ÿÖÜÉý¼¶Í¨¸æ-2022-07-19
Ðû²¼Ê±¼ä 2022-07-19ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_ÅþÁ¬_1 |
Çå¾²ÀàÐÍ£º | ÆäËûÊÂÎñ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíAvzhan¡£¡£¡£¡£AvzhanÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£»£»£»£»£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_OFBiz_rmi·´ÐòÁл¯Îó²î[CVE-2021-26295][CNNVD-202103-1262] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ApacheOFBiz±£´æRMI·´ÐòÁл¯Ç°Ì¨ÏÂÁîÖ´ÐУ¬£¬£¬£¬Î´¾Éí·ÝÑéÖ¤¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬´¥·¢·´ÐòÁл¯£¬£¬£¬£¬´Ó¶øÔì³Éí§Òâ´úÂëÖ´ÐУ¬£¬£¬£¬¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_̽²âphpÔ¶³ÌÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ö÷»úÕýÔÚÏòÄ¿µÄIP·¢ËÍ̽²âphpÔ¶³ÌÏÂÁîÖ´ÐеÄÇëÇ󡣡£¡£¡£´Ë¹¥»÷¶àΪÎó²îɨÃèÆ÷±¬·¢¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Apache-Airflow_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2022-24288][CNNVD-202202-1940] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ÔÚApacheAirflow2.2.4֮ǰµÄ°æ±¾ÖУ¬£¬£¬£¬Ò»Ð©Ê¾ÀýDAGûÓÐ׼ȷÕûÀíÓû§ÌṩµÄ²ÎÊý£¬£¬£¬£¬Ê¹ÆäÈÝÒ×Êܵ½À´×ÔWebUIµÄOSÏÂÁî×¢ÈëµÄÓ°Ïì¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Spring-messaging_´úÂëÖ´ÐÐ[CVE-2018-1270] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½ÊÔͼͨ¹ýʹÓÃSpring¿ò¼ÜSpring-messagingÄ£¿£¿£¿£¿éÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£Spring¿ò¼ÜÊÇÒ»¸ö¿ªÔ´µÄÏîÄ¿£¬£¬£¬£¬ÊÇÒ»¸ö»ùÓÚIOCºÍAOPµÄ¹¹¼Ü¶à²ãJavaEEϵͳµÄ¿ò¼Ü¡£¡£¡£¡£Spring¿ò¼Üͨ¹ýspring-messageingÄ£¿£¿£¿£¿éºÍSTOMPÊðÀí¹¤¾ßͨѶ£¬£¬£¬£¬spring-messageÄ£¿£¿£¿£¿éÖеÄDefaultSubscriptionRegistryÀàÒªÁìaddSubscriptionInternal±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔÖ´ÐÐí§ÒâJava´úÂë¡£¡£¡£¡£ÊµÑéÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_ÌìÈÚÐÅTopApp-LB¸ºÔØÆ½ºâÏÂÁîÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ÌìÈÚПºÔØÆ½ºâTopAPP-LB²úÆ·¾É°æ±¾ÔÚÖÎÀíÃæ±£´æÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬ÏêϸΪÔÚ¿ÉÒÔ»á¼ûÖÎÀíµÇÂ¼Ò³ÃæÇéÐÎÏ£¬£¬£¬£¬¹¥»÷Õßͨ¹ý½á¹¹¶ñÒâÇëÇ󣬣¬£¬£¬Ê¹ÓÃϵͳµÄ´úÂëȱÏÝ£¬£¬£¬£¬¿ÉÆ´½ÓÏà¹Ø×Ö¶ÎÔì³ÉÏÂÁîÖ´ÐС£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_SpamTitanÍø¹Øºǫ́´úÂëÖ´ÐÐÎó²î[CVE-2020-11699][CNNVD-202009-1082] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | SpamTitanÍø¹ØÊǹ¦Ð§Ç¿Ê¢µÄ·´À¬»øÓʼþ×°±¸£¬£¬£¬£¬ËüÎªÍøÂçÖÎÀíÔ±ÌṩÁËÆÕ±éµÄ¹¤¾ßÀ´¿ØÖÆÓʼþÁ÷²¢±ÜÃâÓк¦µÄµç×ÓÓʼþºÍ¶ñÒâÈí¼þ¡£¡£¡£¡£ÓÉÓÚ±£´æ´úÂëȱÏÝ£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayload£¬£¬£¬£¬Ê¹µÃÄ¿µÄÖ÷»úÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÉèÖÃȱÏÝ_Zyxel-NBG2015Éí·ÝÑéÖ¤ÈÆ¹ý[CVE-2021-3297][CNNVD-202101-2231] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ZyxelNBG2105±£´æÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬ÊôÓÚÂß¼/ÉèÖùýʧ£¬£¬£¬£¬¹¥»÷ÕßÎÞÐèµÇ¼£¬£¬£¬£¬¿ÉÒÔÖ±½Ó»á¼ûlogin_ok.htmÒ³Ãæ£¬£¬£¬£¬ÈƹýµÇÂ¼Ò³Ãæ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_gitlist-0.6.0_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | gitlistÊÇÒ»¿îʹÓÃPHP¿ª·¢µÄͼÐλ¯git¿ÍÕ»Éó²é¹¤¾ß¡£¡£¡£¡£ÔÚÆä0.6.0°æ±¾ÖУ¬£¬£¬£¬±£´æÒ»´¦ÏÂÁî²ÎÊý×¢ÈëÎÊÌ⣬£¬£¬£¬¿ÉÒÔµ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_GoAhead_cÓïÑÔ_ÎļþÉÏ´«[CVE-2021-42342][CNNVD-202110-1020] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | GoAheadÊÇÌìÏÂÉÏ×îÊܽӴýµÄ΢ÐÍǶÈëʽWebЧÀÍÆ÷¡£¡£¡£¡£Ëü½á¹¹½ô´Õ¡¢Çå¾²ÇÒÒ×ÓÚʹÓᣡ£¡£¡£GoAhead°²ÅÅÔÚÊýÒŲ́װ±¸ÖУ¬£¬£¬£¬ÊÇ×îСǶÈëʽװ±¸µÄÀíÏëÑ¡Ôñ¡£¡£¡£¡£¿ËÈÕ±¬³öGoAhead±£´æRCEÎó²î£¬£¬£¬£¬Îó²îÔ´ÓÚÎļþÉÏ´«¹ýÂËÆ÷´¦Öóͷ£µÄ²»È«£¬£¬£¬£¬µ±ÓëCGI´¦Öóͷ£³ÌÐòÒ»ÆðʹÓÃʱ£¬£¬£¬£¬¿ÉÓ°ÏìÇéÐαäÁ¿£¬£¬£¬£¬´Ó¶øÊµÏÖRCE |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_ÁÔÓ¥Çå¾²-½ðɽÖÕ¶ËÇ徲ϵͳ_upload.php_í§ÒâÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | Ä¿½ñÖ÷»úÕýÔÚÔâÊܽðɽÖÕ¶ËÇ徲ϵͳupload.phpí§ÒâÎļþÉÏ´«Îó²î¹¥»÷£¬£¬£¬£¬ÎÞÈκιýÂ˵ÄÎļþÉÏ´«¿Éµ¼ÖºڿÍÉÏ´«¶ñÒâÎļþ¿ØÖÆÖ÷»ú¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Webmin-show.cgi_ÏÂÁîÖ´ÐÐ[CVE-2012-2982][CNNVD-201209-215] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | WebminÊÇUnixϵͳÖÎÀíWeb½Ó¿Ú£¬£¬£¬£¬Í¨¹ýÈÎÒ»ä¯ÀÀÆ÷¶¼¿ÉÉèÖÃÓû§ÕË»§¡¢Apache¡¢DNS¡¢DNS¡¢Îļþ¹²Ïí¼°ÆäËû¡£¡£¡£¡£Webmin1.590¼°¸üÔç°æ±¾µÄfile/show.cgiÄÚ±£´æÇå¾²Îó²î£¬£¬£¬£¬¿ÉÔÊÐíͨ¹ýÉí·ÝÑéÖ¤µÄÔ¶³ÌÓû§Í¨¹ý·¾¶ÃûÄÚµÄÎÞЧ×Ö·ûÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Maccms8.x_ÏÂÁîÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | Maccms8.x¼°ÒÔǰ°æ±¾ËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»ÑÏ£¬£¬£¬£¬¹¥»÷Õ߿ɽṹpayload£¬£¬£¬£¬Ö±½ÓevalÖ´ÐÐPHPÓï¾ä£¬£¬£¬£¬ÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_×¢Èë¹¥»÷_Django_SQL×¢Èë[CVE-2022-34265][CNNVD-202207-347] |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò: | DjangoÊÇÒ»¸ö»ùÓÚPythonµÄ¿ªÔ´WebÓ¦Óÿò¼Ü¡£¡£¡£¡£Django±£´æÒ»¸öSQL×¢ÈëÎó²î£¨CVE-2022-34265£©¡£¡£¡£¡£ÔÚÊÜÓ°ÏìµÄDjango°æ±¾£¨3.2.14¡¢4.0.6֮ǰµÄ°æ±¾£©ÖУ¬£¬£¬£¬¿ÉÒÔͨ¹ýת´ï¶ñÒâÊý¾Ý×÷Ϊkind/lookup_nameµÄÖµ£¬£¬£¬£¬ÈôÊÇÓ¦ÓóÌÐòÔÚ½«ÕâЩ²ÎÊýת´ï¸øTrunc()ºÍExtract()Êý¾Ý¿âº¯Êý£¨ÈÕÆÚº¯Êý£©Ö®Ç°Ã»ÓоÓÉÊäÈë¹ýÂË»òתÒ壬£¬£¬£¬ÔòÈÝÒ×Êܵ½SQL×¢Èë¹¥»÷¡£¡£¡£¡£Í¨¹ýʹÓôËÎó²î£¬£¬£¬£¬µÚÈý·½¿ÉÒÔÏòÊý¾Ý¿â·¢ËÍÏÂÁîÒÔ»á¼ûδ¾ÊÚȨµÄÊý¾Ý»òɾ³ýÊý¾Ý¿âµÈ¶ñÒâÐÐΪ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_PhpSpy-MysqlÊý¾Ý¿âÖÎÀí_Webshell»á¼û |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | Á÷Á¿Öмì²âµ½phpspyÖÎÀímysqlÊý¾Ý¿âµÄ²Ù×÷£¬£¬£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_AlmondRat(ÂûÁ黨)_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ¼ì²âµ½AlmondRatÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAlmondRat¡£¡£¡£¡£AlmondRatÊÇÂûÁ黨×éÖ¯ËùʹÓÃÁËÒ»¸öÇáÁ¿»¯ºóÃÅ£¬£¬£¬£¬»ùÓÚCSharpÓïÑÔ£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Advantech-iView-NetworkServlet_ÏÂÁîÖ´ÐÐ[CVE-2022-2143][CNNVD-202206-2735] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | AdvantechiView5_7_04_6469°æ±¾Ç°±£´æÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδµÇ¼µÄÇéÐÎÏÂʹÓÃÏÂÁîÆ´½ÓдÈëwebshell£¬£¬£¬£¬»ñȡĿµÄϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_NetsysÓ²¼þ×°±¸_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | NetsysÊÇÒ»Ì×ÉÏÍøÐÐΪÖÎÀíϵͳ¡£¡£¡£¡£ÓÉÓÚÆäϵͳ±£´æÎó²î£¬£¬£¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâpayload£¬£¬£¬£¬Ö´ÐжñÒâÏÂÁîÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Ruby_conversions.rb_Ruby´úÂëÖ´ÐÐ[CVE-2013-0156] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚÏòÄ¿µÄÖ÷»úÉϵÄRuby½á¹¹¶ñÒâµÄXMLÍⲿʵÌå×¢Èë´úÂë¾ÙÐй¥»÷£»£»£»£»£»£»£»RubyonRailsÊÇÒ»¸ö¿ÉÒÔʹ¿ª·¢¡¢°²ÅÅ¡¢Î¬»¤webÓ¦ÓóÌÐò±äµÃ¼òÆÓµÄ¿ò¼Ü¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_J2EE-WEB-INFÉèÖÃÎļþ_Ãô¸ÐÐÅϢй¶ |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò: | /WEB-INF/web.xml£ºWebÓ¦ÓóÌÐòÉèÖÃÎļþ£¬£¬£¬£¬ÐÎòÁËservletºÍÆäËûµÄÓ¦ÓÃ×é¼þÉèÖü°ÃüÃû¹æÔò¡£¡£¡£¡£/WEB-INF/classes/£º°üÀ¨ËùÓеÄServletÀàºÍÆäËûÀàÎļþ£¬£¬£¬£¬ÀàÎļþËùÔÚµÄĿ¼½á¹¹ÓëËûÃǵİüÃû³ÆÆ¥Åä¡£¡£¡£¡£/WEB-INF/lib/£º´æ·ÅwebÓ¦ÓÃÐèÒªµÄÖÖÖÖJARÎļþ£¬£¬£¬£¬°²ÅŽöÔÚÕâ¸öÓ¦ÓÃÖÐÒªÇóʹÓõÄjarÎļþ,ÈçÊý¾Ý¿âÇý¶¯jarÎļþ/WEB-INF/src/£ºÔ´ÂëĿ¼£¬£¬£¬£¬Æ¾Ö¤°üÃû½á¹¹°²ÅŸ÷¸öjavaÎļþ¡£¡£¡£¡£/WEB-INF/database.properties£ºÊý¾Ý¿âÉèÖÃÎļþ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_Redis_infoÃô¸ÐÐÅÏ¢»ØÏÔ_»ØÏÔÀÖ³É |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IP×°±¸Ê¹ÓÃredisµÄinfoÏÂÁî̽²âÄ¿½ñÄ¿µÄÖ÷»úÉϵÄRedisÊÇ·ñ±£´æÎ´ÊÚȨ»á¼ûÎó²î£»£»£»£»£»£»£»¹¥»÷ÕßÔÚδÊÚȨ»á¼ûRedisµÄÇéÐÎÏ£¬£¬£¬£¬Ê¹ÓÃRedis×ÔÉíµÄÌṩµÄconfigÏÂÁ£¬£¬£¬¿ÉÒÔ¾ÙÐÐдÎļþ²Ù×÷£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÀֳɽ«×Ô¼ºµÄssh¹«Ô¿Ð´ÈëÄ¿µÄЧÀÍÆ÷µÄ/root/.sshÎļþ¼ÐµÄauthotrized_keysÎļþÖУ¬£¬£¬£¬½ø¶ø¿ÉÒÔʹÓöÔӦ˽Կֱ½ÓʹÓÃsshЧÀ͵ǼĿµÄЧÀÍÆ÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_JMX-RMI_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | JMX£¨JavaManagementExtensions£¬£¬£¬£¬¼´JavaÖÎÀíÀ©Õ¹£©ÊÇÒ»¸öΪӦÓóÌÐò¡¢×°±¸¡¢ÏµÍ³µÈÖ²ÈëÖÎÀí¹¦Ð§µÄ¿ò¼Ü¡£¡£¡£¡£ÔÚJMX¶Ë¿Ú¶ÔÍ⿪·Åʱ£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýMlet¼ÓÔØÒ»¸öÔ¶³ÌЧÀÍÆ÷ÉϵĶñÒâMBean£¬£¬£¬£¬´Ó¶øÖ´ÐжñÒâ´úÂë»ñȡĿµÄÖ÷»úµÄȨÏÞ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Spring_Cloud_Netflix_SSRFЧÀͶËÇëÇóαÔì |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃSpring_Cloud_NetflixµÄorigin²ÎÊý½«ÇëÇó·¢Ë͵½²»Ó¦¹ûÕæ¹ûÕæµÄÆäËûЧÀÍÆ÷¡£¡£¡£¡£SpringCloudNetflixͨ¹ý×Ô¶¯ÉèÖúͰ󶨵½SpringEnvironmentºÍÆäËûSpring±à³ÌÄ£×ÓϰϰÓ÷¨£¬£¬£¬£¬ÎªSpringBootÓ¦ÓóÌÐòÌṩNetflixOSS¼¯³É¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | TCP_ÌáÈ¡¹¥»÷_FlaskÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½ÏÖÔÚÄ¿µÄÖ÷»úÉϵÄFlaskЧÀÍÔÚ¿ª·ÅÁËÌí¼Ó·Óɹ¦Ð§µÄÇéÐÎÏ£¬£¬£¬£¬Êܵ½×¢Èë´úÂëÖ´Ðй¥»÷¡£¡£¡£¡£FlaskÊÇÒ»¸öʹÓÃPython±àдµÄÇáÁ¿¼¶WebÓ¦Óÿò¼Ü¡£¡£¡£¡£ÆäWSGI¹¤¾ßÏä½ÓÄÉWerkzeug£¬£¬£¬£¬Ä£°åÒýÇæÔòʹÓÃJinja2¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Bitsadmin_Ô¶³ÌÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍBitsadmin¿ÉÒÉÏÂÁ£¬£¬£¬ÊµÑé¿ØÖÆÄ¿µÄIPÖ÷»ú½¨ÉèÉÏ´«»òÕßÏÂÔØÊ¹Ãü¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_IBOS-4.5.4_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | IBOSµÍÓÚ4.5.5µÄ°æ±¾±£´æºǫ́ÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬¹¥»÷ÕßÔڵǼºó¿ÉÒÔͨ¹ýÊý¾Ý¿â±¸·Ý¹¦Ð§Ö´ÐÐí§ÒâϵͳÏÂÁ£¬£¬£¬¿ØÖÆÏµÍ³È¨ÏÞ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_IBOS_ºǫ́Êý¾Ý¿â_ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚÏòIBOSµÄÎļþÉÏ´«Îó²î£¬£¬£¬£¬ÉÏ´«í§ÒâÎļþ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_Weblogic-Server_Ãô¸ÐÐÅϢй¶[CVE-2022-21371] |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò: | OracleWebLogicServerÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»¿îÊÊÓÃÓÚÔÆÇéÐκ͹ŰåÇéÐεÄÓ¦ÓÃЧÀÍÖÐÐļþ£¬£¬£¬£¬ËüÌṩÁËÒ»¸öÏÖ´úÇáÐÍ¿ª·¢Æ½Ì¨£¬£¬£¬£¬Ö§³ÖÓ¦Óôӿª·¢µ½Éú²úµÄÕû¸öÉúÃüÖÜÆÚÖÎÀí£¬£¬£¬£¬²¢¼ò»¯ÁËÓ¦Óõİ²ÅźÍÖÎÀí¡£¡£¡£¡£OracleWebLogicServer±£´æÂ·¾¶±éÀúÎó²î£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚWebContainer×é¼þÖв»×¼È·µÄÊäÈëÑéÖ¤¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÃô¸ÐÐÅÏ¢¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_º£¿£¿£¿£¿µÍþÊÓHIKVISIONÁ÷ýÌåÖÎÀíЧÀÍÆ÷_Îļþ¶ÁÈ¡[CNVD-2021-14544] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | º£¿£¿£¿£¿µÍþÊÓÊÇÒÔÊÓÆµÎª½¹µãµÄÖÇÄÜÎïÁªÍø½â¾ö¼Æ»®ºÍ´óÊý¾ÝЧÀÍÌṩÉÌ¡£¡£¡£¡£ÆäÁ÷ýÌåÖÎÀíЧÀÍÆ÷±£´æÈõ¿ÚÁîÎó²îºÍí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡í§ÒâÎļþÐÅÏ¢¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉÃô¸ÐÎļþÏÂÔØ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ·¢Ã÷Ãô¸ÐÎļþÏÂÔØÐÐΪ£¬£¬£¬£¬ÈçÏÂÔØ±¸·ÝÎļþ£¬£¬£¬£¬³ÌÐòÔ´Â룬£¬£¬£¬SQLÎļþ£¬£¬£¬£¬ÉèÖÃÎļþµÈÕâÀàÐÐΪ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_Java_ShellcodeÍâµØÀú³Ì×¢Èë |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃWindowsVirtualMachineÀàÖеÄenqueueÒªÁì¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐJavaÍâµØÀú³Ì×¢Èë¹¥»÷µÄÐÐΪ¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄpayload£¬£¬£¬£¬Ê¹ÓöñÒâÀà¾ÙÐÐÀú³Ì×¢ÈëÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬£¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Alibaba_Nacos_δÊÚȨ»á¼û[CVE-2021-29441] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | AlibabaNacos±£´æÒ»¸öÓÉÓÚ²»µ±´¦Öóͷ£µ¼ÖµÄδÊÚȨ»á¼ûÎó²î¡£¡£¡£¡£Í¨¹ý¸ÃÎó²î£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ¾ÙÐÐí§Òâ²Ù×÷£¬£¬£¬£¬°üÀ¨½¨ÉèÐÂÓû§²¢¾ÙÐеǼºó²Ù×÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_MuuyDownLoader(ÂûÁ黨)_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuuyDownLoader¡£¡£¡£¡£MuuyDownLoaderÊÇAPT×éÖ¯ÂûÁ黨ËùʹÓõÄÒ»¸öÏÂÔØÕߣ¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬¿ÉÒÔÏÂÔØÆäËü¶ñÒâÑù±¾£¬£¬£¬£¬ÈçºóÃŵȡ£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_fastjson_1.2.68_·´ÐòÁл¯_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃfastjsonJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬£¬£¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£¡£¡£¡£fastjsonÔÚ1.2.68ÒÔ¼°Ö®Ç°°æ±¾±£´æÔ¶³Ì´úÂëÖ´ÐиßΣÇå¾²Îó²î¡£¡£¡£¡£¿£¿£¿£¿ª·¢ÕßÔÚʹÓÃfastjsonʱ£¬£¬£¬£¬ÈôÊDZàд²»µ±£¬£¬£¬£¬¿ÉÄܵ¼ÖÂJSON·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸öÈ«ÐĽṹµÄJSONÐòÁл¯¶ñÒâ´úÂ룬£¬£¬£¬µ±³ÌÐòÖ´ÐÐJSON·´ÐòÁл¯µÄÀú³ÌÖÐÖ´ÐжñÒâ´úÂ룬£¬£¬£¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£ÊµÑé¾ÙÐжñÒâÏÂÁî»ò´úÂë×¢È룬£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_SangforEDR_v3.2.21ÒÔÏÂ_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | SangforÖն˼ì²âÏìӦƽ̨£¨EDR£©ÊÇÉîÐÅ·þ¹«Ë¾ÌṩµÄÒ»Ì×ÖÕ¶ËÇå¾²½â¾ö¼Æ»®¡£¡£¡£¡£´Ë²úÆ·±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬Î´¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆÇëÇó°ü£¬£¬£¬£¬¿ÉÒÔÔì³ÉÔ¶³ÌÖ´ÐÐÏÂÁîµÄЧ¹û¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Spring-Data-Commons×é¼þ_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2018-1273] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Spring_Data_Commons×é¼þÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¹¥»÷Õ߿ɽṹ°üÀ¨ÓжñÒâ´úÂëµÄSPEL±í´ïʽʵÏÖÔ¶³Ì´úÂë¹¥»÷£¬£¬£¬£¬Ö±½Ó»ñȡЧÀÍÆ÷¿ØÖÆÈ¨ÏÞ¡£¡£¡£¡£SpringDataÊÇÒ»¸öÓÃÓÚ¼ò»¯Êý¾Ý¿â»á¼û£¬£¬£¬£¬²¢Ö§³ÖÔÆÐ§À͵ĿªÔ´¿ò¼Ü,°üÀ¨Commons¡¢Gemfire¡¢JPA¡¢JDBC¡¢MongoDBµÈÄ£¿£¿£¿£¿é¡£¡£¡£¡£´ËÎó²î±¬·¢ÓÚSpringDataCommons×é¼þ£¬£¬£¬£¬¸Ã×é¼þΪÌṩ¹²ÏíµÄ»ù´¡¿ò¼Ü£¬£¬£¬£¬Êʺϸ÷¸ö×ÓÏîĿʹÓ㬣¬£¬£¬Ö§³Ö¿çÊý¾Ý¿â³¤ÆÚ»¯¡£¡£¡£¡£¹¥»÷Àֳɣ¬£¬£¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Weblogic_wls-wsat_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-3506/10271] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÌᳫWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷µÄÐÐΪ¡£¡£¡£¡£OracleWeblogicServerÊÇÓ¦ÓóÌÐòЧÀÍÆ÷¡£¡£¡£¡£OracleWeblogicServer10.3.6.0¡¢12.2.1.2¡¢12.2.1.1¡¢12.1.3.0°æ±¾±£´æ¸ÃÎó²î¡£¡£¡£¡£WeblogicWLS×é¼þÔÊÐíÔ¶³Ì¹¥»÷ÕßÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¹¥»÷ÕßÏòWeblogicЧÀÍÆ÷·¢ËÍÈ«ÐĽṹµÄHTTP¶ñÒâÇëÇ󣬣¬£¬£¬¹¥»÷ÀֳɿÉÒÔ»ñÈ¡µ½Ð§ÀÍÆ÷µÄWebshell£¬£¬£¬£¬½øÒ»²½¿ÉÒÔ»ñµÃÄ¿µÄЧÀÍÆ÷µÄ¿ØÖÆÈ¨¡£¡£¡£¡£ÊµÑéʹÓÃWeblogicwls-wsatÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache_Solr_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-17558][CNNVD-201912-1225] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApacheSolrVelocityResponseWriterÔ¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£ApacheSolrÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿î»ùÓÚLucene£¨Ò»¿îÈ«ÎÄËÑË÷ÒýÇæ£©µÄËÑË÷ЧÀÍÆ÷¡£¡£¡£¡£¸Ã²úÆ·Ö§³Ö²ãÃæËÑË÷¡¢±ÊÖ±ËÑË÷¡¢¸ßÁÁÏÔʾËÑË÷Ч¹ûµÈ¡£¡£¡£¡£ApacheSolr5.0.0°æ±¾ÖÁ8.3.1°æ±¾Öб£´æÊäÈëÑéÖ¤¹ýʧÎó²î¡£¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδ¶ÔÊäÈëµÄÊý¾Ý¾ÙÐÐ׼ȷµÄÑéÖ¤¡£¡£¡£¡£¹¥»÷ÕßÏòÍøÕ¾·¢ËÍÈ«ÐĽṹµÄ¹¥»÷payload£¬£¬£¬£¬¹¥»÷ÀֳɿÉÒÔÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬½ø¶ø¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£ÊµÑé¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡£¬£¬£¬£¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220719 |


¾©¹«Íø°²±¸11010802024551ºÅ