2020-12-16

Ðû²¼Ê±¼ä 2020-12-16

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_ZooKeeper_δÊÚȨ·ÃÎÊ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃZooKeeper´æÔÚµÄδÊÚȨ·ÃÎÊ©¶´½øÐй¥»÷µÄÐÐΪ¡£ZooKeeperÊÇÒ»¸öÂþÑÜʽµÄ£¬¿ª·ÅÔ´ÂëµÄÂþÑÜʽӦÓ÷¨Ê½Ð­µ÷·þÎñ£¬ÊÇGoogleµÄChubbyÒ»¸ö¿ªÔ´µÄʵÏÖ£¬ÊÇHadoopºÍHbaseµÄÖØÒª×é¼þ¡£

¸üÐÂʱ¼ä£º

20201215


1.png


ʼþÃû³Æ

TCP_Äþ¾²Â©¶´_InfluxDB_δÊÚȨ·ÃÎÊ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

influxdb ÊÇÒ»¿îÖøÃûµÄʱÐòÊý¾Ý¿â£¬ÆäʹÓà jwt ×÷Ϊ¼øȨ·½Ê½¡£ÔÚÓû§¿ªÆôÁËÈÏÖ¤£¬µ«Î´ÉèÖòÎÊý shared-secret µÄÇé¿öÏ£¬jwt µÄÈÏÖ¤ÃÜԿΪ¿Õ×Ö·û´®£¬´Ëʱ¹¥»÷Õß¿ÉÒÔαÔìÈÎÒâÓû§Éí·ÝÔÚ influxdb ÖÐÖ´ÐÐ SQL Óï¾ä¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

HTTP_ZoHo_ManageEngine_ÈÎÒâÎļþÉÏ´«Â©¶´[CVE-2019-8394][CNNVD-201902-646]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃZoHo_ManageEngine ServiceDesk PlusµÄ©¶´ÉÏ´«ÈÎÒâÎļþ£»ZOHO ManageEngine ServiceDesk Plus£¨SDP£©ÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÒ»Ì×»ùÓÚITIL¼Ü¹¹µÄIT·þÎñ¹ÜÀíÈí¼þ¡£¸ÃÈí¼þ¼¯³ÉÁËʼþ¹ÜÀí¡¢ÎÊÌâ¹ÜÀí¡¢×ʲú¹ÜÀíITÏîÄ¿¹ÜÀí¡¢²É¹ºÓëºÏͬ¹ÜÀíµÈ¹¦Ð§Ä£¿é¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

HTTP_Struts2_S2-061Ô¶³ÌÃüÁîÖ´Ðй¥»÷[CVE-2020-17530]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_FineCMS_ÈÎÒâÎļþдÈëgetshell©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

FineCMS´æÔÚÈÎÒâÎļþÉÏ´«Â©¶´£¬¿ÉÒÔͨ¹ý½á¹¹²ÎÊýÇëÇóÖ´ÐÐphp´úÂ룬»ñÈ¡Ä¿±êȨÏÞ¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

DNS_ÍÚ¿óÈä³æ_WannaMine_ÏÂÔØÐÐΪ

Äþ¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ʼþÃèÊö£º

¼ì²âµ½ÍÚ¿óÈä³æWannaMineÏÂÔØÐÐΪ¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

DNS_ÍÚ¿óÈä³æ_WannaMine_Á¬½ÓDNS·þÎñÆ÷ͨÐÅ

Äþ¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ʼþÃèÊö£º

¼ì²âµ½ÍÚ¿óÈä³æWannaMineÁ¬½ÓDNS·þÎñÆ÷ͨÐÅ¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

DNS_APT_Ë÷Â×Ö®ÑÛ(ProjectSauron)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½APT×éÖ¯Ë÷Â×Ö®ÑÛ(ProjectSauron)¹¥»÷

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

DNS_ľÂí_¿ÉÒÉdnsËíµÀ¹¤¾ß_Á¬½Ó

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

ÒÉËÆ·ºÆðÁËdnsËíµÀ¹¤¾ß·¢³öµÄdnsÇëÇó£¬Ô´IP¿ÉÄܱ»Ö²ÈëÁËÖîÈçdnscatÖ®ÀàµÄdnsËíµÀ¹¤¾ß¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

TCP_Apache_Tomcat_Websocket_DoS¹¥»÷[CVE-2020-13935][CNNVD-202007-571]

Äþ¾²ÀàÐÍ£º

¾Ü¾ø·þÎñ

ʼþÃèÊö£º

ÔÚÔÚÊÜÓ°Ï췶ΧÄÚµÄtomcat°æ±¾ÖÐ, Óõ½ÁËwebsocketʱ£¬WebSocket frameÖеÄ"¸ºÔس¤¶È"(payload length)ûÓб»ÕýÈ·µØÑéÖ¤£¬´Ó¶ø"ÎÞЧµÄ¸ºÔس¤¶È"(Invalid payload lengths)ÄÜ´¥·¢Ò»¸ö"ÎÞÏÞÑ­»·"(infinite loop)£¬¾ßÓÐ"ÎÞЧµÄ¸ºÔس¤¶È"µÄ¶à¸örequestsÄܹ»µ¼Ö¾ܾø·þÎñ.

¸üÐÂʱ¼ä£º

20201215


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PaloAlto_GlobalProtect_SSL_VPN¸ñʽ»¯×Ö·û´®_ÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃPaloAlto GlobalProtect SSL VPN¸ñʽ»¯×Ö·û´®Â©¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

HTTP_ECShopȫϵÁа汾Զ³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»ú½øÐÐEcshopµÇ¼ҳÃæ×¢Èë¹¥»÷´úÂë¡£

¸üÐÂʱ¼ä£º

20201215


ʼþÃû³Æ£º

SMTP_¿ÉÒɲ¡¶¾Óʼþ_VBS

Äþ¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ʼþÃèÊö£º

ʼþÔ´IPËùÔÚµÄÖ÷»úÕýÔÚ·¢ËÍVBS²¡¶¾Óʼþ¡£

¸üÐÂʱ¼ä£º

20201215