2021-04-15

Ðû²¼Ê±¼ä 2021-04-15
ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_Ô¶³Ì´úÂë_CitrixÔ¶³Ì´úÂëÖ´ÐÐ[CVE-2019-19781]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

CitrixADCÊÇÒ»¿îÓ¦Óý»¸¶Controller£¬£¬£¬ÓÃÓÚÆÊÎöÌØ¶¨ÓÚÓ¦ÓõÄÁ÷Á¿£¬£¬£¬ÒÔ±ãÖÇÄܵØÎªWebÓ¦ÓóÌÐò·ÖÅÉ¡¢ÓÅ»¯ºÍ±£»£»£»¤4²ã7(L4-L7)ÍøÂçÁ÷Á¿¡£¡£¡£CitrixGatewayÕûºÏÁËÔ¶³Ì»á¼û»ù´¡½á¹¹£¬£¬£¬ÒÔ±ã¿çËùÓÐÓ¦ÓóÌÐòÌṩµ¥µãµÇ¼£¬£¬£¬ÎÞÂÛÊÇÔÚÊý¾ÝÖÐÐÄ¡¢ÔÆÖÐÕÕ¾É×÷ΪSaaS´«Êä¡£¡£¡£ÔÚCitrixADCºÍCitrixGatewayÖб£´æÄ¿Â¼±éÀúÎó²î£¬£¬£¬ÔÊÐíδÊÚȨµÄ¹¥»÷Õß¿ÉÒÔ¾ÙÐÐÔ¶³ÌÏÂÁî¹¥»÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_Chromium_V8_JavaScriptÒýÇæ_Ô¶³ÌÏÂÁîÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

»ùÓÚChromiumµÄä¯ÀÀÆ÷µÄV8JavaScriptÒýÇæÖÐ,±£´æÒ»¸öÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î¡£¡£¡£¹¥»÷Õß¿Éͨ¹ý¿ØÖÆhtml¼ÓÔØ¶ñÒâJavaScriptÎļþ£¬£¬£¬µÖ´ïÔÚ±»¹¥»÷ÕßÖ÷»úÉÏÖ´ÐÐí§ÒâÏÂÁîµÄЧ¹û¡£¡£¡£µ«´ËÎó²îÎÞ·¨Í»ÆÆChromeɳÏäÕâÒ»Çå¾²»úÖÆ£¬£¬£¬ÒÔÊÇÓ°ÏìÓÐÏÞ¡£¡£¡£ChromeɳÏäÊÇä¯ÀÀÆ÷µÄÇå¾²½çÏߣ¬£¬£¬¿É±ÜÃâÔ¶³Ì´úÂëÖ´ÐÐÎó²îÔÚÖ÷»úÉÏÆô¶¯³ÌÐò£¬£¬£¬¸ÃÎó²îµ¥¶ÀʹÓÃʱÏÖÔÚÎÞ·¨ÌÓÒÝä¯ÀÀÆ÷µÄɳÏ䣬£¬£¬Òò´Ë¸ÃÎó²îÐèÒªÓëÁíÍâµÄÎó²î£¨ChromeɳÏäÌÓÒÝ£©Á´½ÓÔÚÒ»ÆðÀ´Ê¹Ó㬣¬£¬×îÖÕ¿ÉÒÔʵÏÖÔ¶³Ì´úÂëÖ´ÐС£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_TongWeb_ÎļþÉÏ´«È¨ÏÞÒþ²ØÕË»§µÇ¼ʵÑé

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½¹¥»÷ÕßʹÓÃTongWebÔ¤ÁôµÄ£¬£¬£¬¾ßÓÐÎļþÉÏ´«È¨ÏÞµÄÒþ²ØÕË»§¾ÙÐеǼʵÑéµÄÐÐΪ¡£¡£¡£TongWebÊǺ£ÄÚÕþÆóÓªÒµÆÕ±éÓ¦ÓõÄWEBÓ¦ÓÃЧÀÍÆ÷¡£¡£¡£´ËÓ¦Óñ£´æÒ»¸öÒþ²ØµÄÓû§£¬£¬£¬ÇÒÓÐÀο¿µÄ¡¢ÎÞ·¨¸ü¸ÄµÄĬÈÏÃÜÂ룬£¬£¬¾ßÓÐŲÓÃÎļþÉÏ´«½Ó¿ÚµÄȨÏÞ¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÓû§£¬£¬£¬¾ÙÐÐÉÏ´«í§ÒâÎļþµÄΣÏÕ²Ù×÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Fastjson_dnslog̽²â

Çå¾²ÀàÐÍ£º

Çå¾²Éó¼Æ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÕýÔÚʹÓÃdnslog̽²âÖ÷»úºó¶ËÊÇ·ñÊÇfastjson£»£»£»

¸üÐÂʱ¼ä£º

20210415


ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_Win32/Linux_ircBot_ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½ircBotÊÔͼÅþÁ¬Ô¶³ÌЧÀÍÆ÷¡£¡£¡£Ô´IPËùÔÚµÄÖ÷»ú¿ÉÄܱ»Ö²ÈëÁËircBot¡£¡£¡£ircBotÊÇ»ùÓÚircЭÒéµÄ½©Ê¬ÍøÂ磬£¬£¬Ö÷Òª¹¦Ð§ÊǶÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£»£»£»¹¿ÉÒÔÏÂÔØÆäËû²¡¶¾µ½±»Ö²Èë»úе¡£¡£¡£¶ÔÖ¸¶¨Ä¿µÄÖ÷»úÌᳫDDoS¹¥»÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_webshell_ÖÎÀí¹¤¾ß_asp¿ØÖÆÏÂÁî

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÉϵÄwebshellÖÎÀí¹¤¾ß¿Í»§¹æÔòÔÚÏòÄ¿µÄIPµØµãÖ÷»úÉϵÄwebshellЧÀÍÆ÷¶Ë·¢³ö¿ØÖÆÏÂÁî¡£¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¡£¼òÆÓÀ´Ëµ£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_wget_curlÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐÐ

Çå¾²ÀàÐÍ£º

¿ÉÒÉÐÐΪ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»ú·¢ËÍ¿ÉÒÉÏÂÁ£¬£¬ÊµÑé¿ØÖÆÄ¿µÄIPÖ÷»úÏÂÔØ¿ÉÒÉÎļþ²¢Ö´ÐС£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_±ùЫ3.0ÅþÁ¬

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓñùЫ3.0ÅþÁ¬Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£¡£

¸üÐÂʱ¼ä£º

20210415


ɾ³ýÊÂÎñ


1. TCP_ºóÃÅ_Win32.Avzhan.DDoS.Bot_ÅþÁ¬_1