ÿÖÜÉý¼¶Í¨¸æ-2023-01-17

Ðû²¼Ê±¼ä 2023-01-17
ÐÂÔöʼþ

 

ʼþÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Hashicorp_Consul_Service_API_Ô¶³ÌÃüÁîÖ´ÐÐ

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚÀûÓÃConsulÖдæÔÚµÄÔ¶³ÌÃüÁîÖ´ÐЩ¶´½øÐй¥»÷¡£ConsulÊÇHashiCorp¹«Ë¾ÍƳöµÄÒ»¿î¿ªÔ´¹¤¾ß£¬ÓÃÓÚʵÏÖÂþÑÜʽϵͳµÄ·þÎñ·¢ÏÖÓëÅäÖá£ÔÚÆôÓÃÁ˽ű¾¼ì²é²ÎÊý£¨-enable-script-checks£©µÄConsulËùÓа汾ÖУ¬¶ñÒâ¹¥»÷Õß¿ÉÒÔͨ¹ý·¢Ë;«ÐĽṹµÄHTTPÇëÇóÔÚδ¾­ÊÚȨµÄÇé¿öÏÂÔÚConsul·þÎñ¶ËÔ¶³ÌÖ´ÐÐÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

DNS_½©Ê¬ÍøÂç_Fodcha_Á¬½Ó

Äþ¾²ÀàÐÍ£º

ÆäËûʼþ

ʼþÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçFodchaÊÔͼÏòdns·þÎñÆ÷ÇëÇó½âÎöÆäC&C·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËFodcha¡£FodchaÖ÷Ҫͨ¹ýNDay©¶´ºÍTelnet/SSHÈõ¿ÚÁîÁ÷´«£¬°üÂÞCVE-2021-22205¡¢CVE-2021-35394¡¢AndroidADBDebugServerRCE¡¢LILINDVRRCEµÈ©¶´¡£Ã¿ÈÕÉÏÏß¾³ÄÚÈ⼦ÊýÒÔIPÊý¼ÆËãÒÑÁè¼Ý1Íò£¬ÇÒÿÈÕ»áÕë¶ÔÁè¼Ý100¸ö¹¥»÷Ä¿±êÌᳫDDoS¹¥»÷£¬¹¥»÷·Ç³£»îÔ¾¡£FodchaʹÓÃChaCha20¼ÓÃܺÍC&CµÄͨÐÅÊý¾Ý¡£

¸üÐÂʱ¼ä£º

20230117

 

ÐÞ¸Äʼþ

 

ʼþÃû³Æ£º

HTTP_ÆäËü¿ÉÒÉÐÐΪ_PHPαЭÒé

Äþ¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ʼþÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃPHPµÄһЩ·âװЭÒ飬Èçphp://input,php://filterµÈÌá½»Ò»¾ä»°Ä¾Âí£¬»òÔ¶³ÌÖ´ÐÐÃüÁîÀ´¹¥»÷Êܺ¦Õß·þÎñÆ÷£¬´Ó¶ø»ñÈ¡Ä¿±êϵͳȨÏÞ¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÃüÁî×¢Èë

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÃüÁî×¢È멶´¹¥»÷Ä¿µÄIPÖ÷»ú¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬exportovpn½Ó¿Ú´æÔÚÃüÁî×¢È룬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117

 

ʼþÃû³Æ£º

HTTP_Äþ¾²Â©¶´_ÈôÒÀCMS_Ô¶³ÌÃüÁîÖ´ÐЩ¶´

Äþ¾²ÀàÐÍ£º

Äþ¾²Â©¶´

ʼþÃèÊö£º

ÈôÒÀºǫ́¹ÜÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄ¸ñʽ£¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£ÓÉÓÚÈôÒÀºǫ́¼Æ»®ÈÎÎñ´¦£¬¶ÔÓÚ´«ÈëµÄ"µ÷ÓÃÄ¿±ê×Ö·û´®"ûÓÐÈκÎУÑ飬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³Ìµ÷ÓÃjar°ü£¬´Ó¶øÖ´ÐÐÈÎÒâÃüÁî¡£

¸üÐÂʱ¼ä£º

20230117