¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180903

Ðû²¼Ê±¼ä 2018-09-03

¡¾ÍþвÇ鱨¡¿Ñо¿ÅúעȫÇòǰ100Íò¸öÍøÕ¾ÖÐ51.8%ÒÑʹÓÃHTTPS


ƾ֤Ñо¿Ö°Ô±Scott Helme¶ÔÈ«Çò×î³£»á¼ûµÄAlexaǰ100Íò¸öÍøÕ¾µÄÆÊÎö £¬51.8%µÄÍøÕ¾ÒÑʹÓÃHTTPS £¬¶øÕâÒ»Êý×ÖÔÚÁù¸öÔÂǰÊÇ38.4% ¡£ÕâÒ»ÔöÌíµÄ²¿·ÖÔµ¹ÊÔ­Óɹ鹦ÓÚChrome´Ó7Ô·Ý×îÏȽ«HTTPÍøÕ¾±ê¼ÇΪ²»Çå¾²µÄÍøÕ¾ ¡£HelmeµÄÆäËü·¢Ã÷»¹°üÀ¨£ºÄÚÈÝÇå¾²Õ½ÂÔCSPºÍHTTPÑϿᴫÊäÇå¾²HSTSµÄʹÓÃÂÊÏÔÖøÔöÌí £¬»®·ÖΪ40%ºÍ23%£»¼ÓÃÜËã·¨RSAÈÔÈ»ÊÇ×îÊܽӴýµÄÑ¡Ôñ £¬×ÝÈ»ÍÖÔ²ÇúÏßECDSAÔ½·¢Çå¾² ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/over-50-of-top-global-sites-now-on/


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±ÑÝʾÓÃÓÚÇÔÈ¡ÊÖ»úÃô¸ÐÐÅÏ¢µÄÉùѧ±ßÐŵÀ¹¥»÷SonarSnoop


À´×ÔÀ¼¿¨Ë¹ÌØ´óѧºÍÁÖѩƽ´óѧµÄÒ»¸öÑо¿ÍŶÓÑÝʾÓÃÓÚÇÔÈ¡ÊÖ»úÃô¸ÐÐÅÏ¢µÄÉùѧ±ßÐŵÀ¹¥»÷SonarSnoop ¡£SonarSnoop½«ÖÇÄÜÊÖ»ú¿´³ÉÉùÄÉϵͳ £¬»ùÓÚÓû§ÊÖÖ¸ÔÚÆÁÄ»ÉϵÄÒÆ¶¯À´ÇÔÊØÐÅÏ¢ ¡£¸Ã¹¥»÷·½·¨ÒÀÀµÓÚÊÖ»úÑïÉùÆ÷·¢³öµÄÉùÒôÒÔ¼°Âó¿Ë·çÍøÂçµ½µÄ»ØÉù £¬Ëü²¢²»ÐèÒªÆÚ´ýÓû§±¬·¢ÉùÒôÐźŠ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/sonarsnoop-acoustic-side-channel-attack-can-steal-touchscreen-interactions/


¡¾ÍþвÇ鱨¡¿Çå¾²Ñо¿Ö°Ô±ÑÝʾÕë¶ÔTPMоƬµÄÁ½ÖÖй¥»÷ÊÖÒÕ


º«¹ú¹ú¼ÒÇå¾²Ñо¿ËùµÄ4ÃûÑо¿Ö°Ô±ÑÝʾÕë¶ÔTPMоƬµÄÁ½ÖÖй¥»÷ÊÖÒÕ ¡£TPM£¨¿ÉÐÅÆ½Ì¨Ä £¿é£©Í¨³£°²ÅÅÔڸ߼ÛÖµµÄÅÌËã»úÉÏ £¬ÀýÈçÆóÒµ»òÕþ¸®ÍøÂçÖеÄÅÌËã»ú ¡£Ñо¿Ö°Ô±·¢Ã÷µÄÕâÁ½¸öÎó²î £¬SRTMÎó²î£¨CVE-2018-6622£©ºÍDRTM£¨tboot£©Îó²î£¨CVE-2017-16837£©¶¼ÐèÒª¶Ô×°±¸¾ÙÐÐÎïÆÊÎö¼û £¬µ«ÕⲢûÓнµµÍËüÃǵÄΣÏÕÐÔ ¡£Ïà¹ØÓû§ÐèҪʵʱװÖù̼þ¸üР¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/researchers-detail-two-new-attacks-on-tpm-chips/


¡¾¶ñÒâÈí¼þ¡¿Check PointÐû²¼¹ØÓÚCEIDPageLock rootkitµÄÆÊÎö±¨¸æ


Check PointÑо¿Ö°Ô±Ðû²¼¹ØÓÚCEIDPageLock rootkitµÄÆÊÎö±¨¸æ £¬CEIDPageLockÓÉRIG EK·Ö·¢ £¬Ö÷ÒªÕë¶ÔÖйú ¡£CEIDPageLockÖ÷ÒªÓÃÓÚÐ®ÖÆÓû§ä¯ÀÀÆ÷µÄÖ÷Ò³ £¬½«Óû§Öض¨ÏòÖÁ¹ã¸æÍøÕ¾2345.com¶ø²»¸Ä±ää¯ÀÀÆ÷ÖÐÏÔʾµÄURL ¡£¹¥»÷Õßͨ¹ýÕâÖÖ¹ã¸æÊÕÈë׬Ǯ £¬²¢ÍøÂçÓû§µÄÍøÕ¾»á¼û¼Í¼ÒÔ¾ÙÐо«×¼¹ã¸æÍÆËÍ»ò³öÊÛÕâЩÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£ºhttps://research.checkpoint.com/ceidpagelock-a-chinese-rootkit/


¡¾¶ñÒâÈí¼þ¡¿Çå¾²Ñо¿ÍŶӷ¢Ã÷Ö»¼ÓÃÜexeÎļþµÄÐÂÀÕË÷Èí¼þ


MalwareHunterTeam·¢Ã÷Ò»¸öеÄÖ»¼ÓÃÜexeÎļþµÄÀÕË÷Èí¼þ £¬¸ÃÀÕË÷Èí¼þÓÐÒ»¸öÏ£ÆæµÄÎÊÌ⣺°Â°ÍÂíµÄÓÀºãÖ®À¶ÀÕË÷²¡¶¾ ¡£ÏÖÔÚ»¹²»ÇåÎú¸ÃÀÕË÷Èí¼þµÄ·Ö·¢·½·¨ ¡£¸ÃÀÕË÷Èí¼þÔÚѬȾϵͳºó»áɱËÀ¿¨°Í˹»ù¡¢McAfeeºÍÈðÐǵÈɱ¶¾Èí¼þµÄÀú³Ì £¬²¢ÏÔʾһÕ۰ÍÂíµÄͼƬ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/barack-obamas-blackmail-virus-ransomware-only-encrypts-exe-files/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±·¢Ã÷Fiservƽ̨±£´æÇå¾²Îó²î £¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÓû§ÐÅϢй¶


Çå¾²Ñо¿Ö°Ô±Kristian Erik Hermansen·¢Ã÷½ðÈÚ»ú¹¹ÊÖÒÕ·þÎñÌṩÉÌFiservµÄÍøÂçÆ½Ì¨±£´æÎó²î £¬¿Éµ¼ÖÂÊý°Ù¼ÒÒøÐеÄÊý¾Ýй¶ ¡£FiservûÓÐÃ÷ȷ˵Ã÷Óм¸¶à½ðÈÚ»ú¹¹¿ÉÄÜÊܵ½Ó°Ïì £¬µ«¾Ý±¨µÀÏÖÔÚÓÐ1700¼ÒÒøÐÐÕýÔÚʹÓÃFiservƽ̨ ¡£Fiserv½²»°È˳Ƹù«Ë¾ÔÚÊÕµ½±¨¸æºó24СʱÄÚ¿ª·¢ÁËÐÞ¸´²¹¶¡²¢¾ÙÐÐÁ˰²ÅÅ ¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.infosecurity-magazine.com/news/hundreds-of-banks-exposed-from/