃ·çÏÕ¹ú¶È°²È«ºÍÉç»á¹«¹²ÀûÒæ£¬²»µÃ¼Óº¦¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄºÏ·¨È¨Àû¡£
ÔÎÄÁ´½Ó£º
http://www.cac.gov.cn/2019-11/20/c_1575785387932969.htm2¡¢ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿Í¹¥»÷£¬CLI×°Öðü±»´úÌæÎª¶ñÒâÈí¼þ
ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬¹Ù·½Linux CLI¶þ½øÔìÎļþ±»´úÌæÎªÇÔÈ¡Óû§×ʽðµÄ¶ñÒâÈí¼þ¡£¸ÃÊÂÎñ²úÉúÔÚ11ÔÂ18ÈÕ£¬Ò»ÃûÓû§ÔÚGithubÉϻ㱨Á˸ÃÎÊÌ⣬ÃÅÂÞ±ÒÍŶÓËæºó½øÐÐÁËÈ·ÈÏ¡£½¨ÒéÔÚ18ºÅ2:30 AM UTCÖÁ4:30 PM UTCÖ®¼äÏÂÔØÁËCLIÇ®°üµÄÓû§²é³Æä¶þ½øÔìÎļþµÄ¹þÏ£Öµ£¬ÈôÊÇÓë¹ÙÍøÉϵĹþÏ£Öµ²»Æ¥Å䣬Ôò²»ÒªÔËÐиÃÈí¼þ²¢É¾³ýËü¡£µ±Ç°ÃÅÂÞ±ÒÍŶӰµÊ¾ÈÔÔÚµ÷²é¹¥»÷ÕßÈôºÎÈëÇÔìäÏÂÔØ·þÎñÆ÷£¬Ä¿Ç°Éв»Ã÷ÏÔÓм¸¶àÓû§ÔÚÕâ´ÎºÚ¿Í¹¥»÷ÖÐËðʧÁË×ʽð¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/official-monero-website-compromised-with-malware-that-steals-funds/3¡¢GateHubºÍEpicBotµÄ220ÍòÓû§Êý¾ÝÔÚÍøÉϹ«¿ª
°²È«×êÑÐÔ±Troy Hunt°µÊ¾¼ÓÃÜÇ®±ÒÇ®°ü·þÎñGateHubºÍÓÎÏ·ÍøÕ¾EpicBotµÄ220Óû§ÕË»§Êý¾ÝÔÚÍøÉϹ«¿ª¡£¸ÃÊý¾Ý¿âÔ̺¬140Íò¸öGateHubÕÊ»§ºÍ80Íò¸öEpicBotÕÊ»§µÄÐÅÏ¢£¬Èçµç×ÓÓʼþµØÖ·ºÍ¾¹ýbcrypt´¦ÖõĹþÏ£ÃÜÂë¡£GateHubÈÏ¿ÉÔÚÏÄÌìÔâµ½ºÚ¿ÍÈëÇÖ£¬µ«Æäʱ°µÊ¾½öÓÐ18473¸ö¿Í»§ÕË»§±»·¸·¨½Ó¼û£¬´Ë¿Ì¿´À´ÕâÒ»ÁìÓòÒª´óµÃ¶à¡£EpicBotĿǰÉÐδÈÏ¿ÉËüÒѱ»ºÚ¿ÍÈëÇÖ¡£
ÔÎÄÁ´½Ó£º
https://threatpost.com/hackers-dump-2-2m-gaming-cryptocurrency-passwords-online/150451/4¡¢PayMyTabÒâ±íй¶ÊýǧÃûÃÀ¹ú²Í¹Ý¹Ë¿ÍÊý¾Ý
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/paymytab-data-leak-exposes-personal-information-belonging-to-mobile-diners/
5¡¢ºÚ¿ÍÔÚÍøÉϰ䲼¿ªÂüÒøÐеÄ2TBÊý¾Ý
ºÚ¿Í´Ó¿ªÂüÒøÐÐÇÔÈ¡ÁË2TBµÄÊý¾Ý²¢°ä²¼ÔÚÍøÉÏ¡£¾Ý³ÆÕâЩÊý¾ÝÊÇÓɺڿͻòºÚ¿ÍÍÅ»ïPhineas FisherÇÔÈ¡µÄ£¬²¢Í¨¹ýDistributed Denial of SecretsÏîÄ¿°ä²¼¡£Êý¾Ý¼¯ÖÐÔ̺¬¿ªÂüÒøÐÐΪÆäÈ«Çò¿Í»§ÖÎÀíµÄ³¬¹ý3800¼Ò¹«Ë¾¡¢ÐÅÈκÍÓ×ÎÒÕË»§µÄ¾ßÌ岯ÕþÐÅÏ¢£¬ÉõÖÁÔ̺¬ÕË»§Óà¶î¡£¿ªÂüÒøÐв¢Î´ÈÏ¿ÉÊý¾Ýй¶£¬µ«°²È«×¨¼Ò°ÑÎȵ½ÆäºÜ¶à·þÎñÓÚ11ÔÂ17ÈÕÒò¡°³Á´óÉý¼¶ºÍÊØ»¤¡±¶ø´¦ÓÚ²»³ÉÓÃ״̬¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94136/data-breach/cayman-national-bank-data-leak.html
6¡¢DockerÌÓÒÝ·ì϶(CVE-2019-14271) PoC°ä²¼
×êÑÐÈËÔ±°ä²¼DockerÌÓÒÝ·ì϶£¨CVE-2019-14271£©µÄPoC£¬²¢¶½´ÙÓû§Éý¼¶µ½×îа汾¡£¸Ã·ì϶ÔÚ7Ô·ݵÄDocker°æ±¾19.03.1Öн¨¸´£¬µ«ÈôÊÇδ´ò²¹¶¡£¬¹¥»÷Õß¿ÉÄÜ»áͨ¹ý¶ñÒâÈÝÆ÷¾µÏñÔÚÓû§µÄËÞÖ÷»úÉÏÒÔrootȨÏÞÖ´ÐÐËÁÒâ´úÂë¡£Palo Alto Networks°²È«×êÑÐÔ±Yuval Avrahami¶½´ÙDocker¿ª·¢ÈËԱͨ¹ý½öÔËÐÐÊÜÐÅÀµµÄ¾µÏñÀ´Ï÷¼õ¹¥»÷Ãæ£¬²¢½¨ÒéÔÚ²»±ØÒªrootµÄÇé¿öÏÂÒÔ·ÇrootÓû§Éí·ÝÔËÐÐÈÝÆ÷¡£
ÔÎÄÁ´½Ó£º
https://www.infosecurity-magazine.com/news/researchers-public-poc-docker/


¾©¹«Íø°²±¸11010802024551ºÅ