ÿÖÜÉý¼¶²¼¸æ-2021-12-14
°ä²¼¹¦·ò 2021-12-15ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º£º | TCP_ºóÃÅ_9002.Rat_APT_¹¥»÷ |
°²È«ÀàÐÍ£º£º | Ô¶¿ØºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£9002.RatÊÇÕýÔÚ»îÔ¾µÄAPTs(AdvancedPersistentThreats)¹¥»÷£¬£¬ÄÑÒÔ¼ì²â£¬£¬ÇÒ¼«¶ÈÓÐÕë¶ÔÐÔ¡£¡£¡£ÖØÒªÊÇÀûÓÃʱÏÂÊ¢Ðеķì϶´«²¼£¬£¬ÈçCVE-2013-1347¡¢¡¢CVE-2013-2423¡¢¡¢CVE-2013-1493µÈ¡£¡£¡£·¢ÏÖÓÐÉÏ´«Óû§Îļþ£¬£¬Ô¶³ÌÖ´ÐкÅÁîµÈÖ°ÄÜ¡£¡£¡£¹¥»÷Õß¿ÉÔ¶³Ì½ÚÖÆ±»¿Ø¶ËÖ÷»ú×ö¸÷Àà²Ù×÷¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_D_Link_ºÅÁî×¢Èë·ì϶ |
°²È«ÀàÐÍ£º£º | Âß¼/Éè¼ÆÃýÎó |
ÊÂÎñÃèÊö£º£º | D-LinkÒ»¼Ò³ö²úÍøÂçÓ²¼þºÍÈí¼þ²úÆ·µÄÆóÒµ£¬£¬ÖØÒª²úÆ·Óл¥»»»ú¡¢¡¢ÎÞÏß²úÆ·¡¢¡¢¿í´ø²úÆ·¡¢¡¢Íø¿¨¡¢¡¢Â·ÓÉÆ÷¡¢¡¢ÍøÂçÉãÏñ»úºÍÍøÂ簲ȫ²úÆ·(·À»ðǽ)µÈ¡£¡£¡£D-Link´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏò/getcfg.php·¢ËÍÔ̺¬¶ñÒâºÅÁîµÄÒªÇ󣬣¬´Ó¶øÊµÏÖÔ¶³ÌËÁÒâºÅÁîÖ´ÐÐ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | TCP_ºóÃÅ_Rotajakiro.Oceanlotus(º£Á«»¨)_ÏÎ½Ó |
°²È«ÀàÐÍ£º£º | ÆäËûºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅRotajakiro¡£¡£¡£RotajakiroÒÉËÆÊÇAPT×éÖ¯º£Á«»¨ËùµÄʹÓúóÃÅ£¬£¬Ö°Äܼ«¶È׳´ó£¬£¬ÔËÐкóÄܹ»ÆëÈ«½ÚÖÆ±»Ï°È¾»úе¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | TCP_ºáÏòÒÆ¶¯_PsexecÎļþдÈë |
°²È«ÀàÐÍ£º£º | ÆäËûºóÃÅ |
ÊÂÎñÃèÊö£º£º | PsExecÊÇÒ»¸öÇáÁ¿¼¶µÄtelnet´úÌæ¹¤¾ß£¬£¬ËüʹÄúÎÞÐèÊÖ¶¯×°Öÿͻ§¶ËÈí¼þ¼´¿ÉÖ´ÐÐÆäËûϵͳÉϵĹý³Ì£¬£¬²¢ÇÒÄܹ»»ñµÃÓëºÅÁî½ÚÖÆÌ¨ÏÕЩһÑùµÄʵʱ½»»¥ÐÔ¡£¡£¡£PsExec×î׳´óµÄÖ°ÄܾÍÊÇÔÚÔ¶³ÌϵͳºÍÔ¶³ÌÖ§³Ö¹¤¾ß(Èçipconfig¡¢¡¢whoami)ÖÐÆô¶¯½»»¥Ê½ºÅÁîÌáÐÑ´°¿Ú£¬£¬ÒÔ±ãÏÔʾÎÞ·¨Í¨¹ýÆäËû·½Ê½ÏÔʾµÄÓйØÔ¶³ÌϵͳµÄÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Citrix_SD-WAN_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-8271][CNNVD-202011-1336] |
°²È«ÀàÐÍ£º£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | CitrixSD-WANÊÇÓÉÃÀ¹úCitrix¹«Ë¾¿ª·¢µÄÒ»Ì×¹ãÓòÍø¼¯ÖÐÖÎÀíϵͳ£¬£¬Í¨¹ýÐé¹¹»¯¼¼ÊõʵÏÖÆóÒµ¼¶µÄ°²È«¹ãÓòÍø£¬£¬×ÛºÏÀûÓöàÌõÁ´Â·£¬£¬ÊµÏÖ¸ºÔØÆ½ºâ£¬£¬²¢ÄÜÅäÖᢡ¢¼à¿ØºÍ·ÖÎöWANÉϵÄËùÓÐCitrixSD-WANÉ豸¡£¡£¡£CitrixSD-WANͨ¹ýurlÆ¥ÅäʵÏÖÉí·ÝÑéÖ¤£¬£¬µ«¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâurlʹµÃApache½âÎöµÄurlºÍCakePHP´«ÈëµÄurl²»Ò»Ö£¬£¬´Ó¶øÈƹý¿Í»§¶ËÖ¤Êé²é³£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Redmine_ºÅÁîÖ´ÐÐ[CVE-2011-4929][CNNVD-201210-082] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | RedmineÊÇÒ»Ì׿ªÔ´µÄ»ùÓÚWebµÄÏîÄ¿ÖÎÀíºÍȱµã¸ú×Ù¹¤¾ß¡£¡£¡£¸Ã¹¤¾ßÌṩÏîÄ¿ÖÎÀí¡¢¡¢ÎÊÌâ¸ú×ٺͻùÓÚ½ÇÉ«µÄ½Ó¼û½ÚÖÆµÈÖ°ÄÜ¡£¡£¡£Redmine0.9.x°æ±¾ºÍ1.0.5֮ǰµÄ1.0.x°æ±¾ÖеÄbazaar¿âÊÊÅäÆ÷ÖдæÔÚδÃ÷·ì϶¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýδ֪ÏòÁ¿Ö´ÐÐËÁÒâºÅÁî¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Barracuda-Spam-Firewall-img.pl_Ô¶³ÌºÅÁîÖ´ÐÐ[CVE-2005-2847][CNNVD-200509-075] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | BarracudaSpamFirewallÊÇÓÃÓÚ±£»¤Óʼþ·þÎñÆ÷µÄ¼¯³ÉÓ²¼þºÍÈí¼þÀ¬»øÓʼþ½â¾ö¹æ»®¡£¡£¡£BarracudaSpamFirewallÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¡£¡£img.pl¾ç±¾ÔÚÓû§¶ÁÈ¡ÍêÎļþ»áÊÔͼ¶Ï¿ªÎļþ¡£¡£¡£ÔÚ/cgi-bin/img.pl¾ç±¾ÖУº£ºmy$file_img=\"/tmp/\".CGI£º£º£º£ºparam(\'\'f\'\');open(IMG£¬£¬$file_img)ordie\"Couldnotopenimagebecause£º£º$!£Ün\";...unlink($file_img);perlopenº¯Êý»¹Äܹ»ÓÃÓÚÖ´ÐкÅÁî¡£¡£¡£ÈôÊÇ×Ö·û´®ÒÔ\"|\"ʵÏֵϰ£¬£¬¾ç±¾¾Í»áÖ´ÐкÅÁî¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_VINGA_ºÅÁîÖ´Ðзì϶[CVE-2021-43469][CNNVD-202112-350] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | VINGAWR-N300U77.102.1.4853ÊÜgoahead×é¼þÓ°Ï죬£¬´æÔÚÒ»´¦ºÅÁîÖ´Ðзì϶¡£¡£¡£¸Ã·ì϶ԴÓÚ¶Ô´«ÈëµÄhost²ÎÊý¹ýÂ˲»ÑϽ÷£¬£¬µ¼Ö¹¥»÷ÕßÄܹ»×¢Èë¶ñÒâºÅÁîʵÏÖÔ¶³ÌºÅÁîÖ´ÐС£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_¿ÉÒÉÐÐΪ_tcp_socketŲÓà |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ³¢ÊÔÔÚÖ÷ÕÅÖ÷»ú½øÐÐtcp_socketŲÓ㬣¬¿ÉÄÜΪºÅÁî×¢Èë¹¥»÷¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_Quest_KACE_Systems_ManagementºÅÁîÖ´Ðзì϶[CVE-2018-11138][CNNVD-201805-1216] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÉ豸ÀûÓÃQuest_KACE_Systems_ManagementºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£¡£¡£QuestKACEϵͳÖÎÀíÉ豸8.0.318download_agent_installer.phpÎļþÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÒÔWeb·þÎñÆ÷Óû§wwwµÄÉí·ÝÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´® |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£¡£¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£ |
¸üй¦·ò£º£º | 20211214 |
ÊÂÎñÃû³Æ£º£º | TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´® |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£¡£¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£ |
¸üй¦·ò£º£º | 20211214 |


¾©¹«Íø°²±¸11010802024551ºÅ