Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØÎó²î£»£»£»£»±¾ÌïÒâÍâй¶40GBÊý¾Ý£»£»£»£»DHSÖÒÑÔСÐÍ·É»úCAN×ÜÏßÑÏÖØÎó²î

Ðû²¼Ê±¼ä 2019-08-01
1¡¢±±¿¨ÂÞÀ´ÄÉÖÝÔâBECڲƭ¹¥»÷£¬£¬£¬ £¬£¬Ëðʧ170ÍòÃÀÔª


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


±±¿¨ÂÞÀ´ÄÉÖÝ¿¨°ÍÂ³Ë¹ÏØ£¨Cabarrus County£©ÔâBECÕ©Æ­£¬£¬£¬ £¬£¬Ëðʧ³¬170ÍòÃÀÔª¡£¡£¡£¹¥»÷Õßαװ³É¸ÃÏØÐ¸ßÖеÄÐÞ½¨³Ð°üÉÌ£¬£¬£¬ £¬£¬Í¨¹ýÓʼþ¼û¸æÆäÒøÐÐÕË»§ÒѾ­¸ü¸Ä£¬£¬£¬ £¬£¬¸ÃÏØÒò´ËÏòÕ©Æ­ÕßµÄÕË»§Ö§¸¶ÁË250ÍòÃÀÔª¡£¡£¡£Ö±µ½Èý¸öÐÇÆÚºó³Ð°üÉÌѯÎÊÇ·¿îµÄÎÊÌ⣬£¬£¬ £¬£¬¸ÃÏØ²Å·¢Ã÷Ôâµ½Õ©Æ­£¬£¬£¬ £¬£¬´ËÊ±ÒøÐÐÖ»ÄÜ×·»Ø77ÍòÃÀÔªµÄ×ʽ𡣡£¡£FinCEN×î½üµÄÒ»·Ý±¨¸æÖ¸³ö£¬£¬£¬ £¬£¬BECڲƭ´Ó2016ÄêµÄÿÔÂÆ½¾ù1.1ÒÚÃÀÔªÔöÌíµ½ÁË2018ÄêµÄÿÔÂ3.01ÒÚÃÀÔª¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/north-carolina-county-lost-17-million-in-bec-scam/


2¡¢±¾ÌïÒâÍâй¶40GBÊý¾Ý£¬£¬£¬ £¬£¬°üÀ¨È«Çò30ÍòÔ±¹¤Òþ˽ÐÅÏ¢


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²Ñо¿Ô±Justin Paine·¢Ã÷±¾ÌïµÄÒ»¸öElasticSearchÊý¾Ý¿âûÓÐÃÜÂë±£»£»£»£»¤£¬£¬£¬ £¬£¬µ¼ÖÂ40GBÄÚ²¿ÎĵµÐ¹Â¶¡£¡£¡£¸ÃÊý¾Ý¿â°üÀ¨Ô¼1.34ÒÚ·ÝÎĵµ£¬£¬£¬ £¬£¬²»µ«Ð¹Â¶ÁË30ÍòÔ±¹¤µÄСÎÒ˽¼ÒÐÅÏ¢£¨ÐÕÃû¡¢µç×ÓÓʼþµÈ£©£¬£¬£¬ £¬£¬»¹Ð¹Â¶Á˱¾ÌïÄÚ²¿ÍøÂçµÄÏà¹ØÐÅÏ¢£¬£¬£¬ £¬£¬ÀýÈçÖ÷»úÃû¡¢MACµØµã¡¢ÄÚ²¿IP¡¢²Ù×÷ϵͳ°æ±¾¡¢ÒÑÓ¦ÓõIJ¹¶¡ÒÔ¼°ÖÕ¶ËÇå¾²Èí¼þµÄ״̬µÈ¡£¡£¡£¸ÃÊý¾Ý¿âÔÚ¹«ÍøÉÏ̻¶ÁËÔ¼6ÌìµÄʱ¼ä£¬£¬£¬ £¬£¬ÔÚ½Óµ½±¨¸æºó±¾ÌïÒѾ­¶ÔÊý¾Ý¿â¾ÙÐÐÁ˱£»£»£»£»¤¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/unsecured-database-exposes-security-risks-in-hondas-network/


3¡¢À¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Áè¼Ý1.2ÍòѧÉúÐÅÏ¢±»µÁ


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ó¢¸ñÀ¼Î÷±±²¿µÄÀ¼¿¨Ë¹ÌØ´óѧÔâºÚ¿ÍÈëÇÖ£¬£¬£¬ £¬£¬Ñ§ÉúÒþ˽ÐÅÏ¢±»µÁ¡£¡£¡£ÕâÒ»ÊÂÎñ±¬·¢ÔÚ7ÔÂ19ÈÕ£¬£¬£¬ £¬£¬Ó°ÏìÁË1.2ÍòÖÁ2ÍòѧÉú£¬£¬£¬ £¬£¬Ð¹Â¶µÄÐÅÏ¢°üÀ¨ÐÕÃû¡¢µØµã¡¢µç×ÓÓʼþµØµãºÍµç»°ºÅÂë¡£¡£¡£²¿·ÖѧÉúÊÕµ½ÁËڲƭÐÔµÄÖ§¸¶ÇëÇ󣬣¬£¬ £¬£¬¾Ý±¨µÀÒÑÓÐ6ÃûѧÉúÊÜÆ­¡£¡£¡£¸Ã´óѧÒѾ­×÷·ÏÁËÊÜÓ°ÏìѧÉúÕË»§¶ÔӪҵϵͳµÄ»á¼ûȨÏÞ£¬£¬£¬ £¬£¬²¢½ÓÄɲ½·¥ÔöǿϵͳµÄÇå¾²ÐÔ¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.theregister.co.uk/2019/07/31/lancaster_uni/


4¡¢DHSÖÒÑÔСÐÍ·É»úCAN×ÜÏßÑÏÖØÎó²î£¬£¬£¬ £¬£¬¿Éµ¼Ö·ɻúʧ¿Ø


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÃÀ¹úÁìÍÁÇå¾²²¿Ðû²¼ÁËÒ»·ÝÇå¾²¾¯±¨£¬£¬£¬ £¬£¬ÖÒÑÔСÐÍ·É»ú¿ÉÄÜÊܵ½CAN×ÜÏßÖеÄÑÏÖØÎó²îµÄÓ°Ïì¡£¡£¡£¿£¿£¿£¿ £¿£¿ÉÎïÆÊÎö¼û·É»úµÄ¹¥»÷Õß¿ÉÒÔ½«×°±¸ÅþÁ¬µ½CAN×ÜÏߣ¬£¬£¬ £¬£¬×¢ÈëÐéαÊý¾ÝÔì³Éµç×Ó×°±¸µÄ¶ÁÊý²»×¼È·£¬£¬£¬ £¬£¬×îÖÕ¿ÉÄܵ¼Öº½ÐÐÔ±×öÍÉ»¯ÎóµÄÅжÏÒÔ¼°×¹»úµÈÑÏÖØÐ§¹û¡£¡£¡£¹¥»÷Õß¿ÉÒԸ͝µÄÊý¾Ý°üÀ¨·¢ÄîÍ·Ò£²â¶ÁÊý¡¢Ö¸ÄÏÕëºÍº½ÐÐ×ËÊÆÊý¾Ý¡¢º£°Î¸ß¶È¡¢º½ÐÐËÙÂÊÒÔ¼°AoAÊý¾ÝµÈ¡£¡£¡£ÃÀ¹úCISAÕýÔڱ޲߷ɻúÖÆÔìÉÌÎ§ÈÆCAN×ÜÏßϵͳʵÑé±£»£»£»£»¤£¬£¬£¬ £¬£¬²¢¾¡¿ÉÄÜÑÏ¿áÏÞÖÆÆä¶Ô·É»úµÄ»á¼û¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://thehackernews.com/2019/07/airplane-can-bus-hacking.html


5¡¢Î÷²¿Êý¾ÝSSD¹¤¾ß°ü±£´æÁ½¸öÎó²î£¬£¬£¬ £¬£¬¿Éµ¼ÖÂMitM¹¥»÷


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Ñо¿Ö°Ô±Åû¶Î÷²¿Êý¾ÝÉÁµÏSSD¹¤¾ß°üÖеÄÁ½¸öÎó²î£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÕâÁ½¸öÎó²îʵÑéÖÐÐÄÈ˹¥»÷¡£¡£¡£¸Ã¹¤¾ß°üÓÃÓÚ×ÊÖúÓû§¼à¿ØSSDÐÔÄÜ£¬£¬£¬ £¬£¬²¢Õï¶ÏÎÊÌâºÍÍøÂç¹ÊÕÏÐÅÏ¢¡£¡£¡£TrustwaveÑо¿Ö°Ô±Martin RakhmanovÌåÏÖ£¬£¬£¬ £¬£¬ºÚ¿Í¿ÉÒÔͨ¹ýMitM¹¥»÷À´ÇÔȡϵͳÐÅÏ¢»òͨ¹ý´¥·¢Ó¦ÓóÌÐò¸üÐÂÀ´·Ö·¢¶ñÒâÈí¼þ¡£¡£¡£±¾Ô³õÎ÷ÊýÐû²¼Èí¼þ¸üÐÂÐÞ¸´ÁËÕâÁ½¸öÎó²î¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.bleepingcomputer.com/news/security/trivial-bugs-in-western-digital-ssd-utility-puts-owners-at-risk/


6¡¢Amcrest¼ÒÓÃÉãÏñÍ·ÑÏÖØÎó²î£¬£¬£¬ £¬£¬¿ÉÔÊÐí¹¥»÷ÕßÔ¶³Ì¼àÌýÓû§


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


Çå¾²³§ÉÌTenable·¢Ã÷Amcrest IP2M-841B¼ÒÓÃÉãÏñÍ·±£´æÒ»¸öÑÏÖØÎó²î£¬£¬£¬ £¬£¬¿ÉÔÊÐí¹¥»÷Õßͨ¹ýHTTPÔ¶³Ì¼àÌýÉãÏñÍ·µÄÒôƵÊäÈë¡£¡£¡£¸ÃÎó²î±»±ê¼ÇΪCVE-2019-3948£¬£¬£¬ £¬£¬Ó°ÏìÁËÉãÏñÍ·¹Ì¼þ°æ±¾V2.520.AC00.18.R£¬£¬£¬ £¬£¬²¢ÇÒÎÞÐèÉí·ÝÑéÖ¤¼´¿ÉʹÓᣡ£¡£±ðµÄ£¬£¬£¬ £¬£¬¸Ã²úÆ·Ò²Ò×ÊÜÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¨CVE-2017-7927£©¹¥»÷¡£¡£¡£AmcrestÒѾ­Ðû²¼Ïà¹ØÐÞ¸´²¹¶¡¡£¡£¡£


Ô­ÎÄÁ´½Ó£ºhttps://www.zdnet.com/article/iot-home-security-camera-allows-hackers-to-listen-in-over-http/