2020-05-05

Ðû²¼Ê±¼ä 2020-05-06

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_Oracle_Coherence_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-2915]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle CoherenceÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2915£© £¬ÊÔͼ´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

©¶´´æÔÚµÄCoherence°æ±¾:

Oracle Coherence 3.7.1.0 £¬

Oracle Coherence 12.1.3.0.0 £¬

Oracle Coherence 12.2.1.3.0 £¬

Oracle Coherence 12.2.1.4.0¡£

Èç¹û±»¹¥»÷»úÆ÷ûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡ £¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£

¸üÐÂʱ¼ä£º

20200505














ʼþÃû³Æ£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-2963]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2963£© £¬ÊÔͼ´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

©¶´´æÔÚµÄweblogic°æ±¾:

WebLogic Server 10.3.6.0.0 £¬

WebLogic Server 12.1.3.0.0 £¬

WebLogic Server 12.2.1.3.0 £¬

WebLogic Server 12.2.1.4.0¡£

Èç¹û±»¹¥»÷»úÆ÷ûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡ £¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£

¸üÐÂʱ¼ä£º

20200505














ʼþÃû³Æ£º

TCP_Oracle_WebLogic_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-2883]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracle WebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨CVE-2020-2883£© £¬ÊÔͼ´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

©¶´´æÔÚµÄweblogic°æ±¾:

WebLogic Server 10.3.6.0.0 £¬

WebLogic Server 12.1.3.0.0 £¬

WebLogic Server 12.2.1.3.0 £¬

WebLogic Server 12.2.1.4.0¡£

Èç¹û±»¹¥»÷»úÆ÷ûÓÐÉý¼¶ÏàÓ¦µÄ²¹¶¡ £¬ÔòÓпÉÄܱ»Ö±½Ó»ñµÃȨÏÞ¡£

¸üÐÂʱ¼ä£º

20200505














ʼþÃû³Æ£º

TCP_WebLogic_XXE_ÈÎÒâÎļþ¶Áȡ©¶´[CVE-2020-2949]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWebLogic XXEÈÎÒâÎļþ¶Áȡ©¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20200505








ʼþÃû³Æ£º

TCP_Ô¶³Ì¿ØÖÆÈí¼þ_ÏòÈÕ¿û_V9_½¨Á¢¿ØÖÆÁ¬½Ó

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½ÄúµÄÍøÂçÖÐÓÐһ̨Ö÷»úÕýÔÚÊÔͼʹÓÃÏòÈÕ¿ûÁ¬½Ó¶Ô¶ËÉ豸¡£

ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÊÇÒ»¿îÃæÏòÆóÒµºÍרҵÈËÔ±µÄÔ¶³ÌPC¹ÜÀíºÍ¿ØÖƵķþÎñÈí¼þ¡£ÄúÔÚÈκοÉÁ¬È뻥ÁªÍøµÄËùÔÚ £¬¶¼¿ÉÒÔÇáËÉ·ÃÎʺͿØÖÆ°²×°ÁËÏòÈÕ¿ûÔ¶³Ì¿ØÖÆ¿Í»§¶ËµÄÔ¶³ÌÖ÷»ú £¬Õû¸ö¹ý³ÌÍêÈ«¿ÉÒÔͨ¹ýä¯ÀÀÆ÷½øÐÐ £¬ÎÞÐèÔÙ°²×°Èí¼þ¡£ÏòÈÕ¿ûÔ¶³Ì¿ØÖÆÓµÓÐÎåÃë¿ìËÙ¶øÓÖÇ¿¾¢µÄÄÚÍø´©Í¸¹¦Á¦ £¬ÈÚºÏÁË΢ÈíRDPÔ¶³Ì×ÀÃæ(3389) £¬Óû§¿ÉÒÔÇáËÉÔÚÏòÈÕ¿ûÔ¶³Ì×ÀÃæЭÒéºÍ΢ÈíRDPЭÒéÖÐ×ÔÓÉÇл» £¬ÏíÊÜ×î¼ÑµÄÔ¶³Ì×ÀÃæÌåÑé¡£

¸üÐÂʱ¼ä£º

20200505













ʼþÃû³Æ£º

ľÂíºóÃÅ

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

¼ì²âµ½LeetHozerÊÔͼÁ¬½ÓC&C·þÎñÆ÷¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçLeetHozer¡£

LeetHozerÊÇÒ»¸ö½©Ê¬ÍøÂç £¬Ö÷ÒªÊǶÔÖ¸¶¨Ä¿±êÌᳫDDoS¹¥»÷¡£Í¨¹ý9530¶Ë¿Ú©¶´ÒÔ¼°Telnet Èõ¿ÚÁîÁ÷´«×ÔÉí¡£

¸üÐÂʱ¼ä£º

20200505











ÐÞ¸Äʼþ


ʼþÃû³Æ£º

TCP_RDPÔ¶³Ì×ÀÃæµÇ¼_»á»°Á¬½Ó

Äþ¾²ÀàÐÍ£º

Äþ¾²Éó¼Æ

ʼþÃèÊö£º

 ÕâÊÇÒ»Ìõ»ù´¡Ê¼þ £¬µ¥¶ÀÉϱ¨ÎÞÒâÒå¡£

¸üÐÂʱ¼ä£º

20200505






ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_china_chopper_aspx¿ØÖÆÃüÁî

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¸Ãʼþ±íÃ÷Ô´IPµØÖ·Ö÷»úÉϵÄÖйú²Ëµ¶¿Í»§¶ËÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»úÉϵÄwebshell·þÎñÆ÷¶Ë·¢³ö¿ØÖÆÃüÁî¡£

webshellÊÇwebÈëÇֵĽű¾¹¥»÷¹¤¾ß¡£¼òµ¥Ëµ £¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ £¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó £¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ·ÅÖÃÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖÐ £¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½Ê½ £¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷ £¬°üÂÞÉÏ´«ÏÂÔØÎļþ¡¢¼ì²ìÊý¾Ý¿â¡¢Ö´ÐÐÈÎÒⷨʽÃüÁîµÈ¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ £¬ÓÉÓÚÓë±»¿ØÖƵķþÎñÆ÷»òÔ¶³ÌÖ÷»ú½»»»µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úͨ±¨µÄ £¬Òò´Ë²»»á±»·À»ðǽÀ¹½Ø¡£¶øÇÒʹÓÃwebshellÒ»°ã²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼǼ £¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Ç¼ £¬¹ÜÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£

¸üÐÂʱ¼ä£º

20200505