2020-05-12
Ðû²¼Ê±¼ä 2020-05-12ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_SaltStack_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2020-11651/CVE-2020-11652] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSaltStackµÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2020-11651)¶ÔÄ¿µÄIPÖ÷»úµÄSaltStackÓ¦ÓþÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£ saltstackÊÇ»ùÓÚpython¿ª·¢µÄÒ»Ì×C/S×Ô¶¯»¯ÔËά¹¤¾ß¡£¡£¡£¡£ÓÉÓÚÓ¦ÓÃÖд¦Öóͷ£Î´ÈÏÖ¤ÇëÇóµÄClearFuncsÀàÖб£´æÁ½¸öΣÏÕµÄÒªÁ죬£¬£¬£¬£¬£¬²¢Ì»Â¶ÔÚÍ⣬£¬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇóÒÔÖÎÀíԱȨÏÞÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬£¬»ñȡЧÀÍÆ÷¿ØÖÆÈ¨£¬£¬£¬£¬£¬£¬Î£º¦ÑÏÖØ¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂíºóÃÅ_Win32.Mpsvc_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£ MpsvcÊÇÒ»¸öľÂí£¬£¬£¬£¬£¬£¬ÊÇÖйúAPT×éÖ¯º£µÁÐÜèËùʹÓõÄÒ»¿îľÂíºóÃÅ¡£¡£¡£¡£ MpsvcʹÓÃDLL²à¼ÓÔØÊÖÒÕ£¬£¬£¬£¬£¬£¬»ñÈ¡Êܺ¦Ö÷»úµÄÓ²¼þUUID²¢ÉÏ´«µ½C&C£¬£¬£¬£¬£¬£¬¿ÉÒÔÏÂÔØ²¢Ö´ÐÐÆäËûÎļþ¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspSpy_ÉÏ´«ºóÃųÌÐò |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£¡£ webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_vbs_webshellÒ»¾ä»°Ä¾ÂíÉÏ´« |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«VBSÒ»¾ä»°Ä¾ÂíµÄÐÐΪ ¹¥»÷ÕßʵÑéÏòЧÀÍÆ÷ÉÏ´«VBSÒ»¾ä»°Ä¾ÂíÎļþ£¬£¬£¬£¬£¬£¬ÈôÊÇÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÅþÁ¬¹¤¾ß¶ÔЧÀÍÆ÷¾ÙÐпØÖÆ¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶phpSpy2014_ÉÏ´«ºóÃųÌÐò |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£¡£ webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
UDP_NFS_¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑé |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄIP¾ÙÐÐNFS ¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑéµÄÐÐΪ NFSÈ«³ÆNetwork File System£¬£¬£¬£¬£¬£¬¼´ÍøÂçÎļþϵͳ£¬£¬£¬£¬£¬£¬ÊôÓÚÍøÂç²ã£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÍøÂç¼äÎļþµÄ¹²Ïí£¬£¬£¬£¬£¬£¬×îÔçÓÉsun¹«Ë¾¿ª·¢ ¿ÉÒÔ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐ"showmount -e"²Ù×÷£¬£¬£¬£¬£¬£¬´Ë²Ù×÷½«Ð¹Â¶Ä¿µÄÖ÷»úµÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬£¬ºÃ±ÈĿ¼½á¹¹¡£¡£¡£¡£¸üÔã¸âµÄÊÇ£¬£¬£¬£¬£¬£¬ÈôÊÇ»á¼û¿ØÖƲ»Ñϵϰ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÓпÉÄÜÖ±½Ó»á¼ûµ½Ä¿µÄÖ÷»úÉϵÄÊý¾Ý¡£¡£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
ɾ³ýÊÂÎñ
HTTP_Ŀ¼±éÀú[..\..][CVE-1999-0229]
HTTP_Ŀ¼±éÀú[../]
HTTP_Ŀ¼±éÀú[..\]


¾©¹«Íø°²±¸11010802024551ºÅ