2019-05-22
Ðû²¼Ê±¼ä 2019-05-22ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º |
HTTP_ºóÃÅ_APT×éÖ¯_MuddyWater_Ô¶³ÌЧÀÍÆ÷ÅþÁ¬ |
ÊÂÎñ¼¶±ð£º |
¸ß¼¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMuddyWater×é֯ʹÓõĺóÃÅ¡£¡£¡£¡£¡£ MuddyWaterÊÇÒ»¸öÖ÷ÒªÕë¶ÔÒÁÀ¿ËºÍÉ³ÌØ°¢À²®µÄÕþ¸®»ú¹¹µÄAPT×éÖ¯£¬£¬£¬£¬£¬£¬¸ÃAPT×éÖ¯±³ºóµÄÍŶÓͬÑùÕë¶ÔÖж«Å·ÖÞºÍÃÀ¹úµÈÆäËû¹ú¼Ò¡£¡£¡£¡£¡£ÆäÖ÷ҪʹÓÃPowershell¾ÙÐÐËûÃǵĶñÒâÐÐΪ£¬£¬£¬£¬£¬£¬ÔÚһϵÁÐÐж¯ÖÐÑÜÉú³öÁËËûÃǵÄרÓÐľÂíPOWERSTATS¡£¡£¡£¡£¡£¸Ã×éÖ¯µÄ¹¥»÷Ä¿µÄÖ÷Òª¼¯ÖÐÔÚÕþ¸®£¬£¬£¬£¬£¬£¬Í¨Ñ¶ÓëʯÓÍÁìÓò£¬£¬£¬£¬£¬£¬¸Ã×éÖ¯ÒÉËÆÀ´×ÔÓÚÒÁÀÊ¡£¡£¡£¡£¡£¸ÃÊÂÎñÅú×¢MuddyWater×é֯ʹÓúóÃÅÓëÔ¶³ÌЧÀÍÆ÷ÅþÁ¬²¢ÎüÊÕÏÂÁîÖ´ÐС£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_ľÂí_KPot.Stealer_ÅþÁ¬ |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËKPot¡£¡£¡£¡£¡£
KPotÊÇÒ»¸öÇÔÃÜľÂí£¬£¬£¬£¬£¬£¬¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢Skype¡¢Steam¡¢FTPµÈ¿Í»§¶ËÉúÑĵÄÕ˺ÅÃÜÂë¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Jenkins_GitLab²å¼þÐÅϢй¶Îó²î[CVE-2019-10300] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÕýÔÚʹÓÃGitLab²å¼þÐÅϢй¶µÄÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Jenkins_ScriptSecurityPluginÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-1003005] |
ÊÂÎñ¼¶±ð£º |
¸ß¼¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Jenkins_ScriptSecurityPluginÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
TCP_SpringDataCommon_SPEL_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-1273] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTCP_SpringDataCommon_SPEL_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_NUUO_NVRMini2Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2018-14933] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_NUUO_NVRMini2Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_NUUO_NVRMini2Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2018-15716] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_NUUO_NVRMini2Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
TCP_SpringOAuth2_SPEL_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-1260] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTCP_SpringOAuth2_SPEL_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Çå¾²Îó²î_Spring_Cloud_Config_Server·¾¶´©Ô½Óëí§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2019-3799] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
¼ì²âµ½Spring Cloud Config Server·¾¶´©Ô½Óëí§ÒâÎļþ¶ÁÈ¡Îó²î¡£¡£¡£¡£¡£ Pivotal Software Spring Cloud ConfigÊÇÃÀ¹úPivotal Software¹«Ë¾µÄÒ»Ì×ÂþÑÜʽϵͳµÄÉèÖÃÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¡£¡£¸Ã²úÆ·Ö÷ҪΪÂþÑÜʽϵͳÖеÄÍⲿÉèÖÃÌṩЧÀÍÆ÷ºÍ¿Í»§¶ËÖ§³Ö¡£¡£¡£¡£¡£ Spring Cloud ConfigÖб£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÍøÂçϵͳ»ò²úƷδÄÜ׼ȷµØ¹ýÂË×ÊÔ´»òÎļþ·¾¶ÖеÄÌØÊâÔªËØ¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²î»á¼ûÊÜÏÞĿ¼֮ÍâµÄÃô¸ÐÎļþ£¬£¬£¬£¬£¬£¬Ôì³ÉÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Çå¾²Îó²î_Ruby_on_Rails·¾¶´©Ô½Óëí§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2019-5418] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
Ruby on RailsÊÇÒ»¸ö Web Ó¦ÓóÌÐò¿ò¼Ü,ÊÇÒ»¸öÏà¶Ô½ÏÐ嵀 Web Ó¦ÓóÌÐò¿ò¼Ü£¬£¬£¬£¬£¬£¬¹¹½¨ÔÚ Ruby ÓïÑÔÖ®ÉÏ¡£¡£¡£¡£¡£ ¸ÃÎó²îÊÇAction ViewÖб£´æÇå¾²Îó²î¡£¡£¡£¡£¡£ÓÉÓÚÍøÕ¾Ê¹ÓÃÁËΪָ¶¨²ÎÊýµÄrender fileÀ´äÖȾӦÓÃÖ®ÍâµÄÊÓͼ£¬£¬£¬£¬£¬£¬Í¨¹ý¡°../../../../¡±À´µÖ´ï·¾¶´©Ô½µÄÄ¿µÄ£¬£¬£¬£¬£¬£¬ÇÒͨ¹ý¡°{{¡±À´¾ÙÐÐÄ£°åÅÌÎÊ·¾¶µÄ±ÕºÏ£¬£¬£¬£¬£¬£¬Ê¹µÃËùÒª»á¼ûµÄÎļþ±»µ±×öÍⲿģ°åÀ´ÆÊÎö¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îй¶ÎļþÄÚÈÝ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Çå¾²Îó²î_Ruby_On_Rails·¾¶´©Ô½Îó²î[CVE-2018-3760] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
SprocketsÊÇÈí¼þ¿ª·¢ÕßSam StephensonºÍJoshua PeekÅäºÏÑз¢µÄÒ»¸öRuby¿â£¬£¬£¬£¬£¬£¬ËüÖ÷ÒªÓÃÓÚ¼ì²éJavaScriptÎļþµÄÏ໥ÒÀÀµ¹ØÏµ£¬£¬£¬£¬£¬£¬ÒÔ¼°ÓÅ»¯ÍøÒ³ÖÐÒýÈëµÄJSÎļþ£¬£¬£¬£¬£¬£¬¿É×èÖ¹¼ÓÔØ²»ÐëÒªµÄJSÎļþ£¬£¬£¬£¬£¬£¬¼ÓËÙÍøÒ³»á¼ûËÙÂÊ¡£¡£¡£¡£¡£ Sprockets 4.0.0.beta7¼°Ö®Ç°°æ±¾¡¢3.7.1¼°Ö®Ç°°æ±¾ºÍ2.12.4¼°Ö®Ç°°æ±¾Öб£´æÐÅϢй¶Îó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý·¢ËÍÌØÖÆµÄÇëÇóʹÓøÃÎó²î»á¼ûÎļþϵͳÉϵÄÓ¦ÓóÌÐòrootĿ¼֮ÍâµÄÎļþ¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
HTTP_Çå¾²Îó²î_ZTE_ZXV10_H108L_Router_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
ÊÂÎñÐÎò£º |
ZTE ZXV10 H108L RouterÊÇÖйúÖÐÐËͨѶ£¨ZTE£©¹«Ë¾µÄÒ»¿îÎÞÏß·ÓÉÆ÷²úÆ·¡£¡£¡£¡£¡£Ê¹ÓÃWIND Hellas°æ±¾¹Ì¼þµÄZXV10 H108L·ÓÉÆ÷Öб£´æÏµÍ³ÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓÃrootȨÏÞÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20190522 |
ĬÈÏÐж¯£º |
ÑïÆú |
ÊÂÎñÃû³Æ£º |
TCP_΢ÈíÔ¶³Ì×ÀÃæÐ§ÀÍÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-0708] |
ÊÂÎñ¼¶±ð£º |
Öм¶ÊÂÎñ |
Çå¾²ÀàÐÍ£º |
»º³åÒç³ö |
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃTCP_RDPÔ¶³Ì´úÂëÒç³öÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ |
¸üÐÂʱ¼ä£º |
|
ĬÈÏÐж¯£º |
ͨ¹ý |
ÐÞ¸ÄÊÂÎñ
ÎÞ