2020-06-30

°ä²¼¹¦·ò 2020-06-30

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_×¢Èë¹¥»÷_Apache_SkyWalking_GraphQL½Ó¿Ú_SQL×¢Èë·ì϶[CVE-2020-9483]

°²È«ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÊÔͼͨ¹ýApache_SkyWalking GraphQL½Ó¿ÚµÄSQL×¢Èë·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

Apache SkyWalkingÊÇÒ»¿îÀûÓûúÄÜ¼à¿Ø£¨APM£©¹¤¾ß £¬¶Ô΢·þÎñ¡¢ÔÆÔ­ÉúºÍÈÝÆ÷»¯ÀûÓÃÌṩ×Ô¶¯»¯¡¢¸ß»úÄÜµÄ¼à¿Ø¹æ»®¡£Æä¹Ù·½ÍøÕ¾ÏÔʾ £¬´óÁ¿µÄ¹úÄÚ»¥ÁªÍø¡¢ÒøÐÓ×¢Ãñº½µÈÁìÓòµÄ¹«Ë¾ÔÚʹÓô˹¤¾ß¡£Ô¶³Ì¹¥»÷ÕßÄܹ»Í¨¹ýApache SkyWalkingĬÈÏÊ¢¿ªµÄδÊÚȨGraphQL½Ó¿Ú»ú¹Ø¶ñÒâÒªÇó°ü½øÐÐ×¢Èë £¬³É¹¦ÀûÓô˷ì϶¿ÉÔì³ÉÃô¸ÐÊý¾Ýй©¡£

¸üй¦·ò£º

20200630














ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_ApacheSolr_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-12409]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃApache_Solr_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ £¬Í¨¹ýMlet¼ÓÔØÒ»¸öÔ¶¶Ë¶ñÒâMBeans £¬À´ÊµÏÖËÁÒâ´úÂëµÄÖ´ÐС£SolrÊÇApacheµÄ¶¥¼¶¿ªÔ´ÏîÄ¿ £¬¸ÃÏîÄ¿ÊÇʹÓÃJava¿ª·¢µÄ»ùÓÚluceneµÄÈ«Îı¾ËÑË÷·þÎñÆ÷¡£ÓÉÓÚĬÈÏÅäÖÃÎļþsolr.in.shÖеÄENABLE_REMOTE_JMX_OPTSÅäÖò»µ± £¬»áÆôÓÃJMX¼à¶½²¢½«Æä¶³öÔÚRMI_PORTÉÏ£¨Ä¬ÈÏÖµ= 18983£©¡£¹¥»÷ÕßÎÞÐè½øÐÐÈκÎÉí·ÝÑéÖ¤ £¬¾Í¿ÉÄܽӼûJMX £¬²¢ÇÒÄܹ»ÉÏ´«¶ñÒâ´úÂëÔÚSolr·þÎñÆ÷ÉÏÖ´ÐС£

¸üй¦·ò£º

20200630












ÊÂÎñÃû³Æ£º

DNS_ºóÃÅ_CobaltStrike_DnsBeacon_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Cobalt StrikeµÄdns beaconÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËdns beacon¡£

Cobalt StrikeÊdzÛÃûµÄÉøÈë²âÊÔ¹¤¾ß £¬ËüÓÐÒ»¸ödns beaconºóÃÅ £¬Ö§³Öͨ¹ýdnsºÍ̸´«ÊäÊý¾Ý¡£

¸üй¦·ò£º

20200630










ÊÂÎñÃû³Æ£º

TCP_°²È«·ì϶_Microsoft_SMBv1_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-1301]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»ú¿ÉÄÜÔÚ¶ÔÖ÷ÕÅÖ÷»ú½øÐÐCVE-2020-1301·ì϶ÀûÓõÄÐÐΪ¡£

¸üй¦·ò£º

20200630







ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Gh0st.B3165_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËGh0st.B3165¡£

Gh0st.B3165ÊÇÀûÓÃÒ»¸öƾ¾ÝGh0stÔ¶¿ØµÄÔ´ÂëÅú¸Ä¶øÀ´µÄºóÃÅ¡£ÔËÐкó¿ÉÆëÈ«½ÚÔì±»Ö²Èë»úе¡£

¸üй¦·ò£º

20200630










Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Àà²Ëµ¶Á÷Á¿_ÏìÓ¦

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

Öйú²Ëµ¶ÊÇÖйúºÚ¿ÍȦÄÚʹÓü«¶È¿í·ºµÄÒ»¿îWebshellÖÎÀí¹¤¾ß¡£Öйú²Ëµ¶Óô¦¼«¶È¿í·º,Ö§³Ö¶àÖÖ˵»°,Ó×ÇÉʵÓà £¬ÓµÓÐÎļþÖÎÀí£¨ÓÐ×ã¹»µÄȨÏÞʱ³½Äܹ»ÖÎÀíÕû¸ö´ÅÅÌ/Îļþϵͳ£© £¬Êý¾Ý¿âÖÎÀí £¬Ðé¹¹Öն˵ÈÖ°ÄÜ¡£¶ÔÓÚÕâÀàÖÎÀí¹¤¾ß £¬ÈôÊÇûÓдóÁ¿µÄÅú¸Ä·þÎñ¶Ë¾ç±¾´úÂë £¬Æä·µ»ØÁ÷Á¿³ÇÊÐÓÐһЩ³£¼ûµÄÌØµã £¬±¾ÌõÎÄÔò½«³£¼ûµÄ¹²Í¬ÌصãÌáÈ¡³öÀ´½øÐзÀÓùÐÔ±¨¾¯¡£ÓÉÓÚ´ËÊÂÎñΪ½ÏΪ¿í·ºµÄͨÓÃÌØµã £¬¿ÉÄÜ´æÔÚÎó±¨ £¬Çë²Î¿¼ÌصãÐÔÖÊÅжÏ×ֶνøÐÐÅжÏ¡£

¸üй¦·ò£º

20200630












ÊÂÎñÃû³Æ£º

TCP_ͨÓÃ_Java·´ÐòÁл¯_ysoserial¶ñÒâÊý¾ÝÀûÓÃ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚͨ¹ýTCP·¢ËÍysoserialÌìÉúµÄ¶ñÒâJAVA·´ÐòÁл¯Êý¾Ý¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷¡£

Èô½Ó¼ûµÄÀûÓôæÔÚ·ì϶JAVA·´ÐòÁл¯·ì϶ £¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄJavaÐòÁл¯¶ÔÏó £¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£

¸üй¦·ò£º

20200630