ÿÖÜÉý¼¶Í¨¸æ-2021-05-18
Ðû²¼Ê±¼ä 2021-05-19ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_PHP-zerodiumºóÃÅ_í§Òâ´úÂëÖ´ÐÐÎó²î |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄÆÊÎöÀú³ÌÖз¢Ã÷£¬£¬£¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»Ð®ÖÆµÄÍøÕ¾ÉÏ£¬£¬£¬£¬£¬£¬²¢ÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢Ö°Ô±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£¡£¡£ÏÖÔÚΪֹPHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ¾ÙÐиü¶àÅû¶£¬£¬£¬£¬£¬£¬ÌåÏÖ´Ë´ÎЧÀÍÆ÷±»ºÚµÄÏêϸϸ½ÚÈÔÔÚÊӲ쵱ÖС£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ±»Î¬»¤Ö°Ô±Ç¨áãÖÁGitHubƽ̨£¬£¬£¬£¬£¬£¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϾÙÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Gh0st_htrfhtfe__ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø³ÌÐò£¬£¬£¬£¬£¬£¬¹¦Ð§Ê®·Öǿʢ¡£¡£¡£¾ßÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢½¨É衢ɾ³ý£©¡¢Àú³ÌÖÎÀí¡¢ÏµÍ³Ð§ÀÍ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢Éó²éÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£½üÆÚ·¢Ã÷´ó×ÚÆ¾Ö¤Gh0stÔ´ÂëÐ޸ĵÄÔ¶¿Ø³ÌÐò£¬£¬£¬£¬£¬£¬²¢Ìí¼ÓÁË×Ô¼ºµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳװÖõÄÍøÂçÓÎÏ·µÈ¹¦Ð§¡£¡£¡£ºÚ¿Í»¹¿ÉÒÔ½«º¬ÓÐÉãÏñÍ·»ò×°ÖÃÖ¸¶¨ÓÎÏ·µÄÓû§¹éÀ࣬£¬£¬£¬£¬£¬ÓÐÕë¶ÔÐÔµÄ͵ȡÓû§Òþ˽¡£¡£¡£ÉõÖÁÉó²éÖж¾ÕßµØÀíλÖõĹ¦Ð§£¬£¬£¬£¬£¬£¬¶ÔÓû§µÄÒþ˽Ôì³É¸ü´óµÄÍþв¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Terramaster_TOS_ÏÂÁî×¢ÈëÎó²î[CVE-2020-28188][CNNVD-202012-1548] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×ÓÊÖÒÕ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬£¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NASЧÀÍÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îͨ¹ýÔÚÊÂÎñ²ÎÊýÖаüÀ¨makecvs.php×¢Èë²Ù×÷ϵͳÏÂÁî¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_SSH-RSA˽Կ×ß© |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ£¬£¬£¬£¬£¬£¬LINUXЧÀÍÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH£¬£¬£¬£¬£¬£¬RSA˽Կй¶£¬£¬£¬£¬£¬£¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH£¬£¬£¬£¬£¬£¬µ¼ÖÂÖ÷»ú±»½ÓÊÜ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210511 |
ÊÂÎñÃû³Æ£º | HTTP_Microsoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | Ä¿½ñÖ÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_ЧÀÍÆ÷¶ËÇëÇóαÔì¹¥»÷¸ÃÎó²îÊÇExchangeÖеÄí§ÒâÎļþдÈëÎó²î¡£¡£¡£¸ÃÎó²îÐèÒª¾ÙÐÐÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬£¬Ê¹ÓôËÎó²î¿ÉÒÔ½«ÎļþдÈëЧÀÍÆ÷ÉϵÄÈκη¾¶¡£¡£¡£²¢¿ÉÒÔÁ¬ÏµÊ¹ÓÃCVE-2021-26855SSRFÎó²î»òÈÆ¹ýȨÏÞÈÏÖ¤¾ÙÐÐÎļþдÈë¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_ÅþÁ¬C2ЧÀÍÆ÷ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÅþÁ¬C2ЧÀÍÆ÷µÄÐÐΪ¡£¡£¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí£¬£¬£¬£¬£¬£¬¾ßÓÐËѼ¯Êܺ¦Ö÷»úÃô¸ÐÐÅÏ¢ÉÏ´«µ½C2ЧÀÍÆ÷µÄÐÐΪ£¬£¬£¬£¬£¬£¬ÏÂÔØÍÚ¿ó³ÌÐòµ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIEÀú³ÌÖÐÖ´ÐÐÍڿ󣬣¬£¬£¬£¬£¬Æ¾Ö¤C2ЧÀÍÆ÷µÄÏÂÁîÖ´ÐÐÖݪֲÙ×÷£¬£¬£¬£¬£¬£¬Èç¸üÐÂÉèÖÃÐÅÏ¢¡¢×°ÖÃÍÚ¿ó³ÌÐòµÈ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£ Îó²î±£´æµÄ°æ±¾£º S2-016£ºStruts 2.0.0 - Struts 2.3.15 S2-017£ºStruts 2.0.0 - Struts 2.3.15 S2-018£ºStruts 2.0.0 - Struts 2.3.15.2 |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Raccoon.Stealer_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£¡£¡£RaccoonÒ²±»³ÆÎªMohazo»òRacealer£¬£¬£¬£¬£¬£¬ÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÇÔÃÜľÂí¡£¡£¡£Ëü¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶ËÉúÑĵÄÕ˺ÅÃÜÂë¡£¡£¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬£¬£¬£¬£¬£¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬£¬£¬£¬£¬£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£¡£¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬£¬£¬£¬£¬£¬¿ÉÏòЧÀÍÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷Ö÷»ú¡£¡£¡£ÁíÍ⣬£¬£¬£¬£¬£¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬£¬£¬£¬£¬£¬boundary´óÓÚ½çÏßÖµ£¬£¬£¬£¬£¬£¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬£¬£¬£¬£¬£¬µ¼ÖÂDDOS¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null |
¸üÐÂʱ¼ä£º | 20210518 |
ÐÞ¸ÄÊÂÎñ
1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î
2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ