1. 执行摘要
56 / 100
18
严重
12
高危
5
中危
528
低危/信息
2. 测试范围与方法
| 项目 | 详情 |
|---|---|
| 固件版本 | 4.0.24 x64 Build202601131850 |
| 厂商 | iKuai |
| 样本文件 | iKuai8_x64_4.0.24_Build202601131850.bin |
| MD5 | 4fa9b7183ae1cc505295dc4ef5f5afbf |
| SHA-256 | 1bee8284ee70f633b8b88bd6bbbfc7a366f9b01f1700dac83b35171fa8b9fb63 |
| 文件大小 | 41.7MB |
| 扫描时间 | 2026-04-22 23:22:04 UTC |
| 工具 | Nyarc Professional v1.2.0 |
3. 发现总览
| # | 级别 | CVSS | 发现 |
|---|---|---|---|
| 1 | CRITICAL | 6.9 | 密码已破解:用户 'root' |
| 2 | CRITICAL | 5.3 | OpenSSL libcrypto.so.1.0.0 — 已停止维护 |
| 3 | CRITICAL | 7.5 | OpenSSL 1.0.0 — 已停止维护 |
| 4 | CRITICAL | 9.1 | 私钥泄露: /etc/remote2/ca-certificates.d/ikuai/client.key |
| 5 | CRITICAL | 9.1 | 私钥泄露: /etc/ssl/32015/ca.key |
| 6 | CRITICAL | 9.1 | 私钥泄露: /etc/ssl/32016/ca.key |
| 7 | CRITICAL | 9.1 | 私钥泄露: /etc/ssl/32017/ca.key |
| 8 | CRITICAL | 9.1 | 私钥泄露: /etc/swanctl/ikca/rootCA.key |
| 9 | CRITICAL | 9.1 | 私钥泄露: /usr/ikuai/ctrlclient/priv.key |
| 10 | CRITICAL | 9.1 | 私钥泄露: /usr/openresty/ssl/server.key |
| 11 | CRITICAL | 6.9 | 密码已破解:用户 'root' |
| 12 | CRITICAL | 9.1 | 云控客户端: 私钥与证书泄露 |
| 13 | CRITICAL | 6.1 | 控制客户端(备用): 私钥与证书泄露 |
| 14 | CRITICAL | 9.1 | 内嵌 CA: 私钥与证书泄露 |
| 15 | CRITICAL | 9.1 | 内嵌 CA: 私钥与证书泄露 |
| 16 | CRITICAL | 9.1 | 内嵌 CA: 私钥与证书泄露 |
| 17 | CRITICAL | 9.1 | Web 服务器: 私钥与证书泄露 |
| 18 | CRITICAL | 7.5 | OpenSSL 1.0.0 — 已停止维护 |
| 19 | HIGH | 5.3 | Generic backdoor detected (CVE-2023-50920): Lua random seed (check for predictable values) |
| 20 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 21 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 22 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 23 | HIGH | 5.3 | Generic backdoor detected (CVE-2023-50920): Lua random seed (check for predictable values) |
| 24 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 25 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 26 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 27 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 28 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 29 | HIGH | 7.5 | 远程控制配置文件暴露 |
| 30 | HIGH | 5.3 | Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object) |
| 31 | MEDIUM | 5.3 | 用户 'sshd' 使用 MD5crypt 弱哈希 |
| 32 | MEDIUM | 5.3 | 用户 'root' 使用 MD5crypt 弱哈希 |
| 33 | MEDIUM | 5.3 | 用户 'sshd' 使用 MD5crypt 弱哈希 |
| 34 | MEDIUM | 5.3 | Generic potential vulnerability: Telnet on non-standard port (potential backdoor) |
| 35 | MEDIUM | 5.3 | 用户 'root' 使用 MD5crypt 弱哈希 |
4. 详细发现
1. 密码已破解:用户 'root'CRITICAL (CVSS 6.9)
/etc/shadow: root cracked with common password dictionaryCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LID: NYARC-001
2. OpenSSL libcrypto.so.1.0.0 — 已停止维护CRITICAL (CVSS 5.3)
/usr/lib/libcrypto.so.1.0.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NID: NYARC-002
3. OpenSSL 1.0.0 — 已停止维护CRITICAL (CVSS 7.5)
/usr/lib/libssl.so.1.0.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HID: NYARC-003
4. 私钥泄露: /etc/remote2/ca-certificates.d/ikuai/client.keyCRITICAL (CVSS 9.1)
| Private Key: /etc/remote2/ca-certificates.d/ikuai/client.key | |
| Certificate: /etc/remote2/ca-certificates.d/ikuai/client.crt | |
| 主体 | C = CN, ST = beijing, O = ikuai, OU = ikclient, CN = *.ikuai8.com |
| 签发者 | C = CN, ST = beijing, L = bj, O = ikuai, OU = ik, CN = *.ikuai8.com |
| 生效时间 | Aug 22 09:52:29 2019 GMT |
| 过期时间 | Aug 19 09:52:29 2029 GMT |
| 序列号 | 02 |
| SHA1 指纹 | FB:07:C4:91:0E:A9:26:86:98:4D:EE:CB:33:A1:8C:B6:E1:F4:B3:2F |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-004
5. 私钥泄露: /etc/ssl/32015/ca.keyCRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32015/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32015/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 生效时间 | Aug 29 04:13:19 2017 GMT |
| 过期时间 | Dec 30 04:13:19 3016 GMT |
| 序列号 | BD9552A22264C655 |
| SHA1 指纹 | 68:7C:26:F4:B4:20:1B:C5:04:AD:31:58:0E:4F:C1:04:08:6C:39:B6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-005
6. 私钥泄露: /etc/ssl/32016/ca.keyCRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32016/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32016/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 生效时间 | Aug 29 02:15:37 2017 GMT |
| 过期时间 | Dec 30 02:15:37 3016 GMT |
| 序列号 | 92EDE68AEB529720 |
| SHA1 指纹 | B8:4C:CB:B7:53:F6:70:9E:B8:D8:20:DB:8A:34:49:BE:85:E8:30:F0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-006
7. 私钥泄露: /etc/ssl/32017/ca.keyCRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32017/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32017/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = 302.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = 302.ikuai8.com |
| 生效时间 | Sep 6 04:04:56 2017 GMT |
| 过期时间 | Jan 7 04:04:56 3017 GMT |
| 序列号 | E43325EF748B108B |
| SHA1 指纹 | EC:29:58:77:4B:E1:99:CC:DA:74:14:A2:B9:0B:D9:D7:EF:C9:D5:36 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-007
8. 私钥泄露: /etc/swanctl/ikca/rootCA.keyCRITICAL (CVSS 9.1)
| Private Key: /etc/swanctl/ikca/rootCA.key (4096-bit RSA) | |
| Certificate: /etc/swanctl/ikca/rootCA.crt | |
| 主体 | C = IK, ST = beijing, L = beijing, O = ikuai, OU = ikuai, CN = ikuaitest.com |
| 签发者 | C = IK, ST = beijing, L = beijing, O = ikuai, OU = ikuai, CN = ikuaitest.com |
| 生效时间 | Dec 27 01:59:58 2022 GMT |
| 过期时间 | Feb 25 01:59:58 2042 GMT |
| 序列号 | A1142FC16A202365 |
| SHA1 指纹 | A4:86:5B:9B:F1:6F:66:AF:01:B3:EE:9B:A4:90:90:56:60:DB:2A:7E |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-008
9. 私钥泄露: /usr/ikuai/ctrlclient/priv.keyCRITICAL (CVSS 9.1)
| Private Key: /usr/ikuai/ctrlclient/priv.key (4096-bit RSA) | |
| Certificate: /usr/ikuai/ctrlclient/cert.pem | |
| 主体 | C = CN, ST = BEIJING, O = IKUAI8 Ltd, OU = CERT 0001 OF CA REMOTE CONTROL 0002-01-0001 FOR IKUAI ROUTERS, CN = cert0001.rm_router0002-01-0001.ikuai8.com, emailAddress = [email protected] |
| 签发者 | C = CN, ST = BEIJING, O = IKUAI8 Ltd, OU = REMOTE CONTROL 0002-01 FOR ROUTERS, CN = remote_control.rt0002-01.ikuai8.com, emailAddress = [email protected] |
| 生效时间 | Dec 24 02:44:23 2015 GMT |
| 过期时间 | Dec 22 02:44:23 2021 GMT |
| 序列号 | 100000 |
| SHA1 指纹 | 9B:3C:A3:86:B7:65:80:CB:A8:B4:BA:77:8B:B8:53:B4:84:99:6A:2B |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-009
10. 私钥泄露: /usr/openresty/ssl/server.keyCRITICAL (CVSS 9.1)
| Private Key: /usr/openresty/ssl/server.key (2048-bit RSA) | |
| Certificate: /usr/openresty/ssl/server.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = ikuai8.com |
| 生效时间 | Apr 21 07:23:05 2021 GMT |
| 过期时间 | Aug 22 07:23:05 3020 GMT |
| 序列号 | DB6C3FFC850ABE5E |
| SHA1 指纹 | 45:EF:86:D9:14:1C:AC:5B:45:CB:02:FD:BB:95:5B:75:5E:01:A3:EE |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-010
11. 密码已破解:用户 'root'CRITICAL (CVSS 6.9)
/etc/shadow: root cracked with common password dictionaryCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:LID: NYARC-011
12. 云控客户端: 私钥与证书泄露CRITICAL (CVSS 9.1)
| Private Key: /etc/remote2/ca-certificates.d/ikuai/client.key | |
| Certificate: /etc/remote2/ca-certificates.d/ikuai/client.crt | |
| 主体 | C = CN, ST = beijing, O = ikuai, OU = ikclient, CN = *.ikuai8.com |
| 签发者 | C = CN, ST = beijing, L = bj, O = ikuai, OU = ik, CN = *.ikuai8.com |
| 生效时间 | Aug 22 09:52:29 2019 GMT |
| 过期时间 | Aug 19 09:52:29 2029 GMT |
| 序列号 | 02 |
| SHA1 指纹 | FB:07:C4:91:0E:A9:26:86:98:4D:EE:CB:33:A1:8C:B6:E1:F4:B3:2F |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-012
13. 控制客户端(备用): 私钥与证书泄露CRITICAL (CVSS 6.1)
| Private Key: /usr/ikuai/ctrlclient/priv.key (4096-bit RSA) | |
| Certificate: /usr/ikuai/ctrlclient/cert.pem | |
| 主体 | C = CN, ST = BEIJING, O = IKUAI8 Ltd, OU = CERT 0001 OF CA REMOTE CONTROL 0002-01-0001 FOR IKUAI ROUTERS, CN = cert0001.rm_router0002-01-0001.ikuai8.com, emailAddress = [email protected] |
| 签发者 | C = CN, ST = BEIJING, O = IKUAI8 Ltd, OU = REMOTE CONTROL 0002-01 FOR ROUTERS, CN = remote_control.rt0002-01.ikuai8.com, emailAddress = [email protected] |
| 生效时间 | Dec 24 02:44:23 2015 GMT |
| 过期时间 | Dec 22 02:44:23 2021 GMT |
| 序列号 | 100000 |
| SHA1 指纹 | 9B:3C:A3:86:B7:65:80:CB:A8:B4:BA:77:8B:B8:53:B4:84:99:6A:2B |
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-013
14. 内嵌 CA: 私钥与证书泄露CRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32015/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32015/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 生效时间 | Aug 29 04:13:19 2017 GMT |
| 过期时间 | Dec 30 04:13:19 3016 GMT |
| 序列号 | BD9552A22264C655 |
| SHA1 指纹 | 68:7C:26:F4:B4:20:1B:C5:04:AD:31:58:0E:4F:C1:04:08:6C:39:B6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-014
15. 内嵌 CA: 私钥与证书泄露CRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32016/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32016/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = download.ikuai8.com |
| 生效时间 | Aug 29 02:15:37 2017 GMT |
| 过期时间 | Dec 30 02:15:37 3016 GMT |
| 序列号 | 92EDE68AEB529720 |
| SHA1 指纹 | B8:4C:CB:B7:53:F6:70:9E:B8:D8:20:DB:8A:34:49:BE:85:E8:30:F0 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-015
16. 内嵌 CA: 私钥与证书泄露CRITICAL (CVSS 9.1)
| Private Key: /etc/ssl/32017/ca.key (1024-bit RSA) | |
| Certificate: /etc/ssl/32017/ca.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = 302.ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = 302.ikuai8.com |
| 生效时间 | Sep 6 04:04:56 2017 GMT |
| 过期时间 | Jan 7 04:04:56 3017 GMT |
| 序列号 | E43325EF748B108B |
| SHA1 指纹 | EC:29:58:77:4B:E1:99:CC:DA:74:14:A2:B9:0B:D9:D7:EF:C9:D5:36 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-016
17. Web 服务器: 私钥与证书泄露CRITICAL (CVSS 9.1)
| Private Key: /usr/openresty/ssl/server.key (2048-bit RSA) | |
| Certificate: /usr/openresty/ssl/server.crt | |
| 主体 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = ikuai8.com |
| 签发者 | C = CN, ST = BeiJing, L = BeiJing, O = iKuai, OU = iKuai, CN = ikuai8.com |
| 生效时间 | Apr 21 07:23:05 2021 GMT |
| 过期时间 | Aug 22 07:23:05 3020 GMT |
| 序列号 | DB6C3FFC850ABE5E |
| SHA1 指纹 | 45:EF:86:D9:14:1C:AC:5B:45:CB:02:FD:BB:95:5B:75:5E:01:A3:EE |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NID: NYARC-017
18. OpenSSL 1.0.0 — 已停止维护CRITICAL (CVSS 7.5)
/usr/lib/libssl.so.1.0.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HID: NYARC-018
19. Generic backdoor detected (CVE-2023-50920): Lua random seed (check for predictable values)HIGH (CVSS 5.3)
/usr/sbin/ikntpgetCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/ikntpgetID: NYARC-019
20. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/miniupnpdCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/miniupnpdID: NYARC-020
21. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/pmdCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/pmdID: NYARC-021
22. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/tkgenCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/tkgenID: NYARC-022
23. Generic backdoor detected (CVE-2023-50920): Lua random seed (check for predictable values)HIGH (CVSS 5.3)
/usr/ikuai/script/ik_netoptimize.luaCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/ikuai/script/ik_netoptimize.luaID: NYARC-023
24. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/lib/libjansson.soCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/lib/libjansson.soID: NYARC-024
25. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/lib/libjansson.so.4CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/lib/libjansson.so.4ID: NYARC-025
26. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/lib/libjansson.so.4.13.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/lib/libjansson.so.4.13.0ID: NYARC-026
27. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/creCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/creID: NYARC-027
28. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/ik_rc_clientCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/ik_rc_clientID: NYARC-028
29. 远程控制配置文件暴露HIGH (CVSS 7.5)
etc/remote2/ikuai.conf
{
"as_server":{
"host":["as-v4.ikuai8.com:9444"],
"ca_path":"/etc/remote2/ca-certificates.d/ikuai"
}
}CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NID: NYARC-029
30. Generic backdoor detected: JSON parser library (sscanf overflow CVE in parse_object)HIGH (CVSS 5.3)
/usr/sbin/ik_stats_collectCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/usr/sbin/ik_stats_collectID: NYARC-030
31. 用户 'sshd' 使用 MD5crypt 弱哈希MEDIUM (CVSS 5.3)
/etc/shadow: sshd:$1$BKY7uz3G$vw5dPaPb...CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NID: NYARC-031
32. 用户 'root' 使用 MD5crypt 弱哈希MEDIUM (CVSS 5.3)
/etc/shadow: root:$1$9.EU8ItY$z4EfK4vQ...CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NID: NYARC-032
33. 用户 'sshd' 使用 MD5crypt 弱哈希MEDIUM (CVSS 5.3)
/etc/shadow: sshd:$1$BKY7uz3G$vw5dPaPb...CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NID: NYARC-033
34. Generic potential vulnerability: Telnet on non-standard port (potential backdoor)MEDIUM (CVSS 5.3)
/sbin/sysinitCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/sbin/sysinitID: NYARC-034
35. 用户 'root' 使用 MD5crypt 弱哈希MEDIUM (CVSS 5.3)
/etc/shadow: root:$1$9.EU8ItY$z4EfK4vQ...CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NID: NYARC-035
5. 外连通信分析
| 域名 | 分类 | 引用 |
|---|---|---|
yun.ikuai8.com | 🟡 cloud | 15 files
|
dingtalk.c.app | 🟡 system | 2 files
|
dis-v4.ikuai8.com | 🟡 system | 2 files
|
routers.ikuai8.com | 🟡 system | 2 files
|
api.cloudflare.com | 🟡 api | 2 files
|
ftp.info-zip.org | 🟡 system | 2 files
|
restapi.amap.com | 🟡 system | |
as1.ikuai8.com | 🟡 system | |
time4.aliyun.com | 🟡 system | |
schemas.microsoft.com | 🟡 system | |
pkgmgr-v4.ikuai8.com | 🟡 system | |
time1.aliyun.com | 🟡 system | |
patch.ikuai8.com | 🟡 system | |
time5.aliyun.com | 🟡 system | |
api.weibo.com | 🟡 api | |
cloud.ikuai8.com | 🟡 cloud | |
2015.ikuai8.com | 🟡 system | |
ntp3.ikuai8.com | 🟡 system | |
stedolan.github.com | 🟡 system | |
audit.ikuai8.com | 🟡 telemetry | |
time3.aliyun.com | 🟡 system | |
ntp2.aliyun.com | 🟡 system | |
as2.ikuai8.com | 🟡 system | |
time2.aliyun.com | 🟡 system | |
ntp2.ikuai8.com | 🟡 system | |
update.ikuai8.com | 🟡 update | |
ntp1.ikuai8.com | 🟡 system | |
rsync.samba.org | 🟡 system | |
software.es.net | 🟡 system | |
listi.jpberlin.de | 🟡 system | |
6. 加固建议
建议:审查所有外连通信,更换默认凭据,升级过时的加密库。