ÿÖÜÉý¼¶Í¨¸æ-2022-09-06

Ðû²¼Ê±¼ä 2022-09-06
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_VMware_vCenter_Server_ÎļþÉÏ´«[CVE-2021-22005]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

VMwareÊÇÒ»¼ÒÔÆ»ù´¡¼Ü¹¹ºÍÒÆ¶¯ÉÌÎñ½â¾ö¼Æ»®³§ÉÌ£¬£¬ £¬£¬ £¬£¬Ìṩ»ùÓÚVMwareµÄÐéÄ⻯½â¾ö¼Æ»®¡£¡£¡£2021Äê9ÔÂ22ÈÕ£¬£¬ £¬£¬ £¬£¬VMware¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬ £¬£¬ £¬£¬Åû¶Á˰üÀ¨CVE-2021-22005VMwarevCenterServerí§ÒâÎļþÉÏ´«Îó²îÔÚÄڵĶàÆäÖиßΣÑÏÖØÎó²î¡£¡£¡£ÊܸÃÎó²îµÄÓ°Ïì°æ±¾ÎªVMwarevCenterServer7.0ϵÁÐ<7.0U2c,VMwarevCenterServer6.7ϵÁÐ<6.7U3o,ÔÚCVE-2021-22005ÖУ¬£¬ £¬£¬ £¬£¬¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬ £¬£¬ £¬£¬Í¨¹ývCenterÖеÄAnalyticsЧÀÍ£¬£¬ £¬£¬ £¬£¬¿ÉÉÏ´«¶ñÒâÎļþ£¬£¬ £¬£¬ £¬£¬´Ó¶øÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Zabbix_СÓÚ4.4_δÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZabbixÊÇÀ­ÍÑάÑÇZabbixSIA¹«Ë¾µÄÒ»Ì׿ªÔ´µÄ¼à¿ØÏµÍ³¡£¡£¡£¸Ãϵͳ¿É¼àÊÓÖÖÖÖÍøÂç²ÎÊý£¬£¬ £¬£¬ £¬£¬²¢Ìṩ֪ͨ»úÖÆÈÃϵͳÖÎÀíÔ±¿ìËÙ¶¨Î»¡¢½â¾ö±£´æµÄÖÖÖÖÎÊÌâ¡£¡£¡£Zabbix±£´æÒ»¸öδÊÚȨ»á¼ûÎó²î£¬£¬ £¬£¬ £¬£¬Í¨¹ý¸ÃÎó²î£¬£¬ £¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÔÚδ¾­ÊÚȨµÄÇéÐÎÏ»á¼ûZabbixЧÀÍÆ÷ÉϵÄÊý¾Ý£¬£¬ £¬£¬ £¬£¬µ¼ÖÂÃô¸ÐÐÅϢй¶¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_wmRat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½wmRatÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËwmRat¡£¡£¡£wmRatÊÇÂûÁ黨×éÖ¯ËùʹÓÃÁËÒ»¸öÇáÁ¿»¯ºóÃÅ£¬£¬ £¬£¬ £¬£¬»ùÓÚCSharpÓïÑÔ£¬£¬ £¬£¬ £¬£¬ÔËÐк󣬣¬ £¬£¬ £¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Orchard_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçOrchardÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷£¬£¬ £¬£¬ £¬£¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçOrchard¡£¡£¡£OrchardÊÇ2021Äê2Ô·ºÆðµÄÒ»¸ö½©Ê¬ÍøÂ磬£¬ £¬£¬ £¬£¬Ê¹ÓÃDGAÊÖÒÕ¶Ô¿¹¼ì²â¡£¡£¡£½¹µã¹¦Ð§ÔÚÊܺ¦Õß»úеÉÏ×°ÖÃÖÖÖÖ¶ñÒâÈí¼þ£¬£¬ £¬£¬ £¬£¬ÏÖÔÚΪֹ£¬£¬ £¬£¬ £¬£¬Ö÷ÒªÏÂÔØÃÅÂÞ±ÒÍÚ¿óÈí¼þ¾ÙÐÐÍڿ󡣡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

DNS_¿ÉÒÉÐÐΪ_oast_´øÍâÅÌÎÊ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

oastÊÇÒ»¸öÃâ·ÑµÄ¡¢ÎÞÐè×¢²á¾Í¿ÉÒÔ¿ìËÙʹÓõÄDNSLogƽ̨£¬£¬ £¬£¬ £¬£¬Äܹ»¶Ô·¢ËÍÒÑÍùµÄDNSÇëÇó¾ÙÐмͼ¡£¡£¡£¾­³£±»¹¥»÷ÕßÓÃÓÚ´«ÊäÖ´ÐÐÏÂÁîЧ¹ûµÄ»ØÏÔ¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

DNS_¿ÉÒÉÐÐΪ_interact_´øÍâÅÌÎÊ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

interact.shÊÇinteract.sh¹¤¾ßÅäÌ×µÄDNSLogƽ̨£¬£¬ £¬£¬ £¬£¬Äܹ»¶Ô·¢ËÍÒÑÍùµÄDNSÇëÇó¾ÙÐмͼ¡£¡£¡£¾­³£±»¹¥»÷ÕßÓÃÓÚ´«ÊäÖ´ÐÐÏÂÁîЧ¹ûµÄ»ØÏÔ¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Struts2_S2-045_´úÂëÖ´ÐÐ[CVE-2017-5638]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ÔÚʹÓÃJakarta²å¼þ´¦Öóͷ£ÎļþÉÏ´«²Ù×÷ʱ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÔÚÎļþÉÏ´«Ê±Í¨¹ý½á¹¹HTTPÇëÇóÍ·ÖеÄContent-TypeÖµ¿ÉÄÜÔì³ÉÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºStruts2.3.5-Struts2.3.31£¬£¬ £¬£¬ £¬£¬Struts2.5-Struts2.5.10ʵÑé²âÊÔÑéÖ¤ApacheStruts2S2-045Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬ £¬£¬²âÊÔ²»¾ßÓй¥»÷ÐÔ£¬£¬ £¬£¬ £¬£¬µ«¿ÉÄÜ̻¶ϵͳųÈõÐÔÌØÕ÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Struts2_S2-046_´úÂëÖ´ÐÐ[CVE-2017-5638]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¹¥»÷ÕßÔÚʹÓÃJakarta²å¼þ´¦Öóͷ£ÎļþÉÏ´«²Ù×÷ʱ¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬£¬ £¬£¬ £¬£¬½á¹¹¶ñÒâOGNLʹµÃÉÏ´«ÎļþµÄ´óС£¡£¡£¨ÓÉContent-LengthÍ·Ö¸¶¨£©´óÓÚStruts2ÔÊÐíµÄ×î´ó¾Þϸ2GB¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºStruts2.3.5-Struts2.3.31£¬£¬ £¬£¬ £¬£¬Struts2.5-Struts2.5.10¹¥»÷Àֳɣ¬£¬ £¬£¬ £¬£¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÐÅϢй¶_Ŀ¼±éÀú[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬ £¬£¬ £¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬ £¬£¬ £¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬£¬ £¬£¬ £¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬£¬ £¬£¬ £¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£

¸üÐÂʱ¼ä£º

20220906