¶íÂÞ˹µ±¾Ö°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ£»ÃÀ¹ú»õÔË·þÎñTruckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷

°ä²¼¹¦·ò 2019-12-25


1.¶íÂÞ˹µ±¾Ö°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


¶íÂÞ˹µ±¾ÖÖÜÒ»°ä·¢³É¹¦½øÐл¥ÁªÍø¶Ï¿ª²âÊÔ ¡£¸ÃÏî²âÊÔ´ÓÉÏÖÜÆðÍ·½øÐУ¬³ÖÐøÁ˶àÌì£¬Éæ¼°¶íÂÞ˹µ±¾Ö»ú¹¹¡¢±¾µØ»¥ÁªÍø·þÎñÌṩÉ̺ͶíÂÞ˹±¾µØ»¥ÁªÍø¹«Ë¾ ¡£³¢ÊÔµÄÖ÷ÕÅÊDzâÊԸùú¶ÈµÄ»¥ÁªÍø»ù´¡ÉèÊ©£¨ÔÚ¶íÂÞ˹ÄÚ²¿³ÆÎªRuNet£©ÊÇ·ñÄܹ»ÔÚ²»½Ó¼ûÈ«ÇòDNSϵͳºÍ±í²¿»¥ÁªÍøµÄÇé¿öÏÂÔËÐÐ ¡£»¥ÁªÍøÁ÷Á¿ÔÚ¶íÂÞ˹ÄÚ²¿½øÐÐÁ˳ÁзÓÉ£¬ÓÐЧµØÊ¹¶íÂÞ˹µÄRuNet³ÉΪÊÀ½çÉÏ×î´óµÄÄÚÁªÍø ¡£µ±¾ÖûÓÐй©ÓйزâÊÔ¼°Æä×é¼þµÄÈκμ¼Êõϸ½Ú£¬Ö»ÊÇÅú×¢µ±¾Ö²âÊÔÁ˼¸ÖÖ¶Ï¿ªÏνӵij¡¾°£¬Ô̺¬·ÂÕÕ¹ú±íÍøÂç¹¥»÷µÄ³¡¾° ¡£µ±¾ÖÔÚ°ä²¼»áÉϰµÊ¾¸Ã³¢ÊÔ»ñµÃÁ˳ɹ¦ ¡£


  Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/russia-successfully-disconnected-from-the-internet/


2.Chromeä¯ÀÀÆ÷ÊÜÐÂMagellan 2.0·ì϶ӰÏì


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


Ò»×éеÄSQLite·ì϶Äܹ»Ê¹¹¥»÷ÕßÔÚChromeä¯ÀÀÆ÷ÖÐÔ¶³ÌÖ´ÐжñÒâ´úÂë ¡£¸Ã×é·ì϶¹²ÓÐ5¸ö£¨CVE-2019-13734£¬CVE-2019-13750~CVE-2019-13753£©£¬±»³ÆÎªMagellan 2.0·ì϶ ¡£ÕâЩ·ì϶ÊÇÓÉ´¦ÖÃSQLiteÊý¾Ý¿â´ÓµÚÈý·½½Ó¹Üµ½µÄSQLºÅÁîʱµÄÊäÈëÑéÖ¤²»ÕýÈ·ÒýÆðµÄ ¡£×êÑÐÍŶӰµÊ¾Magellan 2.0·ì϶¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÓעй©·¨Ê½ÄÚ´æ»òµ¼Ö·¨Ê½±ÀÀ£ ¡£¹È¸èÒѾ­ÔÚChrome 79.0.3945.79Öн¨¸´Á˸÷ì϶ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/google-chrome-impacted-by-new-magellan-2-0-vulnerabilities/


3.NVIDIA°ä²¼GFE°²È«¸üУ¬½¨¸´Ò»¸öÌáȨ·ì϶


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


NVIDIA°ä²¼Windows GeForce Experience£¨GFE£©Èí¼þµÄ°²È«¸üУ¬½¨¸´Ò»¸ö¿Éµ¼ÖÂDZÔÚ±¾µØ¹¥»÷Õß´¥·¢»Ø¾ø·þÎñ»òÌØÈ¨ÌáÉýµÄ°²È«·ì϶ ¡£¸Ã·ì϶£¨CVE-2019-5702£©µÄCVSS V3ÆÀ·ÖΪ8.4£¬Ó°ÏìÁËGFE 3.20.2֮ǰµÄ°æ±¾ ¡£Ö»¹Ü´Ë·ì϶ҪÇó¹¥»÷ÕßÓµÓб¾µØÓû§½Ó¼ûȨÏÞ²¢ÇÒ²»Äܱ»Ô¶³ÌÀûÓ㬵«ÈÔÄܹ»Í¨¹ýÔÚϵͳÉÏÔ¶³Ì¿ªÊͶñÒ⹤¾ßÀ´ÀÄÓÃËü ¡£Æ¾¾ÝNVIDIAµÄ˵·¨£¬¸Ã·ì϶µÄÀûÓÃÄѶȽϵÍ£¬Ö»±ØÒªºÜÉÙµÄÌØÈ¨²¢ÇÒÎÞÐèÓû§½»»¥ ¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ×îа汾 ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/nvidia-patches-high-severity-vulnerability-in-geforce-experience/


4.P2P½©Ê¬ÍøÂçMoziÖØÒªÕë¶ÔÍø¼þ¡¢D-LinkºÍ»ªÎªÂ·ÓÉÆ÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


×êÑÐÈËÔ±·¢ÏÖÐÂP2P½©Ê¬ÍøÂçMoziÔÚ»ý¼«Õë¶ÔÍø¼þ¡¢D-LinkºÍ»ªÎªµÄ·ÓÉÆ÷ ¡£¸Ã½©Ê¬ÍøÂçÓë¶ñÒâÈí¼þGafgytÓйØ£¬ÓÉÓÚËü³ÁÓÃÁ˺óÕߵIJ¿ÃÅ´úÂë ¡£MoziµÄÖØÒªÖ÷ÕÅÊÇÓÃÓÚDDoS¹¥»÷ ¡£×êÑÐÈËÔ±·¢Ïָý©Ê¬ÍøÂçʹÓÃÒ»ÖÖ¶¨ÔìµÄÀ©´óÉ¢²¼Ê½¹þÏ£±í£¨DHT£©ºÍ̸À´ÊµÏÖ£¬¸ÃºÍ̸ͨ³£±»torrent¿Í»§¶ËºÍÆäËûP2Pƽ̨ÓÃÓÚ´æ´¢½ÚµãÁªÏµÐÅÏ¢ ¡£Mozi»¹Ê¹ÓÃECDSA384ºÍXORËã·¨À´È·±£½©Ê¬ÍøÂç×é¼þºÍP2PÍøÂçµÄÆëÈ«ÐԺͰ²È«ÐÔ ¡£MoziÖØÒªÍ¨¹ýtelnetÀûÓÃÈõÃÜÂë½Ó¼ûÒ×Êܹ¥»÷µÄÉ豸£¬²¢ÔÚ¼ÓÔØ¶ñÒâÈí¼þºóËÑË÷ºÍϰȾÆäËüÒ×Êܹ¥»÷µÄÉ豸 ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/new-mozi-p2p-botnet-takes-over-netgear-d-link-huawei-routers/


5.ÀÕË÷Èí¼þMaze¹¥»÷ÅíÈø¿ÆÀ­Êв¢ÀÕË÷100ÍòÃÀÔª


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÀÕË÷Èí¼þMaze±³ºóµÄ¹¥»÷Õß°ä²¼Á˾ݳÆÊÇ´ÓÅíÈø¿ÆÀ­ÊÐÇÔÈ¡µÄ2GBÎļþ ¡£±¾Ô³õÅíÈø¿ÆÀ­ÊÐÔâ·êÀÕË÷Èí¼þ¹¥»÷£¬Æäµç×ÓÓʼþ·þÎñ¡¢µç»°·þÎñµÈ¾ùÊÜÓ°Ï죬ÆäʱMaze¹¥»÷ÕßÌá³ö100ÍòÃÀÔªµÄÊê½ðÒªÇ󣬵«ÅíÈø¿ÆÀ­ÊÐûÓÐÈ·ÈÏÕâÒ»ÐÂÎŲ¢°µÊ¾¸ÃÊÐÔÚ´Ó±¸·ÝÖлºÂý¸´Ô­ ¡£Maze¹¥»÷Õß°µÊ¾´Ó¸ÃÊÐÇÔÈ¡ÁË32GBµÄÎļþ£¬²¢°ä²¼ÁË2GBµÄÎļþ×÷Ϊ֤Ã÷ ¡£ÅíÈø¿ÆÀ­ÊÐÉÐδ¶Ô´Ë½øÐлØÓ¦ ¡£


 Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/maze-ransomware-releases-files-stolen-from-city-of-pensacola/


6.ÃÀ¹ú»õÔË·þÎñTruckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷


±¦ÔËÀ³¡¤(ÖйúÇø)×îйٷ½ÍøÕ¾


ÃÀ¹ú»õÔË·þÎñ¹«Ë¾Truckstop.comÔâµ½¶ñÒâÈí¼þ¹¥»÷£¬¶à¸öÔÚÏß·þÎñÖжÏ ¡£Truckstop.comÓÚ12ÔÂ21ÈÕ£¨ÐÇÆÚÁù£©¹«¿ªÃ÷ÖªÓû§Æä¡°Óöµ½¼¼ÊõÎÊÌ⡱£¬²¢ÖÂÁ¦ÓÚ¾¡¿ì½â¾ö¸ÃÎÊÌâ ¡£ÔÚ12ÔÂ23ÈÕÐÇÆÚÒ»µÄÉêÃ÷ÖУ¬Truckstop.com°µÊ¾ÖжÏÊÇ¡°ÓɶñÒâÈí¼þÒýÆðµÄ¡±£¬µ«Ã»ÓÐй©ÊÇ·ñÓпͻ§ÐÅÏ¢±»Ð¹Â¶ ¡£½ØÖÁ12ÔÂ22ÈÕÐÇÆÚÈÕ£¬ÖÁÉÙ7¸öÊôÓÚTruckstop.comµÄÕ¾µã±»¹Ø¹ØÁË£¬Ô̺¬»õÎï×°ÔØ·þÎñ¡¢³ÐÔËÈË·þÎñ¡¢°²È«ºÏ¹æ·þÎñSaferWatch¡¢ÍÐÊÕ±£¸¶·þÎñ¡¢RFP¹¤¾ßºÍʵʱ»õÔË·þÎñµÈ ¡£


 Ô­ÎÄÁ´½Ó£º

https://finance.yahoo.com/news/malware-hits-truckstop-com-sites-175226734.html