2020-05-12
Ðû²¼Ê±¼ä 2020-05-12ÐÂÔöÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
TCP_SaltStack_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î[CVE-2020-11651/CVE-2020-11652] |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSaltStackµÄÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î(CVE-2020-11651)¶ÔÄ¿µÄIPÖ÷»úµÄSaltStackÓ¦ÓþÙÐй¥»÷µÄÐÐΪ¡£¡£ saltstackÊÇ»ùÓÚpython¿ª·¢µÄÒ»Ì×C/S×Ô¶¯»¯ÔËά¹¤¾ß¡£¡£ÓÉÓÚÓ¦ÓÃÖд¦Öóͷ£Î´ÈÏÖ¤ÇëÇóµÄClearFuncsÀàÖб£´æÁ½¸öΣÏÕµÄÒªÁ죬£¬£¬£¬£¬²¢Ì»Â¶ÔÚÍ⣬£¬£¬£¬£¬Ê¹µÃ¹¥»÷Õß¿ÉÒԽṹ¶ñÒâÇëÇóÒÔÖÎÀíԱȨÏÞÔ¶³ÌÖ´ÐÐí§ÒâÏÂÁ£¬£¬£¬£¬»ñȡЧÀÍÆ÷¿ØÖÆÈ¨£¬£¬£¬£¬£¬Î£º¦ÑÏÖØ¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
TCP_ľÂíºóÃÅ_Win32.Mpsvc_ÅþÁ¬ |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£ MpsvcÊÇÒ»¸öľÂí£¬£¬£¬£¬£¬ÊÇÖйúAPT×éÖ¯º£µÁÐÜèËùʹÓõÄÒ»¿îľÂíºóÃÅ¡£¡£ MpsvcʹÓÃDLL²à¼ÓÔØÊÖÒÕ£¬£¬£¬£¬£¬»ñÈ¡Êܺ¦Ö÷»úµÄÓ²¼þUUID²¢ÉÏ´«µ½C&C£¬£¬£¬£¬£¬¿ÉÒÔÏÂÔØ²¢Ö´ÐÐÆäËûÎļþ¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
ÐÞ¸ÄÊÂÎñ
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspSpy_ÉÏ´«ºóÃųÌÐò |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£ webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_vbs_webshellÒ»¾ä»°Ä¾ÂíÉÏ´« |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»úÕýÏòÄ¿µÄÖ÷»úÉÏ´«VBSÒ»¾ä»°Ä¾ÂíµÄÐÐΪ ¹¥»÷ÕßʵÑéÏòЧÀÍÆ÷ÉÏ´«VBSÒ»¾ä»°Ä¾ÂíÎļþ£¬£¬£¬£¬£¬ÈôÊÇÉÏ´«Àֳɽ«Í¨¹ýÒ»¾ä»°Ä¾ÂíÅþÁ¬¹¤¾ß¶ÔЧÀÍÆ÷¾ÙÐпØÖÆ¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
HTTP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶phpSpy2014_ÉÏ´«ºóÃųÌÐò |
|
Çå¾²ÀàÐÍ£º |
ľÂíºóÃÅ |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£ webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬¾³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
|
ÊÂÎñÃû³Æ£º |
UDP_NFS_¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑé |
|
Çå¾²ÀàÐÍ£º |
Çå¾²Îó²î |
|
ÊÂÎñÐÎò£º |
¼ì²âµ½Ô´IPÖ÷»ú¶ÔÄ¿µÄIP¾ÙÐÐNFS ¹²ÏíÎļþЧÀÍÃô¸ÐÐÅϢй¶Îó²îʵÑéµÄÐÐΪ NFSÈ«³ÆNetwork File System£¬£¬£¬£¬£¬¼´ÍøÂçÎļþϵͳ£¬£¬£¬£¬£¬ÊôÓÚÍøÂç²ã£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÍøÂç¼äÎļþµÄ¹²Ïí£¬£¬£¬£¬£¬×îÔçÓÉsun¹«Ë¾¿ª·¢ ¿ÉÒÔ¶ÔÄ¿µÄÖ÷»ú¾ÙÐÐ"showmount -e"²Ù×÷£¬£¬£¬£¬£¬´Ë²Ù×÷½«Ð¹Â¶Ä¿µÄÖ÷»úµÄÃô¸ÐÐÅÏ¢£¬£¬£¬£¬£¬ºÃ±ÈĿ¼½á¹¹¡£¡£¸üÔã¸âµÄÊÇ£¬£¬£¬£¬£¬ÈôÊÇ»á¼û¿ØÖƲ»Ñϵϰ£¬£¬£¬£¬£¬¹¥»÷ÕßÓпÉÄÜÖ±½Ó»á¼ûµ½Ä¿µÄÖ÷»úÉϵÄÊý¾Ý¡£¡£ |
|
¸üÐÂʱ¼ä£º |
20200512 |
ɾ³ýÊÂÎñ
HTTP_Ŀ¼±éÀú[..\..][CVE-1999-0229]
HTTP_Ŀ¼±éÀú[../]
HTTP_Ŀ¼±éÀú[..\]


¾©¹«Íø°²±¸11010802024551ºÅ