¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20181224
Ðû²¼Ê±¼ä 2018-12-24
Ê¥µØÑǸçÑ§Çø£¨SDUSD£©Ôâµ½ÍøÂç´¹ÂÚ¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ýÍøÂçµ½µÄÊÂÇéְԱƾ֤»á¼ûÁ˸ÃÑ§ÇøµÄÍøÂçЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬Áè¼Ý50ÍòѧÉú¡¢âïÊÑÒÔ¼°ÊÂÇéÖ°Ô±µÄÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£¡£SDUSD³Æ¸ÃδÊÚȨ»á¼ûÒ»Á¬ÁË¿ìÒªÒ»ÄêµÄʱ¼ä£¨2018Äê1Ôµ½11Ô£©£¬£¬£¬£¬£¬£¬£¬£¬ÊÜÓ°ÏìµÄÊý¾Ý×îÔç¿É×·ËÝÖÁ2008ÖÁ2009ѧÄ꣬£¬£¬£¬£¬£¬£¬£¬°üÀ¨Ñ§ÉúºÍÔ±¹¤µÄÐÕÃû¡¢³öÉúÈÕÆÚ¡¢¼Òͥסַ¡¢µç»°ºÅÂë¡¢Éç±£ºÅÂë/ѧÉúID¡¢Ñ§ÉúµÄ×¢²áÐÅÏ¢¡¢Ñ§Éú¼Ò³¤¼°Ô±¹¤µÄ½ôÆÈÁªÏµÈËÐÅÏ¢¡¢Ô±¹¤µÄÈËΪÒÔ¼°¸£ÀûÐÅÏ¢µÈ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/info-on-over-500-000-students-and-staff-exposed-in-san-diego-school-district-hack/2¡¢ÐÂÊÖÒÕÖ§³ÖÕ©ÆÒ³Ã潫µ¼ÖÂChromeä¯ÀÀÆ÷¿¨ËÀ
Google ChromeµÄbug±¨¸æÖÐÅû¶ÁËÒ»¸öеÄÊÖÒÕÖ§³Öթƻ£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÕ©ÆÍøÒ³½«Ê¹ÓÃJavaScriptÑ»·ºÄ¾¡ÅÌËã»úµÄCPU×ÊÔ´²¢µ¼ÖÂChrome¿¨ËÀ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍøÒ³µÄÎÊÌâΪ¡°Ö÷ÒªÐÅÏ¢¡±£¬£¬£¬£¬£¬£¬£¬£¬Î±×°³ÉÌáÐÑѬȾµÄWindows¹ýʧ¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬´ËÒ³Ãæ°üÀ¨µÄJavaScript½«Ê¹ä¯ÀÀÖØÊÓ¸´Ìø×ªÖÁ# URL£¬£¬£¬£¬£¬£¬£¬£¬²¢Íù·µµã»÷ÍËÈ´ºÍǰ½ø°´Å¥£¬£¬£¬£¬£¬£¬£¬£¬×îÖÕµ¼ÖÂCPUÕ¼ÓÃ100%¡£¡£¡£¡£¡£¡£¡£¡£Óû§¿Éͨ¹ýɱËÀChromeÀú³ÌÀ´¿¢Ê¿¨ËÀÇéÐΡ£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/new-tech-support-scam-causes-chrome-browser-to-use-100-percent-of-the-cpu/3¡¢Õë¶ÔGmailºÍYahooÕÊ»§µÄд¹ÂÚ¹¥»÷¿ÉÈÆ¹ýSMS 2FAÑéÖ¤
ƾ֤¹ú¼ÊÌØÉâ×éÖ¯µÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯·¢Ã÷Á½ÆðÕë¶ÔÖж«ºÍ·ÇÖÞÖܱߵØÇøµÄÔ¼1000ÃûÈËȨÖ÷ÒåÕߵĴ¹Âڻ¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ´¹Âڻαװ³ÉÕË»§¾¯±¨£¬£¬£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔʹÓûùÓÚSMSµÄ2FAÑéÖ¤ÒªÁìµÄGmailºÍYahooÕÊ»§¡£¡£¡£¡£¡£¡£¡£¡£ÕâЩ»î¶¯»¹Õë¶ÔÁ˸üΪרҵµÄµç×ÓÓʼþЧÀÍ£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçProtonMailºÍTutanota£¬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜËüÃÇĬÈϽÓÄÉÁׯü¸ß¼¶±ðµÄÇå¾²ÐÔºÍÒþ˽ÐÔ¡£¡£¡£¡£¡£¡£¡£¡£Ö¤¾ÝÅúעijЩ°¸ÀýÖÐYahooºÍGmailµÄSMS 2FA±»ÀÖ³ÉÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬£¬µ«Ã»ÓÐProtonMailºÍTutanotaÕË»§Êܵ½Ë𺦡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://nakedsecurity.sophos.com/2018/12/21/more-phishing-attacks-on-yahoo-and-gmail-sms-2fa-authentication/4¡¢Õë¶ÔOrangeµ÷ÖÆ½âµ÷Æ÷µÄ´ó¹æÄ£É¨Ãè»î¶¯£¬£¬£¬£¬£¬£¬£¬£¬ÊÔͼ»ñÈ¡WiFiÃÜÂë
Bad Packets LLCÑо¿Ö°Ô±Troy Mursch·¢Ã÷¹¥»÷ÕßÕýÔÚ´ó¹æÄ£É¨ÃèOrange Livebox ADSLµ÷ÖÆ½âµ÷Æ÷¡£¡£¡£¡£¡£¡£¡£¡£¸ÃɨÃè»î¶¯ÓÚ12ÔÂ21ÈÕÐÇÆÚÎå×îÏÈ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃOrange LiveBox×°±¸ÖеÄÎó²î£¨CVE-2018-20377£©À´»ñÈ¡WiFiÍøÂçµÄSSIDºÍÃÜÂë¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷½ü19.5Íò¸öÒ×Êܹ¥»÷µÄOrangeµ÷ÖÆ½âµ÷Æ÷£¬£¬£¬£¬£¬£¬£¬£¬¾ø´ó´ó¶¼Î»ÓÚ·¨¹úºÍÎ÷°àÑÀ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.zdnet.com/article/over-19000-orange-modems-are-leaking-wifi-credentials/5¡¢Ñо¿Ö°Ô±Åû¶Facebookµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬£¬µ«Facebook²»ÍýÏëÐÞ¸´
²¨À¼Çå¾²Ñо¿Ö°Ô±·¢Ã÷FacebookµÄAndroidÒÆ¶¯°æ±¾±£´æÒ»¸öµã»÷Ð®ÖÆÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýiframe±êǩʹÓøÃÎó²îÔÚÓû§µÄFacebookÉÏÐû²¼Á´½Ó¡£¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÒÔΪ¸ÃÎó²îÓëFacebookµÄÌØ¶¨APIŲÓúöÂÔÁËX-Frame-Options±êÍ·Óйأ¬£¬£¬£¬£¬£¬£¬£¬¸Ã±êÍ·¿ÉÒÔ֪ͨä¯ÀÀÆ÷ÊÇ·ñ¼ÓÔØiFrameÍøÒ³¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ½«ÍøÒ³¼ÓÔØµ½ÓÕ¶üÍøÒ³µÄ¶¥²ãÖУ¨²»¿É¼ûµÄiFrame£©£¬£¬£¬£¬£¬£¬£¬£¬Óû§½«Íû¼ûÓÕ¶üÍøÒ³£¬£¬£¬£¬£¬£¬£¬£¬µ«ÏÖʵÉÏÓë¸ÃiFrame¾ÙÐн»»¥¡£¡£¡£¡£¡£¡£¡£¡£FacebookÒÔΪÕâ²»ÊÇÒ»¸öÇå¾²ÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬ÓÉÓÚËüûÓÐÓ°Ïìµ½Óû§ÕË»§µÄÍêÕûÐÔ¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://www.bleepingcomputer.com/news/security/the-clickjacking-bug-that-facebook-wont-fix/6¡¢¼ÌÓ¢¹úºÍºÉÀ¼Ö®ºó£¬£¬£¬£¬£¬£¬£¬£¬UberÔÙ±»·¨¹úÊý¾Ý±£»£»£»£»£»£»¤»ú¹¹·£¿£¿£¿£¿£¿£¿£¿î40ÍòÅ·Ôª
2016ÄêUberÔâÓöÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÈ«ÇòÔ¼5700ÍòÓû§ºÍ˾»úµÄСÎÒ˽¼ÒÊý¾Ýй¶£¬£¬£¬£¬£¬£¬£¬£¬µ«Ö±µ½Ò»Äê¶àÒÔºóµÄ2017Äê11Ô¸ù«Ë¾²ÅÏòÍâ½çÅû¶ÁËÕâÒ»ÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¡£2018Äê9Ô£¬£¬£¬£¬£¬£¬£¬£¬UberÔÞ³ÉÏòÃÀ¹ú¸çÂ×±ÈÑÇÌØÇøÖ§¸¶1.48ÒÚÃÀÔªµÄÏ¢Õù½ð¡£¡£¡£¡£¡£¡£¡£¡£2018Äê11Ô£¬£¬£¬£¬£¬£¬£¬£¬Ó¢¹úºÍºÉÀ¼µÄÊý¾Ý±£»£»£»£»£»£»¤»ú¹¹»®·ÖÏòUber·£¿£¿£¿£¿£¿£¿£¿î38.5ÍòÓ¢°÷ºÍ60ÍòÅ·ÔªµÄ·£¿£¿£¿£¿£¿£¿£¿î¡£¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬£¬·¨¹úµÄÊý¾Ý±£»£»£»£»£»£»¤»ú¹¹ÔÙ´ÎÏòÆä·£¿£¿£¿£¿£¿£¿£¿î40ÍòÅ·Ôª¡£¡£¡£¡£¡£¡£¡£¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/79104/security/frence-agency-fines-uber.htmlÉùÃ÷£º±¾×ÊѶÓÉ¿·¢k8άËûÃüÇ徲С×é·ÒëºÍÕûÀí


¾©¹«Íø°²±¸11010802024551ºÅ