ÿÖÜÉý¼¶Í¨¸æ-2022-11-22
Ðû²¼Ê±¼ä 2022-11-22ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Beacon.Payload_ÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ä¿µÄIPÖ÷»úÊÔͼÏòÔ´IPÖ÷»ú´«ÊäºóÃÅ¡£¡£¡£¡£¡£³£¼ûµÄBeacon°üÀ¨CobaltStrikeµÄBeacon£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¼°MetasploitµÄMeterpreterµÈ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Apache_Flink_СÓÚ1.11.2_í§ÒâÎļþ¶ÁÈ¡[CVE-2020-17519][CNNVD-202101-271]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheFlink1.11.0,1.11.1,1.11.2°æ±¾ÔÊÐí¹¥»÷Õßͨ¹ýJobManagerÀú³ÌµÄRESTAPI¶ÁÈ¡JobManagerÍâµØÎļþϵͳÉϵÄÈκÎÎļþ£¨JobManagerÀú³ÌÄÜ»á¼ûµ½µÄ£©¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_SQLiteManager_1.2.0_Ŀ¼´©Ô½[CVE-2007-1232]
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSQLiteManagerµÄĿ¼´©Ô½Îó²î»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£¡£SQLiteManager1.2.0°æ±¾ÖеÄĿ¼±éÀúÎó²îÔÊÐíÔ¶³Ì¹¥»÷Õßͨ¹ýSQLiteManager_currentThemeÖеÄ..¶ÁÈ¡í§ÒâÎļþ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_CouchDB_JSON_ÏÂÁîÖ´ÐÐ[CVE-2017-12636][CNNVD-201711-486]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉÏApacheCouchDBµÄRestfulµÄAPI½Ó¿Ú±£´æµÄÎó²î£¬£¬£¬£¬£¬£¬£¬£¬½á¹¹¶ñÒâJsonÃûÌõÄÊý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹·ÇÖÎÀíÔ±Óû§ÒÔÊý¾Ý¿âϵͳÓû§µÄÉí·Ý»á¼ûЧÀÍÆ÷ÉϵÄí§ÒâshellÏÂÁî¡£¡£¡£¡£¡£CouchDBÊÇÒ»¸öʹÓÃJSON×÷Ϊ´æ´¢ÃûÌ㬣¬£¬£¬£¬£¬£¬£¬JavaScript×÷ΪÅÌÎÊÓïÑÔ£¬£¬£¬£¬£¬£¬£¬£¬MapReduceºÍHTTP×÷ΪAPIµÄNoSQLÊý¾Ý¿â¡£¡£¡£¡£¡£CouchDB½ÓÄÉ»ùÓÚErlangµÄJSONÆÊÎöÆ÷£¬£¬£¬£¬£¬£¬£¬£¬Óë»ùÓÚJavaScriptµÄJSONÆÊÎöÆ÷²î±ð£¬£¬£¬£¬£¬£¬£¬£¬CouchDB¿ÉÒÔÔÚÊý¾Ý¿âÖÐÌá½»´øÓнÇɫ֨¸´¼üµÄ_usersÎĵµÓÃÓÚʵÏÖ»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬£¬£¬ÉõÖÁ°üÀ¨ÌåÏÖÖÎÀíÓû§µÄ_admin½ÇÉ«¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ÖÂÔ¶OA_ajax.do_δÊÚȨ»á¼û
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÕýÔÚʹÓÃÖÂÔ¶OAV8.0ÒÔϰ汾µÄδÊÚȨÎó²î»ñȡȨÏÞÀ´¾ÙÐнøÒ»²½ÎļþÉÏ´«µÄ¹¥»÷£»£»£»£»£»£»£»ÖÂÔ¶OA°ì¹«×Ô¶¯»¯Èí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÓÃÓÚOA°ì¹«×Ô¶¯»¯Èí¼þµÄ¿ª·¢ÏúÊÛ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_ÈôÒÀCMS_СÓÚ4.5.1_Îļþ¶ÁÈ¡[CNVD-2021-01931]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃÈôÒÀCMS<4.5.1°æ±¾ÖеÄí§ÒâÎļþ¶ÁÈ¡Îó²î£¬£¬£¬£¬£¬£¬£¬£¬µÇ¼ºǫ́ºó£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÁȡЧÀÍÆ÷ÉϵÄí§ÒâÎļþ¡£¡£¡£¡£¡£ÈôÒÀÖÎÀíϵͳÊÇ»ùÓÚSpringBootµÄȨÏÞÖÎÀíϵͳ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Microsoft_Exchange_Servers_ÏÂÁîÖ´ÐÐ[CVE-2022-40140][CVE-2022-41082]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ExchangeServerÊÇ΢Èí¹«Ë¾µÄÒ»Ì×µç×ÓÓʼþЧÀÍ×é¼þ,ÊǸöÐÂÎÅÓëÐ×÷ϵͳ¡£¡£¡£¡£¡£¸Ãϵͳ±£´æÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚ¾ÓÉExchangeServerÉí·ÝÑéÖ¤²¢ÇÒ¾ßÓÐPowerShell²Ù×÷ȨÏÞµÄÇéÐÎÏÂʹÓÃÕâЩÎó²î£¨×éºÏʹÓã©Ô¶³ÌÖ´ÐжñÒâ´úÂ룺CVE-2022-41040£ºMicrosoftExchangeServerЧÀÍÆ÷¶ËÇëÇóαÔì(SSRF)Îó²î£¬£¬£¬£¬£¬£¬£¬£¬CVE-2022-41082£ºMicrosoftExchangeServerÔ¶³Ì´úÂëÖ´ÐУ¨RCE£©Îó²î¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Oracle_WebLogic_·´ÐòÁл¯Èƹý[CVE-2019-2725][CNNVD-201904-1251]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º OracleWebLogicServerÊÇOracleCorporationÄ¿½ñ¿ª·¢µÄJavaEEÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£¡£¡£OracleWebLogicServer10.3.6.0.0¡¢OracleWebLogicServer12.1.3.0.0°æ±¾±£´æ·´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îÈÆ¹ýCVE-2019-2725²¹¶¡£¬£¬£¬£¬£¬£¬£¬£¬Îó²î±£´æwls-wsatºÍbea_wls9_async_response×é¼þ£¬£¬£¬£¬£¬£¬£¬£¬Î´¾ÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄ¶ñÒâHTTPÇëÇ󣬣¬£¬£¬£¬£¬£¬£¬»ñȡЧÀÍÆ÷ȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º SMTP_ÇÔÃÜľÂí_Snake_Keylogger_ÉÏ´«ÇÔÃÜÐÅÏ¢
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½SnakeKeyloggerÇÔÃÜľÂíÕýÔÚÏòÔ¶³ÌЧÀÍÆ÷ÉÏ´«ÇÔÃܵÄÖÖÖÖÐÅÏ¢¡£¡£¡£¡£¡£Snake¶ñÒâÈí¼þÊÇÒ»ÖÖÒÔ.NET±à³ÌÓïÑÔʵÏÖµÄÐÅÏ¢ÇÔÈ¡¶ñÒâÈí¼þ¡£¡£¡£¡£¡£Í¨¹ýÍøÂç´¹ÂÚÓʼþ·Ö·¢¡£¡£¡£¡£¡£SnakeÊÇÒ»ÖÖ¹¦Ð§¸»ºñµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬¶ÔÓû§µÄÒþ˽ºÍÇå¾²×é³ÉÖØ´óÍþв¡£¡£¡£¡£¡£Snake¾ßÓмͼ»÷¼üÒÔ¼°¼ôÌù°åÊý¾Ý¡¢ÆÁÄ»½ØÍ¼ºÍƾ֤͵ÇÔ¹¦Ð§¡£¡£¡£¡£¡£Snake¿ÉÒÔ´Ó50¶à¸öÓ¦ÓóÌÐòÖÐÇÔȡƾ֤£¬£¬£¬£¬£¬£¬£¬£¬ÆäÖаüÀ¨FTP¿Í»§¶Ë¡¢Óʼþ¿Í»§¶Ë¡¢Í¨Ñ¶Æ½Ì¨ºÍWebä¯ÀÀÆ÷µÈÓ¦ÓóÌÐò¡£¡£¡£¡£¡£SnakeÖ§³Öͨ¹ý¶àÖÖÐÒé¾ÙÐÐÉÏ´«Êý¾Ý£¬£¬£¬£¬£¬£¬£¬£¬ÀýÈçFTP¡¢SMTPºÍTelegramÈýÖÖ·½·¨ÉÏ´«ÇÔÈ¡µÄÐÅÏ¢¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_fileDownload.jsp_ÎļþÏÂÔØ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OAfileDownload.jsp±£´æµÄí§ÒâÎļþÏÂÔØÎó²î¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ý..\/À´Èƹý·ºÎ¢¶Ô../µÄÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖí§ÒâÎļþÏÂÔØ¡£¡£¡£¡£¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒÆ¶¯°ì¹«Õý̨¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_·ºÎ¢OA_Ecology_weaver.eui.EuiServlet_ÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃÄ¿µÄÖ÷»úÉϵķºÎ¢OA_EcologyÉϺǫ́±£´æµÄÎļþÉÏ´«Îó²îÉÏ´«í§ÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñȡȨÏÞ¡£¡£¡£¡£¡£·ºÎ¢OAÊǺ£ÄÚ¹«Ë¾Ðû²¼µÄÒ»¿îÒÆ¶¯°ì¹«Õý̨¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_Apache_Spark_´úÂëÖ´ÐÐ[CVE-2020-9480]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ApacheSparkÊÇÒ»¸ö¿ªÔ´¼¯ÈºÔËËã¿ò¼Ü¡£¡£¡£¡£¡£ÔÚApacheSpark2.4.5ÒÔ¼°¸üÔç°æ±¾ÖÐSparkµÄÈÏÖ¤»úÖÆ±£´æÈ±ÏÝ£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹²ÏíÃÜÔ¿ÈÏ֤ʧЧ¡£¡£¡£¡£¡£¹¥»÷ÕßʹÓøÃÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÔÚδÊÚȨµÄÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬£¬ÔÚÖ÷»úÉÏÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬£¬£¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ºóÃÅ_Yakes.qwqÅþÁ¬
Çå¾²ÀàÐÍ£º ÆäËûÊÂÎñ
ÊÂÎñÐÎò£º ¸ÃÊÂÎñÅú×¢£¬£¬£¬£¬£¬£¬£¬£¬Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¸ÃÊÂÎñÔ´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅYakes.qwq¡£¡£¡£¡£¡£Yakes.qwqÊÇ»ùÓÚIRCÐÒéµÄºóÃÅ£¬£¬£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬£¬£¬°Ñ×ÔÉí´úÂë²åÈ뵽ϵͳÕý³£Àú³Ì¡£¡£¡£¡£¡£ÅþÁ¬Ô¶³ÌIRCÏÂÁîºÍ¿ØÖÆÐ§ÀÍÆ÷£¬£¬£¬£¬£¬£¬£¬£¬ÎüÊÕÆäÖ¸Á£¬£¬£¬£¬£¬£¬£¬²¢Ö´ÐС£¡£¡£¡£¡£ÈçÏÂÔØ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬£¬£¬ÌᳫDDOS¹¥»÷¡£¡£¡£¡£¡£±¾ºóÃÅÔËÐк󣬣¬£¬£¬£¬£¬£¬£¬Ê×ÏȽ¨Éè¼Ù½ÓÄÉÕ¾Îļþ¼Ð£¬£¬£¬£¬£¬£¬£¬£¬²¢¿½±´×ÔÉíµ½¸ÃÎļþ¼ÐÏ£¬£¬£¬£¬£¬£¬£¬£¬µÖ´ïÒþ²ØµÄÄ¿µÄ¡£¡£¡£¡£¡£ÉèÖÃ×¢²á±í£¬£¬£¬£¬£¬£¬£¬£¬ÊµÏÖ¿ª»úÆô¶¯Òþ²ØÔÚ¼Ù½ÓÄÉÕ¾ÀïµÄºóÃųÌÐò¡£¡£¡£¡£¡£ÎüÊÕ²¢Ö´ÐÐIRCЧÀÍÆ÷µÄÖ¸Áî¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ľÂíºóÃÅ_webshell_Altman_PHPÅþÁ¬
Çå¾²ÀàÐÍ£º ľÂíºóÃÅ
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýWebshellÖÎÀí¹¤¾ßAltman»á¼ûÄ¿µÄÖ÷»úÉϵÄÒ»¾ä»°Webshell£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÖ´ÐдúÂë¡¢ÉÏ´«ÏÂÔØÎļþµÈȨÏÞ¡£¡£¡£¡£¡£Altman»ùÓÚ.Net4.0¿ª·¢£¬£¬£¬£¬£¬£¬£¬£¬Õû¸ö³ÌÐò½ÓÄÉmef²å¼þ¼Ü¹¹¡£¡£¡£¡£¡£ÏÖÔÚÍê³ÉµÄ¹¦Ð§ÓУºShellÖÎÀí¡¢ÏÂÁîÖ´ÐС¢ÎļþÖÎÀí¡¢Êý¾Ý¿âÖÎÀí¡¢±àÂëÆ÷µÈ£¬£¬£¬£¬£¬£¬£¬£¬¾ç±¾ÀàÐÍÖ§³Öasp¡¢aspx¡¢php¡¢jsp¡¢python¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_Snews_CMS_ÎļþÉÏ´«¹¥»÷
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSnewsCMSÖеÄÎļþÉÏ´«Îó²î£¬£¬£¬£¬£¬£¬£¬£¬ÉÏ´«¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£¡£¡£¡£¡£sNewsÊÇÒ»ÍêÈ«µØ×ÔÓɵġ¢Çкϱê×¼µÄ¡¢Ê¹ÓÃPHPºÍMySQLÇý¶¯µÄÄÚÈÝÖÎÀíϵͳ(CMS)¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Îļþ²Ù×÷¹¥»÷_PHP_chrº¯Êý_webshellÎļþÉÏ´«
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃchrº¯Êý½á¹¹¶ñÒâÎļþÈÆ¹ýÒªº¦´Ê¼ì²â£¬£¬£¬£¬£¬£¬£¬£¬ÉÏ´«PHP¶ñÒâÎļþ£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶ø»ñµÃÄ¿µÄIPÖ÷»úµÄÖ´ÐдúÂë¡¢ÎļþÉÏ´«¡¢Êý¾Ý¿â²Ù×÷µÈȨÏÞ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_Zabbix_Server_trapper_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´ipÕýÔÚʹÓÃZabbixµÄÎó²î¾ÙÐжñÒâÏÂÁîÖ´ÐС£¡£¡£¡£¡£ZabbixÊÇÓÉAlexeiVladishev¿ª·¢µÄÒ»ÖÖÍøÂç¼àÊÓ¡¢ÖÎÀíϵͳ£¬£¬£¬£¬£¬£¬£¬£¬»ùÓÚServer-Client¼Ü¹¹¡£¡£¡£¡£¡£ÔÚCVE-2017-2824ÖУ¬£¬£¬£¬£¬£¬£¬£¬ÆäServer¶Ëtrappercommand¹¦Ð§±£´æÒ»´¦´úÂëÖ´ÐÐÎó²î£¬£¬£¬£¬£¬£¬£¬£¬¶øÐÞ¸´²¹¶¡²¢²»ÍêÉÆ£¬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¿ÉÒÔʹÓÃIPv6¾ÙÐÐÈÆ¹ý£¬£¬£¬£¬£¬£¬£¬£¬×¢Èëí§ÒâÏÂÁî¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Alibaba_Canal-config_ÔÆÃÜÔ¿_ÐÅϢй¶
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º canalÊǰ¢Àï°Í°ÍÆìϵÄÒ»¿î¿ªÔ´ÏîÄ¿,ÒòȨÏÞÎÊÌ⣬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýÌØ¶¨µÄµØµã»á¼û»ñȡһЩ½ÏΪÃô¸ÐµÄÊý¾Ý¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_¿ÉÒÉ·´µ¯shellÏÂÁî×¢Èë_¹¥»÷ʧ°Ü
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄÖ÷»ú¾ÙÐÐBASH_·´µ¯shellÏÂÁî×¢Èë¹¥»÷¡£¡£¡£¡£¡£·´µ¯ÅþÁ¬£¬£¬£¬£¬£¬£¬£¬£¬ÊÇÖ¸¹¥»÷ÕßÖ¸¶¨Ð§ÀͶˣ¬£¬£¬£¬£¬£¬£¬£¬Êܺ¦ÕßÖ÷»ú×Ô¶¯ÅþÁ¬¹¥»÷ÕßµÄЧÀͶ˳ÌÐò¡£¡£¡£¡£¡£·´µ¯shellͨ³£ÓÃÓÚ±»¿Ø¶ËÒò·À»ðǽÊÜÏÞ¡¢È¨ÏÞȱ·¦¡¢¶Ë¿Ú±»Õ¼ÓõÈÇéÐΡ£¡£¡£¡£¡£¹¥»÷Õß¹¥»÷Àֳɺó¿ÉÒÔÔ¶³ÌÖ´ÐÐϵͳÏÂÁî¡£¡£¡£¡£¡£µ±Ö´ÐÐbash·´µ¯shellÏÂÁîÓÐÎóʱ£¬£¬£¬£¬£¬£¬£¬£¬»á·µ»Øbash:nojobcontrolinthisshell
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º TCP_ÌáȨ¹¥»÷_ASP.NET_ObjectDataProvider-YamlDotNetʹÓÃÁ´_ysoserial¹¤¾ßʹÓÃ_ÏÂÁîÖ´ÐÐ
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ysoserial.netÊÇÔÚ³£¼û.NET¿âÖз¢Ã÷µÄÊÊÓóÌÐòºÍÃæÏòÊôÐԵıà³Ì¡°Ð¡¹¤¾ßÁ´¡±µÄÜöÝÍ£¬£¬£¬£¬£¬£¬£¬£¬¿ÉÒÔÔÚÊʵ±µÄÌõ¼þÏÂʹÓÃ.NETÓ¦ÓóÌÐòÖ´Ðв»Çå¾²µÄ¹¤¾ß·´ÐòÁл¯¡£¡£¡£¡£¡£Ö÷Çý¶¯³ÌÐò½ÓÊÜÓû§Ö¸¶¨µÄÏÂÁî²¢½«Æä°ü×°ÔÚÓû§Ö¸¶¨µÄС¹¤¾ßÁ´ÖУ¬£¬£¬£¬£¬£¬£¬£¬È»ºó½«ÕâЩ¹¤¾ßÐòÁл¯µ½±ê×¼Êä³ö¡£¡£¡£¡£¡£µ±Àà·¾¶ÉϾßÓÐËùÐèС¹¤¾ßµÄÓ¦ÓóÌÐò²»Çå¾²µØ·´ÐòÁл¯´ËÊý¾Ýʱ£¬£¬£¬£¬£¬£¬£¬£¬½«×Ô¶¯Å²ÓÃÁ´²¢µ¼ÖÂÏÂÁîÔÚÓ¦ÓóÌÐòÖ÷»úÉÏÖ´ÐС£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_yii·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2020-15148][CNNVD-202009-926]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏyiiµÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£¡£YiiÊÇÒ»¸ö¸ßÐÔÄܵÄPHP5µÄwebÓ¦ÓóÌÐò¿ª·¢¿ò¼Ü¡£¡£¡£¡£¡£Í¨¹ýÒ»¸ö¼òÆÓµÄÏÂÁîÐй¤¾ßyiic¿ÉÒÔ¿ìËÙ½¨ÉèÒ»¸öwebÓ¦ÓóÌÐòµÄ´úÂë¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬¿ª·¢Õß¿ÉÒÔÔÚÌìÉúµÄ´úÂë¿ò¼Ü»ù´¡ÉÏÌí¼ÓÓªÒµÂß¼£¬£¬£¬£¬£¬£¬£¬£¬ÒÔ¿ìËÙÍê³ÉÓ¦ÓóÌÐòµÄ¿ª·¢¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÌáȨ¹¥»÷_ZendFramework_3.0_·´ÐòÁл¯_´úÂëÖ´ÐÐ[CVE-2021-3007][CNNVD-202101-025]
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPʹÓÃÄ¿µÄipÉÏZendFramework3.0µÄ·´ÐòÁл¯Îó²î½á¹¹ÐòÁл¯Îı¾´Ó¶øÖ´ÐÐÔ¶³ÌÏÂÁîÖ´ÐеÄÐÐΪ¡£¡£¡£¡£¡£ZENDZendFramework£¨ZF£©ÊÇÃÀ¹úZend£¨ZEND£©¹«Ë¾µÄÒ»Ì׿ªÔ´µÄPHP¿ª·¢¿ò¼Ü£¬£¬£¬£¬£¬£¬£¬£¬ËüÖ÷ÒªÓÃÓÚ¿ª·¢Web³ÌÐòºÍЧÀÍ¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_ÐÅϢй¶_Swagger-api¹¤¾ß_Ãô¸ÐÎļþ»á¼û
Çå¾²ÀàÐÍ£º CGI¹¥»÷
ÊÂÎñÐÎò£º SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSONÓïÑÔµÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£¡£¡£¡£¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬£¬£¬£¬£¬£¬£¬£¬Ïà¹ØÎļþ¼Ð±»»á¼ûÓÐÐÅϢй¶Σº¦¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬£¬£¬£¬£¬£¬£¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122
ÊÂÎñÃû³Æ£º HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î
Çå¾²ÀàÐÍ£º Çå¾²Îó²î
ÊÂÎñÐÎò£º ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬£¬£¬£¬£¬£¬£¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬£¬£¬£¬£¬£¬£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬£¬£¬£¬£¬£¬£¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬£¬£¬£¬£¬£¬£¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬£¬£¬£¬£¬£¬£¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£
¸üÐÂʱ¼ä£º 20221122


¾©¹«Íø°²±¸11010802024551ºÅ