ÿÖÜÉý¼¶Í¨¸æ-2022-03-22

Ðû²¼Ê±¼ä 2022-03-22

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ľÂí_jhProtominer(Protominer)_ʵÑéÅþÁ¬¿ó³Ø(PTS)

Çå¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËjhProtMinerľÂí¡£jhProtMinerÊÇÍÚÈ¡Protoshares(PTS £¬±ÈÌعÉ)µÄ¸ßÐÔÄÜÍÚ¿ó³ÌÐò £¬ËüʹÓòî±ðµÄËã·¨ £¬ÒÔÎþÉüÍÚ¾òËÙÂÊΪ¼ÛÇ® £¬ÔÊÐíÿ¸öÏß³Ìí§ÒâʹÓÃÄÚ´æ¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍÚ¿ó¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTPS_ľÂí_¿ÉÒÉ¿ó³ØÖ÷ÓòÃûÆÊÎöÇëÇó8

Çå¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ÊÂÎñÐÎò£º

¼ì²âµ½¿ÉÒÉÍÚ¿óľÂíÊÔͼÅþÁ¬ÓòÃû·þÎñÆ÷ÆÊÎö¿ó³ØµØµã¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£ÍÚ¿óľÂíʵÑéÅþÁ¬¿ó³Ø £¬ÔËÐкóʹÊܺ¦Ö÷»ú±äÂý £¬ÏûºÄCPU×ÊÔ´¡£ÈôÊÇΪÓû§Õý³£»á¼û¿ó³ØÖ÷Ò³ £¬ÔòºöÂÔ¸ÃÊÂÎñ¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_WordPress_WooCommerce²å¼þ_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýʹÓÃWordPressWooCommerce²å¼þí§ÒâÎļþÉÏ´«Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨ £¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£WooCommerceÊÇÒ»¸öµÄ¿ªÔ´µç×ÓÉÌÎñ½â¾ö¼Æ»®¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_WordPress_blaze_manage_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýʹÓÃWordPressµÄblaze_manageÒ³Ãæ¾ÙÐÐí§ÒâÎļþÉÏ´«Îó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨ £¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_beescms_ÈÏÖ¤Èƹý

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

BEESCMSV4.0_R_20160525°æ±¾ÔÚ²ÎÊýת´ïʱʹÓÃÁ˲»Çå¾²µÄ·½·¨ £¬Ê¹ÓÃÊý×é¼üÖµ×÷Ϊ±äÁ¿Öµ¡£µ±±äÁ¿ÖÐÓÐͬÃûµÄÔªËØʱ £¬¸Ãº¯ÊýĬÈϽ«Ô­ÓеÄÖµ¸øÁýÕÖµô £¬Ôì³ÉÁ˱äÁ¿ÁýÕÖÎó²î¡£µ¼Ö¹¥»÷Õß¿ÉÒÔͨ¹ý´ËÎó²îÈƹýµÇ¼ÈÏÖ¤ £¬Ê¹ÓÃÖÎÀíÔ±Éí·ÝµÇ¼ºǫ́¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_PHP168-cache-adminlogin_logs.php_í§Òâ´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

PHP168ÕûÕ¾ÊÇPHPÁìÓòÄ¿½ñ¹¦Ð§×îÇ¿Ê¢µÄ½¨Õ¾ÏµÍ³ £¬´úÂëËùÓпªÔ´ £¬¿É¼«ÆäÀû±ãµÄ¾ÙÐжþ´Î¿ª·¢ £¬ËùÓй¦Ð§Ä£¿é¿ÉÒÔ×ÔÓÉ×°ÖÃÓëɾ³ý £¬Ð¡ÎÒ˽¼ÒÓû§ÍêÈ«Ãâ·ÑʹÓá£ËüÒÀ¸½×Å×ÔÉíµÄÇ¿Ê¢¡¢Îȹ̡¢Çå¾²¡¢ÎÞа¡¢Ò×Óõȶ෽ÃæµÄÓÅÊÆ,Æä°æ±¾±£´æí§Òâ´úÂëÖ´ÐÐ £¬¿ÉÄÜΣº¦µ½ÏµÍ³Çå¾²¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Solr_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2020-13941][CNNVD-202008-850]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃApache-Solr8.6.0°æ±¾ÖеÄí§ÒâÎļþ¶ÁÈ¡Îó²î £¬ÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£ApacheSolrÊÇÒ»¸ö¿ªÔ´µÄËÑË÷·þÎñ £¬Ê¹ÓÃJavaÓïÑÔ¿ª·¢¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Jackson_Databind_¿ÉÒÉ·´ÐòÁл¯Àà_dbcp[CVE-2020-35491/CVE-2020-36179/CVE-2020-36181/CVE-2020-36183/CVE-2020-36186]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

JacksonÊÇÒ»¸öÄܹ»½«java¹¤¾ßÐòÁл¯ÎªJSON×Ö·û´® £¬Ò²Äܹ»½«JSON×Ö·û´®·´ÐòÁл¯Îªjava¹¤¾ßµÄ¿ò¼Ü¡£¹¥»÷Õß¿ÉÄÜʹÓÃjacksonµÄ¿ÉÒÉ·´ÐòÁл¯Ààorg.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource»òorg.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource¹¥»÷Ä¿µÄIPÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_SpringSecurityOauth_´úÂë×¢ÈëÎó²î[CVE-2016-4977][CNNVD-201705-1270]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃSpringµÄ¹ýʧҳÃæ½á¹¹¶ñÒâ²ÎÊý´Ó¶øµ¼ÖÂSpEL´úÂëÖ´ÐС£SpringSecurityOAuthÊÇΪSpring¿ò¼ÜÌṩÇå¾²ÈÏÖ¤Ö§³ÖµÄÒ»¸öÄ£¿é¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

TCP_ľÂí_CGMiner_ʵÑéÅþÁ¬¿ó³Ø(BTC)

Çå¾²ÀàÐÍ£º

Èä³æ²¡¶¾

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCGMinerľÂí¡£CGMinerÊÇÒ»¸öÓÃÓÚ±ÈÌرҵĶàÏ̶߳à¿ó³ØFPGAºÍASIC¿ó¹¤¡£ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£Õ¼ÓÃÓû§×ÊÔ´¾ÙÐÐÍÚ¿ó¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Kibana_Ô¶³ÌÎļþ°üÀ¨Îó²îʹÓÃ[CVE-2018-17246][CNNVD-201811-285]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃKibanaµÄÔ¶³ÌÎļþ°üÀ¨Îó²îÉÏ´«ÎļþÖÁ·þÎñÆ÷í§ÒâλÖà £¬´Ó¶øÖ´ÐÐí§Òâ´úÂë¡£KibanaÊÇÒ»¸ö¿ªÔ´µÄÆÊÎöÓë¿ÉÊÓ»¯Æ½Ì¨,Éè¼Æ³öÀ´ÓÃÓÚºÍElasticsearchÒ»ÆðʹÓõÄ £¬¿ÉÒÔÓÃkibanaËÑË÷¡¢Éó²é´æ·ÅÔÚElasticsearchÖеÄÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20220322


ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_SpringOAuth2_SPEL_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-1260][CNNVD-201805-402]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼʹÓÃSpring¿ò¼ÜOAuth2Ä£¿éÔ¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¹¥»÷Õß¿ÉÒÔÏòÊÚȨ·þÎñÆ÷ÌᳫÊÚȨÇëÇó £¬µ±×ª·¢ÖÁÊÚȨÉóÅúÖնˣ¨ApprovalEndpoint£©Ê± £¬»áµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐÎó²îµÄ¹¥»÷¡£Îó²î±£´æµÄ°æ±¾£ºSpringSecurityOAuth2.3-2.3.2¡¢2.2-2.2.1¡¢2.1-2.1.1¡¢2.0-2.0.14¼°ÔçÆÚ²»Ö§³Ö°æ±¾¹¥»÷ÀÖ³É £¬¿ÉÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£

¸üÐÂʱ¼ä£º

20220322


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJACKSON-ShiroÔ¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ £¬ÊÔͼͨ¹ý´«ÈëÈ«ÐĽṹµÄ¶ñÒâ´úÂë»òÏÂÁîÀ´ÈëÇÖÄ¿µÄIPÖ÷»ú¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Nexus_Repository_Manager_3Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-10204][CNNVD-202004-036]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPʹÓÃNexusRepositoryManager3ͨ¹ýadminȨÏ޽ṹ¶ñÒâjsonÖ´ÐдúÂë¡£NexusRepositoryManager3ÊÇÒ»¸öJava·þÎñÆ÷Ó¦ÓóÌÐò¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_mini_httpd_í§ÒâÎļþ¶ÁÈ¡Îó²î[CVE-2018-18778][CNNVD-201810-1382]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Mini_httpdÊÇÒ»¸ö΢Ð͵ÄHttp·þÎñÆ÷ £¬ÔÚÕ¼ÓÃϵͳ×ÊÔ´½ÏСµÄÇéÐÎÏ¿ÉÒÔ¼á³ÖÒ»¶¨Ë®Æ½µÄÐÔÄÜ£¨Ô¼ÎªApacheµÄ90%£© £¬Òò´ËÆձ鱻ÖÖÖÖIOT£¨Â·ÓÉÆ÷ £¬½»Á÷Æ÷ £¬ÉãÏñÍ·µÈ£©×÷ΪǶÈëʽ·þÎñÆ÷¡£¶ø°üÀ¨»ªÎª £¬zyxel £¬º£¿µÍþÊÓ £¬Ê÷Ý®ÅɵÈÔÚÄڵij§É̵ÄÆìÏÂ×°±¸¶¼Ôø½ÓÄÉMini_httpd×é¼þ¡£ACMEmini_httpd<1.30°æ±¾±£´æÒ»¸öí§ÒâÎļþ¶ÁÈ¡Îó²î £¬¸ÃÎó²îÔ´ÓÚÔÚmini_httpd¿ªÆôÐéÄâÖ÷»úģʽµÄÇéÐÎÏ £¬Óû§ÇëÇóhttp://HOST/FILE½«»á»á¼ûµ½Ä¿½ñĿ¼ÏµÄHOST/FILEÎļþ £¬¶øµ±HOSTΪ¿Õ¡¢FILE=etc/passwdµÄʱ¼ä £¬ÉÏÊöÓï¾äЧ¹ûΪ/etc/passwd¡£¿É×÷Ϊ¾ø¶Ô·¾¶ £¬¶ÁÈ¡µ½ÁË/etc/passwd £¬Ôì³Éí§ÒâÎļþ¶ÁÈ¡Îó²î¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_DDoS.MrBlack_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíMrBlack¡£MrBlackÊÇÒ»¸ö¿çƽ̨µÄ½©Ê¬ÍøÂç £¬Ö§³ÖWindows¡¢Linux¡£Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ElasticSearch_ÏÂÁîÖ´ÐÐÎó²î[CVE-2014-3120]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃElasticSearchÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ £¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£ElasticSearchÊÇÒ»¸ö»ùÓÚLuceneµÄËÑË÷·þÎñÆ÷ £¬»ùÓÚJava¿ª·¢¡£ElasticSearchÖ§³Ö´«È붯̬¾ç±¾£¨MVEL£©À´Ö´ÐÐһЩÖØ´óµÄ²Ù×÷ £¬¶øMVEL¿ÉÖ´ÐÐJava´úÂë £¬¹¥»÷ÕßʹÓøÃÎó²î¿ÉÒÔÔÚElasticSearch·þÎñÆ÷ÖÐÖ´ÐÐí§ÒâJava´úÂë»òÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Linux.AESDDOS(Dofloo)_ÅþÁ¬C2

Çå¾²ÀàÐÍ£º

ÆäËûÊÂÎñ

ÊÂÎñÐÎò£º

Dofloo£¨AESDDoS£©½©Ê¬ÍøÂç´Ó±»Ñ¬È¾ÏµÍ³ÇÔÊØÐÅÏ¢ £¬°üÀ¨²Ù×÷ϵͳ°æ±¾ £¬CPUÐͺš¢ËÙÂʺÍÄÚ´æµÈÐÅÏ¢ÉÏ´«µ½C2·þÎñÆ÷ £¬²¢Æ¾Ö¤·µ»ØµÄÏÂÁî¾ÙÐÐAES½âÃÜ £¬Ö´ÐÐCmdshell»òÕßÌᳫÖÖÖÖÀàÐ͵ÄDDoS¹¥»÷ £¬°üÀ¨DNS¡¢SYN £¬LSYN £¬UDP £¬UDPS £¬TCPºÍCCFlood¡£Ö´ÐÐCmdshellÏÂÁî»òÕßÌᳫDDOS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20220322

 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Spring-Data-REST-PATCHÇëÇó_Ô¶³ÌÖ´ÐдúÂë[CVE-2017-8046][CNNVD-201704-1106]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¸ÃÎó²îΪ¹¥»÷Õßͨ¹ýSpringDataRestÖ§³ÖµÄPATCHÒªÁì £¬½á¹¹¶ñÒâµÄJsonÃûÌÃÊý¾Ý·¢Ë͵½·þÎñ¶Ë £¬µ¼Ö·þÎñ¶ËÔÚÆÊÎöÊý¾Ýʱ»áÖ´ÐÐí§ÒâJava´úÂë¡¢ÆÊÎöSpEL±í´ïʽ £¬´Ó¶øʵÏÖÔ¶³Ìí§Òâ´úÂëÖ´ÐС£

¸üÐÂʱ¼ä£º

20220322