2020-05-12

Ðû²¼Ê±¼ä 2020-05-12

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_SaltStack_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2020-11651/CVE-2020-11652]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSaltStackµÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2020-11651)¶ÔÄ¿µÄIPÖ÷»úµÄSaltStackÓ¦ÓþÙÐй¥»÷µÄÐÐΪ¡£¡£¡£

saltstackÊÇ»ùÓÚpython¿ª·¢µÄÒ»Ì×C/S×Ô¶¯»¯ÔËά¹¤¾ß¡£¡£¡£ÓÉÓÚÓ¦ÓÃÖд¦Öóͷ£Î´ÈÏÖ¤ÇëÇóµÄClearFuncsÀàÖб£´æÁ½¸öΣÏÕµÄÒªÁ죬£¬ £¬²¢Ì»Â¶ÔÚÍ⣬£¬ £¬Ê¹µÃ¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇóÒÔÖÎÀíԱȨÏÞÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬ £¬»ñȡЧÀÍÆ÷¿ØÖÆÈ¨£¬£¬ £¬Î£º¦ÑÏÖØ¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512











ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Mpsvc_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£

MpsvcÊÇÒ»¸öľÂí£¬£¬ £¬ÊÇÖйúAPT×éÖ¯º£µÁÐÜèËùʹÓõÄÒ»¿îľÂíºóÃÅ¡£¡£¡£

MpsvcʹÓÃDLL²à¼ÓÔØÊÖÒÕ£¬£¬ £¬»ñÈ¡Êܺ¦Ö÷»úµÄÓ²¼þUUID²¢ÉÏ´«µ½C&C£¬£¬ £¬¿ÉÒÔÏÂÔØ²¢Ö´ÐÐÆäËûÎļþ¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512










ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspSpy_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£

webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓ˵£¬£¬ £¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬ £¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬ £¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬ £¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬ £¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬ £¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬ £¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬ £¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬ £¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ £¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512















ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_vbs_webshellÒ»¾ä»°Ä¾ÂíÉÏ´«

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«VBSÒ»¾ä»°Ä¾ÂíµÄÐÐΪ

¹¥»÷ÕßʵÑéÏòЧÀÍÆ÷ÉÏ´«VBSÒ»¾ä»°Ä¾ÂíÎļþ£¬£¬ £¬ÈôÊÇÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÅþÁ¬¹¤¾ß¶ÔЧÀÍÆ÷¾ÙÐпØÖÆ¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512









ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶phpSpy2014_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£¡£

webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓ˵£¬£¬ £¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬ £¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬ £¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬ £¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬ £¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬ £¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬ £¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬ £¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬ £¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬ £¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512















ÊÂÎñÃû³Æ£º

UDP_NFS_¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑé

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄIP¾ÙÐÐNFS ¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑéµÄÐÐΪ

NFSÈ«³ÆNetwork File System£¬£¬ £¬¼´ÍøÂçÎļþϵͳ£¬£¬ £¬ÊôÓÚÍøÂç²ã£¬£¬ £¬Ö÷ÒªÓÃÓÚÍøÂç¼äÎļþµÄ¹²Ïí£¬£¬ £¬×îÔçÓÉsun¹«Ë¾¿ª·¢

¿ÉÒÔ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐ"showmount -e"²Ù×÷£¬£¬ £¬´Ë²Ù×÷½«Ð¹Â¶Ä¿µÄÖ÷»úµÄÃô¸ÐÐÅÏ¢£¬£¬ £¬ºÃ±ÈĿ¼½á¹¹¡£¡£¡£¸üÔã¸âµÄÊÇ£¬£¬ £¬ÈôÊÇ»á¼û¿ØÖƲ»Ñϵϰ£¬£¬ £¬¹¥»÷ÕßÓпÉÄÜÖ±½Ó»á¼ûµ½Ä¿µÄÖ÷»úÉϵÄÊý¾Ý¡£¡£¡£

¸üÐÂʱ¼ä£º

20200512













ɾ³ýÊÂÎñ


HTTP_Ŀ¼±éÀú[..\..][CVE-1999-0229]

HTTP_Ŀ¼±éÀú[../]

HTTP_Ŀ¼±éÀú[..\]