ÿÖÜÉý¼¶²¼¸æ-2021-05-18
°ä²¼¹¦·ò 2021-05-19ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_PHP-zerodiumºóÃÅ_ËÁÒâ´úÂëÖ´Ðзì϶ |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄ·ÖÎö¹ý³ÌÖз¢ÏÖ£¬£¬£¬£¬£¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»½Ù³ÖµÄÍøÕ¾ÉÏ£¬£¬£¬£¬£¬²¢ÇÒѡȡÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷£¬£¬£¬£¬£¬²¢ÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢ÈËÔ±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£¡£¡£¡£¡£Ä¿Ç°ÎªÖ¹PHP¹Ù·½²¢Î´¾Í¸ÃÊÂÎñ½øÐиü¶àÅû¶£¬£¬£¬£¬£¬°µÊ¾Õâ´Î·þÎñÆ÷±»ºÚµÄ¾ßÌåϸ½ÚÈÔÔÚµ÷²é°ø±ß¡£¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñµÄÓ°Ï죬£¬£¬£¬£¬PHPµÄ¹Ù·½´úÂë¿âÒѾ±»ÊØ»¤ÈËԱǨáãÖÁGitHubƽ̨£¬£¬£¬£¬£¬Ö®ºóµÄÓйشúÂë¸üС¢Åú¸Ä½«»á¶¼ÔÚGitHubÉϽøÐС£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | TCP_ºóÃÅ_Gh0st_htrfhtfe__ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£Gh0stÊdzÛÃûµÄ¿ªÔ´Ô¶¿Ø·¨Ê½£¬£¬£¬£¬£¬Ö°Äܼ«¶È׳´ó¡£¡£¡£¡£¡£ÓµÓÐÎļþÖÎÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢´´½¨¡¢É¾³ý£©¡¢¹ý³ÌÖÎÀí¡¢ÏµÍ³·þÎñ¡¢×¢²á±í¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢²é¿´ÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈÖ°ÄÜ£¬£¬£¬£¬£¬Äܹ»ÆëÈ«½ÚÔ챻ϰȾ»úе¡£¡£¡£¡£¡£½üÆÚ·¢ÏÖ´óÁ¿Æ¾¾ÝGh0stÔ´ÂëÅú¸ÄµÄÔ¶¿Ø·¨Ê½£¬£¬£¬£¬£¬²¢Ôö³¤ÁË×Ô¼ºµÄÖ°ÄÜ£¬£¬£¬£¬£¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳװÖõÄÍøÂçÓÎÏ·µÈÖ°ÄÜ¡£¡£¡£¡£¡£ºÚ¿Í»¹Äܹ»½«º¬ÓÐÉãÏñÍ·»ò×°ÖÃÖ¸¶¨ÓÎÏ·µÄÓû§¹éÀ࣬£¬£¬£¬£¬ÓÐÕë¶ÔÐԵĵÁÈ¡Óû§ÒþÖÔ¡£¡£¡£¡£¡£ÉõÖÁ²é¿´Öж¾ÕßµØÀíµØÎ»µÄÖ°ÄÜ£¬£¬£¬£¬£¬¶ÔÓû§µÄÒþÖÔÔì³É¸ü´óµÄÍþв¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_°²È«·ì϶_Terramaster_TOS_ºÅÁî×¢Èë·ì϶[CVE-2020-28188][CNNVD-202012-1548] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | TerramasterTOSÊÇÖйúÀö½ÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ£¬£¬£¬£¬£¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£¡£¡£¡£¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýÔÚÊÂÎñ²ÎÊýÖÐÔ̺¬makecvs.php×¢Èë²Ù×÷ϵͳºÅÁî¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_SSH-RSA˽Կй© |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ£¬£¬£¬£¬£¬LINUX·þÎñÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH£¬£¬£¬£¬£¬RSA˽Կй¶£¬£¬£¬£¬£¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH£¬£¬£¬£¬£¬µ¼ÖÂÖ÷»ú±»ÊÕÊÜ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210511 |
ÊÂÎñÃû³Æ£º | HTTP_Microsoft-Exchange-SERVER_·þÎñÆ÷¶ËÒªÇóαÔì[CVE-2021-26855][CNNVD-202103-192] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | µ±Ç°Ö÷»úÔÚÔâ·êMicrosoft-Exchange-SERVER_·þÎñÆ÷¶ËÒªÇóαÔì¹¥»÷¸Ã·ì϶ÊÇExchangeÖеÄËÁÒâÎļþдÈë·ì϶¡£¡£¡£¡£¡£¸Ã·ì϶±ØÒª½øÐÐÉí·ÝÈÏÖ¤£¬£¬£¬£¬£¬ÀûÓô˷ì϶Äܹ»½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκÎõè¾¶¡£¡£¡£¡£¡£²¢Äܹ»½áºÏÀûÓÃCVE-2021-26855SSRF·ì϶»òÈÆ¹ýȨÏÞÈÏÖ¤½øÐÐÎļþдÈë¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_ÏνÓC2·þÎñÆ÷ |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÏνÓC2·þÎñÆ÷µÄÐÐΪ¡£¡£¡£¡£¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí£¬£¬£¬£¬£¬ÓµÓÐÍøÂçÊܺ¦Ö÷»úÁé¸ÐÐÅÏ¢ÉÏ´«µ½C2·þÎñÆ÷µÄÐÐΪ£¬£¬£¬£¬£¬ÏÂÔØÍÚ¿ó·¨Ê½µ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIE¹ý³ÌÖÐÖ´ÐÐÍڿ󣬣¬£¬£¬£¬Æ¾¾ÝC2·þÎñÆ÷µÄºÅÁîÖ´Ðи÷Àà²Ù×÷£¬£¬£¬£¬£¬Èç¸üÐÂÅäÏàÐÅÏ¢¡¢×°ÖÃÍÚ¿ó·¨Ê½µÈ¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£ Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÓ×®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£¡£¡£¡£¡£ ·ì϶´æÔڵİ汾£º S2-016£ºStruts 2.0.0 - Struts 2.3.15 S2-017£ºStruts 2.0.0 - Struts 2.3.15 S2-018£ºStruts 2.0.0 - Struts 2.3.15.2 |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂí_Raccoon.Stealer_ÏÎ½Ó |
°²È«ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£¡£¡£¡£¡£RaccoonÒ²±»³ÆÎªMohazo»òRacealer£¬£¬£¬£¬£¬ÊÇÒ»¸öÖ°ÄÜ׳´óµÄÇÔÃÜľÂí¡£¡£¡£¡£¡£ËüÄܹ»ÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶Ë±£ÁôµÄÕ˺ÅÃÜÂë¡£¡£¡£¡£¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£¡£¡£¡£¡£ |
¸üй¦·ò£º | 20210518 |
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112] |
°²È«ÀàÐÍ£º | °²È«·ì϶ |
ÊÂÎñÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¡£¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÔì»ùÓÚCommonsFileUpload1.3£¬£¬£¬£¬£¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí½Ó¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()²½Ö裩£¬£¬£¬£¬£¬²¢ÔÊÐí½ÚÔìClassLoader¡£¡£¡£¡£¡£ÔÚ¾ßÌåµÄWebÈÝÆ÷²¿Êð»·¾³Ï£¨È磺Tomcat£©£¬£¬£¬£¬£¬¹¥»÷ÕßÀûÓÃWebÈÝÆ÷ϵÄJavaClass¶ÔÏó¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬£¬£¬£¬£¬¿ÉÏò·þÎñÆ÷ÌáÒéÔ¶³Ì´úÂëÖ´Ðй¥»÷£¬£¬£¬£¬£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃŽÚÔìÍøÕ¾·þÎñÆ÷Ö÷»ú¡£¡£¡£¡£¡£Áí±í£¬£¬£¬£¬£¬ÓÉÓÚHTTPÒªÇóµÄContent-Type×Ö¶ÎÖУ¬£¬£¬£¬£¬boundary´óÓÚÌìǵֵ£¬£¬£¬£¬£¬²¢ÇÒpostÒªÇóÄÚÈÝ´óÓÚÌìǵֵ£¬£¬£¬£¬£¬µ¼ÖÂDDOS¡£¡£¡£¡£¡£·ì϶´æÔڵİ汾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null |
¸üй¦·ò£º | 20210518 |
Åú¸ÄÊÂÎñ
1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´Ðзì϶
2¡¢TCP_¿ÉÒÉÐÐΪ_tracertºÅÁî_Ô¶³ÌºÅÁîÖ´ÐÐ


¾©¹«Íø°²±¸11010802024551ºÅ