ÿÖÜÉý¼¶²¼¸æ-2022-07-19

°ä²¼¹¦·ò 2022-07-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º£º£º

TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_ÏνÓ_1

°²È«ÀàÐÍ£º£º£º

ÆäËûÊÂÎñ

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíAvzhan¡£¡£AvzhanÊÇÒ»¸öºóÃÅ£¬£¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö÷ÕÅÖ÷»úÌáÒéDDoS¹¥»÷¡£¡£»¹Äܹ»ÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¶ÔÖ¸¶¨Ö÷ÕÅÖ÷»úÌáÒéDDoS¹¥»÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Apache_OFBiz_rmi·´ÐòÁл¯·ì϶[CVE-2021-26295][CNNVD-202103-1262]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ApacheOFBiz´æÔÚRMI·´ÐòÁл¯Ç°Ì¨ºÅÁîÖ´ÐУ¬£¬Î´¾­Éí·ÝÑéÖ¤¹¥»÷Õ߿ɻú¹Ø¶ñÒâÒªÇ󣬣¬´¥·¢·´ÐòÁл¯£¬£¬´Ó¶øÔì³ÉËÁÒâ´úÂëÖ´ÐУ¬£¬½ÚÀñ·þÎñÆ÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_¿ÉÒÉÐÐΪ_̽²âphpÔ¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö:

¼ì²âµ½Ö÷»úÕýÔÚÏòÖ÷ÕÅIP·¢ËÍ̽²âphpÔ¶³ÌºÅÁîÖ´ÐеÄÒªÇ󡣡£´Ë¹¥»÷¶àΪ·ì϶ɨÃèÆ÷²úÉú¡£¡£

¸üй¦·ò£º£º£º

20220719

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐÕýÈ·ËãÕÊÓû§ÌṩµÄ²ÎÊý£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSºÅÁî×¢ÈëµÄÓ°Ïì¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

TCP_ÌáȨ¹¥»÷_Spring-messaging_´úÂëÖ´ÐÐ[CVE-2018-1270]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃSpring¿ò¼ÜSpring-messagingÄ£¿£¿éÔ¶³Ì´úÂëÖ´Ðзì϶½øÐй¥»÷µÄÐÐΪ£¬£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶ִÐÐËÁÒâ´úÂë¡£¡£Spring¿ò¼ÜÊÇÒ»¸ö¿ªÔ´µÄÏîÄ¿£¬£¬ÊÇÒ»¸ö»ùÓÚIOCºÍAOPµÄ¹¹¼Ü¶à²ãJavaEEϵͳµÄ¿ò¼Ü¡£¡£Spring¿ò¼Üͨ¹ýspring-messageingÄ£¿£¿éºÍSTOMP´úÀí¶ÔÏóͨѶ£¬£¬spring-messageÄ£¿£¿éÖеÄDefaultSubscriptionRegistryÀಽÖèaddSubscriptionInternal´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶£¬£¬¹¥»÷ÕßÀûÓø÷ì϶Äܹ»Ö´ÐÐËÁÒâJava´úÂë¡£¡£³¢ÊÔÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º£º£º

20220719

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅTopApp-LB¸ºÔØÆ½ºâºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ÌìÈÚПºÔØÆ½ºâTopAPP-LB²úÆ·¾É°æ±¾ÔÚÖÎÀíÃæ´æÔÚºÅÁîÖ´Ðзì϶£¬£¬¾ßÌåΪÔÚÄܹ»½Ó¼ûÖÎÀíµÇÂ¼Ò³ÃæÇé¿öÏ£¬£¬¹¥»÷Õßͨ¹ý»ú¹Ø¶ñÒâÒªÇ󣬣¬ÀûÓÃϵͳµÄ´úÂëȱµã£¬£¬¿ÉÆ´½ÓÓйØ×Ö¶ÎÔì³ÉºÅÁîÖ´ÐС£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_SpamTitanÍø¹Øºó¶Ü´úÂëÖ´Ðзì϶[CVE-2020-11699][CNNVD-202009-1082]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

SpamTitanÍø¹ØÊÇÖ°ÄÜ׳´óµÄ·´À¬»øÓʼþÉ豸£¬£¬ËüÎªÍøÂçÖÎÀíÔ±ÌṩÁË¿í·ºµÄ¹¤¾ßÀ´½ÚÖÆÓʼþÁ÷²¢Ô¤·ÀÓк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£¡£ÓÉÓÚ´æÔÚ´úÂëȱµã£¬£¬¹¥»÷Õß¿Éͨ¹ý»ú¹Ø¶ñÒâpayload£¬£¬Ê¹µÃÖ¸±êÖ÷»úÖ´ÐжñÒâºÅÁî¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÉèÖÃȱµã_Zyxel-NBG2015Éí·ÝÑéÖ¤ÈÆ¹ý[CVE-2021-3297][CNNVD-202101-2231]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

ZyxelNBG2105´æÔÚÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬£¬ÊôÓÚÂß¼­/ÉèÖÃÃýÎ󣬣¬¹¥»÷ÕßÎÞÐèµÇ¼£¬£¬Äܹ»Ö±½Ó½Ó¼ûlogin_ok.htmÒ³Ãæ£¬£¬ÈƹýµÇÂ¼Ò³Ãæ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_gitlist-0.6.0_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

gitlistÊÇÒ»¿îʹÓÃPHP¿ª·¢µÄͼÐλ¯git²Ö¿â²é¿´¹¤¾ß¡£¡£ÔÚÆä0.6.0°æ±¾ÖУ¬£¬´æÔÚÒ»´¦ºÅÁî²ÎÊý×¢ÈëÎÊÌ⣬£¬Äܹ»µ¼ÖÂÔ¶³ÌºÅÁîÖ´Ðзì϶¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_GoAhead_c˵»°_ÎļþÉÏ´«[CVE-2021-42342][CNNVD-202110-1020]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

GoAheadÊÇÊÀ½çÉÏ×îÊÜ»¶Ó­µÄ΢ÐÍǶÈëʽWeb·þÎñÆ÷¡£¡£Ëü½á¹¹½ô´Õ ¡¢¡¢°²È«ÇÒÒ×ÓÚʹÓᣡ£GoAhead²¿ÊðÔÚÊýÒŲ́É豸ÖУ¬£¬ÊÇ×îСǶÈëʽÉ豸µÄÃÎÏëÑ¡Ôñ¡£¡£½üÈÕ±¬³öGoAhead´æÔÚRCE·ì϶£¬£¬·ì϶ԴÓÚÎļþÉÏ´«¹ýÂËÆ÷´¦ÖõIJ»È«£¬£¬µ±ÓëCGI´¦Ö÷¨Ê½Ò»Â·Ê¹ÓÃʱ£¬£¬¿ÉÓ°Ïì»·¾³±äÁ¿£¬£¬´Ó¶øÊµÏÖRCE

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_ÁÔÓ¥°²È«-½ðɽÖն˰²Õûϵͳ_upload.php_ËÁÒâÎļþÉÏ´«

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

µ±Ç°Ö÷»úÕýÔÚÔâ·ê½ðɽÖն˰²Õûϵͳupload.phpËÁÒâÎļþÉÏ´«·ì϶¹¥»÷£¬£¬ÎÞÈκιýÂ˵ÄÎļþÉÏ´«¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ½ÚÖÆÖ÷»ú¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Webmin-show.cgi_ºÅÁîÖ´ÐÐ[CVE-2012-2982][CNNVD-201209-215]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

WebminÊÇUnixϵͳÖÎÀíWeb½Ó¿Ú£¬£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§ ¡¢¡¢Apache ¡¢¡¢DNS ¡¢¡¢DNS ¡¢¡¢Îļþ¹²Ïí¼°ÆäËû¡£¡£Webmin1.590¼°¸üÔç°æ±¾µÄfile/show.cgiÄÚ´æÔÚ°²È«·ì϶£¬£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Í¨¹ýõè¾¶ÃûÄÚµÄÎÞЧ×Ö·ûÖ´ÐÐËÁÒâºÅÁî¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_Maccms8.x_ºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

Maccms8.x¼°ÒÔǰ°æ±¾ËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»ÑÏ£¬£¬¹¥»÷Õ߿ɻú¹Øpayload£¬£¬Ö±½ÓevalÖ´ÐÐPHPÓï¾ä£¬£¬ÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_×¢Èë¹¥»÷_Django_SQL×¢Èë[CVE-2022-34265][CNNVD-202207-347]

°²È«ÀàÐÍ£º£º£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö:

DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÀûÓÿò¼Ü¡£¡£Django´æÔÚÒ»¸öSQL×¢Èë·ì϶£¨CVE-2022-34265£©¡£¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14 ¡¢¡¢4.0.6֮ǰµÄ°æ±¾£©ÖУ¬£¬Äܹ»Í¨¹ý´«µÝ¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ£¬£¬ÈôÊÇÀûÓ÷¨Ê½ÔÚ½«ÕâЩ²ÎÊý´«µÝ¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»Óо­¹ýÊäÈë¹ýÂË»òתÒ壬£¬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£¡£Í¨¹ýÀûÓô˷ì϶£¬£¬µÚÈý·½Äܹ»ÏòÊý¾Ý¿â·¢ËͺÅÁîÒÔ½Ó¼ûδ¾­ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ľÂíºóÃÅ_PhpSpy-MysqlÊý¾Ý¿âÖÎÀí_Webshell½Ó¼û

°²È«ÀàÐÍ£º£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

Á÷Á¿Öмì²âµ½phpspyÖÎÀímysqlÊý¾Ý¿âµÄ²Ù×÷£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ½øÐÐÏνÓÐÐΪ¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£µ¥Ò»Ëµ£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬Ê±Ê±½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ¸éÖÃÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖУ¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚһ·¡£¡£¶øºó¹¥»÷Õß¾ÍÄܹ»ÓÃwebµÄ·½Ê½£¬£¬Í¨¹ý¸ÃľÂíºóÃŽÚÖÆÍøÕ¾·þÎñÆ÷£¬£¬Ô̺¬ÉÏ´«ÏÂÔØÎļþ ¡¢¡¢²é¿´Êý¾Ý¿â ¡¢¡¢Ö´ÐÐËÁÒⷨʽºÅÁîµÈ¡£¡£webshellÄܹ»´©Ô½·À»ðǽ£¬£¬ÓÉÓÚÓë±»½ÚÖÆµÄ·þÎñÆ÷»òÔ¶³ÌÖ÷»ú»¥»»µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Ú´«µÝµÄ£¬£¬Òò¶ø²»»á±»·À»ðǽÀ¹½Ø¡£¡£²¢ÇÒʹÓÃwebshellͨ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´³öÈëÇÖºÛ¼£¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

TCP_ľÂíºóÃÅ_AlmondRat(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½AlmondRatÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAlmondRat¡£¡£AlmondRatÊÇÂûÁ黨×éÖ¯ËùʹÓÃÁËÒ»¸öÇáÁ¿»¯ºóÃÅ£¬£¬»ùÓÚCSharp˵»°£¬£¬ÔËÐк󣬣¬Äܹ»ÆëÈ«½ÚÖÆ±»Ö²Èë»úе¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Advantech-iView-NetworkServlet_ºÅÁîÖ´ÐÐ[CVE-2022-2143][CNNVD-202206-2735]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

AdvantechiView5_7_04_6469°æ±¾Ç°´æÔÚºÅÁîÖ´Ðзì϶£¬£¬¹¥»÷ÕßÄܹ»ÔÚδµÇ¼µÄÇé¿öÏÂÀûÓúÅÁîÆ´½ÓдÈëwebshell£¬£¬»ñȡָ±êϵͳȨÏÞ

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_NetsysÓ²¼þÉ豸_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

NetsysÊÇÒ»Ì×ÉÏÍøÐÐΪÖÎÀíϵͳ¡£¡£ÓÉÓÚÆäϵͳ´æÔÚ·ì϶£¬£¬¹¥»÷Õ߿ɻú¹Ø¶ñÒâpayload£¬£¬Ö´ÐжñÒâºÅÁîÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Ruby_conversions.rb_Ruby´úÂëÖ´ÐÐ[CVE-2013-0156]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÏòÖ÷ÕÅÖ÷»úÉϵÄRuby»ú¹Ø¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë½øÐй¥»÷£»RubyonRailsÊÇÒ»¸öÄܹ»Ê¹¿ª·¢ ¡¢¡¢²¿Êð ¡¢¡¢ÊØ»¤webÀûÓ÷¨Ê½±äµÃµ¥Ò»µÄ¿ò¼Ü¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÐÅϢй¶_J2EE-WEB-INFÅäÖÃÎļþ_Ãô¸ÐÐÅϢй¶

°²È«ÀàÐÍ£º£º£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

/WEB-INF/web.xml£º£º£ºWebÀûÓ÷¨Ê½ÅäÖÃÎļþ£¬£¬ÃèÊöÁËservletºÍÆäËûµÄÀûÓÃ×é¼þÅäÖü°¶¨Ãû¹æ¶¨¡£¡£/WEB-INF/classes/£º£º£ºÔ̺¬ËùÓеÄServletÀàºÍÆäËûÀàÎļþ£¬£¬ÀàÎļþµØµãµÄĿ¼½á¹¹ÓëËûÃǵİüÃû³ÆÆ¥Åä¡£¡£/WEB-INF/lib/£º£º£º´æ·ÅwebÀûÓñØÒªµÄ¸÷ÀàJARÎļþ£¬£¬¸éÖýöÔÚÕâ¸öÀûÓÃÖÐÒªÇóʹÓõÄjarÎļþ,ÈçÊý¾Ý¿âÇý¶¯jarÎļþ/WEB-INF/src/£º£º£ºÔ´ÂëĿ¼£¬£¬ÒÀÕÕ°üÃû½á¹¹¸éÖø÷¸öjavaÎļþ¡£¡£/WEB-INF/database.properties£º£º£ºÊý¾Ý¿âÅäÖÃÎļþ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÐÅϢй¶_Redis_infoÃô¸ÐÐÅÏ¢»ØÏÔ_»ØÏԳɹ¦

°²È«ÀàÐÍ£º£º£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÉ豸ʹÓÃredisµÄinfoºÅÁî̽²âµ±Ç°Ö÷ÕÅÖ÷»úÉϵÄRedisÊÇ·ñ´æÔÚδÊÚȨ½Ó¼û·ì϶£»¹¥»÷ÕßÔÚδÊÚȨ½Ó¼ûRedisµÄÇé¿öÏ£¬£¬ÀûÓÃRedis×ÔÉíµÄÌṩµÄconfigºÅÁ£¬Äܹ»½øÐÐдÎļþ²Ù×÷£¬£¬¹¥»÷ÕßÄܹ»³É¹¦½«×Ô¼ºµÄssh¹«Ô¿Ð´ÈëÖ¸±ê·þÎñÆ÷µÄ/root/.sshÎļþ¼ÐµÄauthotrized_keysÎļþÖУ¬£¬½ø¶øÄܹ»Ê¹ÓöÔӦ˽Կֱ½ÓʹÓÃssh·þÎñµÇ¼ָ±ê·þÎñÆ÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

TCP_ÌáȨ¹¥»÷_JMX-RMI_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

JMX£¨JavaManagementExtensions£¬£¬¼´JavaÖÎÀíÀ©´ó£©ÊÇÒ»¸öΪÀûÓ÷¨Ê½ ¡¢¡¢É豸 ¡¢¡¢ÏµÍ³µÈÖ²ÈëÖÎÀíÖ°ÄܵĿò¼Ü¡£¡£ÔÚJMX¶Ë¿Ú¶ÔÍâÊ¢¿ªÊ±£¬£¬¹¥»÷ÕßÄܹ»Í¨¹ýMlet¼ÓÔØÒ»¸öÔ¶³Ì·þÎñÆ÷ÉϵĶñÒâMBean£¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë»ñȡָ±êÖ÷»úµÄȨÏÞ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Spring_Cloud_Netflix_SSRF·þÎñ¶ËÒªÇóαÔì

°²È«ÀàÐÍ£º£º£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃSpring_Cloud_NetflixµÄorigin²ÎÊý½«ÒªÇó·¢Ë͵½²»Ó¦¹«¿ª¹«¿ªµÄÆäËû·þÎñÆ÷¡£¡£SpringCloudNetflixͨ¹ý×Ô¶¯ÅäÖúͰ󶨵½SpringEnvironmentºÍÆäËûSpring±à³ÌÄ£ÐÍϰ¹ßÓ÷¨£¬£¬ÎªSpringBootÀûÓ÷¨Ê½ÌṩNetflixOSS¼¯³É¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

TCP_ÌáÈ¡¹¥»÷_FlaskÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¿Ç°Ö÷ÕÅÖ÷»úÉϵÄFlask·þÎñÔÚÊ¢¿ªÁËÔö³¤Â·ÓÉÖ°ÄܵÄÇé¿öÏ£¬£¬Êܵ½×¢Èë´úÂëÖ´Ðй¥»÷¡£¡£FlaskÊÇÒ»¸öʹÓÃPython±àдµÄÇáÁ¿¼¶WebÀûÓÿò¼Ü¡£¡£ÆäWSGI¹¤¾ßÏäѡȡWerkzeug£¬£¬Ä£°åÒýÇæÔòʹÓÃJinja2¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Bitsadmin_Ô¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÖ÷ÕÅIPÖ÷»ú·¢ËÍBitsadmin¿ÉÒɺÅÁ£¬³¢ÊÔ½ÚÖÆÖ÷ÕÅIPÖ÷»ú´´½¨ÉÏ´«»òÕßÏÂÔØ¹¤×÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_IBOS-4.5.4_ºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

IBOSµÍÓÚ4.5.5µÄ°æ±¾´æÔÚºó¶ÜºÅÁîÖ´Ðзì϶£¬£¬¹¥»÷ÕßÔڵǼºóÄܹ»Í¨¹ýÊý¾Ý¿â±¸·ÝÖ°ÄÜÖ´ÐÐËÁÒâϵͳºÅÁ£¬½ÚÖÆÏµÍ³È¨ÏÞ

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_IBOS_ºó¶ÜÊý¾Ý¿â_ÎļþÉÏ´«

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´ipÕýÔÚÏòIBOSµÄÎļþÉÏ´«·ì϶£¬£¬ÉÏ´«ËÁÒâÎļþ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÐÅϢй¶_Weblogic-Server_Ãô¸ÐÐÅϢй¶[CVE-2022-21371]

°²È«ÀàÐÍ£º£º£º

CGI¹¥»÷

ÊÂÎñÃèÊö:

OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îºÏÓÃÓÚÔÆ»·¾³ºÍ´«Í³»·¾³µÄÀûÓ÷þÎñÖÐÑë¼þ£¬£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬£¬Ö§³ÖÀûÓôӿª·¢µ½³ö²úµÄÕû¸öÐÔÃüÖÜÆÚÖÎÀí£¬£¬²¢¼ò»¯ÁËÀûÓõIJ¿ÊðºÍÖÎÀí¡£¡£OracleWebLogicServer´æÔÚõè¾¶±éÀú·ì϶£¬£¬¸Ã·ì϶ԴÓÚWebContainer×é¼þÖв»ÕýÈ·µÄÊäÈëÑéÖ¤¡£¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶½Ó¼ûÃô¸ÐÐÅÏ¢¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_º£¿£¿µÍþÊÓHIKVISIONÁ÷ýÌåÖÎÀí·þÎñÆ÷_Îļþ¶ÁÈ¡[CNVD-2021-14544]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

º£¿£¿µÍþÊÓÊÇÒÔÊÓÆµÎªÖ÷ÌâµÄÖÇÄÜÎïÁªÍø½â¾ö¹æ»®ºÍ´óÊý¾Ý·þÎñÌṩÉÌ¡£¡£ÆäÁ÷ýÌåÖÎÀí·þÎñÆ÷´æÔÚÈõ¿ÚÁî·ì϶ºÍËÁÒâÎļþ¶ÁÈ¡·ì϶£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡ËÁÒâÎļþÐÅÏ¢¡£¡£

¸üй¦·ò£º£º£º

20220719


Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º£º£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

·¢ÏÖÃô¸ÐÎļþÏÂÔØÐÐΪ£¬£¬ÈçÏÂÔØ±¸·ÝÎļþ£¬£¬·¨Ê½Ô´Â룬£¬SQLÎļþ£¬£¬ÅäÖÃÎļþµÈÕâÀàÐÐΪ¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

TCP_¿ÉÒÉÐÐΪ_Java_Shellcode±¾µØ¹ý³Ì×¢Èë

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃWindowsVirtualMachineÀàÖеÄenqueue²½Öè¶ÔÖ÷ÕÅÖ÷»ú½øÐÐJava±¾µØ¹ý³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄpayload£¬£¬Ê¹ÓöñÒâÀà½øÇ°¹ý³Ì×¢ÈëÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬£¬»ñȡϵͳ½ÚÖÆÈ¨¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Alibaba_Nacos_δÊÚȨ½Ó¼û[CVE-2021-29441]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

AlibabaNacos´æÔÚÒ»¸öÓÉÓÚ²»µ±´¦Öõ¼ÖµÄδÊÚȨ½Ó¼û·ì϶¡£¡£Í¨¹ý¸Ã·ì϶£¬£¬¹¥»÷ÕßÄܹ»½øÐÐËÁÒâ²Ù×÷£¬£¬Ô̺¬´´½¨ÐÂÓû§²¢½øÐеǼºó²Ù×÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÏνÓ

°²È«ÀàÐÍ£º£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö:

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬ÔËÐк󣬣¬Äܹ»ÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬ÈçºóÃŵÈ¡£¡£

¸üй¦·ò£º£º£º

20220719

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_fastjson_1.2.68_·´ÐòÁл¯_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ£¬£¬ÊÔͼͨ¹ý´«È뾫ÐÄ»ú¹ØµÄ¶ñÒâ´úÂë»òºÅÁîÀ´ÈëÇÖÖ÷ÕÅIPÖ÷»ú¡£¡£fastjsonÔÚ1.2.68ÒÔ¼°Ö®Ç°°æ±¾´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¡£¿£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ£¬£¬ÈôÊDZàд²»µ±£¬£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´Ðзì϶¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£³¢ÊÔ½øÐжñÒâºÅÁî»ò´úÂë×¢È룬£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_SangforEDR_v3.2.21ÒÔÏÂ_Ô¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÕÛ·þ¹«Ë¾ÌṩµÄÒ»Ì×Öն˰²È«½â¾ö¹æ»®¡£¡£´Ë²úÆ·´æÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶£¬£¬Î´¾­¹ýÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÒªÇó°ü£¬£¬Äܹ»Ôì³ÉÔ¶³ÌÖ´ÐкÅÁîµÄºó¹û¡£¡£

¸üй¦·ò£º£º£º

20220719

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Spring-Data-Commons×é¼þ_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-1273]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃHTTP_Spring_Data_Commons×é¼þÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£¡£¹¥»÷Õ߿ɻú¹ØÔ̺¬ÓжñÒâ´úÂëµÄSPEL±í°×ʽʵÏÖÔ¶³Ì´úÂë¹¥»÷£¬£¬Ö±½Ó»ñÈ¡·þÎñÆ÷½ÚÖÆÈ¨ÏÞ¡£¡£SpringDataÊÇÒ»¸öÓÃÓÚ¼ò»¯Êý¾Ý¿â½Ó¼û£¬£¬²¢Ö§³ÖÔÆ·þÎñµÄ¿ªÔ´¿ò¼Ü,Ô̺¬Commons ¡¢¡¢Gemfire ¡¢¡¢JPA ¡¢¡¢JDBC ¡¢¡¢MongoDBµÈÄ£¿£¿é¡£¡£´Ë·ì϶²úÉúÓÚSpringDataCommons×é¼þ£¬£¬¸Ã×é¼þΪÌṩ¹²ÏíµÄ»ù´¡¿ò¼Ü£¬£¬Êʺϸ÷¸ö×ÓÏîĿʹÓ㬣¬Ö§³Ö¿çÊý¾Ý¿âÓÆ¾Ã»¯¡£¡£¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Weblogic_wls-wsat_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-3506/10271]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÖ÷ÕÅIPµØÖ·Ö÷»úÌáÒéWeblogicwls-wsatÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷µÄÐÐΪ¡£¡£OracleWeblogicServerÊÇÀûÓ÷¨Ê½·þÎñÆ÷¡£¡£OracleWeblogicServer10.3.6.0 ¡¢¡¢12.2.1.2 ¡¢¡¢12.2.1.1 ¡¢¡¢12.1.3.0°æ±¾´æÔڸ÷ì϶¡£¡£WeblogicWLS×é¼þÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐËÁÒâºÅÁî¡£¡£¹¥»÷ÕßÏòWeblogic·þÎñÆ÷·¢Ë;«ÐÄ»ú¹ØµÄHTTP¶ñÒâÒªÇ󣬣¬¹¥»÷³É¹¦Äܹ»»ñÈ¡µ½·þÎñÆ÷µÄWebshell£¬£¬½øÒ»²½Äܹ»»ñµÃÖ¸±ê·þÎñÆ÷µÄ½ÚÖÆÈ¨¡£¡£³¢ÊÔÀûÓÃWeblogicwls-wsatÔ¶³Ì´úÂëÖ´Ðзì϶¹¥»÷¡£¡£

¸üй¦·ò£º£º£º

20220719


ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Apache_Solr_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-17558][CNNVD-201912-1225]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃApacheSolrVelocityResponseWriterÔ¶³Ì´úÂëÖ´Ðзì϶¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£ApacheSolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷·þÎñÆ÷¡£¡£¸Ã²úÆ·Ö§³Ö²ãÃæËÑË÷ ¡¢¡¢´¹Ö±ËÑË÷ ¡¢¡¢¸ßÁÁÏÔʾËÑË÷Á˾ֵÈ¡£¡£ApacheSolr5.0.0°æ±¾ÖÁ8.3.1°æ±¾ÖдæÔÚÊäÈëÑéÖ¤ÃýÎó·ì϶¡£¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úƷδ¶ÔÊäÈëµÄÊý¾Ý½øÐÐÕýÈ·µÄÑéÖ¤¡£¡£¹¥»÷ÕßÏòÍøÕ¾·¢Ë;«ÐÄ»ú¹ØµÄ¹¥»÷payload£¬£¬¹¥»÷³É¹¦Äܹ»Ô¶³ÌÖ´ÐÐËÁÒâºÅÁ£¬½ø¶ø½ÚÀñ·þÎñÆ÷¡£¡£³¢ÊÔ½øÐÐËÁÒâÎļþ¶ÁÈ¡£¡£¬£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£

¸üй¦·ò£º£º£º

20220719