2020-06-23
Ðû²¼Ê±¼ä 2020-06-24ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_Çå¾²Îó²î_Exchange_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-0688] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÊÔͼͨ¹ýExchangeÓʼþЧÀÍÆ÷Ô¶³ÌÖ´ÐÐÏÂÁîÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£Îó²îÔµ¹ÊÔÓÉÊÇExchangeЧÀÍÆ÷ÔÚ×°ÖÃʱûÓÐ׼ȷ½¨ÉèΨһµÄ¼ÓÃÜÃÜÔ¿¡£¡£¡£µ¼Ö¾ÓÉÉí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ýExchangeĬÈÏ¿ªÆôµÄWebÒ³ÃæµÇ¼£¬£¬£¬£¬£¬£¬£¬·¢ËÍÈ«ÐĽṹµÄÇëÇ󣬣¬£¬£¬£¬£¬£¬ÓÕÆÄ¿µÄЧÀÍÆ÷·´ÐòÁл¯¶ñÒ⽨ÉèµÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬À´µÖ´ïÔÚÄ¿µÄЧÀÍÆ÷ÉÏÒÔ SYSTEM Éí·ÝÖ´ÐÐí§Òâ.net´úÂëµÄÄ¿µÄ¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓúÜÊÇÆÕ±éµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£¡£¡£Öйú²Ëµ¶ÓÃ;ʮ·ÖÆÕ±é,Ö§³Ö¶àÖÖÓïÑÔ,СÇÉÊÊÓ㬣¬£¬£¬£¬£¬£¬¾ßÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ¼ä¿ÉÒÔÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬£¬£¬£¬£¬£¬£¬Êý¾Ý¿âÖÎÀí£¬£¬£¬£¬£¬£¬£¬ÐéÄâÖն˵ȹ¦Ð§¡£¡£¡£¹ØÓÚÕâÀàÖÎÀí¹¤¾ß£¬£¬£¬£¬£¬£¬£¬ÈôÊÇûÓдó×ÚµÄÐÞ¸ÄЧÀͶ˾籾´úÂ룬£¬£¬£¬£¬£¬£¬Æä·µ»ØÁ÷Á¿¶¼»áÓÐһЩ³£¼ûµÄÌØÕ÷£¬£¬£¬£¬£¬£¬£¬±¾Ìõ¹æÔò½«³£¼ûµÄÅäºÏÌØÕ÷ÌáÈ¡³öÀ´¾ÙÐзÀÓùÐÔ±¨¾¯¡£¡£¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØÕ÷£¬£¬£¬£¬£¬£¬£¬¿ÉÄܱ£´æÎ󱨣¬£¬£¬£¬£¬£¬£¬Çë²Î¿¼ÌØÕ÷ÐÔ×ÓÅжÏ×ֶξÙÐÐÅжϡ£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
DNS_ľÂí_¿ÉÒÉ¿ó³ØÓòÃûÆÊÎöÇëÇó |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÍÚ¿óľÂí¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
HTTP_svnÃô¸ÐÎļþ»á¼û |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐHTTP_svnÃô¸ÐÎļþ»á¼û¡£¡£¡£ SvnÊdz£¼ûµÄ°æ±¾¿ØÖƹ¤¾ß£¬£¬£¬£¬£¬£¬£¬ÔÚ¹ýʧÉèÖõÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬svnÃô¸ÐÎļþ̻¶ÔÚWEB·¾¶ÖУ¬£¬£¬£¬£¬£¬£¬Í¨¹ý»á¼ûsvnÎļþ£¬£¬£¬£¬£¬£¬£¬ºÚ¿Í¿ÉÒÔ»ñÈ¡ÍøÕ¾Ô´ÂëµÈÐÅÏ¢¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
HTTP_Nexus_Repository_Manager_3Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-7238] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýNexus Repository Manager 3´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£ Nexus Repository Manager 3ÓÉÓÚ»á¼û¿ØÖÆÈ±·¦£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃȱÏÝ½á¹¹ÌØ¶¨µÄÇëÇóÔÚЧÀÍÆ÷ÉÏδÊÚȨִÐÐJava´úÂ룬£¬£¬£¬£¬£¬£¬´Ó¶øµÖ´ïÔ¶³Ì´úÂëÖ´ÐеÄÄ¿µÄ¡£¡£¡£ Îó²î±£´æµÄ°æ±¾£º Nexus Repository Manager OSS/Pro 3.x - 3.14.0 |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
HTTP_JBOSS_·´ÐòÁл¯_ÏÂÁîÖ´ÐÐÎó²î[CVE-2017-12149] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ¶Ô¿ÉÄܱ£´æÎó²î(CVE-2017-12149)µÄÒ³ÃæÊµÑé¹¥»÷ Ó°ÏìJBossAS 5.x/6.x °æ±¾¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
TCP_RDPÔ¶³Ì×ÀÃæµÇ¼¿ÚÁîÇî¾Ù |
|
Çå¾²ÀàÐÍ£º |
Çî¾Ù̽²â |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»úÔ¶³Ì×ÀÃæµÇ¼¿ÚÁî²Â½âµÄÐÐΪ¡£¡£¡£ Ô¶³Ì×ÀÃæÅþÁ¬×é¼þÊÇ´ÓWindows 2000 Server×îÏÈÓÉ΢Èí¹«Ë¾ÌṩµÄ£¬£¬£¬£¬£¬£¬£¬ÔÚWINDOWS 2000 SERVERÖÐËû²»ÊÇĬÈÏ×°Öõġ£¡£¡£¸Ã×é¼þÒ»¾ÍƳöÊܵ½ÁËÐí¶àÓû§µÄÓµ»¤ºÍϲ»¶£¬£¬£¬£¬£¬£¬£¬ÒÔÊÇÔÚWINDOWS WINDOWS2003¿ªÆôÒªÁìºÍXPÀàËÆ£¬£¬£¬£¬£¬£¬£¬Í¬Ñù¶Ô²Ù×÷°ì·¨¾ÙÐÐÁ˼ò»¯¡£¡£¡£ÒªÁìÈçÏ£º µÚÒ»²½£ºÔÚ×ÀÃæ¡°ÎҵĵçÄÔ¡±ÉϵãÊó±êÓÒ¼ü£¬£¬£¬£¬£¬£¬£¬Ñ¡Ôñ¡°ÊôÐÔ¡±¡£¡£¡£XPºÍ2003ÖÐ΢Èí¹«Ë¾½«¸Ã×é¼þµÄÆôÓÃÒªÁì¾ÙÐÐÁËˢУ¬£¬£¬£¬£¬£¬£¬ÎÒÃÇͨ¹ý¼òÆÓµÄ¹´Ñ¡¾Í¿ÉÒÔÍê³ÉÔÚXPºÍ2003ÏÂÔ¶³Ì×ÀÃæÅþÁ¬¹¦Ð§µÄ¿ªÆô¡£¡£¡£ÈôÊÇÄ¿µÄÖ÷»ú¿ªÆôÁËÔ¶³ÌÖÕ¶ËЧÀÍ£¬£¬£¬£¬£¬£¬£¬Ä¬È϶˿ÚÊÇ3389£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õßͨ¹ý¶à´ÎʵÑéÓû§ÃûºÍÃÜÂëµÄ·½·¨À´²Â½âÓû§¿ÚÁ£¬£¬£¬£¬£¬£¬ÈôÊDZ»ÁÏÖй¥»÷Õ߾ͿÉÒÔ»ñÊÊÄ¿½ñÓû§µÄËùÓÐȨÏÞ£¬£¬£¬£¬£¬£¬£¬½ø¶øÓÐÓпÉÄÜ»ñµÃÖÎÀíԱȨÏÞ¡£¡£¡£ µÚ¶þ²½£ºÔÚµ¯³öµÄϵͳÊôÐÔ´°¿ÚÖÐÑ¡Ôñ¡°Ô¶³Ì¡±±êÇ©¡£¡£¡£ µÚÈý²½£ºÔÚÔ¶³Ì±êÇ©ÖÐÕÒµ½¡°Ô¶³Ì×ÀÃæ¡±£¬£¬£¬£¬£¬£¬£¬ÔÚ¡°ÔÊÐíÓû§ÅþÁ¬µ½Õą̂ÅÌËã»ú¡±Ç°¶Ô¹´È¥µôºóÈ·¶¨¼´¿ÉÍê³ÉÔ¶³Ì×ÀÃæÅþÁ¬¹¦Ð§µÄ¹Ø±Õ¡£¡£¡£ ¿ÚÁîÇî¾Ù̽²âÀàÊÂÎñ½ç˵Ϊ£ºÔÚÔ´IPµØµãÓëÄ¿µÄIPµØµãÏàͬµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬Í³¼Æµ¥Î»Ê±¼äÄڵǼʧ°ÜµÄ´ÎÊý£¬£¬£¬£¬£¬£¬£¬Ä¬ÒÔΪһ·ÖÖÓÄڵǼʧ°ÜµÄ´ÎÊýÁè¼Ý20´Î£¬£¬£¬£¬£¬£¬£¬¾Í»á´¥·¢¿ÚÁîÇî¾ÙÊÂÎñ£¬£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµÄĬÈÏÐж¯ÊÇ×è¶ÏÔ´µØµã¡£¡£¡£ÐèÌØÊâ˵Ã÷µÄÊÇ£¬£¬£¬£¬£¬£¬£¬ÈôIPS»òWAF×°±¸´®Ðа²ÅÅÔÚÆôÓÃNAT(Network Address Translation£¬£¬£¬£¬£¬£¬£¬ÍøÂçµØµãת»»)µÄÍøÂçÇéÐÎÖУ¬£¬£¬£¬£¬£¬£¬¶à¸öÕæÊµµÄÔ´IP¿ÉÄܱ»×ª»»³ÉÒ»¸öÔ´IP£¬£¬£¬£¬£¬£¬£¬¼«¶ËÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬¶à¸öÓû§µÄÕý³£Éϰ¶Ê§°ÜʵÑéÒ²¿ÉÄܻᴥ·¢¿ÚÁîÇî¾Ù̽²âÊÂÎñ£¬£¬£¬£¬£¬£¬£¬´Ëʱ¿ÉÒÔ˼Á¿½«¸ÃÊÂÎñµÄĬÈÏÏìÓ¦Ðж¯ÐÞ¸ÄΪͨ¹ý£¬£¬£¬£¬£¬£¬£¬ÒÔÃâÓ°ÏìÕý³£ÓªÒµ¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
HTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9546/9547/9548] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |
|
ÊÂÎñÃû³Æ£º |
TCP_MS_RDPÔ¶³Ì×ÀÃæ_½¨ÉèµÍÇå¾²ÐÔÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Éó¼Æ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¿µÄIPÖ÷»úÒѾÔÞ³ÉÒÔµÍÓÚCreedSSPµÄÇå¾²ÐÒéÓëÔ´IPÖ÷»úµÄÔ¶³Ì×ÀÃæ¾ÙÐÐÅþÁ¬¡£¡£¡£ÓÉÓڵͰ汾µÄÔ¶³Ì×ÀÃæÇå¾²ÐԽϵͣ¬£¬£¬£¬£¬£¬£¬ÅþÁ¬¿ÉÄܱ£´æÒ»¶¨Çå¾²Òþ»¼¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200623 |


¾©¹«Íø°²±¸11010802024551ºÅ