ÿÖÜÉý¼¶Í¨¸æ-2022-03-08

Ðû²¼Ê±¼ä 2022-03-08

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_ʵÑéʹÓÃí§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

ÓÉÓÚһЩÍøÕ¾µÄÓªÒµÐèÒª,ÍùÍùÐèÒªÌṩÎļþ¶ÁÈ¡»òÏÂÔصÄÒ»¸öÄ£¿é,µ«ÈôÊÇûÓжԶÁÈ¡»òÏÂÔØ×öÒ»¸ö°×Ãûµ¥»òÕßȨÏÞÏÞÖÆ £¬¿ÉÄܵ¼Ö¶ñÒâ¹¥»÷Õ߶ÁÈ¡ÏÂÔØһЩÃô¸ÐÐÅÏ¢(etc/passwdµÈ),¶Ô·þÎñÆ÷×öÏÂÒ»²½µÄ½ø¹¥ÓëÍþв¡£´ËÊÂÎñ¿ÉÒÔͨÓÃÐԵؼì²âʵÑéʹÓÃí§ÒâÎļþ¶ÁÈ¡Îó²îµÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_LinuxÏÂÁîÖ´ÐлØÏÔ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»ú·ºÆðÁËijЩLinuxÏÂÁÈçw¡¢top¡¢uptimeµÈ£©Ö´ÐеĻØÏÔÁ÷Á¿ £¬°üÀ¨Ä¿½ñϵͳʱ¿Ì¡¢ÔËÐÐʱ¼ä¡¢Óû§×ÜÅþÁ¬Êý¡¢Æ½¾ù¸ºÔصÈÐÅÏ¢

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_BEESCMS_Ä£°åÐÞ¸ÄgetshellÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃBEESCMSµÄºǫ́ÖÎÀíÄ£°åÄ£¿éÀ´ÉÏ´«getshell¡£BEESCMSÆóÒµÍøÕ¾ÖÎÀíϵͳÊÇÒ»¿îPHP+MYSQLµÄ¶àÓïÑÔϵͳ £¬ÄÚÈÝÄ£¿éÒ×À©Õ¹ £¬Ä£°åÆø¸Å¶àÑù»¯ £¬Ä£°åÖÆ×÷¼òÆÓ¹¦Ð§Ç¿Ê¢ £¬×¨ÒµSEOÓÅ»¯ £¬ºǫ́²Ù×÷Àû±ã £¬ÍêÈ«¿ÉÒÔÖª×ãÆóÒµÍøÕ¾¡¢ÍâóÍøÕ¾¡¢ÊÂÒµµ¥Î»¡¢½ÌÓý»ú¹¹¡¢Ð¡ÎÒ˽¼ÒÍøվʹÓá£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü £¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌà £¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦ £¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑé £¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü £¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ͨ´ïOA_SQL×¢ÈëÎó²î

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IP×°±¸ÕýÔÚʵÑéʹÓÃSQL×¢ÈëÎó²î¹¥»÷Ä¿µÄIP×°±¸¡£SQL×¢ÈëÊǽÏÁ¿³£¼ûµÄÍøÂç¹¥»÷·½·¨Ö®Ò» £¬ÆäÔµ¹ÊÔ­ÓÉÊÇÓÉÓÚδ¶ÔÊäÈëµÄ²ÎÊýÄÚÈÝ×÷¹ýÂËУÑé £¬µ¼Ö¹¥»÷ÕßÆ´½Ó¶ñÒâSQLÓï¾ä £¬Í¨¹ýSQLÓï¾ä £¬ÊµÏÖÎÞÕ˺ŵǼ £¬ÉõÖÁ¸Ä¶¯Êý¾Ý¿â¡¢Äõ½Ä¿µÄ×°±¸È¨ÏÞ¡£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DLink_DIR8xxϵÁзÓÉÆ÷_δÊÚȨÏÂÁî×¢Èë[CVE-2021-45382][CNNVD-202202-1411]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýCVE-2021-45382Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£DIR-810L¡¢DIR-820L/W¡¢DIR-826L¡¢DIR-830L¡¢DIR-836LϵÁÐÊÇÖйúÓÑѶ£¨D-Link£©¹«Ë¾µÄ·ÓÉÆ÷ £¬ÒѾ­´¦ÓÚ·þÎñÖÕÖ¹Çø(EndofServiceLife)¡£ËüÃǹ̼þÀïµÄDDNSº¯Êý±£´æÏÂÁî×¢ÈëÎó²î £¬¹¥»÷Õ߿ɽè´ËÔ¶³ÌÖ´ÐжñÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_PHP_Nette¿ò¼ÜCallback_δÊÚȨԶ³ÌÏÂÁî×¢Èë[CVE-2020-15227][CNNVD-202010-011]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

NetteÊÇÒ»¿îÊ¢ÐеÄPHPWeb¿ìËÙ¿ª·¢¿ò¼Ü £¬»ùÓÚ×é¼þµÄÊÂÎñÇý¶¯¡£ÆäÉè¼ÆÀíÄîΪ£º¶Ô¿ª·¢Õß¾¡¿ÉÄܵÄÓѺò¢¿ÉÓà £¬Nette¿ò¼Ü¿ÉÒÔ×ÊÖúÄúÇáËɽ¨ÉèºÃÍøÕ¾¡£Nette±£´æÏÂÁî×¢ÈëÎó²î £¬¸ÃÎó²îÔ´ÓÚδ׼ȷ¹ýÂËurlÖеÄÌØÊâ²ÎÊý¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îδÊÚȨԶ³ÌÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20220308

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_ifconfig_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÏÂÁîµÄ»ØÏÔÐÅÏ¢ £¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ £¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÏÂÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220308

 

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈƹýWeb·þÎñÆ÷µÄ»á¼ûÏÞÖÆ £¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð £¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò £¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿ £¬ÒÔÊÇÐèÒªÖصã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20220308