ÿÖÜÉý¼¶²¼¸æ-2022-01-18

°ä²¼¹¦·ò 2022-01-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£

¸üй¦·ò£º£º

20220118


 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_DedeCMSV6.0.3_article_string_mix.php_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬£¬ÓµÓкÜÇ¿µÄ¿ÉÀ©´óÐÔ£¬£¬²¢ÇÒÆëȫʢ¿ªÔ´´úÂë¡£¡£Æäºó¶Üarticle_string_mix.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬¹¥»÷Õß¿ÉÀûÓô˷ì϶Äõ½Ö¸±êÖ÷»úȨÏÞ¡£¡£

¸üй¦·ò£º£º

20220118

 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_À¶ÁèOA_admin.do_JNDIÔ¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

Àö½­ÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬¶ÁÈ¡ÅäÖÃÎļþµÃµ½ÃÜÔ¿ºó½Ó¼ûadmin.do¼´¿ÉÀûÓÃJNDIÔ¶³ÌºÅÁîÖ´ÐлñȡȨÏÞ¡£¡£

¸üй¦·ò£º£º

20220118


 

ÊÂÎñÃû³Æ£º£º

TCP_ľÂíºóÃÅ_Pupy_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Óɺڿ͹¤¾ßPupyÌìÉúµÄhttpÔ¶¿ØºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£¡£Ö´Ðк󣬣¬¹¥»÷Õß¿ÉÆëÈ«½ÚÖÆ±»Ö²Èë»úе£¬£¬²¢½øÐкáÏòÒÆ¶¯¡£¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¡¢¶àÖ°ÄÜÔ¶¿ØºóÃźͺóÉøÈ빤¾ß¡£¡£ËüÓµÓÐall-in-memoryÖ´ÐÐÖ°ÄÜ£¬£¬Õ¼Óÿռ伫¶ÈС¡£¡£PupyÄܹ»Ê¹ÓöàÖÖ·½Ê½½øÐÐͨѶ£¬£¬Ê¹Ó÷´Éä×¢ÈëǨáãµ½¹ý³ÌÖУ¬£¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢¡¢python°üºÍpythonC-extensions¡£¡£

¸üй¦·ò£º£º

20220118


 

ÊÂÎñÃû³Æ£º£º

HTTP_°²È«·ì϶_Zhone-Technologies-zNID-GPON-2426A_ºÅÁîÖ´ÐÐ[CVE-2014-9118][CNNVD-201510-721]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

ZhoneTechnologieszNIDGPON2426AÊÇÃÀ¹úZhoneTechnologies¹«Ë¾µÄÒ»¿î·ÓÉÆ÷¡£¡£webadministrativeportalÊÇÆäÖеÄÒ»¸öWebÖÎÀíÔ±½ÚÖÆÌ¨·¨Ê½¡£¡£ZhoneTechnologieszNIDGPON2426AS3.0.501֮ǰ°æ±¾µÄWebÖÎÀíÔ±½ÚÖÆÌ¨ÖдæÔÚ°²È«·ì϶¡£¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòzhnping.cmdÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®ipAddr¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£¡£

¸üй¦·ò£º£º

20220118