ÿÖÜÉý¼¶Í¨¸æ-2022-07-23

Ðû²¼Ê±¼ä 2022-07-23

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Mida_Solutions_eFramework_2.8.9_²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2020-15922][CNNVD-202007-1515]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2020-15922Îó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷¡£¡£¡£¡£MidaSolutionseFrameworkÊÇÒâ´óÀûMidaSolutions¹«Ë¾µÄÒ»Ì×ͳһͨѶºÍЭ×÷ЧÀÍÌ×¼þ¡£¡£¡£¡£MidaSolutionseFramework2.9.0°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐдúÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCЭÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý1(XMR)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCЭÒéÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃЭÒé¡£¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬ £¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬ £¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£¡£ÃÅÂÞ±ÒÓ¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCЭÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(XMR)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCЭÒéÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃЭÒé¡£¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬ £¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬ £¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£¡£ÃÅÂÞ±ÒÓ¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÒÔÌ«·»JSON-RPCЭÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý1(ETH)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCЭÒéÒÉËÆÅ²ÓÃÁËÒÔÌ«·»ÍÚ¿óAPIº¯Êý¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃЭÒé¡£¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬ £¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖÎÞ״̬ÇáÁ¿¼¶Ô¶³ÌÀú³ÌŲÓã¨RPC£©Ð­Ò飬£¬ £¬£¬£¬£¬£¬¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬ £¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£¡£ÒÔÌ«·»Ó¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëETH½Úµã½»»¥¡£¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÍÚ¿óľÂí_CoinMiner_ÒÔÌ«·»JSON-RPCЭÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(ETH)

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCЭÒéÒÉËÆÅ²ÓÃÁËÒÔÌ«·»ÍÚ¿óAPIº¯Êý¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃЭÒé¡£¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¬£¬ £¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£¡£JSON-RPCÊÇÒ»ÖÖÎÞ״̬ÇáÁ¿¼¶Ô¶³ÌÀú³ÌŲÓã¨RPC£©Ð­Ò飬£¬ £¬£¬£¬£¬£¬¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬ £¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£¡£ÒÔÌ«·»Ó¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹صÄ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëETH½Úµã½»»¥¡£¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Webmine¼Ò×å_ÍøÒ³ÍÚ¿óľÂí_Ö´ÐÐä¯ÀÀÆ÷ÍÚ¿ó

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÍøÒ³ÖаüÀ¨ÍÚ¿ó¾ç±¾´úÂë¡£¡£¡£¡£WebmineÒ²ÊÇÒ»¸öÓëCoinhiveÀàËÆµÄJSÍÚ¿óÒýÇæ£¬£¬ £¬£¬£¬£¬£¬ÔÚÓлá¼ûÁ¿µÄÍøÕ¾ÖÐǶÈëÒ»¶ÎÍøÒ³ÍÚ¿ó´úÂ룬£¬ £¬£¬£¬£¬£¬Ê¹Ó÷ÿ͵ÄÅÌËã»úCPU×ÊÔ´À´ÍÚ¾òÊý×ÖÇ®±Ò¾ÙÐÐIJÀû¡£¡£¡£¡£ÍÚ¿ó¾ç±¾Ö´ÐлáÕ¼ÓÃCPU×ÊÔ´£¬£¬ £¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Jenkins-Git-client²å¼þ_´úÂëÖ´ÐÐ[CVE-2019-10392][CNNVD-201909-632]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Ä¿½ñÖ÷»úÕýÔÚÔâÊÜJenkins-Git-client²å¼þ_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ó°Ïì¹æÄ£GitclientPlugin<=2.8.4

¸üÐÂʱ¼ä£º

20220723



ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix-API-JSON-RPC_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ZabbixÊÇÒ»¸ö»ùÓÚWEB½çÃæµÄÂþÑÜʽϵͳ¼àÊÓÒÔ¼°ÍøÂç¼àÊӵįóÒµ¼¶¿ªÔ´½â¾ö¼Æ»®¡£¡£¡£¡£ZabbixÄܼàÊÓÖÖÖÖÍøÂç²ÎÊý£¬£¬ £¬£¬£¬£¬£¬°ü¹ÜЧÀÍÆ÷ϵͳµÄÇå¾²ÔËÓª£¬£¬ £¬£¬£¬£¬£¬²¢ÌṩÎÞаµÄ֪ͨ»úÖÆÒÔ±ãϵͳÖÎÀíÔ±¿ìËÙ¶¨Î»Ï¢Õù¾ö±£´æµÄÖÖÖÖÎÊÌâ¡£¡£¡£¡£ËüÓÉÁ½²¿·Ö×é³É£¬£¬ £¬£¬£¬£¬£¬ZabbixServerÓë¿ÉÑ¡×é¼þZabbixAgent¡£¡£¡£¡£Zabbixserver¿ÉÒÔͨ¹ýSNMP£¬£¬ £¬£¬£¬£¬£¬ZabbixAgent£¬£¬ £¬£¬£¬£¬£¬ping£¬£¬ £¬£¬£¬£¬£¬¶Ë¿Ú¼àÊÓµÈÒªÁìÌṩ¶ÔÔ¶³ÌЧÀÍÆ÷/ÍøÂç״̬µÄ¼àÊÓ£¬£¬ £¬£¬£¬£¬£¬Êý¾ÝÍøÂçµÈ¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬Ëü¿ÉÒÔÔËÐÐÔÚLinux£¬£¬ £¬£¬£¬£¬£¬Solaris£¬£¬ £¬£¬£¬£¬£¬HP-UX£¬£¬ £¬£¬£¬£¬£¬AIX£¬£¬ £¬£¬£¬£¬£¬FreeBSD£¬£¬ £¬£¬£¬£¬£¬OpenBSD£¬£¬ £¬£¬£¬£¬£¬OSXµÈƽ̨ÉÏ¡£¡£¡£¡£ÔÚÆäjsonrpc2.0°æ±¾±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý´ËÎó²î»ñȡЧÀÍÆ÷ȨÏÞ£¬£¬ £¬£¬£¬£¬£¬Î£º¦ÏµÍ³Çå¾²¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellÏÂÁî×¢Èë_¹¥»÷ʧ°Ü

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐBASH_·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶË£¬£¬ £¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£µ±Ö´ÐÐbash·´µ¯shellÏÂÁîÓÐÎóʱ£¬£¬ £¬£¬£¬£¬£¬»á·µ»Øbash:nojobcontrolinthisshell

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Tp-Link_´úÂëÖ´ÐÐ[CVE-2022-30075][CNNVD-202206-881]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÔÚTp-Link·ÓÉÆ÷ÖоÙÐÐÉí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬ £¬£¬£¬£¬£¬Í¨¹ýÉí·ÝÑéÖ¤ºó¿ÉʹÓñ¸·ÝÎļþ°üÀ¨¾ÙÐÐí§Òâ´úÂëÖ´ÐÐ

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_PHP_imap_ÏÂÁîÖ´ÐÐ[CVE-2018-19518][CNNVD-201811-666]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ÔÚPHPºÍÆäËû²úÆ·µÄimap_open£¨£©ÖÐʹÓõÄUNIXÉϵĻªÊ¢¶Ù´óѧIMAP¹¤¾ß°ü2007fÆô¶¯rshÏÂÁ½èÖúÓÚc-client/imap4r1.cÖеÄimap_rimapº¯ÊýºÍosdep/unix/tcp_unixÖеÄtcp_aopenº¯Êý.c£©£¬£¬ £¬£¬£¬£¬£¬¶ø²»»á×èÖ¹²ÎÊý×¢È룬£¬ £¬£¬£¬£¬£¬ÈôÊÇIMAPЧÀÍÆ÷Ãû³ÆÊDz»ÊÜÐÅÈεÄÊäÈ루ÀýÈ磬£¬ £¬£¬£¬£¬£¬ÓÉWebÓ¦ÓóÌÐòµÄÓû§ÊäÈ룩£¬£¬ £¬£¬£¬£¬£¬²¢ÇÒrshÒѱ»¾ßÓвî±ð²ÎÊýµÄ³ÌÐòÌæ»»£¬£¬ £¬£¬£¬£¬£¬ÔòÔ¶³Ì¹¥»÷Õß¿ÉÄÜ»áÖ´ÐÐí§ÒâOSÏÂÁîÓïÒå¡£¡£¡£¡£ÀýÈ磬£¬ £¬£¬£¬£¬£¬ÈôÊÇrshÊÇsshµÄÁ´½Ó£¨ÈçÔÚDebianºÍUbuntuϵͳÉÏ¿´µ½µÄ£©£¬£¬ £¬£¬£¬£¬£¬Ôò¹¥»÷¿ÉÒÔʹÓðüÀ¨¡°-oProxyCommand¡±²ÎÊýµÄIMAPЧÀÍÆ÷Ãû³Æ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_XML-dtdÍâÁ¬_ÆäËû×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò:

XXE(XMLExternalEntityInjection)XMLÍⲿʵÌå×¢È룬£¬ £¬£¬£¬£¬£¬XMLÊÇÒ»ÖÖÀàËÆÓÚHTML£¨³¬Îı¾±ê¼ÇÓïÑÔ£©µÄ¿ÉÀ©Õ¹±ê¼ÇÓïÑÔ£¬£¬ £¬£¬£¬£¬£¬ÊÇÓÃÓÚ±ê¼Çµç×ÓÎļþʹÆä¾ßÓнṹÐԵıê¼ÇÓïÑÔ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÓÃÀ´±ê¼ÇÊý¾Ý¡¢½ç˵Êý¾ÝÀàÐÍ£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»ÖÖÔÊÐíÓû§¶Ô×Ô¼ºµÄ±ê¼ÇÓïÑÔ¾ÙÐнç˵µÄÔ´ÓïÑÔ¡£¡£¡£¡£XMLÎĵµ½á¹¹°üÀ¨XMLÉùÃ÷¡¢DTDÎĵµÀàÐͽç˵£¨¿ÉÑ¡£¡£¡£¡£©¡¢ÎĵµÔªËØ¡£¡£¡£¡£µ±Ó¦ÓÃÊÇͨ¹ýÓû§ÉÏ´«µÄXMLÎļþ»òPOSTÇëÇó¾ÙÐÐÊý¾ÝµÄ´«Ê䣬£¬ £¬£¬£¬£¬£¬²¢ÇÒÓ¦ÓÃûÓÐեȡXMLÒýÓÃÍⲿʵÌ壬£¬ £¬£¬£¬£¬£¬Ò²Ã»ÓйýÂËÓû§Ìá½»µÄXMLÊý¾Ý£¬£¬ £¬£¬£¬£¬£¬ÄÇô¾Í»á±¬·¢XMLÍⲿʵÌå×¢ÈëÎó²î£¬£¬ £¬£¬£¬£¬£¬¼´XXEÎó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_PhpSpy2013-MysqlÊý¾Ý¿âÖÎÀí_Webshell»á¼û

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

Á÷Á¿Öмì²âµ½phpspy2013ÖÎÀímysqlÊý¾Ý¿âµÄ²Ù×÷£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬ £¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬ £¬£¬£¬£¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬ £¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬ £¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬ £¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ £¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_΢ÐÅĬÈÏ×Ô´øä¯ÀÀÆ÷-´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

΢ÐÅwindows°æ<3.1.2.141°æ±¾ÊÜchromev8ÒýÇæÎó²îÓ°Ï죬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâµÄ´¹ÂÚÓʼþ·¢Ë͸øÄ¿µÄÖ°Ô±£¬£¬ £¬£¬£¬£¬£¬Ä¿µÄÖ°Ô±ÓÃ΢ÐÅ×Ô´øä¯ÀÀÆ÷·­¿ªºóÔò»á´¥·¢Îó²î£¬£¬ £¬£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ØÖÆÄ¿µÄÖ°Ô±ÅÌËã»úȨÏÞ

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Iris-ID-IrisAccess-ICU-7000-2_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

IrisIDµÄIrisAccess7000-2ÊÇLGÉú²úµÄºçĤʶ±ðϵͳ¡£¡£¡£¡£ÓÉÓÚ¸Ãϵͳ±£´æÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayloadʹϵͳִÐжñÒâÏÂÁ£¬ £¬£¬£¬£¬£¬ÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723



ÊÂÎñÃû³Æ£º

TCP_Îļþ²Ù×÷¹¥»÷_IncomCMS-2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñȡĿµÄϵͳȨÏÞ

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Xise-WebshellÖÎÀí¹¤¾ßÅþÁ¬_Webshell»á¼û

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

Á÷Á¿Öмì²âµ½XiseWebshellÖÎÀí¹¤¾ßÅþÁ¬webshellµÄ²Ù×÷£¬£¬ £¬£¬£¬£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬ £¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬ £¬£¬£¬£¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬ £¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬ £¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬ £¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬ £¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬ £¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ £¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÆäËü×¢Èë_Jellyfin_SSRF_ЧÀͶËÇëÇóαÔì[CVE-2021-29490]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò:

JellyfinÊÇÒ»¸öÃâ·ÑµÄÈí¼þýϵһÇУ¬£¬ £¬£¬£¬£¬£¬10.7.3֮ǰµÄ°æ±¾±£´æSSRFÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó¸ÃÎó²î̽²âÄÚÍøÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Èñ½ÝNBR-1300G·ÓÉÆ÷_CLIÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃÈñ½ÝNBR-1300G·ÓÉÆ÷Ô¶³ÌCLIÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£¡£ÔÚ_Èñ½ÝNBR-1300G·ÓÉÆ÷ÉÏ·¢Ã÷ÁËÒ»¸öÎÊÌ⣬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃguestÕË»§Ö´ÐÐCLIÏÂÁî¡£¡£¡£¡£ÕâÔÊÐí»ñÈ¡ËùÓÐÓû§ºÍÃÜÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ClaimsIdentity-BinaryFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-JavaScriptSerializerʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-SharpSerializerBinaryʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-XamlʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_TextFormattingRunProperties-LosFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_TextFormattingRunProperties-NetDataContractSerializerʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_AxHostState-BinaryFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-FastJsonʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-Json.NetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬ £¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬ £¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_Shiro_Cookie³¤¶ÈÒì³£

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò:

ApacheShiroĬÈÏʹÓÃÁËCookieRememberMeManager¡£¡£¡£¡£Æä´¦Öóͷ£cookieµÄÁ÷³ÌÊÇ£º»ñµÃrememberMeµÄcookieÖµ£»£»£»£»Base64½âÂ룻£»£»£»AES½âÃÜ£»£»£»£»·´ÐòÁл¯¡£¡£¡£¡£È»¶øAESµÄÃÜÔ¿ÊÇÓ²±àÂëµÄ£¬£¬ £¬£¬£¬£¬£¬¼´AES¼Ó½âÃܵÄÃÜÔ¿ÊÇдËÀÔÚ´úÂëÖеÄ£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÊý¾ÝÔì³É·´ÐòÁл¯Îó²î£¬£¬ £¬£¬£¬£¬£¬cookie³¤¶ÈÒì³£ÌáÐÑ¿ÉÄÜΪ¹¥»÷Õ߽ṹµÄ¶ñÒâpayload¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_¿ìÅÅCMS-1.2_Ãô¸ÐÐÅϢй¶

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò:

¿ìÅÅCMSÊÇ¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾ÖÆ×÷¡¢½¨Éè¡¢¿ª·¢¡¢ÓÅ»¯SEOÖÎÀíϵͳ¡£¡£¡£¡ £¿£¿£¿£¿£¿£¿£¿ìÅÅCMS<=1.2°æ±¾»áĬÈÏ¿ªÆôÈÕÖ¾¼Í¼£¬£¬ £¬£¬£¬£¬£¬ÈÕÖ¾ÃûÎļþΪʱ¼ä£¬£¬ £¬£¬£¬£¬£¬ÈÕÖ¾¼Í¼ÖаüÀ¨ÖÎÀíÔ±cookieµÈÃô¸ÐÐÅÏ¢£¬£¬ £¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔͨ¹ý»á¼ûÈÕÖ¾¼Í¼£¬£¬ £¬£¬£¬£¬£¬ÕÒµ½ÖÎÀíÔ±cookieµÈÐÅÏ¢¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Éó¼Æ_ÉÏ´«war°ü

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«war°ü¡£¡£¡£¡£war°üÊÇJavaWeb³ÌÐò´òµÄ°ü£¬£¬ £¬£¬£¬£¬£¬Ò»¸öwar°ü¿ÉÒÔÃ÷ȷΪÊÇÒ»¸öwebÏîÄ¿£¬£¬ £¬£¬£¬£¬£¬ÄÚÀïÊÇÏîÄ¿µÄËùÓй¤¾ß¡£¡£¡£¡£ÒÔTomcatΪÀý£¬£¬ £¬£¬£¬£¬£¬½«War°ü°²ÅÅÔÚÆä\webapps\Ŀ¼Ï£¬£¬ £¬£¬£¬£¬£¬È»ºóÆô¶¯Tomcat£¬£¬ £¬£¬£¬£¬£¬Õâ¸ö°ü¾Í»á×Ô¶¯½âѹ£¬£¬ £¬£¬£¬£¬£¬°²ÅÅ¡¢Ðû²¼µ½webЧÀÍÖС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_À¶ÁèOA_treexml.tmpl_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýtreexml.tmpl£¬£¬ £¬£¬£¬£¬£¬ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Blueimp-jQuery-File-Upload_ÎļþÉÏ´«[CVE-2018-9206][CNNVD-201810-561]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

Blueimp-jQuery-File-UploadÊÇÒ»¸öÎļþÉÏ´«Ð¡¹¤¾ß£¬£¬ £¬£¬£¬£¬£¬°üÀ¨¶à¸öÎļþÑ¡Ôñ£¬£¬ £¬£¬£¬£¬£¬ÍÏ·ÅÖ§³Ö£¬£¬ £¬£¬£¬£¬£¬½ø¶ÈÌõ£¬£¬ £¬£¬£¬£¬£¬ÑéÖ¤ºÍÔ¤ÀÀͼÏñ£¬£¬ £¬£¬£¬£¬£¬jQueryµÄÒôƵºÍÊÓÆµ¡£¡£¡£¡£Ö§³Ö¿çÓò¡¢·Ö¿éºÍ¿É»Ö¸´ÎļþÉÏ´«ÒÔ¼°¿Í»§¶ËͼÏñ¾Þϸµ÷½â¡£¡£¡£¡£ÊÊÓÃÓÚÈκÎЧÀÍÆ÷¶Ëƽ̨£¬£¬ £¬£¬£¬£¬£¬Ö§³Ö±ê×¼HTML±íµ¥ÎļþÉÏ´«£¨PHP£¬£¬ £¬£¬£¬£¬£¬Python£¬£¬ £¬£¬£¬£¬£¬RubyonRails£¬£¬ £¬£¬£¬£¬£¬Java£¬£¬ £¬£¬£¬£¬£¬Node.js£¬£¬ £¬£¬£¬£¬£¬GoµÈ£©¡£¡£¡£¡£ÓÉÓÚÆäphp°æ±¾±£´æÎó²î£¬£¬ £¬£¬£¬£¬£¬¿Éµ¼ÖÂí§ÒâÎļþÉÏ´«¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress-Simple-Ads-Manager_ÎļþÉÏ´«[CVE-2015-2825][CNNVD-201504-410]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬ £¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£WordPressSimpleAdsManagerÊÇÒ»¸öworkpressµÄ¹ã¸æÖÎÀí²å¼þ¡£¡£¡£¡£WordPressSimpleAdsManagerµÄsam-ajax-admin.phpÎļþÖб£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬ £¬£¬£¬£¬£¬²¢ÒÔWEBȨÏÞÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Net.FliterÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄFilter¹ýÂËÆ÷£¬£¬ £¬£¬£¬£¬£¬ÉÏ´«FliterÄÚ´æÂí£¬£¬ £¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_IcedID.BCModule_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

¼ì²âµ½IcedIDµÄBCÄ £¿£¿£¿£¿£¿£¿£¿éÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíIcedID¡£¡£¡£¡£IcedIDÊÇ×îÔçÔÚ2017Äê±»Åû¶µÄÄ £¿£¿£¿£¿£¿£¿£¿é»¯ÒøÐÐľÂí£¬£¬ £¬£¬£¬£¬£¬Ò²ÊǽüÄêÀ´×îÊ¢ÐеĶñÒâÈí¼þ¼Ò×åÖ®Ò»¡£¡£¡£¡£IcedIDÖ÷ÒªÕë¶Ô½ðÈÚÐÐÒµÌᳫ¹¥»÷£¬£¬ £¬£¬£¬£¬£¬»¹»á³äµ±ÆäËû¶ñÒâÈí¼þ¼Ò×壨ÈçVatet¡¢Egregor¡¢REvil£©µÄDropper¡£¡£¡£¡£IcedID°üÀ¨Ò»¸öBCÄ £¿£¿£¿£¿£¿£¿£¿é£¬£¬ £¬£¬£¬£¬£¬¿ÉÒÔÖ´Ðй¥»÷ÕßµÄÖ¸Á£¬ £¬£¬£¬£¬£¬ÈçÔËÐÐVNCºÍSOCKSÄ £¿£¿£¿£¿£¿£¿£¿é¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTPS_ľÂíºóÃÅ_Covenant_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü£¬£¬ £¬£¬£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐΣ¬£¬ £¬£¬£¬£¬£¬²»µ«Ö§³ÖLinux£¬£¬ £¬£¬£¬£¬£¬MacOSºÍWindows£¬£¬ £¬£¬£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒ룬£¬ £¬£¬£¬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server£¬£¬ £¬£¬£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¡£¡£¸ÃÊÂÎñÅú×¢£¬£¬ £¬£¬£¬£¬£¬CovenantµÄÌìÉúÎïGruntsÕýÔÚʹÓÃHTTPSЭÒéÓëC2ЧÀÍÆ÷½¨ÉèÅþÁ¬¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_SAP_NETWEAVER_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SAPNetWeaverÊÇ»ùÓÚרҵ±ê×¼µÄ¼¯³É»¯Ó¦ÓÃÆ½Ì¨£¬£¬ £¬£¬£¬£¬£¬Äܹ»´ó·ù¶È½µµÍϵͳÕûºÏµÄÖØ´óÐÔ¡£¡£¡£¡£Æä×é¼þ°üÀ¨ÃÅ»§¡¢Ó¦ÓÃЧÀÍÆ÷¡¢ÉÌÎñÖÇÄܽâ¾ö¼Æ»®ÒÔ¼°ÏµÍ³ÕûºÏºÍÊý¾ÝÕûºÏÊÖÒÕ£¬£¬ £¬£¬£¬£¬£¬SAPNetWeaver×é¼þ±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Shell_´úÂëÖ´ÐÐ[CVE-2022-22965][CNNVD-202203-2642]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

SpringÊÇÏÖÔÚÈ«Çò×îÊܽӴýµÄJavaÇáÁ¿¼¶¿ªÔ´¿ò¼Ü¡£¡£¡£¡£¹ØÓÚCVE-2022-22965Îó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÁ¬ÏµJDK9¼°ÒÔÉϰ汾һ¸öеÄÊôÐÔ£¬£¬ £¬£¬£¬£¬£¬ÀÖ³ÉÈÆ¹ýÀúÊ·Îó²îCVE-2010-1622ÐÞ¸´²¹¶¡£¬£¬ £¬£¬£¬£¬£¬Í¬Ê±Á¬ÏµTomcatÈÝÆ÷µÄһЩ²Ù×÷ÊôÐÔ£¬£¬ £¬£¬£¬£¬£¬¿ÉʵÏÖ¶ñÒâ´úÂëÖ´ÐС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_wpDiscuz_7.0.4_í§ÒâÎļþÉÏ´«[CVE-2020-24186][CNNVD-202008-1145]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

WordPressµÄgVectorswpDiscuz²å¼þ7.0ÖÁ7.0.4°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃδÂÄÀúÖ¤µÄÓû§Í¨¹ýwmuUploadFilesAjax²Ù×÷ÉÏ´«ÈκÎÀàÐ͵ÄÎļþ£¬£¬ £¬£¬£¬£¬£¬°üÀ¨PHPÎļþ,´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ

¸üÐÂʱ¼ä£º

20220723



ÊÂÎñÃû³Æ£º

HTTP_ÉèÖÃȱÏÝ_Confluence_server_Ó²±àÂëÈÆ¹ý[CVE-2022-26138]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

AtlassianConfluenceServerÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×¾ßÓÐÆóҵ֪ʶÖÎÀí¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬²¢Ö§³ÖÓÃÓÚ¹¹½¨ÆóÒµWiKiµÄЭͬÈí¼þµÄЧÀÍÆ÷°æ±¾.ConfluenceServerµÄÀ©Õ¹³ÌÐòQuestionsforConfluenceÔÚijЩ°æ±¾±£´æÒ»¸öĬÈϵÄÓ²±àÂëÓû§£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚδÊÚȨµÄÇéÐÎϵǼconfluence²¢»á¼ûconfluence-users×éÖеÄÓû§¿ÉÒÔ»á¼ûµÄËùÓÐÄÚÈÝ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Zoomla_ÖðÀËCMSϵͳ_í§ÒâÎļþÏÂÔØ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ZoomlaÖðÀËCMSÈí¼þÓÉÉϺ£ÖðÒ»Èí¼þ¿Æ¼¼ÓÐÏÞ¹«Ë¾¡¢½­Î÷ÖðÀËÈí¼þ¿Æ¼¼ÓÐÏÞ¹«Ë¾ÁªºÏ¿ª·¢µÄÍøÕ¾ÖÎÀíϵͳ¡£¡£¡£¡£ÒòϵͳÖб£´æÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÏÂÔØí§ÒâÎļþ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Net.HttpListenerÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄHttpListener¼àÌýÆ÷£¬£¬ £¬£¬£¬£¬£¬ÉÏ´«HttpListenerÄÚ´æÂí£¬£¬ £¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723



ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Wordpress_WP_Property_ÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£WordPressµÄWP-Property²å¼þ£¨1.35.0°æ±¾£©Öб£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬ £¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÓ¦ÓóÌÐò¶ÔÓû§ÌṩµÄÊäÈëδ¾­³ä·Ö¹ýÂË¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚwebЧÀÍÆ÷Àú³ÌÉÏÏÂÎÄÖÐÉÏ´«²¢ÔËÐÐí§ÒâPHP´úÂ룬£¬ £¬£¬£¬£¬£¬Õâ¿ÉÄÜÓÐÀûÓÚδÊÚȨ»á¼û»òȨÏÞÌáÉý£¬£¬ £¬£¬£¬£¬£¬Ò²¿ÉÄÜÖ´ÐÐÆäËûµÄ¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_MessageSolution_·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý[CNVD-2021-10543]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

MessageSolutionÆóÒµÓʼþ¹éµµÖÎÀíϵͳEEAÊDZ±¾©Ò×Ѷ˼´ï¿Æ¼¼¿ª·¢ÓÐÏÞ¹«Ë¾¿ª·¢µÄÒ»¿îÓʼþ¹éµµÏµÍ³£¬£¬ £¬£¬£¬£¬£¬¸Ãϵͳ±£´æÍ¨ÓÃWEBÐÅÏ¢×ß©£¬£¬ £¬£¬£¬£¬£¬Ð¹Â¶WindowsЧÀÍÆ÷administratorhashÓëwebÕ˺ÅÃÜÂë¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_C3Pool_Xmrig_SetupScript_ÏÂÔØ

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò:

¼ì²âµ½ÏÂÔØC3PoolÍÚ¿ó¾ç±¾µÄÐÐΪ¡£¡£¡£¡£Ô´IP¿ÉÄܱ»Ö²ÈëÁ˶ñÒâľÂíºóÃÅ£¬£¬ £¬£¬£¬£¬£¬»òÕßÔ´IP´æÄ³¸öÎó²î£¬£¬ £¬£¬£¬£¬£¬±»¹¥»÷´¥·¢Îó²îÀֳɣ¬£¬ £¬£¬£¬£¬£¬È¥ÏÂÔØC3PoolÍÚ¿ó¾ç±¾¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_˼¸£µÏ±¤ÀÝ»ú_·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

˼¸£µÏ±¤ÀÝ»ú×°±¸ÊÇÓÃÓÚ¶ÔÔËάְԱ¾ÙÐм¯ÖÐÖÎÀí¡¢¶ÔÔËά²Ù×÷¾ÙÐм¯ÖÐÉ󼯵ÄÇå¾²Éó¼Æ×°±¸¡£¡£¡£¡£Ë¼¸£µÏ±¤ÀÝ»ú£¨ÊÜÓ°Ïì°æ±¾£ºLogBase-B798¡¢bh-x64-v7.0.13¡¢bh-x64-v7.0.15£©±£´æí§ÒâÓû§µÇ¼Îó²î£¬£¬ £¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔÈÆ¹ý±¤ÀÝ»úµÄÃÜÂëµÇ¼ÑéÖ¤»úÖÆ£¬£¬ £¬£¬£¬£¬£¬ÒÔí§ÒâÓû§Éí·ÝËæÒâµÇ¼±¤ÀÝ»úWebÖÎÀí½çÃæ£¬£¬ £¬£¬£¬£¬£¬²¢¿ÉÒÔÕý³£µÄʹÓÃÕË»§È¨ÏÞÈ¥²Ù×÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Net.RouteÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄRoute·ÓÉÖÎÀíÆ÷£¬£¬ £¬£¬£¬£¬£¬ÉÏ´«RouteÄÚ´æÂí£¬£¬ £¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

TCP_×¢Èë¹¥»÷_WebLogic_WsrmPayloadContext_XXE×¢Èë[CVE-2019-2649][CNNVD-201904-726]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_WebLogic_WsrmPayloadContext_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£HTTP_WebLogic_WsrmPayloadContext_XXE×¢ÈëÎó²î£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ЭÒéÖУ¬£¬ £¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ЭÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬ £¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlindXXE¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723



ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache-Spark-doAS_ÏÂÁî×¢Èë[CVE-2022-33891]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

ApacheSparkUIͨ¹ýÉèÖÃÑ¡Ïîspark.acls.enableÉí·ÝÑéÖ¤¹ýÂËÆ÷£¬£¬ £¬£¬£¬£¬£¬¼ì²éÓû§ÊÇ·ñ¾ßÓÐÉó²é»òÐÞ¸ÄÓ¦Óᣡ£¡£¡£ÈôÊÇÆôÓÃÁËACL£¬£¬ £¬£¬£¬£¬£¬ÔòHttpSecurityFilterÖеĴúÂëÔÊÐíijÈËͨ¹ýÌṩí§ÒâÓû§ÃûÀ´Ö´ÐÐÄ£Äâ¡£¡£¡£¡£¶ñÒâÓû§¿ÉÄÜÈÆ¹ýȨÏÞ¼ì²é¹¦Ð§£¬£¬ £¬£¬£¬£¬£¬ÊäÈë¹¹½¨Ò»¸öUnixshellÏÂÁ£¬ £¬£¬£¬£¬£¬²¢ÇÒÖ´ÐÐËü¡£¡£¡£¡£½«µ¼ÖÂÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò:

¼ì²âµ½GafgytЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øGafgyt£¬£¬ £¬£¬£¬£¬£¬Ä¿µÄIPÖ÷»ú±»Ö²ÈëÁËGafgyt¡£¡£¡£¡£DDoS.GafgytÊÇÒ»¸öÀàLinuxƽ̨ϵĽ©Ê¬ÍøÂ磬£¬ £¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À­_php_base64

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹À­webshellľÂí¡£¡£¡£¡£¸ç˹À­ºÍ±ùЫһÑù£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬ £¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


0


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À­_php_raw

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹À­webshellľÂí¡£¡£¡£¡£¸ç˹À­ºÍ±ùЫһÑù£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬ £¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723


¿­·¢¡¤k8(ÖйúÓÎ)¹Ù·½ÍøÕ¾


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À­_asp_base64

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹À­webshellľÂí¡£¡£¡£¡£¸ç˹À­ºÍ±ùЫһÑù£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬ £¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬ £¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220723

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_±ùЫ3.0ÅþÁ¬_»ù´¡ÊÂÎñ2

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò:

±ùЫ3.0ÊÇÒ»¿îǿʢµÄwebshellÖÎÀí¹¤¾ß¡£¡£¡£¡£¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓñùЫ3.0ÅþÁ¬Ä¿µÄIPÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20220723

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´«

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò:

¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ

¸üÐÂʱ¼ä£º

20220723