ÿÖÜÉý¼¶Í¨¸æ-2021-11-16
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ľÂí_Win32.Dark_Crystal_RAT/DCRat_Ô¶¿ØľÂí_ÅþÁ¬C2·þÎñÆ÷ |
Çå¾²ÀàÐÍ£º | Ô¶¿ØºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ä¾ÂíDarkCrystalÅþÁ¬C2·þÎñÆ÷£¬Åú×¢Ô´IPÖ÷»úÒÑѬȾ¸ÃľÂí¡£DarkCrystal¶ñÒâÈí¼þÊÇÒ»ÖÖRAT£¨Ô¶³Ì»á¼ûľÂí£©£¬C#ÓïÑÔ£¬¶íÂÞ˹ÈË¿ª·¢¡£DarkCrystalRATÊÇÒ»ÖÖºÜÊÇÏȽøµÄºÚ¿Í¹¤¾ß£¬¾ßÓÐÐí¶à¹¦Ð§£¬ÆäÖаüÀ¨£ºÔËÐÐÔ¶³ÌÏÂÁî¡¢ÍøÂçÓû§ÐÅÏ¢¡¢Í¨¹ýÍøÂçÉãÏñͷ¼ÖÆÊÓƵ¡¢Í¨¹ýÂó¿Ë·ç¼ÖÆÒôƵ¡¢Ö´ÐÐDDoS»òUDP/TCPºéË®¹¥»÷¡¢ÖÎÀíÎļþϵͳµÈµÈ¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_±í´ïʽעÈë_ͨÓà |
Çå¾²ÀàÐÍ£º | ÆäËû×¢Èë |
ÊÂÎñÐÎò£º | 2013Äê4ÔÂ15ÈÕExpressionLanguageInjection´ÊÌõÔÚOWASPÉϱ»½¨É裬¶øÕâ¸ö´ÊµÄ×îÔç·ºÆð¿ÉÒÔ×·Ëݵ½2012Äê12Ôµġ¶Remote-Code-with-Expression-Language-Injection¡·Ò»ÎÄ£¬ÔÚÕâ¸öpaperÖеÚÒ»´ÎÌáµ½ÁËÕâ¸öÃû´Ê¡£¶øÕâ¸öʱÆÚ£¬Ö»²»¹ý»¹Ö»ÊÇ°ÑËü½Ð×öÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡¢Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î»òÕßÉÏÏÂÎIJٿØÎó²î¡£ÏñStruts2ϵÁеÄs2-003¡¢s2-009¡¢s2-016µÈ£¬ÕâÖÖÓÉOGNL±í´ïʽÒýÆðµÄÏÂÁîÖ´ÐÐÎó²î¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_D-Link_DAP-1860_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2019-19597][CNNVD-201912-215] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | D-LinkDAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi¹æÄ£À©Õ¹Æ÷¡£D-LinkDAP-18601.04b03֮ǰ°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õ߿ɽèÖúHTTPÇëÇóÍ·ÖеÄHNAP_AUTH²ÎÊýºó×¢ÈëshellÔª×Ö·ûʹÓøÃÎó²îÒÔrootȨÏÞÖ´ÐÐí§ÒâÏÂÁî¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_passwdÄÚÈÝÎļþ»ØÏÔ |
Çå¾²ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÕýÔÚͨ¹ýÏÂÁîÖ´ÐÐÉó²é/etc/passwdÎļþµÄÄÚÈÝ¡£´ËÎļþÖд洢ÁËϵͳÖеÄËùÓÐÕË»§¡¢È¨ÏÞµÈÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2015-7450] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | WebSphereÊÇIBM¹«Ë¾¿ª·¢µÄÖÐÐļþ»ù´¡Éèʩƽ̨¡£WebSphere7°æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁËApacheCommonsCollections¿âÖеÄInvokerTransformerÀ࣬¸ÃÀà±£´æJava·´ÐòÁл¯Îó²î¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÏÂÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÐaction:¡¢redirect:»òredirectAction:µÄǰ׺²ÎÊýʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£Îó²î±£´æµÄ°æ±¾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | TCP_ͨÓÃ_Java·´ÐòÁл¯_ysoserial¶ñÒâÊý¾ÝʹÓà |
Çå¾²ÀàÐÍ£º | ÏÂÁîÖ´ÐÐ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýTCP·¢ËÍysoserialÌìÉúµÄ¶ñÒâJAVA·´ÐòÁл¯Êý¾Ý¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²î£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬»ñȡϵͳ¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | TCP_½©Ê¬ÍøÂç_Mirai.Putin_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ÆäËû×¢Èë |
ÊÂÎñÐÎò£º | ¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÅþÁ¬C&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍø×°±¸£¨IoT£©£¬°üÀ¨£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVR×°±¸µÈµÈ£¬IoT×°±¸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò±£´æĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØÎó²îδʵʱÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ¹ûÕ棬Mirai·ºÆðÁËÐí¶à±äÖÖ£¬±¾ÊÂÎñÕë¶ÔÆä±äÖÖPutin¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_phpunint_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2017-9841][CNNVD-201706-1127] |
Çå¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÐÎò£º | PHPUnitÊÇPHP³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Î»²âÊÔ(unittesting)¿ò¼Ü£¬Í¨³£phpunitʹÓÃcomposerºÜÊÇÊ¢ÐеÄPHPÒÀÀµÖÎÀíÆ÷¾ÙÐа²ÅÅ,½«»áÔÚÄ¿½ñĿ¼½¨ÉèÒ»¸övendorÎļþ¼Ð.phpunitÉú²úÇéÐÎÖÐÈÔÈ»×°ÖÃÁËËü,ÈôÊǸñàдÆ÷Ä£¿é±£´æÓÚWeb¿É»á¼ûĿ¼£¬Ôò±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_FastjsonÎó²î_hex±àÂëʹÓà |
Çå¾²ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSONÆÊÎö¿â£¬Ëü¿ÉÒÔÆÊÎöJSONÃûÌõÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓùæÄ£ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£fastjson¿É½ÓÊܲ¢ÆÊÎöhex±àÂëÄÚÈÝ£¬Òò´Ë¹¥»÷Õß¿ÉʹÓÃhex±àÂëÈƹý¼ì²â×°±¸¡£ |
¸üÐÂʱ¼ä£º | 20211116 |