ÿÖÜÉý¼¶Í¨¸æ-2022-01-18

Ðû²¼Ê±¼ä 2022-01-18

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´®

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óá£

¸üÐÂʱ¼ä£º

20220118


 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_DedeCMSV6.0.3_article_string_mix.php_Ô¶³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶øÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£Æäºǫ́article_string_mix.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´Äõ½Ä¿±êÖ÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220118

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_À¶ÁèOA_admin.do_JNDIÔ¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚÈÎÒâÎļþ¶Áȡ©¶´¡£¹¥»÷Õß¿ÉÀûÓ鶴»ñÈ¡Ãô¸ÐÐÅÏ¢£¬¶ÁÈ¡ÅäÖÃÎļþµÃµ½ÃÜÔ¿ºó·ÃÎÊadmin.do¼´¿ÉÀûÓÃJNDIÔ¶³ÌÃüÁîÖ´ÐлñȡȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220118


 

ʼþÃû³Æ£º

TCP_ľÂíºóÃÅ_Pupy_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ßPupyÉú³ÉµÄhttpÔ¶¿ØºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£Ö´Ðк󣬹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉø͸¹¤¾ß¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬Õ¼Óÿռä·Ç³£Ð¡¡£Pupy¿ÉÒÔʹÓöàÖÖ·½Ê½½øÐÐͨÐÅ£¬Ê¹Ó÷´Éä×¢ÈëǨÒƵ½½ø³ÌÖУ¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£

¸üÐÂʱ¼ä£º

20220118


 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Zhone-Technologies-zNID-GPON-2426A_ÃüÁîÖ´ÐÐ[CVE-2014-9118][CNNVD-201510-721]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ZhoneTechnologieszNIDGPON2426AÊÇÃÀ¹úZhoneTechnologies¹«Ë¾µÄÒ»¿î·ÓÉÆ÷¡£webadministrativeportalÊÇÆäÖеÄÒ»¸öWeb¹ÜÀíÔ±¿ØÖÆ̨·¨Ê½¡£ZhoneTechnologieszNIDGPON2426AS3.0.501֮ǰ°æ±¾µÄWeb¹ÜÀíÔ±¿ØÖÆ̨ÖдæÔÚÄþ¾²Â©¶´¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòzhnping.cmdÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®ipAddr¡¯²ÎÊýÀûÓø鶴ִÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220118