ÿÖÜÉý¼¶Í¨¸æ-2021-05-18
Ðû²¼Ê±¼ä 2021-05-19ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_PHP-zerodiumºóÃÅ_ÈÎÒâ´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄ·ÖÎö¹ý³ÌÖз¢ÏÖ£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»½Ù³ÖµÄÍøÕ¾ÉÏ£¬¶øÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬¶øÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢ÈËÔ±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£Ä¿Ç°ÎªÖ¹PHP¹Ù·½²¢Î´¾Í¸Ãʼþ½øÐиü¶àÅû¶£¬ÌåÏִ˴ηþÎñÆ÷±»ºÚµÄ¾ßÌåϸ½ÚÈÔÔÚÊӲ쵱ÖС£ÓÉÓÚ´ËʼþµÄÓ°Ï죬PHPµÄ¹Ù·½´úÂë¿âÒѾ±»Î¬»¤ÈËԱǨÒÆÖÁGitHubƽ̨£¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϽøÐС£ |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_Gh0st_htrfhtfe__Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø·¨Ê½£¬¹¦Ð§Ê®·ÖÇ¿´ó¡£¾ßÓÐÎļþ¹ÜÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢´´½¨¡¢É¾³ý£©¡¢½ø³Ì¹ÜÀí¡¢ÏµÍ³·þÎñ¡¢×¢²á±í¡¢¼üÅ̼Ǽ¡¢Ô¶³ÌÖնˡ¢ÆÁÄ»¼à¿Ø¡¢¼ì²ìÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úÆ÷¡£½üÆÚ·¢ÏÖ´óÁ¿Æ¾¾ÝGh0stÔ´ÂëÐ޸ĵÄÔ¶¿Ø·¨Ê½£¬²¢Ìí¼ÓÁË×Ô¼ºµÄ¹¦Ð§£¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳ°²×°µÄÍøÂçÓÎÏ·µÈ¹¦Ð§¡£ºÚ¿Í»¹¿ÉÒÔ½«º¬ÓÐÉãÏñÍ·»ò°²×°Ö¸¶¨ÓÎÏ·µÄÓû§¹éÀ࣬ÓÐÕë¶ÔÐÔµÄ͵ȡÓû§Òþ˽¡£ÉõÖÁ¼ì²ìÖж¾ÕßµØÀíλÖõĹ¦Ð§£¬¶ÔÓû§µÄÒþ˽Ôì³É¸ü´óµÄÍþв¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Terramaster_TOS_ÃüÁî×¢È멶´[CVE-2020-28188][CNNVD-202012-1548] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳÃüÁî×¢È멶´£¬¹¥»÷Õß¿ÉÀûÓø鶴ͨ¹ýÔÚʼþ²ÎÊýÖаüÂÞmakecvs.php×¢Èë²Ù×÷ϵͳÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | HTTP_SSH-RSA˽Կй© |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ£¬LINUX·þÎñÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH£¬RSA˽Կй¶£¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH£¬µ¼ÖÂÖ÷»ú±»½Ó¹Ü¡£ |
¸üÐÂʱ¼ä£º | 20210511 |
ʼþÃû³Æ£º | HTTP_Microsoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | µ±Ç°Ö÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì¹¥»÷¸Ã©¶´ÊÇExchangeÖеÄÈÎÒâÎļþдÈ멶´¡£¸Ã©¶´ÐèÒª½øÐÐÉí·ÝÈÏÖ¤£¬ÀûÓôË©¶´¿ÉÒÔ½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£²¢¿ÉÒÔ½áºÏÀûÓÃCVE-2021-26855SSRF©¶´»òÈƹýȨÏÞÈÏÖ¤½øÐÐÎļþдÈë¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÁ¬½ÓC2·þÎñÆ÷µÄÐÐΪ¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí£¬¾ßÓÐËѼ¯Êܺ¦Ö÷»úÃô¸ÐÐÅÏ¢ÉÏ´«µ½C2·þÎñÆ÷µÄÐÐΪ£¬ÏÂÔØÍÚ¿ó·¨Ê½µ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIE½ø³ÌÖÐÖ´ÐÐÍÚ¿ó£¬Æ¾¾ÝC2·þÎñÆ÷µÄÃüÁîÖ´ÐÐÖÖÖÖ²Ù×÷£¬Èç¸üÐÂÅäÖÃÐÅÏ¢¡¢°²×°ÍÚ¿ó·¨Ê½µÈ¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£ ©¶´´æÔڵİ汾£º S2-016£ºStruts 2.0.0 - Struts 2.3.15 S2-017£ºStruts 2.0.0 - Struts 2.3.15 S2-018£ºStruts 2.0.0 - Struts 2.3.15.2 |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | HTTP_ľÂí_Raccoon.Stealer_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£RaccoonÒ²±»³ÆΪMohazo»òRacealer£¬ÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÇÔÃÜľÂí¡£Ëü¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶ËÉú´æµÄÕ˺ÅÃÜÂë¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ʼþÃû³Æ£º | HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬Æ丽¼ÓµÄParametersInterceptorÔÊÐí·ÃÎÊ'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£ÔÚ¾ßÌåµÄWebÈÝÆ÷²¿Êð»·¾³Ï£¨È磺Tomcat£©£¬¹¥»÷ÕßÀûÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬¿ÉÏò·þÎñÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷Ö÷»ú¡£ÁíÍ⣬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬boundary´óÓÚ½çÏÞÖµ£¬¶øÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏÞÖµ£¬µ¼ÖÂDDOS¡£Â©¶´´æÔڵİ汾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null |
¸üÐÂʱ¼ä£º | 20210518 |
ÐÞ¸Äʼþ
1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐЩ¶´
2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÃüÁî_Ô¶³ÌÃüÁîÖ´ÐÐ