ÿÖÜÉý¼¶Í¨¸æ-2021-11-16
Ðû²¼Ê±¼ä 2021-12-10ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_ľÂí_Win32.Dark_Crystal_RAT/DCRat_Ô¶¿ØľÂí_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º | Ô¶¿ØºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíDarkCrystalÁ¬½ÓC2·þÎñÆ÷£¬±íÃ÷Ô´IPÖ÷»úÒÑѬȾ¸ÃľÂí¡£DarkCrystal¶ñÒâÈí¼þÊÇÒ»ÖÖRAT£¨Ô¶³Ì·ÃÎÊľÂí£©£¬C#ÓïÑÔ£¬¶íÂÞ˹ÈË¿ª·¢¡£DarkCrystalRATÊÇÒ»Öַdz£ÏȽøµÄºÚ¿Í¹¤¾ß£¬¾ßÓкܶ๦Ч£¬ÆäÖаüÂÞ£ºÔËÐÐÔ¶³ÌÃüÁî¡¢ÊÕ¼¯Óû§ÐÅÏ¢¡¢Í¨¹ýÍøÂçÉãÏñͷ¼ÖÆÊÓƵ¡¢Í¨¹ýÂó¿Ë·ç¼ÖÆÒôƵ¡¢Ö´ÐÐDDoS»òUDP/TCPºéË®¹¥»÷¡¢¹ÜÀíÎļþϵͳµÈµÈ¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_±í´ïʽעÈë_ͨÓà |
Äþ¾²ÀàÐÍ£º | ÆäËû×¢Èë |
ʼþÃèÊö£º | 2013Äê4ÔÂ15ÈÕExpressionLanguageInjection´ÊÌõÔÚOWASPÉϱ»´´½¨£¬¶øÕâ¸ö´ÊµÄ×îÔç·ºÆð¿ÉÒÔ×·Ëݵ½2012Äê12Ôµġ¶Remote-Code-with-Expression-Language-Injection¡·Ò»ÎÄ£¬ÔÚÕâ¸öpaperÖеÚÒ»´ÎÌáµ½ÁËÕâ¸öÃû´Ê¡£¶øÕâ¸öʱÆÚ£¬Ö»²»Í⻹ֻÊÇ°ÑËü½Ð×öÔ¶³Ì´úÂëÖ´ÐЩ¶´¡¢Ô¶³ÌÃüÁîÖ´ÐЩ¶´»òÕßÉÏÏÂÎIJٿØ©¶´¡£ÏñStruts2ϵÁеÄs2-003¡¢s2-009¡¢s2-016µÈ£¬ÕâÖÖÓÉOGNL±í´ïʽÒýÆðµÄÃüÁîÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_D-Link_DAP-1860_Ô¶³ÌÃüÁîÖ´ÐЩ¶´[CVE-2019-19597][CNNVD-201912-215] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | D-LinkDAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFi·¶Î§À©Õ¹Æ÷¡£D-LinkDAP-18601.04b03֮ǰ°æ±¾ÖдæÔÚÄþ¾²Â©¶´¡£¹¥»÷Õ߿ɽèÖúHTTPÇëÇóÍ·ÖеÄHNAP_AUTH²ÎÊýºó×¢ÈëshellÔª×Ö·ûÀûÓø鶴ÒÔrootȨÏÞÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_passwdÄÚÈÝÎļþ»ØÏÔ |
Äþ¾²ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÕýÔÚͨ¹ýÃüÁîÖ´Ðмì²ì/etc/passwdÎļþµÄÄÚÈÝ¡£´ËÎļþÖд洢ÁËϵͳÖеÄËùÓÐÕË»§¡¢È¨ÏÞµÈÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ÐÞ¸Äʼþ
ʼþÃû³Æ£º | HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2015-7450] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | WebSphereÊÇIBM¹«Ë¾¿ª·¢µÄÖмä¼þ»ù´¡Éèʩƽ̨¡£WebSphere7°æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁËApacheCommonsCollections¿âÖеÄInvokerTransformerÀ࣬¸ÃÀà´æÔÚJava·´ÐòÁл¯Â©¶´¡£¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌÃüÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÖ÷»úÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÐaction:¡¢redirect:»òredirectAction:µÄǰ׺²ÎÊýÀûÓø鶴ִÐÐÈÎÒâOGNL±í´ïʽ¡£Â©¶´´æÔڵİ汾£ºS2-016£ºStruts2.0.0-Struts2.3.15S2-017£ºStruts2.0.0-Struts2.3.15S2-018£ºStruts2.0.0-Struts2.3.15.2¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | TCP_ͨÓÃ_Java·´ÐòÁл¯_ysoserial¶ñÒâÊý¾ÝÀûÓà |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýTCP·¢ËÍysoserialÉú³ÉµÄ¶ñÒâJAVA·´ÐòÁл¯Êý¾Ý¶ÔÄ¿µÄÖ÷»ú½øÐй¥»÷¡£Èô·ÃÎʵÄÓ¦ÓôæÔÚ©¶´JAVA·´ÐòÁл¯Â©¶´£¬¹¥»÷Õß¿ÉÒÔ·¢Ë;«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂë»òÃüÁî¡£Ô¶³ÌÖ´ÐÐÈÎÒâ´úÂ룬»ñȡϵͳ¿ØÖÆȨ¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | TCP_½©Ê¬ÍøÂç_Mirai.Putin_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ÆäËû×¢Èë |
ʼþÃèÊö£º | ¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÁ¬½ÓC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£Mirai½©Ê¬ÍøÂçÈä³æÖ÷Ҫͨ¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬°üÂÞ£ºÂ·ÓÉÆ÷¡¢ÍøÂçÉãÏñÍ·¡¢DVRÉ豸µÈµÈ£¬IoTÉ豸Ö÷ÒªÊÇMIPS¡¢ARMµÈ¼Ü¹¹£¬Òò´æÔÚĬÈÏÃÜÂë¡¢ÈõÃÜÂë¡¢ÑÏÖØ©¶´Î´¼°Ê±ÐÞ¸´µÈÒòËØ£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬»ñÈ¡¹ÜÀíԱȨÏÞ¡£ÓÉÓÚÔ´´úÂëÒѾ¹ûÈ»£¬Mirai·ºÆðÁ˺ܶà±äÖÖ£¬±¾Ê¼þÕë¶ÔÆä±äÖÖPutin¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_phpunint_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2017-9841][CNNVD-201706-1127] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | PHPUnitÊÇPHP³ÌʽÓïÑÔÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ(unittesting)¿ò¼Ü£¬Í¨³£phpunitʹÓÃcomposer·Ç³£Á÷ÐеÄPHPÒÀÀµ¹ÜÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunitÉú²ú»·¾³ÖÐÈÔÈ»°²×°ÁËËü,Èç¹û¸Ã±àдÆ÷Ä£¿é´æÔÚÓÚWeb¿É·ÃÎÊĿ¼£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´¡£ |
¸üÐÂʱ¼ä£º | 20211116 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Fastjson©¶´_hex±àÂëÀûÓà |
Äþ¾²ÀàÐÍ£º | ÆäËû¿ÉÒÉÐÐΪ |
ʼþÃèÊö£º | FastJsonÊÇ°¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬Ëü¿ÉÒÔ½âÎöJSON¸ñʽµÄ×Ö·û´®£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬Ò²¿ÉÒÔ´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬ÓÉÓÚ¾ßÓÐÖ´ÐÐЧÂʸߵÄÌص㣬ӦÓ÷¶Î§ºÜ¹ã¡£¹¥»÷Àֳɣ¬¿ÉÔ¶³ÌÖ´ÐÐÈÎÒâ´úÂë¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬Òò´Ë¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈƹý¼ì²âÉ豸¡£ |
¸üÐÂʱ¼ä£º | 20211116 |