2018-10-12

Ðû²¼Ê±¼ä 2018-10-12

ÐÂÔöÊÂÎñ

ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_OSX_OCEANLOTUS.D(º£Á«»¨)_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅOceanLotus¡£¡£¡£¡£¡£¡£OceanLotusÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄºóÃÅ£¬£¬£¬ £¬£¬£¬Ö÷Ҫͨ¹ýÓʼþÈö²¥¡£¡£¡£¡£¡£¡£OceanLotusÔËÐк󣬣¬£¬ £¬£¬£¬»áʵÑé»ñÈ¡Ãô¸ÐÐÅÏ¢£¬£¬£¬ £¬£¬£¬Ò²¿ÉÖ´ÐÐC&C·µ»ØÖ¸Á£¬£¬ £¬£¬£¬È¥ÏÂÔØÆäËûºóÃÅ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.Nokki_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅNokkiÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËNokki¡£¡£¡£¡£¡£¡£NokkiÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄºóÃÅ£¬£¬£¬ £¬£¬£¬Ê״ηºÆðÊÇÔÚ2018ÄêÒ»Ô£¬£¬£¬ £¬£¬£¬Ö÷ÒªÕë¶ÔÅ·ÖÞ¡¢¶«ÄÏÑǵȵØÇø¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Apache_Portals_Pluto_3.0.0Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2018-1306]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApache PortletV3AnnotatedDemo.MultipartPortlet²å¼þÎļþÉÏ´«Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£ PortletV3AnnotatedDemo.MultipartPortlet²å¼þ±£´æÎļþÉÏ´«Îó²î£¬£¬£¬ £¬£¬£¬Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÉÏ´«í§ÒâÎļþ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_NVRMini2_ÈÆ¹ýÉí·ÝÑéÖ¤ÐÞ¸ÄÓû§ÃÜÂë[CVE-2018-1150]

ÊÂÎñ¼¶±ð£º

³õ¼¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃNVRMini2_ÈÆ¹ýÉí·ÝÑéÖ¤ÐÞ¸ÄÓû§ÃÜÂë¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£ÈôÊDZ£´æÃûΪ/ tmp / mosesµÄÎļþ£¬£¬£¬ £¬£¬£¬ÔòÆôÓúóÃÅ¡£¡£¡£¡£¡£¡£ËüÔÊÐíÔÚϵͳÉÏÁгöËùÓÐÓû§ÕÊ»§£¬£¬£¬ £¬£¬£¬²¢ÔÊÐíijÈ˸ü¸ÄÈκÎÕÊ»§µÄÃÜÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_NVRMini2_cgi_system_»º³åÇøÒç³öÎó²î[CVE-2018-1149]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

Çå¾²ÀàÐÍ£º

»º³åÒç³ö 

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃNVRMini2_cgi_system»º³åÇøÒç³öÎó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£¡£¡£¡£ NVRMini2ʹÓÿªÔ´WebЧÀÍÆ÷£¬£¬£¬ £¬£¬£¬Í¨¹ý¹«¹²Íø¹Ø½Ó¿Ú£¨CGI£©Ð­ÒéÖ§³ÖһЩ¿ÉÖ´Ðжþ½øÖÆÎļþ¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿ÉÒÔÔÚNVRMini2ÉÏÖ´ÐеÄCGI¶þ½øÖÆÎļþÖ®Ò»ÊÇ¡°cgi_system¡±£¬£¬£¬ £¬£¬£¬¿ÉÒÔͨ¹ýhttp£º// xxxx / cgi-bin / cgi_system»á¼ûËü¡£¡£¡£¡£¡£¡£´Ë¶þ½øÖÆÎļþ´¦Öóͷ£ÐèÒªÓû§¾ÙÐÐÉí·ÝÑéÖ¤µÄÖÖÖÖÏÂÁîºÍ²Ù×÷¡£¡£¡£¡£¡£¡£ÔÚÉí·ÝÑé֤ʱ´ú£¬£¬£¬ £¬£¬£¬²»¼ì²écookie²ÎÊýµÄ»á»°ID¾Þϸ£¬£¬£¬ £¬£¬£¬ÕâÔÊÐísprintfº¯ÊýÖеĿÍÕ»»º³åÇøÒç³ö¡£¡£¡£¡£¡£¡£´ËÎó²îÔÊÐíʹÓá°root¡±»òÖÎÀíԱȨÏÞÖ´ÐÐÔ¶³Ì´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Music_Collection_3.0.3_SQL×¢ÈëÎó²î[CVE-2018-17375]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷ 

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃJoomla_Component_Music_Collection_3.0.3_SQL_InjectionÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Reverse_Auction_Factory_4.3.8_SQL_Injection[CVE-2018-17376]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃJoomla_Component_Reverse_Auction_Factory_4.3.8_SQL_InjectionÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Questions_1.4.3_SQL_Injection[CVE-2018-17377]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApache Struts2Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£ Apache StrutsÊÇÃÀ¹ú°¢ÅÁÆæ£¨Apache£©Èí¼þ»ù½ð»áÈÏÕæÎ¬»¤µÄÒ»¿îÓÃÓÚ½¨ÉèÆóÒµ¼¶JavaWebÓ¦ÓõĿªÔ´¿ò¼Ü¡£¡£¡£¡£¡£¡£ Apache Struts 2.0.0ÖÁ2.3.15.1°æ±¾Öб£´æÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòĬÈÏÆôÓÃDynamic Method Invocation»úÖÆ¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓôËÎó²îÔÚÊÜÓ°ÏìÓ¦ÓÃÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_Joomla_Component_Penny_Auction_Factory_2.0.4_SQL_Injection[CVE-2018-17378]

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÊÔͼʹÓÃJoomla_Component_Questions_1.4.3_SQL_InjectionÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

TCP_Malware_VPNFilter_±äÖÖÅþÁ¬CC

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ 

ÊÂÎñÐÎò£º

¼ì²âµ½VPNFilterÊÔͼͨ¹ýSYNËíµÀÊÖÒÕ»ñÈ¡C&CµÄIPµØµã¡£¡£¡£¡£¡£¡£ ¸Ã¶ñÒâÈí¼þͨ¹ýʹÓ÷ÓÉÆ÷¡¢Íø¹Ø¡¢·À»ðǽµÈÎïÁªÍø×°±¸Îó²î¾ÙÐÐÆÕ±éµÄѬȾºÍÈö²¥

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÐÞ¸ÄÊÂÎñ

ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_ZXShell_·´ÏòÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¸ÃÊÂÎñÔ´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËZXShellľÂí£¬£¬£¬ £¬£¬£¬Ä¾ÂíµÄ¿ØÖÆÕß¿ÉÒÔͨ¹ý¸ÃľÂí¶Ô±»Ö²ÈëľÂíµÄÖ÷»úʵÑéÍêÈ«µÄ¿ØÖÆ¡£¡£¡£¡£¡£¡£ ZXShellÊÇÒ»¿îÔ¶³Ì¿ØÖƳÌÐò£¬£¬£¬ £¬£¬£¬Ö÷Òª¹¦Ð§ÈçÏ£º Ô¶³Ì×¥ÆÁ£¬£¬£¬ £¬£¬£¬ÊÓÆµ²¶»ñ£¬£¬£¬ £¬£¬£¬ÎļþÖÎÀí¡¢×¢²á±íÖÎÀí¡¢Àú³ÌÖÎÀí¡¢¼üÅ̼ͼ¡¢Ô¶³ÌÖ´ÐÐÎļþ£¬£¬£¬ £¬£¬£¬Ô¶³ÌÏÂÔØÎļþµÈ¹¦Ð§¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.DDoS.Gafgyt_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ 

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËDDoS.Gafgyt¡£¡£¡£¡£¡£¡£ DDoS.GafgytÊÇÒ»¸öLinux½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄ»úеÌᳫDDoS¹¥»÷

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú


ÊÂÎñÃû³Æ£º

HTTP_ľÂí_Win32.TaskHost.Stealer_ÅþÁ¬

ÊÂÎñ¼¶±ð£º

Öм¶ÊÂÎñ

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂíTaskHost¡£¡£¡£¡£¡£¡£ TaskHostÊÇÒ»¸öÇÔÃÜľÂí£¬£¬£¬ £¬£¬£¬»áÉÏ´«Ìض¨ºó׺ÃûµÄÎļþµ½ÆäC&C£¬£¬£¬ £¬£¬£¬Èç.doc¡¢.xls¡¢.pdf¡¢.ppt¡¢.eml¡¢.msg¡¢.rtfµÈ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20181012

ĬÈÏÐж¯£º

ÑïÆú