2021-04-08
Ðû²¼Ê±¼ä 2021-04-09ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Ææ°²ÐÅÖÕ¶ËÇå¾²ÖÎÀíϵͳ_ÌìÇæ_ǰ̨SQL×¢Èë |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓÃÌìÇæÇ°Ì¨SQL×¢ÈëÎó²î¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îдÈëwebshellµÈ¶ñÒâÎļþ£¬£¬£¬£¬´Ó¶øgetshell¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA8_ǰ̨SQLÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | ×¢Èë¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA8ǰ̨SQLÖ´ÐÐÎó²î¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îÅÌÎʳöºǫ́ÃÜÂëµÈÃô¸ÐÊý¾Ý¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßÕýÔÚʹÓ÷ºÎ¢OA9ǰ̨ÎÞÏÞÖÆGetshellÎó²î¡£¡£¡£¡£¿£¿£¿ÉÄÜͨ¹ý´ËÎó²îÖ±½ÓÉÏ´«webshellµÈ¶ñÒâÎļþ£¬£¬£¬£¬´Ó¶øgetshell¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_·ºÎ¢OA9_ǰ̨ÎÞÏÞÖÆGetshell |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃeurekaµÄ/env½Ó¿ÚÉèÖÃÊôÐÔ½«eureka.client.serviceUrl.defaultZoneÉèÖÃΪ¶ñÒâÍøÕ¾¡£¡£¡£¡£SpringBootActuatorÊÇÒ»¿î¿ÉÒÔ×ÊÖúÄã¼à¿ØÏµÍ³Êý¾ÝµÄ¿ò¼Ü,Æä¿ÉÒÔ¼à¿ØÐí¶àÐí¶àµÄϵͳÊý¾Ý,ËüÓжÔÓ¦ÓÃϵͳµÄ×ÔÊ¡ºÍ¼à¿ØµÄ¼¯ÀÖ³ÉÄÜ£¬£¬£¬£¬¿ÉÒÔÉó²éÓ¦ÓÃÉèÖõÄÏêϸÐÅÏ¢¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ͨÓÃ_Ŀ¼´©Ô½Îó²î[CVE-2019-11510/CVE-2020-5410/CVE-2019-19781/CVE-2020-5902] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʵÑé¶ÔÄ¿µÄIPÖ÷»ú¾ÙÐÐĿ¼´©Ô½Îó²î¹¥»÷ʵÑéµÄÐÐΪ¡£¡£¡£¡£Ä¿Â¼´©Ô½Îó²îÄÜʹ¹¥»÷ÕßÈÆ¹ýWebЧÀÍÆ÷µÄ»á¼ûÏÞÖÆ£¬£¬£¬£¬¶Ôweb¸ùĿ¼ÒÔÍâµÄÎļþ¼Ð£¬£¬£¬£¬í§ÒâµØ¶ÁÈ¡ÉõÖÁдÈëÎļþÊý¾Ý¡£¡£¡£¡£´Ë¹æÔòÊÇÒ»ÌõͨÓùæÔò£¬£¬£¬£¬ÆäËûÎó²î£¨ÉõÖÁһЩ0dayÎó²î£©¹¥»÷µÄpayloadÒ²ÓпÉÄÜ´¥·¢´ËÊÂÎñ±¨¾¯¡£¡£¡£¡£ÓÉÓÚÕý³£ÓªÒµÖÐÒ»Ñùƽ³£²»»á±¬·¢´ËÊÂÎñÌØÕ÷µÄÁ÷Á¿£¬£¬£¬£¬ÒÔÊÇÐèÒªÖØµã¹Ø×¢¡£¡£¡£¡£ÔÊÐíÔ¶³Ì¹¥»÷Õß»á¼ûÃô¸ÐÎļþ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210408 |
ɾ³ýÊÂÎñ
1¡¢HTTP_ľÂíºóÃÅ_ASP_webshellÒ»¾ä»°Ä¾ÂíÏÂÔØ


¾©¹«Íø°²±¸11010802024551ºÅ