ÿÖÜÉý¼¶Í¨¸æ-2022-12-20

Ðû²¼Ê±¼ä 2022-12-20

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÌáȨ¹¥»÷_Spring_Boot_Admins_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

SpringBootadminsÊÇÒ»¸öÓÃÓÚÖÎÀíSpringBootÓ¦ÓóÌÐòµÄ¿ªÔ´ÖÎÀíÓû§½çÃæ¡£¡£¡£¡£¡£SpringBootadminsµÄnotifiersÍ¨ÖªÄ £¿£¿£¿£¿éÓÉÓÚûÓжÔÓû§ÊäÈë¾ÙÐÐÓÐÓùýÂË£¬£¬ £¬ËùÓÐÔËÐÐSpringBootAdminServer¡¢ÆôÓÃ֪ͨ³ÌÐò£¨ÀýÈçTeams-Notifier£©²¢Í¨¹ýUIдÈëÇéÐαäÁ¿µÄÓû§¶¼»áÊܵ½´úÂë×¢ÈëµÄÓ°Ïì¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉʹÓôËÎó²îͨ¹ýÏòSpringBootAdminServerµÄ/envÖ´ÐÐÆ÷¶Ëµã·¢ËͰüÀ¨¶ñÒâ´úÂëµÄPOSTÇëÇóÔ¶³ÌÖ´ÐжñÒâ´úÂë¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_¿ÉÒÉÐÐΪ_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÃûÌÃ×Ö·û´®[CVE-2021-44228]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãlog4j2×é¼þÖ§³ÖµÄÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬ £¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬ £¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬ £¬´ËÐÐΪ¾ßÓнϸßΣº¦£¬£¬ £¬ÈÝÒ×±»¹¥»÷ÕßÀÄÓ㬣¬ £¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬ £¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓ㬣¬ £¬´Ó¶øÖ´ÐжñÒâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£log4j22.15.0-RC1Ö®ºóµÄ°æ±¾Ä¬ÈϹرÕÁËʹÓôËÊÖ·¨Å²ÓÃjndiŲÓõĹ¦Ð§£¬£¬ £¬²¢ÏÞÖÆÁ˰×Ãûµ¥£¬£¬ £¬¹ÊʹÓÃδ¾­ÏÞÖÆµÄÀϰ汾log4j2×é¼þ¿ÉÄܻᱣ´æjndi×¢ÈëµÄΣº¦¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Apache_Log4j_ǶÌ×ʹÓÃÄÚÖÃlookupÃûÌÃ×Ö·û´®_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ApacheLog4jÊÇÒ»¸öÓÃÓÚJavaµÄÈÕÖ¾¼Í¼¿â£¬£¬ £¬ÆäÖ§³ÖÆô¶¯Ô¶³ÌÈÕ־ЧÀÍÆ÷¡£¡£¡£¡£¡£´ËÊÂÎñ´ú±í·¢Ã÷ÁËÔ´IPÖ÷»ú·¢ËÍÁËÖª×ãÄÚÖÃlookupÃûÌõÄ×Ö·û´®£¬£¬ £¬µ±Ä¿µÄIPÖ÷»úºó¶ËÎüÊÕµ½´ËÃûÌõÄ×Ö·û´®Ê±£¬£¬ £¬»á×Ô¶¯Å²ÓÃlookup¹¦Ð§¡£¡£¡£¡£¡£´ËÊÂÎñ¼ì²âµÄÊÇ¡°Ç¶Ìס±Ê¹ÓÃlookup¼ÇºÅµÄÐÐΪ£¬£¬ £¬´ËÐÐΪ¾ßÓÐÒ»¶¨Î£º¦£¬£¬ £¬¿ÉÄܻᱻ¹¥»÷ÕßÀÄÓ㬣¬ £¬ÈçÈÆ¹ýWAF¼ì²â£¬£¬ £¬²¢¾ÙÐзÇÔ¤ÆÚµÄjndiŲÓᣡ£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ToTolink_N600R·ÓÉÆ÷_Exportovpn_δÊÚȨÏÂÁî×¢Èë

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýToTolinkN600R·ÓÉÆ÷ExportovpnÏÂÁî×¢ÈëÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£¡£¡£¡£ÔÚToTolinkN600R·ÓÉÆ÷µÄcstecgi.cgiÎļþÖУ¬£¬ £¬exportovpn½Ó¿Ú±£´æÏÂÁî×¢È룬£¬ £¬¹¥»÷Õ߿ɽè´ËδÑéÖ¤Ô¶³ÌÖ´ÐжñÒâÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220


 

ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_ÈôÒÀCMS_Ô¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

ÈôÒÀºǫ́ÖÎÀíϵͳʹÓÃÁËsnakeyamlµÄjar°ü£¬£¬ £¬snakeyamlÊÇÓÃÀ´ÆÊÎöyamlµÄÃûÌ㬣¬ £¬¿ÉÓÃÓÚJava¹¤¾ßµÄÐòÁл¯¡¢·´ÐòÁл¯¡£¡£¡£¡£¡£ÓÉÓÚÈôÒÀºǫ́ÍýÏëʹÃü´¦£¬£¬ £¬¹ØÓÚ´«ÈëµÄ"ŲÓÃÄ¿µÄ×Ö·û´®"ûÓÐÈκÎУÑ飬£¬ £¬µ¼Ö¹¥»÷Õß¿ÉÒԽṹpayloadÔ¶³ÌŲÓÃjar°ü£¬£¬ £¬´Ó¶øÖ´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220


 

ÊÂÎñÃû³Æ£º

TCP_Çå¾²Îó²î_Dubbo_Nashorn¾ç±¾Ô¶³Ì´úÂëÖ´ÐÐÎó²î[CVE-2021-30181]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´ipÔÚ¿ÉÄÜÒѾ­¿ØÖÆÈçZooKeeperÉèÖÃÖÐÐĺ󣬣¬ £¬Í¨¹ýÉèÖÃÖÐÐÄÀ´½á¹¹¶ñÒâÇëÇó¶ÔDubbo×¢ÈëNashorn¾ç±¾£¬£¬ £¬Ôì³ÉÔ¶³Ì´úÂëÖ´ÐУ»£» £»£»ApacheDubboÊÇÒ»¸öÂþÑÜʽ¿ò¼Ü£¬£¬ £¬ÖÂÁ¦ÓÚÌṩ¸ßÐÔÄÜ͸Ã÷»¯µÄRPCÔ¶³ÌЧÀÍŲÓüƻ®£¬£¬ £¬ÒÔ¼°SOAЧÀÍÖÎÀí¼Æ»®¡£¡£¡£¡£¡£ApacheDubboÔÚÏÖʵӦÓó¡¾°ÖÐÖ÷ÒªÈÏÕæ½â¾öÂþÑÜʽµÄÏà¹ØÐèÇ󡣡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20221220