ÿÖÜÉý¼¶Í¨¸æ-2022-07-23
Ðû²¼Ê±¼ä 2022-07-23ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Mida_Solutions_eFramework_2.8.9_²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2020-15922][CNNVD-202007-1515] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCVE-2020-15922Îó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷¡£¡£¡£MidaSolutionseFrameworkÊÇÒâ´óÀûMidaSolutions¹«Ë¾µÄÒ»Ì×ͳһͨѶºÍÐ×÷ЧÀÍÌ×¼þ¡£¡£¡£MidaSolutionseFramework2.9.0°æ±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐдúÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCÐÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý1(XMR) |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCÐÒéÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃÐÒé¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¡£¡£¬£¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£ÃÅÂÞ±ÒÓ¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÍÚ¿óľÂí_CoinMiner_ÃÅÂÞ±ÒJSON-RPCÐÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(XMR) |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCÐÒéÒÉËÆÅ²ÓÃÁËÃÅÂÞ±ÒÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃÐÒé¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¡£¡£¬£¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£Ëü¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£ÃÅÂÞ±ÒÓ¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëÍÚ¿ó½Úµã½»»¥¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÍÚ¿óľÂí_CoinMiner_ÒÔÌ«·»JSON-RPCÐÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý1(ETH) |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCÐÒéÒÉËÆÅ²ÓÃÁËÒÔÌ«·»ÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃÐÒé¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¡£¡£¬£¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£JSON-RPCÊÇÒ»ÖÖÎÞ״̬ÇáÁ¿¼¶Ô¶³ÌÀú³ÌŲÓã¨RPC£©ÐÒ飬£¬£¬£¬£¬£¬¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£ÒÔÌ«·»Ó¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëETH½Úµã½»»¥¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÍÚ¿óľÂí_CoinMiner_ÒÔÌ«·»JSON-RPCÐÒé_ÍÚ¿ó¿ØÖÆÏÂÁîͨѶ_ÒÉËÆÅ²ÓÃÍÚ¿óAPIº¯Êý2(ETH) |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¸ÃÊÂÎñÅú×¢¼ì²âµ½Ê¹ÓÃJSON-RPCÐÒéÒÉËÆÅ²ÓÃÁËÒÔÌ«·»ÍÚ¿óAPIº¯Êý¡£¡£¡£JSON-RPCÊÇÒ»ÖÖ»ùÓÚJSONµÄ¿çÓïÑÔÔ¶³ÌŲÓÃÐÒé¡£¡£¡£ÓÐÎı¾´«ÊäÊý¾ÝС£¡£¡£¬£¬£¬£¬£¬£¬±ãÓÚµ÷ÊÔÀ©Õ¹µÄÌØµã¡£¡£¡£JSON-RPCÊÇÒ»ÖÖÎÞ״̬ÇáÁ¿¼¶Ô¶³ÌÀú³ÌŲÓã¨RPC£©ÐÒ飬£¬£¬£¬£¬£¬¹æ·¶½ç˵ÁËÊý¾Ý½á¹¹¼°ÏìÓ¦µÄ´¦Öóͷ£¹æÔò,¹æ·¶Ê¹ÓÃJSON£¨RFC4627£©Êý¾ÝÃûÌ㬣¬£¬£¬£¬£¬¹æ·¶×Ô¼ºÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔÓÃÓÚÀú³ÌÄÚͨѶ¡¢socketÌ×½Ó×Ö¡¢HTTP»òÖÖÖÖÐÂÎÅͨѶÇéÐΡ£¡£¡£ÒÔÌ«·»Ó¦Óÿª·¢½Ó¿Ú½ÓÄÉJSON-PRC±ê×¼£¬£¬£¬£¬£¬£¬ÓÉÓÚËüÊÇ´«ÊäÎ޹ص쬣¬£¬£¬£¬£¬¿ÉÒÔʹÓÃËüͨ¹ýÌ×½Ó×Ö»òHTTPÓëETH½Úµã½»»¥¡£¡£¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍڿ󡣡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Webmine¼Ò×å_ÍøÒ³ÍÚ¿óľÂí_Ö´ÐÐä¯ÀÀÆ÷ÍÚ¿ó |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¼ì²âµ½ÍøÒ³ÖаüÀ¨ÍÚ¿ó¾ç±¾´úÂë¡£¡£¡£WebmineÒ²ÊÇÒ»¸öÓëCoinhiveÀàËÆµÄJSÍÚ¿óÒýÇæ£¬£¬£¬£¬£¬£¬ÔÚÓлá¼ûÁ¿µÄÍøÕ¾ÖÐǶÈëÒ»¶ÎÍøÒ³ÍÚ¿ó´úÂ룬£¬£¬£¬£¬£¬Ê¹Ó÷ÿ͵ÄÅÌËã»úCPU×ÊÔ´À´ÍÚ¾òÊý×ÖÇ®±Ò¾ÙÐÐIJÀû¡£¡£¡£ÍÚ¿ó¾ç±¾Ö´ÐлáÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Jenkins-Git-client²å¼þ_´úÂëÖ´ÐÐ[CVE-2019-10392][CNNVD-201909-632] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | Ä¿½ñÖ÷»úÕýÔÚÔâÊÜJenkins-Git-client²å¼þ_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ó°Ïì¹æÄ£GitclientPlugin<=2.8.4 |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Zabbix-API-JSON-RPC_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ZabbixÊÇÒ»¸ö»ùÓÚWEB½çÃæµÄÂþÑÜʽϵͳ¼àÊÓÒÔ¼°ÍøÂç¼àÊӵįóÒµ¼¶¿ªÔ´½â¾ö¼Æ»®¡£¡£¡£ZabbixÄܼàÊÓÖÖÖÖÍøÂç²ÎÊý£¬£¬£¬£¬£¬£¬°ü¹ÜЧÀÍÆ÷ϵͳµÄÇå¾²ÔËÓª£¬£¬£¬£¬£¬£¬²¢ÌṩÎÞаµÄ֪ͨ»úÖÆÒÔ±ãϵͳÖÎÀíÔ±¿ìËÙ¶¨Î»Ï¢Õù¾ö±£´æµÄÖÖÖÖÎÊÌâ¡£¡£¡£ËüÓÉÁ½²¿·Ö×é³É£¬£¬£¬£¬£¬£¬ZabbixServerÓë¿ÉÑ¡×é¼þZabbixAgent¡£¡£¡£Zabbixserver¿ÉÒÔͨ¹ýSNMP£¬£¬£¬£¬£¬£¬ZabbixAgent£¬£¬£¬£¬£¬£¬ping£¬£¬£¬£¬£¬£¬¶Ë¿Ú¼àÊÓµÈÒªÁìÌṩ¶ÔÔ¶³ÌЧÀÍÆ÷/ÍøÂç״̬µÄ¼àÊÓ£¬£¬£¬£¬£¬£¬Êý¾ÝÍøÂçµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬Ëü¿ÉÒÔÔËÐÐÔÚLinux£¬£¬£¬£¬£¬£¬Solaris£¬£¬£¬£¬£¬£¬HP-UX£¬£¬£¬£¬£¬£¬AIX£¬£¬£¬£¬£¬£¬FreeBSD£¬£¬£¬£¬£¬£¬OpenBSD£¬£¬£¬£¬£¬£¬OSXµÈƽ̨ÉÏ¡£¡£¡£ÔÚÆäjsonrpc2.0°æ±¾±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý´ËÎó²î»ñȡЧÀÍÆ÷ȨÏÞ£¬£¬£¬£¬£¬£¬Î£º¦ÏµÍ³Çå¾²¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellÏÂÁî×¢Èë_¹¥»÷ʧ°Ü |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐBASH_·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬£¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶˣ¬£¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£µ±Ö´ÐÐbash·´µ¯shellÏÂÁîÓÐÎóʱ£¬£¬£¬£¬£¬£¬»á·µ»Øbash:nojobcontrolinthisshell |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Tp-Link_´úÂëÖ´ÐÐ[CVE-2022-30075][CNNVD-202206-881] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ÔÚTp-Link·ÓÉÆ÷ÖоÙÐÐÉí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐУ¬£¬£¬£¬£¬£¬Í¨¹ýÉí·ÝÑéÖ¤ºó¿ÉʹÓñ¸·ÝÎļþ°üÀ¨¾ÙÐÐí§Òâ´úÂëÖ´ÐÐ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_PHP_imap_ÏÂÁîÖ´ÐÐ[CVE-2018-19518][CNNVD-201811-666] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ÔÚPHPºÍÆäËû²úÆ·µÄimap_open£¨£©ÖÐʹÓõÄUNIXÉϵĻªÊ¢¶Ù´óѧIMAP¹¤¾ß°ü2007fÆô¶¯rshÏÂÁ½èÖúÓÚc-client/imap4r1.cÖеÄimap_rimapº¯ÊýºÍosdep/unix/tcp_unixÖеÄtcp_aopenº¯Êý.c£©£¬£¬£¬£¬£¬£¬¶ø²»»á×èÖ¹²ÎÊý×¢È룬£¬£¬£¬£¬£¬ÈôÊÇIMAPЧÀÍÆ÷Ãû³ÆÊDz»ÊÜÐÅÈεÄÊäÈ루ÀýÈ磬£¬£¬£¬£¬£¬ÓÉWebÓ¦ÓóÌÐòµÄÓû§ÊäÈ룩£¬£¬£¬£¬£¬£¬²¢ÇÒrshÒѱ»¾ßÓвî±ð²ÎÊýµÄ³ÌÐòÌæ»»£¬£¬£¬£¬£¬£¬ÔòÔ¶³Ì¹¥»÷Õß¿ÉÄÜ»áÖ´ÐÐí§ÒâOSÏÂÁîÓïÒå¡£¡£¡£ÀýÈ磬£¬£¬£¬£¬£¬ÈôÊÇrshÊÇsshµÄÁ´½Ó£¨ÈçÔÚDebianºÍUbuntuϵͳÉÏ¿´µ½µÄ£©£¬£¬£¬£¬£¬£¬Ôò¹¥»÷¿ÉÒÔʹÓðüÀ¨¡°-oProxyCommand¡±²ÎÊýµÄIMAPЧÀÍÆ÷Ãû³Æ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_XML-dtdÍâÁ¬_ÆäËû×¢Èë |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò: | XXE(XMLExternalEntityInjection)XMLÍⲿʵÌå×¢È룬£¬£¬£¬£¬£¬XMLÊÇÒ»ÖÖÀàËÆÓÚHTML£¨³¬Îı¾±ê¼ÇÓïÑÔ£©µÄ¿ÉÀ©Õ¹±ê¼ÇÓïÑÔ£¬£¬£¬£¬£¬£¬ÊÇÓÃÓÚ±ê¼Çµç×ÓÎļþʹÆä¾ßÓнṹÐԵıê¼ÇÓïÑÔ£¬£¬£¬£¬£¬£¬¿ÉÒÔÓÃÀ´±ê¼ÇÊý¾Ý¡¢½ç˵Êý¾ÝÀàÐÍ£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖÔÊÐíÓû§¶Ô×Ô¼ºµÄ±ê¼ÇÓïÑÔ¾ÙÐнç˵µÄÔ´ÓïÑÔ¡£¡£¡£XMLÎĵµ½á¹¹°üÀ¨XMLÉùÃ÷¡¢DTDÎĵµÀàÐͽç˵£¨¿ÉÑ¡£¡£¡£©¡¢ÎĵµÔªËØ¡£¡£¡£µ±Ó¦ÓÃÊÇͨ¹ýÓû§ÉÏ´«µÄXMLÎļþ»òPOSTÇëÇó¾ÙÐÐÊý¾ÝµÄ´«Ê䣬£¬£¬£¬£¬£¬²¢ÇÒÓ¦ÓÃûÓÐեȡXMLÒýÓÃÍⲿʵÌ壬£¬£¬£¬£¬£¬Ò²Ã»ÓйýÂËÓû§Ìá½»µÄXMLÊý¾Ý£¬£¬£¬£¬£¬£¬ÄÇô¾Í»á±¬·¢XMLÍⲿʵÌå×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¼´XXEÎó²î¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_PhpSpy2013-MysqlÊý¾Ý¿âÖÎÀí_Webshell»á¼û |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | Á÷Á¿Öмì²âµ½phpspy2013ÖÎÀímysqlÊý¾Ý¿âµÄ²Ù×÷£¬£¬£¬£¬£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_΢ÐÅĬÈÏ×Ô´øä¯ÀÀÆ÷-´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ΢ÐÅwindows°æ<3.1.2.141°æ±¾ÊÜchromev8ÒýÇæÎó²îÓ°Ï죬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«¶ñÒâµÄ´¹ÂÚÓʼþ·¢Ë͸øÄ¿µÄÖ°Ô±£¬£¬£¬£¬£¬£¬Ä¿µÄÖ°Ô±ÓÃ΢ÐÅ×Ô´øä¯ÀÀÆ÷·¿ªºóÔò»á´¥·¢Îó²î£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷Õß¿ØÖÆÄ¿µÄÖ°Ô±ÅÌËã»úȨÏÞ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Iris-ID-IrisAccess-ICU-7000-2_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | IrisIDµÄIrisAccess7000-2ÊÇLGÉú²úµÄºçĤʶ±ðϵͳ¡£¡£¡£ÓÉÓÚ¸Ãϵͳ±£´æÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý½á¹¹¶ñÒâpayloadʹϵͳִÐжñÒâÏÂÁ£¬£¬£¬£¬£¬ÒÔ»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_Îļþ²Ù×÷¹¥»÷_IncomCMS-2.0_ÎļþÉÏ´«[CVE-2020-29597][CNNVD-202012-431] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | IncomCMS2.0ÒÔ¼°Ö®Ç°µÄ°æ±¾±£´æÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÉÏ´«webshell»ñȡĿµÄϵͳȨÏÞ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_Xise-WebshellÖÎÀí¹¤¾ßÅþÁ¬_Webshell»á¼û |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | Á÷Á¿Öмì²âµ½XiseWebshellÖÎÀí¹¤¾ßÅþÁ¬webshellµÄ²Ù×÷£¬£¬£¬£¬£¬£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÆäËü×¢Èë_Jellyfin_SSRF_ЧÀͶËÇëÇóαÔì[CVE-2021-29490] |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò: | JellyfinÊÇÒ»¸öÃâ·ÑµÄÈí¼þýϵһÇУ¬£¬£¬£¬£¬£¬10.7.3֮ǰµÄ°æ±¾±£´æSSRFÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇó¸ÃÎó²î̽²âÄÚÍøÐÅÏ¢¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Èñ½ÝNBR-1300G·ÓÉÆ÷_CLIÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IP×°±¸ÕýÔÚʹÓÃÈñ½ÝNBR-1300G·ÓÉÆ÷Ô¶³ÌCLIÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£¡£¡£ÔÚ_Èñ½ÝNBR-1300G·ÓÉÆ÷ÉÏ·¢Ã÷ÁËÒ»¸öÎÊÌ⣬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃguestÕË»§Ö´ÐÐCLIÏÂÁî¡£¡£¡£ÕâÔÊÐí»ñÈ¡ËùÓÐÓû§ºÍÃÜÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ClaimsIdentity-BinaryFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-JavaScriptSerializerʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-SharpSerializerBinaryʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-XamlʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_TextFormattingRunProperties-LosFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_TextFormattingRunProperties-NetDataContractSerializerʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_AxHostState-BinaryFormatterʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-FastJsonʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-Json.NetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÆäËü¿ÉÒÉÐÐΪ_Shiro_Cookie³¤¶ÈÒì³£ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò: | ApacheShiroĬÈÏʹÓÃÁËCookieRememberMeManager¡£¡£¡£Æä´¦Öóͷ£cookieµÄÁ÷³ÌÊÇ£º»ñµÃrememberMeµÄcookieÖµ£»£»£»Base64½âÂ룻£»£»AES½âÃÜ£»£»£»·´ÐòÁл¯¡£¡£¡£È»¶øAESµÄÃÜÔ¿ÊÇÓ²±àÂëµÄ£¬£¬£¬£¬£¬£¬¼´AES¼Ó½âÃܵÄÃÜÔ¿ÊÇдËÀÔÚ´úÂëÖе쬣¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÊý¾ÝÔì³É·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬cookie³¤¶ÈÒì³£ÌáÐÑ¿ÉÄÜΪ¹¥»÷Õ߽ṹµÄ¶ñÒâpayload¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÐÅϢй¶_¿ìÅÅCMS-1.2_Ãô¸ÐÐÅϢй¶ |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò: | ¿ìÅÅCMSÊÇ¿ªÔ´Ãâ·ÑµÄPHPÆóÒµÍøÕ¾ÖÆ×÷¡¢½¨Éè¡¢¿ª·¢¡¢ÓÅ»¯SEOÖÎÀíϵͳ¡£¡£¡£¿£¿£¿£¿ìÅÅCMS<=1.2°æ±¾»áĬÈÏ¿ªÆôÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬£¬ÈÕÖ¾ÃûÎļþΪʱ¼ä£¬£¬£¬£¬£¬£¬ÈÕÖ¾¼Í¼ÖаüÀ¨ÖÎÀíÔ±cookieµÈÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔͨ¹ý»á¼ûÈÕÖ¾¼Í¼£¬£¬£¬£¬£¬£¬ÕÒµ½ÖÎÀíÔ±cookieµÈÐÅÏ¢¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Éó¼Æ_ÉÏ´«war°ü |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«war°ü¡£¡£¡£war°üÊÇJavaWeb³ÌÐò´òµÄ°ü£¬£¬£¬£¬£¬£¬Ò»¸öwar°ü¿ÉÒÔÃ÷ȷΪÊÇÒ»¸öwebÏîÄ¿£¬£¬£¬£¬£¬£¬ÄÚÀïÊÇÏîÄ¿µÄËùÓй¤¾ß¡£¡£¡£ÒÔTomcatΪÀý£¬£¬£¬£¬£¬£¬½«War°ü°²ÅÅÔÚÆä\webapps\Ŀ¼Ï£¬£¬£¬£¬£¬£¬È»ºóÆô¶¯Tomcat£¬£¬£¬£¬£¬£¬Õâ¸ö°ü¾Í»á×Ô¶¯½âѹ£¬£¬£¬£¬£¬£¬°²ÅÅ¡¢Ðû²¼µ½webЧÀÍÖС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_À¶ÁèOA_treexml.tmpl_Ô¶³Ì´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃÀ¶ÁèOAÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ýtreexml.tmpl£¬£¬£¬£¬£¬£¬ÔÚÄ¿µÄЧÀÍÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Blueimp-jQuery-File-Upload_ÎļþÉÏ´«[CVE-2018-9206][CNNVD-201810-561] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | Blueimp-jQuery-File-UploadÊÇÒ»¸öÎļþÉÏ´«Ð¡¹¤¾ß£¬£¬£¬£¬£¬£¬°üÀ¨¶à¸öÎļþÑ¡Ôñ£¬£¬£¬£¬£¬£¬ÍÏ·ÅÖ§³Ö£¬£¬£¬£¬£¬£¬½ø¶ÈÌõ£¬£¬£¬£¬£¬£¬ÑéÖ¤ºÍÔ¤ÀÀͼÏñ£¬£¬£¬£¬£¬£¬jQueryµÄÒôƵºÍÊÓÆµ¡£¡£¡£Ö§³Ö¿çÓò¡¢·Ö¿éºÍ¿É»Ö¸´ÎļþÉÏ´«ÒÔ¼°¿Í»§¶ËͼÏñ¾Þϸµ÷½â¡£¡£¡£ÊÊÓÃÓÚÈκÎЧÀÍÆ÷¶Ëƽ̨£¬£¬£¬£¬£¬£¬Ö§³Ö±ê×¼HTML±íµ¥ÎļþÉÏ´«£¨PHP£¬£¬£¬£¬£¬£¬Python£¬£¬£¬£¬£¬£¬RubyonRails£¬£¬£¬£¬£¬£¬Java£¬£¬£¬£¬£¬£¬Node.js£¬£¬£¬£¬£¬£¬GoµÈ£©¡£¡£¡£ÓÉÓÚÆäphp°æ±¾±£´æÎó²î£¬£¬£¬£¬£¬£¬¿Éµ¼ÖÂí§ÒâÎļþÉÏ´«¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_WordPress-Simple-Ads-Manager_ÎļþÉÏ´«[CVE-2015-2825][CNNVD-201504-410] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£WordPressSimpleAdsManagerÊÇÒ»¸öworkpressµÄ¹ã¸æÖÎÀí²å¼þ¡£¡£¡£WordPressSimpleAdsManagerµÄsam-ajax-admin.phpÎļþÖб£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬ÔÊÐíÔ¶³Ì¹¥»÷ÕßʹÓÃÎó²îÌá½»ÌØÊâµÄÎļþ£¬£¬£¬£¬£¬£¬²¢ÒÔWEBȨÏÞÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Net.FliterÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄFilter¹ýÂËÆ÷£¬£¬£¬£¬£¬£¬ÉÏ´«FliterÄÚ´æÂí£¬£¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_IcedID.BCModule_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ¼ì²âµ½IcedIDµÄBCÄ£¿£¿£¿£¿éÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíIcedID¡£¡£¡£IcedIDÊÇ×îÔçÔÚ2017Äê±»Åû¶µÄÄ£¿£¿£¿£¿é»¯ÒøÐÐľÂí£¬£¬£¬£¬£¬£¬Ò²ÊǽüÄêÀ´×îÊ¢ÐеĶñÒâÈí¼þ¼Ò×åÖ®Ò»¡£¡£¡£IcedIDÖ÷ÒªÕë¶Ô½ðÈÚÐÐÒµÌᳫ¹¥»÷£¬£¬£¬£¬£¬£¬»¹»á³äµ±ÆäËû¶ñÒâÈí¼þ¼Ò×壨ÈçVatet¡¢Egregor¡¢REvil£©µÄDropper¡£¡£¡£IcedID°üÀ¨Ò»¸öBCÄ£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬¿ÉÒÔÖ´Ðй¥»÷ÕßµÄÖ¸Á£¬£¬£¬£¬£¬ÈçÔËÐÐVNCºÍSOCKSÄ£¿£¿£¿£¿é¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTPS_ľÂíºóÃÅ_Covenant_ÅþÁ¬C2ЧÀÍÆ÷ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | CovenantÊÇÒ»¸ö.NET¿ª·¢µÄC2(commandandcontrol)¿ò¼Ü£¬£¬£¬£¬£¬£¬Ê¹ÓÃ.NETCoreµÄ¿ª·¢ÇéÐΣ¬£¬£¬£¬£¬£¬²»µ«Ö§³ÖLinux£¬£¬£¬£¬£¬£¬MacOSºÍWindows£¬£¬£¬£¬£¬£¬»¹Ö§³ÖdockerÈÝÆ÷¡£¡£¡£CovenantÖ§³Ö¶¯Ì¬±àÒ룬£¬£¬£¬£¬£¬Äܹ»½«ÊäÈëµÄC#´úÂëÉÏ´«ÖÁC2Server£¬£¬£¬£¬£¬£¬»ñµÃ±àÒëºóµÄÎļþ²¢Ê¹ÓÃAssembly.Load()´ÓÄÚ´æ¾ÙÐмÓÔØ¡£¡£¡£¸ÃÊÂÎñÅú×¢£¬£¬£¬£¬£¬£¬CovenantµÄÌìÉúÎïGruntsÕýÔÚʹÓÃHTTPSÐÒéÓëC2ЧÀÍÆ÷½¨ÉèÅþÁ¬¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_SAP_NETWEAVER_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | SAPNetWeaverÊÇ»ùÓÚרҵ±ê×¼µÄ¼¯³É»¯Ó¦ÓÃÆ½Ì¨£¬£¬£¬£¬£¬£¬Äܹ»´ó·ù¶È½µµÍϵͳÕûºÏµÄÖØ´óÐÔ¡£¡£¡£Æä×é¼þ°üÀ¨ÃÅ»§¡¢Ó¦ÓÃЧÀÍÆ÷¡¢ÉÌÎñÖÇÄܽâ¾ö¼Æ»®ÒÔ¼°ÏµÍ³ÕûºÏºÍÊý¾ÝÕûºÏÊÖÒÕ£¬£¬£¬£¬£¬£¬SAPNetWeaver×é¼þ±£´æÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Spring_Shell_´úÂëÖ´ÐÐ[CVE-2022-22965][CNNVD-202203-2642] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | SpringÊÇÏÖÔÚÈ«Çò×îÊܽӴýµÄJavaÇáÁ¿¼¶¿ªÔ´¿ò¼Ü¡£¡£¡£¹ØÓÚCVE-2022-22965Îó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÁ¬ÏµJDK9¼°ÒÔÉϰ汾һ¸öеÄÊôÐÔ£¬£¬£¬£¬£¬£¬ÀÖ³ÉÈÆ¹ýÀúÊ·Îó²îCVE-2010-1622ÐÞ¸´²¹¶¡£¡£¡£¬£¬£¬£¬£¬£¬Í¬Ê±Á¬ÏµTomcatÈÝÆ÷µÄһЩ²Ù×÷ÊôÐÔ£¬£¬£¬£¬£¬£¬¿ÉʵÏÖ¶ñÒâ´úÂëÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_WordPress_wpDiscuz_7.0.4_í§ÒâÎļþÉÏ´«[CVE-2020-24186][CNNVD-202008-1145] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | WordPressµÄgVectorswpDiscuz²å¼þ7.0ÖÁ7.0.4°æ±¾Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓÃδÂÄÀúÖ¤µÄÓû§Í¨¹ýwmuUploadFilesAjax²Ù×÷ÉÏ´«ÈκÎÀàÐ͵ÄÎļþ£¬£¬£¬£¬£¬£¬°üÀ¨PHPÎļþ,´Ó¶øÊµÏÖÔ¶³Ì´úÂëÖ´ÐÐ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÉèÖÃȱÏÝ_Confluence_server_Ó²±àÂëÈÆ¹ý[CVE-2022-26138] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | AtlassianConfluenceServerÊǰĴóÀûÑÇAtlassian¹«Ë¾µÄÒ»Ì×¾ßÓÐÆóҵ֪ʶÖÎÀí¹¦Ð§£¬£¬£¬£¬£¬£¬²¢Ö§³ÖÓÃÓÚ¹¹½¨ÆóÒµWiKiµÄÐͬÈí¼þµÄЧÀÍÆ÷°æ±¾.ConfluenceServerµÄÀ©Õ¹³ÌÐòQuestionsforConfluenceÔÚijЩ°æ±¾±£´æÒ»¸öĬÈϵÄÓ²±àÂëÓû§£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚδÊÚȨµÄÇéÐÎϵǼconfluence²¢»á¼ûconfluence-users×éÖеÄÓû§¿ÉÒÔ»á¼ûµÄËùÓÐÄÚÈÝ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Zoomla_ÖðÀËCMSϵͳ_í§ÒâÎļþÏÂÔØ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ZoomlaÖðÀËCMSÈí¼þÓÉÉϺ£ÖðÒ»Èí¼þ¿Æ¼¼ÓÐÏÞ¹«Ë¾¡¢½Î÷ÖðÀËÈí¼þ¿Æ¼¼ÓÐÏÞ¹«Ë¾ÁªºÏ¿ª·¢µÄÍøÕ¾ÖÎÀíϵͳ¡£¡£¡£ÒòϵͳÖб£´æÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÏÂÔØí§ÒâÎļþ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Net.HttpListenerÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄHttpListener¼àÌýÆ÷£¬£¬£¬£¬£¬£¬ÉÏ´«HttpListenerÄÚ´æÂí£¬£¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_Wordpress_WP_Property_ÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨¡£¡£¡£¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£WordPressµÄWP-Property²å¼þ£¨1.35.0°æ±¾£©Öб£´æí§ÒâÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÓ¦ÓóÌÐò¶ÔÓû§ÌṩµÄÊäÈëδ¾³ä·Ö¹ýÂË¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚwebЧÀÍÆ÷Àú³ÌÉÏÏÂÎÄÖÐÉÏ´«²¢ÔËÐÐí§ÒâPHP´úÂ룬£¬£¬£¬£¬£¬Õâ¿ÉÄÜÓÐÀûÓÚδÊÚȨ»á¼û»òȨÏÞÌáÉý£¬£¬£¬£¬£¬£¬Ò²¿ÉÄÜÖ´ÐÐÆäËûµÄ¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_MessageSolution_·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý[CNVD-2021-10543] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | MessageSolutionÆóÒµÓʼþ¹éµµÖÎÀíϵͳEEAÊDZ±¾©Ò×Ѷ˼´ï¿Æ¼¼¿ª·¢ÓÐÏÞ¹«Ë¾¿ª·¢µÄÒ»¿îÓʼþ¹éµµÏµÍ³£¬£¬£¬£¬£¬£¬¸Ãϵͳ±£´æÍ¨ÓÃWEBÐÅÏ¢×ß©£¬£¬£¬£¬£¬£¬Ð¹Â¶WindowsЧÀÍÆ÷administratorhashÓëwebÕ˺ÅÃÜÂë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_C3Pool_Xmrig_SetupScript_ÏÂÔØ |
Çå¾²ÀàÐÍ£º | È䳿²¡¶¾ |
ÊÂÎñÐÎò: | ¼ì²âµ½ÏÂÔØC3PoolÍÚ¿ó¾ç±¾µÄÐÐΪ¡£¡£¡£Ô´IP¿ÉÄܱ»Ö²ÈëÁ˶ñÒâľÂíºóÃÅ£¬£¬£¬£¬£¬£¬»òÕßÔ´IP´æÄ³¸öÎó²î£¬£¬£¬£¬£¬£¬±»¹¥»÷´¥·¢Îó²îÀֳɣ¬£¬£¬£¬£¬£¬È¥ÏÂÔØC3PoolÍÚ¿ó¾ç±¾¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_˼¸£µÏ±¤ÀÝ»ú_·ÇÊÚȨ»á¼û/ȨÏÞÈÆ¹ý |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ˼¸£µÏ±¤ÀÝ»ú×°±¸ÊÇÓÃÓÚ¶ÔÔËάְԱ¾ÙÐм¯ÖÐÖÎÀí¡¢¶ÔÔËά²Ù×÷¾ÙÐм¯ÖÐÉ󼯵ÄÇå¾²Éó¼Æ×°±¸¡£¡£¡£Ë¼¸£µÏ±¤ÀÝ»ú£¨ÊÜÓ°Ïì°æ±¾£ºLogBase-B798¡¢bh-x64-v7.0.13¡¢bh-x64-v7.0.15£©±£´æí§ÒâÓû§µÇ¼Îó²î£¬£¬£¬£¬£¬£¬¶ñÒâ¹¥»÷Õß¿ÉÒÔÈÆ¹ý±¤ÀÝ»úµÄÃÜÂëµÇ¼ÑéÖ¤»úÖÆ£¬£¬£¬£¬£¬£¬ÒÔí§ÒâÓû§Éí·ÝËæÒâµÇ¼±¤ÀÝ»úWebÖÎÀí½çÃæ£¬£¬£¬£¬£¬£¬²¢¿ÉÒÔÕý³£µÄʹÓÃÕË»§È¨ÏÞÈ¥²Ù×÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Net.RouteÄÚ´æÂí×¢Èë_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetFrameworkÉϵÄRoute·ÓÉÖÎÀíÆ÷£¬£¬£¬£¬£¬£¬ÉÏ´«RouteÄÚ´æÂí£¬£¬£¬£¬£¬£¬½ø¶ø¾ÙÐиüÉîÈëµÄ¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | TCP_×¢Èë¹¥»÷_WebLogic_WsrmPayloadContext_XXE×¢Èë[CVE-2019-2649][CNNVD-201904-726] |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_WebLogic_WsrmPayloadContext_XXE×¢ÈëÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£HTTP_WebLogic_WsrmPayloadContext_XXE×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚδÊÚȨµÄÇéÐÎϽ«payload·â×°ÔÚT3ÐÒéÖУ¬£¬£¬£¬£¬£¬Í¨¹ý¶ÔT3ÐÒéÖеÄpayload¾ÙÐз´ÐòÁл¯£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖ¶Ô±£´æÎó²îµÄWebLogic×é¼þ¾ÙÐÐÔ¶³ÌBlindXXE¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ÌáȨ¹¥»÷_Apache-Spark-doAS_ÏÂÁî×¢Èë[CVE-2022-33891] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ApacheSparkUIͨ¹ýÉèÖÃÑ¡Ïîspark.acls.enableÉí·ÝÑéÖ¤¹ýÂËÆ÷£¬£¬£¬£¬£¬£¬¼ì²éÓû§ÊÇ·ñ¾ßÓÐÉó²é»òÐÞ¸ÄÓ¦Óᣡ£¡£ÈôÊÇÆôÓÃÁËACL£¬£¬£¬£¬£¬£¬ÔòHttpSecurityFilterÖеĴúÂëÔÊÐíijÈËͨ¹ýÌṩí§ÒâÓû§ÃûÀ´Ö´ÐÐÄ£Äâ¡£¡£¡£¶ñÒâÓû§¿ÉÄÜÈÆ¹ýȨÏÞ¼ì²é¹¦Ð§£¬£¬£¬£¬£¬£¬ÊäÈë¹¹½¨Ò»¸öUnixshellÏÂÁ£¬£¬£¬£¬£¬²¢ÇÒÖ´ÐÐËü¡£¡£¡£½«µ¼ÖÂÖ´ÐÐí§ÒâshellÏÂÁî¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Linux.DDoS.Gafgyt_¿ØÖÆÏÂÁî |
Çå¾²ÀàÐÍ£º | ÆäËûÊÂÎñ |
ÊÂÎñÐÎò: | ¼ì²âµ½GafgytЧÀÍÆ÷ÊÔͼ·¢ËÍÏÂÁî¸øGafgyt£¬£¬£¬£¬£¬£¬Ä¿µÄIPÖ÷»ú±»Ö²ÈëÁËGafgyt¡£¡£¡£DDoS.GafgytÊÇÒ»¸öÀàLinuxƽ̨ϵĽ©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À_php_base64 |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹ÀwebshellľÂí¡£¡£¡£¸ç˹ÀºÍ±ùЫһÑù£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À_php_raw |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹ÀwebshellľÂí¡£¡£¡£¸ç˹ÀºÍ±ùЫһÑù£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_WebShellÉÏ´«_Godzilla¸ç˹À_asp_base64 |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«¸ç˹ÀwebshellľÂí¡£¡£¡£¸ç˹ÀºÍ±ùЫһÑù£¬£¬£¬£¬£¬£¬ÊÇÒ»ÖÖǿʢµÄwebshellÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬½ÓÄɼÓÃÜÁ÷Á¿¾ÙÐÐͨѶ¡£¡£¡£³£±»ºÚ¿ÍÓÃÀ´Î¬³ÖȨÏÞ£¬£¬£¬£¬£¬£¬²¢¾ÙÐÐÏÂÒ»²½µÄÌáȨ»òÒÆ¶¯¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_±ùЫ3.0ÅþÁ¬_»ù´¡ÊÂÎñ2 |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò: | ±ùЫ3.0ÊÇÒ»¿îǿʢµÄwebshellÖÎÀí¹¤¾ß¡£¡£¡£¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓñùЫ3.0ÅþÁ¬Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º | 20220723 |
ÊÂÎñÃû³Æ£º | HTTP_Îļþ²Ù×÷¹¥»÷_¿ÉÒÉ¿ÉÖ´ÐÐÎļþÉÏ´« |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò: | ¼ì²âµ½Ô´ipÖ÷»ú±£´æÉÏ´«¿ÉÒÉwebshellµ½Ä¿µÄipÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º | 20220723 |