ÿÖÜÉý¼¶Í¨¸æ-2021-05-04
Ðû²¼Ê±¼ä 2021-05-06ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Seowon-SlC-130-Router_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-17456] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Ö÷»úÕýÔÚÔâÊÜSeowon-SlC-130-Router_Ô¶³Ì´úÂëÖ´Ðй¥»÷©¶´±àºÅ:CVE-2020-17456Ó°ÏìÉ豸:SlC-130¡¢SLR-120S©¶´Î£º¦Ë®Æ½:¿ÉÒÔ»ñÈ¡µ½É豸µÄshell£¬¶øÇÒÊÇÒÔrootȨÏÞ¡£Â©¶´·¢ÉúµÄλÖÃ:·¢ÉúµÄλÖÃÔÚ²âÊÔÍøÂçÁªÍ¨µÄµØ·½£¬Ò²¾ÍÊÇpingµÄµØÖ·£¬Õâ¸öµØ·½¿ÉÒÔ±»Èƹý¾¹ýÒÔÇ°¶Ô·ÓÉÆ÷©¶´µÄÑо¿£¬²»ÉٵķÓÉÆ÷©¶´·¢Éúµã¶¼ÔÚÕâ¸ö²¿ÃÅ¡£¿ª·¢ÈËÔ±¶ÔÊäÈëµÄ²ÎÊýûÓнøÐÐÓÐЧµÄÑéÖ¤ºÍ·Ç·¨×Ö·û¹ýÂË¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_F5-BIG-IP_/mgmt/tm/access/bundle-install-tasks´¦_Ô¶³Ì´úÂ멶´[CVE-2021-22986][CNNVD-202103-770] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | µ±Ç°Ö÷»úÕýÔÚÔâÊÜF5-BIG-IP_Ô¶³Ì´úÂ멶´¹¥»÷¡£BIG-IP´æÔÚ´úÂëÖ´ÐЩ¶´£¬¸Ã©¶´ÔÊÐí½ç˵Éí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ýBIG-IP¹ÜÀí½çÃæºÍ×ÔÉíIPµØÖ·¶ÔiControlREST½Ó¿Ú½øÐÐÍøÂç·ÃÎÊ£¬ÒÔÖ´ÐÐÈÎÒâϵͳÃüÁ´´½¨»òɾ³ýÎļþÒÔ¼°Ìæ»»·þÎñ¡£¸Ã©¶´Ö»ÄÜͨ¹ý¿ØÖƽçÃæÀûÓ㬶ø²»ÄÜͨ¹ýÊý¾Ý½çÃæÀûÓᣠ|
¸üÐÂʱ¼ä£º | 20210504 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_IIS½âÎö©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½ÀûÓÃIISÎļþÃûºó׺½âÎö´íÎóµÄÉÏ´«ÐÐΪµ±ÊÔͼʵÑé»òÀûÓÃWEBÓ¦Óûò·þÎñÆ÷ƽ̨µÄMIME¼ì²â©¶´Ê±Ê¼þ±»´¥·¢,¹¥»÷Õß¿ÉÒÔʵÑéͨ¹ýÉÏ´«ÖÖÖÖ¶ñÒâÎļþÀ´¹¥»÷Ä¿±êÖ÷»ú¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Nginx½âÎö©¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½ÀûÓÃNginxÎļþÃûºó׺½âÎö´íÎóµÄÉÏ´«ÐÐΪ¡£nginxÊǶíÂÞ˹Èí¼þ¿ª·¢ÕßIgorSysoevËùÑз¢µÄÒ»¿îHTTPºÍ·´ÏòÊðÀí·þÎñÆ÷£¬Ò²¿ÉÒÔ×÷ΪÓʼþÊðÀí·þÎñÆ÷¡£¸Ã©¶´Ô´ÓÚ·¨Ê½Ã»ÓÐÕýÈ·ÑéÖ¤°üÂÞδתÒå¿Õ¸ñ×Ö·ûµÄÇëÇóURI¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø鶴Èƹý¼È¶¨µÄÏÞÖÆ¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Adobe_ColdFusion·´ÐòÁл¯Â©¶´[CVE-2018-15958/15959][CNNVD-201809-488] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýAdobeColdFusion©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£AdobeColdFusionµÄFlashGateway·þÎñ´æÔÚ·´ÐòÁл¯Â©¶´£¬Î´¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÏòÄ¿±êAdobeColdFusionµÄFlashGateway·þÎñ·¢Ë;«ÐĽṹµÄ¶ñÒâÊý¾Ý£¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂ롣©¶´´æÔڵİ汾£ºAdobeColdFusion2016.0Update6AdobeColdFusion2016.0Update5AdobeColdFusion2016.0Update4AdobeColdFusion2016.0Update3AdobeColdFusion2016.0Update2AdobeColdFusion2016.0Update1AdobeColdFusion2018.0.0.310739AdobeColdFusion11Update9AdobeColdFusion11Update8AdobeColdFusion11Update7AdobeColdFusion11Update6AdobeColdFusion11Update5AdobeColdFusion11Update4AdobeColdFusion11Update3AdobeColdFusion11Update2AdobeColdFusion11Update14AdobeColdFusion11Update13AdobeColdFusion11Update12AdobeColdFusion11Update11AdobeColdFusion11Update10AdobeColdFusion11Update1ʵÑéÀûÓÃCVE-2018-15958AdobeColdFusion·´ÐòÁл¯Â©¶´¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_ThinkPHP5Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂ룬ÔÚÄ¿±ê·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£ThinkPHPÊÇÒ»¸öÁ÷ÐеÄÇáÁ¿¼¶¹ú²úPHP¿ª·¢¿ò¼Ü¡£µ±WebÍøÕ¾ÊÇ»ùÓÚThinkPHP¿ò¼Ü¿ª·¢Ê±£¬¿ÉÄÜ´æÔڸ鶴ʱ¡£¹¥»÷Õß·¢Ë;«ÐĽṹµÄPHP´úÂëÔÚÄ¿±êÖ÷»úÉÏÖ´ÐУ¬Æóͼ½øÒ»²½¿ØÖÆ·þÎñÆ÷¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Apache_Solr_Velocity_Ô¶³Ì´úÂëÖ´ÐЩ¶´_Config_API |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃApache_Solr_VelocityÔ¶³Ì´úÂëÖ´ÐЩ¶´_Config_API¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | TCP_Java¾²Ì¬µ÷ÓÃ_java.lang.Runtime_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´Ä¿±êIPÕýÔÚʹÓÃJava¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½½øÐÐÔ¶³Ì´úÂëÖ´Ðй¥»÷µÄÐÐΪ¡£ÔÚJavaÖУ¬·¨Ê½¿ª·¢ÈËԱͨ³£»áͨ¹ý¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½Ö´ÐÐÍⲿµÄShellÃüÁî¡£RuntimeÀàÊÇJava·¨Ê½µÄÔËÐÐʱ»·¾³£¬¿ª·¢Õß¿ÉÒÔͨ¹ýgetRuntime()ÒªÁì»ñÈ¡µ±Ç°RuntimeÔËÐÐʱ¹¤¾ßµÄÒýÓá£Í¨³£ÔÚJavaÏà¹ØµÄÓ¦ÓÃϵͳÖУ¬Èç¹û´¦ÖÃÍⲿÃüÁîÖ´ÐÐʱ£¬Ã»ÓжÔÓû§µÄÊäÈë×öºÏÀíÓÐЧµÄ¹ýÂË£¬¹¥»÷Õß¿ÉÒÔÀûÓÃÕâ¸ö©¶´Ô¶³Ì×¢ÈëÃüÁî»ò´úÂë²¢Ö´ÐС£ÖîÈçStruts2¡¢SpringÕâЩӦÓÃÔø¾±»Åû¶³ö´æÔÚJavaÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬ÀýÈçOgnl±í´ïʽºÍSpEL±í´ïʽµÄÈÎÒâ´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õßͨ¹ý¾²Ì¬µ÷ÓÃjava.lang.Runtime·½Ê½ÔÚÓÐȱÏÝÓ¦ÓÃÖÐÖ´ÐÐÈÎÒâ´úÂë»òÃüÁ½øÒ»²½ÍêÈ«¿ØÖÆÄ¿±ê·þÎñÆ÷¡£ÊµÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓ÷dz£¹ã·ºµÄÒ»¿îWebshell¹ÜÀí¹¤¾ß¡£Öйú²Ëµ¶ÓÃ;ʮ·Ö¹ã·º,Ö§³Ö¶àÖÖÓïÑÔ,СÇÉʵÓ㬾ßÓÐÎļþ¹ÜÀí£¨ÓÐ×ã¹»µÄȨÏÞʱºò¿ÉÒÔ¹ÜÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬Êý¾Ý¿â¹ÜÀí£¬ÐéÄâÖն˵ȹ¦Ð§¡£¶ÔÓÚÕâÀà¹ÜÀí¹¤¾ß£¬Èç¹ûûÓдóÁ¿µÄÐ޸ķþÎñ¶Ë½Å±¾´úÂ룬Æä·µ»ØÁ÷Á¿¶¼ÊÐÓÐһЩ³£¼ûµÄÌØÕ÷£¬±¾Ìõ¹æÔò½«³£¼ûµÄÅäºÏÌØÕ÷ÌáÈ¡³öÀ´½øÐзÀÓùÐÔ±¨¾¯¡£ÓÉÓÚ´ËʼþΪ½ÏΪ¿í·ºµÄͨÓÃÌØÕ÷£¬¿ÉÄÜ´æÔÚÎ󱨣¬Çë²Î¿¼ÌØÕ÷ÐÔÖÊÅжÏ×ֶνøÐÐÅжϡ£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_WordPress_Easy_WP_SMTPÈÕÖ¾Îļþ̽²â |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWordPressµÄEasy_WP_SMTP²å¼þÈÕ־̻¶ÔÚÍâ½øÐÐδÊÚȨ·ÃÎʼ°ÃÜÂë¶ñÒâÐ޸ģ»EasyWPSMTPÔÊÐíÄúÅäÖúÍͨ¹ýSMTP·þÎñÆ÷·¢ËÍËùÓÐÍâ·¢µç×ÓÓʼþ¡£ÕâÑù¿ÉÒÔ·ÀÖ¹ÄúµÄµç×ÓÓʼþ½øÈëÊÕ¼þÈ˵ÄÀ¬»øÓʼþÎļþ¼Ð¡£ |
¸üÐÂʱ¼ä£º | 20210504 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_wget_curlÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐÐ |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍ¿ÉÒÉÃüÁʵÑé¿ØÖÆÄ¿µÄIPÖ÷»úÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐС£ |
¸üÐÂʱ¼ä£º | 20210504 |
ɾ³ýʼþ
1. HTTP_ľÂíºóÃÅ_webshell_AntSword_php¿ØÖÆÃüÁî
2. TCP_±ùЫ_php_webshell_ÉÏ´«
3. TCP_RealVNC_RFBÐÒéÔ¶³ÌÈÏÖ¤Èƹý©¶´[CVE-2006-2369]
4. HTTP_Citrix_ADC_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-8193][CNNVD-202007-367]
5. HTTP_Äþ¾²Â©¶´_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ