¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180703
Ðû²¼Ê±¼ä 2018-07-03¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷Ô˶¯
PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£×î½ü£¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄÔ˶¯¡£
ÔÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html
¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÐµÄDiameterµç»°ÐÒéÓëSS7Ò»ÑùÒ×Êܹ¥»÷
Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä±ê×¼Ò»ÆðʹÓõÄDiameterÐÒéÈÝÒ×Êܵ½Óë¾ÉµÄµç»°±ê×¼£¨Èç3G£¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7±ê×¼ÏàͬÀàÐ͵ÄÎó²îµÄ¹¥»÷£¬SS7ÊÇÔÚ20ÊÀ¼Í70ÄêÔ¿ª·¢µÄ£¬¿ìÒª¶þÊ®Äê֤ʵÆä±£´æ²»Çå¾²ÒòËØ¡£ÕýÓÉÓÚÔÆÔÆ£¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂç×îÏÈ£¬SS7±»DiameterÐÒéËùÈ¡´ú£¬DiameterÐÒéÊÇÒ»ÖÖˢеÄÍø¼äºÍÍøÄÚÐÅÁîÐÒ飬Ҳ½«ÓÃÓÚ¼´½«ÍƳöµÄ5G±ê×¼¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/
¡¾Çå¾²²¥±¨¡¿ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼
ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£Ô×ÓÄÜ»ú¹¹ÌåÏÖ£¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅ·þÎñÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/
¡¾Çå¾²²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ
FacebookÒѾÈϿɣ¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬FacebookÌåÏÖ£¬ËüÒѾÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£
ÔÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html
¡¾Çå¾²²¥±¨¡¿ÈýÐDz¿·ÖϵÁÐÊÖ»ú±£´æbug£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË
×îа汾µÄÈýÐǶÌÐŶÌÐÅÓ¦ÓóÌÐò±£´æbug£¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£ºÃÐÂÎÅÊÇ£¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬ÈçS9¡¢S9 PlusºÍNote 8£¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬Óöµ½bugµÄÓû§Ëµ£¬ËûÃDz»ÖªµÀÊÖ»úÒѾ·¢ËÍÁËÕÕÆ¬£¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£Ö»Óе±ÕâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬ËûÃDzŷ¢Ã÷¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÓ¦ÓóÌÐòÖ±µ½ÈýÐÇÐÞ¸´ÕâЩÎÊÌâ¡£
ÔÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/
¡¾Îó²î²¹¶¡¡¿VMwareÐû²¼Çå¾²¸üУ¬ÐÞ²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄÎó²î
VMwareÉÏÖÜ֪ͨ¿Í»§£¬ÆäÐÞ²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬WorkstationºÍFusion²úÆ·ÖзºÆð¾Ü¾ø·þÎñ£¨DoS£©»òÐÅϢй¶µÄÎó²î¡£¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓÃÇå¾²Îó²î»ñÊØÐÅÏ¢»òʹÐéÄâ»úÍ߽⡣¸ÃÎó²î±»ÁÐΪÖ÷Òª£¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£Cisco TalosµÄÑо¿Ö°Ô±·¢Ã÷ÁËCVE-2018-6965¡£¾ÝVMware³ÆÕâЩȱÏÝ»áÓ°ÏìÔÚÈÎºÎÆ½Ì¨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬²¢ÒÑÐû²¼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄÐÞ²¹³ÌÐòºÍ¸üС£
ÔÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion


¾©¹«Íø°²±¸11010802024551ºÅ