ÿÖÜÉý¼¶Í¨¸æ-2023-02-14

Ðû²¼Ê±¼ä 2023-02-14
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_·´ÐòÁл¯_Weblogic_T3ЭÒé[CVE-2020-14756]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨ £¬ÓÃÓÚÔÚÍâµØºÍÔƶ˿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555Îó²î¿ÉÒÔÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Çå¾²µÄextractÒªÁì £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷ £¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°Ïì¹æÄ££ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230214

 

ÊÂÎñÃû³Æ£º

HTTP_ÏÂÁî¿ØÖÆ_C2ͨѶ_OrcaC2_ÉÏÏß×¢²á_ÅþÁ¬C2·þÎñÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨѶµÄ¶à¹¦Ð§C&C¿ò¼Ü £¬Ê¹ÓÃGolangʵÏÖ¡£ËüÓÉÈý²¿·Ö×é³É£ºOrca_Server(·þÎñ¶Ë)¡¢Orca_Master(¿ØÖƶË)¡¢(±»¿ØÖƶËOrca_Puppet)¡£OrcaC2½ÓÄÉWebsocketͨѶ £¬jsonÃûÌô«ÊäÊý¾Ý £¬ÐÂÎÅÓëÊý¾ÝÊÕÂÞʹÓÃAES-CBC¼ÓÃÜ+Base64±àÂë £¬¾ßÓÐÔ¶³ÌÏÂÁî¿ØÖÆ¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢ÆÁÄ»½Øͼ£¨±»¿ØÖƶËΪWindowsϵͳ£©¡¢Ô¶³ÌÆÁÄ»¿ØÖÆ¡¢¼üÅ̼ͼµÈµÈ¡£¸ÃÌõÊÂÎñÅú×¢Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí £¬ÕýÔÚÏò·þÎñ¶Ë·¢ËÍÉÏÏß×¢²áÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230214

 

ÊÂÎñÃû³Æ£º

TCP_ÏÂÁî¿ØÖÆ_C2ͨѶ_OrcaC2_WebSocketЭÒé_ÐÄÌøͨѶ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨѶµÄ¶à¹¦Ð§C&C¿ò¼Ü £¬Ê¹ÓÃGolangʵÏÖ¡£ËüÓÉÈý²¿·Ö×é³É£ºOrca_Server(·þÎñ¶Ë)¡¢Orca_Master(¿ØÖƶË)¡¢(±»¿ØÖƶËOrca_Puppet)¡£OrcaC2½ÓÄÉWebsocketͨѶ £¬jsonÃûÌô«ÊäÊý¾Ý £¬ÐÂÎÅÓëÊý¾ÝÊÕÂÞʹÓÃAES-CBC¼ÓÃÜ+Base64±àÂë £¬¾ßÓÐÔ¶³ÌÏÂÁî¿ØÖÆ¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢ÆÁÄ»½Øͼ£¨±»¿ØÖƶËΪWindowsϵͳ£©¡¢Ô¶³ÌÆÁÄ»¿ØÖÆ¡¢¼üÅ̼ͼµÈµÈ¡£¸ÃÌõÊÂÎñÅú×¢Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí £¬Orca_Server·þÎñ¹æÔòÔÚÏò±»¿ØÖƶ˷¢ËÍÐÄÌøͨѶÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230214

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Centos_Web_Panel_7_ÏÂÁîÖ´ÐÐ[CVE-2022-44877]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CWP £¬Ç°ÉíΪCentOSWebPanel £¬ÊÇÒ»¸öÃâ·ÑʹÓõÄLinux¿ØÖÆÃæ°å¡£ÔÚCentOSWebPanel70.9.8.1147°æ±¾Ö®Ç°µÄϵͳÖÐ £¬/login/index.php×é¼þÖб£´æÎó²î £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ýÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÖ´ÐÐí§ÒâϵͳÏÂÁî¡£

¸üÐÂʱ¼ä£º

20230214

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_·´ÐòÁл¯_Oracle_WebLogic_T3ЭÒé[CVE-2020-2555]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPʹÓÃweblogic·´ÐòÁл¯Îó²î¾ÙÐй¥»÷µÄÐÐΪ £¬OracleCoherenceΪOracleÈÚºÏÖÐÐļþÖеIJúÆ· £¬ÔÚWebLogic12c¼°ÒÔÉÏ°æ±¾ÖÐĬÈϼ¯³Éµ½WebLogic×°ÖðüÖÐ £¬¹¥»÷Õßͨ¹ýt3ЭÒé·¢ËͽṹµÄÐòÁл¯Êý¾Ý £¬ÄܹýÔì³ÉÏÂÁîÖ´ÐеÄЧ¹û

¸üÐÂʱ¼ä£º

20230214

 

ÊÂÎñÃû³Æ£º

TCP_Îó²îʹÓÃ_·´ÐòÁл¯_Oracle_Weblogic_T3ЭÒé[CVE-2020-2883]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨ £¬ÓÃÓÚÔÚÍâµØºÍÔƶ˿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555Îó²î¿ÉÒÔͨ¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Çå¾²µÄextractÒªÁì £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷ £¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£Ó°Ïì¹æÄ££ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230214