2021-04-08

Ðû²¼Ê±¼ä 2021-04-09

ÐÂÔöʼþ


1.png


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Ææ°²ÐÅÖÕ¶ËÄþ¾²¹ÜÀíϵͳ_ÌìÇæ_ǰ̨SQL×¢Èë

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚÀûÓÃÌìÇæǰ̨SQL×¢È멶´¡ £¿ÉÄÜͨ¹ý´Ë©¶´Ð´ÈëwebshellµÈ¶ñÒâÎļþ£¬´Ó¶øgetshell¡£

¸üÐÂʱ¼ä£º

20210408


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚÀûÓ÷ºÎ¢OA8ǰ̨SQLÖ´ÐЩ¶´¡ £¿ÉÄÜͨ¹ý´Ë©¶´²éѯ³öºǫ́ÃÜÂëµÈÃô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20210408


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚÀûÓ÷ºÎ¢OA9ǰ̨ÎÞÏÞÖÆGetshell©¶´¡ £¿ÉÄÜͨ¹ý´Ë©¶´Ö±½ÓÉÏ´«webshellµÈ¶ñÒâÎļþ£¬´Ó¶øgetshell¡£

¸üÐÂʱ¼ä£º

20210408


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃeurekaµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«eureka.client.serviceUrl.defaultZoneÉèÖÃΪ¶ñÒâÍøÕ¾¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØºÜ¶àºÜ¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔ¼ì²ìÓ¦ÓÃÅäÖõÄÏêϸÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20210408


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20210408


ɾ³ýʼþ


1¡¢HTTP_ľÂíºóÃÅ_ASP_webshellÒ»¾ä»°Ä¾ÂíÏÂÔØ