2020-03-10
Ðû²¼Ê±¼ä 2020-03-11ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶Ô¿ÉÄܱ£´æ.NET·´ÐòÁл¯Îó²îµÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý
¹¥»÷Õß¿ÉÌύȫÐĽṹµÄ·´ÐòÁл¯Êý¾ÝÀ´Ê¹ÓôËÎó²î¡£¡£¡£¡£¡£¡£ÀÖ³ÉʹÓôËÎó²îµÄ¹¥»÷Õß¿ÉÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_CharmingKitten.Backdoor_ÊÔͼÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½ CharmingKitten.Backdoor ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCharmingKitten.Backdoor¡£¡£¡£¡£¡£¡£
CharmingKitten.BackdoorÊÇCharming Kitten×éÖ¯µÄÒ»¸öºóÃÅ£¬£¬£¬Ëü»áÇÔÈ¡Óû§µÄÅÌËã»úÐÅÏ¢£¬£¬£¬Èç²Ù×÷ϵͳÐÅÏ¢¡¢ipµØµãµÈ£¬£¬£¬²¢ÇÒ»¹»á´ÓÔ¶³ÌЧÀÍÆ÷ÏÂÔØÎļþÖ´ÐС£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º |
UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
ÊÂÎñÐÎò£º |
¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨѶ¡£¡£¡£¡£¡£¡£ÓÉÓÚÊÇ»ùÓÚP2PÐÒ飬£¬£¬Ô´IPºÍÄ¿µÄIPËùÔÚµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£¡£¡£¡£¡£¡£ MoziÊÇÒ»¸ö»ùÓÚP2PÐÒéµÄ½©Ê¬ÍøÂ磬£¬£¬Ö÷ÒªÖ§³ÖµÄ¹¦Ð§Îª£ºDDoS¹¥»÷¡¢ÍøÂçBotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ÏÂÁî¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º |
20200310 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_½©Ê¬ÍøÂç_MiraiXMiner_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½½©Ê¬ÍøÂçMiraiXMinerÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMiraiXMiner¡£¡£¡£¡£¡£¡£
MiraiXMinerÊÇÒ»¸öÈÔÈ»»îÔ¾×ŵĽ©Ê¬ÍøÂ磬£¬£¬ÈÚºÏÁ˶àÖÖÒÑÖª²¡¶¾¼Ò×壬£¬£¬°üÀ¨Mirai¡¢MyKings¡¢Ô¶¿Ø¡¢ÍÚ¿óµÈ¡£¡£¡£¡£¡£¡£Ê¹ÓÃÓÀºãÖ®À¶Îó²î¡¢±Õ·µçÊÓÎïÁªÍø×°±¸Îó²î¡¢MSSQLÎó²î¡¢RDP±¬ÆÆºÍTelnet±¬ÆÆµÈ·½·¨Èö²¥×ÔÉí¡£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£¡£¡£¡£
ircBotÊÇ»ùÓÚircÐÒéµÄ½©Ê¬ÍøÂ磬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£»£»£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º
TCP_Windows_ϵͳĬÈϹ²ÏíÅþÁ¬
Çå¾²ÀàÐÍ£º
Çå¾²Éó¼Æ
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IP¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐĬÈÏÅþÁ¬µÄÐÐΪ.¡£¡£¡£¡£¡£¡£
WindowsÆô¶¯Ê±¶¼»áĬÈÏ·¿ªadmin$ ipc$ ºÍÿ¸öÅÌ·ûµÄ¹²Ïí£¬£¬£¬¹¥»÷Õßͨ³£»£»£»£»£»áʹÓù²ÏíÎó²îÈëÇÖµçÄÔÖ÷»ú¡£¡£¡£¡£¡£¡£
±¨¾¯¸ÃÊÂÎñ˵Ã÷Óпͻ§¶ËÔÚÔ¶³ÌÅþÁ¬¸ÃЧÀÍÆ÷£¬£¬£¬²¢ÇÒÓÐÐÞ¸ÄЧÀͶËÎļþµÄÐÐΪ£¬£¬£¬ÈôÊÇЧÀͶËÇéÐÎ×Ô¼º¾ÍÓÐʹÓÃsmbÏà¹Ø¹¦Ð§µÄÓªÒµ£¬£¬£¬¿ÉÒÔºöÂÔ¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£ÈôÊÇÏëҪեȡC$¡¢D$¡¢E$Ò»ÀàµÄ¹²Ïí£¬£¬£¬¿ÉÒÔµ¥»÷¡°×îÏÈ¡úÔËÐС±ÏÂÁ£¬£¬ÔÚÔËÐд°¿Ú¼üÈë¡°Regedit¡±ºó»Ø³µ£¬£¬£¬·¿ª×¢²á±í±à¼Æ÷¡£¡£¡£¡£¡£¡£ÒÀ´ÎÕö¿ª[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
]·ÖÖ§£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareServer¡±ÉèÖÃΪ¡°0¡±¼´¿É¡£¡£¡£¡£¡£¡£ ÈôÊÇҪեȡADMIN$¹²Ïí£¬£¬£¬¿ÉÒÔÔÚͬÑùµÄ·ÖÖ§Ï£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareWKs¡± ÉèÖÃΪ¡°0¡±¼´¿É¡£¡£¡£¡£¡£¡£ ÈôÊÇҪեȡIPC$¹²Ïí£¬£¬£¬¿ÉÒÔÔÚ×¢²á±í±à¼Æ÷ÖÐÒÀ´ÎÕö¿ª[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]·ÖÖ§£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°restrictanonymous¡±ÉèÖÃֵΪ¡°1¡±¼´¿É¡£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310
ÊÂÎñÃû³Æ£º
HTTP_Java·´ÐòÁл¯_POST·½·¨_ysoserial¶ñÒâÊý¾Ý
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_Java·´ÐòÁл¯_POST·½·¨_ysoserial¶ñÒâÊý¾Ý¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£
Èô»á¼ûµÄÒ³Ãæ±£´æÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄ Java ÐòÁл¯¹¤¾ß£¬£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º
20200310