ÿÖÜÉý¼¶Í¨¸æ-2021-05-25

Ðû²¼Ê±¼ä 2021-05-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÔ¶³Ì´úÂëÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ºÍÐÅÏÂÒ»´úÔÆ×ÀÃæÏµÍ³£¨VENGD£©£¬ £¬£¬ÊǺ£ÄڵĻùÓÚNGD(NextGenerationDesktop)¼Ü¹¹µÄ×ÀÃæÐéÄ⻯²úÆ·£¬ £¬£¬ËüÈÚºÏÁËVDI¡¢VOI¡¢IDVÈý´ó¼Ü¹¹ÓÅÊÆ£¬ £¬£¬ÊµÏÖÁËǰºó¶Ë»ìÏýÅÌË㣬 £¬£¬ÔÚµ÷ÀíЧÀÍÆ÷ºó¶ËÅÌËã×ÊÔ´µÄͬʱ¸üÄܳä·ÖʹÓÃǰ¶Ë×ÊÔ´ ¡£¡£¡£¡£¡£¡£¡£¸Ãϵͳ±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ £¬£¬¹¥»÷Õß¿É½á¹¹ÌØ¶¨ÇëÇó°ügetshell ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_ÖÂÔ¶OA_webmail.doí§ÒâÎļþÏÂÔØÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÖÂÔ¶OAÊDZ±¾©ÖÂÔ¶»¥ÁªÈí¼þ¹É·ÝÓÐÏÞ¹«Ë¾Ñз¢Ò»¿î°ì¹«ÏµÍ³£¬ £¬£¬ÖÂÔ¶OA±£´æí§ÒâÎļþÏÂÔØÎó²î£¬ £¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²îÏÂÔØí§ÒâÎļþ£¬ £¬£¬»ñÈ¡Ãô¸ÐÐÅÏ¢ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


2.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èív8.0í§ÒâÎļþ¶ÁÈ¡Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚ¶ÔÄ¿µÄipÖеķ«Èív8.0¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡ÐÐΪ£¬ £¬£¬ÆäÖпÉÒÔͨ¹ý¶ÁÈ¡privilege.xmlÇÔÈ¡ÃÜÂë¾ÙÐнøÒ»²½µÄ¹¥»÷£» £»£»£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬ £¬£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ £¬£¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬ £¬£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


3.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ8.0_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓ÷«Èí±¨±í²å¼þ8.0ÖеÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ¡²Ù×÷£» £»£»£»FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬ £¬£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ £¬£¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬ £¬£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


4.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_·«Èí±¨±í²å¼þ9.0_GetshellÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÒÔ»ñÈ¡·«Èíºǫ́ȨÏÞ£¬ £¬£¬Í¨¹ýÉÏ´«Ñ¹ËõÎļþ¾ÙÐÐgetshell²Ù×÷£¬ £¬£¬FineReport±¨±íÈí¼þÊÇÒ»¿î´¿Java±àдµÄ¡¢¼¯Êý¾Ýչʾ(±¨±í)ºÍÊý¾Ý¼Èë(±íµ¥)¹¦Ð§ÓÚÒ»ÉíµÄÆóÒµ¼¶web±¨±í¹¤¾ß£¬ £¬£¬Ëü¡°×¨Òµ¡¢¼ò½Ý¡¢ÎÞа¡±µÄÌØµãºÍÎÞÂëÀíÄ £¬£¬½öÐè¼òÆÓµÄÍÏ×§²Ù×÷±ã¿ÉÒÔÉè¼ÆÖØ´óµÄÖйúʽ±¨±í£¬ £¬£¬´î½¨Êý¾Ý¾öÒéÆÊÎöϵͳ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC6.5_í§ÒâÎļþÉÏ´«Îó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNC6.5µÄÎó²î¾ÙÐÐí§ÒâÎļþÉÏ´«£» £»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ £¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_CRM_í§ÒâÎļþ¶ÁÈ¡

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓÑNCµÄÎó²î¾ÙÐÐí§ÒâÎļþ¶ÁÈ¡²Ù×÷£» £»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ £¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÓÃÓÑNC_Ŀ¼±éÀúÎó²î

Çå¾²ÀàÐÍ£º

CGI¹¥»÷

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃÓÃÓѵÄĿ¼±éÀúÎó²î¾ÙÐÐÐÅÏ¢ÇÔÈ ¡£¡£¡£¡£¡£¡£¡£» £»£»£»ÓÃÓÑNCÒÔ¡°È«Çò»¯¼¯ÍŹܿء¢ÐÐÒµ»¯½â¾ö¼Æ»®¡¢È«³Ì»¯µç×ÓÉÌÎñ¡¢Æ½Ì¨»¯Ó¦Óü¯³É¡±µÄÖÎÀíÓªÒµÀíÄî¶øÉè¼Æ£¬ £¬£¬ÊÇÖйú´óÆóÒµ¼¯ÍÅÖÎÀíÐÅÏ¢»¯Ó¦ÓÃϵͳµÄÊ×Ñ¡ ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÐÞ¸ÄÊÂÎñ


1.png


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Weblogic_ServerÔ¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-2109][CNNVD-202101-1453]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃOracleWebLogicÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ £¬£¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔͨ¹ý½á¹¹¶ñÒâHTTPÇëÇóʹÓøÃÎó²î£¬ £¬£¬ÀÖ³ÉʹÓôËÎó²î¿ÉÄܽÓÊÜOracleWebLogicServer ¡£¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20210525


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-020/S2-021/S2-022Ô¶³Ì´úÂëÖ´ÐÐ/DOS[CVE-2014-0094/0112]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú ¡£¡£¡£¡£¡£¡£¡£ApacheStruts2.0.0-2.3.16°æ±¾µÄĬÈÏÉÏ´«»úÖÆ»ùÓÚCommonsFileUpload1.3£¬ £¬£¬Æä¸½¼ÓµÄParametersInterceptorÔÊÐí»á¼û'class'²ÎÊý£¨¸Ã²ÎÊýÖ±½ÓÓ³Éäµ½getClass()ÒªÁ죩£¬ £¬£¬²¢ÔÊÐí¿ØÖÆClassLoader ¡£¡£¡£¡£¡£¡£¡£ÔÚÏêϸµÄWebÈÝÆ÷°²ÅÅÇéÐÎÏ£¨È磺Tomcat£©£¬ £¬£¬¹¥»÷ÕßʹÓÃWebÈÝÆ÷ϵÄJavaClass¹¤¾ß¼°ÆäÊôÐÔ²ÎÊý£¨È磺ÈÕÖ¾´æ´¢²ÎÊý£©£¬ £¬£¬¿ÉÏòЧÀÍÆ÷ÌᳫԶ³Ì´úÂëÖ´Ðй¥»÷£¬ £¬£¬½ø¶øÖ²ÈëÍøÕ¾ºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷Ö÷»ú ¡£¡£¡£¡£¡£¡£¡£ÁíÍ⣬ £¬£¬ÓÉÓÚHTTPÇëÇóµÄContent-Type×Ö¶ÎÖУ¬ £¬£¬boundary´óÓÚ½çÏßÖµ£¬ £¬£¬²¢ÇÒpostÇëÇóÄÚÈÝ´óÓÚ½çÏßÖµ£¬ £¬£¬µ¼ÖÂDDOS ¡£¡£¡£¡£¡£¡£¡£Îó²î±£´æµÄ°æ±¾£ºS2-020£ºStruts2.0.0-Struts2.3.16.1S2-021£ºStruts2.0.0-Struts2.3.16.3S2-022£ºStruts2.0.0-Struts2.3.16.3null

¸üÐÂʱ¼ä£º

20210518


ÐÞ¸ÄÊÂÎñ

1¡¢HTTP_·ºÎ¢OA9.0_Ô¶³Ì´úÂëÖ´ÐÐÎó²î

2¡¢TCP_¿ÉÒÉÐÐΪ_tracertÏÂÁî_Ô¶³ÌÏÂÁîÖ´ÐÐ