2021-04-07

Ðû²¼Ê±¼ä 2021-04-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_Dubbo·´ÐòÁл¯Îó²î[CVE-2020-1948][CNNVD-202006-1649]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApache_Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£µ±DubboЧÀͶË̻¶ʱ(ĬÈ϶˿ڣº20880)£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍδÂÄÀúÖ¤µÄЧÀÍÃû»òÒªÁìÃûµÄRPCÇëÇ󣬣¬£¬£¬£¬Í¬Ê±ÅäºÏ¸½¼Ó¶ñÒâµÄ²ÎÊý¸ºÔØ£»£»£»£»£»ApacheDubboÊÇÒ»ÖÖ»ùÓÚJavaµÄ¸ßÐÔÄÜRPC¿ò¼Ü¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspx_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-057Ô¶³Ì´úÂëÖ´Ðй¥»÷[CVE-2018-11776]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÔÚ¶Ô·½Struts2µÄXMLÉèÖÃÖеÄnamespaceֵδÉèÖÃÇÒ£¨ActionConfiguration£©ÖÐδÉèÖûòÓÃͨÅä·ûnamespaceʱʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºStruts2.0.4-Struts2.3.34£¬£¬£¬£¬£¬Struts2.5.0-Struts2.5.16ʵÑéÀûÓÚStruts2S2-057¾Ü¾øÐ§ÀÍÎó²î¹¥»÷¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬ÆäÖÐÔ¶³Ì´úÂëÈÆ¹ýÁËFastjson1.2.66¼°ÒÔǰ°æ±¾µÄºÚÃûµ¥£¬£¬£¬£¬£¬¹¥»÷ÁËʹÓÃÁËcom.caucho.config.types.ResourceRefÀàµÄÄ¿µÄÖ÷»ú¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-Shiro_Ô¶³Ì´úÂ룬£¬£¬£¬£¬Í¨¹ýJNDI×¢È룬£¬£¬£¬£¬Ö´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XXL_JOB_δÊÚȨ»á¼ûÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶ÂþÑÜʽʹÃüµ÷ÀíÆ½Ì¨¡£¡£¡£¡£¡£Ä¬ÈÏÇéÐÎÏÂXXL-JOBµÄRestfulAPI½Ó¿Ú»òRPC½Ó¿ÚûÓÐÉèÖÃÈÏÖ¤²½·¥£¬£¬£¬£¬£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬Ôì³ÉÔ¶³ÌÖ´ÐÐÏÂÁ£¬£¬£¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210407