¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181224

Ðû²¼Ê±¼ä 2018-12-24
1¡¢Ê¥µØÑǸçÑ§ÇøÔâºÚ¿ÍÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¼°Ô±¹¤µÄÐÅϢй¶

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£

  

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/


2¡¢ÐÂÊÖÒÕÖ§³ÖÕ©Æ­Ò³Ãæ½«µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾



Google ChromeµÄbug±¨¸æÖÐÅû¶ÁËÒ»¸öеÄÊÖÒÕÖ§³ÖÕ©Æ­»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÕ©Æ­ÍøÒ³½«Ê¹ÓÃJavaScriptÑ­»·ºÄ¾¡ÅÌËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÒ³µÄÎÊÌâΪ¡°Ö÷ÒªÐÅÏ¢¡±£¬£¬£¬£¬£¬£¬£¬£¬Î±×°³ÉÌáÐÑѬȾµÄWindows¹ýʧ¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬´ËÒ³Ãæ°üÀ¨µÄJavaScript½«Ê¹ä¯ÀÀÖØÊÓ¸´Ìø×ªÖÁ# URL£¬£¬£¬£¬£¬£¬£¬£¬²¢Íù·µµã»÷ÍËÈ´ºÍǰ½ø°´Å¥£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýɱËÀChromeÀú³ÌÀ´¿¢Ê¿¨ËÀÇéÐΡ£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/


3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹ÂÚ¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ƾ֤¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯·¢Ã÷Á½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÇøµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹Âڻ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ´¹Âڻαװ³ÉÕË»§¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤ÒªÁìµÄGmailºÍYahooÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçProtonMailºÍTutanota£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËüÃÇĬÈϽÓÄÉÁׯü¸ß¼¶±ðµÄÇå¾²ÐÔºÍÒþ˽ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»ÀÖ³ÉÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£¡£

 

 Ô­ÎÄÁ´½Ó£º

https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/


4¡¢Õë¶ÔOrangeµ÷ÖÆ½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


Bad Packets LLCÑо¿Ö°Ô±Troy Mursch·¢Ã÷¹¥»÷ÕßÕýÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷ÖÆ½âµ÷Æ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎå×îÏÈ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃOrange LiveBox×°±¸ÖеÄÎó²î£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷ÖÆ½âµ÷Æ÷£¬£¬£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼Î»ÓÚ·¨¹úºÍÎ÷°àÑÀ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/


5¡¢Ñо¿Ö°Ô±Åû¶Facebookµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ«Facebook²»ÍýÏëÐÞ¸´

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


²¨À¼Çå¾²Ñо¿Ö°Ô±·¢Ã÷FacebookµÄAndroidÒÆ¶¯°æ±¾±£´æÒ»¸öµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýiframe±êǩʹÓøÃÎó²îÔÚÓû§µÄFacebookÉÏÐû²¼Á´½Ó¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÎó²îÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·ÓйØ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã±êÍ·¿ÉÒÔ֪ͨä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«ÍøÒ³¼ÓÔØµ½ÓÕ¶üÍøÒ³µÄ¶¥²ãÖУ¨²»¿É¼ûµÄiFrame£©£¬£¬£¬£¬£¬£¬£¬£¬Óû§½«Íû¼ûÓÕ¶üÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓë¸ÃiFrame¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£¡£¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÍêÕûÐÔ¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/


6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬UberÔÙ±»·¨¹úÊý¾Ý±£» £»£»£»£» £»¤»ú¹¹·£¿ £¿£¿£¿£¿£¿£¿î40ÍòÅ·Ôª

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


2016ÄêUberÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½Ò»Äê¶àÒÔºóµÄ2017Äê11Ô¸ù«Ë¾²ÅÏòÍâ½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£2018Äê9Ô£¬£¬£¬£¬£¬£¬£¬£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£¡£¡£¡£¡£¡£2018Äê11Ô£¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£» £»£»£»£» £»¤»ú¹¹»®·ÖÏòUber·£¿ £¿£¿£¿£¿£¿£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿ £¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬·¨¹úµÄÊý¾Ý±£» £»£»£»£» £»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿ £¿£¿£¿£¿£¿£¿î40ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£¡£

  

Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.html


ÉùÃ÷£º±¾×ÊѶÓÉ¿­·¢k8άËûÃüÇ徲С×é·­ÒëºÍÕûÀí