2020-03-10

°ä²¼¹¦·ò 2020-03-11

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

CMS¹¥»÷¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´ÐÐ[CVE-2020-9548]¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ

¸üй¦·ò£º

20200310







ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉ.NET·´ÐòÁл¯Êý¾Ý

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ¶Ô¿ÉÄÜ´æÔÚ.NET·´ÐòÁл¯·ì϶µÄÒ³Ãæ·¢ËÍ¿ÉÒÉ·´ÐòÁл¯Êý¾Ý

¹¥»÷Õß¿ÉÌá½»¾«ÐÄ»ú¹ØµÄ·´ÐòÁл¯Êý¾ÝÀ´ÀûÓô˷ì϶¡£¡£¡£¡£¡£¡£¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÖ´ÐÐËÁÒâ´úÂë¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310









ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_CharmingKitten.Backdoor_ÊÔͼÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ CharmingKitten.Backdoor ÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷,Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCharmingKitten.Backdoor¡£¡£¡£¡£¡£¡£¡£

CharmingKitten.BackdoorÊÇCharming Kitten×éÖ¯µÄÒ»¸öºóÃÅ £¬£¬£¬£¬£¬Ëü»áÇÔÈ¡Óû§µÄÍÆËã»úÐÅÏ¢ £¬£¬£¬£¬£¬Èç²Ù×÷ϵͳÐÅÏ¢¡¢ipµØÖ·µÈ £¬£¬£¬£¬£¬²¢ÇÒ»¹»á´ÓÔ¶³Ì·þÎñÆ÷ÏÂÔØÎļþÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310










ÊÂÎñÃû³Æ£º

UDP_½©Ê¬ÍøÂç_Mozi.P2PBotnet_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçMoziÊÔͼºÍPeerͨѶ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÊÇ»ùÓÚP2PºÍ̸ £¬£¬£¬£¬£¬Ô´IPºÍÖ÷ÕÅIPµØµãµÄÖ÷»ú¿ÉÄܶ¼±»Ö²ÈëÁ˽©Ê¬ÍøÂçMozi¡£¡£¡£¡£¡£¡£¡£

MoziÊÇÒ»¸ö»ùÓÚP2PºÍ̸µÄ½©Ê¬ÍøÂç £¬£¬£¬£¬£¬ÖØÒªÖ§³ÖµÄÖ°ÄÜΪ£ºDDoS¹¥»÷¡¢ÍøÂçBotÐÅÏ¢¡¢Ö´ÐÐÖ¸¶¨URLµÄpayload¡¢´ÓÖ¸¶¨µÄURL¸üÐÂÑù±¾¡¢Ö´ÐÐϵͳ»ò×Ô½ç˵ºÅÁî¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310










Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_MiraiXMiner_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçMiraiXMinerÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMiraiXMiner¡£¡£¡£¡£¡£¡£¡£

MiraiXMinerÊÇÒ»¸öÒÀÈ»»îÔ¾×ŵĽ©Ê¬ÍøÂç £¬£¬£¬£¬£¬ÈÚºÏÁ˶àÖÖÒÑÖª²¡¶¾¼Ò×å £¬£¬£¬£¬£¬Ô̺¬Mirai¡¢MyKings¡¢Ô¶¿Ø¡¢ÍÚ¿óµÈ¡£¡£¡£¡£¡£¡£¡£ÀûÓÃÓÀºãÖ®À¶·ì϶¡¢¹ØÂ·µçÊÓÎïÁªÍøÉ豸·ì϶¡¢MSSQL·ì϶¡¢RDP±¬ÆÆºÍTelnet±¬ÆÆµÈ·½Ê½´«²¼×ÔÉí¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310











ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ircBotÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£¡£¡£¡£¡£

ircBotÊÇ»ùÓÚircºÍ̸µÄ½©Ê¬ÍøÂç £¬£¬£¬£¬£¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±êÖ÷»úÌáÒéDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¡£»£»£»£»£»£»£»£»¹Äܹ»ÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310









ÊÂÎñÃû³Æ£º

TCP_Windows_ϵͳĬÈϹ²ÏíÏνÓ

°²È«ÀàÐÍ£º

°²È«Éó¼Æ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐĬÈÏÏνӵÄÐÐΪ.¡£¡£¡£¡£¡£¡£¡£

WindowsÆô¶¯Ê±³ÇÊÐĬÈÏ´ò¿ªadmin$ ipc$ ºÍÿ¸öÅÌ·ûµÄ¹²Ïí £¬£¬£¬£¬£¬¹¥»÷Õßͨ³£»£»£»£»£»£»£»£»áÀûÓù²Ïí·ì϶ÈëÇÖµçÄÔÖ÷»ú¡£¡£¡£¡£¡£¡£¡£

±¨¾¯¸ÃÊÂÎñ×¢Ã÷Óпͻ§¶ËÔÚÔ¶³ÌÏνӸ÷þÎñÆ÷ £¬£¬£¬£¬£¬²¢ÇÒÓÐÅú¸Ä·þÎñ¶ËÎļþµÄÐÐΪ £¬£¬£¬£¬£¬ÈôÊÇ·þÎñ¶Ë»·¾³×ÔÉí¾ÍÓÐʹÓÃsmbÓйØÖ°ÄܵÄÒµÎñ £¬£¬£¬£¬£¬Äܹ»ºöÂÔ¸ÃÊÂÎñ¡£¡£¡£¡£¡£¡£¡£ÈôÊÇÏëÒª²»ÈÝC$¡¢D$¡¢E$Ò»ÀàµÄ¹²Ïí £¬£¬£¬£¬£¬Äܹ»µ¥»÷¡°ÆðÍ·¡úÔËÐÓ×±ºÅÁî £¬£¬£¬£¬£¬ÔÚÔËÐд°¿Ú¼üÈë¡°Regedit¡±ºó»Ø³µ £¬£¬£¬£¬£¬´ò¿ª×¢²á±í±à×ëÆ÷¡£¡£¡£¡£¡£¡£¡£Ë³´Î·¢Õ¹[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters ]·ÖÖ§ £¬£¬£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareServer¡±ÉèÖÃΪ¡°0¡±¼´¿É¡£¡£¡£¡£¡£¡£¡£  ÈôÊÇÒª²»ÈÝADMIN$¹²Ïí £¬£¬£¬£¬£¬Äܹ»ÔÚͬÑùµÄ·ÖÖ§Ï £¬£¬£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°AutoShareWKs¡± ÉèÖÃΪ¡°0¡±¼´¿É¡£¡£¡£¡£¡£¡£¡£  ÈôÊÇÒª²»ÈÝIPC$¹²Ïí £¬£¬£¬£¬£¬Äܹ»ÔÚ×¢²á±í±à×ëÆ÷ÖÐ˳´Î·¢Õ¹[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]·ÖÖ§ £¬£¬£¬£¬£¬½«ÓҲര¿ÚÖеÄDOWRDÖµ¡°restrictanonymous¡±ÉèÖÃֵΪ¡°1¡±¼´¿É¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310





















ÊÂÎñÃû³Æ£º

HTTP_Java·´ÐòÁл¯_POST·½Ê½_ysoserial¶ñÒâÊý¾Ý

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Java·´ÐòÁл¯_POST·½Ê½_ysoserial¶ñÒâÊý¾Ý¶ÔÖ÷ÕÅÖ÷»ú½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¡£

Èô½Ó¼ûµÄÒ³Ãæ´æÔÚ·ì϶ £¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»·¢Ë;«ÐÄ»ú¹ØµÄ Java ÐòÁл¯¶ÔÏó £¬£¬£¬£¬£¬Ô¶³ÌÖ´ÐÐËÁÒâ´úÂë»òºÅÁî¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20200310