ÿÖÜÉý¼¶Í¨¸æ-2021-12-14
Ðû²¼Ê±¼ä 2021-12-15ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_ºóÃÅ_9002.Rat_APT_¹¥»÷ |
Äþ¾²ÀàÐÍ£º | Ô¶¿ØºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Ä¾ÂíÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£9002.RatÊÇÕýÔÚ»îÔ¾µÄAPTs(AdvancedPersistentThreats)¹¥»÷£¬ÄÑÒÔ¼ì²â£¬Çҷdz£ÓÐÕë¶ÔÐÔ¡£Ö÷ÒªÊÇÀûÓÃʱÏÂÁ÷ÐеÄ©¶´Á÷´«£¬ÈçCVE-2013-1347¡¢CVE-2013-2423¡¢CVE-2013-1493µÈ¡£·¢ÏÖÓÐÉÏ´«Óû§Îļþ£¬Ô¶³ÌÖ´ÐÐÃüÁîµÈ¹¦Ð§¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»¿Ø¶ËÖ÷»ú×öÖÖÖÖ²Ù×÷¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_D_Link_ÃüÁî×¢È멶´ |
Äþ¾²ÀàÐÍ£º | Âß¼/Éè¼Æ´íÎó |
ʼþÃèÊö£º | D-LinkÒ»¼ÒÉú²úÍøÂçÓ²¼þºÍÈí¼þ²úÎïµÄÆóÒµ£¬Ö÷Òª²úÎïÓн»»»»ú¡¢ÎÞÏß²úÎï¡¢¿í´ø²úÎï¡¢Íø¿¨¡¢Â·ÓÉÆ÷¡¢ÍøÂçÉãÏñ»úºÍÍøÂçÄþ¾²²úÎï(·À»ðǽ)µÈ¡£D-Link´æÔÚÒ»¸öÃüÁî×¢È멶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏò/getcfg.php·¢ËÍ°üÂÞ¶ñÒâÃüÁîµÄÇëÇ󣬴ӶøʵÏÖÔ¶³ÌÈÎÒâÃüÁîÖ´ÐÐ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | TCP_ºóÃÅ_Rotajakiro.Oceanlotus(º£Á«»¨)_Á¬½Ó |
Äþ¾²ÀàÐÍ£º | ÆäËûºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½ºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅRotajakiro¡£RotajakiroÒÉËÆÊÇAPT×éÖ¯º£Á«»¨ËùµÄʹÓúóÃÅ£¬¹¦Ð§·Ç³£Ç¿´ó£¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úÆ÷¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | TCP_ºáÏòÒƶ¯_PsexecÎļþдÈë |
Äþ¾²ÀàÐÍ£º | ÆäËûºóÃÅ |
ʼþÃèÊö£º | PsExecÊÇÒ»¸öÇáÁ¿¼¶µÄtelnetÌæ´ú¹¤¾ß£¬ËüʹÄúÎÞÐèÊÖ¶¯°²×°¿Í»§¶ËÈí¼þ¼´¿ÉÖ´ÐÐÆäËûϵͳÉϵĽø³Ì£¬¶øÇÒ¿ÉÒÔ»ñµÃÓëÃüÁî¿ØÖÆ̨¼¸ºõÏàͬµÄʵʱ½»»¥ÐÔ¡£PsExec×îÇ¿´óµÄ¹¦Ð§¾ÍÊÇÔÚÔ¶³ÌϵͳºÍÔ¶³ÌÖ§³Ö¹¤¾ß(Èçipconfig¡¢whoami)ÖÐÆô¶¯½»»¥Ê½ÃüÁîÌáʾ´°¿Ú£¬ÒÔ±ãÏÔʾÎÞ·¨Í¨¹ýÆäËû·½Ê½ÏÔʾµÄÓйØÔ¶³ÌϵͳµÄÐÅÏ¢¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Citrix_SD-WAN_Ô¶³Ì´úÂëÖ´ÐЩ¶´[CVE-2020-8271][CNNVD-202011-1336] |
Äþ¾²ÀàÐÍ£º | ´úÂëÖ´ÐÐ |
ʼþÃèÊö£º | CitrixSD-WANÊÇÓÉÃÀ¹úCitrix¹«Ë¾¿ª·¢µÄÒ»Ì×¹ãÓòÍø¼¯ÖйÜÀíϵͳ£¬Í¨¹ýÐéÄ⻯¼¼ÊõʵÏÖÆóÒµ¼¶µÄÄþ¾²¹ãÓòÍø£¬×ÛºÏÀûÓöàÌõÁ´Â·£¬ÊµÏÖ¸ºÔؾùºâ£¬²¢ÄÜÅäÖᢼà¿ØºÍ·ÖÎöWANÉϵÄËùÓÐCitrixSD-WANÉ豸¡£CitrixSD-WANͨ¹ýurlÆ¥ÅäʵÏÖÉí·ÝÑéÖ¤£¬µ«¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâurlʹµÃApache½âÎöµÄurlºÍCakePHP´«ÈëµÄurl·×ÆçÖ£¬´Ó¶øÈƹý¿Í»§¶ËÖ¤Êé¼ì²é£¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Redmine_ÃüÁîÖ´ÐÐ[CVE-2011-4929][CNNVD-201210-082] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | RedmineÊÇÒ»Ì׿ªÔ´µÄ»ùÓÚWebµÄÏîÄ¿¹ÜÀíºÍȱÏݸú×Ù¹¤¾ß¡£¸Ã¹¤¾ßÌṩÏîÄ¿¹ÜÀí¡¢ÎÊÌâ¸ú×ٺͻùÓÚ½ÇÉ«µÄ·ÃÎÊ¿ØÖƵȹ¦Ð§¡£Redmine0.9.x°æ±¾ºÍ1.0.5֮ǰµÄ1.0.x°æ±¾ÖеÄbazaar¿âÊÊÅäÆ÷ÖдæÔÚδÃ÷©¶´¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø鶴ͨ¹ýδ֪ÏòÁ¿Ö´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Barracuda-Spam-Firewall-img.pl_Ô¶³ÌÃüÁîÖ´ÐÐ[CVE-2005-2847][CNNVD-200509-075] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | BarracudaSpamFirewallÊÇÓÃÓÚ±£»¤Óʼþ·þÎñÆ÷µÄ¼¯³ÉÓ²¼þºÍÈí¼þÀ¬»øÓʼþ½â¾ö·½°¸¡£BarracudaSpamFirewallÖдæÔÚÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡£img.pl½Å±¾ÔÚÓû§¶ÁÈ¡ÍêÎļþ»áÊÔͼ¶Ï¿ªÎļþ¡£ÔÚ/cgi-bin/img.pl½Å±¾ÖУºmy$file_img=\"/tmp/\".CGI£º£ºparam(\'\'f\'\');open(IMG£¬$file_img)ordie\"Couldnotopenimagebecause£º$!£Ün\";...unlink($file_img);perlopenº¯Êý»¹¿ÉÒÔÓÃÓÚÖ´ÐÐÃüÁî¡£Èç¹û×Ö·û´®ÒÔ\"|\"½áÊøµÄ»°£¬½Å±¾¾Í»áÖ´ÐÐÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_VINGA_ÃüÁîÖ´ÐЩ¶´[CVE-2021-43469][CNNVD-202112-350] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | VINGAWR-N300U77.102.1.4853ÊÜgoahead×é¼þÓ°Ï죬´æÔÚÒ»´¦ÃüÁîÖ´ÐЩ¶´¡£¸Ã©¶´Ô´ÓÚ¶Ô´«ÈëµÄhost²ÎÊý¹ýÂ˲»ÑϽ÷£¬µ¼Ö¹¥»÷Õß¿ÉÒÔ×¢Èë¶ñÒâÃüÁîʵÏÖÔ¶³ÌÃüÁîÖ´ÐС£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_tcp_socketµ÷Óà |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑéÔÚÄ¿µÄÖ÷»ú½øÐÐtcp_socketµ÷Ó㬿ÉÄÜΪÃüÁî×¢Èë¹¥»÷¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Quest_KACE_Systems_ManagementÃüÁîÖ´ÐЩ¶´[CVE-2018-11138][CNNVD-201805-1216] |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ¼ì²âµ½Ô´IPÉ豸ÀûÓÃQuest_KACE_Systems_ManagementÃüÁîÖ´ÐЩ¶´¹¥»÷Ä¿µÄIPÉ豸¡£QuestKACEϵͳ¹ÜÀíÉ豸8.0.318download_agent_installer.phpÎļþÔÊÐíδ¾Éí·ÝÑéÖ¤µÄÓû§ÒÔWeb·þÎñÆ÷Óû§wwwµÄÉí·ÝÖ´ÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´® |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óᣠ|
¸üÐÂʱ¼ä£º | 20211214 |
ʼþÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´® |
Äþ¾²ÀàÐÍ£º | ÃüÁîÖ´ÐÐ |
ʼþÃèÊö£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óᣠ|
¸üÐÂʱ¼ä£º | 20211214 |