ÿÖÜÉý¼¶Í¨¸æ-2021-05-18

Ðû²¼Ê±¼ä 2021-05-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_PHP-zerodiumºóÃÅ_í§Òâ´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄÆÊÎöÀú³ÌÖз¢Ã÷£¬ £¬ £¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»Ð®ÖÆµÄÍøÕ¾ÉÏ£¬ £¬ £¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬ £¬ £¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢Ö°Ô±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£¡£¡£¡£¡£¡£ÏÖÔÚΪֹPHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ¾ÙÐиü¶àÅû¶£¬ £¬ £¬£¬£¬£¬ÌåÏÖ´Ë´ÎЧÀÍÆ÷±»ºÚµÄÏêϸϸ½ÚÈÔÔÚÊӲ쵱ÖС£¡£¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬 £¬ £¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ­±»Î¬»¤Ö°Ô±Ç¨áãÖÁGitHubƽ̨£¬ £¬ £¬£¬£¬£¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϾÙÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Gh0st_htrfhtfe__ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬ £¬ £¬£¬£¬£¬¹¦Ð§Ê®·Öǿʢ¡£¡£¡£¡£¡£¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬ £¬ £¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£¡£½üÆÚ·¢Ã÷´ó×ÚÆ¾Ö¤Gh0stÔ´ÂëÐ޸ĵÄÔ¶¿Ø³ÌÐò£¬ £¬ £¬£¬£¬£¬²¢Ìí¼ÓÁË×Ô¼ºµÄ¹¦Ð§£¬ £¬ £¬£¬£¬£¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳװÖõÄÍøÂçÓÎÏ·µÈ¹¦Ð§¡£¡£¡£¡£¡£¡£ºÚ¿Í»¹¿ÉÒÔ½«º¬ÓÐÉãÏñÍ·»ò×°ÖÃÖ¸¶¨ÓÎÏ·µÄÓû§¹éÀ࣬ £¬ £¬£¬£¬£¬ÓÐÕë¶ÔÐÔµÄ͵ȡÓû§Òþ˽¡£¡£¡£¡£¡£¡£ÉõÖÁÉó²éÖж¾ÕßµØÀíλÖõĹ¦Ð§£¬ £¬ £¬£¬£¬£¬¶ÔÓû§µÄÒþ˽Ôì³É¸ü´óµÄÍþв¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-28188][CNNVD-202012-1548]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬ £¬ £¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬ £¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_SSH-RSA˽Կ×ß©

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ£¬ £¬ £¬£¬£¬£¬LINUXЧÀÍÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH£¬ £¬ £¬£¬£¬£¬RSA˽Կй¶£¬ £¬ £¬£¬£¬£¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH£¬ £¬ £¬£¬£¬£¬µ¼ÖÂÖ÷»ú±»½ÓÊÜ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Microsoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Ä¿½ñÖ÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¸ÃÎó²îÊÇExchangeÖеÄí§ÒâÎļþдÈëÎó²î¡£¡£¡£¡£¡£¡£¸ÃÎó²îÐèÒª¾ÙÐÐÉí·ÝÈÏÖ¤£¬ £¬ £¬£¬£¬£¬Ê¹ÓôËÎó²î¿ÉÒÔ½«ÎļþдÈëЧÀÍÆ÷ÉϵÄÈκη¾¶¡£¡£¡£¡£¡£¡£²¢¿ÉÒÔÁ¬ÏµÊ¹ÓÃCVE-2021-26855SSRFÎó²î»òÈÆ¹ýȨÏÞÈÏÖ¤¾ÙÐÐÎļþдÈë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÅþÁ¬C2ЧÀÍÆ÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí£¬ £¬ £¬£¬£¬£¬¾ßÓÐËѼ¯Êܺ¦Ö÷»úÃô¸ÐÐÅÏ¢ÉÏ´«µ½C2ЧÀÍÆ÷µÄÐÐΪ£¬ £¬ £¬£¬£¬£¬ÏÂÔØÍÚ¿ó³ÌÐòµ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIEÀú³ÌÖÐÖ´ÐÐÍÚ¿ó£¬ £¬ £¬£¬£¬£¬Æ¾Ö¤C2ЧÀÍÆ÷µÄÏÂÁîÖ´ÐÐÖݪֲÙ×÷£¬ £¬ £¬£¬£¬£¬Èç¸üÐÂÉèÖÃÐÅÏ¢¡¢×°ÖÃÍÚ¿ó³ÌÐòµÈ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£

Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£¡£¡£¡£

Îó²î±£´æµÄ°æ±¾£º

S2-016£ºStruts 2.0.0 - Struts 2.3.15

S2-017£ºStruts 2.0.0 - Struts 2.3.15

S2-018£ºStruts 2.0.0 - Struts 2.3.15.2

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Raccoon.Stealer_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£¡£¡£¡£¡£¡£RaccoonÒ²±»³ÆÎªMohazo»òRacealer£¬ £¬ £¬£¬£¬£¬ÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÇÔÃÜľÂí¡£¡£¡£¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶ËÉúÑĵÄÕ˺ÅÃÜÂë¡£¡£¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬ £¬ £¬£¬£¬£¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬ £¬ £¬£¬£¬£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£¡£¡£¡£¡£¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬ £¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬ £¬ £¬£¬£¬£¬¿ÉÏòЧÀÍÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬ £¬ £¬£¬£¬£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷Ö÷»ú¡£¡£¡£¡£¡£¡£ÁíÍ⣬ £¬ £¬£¬£¬£¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬ £¬ £¬£¬£¬£¬boundary´óÓÚ½çÏßÖµ£¬ £¬ £¬£¬£¬£¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬ £¬ £¬£¬£¬£¬µ¼ÖÂDDOS¡£¡£¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ


1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ