Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊ飻×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶

°ä²¼¹¦·ò 2020-09-22

1.Pradeo°ä²¼¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊé


1.jpg


Pradeo°ä²¼ÁË¡¶ÊÖ»úÒøÐУºÂÉÀý¡¢ÍþвºÍڲƭԤ·À¡·°×ƤÊé £¬½éÉÜÁËÓйØÒƶ¯ÒøÐеÄʹÓá¢Ë¾·¨¿ò¼Ü¡¢·çÏÕÒÔ¼°±£»¤Òƶ¯ÒøÐÐÀûÓ÷¨Ê½°²È«µÄ½â¾ö¹æ»®£¨´Ó¿ª·¢µ½Ö´ÐУ©µÄ¾ßÌåÐÅÏ¢ ¡£ÆäÖÐд· £¬Òƶ¯ÒøÐзþÎñѸËÙÊܵ½Ïû·ÑÕßµÄϲ»¶ £¬µ½2019Äêµ× £¬74%µÄÓ¢¹úÈ˺Í75%µÄÃÀ¹úÈËʹÓÃÒÆ¶¯É豸À´ÖÎÀíÆä²ÆÕþ ¡£µ«ÊÇ×êÑÐÅú×¢ £¬ÊÖ»úÒøÐÐÀûÓÃÍùÍùûÓÐÔ¤ÆÚµÄÄÇô°²È« £¬¾ÝRSAµÄڲƭ΢·çÏÕµý±¨ÍŶÓ×î½üÍøÂçµÄÊý¾Ý·ÖÎöÏÔʾ £¬ÓëÊÖ»úÀûÓÃÓйصÄڲƭÐÐΪÔÚ2020ÄêµÚÒ»¼¾¶È·­ÁËÒ»·¬ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.helpnetsecurity.com/2020/09/21/whitepaper-mobile-banking-regulations-threats-and-fraud-prevention/


2.F-Secure°ä²¼2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨


2.jpg


F-Secureµ÷²éÁ˽ñÄêÉϰëÄêÍøÂçÍþвµÄ·¢Õ¹Çé¿ö £¬²¢°ä²¼ÁË2020ÄêÉϰëÄêÍøÂ簲ȫµÄ×êÑл㱨 ¡£»ã±¨ÏÔʾ £¬´Ó½ñÄê3ÔÂÆðÍ· £¬ÀûÓø÷ÀàCOVID-19ÎÊÌâµÄ¶ñÒâµç×ÓÓʼþÏÔ×ÅÔö³¤ £¬ÒÔÓÕʹÓû§Â¶³öÓÚ¸÷Ààµç×ÓÓʼþ¹¥»÷ºÍڲƭÖÐ £¬ÆäÖÐÓÐËÄ·ÖÖ®ÈýµÄµç×ÓÓʼþÖи½¼þÖÐÔ̺¬ÐÅÏ¢ÇÔÈ¡Æ÷ ¡£´Ë±í £¬ÔÚ´¹µöÓʼþÖÐ £¬½ðÈÚÒµÊÇ×î³£±»ºýŪµÄÐÐÒµ £¬µç×ÓÓʼþÊÇ´«²¼¶ñÒâÈí¼þ×îÊ¢Ðеķ½Ê½ £¬Õ¼ËùÓÐϰȾý½éµÄÒ»°ëÒÔÉÏ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.f-secure.com/en/press/p/covid-19-spam--phishing-emails--plagued-users-in-first-half-of-2


3.ר¼Ò·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯


3.jpg


×êÑÐÈËÔ±·¢ÏÖ¿ÉÀûÓÃGoogle App EngineÓò½øÐÐÍøÂç´¹µö»î¶¯ £¬²¢²»Ò×±»ÆóÒµ°²È«²úÆ·¼ì²âµ½ ¡£Google App EngineÊÇÒ»¸ö»ùÓÚÔÆµÄ·þÎñƽ̨ £¬ÓÃÓÚÔÚGoogleµÄ·þÎñÆ÷ÉÏ¿ª·¢ºÍÍйÜWebÀûÓà ¡£Google App EngineÔÚÌìÉú×ÓÓòʱÈκÎ×Ö¶ÎÃýÎó¶¼²»»áÏÔʾ404δÕÒµ½Ò³Ãæ £¬¶øÊÇÏÔʾÆäĬÈÏÒ³Ãæ ¡£Òò¶ø £¬ºÚ¿Í¿ÉÀûÓøÃÖ°ÄÜ´´½¨ÎÞÏÞ¸ö¶ñÒâ´¹µöÍøÕ¾ £¬ÕâÒ²Ôö³¤ÁËϵͳÖÎÀíÔ±×èÖ¹¸Ã¶ñÒâ»î¶¯µÄÄѶÈ ¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/google-app-engine-feature-abused-to-create-unlimited-phishing-pages/


4.×êÑÐÈËÔ±Åû¶ʢÐеÄRuby GemÖÐXSS·ì϶ £¬ÉÐδ±»ÔÚÒ°ÀûÓÃ


4.jpg


×êÑÐÈËÔ±Åû¶ÁËAction ViewÖеÄXSS·ì϶ £¬ÆäÊÇÒ»ÖÖÊ¢ÐеÄRuby Gem £¬Äܹ»ÔÚRails WebÀûÓ÷¨Ê½¿ò¼ÜÖд¦ÖÃWebÒªÇó £¬Ä¿Ç°¸Ã·ì϶ÉÐδ±»ÔÚÒ°ÀûÓà ¡£¸Ã·ì϶λÓÚAction ViewÓÃÀ´·­ÒëÓû§ÊäÈëµÄ·­Ò븱ÊÖÖÐ £¬µ±Ò»¸öhtml²»°²È«µÄ×Ö·û´®×÷Ϊȱʡֵ´«µÝ¸øÒ»¸öÃûΪhtml»òÒÔ_html½áβµÄ©Òë¼üʱ £¬Ä¬ÈÏ×Ö·û´®½«±»ÃýÎóµØÏóÕ÷Ϊhtml°²È«ÇÒûÓÐתÒå £¬ÕâÒâζ׏¥»÷ÕßÄܹ»ÊäÈë¼Ù×°³ÉºÏ·¨µÄ¶ñÒâ´úÂë ¡£


Ô­ÎÄÁ´½Ó£º

https://portswigger.net/daily-swig/action-view-xss-bug-discovered-in-popular-ruby-gem


5.ÃÀ¹úNewhallÑ§ÇøÏ°È¾ÀÕË÷Èí¼þµ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø


5.jpg


ÃÀ¹ú¼ÓÀû¸£ÄáÑǵÄNewhallÑ§ÇøÔâµ½ÀÕË÷Èí¼þ¹¥»÷ £¬µ¼ÖÂÆä·þÎñÆ÷¹Ø¹Ø £¬Ó°ÏìÁË10Ëù·ÖÆç´°Ð£µÄËùÓÐÔ¶³Ì½ÌÓý ¡£¸ÃÑ§ÇøµÄÕÆ¹ÜÈ˰µÊ¾ £¬ºÚ¿ÍµÄ¹¥»÷´ÓÖÜÖçÒ¹¼ä³ÖÐøµ½ÖÜÒ»ÔçÉÏ £¬ËûÔÚÊÔͼ½Ó¼ûOutlookºÍµç×ÓÓʼþʱÊÕµ½ÃýÎóÐÅÏ¢¶ø°ÑÎȵ½¸ÃÎÊÌâ ¡£ÓÐȤµÄÊÇ £¬ºÚ¿Í²¢Ã»ÓÐÌá³öڲƭÀÕË÷µÄÐèÒª ¡£


Ô­ÎÄÁ´½Ó£º

https://threatpost.com/california-elementary-kids-online-learning-ransomware/159319/


6.ArbiterSportsϰȾÀÕË÷Èí¼þ £¬54Íò»áÔ±ÐÅÏ¢±»µÁ


6.jpg


ArbiterSports°µÊ¾ £¬ËüÒÑÓÚ½ñÄê7ÔÂÔâµ½ÁËÀÕË÷Èí¼þ¹¥»÷ ¡£ArbiterSportsÊÇÒ»¼ÒΪÌåÓýÁªÈüÌṩÈí¼þÀ´ÖÎÀí²ÃÅкͽÇÖð¹ÙÔ±µÄ¹«Ë¾ £¬Õâ´ÎÊÂÎñÉæ¼°µ½ÆäÔ¼54ÍòÃû×¢²á»áÔ± £¬ÆäÖÐÔ̺¬²ÃÅÓ×¢ÁªÈü¹ÙÔ±ºÍѧÌôú±í ¡£Õâ´Îй¶µÄÊý¾ÝÔ̺¬Óû§µÄÃô¸ÐÐÅÏ¢ £¬ÀýÈçÕÊ»§Óû§Ãû¡¢ÃÜÂë¡¢ÕæÊµÐÕÃû¡¢µØÖ·¡¢µ®ÉúÈÕÆÚ¡¢µç×ÓÓʼþµØÖ·ºÍÉç»á°²È«ºÅÂë ¡£Ä¿Ç° £¬ ¸Ã¹«Ë¾°µÊ¾ÆäÒѾ­Ö§¸¶ÁËÊê½ð £¬²¢È·ÈϺڿÍ×éÖ¯ÒÑɾ³ý±»µÁÊý¾Ý ¡£


Ô­ÎÄÁ´½Ó£º

https://www.zdnet.com/article/details-of-540000-sports-referees-taken-in-failed-ransomware-attack/