2021-04-07

Ðû²¼Ê±¼ä 2021-04-08

ÐÂÔöÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_Apache_Dubbo·´ÐòÁл¯Îó²î[CVE-2020-1948][CNNVD-202006-1649]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃApache_Dubbo·´ÐòÁл¯Ô¶³Ì´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£µ±DubboЧÀͶË̻¶ʱ(ĬÈ϶˿ڣº20880)£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍδÂÄÀúÖ¤µÄЧÀÍÃû»òÒªÁìÃûµÄRPCÇëÇ󣬣¬£¬£¬£¬£¬Í¬Ê±ÅäºÏ¸½¼Ó¶ñÒâµÄ²ÎÊý¸ºÔØ£»£»£»£»£»£»ApacheDubboÊÇÒ»ÖÖ»ùÓÚJavaµÄ¸ßÐÔÄÜRPC¿ò¼Ü¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

TCP_ľÂíºóÃÅ_webshell_Öйú²Ëµ¶aspx_ÉÏ´«ºóÃųÌÐò

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPµØµãÖ÷»ú´«ËÍ¿ÉÒɵÄwebshellÎļþ¡£¡£webshellÊÇwebÈëÇֵľ籾¹¥»÷¹¤¾ß¡£¡£¼òÆÓ˵£¬£¬£¬£¬£¬£¬webshell¾ÍÊÇÒ»¸öÓÃasp»òphpµÈ±àдµÄľÂíºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÔÚÈëÇÖÁËÒ»¸öÍøÕ¾ºó£¬£¬£¬£¬£¬£¬¾­³£½«ÕâЩasp»òphpµÈľÂíºóÃÅÎļþ°²ÅÅÔÚÍøÕ¾Ð§ÀÍÆ÷µÄwebĿ¼ÖУ¬£¬£¬£¬£¬£¬ÓëÕý³£µÄÍøÒ³Îļþ»ìÔÚÒ»Æð¡£¡£È»ºó¹¥»÷Õ߾ͿÉÒÔÓÃwebµÄ·½·¨£¬£¬£¬£¬£¬£¬Í¨¹ý¸ÃľÂíºóÃÅ¿ØÖÆÍøÕ¾Ð§ÀÍÆ÷£¬£¬£¬£¬£¬£¬°üÀ¨ÉÏ´«ÏÂÔØÎļþ¡¢Éó²éÊý¾Ý¿â¡¢Ö´ÐÐí§Òâ³ÌÐòÏÂÁîµÈ¡£¡£webshell¿ÉÒÔ´©Ô½·À»ðǽ£¬£¬£¬£¬£¬£¬ÓÉÓÚÓë±»¿ØÖƵÄЧÀÍÆ÷»òÔ¶³ÌÖ÷»ú½»Á÷µÄÊý¾Ý¶¼ÊÇͨ¹ý80¶Ë¿Úת´ïµÄ£¬£¬£¬£¬£¬£¬Òò´Ë²»»á±»·À»ðǽ×èµ²¡£¡£²¢ÇÒʹÓÃwebshellÒ»Ñùƽ³£²»»áÔÚϵͳÈÕÖ¾ÖÐÁôϼͼ£¬£¬£¬£¬£¬£¬Ö»»áÔÚÍøÕ¾µÄwebÈÕÖ¾ÖÐÁôÏÂһЩÊý¾ÝÌá½»¼Í¼£¬£¬£¬£¬£¬£¬ÖÎÀíÔ±½ÏÄÑ¿´ÊÕÖ§ÇÖºÛ¼£¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÐÞ¸ÄÊÂÎñ


ÊÂÎñÃû³Æ£º

HTTP_Struts2_S2-057Ô¶³Ì´úÂëÖ´Ðй¥»÷[CVE-2018-11776]

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÊÔͼͨ¹ýApacheStruts2¿ò¼ÜÏÂÁîÖ´ÐÐÎó²î¹¥»÷Ä¿µÄIPÖ÷»ú¡£¡£Ô¶³Ì¹¥»÷ÕßÔÚ¶Ô·½Struts2µÄXMLÉèÖÃÖеÄnamespaceֵδÉèÖÃÇÒ£¨ActionConfiguration£©ÖÐδÉèÖûòÓÃͨÅä·ûnamespaceʱʹÓøÃÎó²îÖ´ÐÐí§ÒâOGNL±í´ïʽ¡£¡£Îó²î±£´æµÄ°æ±¾£ºStruts2.0.4-Struts2.3.34£¬£¬£¬£¬£¬£¬Struts2.5.0-Struts2.5.16ʵÑéÀûÓÚStruts2S2-057¾Ü¾øÐ§ÀÍÎó²î¹¥»÷¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_databind_caucho_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-databind_Ô¶³Ì´úÂëÖ´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ£¬£¬£¬£¬£¬£¬ÆäÖÐÔ¶³Ì´úÂëÈÆ¹ýÁËFastjson1.2.66¼°ÒÔǰ°æ±¾µÄºÚÃûµ¥£¬£¬£¬£¬£¬£¬¹¥»÷ÁËʹÓÃÁËcom.caucho.config.types.ResourceRefÀàµÄÄ¿µÄÖ÷»ú¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_JACKSON_Shiro_Ô¶³Ì´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃHTTP_JACKSON-Shiro_Ô¶³Ì´úÂ룬£¬£¬£¬£¬£¬Í¨¹ýJNDI×¢È룬£¬£¬£¬£¬£¬Ö´Ðй¥»÷Ä¿µÄIPÖ÷»úµÄÐÐΪ¡£¡£

¸üÐÂʱ¼ä£º

20210407


ÊÂÎñÃû³Æ£º

HTTP_Çå¾²Îó²î_XXL_JOB_δÊÚȨ»á¼ûÔ¶³ÌÏÂÁîÖ´ÐÐÎó²î

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

XXL-JOBÊÇÒ»¸öÇáÁ¿¼¶ÂþÑÜʽʹÃüµ÷ÀíÆ½Ì¨¡£¡£Ä¬ÈÏÇéÐÎÏÂXXL-JOBµÄRestfulAPI½Ó¿Ú»òRPC½Ó¿ÚûÓÐÉèÖÃÈÏÖ¤²½·¥£¬£¬£¬£¬£¬£¬Î´ÊÚȨµÄ¹¥»÷Õ߿ɽṹ¶ñÒâÇëÇ󣬣¬£¬£¬£¬£¬Ôì³ÉÔ¶³ÌÖ´ÐÐÏÂÁ£¬£¬£¬£¬£¬Ö±½Ó¿ØÖÆÐ§ÀÍÆ÷¡£¡£

¸üÐÂʱ¼ä£º

20210407