ÿÖÜÉý¼¶Í¨¸æ-2021-05-18

Ðû²¼Ê±¼ä 2021-05-19

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PHP-zerodiumºóÃÅ_ÈÎÒâ´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

PHP¿ª·¢¹¤³ÌʦJakeBirchallÔÚ¶ÔÆäÖÐÒ»¸ö¶ñÒâCOMMITµÄ·ÖÎö¹ý³ÌÖз¢ÏÖ £¬ÔÚ´úÂëÖÐ×¢ÈëµÄºóÃÅÊÇÀ´×ÔÒ»¸öPHP´úÂë±»½Ù³ÖµÄÍøÕ¾ÉÏ £¬¶øÇÒ½ÓÄÉÁËÔ¶³Ì´úÂëÖ´ÐеIJÙ×÷ £¬¶øÇÒ¹¥»÷ÕßµÁÓÃÁËPHP¿ª·¢ÈËÔ±µÄÃûÒåÀ´Ìá½»´ËCOMMIT¡£Ä¿Ç°ÎªÖ¹PHP¹Ù·½²¢Î´¾Í¸Ãʼþ½øÐиü¶àÅû¶ £¬ÌåÏִ˴ηþÎñÆ÷±»ºÚµÄ¾ßÌåϸ½ÚÈÔÔÚÊӲ쵱ÖС£ÓÉÓÚ´ËʼþµÄÓ°Ïì £¬PHPµÄ¹Ù·½´úÂë¿âÒѾ­±»Î¬»¤ÈËÔ±Ç¨ÒÆÖÁGitHubƽ̨ £¬Ö®ºóµÄÏà¹Ø´úÂë¸üС¢Ð޸Ľ«»á¶¼ÔÚGitHubÉϽøÐС£

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

TCP_ºóÃÅ_Gh0st_htrfhtfe__Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£Gh0stÊÇÖøÃûµÄ¿ªÔ´Ô¶¿Ø·¨Ê½ £¬¹¦Ð§Ê®·ÖÇ¿´ó¡£¾ßÓÐÎļþ¹ÜÀí£¨ÈçÉÏ´«¡¢ÏÂÔØ¡¢´´½¨¡¢É¾³ý£©¡¢½ø³Ì¹ÜÀí¡¢ÏµÍ³·þÎñ¡¢×¢²á±í¡¢¼üÅ̼Ǽ¡¢Ô¶³ÌÖÕ¶Ë¡¢ÆÁÄ»¼à¿Ø¡¢¼ì²ìÉãÏñÍ·¡¢¼àÌýÓïÒôµÈµÈ¹¦Ð§ £¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úÆ÷¡£½üÆÚ·¢ÏÖ´óÁ¿Æ¾¾ÝGh0stÔ´ÂëÐ޸ĵÄÔ¶¿Ø·¨Ê½ £¬²¢Ìí¼ÓÁË×Ô¼ºµÄ¹¦Ð§ £¬ÈçºéË®¹¥»÷¡¢¼ì²âϵͳɱ¶¾Èí¼þ¡¢¼ì²âϵͳ°²×°µÄÍøÂçÓÎÏ·µÈ¹¦Ð§¡£ºÚ¿Í»¹¿ÉÒÔ½«º¬ÓÐÉãÏñÍ·»ò°²×°Ö¸¶¨ÓÎÏ·µÄÓû§¹éÀà £¬ÓÐÕë¶ÔÐÔµÄ͵ȡÓû§Òþ˽¡£ÉõÖÁ¼ì²ìÖж¾ÕßµØÀíλÖõĹ¦Ð§ £¬¶ÔÓû§µÄÒþ˽Ôì³É¸ü´óµÄÍþв¡£

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Terramaster_TOS_ÃüÁî×¢Èë©¶´[CVE-2020-28188][CNNVD-202012-1548]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

TerramasterTOSÊÇÖйúÉîÛÚÊÐͼÃÀµç×Ó¼¼Êõ£¨Terramaster£©¹«Ë¾µÄÒ»¿î»ùÓÚLinuxƽ̨µÄ £¬×¨ÓÃÓÚerraMasterÔÆ´æ´¢NAS·þÎñÆ÷µÄ²Ù×÷ϵͳ¡£TerraMasterTOS4.2.06°æ±¾¼°Ö®Ç°°æ±¾´æÔÚ²Ù×÷ϵͳÃüÁî×¢Èë©¶´ £¬¹¥»÷Õß¿ÉÀûÓøÃ©¶´Í¨¹ýÔÚʼþ²ÎÊýÖаüÂÞmakecvs.php×¢Èë²Ù×÷ϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

HTTP_SSH-RSA˽Կй©

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

RSA˽Կ±»ÓÃÔÚRSA¼ÓÃÜÖеĽâÂ븳ÄÜ £¬LINUX·þÎñÆ÷Ö§³ÖʹÓÃRSA˽ԿµÇ¼SSH £¬RSA˽Կй¶ £¬µ¼ÖÂÖ÷»ú¿ÉʹÓÃRSAµÇ¼SSH £¬µ¼ÖÂÖ÷»ú±»½Ó¹Ü¡£

¸üÐÂʱ¼ä£º

20210511


ʼþÃû³Æ£º

HTTP_Microsoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì[CVE-2021-26855][CNNVD-202103-192]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

µ±Ç°Ö÷»úÕýÔÚÔâÊÜMicrosoft-Exchange-SERVER_·þÎñÆ÷¶ËÇëÇóαÔì¹¥»÷¸Ã©¶´ÊÇExchangeÖеÄÈÎÒâÎļþдÈë©¶´¡£¸Ã©¶´ÐèÒª½øÐÐÉí·ÝÈÏÖ¤ £¬ÀûÓôË©¶´¿ÉÒÔ½«ÎļþдÈë·þÎñÆ÷ÉϵÄÈκη¾¶¡£²¢¿ÉÒÔ½áºÏÀûÓÃCVE-2021-26855SSRF©¶´»òÈÆ¹ýȨÏÞÈÏÖ¤½øÐÐÎļþдÈë¡£

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

HTTP_ÍÚ¿óľÂí_Supreme_Logger_Miner_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½ÍÚ¿óľÂíSupremeLoggerÁ¬½ÓC2·þÎñÆ÷µÄÐÐΪ¡£SupremeLoggerÊǸöWindowsƽ̨µÄÍÚ¿óľÂí £¬¾ßÓÐËѼ¯Êܺ¦Ö÷»úÃô¸ÐÐÅÏ¢ÉÏ´«µ½C2·þÎñÆ÷µÄÐÐΪ £¬ÏÂÔØÍÚ¿ó·¨Ê½µ½Êܺ¦Ö÷»úÄÚ´æ²¢×¢ÈëIE½ø³ÌÖÐÖ´ÐÐÍÚ¿ó £¬Æ¾¾ÝC2·þÎñÆ÷µÄÃüÁîÖ´ÐÐÖÖÖÖ²Ù×÷ £¬Èç¸üÐÂÅäÖÃÐÅÏ¢¡¢°²×°ÍÚ¿ó·¨Ê½µÈ¡£

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸Äʼþ


ʼþÃû³Æ£º

HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£

Ô¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓС®action:¡¯¡¢¡®redirect:¡¯»ò¡®redirectAction:¡¯µÄǰ׺²ÎÊýÀûÓøÃ©¶´Ö´ÐÐÈÎÒâOGNL±í´ïʽ¡£

©¶´´æÔڵİ汾£º

S2-016£ºStruts 2.0.0 - Struts 2.3.15

S2-017£ºStruts 2.0.0 - Struts 2.3.15

S2-018£ºStruts 2.0.0 - Struts 2.3.15.2

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

HTTP_ľÂí_Raccoon.Stealer_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËRaccoon¡£RaccoonÒ²±»³ÆÎªMohazo»òRacealer £¬ÊÇÒ»¸ö¹¦Ð§Ç¿´óµÄÇÔÃÜľÂí¡£Ëü¿ÉÒÔÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷¡¢CryptocurrencyWallets¡¢EmailsµÈ¿Í»§¶ËÉú´æµÄÕ˺ÅÃÜÂë¡£ÇÔÈ¡Ãô¸ÐÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20210518


ʼþÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3 £¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí·ÃÎÊ'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩 £¬²¢ÔÊÐí¿ØÖÆClassLoader¡£ÔÚ¾ßÌåµÄWebÈÝÆ÷²¿Êð»·¾³Ï£¨È磺Tomcat£© £¬¹¥»÷ÕßÀûÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£© £¬¿ÉÏò·þÎñÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷ £¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷Ö÷»ú¡£ÁíÍâ £¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖÐ £¬boundary´óÓÚ½çÏÞÖµ £¬¶øÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏÞÖµ £¬µ¼ÖÂDDOS¡£Â©¶´´æÔڵİ汾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸Äʼþ


1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐЩ¶´

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÃüÁî_Ô¶³ÌÃüÁîÖ´ÐÐ