ÿÖÜÉý¼¶Í¨¸æ-2022-06-14

Ðû²¼Ê±¼ä 2022-06-14

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_GitLab_Ó²±àÂ멶´[CVE-2021-22205][CNNVD-202104-1685]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

GitLabÊÇÒ»¸öÓÃÓÚ¶ÑÕ»¹ÜÀíϵͳµÄ¿ªÔ´ÏîÄ¿£¬Ê¹ÓÃGit×÷Ϊ´úÂë¹ÜÀí¹¤¾ß£¬¿Éͨ¹ýWeb½çÃæ·ÃÎʹûÈ»»ò˽ÈËÏîÄ¿¡£ÔÚGitLabCE/EE°æ±¾14.7(14.7.7֮ǰ)¡¢14.8(14.8.5֮ǰ)ºÍ14.9(14.9.2֮ǰ)ÖÐʹÓÃOmniAuthÌṩÉÌ(ÈçOAuth¡¢LDAP¡¢SAML)×¢²áµÄÕÊ»§ÉèÖÃÁËÓ²±àÂëÃÜÂ룬ÔÊÐí¹¥»÷ÕßDZÔڵؿØÖÆÕÊ»§¡£

¸üÐÂʱ¼ä£º

20220614

 

ʼþÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai.Putin_¿ØÖÆÃüÁî

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½Mirai.Putin·þÎñÆ÷ÊÔͼ·¢ËÍÃüÁî¸øMirai.Putin£¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖMirai.Putin¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬°üÂÞ£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉ豸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØ©¶´Î´¼°Ê±ÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ­¹ûÈ»£¬Mirai·ºÆðÁ˺ܶà±äÖÖ£¬±¾Ê¼þÕë¶ÔÆä±äÖÖMirai.Putin¡£

¸üÐÂʱ¼ä£º

20220614

 

ʼþÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Mirai_¿ØÖÆÃüÁî

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½Mirai·þÎñÆ÷ÊÔͼ·¢ËÍÃüÁî¸øMirai£¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai¼«Æä±äÖÖ¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬°üÂÞ£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉ豸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØ©¶´Î´¼°Ê±ÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220614

 

ʼþÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_PHP·´ÐòÁл¯¹¤¾ß¸ñʽÊý¾Ý·¢ÏÖ

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

·¨Ê½Î´¶ÔÓû§ÊäÈëµÄÐòÁл¯×Ö·û´®½øÐмì²â£¬µ¼Ö¹¥»÷Õß¿ÉÒÔ¿ØÖÆ·´ÐòÁл¯¹ý³Ì£¬Í¨¹ýÔÚ²ÎÊýÖÐ×¢ÈëһЩ´úÂ룬´Ó¶øµ½´ï´úÂëÖ´ÐУ¬SQL×¢È룬Ŀ¼±éÀúµÈ²»Ðпغó¹û£¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20220614

 

ʼþÃû³Æ£º

TCP_Äþ¾²Â©¶´_SaltStack_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

SaltStackÊÇ»ùÓÚPython¿ª·¢µÄÒ»Ì×C/S¼Ü¹¹ÅäÖùÜÀí¹¤¾ß£¬ÊÇÒ»¸ö·þÎñÆ÷»ù´¡¼Ü¹¹¼¯Öл¯¹ÜÀíƽ̨£¬¾ß±¸ÅäÖùÜÀí¡¢Ô¶³ÌÖ´ÐС¢¼à¿ØµÈ¹¦Ð§¡£ÔÚCVE-2020-11651ÈÏÖ¤Èƹý©¶´ÖУ¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬿ÉÒÔÈƹýSaltMasterµÄÑéÖ¤Âß¼­£¬µ÷ÓÃÏà¹ØδÊÚȨº¯Êý¹¦Ð§£¬´Ó¶ø¿ÉÒÔÔì³ÉÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£Â©¶´ÓÉClearfuncsÀàÒýÆð,¸ÃÀàÎÞÒâÖÐ̻¶ÁË_send_pub()ºÍ_prep_auth_info()ÒªÁ졣δ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ý·¢ËÍÌØÖƵÄÇëÇó¿ÉÔÚminion¶Ë·þÎñÆ÷ÉÏÖ´ÐÐÈÎÒâÃüÁÄܹ»ÌáÈ¡¸ùÃÜÔ¿À´µ÷ÓÃmaster¶Ë·þÎñÆ÷ÉϵĹÜÀíÃüÁî¡£Ó°Ïì°æ±¾SaltStack<2019.2.4SaltStack<3000.2

¸üÐÂʱ¼ä£º

20220614

 

ʼþÃû³Æ£º

TCP_½©Ê¬ÍøÂç_IoT.Moobot_¿ØÖÆÃüÁî

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½Moobot·þÎñÆ÷ÊÔͼ·¢ËÍÃüÁî¸øMoobot£¬ºÃ±ÈDDoS¹¥»÷Ö¸¶¨Ä¿µÄIPÖ÷»ú¡£Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçMoobot¡£MoobotÊÇIoT½©Ê¬ÍøÂçMiraiµÄÖ÷Òª±äÖÖÖ®Ò»£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿±êÌᳫDDoS¹¥»÷£¬Í¨¹ýÖÖÖÖ©¶´Á÷´«×ÔÉí¡£

¸üÐÂʱ¼ä£º

20220614

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_JAVA_µ÷ÓÃRMIÔ¶³ÌÏÂÔØclass

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

´Ëʼþ¼ì²âJAVAµ÷ÓÃRMIÔ¶³ÌÏÂÔØclassµÄÐÐΪ¡£RMI¼´Ô¶³ÌÒªÁìµ÷Óã¬Ò»ÖÖÓÃÓÚʵÏÖÔ¶³Ì¹ý³Ìµ÷ÓõÄjavaAPI.ÔÚjava©¶´ÖУ¬´æÔÚ´óÁ¿·´ÐòÁл¯ºÍÃüÁîÖ´ÐЩ¶´»áʹÓõ½RMIÔ¶³Ì·ÃÎʶñÒâÀàµÄÊÖ·¨£¬À´ÊµÏÖÈÎÒâÃüÁîÖ´ÐУ¬Î£º¦½Ï´ó¡£

¸üÐÂʱ¼ä£º

20220614