ÿÖÜÉý¼¶Í¨¸æ-2021-05-25

Ðû²¼Ê±¼ä 2021-05-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæϵͳ£¨VENGD£©£¬ÊǺ£ÄڵĻùÓÚNGD(NextGenerationDesktop)¼Ü¹¹µÄ×ÀÃæÐéÄ⻯²úÆ·£¬ËüÈÚºÏÁËVDI¡¢VOI¡¢IDVÈý´ó¼Ü¹¹ÓÅÊÆ£¬ÊµÏÖÁËÇ°ºó¶Ë»ìÏýÅÌË㣬ÔÚµ÷Àí·þÎñÆ÷ºó¶ËÅÌËã×ÊÔ´µÄͬʱ¸üÄܳä·ÖʹÓÃÇ°¶Ë×ÊÔ´¡£¸Ãϵͳ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬¹¥»÷Õ߿ɽṹÌض¨ÇëÇó°ügetshell¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_ÖÂÔ¶OA_webmail.doí§ÒâÎļþÏÂÔØÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÖÂÔ¶OAÊDZ±¾©ÖÂÔ¶»¥ÁªÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Ñз¢Ò»¿î°ì¹«ÏµÍ³£¬ÖÂÔ¶OA±£´æí§ÒâÎļþÏÂÔØÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÏÂÔØí§ÒâÎļþ£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20210525


2.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èív8.0í§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚ¶ÔÄ¿µÄipÖеķ«Èív8.0¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡ÐÐΪ£¬ÆäÖпÉÒÔͨ¹ý¶ÁÈ¡privilege.xmlÇÔÈ¡ÃÜÂë¾ÙÐнøÒ»²½µÄ¹¥»÷£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òÆÓµÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


3.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ8.0_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓ÷«Èí±¨±í²å¼þ8.0ÖеÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òÆÓµÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


4.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ9.0_GetshellÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÒÔ»ñÈ¡·«Èíºǫ́ȨÏÞ£¬Í¨¹ýÉÏ´«Ñ¹ËõÎļþ¾ÙÐÐgetshell²Ù×÷£¬FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òÆÓµÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC6.5_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5µÄÎó²î¾ÙÐÐí§ÒâÎļþÉÏ´«£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_CRM_í§ÒâÎļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡²Ù×÷£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓѵÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ¡£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ÐÞ¸ÄÊÂÎñ


1.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Weblogic_ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-2109][CNNVD-202101-1453]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóʹÓøÃÎó²î£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܽÓÊÜOracleWebLogicServer¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬Æ丽¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬¿ÉÏò·þÎñÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷Ö÷»ú¡£ÁíÍ⣬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬boundary´óÓÚ½çÏßÖµ£¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬µ¼ÖÂDDOS¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ

1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ