2021-04-15
Ðû²¼Ê±¼ä 2021-04-15ÊÂÎñÃû³Æ£º | TCP_Ô¶³Ì´úÂë_CitrixÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2019-19781] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | CitrixADCÊÇÒ»¿îÓ¦Óý»¸¶Controller£¬£¬£¬ÓÃÓÚÆÊÎöÌØ¶¨ÓÚÓ¦ÓõÄÁ÷Á¿£¬£¬£¬ÒÔ±ãÖÇÄܵØÎªWebÓ¦ÓóÌÐò·ÖÅÉ¡¢ÓÅ»¯ºÍ±£»£»£»¤4²ã7(L4-L7)ÍøÂçÁ÷Á¿¡£¡£¡£CitrixGatewayÕûºÏÁËÔ¶³Ì»á¼û»ù´¡½á¹¹£¬£¬£¬ÒÔ±ã¿çËùÓÐÓ¦ÓóÌÐòÌṩµ¥µãµÇ¼£¬£¬£¬ÎÞÂÛÊÇÔÚÊý¾ÝÖÐÐÄ¡¢ÔÆÖÐÕÕ¾É×÷ΪSaaS´«Êä¡£¡£¡£ÔÚCitrixADCºÍCitrixGatewayÖб£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬ÔÊÐíδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁî¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_Chromium_V8_JavaScriptÒýÇæ_Ô¶³ÌÏÂÁîÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | »ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8JavaScriptÒýÇæÖÐ,±£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¿ØÖÆhtml¼ÓÔØ¶ñÒâJavaScriptÎļþ£¬£¬£¬µÖ´ïÔÚ±»¹¥»÷ÕßÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁîµÄЧ¹û¡£¡£¡£µ«´ËÎó²îÎÞ·¨Í»ÆÆChromeɳÏäÕâÒ»Çå¾²»úÖÆ£¬£¬£¬ÒÔÊÇÓ°ÏìÓÐÏÞ¡£¡£¡£ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÇå¾²½çÏߣ¬£¬£¬¿É±ÜÃâÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÖ÷»úÉÏÆô¶¯³ÌÐò£¬£¬£¬¸ÃÎó²îµ¥¶ÀʹÓÃʱÏÖÔÚÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬Òò´Ë¸ÃÎó²îÐèÒªÓëÁíÍâµÄÎó²î£¨ChromeɳÏäÌÓÒÝ£©Á´½ÓÔÚÒ»ÆðÀ´Ê¹Ó㬣¬£¬×îÖÕ¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_Çå¾²Îó²î_TongWeb_ÎļþÉÏ´«È¨ÏÞÒþ²ØÕË»§µÇ¼ʵÑé |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½¹¥»÷ÕßʹÓÃTongWebÔ¤ÁôµÄ£¬£¬£¬¾ßÓÐÎļþÉÏ´«È¨ÏÞµÄÒþ²ØÕË»§¾ÙÐеǼʵÑéµÄÐÐΪ¡£¡£¡£TongWebÊǺ£ÄÚÕþÆóÓªÒµÆÕ±éÓ¦ÓõÄWEBÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£´ËÓ¦Óñ£´æÒ»¸öÒþ²ØµÄÓû§£¬£¬£¬ÇÒÓÐÀο¿µÄ¡¢ÎÞ·¨¸ü¸ÄµÄĬÈÏÃÜÂ룬£¬£¬¾ßÓÐŲÓÃÎļþÉÏ´«½Ó¿ÚµÄȨÏÞ¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÓû§£¬£¬£¬¾ÙÐÐÉÏ´«í§ÒâÎļþµÄΣÏÕ²Ù×÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_Fastjson_dnslog̽²â |
Çå¾²ÀàÐÍ£º | Çå¾²Éó¼Æ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´ipÕýÔÚʹÓÃdnslog̽²âÖ÷»úºó¶ËÊÇ·ñÊÇfastjson£»£»£» |
¸üÐÂʱ¼ä£º | 20210415 |
ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£ircBotÊÇ»ùÓÚircÐÒéµÄ½©Ê¬ÍøÂ磬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_ÖÎÀí¹¤¾ß_asp¿ØÖÆÏÂÁî |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPµØµãÖ÷»úÉϵÄwebshellÖÎÀí¹¤¾ß¿Í»§¹æÔòÔÚÏòÄ¿µÄIPµØµãÖ÷»úÉϵÄwebshellЧÀÍÆ÷¶Ë·¢³ö¿ØÖÆÏÂÁî¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓÀ´Ëµ£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_¿ÉÒÉÐÐΪ_wget_curlÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐÐ |
Çå¾²ÀàÐÍ£º | ¿ÉÒÉÐÐΪ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍ¿ÉÒÉÏÂÁ£¬£¬ÊµÑé¿ØÖÆÄ¿µÄIPÖ÷»úÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐС£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_±ùЫ3.0ÅþÁ¬ |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓñùЫ3.0ÅþÁ¬Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20210415 |
ɾ³ýÊÂÎñ
1. TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_ÅþÁ¬_1


¾©¹«Íø°²±¸11010802024551ºÅ