ÿÖÜÉý¼¶Í¨¸æ-2022-03-15
Ðû²¼Ê±¼ä 2022-03-15ÐÂÔöʼþ
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_ÈÕÖ¾ÎļþÐÅϢй¶ |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃÐÅϢ鶩¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬¿É¶ÁÈ¡Ä¿µÄIPÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢Îļþ¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-±©Á¦ÆƽâÀûÓÃÁ´_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¿Ç°Ö÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÃüÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£½üÈÕ£¬·¢ÏÖÕë¶Ô¸Ã©¶´µÄÀûÓ÷½Ê½Òѱ»Ð¡·¶Î§Á÷´«£¨Â©¶´°æ±¾<=1.2.4£©£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄÉ´ëÊ©¶Ô´Ë©¶´½øÐзÀ»¤¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ShiroAttack2¹¤¾ßʹÓÃ-ÄÚ´æÂí×¢Èë_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¿Ç°Ö÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÃüÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£½üÈÕ£¬·¢ÏÖÕë¶Ô¸Ã©¶´µÄÀûÓ÷½Ê½Òѱ»Ð¡·¶Î§Á÷´«£¨Â©¶´°æ±¾<=1.2.4£©£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄÉ´ëÊ©¶Ô´Ë©¶´½øÐзÀ»¤¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_Win32.Torchwood_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅTorchwood¡£TorchwoodÊÇÒ»¸ö¹¦Ð§·Ç³£Ç¿´óµÄºóÃÅ£¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£Ö÷Ҫͨ¹ýCHMÎļþÁ÷´«¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_LinuxÃüÁîÖ´ÐлØÏÔ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»ú·ºÆðÁËijЩLinuxÃüÁÈçw¡¢top¡¢uptimeµÈ£©Ö´ÐеĻØÏÔÁ÷Á¿£¬°üÂÞµ±Ç°ÏµÍ³Ê±¿Ì¡¢ÔËÐÐʱ¼ä¡¢Óû§×ÜÁ¬½ÓÊý¡¢Æ½¾ù¸ºÔصÈÐÅÏ¢ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_ElasticSearch_Ŀ¼´©Ô½Â©¶´[CVE-2015-5531] |
Äþ¾²ÀàÐÍ£º | CGI¹¥»÷ |
ʼþÃèÊö£º | ¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchĿ¼´©Ô½Â©¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓø鶴¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearch´æÔÚĿ¼´©Ô½Â©¶´£¬¹¥»÷ÕßÀûÓø鶴¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ÊµÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_elasticsearch-head_Ŀ¼´©Ô½Â©¶´[CVE-2015-3337] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃElasticSearchhead²å¼þĿ¼´©Ô½Â©¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓø鶴¶ÁÈ¡µ½²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷£¬»ùÓÚJava¿ª·¢¡£ElasticSearchhead²å¼þ´æÔÚĿ¼´©Ô½Â©¶´£¬¹¥»÷ÕßÀûÓø鶴¿É¶ÁÈ¡²Ù×÷ϵͳÉϵÄÈÎÒâÎļþ¡£ÊµÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Apache_Solr_SSRF©¶´[CVE-2021-27905] |
Äþ¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ʼþÃèÊö£º | ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ£¬Ê¹ÓÃJava±àд¡¢ÔËÐÐÔÚServletÈÝÆ÷µÄÒ»¸ö¶ÀÁ¢µÄÈ«ÎÄËÑË÷·þÎñÆ÷£¬ÊÇApacheLuceneÏîÄ¿µÄ¿ªÔ´ÆóÒµËÑË÷ƽ̨¡£¸Ã©¶´ÊÇÓÉÓÚûÓжÔÊäÈëµÄÄÚÈݽøÐÐУÑ飬¹¥»÷Õß¿ÉÀûÓø鶴ÔÚδÊÚȨµÄÇé¿öÏ£¬½á¹¹¶ñÒâÊý¾ÝÖ´ÐÐSSRF¹¥»÷£¬×îÖÕÔì³ÉÈÎÒâ¶ÁÈ¡·þÎñÆ÷ÉϵÄÎļþ¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_java·´ÐòÁл¯_Ô¶³ÌÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIP·¢ËÍ¿ÉÄÜ´æÔÚÔ¶³ÌÃüÁîÖ´Ðе÷ÓõÄjava·´ÐòÁл¯ÇëÇó¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_POSCMS_ÈÎÒâÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | POSCMS3.2.0°æ±¾Ç°Ì¨½çÃæ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£Ìض¨Â·¾¶´«Èë¶ñÒâ²ÎÊý£¬»áµ¼Ö´úÂëÖ´ÐУ¬µ¼Ö¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý´Ë©¶´Ð´Èë¶ñÒâ´úÂ룬²¢¿ÉÒÔͨ¹ý´Ë©¶´½øÐÐgetshell |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_POSCMS_Îļþ°üÂÞ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | POSCMS3.2.0°æ±¾ºǫ́¹ÜÀí½çÃæµÄ¸½¼þÉÏ´«¹¦Ð§Ö»ÊǶÔÎļþºó׺½øÐÐÁËÑéÖ¤£¬µ«²¢Ã»ÓжÔÎļþÄÚÈݽøÐÐÑéÖ¤£¬µ¼Ö¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý´Ë©¶´ÉÏ´«¶ñÒâÎļþ£¬²¢¿ÉÒÔͨ¹ýÀûÓôËÎļþ½øÐÐgetshell¡£ÒªÖ´Ðй¥»÷£¬ÐèÒªÄܹ»µÇ¼µ½ºǫ́¹ÜÀí½çÃ棬ÇÒÓÐÉÏ´«ÎļþµÄȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_mini_httpd_ÈÎÒâÎļþ¶Áȡ©¶´[CVE-2018-18778][CNNVD-201810-1382] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | Mini_httpdÊÇÒ»¸ö΢Ð͵ÄHttp·þÎñÆ÷£¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇé¿öÏ¿ÉÒÔ±£³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¨Ô¼ÎªApacheµÄ90%£©£¬Òò´Ë¹ã·º±»ÖÖÖÖIOT£¨Â·ÓÉÆ÷£¬½»»»Æ÷£¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽ·þÎñÆ÷¡£¶ø°üÂÞ»ªÎª£¬zyxel£¬º£¿µÍþÊÓ£¬Ê÷Ý®ÅɵÈÔÚÄڵij§É̵ÄÆìÏÂÉ豸¶¼Ôø½ÓÄÉMini_httpd×é¼þ¡£ACMEmini_httpd<1.30°æ±¾´æÔÚÒ»¸öÈÎÒâÎļþ¶Áȡ©¶´£¬¸Ã©¶´Ô´ÓÚÔÚmini_httpd¿ªÆôÐéÄâÖ÷»úģʽµÄÇé¿öÏ£¬Óû§ÇëÇóhttp://HOST/FILE½«»á·ÃÎʵ½µ±Ç°Ä¿Â¼ÏµÄHOST/FILEÎļþ£¬¶øµ±HOSTΪ¿Õ¡¢FILE=etc/passwdµÄʱºò£¬ÉÏÊöÓï¾ä½á¹ûΪ/etc/passwd¡£¿É×÷Ϊ¾ø¶Ô·¾¶£¬¶ÁÈ¡µ½ÁË/etc/passwd£¬Ôì³ÉÈÎÒâÎļþ¶Áȡ©¶´¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ToTolink_Technology·ÓÉÆ÷_δÊÚȨÃüÁî×¢Èë[CVE-2022-25134][CNNVD-202202-1645] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýCVE-2022-25134©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£TOTOLINKTechnology·ÓÉÆ÷¹Ì¼þÀï´æÔÚÃüÁî×¢È멶´£¬¹¥»÷Õ߿ɽè´ËÔ¶³ÌÖ´ÐÐϵͳÃüÁî¡£ÊÜÓ°Ïì·ÓÉÆ÷Ðͺż°Æä¹Ì¼þ°æ±¾Îª£ºA830R(V5.9c.4729_B20191112)¡¢3100R(V4.1.2cu.5050_B20200504)¡¢A950RG(V4.1.2cu.5161_B20200903)¡¢A800R(V4.1.2cu.5137_B20200730)¡¢A3000RU(V5.9c.5185_B20201128)¡¢A810R(V4.1.2cu.5182_B20201026)¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_©¶´ÀûÓÃ_ShiroAttack¹¤¾ßʹÓÃ_Ô¶³Ì´úÂëÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¿Ç°Ö÷»úÕýÊܵ½ApachShiroRememberme²ÎÊýÃüÁî×¢Èë´úÂëÖ´Ðй¥»÷ApacheShiroÊÇÒ»¸öÇ¿´óÇÒÒ×ÓõÄJavaÄþ¾²¿ò¼Ü£¬±»ÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°¹ÜÀí¡£½üÈÕ£¬·¢ÏÖÕë¶Ô¸Ã©¶´µÄÀûÓ÷½Ê½Òѱ»Ð¡·¶Î§Á÷´«£¨Â©¶´°æ±¾<=1.2.4£©£¬ÇëÏà¹ØÓû§¾¡¿ì½ÓÄÉ´ëÊ©¶Ô´Ë©¶´½øÐзÀ»¤¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_ToTolink_EX200ÎÞÏßÖмÌÆ÷_δÊÚȨÃüÁî×¢Èë[CVE-2021-43711][CNNVD-202201-147] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ToTolinkEx200ÊÇÖйúToTolink¹«Ë¾µÄÒ»¿î2.4GÎÞÏßÖмÌÆ÷£¬Ö¼ÔÚÀ©´óÏÖÓÐWi-FiÍøÂçµÄÁýÕÖ·¶Î§¡£ToTolinkEx200¶ÔhttpGET²ÎÊý´¦Öò»Í×£¬´æÔÚÃüÁî×¢È멶´£¬µ¼ÖÂδÊÚȨԶ³ÌÖ´ÐÐÃüÁî¡£¹¥»÷Õß¿ÉÀûÓôË©¶´×¢ÈëÖ´ÐжñÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220315 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´® |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óᣠ|
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´® |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óᣠ|
¸üÐÂʱ¼ä£º | 20220315 |
ʼþÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£ |
¸üÐÂʱ¼ä£º | 20220315 |