ÿÖÜÉý¼¶Í¨¸æ-2023-02-14

Ðû²¼Ê±¼ä 2023-02-14
ÐÂÔöʼþ

 

ʼþÃû³Æ£º

TCP_©¶´ÀûÓÃ_·´ÐòÁл¯_Weblogic_T3ЭÒé[CVE-2020-14756]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨ £¬ÓÃÓÚÔÚµ±µØºÍÔƶ˿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÓ¦Ó÷¨Ê½ £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555©¶´¿ÉÒÔÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Äþ¾²µÄextractÒªÁì £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç·ÃÎʲ¢ÆÆ»µÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷ £¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½Ó¹Ü»òÃô¸ÐÐÅϢй¶¡£Ó°Ï췶Χ£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230214

 

ʼþÃû³Æ£º

HTTP_ÃüÁî¿ØÖÆ_C2ͨÐÅ_OrcaC2_ÉÏÏß×¢²á_Á¬½ÓC2·þÎñÆ÷

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨÐŵĶ๦ЧC&C¿ò¼Ü £¬Ê¹ÓÃGolangʵÏÖ¡£ËüÓÉÈý²¿ÃÅ×é³É£ºOrca_Server(·þÎñ¶Ë)¡¢Orca_Master(¿ØÖƶË)¡¢(±»¿ØÖƶËOrca_Puppet)¡£OrcaC2½ÓÄÉWebsocketͨÐÅ £¬json¸ñʽ´«ÊäÊý¾Ý £¬ÏûÏ¢ÓëÊý¾ÝÊÕÂÞʹÓÃAES-CBC¼ÓÃÜ+Base64±àÂë £¬¾ßÓÐÔ¶³ÌÃüÁî¿ØÖÆ¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢ÆÁÄ»½Øͼ£¨±»¿ØÖƶËΪWindowsϵͳ£©¡¢Ô¶³ÌÆÁÄ»¿ØÖÆ¡¢¼üÅ̼ǼµÈµÈ¡£¸ÃÌõʼþ±íÃ÷Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí £¬ÕýÔÚÏò·þÎñ¶Ë·¢ËÍÉÏÏß×¢²áÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230214

 

ʼþÃû³Æ£º

TCP_ÃüÁî¿ØÖÆ_C2ͨÐÅ_OrcaC2_WebSocketЭÒé_ÐÄÌøͨÐÅ

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨÐŵĶ๦ЧC&C¿ò¼Ü £¬Ê¹ÓÃGolangʵÏÖ¡£ËüÓÉÈý²¿ÃÅ×é³É£ºOrca_Server(·þÎñ¶Ë)¡¢Orca_Master(¿ØÖƶË)¡¢(±»¿ØÖƶËOrca_Puppet)¡£OrcaC2½ÓÄÉWebsocketͨÐÅ £¬json¸ñʽ´«ÊäÊý¾Ý £¬ÏûÏ¢ÓëÊý¾ÝÊÕÂÞʹÓÃAES-CBC¼ÓÃÜ+Base64±àÂë £¬¾ßÓÐÔ¶³ÌÃüÁî¿ØÖÆ¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢ÆÁÄ»½Øͼ£¨±»¿ØÖƶËΪWindowsϵͳ£©¡¢Ô¶³ÌÆÁÄ»¿ØÖÆ¡¢¼üÅ̼ǼµÈµÈ¡£¸ÃÌõʼþ±íÃ÷Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí £¬Orca_Server·þÎñ¶ËÕýÔÚÏò±»¿ØÖƶ˷¢ËÍÐÄÌøͨÐÅÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20230214

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Centos_Web_Panel_7_ÃüÁîÖ´ÐÐ[CVE-2022-44877]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

CWP £¬Ç°ÉíΪCentOSWebPanel £¬ÊÇÒ»¸öÃâ·ÑʹÓõÄLinux¿ØÖÆÃæ°å¡£ÔÚCentOSWebPanel70.9.8.1147°æ±¾Ö®Ç°µÄϵͳÖÐ £¬/login/index.php×é¼þÖдæÔÚ©¶´ £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý¾«ÐÄÉè¼ÆµÄHTTPÇëÇóÖ´ÐÐÈÎÒâϵͳÃüÁî¡£

¸üÐÂʱ¼ä£º

20230214

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

TCP_©¶´ÀûÓÃ_·´ÐòÁл¯_Oracle_WebLogic_T3ЭÒé[CVE-2020-2555]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÀûÓÃweblogic·´ÐòÁл¯Â©¶´½øÐй¥»÷µÄÐÐΪ £¬OracleCoherenceΪOracleÈÚºÏÖмä¼þÖеIJúÎï £¬ÔÚWebLogic12c¼°ÒÔÉÏ°æ±¾ÖÐĬÈϼ¯³Éµ½WebLogic°²×°°üÖÐ £¬¹¥»÷Õßͨ¹ýt3ЭÒé·¢ËͽṹµÄÐòÁл¯Êý¾Ý £¬ÄܹýÔì³ÉÃüÁîÖ´ÐеÄЧ¹û

¸üÐÂʱ¼ä£º

20230214

 

ʼþÃû³Æ£º

TCP_©¶´ÀûÓÃ_·´ÐòÁл¯_Oracle_Weblogic_T3ЭÒé[CVE-2020-2883]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨ £¬ÓÃÓÚÔÚµ±µØºÍÔƶ˿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÓ¦Ó÷¨Ê½ £¬ÀýÈçJava¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£CVE-2020-2555©¶´¿ÉÒÔͨ¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»Äþ¾²µÄextractÒªÁì £¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ЭÒéÍøÂç·ÃÎʲ¢ÆÆ»µÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷ £¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»½Ó¹Ü»òÃô¸ÐÐÅϢй¶¡£Ó°Ï췶Χ£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üÐÂʱ¼ä£º

20230214