ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÆäTomcatÖеÄDoSÎó²î£»£»£»£»£»OneClass±£´æÎó²î£¬£¬£¬£¬£¬Ð¹Â¶Áè¼Ý100ÍòѧÉúÐÅÏ¢

Ðû²¼Ê±¼ä 2020-06-29

1.ApacheÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÆäTomcatÖеÄDoSÎó²î


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ApacheÈí¼þ»ù½ð»áÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´Apache TomcatÖеÄÎó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓôËÎó²îÌᳫ¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÓ°ÏìÁËApache Tomcat 10.0.0-M1ÖÁ10.0.0-M5°æ±¾¡¢ 9.0.0.M1ÖÁ9.0.35°æ±¾ºÍ8.5.0ÖÁ8.5.55°æ±¾¡£¡£¡£¡£¡£¡£¡£ÔÚδÐÞ¸´°æ±¾ÖУ¬£¬£¬£¬£¬ÌØÊâµÄHTTP/2ÇëÇóÐòÁпÉÄܻᵼÖ³¤´ï¼¸ÃëÖӵĸßCPUʹÓÃÂÊ£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔͨ¹ý·¢ËÍ×ã¹»ÊýÄ¿µÄ´ËÀàÇëÇ󣬣¬£¬£¬£¬Ê¹µÃЧÀÍÆ÷¾Ü¾øÏìÓ¦£¬£¬£¬£¬£¬ÊµÏÖDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.us-cert.gov/ncas/current-activity/2020/06/26/apache-releases-security-advisory-apache-tomcat


2.·¨¹úµçÊǪ́T¨¦l¨¦visions¹ÙÍøÔâµ½¹¥»÷ £¬£¬£¬£¬£¬ËæºóÆôÓñ¸ÓÃÕ¾µã


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


·¨¹úµçÊǪ́T¨¦l¨¦visions GroupÓÚÉÏÖÜÎåÐû²¼£¬£¬£¬£¬£¬Æä¹ÙÍøÔâµ½ÁËÍøÂç¹¥»÷¡£¡£¡£¡£¡£¡£¡£¾Ý¸Ã¹«Ë¾³Æ£¬£¬£¬£¬£¬Æä¹ÙÍøÑ¬È¾Á˶ñÒâÈí¼þ£¬£¬£¬£¬£¬Ëæºó¸Ã¹«Ë¾ÆôÓÃÁËÆä±¸ÓÃÕ¾µã£¬£¬£¬£¬£¬²¢½«France 3ƵµÀ×ªÒÆµ½ÁË·¨¹ú¹ã²¥µçÊǪ́×ܲ¿¡£¡£¡£¡£¡£¡£¡£¾ÝϤ£¬£¬£¬£¬£¬´Ë´Î¹¥»÷»î¶¯²¢Ã»ÓÐÓ°Ïìµ½¸Ã¹«Ë¾µÄ¹ã²¥ÌìÏߣ¬£¬£¬£¬£¬²¢ÇÒ£¬£¬£¬£¬£¬¸Ã¹«Ë¾ÏÖÔÚÒѾ­³ä·Ö½ÓÄÉÁËÓ¦¼±²½·¥£¬£¬£¬£¬£¬¹ã²¥ÔÚ¶ÌÆÚÄÚ²»»áÔÙÊܵ½Ó°Ïì¡£¡£¡£¡£¡£¡£¡£Õâ²¢²»ÊǵÚÒ»´ÎÕë¶Ô·¨¹úýÌåµÄ¹¥»÷£¬£¬£¬£¬£¬2019ÄêÀÕË÷Èí¼þÍŻ﹥»÷ÁËM6 ¡ª¡ª ·¨¹ú×î´óµÄµçÊÓÆµµÀÖ®Ò»¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/105269/hacking/france-televisions-group-cyber-attack.html


3.ѧϰƽ̨OneClass±£´æÎó²î£¬£¬£¬£¬£¬Ð¹Â¶Áè¼Ý100ÍòѧÉúÐÅÏ¢


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ѧϰƽ̨OneClassµÄWebÓ³É䲿·Ö±£´æÎó²î£¬£¬£¬£¬£¬Ð¹Â¶Áè¼Ý100ÍòѧÉúÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£´Ë´ÎÊÂÎñй¶ÁË27 GBµÄÊý¾Ý£¬£¬£¬£¬£¬×ܼÆ890ÍòÌõ¼Í¼£¬£¬£¬£¬£¬Éæ¼°µ½ÁËÁè¼Ý100Íò¸öOneClassСÎÒ˽¼ÒÓû§ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£vpnMentorµÄÇå¾²Ñо¿ÍŶӷ¢Ã÷ÁËOneClassµÄWebÓ³É䲿·Ö±£´æÎó²î£¬£¬£¬£¬£¬²¢ÌåÏÖ£¬£¬£¬£¬£¬¸Ãƽ̨µÄÓû§Êý¾Ý¿âÒ²ÊÇδ¼ÓÃÜÇÒÍêÈ«²»Çå¾²µÄ£¬£¬£¬£¬£¬ËûÃÇÏÖÔÚ¾ÍÄܹ»»á¼û´ËÊý¾Ý¿â¡£¡£¡£¡£¡£¡£¡£´Ë´Îй¶ÊÂÎñ¿ÉÄܵ¼ÖÂOneClassµÄδ³ÉÄêÓû§Ôâµ½ÍøÉÏڲƭµÈ¹¥»÷£¬£¬£¬£¬£¬Í¬Ê±ÆäâïÊѵÄÐÅÓÿ¨Ö§¸¶ÐÅÏ¢Ò²½«Êܵ½Íþв¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.breitbart.com/tech/2020/06/26/report-e-learning-data-breach-exposes-1-million-college-students-data/


4.ºÚ¿ÍÔÚ°µÍøÊÛÂôÊý°ÙÍò¶íÂÞ˹ºÍÒÁÀʵÄTelegramÓû§ÐÅÏ¢


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


ºÚ¿ÍÔÚ°µÍøÊÛÂôÊý°ÙÍò¶íÂÞ˹ºÍÒÁÀʵÄTelegram  MessengerÓû§ÐÅÏ¢£¬£¬£¬£¬£¬Telegram¹«Ë¾ÒÑÈ·ÈÏÁ˸ÃÊý¾ÝµÄÕæÊµÐÔ¡£¡£¡£¡£¡£¡£¡£Ñо¿Ö°Ô±ÌåÏÖÕâ¸öÊý¾Ý¿âÊÇÒÔǰ´Ó²î±ð¹ú¼Ò£¬£¬£¬£¬£¬Í¨¹ý²î±ðÒªÁìÍøÂçµÄÖÖÖÖÊý¾Ý¿â¾ÙÐеĻã±à£¬£¬£¬£¬£¬Ö÷ÒªµÄÒªÁìΪͨ¹ý¿ª·Åϵͳ¡¢Ì¸Ìì»úеÈË¡¢ÊÚȨºÍСÎÒ˽¼Ò×¢²áÐÅÏ¢µÄºÅÂëÍøÂç¡£¡£¡£¡£¡£¡£¡£×ÝÈ»Êý¾Ý¿âÖб£´æÖظ´ºÍ¹ýʧÊý¾Ý£¬£¬£¬£¬£¬ÕâÒ²ÊÇÊýÒÔÍòÍò¼ÆµÄÓû§¡£¡£¡£¡£¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨ÁËÓû§id¡¢Óû§Ãû¡¢Ãû¡¢ÐÕ¡¢ÕÕÆ¬¡¢ÊÖ»ú¡¢Ð¡ÎÒ˽¼Ò¼ò½éºÍÍøÕ¾£¬£¬£¬£¬£¬ÓÐЩ»¹°üÀ¨Óû§ÔÚÏßʱµÄÐÅÏ¢¡¢¹ú¼Ò/µØÇøµÈ£¬£¬£¬£¬£¬ÕâЩÊý¾Ýͨ³£¿£¿£¿£¿£¿£¿É±»ÓÃÓÚÎÞÄ¿µÄµÄÀ¬»øÓʼþ¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.ehackingnews.com/2020/06/the-database-of-millions-of-telegram.html


5.Adobe£¬£¬£¬£¬£¬MastercardºÍVisa½¨Òé×èֹʹÓÃMagento 1.x


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Adobe£¬£¬£¬£¬£¬MastercardºÍVisa½¨Òé×èֹʹÓÃMagento 1.x£¬£¬£¬£¬£¬µ«ÏÖÔÚÈÔÓнü11Íò¸öÔÚÏßÊÐËÁÔÚÔËÐÐMagento 1.x CMS¡£¡£¡£¡£¡£¡£¡£Magento 1.xºÜÊDz»Çå¾²£¬£¬£¬£¬£¬ÔÚÒÑÍùÈýÄêÖУ¬£¬£¬£¬£¬ºÚ¿ÍÒ»Ö±ÔÚʹÓÃMagentoÎó²îÀ´¹¥»÷ÍøÉÏÉ̳Ç£¬£¬£¬£¬£¬¾ÙÐÐMagecart¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÔÚ6ÔÂ30ÈÕ£¬£¬£¬£¬£¬Magento 1.xƽ̨½«µÖ´ïÆäÕýʽµÄÊÙÃüÖÕÖ¹£¨EOL£©ÈÕÆÚ£¬£¬£¬£¬£¬ÒÔºóAdobeÍýÏë×èÖ¹ÌṩÇå¾²¸üС£¡£¡£¡£¡£¡£¡£Mastercard·¢³öÖÒÑÔ£¬£¬£¬£¬£¬77%É̳ÇûÓÐ×ñÊØPCI DSSµÄÌõ¿î6£¬£¬£¬£¬£¬Ê¹ÓÃ×îÐµĶøÏµÍ³¡£¡£¡£¡£¡£¡£¡£¶øVisaÔçÔÚ4Ô·ݾͷ¢³öÁËÖÒÑÔ£¬£¬£¬£¬£¬ÒªÇóµêÖ÷¸üе½Magento 2.3¡£¡£¡£¡£¡£¡£¡£6ÔÂ22ÈÕ£¬£¬£¬£¬£¬AdobeÐû²¼ÁËMagento 1.xµÄ×îÖÕÇå¾²¸üУ¬£¬£¬£¬£¬²¢ÌåÏÖÕ⽫ÊÇ×îºóÒ»´Î¸üУ¬£¬£¬£¬£¬ÒªÇóËùÓÐÊÐËÁ¸üе½Magento2.x¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/adobe-mastercard-visa-warn-online-store-owners-of-magento-1-x-eol/


6.ºÚ¿ÍʹÓÃMagecartÕë¶ÔÃÀ¹úÊÐÕþÖ§¸¶Èí¼þClick2Gov


918²©ÌìÌÃ(ÖйúÓÎ)×îйٷ½ÍøÕ¾


Ñо¿Ö°Ô±ÖÒÑÔ˵£¬£¬£¬£¬£¬ÃÀ¹ú8¸ö¶¼»á£¨ºá¿ç3¸öÖÝ£©µÄÍøÕ¾Ôâµ½ÁËMagecart¹¥»÷£¬£¬£¬£¬£¬ÕâÐ©ÍøÕ¾¶¼Ê¹ÓÃÁËÊÐÕþÖ§¸¶Èí¼þClick2Gov¡£¡£¡£¡£¡£¡£¡£Æ¾Ö¤Ç÷ÊÆ¿Æ¼¼µÄÑо¿Ö°Ô±ÆÊÎö£¬£¬£¬£¬£¬ºÚ¿ÍÊÇÔÚÊܺ¦Õßͨ¹ýÊÜѬȾµÄClick2GovÍøÕ¾ÉϾÙÐÐÔÚÏ߸¶¿îʱÌᳫ¹¥»÷µÄ¡£¡£¡£¡£¡£¡£¡£Ôڴ˴ι¥»÷ÖкڿÍʹÓÃÁËÁ½Ì¨exfilteringЧÀÍÆ÷£¬£¬£¬£¬£¬Á½Õß¶¼ÍйÜÁËJavaScript skimmer£¬£¬£¬£¬£¬ÒÔ¼°ÓÃÓÚÎüÊÕ×ß©Êý¾ÝµÄ. jspÎļþ¡£¡£¡£¡£¡£¡£¡£ÆäÖÐһ̨ЧÀÍÆ÷ÓÃÓÚ¹¥»÷Èý¸öÕ¾µã£¬£¬£¬£¬£¬¶øÁíһ̨ЧÀÍÆ÷ÓÃÓÚ¹¥»÷ÆäÓàÎå¸öÕ¾µã¡£¡£¡£¡£¡£¡£¡£Click2GovÒÔÇ°Ò²ÔøÊܵ½Îó²îµÄÓ°Ï죬£¬£¬£¬£¬µ¼ÖÂÁËÁ½´ÎÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£    

Ô­ÎÄÁ´½Ó£º

https://threatpost.com/8-city-gov-websites-magecart/156954/