2019-11-26

Ðû²¼Ê±¼ä 2019-11-26

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_SCADA_Schneider_Electric_U.motion_Builder_ÊäÈëÑéÖ¤Îó²î[CVE-2018-7787]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃSchneider Electric U.motion BuilderÊäÈëÑéÖ¤Îó²îÀ´Ö´Ðй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£

Schneider Electric U.motion BuilderÊÇ·¨¹úÊ©ÄÍµÂµçÆø£¨Schneider Electric£©¹«Ë¾µÄÒ»Ì××Ô¶¯»¯»úÖÆ¹¹½¨½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£

Schneider Electric U.motion Builder 1.3.4֮ǰ°æ±¾Öб£´æÊäÈëÑéÖ¤Îó²î £¬£¬£¬£¬ £¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓÐ׼ȷµÄÑéÖ¤HTTP GETÇëÇóÖС®context¡¯²ÎÊýµÄÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îй¶Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126














ÊÂÎñÃû³Æ£º

HTTP_LCDS_LAquis_SCADAÇå¾²Îó²î[CVE-2018-18996]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLCDS LAquis SCADAÇå¾²Îó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£¡£¡£¡£¡£¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î £¬£¬£¬£¬ £¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØÊÚȨ»ò¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126












ÊÂÎñÃû³Æ£º

HTTP_LAquis_SCADA_HTTP²ÎÊýÏÂÁî×¢ÈëÎó²î[CVE-2018-18992]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃLAquis SCADA PAGINA TITULO HTTP²ÎÊýÏÂÁî×¢ÈëÎó²îÀ´Ö´ÐÐÏÂÁîµÄÐÐΪ¡£¡£¡£¡£¡£¡£

LCDS LAquis SCADAÊǰÍÎ÷LCDS¹«Ë¾µÄÒ»Ì×SCADA£¨Êý¾ÝÊÕÂÞÓë¼àÊÓ¿ØÖÆ£©ÏµÍ³¡£¡£¡£¡£¡£¡£¸ÃϵͳÖ÷ÒªÓÃÓÚ¶ÔÓµÓÐͨѶÊÖÒÕµÄ×°±¸¾ÙÐÐÊý¾ÝÊÕÂÞºÍÀú³Ì¿ØÖÆ¡£¡£¡£¡£¡£¡£

LCDS LAquis SCADA 4.1.0.3870°æ±¾Öб£´æÇå¾²Îó²î £¬£¬£¬£¬ £¬£¬¸ÃÎó²îÔ´ÓÚ³ÌÐòûÓоÙÐÐ׼ȷµØ¹ýÂ˱ãÎüÊÕÁËÓû§ÊäÈë¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îÔÚϵͳÉÏÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£

HTTPÒªÇóacompanhamentotela.lhtmlµÄPAGINA²ÎÊýºÍrelatorioindividual.lhtmlµÄÇëÇóÖеÄTITULO²ÎÊý¶¼²»ÊʺÏÏÂÁî×¢Èë×Ö·û¡£¡£¡£¡£¡£¡£ ¹¥»÷Õß¿ÉÒÔ·¢ËÍÌØÖÆµÄHTTP GET»òPOSTÇëÇó £¬£¬£¬£¬ £¬£¬ÒÔÔÚÄ¿µÄÅÌËã»úÉÏÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191119















ÊÂÎñÃû³Æ£º

TCP_Advantech_WebAccess_SCADA_BwPSLinkZip_Stack_Buffer_Overflow

[CVE-2018-7499]

Çå¾²ÀàÐÍ£º

»º³åÒç³ö

ÊÂÎñÐÎò£º

¼ì²âµ½ÊÔͼͨ¹ýʹÓÃAdvantech WebAccess BwPSLinkZip »ùÓÚÕ»µÄ»º³åÇøÒç³öÎó²îÀ´Ö´ÐÐí§Òâ´úÂëµÄÐÐΪ¡£¡£¡£¡£¡£¡£

Advantech WebAccessÊÇÑлª£¨Advantech£©¹«Ë¾µÄ²úÆ·¡£¡£¡£¡£¡£¡£Advantech WebAccessÊÇÒ»Ì×»ùÓÚä¯ÀÀÆ÷¼Ü¹¹µÄHMI/SCADAÈí¼þ¡£¡£¡£¡£¡£¡£¸ÃÈí¼þÖ§³Ö¶¯Ì¬Í¼ÐÎÏÔʾºÍʵʱÊý¾Ý¿ØÖÆ £¬£¬£¬£¬ £¬£¬²¢ÌṩԶ³Ì¿ØÖƺÍÖÎÀí×Ô¶¯»¯×°±¸µÄ¹¦Ð§¡£¡£¡£¡£¡£¡£WebAccess DashboardÊÇÆäÖеÄÒ»¸öÒDZí°å×é¼þ£»£»£»£»£»WebAccess Scada NodeÊÇÆäÖеÄÒ»¸ö¼à¿Ø½Úµã×é¼þ¡£¡£¡£¡£¡£¡£WebAccess/NMSÊÇÒ»Ì×ÓÃÓÚÍøÂçÖÎÀíϵͳ£¨NMS£©µÄÍøÂçä¯ÀÀÆ÷»ù´¡Ì×¼þ¡£¡£¡£¡£¡£¡£

¸ÃÎó²îÊÇÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½BwPSLinkZip.exeµÄ¿ÍÕ»»º³åÇøÖÐʱȱÉÙ½çÏß¼ì²éËùÖ¡£¡£¡£¡£¡£¡£

ͨ¹ý¹¹½¨ÌØÊâµÄRPCÇëÇó £¬£¬£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÔÚWebAccessÀú³ÌµÄÉÏÏÂÎÄÖе¼ÖÂí§Òâ´úÂëÖ´ÐлòÒì³£ÖÕÖ¹¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126



















ÐÞ¸ÄÊÂÎñ



ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_KG.Rat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£

KuGou.RatÊÇÒ»¸öºóÃÅ £¬£¬£¬£¬ £¬£¬ÅþÁ¬Ô¶³ÌЧÀÍÆ÷ £¬£¬£¬£¬ £¬£¬½ÓÊÜÖ´ÐкڿÍÖ¸Áî £¬£¬£¬£¬ £¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£¡£ÊÔͼ»ñÈ¡Ãô¸Ð £¬£¬£¬£¬ £¬£¬Èç¼Í¼°´¼üÐÅÏ¢ £¬£¬£¬£¬ £¬£¬»ñÈ¡½¹µã´°¿ÚµÄÎÊÌâ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126










ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_PoisonIvy_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£

Poison IvyÊÇÒ»¸öºÜÊÇÊ¢ÐеÄÔ¶³Ì¿ØÖƹ¤¾ß £¬£¬£¬£¬ £¬£¬ÔÊÐí¹¥»÷ÕßÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Win32.WarZoneRat_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ºóÃÅÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËWarZoneRat¡£¡£¡£¡£¡£¡£

WarZoneRatÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄÔ¶¿Ø £¬£¬£¬£¬ £¬£¬ÔËÐкó¿ÉÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_ÓÄÁéÔ¶¿Ø¿ÉÒɱäÖÖ_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£

ÓÄÁéÔ¶¿Ø³ÌÐòÊÇʹÓÃÒ»¸öƾ֤Gh0stÔ¶¿ØµÄÔ´ÂëÐ޸ĶøÀ´µÄºóÃÅ¡£¡£¡£¡£¡£¡£ÔËÐкó¿ÉÒÔÍêÈ«¿ØÖƱ»Ñ¬È¾»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126










ÊÂÎñÃû³Æ£º

TUDP_ºóÃÅ_Win32.ZeroAcess_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£

Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËľÂí¡£¡£¡£¡£¡£¡£

Win32.ZeroAcessÊÇÒ»¸öºóÃÅ £¬£¬£¬£¬ £¬£¬ÔËÐÐºó £¬£¬£¬£¬ £¬£¬×¢ÈëÆäËûÀú³Ì¡£¡£¡£¡£¡£¡£ÏÂÔØÆäËû²¡¶¾»òÕßÉèÖÃÐÅÏ¢»òÕßÄ£¿£¿£¿éµÈ»òÇÔÈ¡Ãô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£

Éϱ¨¸ÃÊÂÎñÓÐÁ½ÖÖ¿ÉÄÜ £¬£¬£¬£¬ £¬£¬Ò»ÊÇÔ´Ö÷»ú±»Ñ¬È¾ÁË £¬£¬£¬£¬ £¬£¬ÅþÁ¬CCЧÀÍÆ÷£»£»£»£»£»¶þÊÇZeroAcessЧÀÍÆ÷¶Ëͨ¹ýshadanÊðÀí·½·¨¾ÙÐÐɨÃèÐÐΪ £¬£¬£¬£¬ £¬£¬Ö÷Òª¿´Ô´IPÊÇ·ñÊDZ¾µ¥Î»µÄIPµØµã¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126












ÊÂÎñÃû³Æ£º

TCP_ºóÃÅ_Linux.BillGates_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅBillGates¡£¡£¡£¡£¡£¡£

BillGatesÊÇLinuxƽ̨ϵÄÒ»¸ö½©Ê¬ÍøÂç £¬£¬£¬£¬ £¬£¬Ö÷Òª¹¦Ð§ÊÇÕë¶ÔÖ¸¶¨Ä¿µÄ¾ÙÐÐDDoS¹¥»÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126









ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_ÅþÁ¬¿ó³ØÀÖ³É

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinMinerľÂí¡£¡£¡£¡£¡£¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ £¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126









ÊÂÎñÃû³Æ£º

HTTP_ºóÃÅ_Win32.wingames(ÂûÁ黨)_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁ˺óÃÅwingames¡£¡£¡£¡£¡£¡£

wingamesÊÇÒ»¸ö¹¦Ð§ºÜÊÇǿʢµÄºóÃÅ £¬£¬£¬£¬ £¬£¬ÔËÐÐºó £¬£¬£¬£¬ £¬£¬¿ÉÒÔÍêÈ«¿ØÖƱ»Ö²Èë»úе¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126








ÊÂÎñÃû³Æ£º

TCP_ľÂí_CoinMiner_ʵÑéÅþÁ¬¿ó³Ø

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ä¾ÂíÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËCoinminerľÂí¡£¡£¡£¡£¡£¡£

CoinMinerÊÇÒ»¿îÍÚ¿ó¶ñÒâ³ÌÐò £¬£¬£¬£¬ £¬£¬ÍÚ¿ó³ÌÐò»áÕ¼ÓÃCPU×ÊÔ´ £¬£¬£¬£¬ £¬£¬¿ÉÄܵ¼ÖÂÊܺ¦Ö÷»ú±äÂý¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20191126