ÿÖÜÉý¼¶Í¨¸æ-2022-07-05

Ðû²¼Ê±¼ä 2022-07-05

ÐÂÔöʼþ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_fastjson_1.2.60_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_fastjson_1.2.67_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSONÃûÌ㬣¬£¬fastjson±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705

 

ÊÂÎñÃû³Æ£º

TCP_ľÂí_BeamMiner_ÍÚ¿óÀÖ³É(BEAM)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½¿ó»úÏò¿ó³ØÌá½»ÍÚ¿óЧ¹ûµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBeamMinerÍÚ¿óľÂí¡£¡£¡£¡£¡£¡£BeamMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£BeamÊÇ»ùÓÚMimbleWimbleЭÒ鿪·¢µÄ¼ÓÃÜÇ®±Ò£¬£¬£¬¾ßÓÐÇ¿Òþ˽ÐÔ¡¢Ìæ»»ÐÔºÍÀ©Õ¹ÐÔ¡£¡£¡£¡£¡£¡£BeamËùÓÐÉúÒⶼĬÈÏÊÇ˽ÃܵÄ¡£¡£¡£¡£¡£¡£Ð½ڵã¼ÓÈëÍøÂçÎÞÐèͬ²½Õû¸öÉúÒâÀúÊ·£¬£¬£¬¿ÉÒÔÇëÇóͬ²½Ö»°üÀ¨ÏµÍ³×´Ì¬µÄѹËõÀúÊ·¼Í¼ºÍÇø¿éÍ·£¬£¬£¬´Ó¶øÊµÏÖ¿ìËÙͬ²½¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.WarZoneRat_ÅþÁ¬(ɨÃè)

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£WarZoneRatÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÔ¶¿Ø£¬£¬£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£±¾ÊÂÎñ±¨¾¯²»ÊÇÕæÊµ¹¥»÷£¬£¬£¬½ö½öÒâζ×ÅÔ´IPÖ÷»úÔÚ¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐɨÃè¡£¡£¡£¡£¡£¡£Ô´IPÒ»Ñùƽ³£ÊôÓÚShodanɨÃèÖ÷»ú£¬£¬£¬Ä¿µÄIPÊǿͻ§Ö÷»ú¡£¡£¡£¡£¡£¡£Ô´IPÖ÷»úÄ£ÄâWarZoneRatÑù±¾ÏòÄ¿µÄIPÖ÷»ú·¢ËÍÉÏÏß±¨ÎÄ£¬£¬£¬ÈôÊÇÊÕµ½ÆÚÍûµÄ·µ»ØÊý¾Ý£¬£¬£¬¼´ÒÔΪĿµÄIPÖ÷»úÉÏÔËÐÐ×ÅGh0st¿ØÖƶË£¬£¬£¬ÊÇWarZoneRatµÄC&CЧÀÍ¡£¡£¡£¡£¡£¡£Shodan¾ÍÊÇͨ¹ýÕâÖÖɨÃèÀ´»ñÈ¡¶ñÒâÈí¼þµÄC&CЧÀÍÆ÷£¬£¬£¬³ýShodanÍ⣬£¬£¬ÆäËüһЩÍþвÇ鱨¹«Ë¾µÄIPÖ÷»úÒ²ÔÚ¾ÙÐÐ×ÅÕâÖÖɨÃè¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_WordPress-3DPrint-Lite_í§ÒâÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

WordPress3DPrintLiteVersion1.9.1.4°æ±¾ÖеÄ3dprint-lite-functions.phpÎļþ±£´æÎļþÉÏ´«Îó²î£¬£¬£¬¹¥»÷Õßͨ¹ý½á¹¹ÇëÇó°ü¿ÉÒÔÉÏ´«í§ÒâÎļþ»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Webmin_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-12840][CNNVD-201906-632]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWebmin1.910ºÍ¸üÔç°æ±¾ÖеÄupdate.cgiÔÊÐíÔ¶³Ì¾­ÓÉÉí·ÝÑéÖ¤µÄÓû§Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£WebminÊǹ¦Ð§×îǿʢµÄ»ùÓÚWebµÄUnixϵͳÖÎÀí¹¤¾ß¡£¡£¡£¡£¡£¡£ÖÎÀíԱͨ¹ýä¯ÀÀÆ÷»á¼ûWebminµÄÖÖÖÖÖÎÀí¹¦Ð§²¢Íê³ÉÏìÓ¦µÄÖÎÀíÐж¯¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_Java·´ÐòÁл¯_CommonsCollections11_ʹÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsCollections11µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËCommonsCollections3.1-3.2.1£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_URLClassLoaderÔ¶³Ì¼ÓÔØ¶ñÒâÀà

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃURLClassLoaderµÄJavaÔ¶³Ì¼ÓÔØ¶ñÒâÀà¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavapayload£¬£¬£¬Ô¶³Ì¼ÓÔØ¶ñÒâÀàÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_JNDIÔ¶³Ì¼ÓÔØ¶ñÒâÀà

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJNDIµÄlookupÒªÁìÔ¶³Ì¼ÓÔØ¶ñÒâÀà¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavapayload£¬£¬£¬Ô¶³Ì¼ÓÔØ¶ñÒâÀàÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Shiro_JNDIÔ¶³Ì¼ÓÔØ¶ñÒâÀà

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃShiroJNDIµÄlookupÒªÁìÔ¶³Ì¼ÓÔØ¶ñÒâÀà¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavapayload£¬£¬£¬Ô¶³Ì¼ÓÔØ¶ñÒâÀàÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Íò»§OA_fileUpload.controller_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Íò»§OA±£´æÒ»¸öí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýfileUpload.controller½Ó¿ÚÉÏ´«¶ñÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ͨ´ïOA_update.php_Îļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ͨ´ïOAv11.8ÒÔϵİ汾±£´æÒ»¸öÎļþ°üÀ¨Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃPHPµÄ.user.iniÎļþÀ´°üÀ¨ÆäËû¶ñÒâÎļþÈÆ¹ýͨ´ïOAµÄÎļþÉÏ´«ÏÞÖÆ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14060][CNNVD-202006-997]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄoadd.org.apache.xalan.lib.sql.JNDIConnectionPool¹ýʧµØ´¦Öóͷ£ÁËÓëoaddÏà¹ØµÄÐòÁл¯gadgetsºÍÊäÈëÖ®¼äµÄ½»»¥

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14062][CNNVD-202006-996]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄcom.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool¹ýʧµØ´¦Öóͷ£ÁËÓëoaddÏà¹ØµÄÐòÁл¯gadgetsºÍÊäÈëÖ®¼äµÄ½»»¥

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-14195][CNNVD-202006-1070]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄorg.jsecurity.realm.jndi.JndiRealmFactory¹ýʧµØ´¦Öóͷ£ÁËÓëoaddÏà¹ØµÄÐòÁл¯gadgetsºÍÊäÈëÖ®¼äµÄ½»»¥

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-24750][CNNVD-202009-1066]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FasterXMLjackson-databind2.x,2.9.10.5°æ±¾Ö®Ç°µÄcom.pastdev.httpcomponents.configuration.JndiConfiguration¹ýʧµØ´¦Öóͷ£ÁËÓëoaddÏà¹ØµÄÐòÁл¯gadgetsºÍÊäÈëÖ®¼äµÄ½»»¥

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²ÊÂÎñ_GitLab_Ô¶³ÌÏÂÁîÖ´ÐÐ[CVE-2018-19571][CVE-2018-19585]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

GitLabÊÇÒ»¸öÓÃÓÚ¿ÍÕ»ÖÎÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬£¬£¬ÆäʹÓÃGit×÷Ϊ´úÂëÖÎÀí¹¤¾ß£¬£¬£¬¿Éͨ¹ýWeb½çÃæ»á¼û¹ûÕæ»ò˽ÈËÏîÄ¿¡£¡£¡£¡£¡£¡£ÔÚ11.4.7°æ±¾Ö®Ç°£¬£¬£¬¸ÃÏîÄ¿±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâpayloadÒÔ»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Mitel_MiVoice_Connect_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-29499][CNNVD-202204-4387]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ä¿µÄipΪ¹¥»÷Õßip£¬£¬£¬Í¨¹ýÔ´ip±£´æÊý¾ÝÑéÖ¤²»×¼È·µÄÎó²î£¬£¬£¬¿ÉÒÔͨ¹ývtest.phpµÄget_url²ÎÊý¾ÙÐÐÍâµØÎļþʹÓ㬣¬£¬´Ó¶øÊ¹µÃÔ´ipÏòÄ¿µÄip£¨¹¥»÷Õߣ©·¢ËÍÃô¸ÐÐÅÏ¢£¬£¬£¬»ò·´µ¯shell£¬£¬£¬µ¼Ö½øÒ»²½¹¥»÷¡£¡£¡£¡£¡£¡£MitelMiVoiceConnectÊǼÓÄôóMitelNetworks¹«Ë¾µÄÒ»¿îÓÃÓÚ¼¯ÖÐÖÎÀíMitelNetworksµÄºô½Ð´¦Öóͷ£ºÍЭ×÷¹¤¾ßµÄÈí¼þ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_СÓãÒ×Á¬ÊÓÆµÏµÍ³_LUA¾ç±¾ÉèÖùýʧ_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

СÓãÒ×Á¬ÊÓÆµ¾Û»áϵͳLUA¾ç±¾È¨ÏÞ·ÖÅɲ»µ±,µ¼ÖÂí§ÒâÓû§¿ÉʹÓÃrootȨÏÞÖ´ÐÐÏÂÁ£¬£¬¹¥»÷ÕßʹÓôËÎó²î¿ÉÍêÈ«»ñȡϵͳȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÖÐÔ¶÷è÷ë_iAudit±¤ÀÝ»ú_get_luser_by_sshport.php_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÖÐÔ¶÷è÷ëiAudit±¤ÀÝ»úget_luser_by_sshport.phpÎļþ±£´æÏÂÁîÆ´½Ó£¬£¬£¬¹¥»÷Õßͨ¹ýÎó²î¿É»ñȡЧÀÍÆ÷ȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÌìÈÚÐÅ_TopApp-LB_enable_tool_debug.php_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÌìÈÚÐÅTopSec-LBenable_tool_debug.phpÎļþ±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬Í¨¹ýÏÂÁîÆ´½Ó¹¥»÷Õß¿ÉÒÔÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÉîÐÅ·þÓ¦Óý»¸¶ÖÎÀíϵͳ_sys_user.conf_Õ˺ÅÃÜÂë×ß©

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

ÉîÐÅ·þÓ¦Óý»¸¶ÖÎÀíϵͳÎļþsys_user.conf¿ÉÔÚδÊÚȨµÄÇéÐÎÏÂÖ±½Ó»á¼û£¬£¬£¬µ¼ÖÂÕ˺ÅÃÜÂë×ß©¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÉîÐÅ·þÓ¦Óý»¸¶±¨±íϵͳ_download.php_í§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉîÐÅ·þÓ¦Óý»¸¶±¨±íϵͳdownload.phpÎļþ±£´æí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬¹¥»÷Õßͨ¹ýÎó²î¿ÉÒÔÏÂÔØÐ§ÀÍÆ÷í§ÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÉîÐÅ·þÓ¦Óý»¸¶±¨±íϵͳ_login.php_ÏÂÁî×¢ÈëÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÉîÐÅ·þÓ¦Óý»¸¶±¨±íϵͳ£¨4.5ÒÔϰ汾£©±£´æÒ»¸öÏÂÁî×¢ÈëÎó²î£¬£¬£¬¸ÃÎó²îÔ´ÓÚ¶Ô´«ÈëµÄuserPswºÍuserID¹ýÂ˲»ÑϽ÷µ¼Ö£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÌØÖÆÇëÇóÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÂÌÃËUTS×ÛºÏÍþв̽Õë_ÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

ÂÌÃËUTS×ÛºÏÍþв̽Õëij¸ö½Ó¿Úδ×öÊÚȨµ¼ÖÂδÊÚȨ»á¼û£¬£¬£¬ÆäÖаüÀ¨²¿·ÖÕ˺ÅÃÜÂëÐÅÏ¢£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃÀ´¾ÙÐеÇÂ¼ÈÆ¹ý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

DNS_¿ÉÒÉÐÐΪ_GotoHTTPÔ¶³ÌÅþÁ¬¹¤¾ßʹÓÃ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

GotohttpÊÇÒ»¿îÔ¶³Ì×ÀÃæ¹¤¾ß£¬£¬£¬¿ÉÄÜΪºÚ¿ÍÕýÔÚʹÓᣡ£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Microsoft_Exchange_Server_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-16875][CNNVD-202009-374]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÓÉÓÚ¶Ôcmdlet²ÎÊýµÄÑéÖ¤²»×¼È·£¬£¬£¬MicrosoftExchangeЧÀÍÆ÷Öб£´æÔ¶³ÌÖ´ÐдúÂëÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚϵͳÓû§µÄÉÏÏÂÎÄÖÐÔËÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£Ê¹ÓôËÎó²îÐèÒªÒÑͨ¹ýÉí·ÝÑéÖ¤µÄÓû§¾ßÓÐÊܵ½ÍþвµÄÌØ¶¨Exchange½ÇÉ«¡£¡£¡£¡£¡£¡£´ËÇå¾²¸üÐÂͨ¹ý¸üÕýMicrosoftExchange´¦Öóͷ£cmdlet²ÎÊýµÄ·½·¨À´ÐÞ¸´´ËÎó²î¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CMS-Discuz:X_uc_centerºǫ́´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Discuz!MLϵͳÖУ¬£¬£¬Í¨Êºǫ́ÐÞ¸ÄUcenterÊý¾Ý¿âÅþÁ¬ÐÅÏ¢£¬£¬£¬¿É½«¶ñÒâ´úÂëдÈëconfig/config_ucenter.phpÎļþÖУ¬£¬£¬µ¼Ö´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Jackson_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2019-14540][CNNVD-201909-716]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

JacksonÊÇÄ¿½ñÓõĽÏÁ¿ÆÕ±éµÄ£¬£¬£¬ÓÃÀ´ÐòÁл¯ºÍ·´ÐòÁл¯jsonµÄJava¿ªÔ´¿ò¼Ü¡£¡£¡£¡£¡£¡£ÔÚ2.9.10֮ǰµÄFasterXMLjackson-databindÖÐÓÉÓÚcom.zaxxer.hikari.HikariConfig´¦Öóͷ£Êý¾ÝÎÊÌ⣬£¬£¬±£´æ·´ÐòÁл¯Îó²î

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_CMS_Discuz!X3.4_í§ÒâÎļþɾ³ýÅäºÏinstallÀú³Ìgetshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Discuz!MLϵͳװÖúóδÉϰ¶ºǫ́ʱ£¬£¬£¬¿ÉʹÓÃÎļþɾ³ýÎó²îɾµôinstall.lockÎļþ£¬£¬£¬Èƹý¶Ô×°ÖÃÍê³ÉµÄÅжÏÄܹ»ÔÙ¾ÙÐÐ×°ÖõÄÀú³Ì£¬£¬£¬È»ºó½«¶ñÒâ´úÂëдÈëÉèÖÃÎļþÖдӶøÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Eyoucms_1.4.3_í§ÒâÎļþдÈë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

EyouCmsÊÇ»ùÓÚTP5.0¿ò¼ÜΪ½¹µã¿ª·¢µÄÃâ·Ñ+¿ªÔ´µÄÆóÒµÄÚÈÝÖÎÀíϵͳ£¬£¬£¬×¨×¢ÆóÒµ½¨Õ¾Óû§ÐèÇóÌṩº£Á¿¸÷ÐÐҵģ°å¡£¡£¡£¡£¡£¡£ÔÚ1.4.3°æ±¾ÒÔǰ£¬£¬£¬¸ÃϵͳÖб£´æí§ÒâÎļþдÈëÎó²î£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâpayload¾ÙÐÐÎļþдÈë²Ù×÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Covenant_ÐÄÌø°ü_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐΣ¬£¬£¬²»µ«Ö§³ÖLinux£¬£¬£¬MacOSºÍWindows£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£¡£¡£¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒ룬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÅú×¢£¬£¬£¬CovenantµÄÌìÉúÎïGruntsÕýÔÚʹרÐÄÌø±¨ÎÄÓëC2ЧÀÍÆ÷¼á³ÖÅþÁ¬¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_fastjson_1.2.47_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSONÃûÌ㬣¬£¬fastjsonÔÚ1.2.47ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_fastjson_·´ÐòÁл¯¼ÓÔØBCEL

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSONÃûÌ㬣¬£¬fastjsonÔÚ1.2.24ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò:

¼ì²âµ½GafgytЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øGafgyt£¬£¬£¬Ä¿µÄIPÖ÷»ú±»Ö²ÈëÁËGafgyt¡£¡£¡£¡£¡£¡£DDoS.GafgytÊÇÒ»¸öÀàLinuxƽ̨ϵĽ©Ê¬ÍøÂ磬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_fastjson_1.2.45_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-18349]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

FastjsonÊÇÒ»¸öJava¿â£¬£¬£¬¿ÉÒÔ½«Java¹¤¾ßת»»ÎªJSONÃûÌ㬣¬£¬fastjsonÔÚ1.2.24ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_fastjson_1.2.62_·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬£¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬£¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_ͨ´ïOA_í§ÒâÎļþÉÏ´«/Îļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ͨ´ïOAÊÇÒ»Ìװ칫ϵͳ¡£¡£¡£¡£¡£¡£ÓÉÓÚͨ´ïOAÖб£´æµÄÁ½Ã¶Îó²î(ÎļþÉÏ´«Îó²î£¬£¬£¬Îļþ°üÀ¨Îó²î)£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÕâÁ½Ã¶Îó²îʵÏÖÔ¶³ÌÏÂÁîÖ´ÐС£¡£¡£¡£¡£¡£/ispirit/im/upload.php±£´æÈƹýµÇ¼(í§ÒâÎļþÉÏ´«Îó²î)£¬£¬£¬Á¬Ïµgateway.php´¦±£´æµÄÎļþ°üÀ¨Îó²î£¬£¬£¬×îÖÕµ¼ÖÂgetshell¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson_dnslog̽²â

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃdnslog̽²âÖ÷»úºó¶ËÊÇ·ñÊÇfastjson£»£»£»£»

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_FastjsonÎó²î_±àÂëʹÓÃ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬£¬£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌØµã£¬£¬£¬Ó¦ÓùæÄ£ºÜ¹ã¡£¡£¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£fastjson¿É½ÓÊܲ¢ÆÊÎöhex±àÂëÄÚÈÝ£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉʹÓÃhex±àÂëÈÆ¹ý¼ì²â×°±¸¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705


ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_BlackMoon_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò:

¼ì²âµ½BlackMoonÔ¶¿ØÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷£¬£¬£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçBlackMoon¡£¡£¡£¡£¡£¡£BlackMoonÖ÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÌᳫDDoS¹¥»÷£¬£¬£¬Í¨¹ý¹ØÁªÆÊÎö·¢Ã÷£¬£¬£¬¸ÃBlackMoon½©Ê¬ÍøÂçÈö²¥·½·¨Ö®Ò»ÊǽèÖú¶ÀÀÇ£¨Rovnix£©½©Ê¬ÍøÂç¾ÙÐÐÈö²¥¡£¡£¡£¡£¡£¡£¶ÀÀǽ©Ê¬ÍøÂçͨ¹ý´ø¶¾¼¤»î¹¤¾ß£¨¿ñ·ç¼¤»î¡¢Ð¡Âí¼¤»î¡¢KMSµÈ£©¾ÙÐÐÈö²¥£¬£¬£¬³£±»ÓÃÀ´Íƹ㲡¶¾ºÍÁ÷Ã¥Èí¼þ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220705