中心公告

上一頁 下一頁  至頁底

5月份-微軟發佈05月份安全性公告,建議請儘速更新!

影響平台:

Microsoft Edge and Internet Explorer:
● Microsoft Edge installed on Windows (all editions)
● Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11 installed on Windows (all editions)

Microsoft Office:
● Microsoft Excel 2010 Service Pack 2 (32-bit editions)
● Microsoft Excel 2010 Service Pack 2 (64-bit editions)
● Microsoft Excel 2013 RT Service Pack 1
● Microsoft Excel 2013 Service Pack 1 (32-bit editions)
● Microsoft Excel 2013 Service Pack 1 (64-bit editions)
● Microsoft Excel 2016 (32-bit edition)
● Microsoft Excel 2016 (64-bit edition)
● Microsoft Infopath 2013 Service Pack 1 (32-bit edition)
● Microsoft Infopath 2013 Service Pack 1 (64-bit edition)
● Microsoft Office 2010 Service Pack 2 (32-bit editions)
● Microsoft Office 2010 Service Pack 2 (64-bit editions)
● Microsoft Office 2013 RT Service Pack 1
● Microsoft Office 2013 Service Pack 1 (32-bit editions)
● Microsoft Office 2013 Service Pack 1 (64-bit editions)
● Microsoft Office 2016 (32-bit edition)
● Microsoft Office 2016 (64-bit edition)
● Microsoft Office 2016 Click-to-Run (C2R) for 32-bit editions
● Microsoft Office 2016 Click-to-Run (C2R) for 64-bit editions
● Microsoft Office Compatibility Pack Service Pack 3
● Microsoft Office Web Apps 2010 Service Pack 2
● Microsoft Office Web Apps Server 2013 Service Pack 1
● Microsoft Project Server 2010 Service Pack 2
● Microsoft Project Server 2013 Service Pack 1
● Microsoft SharePoint Enterprise Server 2016
● Microsoft SharePoint Enterprise Server 2013 Service Pack 1
● Microsoft SharePoint Server 2010 Service Pack 2
● Microsoft Word 2010 Service Pack 2 (32-bit editions)
● Microsoft Word 2010 Service Pack 2 (64-bit editions)
● Microsoft Word 2013 RT Service Pack 1
● Microsoft Word 2013 Service Pack 1 (32-bit editions)
● Microsoft Word 2013 Service Pack 1 (64-bit editions)
● Microsoft Word 2016 (32-bit edition)
● Microsoft Word 2016 (64-bit edition)
● Word Automation Services
● Word Automation Services

Microsoft Windows:
● Microsoft .NET Framework (all editions)
● Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 21
● Microsoft Exchange Server 2013 Cumulative Update 19
● Microsoft Exchange Server 2013 Cumulative Update 20
● Microsoft Exchange Server 2013 Service Pack 1
● Microsoft Exchange Server 2016 Cumulative Update 8
● Microsoft Exchange Server 2016 Cumulative Update 9
● Windows 10 for 32-bit Systems
● Windows 10 for x64-based Systems
● Windows 10 Version 1607 for 32-bit Systems
● Windows 10 Version 1607 for x64-based Systems
● Windows 10 Version 1703 for 32-bit Systems
● Windows 10 Version 1703 for x64-based Systems
● Windows 10 Version 1709 for 32-bit Systems
● Windows 10 Version 1709 for x64-based Systems
● Windows 10 Version 1803 for 32-bit Systems
● Windows 10 Version 1803 for x64-based Systems
● Windows 7 for 32-bit Systems Service Pack 1
● Windows 7 for x64-based Systems Service Pack 1
● Windows 8.1 for 32-bit systems
● Windows 8.1 for x64-based systems
● Windows RT 8.1
● Windows Server 2008 for 32-bit Systems Service Pack 2
● Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
● Windows Server 2008 for Itanium-Based Systems Service Pack 2
● Windows Server 2008 for x64-based Systems Service Pack 2
● Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
● Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
● Windows Server 2008 R2 for x64-based Systems Service Pack 1
● Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
● Windows Server 2012
● Windows Server 2012 (Server Core installation)
● Windows Server 2012 R2
● Windows Server 2012 R2 (Server Core installation)
● Windows Server 2016
● Windows Server 2016 (Server Core installation)
● Windows Server, version 1709 (Server Core Installation)
● Windows Server, version 1803 (Server Core Installation)
● Adobe Flash Player
● .NET Core 2.0
● C SDK for Azure IoT
● ChakraCore
● Java SDK for Azure IoT
● Windows Host Compute Service Shim

說明:Microsoft 發佈05月份安全性公告,Microsoft 軟體存在弱點,遠端攻擊者可利用弱點控制受影響的系統。

目前已知多個軟體版本受到影響,HiNet SOC 建議請管理者/使用者儘速更新,以降低受駭風險

詳細資訊請參考微軟官方網站


更多公告

106年度資訊安全研討會

南投區網中心暨國網中心
106年度資訊安全研討會議程

  1. 主辦單位:南投區域網路中心、國家高速網路與計算中心、國立暨南國際大學
  2. 協辦單位:南投縣教育處
  3. 研習目的:藉由實例分享律師的專業經驗,加強師生對於教材使用著作權方面的法律知識及概念;近期勒索病毒案件頻傳,造成許多損失,特意聘請資安方面專家劉得民講師來講解社交工程及勒索病毒的案例及防範方式,加強其師生資安觀念。
  4. 參加對象:公私立國民中小學、公私立高中職校、大專院校師生。
  5. 研習時間:106年11月8日(三)。
  6. 報名期限:即日起至106年11月6日止。
  7. 本研習為響應環保不提供紙本講義及紙杯

議程:
106年11月08日(星期三)


時間

活動項目

地點

09:40-10:00

報到

圖資大樓B1
多功能演講廳

10:00-12:00

議題一:智慧財產權-著作權
主講人:吳梓生律師

12:00-13:30

午餐及休息

13:30-14:30

議題二:網路資訊安全電子郵件社交工程
主講人:劉得民老師

圖資大樓B1
多功能演講廳

14:30-15:00

中場休息-茶點時間

15:00-16:00

議題二:網路資訊安全電子郵件社交工程
主講人:劉得民老師

 

微軟作業系統漏洞預警公告

事故類型:ANA-漏洞預警
影響等級:高
主旨說明:漏洞預警-微軟伺服器訊息區塊(SMB)協定存在數個安全漏洞,允許攻擊者遠端執行任意程式碼,請儘速進行更新
內容說明:轉發行政法人國家資通安全科技中心 資安訊息警訊 NCCST-ANA-201704-0082
微軟伺服器訊息區塊(Server Message Block,SMB)又名網路檔案分享系統,是微軟所開發的應用層網路傳輸協定,主要功能是讓網路上的機器能夠共享檔案、印表機、串列埠及通訊等資源。
2017年4月14日,國際上名為影子掮客(The Shadow Brokers)的駭客團體,公開釋出新一波的網路攻擊工具,當中多款工具(EternalBlue、EternalRomance、 EternalChampion及DoublePulsar等)鎖定用於SMB協定,攻擊者可先透過EternalBlue工具發送特製的惡意封包到未進行安全更新且啟用SMB協定的作業系統中,並透過DoublePulsar工具執行惡意操作指令或下載其他的惡意程式等。導致攻擊者遠端執行任意程式碼。
此訊息僅發送到「區縣市網路中心」,煩請貴單位協助公告或轉發

影響平台:
Windows Vista
Windows 7
Windows 8.1
Windows RT 8.1
Windows 10
Windows Server 2008
Windows Server 2008 R2
Windows Server 2012
Windows Server 2012 R2
Windows Server 2016

建議措施:微軟官方已針對此弱點釋出修復程式,請儘速至微軟官方網頁(https://technet.microsoft.com/zh-tw/library/security/ms17-010.aspx)進行更新。

[參考資料:]
1. http://www.ithome.com.tw/news/113667
2. https://twitter.com/belowzeroday/status/856066791319195648
3. http://thehackernews.com/2017/04/windows-hacking-tools.html

(此通報僅在於告知相關資訊,並非為資安事件),如果您對此通報的內容有疑問或有關於此事件的建議,歡迎與我們連絡。
教育機構資安通報應變小組
網址:https://info.cert.tanet.edu.tw/
專線電話:07-5250211
網路電話:98400000
E-Mail:service@cert.tanet.edu.tw

近日比特幣集體勒索事件頻傳,請各位夥伴提高警覺

近日比特幣集體勒索事件頻傳,駭客利用連線印表機的公開IP和預設密碼,侵入學校網路列印,請各位夥伴提高警覺。

安通報應變小組,建議各校提高戒備,檢視印表機或校園監視器等物聯網設備,設定強健密碼,刪除非必要的帳號和程式,別使用公開IP或應設防火牆等。
如有收到勒索信件的單位,請與我們反映,並敘明以下訊息:
1. 接獲勒索訊息時間
2. 受害設備IP位址
3. 受害設備廠牌
4. 受害設備型號
並提供資訊至yhliu@ncnu.edu.tw及yenlchen@ncnu.edu.tw信箱,以利通報至教育部


個資、資訊安全、智慧財產權宣導及開源軟體教育應用研討會

個資、資訊安全、智慧財產權宣導及開源軟體教育應用研討會

  1. 主辦單位:南投區域網路中心、國家高速網路與計算中心、國立暨南國際大學
  2. 協辦單位:南投縣教育處
  3. 參加對象:本校師生(暨大)、南投縣各公私立國民中小學、各公私立高中職校、大專院校師生。
  4. 研習時間:105年10月21日(五)、105年10月26日(三)
  5. 報名系統:國高中教師請至全國教師進修網報名http://www1.inservice.edu.tw/; 暨大教職員生 http://ccweb1.ncnu.edu.tw/SLLL/
  6. 報名期限:即日起至105年10月20日止。

活動議程

105年10月21日(五)
08:30-09:00 報到
09:00-12:00 議題一:個資法令宣導講座-講師:博創資訊科技股份有限公司 顧問
13:30-15:30 議題二:網路著作權與學術研究著作權(暫定)-保護智慧財產權服務團─麥智德律師
15:40-16:40 議題三:資訊安全及網路基本檢測-講師:計網中心 楊世偉技術員

105年10月26日(三)
08:30-09:00 報到
09:00-12:00 個資法令宣導講座-講師:博創資訊科技股份有限公司 顧問
13:30-16:30 議題二:LibreOffice 辦公室應用-君邑資訊有限公司執行長李燕秋老師


 


上一頁 下一頁  至頁首