ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥(Õ÷ÇóÒâ¼û¸å)£»ºÚ¿ÍÔÚÍøÉÏÐû²¼¿ªÂüÒøÐеÄ2TBÊý¾Ý£»DockerÌÓÒÝÎó²î

Ðû²¼Ê±¼ä 2019-11-21
1¡¢ÍøÐŰìÐû²¼¡¶ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥(Õ÷ÇóÒâ¼û¸å)¡·

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

ΪÓÐÓÃÓ¦¶ÔÍøÂçÇå¾²ÍþвºÍΣº¦£¬°ü¹ÜÍøÂçÔËÐÐÇå¾²£¬¹ú¼Ò»¥ÁªÍøÐÅÏ¢°ì¹«ÊÒ20Èվ͡¶ÍøÂçÇå¾²ÍþвÐÅÏ¢Ðû²¼ÖÎÀí²½·¥£¨Õ÷ÇóÒâ¼û¸å£©¡·¹ûÕæÕ÷ÇóÉç»áÒâ¼û£¬¶ÔÐû²¼ÍøÂçÇå¾²ÍþвÐÅÏ¢µÄÐÐΪ×÷³ö¹æ·¶¡£Æ¾Ö¤Õ÷ÇóÒâ¼û¸å£¬ÍøÂçÇå¾²ÍþвÐÅÏ¢°üÀ¨(Ò»)¶Ô¿ÉÄÜÍþÐ²ÍøÂçÕý³£ÔËÐеÄÐÐΪ£¬ÓÃÓÚÐÎòÆäÒâͼ¡¢ÒªÁì¡¢¹¤¾ß¡¢Àú³Ì¡¢Ð§¹ûµÈµÄÐÅÏ¢£»(¶þ)¿ÉÄÜÌ»Â¶ÍøÂçųÈõÐÔµÄÐÅÏ¢¡£Õ÷ÇóÒâ¼û¸åÃ÷È·£¬Ðû²¼ÍøÂçÇå¾²ÍþвÐÅÏ¢£¬Ó¦ÒÔά»¤ÍøÂçÇå¾²¡¢Ôö½øÍøÂçÇå¾²ÒâʶÌáÉý¡¢½»Á÷ÍøÂçÇå¾²·À»¤ÊÖÒÕ֪ʶΪĿµÄ£¬²»µÃΣº¦¹ú¼ÒÇå¾²ºÍÉç»á¹«¹²ÀûÒæ£¬²»µÃÇÖÕ¼¹«Ãñ¡¢·¨ÈËºÍÆäËû×éÖ¯µÄÕýµ±È¨Òæ¡£

   

Ô­ÎÄÁ´½Ó£º

http://www.cac.gov.cn/2019-11/20/c_1575785387932969.htm

2¡¢ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿Í¹¥»÷£¬CLI×°Öðü±»Ì滻Ϊ¶ñÒâÈí¼þ


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÅÂÞ±Ò¹ÙÍøÔâºÚ¿ÍÈëÇÖ£¬¹Ù·½Linux CLI¶þ½øÖÆÎļþ±»Ì滻ΪÇÔÈ¡Óû§×ʽðµÄ¶ñÒâÈí¼þ¡£¸ÃÊÂÎñ±¬·¢ÔÚ11ÔÂ18ÈÕ£¬Ò»ÃûÓû§ÔÚGithubÉϱ¨¸æÁ˸ÃÎÊÌ⣬ÃÅÂÞ±ÒÍŶÓËæºó¾ÙÐÐÁËÈ·ÈÏ¡£½¨ÒéÔÚ18ºÅ2:30 AM UTCÖÁ4:30 PM UTCÖ®¼äÏÂÔØÁËCLIÇ®°üµÄÓû§¼ì²éÆä¶þ½øÖÆÎļþµÄ¹þÏ£Öµ£¬ÈôÊÇÓë¹ÙÍøÉϵĹþÏ£Öµ²»Æ¥Å䣬Ôò²»ÒªÔËÐиÃÈí¼þ²¢É¾³ýËü¡£Ä¿½ñÃÅÂÞ±ÒÍŶÓÌåÏÖÈÔÔÚÊӲ칥»÷ÕßÔõÑùÈëÇÖÆäÏÂÔØ·þÎñÆ÷£¬ÏÖÔÚÉв»ÇåÎúÓм¸¶àÓû§ÔÚÕâ´ÎºÚ¿Í¹¥»÷ÖÐËðʧÁË×ʽð¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/official-monero-website-compromised-with-malware-that-steals-funds/

3¡¢GateHubºÍEpicBotµÄ220ÍòÓû§Êý¾ÝÔÚÍøÉϹûÕæ

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!

Çå¾²Ñо¿Ô±Troy HuntÌåÏÖ¼ÓÃÜÇ®±ÒÇ®°ü·þÎñGateHubºÍÓÎÏ·ÍøÕ¾EpicBotµÄ220Óû§ÕË»§Êý¾ÝÔÚÍøÉϹûÕæ¡£¸ÃÊý¾Ý¿â°üÀ¨140Íò¸öGateHubÕÊ»§ºÍ80Íò¸öEpicBotÕÊ»§µÄÐÅÏ¢£¬Èçµç×ÓÓʼþµØµãºÍ¾­ÓÉbcrypt´¦Öóͷ£µÄ¹þÏ£ÃÜÂë¡£GateHubÈÏ¿ÉÔÚÑ×ÌìÔâµ½ºÚ¿ÍÈëÇÖ£¬µ«ÆäʱÌåÏÖ½öÓÐ18473¸ö¿Í»§ÕË»§±»²»·¨»á¼û£¬ÏÖÔÚ¿´À´ÕâÒ»¹æÄ£Òª´óµÃ¶à¡£EpicBotÏÖÔÚÉÐδÈÏ¿ÉËüÒѱ»ºÚ¿ÍÈëÇÖ¡£

  

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/hackers-dump-2-2m-gaming-cryptocurrency-passwords-online/150451/

4¡¢PayMyTabÒâÍâй¶ÊýǧÃûÃÀ¹ú²Í¹ÝÖ÷¹ËÊý¾Ý

×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ÃÀ¹úÒÆ¶¯Ö§¸¶·þÎñÉÌPayMyTabÒòδ×ñÕÕAWSµÄÇ徲ЭÒ飬µ¼ÖÂÊýǧÃû²Í¹ÝÖ÷¹ËµÄÊý¾Ýй¶¡£¸Ã¹«Ë¾×Ô2018Äê7ÔÂ2ÈÕÆðûÓн«´æ´¢¿Í»§Êý¾ÝµÄAWS S3´æ´¢Í°¸ü¸ÄΪ˽ÓУ¬Ê¹µÃÈκÎÈ˶¼¿ÉÒÔ»á¼ûʹÓÃPayMyTab·þÎñµÄ²ÍÌüÖ÷¹ËÊý¾Ý£¬°üÀ¨¿Í»§µÄÐÕÃû¡¢µç×ÓÓʼþµØµã¡¢µç»°ºÅÂë¡¢ÐÅÓÿ¨ºóËÄλ¡¢¾Í²ÍÂÄÀúµÈÐÅÏ¢¡£Æ¾Ö¤vpnMentorµÄ˵·¨£¬¸ÃÊý¾Ý¿â̻¶Á˳¤´ï16¸öÔµÄʱ¼ä£¬ËäȻûÓÐй¶µÄÊý¾ÝÁ¿»ò¿Í»§ÊýÄ¿¼òÖ±ÇÐÊý×Ö£¬µ«ÊýǧÃû¿Í»§¿ÉÄÜÒò´ËÊܵ½ÔÚÏßڲƭ»ò¹¥»÷¡£

Ô­ÎÄÁ´½Ó£º
https://www.zdnet.com/article/paymytab-data-leak-exposes-personal-information-belonging-to-mobile-diners/

5¡¢ºÚ¿ÍÔÚÍøÉÏÐû²¼¿ªÂüÒøÐеÄ2TBÊý¾Ý


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


ºÚ¿Í´Ó¿ªÂüÒøÐÐÇÔÈ¡ÁË2TBµÄÊý¾Ý²¢Ðû²¼ÔÚÍøÉÏ¡£¾Ý³ÆÕâЩÊý¾ÝÊÇÓɺڿͻòºÚ¿ÍÍÅ»ïPhineas FisherÇÔÈ¡µÄ£¬²¢Í¨¹ýDistributed Denial of SecretsÏîÄ¿Ðû²¼¡£Êý¾Ý¼¯ÖаüÀ¨¿ªÂüÒøÐÐΪÆäÈ«Çò¿Í»§ÖÎÀíµÄÁè¼Ý3800¼Ò¹«Ë¾¡¢ÐÅÍкÍСÎÒ˽¼ÒÕË»§µÄÏêϸ²ÆÎñÐÅÏ¢£¬ÉõÖÁ°üÀ¨ÕË»§Óà¶î¡£¿ªÂüÒøÐв¢Î´ÈÏ¿ÉÊý¾Ýй¶£¬µ«Ç徲ר¼Ò×¢ÖØµ½ÆäÐí¶à·þÎñÓÚ11ÔÂ17ÈÕÒò¡°ÖØ´óÉý¼¶ºÍά»¤¡±¶ø´¦ÓÚ²»¿ÉÓÃ״̬¡£

Ô­ÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/94136/data-breach/cayman-national-bank-data-leak.html

6¡¢DockerÌÓÒÝÎó²î(CVE-2019-14271) PoCÐû²¼


×ðÁú¿­Ê±¡¤(ÖйúÇø)ÈËÉú¾ÍÊDz«!


Ñо¿Ö°Ô±Ðû²¼DockerÌÓÒÝÎó²î£¨CVE-2019-14271£©µÄPoC£¬²¢´ß´ÙÓû§Éý¼¶µ½×îа汾¡£¸ÃÎó²îÔÚ7Ô·ݵÄDocker°æ±¾19.03.1ÖÐÐÞ¸´£¬µ«ÈôÊÇδ´ò²¹¶¡£¬¹¥»÷Õß¿ÉÄÜ»áͨ¹ý¶ñÒâÈÝÆ÷¾µÏñÔÚÓû§µÄËÞÖ÷»úÉÏÒÔrootȨÏÞÖ´ÐÐí§Òâ´úÂë¡£Palo Alto NetworksÇå¾²Ñо¿Ô±Yuval Avrahami±Þ²ßDocker¿ª·¢Ö°Ô±Í¨¹ý½öÔËÐÐÊÜÐÅÍеľµÏñÀ´ïÔÌ­¹¥»÷Ãæ£¬²¢½¨ÒéÔÚ²»ÐèÒªrootµÄÇéÐÎÏÂÒÔ·ÇrootÓû§Éí·ÝÔËÐÐÈÝÆ÷¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.infosecurity-magazine.com/news/researchers-public-poc-docker/