免责声明
今天是2023年8月10号周四,HW开始第二天,风急天高猿啸哀,部分BT已飞回!(徐总写的文案就是有文采,笑死😆)
第一天被日穿的佬天启建议您:pip install -r kfc.txt试试呢
天启:纯情蓝高!!!,有看上的RT女师傅抓抓紧吧!
天启:如果忘记带纸可以敲敲隔壁倾月师傅的门!
哦吼,小红书SRC开通了
一、今日份漏洞情报
PeiQiwiki文库漏洞更新
https://github.com/PeiQi0/PeiQi-WIKI-Book
360漏洞情报今日更新情况
【演练实时消息】
【消息时间】:2023-08-10 01:10
【消息标题】:绿盟SAS安全审计系统 GetFile 任意文件读取漏洞
【消息详情】:360漏洞云监测到《绿盟SAS安全审计系统 GetFile 任意文件读取漏洞》消息,经漏洞云复核,确认为【真实】漏洞,漏洞影响版本【未知】,该漏洞标准化POC已经上传漏洞云情报平台,平台编号:360LDYLD-2023-00002408,情报订阅用户可登录漏洞云情报平台( https://loudongyun.360.cn/bug/list )查看漏洞详情。
【演练实时消息】
【消息时间】:2023-08-10 00:50
【消息标题】:亿赛通电子文档安全管理系统 importFileType 文件上传漏洞
【消息详情】:360漏洞云监测到《亿赛通电子文档安全管理系统 importFileType 文件上传漏洞》消息,经漏洞云复核,确认为【真实】Nday漏洞,漏洞影响版本【未知】,该漏洞标准化POC已经上传漏洞云情报平台,平台编号:360LDYLD-2023-00002494,情报订阅用户可登录漏洞云情报平台( https://loudongyun.360.cn/bug/list )查看漏洞详情。
【演练实时消息】
【消息时间】:2023-08-10 10:30
【消息标题】:泛微 E-Office 任意文件上传漏洞
【消息详情】:360漏洞云监测到《泛微 E-Office 任意文件上传漏洞(CVE-2023-2523)》POC已公开,经漏洞云复核,确认为【真实】漏洞,POC真实有效,漏洞影响版本【泛微 E-office=9.5 】,该漏洞标准化POC已经上传漏洞云情报平台,平台编号:360LDYLD-2023-00002492,情报订阅用户可登录漏洞云情报平台( https://loudongyun.360.cn/bug/list )查看漏洞详情。
【演练实时消息】
【消息时间】:2023-08-10 11:00
【消息标题】:通达OA SQL注入漏洞
【消息详情】:360漏洞云监测到《通达OA SQL注入漏洞(CVE-2023-2523)》POC已公开,经漏洞云复核,确认为POC【真实】,漏洞影响版本【通达OA<11.10】,该漏洞标准化POC已经上传漏洞云情报平台,平台编号:360LDYLD-2023-00002486,情报订阅用户可登录漏洞云情报平台( https://loudongyun.360.cn/bug/list )查看漏洞详情。
【消息时间】:2023-08-10 11:10
【消息标题】:网神 SecGate 3600 防火墙 obj_app_upfile 任意文件上传漏洞
【消息详情】:360漏洞云监测到《网神 SecGate 3600 防火墙 obj_app_upfile 任意文件上传漏洞》消息,经漏洞云复核,确认为历史漏洞,相关Poc在往年攻防演练中已有出现,该漏洞标准化POC已经上传漏洞云情报平台,平台编号:360LDYLD-2022-00005790,情报订阅用户可登录漏洞云情报平台( https://loudongyun.360.cn/bug/list )查看漏洞详情。
来自红蓝攻防实验室
2023HW-Day nday集合
1、Hillstone LMS 系统命令执行漏洞
2、天翼云网页防篡改系统命令执行漏洞
3、中远麒麟堡垒机系统 SQL 注入漏洞
4、致远 OA 系统命令执行漏洞
5、致远 OA 系统 V5-V6 模块命令执行漏洞
6、山石网科 EDR 系统 PHP 模块命令执行漏洞
7、H3C NX54 系统 web 模块信息泄露漏洞
8、锐捷 EG 易网关系统命令执行漏洞
9、H3C 虚拟授权管理系统系统命令执行漏洞
10、H3C 虚拟授权管理系统系统 web 模块命令执行漏洞
11、H3C 综合日志审计平台系统命令执行漏洞
12、Logbase 堡垒机系统 web 模块 SQL 注入漏洞
13、绿盟 SAS堡垒机localuser.php 任意用户登录漏洞
14、绿盟SAS堡垒机 GetFile 任意文件读取漏洞
15、绿盟SAS堡垒机 Exec 远程命令执行漏洞
16、HiKVISION综合安防管理平台env 信息泄漏漏洞
17、安恒明御运维审计与风险控制系统 xmlrpc.sock 任意用户添加漏洞
18、锐捷 NBR 路由器 fileupload.php 任意文件上传漏洞
19、H3C Magic CVE-2023-34928 远程代码执行漏洞
20、JCG路由器命令执行漏洞
21、通达 OA getdata 远程代码执行漏洞
22、红帆OA ioRepPicAdd 前台任意文件上传漏洞
23、九思OA wap.do SQL注入漏洞
24、九思OA wap.do 任意文件下载漏洞
25、Finetree-5MP-摄像机未授权任意用户添加漏洞(老)
POC可以直接去PeiQiwiki文库搜一下哦!
二、恶意IP(建议封禁)
来源:知道创宇安全智脑,微步情报社区,CT情报,以及本小弟收集
185.191.171.4
205.210.31.24
79.174.13.220
205.210.31.5
198.235.24.220
119.52.208.2
185.191.171.22
205.210.31.85
185.201.9.209
205.210.31.193
176.58.110.137
205.210.31.39
27.124.42.18
154.41.228.146
198.235.24.255
121.60.81.170
66.36.234.18
198.235.24.193
212.237.37.217
198.235.24.226
61.75.17.124
119.52.216.106
198.235.24.214
38.54.88.174
54.193.34.2
219.151.149.152
205.210.31.43
205.210.31.167
205.210.31.99
205.210.31.57
185.191.171.12
205.210.31.44
205.210.31.172
135.125.234.192
164.92.155.72
171.212.209.209
92.42.107.232
198.235.24.230
116.50.239.166
205.210.31.53
85.208.139.70
118.107.46.131
124.248.69.83
85.208.98.20
194.163.144.192
198.235.24.178
205.210.31.98
85.208.98.16
185.191.171.25
217.76.53.63
153.120.7.63
198.235.24.161
198.235.24.227
205.210.31.76
198.235.24.238
198.235.24.228
205.210.31.221
205.210.31.84
198.235.24.144
205.210.31.79
205.210.31.22
185.191.171.19
203.146.170.155
198.235.24.194
205.210.31.169
45.81.39.20
205.210.31.87
198.235.24.129
205.210.31.56
45.141.215.19
139.213.210.216
188.65.36.68
85.208.96.202
119.52.106.108
205.210.31.246
38.242.241.179
27.210.138.122
85.208.96.200
198.235.24.162
205.210.31.171
119.52.106.117
172.104.181.101
205.210.31.90
205.210.31.17
205.210.31.254
198.235.24.184
205.210.31.237
198.235.24.229
151.106.108.24
198.235.24.246
185.191.171.16
198.235.24.149
27.18.27.235
198.235.24.231
38.242.249.157
103.136.221.238
185.191.171.8
205.210.31.106
205.210.31.109
205.210.31.110
205.210.31.143
198.235.24.204
222.163.61.199
175.27.223.15
205.210.31.92
205.210.31.154
46.229.237.101
205.210.31.198
222.213.119.61
198.235.24.175
185.191.171.1
122.138.102.141
205.210.31.81
107.189.12.105
205.210.31.250
162.55.85.215
85.208.96.193
137.226.113.44
198.235.24.223
222.163.46.119
205.210.31.222
205.210.31.97
205.210.31.66
85.208.96.204
50.18.246.37
124.248.69.175
205.210.31.30
205.210.31.225
198.235.24.248
205.210.31.19
205.210.31.100
205.210.31.223
85.208.96.198
94.102.61.75
205.210.31.128
205.210.31.251
139.209.175.83
205.210.31.163
154.204.35.133
205.210.31.73
198.235.24.165
13.57.15.9
205.210.31.192
85.208.96.205
205.210.31.144
198.235.24.205
205.210.31.134
205.210.31.142
205.210.31.162
205.210.31.72
198.235.24.139
103.20.220.64
205.210.31.23
205.210.31.3
205.210.31.185
205.210.31.153
27.124.10.187
198.235.24.155
205.210.31.83
122.10.45.233
170.187.237.228
172.245.205.158
198.235.24.182
185.191.171.6
139.209.171.51
119.52.215.40
46.101.193.196
205.210.31.226
171.212.116.210
122.138.100.103
205.210.31.232
85.208.96.209
185.191.171.34
205.210.31.40
216.244.66.247
205.210.31.164
210.16.189.4
205.210.31.95
101.71.140.6
205.210.31.203
198.235.24.216
205.210.31.80
85.208.96.206
205.210.31.75
198.235.24.199
198.235.24.136
222.160.184.6
173.224.126.236
159.69.61.178
20.171.240.220
101.71.140.9
85.208.96.197
205.210.31.111
87.120.84.184
198.235.24.159
217.182.134.106
205.210.31.27
216.244.66.243
157.90.182.23
139.214.87.195
51.144.113.144
205.210.31.227
198.235.24.147
205.210.31.78
194.169.175.167
135.148.237.208
205.210.31.129
198.235.24.141
122.138.96.207
205.210.31.238
85.208.96.201
198.235.24.202
85.217.144.60
198.235.24.130
34.27.12.141
3.215.135.50
137.117.121.68
205.210.31.132
198.235.24.183
198.235.24.224
205.210.31.151
198.235.24.242
205.210.31.137
115.85.21.85
103.42.58.103
222.163.47.186
198.235.24.252
205.210.31.213
51.75.133.70
205.210.31.103
205.210.31.184
43.128.11.242
185.191.171.14
205.210.31.208
185.191.171.3
202.79.169.18
159.223.17.119
124.248.69.230
205.210.31.18
195.191.219.131
205.210.31.195
198.235.24.154
218.146.39.67
162.55.85.220
205.210.31.236
205.210.31.231
198.235.24.215
198.235.24.196
139.214.87.85
205.210.31.65
205.210.31.74
36.134.130.57
205.210.31.244
35.87.158.36
205.210.31.10
121.22.5.241
104.160.42.76
205.210.31.141
198.235.24.168
205.210.31.220
205.210.31.48
205.210.31.89
205.210.31.239
205.210.31.183
198.235.24.237
198.235.24.212
198.235.24.201
205.210.31.8
205.210.31.148
85.208.98.22
198.235.24.235
198.235.24.225
205.210.31.130
54.177.102.232
198.235.24.236
46.19.136.74
205.210.31.255
38.55.128.102
87.121.221.210
222.163.61.159
185.191.171.18
3.226.97.26
205.210.31.170
205.210.31.34
205.210.31.215
208.91.69.21
103.115.164.81
27.124.40.56
205.210.31.47
198.235.24.148
198.235.24.169
154.9.228.199
85.208.96.210
101.71.140.7
205.210.31.38
119.52.233.95
205.210.31.207
109.237.98.53
122.138.96.167
47.243.189.77
93.188.165.75
43.153.174.46
119.52.105.201
205.210.31.54
198.235.24.232
143.244.138.155
185.191.171.20
107.148.73.70
38.49.39.117
208.91.69.30
198.235.24.146
205.210.31.253
205.210.31.245
85.208.96.196
205.210.31.194
205.210.31.96
205.210.31.42
205.210.31.211
195.191.219.132
205.210.31.35
205.210.31.252
198.235.24.195
198.235.24.142
198.235.24.203
205.210.31.197
27.203.244.107
205.210.31.155
112.237.3.7
121.196.195.153
143.198.32.12
205.210.31.14
205.210.31.196
205.210.31.86
85.208.98.29
185.191.171.11
205.210.31.55
74.249.156.221
198.187.28.23
185.191.171.33
8.222.188.83
43.136.181.37
119.52.107.175
205.210.31.205
205.210.31.168
175.23.128.80
205.210.31.52
34.223.106.245
185.191.171.17
205.210.31.201
154.61.74.7
205.210.31.135
205.210.31.186
85.208.98.19
198.235.24.156
216.244.66.228
185.191.171.10
85.208.96.199
198.235.24.247
205.210.31.41
205.210.31.214
205.210.31.146
85.208.96.203
205.210.31.241
205.210.31.233
198.235.24.211
47.107.66.8
119.52.107.249
205.210.31.156
205.210.31.216
205.210.31.36
85.208.98.17
97.74.94.186
154.43.165.6
198.235.24.166
198.235.24.208
198.235.24.239
198.235.24.198
54.93.164.158
185.191.171.24
205.210.31.2
205.210.31.60
205.210.31.249
205.210.31.229
205.210.31.45
205.210.31.161
85.208.98.18
205.210.31.180
205.210.31.68
103.27.62.174
42.91.178.75
122.138.105.53
44.210.236.62
207.154.254.209
85.208.96.194
205.210.31.69
129.204.197.133
92.204.138.222
213.136.75.229
154.9.228.159
205.210.31.6
198.235.24.163
205.210.31.176
205.210.31.46
198.235.24.240
87.76.8.76
222.160.187.180
216.118.246.34
205.210.31.150
198.235.24.145
205.210.31.248
205.210.31.230
205.210.31.51
85.208.98.23
205.210.31.71
185.191.171.26
198.235.24.131
85.208.98.24
205.210.31.105
198.235.24.213
205.210.31.202
205.210.31.20
205.210.31.82
198.235.24.233
198.235.24.132
217.160.232.32
122.141.192.35
205.210.31.217
142.93.56.228
120.38.11.44
59.59.14.221
198.235.24.180
45.81.39.227
198.235.24.153
198.235.24.197
205.210.31.181
205.210.31.13
185.191.171.9
198.235.24.150
185.191.171.35
198.235.24.245
198.235.24.134
208.91.69.19
205.210.31.32
139.209.171.12
205.210.31.212
205.210.31.26
205.210.31.107
205.210.31.158
205.210.31.88
222.163.58.250
198.235.24.137
20.150.220.197
23.88.67.81
198.235.24.217
95.111.226.15
119.52.210.182
198.235.24.151
205.210.31.77
44.203.94.250
198.235.24.244
85.208.96.208
205.210.31.15
198.235.24.185
205.210.31.177
205.210.31.178
205.210.31.25
205.210.31.138
3.237.254.8
38.45.123.162
119.8.180.84
198.235.24.158
198.235.24.254
205.210.31.209
153.120.43.149
18.208.210.158
124.248.69.223
205.210.31.104
198.235.24.186
124.248.69.221
85.208.96.212
185.191.171.23
205.210.31.21
54.175.183.40
167.86.122.200
124.248.69.143
101.71.140.8
148.251.4.36
198.235.24.251
198.235.24.207
205.210.31.235
198.235.24.135
119.52.106.99
198.235.24.152
198.235.24.241
205.210.31.28
198.235.24.222
103.136.220.238
185.191.171.2
198.235.24.128
198.235.24.249
198.235.24.133
205.210.31.108
185.191.171.21
205.210.31.140
205.210.31.219
205.210.31.175
112.44.190.143
205.210.31.206
205.210.31.37
185.191.171.13
205.210.31.210
198.235.24.243
129.146.41.159
205.210.31.59
162.215.212.39
198.235.24.209
205.210.31.11
65.108.125.120
119.52.208.95
205.210.31.204
205.210.31.242
205.210.31.165
198.235.24.143
205.210.31.218
14.128.13.2
205.210.31.50
198.235.24.219
205.210.31.91
85.208.96.207
205.210.31.152
216.244.66.195
205.210.31.243
205.210.31.12
85.208.98.31
198.235.24.234
205.210.31.93
67.211.214.155
107.172.5.251
205.210.31.173
94.102.61.7
198.235.24.177
103.174.87.250
216.244.66.239
162.55.86.59
205.210.31.67
103.136.221.239
3.99.47.227
205.210.31.240
205.210.31.199
185.191.171.7
54.218.46.79
175.178.215.205
154.12.240.150
15.228.79.181
198.235.24.171
110.82.17.90
205.210.31.149
122.138.100.46
52.8.247.135
205.210.31.159
34.222.201.120
198.235.24.140
198.235.24.192
85.208.96.195
205.210.31.102
139.214.91.169
117.27.161.171
103.114.162.188
205.210.31.224
192.241.141.91
205.210.31.147
205.210.31.31
198.235.24.253
205.210.31.94
185.65.207.26
216.244.66.244
205.210.31.136
205.210.31.33
85.208.96.211
205.210.31.29
198.235.24.164
120.38.159.233
104.236.104.29
198.235.24.176
45.81.39.174
36.157.11.43
205.210.31.145
205.210.31.139
185.191.171.15
207.244.248.83
195.191.219.133
74.208.34.76
198.235.24.218
205.210.31.166
205.210.31.9
198.235.24.174
183.60.21.9
119.52.213.177
185.191.171.5
使用需知
由于传播、利用此文所提供的信息而造成的任何直接或者间接的后果及损失,均由使用者本人负责,文章作者不为此承担任何责任。
封面图片来源网络,如有侵权联系必删。
安全小白,不喜绕过。
仅供参考,请勿用于违法行为,如有侵权以及各种情况可以私聊!
原文始发于微信公众号(天启实验室):HW第二天0day以及恶意IP简单汇总
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论