ÿÖÜÉý¼¶Í¨¸æ-2021-05-25

Ðû²¼Ê±¼ä 2021-05-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÏµÍ³£¨VENGD£©£¬£¬ £¬£¬£¬£¬ £¬ÊǺ£ÄڵĻùÓÚNGD(NextGenerationDesktop)¼Ü¹¹µÄ×ÀÃæÐéÄ⻯²úÆ·£¬£¬ £¬£¬£¬£¬ £¬ËüÈÚºÏÁËVDI¡¢VOI¡¢IDVÈý´ó¼Ü¹¹ÓÅÊÆ£¬£¬ £¬£¬£¬£¬ £¬ÊµÏÖÁËǰºó¶Ë»ìÏýÅÌË㣬£¬ £¬£¬£¬£¬ £¬ÔÚµ÷ÀíЧÀÍÆ÷ºó¶ËÅÌËã×ÊÔ´µÄͬʱ¸üÄܳä·ÖʹÓÃǰ¶Ë×ÊÔ´¡£¡£ ¡£¡£¡£¡£¸Ãϵͳ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õß¿É½á¹¹ÌØ¶¨ÇëÇó°ügetshell¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_ÖÂÔ¶OA_webmail.doí§ÒâÎļþÏÂÔØÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÖÂÔ¶OAÊDZ±¾©ÖÂÔ¶»¥ÁªÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Ñз¢Ò»¿î°ì¹«ÏµÍ³£¬£¬ £¬£¬£¬£¬ £¬ÖÂÔ¶OA±£´æí§ÒâÎļþÏÂÔØÎó²î£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÏÂÔØí§ÒâÎļþ£¬£¬ £¬£¬£¬£¬ £¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


2.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èív8.0í§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚ¶ÔÄ¿µÄipÖеķ«Èív8.0¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡ÐÐΪ£¬£¬ £¬£¬£¬£¬ £¬ÆäÖпÉÒÔͨ¹ý¶ÁÈ¡privilege.xmlÇÔÈ¡ÃÜÂë¾ÙÐнøÒ»²½µÄ¹¥»÷£»£»£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬£¬ £¬£¬£¬£¬ £¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ£¬ £¬£¬£¬£¬ £¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬£¬ £¬£¬£¬£¬ £¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


3.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ8.0_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓ÷«Èí±¨±í²å¼þ8.0ÖеÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷£»£»£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬£¬ £¬£¬£¬£¬ £¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ£¬ £¬£¬£¬£¬ £¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬£¬ £¬£¬£¬£¬ £¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


4.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ9.0_GetshellÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÒÔ»ñÈ¡·«Èíºǫ́ȨÏÞ£¬£¬ £¬£¬£¬£¬ £¬Í¨¹ýÉÏ´«Ñ¹ËõÎļþ¾ÙÐÐgetshell²Ù×÷£¬£¬ £¬£¬£¬£¬ £¬FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬£¬ £¬£¬£¬£¬ £¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ£¬ £¬£¬£¬£¬ £¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬£¬ £¬£¬£¬£¬ £¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC6.5_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5µÄÎó²î¾ÙÐÐí§ÒâÎļþÉÏ´«£»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬ £¬£¬£¬£¬ £¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_CRM_í§ÒâÎļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡²Ù×÷£»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬ £¬£¬£¬£¬ £¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓѵÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ¡£¡£ ¡£¡£¡£¡£»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬£¬ £¬£¬£¬£¬ £¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÐÞ¸ÄÊÂÎñ


1.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Weblogic_ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-2109][CNNVD-202101-1453]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóʹÓøÃÎó²î£¬£¬ £¬£¬£¬£¬ £¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܽÓÊÜOracleWebLogicServer¡£¡£ ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£ ¡£¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬£¬ £¬£¬£¬£¬ £¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬£¬ £¬£¬£¬£¬ £¬²¢ÔÊÐí¿ØÖÆClassLoader¡£¡£ ¡£¡£¡£¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬£¬ £¬£¬£¬£¬ £¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬£¬ £¬£¬£¬£¬ £¬¿ÉÏòЧÀÍÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬£¬ £¬£¬£¬£¬ £¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷Ö÷»ú¡£¡£ ¡£¡£¡£¡£ÁíÍ⣬£¬ £¬£¬£¬£¬ £¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬£¬ £¬£¬£¬£¬ £¬boundary´óÓÚ½çÏßÖµ£¬£¬ £¬£¬£¬£¬ £¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬£¬ £¬£¬£¬£¬ £¬µ¼ÖÂDDOS¡£¡£ ¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ

1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ