¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180703

Ðû²¼Ê±¼ä 2018-07-03

¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±·¢Ã÷ʹÓÃPROPagate´úÂë×¢ÈëÊÖÒյĶñÒâ¹¥»÷»î¶¯


PROPagate´úÂë×¢ÈëÊÖÒÕ×îÔçÓÚ2017Äê11ÔÂÓÉHexacornÇå¾²Ñо¿Ö°Ô±·¢Ã÷£¬£¬£¬£¬ £¬¸ÃÑо¿Ö°Ô±Ö¤ÊµËü¿ÉÒÔÔÚËùÓÐ×îеÄWindows°æ±¾ÉÏÔËÐУ¬£¬£¬£¬ £¬²¢ÇÒ¿ÉÄÜÔÊÐí¹¥»÷Õß½«¶ñÒâ´úÂë×¢ÈëÆäËûÓ¦ÓóÌÐò¡£¡£¡£¡£¡£×¨¼Ò³ÆÊÇÓÉÓÚSetWindowSubclassº¯ÊýÄÚ²¿Ê¹ÓõÄÕýµ±GUI´°¿ÚÊôÐÔ£¨UxSubclassInfoºÍCC32SubclassInfo£©ÔÚÆäËûÓ¦ÓóÌÐòÄÚ²¿¼ÓÔØºÍÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£×î½ü£¬£¬£¬£¬ £¬FireEyeµÄר¼Ò·¢Ã÷ÁËÒ»¸öʹÓÃRIG Exploit Kitͨ¹ýPROPagate´úÂë×¢ÈëÊÖÒÕ¶ñÒâÍÚ¾òMoneroµÄ»î¶¯¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://securityaffairs.co/wordpress/74068/malware/propagate-code-injection-malware.html


¡¾ÍþвÇ鱨¡¿Ñо¿Ö°Ô±³ÆÐµÄDiameterµç»°Ð­ÒéÓëSS7Ò»ÑùÒ×Êܹ¥»÷


Çå¾²Ñо¿Ö°Ô±ÌåÏÖ£¬£¬£¬£¬ £¬Óë½ñÌìµÄ4G£¨LTE£©µç»°ºÍÊý¾Ý´«Êä±ê×¼Ò»ÆðʹÓõÄDiameterЭÒéÈÝÒ×Êܵ½Óë¾ÉµÄµç»°±ê×¼£¨Èç3G£¬£¬£¬£¬ £¬2GºÍ¸üÔç°æ±¾£©Ê¹ÓõľÉSS7±ê×¼ÏàͬÀàÐ͵ÄÎó²îµÄ¹¥»÷£¬£¬£¬£¬ £¬SS7ÊÇÔÚ20ÊÀ¼Í70ÄêÔ¿ª·¢µÄ£¬£¬£¬£¬ £¬¿ìÒª¶þÊ®Äê֤ʵÆä±£´æ²»Çå¾²ÒòËØ¡£¡£¡£¡£¡£ÕýÓÉÓÚÔÆÔÆ£¬£¬£¬£¬ £¬´ÓÍÆ³ö4G£¨LTE£©ÍøÂç×îÏÈ£¬£¬£¬£¬ £¬SS7±»DiameterЭÒéËùÈ¡´ú£¬£¬£¬£¬ £¬DiameterЭÒéÊÇÒ»ÖÖˢеÄÍø¼äºÍÍøÄÚÐÅÁîЭÒ飬£¬£¬£¬ £¬Ò²½«ÓÃÓÚ¼´½«ÍƳöµÄ5G±ê×¼¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/newer-diameter-telephony-protocol-just-as-vulnerable-as-ss7/


¡¾Çå¾²²¥±¨¡¿ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼½«É¾³ýÊýÒÔÒڼƵĵ绰ºÍ¶ÌÐżÍ¼


ÃÀ¹ú¹ú¼ÒÇå¾²¾Ö£¨NSA£©ÉÏÖÜÐû²¼£¬£¬£¬£¬ £¬ËüÕýÔÚ´ó×Úɾ³ýÊýÒÚÌõ¿É×·Ëݵ½2015ÄêµÄµç»°ºÍ¶ÌÐżÍ¼¡£¡£¡£¡£¡£Ô­×ÓÄÜ»ú¹¹ÌåÏÖ£¬£¬£¬£¬ £¬ÔÚÃÀ¹ú¹ú¼ÒÇå¾²¾ÖÆÊÎöÖ°Ô±·¢Ã÷¡°´ÓµçÐÅЧÀÍÌṩÉÌ´¦ÊÕµ½µÄһЩÊý¾Ý±£´æÊÖÒÕÎ¥¹æÐÐΪ¡±ºó£¬£¬£¬£¬ £¬Ëü½«´ÓÆäϵͳÖÐɾ³ýÊý¾Ý¡£¡£¡£¡£¡£NSAÈÏ¿ÉËüÊÕµ½µÄÔªÊý¾Ý¶àÓÚÔÊÐíµÄÔªÊý¾Ý£¬£¬£¬£¬ £¬NSAɾ³ýÁ˽üÈýÄêµÄÔªÊý¾Ý¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/government/nsa-deletes-hundreds-of-millions-of-call-records-over-technical-irregularities/


¡¾Çå¾²²¥±¨¡¿FacebookÈÏ¿ÉÏò61¼Ò¹«Ë¾Ìṩ¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ

FacebookÒѾ­ÈϿɣ¬£¬£¬£¬ £¬¸Ã¹«Ë¾ÒÑÏòÊýÊ®¼Ò¿Æ¼¼¹«Ë¾ºÍÓ¦Óÿª·¢ÉÌÌṩÁË¶ÔÆäÓû§Êý¾ÝµÄÌØÊâ»á¼ûȨÏÞ£¬£¬£¬£¬ £¬ÔÚ½ñÄê3ÔÂÐû²¼µÄCambridge Analytica³óÎÅʱ´ú£¬£¬£¬£¬ £¬FacebookÌåÏÖ£¬£¬£¬£¬ £¬ËüÒѾ­ÔÚ2015Äê5ÔÂ×èÖ¹Á˵ÚÈý·½»á¼ûÆäÓû§Êý¾Ý¡£¡£¡£¡£¡£È»¶øÔÚ½üÆÚÐû²¼µÄÒ»·Ý³¤´ï747Ò³µÄÎļþÖÐÈϿɣ¬£¬£¬£¬ £¬¸Ã¹«Ë¾ÔÚ2015ÄêÖ®ºó¼ÌÐøÓë61¼ÒÓ²¼þºÍÈí¼þÖÆÔìÉÌÒÔ¼°Ó¦Óÿª·¢É̹²ÏíÊý¾Ý¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/07/facebook-data-privacy.html


¡¾Çå¾²²¥±¨¡¿ÈýÐDz¿·ÖϵÁÐÊÖ»ú±£´æbug£¬£¬£¬£¬ £¬¿É½«Ëæ»úͼƬ·¢Ë͸øÁªÏµÈË


×îа汾µÄÈýÐǶÌÐŶÌÐÅÓ¦ÓóÌÐò±£´æbug£¬£¬£¬£¬ £¬¿É½«Ëæ»úͼƬ·¢Ë͸øÓû§µÄÁªÏµÈË¡£¡£¡£¡£¡£ºÃÐÂÎÅÊÇ£¬£¬£¬£¬ £¬Õâ¸öÎÊÌâËÆºõÖ»ÏÞÓÚGalaxyϵÁУ¬£¬£¬£¬ £¬ÈçS9¡¢S9 PlusºÍNote 8£¬£¬£¬£¬ £¬¶ø²»ÊÇËùÓÐÈýÐÇÊÖ»ú¡£¡£¡£¡£¡£Ö»ÓÐÔÚ×îа汾ÖиüеÄÓû§²Å»áÊܵ½Ó°Ï죬£¬£¬£¬ £¬Óöµ½bugµÄÓû§Ëµ£¬£¬£¬£¬ £¬ËûÃDz»ÖªµÀÊÖ»úÒѾ­·¢ËÍÁËÕÕÆ¬£¬£¬£¬£¬ £¬ÓÉÓÚËüÃDz»ÏÔʾΪ·¢Ë͵ÄÐÂÎÅ¡£¡£¡£¡£¡£Ö»Óе±ÕâЩÕÕÆ¬µÄÊÕ¼þÈË»ØÐÅѯÎÊÕâЩÉñÃØµÄÐÂÎÅʱ£¬£¬£¬£¬ £¬ËûÃDzŷ¢Ã÷¡£¡£¡£¡£¡£ÈýÐǽ¨ÒéÓû§²»Òª¸üе½×îеÄÈýÐÇÐÂÎÅÓ¦ÓóÌÐòÖ±µ½ÈýÐÇÐÞ¸´ÕâЩÎÊÌâ¡£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/mobile/glitch-in-samsung-messages-app-sends-photos-to-random-contacts/


¡¾Îó²î²¹¶¡¡¿VMwareÐû²¼Çå¾²¸üУ¬£¬£¬£¬ £¬ÐÞ²¹Æä¶à¸ö²úÆ·Öпɵ¼ÖÂDoS»òÐÅϢй¶µÄÎó²î


VMwareÉÏÖÜ֪ͨ¿Í»§£¬£¬£¬£¬ £¬ÆäÐÞ²¹Á˶à¸ö¿ÉÄܵ¼ÖÂÆäESXi£¬£¬£¬£¬ £¬WorkstationºÍFusion²úÆ·ÖзºÆð¾Ü¾øÐ§ÀÍ£¨DoS£©»òÐÅϢй¶µÄÎó²î¡£¡£¡£¡£¡£¾ßÓÐͨÀýÓû§È¨Ï޵Ĺ¥»÷Õß¿ÉʹÓÃÇå¾²Îó²î»ñÊØÐÅÏ¢»òʹÐéÄâ»úÍ߽⡣¡£¡£¡£¡£¸ÃÎó²î±»ÁÐΪÖ÷Òª£¬£¬£¬£¬ £¬¸ú×ÙΪCVE-2018-6965¡¢CVE-2018-6966ºÍCVE-2018-6967¡£¡£¡£¡£¡£Cisco TalosµÄÑо¿Ö°Ô±·¢Ã÷ÁËCVE-2018-6965¡£¡£¡£¡£¡£¾ÝVMware³ÆÕâЩȱÏÝ»áÓ°ÏìÔÚÈÎºÎÆ½Ì¨ÉÏÔËÐеÄESXi 6.7ºÍWorkstation 14.x£¬£¬£¬£¬ £¬ÒÔ¼°ÔÚOS XÉÏÔËÐеÄFusion 10.x£¬£¬£¬£¬ £¬²¢ÒÑÐû²¼Õë¶ÔÿÖÖÊÜÓ°Ïì²úÆ·µÄÐÞ²¹³ÌÐòºÍ¸üС£¡£¡£¡£¡£

 

Ô­ÎÄÁ´½Ó£ºhttps://www.securityweek.com/vulnerabilities-patched-vmware-esxi-workstation-fusion