ÿÖÜÉý¼¶²¼¸æ-2022-01-18

°ä²¼¹¦·ò 2022-01-18

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´® £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪӵÓп϶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈÆ¹ýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20220118


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_DedeCMSV6.0.3_article_string_mix.php_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

DedeCMSV6ϵͳ»ùÓÚPHP7.X¿ª·¢ £¬ÓµÓкÜÇ¿µÄ¿ÉÀ©´óÐÔ £¬²¢ÇÒÆëȫʢ¿ªÔ´´úÂë¡£Æäºó¶Üarticle_string_mix.phpÎļþ´æÔÚÔ¶³Ì´úÂëÖ´Ðзì϶ £¬¹¥»÷Õß¿ÉÀûÓô˷ì϶Äõ½Ö¸±êÖ÷»úȨÏÞ¡£

¸üй¦·ò£º

20220118

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_À¶ÁèOA_admin.do_JNDIÔ¶³ÌºÅÁîÖ´ÐÐ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Àö½­ÊÐÀ¶ÁèÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Êý×ÖOA(EKP)´æÔÚËÁÒâÎļþ¶ÁÈ¡·ì϶¡£¹¥»÷Õß¿ÉÀûÓ÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢ £¬¶ÁÈ¡ÅäÖÃÎļþµÃµ½ÃÜÔ¿ºó½Ó¼ûadmin.do¼´¿ÉÀûÓÃJNDIÔ¶³ÌºÅÁîÖ´ÐлñȡȨÏÞ¡£

¸üй¦·ò£º

20220118


 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Pupy_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Óɺڿ͹¤¾ßPupyÌìÉúµÄhttpÔ¶¿ØºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËPupyÔ¶¿ØºóÃÅ¡£Ö´Ðкó £¬¹¥»÷Õß¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе £¬²¢½øÐкáÏòÒÆ¶¯¡£PupyÊÇÒ»¸öpython±àдµÄ¿çƽ̨¡¢¶àÖ°ÄÜÔ¶¿ØºóÃźͺóÉøÈ빤¾ß¡£ËüÓµÓÐall-in-memoryÖ´ÐÐÖ°ÄÜ £¬Õ¼Óÿռ伫¶ÈÓס£PupyÄܹ»Ê¹ÓöàÖÖ·½Ê½½øÐÐͨѶ £¬Ê¹Ó÷´Éä×¢ÈëǨáãµ½¹ý³ÌÖÐ £¬²¢´ÓÄÚ´æ¼ÓÔØÔ¶³Ìpython´úÂë¡¢python°üºÍpythonC-extensions¡£

¸üй¦·ò£º

20220118


 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Zhone-Technologies-zNID-GPON-2426A_ºÅÁîÖ´ÐÐ[CVE-2014-9118][CNNVD-201510-721]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ZhoneTechnologieszNIDGPON2426AÊÇÃÀ¹úZhoneTechnologies¹«Ë¾µÄÒ»¿î·ÓÉÆ÷¡£webadministrativeportalÊÇÆäÖеÄÒ»¸öWebÖÎÀíÔ±½ÚÔį̀·¨Ê½¡£ZhoneTechnologieszNIDGPON2426AS3.0.501֮ǰ°æ±¾µÄWebÖÎÀíÔ±½ÚÔį̀ÖдæÔÚ°²È«·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏòzhnping.cmdÎļþ·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®ipAddr¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20220118