¡¶Î¬ËûÃü¡·ÖðÈÕÇå¾²¼òѶ20180622

Ðû²¼Ê±¼ä 2018-06-22

¡¾Êý¾Ýй¶¡¿Flightradar24ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Ô¼23ÍòÓû§µÄÐÅϢй¶


Èðµä¹«Ë¾Flightradar24֤ʵÆäһ̨ЧÀÍÆ÷ÓÚÉÏÖÜÄ©ÔâºÚ¿ÍÈëÇÖ£¬£¬£¬Ô¼23ÍòÓû§µÄµç×ÓÓʼþµØµãºÍ¹þÏ£ÃÜÂëй¶¡£¡£¡£¡£¡£Flightradar24ÊÇÒ»¼ÒÌṩº½°à×·×ÙЧÀ͵Ĺ«Ë¾£¬£¬£¬¸Ã¹«Ë¾ÌåÏÖ´Ë´Îй¶ӰÏìÁË2016Äê3ÔÂ16ÈÕ֮ǰע²áµÄÓû§¡£¡£¡£¡£¡£Flightradar24ÒÑÏòÓû§·¢ËÍÁ˰üÀ¨ÃÜÂëÖØÖÃÁ´½ÓµÄÓʼþ£¬£¬£¬ÒªÇóÕâЩÓû§¸ü¸ÄÃÜÂë¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/flightradar24-data-breach.html


¡¾Êý¾Ýй¶¡¿Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öappµÄFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û


Çå¾²Ñо¿Ö°Ô±·¢Ã÷Áè¼Ý3000¸öapp£¨°üÀ¨2446¸öAndroid appºÍ600¸öiOS app£©µÄÔ¼2300¸öFirebaseÊý¾Ý¿â¿É¹ûÕæ»á¼û£¬£¬£¬Áè¼Ý1ÒÚÌõÓû§ÐÅϢй¶£¨Áè¼Ý113GB£©¡£¡£¡£¡£¡£ÕâЩй¶µÄÐÅÏ¢°üÀ¨Ã÷ÎÄÃÜÂë¡¢Óû§ID¡¢Î»ÖÃÒÔ¼°²¿·Ö²ÆÎñ¼Í¼£¨ÒøÐС¢¼ÓÃÜÇ®±ÒÉúÒ⣩µÈ¡£¡£¡£¡£¡£GoogleµÄFirebaseÊÇ×îÊܽӴýµÄÒÆ¶¯ºÍWebÓ¦Óõĺó¶Ë¿ª·¢Æ½Ì¨Ö®Ò»£¬£¬£¬ËüΪ¿ª·¢Ö°Ô±ÌṩÁË»ùÓÚÔÆµÄÊý¾Ý¿â£¬£¬£¬²¢ÒÔJSONÃûÌô洢Êý¾Ý¡£¡£¡£¡£¡£Ñо¿Ö°Ô±·¢Ã÷Ðí¶à¿ª·¢Ö°Ô±Î´Í×ÉÆ±£»£»¤ÆäFirebaseÊý¾Ý¿â£¬£¬£¬Ê¹µÃ¹¥»÷ÕßÖ»ÐèÔÚÖ÷»úÃûĩβÌí¼Ó¿ÕÊý¾Ý¿âÃû+¡°/.json¡±¼´¿É»á¼ûÕâЩÊý¾Ý¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/mobile-security-firebase-hosting.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ÇÔÊØÐÅÏ¢µÄ¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯


˼¿ÆTalosÑо¿ÍŶӷ¢Ã÷¶ñÒâÈí¼þFormBookµÄй¥»÷»î¶¯£¬£¬£¬FormBookÖ÷ÒªÓÃÓÚÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬°üÀ¨¼üÅ̼ͼ¡¢ÇÔÈ¡ÃÜÂ루ÍâµØÃÜÂëºÍweb±íµ¥ÖеÄÃÜÂ룩ÒÔ¼°½ØÆÁµÈ¹¦Ð§¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄй¥»÷»î¶¯ÔÚͳһ·â´¹ÂÚÓʼþÖÐʹÓÃÁË4¸ö²î±ðµÄ¶ñÒâÎĵµ£¨°üÀ¨PDFºÍWordÃûÌã©£¬£¬£¬²¢Ê¹ÓÃÁ½¸ö¹ûÕæµÄOfficeÎó²îʹÓã¨CVE-2017-0199ºÍCVE-2017-11882£©·Ö·¢ÓÐÓúÉÔØ¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://blog.talosintelligence.com/2018/06/my-little-formbook.html


¡¾¶ñÒâÈí¼þ¡¿Ñо¿ÍŶӷ¢Ã÷ѬȾÁè¼Ý6Íò¸öÊÖ»úµÄ¶ñÒâÈí¼þScammy


RiskIQÑо¿ÍŶӷ¢Ã÷Ò»¸öжñÒâapp Scammy£¬£¬£¬ScammyÖ÷ÒªÓÃÓÚ×Ô¶¯µã»÷¹ã¸æºÍÇÔÈ¡Óû§µÄÐÅÏ¢£¬£¬£¬°üÀ¨IMEI¡¢µç»°ºÅÂë¡¢ÊÖ»úÐÍºÅºÍÆ·ÅÆ¡¢Î»ÖõÈ¡£¡£¡£¡£¡£Ñо¿Ö°Ô±³Æ¸Ã¶ñÒâÈí¼þÖÁÉÙÒÑѬȾÁË6Íò¸öAndroidÊÖ»ú¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þµÄIoCÇë²Î¿¼ÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.riskiq.com/blog/interesting-crawls/battery-saving-mobile-scam-app/


¡¾Îó²î²¹¶¡¡¿Ñо¿Ö°Ô±³ÆFireFoxºÍEdge±£´æÎó²îWavethrough£¬£¬£¬¿Éµ¼ÖÂÓû§ÐÅϢй¶


GoogleÑо¿Ö°Ô±Jake Archibald·¢Ã÷ÏÖ´úä¯ÀÀÆ÷±£´æÇå¾²Îó²îWavethrough£¬£¬£¬¿ÉÔÊÐí¶ñÒâÍøÕ¾ÇÔÈ¡ÔÚ¸Ãä¯ÀÀÆ÷ÉϵǼ¹ýµÄÆäËüÍøÕ¾µÄÕË»§µÈÃô¸ÐÄÚÈÝ¡£¡£¡£¡£¡£¸ÃÎó²îÓëä¯ÀÀÆ÷´¦Öóͷ£¶ÔÊÓÆµºÍÒôƵÎļþµÄ¿çÓòÇëÇóµÄ·½·¨Óйأ¬£¬£¬ÉõÖÁ¿ÉÔÊÐíÔ¶³Ì¹¥»÷Õß¶ÁÈ¡Óû§µÄGmail»òFacebook˽ÈËÐÂÎÅ¡£¡£¡£¡£¡£ChromeºÍSafari²»ÊÜÓ°Ï죬£¬£¬FireFoxºÍEdgeÒ²ÒÑÔÚ×îа汾ÖÐÐÞ¸´Á˸ÃÎó²î¡£¡£¡£¡£¡£

Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2018/06/browser-cross-origin-vulnerability.html


¡¾Îó²î²¹¶¡¡¿Ë¼¿ÆÐÞ¸´FXOSºÍNX-OSÖеÄ24¸öÇå¾²Îó²î£¬£¬£¬¶à¸öÐͺŵĽ»Á÷»úÊÜÓ°Ïì


±¾ÖÜÈý˼¿ÆÐû²¼FXOSºÍNX-OSµÄÇå¾²¸üУ¬£¬£¬¹²ÐÞ¸´24¸öÇå¾²Îó²î£¬£¬£¬ÆäÖаüÀ¨5¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеĸßΣÎó²î£¨CVE-2018-0301¡¢CVE-2018-0308¡¢CVE-2018-0304¡¢CVE-2018-0314ºÍCVE-2018-0312£©¡£¡£¡£¡£¡£Îó²î¹æÄ£°üÀ¨Î´ÊÚȨ»á¼û¡¢ÌáȨ¡¢í§Òâ´úÂëÖ´ÐС¢í§ÒâÏÂÁîÖ´ÐС¢Ãô¸ÐÐÅϢй¶ºÍDoS¡£¡£¡£¡£¡£Ë¼¿ÆÈ·ÈϳÆÕâЩÎó²îûÓÐÓ°ÏìCisco IOS»òIOS XE¡£¡£¡£¡£¡£ÏêϸÎó²îÁбíÇë»á¼ûÒÔÏÂÁ´½Ó¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://tools.cisco.com/security/center/viewErp.x?alertId=ERP-67770