2020-12-29
Ðû²¼Ê±¼ä 2020-12-29ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ColdFusionδÊÚȨÉÏ´«Â©¶´[CVE-2018-15961][CNNVD-201809-485] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ColdFusionδÊÚȨÉÏ´«Â©¶´¿ÉÒÔͨ¹ýÒ»¸ö¼òµ¥µÄHTTPPOSTÇëÇóµ½upload.cfmÎļþ½øÐÐÀûÓã¬upload.cfmÊÇûÓÐÏÞÖƵģ¬Ò²²»ÐèÒªÈκεÄÈÏÖ¤¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | HTTP_TeaLaTex1_0_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃTeaLaTex1_0µÄ©¶´½øÐÐÔ¶³Ì´úÂëÖ´ÐУ»LaTeXÊÇÒ»Öֱ༹¤¾ß£¬Í¨³£ÓÃÓÚ×¼±¸¿ÆѧÎļþ£¬ÌرðÊÇÔÚÊýѧ£¬Í³¼Æ£¬¼ÆËã»ú¿ÆѧºÍ¹¤³ÌÁìÓò¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | HTTP_Moobot_¾Ü¾ø·þÎñ¹¥»÷ |
Äþ¾²ÀàÐÍ£º | ÂþÑÜʽ¾Ü¾ø·þÎñ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÊÔͼ¶ÔÄ¿µÄIPÖ÷»ú½øÐÐMoobot_¾Ü¾ø·þÎñ¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ÐÞ¸Äʼþ
ʼþÃû³Æ | HTTP_ThinkPHP5Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£ThinkPHPÊÇÒ»¸öÁ÷ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£µ±WebÍøÕ¾ÊÇ»ùÓÚThinkPHP¿ò¼Ü¿ª·¢Ê±£¬¿ÉÄÜ´æÔڸ鶴ʱ¡£¹¥»÷Õß·¢Ë;«ÐĽṹµÄPHP´úÂëÔÚÄ¿±êÖ÷»úÉÏÖ´ÐУ¬Æóͼ½øÒ»²½¿ØÖÆ·þÎñÆ÷¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | TCP_DrayTek_Ô¤Éí·ÝÑéÖ¤ÃüÁî×¢È멶´[CVE-2020-8515] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½¹¥»÷ÕßÀûÓÃDrayTekÔ¤Éí·ÝÑéÖ¤´¦µÄÁ½´¦ÃüÁî×¢È멶´½øÐй¥»÷µÄÐÐΪ¡£DrayTekÊÇÒ»¼ÒÔÚÖйúÉú²ú·À»ðǽ£¬VPNÉ豸£¬Â·ÓÉÆ÷£¬WLANÉ豸µÈµÄÖÆÔìÉÌ¡£¸Ã©¶´Ô´ÓÚ/cgi-bin/mainfunction.cgi·¨Ê½Î´ÕýÈ·¹ýÂËkeyPath×ֶκÍrtick×Ö¶ÎÆäÖеÄÌØÊâ×Ö·û£¬¹¥»÷Õß¿ÉÀûÓø鶴²»¾¹ýÉí·ÝÑéÖ¤ÒÔrootȨÏÞÖ´ÐдúÂë¡£¹¥»÷Àֳɣ¬¿ÉÒÔrootȨÏÞÖ´ÐдúÂë¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£wingamesÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£Ö´Ðй¥»÷Õß·¢À´µÄÖÖÖÖÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_MSAServices.Bitter.Rat(ÂûÁ黨)_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½BitterľÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitterľÂí¡£BitterľÂíÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_PC_Access_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¸ÃʼþÔ´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPC_AccessľÂí£¬Ä¾ÂíµÄ¿ØÖÆÕß¿ÉÒÔͨ¹ý¸ÃľÂí¶Ô±»Ö²ÈëľÂíµÄÖ÷»úʵʩÍêÈ«µÄ¿ØÖÆ¡£¸ÃľÂí»á±£Áô¹¥»÷ÕßÔÚÄ¿±êÖ÷»úÉϵĹÜÀíԱȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ʼþÃû³Æ£º | DNS_ºóÃÅ_Win32.KcnaBot_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅKcnaBot¡£KcnaBotÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÀûÓÃDNSÐÒéÓëC&C·þÎñÆ÷ͨÐÅ¡£¿ØÖƱ»Ö²Èë»úÆ÷£¬ÇÔÃÜÃô¸ÐÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20201229 |
ɾ³ýʼþ
1. HTTP_ľÂíºóÃÅ_Marap.Downloader_Á¬½Ó
2. TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©¶´É¨Ãè[MS17-010]_1
3. TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©¶´É¨Ãè[MS17-010]_2