2019-12-03

Ðû²¼Ê±¼ä 2019-12-03

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_vBulletin_ÊäÈëÑéÖ¤¹ýʧÎó²î[CVE-2019-16759]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃvBulletinÊäÈëÑéÖ¤¹ýʧÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳³ÌÐò¡£

vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾Öб£´æÇå¾²Îó²î¡£¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐÏÂÁî¡£

¸üÐÂʱ¼ä£º

20191203











ÊÂÎñÃû³Æ£º

HTTP_D-Link_DNS-320²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2019-16057]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃD-Link DNS-320²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ¡£

D-Link DNS-320ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îNAS£¨ÍøÂçÁ¥Êô´æ´¢£©×°±¸¡£

D-Link DNS-320 2.05.B10¼°Ö®Ç°°æ±¾ÖеÄlogin_mgr.cgi¾ç±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£

¸üÐÂʱ¼ä£º

20191203











ÊÂÎñÃû³Æ£º

HTTP_SCADA_Schneider_Electric_U.Motion_Builder_SQL×¢ÈëÎó²î[CVE-2018-7841]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ê¹ÓÃSchneider Electric U.Motion Builder SQL×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

Schneider Electric U.Motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì×ÐÞ½¨ÎïÖÇÄܹÜÀíϵͳ¡£

Schneider Electric U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾ÖеÄtrack_import_export.php¾ç±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î £¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖÐ £¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£

¸üÐÂʱ¼ä£º

20191203















ÊÂÎñÃû³Æ£º

HTTP_IOT_¶à¿î·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î[CVE-2019-3929]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ê¹Óöà¿î·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

¶à¿î·ÓÉÆ÷Öб£´æÏÂÁî×¢ÈëÎó²î¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖÐ £¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£

¸üÐÂʱ¼ä£º

20191203










ÊÂÎñÃû³Æ£º

HTTP_LSP4XML_XXE_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-18213/CVE-2019-18212]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_LSP4XML_XXE_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ

1.LSP4XMLÊÇÒ»¸öXMLÎļþÆÊÎö¿â £¬±»VSCode/EclipseµÈ×ÅÃû±à¼­Æ÷ÖÐʹÓá£

¸üÐÂʱ¼ä£º

20191203









ÊÂÎñÃû³Æ£º

TCP_ľÂí_SDBbotRat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£

SDBbotÊÇʹÓÃC++ÓïÑÔ±àдµÄÐÂÐÍÔ¶³Ì»á¼ûľÂí£¨RAT£© £¬ÓÉGet2ÏÂÔØ¹¤¾ßÔÚ×îеÄTA505¶ñÒâ»î¶¯ÖÐʹÓá£SDBbotÒþ²ØÐÔ¼«Ç¿ £¬ÇÒ¹¦Ð§ÆëÈ« £¬È磺Զ³ÌÏÂÁîÖ´ÐС¢ÉÏ´«/ÏÂÔØÎļþ¡¢ÊÓÆµ¼à¿ØµÈ¡£

¸üÐÂʱ¼ä£º

20191203










ÊÂÎñÃû³Æ£º

TCP_ľÂí_ParasiteStealer_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ ParasiteStealerľÂí ÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË ParasiteStealerľÂí¡£

¸ÃľÂí»á͵ȡ¶à¸öä¯ÀÀÆ÷¼Í¼µÄµÇ¼ÐÅÏ¢¡¢OutlookÓÊÏäÃÜÂë¼°ÆäËûÉñÃØÐÅÏ¢ÉÏ´«µ½Ö¸¶¨·þÎñÆ÷¡£

¸üÐÂʱ¼ä£º

20191203










ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£

ircBotÊÇ»ùÓÚircЭÒéµÄ½©Ê¬ÍøÂç £¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191203









ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Bitter.Rat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitter¡£

BitterÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ £¬ÔËÐкó £¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191203








ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Bitter.Rat(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitter¡£

BitterÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ £¬ÔËÐкó £¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£

¸üÐÂʱ¼ä£º

20191203








ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.FileStolen_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíFileStolen¡£

FileStolenµÄÖ÷Òª¹¦Ð§ÎªÎļþÇÔÈ¡ £¬ÇÔȡָ¶¨Âß¼­´ÅÅÌÏÂÖ¸¶¨ÎļþÃûµÄÎļþ²¢ÇÒÉÏ´«µÄµ½CC·þÎñÆ÷ £¬ÇÔÈ¡µÄÎļþÀàÐͰüÀ¨£ºtxt¡¢ppt¡¢pptx¡¢pdf¡¢doc¡¢docx¡¢xls¡¢xlsx¡¢zip¡¢7z¡¢rtf¡£

¸üÐÂʱ¼ä£º

20191203











ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDDoS.Gafgyt¡£

DDoS.GafgytÊÇÒ»¸öLinux½©Ê¬ÍøÂç £¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£

¸üÐÂʱ¼ä£º

20191203








ÊÂÎñÃû³Æ£º

TCP_NSA_EternalChampion_(ÓÀºã¹Ú¾ü)_SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²îSync_Response[MS17-010]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMicrosoft Windows SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­È«ÐĽṹµÄ»ûÐÎÇëÇó°ü £¬¿ÉÒÔ»ñȡĿµÄ·þÎñÆ÷µÄϵͳȨÏÞ £¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£

¸üÐÂʱ¼ä£º

20191203












ÊÂÎñÃû³Æ£º

TCP_NSA_EternalChampion_(ÓÀºã¹Ú¾ü)_SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²îSync_Request[MS17-010]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMicrosoft Windows SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£

Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­È«ÐĽṹµÄ»ûÐÎÇëÇó°ü £¬¿ÉÒÔ»ñȡĿµÄ·þÎñÆ÷µÄϵͳȨÏÞ £¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£

¸üÐÂʱ¼ä£º

20191203












ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_ASP_Cmd_Shell_On_IIS_5.1_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØÖ·Ö÷»úÕýÔÚÏòÄ¿µÄIPµØÖ·Ö÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£

webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¼òÆÓ˵ £¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ £¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó £¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾·þÎñÆ÷µÄwebĿ¼ÖÐ £¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨ £¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾·þÎñÆ÷ £¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ £¬ÓÉÓÚÓë±»¿ØÖƵķþÎñÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ £¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ £¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼ £¬¹ÜÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£

¸üÐÂʱ¼ä£º

20191203















ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉĿ¼ä¯ÀÀ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½ÓÉÓÚÉèÖò»µ±µ¼ÖµÄĿ¼ä¯ÀÀ

ÍøÕ¾±£´æÉèÖÃȱÏÝ £¬±£´æÄ¿Â¼¿Éä¯ÀÀÎó²î £¬Õâ»áµ¼ÖÂÍøÕ¾Ðí¶àÒþ˽ÎļþÓëĿ¼й¶ £¬ºÃ±ÈÊý¾Ý¿â±¸·ÝÎļþ¡¢ÉèÖÃÎļþµÈ £¬¹¥»÷ÕßʹÓøÃÐÅÏ¢¿ÉÒÔ¸üÈÝÒ×»ñµÃÍøÕ¾È¨ÏÞ £¬µ¼ÖÂÍøÕ¾±»ºÚ¡£

¸üÐÂʱ¼ä£º

20191203










ÊÂÎñÃû³Æ£º

TCP_Win32.¹íÓ°DDoS¹¥»÷_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³Ì·þÎñÆ÷¡£

¹íÓ°DDoSÊÇÒ»¸öÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷¹¤¾ß £¬×¥È¡´ó×ÚÈ⼦ £¬¿ÉÒÔ¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDos¹¥»÷¡£

DoS£¨Denial Of Service£©¼´¾Ü¾ø·þÎñ¹¥»÷ £¬×î»ù±¾µÄDoS¹¥»÷¾ÍÊÇʹÓúÏÀíµÄ·þÎñÇëÇóÀ´Õ¼Óùý¶àµÄ·þÎñ×ÊÔ´ £¬´Ó¶øÊ¹Õýµ±Óû§ÎÞ·¨»ñµÃ·þÎñµÄÏìÓ¦¡£DDoS£¨Distributed Denial Of Service£©¼´ÂþÑÜʽ¾Ü¾ø·þÎñ¹¥»÷¡£¼´Í¬Ê±Ê¹ÓÃÈô¸Ę́Ö÷»ú £¬Í¬Ê±¶Ôһ̨Ö÷»ú¾ÙÐÐDoS¹¥»÷¡£

DDoSÊÇDistributed Denial of ServiceµÄ¼ò³Æ £¬¼´ÂþÑÜʽ¾Ü¾ø·þÎñ¡£¹¥»÷Ö¸½èÖúÓÚ¿Í»§/·þÎñÆ÷ÊÖÒÕ £¬½«¶à¸öÅÌËã»úÍŽáÆðÀ´×÷Ϊ¹¥»÷ƽ̨ £¬¶ÔÒ»¸ö»ò¶à¸öÄ¿µÄ·¢¶¯DoS¹¥»÷ £¬´Ó¶ø³É±¶µØÌá¸ß¾Ü¾ø·þÎñ¹¥»÷µÄÍþÁ¦¡£Í¨³£ £¬¹¥»÷ÕßʹÓÃÒ»¸ö͵ÇÔÕʺŽ«DDoSÖ÷¿Ø³ÌÐò×°ÖÃÔÚһ̨ÅÌËã»úÉÏ £¬ÔÚÒ»¸öÉ趨µÄʱ¼äÖ÷¿Ø³ÌÐò½«Óë´ó×Ú´úÀí³ÌÐòͨѶ £¬´úÀí³ÌÐòÒѾ­±»×°ÖÃÔÚInternetÉϵÄÐí¶àÅÌËã»úÉÏ¡£´úÀí³ÌÐòÊÕµ½Ö¸Áîʱ¾Í·¢¶¯¹¥»÷¡£Ê¹Óÿͻ§/·þÎñÆ÷ÊÖÒÕ £¬Ö÷¿Ø³ÌÐòÄÜÔÚ¼¸ÃëÖÓÄÚ¼¤»î³É°ÙÉÏǧ¸ö´úÀí³ÌÐòµÄÔËÐС£

¸üÐÂʱ¼ä£º

20191203