2020-07-21

°ä²¼¹¦·ò 2020-07-22

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Laravel_Framework_·´ÐòÁл¯·ì϶[CVE-2019-9081]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½ÀûÓÃLaravel Framework ·´ÐòÁл¯·ì϶½øÐй¥»÷µÄÐÐΪ¡£Laravel FrameworkÊÇTaylor OtwellÈí¼þ¿ª·¢Õß¿ª·¢µÄÒ»¿î»ùÓÚPHPµÄWebÀûÓ÷¨Ê½¿ª·¢¿ò¼Ü¡£IlluminateÊÇÆäÖеÄÒ»¸ö×é¼þ¡£Laravel Framework 5.7.x°æ±¾ÖеÄIlluminate×é¼þ´æÔÚ·´ÐòÁл¯·ì϶ £¬Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ִÐдúÂë¡£

¸üй¦·ò£º

20200721










ÊÂÎñÃû³Æ£º

DNS_°²È«·ì϶_Microsoft_DNS_Server_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-1350]

°²È«ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÃèÊö£º

Windows DNS Server ÊÇ Windows Server ·þÎñÆ÷ÉÏÒ»Ïî³ÁÒªÖ°ÄÜ×é¼þ £¬ÕƹÜÓòÄÚÖ÷»úµÄËùÓÐDNSÓйطþÎñµÄµ÷¶ÈºÍ´¦Öá£Windows DNS ServerÎÞ·¨ÕýÈ·´¦ÖÃSIGÒªÇó £¬Ô¶³Ì¹¥»÷Õ߿ɲ»¾­¹ýÉí·ÝÑéÖ¤ £¬ÏòÊÜÓ°ÏìµÄ·þÎñÆ÷·¢ËÍÌØÔìµÄÒªÇó°ü £¬×îÖÕ´¥·¢¸Ã·ì϶¡£³É¹¦ÀûÓô˷ì϶µÄ¹¥»÷Õß¿ÉÔÚÊÜÓ°ÏìµÄϵͳÉÏÖ´ÐÐËÁÒâ´úÂë £¬½ø¶ø½ÚÔìÆäËûÏàÁ¬Í¨µÄ·þÎñÔì³ÉÑϳÁ·çÏÕ¡£

¸üй¦·ò£º

20200721











ÊÂÎñÃû³Æ£º

TCP_Fastjson_JSON·´ÐòÁл¯_Ô¶³Ì´úÂëÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

FastjsonÊÇÒ»¸öJava¿â £¬Äܹ»½«Java¶ÔÏóת»»ÎªJSONÌåʽ £¬fastjson´æÔÚÔ¶³Ì´úÂëÖ´ÐиßΣ°²È«·ì϶¡£¹¥»÷Õßͨ¹ý·¢ËÍÒ»¸ö¾«ÐÄ»ú¹ØµÄJSONÐòÁл¯¶ñÒâ´úÂë £¬µ±·¨Ê½Ö´ÐÐJSON·´ÐòÁл¯µÄ¹ý³ÌÖÐÖ´ÐжñÒâ´úÂë £¬´Ó¶øµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20200721









ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Jenkins_Groovy²å¼þshellÖ´Ðзì϶

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ê¹ÓÃjavaÃô¸Ðº¯Êýexcute,Ö´Ðгɹ¦¿ÉÄÜ»áÔì³ÉºÅÁîÖ´ÐС£

¸üй¦·ò£º

20200721







ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Lucifer_Satan_DDos_ÉÏ´«ÍÚ¿ó״̬

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

Lucifer/Satan_DDosÊÇÒ»¸ö»ìºÏÐÍľÂí £¬¼ÈÄܹ»½øÐÐÍÚ¿ó £¬ÓÖ¿ÉÄܽøÐÐDDOS¹¥»÷ £¬²¢ÇÒ»¹¿ÉÄÜͨ¹ýÀûÓöà¸ö·ì϶ºÍMSSQL±©Á¦ÆÆ½âÀ´½øÐÐ×ÔÎÒ´«²¼¡£´Ë±í £¬Ëü»áÕë¶ÔÄÚ²¿ÍøÏ°È¾µÄÒ×Êܹ¥»÷Ö¸±ê¿ªÊͲ¢ÔËÐÐEternalBlue £¬EternalRomanceºÍDoublePulsarºóÃÅ¡£¸ÃľÂíÀûÓõķì϶Çåµ¥Ô̺¬£ºCVE-2014-6287 £¬CVE-2018-1000861 £¬CVE-2017-10271 £¬ThinkPHP RCE·ì϶£¨CVE-2018-20062£© £¬CVE-2018-7600 £¬CVE-2017-9791 £¬CVE-2019-9081 £¬PHPStudyºóÃÅRCE £¬CVE-2017-0144 £¬CVE-2017-0145ºÍCVE-2017-8464¡£¸ÃÊÂÎñÅú×¢ÍÚ¿ó·¨Ê½ÔÚÉÏ´«ÍÚ¿ó״̬ÐÅÏ¢¡£

¸üй¦·ò£º

20200721














ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32.Lucifer_Satan_DDos_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ÀûÓûìºÏÐÍľÂíLucifer/Satan_DDosÏνӷþÎñÆ÷µÄÐÐΪ¡£Lucifer/Satan_DDosÊÇÒ»¸ö»ìºÏÐÍľÂí £¬¼ÈÄܹ»½øÐÐÍÚ¿ó £¬ÓÖ¿ÉÄܽøÐÐDDOS¹¥»÷ £¬²¢ÇÒ»¹¿ÉÄÜͨ¹ýÀûÓöà¸ö·ì϶ºÍMSSQL±©Á¦ÆÆ½âÀ´½øÐÐ×ÔÎÒ´«²¼¡£´Ë±í £¬Ëü»áÕë¶ÔÄÚ²¿ÍøÏ°È¾µÄÒ×Êܹ¥»÷Ö¸±ê¿ªÊͲ¢ÔËÐÐEternalBlue £¬EternalRomanceºÍDoublePulsarºóÃÅ¡£¸ÃľÂíÀûÓõķì϶Çåµ¥Ô̺¬£ºCVE-2014-6287 £¬CVE-2018-1000861 £¬CVE-2017-10271 £¬ThinkPHP RCE·ì϶£¨CVE-2018-20062£© £¬CVE-2018-7600 £¬CVE-2017-9791 £¬CVE-2019-9081 £¬PHPStudyºóÃÅRCE £¬CVE-2017-0144 £¬CVE-2017-0145ºÍCVE-2017-8464¡£

¸üй¦·ò£º

20200721















Åú¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_³¢ÊÔÏνӿó³Ø

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£

¸üй¦·ò£º

20200721