ÿÖÜÉý¼¶²¼¸æ-2023-02-07

°ä²¼¹¦·ò 2023-02-07

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Merlin_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Merlin_agentÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMerlinagent¡£¡£¡£¡£¡£¡£MerlinagentÊÇÒ»¸öÖ°Äܼ«¶È׳´óµÄºóÃÅ£¬ £¬£¬£¬£¬ÔËÐкó£¬ £¬£¬£¬£¬Äܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õ߯ëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õß½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_F5_BIGIP_WSDLÌåʽ×Ö·û´®·ì϶[CVE-2023-22374]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

F5BIG-IPµÄiControlPortal.cgi½Ó¿Ú´æÔÚ·ì϶£¬ £¬£¬£¬£¬¹¥»÷ÕßÔÚ¾­¹ýÉí·ÝУÑéµÄÇé¿öÏ¿Éͨ¹ý»ú¹ØÌØÊâpayload£¬ £¬£¬£¬£¬Ê¹Ö¸±êÖ÷»ú·þÎñ±ÀÀ£»£»£»£»£»ò»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£¡£¡£¡£´ËÎÊÌâ½öÓ°ÏìBIG-IP(²»Ó°ÏìBIG-IQ)Ó°Ïì°æ±¾:F5BIG-IP17.0.0F5BIG-IP16.1.2.2-16.1.3F5BIG-IP15.1.5.1-15.1.8F5BIG-IP14.1.4.6-14.1.5F5BIG-IP13.1.5

¸üй¦·ò£º

20230207


 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_HinataBot_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½HinataBotÊÔͼÏνÓC&C·þÎñÆ÷£¬ £¬£¬£¬£¬Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçHinataBot¡£¡£¡£¡£¡£¡£HinataBotÊÇGo˵»°±àдµÄDDoS½©Ê¬ÍøÂ磬 £¬£¬£¬£¬ÖØÒªÖ°ÄÜÊǶÔÖ¸¶¨Ö¸±êÌáÒéDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¹²Ö§³Ölinux¡¢windows¡¢freebsd¡¢netbsd¡¢openbsd¡¢solaris¡¢darwin¡¢dragonfly¡¢plan9¡¢androidµÈ10¸ö²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£Ö§³Ö386¡¢amd64¡¢arm¡¢mips¡¢ppcµÈ¶à¸öÖ¸Á¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_APISIX_ĬÈÏÃÜÔ¿[CVE-2020-13945][CNNVD-202012-424]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃApacheAPISIXµÄĬÈÏÃÜÔ¿·ì϶½øÐй¥»÷£¬ £¬£¬£¬£¬ÔÚÓû§Î´Ö¸¶¨ÖÎÀíÔ±Token»òʹÓÃÁËĬÈÏÅäÖÃÎļþµÄÇé¿öÏ£¬ £¬£¬£¬£¬ApacheAPISIX½«Ê¹ÓÃĬÈϵÄÖÎÀíÔ±Tokenedd1c9f034335f136f87ad84b625c8f1£¬ £¬£¬£¬£¬¹¥»÷ÕßÀûÓÃÕâ¸öTokenÄܹ»½Ó¼ûµ½ÖÎÀíÔ±½Ó¿Ú£¬ £¬£¬£¬£¬½ø¶øÍ¨¹ýscript²ÎÊýÀ´²åÈëËÁÒâLUA¾ç±¾²¢Ö´ÐС£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Gh0st.Get_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Gh0st.GetÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£¡£¡£¡£¡£¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿ØºóÃÅGh0st.Get¡£¡£¡£¡£¡£¡£Gh0st.GetÊÇÀûÓÃÒ»¸öƾ¾ÝGh0stÔ¶¿ØµÄÔ´ÂëÅú¸Ä¶øÀ´µÄÔ¶¿ØºóÃÅ£¬ £¬£¬£¬£¬ÔËÐкóÄܹ»ÆëÈ«½ÚÔì±»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207


 

ÊÂÎñÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_LiteHTTP_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½LiteHTTPÊÔͼÏνÓC&C·þÎñÆ÷¡£¡£¡£¡£¡£¡£LiteHTTPÊÇÒ»¸öʹÓÃC#±àдµÄ¿ªÔ´½©Ê¬ÍøÂç¶ñÒâÈí¼þ£¬ £¬£¬£¬£¬ÏîÄ¿µØÖ·Îª£ºhttps://github.com/zettabithf/LiteHTTP£¬ £¬£¬£¬£¬ÏîÄ¿ÓÐ3¸öĿ¼£¬ £¬£¬£¬£¬BotÊDz¡¶¾·¨Ê½µÄ´úÂ룬 £¬£¬£¬£¬PanelÊǽÚÔì¶ËµÄ´úÂ룬 £¬£¬£¬£¬Ê¹ÓÃPHP±àд£¬ £¬£¬£¬£¬BuilderÊÇÒ»¸öÌìÉúÆ÷£¬ £¬£¬£¬£¬ÓÃÓÚ¼±¾çÌìÉú²¡¶¾·¨Ê½¡£¡£¡£¡£¡£¡£LiteHTTPÄܹ»ÍøÂçÖ÷»úÐÅÏ¢£¬ £¬£¬£¬£¬Ê¹ÓÃÔ¤ÏÈÔ¼¶¨µÄÃÜÔ¿½øÐмÓÃÜ£¬ £¬£¬£¬£¬¶øºó½«¼ÓÃܺóµÄÐÅÏ¢ÒÔHTTPµÄ·½Ê½ÉÏ´«ÖÁ½ÚÔì¶Ë·þÎñÆ÷£¬ £¬£¬£¬£¬½ÓÊܽÚÔì¶ËµÄ½ÚÔìÂë²¢Ö´ÐÐÏàÓ¦µÄ²Ù×÷£¬ £¬£¬£¬£¬ÉÏ´«Ö´ÐеÄÁ˾Ö¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Zimbra_ÎļþÉÏ´«[CVE-2022-27925][CVE-2022-37042][CNNVD-202204-3909]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

ZimbraCollaborationSuite(ZCS)8.8.15ºÍ9.0ÓµÓÐmboximportÖ°ÄÜ£¬ £¬£¬£¬£¬¿É½Ó¹ÜZIP´æµµ²¢´ÓÖÐÌáÈ¡Îļþ¡£¡£¡£¡£¡£¡£Í¨¹ýÈÆ¹ýÉí·ÝÑéÖ¤£¨¼´Ã»ÓÐÉí·ÝÑéÖ¤ÁîÅÆ£©£¬ £¬£¬£¬£¬¹¥»÷ÕßÄܹ»½«ËÁÒâÎļþÉÏ´«µ½ÏµÍ³£¬ £¬£¬£¬£¬´Ó¶øµ¼ÖÂĿ¼±éÀúºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨£¬ £¬£¬£¬£¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½£¬ £¬£¬£¬£¬ÀýÈçJava¡£¡£¡£¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£¡£¡£¡£¡£¡£ÓÉÓÚForeignOpaqueReferenceÀà´æÔÚ°²È«ÎÊÌ⣬ £¬£¬£¬£¬CVE-2023-21839·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬ £¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£Ó°ÏìÁìÓò£ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_ZOHO_ManageEngine_Desktop_Central_statusUpdate[CVE-2014-5005]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃZOHOManageEngineDesktopCentralÖдæÔڵķì϶½øÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ZOHOManageEngineDesktopCentral£¨DC£©ÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÒ»Ì××ÀÃæÖÎÀí½â¾ö¹æ»®¡£¡£¡£¡£¡£¡£¸Ã¹æ»®Ô̺¬Èí¼þ·Ö·¢¡¢²¹¶¡ÖÎÀí¡¢ÏµÍ³ÅäÖá¢Ô¶³Ì½ÚÔìµÈÖ°ÄÜÄ£¿£¿£¿£¿£¿£¿é£¬ £¬£¬£¬£¬¿É¶Ô×ÀÃæ»úÒÔ¼°·þÎñÆ÷ÖÎÀíµÄÕû¸öÐÔÃüÖÜÆÚÌṩ֧³Ö¡£¡£¡£¡£¡£¡£ZOHOManageEngineDC9build90055֮ǰ°æ±¾ÖдæÔÚÒ»¸öĿ¼±éÀúÔì³ÉµÄËÁÒâÎļþÉÏ´«·ì϶£¬ £¬£¬£¬£¬¸Ã·ì϶ԴÓÚ·¨Ê½Ö´ÐÐLFU²Ù×÷ʱ£¬ £¬£¬£¬£¬statusUpdateûÓгä·Ö¹ýÂË¡®fileName¡¯²ÎÊý£¬ £¬£¬£¬£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúĿ¼±éÀú×Ö·û¡®..¡¯£¬ £¬£¬£¬£¬ÉÏ´«ËÁÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Splunk_´úÂëÖ´ÐÐ[CVE-2022-43571]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

SplunkEnterpriseÊÇ»úеÊý¾ÝµÄÒýÇæ¡£¡£¡£¡£¡£¡£Ê¹ÓÃSplunk¿ÉÍøÂç¡¢Ë÷ÒýºÍÀûÓÃËùÓÐÀûÓ÷¨Ê½¡¢·þÎñÆ÷ºÍÉ豸ÌìÉúµÄ¼±¾çÒÆ¶¯ÐÍÍÆËã»úÊý¾Ý¡£¡£¡£¡£¡£¡£¹ØÁª²¢·ÖÎöÓâÔ½¶à¸öϵͳµÄ¸´ÔÓÊÂÎñ¡£¡£¡£¡£¡£¡£»£»£»£»£»ñȡеµ´ÎµÄÔËÓª¿É¼ûÐÔÒÔ¼°ITºÍÒµÎñÖÇÄÜ¡£¡£¡£¡£¡£¡£ÓÉÓÚSplunkEnterpriseÖÐSimpleXMLÒDZí°å´æÔÚ´úÂë×¢È룬 £¬£¬£¬£¬¾­¹ýÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õ߿ɻú¹ØÌØÔìµÄÊý¾Ý°ü£¬ £¬£¬£¬£¬Í¨¹ýPDFµ¼³ö²Ù×÷´¥·¢ËÁÒâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230207