2020-12-01
Ðû²¼Ê±¼ä 2020-12-02ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_powershellÃüÁî×¢Èë¹¥»÷ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PowerShellÊÇ΢ÈíWindows²Ù×÷ϵͳÖÐ×Ô´øµÄÈí¼þ°ü£¬Òò´Ë£¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßÖ÷»úÖÐËæʱʹÓÃÕâ¿î¹¤¾ß¡£ÔÚʵ¼ÊÊӲ쵽µÄ¹¥»÷»î¶¯ÖУ¬PowerShellµÄÖ÷Òª×÷ÓÃÊÇ´ÓÔ¶³ÌλÖÃÏÂÔضñÒâÎļþµ½Êܺ¦ÕßÖ÷»úÖУ¬È»ºóʹÓÃÖîÈçStart-Porcess¡¢Invoke-Item»òÕßInvoke-Expression£¨-IEX£©Ö®ÀàµÄÃüÁîÖ´ÐжñÒâÎļþ£¬PowerShellÒ²¿ÉÒÔ½«Ô¶³ÌÎļþÖ±½ÓÏÂÔص½Êܺ¦ÕßÖ÷»úÄÚ´æÖУ¬È»ºó´ÓÄÚ´æÖÐÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Nagios_XI_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-5791][CNNVD-202010-1115] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Nagios XIÊÇÒ»¸ö½¨Á¢ÔÚNagiosºËÐÄÉϵÄÆóÒµ¼¶¼à²âºÍ±¨¾¯·½°¸µÄ¿ªÔ´×é¼þ¡£¹¦Ð§°üÂÞPHPÍøÕ¾½çÃæ¡¢×ÛºÏÌåÏÖͼ¡¢¿É¶¨ÖƵÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÅäÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§¹ÜÀíµÈ¡£Nagios XI 5.7.3ÖдæÔÚÔ¶³Ì´úÂëÖ´ÐÐÄþ¾²Â©¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´ÒÔ¡°apache¡±Óû§Ö´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_Asruex_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Asruex×é¼þʵÑéÁ¬½Ó·þÎñÆ÷£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAsruexºóÃÅ¡£Ñо¿ÈËÔ±ÔçÔÚ2015Äê¾Í·¢ÏÖÁËAsruexºóÃÅ£¬¶øÇÒÓëDarkHotel¼à¿Ø¶ñÒâÈí¼þÓйØÁª¡£¸Ã¹¥»÷ÍÅ»ïÖÁÉÙ´Ó2015Ä꿪ʼ¾ÍÒѾÕë¶ÔÎïÀí¸ôÀëÍøÂç½øÐÐÕë¶ÔÐԵĹ¥»÷ÁË£¬ÆäÖ÷Òª¹¥»÷Ä¿±êΪ³¯Ïʰ뵺Ïà¹ØµÄÖØÒªÕþÖÎÈËÎï»òÕßÒªº¦²¿ÃÅ£¬Å¼¶ûÒ²»áÕë¶Ô¶«ÄÏÑǵȹú½øÐй¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Webshell_php_COMµ÷Óà |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«Ò»¾ä»°Ä¾ÂíµÄÐÐΪ¡£ ¹¥»÷ÕßʵÑéÏò·þÎñÆ÷ÉÏ´«Ò»¾ä»°Ä¾ÂíÎļþ£¬Èç¹ûÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÁ¬½Ó¹¤¾ß¶Ô·þÎñÆ÷½øÐпØÖÆ¡£ ʵÑéÉÏ´«Webshell£¬»ñÈ¡ÍøÕ¾¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Citrix_XenMobile_ÈÎÒâÎļþ¶Áȡ©¶´[CVE-2020-8209][CNNVD-202008-646] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | XenMobileÊÇCitrix¿ª·¢µÄÆóÒµÒƶ¯ÐÔ¹ÜÀíÈí¼þ¡£¸Ã²úÎïÔÊÐíÆóÒµ¹ÜÀíÔ±¹¤µÄÒƶ¯É豸ºÍÒƶ¯Ó¦Ó÷¨Ê½¡£¸ÃÈí¼þµÄÄ¿µÄÊÇͨ¹ýÔÊÐíÔ±¹¤Äþ¾²µØÔÚÆóÒµÓµÓеĺ͸öÈËÒƶ¯É豸¼°Ó¦Ó÷¨Ê½ÉÏÊÂÇéÀ´Ìá¸ßÉú²úÂÊ¡£Citrix Endpoint Management ´æÔÚÈÎÒâÎļþ¶Áȡ©¶´£¬Ô¶³ÌδÊÚȨ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇ󣬿ÉÒÔÔì³É¶ÁÈ¡ÊÜÓ°ÏìÉ豸ÉÏÈÎÒâÎļþµÄÓ°Ïì¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_D-Link-HNAP-SoapAction-HeaderÃüÁîÖ´ÐЩ¶´[CVE-2015-2051] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | D-LinkDIR-645Wired/WirelessRouterÊÇÓÑѶ(D-Link)¹«Ë¾µÄÒ»¿îÖÇÄÜÎÞÏß·ÓÉÆ÷²úÎʹÓÃ1.04b12¼°Ö®Ç°°æ±¾¹Ì¼þµÄD-LinkDIR-645ÖдæÔÚÄþ¾²Â©¶´£¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶ÔHNAP½Ó¿ÚÖ´ÐÐGetDeviceSettings²Ù×÷£¬ÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_phpunint_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-9841][CNNVD-201706-1127] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PHPUnit ÊÇ PHP ³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ (unit testing) ¿ò¼Ü£¬Í¨³£phpunitʹÓÃcomposer·Ç³£Á÷ÐеÄPHPÒÀÀµ¹ÜÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunitÉú²ú»·¾³ÖÐÈÔÈ»°²×°ÁËËü,Èç¹û¸Ã±àдÆ÷Ä£¿é´æÔÚÓÚWeb¿É·ÃÎÊĿ¼£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_EyouCms_ÈÎÒâÎļþÉÏ´«Â©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | EyouCmsÊÇ»ùÓÚTP5.0¿ò¼ÜΪºËÐÄ¿ª·¢µÄÃâ·Ñ¿ªÔ´µÄÆóÒµÄÚÈݹÜÀíϵͳ¡£EyouCms´æÔÚÎļþÉÏ´«Â©¶´£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñÈ¡ÍøÕ¾·þÎñÆ÷¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÃüÁ´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ÷ÈħӰϷ·¨Ê½(Maccms PHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉƵÄÇ¿´óÊÓƵӰϷϵͳ¡£ÍêÃÀÖ§³ÖÖÚ¶àÊÓƵÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ)£¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸Ã©¶´Ö÷ÒªµÄ·¢ÉúÔÒòÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_MODx_ÈÎÒâÎļþÉÏ´«Â©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÀûÓÃMODxÖ´ÐÐÈÎÒâ´úÂ룬´Ó¶ø»ñÈ¡ÍøÕ¾µÄ¿ØÖÆȨ»òÕßɾ³ýÈÎÒâÎļþ¡£MODx ÊÇÒ»¸ö¿ªÔ´µÄ PHP Ó¦Óÿò¼Ü£¬¿ÉÒÔ×ÊÖúʹÓÃÕß¿ØÖÆ×Ô¼ºµÄÍøÉÏÄÚÈÝ¡£ËüÊÇ¿ª·¢ÈËÔ±ºÍ¸ß¼¶Óû§ÀíÏëµÄ¿ØÖÆϵͳ£¬ÈκÎÈ˶¼¿ÉÒÔʹÓà MODx Ðû²¼¡¢¸üС¢Î¬»¤¶¯Ì¬ÍøÕ¾£¬»ò html ¾²Ì¬Ò³ÃæµÄÍøÕ¾ÄÚÈÝ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ThinkCMFÈÎÒâ´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ThinkCMFÊÇÒ»¿î»ùÓÚThinkPHP+MySQL¿ª·¢µÄ¿ªÔ´ÖÐÎÄÄÚÈݹÜÀí¿ò¼Ü¡£Ô¶³Ì¹¥»÷ÕßÔÚÎÞÐèÈκÎȨÏÞÇé¿öÏ£¬¿ÉÀûÓôË©¶´½á¹¹¶ñÒâµÄurl£¬Ïò·þÎñÆ÷дÈëÈÎÒâÄÚÈݵÄÎļþ£¬µ½´ïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ThinkCMFÈÎÒâÎļþ°üÂÞ©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ThinkCMFÊÇÒ»¿î»ùÓÚThinkPHP+MySQL¿ª·¢µÄ¿ªÔ´ÖÐÎÄÄÚÈݹÜÀí¿ò¼Ü¡£Ô¶³Ì¹¥»÷ÕßÔÚÎÞÐèÈκÎȨÏÞÇé¿öÏ£¬¿ÉÀûÓôË©¶´½á¹¹¶ñÒâµÄurl£¬ÀûÓÃÎļþ°üÂÞ©¶´£¬»ñÈ¡É豸ȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | TCP_Äþ¾²Â©¶´_Docker_Remote_API_δÊÚȨ·ÃÎÊ©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Docker Remote API ÊÇÒ»¸öÈ¡´úÔ¶³ÌÃüÁîÐнçÃ棨rcli£©µÄREST API¡£Docker Remote APIÈçÅäÖò»Í׿ɵ¼ÖÂδÊÚȨ·ÃÎÊ£¬¹¥»÷ÕßÀûÓÃdocker client»òÕßhttpÖ±½ÓÇëÇó¾Í¿ÉÒÔ·ÃÎÊÕâ¸öAPI£¬¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶£¬ºÚ¿ÍÒ²¿ÉÒÔɾ³ýDockerÉϵÄÊý¾Ý¡£¹¥»÷Õ߿ɽøÒ»²½ÀûÓÃDocker×ÔÉíÌØÐÔ£¬Ö±½Ó·ÃÎÊËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢£¬»ò¶ÔÃô¸ÐÎļþ½øÐÐÐ޸ģ¬×îÖÕÍêÈ«¿ØÖÆ·þÎñÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Typecho_install.php·´ÐòÁл¯Â©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | TypechoÊÇÒ»¸ö¼òµ¥£¬ÇáÇɵIJ©¿Í·¨Ê½¡£»ùÓÚPHP£¬Ê¹ÓöàÖÖÊý¾Ý¿â£¨Mysql£¬PostgreSQL£¬SQLite£©´¢´æÊý¾Ý¡£ÔÚGPL Version 2Ðí¿É֤Ͽ¯ÐУ¬ÊÇÒ»¸ö¿ªÔ´µÄ·¨Ê½£¬Ä¿Ç°Ê¹ÓÃSVNÀ´×ö°æ±¾¹ÜÀí¡£TypechoµÄinstall.phpÎļþ´æÔڵķ´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÖ´ÐÐphp´úÂë½ø¶ø»ñÈ¡Ä¿±êȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | TELNET_Äþ¾²Â©¶´_Cisco_Catalyst_½»»»»ú_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-3881][CVE-2017-3881][CNNVD-201703-840][CVE-2017-3881][CNNVD-201703-840] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Cisco IOSºÍCisco IOS XEÈí¼þÖеÄCisco¼¯Èº¹ÜÀíÐÒ飨CMP£©´¦ÖôúÂëÖеÄ©¶´¿ÉÄÜÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖØмÓÔØÊÜÓ°ÏìµÄÉ豸»òÒÔÌáÉýµÄÌØȨԶ³ÌÖ´ÐдúÂë¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | SNMP_Äþ¾²Â©¶´_Cisco_IOS_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-6736][CNNVD-201706-1229] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ˼¿ÆIOSºÍIOS XEÈí¼þµÄ¼òµ¥ÍøÂç¹ÜÀíÐÒé(SNMP)×Óϵͳ°üÂÞ¶à¸ö©¶´£¬ÕâЩ©¶´¿ÉÄÜÔÊÐí¾¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂ룬»òµ¼ÖÂÊÜÓ°ÏìµÄϵͳÖØмÓÔØ¡£¹¥»÷Õß¿ÉÒÔÀûÓÃÕâЩ©¶´£¬Í¨¹ýIPv4»òIPv6ÏòÊÜÓ°ÏìµÄϵͳ·¢Ë;«ÐÄÖÆ×÷µÄSNMP°ü¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_ECShopȫϵÁа汾Զ³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»ú½øÐÐEcshopµÇ¼ҳÃæ×¢Èë¹¥»÷´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_PHP_eval_base64_decodeľÂí |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ BitterľÂí ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£ |
¸üÐÂʱ¼ä£º | 20201117 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Discuz_7.x_faq.php_SQL×¢È멶´ |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»ú½øÐÐDiscuz_7.x_faq.php_grouppermission_SQL×¢Èë¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_Nginx½âÎö©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½ÀûÓÃNginxÎļþÃûºó׺½âÎö´íÎóµÄÉÏ´«ÐÐΪ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_seacms_search.php_ǰ̨getshell©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃseacms search.php ǰ̨getshell©¶´½øÐй¥»÷µÄÐÐΪ¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_ThinkPHP5Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_ZeroShell_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2019-12725] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ZeroshellÊÇÒ»Ì×ÃæÏò·þÎñÆ÷ºÍǶÈëʽϵͳµÄLinux¿¯Ðа档Zeroshell 3.9.0°æ±¾ÖдæÔÚÄþ¾²Â©¶´£¬¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·´¦ÖÃHTTP²ÎÊý¡£ |
¸üÐÂʱ¼ä£º | 20201201 |
ʼþÃû³Æ£º | HTTP_ľÂíºóÃÅ_CobaltStrike.Powershell_´úÂëÏÂÔØÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike Éú³ÉµÄ ºóÃÅpowershellÃüÁî ÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØľÂí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁ˺óÃÅPowershellÃüÁî¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉÀûÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£ |
¸üÐÂʱ¼ä£º | 20201201 |