ÿÖÜÉý¼¶²¼¸æ-2023-01-17

°ä²¼¹¦·ò 2023-01-17
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Hashicorp_Consul_Service_API_Ô¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃConsulÖдæÔÚµÄÔ¶³ÌºÅÁîÖ´Ðзì϶½øÐй¥»÷¡ £¡£ConsulÊÇHashiCorp¹«Ë¾ÍƳöµÄÒ»¿î¿ªÔ´¹¤¾ß£¬£¬ÓÃÓÚʵÏÖÉ¢²¼Ê½ÏµÍ³µÄ·þÎñ·¢ÏÖÓëÅäÖá £¡£ÔÚÆôÓÃÁ˾籾²é³­²ÎÊý£¨-enable-script-checks£©µÄConsulËùÓа汾ÖУ¬£¬¶ñÒâ¹¥»÷ÕßÄܹ»Í¨¹ý·¢Ë;«ÐÄ»ú¹ØµÄHTTPÒªÇóÔÚδ¾­ÊÚȨµÄÇé¿öÏÂÔÚConsul·þÎñ¶ËÔ¶³ÌÖ´ÐкÅÁî¡ £¡£

¸üй¦·ò£º

20230117

 

ÊÂÎñÃû³Æ£º

DNS_½©Ê¬ÍøÂç_Fodcha_ÏνÓ

°²È«ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÏòdns·þÎñÆ÷ÒªÇó½âÎöÆäC&C·þÎñÆ÷¡ £¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡ £¡£FodchaÖØÒªÍ¨¹ýNDay·ì϶ºÍTelnet/SSHÈõ¿ÚÁî´«²¼£¬£¬Ô̺¬CVE-2021-22205¡¢¡¢CVE-2021-35394¡¢¡¢AndroidADBDebugServerRCE¡¢¡¢LILINDVRRCEµÈ·ì϶¡ £¡£ÖðÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊýÍÆËãÒѳ¬¹ý1Íò£¬£¬ÇÒÖðÈÕ»áÕë¶Ô³¬¹ý100¸ö¹¥»÷Ö¸±êÌáÒéDDoS¹¥»÷£¬£¬¹¥»÷·Ç³£»£»£»îÔ¾¡ £¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨѶÊý¾Ý¡ £¡£

¸üй¦·ò£º

20230117

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαºÍ̸

°²È«ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·â×°ºÍ̸£¬£¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬£¬»òÔ¶³ÌÖ´ÐкÅÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷£¬£¬´Ó¶ø»ñȡָ±êϵͳȨÏÞ¡ £¡£

¸üй¦·ò£º

20230117

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡ £¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡ £¡£

¸üй¦·ò£º

20230117

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_ÈôÒÀCMS_Ô¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ÈôÒÀºó¶ÜÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄÌåʽ£¬£¬¿ÉÓÃÓÚJava¶ÔÏóµÄÐòÁл¯¡¢¡¢·´ÐòÁл¯¡ £¡£ÓÉÓÚÈôÒÀºó¶Ü´òË㹤×÷´¦£¬£¬¶ÔÓÚ´«ÈëµÄ"ŲÓÃÖ¸±ê×Ö·û´®"ûÓÐÈκÎУÑ飬£¬µ¼Ö¹¥»÷ÕßÄܹ»»ú¹ØpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡ £¡£

¸üй¦·ò£º

20230117