ÿÖÜÉý¼¶²¼¸æ-2023-04-04

°ä²¼¹¦·ò 2023-04-04

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_δÊÚȨ½Ó¼û_Apache_ShenYu_ÖÎÀíϵͳ[CVE-2021-37580]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÔÚÀûÓÃApacheShenYuÖÎÀíϵͳµÄδÊÚȨµÇ¼·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¸Ã·ìÏ¶ÈÆ¹ýJSONWebToken(JWT)°²È«ÈÏÖ¤£¬£¬£¬ £¬£¬£¬£¬£¬Ö±½Ó½øÈëϵͳºó¶Ü¡£¡£¡£¡£¡£¡£¡£ApacheShenYuÊÇÒ»¸öÒì²½µÄ£¬£¬£¬ £¬£¬£¬£¬£¬¸ß»úÄܵÄ£¬£¬£¬ £¬£¬£¬£¬£¬¿ç˵»°µÄ£¬£¬£¬ £¬£¬£¬£¬£¬ÏìӦʽµÄAPIÍø¹Ø¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

DNS_ºÅÁî½ÚÔì_ľÂíºóÃÅ_3CXDesktop.Backdoor_ÏνӷþÎñÆ÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

3CXDesktop App²¿ÃŰ汾ÔÚ¹¹½¨×°Ö÷¨Ê½Ê±£¬£¬£¬ £¬£¬£¬£¬£¬»á´¥·¢¹¥»÷ÕßǶÈëµÄ¶ñÒâ´úÂ룬£¬£¬ £¬£¬£¬£¬£¬²¢ÏÂÔØÏÂÒ»²½¶ñÒâ¸ºÔØÖÁÊܺ¦Ö÷»úÖ´ÐÓ×£¡£¡£¡£¡£¡£¡£

3CXDesktop AppºÏÓÃÓÚLinux¡¢MacOSºÍWindows¡£¡£¡£¡£¡£¡£¡£Óû§¿ÉʹÓÃ3CXDesktop½øÐÐÎÄ×Ö¡¢ÓïÒô¡¢ÊÓÆµ½»»¥¡£¡£¡£¡£¡£¡£¡£3CXÊÇÒ»¼ÒVoIP IPBXÈí¼þ¿ª·¢¹«Ë¾£¬£¬£¬ £¬£¬£¬£¬£¬Ðû³ÆÕ¼Óг¬¹ý60Íò¼Ò¹«Ë¾ºÍ1200ÍòÓû§Ê¹Ó㬣¬£¬ £¬£¬£¬£¬£¬ÆäÖÐÔ̺¬Æû³µ¡¢º½¿Õº½Ìì¡¢½ðÈÚ¡¢Ê³Æ·ÒûÁÏ¡¢µ±¾Ö¡¢¾ÆµêµÈ¶à¸öÐÐÒµµÄ³ÛÃûÆóÒµ¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

DNS_ºÅÁî½ÚÔì_Ô¶¿ØºóÃÅ_¶¾ÔÆÌÙ_ÏνÓC2·þÎñÆ÷

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

·¢ÏÖ¶¾ÔÆÌÙ´¹µöÊÂÎñ¡£¡£¡£¡£¡£¡£¡£¶¾ÔÆÌÙ£¬£¬£¬ £¬£¬£¬£¬£¬±ðÃûÂ̰ߡ¢APT-C-01µÈ£¬£¬£¬ £¬£¬£¬£¬£¬ÊÇÒ»¸ö³Ö¾ÃÕë¶Ô¹úÄÚ¹ú·À¡¢µ±¾Ö¡¢¿Æ¼¼ºÍ½ÌÓýÁìÓòµÄ³ÁÒª»ú¹¹Ö´ÐÐÍøÂç¼äµý¹¥»÷»î¶¯µÄAPTÍŻ£¬£¬ £¬£¬£¬£¬£¬×îÔçÄܹ»×·Òäµ½2007Äê¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯¹ßÓÃÓã²æÊ½´¹µöÍøÂç¹¥»÷£¬£¬£¬ £¬£¬£¬£¬£¬»á°ÎÈ¡Óë¹¥»÷Ö¸±êÌùºÏµÄµö¶üÄÚÈݽøÐй¥»÷»î¶¯£¬£¬£¬ £¬£¬£¬£¬£¬¹ßÓõÄÖ÷ÌâÔ̺¬Í¨Öª¡¢»áÒé×ÊÁÏ¡¢×êÑл㱨µÈ»òÊÇѡȡ¹¥»÷¹¦·ò¶ÎʱÊÂÖ÷Ìâ¡£¡£¡£¡£¡£¡£¡£³ýÁ˸½¼þͶµÝľÂí±í£¬£¬£¬ £¬£¬£¬£¬£¬¶¾ÔÆÌÙ»¹¹ßÓô¹µöÍøÕ¾´¹µö£¬£¬£¬ £¬£¬£¬£¬£¬ÇÔȡָ±êµÄÕË»§ÃÜÂ룬£¬£¬ £¬£¬£¬£¬£¬½ø¶ø»ñµÃ¸ü¶à³ÁÒªÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¸Ã×éÖ¯ÖØÒª¹Ø×¢·½ÏòÔ̺¬£ºº£Ê¡¢¾ü¹¤¡¢ÉæÌ¨Á½°¶¹ØÏµ¡¢ÖÐÃÀ¹ØÏµµÈ¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

DNS_ľÂí_˫ǹľÂí(DoubleGun)_C2ÓòÃû½âÎöÒªÇó

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

˫ǹľÂí×ÔÉí¼¯RootkitºÍBootkit(ͬʱϰȾMBRºÍVBR)ÓÚÒ»Éí£¬£¬£¬ £¬£¬£¬£¬£¬»¹ÓÐÖî¶àÆ¥µÐ´ëÊ©¡£¡£¡£¡£¡£¡£¡£³ý´ËÖ®±í£¬£¬£¬ £¬£¬£¬£¬£¬Ë«Ç¹Ä¾Âí¶ñÒâ»î¶¯ÓйصÄÍøÂç»ù´¡ÉèÊ©¼«¶È´íÔÓ£¬£¬£¬ £¬£¬£¬£¬£¬Ï°È¾õè¾¶·±Ëö¡¢´«²¼¼¿Á©¶àÑù¡£¡£¡£¡£¡£¡£¡£¸ÃÊÂÎñÅúע˫ǹľÂíÔÚÒªÇó¶ñÒâC2ÓòÃû¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

DNS_ľÂíºóÃÅ_ħµÁ_C2ÓòÃû½âÎöÒªÇó

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

2022Äê9Ô£¬£¬£¬ £¬£¬£¬£¬£¬ÎÒÃǼà²âµ½Ò»Åú¼Ù×°³ÉCorelDraw¡¢Notepad++¡¢IDA Pro¡¢WinHexµÈ¶à¿îʵÓÃÈí¼þ½øÐд«²¼µÄÇÔÃÜľÂí¡£¡£¡£¡£¡£¡£¡£Í¨¹ý¸ú×Ù¼à²â·¢ÏÔìäÖðÈÕÉÏÏß¾³ÄÚÈ⼦Êý£¨ÒÔIPÊýÍÆË㣩×î¶àÒѳ¬¹ý1.3Íò£¬£¬£¬ £¬£¬£¬£¬£¬ÓÉÓÚ¸ÃÇÔÃÜľÂí»áÍøÂçä¯ÀÀÆ÷ÊéÇ©¡¢ÓÊÏäÕË»§µÈÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬¹ÊÎÒÃǽ«¶¨ÃûΪ¡°Ä§µÁ¡±¡£¡£¡£¡£¡£¡£¡£

 

¹¥»÷ÕßÀûÓà ¡°cdr[.]jyxwlkj.cn¡±¼°¡°cdrnb[.]jyxwlkj.cn¡±ÓòÃû³ÉÁ¢¶à¸öÈí¼þÏÂÔØÒ³Ãæ£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚͶ·Å¼Ù×°³ÉʵÓÃÈí¼þµÄ¡°Ä§µÁ¡±ÇÔÃÜľÂí¡£¡£¡£¡£¡£¡£¡£ÇÔÃÜľÂíÔËÐкó»áÍøÂçÊܺ¦ÕßÖ÷»úÖÐÒÑ×°ÖõÄÈí¼þÁбíÓë¶à¿îä¯ÀÀÆ÷µÄº¹Çà¼Í¼¡¢ÊéÇ©Êý¾ÝºÍÓʼþ¿Í»§¶ËÓÊÏäÕË»§ÐÅÏ¢£¬£¬£¬ £¬£¬£¬£¬£¬²¢¼ÓÃܻش«ÖÁ¹¥»÷Õß·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚ²¿ÃŶñÒⷨʽ¾ß±¸ÔÚÏßÉý¼¶ÄÜÁ¦£¬£¬£¬ £¬£¬£¬£¬£¬Òò¶ø¹¥»÷Õß¿ÉËæÊ±¸ü¸Ä¹¥»÷ÔØºÉ£¨ÈçÀÕË÷¡¢ÍÚ¿ó¡¢ÇÔÃÜµÈ·ÖÆçÖ÷ÕŵĹ¥»÷ÔØºÉ£©£¬£¬£¬ £¬£¬£¬£¬£¬¸øÊܺ¦ÕßÔì³É¸ü´óËðʧ¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ÎļþÉÏ´«_ÖÂÔ¶OA_htmlofficeservlet

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´ipÖ÷»úÔÚÀûÓÃÖÂÔ¶OAÖдæÔÚµÄÎļþÉÏ´«·ì϶½øÐй¥»÷¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷ÕßÔÚÎÞÐèµÇ¼µÄÇé¿öÏ¿Éͨ¹ýÏò/seeyon/htmlofficeservlet·¢Ë;«ÐÄ»ú¹ØµÄÊý¾Ý¼´¿ÉÏòÖ¸±ê·þÎñÆ÷дÈëËÁÒâÎļþ£¬£¬£¬ £¬£¬£¬£¬£¬Ð´Èë³É¹¦ºó¿ÉÖ´ÐÐËÁÒâϵͳºÅÁî½ø¶ø½ÚÔìÖ¸±ê·þÎñÆ÷¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_·´ÐòÁл¯_Apache_InLong_JDBC[CVE-2023-27296]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

Apache InLongÊÇÒ»¸öÓÃÓÚº£Á¿Êý¾ÝµÄһվʽ¼¯³É¿ò¼Ü£¬£¬£¬ £¬£¬£¬£¬£¬Ìṩ×Ô¶¯¡¢°²È«ºÍ¿¿µÃסµÄÊý¾Ý´«ÊäÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£InLongͬʱ֧³ÖÅú´¦ÖúÍÁ÷Êý¾Ý´¦Ö㬣¬£¬ £¬£¬£¬£¬£¬Îª»ùÓÚÁ÷Êý¾Ý¹¹½¨Êý¾Ý·ÖÎö¡¢½¨Ä£ºÍÆäËûʵʱÀûÓ÷¨Ê½ÌṩÁË׳´óµÄÄÜÁ¦¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚÆä´æÔÚ²»°²È«µÄ·´ÐòÁл¯·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ý¾«ÐÄ»ú¹ØµÄpayload¹¥»÷Ö¸±ê·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬Ôì³ÉËÁÒâ´úÂëÖ´ÐлòËÁÒâÎļþ¶ÁÈ¡¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_´úÂëÖ´ÐÐ_pyLoad-pyimport[CVE-2023-0297]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÖ÷ÕÅÖ÷»úÉϵÄpyLoad£¨Ó×ÓÚ0.5.0b3.dev31£©£¬£¬£¬ £¬£¬£¬£¬£¬ÀûÓÃjs2pyÖ°ÄܵÄδÊÚȨ·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬»ú¹Ø¶ñÒâpython´úÂë½øÐй¥»÷¡£¡£¡£¡£¡£¡£¡£pyLoadÊÇÒ»¸öÓÃPython±àдµÄÃâ·ÑºÍ¿ªÔ´ÏÂÔØÖÎÀíÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬¿ÉÓÃÓÚNAS¡¢ÏÂÒ»´ú·ÓÉÆ÷¡¢ÎÞÍ·¼ÒÍ¥·þÎñÆ÷ÒÔ¼°ÈκοÉÄÜÏνӵ½»¥ÁªÍø²¢Ö§³ÖPython±à³Ì˵»°µÄÉ豸¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

Åú¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_°²È«·çÏÕ_ÅäÏàÐÅÏ¢_Swagger½Ó¿Ú

°²È«ÀàÐÍ£º

°²È«Éó¼Æ

ÊÂÎñÃèÊö£º

SwaggerÊÇÒ»¿îRESTFUL½Ó¿ÚµÄ¡¢»ùÓÚYAML¡¢JSON˵»°µÄÎĵµÔÚÏß×Ô¶¯ÌìÉú¡¢´úÂë×Ô¶¯ÌìÉúµÄ¹¤¾ß¡£¡£¡£¡£¡£¡£¡£spring¿ò¼ÜÖÐÒ²»áʹÓÃSwagger£ºspringfox-swagger2£¨2.4£©springfox-swagger-ui£¨2.4£©£¬£¬£¬ £¬£¬£¬£¬£¬ÓйØÎļþ¼Ð±»½Ó¼ûÓÐÐÅϢй¶·çÏÕ¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Weblogic_ForeignOpaqueReference×é¼þ_JNDI×¢Èë_´úÂëÖ´ÐÐ[CVE-2023-21839]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÀýÈçJava¡£¡£¡£¡£¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚForeignOpaqueReferenceÀà´æÔÚ°²È«ÎÊÌ⣬£¬£¬ £¬£¬£¬£¬£¬CVE-2023-21839·ì϶ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3/IIOPºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Ó°ÏìÁìÓò£ºOracleWebLogicServer12.2.1.3.0OracleWebLogicServer12.2.1.4.0OracleWebLogicServer14.1.1.0.0

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

TCP_·ì϶ÀûÓÃ_Oracle_·´ÐòÁл¯_Weblogic_T3ºÍ̸[CVE-2020-14756][CVE-2021-2394]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

OracleWebLogicServerÊÇÒ»¸öͳһµÄ¿ÉÀ©´óƽ̨£¬£¬£¬ £¬£¬£¬£¬£¬ÓÃÓÚÔÚ±¾µØºÍÔÆ¶Ë¿ª·¢¡¢²¿ÊðºÍÔËÐÐÆóÒµÀûÓ÷¨Ê½£¬£¬£¬ £¬£¬£¬£¬£¬ÀýÈçJava¡£¡£¡£¡£¡£¡£¡£WebLogicServerÌṩÁËJavaEnterpriseEdition(EE)ºÍJakartaEEµÄ¿¿µÃס¡¢³ÉÊìºÍ¿ÉÀ©´óµÄʵÏÖ¡£¡£¡£¡£¡£¡£¡£CVE-2020-2555·ì϶Äܹ»ÈƹýºÚÃûµ¥Í¨¹ý·´ÐòÁл¯´¥·¢ExtractorÖв»°²È«µÄextract²½Ö裬£¬£¬ £¬£¬£¬£¬£¬ÔÊÐíδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì¹¥»÷Õßͨ¹ýT3ºÍÌ¸ÍøÂç½Ó¼û²¢·ÛËéÒ×Êܹ¥»÷µÄWebLogic·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬³É¹¦ÀûÓô˷ì϶¿ÉÄܵ¼ÖÂOracleWebLogic·þÎñÆ÷±»ÊÕÊÜ»òÃô¸ÐÐÅϢй¶¡£¡£¡£¡£¡£¡£¡£Ó°ÏìÁìÓò£ºOracleCoherence10.3.6.0.0OracleCoherence12.1.3.0.0OracleCoherence12.2.1.3.0OracleCoherence12.2.1.4.0

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

HTTP_½©Ê¬ÍøÂç_Andromeda_ÏνÓ

°²È«ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÃèÊö£º

¼ì²âµ½½©Ê¬ÍøÂçAndromedaÊÔͼÏνÓÔ¶³Ì·þÎñÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬Ô´IPµØµãµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËAndromeda¡£¡£¡£¡£¡£¡£¡£AndromedaÊÇÒ»¸öÄ £¿£¿£¿£¿£¿£¿£¿£¿é»¯µÄ½©Ê¬ÍøÂ磬£¬£¬ £¬£¬£¬£¬£¬×îԭʼµÄÎļþ½öÔ̺¬Ò»¸ö¼ÓÔØÆ÷¡£¡£¡£¡£¡£¡£¡£ÔËÐÐÆÚ¼ä£¬£¬£¬ £¬£¬£¬£¬£¬»á´ÓC&C·þÎñÆ÷ÏÂÔØ¸÷ÀàÄ £¿£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬ £¬£¬£¬£¬£¬Í¬Ê±Ò²ÓµÓз´Ðé¹¹»úºÍ·´µ÷ÊÔµÄÖ°ÄÜ¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404

 

ÊÂÎñÃû³Æ£º

HTTP_·ì϶ÀûÓÃ_ºÅÁîÖ´ÐÐ_ºêµçH8922[CVE-2021-28150][CNNVD-202105-280]

°²È«ÀàÐÍ£º

°²È«·ì϶

ÊÂÎñÃèÊö£º

¼ì²âµ½Ô´IPÖ÷»úÔÚÀûÓÃÖ÷ÕÅIPÖ÷»úºêµçH8922·ÓÉÆ÷µÄtools.cgiÀïµÄ·ì϶½øÐÐÔ¶³ÌºÅÁîÖ´Ðй¥»÷¡£¡£¡£¡£¡£¡£¡£H8922ÊÇÀö½­Êкêµç¼¼Êõ¹É·ÝÓÐÏÞ¹«Ë¾µÄÒ»¿î¹¤ÒµÂ·ÓÉÆ÷£¬£¬£¬ £¬£¬£¬£¬£¬Àû2G/3G/4GÎÞÏßÍøÂçΪÓû§ÌṩÎÞÏß³¤¾àÀëÊý¾Ý´«ÊäÖ°ÄÜ£¬£¬£¬ £¬£¬£¬£¬£¬ÖØÒªÀûÓÃÓÚ½ðÈÚ¡¢½»Í¨¡¢µçÁ¦¡¢»·±£¡¢¹¤Òµ×Ô¶¯»¯¡¢Ã³Ò×Á¬ËøµÈÐÐÒµ¡£¡£¡£¡£¡£¡£¡£HongdianH89223.0.5ÀïµÄtools.cgi´æÔÚ°²È«·ì϶£¬£¬£¬ £¬£¬£¬£¬£¬¸Ã·ì϶ÔÊÐí·ÇÌØÈ¨Óû§Í¨¹ýĬÈÏÓû§½øÈëºó¶ÜÖ´ÐÐËÁÒâϵͳºÅÁî¡£¡£¡£¡£¡£¡£¡£

¸üй¦·ò£º

20230404