ÿÖÜÉý¼¶Í¨¸æ-2022-07-19

Ðû²¼Ê±¼ä 2022-07-19

ÐÂÔöʼþ


ʼþÃû³Æ£º

TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_Á¬½Ó_1

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíAvzhan¡£AvzhanÊÇÒ»¸öºóÃÅ£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úÆ÷¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_OFBiz_rmi·´ÐòÁл¯Â©¶´[CVE-2021-26295][CNNVD-202103-1262]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

ApacheOFBiz´æÔÚRMI·´ÐòÁл¯Ç°Ì¨ÃüÁîÖ´ÐУ¬Î´¾­Éí·ÝÑéÖ¤¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬴¥·¢·´ÐòÁл¯£¬´Ó¶øÔì³ÉÈÎÒâ´úÂëÖ´ÐУ¬¿ØÖÆ·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_̽²âphpÔ¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö:

¼ì²âµ½Ö÷»úÕýÔÚÏòÄ¿µÄIP·¢ËÍ̽²âphpÔ¶³ÌÃüÁîÖ´ÐеÄÇëÇ󡣴˹¥»÷¶àΪ©¶´É¨ÃèÆ÷·¢Éú¡£

¸üÐÂʱ¼ä£º

20220719

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬Ò»Ð©Ê¾ÀýDAGûÓÐÕýÈ·ÇåÀíÓû§ÌṩµÄ²ÎÊý£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÃüÁî×¢ÈëµÄÓ°Ïì¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring-messaging_´úÂëÖ´ÐÐ[CVE-2018-1270]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃSpring¿ò¼ÜSpring-messagingÄ£¿éÔ¶³Ì´úÂëÖ´ÐЩ¶´½øÐй¥»÷µÄÐÐΪ£¬¹¥»÷Õß¿ÉÒÔÀûÓø鶴ִÐÐÈÎÒâ´úÂë¡£Spring¿ò¼ÜÊÇÒ»¸ö¿ªÔ´µÄÏîÄ¿£¬ÊÇÒ»¸ö»ùÓÚIOCºÍAOPµÄ¹¹¼Ü¶à²ãJavaEEϵͳµÄ¿ò¼Ü¡£Spring¿ò¼Üͨ¹ýspring-messageingÄ£¿éºÍSTOMPÊðÀí¹¤¾ßͨѶ£¬spring-messageÄ£¿éÖеÄDefaultSubscriptionRegistryÀàÒªÁìaddSubscriptionInternal´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷ÕßÀûÓø鶴¿ÉÒÔÖ´ÐÐÈÎÒâJava´úÂ롣ʵÑéÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220719

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅTopApp-LB¸ºÔؾùºâÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

ÌìÈÚПºÔؾùºâTopAPP-LB²úÎï¾É°æ±¾ÔÚ¹ÜÀíÃæ´æÔÚÃüÁîÖ´ÐЩ¶´£¬¾ßÌåΪÔÚ¿ÉÒÔ·ÃÎʹÜÀíµÇ¼ҳÃæÇé¿öÏ£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇó£¬ÀûÓÃϵͳµÄ´úÂëȱÏÝ£¬¿ÉÆ´½ÓÏà¹Ø×Ö¶ÎÔì³ÉÃüÁîÖ´ÐС£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SpamTitanÍø¹Øºǫ́´úÂëÖ´ÐЩ¶´[CVE-2020-11699][CNNVD-202009-1082]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

SpamTitanÍø¹ØÊǹ¦Ð§Ç¿´óµÄ·´À¬»øÓʼþÉ豸£¬ËüΪÍøÂç¹ÜÀíÔ±ÌṩÁ˹㷺µÄ¹¤¾ßÀ´¿ØÖÆÓʼþÁ÷²¢·ÀÖ¹Óк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£ÓÉÓÚ´æÔÚ´úÂëȱÏÝ£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayload£¬Ê¹µÃÄ¿±êÖ÷»úÖ´ÐжñÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÉèÖÃȱÏÝ_Zyxel-NBG2015Éí·ÝÑéÖ¤Èƹý[CVE-2021-3297][CNNVD-202101-2231]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

ZyxelNBG2105´æÔÚÉí·ÝÑéÖ¤Èƹý©¶´£¬ÊôÓÚÂß¼­/ÉèÖôíÎ󣬹¥»÷ÕßÎÞÐèµÇ¼£¬¿ÉÒÔÖ±½Ó·ÃÎÊlogin_ok.htmÒ³Ã棬ÈƹýµÇ¼ҳÃæ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_gitlist-0.6.0_ÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

gitlistÊÇÒ»¿îʹÓÃPHP¿ª·¢µÄͼÐλ¯git¶ÑÕ»¼ì²ì¹¤¾ß¡£ÔÚÆä0.6.0°æ±¾ÖУ¬´æÔÚÒ»´¦ÃüÁî²ÎÊý×¢ÈëÎÊÌ⣬¿ÉÒÔµ¼ÖÂÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_GoAhead_cÓïÑÔ_ÎļþÉÏ´«[CVE-2021-42342][CNNVD-202110-1020]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

GoAheadÊÇÊÀ½çÉÏ×îÊÜ»¶Ó­µÄ΢ÐÍǶÈëʽWeb·þÎñÆ÷¡£Ëü½á¹¹½ô´Õ¡¢Äþ¾²ÇÒÒ×ÓÚʹÓá£GoAhead²¿ÊðÔÚÊýÒŲ́É豸ÖУ¬ÊÇ×îСǶÈëʽÉ豸µÄÀíÏëÑ¡Ôñ¡£½üÈÕ±¬³öGoAhead´æÔÚRCE©¶´£¬Â©¶´Ô´ÓÚÎļþÉÏ´«¹ýÂËÆ÷´¦ÖõIJ»È«£¬µ±ÓëCGI´¦Ö÷¨Ê½Ò»ÆðʹÓÃʱ£¬¿ÉÓ°Ïì»·¾³±äÁ¿£¬´Ó¶øʵÏÖRCE

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÁÔÓ¥Äþ¾²-½ðɽÖÕ¶ËÄþ¾²ÏµÍ³_upload.php_ÈÎÒâÎļþÉÏ´«

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

µ±Ç°Ö÷»úÕýÔÚÔâÊܽðɽÖÕ¶ËÄþ¾²ÏµÍ³upload.phpÈÎÒâÎļþÉÏ´«Â©¶´¹¥»÷£¬ÎÞÈκιýÂ˵ÄÎļþÉÏ´«¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ¿ØÖÆÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Webmin-show.cgi_ÃüÁîÖ´ÐÐ[CVE-2012-2982][CNNVD-201209-215]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

WebminÊÇUnixϵͳ¹ÜÀíWeb½Ó¿Ú£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§¡¢Apache¡¢DNS¡¢DNS¡¢Îļþ¹²Ïí¼°ÆäËû¡£Webmin1.590¼°¸üÔç°æ±¾µÄfile/show.cgiÄÚ´æÔÚÄþ¾²Â©¶´£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Í¨¹ý·¾¶ÃûÄÚµÄÎÞЧ×Ö·ûÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Maccms8.x_ÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

Maccms8.x¼°ÒÔÇ°°æ±¾ËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»ÑÏ£¬¹¥»÷Õ߿ɽṹpayload£¬Ö±½ÓevalÖ´ÐÐPHPÓï¾ä£¬ÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Django_SQL×¢Èë[CVE-2022-34265][CNNVD-202207-347]

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö:

DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÓ¦Óÿò¼Ü¡£Django´æÔÚÒ»¸öSQL×¢È멶´£¨CVE-2022-34265£©¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14¡¢4.0.6֮ǰµÄ°æ±¾£©ÖУ¬¿ÉÒÔͨ¹ýͨ±¨¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ£¬Èç¹ûÓ¦Ó÷¨Ê½ÔÚ½«ÕâЩ²ÎÊýͨ±¨¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»Óо­¹ýÊäÈë¹ýÂË»òתÒ壬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£Í¨¹ýÀûÓôË©¶´£¬µÚÈý·½¿ÉÒÔÏòÊý¾Ý¿â·¢ËÍÃüÁîÒÔ·ÃÎÊδ¾­ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ľÂíºóÃÅ_PhpSpy-MysqlÊý¾Ý¿â¹ÜÀí_Webshell·ÃÎÊ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö:

Á÷Á¿Öмì²âµ½phpspy¹ÜÀímysqlÊý¾Ý¿âµÄ²Ù×÷£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ½øÐÐÁ¬½ÓÐÐΪ¡£webshellÊÇwebÈëÇֵĽű¾¹¥»÷¹¤¾ß¡£¼òµ¥Ëµ£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ·ÅÖÃÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖУ¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½Ê½£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷£¬°üÂÞÉÏ´«ÏÂÔØÎļþ¡¢¼ì²ìÊý¾Ý¿â¡¢Ö´ÐÐÈÎÒⷨʽÃüÁîµÈ¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬ÓÉÓÚÓë±»¿ØÖƵķþÎñÆ÷»òÔ¶³ÌÖ÷»ú½»»»µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úͨ±¨µÄ£¬Òò´Ë²»»á±»·À»ðǽÀ¹½Ø¡£¶øÇÒʹÓÃwebshellÒ»°ã²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼǼ£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Ç¼£¬¹ÜÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

TCP_ľÂíºóÃÅ_AlmondRat(ÂûÁ黨)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö:

¼ì²âµ½AlmondRatÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAlmondRat¡£AlmondRatÊÇÂûÁ黨×éÖ¯ËùʹÓÃÁËÒ»¸öÇáÁ¿»¯ºóÃÅ£¬»ùÓÚCSharpÓïÑÔ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Advantech-iView-NetworkServlet_ÃüÁîÖ´ÐÐ[CVE-2022-2143][CNNVD-202206-2735]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

AdvantechiView5_7_04_6469°æ±¾Ç°´æÔÚÃüÁîÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÒÔÔÚδµÇ¼µÄÇé¿öÏÂÀûÓÃÃüÁîÆ´½ÓдÈëwebshell£¬»ñÈ¡Ä¿±êϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_NetsysÓ²¼þÉ豸_ÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

NetsysÊÇÒ»Ì×ÉÏÍøÐÐΪ¹ÜÀíϵͳ¡£ÓÉÓÚÆäϵͳ´æÔÚ©¶´£¬¹¥»÷Õ߿ɽṹ¶ñÒâpayload£¬Ö´ÐжñÒâÃüÁîÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Ruby_conversions.rb_Ruby´úÂëÖ´ÐÐ[CVE-2013-0156]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë½øÐй¥»÷£»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢²¿Êð¡¢Î¬»¤webÓ¦Ó÷¨Ê½±äµÃ¼òµ¥µÄ¿ò¼Ü¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÐÅϢй¶_J2EE-WEB-INFÅäÖÃÎļþ_Ãô¸ÐÐÅϢй¶

Äþ¾²ÀàÐÍ£º

CGI¹¥»÷

ʼþÃèÊö:

/WEB-INF/web.xml£ºWebÓ¦Ó÷¨Ê½ÅäÖÃÎļþ£¬ÃèÊöÁËservletºÍÆäËûµÄÓ¦ÓÃ×é¼þÅäÖü°ÃüÃû¹æÔò¡£/WEB-INF/classes/£º°üÂÞËùÓеÄServletÀàºÍÆäËûÀàÎļþ£¬ÀàÎļþËùÔÚµÄĿ¼½á¹¹ÓëËûÃǵİüÃû³ÆÆ¥Åä¡£/WEB-INF/lib/£º´æ·ÅwebÓ¦ÓÃÐèÒªµÄÖÖÖÖJARÎļþ£¬·ÅÖýöÔÚÕâ¸öÓ¦ÓÃÖÐÒªÇóʹÓõÄjarÎļþ,ÈçÊý¾Ý¿âÇý¶¯jarÎļþ/WEB-INF/src/£ºÔ´ÂëĿ¼£¬Æ¾¾Ý°üÃû½á¹¹·ÅÖø÷¸öjavaÎļþ¡£/WEB-INF/database.properties£ºÊý¾Ý¿âÅäÖÃÎļþ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÐÅϢй¶_Redis_infoÃô¸ÐÐÅÏ¢»ØÏÔ_»ØÏÔÀÖ³É

Äþ¾²ÀàÐÍ£º

CGI¹¥»÷

ʼþÃèÊö:

¼ì²âµ½Ô´IPÉ豸ʹÓÃredisµÄinfoÃüÁî̽²âµ±Ç°Ä¿µÄÖ÷»úÉϵÄRedisÊÇ·ñ´æÔÚδÊÚȨ·ÃÎÊ©¶´£»¹¥»÷ÕßÔÚδÊÚȨ·ÃÎÊRedisµÄÇé¿öÏ£¬ÀûÓÃRedis×ÔÉíµÄÌṩµÄconfigÃüÁ¿ÉÒÔ½øÐÐдÎļþ²Ù×÷£¬¹¥»÷Õß¿ÉÒÔÀֳɽ«×Ô¼ºµÄssh¹«Ô¿Ð´ÈëÄ¿±ê·þÎñÆ÷µÄ/root/.sshÎļþ¼ÐµÄauthotrized_keysÎļþÖУ¬½ø¶ø¿ÉÒÔʹÓöÔӦ˽Կֱ½ÓʹÓÃssh·þÎñµÇ¼Ŀ±ê·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JMX-RMI_´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

JMX£¨JavaManagementExtensions£¬¼´Java¹ÜÀíÀ©Õ¹£©ÊÇÒ»¸öΪӦÓ÷¨Ê½¡¢É豸¡¢ÏµÍ³µÈÖ²Èë¹ÜÀí¹¦Ð§µÄ¿ò¼Ü¡£ÔÚJMX¶Ë¿Ú¶ÔÍ⿪·Åʱ£¬¹¥»÷Õß¿ÉÒÔͨ¹ýMlet¼ÓÔØÒ»¸öÔ¶³Ì·þÎñÆ÷ÉϵĶñÒâMBean£¬´Ó¶øÖ´ÐжñÒâ´úÂë»ñÈ¡Ä¿±êÖ÷»úµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Cloud_Netflix_SSRF·þÎñ¶ËÇëÇóαÔì

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSpring_Cloud_NetflixµÄorigin²ÎÊý½«ÇëÇó·¢Ë͵½²»Ó¦¹ûÈ»¹ûÈ»µÄÆäËû·þÎñÆ÷¡£SpringCloudNetflixͨ¹ý×Ô¶¯ÅäÖúͰ󶨵½SpringEnvironmentºÍÆäËûSpring±à³ÌÄ£ÐÍÏ°¹ßÓ÷¨£¬ÎªSpringBootÓ¦Ó÷¨Ê½ÌṩNetflixOSS¼¯³É¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

TCP_ÌáÈ¡¹¥»÷_FlaskÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ä¿Ç°Ä¿µÄÖ÷»úÉϵÄFlask·þÎñÔÚ¿ª·ÅÁËÌí¼Ó·Óɹ¦Ð§µÄÇé¿öÏ£¬Êܵ½×¢Èë´úÂëÖ´Ðй¥»÷¡£FlaskÊÇÒ»¸öʹÓÃPython±àдµÄÇáÁ¿¼¶WebÓ¦Óÿò¼Ü¡£ÆäWSGI¹¤¾ßÏä½ÓÄÉWerkzeug£¬Ä£°åÒýÇæÔòʹÓÃJinja2¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Bitsadmin_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍBitsadmin¿ÉÒÉÃüÁʵÑé¿ØÖÆÄ¿µÄIPÖ÷»ú´´½¨ÉÏ´«»òÕßÏÂÔØÈÎÎñ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_IBOS-4.5.4_ÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

IBOSµÍÓÚ4.5.5µÄ°æ±¾´æÔÚºǫ́ÃüÁîÖ´ÐЩ¶´£¬¹¥»÷ÕßÔڵǼºó¿ÉÒÔͨ¹ýÊý¾Ý¿â±¸·Ý¹¦Ð§Ö´ÐÐÈÎÒâϵͳÃüÁ¿ØÖÆϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_IBOS_ºǫ́Êý¾Ý¿â_ÎļþÉÏ´«

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÏòIBOSµÄÎļþÉÏ´«Â©¶´£¬ÉÏ´«ÈÎÒâÎļþ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÐÅϢй¶_Weblogic-Server_Ãô¸ÐÐÅϢй¶[CVE-2022-21371]

Äþ¾²ÀàÐÍ£º

CGI¹¥»÷

ʼþÃèÊö:

OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚÔÆ»·¾³ºÍ´«Í³»·¾³µÄÓ¦Ó÷þÎñÖмä¼þ£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬Ö§³ÖÓ¦Óôӿª·¢µ½Éú²úµÄÕû¸öÉúÃüÖÜÆÚ¹ÜÀí£¬²¢¼ò»¯ÁËÓ¦ÓõIJ¿ÊðºÍ¹ÜÀí¡£OracleWebLogicServer´æÔÚ·¾¶±éÀú©¶´£¬¸Ã©¶´Ô´ÓÚWebContainer×é¼þÖв»ÕýÈ·µÄÊäÈëÑéÖ¤¡£¹¥»÷Õß¿ÉÀûÓø鶴·ÃÎÊÃô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_º£¿µÍþÊÓHIKVISIONÁ÷ýÌå¹ÜÀí·þÎñÆ÷_Îļþ¶ÁÈ¡[CNVD-2021-14544]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

º£¿µÍþÊÓÊÇÒÔÊÓƵΪºËÐĵÄÖÇÄÜÎïÁªÍø½â¾ö·½°¸ºÍ´óÊý¾Ý·þÎñÌṩÉÌ¡£ÆäÁ÷ýÌå¹ÜÀí·þÎñÆ÷´æÔÚÈõ¿ÚÁ´ºÍÈÎÒâÎļþ¶Áȡ©¶´£¬¹¥»÷Õß¿ÉÀûÓø鶴»ñÈ¡ÈÎÒâÎļþÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20220719


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

·¢ÏÖÃô¸ÐÎļþÏÂÔØÐÐΪ£¬ÈçÏÂÔر¸·ÝÎļþ£¬·¨Ê½Ô´Â룬SQLÎļþ£¬ÅäÖÃÎļþµÈÕâÀàÐÐΪ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Java_Shellcodeµ±µØ½ø³Ì×¢Èë

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú½øÐÐJavaµ±µØ½ø³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄpayload£¬Ê¹ÓöñÒâÀà½øÐнø³Ì×¢ÈëÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂ룬»ñȡϵͳ¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Alibaba_Nacos_δÊÚȨ·ÃÎÊ[CVE-2021-29441]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

AlibabaNacos´æÔÚÒ»¸öÓÉÓÚ²»Í×´¦Öõ¼ÖµÄδÊÚȨ·ÃÎÊ©¶´¡£Í¨¹ý¸Ã©¶´£¬¹¥»÷Õß¿ÉÒÔ½øÐÐÈÎÒâ²Ù×÷£¬°üÂÞ´´½¨ÐÂÓû§²¢½øÐеǼºó²Ù×÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬ÔËÐк󣬿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬ÈçºóÃŵÈ¡£

¸üÐÂʱ¼ä£º

20220719

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_fastjson_1.2.68_·´ÐòÁл¯_´úÂëÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬ÊÔͼͨ¹ý´«È뾫ÐĽṹµÄ¶ñÒâ´úÂë»òÃüÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£fastjsonÔÚ1.2.68ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣÄþ¾²Â©¶´¡£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ£¬Èç¹û±àд²»Í×£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐЩ¶´¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£ÊµÑé½øÐжñÒâÃüÁî»ò´úÂë×¢È룬Զ³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SangforEDR_v3.2.21ÒÔÏÂ_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÄþ¾²½â¾ö·½°¸¡£´Ë²úÎï´æÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´£¬Î´¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬¿ÉÒÔÔì³ÉÔ¶³ÌÖ´ÐÐÃüÁîµÄºó¹û¡£

¸üÐÂʱ¼ä£º

20220719

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring-Data-Commons×é¼þ_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-1273]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_Spring_Data_Commons×é¼þÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¹¥»÷Õ߿ɽṹ°üÂÞÓжñÒâ´úÂëµÄSPEL±í´ïʽʵÏÖÔ¶³Ì´úÂë¹¥»÷£¬Ö±½Ó»ñÈ¡·þÎñÆ÷¿ØÖÆȨÏÞ¡£SpringDataÊÇÒ»¸öÓÃÓÚ¼ò»¯Êý¾Ý¿â·ÃÎÊ£¬²¢Ö§³ÖÔÆ·þÎñµÄ¿ªÔ´¿ò¼Ü,°üÂÞCommons¡¢Gemfire¡¢JPA¡¢JDBC¡¢MongoDBµÈÄ£¿é¡£´Ë©¶´·¢ÉúÓÚSpringDataCommons×é¼þ£¬¸Ã×é¼þΪÌṩ¹²ÏíµÄ»ù´¡¿ò¼Ü£¬Êʺϸ÷¸ö×ÓÏîĿʹÓã¬Ö§³Ö¿çÊý¾Ý¿â³Ö¾Ã»¯¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Weblogic_wls-wsat_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-3506/10271]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»úÌᳫWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷µÄÐÐΪ¡£OracleWeblogicServerÊÇÓ¦Ó÷¨Ê½·þÎñÆ÷¡£OracleWeblogicServer10.3.6.0¡¢12.2.1.2¡¢12.2.1.1¡¢12.1.3.0°æ±¾´æÔڸ鶴¡£WeblogicWLS×é¼þÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐÈÎÒâÃüÁî¡£¹¥»÷ÕßÏòWeblogic·þÎñÆ÷·¢Ë;«ÐĽṹµÄHTTP¶ñÒâÇëÇ󣬹¥»÷ÀֳɿÉÒÔ»ñÈ¡µ½·þÎñÆ÷µÄWebshell£¬½øÒ»²½¿ÉÒÔ»ñµÃÄ¿±ê·þÎñÆ÷µÄ¿ØÖÆȨ¡£ÊµÑéÀûÓÃWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐЩ¶´¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220719


ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_Solr_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2019-17558][CNNVD-201912-1225]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃApacheSolrVelocityResponseWriterÔ¶³Ì´úÂëÖ´ÐЩ¶´¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£ApacheSolrÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇ棩µÄËÑË÷·þÎñÆ÷¡£¸Ã²úÎïÖ§³Ö²ãÃæËÑË÷¡¢´¹Ö±ËÑË÷¡¢¸ßÁÁÏÔʾËÑË÷½á¹ûµÈ¡£ApacheSolr5.0.0°æ±¾ÖÁ8.3.1°æ±¾ÖдæÔÚÊäÈëÑéÖ¤´íÎ󩶴¡£¸Ã©¶´Ô´ÓÚÍøÂçϵͳ»ò²úÎïδ¶ÔÊäÈëµÄÊý¾Ý½øÐÐÕýÈ·µÄÑéÖ¤¡£¹¥»÷ÕßÏòÍøÕ¾·¢Ë;«ÐĽṹµÄ¹¥»÷payload£¬¹¥»÷ÀֳɿÉÒÔÔ¶³ÌÖ´ÐÐÈÎÒâÃüÁ½ø¶ø¿ØÖÆ·þÎñÆ÷¡£ÊµÑé½øÐÐÈÎÒâÎļþ¶ÁÈ¡£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20220719