ÿÖÜÉý¼¶Í¨¸æ-2022-03-08

Ðû²¼Ê±¼ä 2022-03-08

ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_ͨÓÃ_ʵÑéÀûÓÃÈÎÒâÎļþ¶Áȡ©¶´

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

ÓÉÓÚÒ»Ð©ÍøÕ¾µÄÒµÎñÐèÒª,ÍùÍùÐèÒªÌṩÎļþ¶ÁÈ¡»òÏÂÔØµÄÒ»¸öÄ£¿é,µ«Èç¹ûûÓжԶÁÈ¡»òÏÂÔØ×öÒ»¸ö°×Ãûµ¥»òÕßȨÏÞÏÞÖÆ£¬¿ÉÄܵ¼Ö¶ñÒâ¹¥»÷Õß¶ÁÈ¡ÏÂÔØÒ»Ð©Ãô¸ÐÐÅÏ¢(etc/passwdµÈ),¶Ô·þÎñÆ÷×öÏÂÒ»²½µÄ½ø¹¥ÓëÍþв¡£´Ëʼþ¿ÉÒÔͨÓÃÐԵؼì²âʵÑéÀûÓÃÈÎÒâÎļþ¶Áȡ©¶´µÄÐÐΪ¡£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_LinuxÃüÁîÖ´ÐлØÏÔ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú·ºÆðÁËijЩLinuxÃüÁÈçw¡¢top¡¢uptimeµÈ£©Ö´ÐеĻØÏÔÁ÷Á¿£¬°üÂÞµ±Ç°ÏµÍ³Ê±¿Ì¡¢ÔËÐÐʱ¼ä¡¢Óû§×ÜÁ¬½ÓÊý¡¢Æ½¾ù¸ºÔصÈÐÅÏ¢

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_BEESCMS_Ä£°åÐÞ¸Ägetshell©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃBEESCMSµÄºǫ́¹ÜÀíÄ£°åÄ£¿éÀ´ÉÏ´«getshell¡£BEESCMSÆóÒµÍøÕ¾¹ÜÀíϵͳÊÇÒ»¿îPHP+MYSQLµÄ¶àÓïÑÔϵͳ£¬ÄÚÈÝÄ£¿éÒ×À©Õ¹£¬Ä£°å·ç¸ñ¶àÑù»¯£¬Ä£°åÖÆ×÷¼òµ¥¹¦Ð§Ç¿´ó£¬×¨ÒµSEOÓÅ»¯£¬ºǫ́²Ù×÷·½±ã£¬ÍêÈ«¿ÉÒÔÂú×ãÆóÒµÍøÕ¾¡¢ÍâÃ³ÍøÕ¾¡¢ÊÂÒµµ¥Ôª¡¢½ÌÓý»ú¹¹¡¢¸öÈËÍøÕ¾Ê¹Óá£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÈôÒÀCMS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÈôÒÀºǫ́¹ÜÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄ¸ñʽ£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́¼Æ»®ÈÎÎñ´¦£¬¶ÔÓÚ´«ÈëµÄ"µ÷ÓÃÄ¿±ê×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³Ìµ÷ÓÃjar°ü£¬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ͨ´ïOA_SQL×¢Èë©¶´

Äþ¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÕýÔÚʵÑéʹÓÃSQL×¢Èë©¶´¹¥»÷Ä¿µÄIPÉ豸¡£SQL×¢ÈëÊDZÈÁ¦³£¼ûµÄÍøÂç¹¥»÷·½Ê½Ö®Ò»£¬ÆäÔ­ÒòÊÇÓÉÓÚδ¶ÔÊäÈëµÄ²ÎÊýÄÚÈÝ×÷¹ýÂËУÑ飬µ¼Ö¹¥»÷Õ߯´½Ó¶ñÒâSQLÓï¾ä£¬Í¨¹ýSQLÓï¾ä£¬ÊµÏÖÎÞÕ˺ŵǼ£¬ÉõÖÁ¸Ä¶¯Êý¾Ý¿â¡¢Äõ½Ä¿µÄÉ豸ȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_DLink_DIR8xxϵÁзÓÉÆ÷_δÊÚȨÃüÁî×¢Èë[CVE-2021-45382][CNNVD-202202-1411]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýCVE-2021-45382©¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£DIR-810L¡¢DIR-820L/W¡¢DIR-826L¡¢DIR-830L¡¢DIR-836LϵÁÐÊÇÖйúÓÑѶ£¨D-Link£©¹«Ë¾µÄ·ÓÉÆ÷£¬ÒѾ­´¦ÓÚ·þÎñÖÕÖ¹Çø(EndofServiceLife)¡£ËüÃǹ̼þÀïµÄDDNSº¯Êý´æÔÚÃüÁî×¢Èë©¶´£¬¹¥»÷Õ߿ɽè´ËÔ¶³ÌÖ´ÐжñÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_PHP_Nette¿ò¼ÜCallback_δÊÚȨԶ³ÌÃüÁî×¢Èë[CVE-2020-15227][CNNVD-202010-011]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

NetteÊÇÒ»¿îÁ÷ÐеÄPHPWeb¿ìËÙ¿ª·¢¿ò¼Ü£¬»ùÓÚ×é¼þµÄʼþÇý¶¯¡£ÆäÉè¼ÆÀíÄîΪ£º¶Ô¿ª·¢Õß¾¡¿ÉÄܵÄÓѺò¢¿ÉÓã¬Nette¿ò¼Ü¿ÉÒÔ×ÊÖúÄúÇáËɽ¨Á¢ºÃÍøÕ¾¡£Nette´æÔÚÃüÁî×¢Èë©¶´£¬¸Ã©¶´Ô´ÓÚδÕýÈ·¹ýÂËurlÖеÄÌØÊâ²ÎÊý¡£¹¥»÷Õß¿ÉÀûÓøÃ©¶´Î´ÊÚȨԶ³ÌÖ´ÐдúÂë¡£

¸üÐÂʱ¼ä£º

20220308

 

ʼþÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_ifconfig_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

Á÷Á¿Öмì²âµ½Ö´ÐÐÁËÃô¸ÐϵͳÃüÁîµÄ»ØÏÔÐÅÏ¢£¬ËµÃ÷Ö÷»úÓпÉÄÜÒѾ­±»ÈëÇÖ£¬ÇÒ¹¥»÷Õß¾ßÓÐÖ´ÐÐϵͳÃüÁîµÄȨÏÞ¡£

¸üÐÂʱ¼ä£º

20220308

 

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Â©¶´[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú½øÐÐĿ¼´©Ô½Â©¶´¹¥»÷ʵÑéµÄÐÐΪ¡£Ä¿Â¼´©Ô½Â©¶´ÄÜʹ¹¥»÷ÕßÈÆ¹ýWeb·þÎñÆ÷µÄ·ÃÎÊÏÞÖÆ£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ÈÎÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬ÆäËû©¶´£¨ÉõÖÁһЩ0day©¶´£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´Ëʼþ±¨¾¯¡£ÓÉÓÚÕý³£ÒµÎñÖÐÒ»°ã²»»á·¢Éú´ËʼþÌØÕ÷µÄÁ÷Á¿£¬ËùÒÔÐèÒªÖØµã¹Ø×¢¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß·ÃÎÊÃô¸ÐÎļþ¡£

¸üÐÂʱ¼ä£º

20220308