ÿÖÜÉý¼¶Í¨¸æ-2022-07-29

Ðû²¼Ê±¼ä 2022-07-29

ÐÂÔöÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_ÆäËü×¢Èë_ÓÃÓÑnc-uapws-wsdl_XMLÍⲿʵÌå×¢Èë

Çå¾²ÀàÐÍ£º

×¢Èë¹¥»÷

ÊÂÎñÐÎò£º

ÓÃÓÑÊý¿ØÊý×Ö»¯Æ½Ì¨ÃæÏò´óÐÍÆóÒµ£¬£¬ £¬£¬ÉîÈëÓ¦ÓÃÐÂÒ»´úÊý×ÖÖÇÄÜÊÖÒÕ£¬£¬ £¬£¬´òÔ쿪·Å¡¢»¥Áª¡¢¼¯³É¡¢ÖÇÄÜÒ»Ì廯µÄƽ̨£¬£¬ £¬£¬ÖصãÎ§ÈÆÊý×ÖÖÇÄÜÖÎÀí¡¢Êý×ÖÖÇÄÜÔËÓª¡¢Êý×ÖÖÇÄÜÓªÒµÈý´óÆóÒµÊý×ÖÖÇÄÜ»¯×ªÐÍÕ½ÂÔÆ«Ïò£¬£¬ £¬£¬Ìṩº­¸ÇÊý×ÖÓªÏú¡¢½ðÈÚ¹²Ïí¡¢È«Çò½ð¿â¡¢ÖÇÄÜÖÆÔ졢ѸËÙ¹©Ó¦Á´¡¢È˲ÅÖÎÀí¡¢ÖÇÄÜЭ×÷µÈ18¸ö½â¾ö¼Æ»®£¬£¬ £¬£¬×ÊÖú´óÐÍÆóÒµÖÜȫʵÑéÊý×ÖÖÇÄÜ¡£¡£¡£¡£¡£¡£ÓÃÓÑNCϵͳuapwsÓÐÒ»¸öWSDL½Ó¿Ú£¬£¬ £¬£¬¿ÉÒÔ½«Ö¸¶¨µÄ·¾¶×ª´ïµ½ÄÚ²¿»òÍⲿXML¾ÙÐÐÆÊÎö£¬£¬ £¬£¬µ¼ÖÂXXE(XMLÍⲿʵÌå×¢Èë)Îó²î¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýXXEÎó²î¶ÁȡЧÀÍÆ÷Îļþ²¢Ö´ÐÐí§ÒâÏÂÁî¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729


1.png

 

ÊÂÎñÃû³Æ£º

HTTP_ľÂíºóÃÅ_Webshell_ASP_±äÐÎÒ»¾ä»°

Çå¾²ÀàÐÍ£º

ľÂíºóÃÅ

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPµØµãÖ÷»úÕýÔÚÏòÄ¿µÄIPÖ÷»úÉÏ´«ASPX_±äÐÎÒ»¾ä»°Ä¾ÂíºóÃÅ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÔ¶³Ì¿ØÖƱ»ÉÏ´«webshellÖ÷»úÖ´ÐÐí§Òâ²Ù×÷¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÐÞ¸ÄÊÂÎñ

 

ÊÂÎñÃû³Æ£º

HTTP_´úÂëÖ´ÐÐ_CMS-Phpcms:V9.5.8_ºǫ́getshell

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCMS-Phpcms:V9.5.8ºǫ́í§Òâ´úÂëÖ´ÐÐÎó²î¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ£¬£¬ £¬£¬¸ÃÎó²îʹÓÃcontent.phpÎļþ½á¹¹¶ñÒâpayload£¬£¬ £¬£¬´Ó¶øÔì³É´úÂëÖ´ÐС£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Spring3_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃSpring3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËspring-tx:5.2.3.RELEASE,spring-context:5.2.3.RELEASE,javax.transaction-api:1.2£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Myfaces2_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃMyfaces2µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPListener_Java·´ÐòÁл¯Ê¹ÓÃÁ´¹¥»÷

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPListenerµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729


 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JBossInterceptors1_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJBossInterceptors1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËjavassist:3.12.1.GA,jboss-interceptor-core:2.0.0.Final,cdi-api:1.0-SP1,javax.interceptor-api:3.1,jboss-interceptor-spi:2.0.0.Final,slf4j-api:1.7.21£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_Click1_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃClick1µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËclick-nodeps:2.3.0£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_CommonsBeanutils1_2_183NOCC_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsBeanutils1183NOCCµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËcommons-beanutils:1.8.3£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁ£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_CommonsBeanutils3_3183_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃCommonsBeanutils3µÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£Èô»á¼ûµÄÓ¦Óñ£´æÎó²îJAVA·´ÐòÁл¯Îó²îÇÒʹÓÃÁËcommons-beanutils:1.9.2,commons-collections:3.1£¬£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_JRMPClient_Obj_Java·´ÐòÁл¯Ê¹ÓÃÁ´_´úÂëÖ´ÐÐ

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

¼ì²âµ½Ô´IPÖ÷»úÕýÔÚʹÓÃJRMPClient_ObjµÄJava·´ÐòÁл¯Ê¹ÓÃÁ´¶ÔÄ¿µÄÖ÷»ú¾ÙÐй¥»÷µÄÐÐΪ¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔ·¢ËÍÈ«ÐĽṹµÄJavaÐòÁл¯¹¤¾ß£¬£¬ £¬£¬Ô¶³ÌÖ´ÐÐí§Òâ´úÂë»òÏÂÁî¡£¡£¡£¡£¡£¡£Ô¶³ÌÖ´ÐÐí§Òâ´úÂ룬£¬ £¬£¬»ñȡϵͳ¿ØÖÆÈ¨¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729

 

ÊÂÎñÃû³Æ£º

TCP_ÌáȨ¹¥»÷_docker_Ô¶³Ì·ÇÊÚȨ»á¼û

Çå¾²ÀàÐÍ£º

Çå¾²Îó²î

ÊÂÎñÐÎò£º

dockerswarmÊÇdockerϵÄÂþÑÜ»¯Ó¦ÓõÄÍâµØ¼¯Èº£¬£¬ £¬£¬ÔÚ¿ª·Å2375¼àÌý¼¯ÈºÈÝÆ÷ʱ£¬£¬ £¬£¬Èô½«¸Ã¶Ë¿Ú̻¶ÔÚ¹«ÍøÉÏÔò»áµ¼ÖÂδÊÚȨ»á¼û£¬£¬ £¬£¬¹¥»÷Õß¿ÉʹÓøÃÎó²î¹¥»÷ЧÀÍÆ÷ÒÔ»ñȡȨÏÞ¡£¡£¡£¡£¡£¡£

¸üÐÂʱ¼ä£º

20220729


2.png