ÐÅÏ¢Çå¾²Öܱ¨-2018ÄêµÚ47ÖÜ
Ðû²¼Ê±¼ä 2018-11-26±¾ÖÜÇ徲̬ÊÆ×ÛÊö
±¾ÖÜÖµµÃ¹Ø×¢µÄÍøÂçÇå¾²ÊÂÎñÊÇ°µÍøÍйܷþÎñÉÌDaniel's HostingÔâºÚ¿ÍÈëÇÖ£¬Áè¼Ý6500¸öÍøÕ¾±»É¾£»Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ÒÉÓ°ÏìÊýÍòÍòÆû³µ£»¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊƵÄÕ¹Íû±¨¸æ£»VMwareÐû²¼¸üУ¬ÐÞ¸´ÐéÄâ»úÌÓÒÝÎó²îCVE-2018-6983£»¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƹ¥»÷¡£
ƾ֤ÒÔÉÏ×ÛÊö£¬±¾ÖÜÇå¾²ÍþвΪÖС£
Ö÷ÒªÇå¾²Îó²îÁбí
1. Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷í§Òâ´úÂëÖ´ÐÐÎó²î
Apache Sparkµ¥»ú×ÊÔ´ÖÎÀíÆ÷±£´æÇå¾²Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÔÚ¡®master¡¯Ö÷»úÉÏÖ´ÐдúÂë¡£
https://lists.apache.org/thread.html/341c3187f15cdb0d353261d2bfecf2324d56cb7db1339bfc7b30f6e5@%3Cdev.spark.apache.org%3E
2. Dell EMC Avamar Server/EMC Integrated Data Protection Appliance CVE-2018-11077ÏÂÁî×¢ÈëÎó²î
Dell EMC Avamar Server/EMC Integrated Data Protection Appliance±£´æÊäÈëÑéÖ¤Îó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇó£¬ÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£
http://packetstormsecurity.com/files/150420/Dell-EMC-Avamar-IDPA-Command-Injection.html
3. TP-Link TL-R600VPN HTTP Server CVE-2018-3950»º³åÇøÒç³öÎó²î
TP-Link TL-R600VPN HTTP Server±£´æ»º³åÇøÒç³öÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÇëÇ󣬿Éʹϵͳ±ÀÀ£»ò¿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://www.tp-link.com/us/products/details/cat-4909_TL-R600VPN.html
4. Adobe Flash PlayerÀàÐÍ»ìÏýÔ¶³Ì´úÂëÖ´ÐÐÎó²î
Adobe Flash Player±£´æÀàÐÍ»ìÏýÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþÇëÇó£¬ÓÕʹÓû§ÆÊÎö£¬¿ÉÖ´ÐÐí§Òâ´úÂë¡£
https://helpx.adobe.com/security/products/flash-player/apsb18-44.html
5. Google Chrome GPUÊͷźóʹÓÃÎó²î
Google Chrome GPU±£´æÊͷźóʹÓÃÎó²î£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄWEBÇëÇ󣬿ÉʹӦÓóÌÐò±ÀÀ£»òÖ´ÐÐí§Òâ´úÂë¡£
https://chromereleases.googleblog.com/2018/11/stable-channel-update-for-desktop_19.html
Ö÷ÒªÇå¾²ÊÂÎñ×ÛÊö

11ÔÂ15ÈÕ°µÍø×î´óµÄÍøÂçÍйܷþÎñÉÌDaniel's HostingÔâµ½ºÚ¿ÍÈëÇÖ£¬¹¥»÷Õßɾ³ýÁË6500¶à¸öÍøÕ¾£¬²¢ÇÒÕâЩÍøÕ¾¶¼Ã»Óб¸·Ý¡£¸ÃÍйܷþÎñÉ̱³ºóµÄ¿ª·¢Ö°Ô±Daniel Winzen֤ʵ³Æ£¬·þÎñÆ÷µÄrootÕË»§Ò²±»É¾³ýÁË£¬²¢ÇÒƽ̨ÉÏÍйܵÄÁè¼Ý6500¸öÍøÕ¾µÄÊý¾Ý¶¼Òѳ¹µ×ɥʧ¡£¹¥»÷Õß¿ÉÄÜÊÇʹÓÃÁËphpÖеÄÁãÈÕÎó²î£¬µ«Ò²ÓпÉÄÜÊÇʹÓÃÁËÆäËüµÄÎó²î¡£ÏÖÔÚ»¹Ã»Óй¥»÷ÕßÐû³Æ¶Ô´ËÊÂÈÏÕæ¡£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78165/cyber-crime/daniels-hosting-hacked.html
2¡¢Ñо¿»ú¹¹Åû¶ͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬ÒÉÓ°ÏìÊýÍòÍòÆû³µ

Privacy4Cars·¢Ã÷Ò»ÖÖͨ¹ýÀ¶ÑÀÈëÇÖÆû³µµÄCarsBlues¹¥»÷£¬¸Ã¹¥»÷ÒªÁìÓëÏÖ´ú³µÁ¾ÖеijµÔØÓéÀÖϵͳÓйأ¬Í¨¹ýÀ¶ÑÀÐÒ飬¹¥»÷Õß¿É»ñµÃÓû§µÄÁªÏµÈËÁÐ±í¡¢Í¨»°¼Í¼¡¢ÎĽñÈÕÖ¾ÉõÖÁÊǶÌÐÅÄÚÈݵÈСÎÒ˽¼ÒÐÅÏ¢¡£Privacy4Cars³ÆÕâÖÖ¹¥»÷Ö»ÐèҪʹÓÃÁ®¼ÛÇÒÒ×ÓÚ»ñµÃµÄÓ²¼þ/Èí¼þÔÚ¼¸·ÖÖÓÄÚ¼´¿ÉÍê³É£¬²¢ÇÒ²»ÐèÒª¸ßÉîµÄÊÖÒÕ֪ʶ¡£È«ÇòÊýÍòÍòÁ¾Æû³µÒÉÊܵ½Ó°Ï죬²¿·Ö³§ÉÌÒѾÐû²¼Á˸üС£
ÔÎÄÁ´½Ó£º
https://www.privacy4cars.com/can-my-car-be-hacked/default.aspx3¡¢¿¨°Í˹»ùÐû²¼2019ÄêÍøÂçÍþвÇ÷ÊƵÄÕ¹Íû±¨¸æ

¿¨°Í˹»ùʵÑéÊÒÐû²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÊƵÄÒ»¸öÕ¹ÍûÆÊÎö£¬Ö÷ÒªÄÚÈÝ°üÀ¨£º»òÐí²»»áÔÙ·¢Ã÷¸ü¶àµÄ´óÐÍAPT×éÖ¯£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»áÒ»Ö±ÔöÇ¿£»ÓëÍâ½»ºÍÕþÖÎÓйصĹûÕæÅê»÷£»¶«ÄÏÑǺÍÖж«µØÇø»òÐí»á·ºÆð¸ü¶àµÄ¹¥»÷×éÖ¯£»£¨Ring -£©È¨ÏÞ£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»×îÊܽӴýµÄѬȾǰÑÔ-´¹ÂÚ£»»ò½«·ºÆð¸ü¶àÀàËÆ¡°°ÂÔËÇýÖ𽢡±µÄ¹¥»÷£»¹©Ó¦Á´¹¥»÷½«¼ÌÐø£»Òƶ¯¶ñÒâÈí¼þ²»»á·ºÆð´ó±¬·¢£¬µ«¸ß¼¶¹¥»÷Õß»á¼ÌÐøÑ°ÕÒÈëÇÖ×°±¸µÄÒªÁì¡£
ÔÎÄÁ´½Ó£º
https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/
4¡¢VMwareÐû²¼¸üУ¬ÐÞ¸´ÐéÄâ»úÌÓÒÝÎó²îCVE-2018-6983

VMwareÐÞ¸´Ì츮±ÉÏÅû¶µÄÐéÄâ»úÌÓÒÝÎó²î£¨CVE-2018-6983£©£¬¸ÃÎó²îÊÇÒ»¸öÕûÊýÒç³öÎó²î£¬ÀÖ³ÉʹÓøÃÎó²î¿Éµ¼ÖÂÐéÄâ»úÌÓÒݲ¢ÔÚËÞÖ÷»úÉÏÖ´ÐдúÂë¡£ÊÜÓ°ÏìµÄ²úÆ·°üÀ¨VMware Workstation¡¢VMware FusionµÈ£¬VMwareÔÚWorkstation°æ±¾ 14.1.2/15.0.2¼°Fusion°æ±¾10.1.5/11.0.2ÖÐÐÞ¸´Á˸ÃÎó²î£¬½¨ÒéÓû§¾¡¿ì¾ÙÐиüС£
ÔÎÄÁ´½Ó£º
https://www.vmware.com/security/advisories/VMSA-2018-0030.html
5¡¢¼ÓÃÜÓʼþ·þÎñÉÌProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƹ¥»÷

Ê¢ÐеļÓÃܵç×ÓÓʼþ·þÎñProtonMailÔâµ½ÒÉËÆÀÕË÷Èí¼þڲƵĹ¥»÷Ô˶¯¡£¹¥»÷ÕßAmFearLiathMorÉù³ÆÈëÇÖÁ˸ù«Ë¾²¢ÇÔÈ¡ÁË¡°´ó×Ú¡±µÄÓû§Êý¾Ý¡£¹¥»÷Õß½«ÆäÊê½ðÒªÇóÐû²¼ÔÚPastebinÉÏ£¬²¢ÍþвҪÏòÈ«ÌìÏÂÐû²¼»òÏúÊÛÕâЩÊý¾Ý£¬µ«²¢Î´Ìṩ±»µÁÊý¾ÝµÄÑù±¾¡£ProtonMailÔÚÊÓ²ìÖ®ºó·ñ¶¨ÁËÕâÆð¹¥»÷ÊÂÎñ£¬Éù³ÆÕâÖ»ÊÇÒ»¸öÊÔͼڲƵÄȦÌס£
ÔÎÄÁ´½Ó£º
https://securityaffairs.co/wordpress/78133/hacking/protonmail-hacked-hoax.html
ÉùÃ÷£º±¾×ÊѶÓÉÓÅ·¢¹ú¼ÊÍøÕ¾¹ÙÍøάËûÃüÇ徲С×é·ÒëºÍÕûÀí