2021-04-08
Ðû²¼Ê±¼ä 2021-04-09ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳ_ÌìÇæ_ǰ̨SQL×¢Èë |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæÇ°Ì¨SQL×¢ÈëÎó²î¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îдÈëwebshellµÈ¶ñÒâÎļþ£¬£¬£¬£¬´Ó¶øgetshell¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA8ǰ̨SQLÖ´ÐÐÎó²î¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îÅÌÎʳöºǫ́ÃÜÂëµÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA9ǰ̨ÎÞÏÞÖÆGetshellÎó²î¡£¡£¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îÖ±½ÓÉÏ´«webshellµÈ¶ñÒâÎļþ£¬£¬£¬£¬´Ó¶øgetshell¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃeurekaµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«eureka.client.serviceUrl.defaultZoneÉèÖÃΪ¶ñÒâÍøÕ¾¡£¡£¡£¡£¡£¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬£¬£¬£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬£¬£¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬£¬£¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ɾ³ýÊÂÎñ
1¡¢HTTP_ľÂíºóÃÅ_ASP_webshellÒ»¾ä»°Ä¾ÂíÏÂÔØ


¾©¹«Íø°²±¸11010802024551ºÅ