ÿÖÜÉý¼¶²¼¸æ-2021-11-16
°ä²¼¹¦·ò 2021-12-10ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º£º | TCP_ľÂí_Win32.Dark_Crystal_RAT/DCRat_Ô¶¿ØÄ¾Âí_ÏνÓC2·þÎñÆ÷ |
°²È«ÀàÐÍ£º£º | Ô¶¿ØºóÃÅ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ä¾ÂíDarkCrystalÏνÓC2·þÎñÆ÷£¬£¬Åú×¢Ô´IPÖ÷»úÒÑϰȾ¸ÃľÂí¡£¡£¡£DarkCrystal¶ñÒâÈí¼þÊÇÒ»ÖÖRAT£¨Ô¶³Ì½Ó¼ûľÂí£©£¬£¬C#˵»°£¬£¬¶íÂÞ˹ÈË¿ª·¢¡£¡£¡£DarkCrystalRATÊÇÒ»ÖÖ¼«¶ÈÏȽøµÄºÚ¿Í¹¤¾ß£¬£¬ÓµÓкöàÖ°ÄÜ£¬£¬ÆäÖÐÔ̺¬£º£ºÔËÐÐÔ¶³ÌºÅÁî¡¢¡¢ÍøÂçÓû§ÐÅÏ¢¡¢¡¢Í¨¹ýÍøÂçÉãÏñÍ·Â¼ÖÆÊÓÆµ¡¢¡¢Í¨¹ýÂó¿Ë·çÂ¼ÖÆÒôƵ¡¢¡¢Ö´ÐÐDDoS»òUDP/TCPºéË®¹¥»÷¡¢¡¢ÖÎÀíÎļþϵͳµÈµÈ¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_±í°×ʽעÈë_ͨÓà |
°²È«ÀàÐÍ£º£º | ÆäËû×¢Èë |
ÊÂÎñÃèÊö£º£º | 2013Äê4ÔÂ15ÈÕExpressionLanguageInjection´ÊÌõÔÚOWASPÉϱ»´´½¨£¬£¬¶øÕâ¸ö´ÊµÄ×îÔç³öÏÖÄܹ»×·Òäµ½2012Äê12Ôµġ¶Remote-Code-with-Expression-Language-Injection¡·Ò»ÎÄ£¬£¬ÔÚÕâ¸öpaperÖеÚÒ»´ÎÌáµ½ÁËÕâ¸öÃû´Ê¡£¡£¡£¶øÕâ¸öʱÆÚ£¬£¬Ö»²»Í⻹ֻÊǰÑËü½Ð×öÔ¶³Ì´úÂëÖ´Ðзì϶¡¢¡¢Ô¶³ÌºÅÁîÖ´Ðзì϶»òÕ߸ߵÍÎIJٿطì϶¡£¡£¡£ÏñStruts2ϵÁеÄs2-003¡¢¡¢s2-009¡¢¡¢s2-016µÈ£¬£¬ÕâÖÖÓÉOGNL±í°×ʽÒýÆðµÄºÅÁîÖ´Ðзì϶¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_D-Link_DAP-1860_Ô¶³ÌºÅÁîÖ´Ðзì϶[CVE-2019-19597][CNNVD-201912-215] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | D-LinkDAP-1860ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îWiFiÁìÓòÀ©´óÆ÷¡£¡£¡£D-LinkDAP-18601.04b03֮ǰ°æ±¾ÖдæÔÚ°²È«·ì϶¡£¡£¡£¹¥»÷Õ߿ɽèÖúHTTPÒªÇóÍ·ÖеÄHNAP_AUTH²ÎÊýºó×¢ÈëshellÔª×Ö·ûÀûÓø÷ì϶ÒÔrootȨÏÞÖ´ÐÐËÁÒâºÅÁî¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_¿ÉÒÉÐÐΪ_passwdÄÚÈÝÎļþ»ØÏÔ |
°²È«ÀàÐÍ£º£º | ÆäËû¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÕýÔÚͨ¹ýºÅÁîÖ´Ðв鿴/etc/passwdÎļþµÄÄÚÈÝ¡£¡£¡£´ËÎļþÖд洢ÁËϵͳÖеÄËùÓÐÕË»§¡¢¡¢È¨ÏÞµÈÐÅÏ¢¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
Åú¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º£º | HTTP_IBM_WebSphere_Java·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2015-7450] |
°²È«ÀàÐÍ£º£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | WebSphereÊÇIBM¹«Ë¾¿ª·¢µÄÖÐÑë¼þ»ù´¡Éèʩƽ̨¡£¡£¡£WebSphere7°æ±¾ÔÚ¿ª·¢ÖÐʹÓÃÁËApacheCommonsCollections¿âÖеÄInvokerTransformerÀ࣬£¬¸ÃÀà´æÔÚJava·´ÐòÁл¯·ì϶¡£¡£¡£¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏ󣬣¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_Struts2_S2-016/S2-017/S2-018Ô¶³ÌºÅÁîÖ´ÐбäÐι¥»÷[CVE-2013-2251/4310] |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úÔ¶³Ì¹¥»÷Õß¿Éͨ¹ý´øÓÐaction:¡¢¡¢redirect:»òredirectAction:µÄǰ׺²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâOGNL±í°×ʽ¡£¡£¡£·ì϶´æÔڵİ汾£º£ºS2-016£º£ºStruts2.0.0-Struts2.3.15S2-017£º£ºStruts2.0.0-Struts2.3.15S2-018£º£ºStruts2.0.0-Struts2.3.15.2¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | TCP_ͨÓÃ_Java·´ÐòÁл¯_ysoserial¶ñÒâÊý¾ÝÀûÓà |
°²È«ÀàÐÍ£º£º | ºÅÁîÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚͨ¹ýTCP·¢ËÍysoserialÌìÉúµÄ¶ñÒâJAVA·´ÐòÁл¯Êý¾Ý¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷¡£¡£¡£Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶£¬£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏ󣬣¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£¡£Ô¶³ÌÖ´ÐÐËÁÒâ´úÂ룬£¬»ñȡϵͳ½ÚÖÆÈ¨¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | TCP_½©Ê¬ÍøÂç_Mirai.Putin_ÏÎ½Ó |
°²È«ÀàÐÍ£º£º | ÆäËû×¢Èë |
ÊÂÎñÃèÊö£º£º | ¼ì²âµ½½©Ê¬ÍøÂçMirai±äÖÖPutinÊÔͼÏνÓC&C·þÎñÆ÷¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMirai±äÖÖPutin¡£¡£¡£Mirai½©Ê¬ÍøÂçÈä³æÖØÒªÍ¨¹ýɨÃè·À»¤ÄÜÁ¦²»Ç¿µÄÎïÁªÍøÉ豸£¨IoT£©£¬£¬Ô̺¬£º£ºÂ·ÓÉÆ÷¡¢¡¢ÍøÂçÉãÏñÍ·¡¢¡¢DVRÉ豸µÈµÈ£¬£¬IoTÉè±¸ÖØÒªÊÇMIPS¡¢¡¢ARMµÈ¼Ü¹¹£¬£¬Òò´æÔÚĬÈÏÃÜÂë¡¢¡¢ÈõÃÜÂë¡¢¡¢ÑÏÖØ·ì϶δʵʱÐÞ¸´µÈ³É·Ö£¬£¬µ¼Ö±»¹¥»÷ÕßÖ²ÈëľÂí¡£¡£¡£ÇÔÈ¡Ãô¸ÐÐÅÏ¢£¬£¬»ñÈ¡ÖÎÀíԱȨÏÞ¡£¡£¡£ÓÉÓÚÔ´´úÂëÒѾ¹«¿ª£¬£¬Mirai³öÏÖÁ˺öà±äÖÖ£¬£¬±¾ÊÂÎñÕë¶ÔÆä±äÖÖPutin¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_°²È«·ì϶_phpunint_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2017-9841][CNNVD-201706-1127] |
°²È«ÀàÐÍ£º£º | ´úÂëÖ´ÐÐ |
ÊÂÎñÃèÊö£º£º | PHPUnitÊÇPHP³Ìʽ˵»°ÖÐ×î³£¼ûµÄµ¥Ôª²âÊÔ(unittesting)¿ò¼Ü£¬£¬Í¨³£phpunitʹÓÃcomposer¼«¶ÈÊ¢ÐеÄPHPÒÀÀµÖÎÀíÆ÷½øÐв¿Êð,½«»áÔÚµ±Ç°Ä¿Â¼´´½¨Ò»¸övendorÎļþ¼Ð.phpunit³ö²ú»·¾³ÖÐÒÀÈ»×°ÖÃÁËËü,ÈôÊǸñàдÆ÷Ä£¿£¿£¿é´æÔÚÓÚWeb¿É½Ó¼ûĿ¼£¬£¬Ôò´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |
ÊÂÎñÃû³Æ£º£º | HTTP_¿ÉÒÉÐÐΪ_Fastjson·ì϶_hex±àÂëÀûÓà |
°²È«ÀàÐÍ£º£º | ÆäËû¿ÉÒÉÐÐΪ |
ÊÂÎñÃèÊö£º£º | FastJsonÊǰ¢Àï°Í°ÍµÄ¿ªÔ´JSON½âÎö¿â£¬£¬ËüÄܹ»½âÎöJSONÌåʽµÄ×Ö·û´®£¬£¬Ö§³Ö½«JavaBeanÐòÁл¯ÎªJSON×Ö·û´®£¬£¬Ò²Äܹ»´ÓJSON×Ö·û´®·´ÐòÁл¯µ½JavaBean£¬£¬ÓÉÓÚÓµÓÐÖ´ÐÐЧÄܸߵÄÌØµã£¬£¬ÀûÓÃÁìÓòºÜ¹ã¡£¡£¡£¹¥»÷³É¹¦£¬£¬¿ÉÔ¶³ÌÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£fastjson¿É½ÓÊܲ¢½âÎöhex±àÂëÄÚÈÝ£¬£¬Òò¶ø¹¥»÷Õß¿ÉÀûÓÃhex±àÂëÈÆ¹ý¼ì²âÉ豸¡£¡£¡£ |
¸üй¦·ò£º£º | 20211116 |


¾©¹«Íø°²±¸11010802024551ºÅ