2021-04-08

Ðû²¼Ê±¼ä 2021-04-09

ÐÂÔöÊÂÎñ


1.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳ_ÌìÇæ_ǰ̨SQL×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæǰ̨SQL×¢ÈëÎó²î¡ £¿ÉÄÜͨ¹ý´ËÎó²îдÈëwebshellµÈ¶ñÒâÎļþ£¬´Ó¶øgetshell¡£

¸üÐÂʱ¼ä£º

20210408


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA8ǰ̨SQLÖ´ÐÐÎó²î¡ £¿ÉÄÜͨ¹ý´ËÎó²îÅÌÎʳöºǫ́ÃÜÂëµÈÃô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20210408


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA9ǰ̨ÎÞÏÞÖÆGetshellÎó²î¡ £¿ÉÄÜͨ¹ý´ËÎó²îÖ±½ÓÉÏ´«webshellµÈ¶ñÒâÎļþ£¬´Ó¶øgetshell¡£

¸üÐÂʱ¼ä£º

20210408


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃeurekaµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«eureka.client.serviceUrl.defaultZoneÉèÖÃΪ¶ñÒâÍøÕ¾¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØϵͳÊý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20210408


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ»á¼ûÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬ÒÔÊÇÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20210408


ɾ³ýÊÂÎñ


1¡¢HTTP_ľÂíºóÃÅ_ASP_webshellÒ»¾ä»°Ä¾ÂíÏÂÔØ