2021-04-07

Ðû²¼Ê±¼ä 2021-04-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_Dubbo·´ÐòÁл¯Îó²î[CVE-2020-1948][CNNVD-202006-1649]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApache_Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£µ±DubboЧÀͶË̻¶ʱ(ĬÈ϶˿ڣº20880)£¬£¬£¬ £¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍδÂÄÀúÖ¤µÄЧÀÍÃû»òÒªÁìÃûµÄRPCÇëÇ󣬣¬£¬ £¬ £¬£¬Í¬Ê±ÅäºÏ¸½¼Ó¶ñÒâµÄ²ÎÊý¸ºÔØ£»£»£»£»ApacheDubboÊÇÒ»ÖÖ»ùÓÚJavaµÄ¸ßÐÔÄÜRPC¿ò¼Ü¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspx_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬ £¬ £¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬ £¬ £¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬ £¬ £¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬ £¬ £¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬ £¬ £¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬ £¬ £¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬ £¬ £¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬ £¬ £¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬ £¬ £¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬ £¬ £¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-057Ô¶³Ì´úÂëÖ´Ðй¥»÷[CVE-2018-11776]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÔÚ¶Ô·½Struts2µÄXMLÉèÖÃÖеÄnamespaceֵδÉèÖÃÇÒ£¨ActionConfiguration£©ÖÐδÉèÖûòÓÃͨÅä·ûnamespaceʱʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºStruts2.0.4-Struts2.3.34£¬£¬£¬ £¬ £¬£¬Struts2.5.0-Struts2.5.16ʵÑéÀûÓÚStruts2S2-057¾Ü¾øÐ§ÀÍÎó²î¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬ £¬ £¬£¬ÆäÖÐÔ¶³Ì´úÂëÈÆ¹ýÁËFastjson1.2.66¼°ÒÔǰ°æ±¾µÄºÚÃûµ¥£¬£¬£¬ £¬ £¬£¬¹¥»÷ÁËʹÓÃÁËcom.caucho.config.types.ResourceRefÀàµÄÄ¿µÄÖ÷»ú¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-Shiro_Ô¶³Ì´úÂ룬£¬£¬ £¬ £¬£¬Í¨¹ýJNDI×¢È룬£¬£¬ £¬ £¬£¬Ö´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XXL_JOB_δÊÚȨ»á¼ûÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶ÂþÑÜʽʹÃüµ÷ÀíÆ½Ì¨¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂXXL-JOBµÄRestfulAPI½Ó¿Ú»òRPC½Ó¿ÚûÓÐÉèÖÃÈÏÖ¤²½·¥£¬£¬£¬ £¬ £¬£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬ £¬ £¬£¬Ôì³ÉÔ¶³ÌÖ´ÐÐÏÂÁ£¬£¬ £¬ £¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407