·¢²¼Ê±¼ä£º2024-03-14
½üÈÕ£¬¹«º£²Ê´¬¡¤6600“ÌìÄ»”°²È«ÊµÑéÊÒÔÚһϵÁй㷺ʹÓõÄÄÚÈݹÜÀíϵͳ£¨CMS£©ÖУ¬·¢ÏÖ¶à¸ö0Day¸ßΣ©¶´£¬°üÀ¨µ«²»ÏÞÓÚÉϺ£**ÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄCMSÎļþÉÏ´«Â©¶´£¨CNVD-2024-03360£©¡¢WB** CMS´æÔÚÎļþÉÏ´«Â©¶´£¨CNVD-2024-05823£©¡¢É½¶«**ÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄCMSϵͳ´æÔÚÎļþÉÏ´«Â©¶´(CNVD-2023-71326)
ÄÚÈݹÜÀíϵͳ£¨CMS£©Í¨³£ÓÃÓÚÍøÕ¾ºÍÔÚÏßÓ¦ÓõĹ¹½¨¡£ÊµÑéÊÒÑо¿·¢ÏÖ£¬ÈçÈôºÚ¿Íͨ¹ýÕâЩ¸ßΣ©¶´ÉÏ´«°üº¬¶ñÒâ´úÂëµÄÎļþ£¨Èç¶ñÒâ½Å±¾¡¢Ä¾Âí¡¢²¡¶¾£©²¢Ö´ÐУ¬²»½ö¿ÉÒÔʹ²¿Êð¸ÃϵͳµÄ·þÎñÆ÷ÏÝÈë̱»¾¡¢ÆÆ»µºËÐÄÎļþ¡¢»ñȡδ¾ÊÚȨµÄ·ÃÎÊȨÏÞ£¬ÉõÖÁ¿ÉÒÔÇÖ·¸Óû§Òþ˽¡£
ÉÏÊöÉϺ£**ÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾µÄCMSϵͳ£¬ÊǹúÄÚÓû§×î¶àµÄPHPÀàCMSϵͳ¡£¸ù¾Ý×ʲú²â»æÏµÍ³quake·¢ÏÖ£¬ÆäÈ«ÇòÓÐ1040¶àÍò¸öʹÓüǼ£¬ÆäÖÐÖйú¾ÍÓг¬¹ý247Íò¸öʹÓüǼ¡£Èç¹ûºÚ¿ÍÀûÓÃÕâ¸öÎļþÉÏ´«Â©¶´£¬²»½öÄܹ¥ÏÝÕâ¸öϵͳ×ÔÉí£¬»¹½«¼ä½ÓÓ°Ï쵽ȫ¹úÉϰÙÍò¸öʹÓôËϵͳµÄÍøÕ¾£¬´øÀ´ÑÏÖØµÄºó¹û¡£
¹«º£²Ê´¬¡¤6600“ÌìÄ»”°²È«ÊµÑéÊÒµÚһʱ¼ä·¢ÏÖ²¢Éϱ¨¹ú¼ÒÐÅÏ¢°²È«Â©¶´¹²ÏíÆ½Ì¨£¨China National Vulnerability Database£¬¼ò³ÆCNVD£©£¬²¢»ñµÃCNVD 0day©¶´µÄÈ·ÈÏ¡£
¹«º£²Ê´¬¡¤6600µÄ·À»ðǽÒѾÉý¼¶´Ë©¶´¿â£¬¹ºÂò¹«º£²Ê´¬¡¤6600·À»ðǽµÄ¿Í»§¶¼×Ô¶¯ÊµÏÖ¶ÔÕâЩ©¶´µÄÔ¤·À¡£
“ÌìÄ»”°²È«ÊµÑéÊÒÁ¥ÊôÓÚ¹«º£²Ê´¬¡¤6600ÍøÂ簲ȫ²úÆ·ÊÂÒµ²¿£¬×¨×¢ÓÚ°²È«Íþв¼à²â·ÖÎöÓëÑо¿£¬¹¥·À¶Ô¿¹¼¼ÊõÑо¿¡£Ñо¿Ä¿±ê°üÀ¨ Botnet¡¢½©Ä¾Èä·ÖÎö£¬APT ¸ß¼¶Íþв¡¢ÀÕË÷¡¢ÍÚ¿ó£¬WEB Óëϵͳ©¶´·ÖÎö¡£
2023Äê9Ô£¬¹«º£²Ê´¬¡¤6600±»¹ú¼ÒÐÅÏ¢°²È«Â©¶´¹²ÏíÆ½Ì¨£¨¼ò³ÆCNVD£©ÊÚÓè“2022Äê¶È©¶´´¦Öù¤×÷Í»³ö¹±Ï×µ¥Î»”³ÆºÅ£¬ÒÔ±íÕù«º£²Ê´¬¡¤6600ÔÚÐÅÏ¢°²È«Â©¶´´¦Öù¤×÷·½ÃæµÄÍ»³ö¹±Ïס£¹«º£²Ê´¬¡¤6600ÒÑÁ¬Ðø¶àÄê»ñ´Ë³ÆºÅ¡£

·À²¡¶¾£¨AV£©Ñо¿£º¹«º£²Ê´¬¡¤6600“ÌìÄ»”°²È«ÊµÑéÊÒÓëºÍ¹úÄÚÍⰲȫ³§É̺ÍÍŶÓÁªºÏ³ÉÁ¢°²È«´´ÐÂʵÑéÊÒ£¬²ú³öµÄZϵÁзÀ»ðǽAVÌØÕ÷ÊýÁ¿´ïµ½1000W+£¬°²È«¼ì²â׼ȷ¶È´ïµ½99.97%¡£
ÍþвÇ鱨£¨TI£©Ñо¿£º¹«º£²Ê´¬¡¤6600“ÌìÄ»”°²È«ÊµÑéÊÒÓëÌÚѶ°²È«Ç¿Ç¿ÁªºÏ£¬»ùÓںϹæ¼ì²â³¡¾°½øÐд´Ð£¬Í»ÆÆ¼ì²â×è¶ÏÑÓ³Ù¡¢¼ì²âÐÔÄܵͺ;«×¼¶ÈÎÊÌ⣬Èð²È«²»³öȦ£¬·çÏÕ²»ÍâÒç¡£

ÈëÇÖ·ÀÓù£¨IPS£©Ñо¿£º¹«º£²Ê´¬¡¤6600“ÌìÄ»”°²È«ÊµÑéÊÒ²ú³öµÄIPSÌØÕ÷¿â¹²¼Æ13000+Ìõ¡¢90+·ÖÀ࣬¸²¸ÇÍÚ¿ó¡¢ÀÕË÷µÈÈÈÃŹ¥»÷£¬±£³ÖÿÖܸüУ¬²»¶ÏÌáÉý°²È«·À»¤ÄÜÁ¦¡£
ÔÚÕâÈÕÒæ¸´ÔÓµÄÍøÂçÊÀ½ç£¬¹«º£²Ê´¬¡¤6600°²È«£¬»ùÓÚ³¡¾°µÄ×Ô¶¯»¯ÔËÓª£¬ÓëÄúÒ»Æð¹¹½¨¸ü¸ßЧ¡¢¸ü°²È«µÄÍøÂç»·¾³£¬±£»¤ÄúµÄÊý×Ö×ʲú¡£
