{"id":62968,"date":"2019-12-25T09:00:35","date_gmt":"2019-12-25T01:00:35","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=62968"},"modified":"2019-12-23T17:39:07","modified_gmt":"2019-12-23T09:39:07","slug":"ddos%e6%94%bb%e6%93%8a%e5%92%8ciot%e6%bc%8f%e6%b4%9e%e6%94%bb%e6%93%8a%ef%bc%9amomentum%e6%ae%ad%e5%b1%8d%e7%b6%b2%e8%b7%af%e7%9a%84%e6%96%b0%e5%8b%95%e6%85%8b","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=62968","title":{"rendered":"DDoS\u653b\u64ca\u548cIoT\u6f0f\u6d1e\u653b\u64ca\uff1aMomentum\u6bad\u5c4d\u7db2\u8def\u7684\u65b0\u52d5\u614b"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.trendmicro.com.tw\/edm\/Tracking.asp?id=2651&amp;name=20110916\">\u8da8\u52e2\u79d1\u6280<\/a>\u6700\u8fd1\u767c\u73fe\u4e86\u6703\u986f\u8457\u5f71\u97ffLinux\u88dd\u7f6e\u7684\u60e1\u610f\u8edf\u9ad4\u6d3b\u52d5\uff0cLinux\u5e73\u53f0\u4eca\u5e74\u5df2\u7d93\u8207<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/a-quick-and-efficient-method-for-locating-the-main-function-of-linux-elf-malware-variants\/\">\u8a31\u591a\u554f\u984c<\/a>\u5728\u596e\u6230\u4e2d\u3002\u9032\u4e00\u6b65\u5206\u6790\u53d6\u5f97\u7684\u60e1\u610f\u8edf\u9ad4\u6a23\u672c\u986f\u793a\u9019\u4e9b\u6d3b\u52d5\u8207\u540d\u70baMomentum\u7684\u6bad\u5c4d\u7db2\u8def\uff08\u5f9e\u901a\u8a0a\u983b\u9053\u5167\u6240\u767c\u73fe\u5716\u7247\u547d\u540d\uff09\u6709\u95dc\u3002\u6211\u5011\u767c\u73fe\u4e86\u6bad\u5c4d\u7db2\u8def\u7528\u4f86\u5165\u4fb5\u88dd\u7f6e\u4e26\u57f7\u884c\u5206\u6563\u5f0f\u963b\u65b7\u670d\u52d9\uff08DDoS\uff09\u653b\u64ca\u7684\u5de5\u5177\u53ca\u6280\u8853\u7d30\u7bc0\u3002<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignleft\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2016\/07\/IoT-feature-image-200x200.jpg\" alt=\"\"\/><\/figure><\/div>\n\n\n\n<p>Momentum\u6703\u91dd\u5c0d\u63a1\u7528\u5404\u7a2eCPU\u67b6\u69cb\u7684Linux\u5e73\u53f0\uff0c\u5305\u62ecARM\u3001MIPS\u3001Intel\u3001Motorola 68020\u7b49\u3002\u5b83\u7684\u4e3b\u8981\u76ee\u7684\u662f\u8981\u958b\u555f\u5f8c\u9580\u4f86\u63a5\u53d7\u547d\u4ee4\u5c0d\u7d66\u5b9a\u76ee\u6a19\u9032\u884c\u5404\u7a2e\u963b\u65b7\u670d\u52d9\uff08DoS\uff09\u653b\u64ca\u3002Momentum\u6bad\u5c4d\u7db2\u8def\u6703\u6563\u64ad\u7684\u5f8c\u9580\u7a0b\u5f0f\u5305\u62ec\u4e86Mirai\u3001Kaiten\u548cBashlite\u7b49\u75c5\u6bd2\u8b8a\u7a2e\u3002\u6211\u5011\u6240\u5206\u6790\u7684\u6a23\u672c\u6b63\u5728\u6d3e\u9001Mirai\u5f8c\u9580\u7a0b\u5f0f\u3002\u6b64\u5916\uff0cMomentum\u662f\u900f\u904e\u653b\u64ca\u591a\u7a2e\u8def\u7531\u5668\u548c\u7db2\u9801\u670d\u52d9\u6f0f\u6d1e\u4f86\u9032\u884c\u6563\u64ad\uff0c\u9032\u800c\u5728\u76ee\u6a19\u88dd\u7f6e\u4e0b\u8f09\u4e26\u57f7\u884cShell\u8173\u672c\u3002<\/p>\n\n\n\n<p><strong>Momentum<\/strong><strong>\u5982\u4f55\u904b\u4f5c\uff1f<\/strong><\/p>\n\n\n\n<p>Momentum\u5728\u611f\u67d3\u88dd\u7f6e\u5f8c\u6703\u7d93\u7531\u4fee\u6539 rc\u6a94\u6848\u4f86\u5be6\u73fe\u6301\u7e8c\u6027\u3002\u63a5\u8457\u6703\u52a0\u5165\u547d\u4ee4\u548c\u63a7\u5236\uff08C&amp;C\uff09\u4f3a\u670d\u5668\uff0c\u9023\u5230\u540d\u70ba#HellRoom\u7684IRC\u983b\u9053\u4f86\u8a3b\u518a\u81ea\u5df1\u4e26\u63a5\u6536\u547d\u4ee4\u3002IRC\u5354\u5b9a\u662f\u5b83\u8207\u547d\u4ee4\u548c\u63a7\u5236\uff08C&amp;C\uff09\u4f3a\u670d\u5668\u901a\u8a0a\u7684\u4e3b\u8981\u65b9\u6cd5\u3002\u63a5\u8457\u6bad\u5c4d\u7db2\u8def\u64cd\u4f5c\u8005\u5c31\u53ef\u4ee5\u767c\u9001\u8a0a\u606f\u5230IRC\u983b\u9053\u4f86\u63a7\u5236\u53d7\u611f\u67d3\u7cfb\u7d71\u3002<\/p>\n\n\n\n<!--more-->\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/12\/momentum-1.png\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u57161. \u53d7\u611f\u67d3\u88dd\u7f6e\u52a0\u5165\u653b\u64ca\u8005\u7684IRC\u547d\u4ee4\u548c\u63a7\u5236\u983b\u9053<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/files\/2019\/12\/Momentum-Botnet-Figure-2.jpg\" alt=\"\"\/><\/figure>\n\n\n\n<p>\u57162. \u547d\u4ee4\u548c\u63a7\u5236\u901a\u8a0a\u8def\u5f91\uff08\u4e0b\u8f09\u5668\/\u6d3e\u9001\u4f3a\u670d\u5668\u3001IRC\u4f3a\u670d\u5668\uff09<\/p>\n\n\n\n<p>\u6d3e\u9001\u4f3a\u670d\u5668\uff08\u5982\u4e0a\u6240\u793a\uff09\u653e\u6709\u60e1\u610f\u8edf\u9ad4\u57f7\u884c\u6a94\u3002\u53e6\u4e00\u53f0\u4f3a\u670d\u5668\u662f\u6bad\u5c4d\u7db2\u8def\u7684C&amp;C\u4f3a\u670d\u5668\u3002C&amp;C\u4f3a\u670d\u5668\u662f\u57282019\u5e7411\u670818\u65e5\u958b\u59cb\u555f\u7528\u3002<\/p>\n\n\n\n<p>\u4e00\u65e6\u5efa\u7acb\u4e86\u901a\u8a0a\u9023\u7dda\uff0cMomentum\u4fbf\u53ef\u4ee5\u900f\u904e\u5404\u7a2e\u547d\u4ee4\u4f86\u5229\u7528\u53d7\u611f\u67d3\u88dd\u7f6e\u9032\u884c\u653b\u64ca\u3002\u5177\u9ad4\u5730\u8aaa\uff0cMomentum\u80fd\u5920\u90e8\u7f7236\u7a2e\u4e0d\u540c\u7684DoS\u653b\u64ca\uff0c\u5982\u4e0b\u6240\u793a\u3002<\/p>\n\n\n\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>\u547d\u4ee4<\/strong>\n  <\/td><td>\n  <strong>\u63cf\u8ff0<\/strong>\n  <\/td><\/tr><tr><td>\n  ACK\n  <\/td><td>\n  ACK\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  ADV-TCP\n  <\/td><td>\n  TCP\u6d2a\u6c34\u653b\u64ca \u2013 \u6539\u826f\u7684SSYN\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  BLACKNURSE\n  <\/td><td>\n  ICMP\u5c01\u5305\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  DNS\n  <\/td><td>\n  DNS \u653e\u5927\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  ECE attacking (Not in use)\n  <\/td><td>\n  \u4e00\u7a2eSYN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  ESSYN\n  <\/td><td>\n  ExecuteSpoofedSyn\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  FIN attacking (Not in use)\n  <\/td><td>\n  FIN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  FRAGACK\n  <\/td><td>\n  ACK\u788e\u7247\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  FRAG-TCP\n  <\/td><td>\n  \u507d\u9020TCP\u788e\u7247\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  GRE\n  <\/td><td>\n  GRE\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  HOLD (Not in use)\n  <\/td><td>\n  TCP\u6d2a\u6c34\u653b\u64ca (frag)\n  <\/td><\/tr><tr><td>\n  HTTP\n  <\/td><td>\n  HTTP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  HTTPFLOOD\n  <\/td><td>\n  HTTP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  JUNK\n  <\/td><td>\n  TCP\u6d2a\u6c34\u653b\u64ca (frag)\n  <\/td><\/tr><tr><td>\n  LDAP\n  <\/td><td>\n  LDAP\u653e\u5927\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  MEMCACHE\n  <\/td><td>\n  MEMCACHE\u653e\u5927\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  NSACK\n  <\/td><td>\n  \u4e00\u7a2eACK\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  NSSYN\n  <\/td><td>\n  \u4e00\u7a2eSYN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  OVH\n  <\/td><td>\n  \u4e00\u7a2eUDP\u6d2a\u6c34\u653b\u64ca (DOMINATE)\n  <\/td><\/tr><tr><td>\n  PHATWONK\n  <\/td><td>\n  \u591a\u5408\u4e00\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  RTCP\n  <\/td><td>\n  \u4f7f\u7528\u788e\u7247\u5316\u5c01\u5305\u6a19\u982d\u7684\u96a8\u6a5fTCP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  SACK\n  <\/td><td>\n  \u4e00\u7a2eTCP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  SEW Attack\n  <\/td><td>\n  \u4e00\u7a2eSYN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  SSYN2\n  <\/td><td>\n  \u4e00\u7a2eSYN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  STUDP\n  <\/td><td>\n  STD\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  STUDP\n  <\/td><td>\n  STD\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  SYN\n  <\/td><td>\n  SYN\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  SYNACK\n  <\/td><td>\n  SYN-ACK\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  TCPNULL\n  <\/td><td>\n  TCP-Nulled\u6d2a\u6c34\u653b\u64ca \u2013 \u5229\u7528\u6c92\u6709\u8a2dflag\u7684TCP\u5c01\u5305\n  <\/td><\/tr><tr><td>\n  UDP\n  <\/td><td>\n  UDP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  UDP-BYPASS\n  <\/td><td>\n  UDP\u6d2a\u6c34\u653b\u64ca (vulnMix)\n  <\/td><\/tr><tr><td>\n  UNKNOWN\n  <\/td><td>\n  UDP\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  URG attacking\n  <\/td><td>\n  \u2013\n  <\/td><\/tr><tr><td>\n  VOLT-UDP\n  <\/td><td>\n  \u507d\u9020UDP\u6d2a\u6c34\u653b\u64ca, \u53ef\u4ee5\u7a7f\u900f\u591a\u6578\u9632\u706b\u7246\n  <\/td><\/tr><tr><td>\n  VSE\n  <\/td><td>\n  VSE\u653e\u5927\u653b\u64ca\n  <\/td><\/tr><tr><td>\n  XMAS\n  <\/td><td>\n  TCP Xmas\u6d2a\u6c34\u653b\u64ca\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>\u88681. Momentum\u80fd\u5920\u652f\u63f4\u7684\u5404\u7a2eDoS\u65b9\u5f0f<\/p>\n\n\n\n<p>\u6b64\u60e1\u610f\u8edf\u9ad4\u6703\u7528\u8a31\u591a\u53cd\u5c04\u548c\u653e\u5927\u653b\u64ca\u624b\u6cd5\u4f86\u91dd\u5c0d\u591a\u7a2e\u76ee\u6a19\uff1aMEMCACHE\u3001LDAP\u3001DNS\u548cValve Source Engine\uff08VSE\uff09\u3002\u5728\u9019\u4e9b\u985e\u578b\u7684\u653b\u64ca\u4e2d\uff0c\u60e1\u610f\u8edf\u9ad4\u901a\u5e38\u6703\u767c\u9001\u507d\u9020\u4f86\u6e90IP\u5730\u5740\uff08\u53d7\u5bb3\u8005\uff09\u7684\u5c01\u5305\u5230\u516c\u958b\u4f3a\u670d\u5668\u7684\u5404\u985e\u670d\u52d9\uff0c\u5f9e\u800c\u5c0e\u81f4\u5927\u91cf\u56de\u61c9\u4f86\u6df9\u6c92\u53d7\u5bb3\u8005IP\u5730\u5740\u3002<\/p>\n\n\n\n<p>\u9664\u4e86DoS\u653b\u64ca\u4e4b\u5916\uff0c\u6211\u5011\u767c\u73feMomentum\u9084\u53ef\u4ee5\u9032\u884c\u5176\u4ed6\u64cd\u4f5c\uff1a\u5728\u6307\u5b9aIP\u7aef\u53e3\u958b\u555f\u4ee3\u7406\u7a0b\u5f0f\uff0c\u66f4\u6539\u5ba2\u6236\u7aef\u66b1\u7a31\uff0c\u505c\u7528\u6216\u555f\u7528\u4f86\u81ea\u5ba2\u6236\u7aef\u7684\u5c01\u5305\u7b49\u7b49\u3002<\/p>\n\n\n\n<p>\u5728\u4e0b\u9762\u7ae0\u7bc0\uff0c\u6211\u5011\u5c07\u6703\u4ecb\u7d39Momentum\u7279\u5b9a\u7684\u653b\u64ca\u529f\u80fd\uff1a<\/p>\n\n\n\n<p><strong>Momentum<\/strong><strong>\u7684\u963b\u65b7\u670d\u52d9\uff08DoS<\/strong><strong>\uff09\u653b\u64ca<\/strong><\/p>\n\n\n\n<p><em>LDAP DDoS<\/em><em>\u53cd\u5c04\u653b\u64ca<\/em><\/p>\n\n\n\n<p>\u5728\u9032\u884cLDAP DDoS\u53cd\u5c04\u653b\u64ca\u6642\uff0c\u60e1\u610f\u8edf\u9ad4\u6703\u5c07\u4f86\u6e90IP\u5730\u5740\u507d\u88dd\u6210\u76ee\u6a19\u7cfb\u7d71\u4f86\u67e5\u8a62\u53ef\u516c\u958b\u8a2a\u554f\u7684LDAP\u4f3a\u670d\u5668\uff0c\u5c0e\u81f4\u5927\u91cf\u56de\u61c9\u6d41\u91cf\u50b3\u9001\u7d66\u76ee\u6a19\u3002<\/p>\n\n\n\n<p><em>Memcache<\/em><em>\u653b\u64ca<\/em><\/p>\n\n\n\n<p>\u9060\u7aef\u653b\u64ca\u8005\u5728\u9032\u884cMemcache\u653b\u64ca\u6642\u6703\u5c07\u4f86\u6e90IP\u5730\u5740\u507d\u88dd\u6210\u76ee\u6a19\u7cfb\u7d71\u4f86\u5c0d\u53ef\u88ab\u653b\u64ca\u7684UDP Memcached\u4f3a\u670d\u5668\u767c\u9001\u7279\u88fd\u7684\u60e1\u610fUDP\u8acb\u6c42\u3002\u63a5\u8457\u9019Memcached\u4f3a\u670d\u5668\u5c31\u6703\u5411\u76ee\u6a19\u767c\u9001\u5927\u91cf\u56de\u61c9\u3002Momentum\u4f7f\u7528HTTP GET\u8acb\u6c42\u4e0b\u8f09\u53cd\u5c04\u6a94\u6848 \u2013 \u60e1\u610f\u8edf\u9ad4\u5728\u5176\u4ed6\u653e\u5927\u5f0fDoS\u653b\u64ca\u4e5f\u6703\u51fa\u65bc\u76f8\u540c\u76ee\u7684\u4f86\u4f7f\u7528\u76f8\u540c\u7684\u8acb\u6c42\u3002<\/p>\n\n\n\n<p>\u6839\u64daShodan\u7684\u521d\u6b65\u8cc7\u6599\uff0c\u6709\u8d85\u904e42,000\u500b\u53ef\u88ab\u653b\u64ca\u7684Memcached\u4f3a\u670d\u5668\u53ef\u80fd\u906d\u53d7\u6b64\u985e\u653b\u64ca\u7684\u5f71\u97ff\u3002<\/p>\n\n\n\n<p>Momentum\u6bad\u5c4d\u7db2\u8def\u4f7f\u7528\u4e0b\u9762\u7684HTTP\nGET\u8acb\u6c42\u4e0b\u8f09\u53cd\u5c04\u6a94\u6848\uff1a<\/p>\n\n\n\n<p>GET\n\/ HTTP\/1.1<br>\nUser-Agent: Mozilla\/4.75 [en] (X11; U; Linux 2.2.16-3 i686)<br>\nHost: &lt;HOST_Address&gt;:80<br>\nAccept: *\/*<br>\nConnection: Keep-Alive<\/p>\n\n\n\n<p><em>UDP-BYPASS<\/em><em>\u653b\u64ca<\/em><\/p>\n\n\n\n<p>Momentum\u5728\u9032\u884cUDP-BYPASS\u653b\u64ca\u6642\u6703\u5c0d\u7279\u5b9a\u7aef\u53e3\u4e0a\u50b3\u7279\u88fd\u7684\u5408\u6cd5UDP\u5c01\u5305\u4f86\u6df9\u6c92\u76ee\u6a19\u4e3b\u6a5f\u3002\u5728\u57f7\u884c\u6b64\u653b\u64ca\u6642\uff0c\u60e1\u610f\u8edf\u9ad4\u6703\u9078\u64c7\u4e00\u500b\u96a8\u6a5f\u7aef\u53e3\u548c\u5c0d\u61c9\u7684\u7279\u88fd\u5c01\u5305\uff0c\u7136\u5f8c\u767c\u9001\u5230\u76ee\u6a19\u4e3b\u6a5f\u3002\u60e1\u610f\u8edf\u9ad4\u6703\u7528\u591a\u57f7\u884c\u7dd2\u9032\u884c\u653b\u64ca\uff1b\u6bcf\u500b\u57f7\u884c\u7dd2\u4f54\u7528\u4e00\u500b\u7aef\u53e3\u4f86\u4e0a\u50b3\u7279\u88fd\u5c01\u5305\u3002<\/p>\n\n\n\n<p>\u4ee5\u4e0b\u662f\u4e00\u4e9b\u7aef\u53e3\u53ca\u6240\u4f7f\u7528\u7684\u5c01\u5305\u5167\u5bb9\uff1a<\/p>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>\u7aef\u53e3<\/strong>\n  <\/td><td>\n  <strong>Payload<\/strong>\n  <\/td><td>\n  <strong>\u6558\u8ff0<\/strong>\n  <\/td><\/tr><tr><td>\n  500\n  <\/td><td>\n  \\x00\\x11\\x22\\x33\\x44\\x55\\x66\\x77\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x10\\x02\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xC0\\x00\\x00\\x00\\xA4\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x98\\x01\\x01\\x00\\x04\\x03\\x00\\x00\\x24\\x01\\x01\\x00\\x00\\x80\\x01\\x00\\x05\\x80\\x02\\x00\\x02\\x80\\x03\\x00\\x01\\x80\\x04\\x00\\x02\\x80\\x0B\\x00\\x01\\x00\\x0C\\x00\\x04\\x00\\x00\\x00\\x01\\x03\\x00\\x00\\x24\\x02\\x01\\x00\\x00\\x80\\x01\\x00\\x05\\x80\\x02\\x00\\x01\\x80\\x03\\x00\\x01\\x80\\x04\\x00\\x02\\x80\\x0B\\x00\\x01\\x00\\x0C\\x00\\x04\\x00\\x00\\x00\\x01\\x03\\x00\\x00\\x24\\x03\\x01\\x00\\x00\\x80\\x01\\x00\\x01\\x80\\x02\\x00\\x02\\x80\\x03\\x00\\x01\\x80\\x04\\x00\\x02\\x80\\x0B\\x00\\x01\\x00\\x0C\\x00\\x04\\x00\\x00\\x00\\x01\n  <\/td><td>\n  IKE v1, \u7b2c\u4e00\u968e\u6bb5\u4e3b\u8981\u6a21\u5f0f\n  <\/td><\/tr><tr><td>\n  1434\n  <\/td><td>\n  \\x02\n  <\/td><td>\n  MS-SQL ping \u5617\u8a66\n  <\/td><\/tr><tr><td>\n  5353\n  <\/td><td>\n  \\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x09_services\\x07_dns-sd\\x04_udp\\x05local\\x00\\x00\\x0C\\x00\\x01\n  <\/td><td>\n  DNS \u670d\u52d9\u767c\u73fe\n  <\/td><\/tr><tr><td>\n  8767\n  <\/td><td>\n  xf4\\xbe\\x03\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x01\\x00\\x00\\x002x\\xba\\x85\\tTeamSpeak\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\nWindows\n  XP\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x00\\x00\n  \\x00&lt;\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08nickname\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\n  <\/td><td>\n  TeamSpeak 2 UDP \u767b\u5165\u8acb\u6c42\n  <\/td><\/tr><tr><td>\n  9987\n  <\/td><td>\n  \\x05\\xca\\x7f\\x16\\x9c\\x11\\xf9\\x89\\x00\\x00\\x00\\x00\\x02\\x9d\\x74\\x8b\\x45\\xaa\\x7b\\xef\\xb9\\x9e\\xfe\\xad\\x08\\x19\\xba\\xcf\\x41\\xe0\\x16\\xa2\\x32\\x6c\\xf3\\xcf\\xf4\\x8e\\x3c\\x44\\x83\\xc8\\x8d\\x51\\x45\\x6f\\x90\\x95\\x23\\x3e\\x00\\x97\\x2b\\x1c\\x71\\xb2\\x4e\\xc0\\x61\\xf1\\xd7\\x6f\\xc5\\x7e\\xf6\\x48\\x52\\xbf\\x82\\x6a\\xa2\\x3b\\x65\\xaa\\x18\\x7a\\x17\\x38\\xc3\\x81\\x27\\xc3\\x47\\xfc\\xa7\\x35\\xba\\xfc\\x0f\\x9d\\x9d\\x72\\x24\\x9d\\xfc\\x02\\x17\\x6d\\x6b\\xb1\\x2d\\x72\\xc6\\xe3\\x17\\x1c\\x95\\xd9\\x69\\x99\\x57\\xce\\xdd\\xdf\\x05\\xdc\\x03\\x94\\x56\\x04\\x3a\\x14\\xe5\\xad\\x9a\\x2b\\x14\\x30\\x3a\\x23\\xa3\\x25\\xad\\xe8\\xe6\\x39\\x8a\\x85\\x2a\\xc6\\xdf\\xe5\\x5d\\x2d\\xa0\\x2f\\x5d\\x9c\\xd7\\x2b\\x24\\xfb\\xb0\\x9c\\xc2\\xba\\x89\\xb4\\x1b\\x17\\xa2\\xb6\n  <\/td><td>\n  TeamSpeak 3 UDP \u767b\u5165\u8acb\u6c42\n  <\/td><\/tr><tr><td>\n  1604\n  <\/td><td>\n  \\x1e\\x00\\x01\\x30\\x02\\xfd\\xa8\\xe3\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\n  <\/td><td>\n  Citrix MetaFrame \u61c9\u7528\u7a0b\u5f0f\u700f\u89bd\u5668\u670d\u52d9\n  <\/td><\/tr><tr><td>\n  1900\n  <\/td><td>\n  \\x4d\\x2d\\x53\\x45\\x41\\x52\\x43\\x48\\x20\\x2a\\x20\\x48\\x54\\x54\\x50\\x2f\\x31\\x2e\\x31\\x0D\\x0A\\x48\\x6f\\x73\\x74\\x3a\\x32\\x33\\x39\\x2e\\x32\\x35\\x35\\x2e\\x32\\x35\\x35\\x2e\\x32\\x35\\x30\\x3a\\x31\\x39\\x30\\x30\\x0D\\x0A\\x53\\x54\\x3a\\x73\\x73\\x64\\x70\\x3a\\x61\\x6c\\x6c\\x0D\\x0A\\x4d\\x61\\x6e\\x3a\\x22\\x73\\x73\\x64\\x70\\x3a\\x64\\x69\\x73\\x63\\x6f\\x76\\x65\\x72\\x22\\x0D\\x0A\\x4d\\x58\\x3a\\x33\\x0D\\x0A\\x0D\\x0A\n  <\/td><td>\n  SSDP\n  <\/td><\/tr><tr><td>\n  623\n  <\/td><td>\n  \\x06\\x00\\xff\\x07\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x09\\x20\\x18\\xc8\\x81\\x00\\x38\\x8e\\x04\\xb5\n  <\/td><td>\n  IPMI \u2013 RMCP Get Channel Auth Capabilities\n  <\/td><\/tr><tr><td>\n  626\n  <\/td><td>\n  SNQUERY: 127.0.0.1:AAAAAA:xsvr\n  <\/td><td>\n  Serialnumberd \u2013 Mac OS X Server\n  <\/td><\/tr><tr><td>\n  1194\n  <\/td><td>\n  8d\\xc1x\\x01\\xb8\\x9b\\xcb\\x8f\\0\\0\\0\\0\\0\n  <\/td><td>\n  OpenVPN P_CONTROL_HARD_RESET_CLIENT_V2\n  <\/td><\/tr><tr><td>\n  520\n  <\/td><td>\n  \\x01\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\n  <\/td><td>\n  RIP v1\n  <\/td><\/tr><tr><td>\n  177\n  <\/td><td>\n  \\x00\\x01\\x00\\x02\\x00\\x01\\x00\n  <\/td><td>\n  xdmcp \u2013 X Display Manager Control Protocol\n  <\/td><\/tr><tr><td>\n  389\n  <\/td><td>\n  \\x30\\x84\\x00\\x00\\x00\\x2d\\x02\\x01\\x07\\x63\\x84\\x00\\x00\\x00\\x24\\x04\\x00\\x0a\\x01\\x00\\x0a\\x01\\x00\\x02\\x01\\x00\\x02\\x01\\x64\\x01\\x01\\x00\\x87\\x0b\\x6f\\x62\\x6a\\x65\\x63\\x74\\x43\\x6c\\x61\\x73\\x73\\x30\\x84\\x00\\x00\\x00\\x00\n  <\/td><td>\n  Connectionless LDAP\n  <\/td><\/tr><tr><td>\n  161\n  <\/td><td>\n  \\x30\\x3A\\x02\\x01\\x03\\x30\\x0F\\x02\\x02\\x4A\\x69\\x02\\x03\\x00\\xFF\\xE3\\x04\\x01\\x04\\x02\\x01\\x03\\x04\\x10\\x30\\x0E\\x04\\x00\\x02\\x01\\x00\\x02\\x01\\x00\\x04\\x00\\x04\\x00\\x04\\x00\\x30\\x12\\x04\\x00\\x04\\x00\\xA0\\x0C\\x02\\x02\\x37\\xF0\\x02\\x01\\x00\\x02\\x01\\x00\\x30\\x00\n  <\/td><td>\n  SNMPv3GetRequest\n  <\/td><\/tr><tr><td>\n  53\n  <\/td><td>\n  %getPayload%getPayload\\x01\\x00\\x00\\x01\\x00\\x00\\x00\\x00\\x00\\x00\\x03\\x77\\x77\\x77\\x06\\x67\\x6f\\x6f\\x67\\x6c\\x65\\x03\\x63\\x6f\\x6d\\x00\\x00\\x01\\x00\\x01\n  <\/td><td>\n  \u67e5\u8a62DNS\n  &nbsp;\n  <\/td><\/tr><tr><td>\n  7\n  <\/td><td>\n  \\x0D\\x0A\\x0D\\x0A\n  <\/td><td>\n  echo\u670d\u52d9\n  <\/td><\/tr><tr><td>\n  111\n  <\/td><td>\n  \\x72\\xFE\\x1D\\x13\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x02\\x00\\x01\\x86\\xA0\\x00\\x01\\x97\\x7C\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\n  <\/td><td>\n  RPCCheck\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>\u88682. \u7aef\u53e3\u53ca\u5c0d\u61c9\u7684\u5c01\u5305\u5167\u5bb9<\/p>\n\n\n\n<p>\u4e0a\u9762\u6240\u770b\u5230\u7684\u8173\u672c\u5927\u591a\u90fd\u7528\u65bc\u670d\u52d9\u767c\u73fe\u3002\u5982\u679c\u5c07\u5b83\u5011\u767c\u9001\u5230\u76ee\u6a19\u88dd\u7f6e\u8d85\u904e\u4e00\u6bb5\u9577\u6642\u9593\uff0c\u5c31\u53ef\u80fd\u9020\u6210\u670d\u52d9\u5d29\u6f70\u9054\u5230\u963b\u65b7\u670d\u52d9\u7684\u6548\u679c\u3002<\/p>\n\n\n\n<p><em>Phatwonk<\/em><em>\u653b\u64ca<\/em><\/p>\n\n\n\n<p>Phatwonk\u653b\u64ca\u53ef\u4e00\u6b21\u57f7\u884c\u591a\u7a2eDoS\u65b9\u6cd5\uff1aXMAS\uff0c\u540c\u6642\u8a2d\u5b9a\u6240\u6709flag\uff0cusyn\uff08urg syn\uff09\u548c\u4efb\u610fTCP flag\u7d44\u5408\u3002<\/p>\n\n\n\n<p>Momentum<strong>\u7684\u5176\u4ed6\u529f\u80fd<\/strong><\/p>\n\n\n\n<p>\u8981\u9054\u5230\u60f3\u8981\u7684\u7d50\u679c\u9700\u8981\u9760\u653b\u64ca\u4ee5\u5916\u7684\u529f\u80fd\u3002\u901a\u5e38\u60e1\u610f\u8edf\u9ad4\u6703\u60f3\u8981\u8eb2\u907f\u5075\u6e2c\uff0c\u4fdd\u6301\u958b\u653e\u7684\u901a\u8a0a\u7ba1\u9053\uff0c\u4ee5\u53ca\u9032\u884c\u66f4\u591a\u5f8c\u7e8c\u6210\u529f\u7684\u6d3b\u52d5\u3002<\/p>\n\n\n\n<p>Momentum\u9084\u6709\u5176\u4ed6\u529f\u80fd\u4f86\u5e6b\u52a9\u81ea\u5df1\u6563\u64ad\u548c\u5165\u4fb5\u88dd\u7f6e\uff1a<\/p>\n\n\n\n<ul><li><em>\u5feb\u901f\u8b8a\u52d5\uff08Fast Flux<\/em><em>\uff09<\/em>\u3002Momentum\u6bad\u5c4d\u7db2\u8def\u4f7f\u7528\u5feb\u901f\u8b8a\u52d5\u6280\u8853\u4f86\u8b93\u81ea\u5df1\u7684\u547d\u4ee4\u548c\u63a7\u5236\u7db2\u8def\u66f4\u52a0\u6709\u5f48\u6027\u3002\u5feb\u901f\u8b8a\u52d5\u7db2\u8def\u4ee3\u8868\u6709\u591a\u500bIP\u5730\u5740\u8ddf\u4e00\u500b\u7db2\u57df\u76f8\u95dc\u806f\uff0c\u7136\u5f8c\u4e0d\u65b7\u5feb\u901f\u5730\u9032\u884c\u9023\u7e8c\u8b8a\u66f4\n\u2013 \u653b\u64ca\u8005\u7528\u5b83\u4f86\u8aa4\u5c0e\u6216\u8eb2\u907f\u5b89\u5168\u8abf\u67e5\u3002<\/li><li><em>\u5f8c\u9580\u7a0b\u5f0f<\/em>\u3002\u653b\u64ca\u8005\u53ef\u5411IRC\u983b\u9053\u767c\u9001\u547d\u4ee4\uff08\u201c BASH\u201d\u3001\u201c SHD\u201d\u6216SH\u547d\u4ee4\uff09\uff0c\u60e1\u610f\u8edf\u9ad4\u5ba2\u6236\u7aef\u6703\u5728\u53d7\u611f\u67d3\u7cfb\u7d71\u4e0a\u63a5\u6536\u4e26\u57f7\u884c\u547d\u4ee4\u3002\u5c07\u7d50\u679c\u9001\u56de\u653b\u64ca\u8005\u4e0b\u6307\u4ee4\u7684\u540c\u4e00IRC\u983b\u9053\u3002<\/li><li><em>\u6563\u64ad<\/em>\u3002Momentum\u6703\u5229\u7528\u4e0b\u8868\u5217\u51fa\u7684\u6f0f\u6d1e\u4f86\u9032\u884c\u6563\u64ad\u3002\u6211\u5011\u6240\u8abf\u67e5\u7684C&amp;C\u4f3a\u670d\u5668\u986f\u793a\u67091,232\u540d\u53d7\u5bb3\u8005\u3002\u800c\u5176\u4ed6Momentum\u8b8a\u7a2e\u548cC&amp;C\u4f3a\u670d\u5668\u53ef\u80fd\u9084\u6709\u66f4\u591a\u7684\u53d7\u5bb3\u8005\u3002<\/li><\/ul>\n\n\n\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>\u6f0f\u6d1e<\/strong>\n  <\/td><td>\n  <strong>\u6f0f\u6d1e\u653b\u64ca\u78bc\u683c\u5f0f<\/strong>\n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/www.exploit-db.com\/exploits\/39596\">CCTV-DVR RCE<\/a>\n  <a href=\"https:\/\/www.exploit-db.com\/exploits\/39596\">\u591a\u5bb6\u5ee0\u5546<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  ZyXEL\u8def\u7531\u5668\n  (\u6f0f\u6d1e\u653b\u64ca\u78bc\u4f3c\u4e4e\u4e0d\u5b8c\u5168,\n  \u985e\u4f3c\u65bc<a href=\"https:\/\/seclists.org\/fulldisclosure\/2017\/Jan\/40\">\u6b64\u7bc7<\/a>)\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-17215\">\u83ef\u70ba\u8def\u7531\u5668<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  &nbsp;\n  <\/td><\/tr><tr><td>\n  &nbsp;\n  \u591a\u5bb6\u5ee0\u5546:\n  Crestron AM, Barco wePresent WiPG, Extron ShareLink, Teq AV IT, SHARP\n  PN-L703WA, Optoma WPS-Pro, Blackbox HD WPS, InFocus LiteShow&nbsp; \u9060\u7aef\u547d\u4ee4\u6ce8\u5165\n  &nbsp;\n  (\u8207CVE\n  2019-3929 \u53ca\u985e\u4f3c\u65bc<a href=\"https:\/\/www.exploit-db.com\/exploits\/46786\">\u6b64\u7bc7<\/a>)\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/dl.packetstormsecurity.net\/papers\/attack\/dlink_hnap_captcha.pdf\">D-Link HNAP1<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2014-8361\">Realtek SDK UPnP SOAP\u547d\u4ee4\u57f7\u884c\u6f0f\u6d1e<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-10562\">GPON80<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-10562\">GPON8080<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2018-10562\">GPON443<\/a>\n  &nbsp;\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/www.exploit-db.com\/exploits\/41471\">JAWS Webserver\u7121\u8a8d\u8b49shell\u547d\u4ee4\u57f7\u884c\u6f0f\u6d1e<\/a>\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/vulners.com\/openvas\/OPENVAS:1361412562310107187\">Vacron NVR RCE<\/a>\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  UPnP SOAP \u547d\u4ee4\u57f7\u884c\u6f0f\u6d1e\n  (\u985e\u4f3c\u65bc<a href=\"https:\/\/www.exploit-db.com\/exploits\/40740\">\u6b64\u7bc7<\/a>)\n  <\/td><td>\n  \n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/www.exploit-db.com\/exploits\/46150\">THINK-PHP<\/a>\n  <\/td><td>\n  &nbsp;\n  \n  &nbsp;\n  <\/td><\/tr><tr><td>\n  <a href=\"https:\/\/www.exploit-db.com\/exploits\/46143\">HooTooTripMate\n  RCE<\/a>\n  <\/td><td>\n  &nbsp;\n  \n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>\u88683. \u6563\u64ad\u6642\u6240\u7528\u7684\u6f0f\u6d1e\u548c\u653b\u64ca\u78bc<\/p>\n\n\n\n<p><strong>\u5b89\u5168\u5efa\u8b70\u548c\u89e3\u6c7a\u65b9\u6848<\/strong><\/p>\n\n\n\n<p>\u7531\u65bc\u5b89\u5168\u8a2d\u5b9a\u548c\u4fdd\u8b77\u63aa\u65bd\u7684\u53d7\u9650\uff0c\u667a\u6167\u578b\u806f\u7db2\u88dd\u7f6e\u5bb9\u6613\u906d\u53d7\u5165\u4fb5\u5a01\u8105\u3002\u88dd\u7f6e\u88fd\u9020\u6642\u901a\u5e38\u53ea\u8003\u616e\u5230\u64cd\u4f5c\u6027\u800c\u975e\u5b89\u5168\u6027\u3002\u4f7f\u7528\u8005\u5fc5\u9808\u63a1\u53d6\u7a4d\u6975\u63aa\u65bd\u4f86<a href=\"https:\/\/www.trendmicro.com\/vinfo\/hk-en\/security\/news\/internet-of-things\/the-first-steps-in-effective-iot-device-security\">\u4fdd\u8b77\u81ea\u5df1\u7684\u88dd\u7f6e<\/a>\uff08\u5c24\u5176\u662f<a href=\"https:\/\/www.trendmicro.com\/vinfo\/us\/security\/news\/home-router\">\u8def\u7531\u5668<\/a>\uff09\u5b89\u5168\u3002\u5982\u524d\u6240\u8ff0\uff0cMomentum\u6bad\u5c4d\u7db2\u8def\u91dd\u5c0d\u7684\u662fLinux\u88dd\u7f6e\uff0c\u9019\u4e9b\u88dd\u7f6e\u5df2\u77e5\u5bb9\u6613\u906d\u53d7<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=60878\">\u6bad\u5c4d\u7db2\u8def<\/a>\u3001<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=60839\">\u52d2\u7d22\u8edf\u9ad4<\/a>\u548c<a href=\"https:\/\/www.trendmicro.com\/vinfo\/ph\/security\/news\/cybercrime-and-digital-threats\/cryptocurrency-mining-malware-targets-linux-systems-uses-rootkit-for-stealth?_ga=2.76607573.1739751013.1575426438-61030443.1557222425\">\u865b\u64ec\u8ca8\u5e63\u6316\u7926<\/a>\u7b49\u653b\u64ca\u3002\u4f46\u6709\u8a31\u591a\u65b9\u6cd5\u53ef\u4ee5<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/a-quick-and-efficient-method-for-locating-the-main-function-of-linux-elf-malware-variants\/\">\u4fdd\u8b77\u9019\u985e\u88dd\u7f6e<\/a>\u62b5\u79a6\u653b\u64ca\u3002<\/p>\n\n\n\n<table  class=\"wp-block-table is-style-stripes table table-hover\" ><tbody><tr><td> <strong>\u5ef6\u4f38\u95b1\u8b80:<\/strong><br> <a href=\"https:\/\/blog.trendmicro.com.tw\/?p=60878\">AESDDoS \u6bad\u5c4d\u7db2\u8def\u8b8a\u7a2e,\u7d93\u7531\u66b4\u9732\u5728\u5916\u7684 Docker API \u6ef2\u900f\u5bb9\u5668<\/a><br> <a href=\"https:\/\/blog.trendmicro.com.tw\/?p=60839\">HiddenWasp\u60e1\u610f\u8edf\u9ad4\u501f\u7528Mirai\u53caWinnti\u7a0b\u5f0f\u78bc\u653b\u64caLinux\u7cfb\u7d71<\/a> <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p><a href=\"https:\/\/www.trendmicro.tw\/tw\/business\/complete-software-protection\/index.html\">Smart Protection Network&#x2122;<\/a>\u63d0\u4f9b\u5d4c\u5165\u5f0f\u7db2\u8def\u5b89\u5168\u89e3\u6c7a\u65b9\u6848\uff0c\u80fd\u5920\u4fdd\u8b77\u6240\u6709\u9023\u63a5\u5bb6\u5ead\u7db2\u8def\u7684\u88dd\u7f6e\u62b5\u79a6\u7db2\u8def\u653b\u64ca\u3002\u85c9\u7531\u8da8\u52e2\u79d1\u6280\u8c50\u5bcc\u7684\u5a01\u8105\u7814\u7a76\u7d93\u9a57\u4ee5\u53ca\u696d\u754c\u9818\u5148\u7684\u6df1\u5ea6\u5c01\u5305\u6aa2\u6e2c\uff08DPI\uff09\u6280\u8853\uff0c\u8da8\u52e2\u79d1\u6280\u7684Smart Home Network\u63d0\u4f9b\u4e86\u667a\u6167\u5316\u670d\u52d9\u54c1\u8cea\uff08iQoS\uff09\u3001\u5bb6\u9577\u5b88\u8b77\u548c\u7db2\u8def\u5b89\u5168\u9632\u8b77\u7b49\u529f\u80fd\u3002<\/p>\n\n\n\n<p><a href=\"https:\/\/t.rend.tw\/?i=NDIwMw==\">\u8da8\u52e2\u79d1\u6280Deep Discovery\u9032\u968e\u7db2\u8def\u5b89\u5168\u9632\u8b77<\/a>\u900f\u904e\u7279\u88fd\u5f15\u64ce\u3001\u5ba2\u88fd\u5316<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/deploying-a-smart-sandbox-for-unknown-threats-and-zero-day-attacks\/\">\u6c99\u7bb1<\/a>\u548c\u8de8\u8d8a\u6574\u500b\u653b\u64ca\u751f\u547d\u9031\u671f\u7684\u7121\u7e2b\u95dc\u806f\u6280\u8853\u4f86\u5c0d\u6f0f\u6d1e\u653b\u64ca\u53ca\u5176\u4ed6\u985e\u4f3c\u5a01\u8105\u9032\u884c\u5075\u6e2c\u3001\u6df1\u5165\u5206\u6790\u548c\u4e3b\u52d5\u56de\u61c9\uff0c\u5f9e\u800c\u53ef\u4ee5\u7121\u9700\u66f4\u65b0\u5f15\u64ce\u548c\u7279\u5fb5\u78bc\u5c31\u80fd\u5920\u5075\u6e2c\u9019\u4e9b\u985e\u578b\u7684\u653b\u64ca\u3002\u9019\u4e9b\u89e3\u6c7a\u65b9\u6848\u7531<a href=\"https:\/\/www.trendmicro.tw\/business\/xgen-security.html\">\u8da8\u52e2\u79d1\u6280\u7684XGen\u5b89\u5168\u9632\u8b77\u6280\u8853<\/a>\u6280\u8853\u9a45\u52d5\uff0c\u5b83\u63d0\u4f9b\u4e86\u8de8\u4e16\u4ee3\u7684\u6df7\u5408\u5a01\u8105\u9632\u79a6\u6280\u8853\uff0c\u53ef\u4ee5\u62b5\u79a6<a href=\"https:\/\/www.trendmicro.com\/zh_tw\/business\/products\/user-protection\/sps\/endpoint.html\">\u7aef\u9ede<\/a>\uff0c<a href=\"https:\/\/www.trendmicro.com\/zh_tw\/business\/products\/network.html\">\u7db2\u8def<\/a>\uff0c<a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/hybrid-cloud\/deep-security-data-center.html\">\u4f3a\u670d\u5668<\/a>\u4ee5\u53ca<a href=\"https:\/\/www.trendmicro.tw\/tw\/business\/complete-software-protection\/index.html\">\u9598\u9053<\/a>\u6240\u9762\u81e8\u7684\u5404\u7a2e\u5a01\u8105\u3002\u7cbe\u6e96\u3001\u6700\u4f73\u5316\u3001\u74b0\u74b0\u76f8\u6263\u7684XGen\u9632\u8b77\u6280\u8853\u9a45\u52d5\u8457\u8da8\u52e2\u79d1\u6280\u4e00\u7cfb\u5217\u7684\u9632\u8b77\u89e3\u6c7a\u65b9\u6848\uff1aHybrid\u00a0Cloud Security\uff08\u6df7\u5408\u5f0f\u96f2\u7aef\u9632\u8b77\uff09\uff0cUser Protection\uff08\u4f7f\u7528\u8005\u9632\u8b77\uff09\u548cNetwork Defense\uff08\u5167\u7db2\u9632\u8b77\uff09\u3002<\/p>\n\n\n\n<p>\u5165\u4fb5\u6307\u6a19<\/p>\n\n\n\n<style>\n   table {border-collapse:collapse; table-layout:fixed; width:310px;}\n   table td {border:solid 1px ; width:100px; word-wrap:break-word;}\n   <\/style>\n<table  class=\"wp-block-table table table-hover\" ><tbody><tr><td>\n  <strong>SHA-256<\/strong>\n  <\/td><td>\n  <strong>\u6558\u8ff0<\/strong>\n  <\/td><\/tr><tr><td>\n  3c6d31b289c46b98be7908acd84086653a0774206b3310e0ea4e6779e1ff4124\n  <\/td><td>\n  Trojan.Linux.MIRAI.SMMR1\n  <\/td><\/tr><\/tbody><\/table>\n\n\n\n<p>@\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/ddos-attacks-and-iot-exploits-new-activity-from-momentum-botnet\/\">DDoS\nAttacks and IoT Exploits: New Activity from Momentum Botnet<\/a> \u4f5c\u8005\uff1aAliakbar Zahravi<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u8da8\u52e2\u79d1\u6280\u6700\u8fd1\u767c\u73fe\u4e86\u6703\u986f\u8457\u5f71\u97ffLinux\u88dd\u7f6e\u7684\u60e1\u610f\u8edf\u9ad4\u6d3b\u52d5\uff0cLinux\u5e73\u53f0\u4eca\u5e74\u5df2\u7d93\u8207\u8a31\u591a\u554f\u984c\u5728\u596e\u6230\u4e2d\u3002\u9032\u4e00\u6b65\u5206\u6790 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[1335,11,3654,156],"tags":[333,1599,23,452,1593,2981],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/62968"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=62968"}],"version-history":[{"count":0,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/62968\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=62968"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=62968"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=62968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}