Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飻×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶

°ä²¼¹¦·ò 2020-09-22

1.Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊé


1.jpg


Pradeo°ä²¼ÁË¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飬½éÉÜÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ë¾·¨¿ò¼Ü¡¢·çÏÕÒÔ¼°±£»¤Òƶ¯ÒøÐÐÀûÓ÷¨Ê½°²È«µÄ½â¾ö¹æ»®£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄ¾ßÌåÐÅÏ¢¡£ÆäÖÐд·£¬Òƶ¯ÒøÐзþÎñѸ¿ìÊܵ½Ïû·ÑÕßµÄϲ»¶£¬µ½2019Äêµ×£¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒÆ¶¯É豸À´ÖÎÀíÆä²ÆÕþ¡£µ«ÊÇ×êÑÐÅú×¢£¬ÊÖ»úÒøÐÐÀûÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇô°²È«£¬¾ÝRSAµÄڲƭ΢·çÏÕµý±¨ÍŶÓ×î½üÍøÂçµÄÊý¾Ý·ÖÎöÏÔʾ£¬ÓëÊÖ»úÀûÓÃÓйصÄڲƭÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·­ÁËÒ»·¬¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention/


2.F-Secure°ä²¼2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨


2.jpg


F-Secureµ÷²éÁ˽ñÄêÉϰëÄêÍøÂçÍþвµÄ·¢Õ¹Çé¿ö£¬²¢°ä²¼ÁË2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨¡£»ã±¨ÏÔʾ£¬´Ó½ñÄê3ÔÂÆðÍ·£¬ÀûÓø÷ÀàCOVID-19ÎÊÌâµÄ¶ñÒâµç×ÓÓʼþÏÔ×ÅÔö³¤£¬ÒÔÓÕʹÓû§Â¶³öÓÚ¸÷Ààµç×ÓÓʼþ¹¥»÷ºÍڲƭÖУ¬ÆäÖÐÓÐËÄ·ÖÖ®ÈýµÄµç×ÓÓʼþÖи½¼þÖÐÔ̺¬ÐÅÏ¢ÇÔÈ¡Æ÷¡£´Ë±í£¬ÔÚ´¹µöÓʼþÖУ¬½ðÈÚÒµÊÇ×î³£±»ºýŪµÄÐÐÒµ£¬µç×ÓÓʼþÊÇ´«²¼¶ñÒâÈí¼þ×îÊ¢Ðеķ½Ê½£¬Õ¼ËùÓÐϰȾý½éµÄÒ»°ëÒÔÉÏ¡£


Ô­ÎÄÁ´½Ó£º

https://www.f-secure.com/en/press/p/covid-19-spam--phishing-emails--plagued-users-in-first-half-of-2


3.ר¼Ò·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯


3.jpg


×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯£¬²¢²»Ò×±»ÆóÒµ°²È«²úÆ·¼ì²âµ½¡£Google App EngineÊÇÒ»¸ö»ùÓÚÔÆµÄ·þÎñƽ̨£¬ÓÃÓÚÔÚGoogleµÄ·þÎñÆ÷ÉÏ¿ª·¢ºÍÍйÜWebÀûÓá£Google App EngineÔÚÌìÉú×ÓÓòʱÈκÎ×Ö¶ÎÃýÎó¶¼²»»áÏÔʾ404δÕÒµ½Ò³Ã棬¶øÊÇÏÔʾÆäĬÈÏÒ³Ãæ¡£Òò¶ø£¬ºÚ¿Í¿ÉÀûÓøÃÖ°ÄÜ´´½¨ÎÞÏÞ¸ö¶ñÒâ´¹µöÍøÕ¾£¬ÕâÒ²Ôö³¤ÁËϵͳÖÎÀíÔ±×èÖ¹¸Ã¶ñÒâ»î¶¯µÄÄѶÈ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-app-engine-feature-abused-to-create-unlimited-phishing-pages/


4.×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶£¬ÉÐδ±»ÔÚÒ°ÀûÓÃ


4.jpg


×êÑÐÈËÔ±Åû¶ÁËAction ViewÖеÄXSS·ì϶£¬ÆäÊÇÒ»ÖÖÊ¢ÐеÄRuby Gem£¬Äܹ»ÔÚRails WebÀûÓ÷¨Ê½¿ò¼ÜÖд¦ÖÃWebÒªÇó£¬Ä¿Ç°¸Ã·ì϶ÉÐδ±»ÔÚÒ°ÀûÓ᣸÷ì϶λÓÚAction ViewÓÃÀ´·­ÒëÓû§ÊäÈëµÄ·­Ò븱ÊÖÖУ¬µ±Ò»¸öhtml²»°²È«µÄ×Ö·û´®×÷Ϊȱʡֵ´«µÝ¸øÒ»¸öÃûΪhtml»òÒÔ_html½áβµÄ©Òë¼üʱ£¬Ä¬ÈÏ×Ö·û´®½«±»ÃýÎóµØÏóÕ÷Ϊhtml°²È«ÇÒûÓÐתÒ壬ÕâÒâζ׏¥»÷ÕßÄܹ»ÊäÈë¼Ù×°³ÉºÏ·¨µÄ¶ñÒâ´úÂë¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/action-view-xss-bug-discovered-in-popular-ruby-gem


5.ÃÀ¹úNewhallÑ§ÇøÏ°È¾ÀÕË÷Èí¼þµ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø


5.jpg


ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄNewhallÑ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷£¬µ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø£¬Ó°ÏìÁË10Ëù·ÖÆç´°Ð£µÄËùÓÐÔ¶³Ì½ÌÓý¡£¸ÃÑ§ÇøµÄÕÆ¹ÜÈ˰µÊ¾£¬ºÚ¿ÍµÄ¹¥»÷´ÓÖÜÖçÒ¹¼ä³ÖÐøµ½ÖÜÒ»ÔçÉÏ£¬ËûÔÚÊÔͼ½Ó¼ûOutlookºÍµç×ÓÓʼþʱÊÕµ½ÃýÎóÐÅÏ¢¶ø°ÑÎȵ½¸ÃÎÊÌâ¡£ÓÐȤµÄÊÇ£¬ºÚ¿Í²¢Ã»ÓÐÌá³öڲƭÀÕË÷µÄÐèÒª¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/california-elementary-kids-online-learning-ransomware/159319/


6.ArbiterSportsϰȾÀÕË÷Èí¼þ£¬54Íò»áÔ±ÐÅÏ¢±»µÁ


6.jpg


ArbiterSports°µÊ¾£¬ËüÒÑÓÚ½ñÄê7ÔÂÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷¡£ArbiterSportsÊÇÒ»¼ÒΪÌåÓýÁªÈüÌṩÈí¼þÀ´ÖÎÀí²ÃÅкͽÇÖð¹ÙÔ±µÄ¹«Ë¾£¬Õâ´ÎÊÂÎñÉæ¼°µ½ÆäÔ¼54ÍòÃû×¢²á»áÔ±£¬ÆäÖÐÔ̺¬²ÃÅÓ×¢ÁªÈü¹ÙÔ±ºÍѧÌôú±í¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§µÄÃô¸ÐÐÅÏ¢£¬ÀýÈçÕÊ»§Óû§Ãû¡¢ÃÜÂë¡¢ÕæÊµÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍÉç»á°²È«ºÅÂ롣Ŀǰ£¬ ¸Ã¹«Ë¾°µÊ¾ÆäÒѾ­Ö§¸¶ÁËÊê½ð£¬²¢È·ÈϺڿÍ×éÖ¯ÒÑɾ³ý±»µÁÊý¾Ý¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-of-540000-sports-referees-taken-in-failed-ransomware-attack/