ÿÖÜÉý¼¶Í¨¸æ-2021-05-25

Ðû²¼Ê±¼ä 2021-05-26

ÐÂÔöʼþ


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÔ¶³Ì´úÂëÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæϵͳ£¨VENGD£©£¬ÊǹúÄڵĻùÓÚNGD(NextGenerationDesktop)¼Ü¹¹µÄ×ÀÃæÐéÄ⻯²úÎËüÈÚºÏÁËVDI¡¢VOI¡¢IDVÈý´ó¼Ü¹¹ÓÅÊÆ£¬ÊµÏÖÁËÇ°ºó¶Ë»ìºÏ¼ÆË㣬ÔÚµ÷ÖηþÎñÆ÷ºó¶Ë¼ÆËã×ÊÔ´µÄͬʱ¸üÄܳäʵÀûÓÃÇ°¶Ë×ÊÔ´¡£¸Ãϵͳ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õ߿ɽṹÌض¨ÇëÇó°ügetshell¡£

¸üÐÂʱ¼ä£º

20210525


ʼþÃû³Æ£º

HTTP_ÖÂÔ¶OA_webmail.doÈÎÒâÎļþÏÂÔØ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÖÂÔ¶OAÊDZ±¾©ÖÂÔ¶»¥ÁªÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Ñз¢Ò»¿î°ì¹«ÏµÍ³£¬ÖÂÔ¶OA´æÔÚÈÎÒâÎļþÏÂÔØ©¶´£¬¹¥»÷Õß¿ÉÀûÓø鶴ÏÂÔØÈÎÒâÎļþ£¬»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üÐÂʱ¼ä£º

20210525


2.png


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·«Èív8.0ÈÎÒâÎļþ¶Áȡ©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚ¶ÔÄ¿µÄipÖеķ«Èív8.0½øÐÐÈÎÒâÎļþ¶ÁÈ¡ÐÐΪ£¬ÆäÖпÉÒÔͨ¹ý¶ÁÈ¡privilege.xmlÇÔÈ¡ÃÜÂë½øÐнøÒ»²½µÄ¹¥»÷£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢Áé»î¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òµ¥µÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÅÓ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾ö²ß·ÖÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


3.png


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·«Èí±¨±í²å¼þ8.0_Ŀ¼±éÀú©¶´

Äþ¾²ÀàÐÍ£º

ľÂíºóÃÅ

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓ÷«Èí±¨±í²å¼þ8.0ÖеÄĿ¼±éÀú©¶´½øÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢Áé»î¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òµ¥µÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÅÓ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾ö²ß·ÖÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


4.png


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_·«Èí±¨±í²å¼þ9.0_Getshell©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÒÔ»ñÈ¡·«Èíºǫ́ȨÏÞ£¬Í¨¹ýÉÏ´«Ñ¹ËõÎļþ½øÐÐgetshell²Ù×÷£¬FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢Áé»î¡±µÄÌصãºÍÎÞÂëÀíÄ½öÐè¼òµ¥µÄÍÏק²Ù×÷±ã¿ÉÒÔÉè¼ÆÅÓ´óµÄÖйúʽ±¨±í£¬´î½¨Êý¾Ý¾ö²ß·ÖÎöϵͳ¡£

¸üÐÂʱ¼ä£º

20210525


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÓÃÓÑNC6.5_ÈÎÒâÎļþÉÏ´«Â©¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓÑNC6.5µÄ©¶´½øÐÐÈÎÒâÎļþÉÏ´«£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö·½°¸¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄ¹ÜÀíÒµÎñÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍŹÜÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÓÃÓÑNC_CRM_ÈÎÒâÎļþ¶ÁÈ¡

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓÑNCµÄ©¶´½øÐÐÈÎÒâÎļþ¶ÁÈ¡²Ù×÷£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö·½°¸¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄ¹ÜÀíÒµÎñÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍŹÜÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÓÃÓÑNC_Ŀ¼±éÀú©¶´

Äþ¾²ÀàÐÍ£º

CGI¹¥»÷

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÕýÔÚÀûÓÃÓÃÓѵÄĿ¼±éÀú©¶´½øÐÐÐÅÏ¢ÇÔÈ¡£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö·½°¸¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄ¹ÜÀíÒµÎñÀíÄî¶øÉè¼Æ£¬ÊÇÖйú´óÆóÒµ¼¯ÍŹÜÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡¡£

¸üÐÂʱ¼ä£º

20210525


ÐÞ¸Äʼþ


1.png


ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_Weblogic_ServerÔ¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2021-2109][CNNVD-202101-1453]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÀûÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóÀûÓø鶴£¬ÀÖ³ÉÀûÓôË©¶´¿ÉÄܽӹÜOracleWebLogicServer¡£

¸üÐÂʱ¼ä£º

20210525


ʼþÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬Æ丽¼ÓµÄParametersInterceptorÔÊÐí·ÃÎÊ'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬²¢ÔÊÐí¿ØÖÆClassLoader¡£ÔÚ¾ßÌåµÄWebÈÝÆ÷²¿Êð»·¾³Ï£¨È磺Tomcat£©£¬¹¥»÷ÕßÀûÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬¿ÉÏò·þÎñÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷Ö÷»ú¡£ÁíÍ⣬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬boundary´óÓÚ½çÏÞÖµ£¬¶øÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏÞÖµ£¬µ¼ÖÂDDOS¡£Â©¶´´æÔڵİ汾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸Äʼþ

1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐЩ¶´

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÃüÁî_Ô¶³ÌÃüÁîÖ´ÐÐ