ÿÖÜÉý¼¶²¼¸æ-2022-12-20

°ä²¼¹¦·ò 2022-12-20

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_Admins_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

SpringBootadminsÊÇÒ»¸öÓÃÓÚÖÎÀíSpringBootÀûÓ÷¨Ê½µÄ¿ªÔ´ÖÎÀíÓû§½çÃæ¡£ ¡£SpringBootadminsµÄnotifiers֪ͨÄ£¿£¿£¿éÓÉÓÚûÓжÔÓû§ÊäÈë½øÐÐÓÐЧ¹ýÂË£¬£¬ £¬ËùÓÐÔËÐÐSpringBootAdminServer¡¢¡¢ÆôÓÃ֪ͨ·¨Ê½£¨ÀýÈçTeams-Notifier£©²¢Í¨¹ýUIдÈë»·¾³±äÁ¿µÄÓû§³ÇÊÐÊܵ½´úÂë×¢ÈëµÄÓ°Ïì¡£ ¡£¹¥»÷Õß¿ÉÀûÓô˷ì϶ͨ¹ýÏòSpringBootAdminServerµÄ/envÖ´ÐÐÆ÷¶Ëµã·¢ËÍÔ̺¬¶ñÒâ´úÂëµÄPOSTÒªÇóÔ¶³ÌÖ´ÐжñÒâ´úÂë¡£ ¡£

¸üй¦·ò£º£º£º

20221220

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®[CVE-2021-44228]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£ ¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬ £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬ £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£ ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬ £¬´ËÐÐΪӵÓнϸ߷çÏÕ£¬£¬ £¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓ㬣¬ £¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬ £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓ㬣¬ £¬´Ó¶øÖ´ÐжñÒâ´úÂë»òºÅÁî¡£ ¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨Å²ÓÃjndiŲÓõÄÖ°ÄÜ£¬£¬ £¬²¢ÏÞ¶ÈÁ˰×Ãûµ¥£¬£¬ £¬¹ÊʹÓÃδ¾­Ï޶ȵÄÀϰ汾log4j2×é¼þ¿ÉÄÜ»á´æÔÚjndi×¢ÈëµÄ·çÏÕ¡£ ¡£

¸üй¦·ò£º£º£º

20221220


 

ÊÂÎñÃû³Æ£º£º£º

TCP_ÌáȨ¹¥»÷_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®_´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£ ¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´®£¬£¬ £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê±£¬£¬ £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£ ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬ £¬´ËÐÐΪӵÓп϶¨·çÏÕ£¬£¬ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ £¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬ £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓᣠ¡£

¸üй¦·ò£º£º£º

20221220


 

ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨºÅÁî×¢Èë

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnºÅÁî×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£ ¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬ £¬exportovpn½Ó¿Ú´æÔÚºÅÁî×¢È룬£¬ £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâºÅÁî¡£ ¡£

¸üй¦·ò£º£º£º

20221220


 

ÊÂÎñÃû³Æ£º£º£º

HTTP_°²È«·ì϶_ÈôÒÀCMS_Ô¶³ÌºÅÁîÖ´Ðзì϶

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

ÈôÒÀºó¶ÜÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬ £¬snakeyamlÊÇÓÃÀ´½âÎöyamlµÄÌåʽ£¬£¬ £¬¿ÉÓÃÓÚJava¶ÔÏóµÄÐòÁл¯¡¢¡¢·´ÐòÁл¯¡£ ¡£ÓÉÓÚÈôÒÀºó¶Ü´òË㹤×÷´¦£¬£¬ £¬¶ÔÓÚ´«ÈëµÄ"ŲÓÃÖ¸±ê×Ö·û´®"ûÓÐÈκÎУÑ飬£¬ £¬µ¼Ö¹¥»÷ÕßÄܹ»»ú¹ØpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬ £¬´Ó¶øÖ´ÐÐËÁÒâºÅÁî¡£ ¡£

¸üй¦·ò£º£º£º

20221220


 

ÊÂÎñÃû³Æ£º£º£º

TCP_°²È«·ì϶_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2021-30181]

°²È«ÀàÐÍ£º£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º£º

¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ­½ÚÖÆÈçZooKeeperÅäÖÃÖÐÐĺ󣬣¬ £¬Í¨¹ýÅäÖÃÖÐÐÄÀ´»ú¹Ø¶ñÒâÒªÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬£¬ £¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»£»ApacheDubboÊÇÒ»¸öÉ¢²¼Ê½¿ò¼Ü£¬£¬ £¬ÖÂÁ¦ÓÚÌṩ¸ß»úÄÜͨÃ÷»¯µÄRPCÔ¶³Ì·þÎñŲÓù滮£¬£¬ £¬ÒÔ¼°SOA·þÎñÖÎÀí¹æ»®¡£ ¡£ApacheDubboÔÚÏÖʵÀûÓó¡¾°ÖÐÖØÒªÕÆ¹Ü½â¾öÉ¢²¼Ê½µÄÓйØÐèÒª¡£ ¡£

¸üй¦·ò£º£º£º

20221220