ÃÀ¹ú¹ú·À²¿³ÆÎå½Ç´óÂ¥ÌìÌìÎüÊÕµ½3600Íò·â¶ñÒâµç×ÓÓʼþ£»£»£»£»£»£»£»ÑÇÂíÑ·DNSЧÀÍÔâDDoS¹¥»÷̱»¾ÊýСʱ

Ðû²¼Ê±¼ä 2019-10-25
1¡¢ÃÀ¹ú¹ú·À²¿³ÆÎå½Ç´óÂ¥ÌìÌìÎüÊÕµ½3600Íò·â¶ñÒâµç×ÓÓʼþ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

ÓÉÓÚÓµÓдó×ÚÉÌÒµºÍÊÖÒÕÉñÃØ£¬£¬£¬£¬£¬£¬£¬£¬ÃÀ¹ú¹ú·À²¿£¨DoD£©³ÉÎªÍøÂç·¸·¨·Ö×ÓµÄÓÐÀû¿ÉͼµÄÄ¿µÄ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã²¿·ÖÕý½ß¾¡È«Á¦À´×èÖ¹¹¥»÷¡£¡£¡£¡£Æ¾Ö¤Ë®Ê¦ÍøÂç·ÀÓùÐж¯Ë¾ÁµÄ˵·¨£¬£¬£¬£¬£¬£¬£¬£¬Îå½Ç´óÂ¥ÌìÌì×èÖ¹ÁË3600Íò·â°üÀ¨¶ñÒâÈí¼þ¡¢²¡¶¾ºÍÍøÂç´¹ÂÚ¹¥»÷µÄ¶ñÒâµç×ÓÓʼþ¡£¡£¡£¡£¾ÝÔ¤¼Æ£¬£¬£¬£¬£¬£¬£¬£¬Ë®Ê¦Ã¿ÄêÆÆ·ÑÔ¼1.6ÒÚÃÀÔªÀ´Ó¦¶ÔÍøÂçÈëÇÖ£¬£¬£¬£¬£¬£¬£¬£¬¸Ã±¾Ç®°üÀ¨å´»úʱ¼ä¡¢Éú²úºÍ¹¤Ê±ËðʧµÄ×ÜÌåÓöÈ¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://cyware.com/news/pentagon-thwarts-36-million-malicious-emails-every-day-navy-cyber-defense-operations-command-reveals-4a5447bf

2¡¢ÑÇÂíÑ·DNSЧÀÍÔâDDoS¹¥»÷̱»¾ÊýСʱ


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÑÇÂíÑ·AWS DNSЧÀÍÆ÷Ôâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂЧÀÍÎÞ·¨»á¼û¡£¡£¡£¡£Ä¿½ñÑÇÂíÑ·Éù³ÆÊÂÎñÒѾ­¿¢Ê£¬£¬£¬£¬£¬£¬£¬£¬Æ¾Ö¤ÆäÐû²¼µÄÉùÃ÷£¬£¬£¬£¬£¬£¬£¬£¬ÔÚ̫ƽÑóÏÄÁîʱ¼ä10:30 AMµ½6:30 PMÖ®¼äÔâµ½DDoS¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬´ÓÏÂÖç5:16×îÏÈÉÙÉÙÊýÌØ¶¨DNSÃû³ÆµÄ¹ýʧÆÊÎöÂʸü¸ß£¬£¬£¬£¬£¬£¬£¬£¬ÕâЩÎÊÌâÄ¿½ñÒѱ»½â¾ö¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.theregister.co.uk/2019/10/22/aws_dns_ddos/

3¡¢BridgeÁ½¸öÖØ¶¨ÏòÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚÌᳫ´¹ÂÚ¹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾

Bridge±£´æÁ½¸ö¿ª·ÅÖØ¶¨ÏòÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¶ÔÍøÕ¾ÖÎÀíÔ±Ìᳫ´¹ÂÚ¹¥»÷¡£¡£¡£¡£BridgeÊÇÒ»¸öÉÌÒµWordPressÖ÷Ì⣬£¬£¬£¬£¬£¬£¬£¬ÆäÏÂÔØ´ÎÊýΪ12Íò¶à´Î¡£¡£¡£¡£WordfenceÑо¿Ö°Ô±·¢Ã÷¸ÃÖ÷ÌâµÄԤװÖòå¼þQode Instagram WidgetºÍQode Twitter FeedÖб£´æ¿ª·ÅÖØ¶¨ÏòÎó²î¡£¡£¡£¡£QodeÐû²¼ÁËÁ½¸ö²å¼þµÄ²¹¶¡³ÌÐò£¬£¬£¬£¬£¬£¬£¬£¬°üÀ¨ÔÚ°æ±¾2.0.2ÖУ¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚÓû§½«BridgeÖ÷Ìâ¸üÐÂΪ°æ±¾18.2.1ºóÓ¦Óᣡ£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/open-redirect-bug-bridge-theme/149437/

4¡¢Henn naÂùݵĻúеÈ˱£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚ¼àÊÓÓοÍ

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÈÕ±¾Á¬ËøÂùÝHenn naʹÓûúеְԱ¹¤È¡´úÈËÀ࣬£¬£¬£¬£¬£¬£¬£¬È»¶øÇå¾²Ñо¿Ö°Ô±Lance R. Vick·¢Ã÷¸ÃÂùݵÄTapia»úеÈ˱£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÊÐí¹¥»÷Õß¼àÊÓÂùݿÍÈË¡£¡£¡£¡£¸ÃÎó²îÓë»úеÈËNFC±êÇ©µÄ»á¼û´úÂëδ¾ÙÐÐÊðÃûÓйØ£¬£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÖ»ÐèÒª¶ÔNFC±êÇ©¾ÙÐÐÉÙÁ¿µÄÖØÐ±à³Ì£¬£¬£¬£¬£¬£¬£¬£¬¼´¿ÉÒ»Á¬Ò»Ö±µØ»á¼ûÊÓÆµºÍÒôƵÁ÷Êý¾Ý¡£¡£¡£¡£Æ¾Ö¤ÍâµØÃ½Ì壬£¬£¬£¬£¬£¬£¬£¬Ö»¹ÜÑо¿Ö°Ô±¶ÔÆäΣº¦¾ÙÐÐÁËÆÀ¹À£¬£¬£¬£¬£¬£¬£¬£¬Tapia»úеÈ˵ÄÖÆÔìÉÌÈÔÌåÏÖδÊÚȨ»á¼ûµÄΣº¦ºÜµÍ¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/bedside-hotel-robot-hacked-video/149491/

5¡¢FujitsuÎÞÏß¼üÅ̱£´æÁ½¸öÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂ×¢Èë¹¥»÷

¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


FujitsuÎÞÏß¼üÅ̱£´æÁ½¸ö¸ßΣÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂÃÜÂë̻¶¼°×¢Èë¹¥»÷¡£¡£¡£¡£Æ¾Ö¤SySSÑо¿Ô±Matthias DeegµÄ±¨¸æ£¬£¬£¬£¬£¬£¬£¬£¬LX390ÔÚÎÞÏß¼üÅ̺ÍÎüÊÕÆ÷Ö®¼äûÓÐʹÓüÓÃÜ´«ÊäÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬Õâµ¼Ö¹¥»÷Õß¿ÉÒÔÐá̽Êý¾Ý°ü²¢ÆÊÎö³öÃÜÂ루CVE-2019-18201£©¡£¡£¡£¡£ÁíÒ»¸öÎó²î£¨CVE-2019-18200£©ÔÊÐí¹¥»÷ÕßÌᳫעÈë¹¥»÷£¬£¬£¬£¬£¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂ×°ÖöñÒâRootkitµÈ¡£¡£¡£¡£ÊÜÓ°ÏìµÄÐͺÅÊÇLX390£¬£¬£¬£¬£¬£¬£¬£¬¸Ã²úÆ·ÒÑÓÚ2019Äê5ÔµִïÉúÃüÖÜÆÚ£¬£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×Ų»»áÓÐÐÞ¸´²¹¶¡Ðû²¼¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£º
https://threatpost.com/fujitsu-wireless-keyboard-unpatched-flaws/149477/ 

6¡¢PHPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-11043£©


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


9ÔÂ26ÈÕPHP¹Ù·½Ðû²¼Îó²îͨ¸æ£¬£¬£¬£¬£¬£¬£¬£¬Ö¸³öʹÓÃNginx + php-fpmµÄЧÀÍÆ÷ÔÚ²¿·ÖÉèÖÃϱ£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2019-11043£©£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÉèÖÃÒѱ»ÆÕ±éʹÓ㬣¬£¬£¬£¬£¬£¬£¬Î£º¦½Ï´ó¡£¡£¡£¡£¸ÃÎó²îµÄPoCÔÚ10ÔÂ22ÈÕ¹ûÕæ¡£¡£¡£¡£ÊÜÓ°ÏìµÄPHP°æ±¾°üÀ¨7.0¡¢7.1¡¢7.2¡¢7.3ÒÔ¼°5.6¡£¡£¡£¡£PHPÒÑÓÚ10ÔÂ12ºÅÐû²¼ÐÞ¸´²¹¶¡¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://lab.wallarm.com/php-remote-code-execution-0-day-discovered-in-real-world-ctf-exercise/