ÿÖÜÉý¼¶Í¨¸æ-2023-04-18
Ðû²¼Ê±¼ä 2023-04-18ÐÂÔöÊÂÎñ
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_webshell_AntSword_php¿ØÖÆÏÂÁî |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPµØµãÖ÷»úÉϵÄÖйúÒϽ£AntSwordwebshell¿Í»§¹æÔòÔÚÏòÄ¿µÄIPµØµãÖ÷»úÉϵÄwebshellЧÀÍÆ÷¶Ë·¢³ö¿ØÖÆÏÂÁî,ÊÔͼ¿ØÖÆÖ÷»ú¡£¡£¡£¡£ÉÏ´«Webshell£¬£¬»ñµÃÍøÕ¾ÖÎÀíȨ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | HTTP_Apache_Commons_Fileupload_·´ÐòÁл¯Îó²î[CVE-2016-1000031] |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApache_Commons_Fileupload_·´ÐòÁл¯Îó²î¹¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬Commons FileUpload ×÷ΪApache Struts 2µÄÒ»²¿·Ö£¬£¬±»ÓÃ×÷ÎļþÉÏ´«µÄĬÈÏ»úÖÆ¡£¡£¡£¡£Apache Struts 2.3.36¼°Ö®Ç°µÄ°æ±¾ÊÇÒ×Êܹ¥»÷µÄ¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚÔËÐÐÒ×Êܹ¥»÷µÄApache Struts°æ±¾µÄ¹ûÕæÍøÕ¾ÉÏ»ñµÃÔ¶³Ì´úÂëÖ´ÐÐÄÜÁ¦¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | HTTP_ľÂíºóÃÅ_Webshell_AntSwordľÂíÅþÁ¬_0xÊý¾Ý¼ì²é |
Çå¾²ÀàÐÍ£º | ľÂíºóÃÅ |
ÊÂÎñÐÎò£º | Á÷Á¿Öмì²âµ½AntsowrdµÄ¿ØÖÆÏÂÁ£¬¿ÉÄÜWebshellÒѱ»Ö²ÈëÕýÔÚ¾ÙÐÐÅþÁ¬ÐÐΪ¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | HTTP_Îó²îʹÓÃ_ÐÅϢй¶_nginx¼à¿ØÒ³Ãæ |
Çå¾²ÀàÐÍ£º | CGI¹¥»÷ |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚ̽²âÄ¿µÄipÖ÷»úÖеÄnginx¼à¿ØÒ³Ã棬£¬¿ÉÒÔͨ¹ý»á¼û¸ÃÒ³ÃæÀ´Éó²éЧÀÍÆ÷ÔËÐÐ״̬¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÐÞ¸ÄÊÂÎñ
ÊÂÎñÃû³Æ£º | TCP_Java·´ÐòÁл¯_ROME_ʹÓÃÁ´¹¥»÷ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃROMEµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ. |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_AspectJWeaver_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃaspectjweaverµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁ˱£´æaspectjweaver:1.9.2,commons-collections:3.2.2µÄÒÀÀµ£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_CommonsBeanutils3_3183_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsBeanutils3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËcommons-beanutils:1.9.2,commons-collections:3.1£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Groovy1_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃGroovy1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£ApacheGroovyÊÇÒ»¸ö¹¦Ð§Ç¿Ê¢µÄ¶¯Ì¬±à³ÌÓïÑÔ£¬£¬¿¿×ů侫Á·¡¢ÓëJavaºÜÊÇÏàËÆÒÔ¼°Ò×ÓÚѧϰµÄÓï·¨£¬£¬»ùÓÚJavaƽ̨µÄGroovy¹Ø×¢ÓÚÌá¸ß¿ª·¢ÕßµÄÉú²úÐÔ¡£¡£¡£¡£Ëü¿ÉÒÔºÍÈκÎJavaÓïÑÔ¾ÙÐÐÎ޷켯³É£¬£¬Ö§³ÖDSL£¬£¬ÌṩÔËÐн׶κͱàÒë½×¶ÎÔªÊý¾Ý±à³ÌµÈǿʢµÄ¹¦Ð§¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_BeanShell1_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃBeanshellµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËBeanShell2.0b6ÒÔǰµÄ°æ±¾£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |
ÊÂÎñÃû³Æ£º | TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ |
Çå¾²ÀàÐÍ£º | Çå¾²Îó²î |
ÊÂÎñÐÎò£º | ¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£ |
¸üÐÂʱ¼ä£º | 20230418 |