2019-12-03
Ðû²¼Ê±¼ä 2019-12-03ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º
HTTP_vBulletin_ÊäÈëÑéÖ¤¹ýʧÎó²î[CVE-2019-16759]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃvBulletinÊäÈëÑéÖ¤¹ýʧÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£
vBulletinÊÇÃÀ¹úInternetBrandsºÍvBulletinSolutions¹«Ë¾µÄÒ»¿î»ùÓÚPHPºÍMySQLµÄ¿ªÔ´WebÂÛ̳³ÌÐò¡£¡£¡£
vBulletin 5.x°æ±¾ÖÁ5.5.4°æ±¾Öб£´æÇå¾²Îó²î¡£¡£¡£¹¥»÷Õ߿ɽèÖú¡®widgetConfig[code]¡¯²ÎÊýʹÓøÃÎó²îÖ´ÐÐÏÂÁî¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_D-Link_DNS-320²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î[CVE-2019-16057]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½ÊÔͼͨ¹ýʹÓÃD-Link
DNS-320²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ¡£¡£¡£
D-Link DNS-320ÊÇÖйų́ÍåÓÑѶ£¨D-Link£©¹«Ë¾µÄÒ»¿îNAS£¨ÍøÂçÁ¥Êô´æ´¢£©×°±¸¡£¡£¡£
D-Link DNS-320 2.05.B10¼°Ö®Ç°°æ±¾ÖеÄlogin_mgr.cgi¾ç±¾±£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_SCADA_Schneider_Electric_U.Motion_Builder_SQL×¢ÈëÎó²î[CVE-2018-7841]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ê¹ÓÃSchneider
Electric U.Motion Builder SQL×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£
Schneider Electric
U.Motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì×ÐÞ½¨ÎïÖÇÄÜÖÎÀíϵͳ¡£¡£¡£
Schneider Electric
U.Motion Builder 1.3.4¼°Ö®Ç°°æ±¾ÖеÄtrack_import_export.php¾ç±¾Öб£´æ²Ù×÷ϵͳÏÂÁî×¢ÈëÎó²î£¬£¬£¬£¬£¬£¬¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹²Ù×÷ϵͳ¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ÏÂÁîµÈ¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨²Ù×÷ϵͳÏÂÁî¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_IOT_¶à¿î·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î[CVE-2019-3929]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ê¹Óöà¿î·ÓÉÆ÷ÏÂÁî×¢ÈëÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£
¶à¿î·ÓÉÆ÷Öб£´æÏÂÁî×¢ÈëÎó²î¡£¡£¡£¸ÃÎó²îÔ´ÓÚÍⲿÊäÈëÊý¾Ý½á¹¹¿ÉÖ´ÐÐÏÂÁîÀú³ÌÖУ¬£¬£¬£¬£¬£¬ÍøÂçϵͳ»ò²úƷδ׼ȷ¹ýÂËÆäÖеÄÌØÊâÔªËØ¡£¡£¡£¹¥»÷Õß¿ÉʹÓøÃÎó²îÖ´Ðв»·¨ÏÂÁî¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_LSP4XML_XXE_Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2019-18213/CVE-2019-18212]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_LSP4XML_XXE_Ô¶³Ì´úÂëÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ
1.LSP4XMLÊÇÒ»¸öXMLÎļþÆÊÎö¿â£¬£¬£¬£¬£¬£¬±»VSCode/EclipseµÈ×ÅÃû±à¼Æ÷ÖÐʹÓᣡ£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_ľÂí_SDBbotRat_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£
SDBbotÊÇʹÓÃC++ÓïÑÔ±àдµÄÐÂÐÍÔ¶³Ì»á¼ûľÂí£¨RAT£©£¬£¬£¬£¬£¬£¬ÓÉGet2ÏÂÔØ¹¤¾ßÔÚ×îеÄTA505¶ñÒâ»î¶¯ÖÐʹÓᣡ£¡£SDBbotÒþ²ØÐÔ¼«Ç¿£¬£¬£¬£¬£¬£¬ÇÒ¹¦Ð§ÆëÈ«£¬£¬£¬£¬£¬£¬È磺Զ³ÌÏÂÁîÖ´ÐС¢ÉÏ´«/ÏÂÔØÎļþ¡¢ÊÓÆµ¼à¿ØµÈ¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_ľÂí_ParasiteStealer_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½ ParasiteStealerľÂí
ÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË ParasiteStealerľÂí¡£¡£¡£
¸ÃľÂí»á͵ȡ¶à¸öä¯ÀÀÆ÷¼Í¼µÄµÇ¼ÐÅÏ¢¡¢OutlookÓÊÏäÃÜÂë¼°ÆäËûÉñÃØÐÅÏ¢ÉÏ´«µ½Ö¸¶¨Ð§ÀÍÆ÷¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º
TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£
ircBotÊÇ»ùÓÚircÐÒéµÄ½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£»£»£»£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_Bitter.Rat(ÂûÁ黨)_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitter¡£¡£¡£
BitterÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_ºóÃÅ_Bitter.Rat(ÂûÁ黨)_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËBitter¡£¡£¡£
BitterÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ£¬£¬£¬£¬£¬£¬ÔËÐк󣬣¬£¬£¬£¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_ľÂí_Win32.FileStolen_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíFileStolen¡£¡£¡£
FileStolenµÄÖ÷Òª¹¦Ð§ÎªÎļþÇÔÈ¡£¬£¬£¬£¬£¬£¬ÇÔȡָ¶¨Âß¼´ÅÅÌÏÂÖ¸¶¨ÎļþÃûµÄÎļþ²¢ÇÒÉÏ´«µÄµ½CCЧÀÍÆ÷£¬£¬£¬£¬£¬£¬ÇÔÈ¡µÄÎļþÀàÐͰüÀ¨£ºtxt¡¢ppt¡¢pptx¡¢pdf¡¢doc¡¢docx¡¢xls¡¢xlsx¡¢zip¡¢7z¡¢rtf¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_ºóÃÅ_Linux.DDoS.Gafgyt_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDDoS.Gafgyt¡£¡£¡£
DDoS.GafgytÊÇÒ»¸öLinux½©Ê¬ÍøÂ磬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_NSA_EternalChampion_(ÓÀºã¹Ú¾ü)_SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²îSync_Response[MS17-010]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMicrosoft Windows SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£
Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£
ÈôÊǹ¥»÷ÕßÏò Microsoft ЧÀÍÆ÷·¢Ë;ȫÐĽṹµÄ»ûÐÎÇëÇó°ü£¬£¬£¬£¬£¬£¬¿ÉÒÔ»ñȡĿµÄЧÀÍÆ÷µÄϵͳȨÏÞ£¬£¬£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_NSA_EternalChampion_(ÓÀºã¹Ú¾ü)_SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²îSync_Request[MS17-010]
Çå¾²ÀàÐÍ£º
Çå¾²Îó²î
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMicrosoft Windows SMBÔ¶³Ì´úÂëÖ´ÐÐÎó²î¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£
Microsoft WindowsÊÇ΢ÈíÐû²¼µÄºÜÊÇÊ¢ÐеIJÙ×÷ϵͳ¡£¡£¡£
ÈôÊǹ¥»÷ÕßÏò Microsoft ЧÀÍÆ÷·¢Ë;ȫÐĽṹµÄ»ûÐÎÇëÇó°ü£¬£¬£¬£¬£¬£¬¿ÉÒÔ»ñȡĿµÄЧÀÍÆ÷µÄϵͳȨÏÞ£¬£¬£¬£¬£¬£¬²¢ÇÒÍêÈ«¿ØÖÆÄ¿µÄϵͳ¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_ľÂíºóÃÅ_webshell_ASP_Cmd_Shell_On_IIS_5.1_ÉÏ´«ºóÃųÌÐò
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£
webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
HTTP_¿ÉÒÉĿ¼ä¯ÀÀ
Çå¾²ÀàÐÍ£º
CGI¹¥»÷
ÊÂÎñÐÎò£º
¼ì²âµ½ÓÉÓÚÉèÖò»µ±µ¼ÖµÄĿ¼ä¯ÀÀ
ÍøÕ¾±£´æÉèÖÃȱÏÝ£¬£¬£¬£¬£¬£¬±£´æÄ¿Â¼¿Éä¯ÀÀÎó²î£¬£¬£¬£¬£¬£¬Õâ»áµ¼ÖÂÍøÕ¾Ðí¶àÒþ˽ÎļþÓëĿ¼й¶£¬£¬£¬£¬£¬£¬ºÃ±ÈÊý¾Ý¿â±¸·ÝÎļþ¡¢ÉèÖÃÎļþµÈ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓøÃÐÅÏ¢¿ÉÒÔ¸üÈÝÒ×»ñµÃÍøÕ¾È¨ÏÞ£¬£¬£¬£¬£¬£¬µ¼ÖÂÍøÕ¾±»ºÚ¡£¡£¡£
¸üÐÂʱ¼ä£º
20191203
ÊÂÎñÃû³Æ£º
TCP_Win32.¹íÓ°DDoS¹¥»÷_ÅþÁ¬
Çå¾²ÀàÐÍ£º
ľÂíºóÃÅ
ÊÂÎñÐÎò£º
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£
¹íÓ°DDoSÊÇÒ»¸öÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷¹¤¾ß£¬£¬£¬£¬£¬£¬×¥È¡´ó×ÚÈ⼦£¬£¬£¬£¬£¬£¬¿ÉÒÔ¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDos¹¥»÷¡£¡£¡£
DoS£¨Denial Of Service£©¼´¾Ü¾øÐ§À͹¥»÷£¬£¬£¬£¬£¬£¬×î»ù±¾µÄDoS¹¥»÷¾ÍÊÇʹÓúÏÀíµÄЧÀÍÇëÇóÀ´Õ¼Óùý¶àµÄЧÀÍ×ÊÔ´£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹Õýµ±Óû§ÎÞ·¨»ñµÃЧÀ͵ÄÏìÓ¦¡£¡£¡£DDoS£¨Distributed Denial Of Service£©¼´ÂþÑÜʽ¾Ü¾øÐ§À͹¥»÷¡£¡£¡£¼´Í¬Ê±Ê¹ÓÃÈô¸Ę́Ö÷»ú£¬£¬£¬£¬£¬£¬Í¬Ê±¶Ôһ̨Ö÷»ú¾ÙÐÐDoS¹¥»÷¡£¡£¡£
DDoSÊÇDistributed Denial
of ServiceµÄ¼ò³Æ£¬£¬£¬£¬£¬£¬¼´ÂþÑÜʽ¾Ü¾øÐ§ÀÍ¡£¡£¡£¹¥»÷Ö¸½èÖúÓÚ¿Í»§/ЧÀÍÆ÷ÊÖÒÕ£¬£¬£¬£¬£¬£¬½«¶à¸öÅÌËã»úÁªºÏÆðÀ´×÷Ϊ¹¥»÷ƽ̨£¬£¬£¬£¬£¬£¬¶ÔÒ»¸ö»ò¶à¸öÄ¿µÄ·¢¶¯DoS¹¥»÷£¬£¬£¬£¬£¬£¬´Ó¶ø³É±¶µØÌá¸ß¾Ü¾øÐ§À͹¥»÷µÄÍþÁ¦¡£¡£¡£Í¨³££¬£¬£¬£¬£¬£¬¹¥»÷ÕßʹÓÃÒ»¸ö͵ÇÔÕʺŽ«DDoSÖ÷¿Ø³ÌÐò×°ÖÃÔÚһ̨ÅÌËã»úÉÏ£¬£¬£¬£¬£¬£¬ÔÚÒ»¸öÉ趨µÄʱ¼äÖ÷¿Ø³ÌÐò½«Óë´ó×ÚÊðÀí³ÌÐòͨѶ£¬£¬£¬£¬£¬£¬ÊðÀí³ÌÐòÒѾ±»×°ÖÃÔÚInternetÉϵÄÐí¶àÅÌËã»úÉÏ¡£¡£¡£ÊðÀí³ÌÐòÊÕµ½Ö¸Áîʱ¾Í·¢¶¯¹¥»÷¡£¡£¡£Ê¹Óÿͻ§/ЧÀÍÆ÷ÊÖÒÕ£¬£¬£¬£¬£¬£¬Ö÷¿Ø³ÌÐòÄÜÔÚ¼¸ÃëÖÓÄÚ¼¤»î³É°ÙÉÏǧ¸öÊðÀí³ÌÐòµÄÔËÐС£¡£¡£
¸üÐÂʱ¼ä£º
20191203


¾©¹«Íø°²±¸11010802024551ºÅ