2019-12-10

°ä²¼¹¦·ò 2019-12-10

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB©³¨ÆðÍ·ÀûÓÃ[MS17-010]_ÒÉËÆ

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»ú½øÐÐMS17-010·ì϶ÀûÓõÄÐÐΪ.

Microsoft WindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü£¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÆëÈ«½ÚÔìÖ¸±êϵͳ¡£

¸üй¦·ò£º

20191210










ÊÂÎñÃû³Æ£º

TCP_NSA_EternalBlue_(ÓÀºãÖ®À¶)_SMB·ì϶дÈëshellcode[MS17-010]_ʵÏÖshellcodeдÈë

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IP¶ÔÖ÷ÕÅÖ÷»úÀûÓÃMS17-010·ì϶дÈëshellcodeµÄÐÐΪ.

Microsoft WindowsÊÇ΢Èí°ä²¼µÄ¼«¶ÈÊ¢ÐеIJÙ×÷ϵͳ¡£

ÈôÊǹ¥»÷ÕßÏò Microsoft ·þÎñÆ÷·¢Ë;­¾«ÐÄ»ú¹ØµÄ»ûÐÎÒªÇó°ü£¬Äܹ»»ñȡָ±ê·þÎñÆ÷µÄϵͳȨÏÞ£¬²¢ÇÒÆëÈ«½ÚÔìÖ¸±êϵͳ¡£

¸üй¦·ò£º

20191210











ÊÂÎñÃû³Æ£º

HTTP_OpenDreamBox_²Ù×÷ϵͳºÅÁî×¢Èë·ì϶[CVE-2017-14135]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃOpenDreamBox²Ù×÷ϵͳºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£

OpenDreamBox 2.0.0°æ±¾ÖеÄwebadmin²å¼þµÄenigma2-plugins/blob/master/webadmin/src/WebChilds/Script.pyÎļþ´æÔÚ°²È«·ì϶¡£Ô¶³Ì¹¥»÷Õß¿Éͨ¹ýÏò/script URL·¢ËÍ´øÓÐshellÔª×Ö·ûµÄ¡®command¡¯²ÎÊýÀûÓø÷ì϶ִÐÐËÁÒâµÄ²Ù×÷ϵͳºÅÁî¡£

¸üй¦·ò£º

20191210











ÊÂÎñÃû³Æ£º

HTTP_Geutebruck_IP_Camera_G-Cam/EFD-2250°²È«·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÊÔͼͨ¹ýÀûÓÃGeutebruck IP Camera G-Cam/EFD-2250°²È«·ì϶À´Ö´ÐкÅÁîµÄÐÐΪ¡£

Geutebruck IP Camera G-Cam/EFD-2250Êǵ¹úGeutebruck¹«Ë¾µÄÒ»¿îÍøÂçÉãÏñ»ú¡£

Geutebruck IP Camera G-Cam/EFD-2250 1.11.0.12°æ±¾ÖдæÔÚ°²È«·ì϶¡£Ô¶³Ì¹¥»÷Õ߿ɽèÖú¶à¸ö²ÎÊýÀûÓø÷ì϶½Ó¼ûroot¼¶´ËÍâ²Ù×÷ϵͳ£¬Ö´ÐдúÂë¡£

¸üй¦·ò£º

20191210












ÊÂÎñÃû³Æ£º

HTTP_HooToo_TripMate_Titan_HT-TM05²Ù×÷ϵͳºÅÁî×¢Èë·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÀûÓÃHooToo TripMate Titan HT-TM05 ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶½øÐй¥»÷µÄÐÐΪ¡£

HooToo TripMate Titan HT-TM05ÊÇÃÀ¹úHooToo¹«Ë¾µÄÒ»¿î±ãЯʽÎÞÏß·ÓÉÆ÷¡£

ʹÓÃ2.000.022°æ±¾ºÍ2.000.082°æ±¾¹Ì¼þµÄHooToo TripMate Titan HT-TM05·ÓÉÆ÷ÖдæÔÚ²Ù×÷ϵͳºÅÁî×¢Èë·ì϶¡£¸Ã·ì϶ԴÓÚ±í²¿ÊäÈëÊý¾Ý»ú¹Ø²Ù×÷ϵͳ¿ÉÖ´ÐкÅÁî¹ý³ÌÖУ¬ÍøÂçϵͳ»ò²úƷδÕýÈ·¹ýÂËÆäÖеÄÌØÊâ×Ö·û¡¢ºÅÁîµÈ¡£¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐз¸·¨²Ù×÷ϵͳºÅÁî¡£

¸üй¦·ò£º

20191210













ÊÂÎñÃû³Æ£º

HTTP_CyberArk_Software_Enterprise_Password_Vault´úÂëÎÊÌâ·ì϶[CVE-2019-7442]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÀûÓÃCyberArk Software Enterprise Password Vault´úÂëÎÊÌâ·ì϶½øÐй¥»÷µÄÐÐΪ¡£

CyberArk Software Enterprise Password VaultÊÇÒÔÉ«ÁÐCyberArk Software¹«Ë¾µÄÒ»ÌׯóÒµÃÜÂëÆ¾Ö¤ÖÎÀí½â¾ö¹æ»®¡£

CyberArk Enterprise Password Vault 10.7¼°Ö®Ç°°æ±¾ÖеÄPassword Vault Web Access (PVWA) ´æÔÚ´úÂëÎÊÌâ·ì϶¡£¸Ã·ì϶ԴÓÚÍøÂçϵͳ»ò²úÆ·µÄ´úÂ뿪·¢¹ý³ÌÖдæÔÚÉè¼Æ»òʵÏÖ²»µ±µÄÎÊÌâ¡£

¸üй¦·ò£º

20191203














ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_×ϺüGad_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½×ϺüľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË×ϺüľÂí¡£

×ϺüÊÇÒ»¿î¶ñÒâľÂí£¬±»·ÖÆç°²È«³§É̶¨ÃûΪºÚºü¡¢·ÊÍᢾò½ð¹í»êµÈ¡£´«²¼Çþ·¶àÑù£¬Í¨³£Í¨¹ýÓÎÏ·±í¹Ò¡¢µÚÈý·½×°Ö÷¨Ê½°ó¸¿´«²¼¡£»¹Äܹ»Í¨¹ýÓÀºãÖ®À¶ÒÔ¼°MSSQL±¬ÆÆ½øÐд«²¼¡£

×ϺüľÂíÔËÐÐÖ®ºó£¬»áÏÂÖîÈçµØÆ¦ÍÆ¹ã¡¢DDoS¹¥»÷¡¢ÍÚ¿ó¡¢Ô¶¿Ø¡¢Ö÷Ò³½Ù³ÖµÈ¶àÖÖ¶ñÒâ²å¼þ¡£ÆäÖÐDDoS¹¥»÷Ö¸±ê¼¯ÖÐÔÚÓÎϷ˽·þ¡¢ÆåÅÆ´ò¶ÄÓÎÏ·¡¢É«ÇéÍøÕ¾µÈ»Ò²úÐÐÒµ¡£

¸üй¦·ò£º

20191210













ÊÂÎñÃû³Æ£º

UDP_ľÂíºóÃÅ_×ϺüGad_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½×ϺüľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË×ϺüľÂí¡£

×ϺüÊÇÒ»¿î¶ñÒâľÂí£¬±»·ÖÆç°²È«³§É̶¨ÃûΪºÚºü¡¢·ÊÍᢾò½ð¹í»êµÈ¡£´«²¼Çþ·¶àÑù£¬Í¨³£Í¨¹ýÓÎÏ·±í¹Ò¡¢µÚÈý·½×°Ö÷¨Ê½°ó¸¿´«²¼¡£»¹Äܹ»Í¨¹ýÓÀºãÖ®À¶ÒÔ¼°MSSQL±¬ÆÆ½øÐд«²¼¡£

×ϺüľÂíÔËÐÐÖ®ºó£¬»áÏÂÖîÈçµØÆ¦ÍÆ¹ã¡¢DDoS¹¥»÷¡¢ÍÚ¿ó¡¢Ô¶¿Ø¡¢Ö÷Ò³½Ù³ÖµÈ¶àÖÖ¶ñÒâ²å¼þ¡£ÆäÖÐDDoS¹¥»÷Ö¸±ê¼¯ÖÐÔÚÓÎϷ˽·þ¡¢ÆåÅÆ´ò¶ÄÓÎÏ·¡¢É«ÇéÍøÕ¾µÈ»Ò²úÐÐÒµ¡£

¸üй¦·ò£º

20191210













ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_×ϺüGad_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½×ϺüľÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁË×ϺüľÂí¡£

×ϺüÊÇÒ»¿î¶ñÒâľÂí£¬±»·ÖÆç°²È«³§É̶¨ÃûΪºÚºü¡¢·ÊÍᢾò½ð¹í»êµÈ¡£´«²¼Çþ·¶àÑù£¬Í¨³£Í¨¹ýÓÎÏ·±í¹Ò¡¢µÚÈý·½×°Ö÷¨Ê½°ó¸¿´«²¼¡£»¹Äܹ»Í¨¹ýÓÀºãÖ®À¶ÒÔ¼°MSSQL±¬ÆÆ½øÐд«²¼¡£

×ϺüľÂíÔËÐÐÖ®ºó£¬»áÏÂÖîÈçµØÆ¦ÍÆ¹ã¡¢DDoS¹¥»÷¡¢ÍÚ¿ó¡¢Ô¶¿Ø¡¢Ö÷Ò³½Ù³ÖµÈ¶àÖÖ¶ñÒâ²å¼þ¡£ÆäÖÐDDoS¹¥»÷Ö¸±ê¼¯ÖÐÔÚÓÎϷ˽·þ¡¢ÆåÅÆ´ò¶ÄÓÎÏ·¡¢É«ÇéÍøÕ¾µÈ»Ò²úÐÐÒµ¡£

¸üй¦·ò£º

20191210













ÊÂÎñÃû³Æ£º

HTTP_Squid_v4.7_»º³åÇøÒç³ö_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2019-12527]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

¸ÃÊÂÎñÅú×¢Ô´IPÖ÷»úÕýÊÔͼͨ¹ýSquid v4.7µÄ»º³åÇøÒç¶Âí½Å¹¥»÷Ö÷ÕÅIPÖ÷»ú¡£¸Ã·ì϶ÊÇÓÉÓÚ¶ÔSquid v4.7ÖеÄdecodeAuthTokenÌìÇÕмܻ×ã²é³­¶ø²úÉú¡£Î´¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷ÕßÄܹ»ÔÚÖ¸±ê·þÎñÆ÷ÉÏÖ´ÐÐËÁÒâ´úÂë¡£

¸üй¦·ò£º

20191210











ÊÂÎñÃû³Æ£º

HTTP_WordPress_Plugin_FastVelocityMinify_¾ø¶Ôõ辶й¶·ì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

WordPress Plugin FastVelocityMinify ¾ø¶Ôõ辶й¶·ì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ¡£

WordPress Plugin Fast Velocity MinifyÖдæÔÚ¾ø¶Ôõ辶й¶·ì϶£¬¹¥»÷Õß¿ÉÀûÓø÷ì϶»ñÈ¡Ãô¸ÐÐÅÏ¢¡£

¸üй¦·ò£º

20191210











Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_VBS.H.Worm.Rat_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£

H-wormÊÇÒ»¸ö»ùÓÚVBS˵»°µÄºóÃÅ£¬Ö°Äܼ«¶È׳´ó¡£H-worm½è¼øÁËnjRATµÄ¿ªÔ´´úÂ룬·þÎñ¶ËΪʹÓÃVBS¾ç±¾±àдµÄÈ䳿²¡¶¾£¬ºÏÓÃÓÚWindowsȫϵ²Ù×÷ϵͳ²¢ÇÒʹÓÃÁ˱ÈÁ¦ÏȽøµÄUser-Agent´«µÝÊý¾ÝµÄ·½Ê½£¬ÖØÒª´«²¼·½Ê½ÓÐÈýÖÖ:µç×ÓÓʼþ¸½¼þ¡¢¶ñÒâÁ´½ÓºÍ±»Ï°È¾µÄUÅÌ´«²¼,Èä³æÊ½µÄ´«²¼»úÔì»áÐγɴóÁ¿µÄϰȾ¡£ÓÉÓÚÆä¼ò½àÓÐЧµÄÔ¶¿ØÖ°ÄÜ¡¢·ÇPE¾ç±¾Ò×ÓÚÃâɱ¡¢±ãÓÚÅú¸ÄµÈ¸öÐÔ,Ò»Ïò±»ºÚ²úËùÇàíù¶ø»îÔ¾ÖÁ½ñ¡£

¸üй¦·ò£º

20191210













ÊÂÎñÃû³Æ£º

HTTP_Jenkins_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2018-1000861]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃHTTP_Jenkins_Ô¶³Ì´úÂëÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÖ÷»úµÄÐÐΪ

¸üй¦·ò£º

20191210