2020-06-23

Ðû²¼Ê±¼ä 2020-06-24

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Exchange_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0688]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýExchangeÓʼþЧÀÍÆ÷Ô¶³ÌÖ´ÐÐÏÂÁîÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£Îó²îÔµ¹ÊÔ­ÓÉÊÇExchangeЧÀÍÆ÷ÔÚ×°ÖÃʱûÓÐ׼ȷ½¨ÉèΨһµÄ¼ÓÃÜÃÜÔ¿¡£¡£¡£¡£µ¼Ö¾­ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýExchangeĬÈÏ¿ªÆôµÄWebÒ³ÃæµÇ¼£¬£¬£¬£¬£¬£¬£¬·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕÆ­Ä¿µÄЧÀÍÆ÷·´ÐòÁл¯¶ñÒ⽨ÉèµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬À´µÖ´ïÔÚÄ¿µÄЧÀÍÆ÷ÉÏÒÔ SYSTEM Éí·ÝÖ´ÐÐí§Òâ.net´úÂëµÄÄ¿µÄ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623











ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓúÜÊÇÆÕ±éµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£¡£¡£¡£Öйú²Ëµ¶ÓÃ;ʮ·ÖÆÕ±é,Ö§³Ö¶àÖÖÓïÑÔ,СÇÉÊÊÓ㬣¬£¬£¬£¬£¬£¬¾ßÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ¼ä¿ÉÒÔÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÐéÄâÖն˵ȹ¦Ð§¡£¡£¡£¡£¹ØÓÚÕâÀàÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÈôÊÇûÓдó×ÚµÄÐÞ¸ÄЧÀͶ˾籾´úÂ룬£¬£¬£¬£¬£¬£¬Æä·µ»ØÁ÷Á¿¶¼»áÓÐһЩ³£¼ûµÄÌØÕ÷£¬£¬£¬£¬£¬£¬£¬±¾Ìõ¹æÔò½«³£¼ûµÄÅäºÏÌØÕ÷ÌáÈ¡³öÀ´¾ÙÐзÀÓùÐÔ±¨¾¯¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØÕ÷£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ£´æÎ󱨣¬£¬£¬£¬£¬£¬£¬Çë²Î¿¼ÌØÕ÷ÐÔ×ÓÅжÏ×ֶξÙÐÐÅжÏ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623












ÊÂÎñÃû³Æ£º

DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623







ÊÂÎñÃû³Æ£º

HTTP_svnÃô¸ÐÎļþ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐHTTP_svnÃô¸ÐÎļþ»á¼û¡£¡£¡£¡£

SvnÊdz£¼ûµÄ°æ±¾¿ØÖƹ¤¾ß£¬£¬£¬£¬£¬£¬£¬ÔÚ¹ýʧÉèÖõÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬svnÃô¸ÐÎļþ̻¶ÔÚWEB·¾¶ÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ý»á¼ûsvnÎļþ£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔ»ñÈ¡ÍøÕ¾Ô´ÂëµÈÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623









ÊÂÎñÃû³Æ£º

HTTP_Nexus_Repository_Manager_3Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-7238]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýNexus Repository Manager 3´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£

Nexus Repository Manager 3ÓÉÓÚ»á¼û¿ØÖÆÈ±·¦£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃȱÏÝ½á¹¹ÌØ¶¨µÄÇëÇóÔÚЧÀÍÆ÷ÉÏδÊÚȨִÐÐJava´úÂ룬£¬£¬£¬£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£¡£¡£¡£

Îó²î±£´æµÄ°æ±¾£º

Nexus Repository Manager OSS/Pro 3.x - 3.14.0

¸üÐÂʱ¼ä£º

20200623












ÊÂÎñÃû³Æ£º

HTTP_JBOSS_·´ÐòÁл¯_ÏÂÁîÖ´ÐÐÎó²î[CVE-2017-12149]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶Ô¿ÉÄܱ£´æÎó²î(CVE-2017-12149)µÄÒ³ÃæÊµÑé¹¥»÷

Ó°ÏìJBossAS 5.x/6.x °æ±¾¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623








ÊÂÎñÃû³Æ£º

TCP_RDPÔ¶³Ì×ÀÃæµÇ¼¿ÚÁîÇî¾Ù

Çå¾²ÀàÐÍ£º

Çî¾Ù̽²â

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÔ¶³Ì×ÀÃæµÇ¼¿ÚÁî²Â½âµÄÐÐΪ¡£¡£¡£¡£

Ô¶³Ì×ÀÃæÅþÁ¬×é¼þÊÇ´ÓWindows 2000 Server×îÏÈÓÉ΢Èí¹«Ë¾ÌṩµÄ£¬£¬£¬£¬£¬£¬£¬ÔÚWINDOWS 2000 SERVERÖÐËû²»ÊÇĬÈÏ×°ÖõÄ¡£¡£¡£¡£¸Ã×é¼þÒ»¾­ÍƳöÊܵ½ÁËÐí¶àÓû§µÄÓµ»¤ºÍϲ»¶£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇÔÚWINDOWS     WINDOWS2003¿ªÆôÒªÁìºÍXPÀàËÆ£¬£¬£¬£¬£¬£¬£¬Í¬Ñù¶Ô²Ù×÷°ì·¨¾ÙÐÐÁ˼ò»¯¡£¡£¡£¡£ÒªÁìÈçÏ£º

µÚÒ»²½£ºÔÚ×ÀÃæ¡°ÎҵĵçÄÔ¡±ÉϵãÊó±êÓÒ¼ü£¬£¬£¬£¬£¬£¬£¬Ñ¡Ôñ¡°ÊôÐÔ¡±¡£¡£¡£¡£XPºÍ2003ÖÐ΢Èí¹«Ë¾½«¸Ã×é¼þµÄÆôÓÃÒªÁì¾ÙÐÐÁËˢУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇͨ¹ý¼òÆÓµÄ¹´Ñ¡¾Í¿ÉÒÔÍê³ÉÔÚXPºÍ2003ÏÂÔ¶³Ì×ÀÃæÅþÁ¬¹¦Ð§µÄ¿ªÆô¡£¡£¡£¡£ÈôÊÇÄ¿µÄÖ÷»ú¿ªÆôÁËÔ¶³ÌÖÕ¶ËЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ä¬È϶˿ÚÊÇ3389£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¶à´ÎʵÑéÓû§ÃûºÍÃÜÂëµÄ·½·¨À´²Â½âÓû§¿ÚÁ£¬£¬£¬£¬£¬£¬ÈôÊDZ»ÁÏÖй¥»÷Õ߾ͿÉÒÔ»ñÊÊÄ¿½ñÓû§µÄËùÓÐȨÏÞ£¬£¬£¬£¬£¬£¬£¬½ø¶øÓÐÓпÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£¡£¡£¡£

µÚ¶þ²½£ºÔÚµ¯³öµÄϵͳÊôÐÔ´°¿ÚÖÐÑ¡Ôñ¡°Ô¶³Ì¡±±êÇ©¡£¡£¡£¡£

µÚÈý²½£ºÔÚÔ¶³Ì±êÇ©ÖÐÕÒµ½¡°Ô¶³Ì×ÀÃæ¡±£¬£¬£¬£¬£¬£¬£¬ÔÚ¡°ÔÊÐíÓû§ÅþÁ¬µ½Õą̂ÅÌËã»ú¡±Ç°¶Ô¹´È¥µôºóÈ·¶¨¼´¿ÉÍê³ÉÔ¶³Ì×ÀÃæÅþÁ¬¹¦Ð§µÄ¹Ø±Õ¡£¡£¡£¡£

¿ÚÁîÇî¾Ù̽²âÀàÊÂÎñ½ç˵Ϊ£ºÔÚÔ´IPµØµãÓëÄ¿µÄIPµØµãÏàͬµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Í³¼Æµ¥Î»Ê±¼äÄڵǼʧ°ÜµÄ´ÎÊý£¬£¬£¬£¬£¬£¬£¬Ä¬ÒÔΪһ·ÖÖÓÄڵǼʧ°ÜµÄ´ÎÊýÁè¼Ý20´Î£¬£¬£¬£¬£¬£¬£¬¾Í»á´¥·¢¿ÚÁîÇî¾ÙÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµÄĬÈÏÐж¯ÊÇ×è¶ÏÔ´µØµã¡£¡£¡£¡£ÐèÌØÊâ˵Ã÷µÄÊÇ£¬£¬£¬£¬£¬£¬£¬ÈôIPS»òWAF×°±¸´®Ðа²ÅÅÔÚÆôÓÃNAT(Network Address Translation£¬£¬£¬£¬£¬£¬£¬ÍøÂçµØµãת»»)µÄÍøÂçÇéÐÎÖУ¬£¬£¬£¬£¬£¬£¬¶à¸öÕæÊµµÄÔ´IP¿ÉÄܱ»×ª»»³ÉÒ»¸öÔ´IP£¬£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬¶à¸öÓû§µÄÕý³£Éϰ¶Ê§°ÜʵÑéÒ²¿ÉÄܻᴥ·¢¿ÚÁîÇî¾Ù̽²âÊÂÎñ£¬£¬£¬£¬£¬£¬£¬´Ëʱ¿ÉÒÔ˼Á¿½«¸ÃÊÂÎñµÄĬÈÏÏìÓ¦Ðж¯ÐÞ¸ÄΪͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÒÔÃâÓ°ÏìÕý³£ÓªÒµ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623



























ÊÂÎñÃû³Æ£º

HTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9546/9547/9548]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623








ÊÂÎñÃû³Æ£º

TCP_MS_RDPÔ¶³Ì×ÀÃæ_½¨ÉèµÍÇå¾²ÐÔÅþÁ¬

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¿µÄIPÖ÷»úÒѾ­ÔÞ³ÉÒÔµÍÓÚCreedSSPµÄÇ徲ЭÒéÓëÔ´IPÖ÷»úµÄÔ¶³Ì×ÀÃæ¾ÙÐÐÅþÁ¬¡£¡£¡£¡£ÓÉÓڵͰ汾µÄÔ¶³Ì×ÀÃæÇå¾²ÐԽϵͣ¬£¬£¬£¬£¬£¬£¬ÅþÁ¬¿ÉÄܱ£´æÒ»¶¨Çå¾²Òþ»¼¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200623