ÿÖÜÉý¼¶²¼¸æ-2022-07-12

°ä²¼¹¦·ò 2022-07-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Atlassian-Jira_8.2.3Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2019-11581]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Atlassian-Jira_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-11581]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£AtlassianJiraÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×ȱµã¸ú×ÙÖÎÀíϵͳ¡£¸ÃÏµÍ³ÖØÒªÓÃÓÚ¶Ô¹¤×÷Öи÷ÀàÎÊÌ⡢ȱµã½øÐиú×ÙÖÎÀí¡£AtlassianJiraServerºÍJiraDataCenter´æÔÚ·þÎñ¶ËÄ£°å×¢Èë·ì϶£¬³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚÔËÐÐÊÜÓ°Ïì°æ±¾µÄJiraServer»òJiraDataCenterϵͳÉÏÖ´ÐÐËÁÒâºÅÁĿǰPoCÒѷųö£¬½¨ÒéÊÜÓ°ÏìµÄ¿Í»§¾¡¿ìÉý¼¶»òѡȡһʱ»º½â´ëÊ©¡£µÚÒ»ÖÖÇé¿ö£¬Jira·þÎñ¶ËÒÑÅäÖúÃSMTP·þÎñÆ÷£¬ÇÒ¡°ÁªÏµÖÎÀíÔ±±íµ¥¡±Ö°ÄÜÒÑ¿ªÆô(ĬÈÏÅäÖò»¿ªÆô)£»µÚ¶þÖÖÇé¿ö£¬Jira·þÎñ¶ËÒÑÅäÖúÃSMTP·þÎñÆ÷£¬ÇÒ¹¥»÷ÕßÓµÓÐ"JIRAÖÎÀíÔ±"µÄ½Ó¼ûȨÏÞ¡£ÔÚµÚÒ»ÖÖÇé¿öÏ£¬¡°ÁªÏµÖÎÀíÔ±±íµ¥¡±Ö°ÄÜ¿ªÆôµÄÇé¿öÏ£¬¹¥»÷ÕßÄܹ»Î´¾­ÈκÎÈÏÖ¤£¬Í¨¹ýÏò/secure/ContactAdministrators."font-family:MS Mincho">ÌáÒéÒªÇóÀûÓô˷ì϶¡£ÔÚµÚ¶þÖÖÇé¿öÏ£¬¹¥»÷ÕßÓµÓÐ"JIRAÖÎÀíÔ±"µÄ½Ó¼ûȨÏÞÏ¿Éͨ¹ý/secure/admin/SendBulkMail!default."font-family:MS Mincho">ÀûÓô˷ì϶¡£Ó°Ïì°æ±¾4.4.x5.x.x6.x.x7.0.x7.1.x7.2.x7.3.x7.4.x7.5.x7.6.x<7.6.147.7.x7.8.x7.9.x7.10.x7.11.x7.12.x7.13.x<7.13.58.0.x<8.0.38.1.x<8.1.28.2.x<8.2.3½¨¸´°æ±¾7.6.147.13.58.0.38.1.28.2.3¹¥»÷³É¹¦£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_PowershellEmpire_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½EmpireµÄºóÃÅÄ£¿éÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËEmpireµÄºóÃÅÄ£¿é¡£EmpireÊÇÒ»¿îÀàËÆMetasploitµÄÉøÈë²âÊÔ¿ò¼Ü£¬Ê¹ÓÃPowerShell¾ç±¾×÷Ϊ¹¥»÷ÔØºÉ¡£Äܹ»¼±¾çÔÚºóÆÚ²¿Êð·ì϶ÀûÓÃÄ£¿é£¬ÄÚÖÃÄ£¿éÓмüÅ̼ͼ¡¢Mimikatz¡¢ÈƹýUAC¡¢ÄÚÍøÉ¨ÃèµÈ¡£ÆäÄÚÖÃÁË»ùÓÚPowerShellµÄºóÃÅÄ£¿é£¬Ö°ÄÜÀàËÆÓÚMeterpreter¡£Ô¶³Ì½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20220712

 


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_º£³±ClusterEngineV4.0_sysShell_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÏòÖ÷ÕÅipÉϵĺ£³±ClusterEngineV4.0·¢ËÍÌØÊâµÄÒªÇó´Ó¶ø»ñÈ¡·þÎñÆ÷ȨÏÞ¡£º£³±InspurClusterEngineÊÇÖйúº£³±¹«Ë¾µÄÒ»¸öÀûÓÃÈí¼þ¡£ÌṩÖÎÀí¼¯ÈºÏµÍ³ÖÐÈíÓ²¼þÌá½»µÄ×÷Òµ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_BitCoinMiner_GetBlockTemplateºÍ̸_³¢ÊÔÏνӿó³Ø_»ñÈ¡Çø¿éÄ£°å(BTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏÎ½Ó¿ó³Ø»ñÈ¡Çø¿éÄ£°å¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitCoinMinerľÂí¡£GetblocktemplateºÍ̸ÊÇеķÖɢʽµÄ±ÈÌØ±ÒÍÚ¿óºÍ̸£¬ÓÚ2012ÄêÖÐÑ®ÔÚ±ÈÌØ±ÒÉçÇøÊ¢¿ª×ÔÖ÷Ñз¢£¬ËüÈ¡´úÁËÀϵÄgetworkÍÚ¿óºÍ̸¡£¸ÃÊÂÎñÅú×¢¿ó¹¤ÔÚ³¢ÊÔÏÎ½Ó¿ó³Ø²¢ÒªÇó³õʼģ°å¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍÚ¿ó¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_BitCoinMiner_GetBlockTemplateºÍ̸_ÏÎ½Ó¿ó³Ø³É¹¦_·µ»ØÇø¿éÄ£°å(BTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂíÏÎ½Ó¿ó³Ø³É¹¦µÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitCoinMinerľÂí¡£GetBlockTemplateºÍ̸ÊÇеķÖɢʽµÄ±ÈÌØ±ÒÍÚ¿óºÍ̸£¬ÓÚ2012ÄêÖÐÑ®ÔÚ±ÈÌØ±ÒÉçÇøÊ¢¿ª×ÔÖ÷Ñз¢£¬ËüÈ¡´úÁËÀϵÄgetworkÍÚ¿óºÍ̸¡£¸ÃÊÂÎñÅú×¢¿ó¹¤ÔÚÏÎ½Ó¿ó³Ø³É¹¦²¢·µ»ØÇø¿éÄ£°å¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍÚ¿ó¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring_Cloud_Function_SpEL_±í°×ʽעÈë_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

SpringCloudFunctionÊÇÀ´×ÔPivotalµÄSpringÍŶӵÄÐÂÏîÄ¿£¬ËüÖÂÁ¦ÓÚÍÆ½øº¯Êý×÷ÎªÖØÒªµÄ¿ª·¢µ¥Ôª¡£¸ÃÏîÄ¿ÌṩÁËÒ»¸öͨÓõÄÄ£ÐÍ£¬ÓÃÓÚÔÚ¸÷ÀàÆ½Ì¨Éϲ¿Êð»ùÓÚº¯ÊýµÄÈí¼þ£¬Ô̺¬ÏñAmazonAWSLambdaÕâÑùµÄFaaS£¨º¯Êý¼´·þÎñ£¬functionasaservice£©Æ½Ì¨¡£ÓÉÓÚSpringCloudFunctionδ¶ÔHTTPÒªÇóÍ·²¿Êý¾Ý½øÐÐÓÐЧµÄÑéÖ¤£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ÔÚδÊÚȨµÄÇé¿öÏ£¬»ú¹Ø¶ñÒâÊý¾Ý½øÐÐÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷£¬×îÖÕ»ñÈ¡·þÎñÆ÷×î¸ßȨÏÞ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_BitCoinMiner_GetBlockTemplateºÍ̸_³¢ÊÔÏνӿó³Ø_ÒªÇó¸ü¸ÄÄ£°å(BTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì¿ó³Ø·þÎñÆ÷ÒªÇó¸ü¸ÄΪÐÂÄ£°å¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitCoinMinerľÂí¡£GetblocktemplateºÍ̸ÊÇеķÖɢʽµÄ±ÈÌØ±ÒÍÚ¿óºÍ̸£¬ÓÚ2012ÄêÖÐÑ®ÔÚ±ÈÌØ±ÒÉçÇøÊ¢¿ª×ÔÖ÷Ñз¢£¬ËüÈ¡´úÁËÀϵÄgetworkÍÚ¿óºÍ̸¡£¸ÃÊÂÎñÅú×¢¿ó¹¤ÔÚ³¢ÊÔÏÎ½Ó¿ó³Ø²¢ÒªÇó³õʼģ°å¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍÚ¿ó¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_BitCoinMiner_GetBlockTemplateºÍ̸_ÍÚ¿ó³É¹¦_Ìá½»Çø¿é(BTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½¿ó¹¤ÕÒµ½ÇкÏÒªÇóÄѶȵŤ×÷ʱ£¬Ïò¿ó³Ø·þÎñÆ÷Ìá½»shares¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitCoinMinerľÂí¡£GetblocktemplateºÍ̸ÊÇеķÖɢʽµÄ±ÈÌØ±ÒÍÚ¿óºÍ̸£¬ÓÚ2012ÄêÖÐÑ®ÔÚ±ÈÌØ±ÒÉçÇøÊ¢¿ª×ÔÖ÷Ñз¢£¬ËüÈ¡´úÁËÀϵÄgetworkÍÚ¿óºÍ̸¡£ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´½øÐÐÍÚ¿ó¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Fbot_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½FbotÊÔͼÏνÓC&C·þÎñÆ÷¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçFbot¡£FbotÊǽ©Ê¬ÍøÂçMiraiµÄÒ»¸ö³ÁÒª±äÖÖ£¬Ò»ÏòºÜ»îÔ¾¡£ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±êÌáÒéDDoS¹¥»÷£¬Í¨¹ý¸÷Àà·ì϶´«²¼×ÔÉí¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CortexMiner_³¢ÊÔÏνӿó³Ø(CTXC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCortexMinerÍÚ¿óľÂí¡£CortexMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£CTXC±ÒÓ¢ÎÄÈ«³Æcortex£¬CTXCµÄÖ¸±êÊÇ´òÔìÒ»¸öÕæÕýÈ¥ÖÐÐÄ»¯ÈËΪÖÇÄÜ×ÔÖÎϵͳ£¬ÔÚÇø¿éÁ´ÉÏÌṩ×îÏȽøµÄ»úе½ø½¨Ä£ÐÍ£¬Óû§Äܹ»Ê¹ÓÃcortexÇø¿éÁ´ÉϵÄÖÇÄܺÏÔ¼À´´§¶È¸ÃÄ£ÐÍ¡£cortexµÄÖ¸±êÖ®Ò»»¹Ô̺¬ÊµÏÖÒ»¸ö»úе½ø½¨Æ½Ì¨£¬ÔÊÐíÓû§ÔÚÆ½Ì¨Éϰ䲼¹¤×÷£¬Ìá½»aidapps¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CortexMiner_»ñÈ¡ÍÚ¿ó¹¤×÷(CTXC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂí»ñÈ¡ÍÚ¿ó¹¤×÷µÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCortexMinerÍÚ¿óľÂí¡£CortexMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£CTXC±ÒÓ¢ÎÄÈ«³Æcortex£¬CTXCµÄÖ¸±êÊÇ´òÔìÒ»¸öÕæÕýÈ¥ÖÐÐÄ»¯ÈËΪÖÇÄÜ×ÔÖÎϵͳ£¬ÔÚÇø¿éÁ´ÉÏÌṩ×îÏȽøµÄ»úе½ø½¨Ä£ÐÍ£¬Óû§Äܹ»Ê¹ÓÃcortexÇø¿éÁ´ÉϵÄÖÇÄܺÏÔ¼À´´§¶È¸ÃÄ£ÐÍ¡£cortexµÄÖ¸±êÖ®Ò»»¹Ô̺¬ÊµÏÖÒ»¸ö»úе½ø½¨Æ½Ì¨£¬ÔÊÐíÓû§ÔÚÆ½Ì¨Éϰ䲼¹¤×÷£¬Ìá½»aidapps¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CortexMiner_ÍÚ¿ó³É¹¦(CTXC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂíÍÚ¿ó³É¹¦µÄÐÐΪ£¬¼´¿ó»úÏò¿ó³ØÌá½»ÍÚ¿óÁ˾Ö¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCortexMinerÍÚ¿óľÂí¡£CortexMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£CTXC±ÒÓ¢ÎÄÈ«³Æcortex£¬CTXCµÄÖ¸±êÊÇ´òÔìÒ»¸öÕæÕýÈ¥ÖÐÐÄ»¯ÈËΪÖÇÄÜ×ÔÖÎϵͳ£¬ÔÚÇø¿éÁ´ÉÏÌṩ×îÏȽøµÄ»úе½ø½¨Ä£ÐÍ£¬Óû§Äܹ»Ê¹ÓÃcortexÇø¿éÁ´ÉϵÄÖÇÄܺÏÔ¼À´´§¶È¸ÃÄ£ÐÍ¡£cortexµÄÖ¸±êÖ®Ò»»¹Ô̺¬ÊµÏÖÒ»¸ö»úе½ø½¨Æ½Ì¨£¬ÔÊÐíÓû§ÔÚÆ½Ì¨Éϰ䲼¹¤×÷£¬Ìá½»aidapps¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CortexMiner_ÏÎ½Ó¿ó³Ø³É¹¦(CTXC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½ÍÚ¿óľÂíÏÎ½Ó¿ó³Ø³É¹¦µÄÐÐΪ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCortexMinerÍÚ¿óľÂí¡£CortexMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£CTXC±ÒÓ¢ÎÄÈ«³Æcortex£¬CTXCµÄÖ¸±êÊÇ´òÔìÒ»¸öÕæÕýÈ¥ÖÐÐÄ»¯ÈËΪÖÇÄÜ×ÔÖÎϵͳ£¬ÔÚÇø¿éÁ´ÉÏÌṩ×îÏȽøµÄ»úе½ø½¨Ä£ÐÍ£¬Óû§Äܹ»Ê¹ÓÃcortexÇø¿éÁ´ÉϵÄÖÇÄܺÏÔ¼À´´§¶È¸ÃÄ£ÐÍ¡£cortexµÄÖ¸±êÖ®Ò»»¹Ô̺¬ÊµÏÖÒ»¸ö»úе½ø½¨Æ½Ì¨£¬ÔÊÐíÓû§ÔÚÆ½Ì¨Éϰ䲼¹¤×÷£¬Ìá½»aidapps¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CPUMiner_ÍÚ¿ó½ÚÔìºÅÁîͨѶ_¿ó»úÖ§³ÖMining.set_extranonce²½Öè(BTC/LTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½¿ó»úÏò¿ó³ØÅú×¢Ö§³ÖMining.set_extranonce²½Öè¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CPUMiner_ÍÚ¿ó½ÚÔìºÅÁîͨѶ_¿ó³Ø¸üÐÂExtranonce(BTC/LTC)

°²È«ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÃèÊö:

¼ì²âµ½¿ó³ØÍ¨¹ýmining.set_extranonce²½Öè¸üпó»úµÄExtranonce¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCPUMinerÍÚ¿óľÂí¡£CPUMinerÊÇÒ»¿îÍÚ¿ó¶ñÒⷨʽ£¬ÍÚ¿ó·¨Ê½»áÕ¼ÓÃCPU×ÊÔ´£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Click1_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃClick1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËclick-nodeps:2.3.0£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_jolokia_logback_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÀûÓÃActuatorµÄ/jolokia½Ó¿ÚŲÓÃch.qos.logback.classic.jmx.JMXConfiguratorÀàµÄreloadByURL²½ÖèÉèÖÃ±í²¿ÈÕÖ¾ÅäÖÃurlµØÖ·¡£SpringBootActuatorÊÇÒ»¿îÄܹ»Ô®ÊÖÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,ÆäÄܹ»¼à¿ØºÃ¶àºÃ¶àµÄϵͳÊý¾Ý,ËüÓжÔÀûÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯³É¹¦ÄÜ£¬Äܹ»²é¿´ÀûÓÃÅäÖõľßÌåÐÅÏ¢¡£JolokiaÔÊÐíͨ¹ýHTTP½Ó¼ûËùÓÐÒÑ×¢²áµÄMBean£¬Í¬Ê±Äܹ»Ê¹ÓÃURLÁгöËùÓпÉÓõÄMBeans²Ù×÷¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_Actuator_mysqljdbc_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÀûÓÃActuatorµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«spring.datasource.urlÉèÖÃΪ±í²¿¶ñÒâmysqljdbcurlµØÖ·¡£SpringBootActuatorÊÇÒ»¿îÄܹ»Ô®ÊÖÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,ÆäÄܹ»¼à¿ØºÃ¶àºÃ¶àµÄϵͳÊý¾Ý,ËüÓжÔÀûÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯³É¹¦ÄÜ£¬Äܹ»²é¿´ÀûÓÃÅäÖõľßÌåÐÅÏ¢¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_H3C_IMC_ºÅÁî×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÔÚÀûÓÃH3CµÄ·ì϶½øÐжñÒâºÅÁî×¢Èë¡£H3CIMC£¨IntlligentManagementCenter£©ÖÇÄÜÖÎÀíÖÐÐÄÊÇH3CÍÆ³öµÄÏÂÒ»´úÒµÎñÖ»ÄÜÖÎÀí²úÆ·¡£ËüÈÚºÏÁ˵±Ç°¶à¸ö²úÆ·£¬ÒÔͳһ·ç¸ñÌṩÓëÍøÂçÓйصĸ÷ÀàÖÎÀí¡¢½ÚÔì¡¢¼à¿ØµÈÖ°ÄÜ£»Í¬Ê±ÒÔÊ¢¿ªµÄ×é¼þ»¯µÄ¼Ü¹¹Ô­ÐÍ£¬Ïòƽ̨¼°Æä³ÐÔØÒµÎñÌṩɢ²¼Ê½¡¢·Ö¼¶Ê½½»»¥ÖÎÀí¸öÐÔ£»²¢Î´ÒµÎñÈí¼þµÄÏÂÒ»´ú²úÆ·Ìṩ×î¿¿µÃסµÄ¡¢¿ÉÀ©´ó¡¢¸ß»úÄܵÄÒµÎñƽ̨¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÆäËü¿ÉÒÉÐÐΪ_ScriptEngineManager¼ÓÔØJS´úÂëÐÐΪ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö:

ÔÚJAVAÖУ¬javax.script.ScriptEngineManager¿ÉÓÃÀ´Ö´ÐÐjs´úÂ룬¹¥»÷Õß¿ÉÀûÓôËÀàÖ´ÐжñÒâjs´úÂ룬´Ó¶ø½ÚÔìÖ÷ÕÅIPÉ豸ȨÏÞ

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Boat_ÏνÓ

°²È«ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÃèÊö:

BoatÊÇÒ»¸öÈÚºÏÁË¿ªÔ´½©Ê¬ÍøÂçDDoS¹¥»÷Ô´´úÂëµÄн©Ê¬ÍøÂç¼Ò×壬µ«ºÍC2µÄͨѶºÍ̸¼°½»»¥Âß¼­ÊÇȫУ¬ÆëÈ«·ÖÆçÓÚ֮ǰÖ÷Á÷µÄ½©Ê¬ÍøÂ硣Ŀǰ£¬BoatÓÐx86¡¢x64¡¢arm¡¢mipsƽ̨°æ±¾£¬ÖØÒªÖ°ÄÜÔ̺¬ÐÅÏ¢ÍøÂç¡¢DDoS¹¥»÷¡¢Èõ¿ÚÁîɨÃè¡¢×Ôɾ³ýµÈ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÆäËü¿ÉÒÉÐÐΪ_дÈëjarÎļþ

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö:

ÔÚJAVAÖУ¬java.io.FileOutputStreamÄܹ»ÓÃÀ´ÎļþдÈ룬¹¥»÷Õß¿ÉÀûÓøÃÀàдÈë¶ñÒâjar°ü£¬¹²Í¬ÆäËü·ì϶¼°ÊÖ·¨´Ó¶ø»ñÈ¡Ö÷ÕÅIPÉ豸ȨÏÞ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange_Server_δÊÚȨ½Ó¼û[CVE-2020-0692][CNNVD-202002-555]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

MicrosoftExchangeServerÊǸöÐÂÎÅÓëºÏ×÷ϵͳ¡£MicrosoftExchangeServerÖдæÔÚÌØÈ¨ÌáÉý·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷ÕßÄܹ»»ñµÃÓëExchangeServerµÄÆäËûÈκÎÓû§Ò»ÑùµÄȨÏÞ¡£Õâ¿ÉÄÜÔÊÐí¹¥»÷ÕßÖ´ÐÐÖîÈç½Ó¼ûÆäËûÓû§ÓÊÏäÖ®ÀàµÄ»î¶¯¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÖпÆÍøÍþ_NPFW·À»ðǽ_CommandsPolling.php_Îļþ¶ÁÈ¡

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÖпÆÍøÍþNPFW·À»ðǽ´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶£¬ÓÉÓÚ´úÂë¹ýÂ˲»¼°£¬¿É¶ÁÈ¡·þÎñÆ÷ËÁÒâÎļþ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_D-Link_DIR-645_service.cgi_Ô¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

D-LinkDIR-645¹Ì¼þ°æ±¾Ó×ÓÚµÅ×Ú1.03°æ±¾´æÔÚÒ»¸öÔ¶³ÌºÅÁîÖ´Ðзì϶£¬¸Ã·ì϶ÐγɵÄÔ­ÒòÊÇÓÉÓÚservice.cgiÔÚ´¦ÖÃHTTPÒªÇóÖеÄÊý¾Ý²»µ±£¬ÐγɺÅÁîÆ´½Ó£¬µ¼Ö¿ÉÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÐÅϢй¶_ASUSWRT_RT-AC53»á»°Ð¹Â¶_¹¥»÷³¢ÊÔ[CVE-2017-6549][CNNVD-201703-321]

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÏòCookieÖз¢ËÍcgi_logout£¬À´ÇÔÈ¡ASUSWRT_RT-AC53É豸ÖеÄÈκλµÄÖÎÀí²Ç»°¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_½ðɽV8Öն˰²Õûϵͳ_pdf_maker.php_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

½ðɽV8Öն˰²Õûϵͳpdfmaker.php´æÔÚºÅÁîÖ´Ðзì϶£¬ÓÉÓÚûÓйýÂËΣÏÕ×Ö·û£¬µ¼Ö»ú¹ØÌØÊâ×Ö·û¼´¿É½øÐкÅÁîÆ´½ÓÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_BSPHP_δÊÚȨ½Ó¼û

°²È«ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

BSPHP´æÔÚδÊÚȨ½Ó¼û·ì϶£¬¹¥»÷Õß¿ÉδÊÚȨ½Ó¼ûÓйؽӿÚ£¬»ñÈ¡Óû§ÃûºÍµÇ½ipµÈÃô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Nodejs_Squirrelly×é¼þ_´úÂëÖ´ÐÐ[CVE-2021-32819]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¸Ã·ì϶λÓÚSquirrellyºÍExpressÄ£°åÒýÇæ×é¼þÖУ¬Squirrellyͨ¹ýExpressäÖȾAPI½«´¿Ä£°åÊý¾ÝÓëÒýÇæÅäÖÃÑ¡Ïî»ìºÏ¡£·ì϶ÐγÉÔ­ÒòÔÚÓÚ¹¥»÷ÕßÉèÖÃdefaultFilterµÄ²ÎÊýÖµ¸²¸ÇÔ­ÉúÅäÖÃÊôÐÔµÄÖµ¡£¹¥»÷ÕßÄܹ»ÔÚdefaultFilterÖµÖÐ×¢Èë¶ñÒâÄÚÈÝ£¬´Ó¶øÖ´ÐжñÒâ´úÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÓÓÓÑ·À»ðǽºó¶Üindex.php_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÓÓÓÑ·À»ðǽºó¶ÜÊØ»¤¹¤¾ß´æÔÚºÅÁîÖ´Ðзì϶£¬ÓÉÓÚûÓйýÂËΣÏÕ×Ö·û£¬µ¼ÖÂÔ¶³Ì¹¥»÷ÕßÄܹ»Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Myfaces2_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃMyfaces2µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JBossInterceptors1_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃJBossInterceptors1µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËjavassist:3.12.1.GA,jboss-interceptor-core:2.0.0.Final,cdi-api:1.0-SP1,javax.interceptor-api:3.1,jboss-interceptor-spi:2.0.0.Final,slf4j-api:1.7.21£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Pi-hole_ºÅÁîÖ´ÐÐ[CVE-2020-8816][CNNVD-202003-1972]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Pi-holeÊÇÒ»¸öÓÃÓÚÄÚÈݹýÂ˵ÄDNS·þÎñÆ÷£¬v4.3.2¼°Æä֮ǰµÄ°æ±¾´æÔÚºÅÁîÖ´Ðзì϶£¬ÔÚ¹¥»÷ÕߵǼºóÄܹ»Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_js-yaml_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2013-4660]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

js-yamlÊÇYAML1.2µÄJavaScript½âÎöÆ÷ºÍ´®ÁªÆ÷¡£Node.jsµÄjs-yamlÄ£¿é2.0.5֮ǰ°æ±¾ÔÚ½âÎöÊäÈëʱ£¬Ã»ÓÐ˼¿¼²»°²È«µÄ!!js/functionÆì±ê£¬¿ÉʹԶ³Ì¹¥»÷Õßͨ¹ýÌØÔìµÄ×Ö·û´®´¥·¢eval²Ù×÷£¬Ö´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_PostgreSQL-JDBC-Driver_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-21724]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

PostgreSQL-JDBC-Driver9.4.1208-42.3.2°æ±¾»áÊ·ý»¯jdbcurlÖÐÖ¸¶¨µÄÀ࣬µ±¹¥»÷Õß½ÚÔìjdbcurl»òÊôÐÔʱ¿ÉÄÜÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐ

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_CommonsBeanutils1/2/183NOCC_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsBeanutils1183NOCCµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-beanutils:1.8.3£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁ»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_CommonsBeanutils3/3183_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃCommonsBeanutils3µÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ÇÒʹÓÃÁËcommons-beanutils:1.9.2,commons-collections:3.1£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPClient_Obj_Java·´ÐòÁл¯ÀûÓÃÁ´_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃJRMPClient_ObjµÄJava·´ÐòÁл¯ÀûÓÃÁ´¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬»ñȡϵͳ½ÚÔìȨ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Redis_ºÅÁîÖ´ÐÐ[CNVD-2019-21763]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Redis±»±¬³öRedis4.x/5.x°æ±¾´æÔÚÖ÷´Óͬ²½ºÅÁîÖ´Ðзì϶£¬¹¥»÷Õßͨ¹ý»ú¹ØÌض¨µÄÒªÇóʵÏÖ·ì϶ÀûÓ㬳ɹ¦ÀûÓ÷ì϶¿ÉÔÚÖ¸±ê·þÎñÆ÷ÉÏʵÏÖGetshell¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_MSIL.Raudotek_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½ÏÂÔØÕßľÂíRaudotekÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaudotek¡£RaudotekÊÇ»ùÓÚCSharpµÄÏÂÔØÕßľÂí£¬ÖØÒªÖ°ÄÜÊÇÏÂÔØÆäËü¶ñÒâÈí¼þ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PlaySMS_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-8644][CNNVD-202002-145]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

PlaySmsÊÇÒ»¸ö½Ã½ÝµÄ»ùÓÚWebµÄ¶ÌÐÅÆ½Ì¨£¬1.4.3ǰµÄ°æ±¾´æÔÚÄ£°å×¢Èë·ì϶£¬¹¥»÷Õß¿ÉÄÜÔÚδµÇ¼ʱִÐÐËÁÒâ´úÂë

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Zoho_ManageEngine_ADAudit_Plus_XXE×¢Èë[CVE-2022-28219][CNNVD-202204-2014]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚÏòÖ÷ÕÅipÉϵÄZoho_ManageEngine_ADAudit_Plus½øÐÐXML±í²¿ÊµÌå(XXE)×¢È룬½ø¶øÖ´ÐдúÂë¡£ZohoManageEngineAdauditPlusÊÇÃÀ¹úZohoCorporation¹«Ë¾µÄÓÃÓÚ¼ò»¯É󼯡¢Ö¤Ã÷ºÏ¹æÐԺͼì²âÍþв¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

UDP_ÌáȨ¹¥»÷_Nginx_DNS_Resolver_´úÂëÖ´ÐÐ[CVE-2021-23017]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÔÚͨ¹ýÖ÷ÕÅÖ÷»úÉϵÄNginx_DNS_Resolver·ì϶£¬Î±ÔìÀ´×ÔDNS·þÎñÆ÷µÄUDPÊý¾Ý°ü£¬»ú¹ØDNSÏìÓ¦Ôì³É1-byteÄڴ渲¸Ç£¬´Ó¶øµ¼Ö»ؾø·þÎñ»òËÁÒâ´úÂëÖ´ÐС£NginxÊÇÒ»¸ö¸ß»úÄܵÄHTTPºÍ·´Ïò´úÀíweb·þÎñÆ÷£¬Í¬Ê±Ò²ÌṩÁËIMAP/POP3/SMTP·þÎñ£¬ÓÉÓÚÆäÓµÓкܶàÓźñµÄ¸öÐÔ£¬µ¼ÖÂÔÚÈ«ÇòÁìÓòÄÚ±»¿í·ºÊ¹Óá£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÉèÖÃȱµã_ÉîÕÛ·þ_SSLVPN_changetelnum.csp_ËÁÒâÕË»§°ó¶¨ÊÖ»úºÅÅú¸Ä

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÉîÕÛ·þSSLVPNµÄchangetelnum.csp´æÔÚÂß¼­Ô½È¨·ì϶£¬¹¥»÷ÕߵǼ³É¹¦ºó¿ÉÅú¸ÄËÁÒâÓû§°ó¶¨µÄÊÖ»úºÅÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Citrix_ËÁÒâ´úÂëÖ´ÐÐ[CVE-2020-8194][CNNVD-202007-364]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

CitrixADCºÍCitrixNetScalerGateway´æÔÚÒ»¸ö´úÂë×¢Èë·ì϶¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÀûÓÃËüÀ´´´½¨¶ñÒâÎļþ£¬ÈôÊǸöñÒâÎļþÓÉÖÎÀíÍøÂçÉϵÄÊܺ¦ÕßÖ´ÐУ¬ÔòÄܹ»ÔÊÐí¹¥»÷ÕßÔÚ¸ÃÓû§µÄ¸ßµÍÎÄÖÐÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_5.0.17_items.php_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ZabbixÊÇÒ»¸ö¿ªÔ´Èí¼þ¹¤¾ß£¬ÓÃÓÚ¼à¿ØÍøÂç¡¢·þÎñÆ÷¡¢Ðé¹¹»úºÍÔÆ·þÎñµÈIT»ù´¡ÉèÊ©£¬Æä5.0.17°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ö÷ÕÅIPÉ豸ȨÏÞ¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_GilaCMS_ÎļþÔ̺¬[CVE-2019-16679][CNNVD-201909-1026]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

GilaCMS0.1-1.10.9°æ±¾´æÔÚÎļþÔ̺¬·ì϶£¬¹¥»÷ÕßÔڵǽºóÄܹ»ÀûÓø÷ì϶¶ÁÈ¡ËÁÒâÎļþ»òÔ̺¬ÉÏ´«µÄwebshellÎļþ¡£

¸üй¦·ò£º

20220712

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_PoshC2_ÏνÓC2·þÎñÆ÷_³É¹¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½Óɺڿ͹¤¾ßPoshC2ÌìÉúµÄºóÃÅImplantÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoshC2.Implant¡£PoshC2.ImplantÖ´Ðк󹥻÷Õß¿ÉÀûÓÃPoshC2ÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£PoshC2ÊÇÒ»¸öʹÓÃPython3±àдµÄºóÉøÈë´úÀíC2¿ò¼Ü£¬×ñÑ­Ä£¿é»¯Ìåʽ£¬Óû§Äܹ»Ôö³¤×Ô¼ºµÄÄ£¿é¹¤¾ß£¬´Ó¶ø±£ÕϽýݵĿÉÀ©´óÐÔ¡£PoshC2Õ¼ÓжàÖÖ±àÒë˵»°µÄÓÐÐ§ÔØºÉ£¬È磺Powershell¡¢C#¡¢C++¡¢PythonµÈ£¬Í¬Ê±ÌṩÓйØÔغɵÄÔ´´úÂë¡¢¸÷Àà¿ÉÖ´ÐÐÎļþ¡¢DllºÍԭʼShell´úÂ룬ÕâЩʹPoshC2¿ÉÄÜÀûÓÃÓÚ¿í·ºµÄ²Ù×÷ϵͳÉ豸ÉÏ£¬Ô̺¬Windows¡¢*nixºÍOSX

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_PoshC2_ÏνÓC2·þÎñÆ÷2_³É¹¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½Óɺڿ͹¤¾ßPoshC2ÌìÉúµÄºóÃÅImplantÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoshC2.Implant¡£PoshC2.ImplantÖ´Ðк󹥻÷Õß¿ÉÀûÓÃPoshC2ÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£PoshC2ÊÇÒ»¸öʹÓÃPython3±àдµÄºóÉøÈë´úÀíC2¿ò¼Ü£¬×ñÑ­Ä£¿é»¯Ìåʽ£¬Óû§Äܹ»Ôö³¤×Ô¼ºµÄÄ£¿é¹¤¾ß£¬´Ó¶ø±£ÕϽýݵĿÉÀ©´óÐÔ¡£PoshC2Õ¼ÓжàÖÖ±àÒë˵»°µÄÓÐÐ§ÔØºÉ£¬È磺Powershell¡¢C#¡¢C++¡¢PythonµÈ£¬Í¬Ê±ÌṩÓйØÔغɵÄÔ´´úÂë¡¢¸÷Àà¿ÉÖ´ÐÐÎļþ¡¢DllºÍԭʼShell´úÂ룬ÕâЩʹPoshC2¿ÉÄÜÀûÓÃÓÚ¿í·ºµÄ²Ù×÷ϵͳÉ豸ÉÏ£¬Ô̺¬Windows¡¢*nixºÍOSX

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_PoshC2_ÏνÓC2·þÎñÆ÷3_³É¹¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½Óɺڿ͹¤¾ßPoshC2ÌìÉúµÄºóÃÅImplantÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoshC2.Implant¡£PoshC2.ImplantÖ´Ðк󹥻÷Õß¿ÉÀûÓÃPoshC2ÆëÈ«½ÚÔìÊܺ¦»úе£¬²¢½øÐкáÏòÒÆ¶¯¡£PoshC2ÊÇÒ»¸öʹÓÃPython3±àдµÄºóÉøÈë´úÀíC2¿ò¼Ü£¬×ñÑ­Ä£¿é»¯Ìåʽ£¬Óû§Äܹ»Ôö³¤×Ô¼ºµÄÄ£¿é¹¤¾ß£¬´Ó¶ø±£ÕϽýݵĿÉÀ©´óÐÔ¡£PoshC2Õ¼ÓжàÖÖ±àÒë˵»°µÄÓÐÐ§ÔØºÉ£¬È磺Powershell¡¢C#¡¢C++¡¢PythonµÈ£¬Í¬Ê±ÌṩÓйØÔغɵÄÔ´´úÂë¡¢¸÷Àà¿ÉÖ´ÐÐÎļþ¡¢DllºÍԭʼShell´úÂ룬ÕâЩʹPoshC2¿ÉÄÜÀûÓÃÓÚ¿í·ºµÄ²Ù×÷ϵͳÉ豸ÉÏ£¬Ô̺¬Windows¡¢*nixºÍOSX

¸üй¦·ò£º

20220712

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring-Data-REST-PATCHÒªÇó_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2017-8046][CNNVD-201704-1106]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¸Ã·ì϶Ϊ¹¥»÷Õßͨ¹ýSpringDataRestÖ§³ÖµÄPATCH²½Ö裬»ú¹Ø¶ñÒâµÄJsonÌåʽÊý¾Ý·¢Ë͵½·þÎñ¶Ë£¬µ¼Ö·þÎñ¶ËÔÚ½âÎöÊý¾Ýʱ»áÖ´ÐÐËÁÒâJava´úÂë¡¢½âÎöSpEL±í°×ʽ£¬´Ó¶øÊµÏÖÔ¶³ÌËÁÒâ´úÂëÖ´ÐС£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_XStream_´úÂëÖ´ÐÐ[CVE-2021-21351][CNNVD-202103-1234]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö:

XStreamÊÇÒ»¸öJava¿â£¬ÓÃÓÚ½«¶ÔÏóÐòÁл¯ÎªXML²¢Ôٴηµ»Ø¡£½â×éʱ´¦ÖõÄÁ÷Ô̺¬ÀàÐÍÐÅÏ¢ÒÔ³Áд´½¨ÒÔǰ±àдµÄ¶ÔÏó¡£XStreamÒò¶ø»ùÓÚÕâЩÀàÐÍÐÅÏ¢´´½¨ÐÂÊ·ý¡£¹¥»÷ÕßÄܹ»°Ñ³Ö´¦ÖùýµÄÊäÈëÁ÷²¢´úÌæ»ò×¢Èë¶ÔÏ󣬴ӶøÖ´ÐдÓÔ¶³Ì·þÎñÆ÷¼ÓÔØµÄËÁÒâ´úÂë¡£

¸üй¦·ò£º

20220712


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_PoisonIvy_shellcode_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âÔ´IPÖ÷»ú±ÉÈËÔØPoisonIvyµÄshellcodeÔØºÉ¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPoisonIvy¡£PoisonIvyÊÇÒ»¸ö¼«¶ÈÊ¢ÐеÄÔ¶³Ì½ÚÔ칤¾ß£¬ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£PoisonIvyÄܹ»ÌìÉúshellcodeÔØºÉ£¬¼´°ÑËùÓжñÒâ´úÂë·ÅÔÚshellcodeÀï¡£

¸üй¦·ò£º

20220712