2021-04-15

Ðû²¼Ê±¼ä 2021-04-15
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_Ô¶³Ì´úÂë_CitrixÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2019-19781]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CitrixADCÊÇÒ»¿îÓ¦Óý»¸¶Controller£¬ £¬£¬£¬£¬ £¬ÓÃÓÚÆÊÎöÌØ¶¨ÓÚÓ¦ÓõÄÁ÷Á¿£¬ £¬£¬£¬£¬ £¬ÒÔ±ãÖÇÄܵØÎªWebÓ¦ÓóÌÐò·ÖÅÉ¡¢ÓÅ»¯ºÍ±£»£»£»£»¤4²ã7(L4-L7)ÍøÂçÁ÷Á¿¡£¡£¡£¡£¡£¡£¡£CitrixGatewayÕûºÏÁËÔ¶³Ì»á¼û»ù´¡½á¹¹£¬ £¬£¬£¬£¬ £¬ÒÔ±ã¿çËùÓÐÓ¦ÓóÌÐòÌṩµ¥µãµÇ¼£¬ £¬£¬£¬£¬ £¬ÎÞÂÛÊÇÔÚÊý¾ÝÖÐÐÄ¡¢ÔÆÖÐÕÕ¾É×÷ΪSaaS´«Êä¡£¡£¡£¡£¡£¡£¡£ÔÚCitrixADCºÍCitrixGatewayÖб£´æÄ¿Â¼±éÀúÎó²î£¬ £¬£¬£¬£¬ £¬ÔÊÐíδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁî¹¥»÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Chromium_V8_JavaScriptÒýÇæ_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8JavaScriptÒýÇæÖÐ,±£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¿ØÖÆhtml¼ÓÔØ¶ñÒâJavaScriptÎļþ£¬ £¬£¬£¬£¬ £¬µÖ´ïÔÚ±»¹¥»÷ÕßÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁîµÄЧ¹û¡£¡£¡£¡£¡£¡£¡£µ«´ËÎó²îÎÞ·¨Í»ÆÆChromeɳÏäÕâÒ»Çå¾²»úÖÆ£¬ £¬£¬£¬£¬ £¬ÒÔÊÇÓ°ÏìÓÐÏÞ¡£¡£¡£¡£¡£¡£¡£ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÇå¾²½çÏߣ¬ £¬£¬£¬£¬ £¬¿É±ÜÃâÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÖ÷»úÉÏÆô¶¯³ÌÐò£¬ £¬£¬£¬£¬ £¬¸ÃÎó²îµ¥¶ÀʹÓÃʱÏÖÔÚÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬 £¬£¬£¬£¬ £¬Òò´Ë¸ÃÎó²îÐèÒªÓëÁíÍâµÄÎó²î£¨ChromeɳÏäÌÓÒÝ£©Á´½ÓÔÚÒ»ÆðÀ´Ê¹Ó㬠£¬£¬£¬£¬ £¬×îÖÕ¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TongWeb_ÎļþÉÏ´«È¨ÏÞÒþ²ØÕË»§µÇ¼ʵÑé

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßʹÓÃTongWebÔ¤ÁôµÄ£¬ £¬£¬£¬£¬ £¬¾ßÓÐÎļþÉÏ´«È¨ÏÞµÄÒþ²ØÕË»§¾ÙÐеǼʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£TongWebÊǺ£ÄÚÕþÆóÓªÒµÆÕ±éÓ¦ÓõÄWEBÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£´ËÓ¦Óñ£´æÒ»¸öÒþ²ØµÄÓû§£¬ £¬£¬£¬£¬ £¬ÇÒÓÐÀο¿µÄ¡¢ÎÞ·¨¸ü¸ÄµÄĬÈÏÃÜÂ룬 £¬£¬£¬£¬ £¬¾ßÓÐŲÓÃÎļþÉÏ´«½Ó¿ÚµÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÓû§£¬ £¬£¬£¬£¬ £¬¾ÙÐÐÉÏ´«í§ÒâÎļþµÄΣÏÕ²Ù×÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson_dnslog̽²â

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃdnslog̽²âÖ÷»úºó¶ËÊÇ·ñÊÇfastjson£»£»£»£»

¸üÐÂʱ¼ä£º

20210415


ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£¡£¡£¡£¡£ircBotÊÇ»ùÓÚircЭÒéµÄ½©Ê¬ÍøÂ磬 £¬£¬£¬£¬ £¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£»£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_ÖÎÀí¹¤¾ß_asp¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÉϵÄwebshellÖÎÀí¹¤¾ß¿Í»§¹æÔòÔÚÏòÄ¿µÄIPµØµãÖ÷»úÉϵÄwebshellЧÀÍÆ÷¶Ë·¢³ö¿ØÖÆÏÂÁî¡£¡£¡£¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¡£¡£¡£¼òÆÓÀ´Ëµ£¬ £¬£¬£¬£¬ £¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬ £¬£¬£¬£¬ £¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬ £¬£¬£¬£¬ £¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬ £¬£¬£¬£¬ £¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬ £¬£¬£¬£¬ £¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬ £¬£¬£¬£¬ £¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬ £¬£¬£¬£¬ £¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬ £¬£¬£¬£¬ £¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬ £¬£¬£¬£¬ £¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬ £¬£¬£¬£¬ £¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_wget_curlÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍ¿ÉÒÉÏÂÁ £¬£¬£¬£¬ £¬ÊµÑé¿ØÖÆÄ¿µÄIPÖ÷»úÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐС£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_±ùЫ3.0ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓñùЫ3.0ÅþÁ¬Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ɾ³ýÊÂÎñ


1. TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_ÅþÁ¬_1