Äê¹Ø½«ÖÁ£¡2018£¡

Ðû²¼Ê±¼ä 2019-01-25
Èȵãʼþ·ÖÎöÔ¤¾¯

¡¾Â©¶´Ô¤¾¯¡¿WebLogic CVE-2018-2628·´ÐòÁл¯Â©¶´¸´ÏÖ


¡¾Ô­´´Â©¶´¡¿WebLogic·´ÐòÁл¯Â©¶´CVE-2018-2893Ô¤¾¯


¡¾Ô­´´Â©¶´¡¿Weblogic·´ÐòÁл¯Â©¶´CVE-2018-3245Ô¤¾¯


¶¶È¦Îª¶Ä¶øÉúADLab·¢ÏÖWebLogic´æÔÚÉÏÊö·´ÐòÁл¯Â©¶´ £¬Â©¶´Ó°ÏìWebLogic 10.3.6.0¡¢12.1.3.0¡¢12.2.1.2¡¢12.2.1.3¶à¸ö°æ±¾¡£¹¥»÷Õß¿ÉÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ЭÒé¶Ô´æÔÚ©¶´µÄWebLogic×é¼þ½øÐÐÔ¶³Ì¹¥»÷ £¬²¢¿É»ñȡĿ±êϵͳËùÓÐȨÏÞ¡£


¡¾Â©¶´Ô¤¾¯¡¿ºáºÓµç»úSTARDOM¿ØÖÆÆ÷´æÔÚ¸ßΣ©¶´


¶«·½µçÆø-¶¶È¦Îª¶Ä¶øÉú¹¤¿ØÐÅÏ¢Äþ¾²ÁªºÏʵÑéÊÒ£¨VDLab£©·¢ÏÖ¹¤Òµ×Ô¶¯»¯¿ØÖƺÍÐÅϢϵÍÂäìµ¼ÆóÒµÈÕ±¾ºáºÓµç»úSTARDOM¿ØÖÆÆ÷´æÔÚ¸ßΣ©¶´¡£Â©¶´Ó°ÏìºáºÓµç»úµÄSTARDOM¶à¿î¿ØÖÆÆ÷ £¬²¢¶ÔÓ¦ÓÃÆä¿ØÖÆÆ÷µÄÄÜÔ´¡¢Òªº¦ÖÆÔ졢ʳƷºÍũҵµÈÐÐÒµÔì³ÉÑÏÖØÎ£º¦ £¬Ó°Ï켫Ϊ¹ã·º¡£

¡¾Â©¶´Ô¤¾¯¡¿LinuxÄں˴æÔÚTCPÄþ¾²Â©¶´£¨CVE-2018-5390£©


©¶´¿ÉÔÊÐíÔ¶³Ì¹¥»÷ÕßÎÞÐèÈκÎȨÏÞÔÚÊÜÓ°ÏìµÄLinuxÉè±¹ØÁ¬¼ÖÂÔ¶³Ì¾Ü¾ø·þÎñ¡£ÄÚºË4.9¼°ÒÔÉϵÄLinux°æ±¾¾ùÊÜ©¶´Ó°Ïì £¬ÊÜÓ°ÏìµÄÉ豸°üÂÞ°²×°ÁËÉÏÊöÄں˵ļÆËã»úƽ̨¼°LinuxǶÈëʽÉ豸¡£


¡¾Â©¶´Ô¤¾¯¡¿Apache Struts2Ô¶³Ì´úÂëÖ´ÐЩ¶´£¨S2-057£©


Apache Struts2´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨S2-057£© £¬¿ÉÓ°ÏìApache Struts 2.3 - Struts 2.3.34 £¬Apache Struts 2.5 - Struts 2.5.16°æ±¾¡£

¡¾Â©¶´Ô¤¾¯¡¿Win10 ´æÔÚµ±µØÌáȨ0day©¶´


Windows 10ϵͳÖÐÒ»¸öµ±µØÌáȨ0day©¶´ £¬´æÔÚÓÚWindowsµÄÈÎÎñµ÷ÖηþÎñÖÐ £¬ÔÊÐí¹¥»÷Õß´ÓUSERȨÏÞÌáȨµ½SYSTEMȨÏÞ¡£Â©¶´¿ÉÓ°ÏìWindows 10ºÍWindows Server 2016¡£


¡¾Â©¶´Ô¤¾¯¡¿Adobe ColdFusion ·´ÐòÁл¯Â©¶´


¶¶È¦Îª¶Ä¶øÉúADLab·¢ÏÖAdobe Coldfusion´æÔÚ·´ÐòÁл¯Â©¶´CVE-2018-15958ºÍCVE-2018-15959¡£Â©¶´¿ÉÓ°ÏìColdFusion 11 Update 14¼°Ö®Ç°°æ±¾¡¢2016.0 Update 6¼°Ö®Ç°°æ±¾¡£

ÎïÁªÍø×¨Ìâ·ÖÎö

ÖÇÄÜÃÅËøÍøÂçÄþ¾²·ÖÎö³ÂËß


2017ÄêÖÇÄÜÃÅËø²úÖµÁè¼Ý°ÙÒÚÔª £¬Êг¡¹æÄ£½Ó½ü800Íò°Ñ £¬Ô¤¼Æ2020ÄêÖÇÄÜÃÅËøÊг¡¹æÄ£½«µ½´ï4000Íò°Ñ¡£ ÖÇÄÜÃÅËøµÄÄþ¾²½«»áÖ±½Óµ¼Ö¸öÈ˺ͼÒÍ¥µÄÉúÃü¹¤ÒµÄþ¾² £¬±¾³ÂËßÖØµã¹Ø×¢ÖÇÄÜÃÅËøµÄÍøÂçÄþ¾²ÎÊÌâ¡£


VPNFilter£ºÎ£¼°È«Çò¹¤¿ØÉ豸ºÍ°ì¹«ÍøÂçµÄÎïÁªÍø¸ß¼¶Íþв


VPNFilterÊÇÒ»ÆðÒÔÈëÇÖÎïÁªÍøÎªÔØÌå´ÓÊ¿ÉÄÜÓɹú¼ÒÌᳫµÄÈ«ÇòÐԸ߼¶¶ñÒâÈí¼þ¹¥»÷ £¬ÖÁÉÙÓÐ50Íǫ̀É豸ÔâÊÜѬȾ¡£±¾³ÂËß¶ÔΣ¼°¹¤¿Ø¼°°ì¹«ÍøÂçµÄÎïÁªÍø¼äµýÈí¼þVPNFilter½øÐÐÉîÈë·ÖÎö £¬ÏêÊöC&C±»¶¯»ñÈ¡µÄSYNËíµÀ¼¼Êõ¡£


ºÚȸ¹¥»÷£º½ÒÃØTF½©Ê¬ÎïÁªÍøºÚ¿Í±³ºóµÄºÚ¿Í


¶¶È¦Îª¶Ä¶øÉúADLabÔÚºã¾ÃµÄ½©Ê¬Éú̬Ñо¿·ÖÎöÖз¢ÏÖÒ»¿îÎïÁªÍø½©Ê¬±»¹ã·ºµØÖ²ÈëÁ˺Úȸ £¬Í¨¹ýËÝÔ´·ÖÎöÈ·ÈÏÊÇÒ»ÖÖÖ§³Ö¶àCPUƽ̨µÄDdostf½©Ê¬ÍøÂç¼Ò×å±äÖÖ¡£±¾³ÂËßÖØµã½éÉÜÆäºÚȸ¹¥»÷µÄÔ­ÀíÒÔ¼°¡°¶¾ÉϼӶ¾¡±µÄÏÖÏó¡£


ÐÛÂõ¶à¸öÉãÏñͷ©¶´Ô¤¾¯¼°ÐÞ¸´£¨¸½¹¤¾ß£©


ÐÛÂõ²úÎï´æÔÚ¶à¸öÄþ¾²Â©¶´ £¬¶ñÒâ¹¥»÷Õß¿Éͨ¹ýÄÚÍâÍø½Ø»ñÉãÏñÍ·ÊÓÆµÔ´¡¢°²×°¶ñÒâ´úÂë¡¢Ìᳫ´ó¹æÄ£ÍøÂç¹¥»÷µÈÐÐΪ¡£¶¶È¦Îª¶Ä¶øÉúADLab¾ùÔÚÏà¹ØÐͺŵÄ×îй̼þ°æ±¾ÉϽøÐÐÁËÑéÖ¤¡£ÊÜÓ°ÏìµÄÔÚÍøÉ豸ÊýÁ¿ÔÚ°ÙÍòÒÔÉÏ¡£

ºÚ¿Í¹¥»÷ÓëÍþв·ÖÎö

¶ãÔÚP2PÈä³æÍøÂç±³ºóµÄÓÄÁ飺DridexÈ䳿ÐÂÐͱäÖÖÌ½ÃØ£¨¸½×¨É±¹¤¾ß£©


DridexÒÑÐγɼ¯È䳿¡¢½©Ê¬¡¢ÇÔÃÜľÂí¡¢ÀÕË÷Èí¼þ¡¢P2PÊðÀíÓÚÒ»ÉíµÄ»ìºÏÐÍÈ䳿²¡¶¾¡£ÔÚÇÔÃܹ¦Ð§ÉÏ £¬Ëü²»½ö¿ÉÇÔÈ¡ÖÖÖÖÖ÷Á÷Óʼþ¿Í»§¶ËÒÔ¼°ä¯ÀÀÆ÷Éú´æµÄµÇ¼ƾ֤ £¬»¹»áÊÕ¼¯ÒøÐС¢ÐÅÓÿ¨µÈµÇ¼ºÍÖ§¸¶Æ¾Ö¤ £¬Î£º¦¼«´ó¡£


Ê׿îÀûÓÃFirebaseÔÆÏûϢͨ±¨»úÖÆµÄ¸ß¼¶¼äµýÈí¼þ


¸Ã¼äµýÈí¼þÊÇĿǰAndroidƽ̨ÉÏ×îΪǿ´óµÄ¶ñÒâÓ¦ÓÃÖ®Ò» £¬¿ÉʵÏÖÔ¶³ÌrootÌáÉýµ½×î¸ßȨÏÞ £¬¶øÇÒʵÏÖÁËAndroid²ãµÄÃô¸ÐÐÅÏ¢ÇÔÈ¡ £¬ÉõÖÁʵÏÖÁËLinux²ãÃæµÄ¡°·´µ¯Shell¡±ÒÔµ½´ïÆä¶ÔÄ¿±êÉ豸µÄÍêÈ«¿ØÖÆ¡£±¾ÎÄÖØµãÆÊÎöÑù±¾Android¶ËµÄ¸÷¸ö·þÎñºÍ¿ØÖƵÄÂß¼­²¿ÃÅ¡£


Crysis¼Ò×åÀÕË÷²¡¶¾×îбäÖÖ·ÖÎö


Crysis¼Ò×åбäÖÖ×åÖ÷Ҫͨ¹ýµöÓãÓʼþºÍÀûÓÃRDP±¬ÆÆ½øÐÐÁ÷´« £¬ÆäʹÓüÓÃܵÄshellcode £¬ÔÚshellcodeÖÐÀûÓû»Ìå¼¼Êõ¶Ô·¨Ê½µØÖ·¿Õ¼ä½øÐÐÐÞ¸Ä £¬ÒÔµ½´ï×ÌÈÅɱ¶¾Èí¼þµÄ²éɱºÍ·´¿¹¶þ½øÖÆ·ÖÎöµÄÄ¿µÄ¡£


ÐÂÐÍÀÕË÷²¡¶¾BadCkatαװ³É·¨Ôº´«Æ±½øÐй¥»÷


BadCkatÊÇÒ»¿îÀûÓá°EDA2¡±¿ªÔ´ÀÕË÷ÏîÄ¿¸ïжø³ÉµÄÀÕË÷²¡¶¾ £¬ÔÚÊÀ½ç·¶Î§ÄÚ½øÐй㷺µÄ¹¥»÷»î¶¯¡£¸ÃÀÕË÷²¡¶¾½ö¶ÔÎļþÍ·µÄ²¿ÃÅÊý¾Ý½øÐмÓÃÜ £¬Òò´Ë¼ÓÃÜËٶȼ«¿ì £¬Í¬Ê±µ½´ïÁËÆÆ»µ·¨Ê½Õý³£ÔËÐÐ £¬Îĵµ¼ÓÃܲ»ÄÜ´ò¿ªµÄÄ¿µÄ¡£


Ê׿ÀÕË÷¡¢¼äµý¡¢ÒøÐÐľÂíÓÚÒ»ÌåµÄÐÂÐÍ×ÛºÏÐÍAndroid²¡¶¾Éî¶È·ÖÎö


ÐÂÐͲ¡¶¾ÊµÏÖÁ˼ÓÃÜÀÕË÷¡¢¼üÅ̼Ǽ¡¢Ô¶³Ì·ÃÎÊľÂí¡¢¶ÌÐÅÀ¹½Ø¡¢ºô½Ð×ªÒÆºÍËø¶¨ÆÁÄ»µÈ¹¦Ð§ £¬¿É½Ù³Ö¼¸ºõº­¸ÇÊÀ½ç¸÷´ó½ðÈÚ»ú¹¹µÄÊÖ»úAPP £¬×ÜÊýÓÐ300¶à¸ö £¬Éæ¼°Öйú¡¢ÃÀ¹ú¡¢Ó¢¹ú¡¢ÈÕ±¾¡¢ÖйúÏã¸ÛµÈ40¶à¸ö¹ú¼ÒºÍµØÓò¡£


¾¯Ì裺´óÁ¿ÖªÃûÈí¼þ°²×°°ü±»Ö²Èë¡°°²×°ÓÄÁ顱Íڿ󲡶¾
¶¶È¦Îª¶Ä¶øÉúADLab·¢ÏÖ´óÁ¿ÖªÃûÈí¼þ°²×°·¨Ê½±»Ö²Èë¡°°²×°ÓÄÁ顱Íڿ󲡶¾ £¬¸Ã²¡¶¾±³ºóµÄºÚ¿ÍÊÔͼͨ¹ýÈí¼þ¹²ÏíÂÛ̳µÈÇþµÀÐû²¼À¦°óÓиò¡¶¾µÄÁ÷ÐÐÓ¦ÓÃµÄÆÆ½â°æ±¾ £¬Éæ¼°Ó¦Óù²¼Æ26ÖÖ £¬Á¬Í¬²îÒìµÄ°æ±¾¹²Ðû²¼ÓÐ99¸öÖ®¶à¡£

Äþ¾²Â©¶´·ÖÎö

 CPU¡°ÓÄÁ顱©¶´·ÖÎöÓëÑéÖ¤


CPUµ×²ã©¶´Äþ¾²Ê¼þÒѲ¨¼°È«Çò¼¸ºõËùÓеÄÊÖ»ú¡¢µçÄÔ¡¢ÔƼÆËã²úÎï¡£¡°ÓÄÁ顱©¶´¿ÉÔì³ÉÊܱ £»¤µÄÃÜÂë¡¢Ãô¸ÐÐÅϢй¶¡£±¾ÎÄÖØµã¶Ô¡°ÓÄÁ顱µÄ©¶´Ô­Àí¡¢Â©¶´ÑéÖ¤¡¢Î£º¦¼°·À»¤½øÐнéÉÜ¡£


WPA2¡°KRACK¡±Â©¶´¼ò½éÓëÖØÏÖ


ÎÞÏßÍøÂçЭÒéWPA2´æÔÚ¸ßΣ©¶´ £¬Â©¶´ÔÊÐí¹¥»÷Õß¼àÌýAPºÍ½ÓÈëµãSTAÖ®¼ä´«ÊäµÄWi-FiÊý¾ÝÁ÷Á¿ £¬ÀíÂÛÉÏËùÓÐÖ§³ÖWPA2µÄ¿Í»§¶Ë¶¼½«Êܵ½¡°KRACK¡±¹¥»÷µÄÓ°Ïì¡£¶¶È¦Îª¶Ä¶øÉúADLabͨ¹ý¶ÔÈ«ÁãÃÜԿ©¶´µÄ·ÖÎöÀÖ³ÉÖØÏÖ¡°KRACK¡±¹¥»÷¡£


DrupalÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2018-7600)·ÖÎöÓëÑéÖ¤

                           

Drupal 6.x¡¢7.x¡¢8.x¶à¸ö×Ó°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ©¶´ £¬¹¥»÷ÕßÀûÓôË©¶´¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë £¬²¢¿ØÖÆÊ¹ÓÃDrupalµÄÕ¾µã¡£Â©¶´´æÔÚÓÚÓû§×¢²áÒ³Ãæ £¬ËùÒÔÈκÎÄäÃû¹¥»÷Õß¶¼¿ÉÒÔ´¥·¢ £¬Î£º¦Ë®Æ½½Ï¸ß¡£


WebKitä¯ÀÀÆ÷©¶´ÃæÃæ¹Û


¶¶È¦Îª¶Ä¶øÉúADLab¶ÔWebKitÒýÇæ½øÐЩ¶´ÍÚ¾òºÍ´úÂëÉó¼ÆÊ± £¬·¢ÏÖWebkit´æÔÚ¶à¸öÄþ¾²Â©¶´¡£±¾ÎÄÏêϸ·ÖÎöWebKit¸÷Ä£¿éµÄ©¶´°¸Àý £¬¶Ô WebKitä¯ÀÀÆ÷©¶´Ãæ½øÐÐÈ«ÃæÂÛÊö¡£


AndroidÀ¶ÑÀ×é¼þ©¶´Á¬Á¬¿´ 


AndroidϵͳÖÐ £¬À¶ÑÀ×é¼þ¿ÉÒÔ˵ÊÇÄþ¾²Â©¶´ÖØÔÖÇø¡£±¾ÎÄÖØµã½éÉÜÀ¶ÑÀЭÒéÕ»ÖеÄL2CAPЭÒéºÍSMPЭÒé £¬²¢¶ÔCVE-2018-9359ºÍCVE-2018-9365ÕâÁ½¸ö©¶´°¸Àý½øÐÐÏêϸ·ÖÎö¡£


ThinkPHP5Ô¶³Ì´úÂëÖ´ÐЩ¶´·ÖÎö


©¶´ÊÇÓÉÓÚ·ÓɽâÎöȱÏÝËùµ¼Ö £¬Î£º¦Ë®Æ½·Ç³£¸ß £¬Ä¬ÈÏ»·¾³ÅäÖü´¿Éµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¾­¹ý¶¶È¦Îª¶Ä¶øÉúADLab¶ÔThinkPHPµÄ56¸öС°æ±¾µÄÔ´Âë·ÖÎöºÍÑéÖ¤ £¬È·¶¨¾ßÌåÊÜÓ°ÏìµÄ°æ±¾ÎªThinkPHP 5.0.5-5.0.22¡¢5.1.0-5.1.30¡£


ChakraÒýÇæÖÐJIT±àÒëÓÅ»¯¹ý³ÌÖеÄÊý×éÀàÐÍ»ìÏý©¶´·ÖÎö


ChakraÊÇÒ»¸öÓÉ΢ÈíΪMicrosoft Edgeä¯ÀÀÆ÷¿ª·¢µÄJavaScriptÒýÇæ¡£ËüÔÚÒ»¸ö¶ÀÁ¢µÄCPUºËÐÄÉϼ´Ê±±àÒë½Å±¾ £¬Óëä¯ÀÀÆ÷²¢ÐС£±¾ÎÄÖ÷Òª¶ÔChakraÒýÇæÖÐJIT±àÒëÓÅ»¯¹ý³ÌÖеÄÊý×éÀàÐÍ»ìÏý©¶´½øÐзÖÎö¡£

Çø¿éÁ´×¨Ìâ·ÖÎö

¾¯ÌèÖÇÄܺÏԼ©¶´£ºÇø¿éÁ´Éϵġ°¿ÕÆø¡±±Ò


¶¶È¦Îª¶Ä¶øÉúADLab½üÄêÀ´Á¬Ðø¹Ø×¢Çø¿éÁ´¼¼ÊõÄþ¾²ÎÊÌâ £¬Í¨¹ý¶ÔÒÔÌ«·»Ö÷Á´ÖÇÄܺÏÔ¼½øÐÐÑо¿ £¬·¢ÏÖÁË400¶à¸öCVE©¶´¡£ÀûÓÃÖÇÄܺÏԼ©¶´¹¥»÷Õ߿ɿØÖÆÊг¡ÉϵĻõ±Ò×ÜÁ¿»òÈÎÒâÕË»§µÄ»õ±ÒÁ¿ £¬Ê¹Ô­À´¾ÍÎÞêµÄ»õ±Ò³¹µ×ʧȥÐÅÓà £¬³ÉΪ¡°¿ÕÆø¡±±Ò¡£


Ê׸öÇø¿éÁ´tokenµÄ×Ô¶¯»¯Þ¶Ñòë¹¥»÷·ÖÎö


¶¶È¦Îª¶Ä¶øÉúADLabÁªºÏµç×ӿƼ¼´óѧ³ÂÌü¸±½ÌÊÚ×·×Ùµ½ÒÔÌ«·»tokenÖеÄÊ׸ö×Ô¶¯»¯Þ¶Ñòë¹¥»÷ʼþ¡£tokenÃû³ÆÎªSimoleon (SIM) £¬Óнӽü57ÍòÕË»§³ÖÓиúÏÔ¼µÄtoken¡£¹¥»÷Õßͨ¹ý²¿Êð¹¥»÷ºÏÔ¼»ñµÃÁËÁè¼Ý700ÍòµÄtoken £¬Ò»¾Ù³ÉΪ¸ÃºÏÔ¼tokenµÄµÚËÄ´ó³ÖÓÐÕß¡£


´ÓsolidityÓïÑÔÌØÐÔÉî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏԼ©¶´Ô­ÀíºÍ¹¥»÷ÀûÓÃ


ÖÇÄܺÏÔ¼µÄ¿ª·¢ÓïÑÔ¡¢Éè¼ÆÄ£Ê½¡¢ÔËÐлúÖÆ¶¼Ó봫ͳӦÓÃÓнϴó²îÒì¡£±¾³ÂËßÒÔWCTF2018µÄÒ»µÀÖÇÄܺÏԼ©¶´ÈüÌâΪÀý £¬´ÓsolidityÓïÑÔÌØÐÔ³ö·¢ £¬Éî¶È½â¶ÁÒÔÌ«·»ÖÇÄܺÏԼ©¶´Ô­ÀíºÍ¹¥»÷ÀûÓá£


God.GameÖÇÄܺÏÔ¼¹¥»÷ʼþ·ÖÎö


2018Äê8Ô £¬God.GameÔÚÒÔÌ«·»Çø¿éÁ´Éϲ¿ÊðÆäºÏÔ¼ºóµÚ¶þÌì±ã±»ÍµÈ¡ÁË243¸öÒÔÌ«±Ò £¬¼ÛÖµÁè¼Ý6ÍòÃÀÔª¡£¾­¶¶È¦Îª¶Ä¶øÉúADLabÏêϸ·ÖÎöºÍÖØÏÖ £¬·¢ÏÖ¹¥»÷ÕßÊÇͨ¹ý¶à´Î´¥·¢GodºÏÔ¼µÄ²îÒìÒµÎñÂß¼­×îÖÕÔì³ÉÕûÊýÒç³ö¡£


ÒÔÌ«·»ÖÇÄܺÏÔ¼¶à¸ö¹¥»÷°¸Àý·ÖÎö


ÔÚÖÚ¶àÖÇÄܺÏÔ¼¹¥»÷°¸ÀýÖÐ £¬ÓÐЩ©¶´³ÉÒò»ò¹¥»÷ģʽÉÙÓÐÑо¿Éæ¼° £¬Ò²·ºÆðÁËһЩ±ÈÁ¦Òþ±ÎµÄ¹¥»÷Á´¡£±¾ÎÄÖØµã´ÓʹÓÃOraclize·þÎñµÄÊèºö¡¢ÅÓÊÏ´ú±ÒºÏԼ©¶´¡¢SafeMathʹÓò»Í׵ȳÉÒòÈëÊÖÆÊÎöºÚ¿Í¹¥»÷ÐÐΪ¡£


×ðÁú¶¶È¦ - Ϊdu¶øÉú