ÿÖÜÉý¼¶Í¨¸æ-2023-02-07

Ðû²¼Ê±¼ä 2023-02-07

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Merlin_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Merlin_agentÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËMerlinagent¡£¡£¡£¡£¡£¡£MerlinagentÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬ÔËÐк󣬣¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£ÔÊÐí¹¥»÷Õß¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_´úÂëÖ´ÐÐ_F5_BIGIP_WSDLÃûÌÃ×Ö·û´®Îó²î[CVE-2023-22374]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

F5BIG-IPµÄiControlPortal.cgi½Ó¿Ú±£´æÎó²î£¬£¬¹¥»÷ÕßÔÚ¾­ÓÉÉí·ÝУÑéµÄÇéÐÎÏ¿Éͨ¹ý½á¹¹ÌØÊâpayload£¬£¬Ê¹Ä¿µÄÖ÷»úЧÀÍÍ߽⻣»£»ò»ñÈ¡Ö÷»úȨÏÞ¡£¡£¡£¡£¡£¡£´ËÎÊÌâ½öÓ°ÏìBIG-IP(²»Ó°ÏìBIG-IQ)Ó°Ïì°æ±¾:F5BIG-IP17.0.0F5BIG-IP16.1.2.2-16.1.3F5BIG-IP15.1.5.1-15.1.8F5BIG-IP14.1.4.6-14.1.5F5BIG-IP13.1.5

¸üÐÂʱ¼ä£º

20230207


 

ÊÂÎñÃû³Æ£º

TCP_½©Ê¬ÍøÂç_HinataBot_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½HinataBotÊÔͼÅþÁ¬C&CЧÀÍÆ÷£¬£¬Ô´IPÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˽©Ê¬ÍøÂçHinataBot¡£¡£¡£¡£¡£¡£HinataBotÊÇGoÓïÑÔ±àдµÄDDoS½©Ê¬ÍøÂ磬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÌᳫDDoS¹¥»÷¡£¡£¡£¡£¡£¡£¹²Ö§³Ölinux¡¢windows¡¢freebsd¡¢netbsd¡¢openbsd¡¢solaris¡¢darwin¡¢dragonfly¡¢plan9¡¢androidµÈ10¸ö²Ù×÷ϵͳ¡£¡£¡£¡£¡£¡£Ö§³Ö386¡¢amd64¡¢arm¡¢mips¡¢ppcµÈ¶à¸öÖ¸Á¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Apache_APISIX_ĬÈÏÃÜÔ¿[CVE-2020-13945][CNNVD-202012-424]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÖ÷»úÕýÔÚʹÓÃApacheAPISIXµÄĬÈÏÃÜÔ¿Îó²î¾ÙÐй¥»÷£¬£¬ÔÚÓû§Î´Ö¸¶¨ÖÎÀíÔ±Token»òʹÓÃÁËĬÈÏÉèÖÃÎļþµÄÇéÐÎÏ£¬£¬ApacheAPISIX½«Ê¹ÓÃĬÈϵÄÖÎÀíÔ±Tokenedd1c9f034335f136f87ad84b625c8f1£¬£¬¹¥»÷ÕßʹÓÃÕâ¸öToken¿ÉÒÔ»á¼ûµ½ÖÎÀíÔ±½Ó¿Ú£¬£¬½ø¶øÍ¨¹ýscript²ÎÊýÀ´²åÈëí§ÒâLUA¾ç±¾²¢Ö´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Gh0st.Get_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Gh0st.GetÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËÔ¶¿ØºóÃÅGh0st.Get¡£¡£¡£¡£¡£¡£Gh0st.GetÊÇʹÓÃÒ»¸öƾ֤Gh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄÔ¶¿ØºóÃÅ£¬£¬ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207


 

ÊÂÎñÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_LiteHTTP_ÅþÁ¬C2ЧÀÍÆ÷

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½LiteHTTPÊÔͼÅþÁ¬C&CЧÀÍÆ÷¡£¡£¡£¡£¡£¡£LiteHTTPÊÇÒ»¸öʹÓÃC#±àдµÄ¿ªÔ´½©Ê¬ÍøÂç¶ñÒâÈí¼þ£¬£¬ÏîÄ¿µØµãΪ£ºhttps://github.com/zettabithf/LiteHTTP£¬£¬ÏîÄ¿ÓÐ3¸öĿ¼£¬£¬BotÊDz¡¶¾³ÌÐòµÄ´úÂ룬£¬PanelÊÇ¿ØÖƶ˵ĴúÂ룬£¬Ê¹ÓÃPHP±àд£¬£¬BuilderÊÇÒ»¸öÌìÉúÆ÷£¬£¬ÓÃÓÚ¿ìËÙÌìÉú²¡¶¾³ÌÐò¡£¡£¡£¡£¡£¡£LiteHTTP¿ÉÒÔÍøÂçÖ÷»úÐÅÏ¢£¬£¬Ê¹ÓÃÔ¤ÏÈÔ¼¶¨µÄÃÜÔ¿¾ÙÐмÓÃÜ£¬£¬È»ºó½«¼ÓÃܺóµÄÐÅÏ¢ÒÔHTTPµÄ·½·¨ÉÏ´«ÖÁ¿ØÖƶËЧÀÍÆ÷£¬£¬½ÓÊÜ¿ØÖƶ˵ĿØÖÆÂë²¢Ö´ÐÐÏìÓ¦µÄ²Ù×÷£¬£¬ÉÏ´«Ö´ÐеÄЧ¹û¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_Îļþ²Ù×÷¹¥»÷_Zimbra_ÎļþÉÏ´«[CVE-2022-27925][CVE-2022-37042][CNNVD-202204-3909]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ZimbraCollaborationSuite(ZCS)8.8.15ºÍ9.0¾ßÓÐmboximport¹¦Ð§£¬£¬¿ÉÎüÊÕZIP´æµµ²¢´ÓÖÐÌáÈ¡Îļþ¡£¡£¡£¡£¡£¡£Í¨¹ýÈÆ¹ýÉí·ÝÑéÖ¤£¨¼´Ã»ÓÐÉí·ÝÑéÖ¤ÁîÅÆ£©£¬£¬¹¥»÷Õß¿ÉÒÔ½«í§ÒâÎļþÉÏ´«µ½ÏµÍ³£¬£¬´Ó¶øµ¼ÖÂĿ¼±éÀúºÍÔ¶³Ì´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©Õ¹Æ½Ì¨£¬£¬ÓÃÓÚÔÚÍâµØºÍÔÆ¶Ë¿ª·¢¡¢°²ÅźÍÔËÐÐÆóÒµÓ¦ÓóÌÐò£¬£¬ÀýÈçJava¡£¡£¡£¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿É¿¿¡¢³ÉÊìºÍ¿ÉÀ©Õ¹µÄʵÏÖ¡£¡£¡£¡£¡£¡£ÓÉÓÚForeignOpaqueReferenceÀà±£´æÇå¾²ÎÊÌ⣬£¬CVE-2023-21839Îó²îÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPЭÒéÍøÂç»á¼û²¢ÆÆËðÒ×Êܹ¥»÷µÄWebLogicЧÀÍÆ÷£¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܵ¼ÖÂOracleWebLogicЧÀÍÆ÷±»½ÓÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£Ó°Ïì¹æÄ££ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_Îó²îʹÓÃ_ÎļþÉÏ´«_ZOHO_ManageEngine_Desktop_Central_statusUpdate[CVE-2014-5005]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃZOHOManageEngineDesktopCentralÖб£´æµÄÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ZOHOManageEngineDesktopCentral£¨DC£©ÊÇÃÀ¹ú׿ºÀ£¨ZOHO£©¹«Ë¾µÄÒ»Ì××ÀÃæÖÎÃ÷È·¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¸Ã¼Æ»®°üÀ¨Èí¼þ·Ö·¢¡¢²¹¶¡ÖÎÀí¡¢ÏµÍ³ÉèÖá¢Ô¶³Ì¿ØÖƵȹ¦Ð§Ä£¿£¿£¿£¿é£¬£¬¿É¶Ô×ÀÃæ»úÒÔ¼°Ð§ÀÍÆ÷ÖÎÀíµÄÕû¸öÉúÃüÖÜÆÚÌṩ֧³Ö¡£¡£¡£¡£¡£¡£ZOHOManageEngineDC9build90055֮ǰ°æ±¾Öб£´æÒ»¸öĿ¼±éÀúÔì³ÉµÄí§ÒâÎļþÉÏ´«Îó²î£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòÖ´ÐÐLFU²Ù×÷ʱ£¬£¬statusUpdateûÓгä·Ö¹ýÂË¡®fileName¡¯²ÎÊý£¬£¬Ô¶³Ì¹¥»÷Õ߿ɽèÖúĿ¼±éÀú×Ö·û¡®..¡¯£¬£¬ÉÏ´«í§ÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Splunk_´úÂëÖ´ÐÐ[CVE-2022-43571]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SplunkEnterpriseÊÇ»úеÊý¾ÝµÄÒýÇæ¡£¡£¡£¡£¡£¡£Ê¹ÓÃSplunk¿ÉÍøÂç¡¢Ë÷ÒýºÍʹÓÃËùÓÐÓ¦ÓóÌÐò¡¢Ð§ÀÍÆ÷ºÍ×°±¸ÌìÉúµÄ¿ìËÙÒÆ¶¯ÐÍÅÌËã»úÊý¾Ý¡£¡£¡£¡£¡£¡£¹ØÁª²¢ÆÊÎö¿çÔ½¶à¸öϵͳµÄÖØ´óÊÂÎñ¡£¡£¡£¡£¡£¡£»£»£»ñÈ¡ÐÂÌõÀíµÄÔËÓª¿É¼ûÐÔÒÔ¼°ITºÍÓªÒµÖÇÄÜ¡£¡£¡£¡£¡£¡£ÓÉÓÚSplunkEnterpriseÖÐSimpleXMLÒDZí°å±£´æ´úÂë×¢È룬£¬¾­ÓÉÉí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õß¿É½á¹¹ÌØÖÆµÄÊý¾Ý°ü£¬£¬Í¨¹ýPDFµ¼³ö²Ù×÷´¥·¢í§Òâ´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20230207