ÿÖÜÉý¼¶²¼¸æ-2021-12-14

°ä²¼¹¦·ò 2021-12-15

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_9002.Rat_APT_¹¥»÷

°²È«ÀàÐÍ£º

Ô¶¿ØºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ä¾ÂíÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£9002.RatÊÇÔÚ»îÔ¾µÄAPTs(AdvancedPersistentThreats)¹¥»÷ £¬ÄÑÒÔ¼ì²â £¬ÇÒ¼«¶ÈÓÐÕë¶ÔÐÔ¡£ÖØÒªÊÇÀûÓÃʱÏÂÊ¢Ðеķì϶´«²¼ £¬ÈçCVE-2013-1347¡¢CVE-2013-2423¡¢CVE-2013-1493µÈ¡£·¢ÏÖÓÐÉÏ´«Óû§Îļþ £¬Ô¶³ÌÖ´ÐкÅÁîµÈÖ°ÄÜ¡£¹¥»÷Õß¿ÉÔ¶³Ì½ÚÔì±»¿Ø¶ËÖ÷»ú×ö¸÷Àà²Ù×÷¡£

¸üй¦·ò£º

20211214

 

 

ÊÂÎñÃû³Æ£º

HTTP_D_Link_ºÅÁî×¢Èë·ì϶

°²È«ÀàÐÍ£º

Âß¼­/Éè¼ÆÃýÎó

ÊÂÎñÃèÊö£º

D-LinkÒ»¼Ò³ö²úÍøÂçÓ²¼þºÍÈí¼þ²úÆ·µÄÆóÒµ £¬ÖØÒª²úÆ·Óл¥»»»ú¡¢ÎÞÏß²úÆ·¡¢¿í´ø²úÆ·¡¢Íø¿¨¡¢Â·ÓÉÆ÷¡¢ÍøÂçÉãÏñ»úºÍÍøÂ簲ȫ²úÆ·(·À»ðǽ)µÈ¡£D-Link´æÔÚÒ»¸öºÅÁî×¢Èë·ì϶ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÏò/getcfg.php·¢ËÍÔ̺¬¶ñÒâºÅÁîµÄÒªÇó £¬´Ó¶øÊµÏÖÔ¶³ÌËÁÒâºÅÁîÖ´ÐÐ

¸üй¦·ò£º

20211214

 

 

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Rotajakiro.Oceanlotus(º£Á«»¨)_ÏνÓ

°²È«ÀàÐÍ£º

ÆäËûºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½ºóÃÅÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷¡£Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅRotajakiro¡£RotajakiroÒÉËÆÊÇAPT×éÖ¯º£Á«»¨ËùµÄʹÓúóÃÅ £¬Ö°Äܼ«¶È׳´ó £¬ÔËÐкóÄܹ»ÆëÈ«½ÚÔ챻ϰȾ»úе¡£

¸üй¦·ò£º

20211214

 


ÊÂÎñÃû³Æ£º

TCP_ºáÏòÒÆ¶¯_PsexecÎļþдÈë

°²È«ÀàÐÍ£º

ÆäËûºóÃÅ

ÊÂÎñÃèÊö£º

PsExecÊÇÒ»¸öÇáÁ¿¼¶µÄtelnet´úÌæ¹¤¾ß £¬ËüʹÄúÎÞÐèÊÖ¶¯×°Öÿͻ§¶ËÈí¼þ¼´¿ÉÖ´ÐÐÆäËûϵͳÉϵĹý³Ì £¬²¢ÇÒÄܹ»»ñµÃÓëºÅÁî½ÚÔį̀ÏÕЩһÑùµÄʵʱ½»»¥ÐÔ¡£PsExec×î׳´óµÄÖ°ÄܾÍÊÇÔÚÔ¶³ÌϵͳºÍÔ¶³ÌÖ§³Ö¹¤¾ß(Èçipconfig¡¢whoami)ÖÐÆô¶¯½»»¥Ê½ºÅÁîÌáÐÑ´°¿Ú £¬ÒÔ±ãÏÔʾÎÞ·¨Í¨¹ýÆäËû·½Ê½ÏÔʾµÄÓйØÔ¶³ÌϵͳµÄÐÅÏ¢¡£

¸üй¦·ò£º

20211214

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Citrix_SD-WAN_Ô¶³Ì´úÂëÖ´Ðзì϶[CVE-2020-8271][CNNVD-202011-1336]

°²È«ÀàÐÍ£º

´úÂëÖ´ÐÐ

ÊÂÎñÃèÊö£º

CitrixSD-WANÊÇÓÉÃÀ¹úCitrix¹«Ë¾¿ª·¢µÄÒ»Ì×¹ãÓòÍø¼¯ÖÐÖÎÀíϵͳ £¬Í¨¹ýÐé¹¹»¯¼¼ÊõʵÏÔìóÒµ¼¶µÄ°²È«¹ãÓòÍø £¬×ÛºÏÀûÓöàÌõÁ´Â· £¬ÊµÏÖ¸ºÔØÆ½ºâ £¬²¢ÄÜÅäÖá¢¼à¿ØºÍ·ÖÎöWANÉϵÄËùÓÐCitrixSD-WANÉ豸¡£CitrixSD-WANͨ¹ýurlÆ¥ÅäʵÏÖÉí·ÝÑéÖ¤ £¬µ«¹¥»÷ÕßÄܹ»Í¨¹ý»ú¹Ø¶ñÒâurlʹµÃApache½âÎöµÄurlºÍCakePHP´«ÈëµÄurl²»Ò»Ö £¬´Ó¶øÈƹý¿Í»§¶ËÖ¤Êé²é³­ £¬ÊµÏÖÔ¶³Ì´úÂëÖ´ÐС£

¸üй¦·ò£º

20211214

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Redmine_ºÅÁîÖ´ÐÐ[CVE-2011-4929][CNNVD-201210-082]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

RedmineÊÇÒ»Ì׿ªÔ´µÄ»ùÓÚWebµÄÏîÄ¿ÖÎÀíºÍȱµã¸ú×Ù¹¤¾ß¡£¸Ã¹¤¾ßÌṩÏîÄ¿ÖÎÀí¡¢ÎÊÌâ¸ú×ٺͻùÓÚ½ÇÉ«µÄ½Ó¼û½ÚÔìµÈÖ°ÄÜ¡£Redmine0.9.x°æ±¾ºÍ1.0.5֮ǰµÄ1.0.x°æ±¾ÖеÄbazaar¿âÊÊÅäÆ÷ÖдæÔÚδÃ÷·ì϶¡£Ô¶³Ì¹¥»÷Õß¿ÉÀûÓø÷ì϶ͨ¹ýδ֪ÏòÁ¿Ö´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20211214

 

 

ÊÂÎñÃû³Æ£º

 HTTP_°²È«·ì϶_Barracuda-Spam-Firewall-img.pl_Ô¶³ÌºÅÁîÖ´ÐÐ[CVE-2005-2847][CNNVD-200509-075]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

BarracudaSpamFirewallÊÇÓÃÓÚ±£»¤Óʼþ·þÎñÆ÷µÄ¼¯³ÉÓ²¼þºÍÈí¼þÀ¬»øÓʼþ½â¾ö¹æ»®¡£BarracudaSpamFirewallÖдæÔÚÔ¶³ÌºÅÁîÖ´Ðзì϶¡£img.pl¾ç±¾ÔÚÓû§¶ÁÈ¡ÍêÎļþ»áÊÔͼ¶Ï¿ªÎļþ¡£ÔÚ/cgi-bin/img.pl¾ç±¾ÖУºmy$file_img=\"/tmp/\".CGI£º£ºparam(\'\'f\'\');open(IMG £¬$file_img)ordie\"Couldnotopenimagebecause£º$!£Ün\";...unlink($file_img);perlopenº¯Êý»¹Äܹ»ÓÃÓÚÖ´ÐкÅÁî¡£ÈôÊÇ×Ö·û´®ÒÔ\"|\"ʵÏֵϰ £¬¾ç±¾¾Í»áÖ´ÐкÅÁî¡£

¸üй¦·ò£º

20211214

 


ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_VINGA_ºÅÁîÖ´Ðзì϶[CVE-2021-43469][CNNVD-202112-350]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

VINGAWR-N300U77.102.1.4853ÊÜgoahead×é¼þÓ°Ïì £¬´æÔÚÒ»´¦ºÅÁîÖ´Ðзì϶¡£¸Ã·ì϶ԴÓÚ¶Ô´«ÈëµÄhost²ÎÊý¹ýÂ˲»ÑϽ÷ £¬µ¼Ö¹¥»÷ÕßÄܹ»×¢Èë¶ñÒâºÅÁîʵÏÖÔ¶³ÌºÅÁîÖ´ÐС£

¸üй¦·ò£º

20211214

 


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_tcp_socketŲÓÃ

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚ³¢ÊÔÔÚÖ÷ÕÅÖ÷»ú½øÐÐtcp_socketŲÓà £¬¿ÉÄÜΪºÅÁî×¢Èë¹¥»÷¡£

¸üй¦·ò£º

20211214

 

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·ì϶_Quest_KACE_Systems_ManagementºÅÁîÖ´Ðзì϶[CVE-2018-11138][CNNVD-201805-1216]

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÉ豸ÀûÓÃQuest_KACE_Systems_ManagementºÅÁîÖ´Ðзì϶¹¥»÷Ö÷ÕÅIPÉ豸¡£QuestKACEϵͳÖÎÀíÉ豸8.0.318download_agent_installer.phpÎļþÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÓû§ÒÔWeb·þÎñÆ÷Óû§wwwµÄÉí·ÝÖ´ÐÐËÁÒâºÅÁî¡£

¸üй¦·ò£º

20211214


 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´® £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪӵÓп϶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈÆ¹ýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211214

 


ÊÂÎñÃû³Æ£º

TCP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÌåʽ×Ö·û´®

°²È«ÀàÐÍ£º

ºÅÁîÖ´ÐÐ

ÊÂÎñÃèÊö£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â £¬ÆäÖ§³Ôìô¶¯Ô¶³ÌÈÕÖ¾·þÎñÆ÷¡£´ËÊÂÎñ´ú±í·¢ÏÖÁËÔ´IPÖ÷»ú·¢ËÍÁËÂú×ãÄÚÖÃlookupÌåʽµÄ×Ö·û´® £¬µ±Ö÷ÕÅIPÖ÷»úºó¶Ë½Ó¹Üµ½´ËÌåʽµÄ×Ö·û´®Ê± £¬»á×Ô¶¯Å²ÓÃlookupÖ°ÄÜ¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ £¬´ËÐÐΪӵÓп϶¨·çÏÕ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓà £¬ÈçÈÆ¹ýWAF¼ì²â £¬²¢½øÐзÇÔ¤ÆÚµÄjndiŲÓá£

¸üй¦·ò£º

20211214