ÿÖÜÉý¼¶Í¨¸æ-2022-04-26

Ðû²¼Ê±¼ä 2022-04-26
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_LinuxÏÂÁî×¢Èë¹¥»÷

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

ÏÂÁî×¢Èë¹¥»÷£¬ÊÇÖ¸ÕâÑùÒ»ÖÖ¹¥»÷ÊֶΣ¬ºÚ¿Íͨ¹ý°ÑϵͳÏÂÁî¼ÓÈëµ½webÇëÇóÒ³ÃæÍ·²¿ÐÅÏ¢ÖУ¬Ò»¸ö¶ñÒâºÚ¿ÍÒÔʹÓÃÕâÖÖ¹¥»÷ÒªÁìÀ´²»·¨»ñÈ¡Êý¾Ý»òÕßÍøÂ硢ϵͳ×ÊÔ´

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_pingÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐлØÏÔ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

·¢Ã÷ÓÐÖ´ÐÐpingϵͳÏÂÁîµÄ»ØÏÔÒ³Ã棬ӦÓóÌÐòµÄijЩ¹¦Ð§ÐèҪŲÓÿÉÒÔÖ´ÐÐϵͳÏÂÁîµÄº¯Êý£¬ÈôÊÇÕâЩº¯Êý»òÕߺ¯ÊýµÄ²ÎÊý±»Óû§¿ØÖÆ£¬¾ÍÓпÉÄÜͨ¹ýÏÂÁîÅþÁ¬·û½«¶ñÒâÏÂÁîÆ´½Óµ½Õý³£µÄº¯ÊýÖУ¬´Ó¶øÖ´ÐÐϵͳÏÂÁî¡£ÊôÓÚ¸ßΣÎó²î£¬ÈôÊÇwebʹÓõÄrootȨÏÞ£¬Ôò¹¥»÷Õß¿ÉÒÔÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_dirÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

·¢Ã÷ÓÐÖ´ÐÐdirϵͳÏÂÁîµÄ»ØÏÔÒ³Ãæ

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_netstat_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÏÂÁîµÄ»ØÏÔÐÅÏ¢£¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ£¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÏÂÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_psÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÏÂÁîµÄ»ØÏÔÐÅÏ¢£¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ£¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÏÂÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_NPSÊðÀí¹¤¾ß_ÄÚÍø´©Í¸Ê¹ÓÃ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½NPSÊðÀí¹¤¾ßÅþÁ¬·þÎñÆ÷£¬Ô´µØµãÖ÷»úÕýÔÚʹÓÃNPSÊðÀí¹¤¾ß¡£npsÊÇÒ»¿îÇáÁ¿¼¶¡¢¸ßÐÔÄÜ¡¢¹¦Ð§Ç¿Ê¢µÄÄÚÍø´©Í¸ÊðÀí·þÎñÆ÷¡£ÏÖÔÚÖ§³Ötcp¡¢udpÁ÷Á¿×ª·¢£¬¿ÉÖ§³ÖÈκÎtcp¡¢udpÉϲãЭÒ飨»á¼ûÄÚÍøÍøÕ¾¡¢ÍâµØÖ§¸¶½Ó¿Úµ÷ÊÔ¡¢ssh»á¼û¡¢Ô¶³Ì×ÀÃ棬ÄÚÍødnsÆÊÎöµÈµÈ¡­¡­£©£¬±ðµÄ»¹Ö§³ÖÄÚÍøhttpÊðÀí¡¢ÄÚÍøsocks5ÊðÀí¡¢p2pµÈ£¬²¢´øÓй¦Ð§Ç¿Ê¢µÄwebÖÎÀí¶Ë¡£Òò´Ë£¬¹¥»÷Õß³£Ê¹Óøù¤¾ß¾ÙÐÐÄÚÍøÉø͸¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_arpÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

·¢Ã÷±£´æwindowsÇéÐÎÏÂÖ´ÐÐarp-aϵͳÏÂÁîµÄ»ØÏÔÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

ľÂíºóÃÅ

Çå¾²ÀàÐÍ£º

ÓÕƭЮÖÆ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçEnemybotÊÔͼÅþÁ¬C&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËEnemybot¡£EnemybotÊÇÍŽᲢÐÞ¸ÄMiraiºÍGafgytÔ´´úÂëµÄ²úÆ·£¬ÒÉËƳö×ÔÃûΪKeksec(ÓÖÃûKekSecurity¡¢Necro»òÕßFreakOut)µÄ¹¥»÷ÍÅ»ïÖ®ÊÖ¡£EnemybotÖ÷Òª¹¥»÷SeowonIntech¡¢D-LinkºÍiRZ·ÓÉÆ÷

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Webshell_AntSword-2.1.x_ľÂíÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

AntSwordÊÇÒ»¿î¼¯±àÂëÈƹý£¬·Ö¿é´«ÊäµÈÖÚ¶àÈƹý·½·¨ÎªÒ»ÌåµÄÍøÕ¾ºóÃÅÖÎÀíÆ÷¡£AntSwordv2.1.14£¨×îа棩ÐÂÔöCMDLINUXShellÀàÐÍ»ùÓÚÏÂÁîÖ´ÐеÄÒ»¾ä»°ÀàÐÍ,½öÖ§³ÖLinuxÇéÐÎ.

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_phpMoAdmin_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉϵÄphpMoAdminÖ´ÐжñÒâ´úÂ롣ʹÓÃsystem,exec,shell_exec,passthru,pcntl_exec,popen,proc_openº¯Êý¶Ô´«ÈëµÄ¡°find¡±²ÎÊý¾ÙÐÐÖ´ÐУ¬µÖ´ï¿ØÖÆ·þÎñÆ÷µÄÄ¿µÄ¡£phpMoAdminÊÇÒ»¸öÓÃPHP¿ª·¢µÄÔÚÏßMongoDBÖÎÀí¹¤¾ß£¬¿ÉÓÃÓÚ½¨É衢ɾ³ýºÍÐÞ¸ÄÊý¾Ý¿âºÍË÷Òý£¬ÌṩÊÓͼºÍÊý¾ÝËÑË÷¹¤¾ß£¬ÌṩÊý¾Ý¿âÆô¶¯Ê±¼äºÍÄÚ´æµÄͳ¼Æ£¬Ö§³ÖJSONÃûÌÃÊý¾ÝµÄµ¼Èëµ¼³ö¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TendaM3_Ô¶³ÌÏÂÁî×¢ÈëÎó²î[CVE-2022-26290][CNNVD-202203-2102]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

TendaM3ÊÇÖйúÌڴTenda£©¹«Ë¾µÄÒ»¿îÃŽû¿ØÖÆÆ÷¡£TendaM31.101.0.0.12(4856)°æ±¾±£´æÇå¾²Îó²î£¬¸ÃÎó²îÔ´ÓÚͨ¹ý×é¼þ/goform/WriteFacMacµÄÏÂÁî×¢ÈëÎó²î¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Adobe-ColdFusion_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2017-3066][CNNVD-201704-1418]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

AdobeColdFusionÊÇÃÀ¹úAdobe¹«Ë¾µÄÒ»¿î¶¯Ì¬Web·þÎñÆ÷²úÆ·£¬ÆäÔËÐеÄCFML£¨ColdFusionMarkupLanguage£©ÊÇÕë¶ÔWebÓ¦ÓõÄÒ»ÖÖ³ÌÐòÉè¼ÆÓïÑÔ¡£AdobeColdFusionÖб£´æjava·´ÐòÁл¯Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚÊÜÓ°ÏìÓ¦ÓóÌÐòµÄÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë»òÔì³É¾Ü¾ø·þÎñ¡£ÒÔÏ°汾Êܵ½Ó°Ï죺AdobeColdFusion(2016release)Update3¼°Ö®Ç°µÄ°æ±¾£¬ColdFusion11Update11¼°Ö®Ç°µÄ°æ±¾£¬ColdFusion10Update22¼°Ö®Ç°µÄ°æ±¾¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Oracle-Business_XMLÍⲿʵÌå×¢Èë[CVE-2019-2616][CNNVD-201904-746]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

OracleFusionMiddleware£¨OracleÈÚºÏÖÐÐļþ£©ÊÇÃÀ¹ú¼×¹ÇÎÄ£¨Oracle£©¹«Ë¾µÄÒ»Ì×ÃæÏòÆóÒµºÍÔÆÇéÐεÄÓªÒµÁ¢Òìƽ̨¡£¸Ãƽ̨ÌṩÁËÖÐÐļþ¡¢Èí¼þÜöÝ͵ȹ¦Ð§¡£BIPublisher£¨Ç°³ÆXMLPublisher£©ÊÇÆäÖеÄÒ»¸ö±¨±í×é¼þ¡£OracleFusionMiddlewareÖеÄBIPublisher×é¼þ11.1.1.9.0°æ±¾¡¢12.2.1.3.0°æ±¾ºÍ12.2.1.4.0°æ±¾µÄBIPublisherSecurity×Ó×é¼þ±£´æÇå¾²Îó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îδÊÚȨ¶ÁÈ¡¡¢¸üС¢²åÈë»òɾ³ýÊý¾Ý£¬Ó°ÏìÊý¾ÝµÄ±£ÃÜÐÔºÍÍêÕûÐÔ¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache-Airflow-1.10.10_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-11978][CNNVD-202007-1187]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheAirflowÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»Ì×ÓÃÓÚ½¨Éè¡¢ÖÎÀíºÍ¼à¿ØÊÂÇéÁ÷³ÌµÄ¿ªÔ´Æ½Ì¨¡£¸Ãƽ̨¾ßÓпÉÀ©Õ¹ºÍ¶¯Ì¬¼à¿ØµÈÌصã¡£ApacheAirflow1.10.10¼°Ö®Ç°°æ±¾ÖеÄexampleDAGs±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÔËÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ArticaTech-Artica-Proxy_ÏÂÁî×¢Èë[CVE-2020-17505][CNNVD-202008-677]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ArticaTechArticaProxyÊÇ·¨¹úArticaTech¹«Ë¾µÄÒ»¿î¿ªÔ´µÄArticaÊðÃ÷È·¾ö¼Æ»®¡£ArticaWebProxy4.30.000000°æ±¾cyrus.phpÎļþµÄservice-cmds²ÎÊý±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýservice_cmds_peformʹÓøÃÎó²îÒÔrootȨÏÞ×¢Èë²¢Ö´ÐÐÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ArticaTech-Artica-Proxy_SQL×¢Èë[CVE-2020-17506][CNNVD-202008-679]

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

ArticaTechArticaProxyÊÇ·¨¹úArticaTech¹«Ë¾µÄÒ»¿î¿ªÔ´µÄArticaÊðÃ÷È·¾ö¼Æ»®¡£ArticaWebProxy4.30.000000°æ±¾ÈÝÒ×Êܵ½fw.login.phpÖеÄapi¼ü²ÎÊýµÄSQL×¢ÈëµÄ¹¥»÷¡£¸ÃÎó²î¿ÉÒÔÈƹýArtica£¬Í¨¹ýSQL×¢ÈëÎó²î»ñµÃÖÎÀíԱȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Cisco-HyperFlex-HX-storfs-asup_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CiscoHyperFlexHXÊý¾Ýƽ̨»ùÓÚWebµÄÖÎÀí½çÃæÖеÄÎó²î¿ÉÄÜÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߶ÔÊÜÓ°ÏìµÄ×°±¸Ö´ÐÐÏÂÁî×¢Èë¹¥»÷¡£´ËÎó²îÊÇÓÉÓÚ¶ÔÓû§ÌṩµÄÊäÈëµÄÑé֤ȱ·¦¶øÒýÆðµÄ¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÏò»ùÓÚWebµÄÖÎÀí½çÃæ·¢ËÍÈ«ÐÄÉè¼ÆµÄÇëÇóÀ´Ê¹ÓôËÎó²î¡£ÀÖ³ÉʹÓøÃÎó²î¿ÉÄÜʹ¹¥»÷ÕßÒÔtomcat8Óû§µÄÉí·ÝÔÚÊÜÓ°ÏìµÄ×°±¸ÉÏÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Advantech-R-SeeNet-device_¿çÕ¾¾ç±¾[CVE-2021-21801][CNNVD-202107-1107]

Çå¾²ÀàÐÍ£º

XSS¹¥»÷

ÊÂÎñÐÎò£º

AdvantechR-SeeNetv2.4.12(20.10.2020)µÄdevice_graph_page.php¾ç±¾¹¦Ð§Öб£´æ¶à¸ö¿çÕ¾µã¾ç±¾Îó²î¡£ÈôÊÇÓû§»á¼ûÌØÖƵÄURL£¬Ëü¿ÉÄܻᵼÖÂÔÚÄ¿µÄÓû§ä¯ÀÀÆ÷µÄÉÏÏÂÎÄÖÐÖ´ÐÐí§ÒâJavaScript´úÂë¡£¹¥»÷Õß¿ÉÒÔÌṩÕâЩȫÐÄÖÆ×÷µÄURLÀ´´¥·¢Îó²î¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Èñ½ÝNBR·ÓÉÆ÷EWEBÍø¹Üϵͳ_Ô¶³ÌÏÂÁîÖ´ÐÐ[CVE-2021-21801][CNNVD-202107-1107]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Èñ½ÝÍøÂçÊÇÒ»¼ÒÓµÓаüÀ¨½»Á÷»ú¡¢Â·ÓÉÆ÷¡¢Èí¼þ¡¢Çå¾²·À»ðǽ¡¢ÎÞÏß²úÆ·¡¢´æ´¢µÈȫϵÁеÄÍøÂç×°±¸²úÆ·Ïß¼°½â¾ö¼Æ»®µÄרҵ»¯ÍøÂ糧ÉÌ¡£Èñ½ÝÍøÂç¹É·ÝÓÐÏÞ¹«Ë¾NBR·ÓÉÆ÷EWEBÍø¹Üϵͳ±£´æÏÂÁîÖ´ÐÐÎó²î£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î»ñÈ¡·þÎñÆ÷¿ØÖÆȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_DLink·ÓÉÆ÷_DAP_2020_Ô¶³Ìí§ÒâÏÂÁîÖ´ÐÐÎó²î[CVE-2021-27249][CNNVD-201312-320]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÕýÔÚʹÓÃDLinkµÄÎó²î¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡¡¢Ö´ÐÐí§ÒâÏÂÁîµÈ²Ù×÷£¬D-LinkDAP-2020ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi¹æÄ£À©Õ¹Æ÷¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_ÏÂÁîÖ´ÐÐ_Netgear·ÓÉÆ÷_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃNetgearµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷£»ÃÀ¹úÍø¼þNETGEARµÄ·ÓÉÆ÷ÖÂÁ¦ÓÚΪȫÇòÉÌÓÃÆóÒµÓû§ºÍ¼ÒͥСÎÒ˽¼ÒÓû§ÌṩÁ¢ÒìµÄ²úÆ·¡¢ÓÅÖʵÄÖÇÄܼÒÍ¥½â¾ö¼Æ»®¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_ÎļþÉÏ´«_NETGEAR_ProSafe_í§ÒâÎļþÉÏ´«Îó²î[CVE-2016-1524][CNNVD-201602-129]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃNETGEARProSafeÖÎÀíϵͳµÄÎļþÉÏ´«Îó²îÉÏ´«¶ñÒâÎļþ£»NETGEARÍøÂçÖÎÀíϵͳNMS300ÊÇΪNETGEARͳһ»ù´¡¼Ü¹¹Éè¼ÆµÄ¡£×¨ÃÅÕë¶ÔÍøÂç×°±¸¾ÙÐмà²â£¬ÉèÖú͹ÊÕÏÕï¶Ï¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_FreePBX_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2012-4869][CNNVD-201203-383]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃFreePBXµÄcallmenum²ÎÊý´¦µÄÎó²î½á¹¹¶ñÒâ´úÂ룬FreePBX֮ǰ±»³ÆΪAsteriskManagementPortal£¬ÊÇIPµç»°¹¤¾ßAsteriskµÄ±ê×¼»¯ÊµÏÖ£¬¿ÉÌṩWebÉèÖýçÃæºÍÆäËû¹¤¾ß¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_mod_jk_»á¼û¿ØÖÆÈƹý[CVE-2018-11759][CNNVD-201810-1558]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheTomcatJK£¨mod_jk£©ConnectorÊÇÃÀ¹ú°¢ÅÁÆ棨Apache£©Èí¼þ»ù½ð»áµÄÒ»¿îΪApache»òIISÌṩÅþÁ¬ºǫ́TomcatµÄÄ£¿é£¬ÓÃÒÔΪApache»òIIS·þÎñÆ÷Ìṩ´¦Öóͷ£"font-family:ËÎÌå;font-size:13px">¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Wireless_IP_Camera_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃWireless_IP_CameraµÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷£¬ÎÞÏßÍøÂçÉãÏñ»ú(P2)WIFICAMÊÇÒ»¿îÕûÌåÉè¼Æ²»Á¼µÄÉãÏñ»ú£¬±£´æÐí¶àÎó²î¡£Õâ¿îÏà»úÓëÐí¶àÆäËûÖйúÏà»úºÜÊÇÏàËÆ£¬ÎÞÏßÍøÂçÉãÏñ»ú(P2)WIFICAMÊÇÆ·ÅÆÉãÏñ»úÖ®Ò»¡£

¸üÐÂʱ¼ä£º

20220426


ÊÂÎñÃû³Æ£º

HTTP_Ç徲ɨÃè_DisBusterɨÃèÆ÷

Çå¾²ÀàÐÍ£º

Ç徲ɨÃè

ÊÂÎñÐÎò£º

DisBusterÊÇÉø͸²âÊÔÀú³ÌÖг£ÓõÄɨÃ蹤¾ß£¬¿ÉÒÔ×Ô½ç˵¼ÓÔØ×Ô½ç˵×Öµä¶ÔÄ¿µÄ¾ÙÐÐĿ¼»òÒ³ÃæɨÃèºÍ±¬ÆÆ¡£

¸üÐÂʱ¼ä£º

20220426

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.Dyzap_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWin32.Dyzap¡£

Win32.DyzapÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÇÔÃÜľÂí£¬¿ÉÇÔÃÜ°üÀ¨ä¯ÀÀÆ÷¡¢Óʼþ¡¢FTPµÈ¿Í»§¶ËÉúÑĵÄÕ˺ÅÃÜÂë¡£

ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSIL.Crimson_¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅCrimsonµÄ·þÎñÆ÷ÔÚÏòCrimson·¢ËÍ¿ØÖÆÏÂÁĿµÄIPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅ Crimson¡£

 

CrimsonÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£Crimsonͨ¹ýÖÖÖÖÄ£¿éÀ´À©Õ¹Æ书Ч£¬Èç»ñȡƾ֤£¬¼üÅ̼ͼµÈ¡£

¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_MSIL.Crimson_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCrimson¡£

CrimsonÊÇÒ»¸ö¹¦Ð§ºÜÊÇÇ¿Ê¢µÄºóÃÅ£¬ÔËÐк󣬿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£Crimsonͨ¹ýÖÖÖÖÄ£¿éÀ´À©Õ¹Æ书Ч£¬Èç»ñȡƾ֤£¬¼üÅ̼ͼµÈ¡£

¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_Fodcha_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÅþÁ¬C&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£FodchaÖ÷Ҫͨ¹ýNDayÎó²îºÍTelnet/SSHÈõ¿ÚÁîÈö²¥£¬°üÀ¨CVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈÎó²î¡£ÖðÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊýÅÌËãÒÑÁè¼Ý1Íò£¬ÇÒÖðÈÕ»áÕë¶ÔÁè¼Ý100¸ö¹¥»÷Ä¿µÄÌᳫDDoS¹¥»÷£¬¹¥»÷·Ç³£»îÔ¾¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨѶÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20220426

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓúÜÊÇÆÕ±éµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£Öйú²Ëµ¶ÓÃ;ʮ·ÖÆÕ±é,Ö§³Ö¶àÖÖÓïÑÔ,СÇÉÊÊÓ㬾ßÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ¼ä¿ÉÒÔÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬Êý¾Ý¿âÖÎÀí£¬ÐéÄâÖն˵ȹ¦Ð§¡£¹ØÓÚÕâÀàÖÎÀí¹¤¾ß£¬ÈôÊÇûÓдó×ÚµÄÐ޸ķþÎñ¶Ë¾ç±¾´úÂ룬Æä·µ»ØÁ÷Á¿¶¼»áÓÐһЩ³£¼ûµÄÌØÕ÷£¬±¾Ìõ¹æÔò½«³£¼ûµÄÅäºÏÌØÕ÷ÌáÈ¡³öÀ´¾ÙÐзÀÓùÐÔ±¨¾¯¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØÕ÷£¬¿ÉÄܱ£´æÎ󱨣¬Çë²Î¿¼ÌØÕ÷ÐÔ×ÓÅжÏ×ֶξÙÐÐÅжÏ¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20220426