2020-12-01

Ðû²¼Ê±¼ä 2020-12-02

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_powershellÏÂÁî×¢Èë¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PowerShellÊÇ΢ÈíWindows²Ù×÷ϵͳÖÐ×Ô´øµÄÈí¼þ°ü £¬Òò´Ë £¬¹¥»÷Õß¿ÉÒÔÔÚÊܺ¦ÕßÖ÷»úÖÐËæʱʹÓÃÕâ¿î¹¤¾ß¡£ÔÚÏÖʵÊӲ쵽µÄ¹¥»÷Ô˶¯ÖÐ £¬PowerShellµÄÖ÷Òª×÷ÓÃÊÇ´ÓÔ¶³ÌλÖÃÏÂÔضñÒâÎļþµ½Êܺ¦ÕßÖ÷»úÖÐ £¬È»ºóʹÓÃÖîÈçStart-Porcess¡¢Invoke-Item»òÕßInvoke-Expression£¨-IEX£©Ö®ÀàµÄÏÂÁîÖ´ÐжñÒâÎļþ £¬PowerShellÒ²¿ÉÒÔ½«Ô¶³ÌÎļþÖ±½ÓÏÂÔص½Êܺ¦ÕßÖ÷»úÄÚ´æÖÐ £¬È»ºó´ÓÄÚ´æÖÐÖ´ÐС£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Nagios_XI_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-5791][CNNVD-202010-1115]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Nagios XIÊÇÒ»¸ö½¨ÉèÔÚNagios½¹µãÉϵÄÆóÒµ¼¶¼à²âºÍ±¨¾¯¼Æ»®µÄ¿ªÔ´×é¼þ¡£¹¦Ð§°üÀ¨PHPÍøÕ¾½çÃæ¡¢×ÛºÏÌåÏÖͼ¡¢¿É¶¨ÖƵÄÒDZí°å¡¢ÍøÂç½á¹¹¡¢ÉèÖÃGUI(ͼÐÎÓû§½Ó¿Ú)¡¢Óû§ÖÎÀíµÈ¡£Nagios XI 5.7.3Öб£´æÔ¶³Ì´úÂëÖ´ÐÐÇå¾²Îó²î £¬¹¥»÷Õß¿ÉʹÓôËÎó²îÒÔ¡°apache¡±Óû§Ö´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Asruex_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Asruex×é¼þʵÑéÅþÁ¬·þÎñÆ÷ £¬Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAsruexºóÃÅ¡£Ñо¿Ö°Ô±ÔçÔÚ2015Äê¾Í·¢Ã÷ÁËAsruexºóÃÅ £¬²¢ÇÒÓëDarkHotel¼à¿Ø¶ñÒâÈí¼þÓйØÁª¡£¸Ã¹¥»÷ÍÅ»ïÖÁÉÙ´Ó2015Äê×îÏȾÍÒѾ­Õë¶ÔÎïÀí¸ôÀëÍøÂç¾ÙÐÐÕë¶ÔÐԵĹ¥»÷ÁË £¬ÆäÖ÷Òª¹¥»÷Ä¿µÄΪ³¯Ïʰ뵺Ïà¹ØµÄÖ÷ÒªÕþÖÎÈËÎï»òÕßÒªº¦²¿·Ö £¬ÎÞÒâÒ²»áÕë¶Ô¶«ÄÏÑǵȹú¾ÙÐй¥»÷¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Webshell_php_COMŲÓÃ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²â¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«Ò»¾ä»°Ä¾ÂíµÄÐÐΪ¡£ ¹¥»÷ÕßʵÑéÏò·þÎñÆ÷ÉÏ´«Ò»¾ä»°Ä¾ÂíÎļþ £¬ÈôÊÇÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÅþÁ¬¹¤¾ß¶Ô·þÎñÆ÷¾ÙÐпØÖÆ¡£ ʵÑéÉÏ´«Webshell £¬»ñÈ¡ÍøÕ¾¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Citrix_XenMobile_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2020-8209][CNNVD-202008-646]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XenMobileÊÇCitrix¿ª·¢µÄÆóÒµÒƶ¯ÐÔÖÎÀíÈí¼þ¡£¸Ã²úÆ·ÔÊÐíÆóÒµÖÎÀíÔ±¹¤µÄÒƶ¯×°±¸ºÍÒƶ¯Ó¦ÓóÌÐò¡£¸ÃÈí¼þµÄÄ¿µÄÊÇͨ¹ýÔÊÐíÔ±¹¤Çå¾²µØÔÚÆóÒµÓµÓеĺÍСÎÒ˽¼ÒÒƶ¯×°±¸¼°Ó¦ÓóÌÐòÉÏÊÂÇéÀ´Ìá¸ßÉú²úÂÊ¡£Citrix Endpoint Management ±£´æí§ÒâÎļþ¶ÁÈ¡Îó²î £¬Ô¶³ÌδÊÚȨ¹¥»÷Õßͨ¹ý·¢ËÍÌØÖÆHTTPÇëÇó £¬¿ÉÒÔÔì³É¶ÁÈ¡ÊÜÓ°Ïì×°±¸ÉÏí§ÒâÎļþµÄÓ°Ïì¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_D-Link-HNAP-SoapAction-HeaderÏÂÁîÖ´ÐÐÎó²î[CVE-2015-2051]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

D-LinkDIR-645Wired/WirelessRouterÊÇÓÑѶ(D-Link)¹«Ë¾µÄÒ»¿îÖÇÄÜÎÞÏß·ÓÉÆ÷²úÆ·¡£Ê¹ÓÃ1.04b12¼°Ö®Ç°°æ±¾¹Ì¼þµÄD-LinkDIR-645Öб£´æÇå¾²Îó²î £¬Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý¶ÔHNAP½Ó¿ÚÖ´ÐÐGetDeviceSettings²Ù×÷ £¬Ê¹ÓøÃÎó²îÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_phpunint_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-9841][CNNVD-201706-1127]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHPUnit ÊÇ PHP ³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Î»²âÊÔ (unit testing) ¿ò¼Ü £¬Í¨³£phpunitʹÓÃcomposerºÜÊÇÊ¢ÐеÄPHPÒÀÀµÖÎÀíÆ÷¾ÙÐа²ÅÅ,½«»áÔÚÄ¿½ñĿ¼½¨ÉèÒ»¸övendorÎļþ¼Ð.phpunitÉú²úÇéÐÎÖÐÈÔÈ»×°ÖÃÁËËü,ÈôÊǸñàдÆ÷Ä£¿é±£´æÓÚWeb¿É»á¼ûĿ¼ £¬Ôò±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_EyouCms_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

EyouCmsÊÇ»ùÓÚTP5.0¿ò¼ÜΪ½¹µã¿ª·¢µÄÃâ·Ñ¿ªÔ´µÄÆóÒµÄÚÈÝÖÎÀíϵͳ¡£EyouCms±£´æÎļþÉÏ´«Îó²î £¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡ÍøÕ¾·þÎñÆ÷¿ØÖÆȨ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_MacCms8.X_Ô¶³Ì´úÂëÖ´ÐÐÏÂÁîÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

÷ÈħӰϷ³ÌÐò(Maccms PHP)ÊÇÒ»Ì×½ÓÄÉPHP/MySQLÊý¾Ý¿âÔËÐеÄÈ«ÐÂÇÒÍêÉƵÄÇ¿Ê¢ÊÓƵӰϷϵͳ¡£ÍêÉÆÖ§³ÖÖÚ¶àÊÓƵÍøÕ¾ºÍ¸ßÇå²¥·ÅÆ÷(youku,tudou,qvod,gvodµÈ) £¬ÍêÈ«Ãâ·Ñ¿ªÔ´¡£¸ÃÎó²îÖ÷ÒªµÄ±¬·¢Ôµ¹ÊÔ­ÓÉÊÇCMSËÑË÷Ò³ÃæËÑË÷²ÎÊý¹ýÂ˲»Ñϵ¼ÖÂÖ±½ÓevalÖ´ÐÐPHPÓï¾ä¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_MODx_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPʹÓÃMODxÖ´ÐÐí§Òâ´úÂë £¬´Ó¶ø»ñÈ¡ÍøÕ¾µÄ¿ØÖÆȨ»òÕßɾ³ýí§ÒâÎļþ¡£MODx ÊÇÒ»¸ö¿ªÔ´µÄ PHP Ó¦Óÿò¼Ü £¬¿ÉÒÔ×ÊÖúʹÓÃÕß¿ØÖÆ×Ô¼ºµÄÍøÉÏÄÚÈÝ¡£ËüÊÇ¿ª·¢Ö°Ô±ºÍ¸ß¼¶Óû§ÀíÏëµÄ¿ØÖÆϵͳ £¬ÈκÎÈ˶¼¿ÉÒÔʹÓà MODx Ðû²¼¡¢¸üС¢Î¬»¤¶¯Ì¬ÍøÕ¾ £¬»ò html ¾²Ì¬Ò³ÃæµÄÍøÕ¾ÄÚÈÝ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ThinkCMFí§Òâ´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ThinkCMFÊÇÒ»¿î»ùÓÚThinkPHP+MySQL¿ª·¢µÄ¿ªÔ´ÖÐÎÄÄÚÈÝÖÎÀí¿ò¼Ü¡£Ô¶³Ì¹¥»÷ÕßÔÚÎÞÐèÈκÎȨÏÞÇéÐÎÏ £¬¿ÉʹÓôËÎó²î½á¹¹¶ñÒâµÄurl £¬Ïò·þÎñÆ÷дÈëí§ÒâÄÚÈݵÄÎļþ £¬µÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ThinkCMFí§ÒâÎļþ°üÀ¨Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ThinkCMFÊÇÒ»¿î»ùÓÚThinkPHP+MySQL¿ª·¢µÄ¿ªÔ´ÖÐÎÄÄÚÈÝÖÎÀí¿ò¼Ü¡£Ô¶³Ì¹¥»÷ÕßÔÚÎÞÐèÈκÎȨÏÞÇéÐÎÏ £¬¿ÉʹÓôËÎó²î½á¹¹¶ñÒâµÄurl £¬Ê¹ÓÃÎļþ°üÀ¨Îó²î £¬»ñȡװ±¸È¨ÏÞ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Docker_Remote_API_δÊÚȨ»á¼ûÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Docker Remote API ÊÇÒ»¸öÈ¡´úÔ¶³ÌÏÂÁîÐнçÃ棨rcli£©µÄREST API¡£Docker Remote APIÈçÉèÖò»µ±¿Éµ¼ÖÂδÊÚȨ»á¼û £¬¹¥»÷ÕßʹÓÃdocker client»òÕßhttpÖ±½ÓÇëÇó¾Í¿ÉÒÔ»á¼ûÕâ¸öAPI £¬¿ÉÄܵ¼ÖÂÃô¸ÐÐÅϢй¶ £¬ºÚ¿ÍÒ²¿ÉÒÔɾ³ýDockerÉϵÄÊý¾Ý¡£¹¥»÷Õ߿ɽøÒ»²½Ê¹ÓÃDocker×ÔÉíÌØÕ÷ £¬Ö±½Ó»á¼ûËÞÖ÷»úÉϵÄÃô¸ÐÐÅÏ¢ £¬»ò¶ÔÃô¸ÐÎļþ¾ÙÐÐÐÞ¸Ä £¬×îÖÕÍêÈ«¿ØÖÆ·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Typecho_install.php·´ÐòÁл¯Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TypechoÊÇÒ»¸ö¼òÆÓ £¬ÇáÓ¯µÄ²©¿Í³ÌÐò¡ £»ùÓÚPHP £¬Ê¹ÓöàÖÖÊý¾Ý¿â£¨Mysql £¬PostgreSQL £¬SQLite£©Öü´æÊý¾Ý¡£ÔÚGPL Version 2ÔÊÐí֤Ͽ¯ÐÐ £¬ÊÇÒ»¸ö¿ªÔ´µÄ³ÌÐò £¬ÏÖÔÚʹÓÃSVNÀ´×ö°æ±¾ÖÎÀí¡£TypechoµÄinstall.phpÎļþ±£´æµÄ·´ÐòÁл¯Îó²î £¬¹¥»÷Õß¿ÉÒÔʹÓÃÖ´ÐÐphp´úÂë½ø¶ø»ñÈ¡Ä¿µÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

TELNET_Çå¾²Îó²î_Cisco_Catalyst_½»Á÷»ú_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-3881][CVE-2017-3881][CNNVD-201703-840][CVE-2017-3881][CNNVD-201703-840]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Cisco IOSºÍCisco IOS XEÈí¼þÖеÄCisco¼¯ÈºÖÎÀíЭÒ飨CMP£©´¦Öóͷ£´úÂëÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÖØмÓÔØÊÜÓ°ÏìµÄ×°±¸»òÒÔÌáÉýµÄÌØȨԶ³ÌÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

SNMP_Çå¾²Îó²î_Cisco_IOS_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-6736][CNNVD-201706-1229]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

˼¿ÆIOSºÍIOS XEÈí¼þµÄ¼òÆÓÍøÂçÖÎÀíЭÒé(SNMP)×Óϵͳ°üÀ¨¶à¸öÎó²î £¬ÕâЩÎó²î¿ÉÄÜÔÊÐí¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÔÚÊÜÓ°ÏìµÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë £¬»òµ¼ÖÂÊÜÓ°ÏìµÄϵͳÖØмÓÔØ¡£¹¥»÷Õß¿ÉÒÔʹÓÃÕâЩÎó²î £¬Í¨¹ýIPv4»òIPv6ÏòÊÜÓ°ÏìµÄϵͳ·¢ËÍÈ«ÐÄÖÆ×÷µÄSNMP°ü¡£

¸üÐÂʱ¼ä£º

20201201


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ECShopȫϵÁа汾Զ³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»ú¾ÙÐÐEcshopµÇ¼ҳÃæ×¢Èë¹¥»÷´úÂë¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_PHP_eval_base64_decodeľÂí

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ BitterľÂí ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË BitterľÂí¡£

¸üÐÂʱ¼ä£º

20201117


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Discuz_7.x_faq.php_SQL×¢ÈëÎó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»ú¾ÙÐÐDiscuz_7.x_faq.php_grouppermission_SQL×¢Èë¹¥»÷¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_NginxÆÊÎöÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ê¹ÓÃNginxÎļþÃûºó׺ÆÊÎö¹ýʧµÄÉÏ´«ÐÐΪ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_seacms_search.php_ǰ̨getshellÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃseacms search.php ǰ̨getshellÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_ThinkPHP5Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃThinkPHP¿ò¼ÜÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ £¬ÊÔͼԶ³Ì×¢ÈëPHP´úÂë £¬ÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_ZeroShell_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-12725]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZeroshellÊÇÒ»Ì×ÃæÏò·þÎñÆ÷ºÍǶÈëʽϵͳµÄLinux¿¯Ðаæ¡£Zeroshell 3.9.0°æ±¾Öб£´æÇå¾²Îó²î £¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷ´¦Öóͷ£HTTP²ÎÊý¡£

¸üÐÂʱ¼ä£º

20201201


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_CobaltStrike.Powershell_´úÂëÏÂÔØÖ´ÐÐ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Óɺڿ͹¤¾ß CobaltStrike ÌìÉúµÄ ºóÃÅpowershellÏÂÁî ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷ÏÂÔØľÂí CobaltStrike.Beacon, Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄÜÖ´ÐÐÁ˺óÃÅPowershellÏÂÁî¡£CobaltStrike.BeaconÖ´Ðк󹥻÷Õß¿ÉʹÓÃCobaltStrikeÍêÈ«¿ØÖÆÊܺ¦»úе £¬²¢¾ÙÐкáÏòÒƶ¯¡£

¸üÐÂʱ¼ä£º

20201201