2020-07-07

Ðû²¼Ê±¼ä 2020-07-09

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Liferay_Portal_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-7961]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

LiferayÊÇÒ»¸ö¿ªÔ´µÄPortal(ÈÏÖ¤)²úÆ·,Ìṩ¶Ô¶à¸ö×ÔÁ¦ÏµÍ³µÄÄÚÈݼ¯³É,ΪÆóÒµÐÅÏ¢¡¢Á÷³ÌµÈµÄÕûºÏÌṩÁËÒ»Ì×ÍêÕûµÄ½â¾ö¼Æ»®,ºÍÆäËûÉÌÒµ²úÆ·Ïà±È,LiferayÓÐ×ÅÐí¶àÓÅÁ¼µÄÌØÕ÷,²¢ÇÒÃâ·Ñ,ÔÚÈ«Çò¶¼Óн϶àÓû§¡£¡£¡£¡£ÔÚLiferay6.1.x-7.2.x°æ±¾Öб£´æÍ¨¹ýδÊÚȨ»á¼ûµÄapi½á¹¹jsonÓï¾äµ¼Ö·´ÐòÁл¯Îó²î½ø¶øÖ´Ðй¥»÷Õß´úÂëÏÂÁîµÄÎó²î¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707











ÊÂÎñÃû³Æ£º

HTTP_F5_BIG_IP_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

F5 BIG-IPÊÇÃÀ¹úF5¹«Ë¾µÄÒ»¿î¼¯³ÉÍøÂçÁ÷Á¿ÖÎÀí£¬ £¬£¬Ó¦ÓóÌÐòÇå¾²ÖÎÀí£¬ £¬£¬¸ºÔØÆ½ºâµÈ¹¦Ð§µÄÓ¦Óý»¸¶Æ½Ì¨¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707








ÊÂÎñÃû³Æ£º

DNS_ºóÃÅ_Worm.Morto_ÅþÁ¬

Çå¾²ÀàÐÍ£º

È䳿²¡¶¾

ÊÂÎñÐÎò£º

¼ì²âµ½È䳿MortoÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMorto¡£¡£¡£¡£

MortoÊÇÒ»ÖÖÈ䳿£¬ £¬£¬Ê¹ÓÃRDP¼´Ô¶³Ì×ÀÃæÐ­ÒéÀ´Èö²¥¡£¡£¡£¡£MortoÀïÄÚǶÁ˳£¼ûÈõ¿ÚÁ £¬£¬Ê¹ÓÃÈõ¿ÚÁîµÇ¼Զ³Ì×ÀÃæÀֳɣ¬ £¬£¬¼´°Ñ×ÔÉíÈö²¥ÒÑÍù¡£¡£¡£¡£×èÖ¹µ½ÏÖÔÚ£¬ £¬£¬ÔÚº£ÄÚÈÔÈ»ºÜÊÇ»£» £»îÔ¾¡£¡£¡£¡£

Mortoͨ¹ýDNSЭÒéÓëÆäC&CͨѶ£¬ £¬£¬¿ÉÒÔÖ´ÐÐC&C·¢ËÍÀ´µÄÖÖÖÖÏÂÁ £¬£¬ÈçÏÂÔØ¡¢DDoS¹¥»÷µÈ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707












ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Apache_Shiro_Éí·ÝÑéÖ¤ÈÆ¹ýÎó²î[CVE-2020-11989]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

Apache ShiroÊÇÒ»¸öǿʢÇÒÒ×ÓõÄJavaÇå¾²¿ò¼Ü£¬ £¬£¬Ëü¿ÉÒÔÓÃÀ´Ö´ÐÐÉí·ÝÑéÖ¤¡¢ÊÚȨ¡¢ÃÜÂëºÍ»á»°ÖÎÀí¡£¡£¡£¡£ÏÖÔÚ³£¼û¼¯³ÉÓÚÖÖÖÖÓ¦ÓÃÖоÙÐÐÉí·ÝÑéÖ¤£¬ £¬£¬ÊÚȨµÈ¡£¡£¡£¡£¹ØÓÚApache Shiro 1.5.3֮ǰµÄ°æ±¾£¬ £¬£¬µ±½«Apache ShiroÓëSpring¿ØÖÆÆ÷Ò»ÆðʹÓÃʱ£¬ £¬£¬¹¥»÷ÕßÌØÖÆÇëÇó¿ÉÄܻᵼÖÂÉí·ÝÑéÖ¤ÈÆ¹ý¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707










ÊÂÎñÃû³Æ£º

HTTP_ͨ´ïOA_ǰ̨í§ÒâÓû§µÇ¼Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_ͨ´ïOA_ǰ̨í§ÒâÓû§µÇ¼Îó²î¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¸ÃÎó²î¿ÉÔì³Éǰ̨ÎÞÐèÃÜÂëµÇ¼ÖÎÀíÔ±Õ˺Å£¬ £¬£¬¹¥»÷ÕßʹÓÃÎó²î½øÈëºǫ́ºó¿ÉÅäºÏÎļþÉÏ´«Îó²î»ñȡЧÀÍÆ÷¿ØÖÆÈ¨£¬ £¬£¬Î£º¦ÑÏÖØ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707










ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓúÜÊÇÆÕ±éµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£¡£¡£¡£Öйú²Ëµ¶ÓÃ;ʮ·ÖÆÕ±é,Ö§³Ö¶àÖÖÓïÑÔ,СÇÉÊÊÓ㬠£¬£¬¾ßÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ¼ä¿ÉÒÔÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£©£¬ £¬£¬Êý¾Ý¿âÖÎÀí£¬ £¬£¬ÐéÄâÖն˵ȹ¦Ð§¡£¡£¡£¡£¹ØÓÚÕâÀàÖÎÀí¹¤¾ß£¬ £¬£¬ÈôÊÇûÓдó×ÚµÄÐÞ¸ÄЧÀͶ˾籾´úÂ룬 £¬£¬Æä·µ»ØÁ÷Á¿¶¼»áÓÐһЩ³£¼ûµÄÌØÕ÷£¬ £¬£¬±¾Ìõ¹æÔò½«³£¼ûµÄÅäºÏÌØÕ÷ÌáÈ¡³öÀ´¾ÙÐзÀÓùÐÔ±¨¾¯¡£¡£¡£¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØÕ÷£¬ £¬£¬¿ÉÄܱ£´æÎ󱨣¬ £¬£¬Çë²Î¿¼ÌØÕ÷ÐÔ×ÓÅжÏ×ֶξÙÐÐÅжÏ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707












ÊÂÎñÃû³Æ£º

HTTP_ÈÏÖ¤ÇëÇó

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¸ÃÊÂÎñÅú×¢ÓÐÓû§ÕýÔÚÏòHTTPЧÀÍÆ÷·¢ËÍ»ù±¾ÈÏÖ¤ÇëÇ󡣡£¡£¡£

HTTP»ù±¾ÈÏÖ¤²î±ðÓÚSSL£¬ £¬£¬SSLÌṩ¶ÔÃô¸ÐÊý¾Ý¼ÓÃÜ´«ÊäµÄ»úÖÆ£¬ £¬£¬¶øHTTP»ù±¾ÈÏÖ¤ÌṩÁ˶ÔÊܱ£»£» £»¤×ÊÔ´µÄ»á¼û¿ØÖÆÕ½ÂÔ¡£¡£¡£¡£

ÔÚHTTPЭÒé¾ÙÐÐͨѶµÄÀú³ÌÖУ¬ £¬£¬HTTPЭÒé½ç˵ÁË»ù±¾ÈÏÖ¤Àú³ÌÒÔÔÊÐíHTTPЧÀÍÆ÷¶ÔWEBä¯ÀÀÆ÷¾ÙÐÐÓû§Éí·ÝÈÏÖ¤µÄÒªÁì¡£¡£¡£¡£µ±Ò»¸ö¿Í»§¶ËÏòHTTPЧÀÍÆ÷¾ÙÐÐÊý¾ÝÇëÇóʱ£¬ £¬£¬ÈôÊǿͻ§¶Ëδ±»ÈÏÖ¤£¬ £¬£¬ÔòHTTPЧÀÍÆ÷½«Í¨¹ý»ù±¾ÈÏÖ¤Àú³Ì¶Ô¿Í»§¶ËµÄÓû§Ãû¼°ÃÜÂë¾ÙÐÐÑéÖ¤£¬ £¬£¬ÒÔ¾öÒéÓû§ÊÇ·ñÕýµ±¡£¡£¡£¡£

¿Í»§¶ËÔÚÎüÊÕµ½HTTPЧÀÍÆ÷µÄÉí·ÝÈÏÖ¤ÒªÇóºó£¬ £¬£¬»áÌáÐÑÓû§ÊäÈëÓû§Ãû¼°ÃÜÂ룬 £¬£¬¿Í»§¶Ë½«Óû§ÃûºÍÃÜÂëÓá°£º¡±ºÏ²¢£¬ £¬£¬²¢½«ºÏ²¢ºóµÄ×Ö·û´®ÓÃBASE64¼ÓÃÜΪÃÜÎÄ£¬ £¬£¬²¢ÓÚÿ´ÎÇëÇóÊý¾Ýʱ£¬ £¬£¬½«ÃÜÎĸ½¼ÓÓÚÇëÇóÍ·£¨Request Header£©ÖС£¡£¡£¡£HTTPЧÀÍÆ÷ÔÚÿ´ÎÊÕµ½ÇëÇó°üºó£¬ £¬£¬Æ¾Ö¤Ð­ÒéÈ¡µÃ¿Í»§¶Ë¸½¼ÓµÄÓû§ÐÅÏ¢£¨BASE64¼ÓÃܵÄÓû§ÃûºÍÃÜÂ룩£¬ £¬£¬½â¿ªÇëÇó°ü£¬ £¬£¬¶ÔÓû§Ãû¼°ÃÜÂë¾ÙÐÐÑéÖ¤£¬ £¬£¬ÈôÊÇÓû§Ãû¼°ÃÜÂë׼ȷ£¬ £¬£¬Ôòƾ֤¿Í»§¶ËÇëÇó£¬ £¬£¬·µ»Ø¿Í»§¶ËËùÐèÒªµÄÊý¾Ý£»£» £»²»È»£¬ £¬£¬·µ»Ø¹ýʧ´úÂë»òÖØÐÂÒªÇó¿Í»§¶ËÌṩÓû§Ãû¼°ÃÜÂë¡£¡£¡£¡£

HTTP»ù±¾ÈÏÖ¤µÄÄ¿µÄÊÇÌṩ¼òÆÓµÄÓû§ÑéÖ¤¹¦Ð§£¬ £¬£¬ÆäÈÏÖ¤Àú³Ì¼òÆÓÃ÷Îú£¬ £¬£¬ÊʺÏÓÚ¶ÔÇå¾²ÐÔÒªÇ󲻸ߵÄϵͳ»ò×°±¸ÖС£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707






















ÊÂÎñÃû³Æ£º

TCP_SSHʵÑéµÇ¼

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú¾ÙÐÐSSHµÇ¼¿ÚÁî²Â½âµÄÐÐΪ¡£¡£¡£¡£

SSH Ϊ Secure Shell µÄËõд£¬ £¬£¬ÓÉ IETF µÄÍøÂçÊÂÇéС×飨Network Working Group£©ËùÖÆ¶©£»£» £»SSH Ϊ½¨ÉèÔÚÓ¦ÓòãºÍ´«Êä²ã»ù´¡ÉϵÄÇ徲ЭÒé¡£¡£¡£¡£SSH ÊÇÏÖÔڽϿɿ¿£¬ £¬£¬×¨ÎªÔ¶³ÌµÇ¼»á»°ºÍÆäËûÍøÂçЧÀÍÌṩÇå¾²ÐÔµÄЭÒé¡£¡£¡£¡£Ê¹Óà SSH ЭÒé¿ÉÒÔÓÐÓñÜÃâÔ¶³ÌÖÎÀíÀú³ÌÖеÄÐÅϢй¶ÎÊÌâ¡£¡£¡£¡£SSH×î³õÊÇUNIXϵͳÉϵÄÒ»¸ö³ÌÐò£¬ £¬£¬ØÊºóÓÖѸËÙÀ©Õ¹µ½ÆäËû²Ù×÷ƽ̨¡£¡£¡£¡£SSHÔÚ׼ȷʹÓÃʱ¿ÉÌî²¹ÍøÂçÖеÄÎó²î¡£¡£¡£¡£SSH¿Í»§¶ËÊÊÓÃÓÚ¶àÖÖÆ½Ì¨¡£¡£¡£¡£ÏÕЩËùÓÐUNIXƽ̨°üÀ¨HP-UX¡¢Linux¡¢AIX¡¢Solaris¡¢Digital UNIX¡¢Irix£¬ £¬£¬ÒÔ¼°ÆäËûƽ̨£¬ £¬£¬¶¼¿ÉÔËÐÐSSH¡£¡£¡£¡£

¹¥»÷Õß¾­³£»£» £»áʹÓÃһЩ±©Á¦ÆÆ½â¹¤¾ß¼ÓÉÏÃÜÂë×ÖµäµÄ·½·¨À´ÆÆ½âЧÀÍÆ÷µÄSSHµÇÈÎÃü»§¼°¿ÚÁî¡£¡£¡£¡£

¿ÚÁîÇî¾Ù̽²âÀàÊÂÎñ½ç˵Ϊ£ºÔÚÔ´IPµØµãÓëÄ¿µÄIPµØµãÏàͬµÄÇéÐÎÏ£¬ £¬£¬Í³¼Æµ¥Î»Ê±¼äÄڵǼʧ°ÜµÄ´ÎÊý£¬ £¬£¬Ä¬ÒÔΪһ·ÖÖÓÄڵǼʧ°ÜµÄ´ÎÊýÁè¼Ý20´Î£¬ £¬£¬¾Í»á´¥·¢¿ÚÁîÇî¾ÙÊÂÎñ£¬ £¬£¬¸ÃÊÂÎñµÄĬÈÏÐж¯ÊÇ×è¶ÏÔ´µØµã¡£¡£¡£¡£ÐèÌØÊâ˵Ã÷µÄÊÇ£¬ £¬£¬ÈôIPS»òWAF×°±¸´®Ðа²ÅÅÔÚÆôÓÃNAT(Network Address Translation£¬ £¬£¬ÍøÂçµØµãת»»)µÄÍøÂçÇéÐÎÖУ¬ £¬£¬¶à¸öÕæÊµµÄÔ´IP¿ÉÄܱ»×ª»»³ÉÒ»¸öÔ´IP£¬ £¬£¬¼«¶ËÇéÐÎÏ£¬ £¬£¬¶à¸öÓû§µÄÕý³£Éϰ¶Ê§°ÜʵÑéÒ²¿ÉÄܻᴥ·¢¿ÚÁîÇî¾Ù̽²âÊÂÎñ£¬ £¬£¬´Ëʱ¿ÉÒÔ˼Á¿½«¸ÃÊÂÎñµÄĬÈÏÏìÓ¦Ðж¯ÐÞ¸ÄΪͨ¹ý£¬ £¬£¬ÒÔÃâÓ°ÏìÕý³£ÓªÒµ¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707























ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Bitter.Rat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitter¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707







ÊÂÎñÃû³Æ£º

HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î
[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬ £¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬ £¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200707