ÿÖÜÉý¼¶²¼¸æ-2023-02-14

°ä²¼¹¦·ò 2023-02-14
ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º

TCP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Weblogic_T3ºÍ̸[CVE-2020-14756]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨£¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½£¬ÀýÈçJava¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£¡£CVE-2020-2555·ì϶Äܹ»ÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»°²È«µÄextract²½Ö裬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£Ó°ÏìÁìÓò£º£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üй¦·ò£º£º

20230214

 

ÊÂÎñÃû³Æ£º£º

HTTP_ºÅÁî½ÚÖÆ_C2ͨѶ_OrcaC2_ÉÏÏß×¢²á_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨѶµÄ¶àÖ°ÄÜC&C¿ò¼Ü£¬Ê¹ÓÃGolangʵÏÖ¡£¡£ËüÓÉÈý²¿ÃÅ×é³É£º£ºOrca_Server(·þÎñ¶Ë)¡¢¡¢Orca_Master(½ÚÖÆ¶Ë)¡¢¡¢(±»½ÚÖÆ¶ËOrca_Puppet)¡£¡£OrcaC2ѡȡWebsocketͨѶ£¬jsonÌåʽ´«ÊäÊý¾Ý£¬ÐÂÎÅÓëÊý¾Ý²É¼¯Ê¹ÓÃAES-CBC¼ÓÃÜ+Base64±àÂ룬ӵÓÐÔ¶³ÌºÅÁî½ÚÖÆ¡¢¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢¡¢ÆÁÄ»½ØÍ¼£¨±»½ÚÖÆ¶ËΪWindowsϵͳ£©¡¢¡¢Ô¶³ÌÆÁÄ»½ÚÖÆ¡¢¡¢¼üÅ̼ͼµÈµÈ¡£¡£¸ÃÌõÊÂÎñÅú×¢Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí£¬ÕýÔÚÏò·þÎñ¶Ë·¢·îÉÏÏß×¢²áÐÅÏ¢¡£¡£

¸üй¦·ò£º£º

20230214

 

ÊÂÎñÃû³Æ£º£º

TCP_ºÅÁî½ÚÖÆ_C2ͨѶ_OrcaC2_WebSocketºÍ̸_ÐÄÌøÍ¨Ñ¶

°²È«ÀàÐÍ£º£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º£º

OrcaC2ÊÇÒ»¿î»ùÓÚWebsocket¼ÓÃÜͨѶµÄ¶àÖ°ÄÜC&C¿ò¼Ü£¬Ê¹ÓÃGolangʵÏÖ¡£¡£ËüÓÉÈý²¿ÃÅ×é³É£º£ºOrca_Server(·þÎñ¶Ë)¡¢¡¢Orca_Master(½ÚÖÆ¶Ë)¡¢¡¢(±»½ÚÖÆ¶ËOrca_Puppet)¡£¡£OrcaC2ѡȡWebsocketͨѶ£¬jsonÌåʽ´«ÊäÊý¾Ý£¬ÐÂÎÅÓëÊý¾Ý²É¼¯Ê¹ÓÃAES-CBC¼ÓÃÜ+Base64±àÂ룬ӵÓÐÔ¶³ÌºÅÁî½ÚÖÆ¡¢¡¢ÎļþÉÏ´«/ÏÂÔØ¡¢¡¢ÆÁÄ»½ØÍ¼£¨±»½ÚÖÆ¶ËΪWindowsϵͳ£©¡¢¡¢Ô¶³ÌÆÁÄ»½ÚÖÆ¡¢¡¢¼üÅ̼ͼµÈµÈ¡£¡£¸ÃÌõÊÂÎñÅú×¢Ô´IPÖ÷»úÕýÔÚÔËÐÐOrca_PuppetľÂí£¬Orca_Server·þÎñ¶ËÕýÔÚÏò±»½ÚÖÆ¶Ë·¢ËÍÐÄÌøÍ¨Ñ¶ÐÅÏ¢¡£¡£

¸üй¦·ò£º£º

20230214

 

ÊÂÎñÃû³Æ£º£º

HTTP_ÌáȨ¹¥»÷_Centos_Web_Panel_7_ºÅÁîÖ´ÐÐ[CVE-2022-44877]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

CWP£¬Ç°ÉíΪCentOSWebPanel£¬ÊÇÒ»¸öÃâ·ÑʹÓõÄLinux½ÚÖÆÃæ°å¡£¡£ÔÚCentOSWebPanel70.9.8.1147°æ±¾Ö®Ç°µÄϵͳÖУ¬/login/index.php×é¼þÖдæÔÚ·ì϶£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿Éͨ¹ý¾«ÐÄÉè¼ÆµÄHTTPÒªÇóÖ´ÐÐËÁÒâϵͳºÅÁî¡£¡£

¸üй¦·ò£º£º

20230214

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º£º

TCP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Oracle_WebLogic_T3ºÍ̸[CVE-2020-2555]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

¼ì²âµ½Ô´IPÀûÓÃweblogic·´ÐòÁл¯·ì϶½øÐй¥»÷µÄÐÐΪ£¬OracleCoherenceΪOracleÈÚºÏÖÐÑë¼þÖеIJúÆ·£¬ÔÚWebLogic12c¼°ÒÔÉϰ汾ÖÐĬÈϼ¯³Éµ½WebLogic×°ÖðüÖУ¬¹¥»÷Õßͨ¹ýt3ºÍ̸·¢ËÍ»ú¹ØµÄÐòÁл¯Êý¾Ý£¬ÄܹýÔì³ÉºÅÁîÖ´ÐеijÉЧ

¸üй¦·ò£º£º

20230214

 

ÊÂÎñÃû³Æ£º£º

TCP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Oracle_Weblogic_T3ºÍ̸[CVE-2020-2883]

°²È«ÀàÐÍ£º£º

°²È«·ì϶

ÊÂÎñÃèÊö£º£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨£¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½£¬ÀýÈçJava¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£¡£CVE-2020-2555·ì϶Äܹ»Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»°²È«µÄextract²½Ö裬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£Ó°ÏìÁìÓò£º£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üй¦·ò£º£º

20230214