ÿÖÜÉý¼¶Í¨¸æ-2021-11-16

Ðû²¼Ê±¼ä 2021-12-10

ÐÂÔöʼþ




ʼþÃû³Æ£º

TCP_ľÂí_Win32.Dark_Crystal_RAT/DCRat_Ô¶¿ØľÂí_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

Ô¶¿ØºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíDarkCrystalÁ¬½ÓC2·þÎñÆ÷£¬±íÃ÷Ô´IPÖ÷»úÒÑѬȾ¸ÃľÂí¡£DarkCrystal¶ñÒâÈí¼þÊÇÒ»ÖÖRAT£¨Ô¶³Ì·ÃÎÊľÂí£©£¬C#ÓïÑÔ£¬¶íÂÞ˹ÈË¿ª·¢¡£DarkCrystalRATÊÇÒ»Öַdz£ÏȽøµÄºÚ¿Í¹¤¾ß£¬¾ßÓкܶ๦Ч£¬ÆäÖаüÂÞ£ºÔËÐÐÔ¶³ÌÃüÁî¡¢ÊÕ¼¯Óû§ÐÅÏ¢¡¢Í¨¹ýÍøÂçÉãÏñͷ¼ÖÆÊÓƵ¡¢Í¨¹ýÂó¿Ë·ç¼ÖÆÒôƵ¡¢Ö´ÐÐDDoS»òUDP/TCPºéË®¹¥»÷¡¢¹ÜÀíÎļþϵͳµÈµÈ¡£

¸üÐÂʱ¼ä£º

20211116

 

 

ʼþÃû³Æ£º

HTTP_±í´ïʽעÈë_ͨÓÃ

Äþ¾²ÀàÐÍ£º

ÆäËû×¢Èë

ʼþÃèÊö£º

2013Äê4ÔÂ15ÈÕExpressionLanguageInjection´ÊÌõÔÚOWASPÉϱ»´´½¨£¬¶øÕâ¸ö´ÊµÄ×îÔç·ºÆð¿ÉÒÔ×·Ëݵ½2012Äê12Ôµġ¶Remote-Code-with-Expression-Language-Injection¡·Ò»ÎÄ£¬ÔÚÕâ¸öpaperÖеÚÒ»´ÎÌáµ½ÁËÕâ¸öÃû´Ê¡£¶øÕâ¸öʱÆÚ£¬Ö»²»Í⻹ֻÊÇ°ÑËü½Ð×öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡¢Ô¶³ÌÃüÁîÖ´ÐЩ¶´»òÕßÉÏÏÂÎIJٿØ©¶´¡£ÏñStruts2ϵÁеÄs2-003¡¢s2-009¡¢s2-016µÈ£¬ÕâÖÖÓÉOGNL±í´ïʽÒýÆðµÄÃüÁîÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20211116

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_D-Link_DAP-1860_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-19597][CNNVD-201912-215]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

D-LinkDAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi·¶Î§À©Õ¹Æ÷¡£D-LinkDAP-18601.04b03֮ǰ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õ߿ɽèÖúHTTPÇëÇóÍ·ÖеÄHNAP_AUTH²ÎÊýºó×¢ÈëshellÔª×Ö·ûÀûÓø鶴ÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20211116

 

 

ʼþÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_passwdÄÚÈÝÎļþ»ØÏÔ

Äþ¾²ÀàÐÍ£º

ÆäËû¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÕýÔÚͨ¹ýÃüÁîÖ´Ðмì²ì/etc/passwdÎļþµÄÄÚÈÝ¡£´ËÎļþÖд洢ÁËϵͳÖеÄËùÓÐÕË»§¡¢È¨ÏÞµÈÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20211116

 

ÐÞ¸Äʼþ



ʼþÃû³Æ£º

HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2015-7450]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

WebSphereÊÇIBM¹«Ë¾¿ª·¢µÄÖмä¼þ»ù´¡Éèʩƽ̨¡£WebSphere7°æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁËApacheCommonsCollections¿âÖеÄInvokerTransformerÀ࣬¸ÃÀà´æÔÚJava·´ÐòÁл¯Â©¶´¡£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî

¸üÐÂʱ¼ä£º

20211116

 

 

ʼþÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÐaction:¡¢redirect:»òredirectAction:µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20211116

 


ʼþÃû³Æ£º

TCP_ͨÓÃ_Java·´ÐòÁл¯_ysoserial¶ñÒâÊý¾ÝÀûÓÃ

Äþ¾²ÀàÐÍ£º

ÃüÁîÖ´ÐÐ

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýTCP·¢ËÍysoserialÉú³ÉµÄ¶ñÒâJAVA·´ÐòÁл¯Êý¾Ý¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷¡£Èô·ÃÎʵÄÓ¦ÓôæÔÚ©¶´JAVA·´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂ룬»ñȡϵͳ¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20211116

 


ʼþÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai.Putin_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ÆäËû×¢Èë

ʼþÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÁ¬½ÓC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬°üÂÞ£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉ豸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØ©¶´Î´¼°Ê±ÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ­¹ûÈ»£¬Mirai·ºÆðÁ˺ܶà±äÖÖ£¬±¾Ê¼þÕë¶ÔÆä±äÖÖPutin¡£

¸üÐÂʱ¼ä£º

20211116

 

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_phpunint_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-9841][CNNVD-201706-1127]

Äþ¾²ÀàÐÍ£º

´úÂëÖ´ÐÐ

ʼþÃèÊö£º

PHPUnitÊÇPHP³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ(unittesting)¿ò¼Ü£¬Í¨³£phpunitʹÓÃcomposer·Ç³£Á÷ÐеÄPHPÒÀÀµ¹ÜÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunitÉú²ú»·¾³ÖÐÈÔÈ»°²×°ÁËËü,Èç¹û¸Ã±àдÆ÷Ä£¿é´æÔÚÓÚWeb¿É·ÃÎÊĿ¼£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20211116

 


ʼþÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson©¶´_hex±àÂëÀûÓÃ

Äþ¾²ÀàÐÍ£º

ÆäËû¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬Ëü¿ÉÒÔ½âÎöJSON¸ñʽµÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓ÷¶Î§ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬Òò´Ë¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈƹý¼ì²âÉ豸¡£

¸üÐÂʱ¼ä£º

20211116