Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ¡¶ÈëÇÖÉúÃüÖÜÆÚϸ·Öʵ¼ùÖ¸ÄÏϵÁС·£ºÈÝÆ÷²¿Êð¹¥»÷
      ·¢²¼Ê±¼ä£º2022-08-05 ×÷Õߣº»Æ½ð³Ç¿Æ¼¼»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ ÔĶÁ´ÎÊý£º 846 ´Î

      »Æ½ð³Ç¿Æ¼¼ÎªÁ˸üºÃµØ½øÐÐÈëÇÖ¼ì²âºÍ·ÀÓù£¬²ÎÕÕ¸÷Öֻƽð³Ç¹ÙÍøÍþв¿ò¼ÜºÍ×ÔÉíµÄʵ¼ùÓë˼¿¼£¬Ìá³öÁË»ùÓÚÈëÇÖÉúÃüÖÜÆÚµÄ¹¥»÷¹ÜÀíÄ£ÐÍ£¬×÷Ϊ»Æ½ð³ÇÐÂÒ»´ú»Æ½ð³Ç¹ÙÍø¼Ü¹¹µÄÈý´óÖ§ÖùÖ®Ò»¡£

      ÈëÇÖÉúÃüÖÜÆÚv1.0°ÑÈëÇÖ¹ý³Ì»®·ÖΪ7¸ö½×¶Î£ºÌ½Ë÷·¢ÏÖ¡¢ÈëÇֺ͸ÐȾ¡¢Ì½Ë÷¸ÐÖª¡¢´«²¥¡¢³Ö¾Ã»¯¡¢¹¥»÷ºÍÀûÓᢻָ´¡£ÈëÇÖÉúÃüÖÜÆÚv1.0ͬÑùÒÔATT&CK×÷Ϊ»ù±¾Õ½Êõ֪ʶ¿â£¬Æ¥Åäµ½²»Í¬µÄÈëÇֽ׶Ρ£ÐèҪעÒâµÄÊÇ£¬²¢·ÇËùÓеÄÈëÇÖ¶¼»á¾­ÀúÕâ7¸ö½×¶Î£¬Ò²Ã»Óоø¶ÔµÄÏßÐÔ´ÎÐò¡£

      1£©Ì½Ë÷·¢ÏÖ

      ÔÚÕâ¸ö½×¶ÎÖУ¬¹¥»÷Õß»áÏÈËø¶¨¹¥»÷¶ÔÏó£¬È»ºóÀûÓÃijЩ¼¼ÊõÊֶΣ¬¾¡¿ÉÄÜ¶àµØ»ñȡĿ±ê±©Â¶³öÀ´µÄÐÅÏ¢£¬Èçͨ¹ý¶Ë¿ÚɨÃè¡¢Ö¸ÎÆÌ½²âµÈ·½Ê½£¬·¢ÏÖÃô¸Ð¶Ë¿Ú¼°°æ±¾ÐÅÏ¢£¬½ø¶øÑ°ÕÒ¹¥»÷µã£¬ÎªÏÂÒ»²½ÈëÇÖ×ö×¼±¸¡£

      2£©ÈëÇֺ͸ÐȾ

      ÔÚÕâ¸ö½×¶Î£¬¹¥»÷Õß»á¸ù¾Ý¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎËù·¢ÏÖµÄÖØÒªÐÅÏ¢£¬À´¶ÔÄ¿±ê±©Â¶³öµÄ¹¥»÷Ãæ½øÐй¥»÷³¢ÊÔ£¬ÔÚ¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎÊÕ¼¯µ½µÄÐÅÏ¢Ô½¶à£¬¹¥»÷¶ÔÏóËù±©Â¶µÄ¹¥»÷ÃæÒ²¾ÍÔ½¶à£¬¹¥»÷¸üÒ׳ɹ¦¡£

      3£©Ì½Ë÷¸ÐÖª

      ¹¥»÷ÕßÔڳɹ¦½øÈëϵͳÄÚ²¿ºó£¬ÓÉÓÚÊÇÊ״νøÈëËùÒÔ»á³öÏÖ¶ÔÄÚ²¿»·¾³²»ÊìϤµÄÇé¿ö£¬Õâʱ¹¥»÷Õߵ͝×÷Ò»°ã»áÊǶԵ±Ç°Ëù´¦»·¾³½øÐÐ̽Ë÷£¬ÃþÇåÄÚ²¿´óÖµÄÍøÂç½á¹¹£¬³£³£°éËæ×ű»ÈëÇÖ±¾»úµÄÃô¸ÐÐÅÏ¢ÊÕ¼¯ÒÔ¼°¶ÔÄÚÍø´óÁ¿µÄ¶Ë¿Ú½øÐÐɨÃ裬ºóÐø¸ù¾Ý¹¥»÷ÕßµÄÄ¿µÄ½øÐÐÏÂÒ»²½²Ù×÷¡£

      4£©´«²¥

      Ôڴ˽׶Σ¬¹¥»÷Õ߸ù¾ÝÉÏÒ»½×¶ÎÔÚÄÚÍøÌ½Ë÷¸ÐÖªÊÕ¼¯µ½µÄÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨µÄ¹¥»÷ÊÖ·¨¡£ÈçÈô·¢ÏÖÄÚ²¿ÊÇÓò»·¾³£¬¹¥»÷Õß¿ÉÄ᳢ܻÊÔÏȹ¥ÆÆÓò¿Ø·þÎñÆ÷£¬ÔÙ´«²¥ÆäËû»úÆ÷¡£ÈôÊǹ¤×÷×é»·¾³£¬¿ÉÄÜ»áÀûÓÃÊÕ¼¯µ½µÄ¶Ë¿ÚºÍ·þÎñÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨Â©¶´½øÐÐÅúÁ¿É¨Ãè¹¥»÷£¬À´¾¡¿ÉÄÜ¶àµØ¼ÌÐø»ñµÃÆäËû¼ÆËã»úµÄ¿ØÖÆÈ¨¡£

      5£©³Ö¾Ã»¯

      ¹¥»÷ÕßÔÚ¶Ô×ʲú½øÐжñÒâ²Ù×÷ºó£¬ÎªÁËÄܹ»¼õÉÙÔÙ´ÎÁ¬½ÓµÄ¹¥»÷³É±¾£¬·½±ãÏ´νøÈ룬»á½øÐС°ÁôºóÃÅ¡±µÄ²Ù×÷£¬³£¼ûµÄºóÃÅÈ磺½¨Á¢¼Æ»®ÈÎÎñ£¬¶¨Ê±Á¬½ÓÔ¶³Ì·þÎñÆ÷£»ÉèÖÿª»úÆô¶¯³ÌÐò£¬ÔÚÿ´Î¿ª»úʱ´¥·¢Ö´ÐÐÌØ¶¨¶ñÒâ³ÌÐò£»Ð½¨ÏµÍ³¹ÜÀíÔ±Õ˺ŵÈ¡£ÕâÑù±ãÓÚ¹¥»÷ÕßÏ´οìËٵǼ²¢¿ØÖƸÃϵͳ¡£

      6£©¹¥»÷ºÍÀûÓÃ

      ¹¥»÷ÕßÔڴ˽׶αã»á¿ªÊ¼¶ÔÄ¿±ê×ʲú½øÐжñÒâ²Ù×÷£¬°´ÕÕ¹¥»÷ÕßÒâÔ¸£¬¶ÔÄÜÀûÓõÄÊý¾Ý½øÐÐÇÔÈ¡¡¢ÀûÓã»¶Ô²Ù×÷ϵͳ¡¢Ãô¸ÐÎļþ½øÐÐÆÆ»µ¡¢É¾³ý¡£ËùÓеķÀÓùÊֶζ¼Ó¦¸Ã¼«Á¦×èÖ¹¹¥»÷Õß½øÐе½ÕâÒ»½×¶Î¡£

      7£©»Ö¸´

      ¹¥»÷ÕßÔÚÖ´ÐÐËùÓеĹ¥»÷²Ù×÷ʱ£¬ÍùÍù»áÔÚϵͳÉÏÁôÏ´óÁ¿µÄÐÐΪÈÕÖ¾£¬Òò´ËÔÚÕâÒ»½×¶Î£¬¹¥»÷Õß»á¶Ô¼Ç¼×ÔÉíºÛ¼£µÄËùÓÐÈÕÖ¾½øÐд¦Àí£¬»òɾ³ý»ò»ìÏý£¬´Ó¶øÏûÃðÖ¤¾Ý£¬ÌÓ±Ü×·×Ù¡£


      ±¾ÏµÁÐÎÄÕ»ùÓڻƽð³Ç¿Æ¼¼ÈëÇÖÉúÃüÖÜÆÚ1.0¼Ü¹¹£¬Ï¸·Ö¸÷½×¶Î¹¥»÷Õߵij£Óù¥»÷ÊֶΣ¬²¢¶ÔÏà¹Ø¹¥»÷ÊֶεľßÌåʵʩ·½Ê½½øÐÐÖðÒ»ÆÊÎö£¬Îª»Æ½ð³Ç¹ÙÍø·ÀÓù½¨ÉèÌṩÓÐÁ¦ÖªÊ¶²¹³äºÍ·´ÖÆ×¼±¸¡£





      ÈÝÆ÷²¿Êð¹¥»÷£¨´«²¥£©




      DockerÊÇÒ»ÖÖÁ÷ÐÐµÄÆ½Ì¨¼´·þÎñÈÝÆ÷²úÆ·£¬Èÿª·¢Õß¿ÉÒÔÒÔͳһµÄ·½Ê½´ò°üËûÃǵÄÓ¦ÓÃÒÔ¼°ÒÀÀµ°üµ½Ò»¸ö¿ÉÒÆÖ²µÄÈÝÆ÷ÖУ¬È»ºó·¢²¼µ½Èκΰ²×°ÁËdockerÒýÇæµÄ·þÎñÆ÷ÉÏ£¨°üÀ¨Á÷ÐеÄLinux»úÆ÷¡¢windows»úÆ÷£©£¬Ò²¿ÉÒÔʵÏÖÐéÄ⻯¡£ÈÝÆ÷ÊÇÍêȫʹÓÃɳÏä»úÖÆ£¬Ï໥֮¼ä²»»áÓÐÈκνӿڣ¬²¢ÇÒ¼¸ºõûÓÐÐÔÄÜ¿ªÏú,¿ÉÒÔºÜÈÝÒ×µØÔÚ»úÆ÷ºÍÊý¾ÝÖÐÐÄÖÐÔËÐС£×îÖØÒªµÄÊÇ,ËûÃDz»ÒÀÀµÓÚÈκÎÓïÑÔ¡¢¿ò¼Ü°üÀ¨ÏµÍ³¡£

      ´Ó¹¥»÷ÕߵĽǶÈÀ´·ÖÎö£¬¹¥»÷ÕßÔÚÉøÍ¸¹ý³ÌÖпÉÄܻᲿÊðÒ»¸öûÓÐÍøÂç¹æÔò¡¢Óû§ÏÞÖÆµÈÅäÖõÄÐÂÈÝÆ÷£¬Í¨¹ýÔÚÐÂÈÝÆ÷ÖÐÏÂÔØ»òÖ´ÐжñÒâÈí¼þÀ´Èƹý»·¾³ÖеÄÏÖÓзÀÓù¡£ÀýÈ磬¹¥»÷Õß¿ÉÒÔÔÚ²¿ÊðµÄÐÂÈÝÆ÷ÖÐÖ´ÐЩ¶´É¨Ã蹤¾ß£¬²¢½øÐЩ¶´ÀûÓã¬ÒÔ»ñµÃÆäËû»úÆ÷µÄ¿ØÖÆÈ¨¡£Òà¿ÉÒÔÔÚÐÂÈÝÆ÷Öв¿Êð¿ÉºáÏòÒÆ¶¯µÄ²¡¶¾À´¶Ô²Ù×÷ϵͳ¡¢Ãô¸ÐÎļþµÈ½øÐÐÆÆ»µ¡¢É¾³ý¡£Òò´Ë£¬´ÓÈëÇÖÉúÃüÖÜÆÚ½Ç¶È·ÖÎö£¬ÈÝÆ÷²¿Êð¿É±»¹¥»÷ÕßÓÃÓÚ´«²¥½×¶ÎºÍ¹¥»÷ºÍÀûÓý׶Ρ£

      ´Ó¹¥»÷ÐÐΪÁ´ÌõµÄÉÏÏÂÎÄÀ´¿´£¬Õë¶ÔÈÝÆ÷²¿ÊðµÄÐÐΪÁ´ÌõÊäÈëÊä³öÈçÏ¡£


      ÊäÈ룺dockerÈÝÆ÷Ïà¹ØÃüÁî¡¢¹¥»÷ÕßÔÚdockerÖÐÖ´ÐеĶñÒâ²Ù×÷

      Êä³ö£º´´½¨µÄdockerÈÝÆ÷ÒÔ¼°¶ñÒâ²Ù×÷Ö´Ðнá¹û



      Õë¶ÔÈÝÆ÷²¿Êð£¬Ä¿Ç°³£ÓÃÊÖ¶ÎÈçÏ£º

      1£®»·¾³×¼±¸

      (1)ʹÓÃÇ廪¾µÏñ

      curl-fsSL https://mirrors.tuna.tsinghua.edu.cn/docker-ce/linux/debian/gpg | sudo apt-key add -

      (2)ÅäÖÃdocker apt

      echo 'deb https://mirrors.tuna.tsinghua.edu.cn/docker-ce/linux/debian/ buster stable' | sudo tee /etc/apt/sources.list.d/docker.list

      (3)¸üÐÂapt

      sudo apt-get £õ£ð£ä£á£ô£å

      2£®°²×°dockerÈÝÆ÷

      (1)¼ì²éÊÇ·ñ°²×°¹ýdocker

      sudo apt-get docker docker-engine docker.io

      Èôδ°²×°¹ý»áÏÔʾÎÞЧµÄ²Ù×÷£º

      (2)docker°²×°

      sudo apt-get install docker-ce

      (3)²é¿´docker°æ±¾

      docker -v

      (4)²é¿´dockerÈÝÆ÷ÔËÐÐ״̬

      sudo systemctl status docker »ò sudo service docker status

      (5)Æô¶¯ºÍÍ£Ö¹dockerÃüÁî

      Æô¶¯docker£ºsudo systemctl start docker »òÕßsudo service docker start
      Í£Ö¹docker£ºsudo systemctl stop docker »òÕß sudo service docker stop

      (6)ÅäÖÿª»ú×ÔÆô¶¯docker·þÎñ

      sudo systemctl enable docker¡¡¡¡£¨disableΪ¹Ø±Õ×ÔÆô¶¯£©

      3£®°²×°docker-compose

      sudo curl-L"https://github.com/docker/compose/releases/download/1.23.2/dockercompose-$(uname-s)-$(uname -m)"-o/usr/local/bin/docker-compose
      chmod +x /usr/local/bin/
      docker-composedocker-compose version  #²é¿´°æ±¾ºÅ£¬²âÊÔÊÇ·ñ°²×°³É¹¦

      4£®dockerÈÝÆ÷ÖÐÔËÐÐUbuntu

      (1)°²×°Ubuntu

      docker pull ubuntu

      (2)²é¿´±¾µØ¾µÏñ

      docker images

      (3)½øÈëdockerÈÝÆ÷ÖеÄUbuntuϵͳ

      docker run -ti ubuntu /bin/bash

      (4)ʹÓÃapt-get £õ£ð£ä£á£ô£åÉý¼¶ÏµÍ³

      (5)°²×°apt-get install wgetÃüÁî

      5£®°²×°python

      (1)ÏÂÔØpython

      wget https://www.python.org/ftp/python/3.8.0/Python-3.8.0.tgz

      (2)ÏÂÔØÍêºó¾ÍÔÚµ±Ç°Ä¿Â¼½âѹ

      tar -zxvf Python-3.8.0.tgz

      (3)°²×°Ò»Ð©ËùÒªÒÀÀµµÄ°ü

      apt-get install -y make build-essential libssl-dev zlib1g-dev libbz2-dev libreadline-dev libsqlite3-dev wget cu

      (4)±àÒë°²×°

      ./configure --enable-optimizations --prefix=/usr/local/Python3/ && make && make install

      (5)ÐÞ¸ÄÈíÁ¬½Ó

      ln -s /usr/local/Python3/bin/python3.8 /usr/bin/python

      (6)ÑéÖ¤ÊÇ·ñÆô¶¯python3

      6£®ÔÚdockerÈÝÆ÷ÖÐÉÏ´«Â©¶´É¨Ã蹤¾ß£¬²¢É¨Ãè

      (1)ÏÂÔØStruts2©¶´ÀûÓÃɨÃ蹤¾ß°ü

      wget https://codeload.github.com/ch1st/struts2-scan/zip/refs/heads/£í£á£ó£ô£å£ò

      (2)½âѹStruts2©¶´ÀûÓÃɨÃ蹤¾ß°ü

      unzip £í£á£ó£ô£å£ò

      (3)ɨÃèÄ¿±êÊÇ·ñ´æÔÚStruts2©¶´£¬ÈçÏÂͼËùʾ£¬¿ÉÒÔ¿´µ½Ä¿±ê´æÔÚS2-016©¶´

      python scan.py -u http://219..153.49.228:47999/index.action

      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿