ÿÖÜÉý¼¶Í¨¸æ-2022-01-18
Ðû²¼Ê±¼ä 2022-01-18ÐÂÔöʼþ
ʼþÃû³Æ£º | TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookup¸ñʽ×Ö·û´® |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Ç¼¿â£¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´Ëʼþ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookup¸ñʽµÄ×Ö·û´®£¬µ±Ä¿µÄIPÖ÷»úºó¶Ë½ÓÊÕµ½´Ë¸ñʽµÄ×Ö·û´®Ê±£¬»á×Ô¶¯µ÷ÓÃlookup¹¦Ð§¡£´Ëʼþ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬´ËÐÐΪ¾ßÓÐÒ»¶¨·çÏÕ£¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓã¬ÈçÈƹýWAF¼ì²â£¬²¢½øÐзÇÔ¤ÆÚµÄjndiµ÷Óᣠ|
¸üÐÂʱ¼ä£º | 20220118 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_DedeCMSV6.0.3_article_string_mix.php_Ô¶³Ì´úÂëÖ´ÐЩ¶´ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢£¬¾ßÓкÜÇ¿µÄ¿ÉÀ©Õ¹ÐÔ£¬¶øÇÒÍêÈ«¿ª·ÅÔ´´úÂë¡£Æäºǫ́article_string_mix.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´ÐЩ¶´£¬¹¥»÷Õß¿ÉÀûÓôË©¶´Äõ½Ä¿±êÖ÷»úȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220118 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_À¶ÁèOA_admin.do_JNDIÔ¶³ÌÃüÁîÖ´ÐÐ |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ÉîÛÚÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚÈÎÒâÎļþ¶Áȡ©¶´¡£¹¥»÷Õß¿ÉÀûÓ鶴»ñÈ¡Ãô¸ÐÐÅÏ¢£¬¶ÁÈ¡ÅäÖÃÎļþµÃµ½ÃÜÔ¿ºó·ÃÎÊadmin.do¼´¿ÉÀûÓÃJNDIÔ¶³ÌÃüÁîÖ´ÐлñȡȨÏÞ¡£ |
¸üÐÂʱ¼ä£º | 20220118 |
ʼþÃû³Æ£º | TCP_ľÂíºóÃÅ_Pupy_Á¬½ÓC2·þÎñÆ÷ |
Äþ¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ʼþÃèÊö£º | ¼ì²âµ½Óɺڿ͹¤¾ßPupyÉú³ÉµÄhttpÔ¶¿ØºóÃÅÊÔͼÁ¬½ÓÔ¶³Ì·þÎñÆ÷,Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£Ö´Ðк󣬹¥»÷Õß¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úÆ÷£¬²¢½øÐкáÏòÒƶ¯¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶à¹¦Ð§Ô¶¿ØºóÃźͺóÉø͸¹¤¾ß¡£Ëü¾ßÓÐall-in-memoryÖ´Ðй¦Ð§£¬Õ¼Óÿռä·Ç³£Ð¡¡£Pupy¿ÉÒÔʹÓöàÖÖ·½Ê½½øÐÐͨÐÅ£¬Ê¹Ó÷´Éä×¢ÈëǨÒƵ½½ø³ÌÖУ¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£ |
¸üÐÂʱ¼ä£º | 20220118 |
ʼþÃû³Æ£º | HTTP_Äþ¾²Â©¶´_Zhone-Technologies-zNID-GPON-2426A_ÃüÁîÖ´ÐÐ[CVE-2014-9118][CNNVD-201510-721] |
Äþ¾²ÀàÐÍ£º | Äþ¾²Â©¶´ |
ʼþÃèÊö£º | ZhoneTechnologieszNIDGPON2426AÊÇÃÀ¹úZhoneTechnologies¹«Ë¾µÄÒ»¿î·ÓÉÆ÷¡£webadministrativeportalÊÇÆäÖеÄÒ»¸öWeb¹ÜÀíÔ±¿ØÖÆ̨·¨Ê½¡£ZhoneTechnologieszNIDGPON2426AS3.0.501֮ǰ°æ±¾µÄWeb¹ÜÀíÔ±¿ØÖÆ̨ÖдæÔÚÄþ¾²Â©¶´¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòzhnping.cmdÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®ipAddr¡¯²ÎÊýÀûÓø鶴ִÐÐÈÎÒâÃüÁî¡£ |
¸üÐÂʱ¼ä£º | 20220118 |