ÿÖÜÉý¼¶Í¨¸æ-2021-05-18

Ðû²¼Ê±¼ä 2021-05-19

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_PHP-zerodiumºóÃÅ_í§Òâ´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄÆÊÎöÀú³ÌÖз¢Ã÷£¬£¬ £¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»Ð®ÖÆµÄÍøÕ¾ÉÏ£¬£¬ £¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬£¬ £¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢Ö°Ô±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£¡£¡£ÏÖÔÚΪֹPHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ¾ÙÐиü¶àÅû¶£¬£¬ £¬£¬£¬£¬ÌåÏÖ´Ë´ÎЧÀÍÆ÷±»ºÚµÄÏêϸϸ½ÚÈÔÔÚÊӲ쵱ÖС£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬£¬ £¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ­±»Î¬»¤Ö°Ô±Ç¨áãÖÁGitHubƽ̨£¬£¬ £¬£¬£¬£¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϾÙÐС£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Gh0st_htrfhtfe__ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬£¬ £¬£¬£¬£¬¹¦Ð§Ê®·Öǿʢ¡£¡£¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬£¬ £¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£½üÆÚ·¢Ã÷´ó×ÚÆ¾Ö¤Gh0stÔ´ÂëÐ޸ĵÄÔ¶¿Ø³ÌÐò£¬£¬ £¬£¬£¬£¬²¢Ìí¼ÓÁË×Ô¼ºµÄ¹¦Ð§£¬£¬ £¬£¬£¬£¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳװÖõÄÍøÂçÓÎÏ·µÈ¹¦Ð§¡£¡£¡£ºÚ¿Í»¹¿ÉÒÔ½«º¬ÓÐÉãÏñÍ·»ò×°ÖÃÖ¸¶¨ÓÎÏ·µÄÓû§¹éÀ࣬£¬ £¬£¬£¬£¬ÓÐÕë¶ÔÐÔµÄ͵ȡÓû§Òþ˽¡£¡£¡£ÉõÖÁÉó²éÖж¾ÕßµØÀíλÖõĹ¦Ð§£¬£¬ £¬£¬£¬£¬¶ÔÓû§µÄÒþ˽Ôì³É¸ü´óµÄÍþв¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-28188][CNNVD-202012-1548]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬ £¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬£¬ £¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_SSH-RSA˽Կ×ß©

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ£¬£¬ £¬£¬£¬£¬LINUXЧÀÍÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH£¬£¬ £¬£¬£¬£¬RSA˽Կй¶£¬£¬ £¬£¬£¬£¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH£¬£¬ £¬£¬£¬£¬µ¼ÖÂÖ÷»ú±»½ÓÊÜ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210511


ÊÂÎñÃû³Æ£º

HTTP_Microsoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Ä¿½ñÖ÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¸ÃÎó²îÊÇExchangeÖеÄí§ÒâÎļþдÈëÎó²î¡£¡£¡£¸ÃÎó²îÐèÒª¾ÙÐÐÉí·ÝÈÏÖ¤£¬£¬ £¬£¬£¬£¬Ê¹ÓôËÎó²î¿ÉÒÔ½«ÎļþдÈëЧÀÍÆ÷ÉϵÄÈκη¾¶¡£¡£¡£²¢¿ÉÒÔÁ¬ÏµÊ¹ÓÃCVE-2021-26855SSRFÎó²î»òÈÆ¹ýȨÏÞÈÏÖ¤¾ÙÐÐÎļþдÈë¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÅþÁ¬C2ЧÀÍÆ÷µÄÐÐΪ¡£¡£¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí£¬£¬ £¬£¬£¬£¬¾ßÓÐËѼ¯Êܺ¦Ö÷»úÃô¸ÐÐÅÏ¢ÉÏ´«µ½C2ЧÀÍÆ÷µÄÐÐΪ£¬£¬ £¬£¬£¬£¬ÏÂÔØÍÚ¿ó³ÌÐòµ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIEÀú³ÌÖÐÖ´ÐÐÍڿ󣬣¬ £¬£¬£¬£¬Æ¾Ö¤C2ЧÀÍÆ÷µÄÏÂÁîÖ´ÐÐÖݪֲÙ×÷£¬£¬ £¬£¬£¬£¬Èç¸üÐÂÉèÖÃÐÅÏ¢¡¢×°ÖÃÍÚ¿ó³ÌÐòµÈ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£

Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£

Îó²î±£´æµÄ°æ±¾£º

S2-016£ºStruts 2.0.0 - Struts 2.3.15

S2-017£ºStruts 2.0.0 - Struts 2.3.15

S2-018£ºStruts 2.0.0 - Struts 2.3.15.2

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Raccoon.Stealer_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£¡£¡£RaccoonÒ²±»³ÆÎªMohazo»òRacealer£¬£¬ £¬£¬£¬£¬ÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÇÔÃÜľÂí¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶ËÉúÑĵÄÕ˺ÅÃÜÂë¡£¡£¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£

¸üÐÂʱ¼ä£º

20210518


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬£¬ £¬£¬£¬£¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬£¬ £¬£¬£¬£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£¡£¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬£¬ £¬£¬£¬£¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬£¬ £¬£¬£¬£¬¿ÉÏòЧÀÍÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬£¬ £¬£¬£¬£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷Ö÷»ú¡£¡£¡£ÁíÍ⣬£¬ £¬£¬£¬£¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬£¬ £¬£¬£¬£¬boundary´óÓÚ½çÏßÖµ£¬£¬ £¬£¬£¬£¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬£¬ £¬£¬£¬£¬µ¼ÖÂDDOS¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ


1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ