ÍÆ¼ö²¿ÊðÔÚÖдóÐ;ÖÓòÍø£¬Ö§³ÖϵͳɨÃè¡¢WebɨÃè¡¢Êý¾Ý¿âɨÃè¡¢Èõ¿ÚÁîɨÃèµÈÖ°ÄÜ
²úÆ·¸öÐÔ£º
ϵͳ·ì϶¼ì²â
ÍøÂçÖ÷»ú£º·þÎñÆ÷¡¢¿Í»§»ú¡¢ÍøÂç´òÓ¡»ú¡¢Òƶ¯É豸¡¢Ðé¹¹»¯É豸µÈ£»
²Ù×÷ϵͳ£ºMicrosoft Windows 9X/NT/2000/XP/2003¡¢Æ»¹û²Ù×÷ϵͳ¡¢¹ú²ú²Ù×÷ϵͳ¡¢Sun Solaris¡¢HP Unix¡¢IBM AIX¡¢IRIX¡¢Linux¡¢BSD¡¢HPUXµÈ£»
ÍøÂçÉ豸£ºCisco¡¢Juniper¡¢F5¡¢3Com¡¢CheckpointµÈÖ÷Á÷³§ÉÌÍøÂçÉ豸£»
°²È«É豸£ºCheckpoint¡¢ÈüÃÅÌú¿Ë¡¢Cisco¡¢Juniper¡¢Palo AltoµÈÖ÷Á÷³§É̵ݲȫÉ豸£»
ÀûÓÃϵͳ£ºÊý¾Ý¿â¡¢Web¡¢FTP¡¢µç×ÓÓʼþµÈ¡£
±¾²úÆ··ì϶¿âº¸Ç·á˶µÄ°²È«·ì϶ºÍ¹¥»÷ÌØµã£¬ÖÁÉÙÖ§³ÖCVE¡¢CVSS¡¢CNVID¡¢CNNVD¡¢CNCVE¡¢BugtraqµÈ·ì϶ÖÖÀ࣬Ô̺¬×Å·á˶µÄ×êÑоÑéºÍÉîºñµÄ֪ʶ¶Ñ¼¯£¬ÊÕ¼¶à¸ö³ß¶Èϵķì϶£¬¿ÉÄÜΪ¿Í»§Ìá³ÖÐøµÄ¡¢¸ßÆ·ÖʵIJúÆ·ÀûÓüÛÖµ¡£
Web·ì϶¼ì²â
¡ñÍøÕ¾°²È«·ìÏ¶È«Ãæ¼ì²â
ÓëĿǰÊÐÃæÉÏµÄÆäËüÍøÕ¾°²È«¼ì²âÀà²úÆ·µ¥Ò»µØË¼¿¼ÏµÍ³°²È«¡¢ÍøÒ³±à³Ì°²È«¡¢SQL×¢Èë¡¢¿çÕ¾·ì϶µÈ·½ÃæµÄ°²È«ÎÊÌâ·ÖÆç£¬±¾²úÆ·´ÓÉè¼ÆÍøÕ¾°²È«µÄ¸÷¸ö·½ÃæÀ´¶ÔÍøÕ¾°²È«Çé¿ö×ö³ö×îÈ«ÃæµÄÆÀ¹À£¬Ô̺¬£ºÏµÍ³²¹¶¡¡¢Î£ÏÕ²å¼þ¡¢´úÂëÉ󼯡¢¶ñÒâÍøÕ¾¡¢ÍøÒ³Ä¾Âí¡¢ÍøÕ¾°µÁ´¡¢SQL×¢Èë¡¢¿çÕ¾×¢Èë¡¢ÖÎÀíÈë¿ÚÒÔ¼°Ãô¸ÐÐÅÏ¢µÈµÈ¡£
¡ñÍøÕ¾´úÂë±¾µØ°²È«²é³
ĿǰµÄÔ¶³ÌSQL×¢ÈëɨÃè¡¢¿çÕ¾·ì϶ɨÃèµÈÊÇÕë¶ÔÍøÕ¾´úÂë½øÐÐ±í²¿µÄºÚºÐ²âÊÔ£¬¶øÎÒÃÇÕë¶ÔÍøÕ¾´úÂëµÄ°²È«²é³ÊÇÕë¶ÔÍøÕ¾´úÂë½øÐÐÈ«ÃæÖ±½ÓµÄ²é³£¬ÕÒµ½SQL×¢Èë¡¢¿çÕ¾·ì϶¡¢ÍøÂíµÈһϵÁа²È«ÎÊÌâ¡£¼´Õë¶ÔÍøÕ¾´úÂë½øÐб¾µØµÄ°²È«²é³¡£
¡ñ¶Ñ¼¯·á˶µÄÍøÂíÌØµã¿â
±¾²úƷѡȡÁË×êÑÐÍŶӶàÄê¶Ñ¼¯µÄ·á˶µÄÍøÂíÌØµã¿â£¬²»½öÔ̺¬ÍøÂí´úÂëÌØµã¡¢²¢ÇÒÔ̺¬¹ÒÂíÍøÕ¾µÄÁÐ±í£¬Ë«³Á¼ì²â¼¿Á©±£ÏÕÍøÂí¼ì²â½ÏµÍµÄ©±¨ÂʺÍÎó±¨ÂÊ£¬Í¬Ê±ÎÒÃÇά³ÖÿÖÜÖÁÉÙÒ»´ÎµÄÌØµã¿âµÄÉý¼¶ÒÔ¼°0day·ì϶µÄ24Ó×ʱ´¹Î£Éý¼¶±£ÏÕ¡£
¡ñ¸ßЧµÄÍøÒ³ÅÀ³æ¼¼Êõ
±¾²úÆ·µÄÍøÒ³×¥È¡Ä£¿éѡȡ¹ã¶Å×ÅÏÈÅÀ³æ¼¼Êõ¡¢Éî¶Å×ÅÏÈÅÀ³æ¼¼ÊõÒÔ¼°ÍøÕ¾Ä¿Â¼»¹Ô¼¼Êõ¡£¹ã¶Å×ÅÏȵÄÅÀ³æ¼¼Êõ²»»á²úÉúÅÀ³æÏÝÈëµÄÎÊÌâ£¬ÍøÕ¾Ä¿Â¼»¹Ô¼¼ÊõÔòÈ¥³ýÁËÎÞ¹ØÁ˾֣¬Ìá¸ßץȡЧÄÜ¡£
¡ñ»ùÓÚ״̬µÄSQL×¢ÈëɨÃè¼¼Êõ
±¾²úÆ··ÖÆçÓÚ´«Í³µÄÕë¶ÔÃýÎó·´À¡ÅжÏÊÇ·ñ´æÔÚ×¢Èë·ì϶µÄ·½Ê½£¬¶øÑ¡È¡×ÔÖ÷´´ÐµÄ״̬¼ì²âÀ´Åжϡ£Ëùν״̬¼ì²â£¬¼´£ºÕë¶ÔijһÁ´½ÓÊäÈë·ÖÆçµÄ²ÎÊý£¬Í¨¹ý¶ÔÍøÕ¾·´À¡µÄÁ˾ÖʹÓÃÏòÁ¿±ÈÁ¦Ëã·¨½øÐбȶÔÅжϣ¬´Ó¶øÈ·¶¨¸ÃÁ´½ÓÊÇ·ñΪעÈëµã£¬´Ë²½Öè²»ÒÀÀµÓÚÌØ¶¨µÄÊý¾Ý¿âÀàÐÍ¡¢ÉèÖÃÒÔ¼°CGI˵»°µÄÖÖÀ࣬¶ÔÓÚ×¢Èëµã¼ì²âÈ«Ãæ£¬²»»á²úÉú©±¨¾°Ïó¡£¶ø³£¼ûµÄSQL×¢ÈëɨÃè²úÆ·¾ù²»¾ß±¸´ËÏî¼¼Êõ¡£
¡ñ»ùÓÚ״̬±ÈÁ¦µÄ×¢ÈëÑéÖ¤¼¼Êõ
±¾²úƷѡȡ״̬¼ì²âÀ´¶ÔÊý¾Ý¿âµÄÊý¾Ý½øÐв½⣬ÎÞÂÛÍøÕ¾Ñ¡È¡Ê²Ã´CGI˵»°£¬ÎÞÂÛÍøÕ¾ÊÇ·ñ·´À¡ÃýÎóÐÅÏ¢£¬¶¼ÄܽøÐÐÕý³£µÄ²Â½â£¬¶ø³£¼ûµÄSQL×¢ÈëɨÃè²úÆ·¾ù²»¾ß±¸´ËÏî¼¼Êõ¡£
¡ñ»ùÓÚÍÌÍÂÆ¥ÅäµÄÖÎÀíÈë¿Ú¼ì²â¼¼Êõ
±¾²úÆ·ÖÎÀíÈë¿Ú¼ì²âÄ£¿é²»½öѡȡͨÀýÖÎÀíÈë¿Ú¼ì²â¼¼Êõ£¬¼´£ºÊ¹Óó£ÓõÄÖÎÀíÈë¿Ú¿â½øÐÐÖðһƥÅä²é³£¬²¢ÇÒ»¹Ñ¡È¡ÁËÍÌÍÂÆ¥ÅäµÄ·½Ê½À´¼ì²âÖÎÀíÈë¿Ú£¬ËùνµÄÍÌÍÂÆ¥Åä¼´Èí¼þʹÓÃÍÌÍÂÆ¥ÅäµÄ·½Ê½À´¶ÔÍøÕ¾ËùÓÐÁ´½Ó½øÐÐÆ¥Å䣬´Ó¶ø×î´ó¿ÉÄÜÕÒ³öËùÓÐÖÎÀíÈë¿Ú¡£
¡ñÇ¿ÓÐÁ¦µÄ½âÎö·½Ê½
±¾²úÆ·Ö§³ÖÖ§³ÖÅÀ³æ±íµ¥×Ô¶¯·ÖÎö¡¢Javascript½âÎö¡¢JavaÓëHtmlElement×Ô¶¯½»»¥¡¢Ajax½âÎö¡¢Flash½âÎöµÈÐÂÐÍ¡¢·á˶¶ø¸ßЧµÄ½âÎö·½Ê½¡£Éî¶È½âÎöwebÒ³Ãæ£¬Äܹ»ÕýÈ·¶ø¸ßЧµÄ·¢ÏÖweb·ì϶¡£
Êý¾Ý¿â·ì϶¼ì²â
±¾²úƷѡȡÏȽøµÄÊý¾Ý¿â·¢ÏÖ¼¼ÊõºÍÊ·ý·¢ÏÖ¼¼ÊõµÈ£¬Äܹ»Õë¶Ôµ±ÏÂÖ÷Á÷µÄÊý¾Ý¿â£¬ÈçOracle¡¢MySQL¡¢DB2¡¢PostgreSQL¡¢sybase¡¢SQL Server¡¢InformixµÈ½øÐзì϶¼ì²â£¬Ô̺¬¶ÔÊý¾Ý¿âϵͳµÄ¸÷ÏîÉèÖá¢Êý¾Ý¿âϵͳÈí¼þ×ÔÉíÒÑÖª·ì϶¡¢Êý¾Ý¿âϵͳÆëÈ«ÐÔ½øÐв鳺ͶÔÊý¾Ý¿âϵͳµÄÕûÌ尲ȫÐÔ×ö³öÆÀ¹À£¬²¢¸ø³öÌá¸ßÊý¾Ý¿â°²È«ÐԵĽ¨¸´½¨Ò顣ͨ¹ýµÇ¼ɨÃè¿É¶ÔÊý¾Ý¿âµÄÿÕűíÿ¸ö×ֶνøÐа²È«¼ì²â¡£
¸²¸ÇÃæ¹ãµÄ·ì϶¿â
±¾²úÆ·Ô̺¬CNNVDÈÏÖ¤µÄϵͳ·ì϶¿â20¶àÀ࣬50000¶àÌõ£»Web·ì϶¿â¹²¸²¸ÇOWASP½ç˵µÄ10´óÀà·ì϶¹æ¶¨¡£Ô̺¬Ðé¹¹»¯É豸¡¢Òƶ¯É豸¡¢ÍøÂçÉ豸¡¢°²È«É豸µÈ¶àÖÖÀàÐ͵Ĺ涨£¬¸²¸ÇÁ˵±Ç°ÍøÂç»·¾³ÖгÁÒªµÄ£¬Ö÷Á÷µÄϵͳºÍÊý¾Ý¿âµÈ·ì϶£¬²¢ÇÒ¿ÉÄÜÆ¾¾Ý¼´Ê±¸üУ¬È·±£·ì϶ʶ´ËÍâÈ«ÃæÐÔºÍʱЧÐÔ¡£
¿É×Ô½ç˵¹æ¶¨¿â
±¾²úÆ·ÖУ¬Óû§³ýÁËÄܹ»Ê¹ÓÃÈí¼þĬÈÏÌṩµÄ¼ì²â¿â±í£¬Ò²Äܹ»Ôö³¤×Ô½ç˵µÄ¹æ¶¨¿âÄ£°å£¬ÅúÁ¿É¸Ñ¡ËùÐèÄ£°å£¬Í¨¹ýн¨Ä£°å²¢Ñ¡ÔñËùÐèµÄ¹æ¶¨£¬¿É¸ßЧ¡¢ÓÐÕë¶ÔÐԵļì²â·ì϶¡£
Ç¿ÓÐÁ¦µÄɨÃèЧÄÜ
±¾²úÆ·×ÛºÏʹÓÃԤ̽²â¡¢½¥½øÊ½¡¢¶àÏ̵߳ÄɨÃè¼¼Êõ£¬¿ÉÄܼ±¾ç·¢ÏÖÖ¸±êÍøÂçÖеĴæ»îÖ÷»ú£¬¶øºóƾ¾Ý½¥½øÊ½Ì½²âÁ˾ÖÑ¡ÔñÊʺϵÄɨÃèÕ½Êõ£¬Æô¶¯¶à¸öÏ߳̽øÐв¢·¢É¨Ã裬´Ó¶ø±£ÕÏÁËɨÃ蹤×÷Äܹ»Ñ¸¿ìʵÏÖ¡£
ÕýÈ·µÄ·ì϶¼ø±ðÂÊ
±¾²úƷѡȡ½¥½øÊ½É¨Ãè·ÖÎö²½Ö裬ÈÚºÏÇ°ÑØµÄ²Ù×÷ÏµÍ³Ö¸ÎÆ¼ø±ð¡¢ÖÇÄܶ˿ڷþÎñ¼ø±ðµÈ¼¼Êõ£¬¿ÉÄÜÕýÈ·¼ø±ð±»É¨Ãè¶ÔÏóµÄ¸÷ÀàÐÅÏ¢£¬Èç²Ù×÷ϵͳ¡¢ÍøÂçÃû¡¢Óû§ÐÅÏ¢¡¢¼«¶È¹æ¶Ë¿ÚÉÏÊ¢¿ªµÄ·þÎñµÈ¡£
±ã½ÝµÄ·ì϶ÑéÖ¤¹¤¾ß¼¯
±¾²úÆ·Ìṩһ¼üʽ·ì϶ÑéÖ¤¹¤¾ß¼¯£¬Ô̺¬SQL×¢Èë·ì϶ÑéÖ¤¡¢ä¯ÀÀÆ÷·ì϶ÑéÖ¤¼°Í¨Ó÷ì϶ÑéÖ¤µÈ¡£ÔËάÈËÔ±Äܹ»Ö±½ÓÔÚϵͳ½çÃæµ±Ñ¡ÔñÏàÓ¦µÄºÍ̸²¢Ìî³ä²âÊÔ×ֶζÔÖ¸±ê½øÐзì϶ÑéÖ¤£¬²¢ÇÒÕë¶ÔϵͳÒÑ·¢Ïֵķì϶Äܹ»ÊµÏÖÒ»¼üÌî³äʽ×Ô¶¯ÑéÖ¤Ö°ÄÜ£¬½µµÍÈËΪ²Ù×÷ÄѶȵÄͬʱÌáÉýÁ˾ÖÑéÖ¤µÄÕýÈ·ÐÔ¡£
¶àÑù»¯µÄÁ˾ֱ¨±í³öÏÖ
±¾²úÆ·¿ÉÄÜÌìÉúÃæÏò¶à¸öÓû§½ÇÉ«µÄ¿Í»§»¯±¨±í£¬²¢ÒÔͼ¡¢±í¡¢ÎÄ×Ö×¢Ã÷µÈ¶àÖÖ´ó¾Ö½øÐÐչʾ£¬Í¬Ê±Ö§³ÖÒÔPDF¡¢XML¡¢HTML¡¢EXCEL¡¢WORDµÈ¶àÖÖÌåʽµ¼³öÁ˾ֱ¨±í¡£
| Ó²¼þ¹æ¸ñ | ||||
| ²úÆ·ÐͺŠ| RG-Scan | |||
| ǧÕ×µç¿Ú | 6¸ö | ǧÕ×¹â¿Ú | 4¸ö | |
| ÖÎÀí¿Ú | Console½Ó¿Ú£¨RJ45½Ó¿Ú״̬£© | À©´ó²Û | 2¸ö | |
| USB¿Ú | 2¸ö | »ú¼Ü³ß´ç | 1U | |
| ¹¤×÷ÎÂ¶È | 0¡æ¡«40¡æ | ¹¤×÷ʪ¶È | 5%¡«90% RH | |
| Ó²¼þÖʱ£ÆÚ | 3Äê | ÉÏÊй¦·ò | 2021Äê1Ô | |
| Èí¼þÖ°ÄÜ | ||||
| ²úÆ·ÐͺŠ| RG-Scan | |||
| ²úÆ·²¿Êð | Ö§³Ö¶à¸ö»ò¶à¼¶²úÆ·µÄͳһ¹Ü¿Ø | |||
| Ö§³ÖÕ½ÊõµÄͳһÔì¶©ºÍ·Ö·¢£¬Ìṩ¿É±à×ëµÄÕ½ÊõÄ£°å | ||||
| Ö§³Ö¶ÔÈ«ÍøÉ¨ÃèÁ˾ֵļ¯ÖвéÎÊ¡¢·ÖÎö | ||||
| ÍøÂçÖÎÀí | Ö§³ÖVLAN»®·Ö£¬Ö§³Ö¶àVLAN»·¾³ÏµIJ¿Êð | |||
| ×Ô½çËµÍøÂç½Ó¿ÚÊôÐÔ£¬½ç˵¸öÐÔ»¯ÐèÒª | ||||
| ¹¤×÷ÖÎÀí | Ö§³ÖÏÞ¶Å×û§ÏµÍ³É¨ÃèIPÁìÓò | |||
| Ö§³ÖÏÔʾɨÃèÔü×Ò¹¦·ò£¬ËæÊ±²é¿´É¨Ãè½ø¶ÈÁË¾Ö | ||||
| ϵͳ·ì϶ɨÃè | Ö§³Ö¼ø±ðÖ÷»úÐÅÏ¢¡¢Óû§ÐÅÏ¢¡¢·þÎñÐÅÏ¢¡¢·ì϶ÐÅÏ¢µÈÄÚÈÝ | |||
| Ö§³Ö¶ÔɨÃè¶ÔÏó´àÈõÐÔµÄÈ«Ãæ²é³£¬È簲ȫ²¹¶¡¡¢¿ÚÁî¡¢·þÎñÅäÖÃµÈ | ||||
| ·ì϶¿â¾ß±¸CVE¡¢CVSS¡¢CNVID¡¢CNNVD¡¢CNCVE¡¢Bugtraq±àºÅ | ||||
| Ö§³Ö¶¯Ì¬µÄÏÔʾɨÃèÁ˾ֺÍʵʱµÄ²é¿´É¨ÃèÁË¾Ö | ||||
| Ö§³ÖÔÚÏ߲鿴¶Ô±È·ÖÎöºÍÇ÷Ïò»ã±¨£»Ö§³Ö·ì϶Á˾ַ¢Ë͵½Ö¸¶¨FTP·þÎñÆ÷ | ||||
| Web·ì϶ɨÃè | Ö§³Ö±»É¨ÃèÍøÕ¾×éÖ¯¼Ü¹¹µÄʵʹعʾ | |||
| ·ì϶ɨÃèÖ§³ÖSQL×¢Èë¡¢Cookie×¢È롢äע¡¢¿çÕ¾¡¢ÎļþÔ̺¬µÈ·ì϶¼ì²âÄÜÁ¦ | ||||
| ÄÜÆ¾¾Ý·ÖÆçÖ¸±êÔì¶©·ÖÆçɨÃèÕ½ÊõµÄÄÜÁ¦ | ||||
| Êý¾Ý¿â·ì϶ɨÃè | Ö§³ÖÖ÷Á÷Êý¾Ý¿â·ì϶µÄ¼ì²â | |||
| Èõ¿ÚÁîɨÃè | Ö§³ÖĿǰ³ÛÃûµÄ¼ì²âºÍ̸£¬TELNET¡¢FTP¡¢SSH¡¢POP3¡¢SMB¡¢SNMP¡¢RDPµÈ | |||
| ±¨±íÄÜÁ¦ | »ã±¨ÓµÓÐÒ×¶®µÄ·ìϼûèÊöºÍÏ꾡µÄ°²È«½¨²¹¹æ»®½¨Òé | |||
| Äܹ»µ¼³ö·ÖÆçÌåʽµÄ±¨±í£¬ÈçWORD¡¢HTML¡¢Excel¡¢PDF¡¢XMLµÈ | ||||
| Éý¼¶¡¢ÖÎÀí | Ö§³Ö×Ô¶¯ºÍÈËΪԶ³ÌÉý¼¶£¬Éý¼¶ÄÚÈÝÔ̺¬×îеķì϶¿âºÍϵͳ×ÔÉíµÄ²¹¶¡·¨Ê½ | |||
| Ö§³ÖSSLµÄWeb½çÃæ¡¢SSH¡¢Console¶àÖÖ·½Ê½½øÐÐÖÎÀí | ||||
| Ö§³ÖPING¡¢WGETµÈ·½Ê½¶ÔÍøÂç½øÐÐÕï¶Ï | ||||