2019-11-26
Ðû²¼Ê±¼ä 2019-11-26ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º
TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑéÖ¤Îó²î[CVE-2018-7787]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃSchneider
Electric U.motion BuilderÊäÈëÑéÖ¤Îó²îÀ´Ö´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£
Schneider Electric
U.motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÖÆ¹¹½¨½â¾ö¼Æ»®¡£¡£¡£¡£¡£
Schneider Electric
U.motion Builder 1.3.4֮ǰ°æ±¾Öб£´æÊäÈëÑéÖ¤Îó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷµÄÑéÖ¤HTTP GETÇëÇóÖС®context¡¯²ÎÊýµÄÊäÈë¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
HTTP_LCDS_LAquis_SCADAÇå¾²Îó²î[CVE-2018-18996]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLCDS LAquis
SCADAÇå¾²Îó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ
LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£¡£¡£¡£¡£
LCDS LAquis SCADA
4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØÊÚȨ»ò¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
HTTP_LAquis_SCADA_HTTP²ÎÊýÏÂÁî×¢ÈëÎó²î[CVE-2018-18992]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLAquis
SCADA PAGINA TITULO HTTP²ÎÊýÏÂÁî×¢ÈëÎó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ¡£¡£¡£¡£¡£
LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£¡£¡£¡£¡£
LCDS LAquis SCADA
4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØ¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£
HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÇëÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺÏÏÂÁî×¢Èë×Ö·û¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄHTTP GET»òPOSTÇëÇ󣬣¬£¬£¬£¬£¬£¬ÒÔÔÚÄ¿µÄÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191119
ÊÂÎñÃû³Æ£º
TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow
[CVE-2018-7499]
Çå¾²ÀàÐÍ£º
»º³åÒç³ö
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃAdvantech
WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²îÀ´Ö´ÐÐí§Òâ´úÂëµÄÐÐΪ¡£¡£¡£¡£¡£
Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»£»£»£»£»£»WebAccess
Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£¡£¡£¡£¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£¡£¡£¡£¡£
¸ÃÎó²îÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½BwPSLinkZip.exeµÄ¿ÍÕ»»º³åÇøÖÐʱȱÉÙ½çÏß¼ì²éËùÖ¡£¡£¡£¡£¡£
ͨ¹ý¹¹½¨ÌØÊâµÄRPCÇëÇ󣬣¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÔÚWebAccessÀú³ÌµÄÉÏÏÂÎÄÖе¼ÖÂí§Òâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_KG.Rat_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£
Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£
KuGou.RatÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÅþÁ¬Ô¶³ÌЧÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬½ÓÊÜÖ´ÐкڿÍÖ¸Á£¬£¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£ÊÔͼ»ñÈ¡Ãô¸Ð£¬£¬£¬£¬£¬£¬£¬Èç¼Í¼°´¼üÐÅÏ¢£¬£¬£¬£¬£¬£¬£¬»ñÈ¡½¹µã´°¿ÚµÄÎÊÌâ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_PoisonIvy_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£
Poison IvyÊÇÒ»¸öºÜÊÇÊ¢ÐеÄÔ¶³Ì¿ØÖƹ¤¾ß£¬£¬£¬£¬£¬£¬£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_Win32.WarZoneRat_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£¡£¡£¡£¡£
WarZoneRatÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÔ¶¿Ø£¬£¬£¬£¬£¬£¬£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_ÓÄÁéÔ¶¿Ø¿ÉÒɱäÖÖ_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£
Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£
ÓÄÁéÔ¶¿Ø³ÌÐòÊÇʹÓÃÒ»¸öƾ֤Gh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅ¡£¡£¡£¡£¡£ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TUDP_ºóÃÅ_Win32.ZeroAcess_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£
Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£
Win32.ZeroAcessÊÇÒ»¸öºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬£¬×¢ÈëÆäËûÀú³Ì¡£¡£¡£¡£¡£ÏÂÔØÆäËû²¡¶¾»òÕßÉèÖÃÐÅÏ¢»òÕßÄ£¿£¿£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£
Éϱ¨¸ÃÊÂÎñÓÐÁ½ÖÖ¿ÉÄÜ£¬£¬£¬£¬£¬£¬£¬Ò»ÊÇÔ´Ö÷»ú±»Ñ¬È¾ÁË£¬£¬£¬£¬£¬£¬£¬ÅþÁ¬CCЧÀÍÆ÷£»£»£»£»£»£»¶þÊÇZeroAcessЧÀÍÆ÷¶Ëͨ¹ýshadanÊðÀí·½·¨¾ÙÐÐɨÃèÐÐΪ£¬£¬£¬£¬£¬£¬£¬Ö÷Òª¿´Ô´IPÊÇ·ñÊDZ¾µ¥Î»µÄIPµØµã¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_Linux.BillGates_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£¡£¡£¡£¡£
BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐDDoS¹¥»÷¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ľÂí_CoinMiner_ÅþÁ¬¿ó³ØÀÖ³É
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£¡£¡£¡£¡£
CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£¡£¡£¡£¡£
wingamesÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126
ÊÂÎñÃû³Æ£º
TCP_ľÂí_CoinMiner_ʵÑéÅþÁ¬¿ó³Ø
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£¡£¡£¡£¡£
CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò£¬£¬£¬£¬£¬£¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´£¬£¬£¬£¬£¬£¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191126


¾©¹«Íø°²±¸11010802024551ºÅ