ÿÖÜÉý¼¶Í¨¸æ-2023-01-17

Ðû²¼Ê±¼ä 2023-01-17
ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Hashicorp_Consul_Service_API_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃConsulÖдæÔÚµÄÔ¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷¡£ConsulÊÇHashiCorp¹«Ë¾ÍƳöµÄÒ»¿î¿ªÔ´¹¤¾ß £¬ÓÃÓÚʵÏÖÂþÑÜʽϵͳµÄ·þÎñ·¢ÏÖÓëÅäÖá£ÔÚÆôÓÃÁ˽ű¾¼ì²é²ÎÊý£¨-enable-script-checks£©µÄConsulËùÓа汾ÖÐ £¬¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢Ë;«ÐĽṹµÄHTTPÇëÇóÔÚδ¾­ÊÚȨµÄÇé¿öÏÂÔÚConsul·þÎñ¶ËÔ¶³ÌÖ´ÐÐÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

DNS_½©Ê¬ÍøÂç_Fodcha_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÏòdns·þÎñÆ÷ÇëÇó½âÎöÆäC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£FodchaÖ÷Ҫͨ¹ýNDay©¶´ºÍTelnet/SSHÈõ¿ÚÁîÁ÷´« £¬°üÂÞCVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈ©¶´¡£Ã¿ÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊý¼ÆËãÒÑÁè¼Ý1Íò £¬ÇÒÿÈÕ»áÕë¶ÔÁè¼Ý100¸ö¹¥»÷Ä¿±êÌᳫDDoS¹¥»÷ £¬¹¥»÷·Ç³£»îÔ¾¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨÐÅÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20230117

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαЭÒé

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·âװЭÒé £¬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí £¬»òÔ¶³ÌÖ´ÐÐÃüÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷ £¬´Ó¶ø»ñȡĿ±êϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÃüÁî×¢Èë

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÃüÁî×¢Èë©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖÐ £¬exportovpn½Ó¿Ú´æÔÚÃüÁî×¢Èë £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÈôÒÀCMS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÈôÒÀºǫ́¹ÜÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü £¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄ¸ñʽ £¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́¼Æ»®ÈÎÎñ´¦ £¬¶ÔÓÚ´«ÈëµÄ"µ÷ÓÃÄ¿±ê×Ö·û´®"ûÓÐÈκÎУÑé £¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³Ìµ÷ÓÃjar°ü £¬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117