Detect and fix risks

Updated at:

The Agentless Detection feature supports security risk assessment of cloud servers without installing the Security Center agent. The feature scans server disk snapshots or images, and combines AI sandbox dynamic analysis to perform multi-dimensional security detection such as vulnerabilities, malware, configuration baselines, and sensitive files in an isolated environment. It also supports AI vulnerability fixing. This process has almost no impact on server performance.

Scope

  • Supported asset types:

    • Chinese Mainland region: You can scan Alibaba Cloud Elastic Compute Service (ECS) instances, cloud disk snapshots, or custom images, along with AWS EC2 instances.

    • Outside Chinese Mainland regions: You can scan Alibaba Cloud ECS instances, cloud disk snapshots, and custom images, along with AWS EC2 instances and Azure virtual machines.

  • Supported regions for Alibaba Cloud servers:

    • China (Qingdao), China (Beijing), China (Zhangjiakou)

    • China (Hangzhou) and China (Shanghai)

    • China (Shenzhen)

    • China (Chengdu)

    • China (Hong Kong), Singapore, US (Virginia), Indonesia (Jakarta)

  • Operating system compatibility: For a detailed list of operating systems that support vulnerability scanning, see Supported operating systems for vulnerability scanning.

    Note

    FreeBSD operating systems do not support baseline checks, malicious sample detection, or sensitive file detection.

  • Supported vulnerability fix types: Only the application vulnerability type can be fixed. For the detailed list of supported vulnerabilities, see Vulnerability fix support list.

    Note

    The vulnerability fixing capability is continuously evolving. For the most accurate information, refer to the console.

Connect detection assets

Alibaba Cloud assets

Agentless Detection automatically synchronizes assets under the current Alibaba Cloud account. No manual operation is required.

Multicloud assets

Connect to Amazon Web Services (AWS) or Azure for Agentless Detection:

Connect to AWS

  1. Prepare AWS access credentials

    In your AWS account, create an IAM user with programmatic access and obtain the Access Key ID and Secret Access Key. This user needs permissions to access and create EC2 snapshots.

    Important

    To use the Agentless DetectionAgentless Detection feature, create a custom IAM policy in your AWS account with the permissions described in Create a custom policy for Agentless Detection.

  2. Configure the connection method

    1. Go to the Agentless DetectionAgentless Detection page. On the Server Check tab, in the Add Multi-cloud Asset section, click Add below the image icon.

    2. On the Add Assets Outside Cloud page, complete the configuration on the Create Sub-account page as described below and click Next.

      • Solution Selection: Manual Configuration.

      • Permission Description: Select Agentless DetectionAgentless Detection.

  3. Submit credential information

    On the Submit AccessKey Pair tab, accurately enter the credentials that you created in AWS and click Next.

    • Sub-account SecretID and Sub-account SecretKey: Enter the AWS sub-account API key information that you obtained in Step 1.

    • Connection Region: Select an available region. The system uses the selected region to verify asset accessibility and retrieve corresponding cloud resource data.

    • Domain: Configure this parameter based on the selected connection region. For AWS China regions, select China. For all other regions, select International.

  4. Configure policy

    On the Policy Configuration tab, complete the configuration as described below.

    • Select region: Select the AWS region where the assets you want to onboard are located.

      Note

      Asset data is automatically attributed to the data center corresponding to the region selected in the upper-left corner of the Security Center console.

      • Chinese Mainland: Chinese mainland data center.

      • Outside Chinese Mainland: Singapore data center.

    • Region Management: Recommended. After selected, assets in new regions under this AWS account will be automatically synchronized without manual configuration.

    • AK Service Status Check: Set the interval for Security Center to automatically check the validity of the AWS account API key. You can select "Off" to disable detection.

  5. Click OK.

    After completing permission verification and policy configuration, create Agentless Detection tasks for your AWS EC2 instances.

Connect to Azure

  1. Prepare Azure access credentials

    In the Azure portal, create an app registration and grant it subscription-level access permissions. Obtain the following credentials: Application (client) ID, Directory (tenant) ID, and the client secret Value.

    Important

    To use the Agentless DetectionAgentless Detection feature, grant the Reader and Disk Snapshot Contributor roles to Security Center in your Azure account. For specific operations, see Add Azure assets.

  2. Configure the connection method

    1. In the upper-left corner of the console, select the Outside Chinese Mainland region.

    2. Go to the Agentless DetectionAgentless Detection page. On the Server Check tab, in the Add Multi-cloud Asset section, click Add below the image icon.

    3. Go to the Add Assets Outside Cloud page. In the Create Sub-account step, select Agentless DetectionAgentless Detection in the Permission Description section and click Next.

  3. Submit credential information

    In the Submit AccessKey Pair tab, accurately enter the credentials that you created in Azure, and then click Next.

    • Enter an AppID: The Application (client) ID that you obtain from your Azure application registration.

    • Enter a password: The client secret value obtained from your Azure app registration.

    • Tenant ID: The Directory (tenant) ID from your Azure application registration.

    • Domain (Select Chinese Edition for China and International Edition for others): For 21Vianet users, select the Chinese Edition.

  4. Configure policy

    On the Policy Configuration tab, complete the configuration by referring to the following instructions.

    • Select region: Select the regions where the Azure assets to be onboarded are located.

      Note

      Asset data is automatically stored in the data center corresponding to the region selected in the upper-left corner of the Security Center console.

      • Chinese Mainland: Data center in Chinese Mainland.

      • Outside Chinese Mainland: Data center in Singapore (Singapore).

    • Region Management: We recommend that you select this option. After you select this option, assets in new regions added to this Azure account in the future will be automatically synchronized without manual configuration.

    • AK Service Status Check: Set the interval for Security Center to automatically check the validity of the Azure account credentials. You can select Off to disable the check.

  5. After completing permission verification and policy configuration, create Agentless Detection tasks for your Azure virtual machines.

Create and run detection tasks

Configure detection whitelists (optional)

  1. On the Agentless DetectionAgentless Detection page, click Scan Configuration, and then click the Manage Whitelist tab.

  2. Based on the risk type, click Create Rule on the corresponding tab.

  3. Configure the whitelist rule as described below.

    Important

    The following whitelist configurations apply to all assets.

    Vulnerability whitelist

    • Vulnerability Type: Only Linux Software Vulnerability, Windows System Vulnerability, and Application Vulnerability are supported.

    • Vulnerability Name: The latest vulnerability data is retrieved based on the selected Vulnerability Type.

    Malicious sample whitelist

    • Alert Name: The default value is ALL, which means that the whitelist rule applies to all alert types. This value cannot be changed.

    • Allowlist Field: The default value is fileMd5, which means that files are whitelisted by MD5 hash. This value cannot be changed.

    • Wildcard Character: Only Equal is supported.

    • Rule Content: Enter the MD5 hash of the file.

    Baseline whitelist

    • Check Item Type: Specify the type of baseline check items to exclude from detection.

    • Check Item: Specific check items are retrieved based on the selected Check Item Type.

    Sensitive file whitelist

    • Check Item for Sensitive Files: Specify the items to exclude from detection.

    • Configure Whitelist Conditions:

      Note

      You can configure multiple rules. The rules have an AND relationship. A file is added to the whitelist only if it meets all rule conditions.

      • MD5: For the wildcard, only Equal is supported. Then, enter the MD5 hash of the file.

      • Path: For the wildcard, Contains, Prefix, and Suffix are supported. Then, enter the path.

Create a detection task

Agentless Detection supports two task types: on-demand and scheduled.

Immediate detection task

Use these tasks for one-time security scans of specific assets.

Host security scan

  1. On the Agentless Detection > Server Check tab, in the Risk Detection section, click Scan Now.

  2. In the Scan Now panel, configure the settings as described below, and then click OK.

    • Scan Scope: We recommend that you select the data disks. More complete data sources improve the detection of vulnerabilities, alerts, and other risks.

    • Snapshot/Image Storage Time:

      • Valid values: 1 to 365. Unit: days.

      • You are charged for creating snapshots or images. The longer you retain the snapshots or images, the higher the fees.

        Important

        If you select Retain Only At-risk Snapshots or Images, the system automatically deletes risk-free snapshots or images after the scan is complete.

  3. After you create the task, Security Center automatically creates snapshots or images and runs the scan. If risks are detected after the scan, the system also automatically triggers parallel sandbox analysis. For more information, see Automatic creation of snapshots and images and Automatically run AI parallel sandbox analysis. For information about how to view task progress and reports, see View task progress and reports.

    Note

    The more server data that is scanned, the longer the task takes. Wait for the task to complete.

Snapshot security scan

Important

To use snapshots for detection, first enable the snapshot feature. For more information, see Enable snapshots.

  1. On the Agentless Detection > Snapshot-based Check tab, in the Risk Detection section, click Scan Now.

  2. In the Scan Now panel, select the target snapshot, and then click OK.

Custom image security scan

  1. On the Agentless Detection > Custom Image Check tab, in the Risk Detection section, click Scan Now.

  2. In the Scan Now panel, select the target image, and then click OK.

    Note

    If the image that you want to scan does not appear in the detection task panel, go to the Asset Center > Cloud Service page and click Synchronize Assets. After synchronization is complete, repeat this step.

Scheduled detection tasks

Use scheduled tasks to run regular, automated security inspections of asset groups.

  1. Go to the configuration page

    In the upper-right corner of the Agentless DetectionAgentless Detection page, click Scan Configuration.

  2. Configure the detection scope

    On the Security Check Scope tab, configure the settings as described below, and then click Save.

    • Baseline Check Scope: Click Manage to go to the Baseline Check Configuration page, where you can view and configure the supported baseline check scope.

    • Sensitive File: Click Manage to go to the Sensitive File Scan Settings page, where you can view and configure check items.

      Important

      If you select Default Scan for New Check Items, the system automatically scans new check items when they are added.

  3. Configure the detection policy

    On the Automatic Detection Policy tab, configure the settings as described below, and then click Save.

    • Check Host: Configure the assets to scan as described below. For information about the other settings, see Host security scan.

      1. Configure Scan Cycle:

        • Set how often the detection task runs, such as daily or weekly.

        • If you select Do Not Scan, the Check Host task is paused.

        • After you configure the schedule, the system starts running scan tasks the next day.

      2. Configure Scan Assets:

        1. In the Scan Assets section, click Management.

        2. Default Scan for New Assets: We recommend that you select this option. The system then automatically includes newly added servers in the next scan cycle without requiring you to add them manually.

        3. Adjust the detection scope: In the asset list, select or clear specific servers as needed to configure the asset scope of the detection task.

    • Snapshot-based Check/Custom Image Check: If you turn on Incremental Check, the system automatically runs incremental scans on snapshots or custom images that have not been scanned.

      Important

      Incremental detection requires Data Delivery of ActionTrail. On the Feature Settings > Settings > Other Configurations tab, turn on Data Delivery of ActionTrail. For more information, see the authorization configuration instructions.

Automatic creation of snapshots and images

When you execute a Server Check task, the system uses the service-linked role AliyunServiceRoleForSas to perform the following automated operations:

  1. Create a snapshot or image: The system automatically creates a temporary server snapshot with a name that starts with SAS_Agentless.

  2. Share securely: The system shares the snapshot or image with the official Security Center service account for scanning and analysis.

  3. Automatic cleanup: After the scan is complete and the Snapshot/Image Storage Time expires, the snapshot or image is automatically deleted and sharing is canceled.

    Note
    • The snapshot or image is used only for security scanning, and no fees are incurred for sharing.

    • In Event Query in the ActionTrail console, you can view a record of AliyunServiceRoleForSas creating a snapshot or image.

  4. View snapshots: On the Cloud Disk Snapshots page in the ECS console, you can view the temporary snapshots automatically created by Security Center. The snapshot name starts with SAS_Agentless, its Status is Available, its Retention Period is 7 days, and its upload progress to OSS is 100%.

Automatically run AI parallel sandbox analysis

After a detection task is complete, the system automatically creates a parallel sandbox analysis task. You can view the task progress and download analysis reports in Task Management. For specific operations, see View task progress and reports.

  • Trigger conditions: The following conditions must be met at the same time.

    • The host security detection, snapshot security detection, or custom image security detection task is complete.

    • Risks such as vulnerabilities, baselines, and sensitive files exist in the detection results.

  • Trigger method: Parallel sandbox analysis is automatically triggered by the system and cannot be manually executed.

View task progress and reports

  1. In the upper-right corner of the Agentless DetectionAgentless Detection page, click Task Management.

  2. In the pop-up Task Management panel, select the tab based on the detection type.

    Server Check/Snapshot-based Check/Custom Image Check
    1. View status and progress: In the list on the corresponding tab, view the task Status and Progress.

    2. View and download reports:

      • Download the report for an entire task: In the Actions column of the target task, click Download Report.

      • Download the report for a single server:

        • In the Actions column of the target task, click Details or View.

        • In the Task Details panel, click Download Report in the Actions column.

    Parallel Sandbox Analysis
    1. View status and progress: In the list on the Parallel Sandbox Analysis tab, view the task Status and Progress.

    2. View and download reports:

      1. In the Actions column of the target task, click Details.

      2. On the Task Details page, click Download Report in the asset Actions column.

Analyze and handle risks

After a task is successfully completed, you can view and handle the detected security risks on the Agentless Detection page.

Important

If the same server is scanned multiple times, only the most recent scan results are displayed. Older results are overwritten.

  1. View risk details

    On the Agentless DetectionAgentless Detection page, go to the tab for the detection policy, such as Server Check, and then go to the tab for the risk type, such as Vul Risk. In the list, find the risk item and click View or Details in the Actions column to view its details.

  2. Handle risk alerts

    Note

    Whitelist rules that you create when analyzing and handling risks are also automatically synchronized to the detection whitelist, where you can modify, delete, or otherwise manage them.

    Vulnerability risks

    1. Procedure:

      1. Add to Whitelist: Locate the vulnerability that you want to handle and click Add to Whitelist in the Actions column.

      2. Fix vulnerabilities:

        1. Create a fix task:

          1. On the Application Vulnerability tab, locate the vulnerability that you want to fix and click Fix in the Actions column.

          2. In the Affected Asset section of the vulnerability Details tab, click Fix in the Actions column of the target asset. To fix the vulnerability on multiple assets at a time, select the assets and click Fix below the list.

          3. On the vulnerability fix confirmation page, confirm the Asset Information and Fixed Custom Image Name.

          4. Bulk Fix other vulnerabilities (optional): If the custom images have other fixable vulnerabilities, select the vulnerabilities to fix them together with the current vulnerability in the same task. The fixes are included in the new image that corresponds to each custom image.

          5. After you confirm that the information is correct, click Fix Now.

        2. View and download fix results:

          1. View results and progress:

            1. Return to the Agentless DetectionAgentless Detection homepage and click Task Management in the upper-right corner.

            2. On the Fix Task tab, view the fix Status and Progress.

          2. View and download the report

            1. If the fix succeeds, click Details in the task Actions column.

            2. On the Task Details page, click View Fix Report in the asset Actions column.

            3. On the report page, click the download icon in the upper-right corner.

    2. Handling instructions:

      1. Add to whitelist:

        • After you add a vulnerability to the whitelist, alerts are no longer generated for the vulnerability. Proceed with caution.

        • After you add a vulnerability to the whitelist, the system automatically synchronizes it to the Scan Configuration > Manage Whitelist > Vulnerability Whitelist tab. You can view the added entry on that tab.

      2. Fix vulnerabilities:

        1. Only some vulnerabilities can be fixed.

        2. Vulnerability fixing is billed separately, and no fee is incurred if you do not use it. The price is CNY 10 per vulnerability. For more information, see the vulnerability fixing billing documentation.

    Baseline checks

    • Procedure: In the check item list, locate the check item that you want to handle and click Add to Whitelist in the Actions column.

    • Handling instructions: Add to whitelist.

      • After you add a check item to the whitelist, newly added servers are no longer scanned for that item. Proceed with caution.

      • After you add a check item to the whitelist, the system automatically synchronizes it to the Scan Configuration > Manage Whitelist > Baseline Whitelist tab. You can view the added entry on that tab.

    Malicious samples

    • Procedure:

      • Handle new alerts: Set the handling status in the filter to Unhandled, and then click Handle in the Actions column of the target alert.

      • Review or revise archived alerts: Set the handling status in the filter to Handled, and then click Change Status in the Actions column of the target alert.

    • Handling instructions:

      • Add to Whitelist: If you confirm that an alert does not involve malicious behavior, you can add it to the whitelist based on the whitelist rule and application scope.

        Important
        • If you add an alert to the whitelist, future occurrences of the same alert are automatically moved to the handled list and no notifications are sent. Proceed with caution.

        • You can handle identical alerts in batches. The supported handling methods vary by alert type. Refer to the console for the available methods.

        • After you add an alert to the whitelist, the system automatically synchronizes it to the Scan Configuration > Manage Whitelist > Malicious Sample Whitelist tab. You can view the added entry on that tab.

      • Manually Handled: After you manually resolve the risk that caused the alert, mark the alert as Manually Handled.

      • Mark as False Positive: Mark the current alert as a false positive. Security Center uses your feedback to continuously improve its scanning capabilities.

      • Ignore: Ignore only the current alert. If a subsequent scan matches the detection policy, another alert is generated.

    Sensitive files

    • Procedure:

      1. In the sensitive file alert list, locate the alert that you want to handle and click Details in the Actions column to view the detailed description and hardening recommendations.

      2. In the operation column of the risk list on the details panel, click Handle. In the dialog box, select a method to handle the alert and click OK.

    • Handling instructions:

      • Add to Whitelist: If you confirm that an alert does not involve malicious behavior, you can add it to the whitelist based on the whitelist rules. The following rules apply:

        Important
        • If you add an alert to the whitelist, future occurrences of the same alert are automatically moved to the handled list and no notifications are sent. Proceed with caution.

        • You can configure multiple rules. All rules are combined by using the AND operator. An alert is added to the whitelist only if all rule conditions are met.

        • After you add an alert to the whitelist, the system automatically synchronizes it to the Scan Configuration > Manage Whitelist > Sensitive File Whitelist tab. You can view the added entry on that tab.

        • MD5: The wildcard condition supports only Equals. Enter the MD5 hash of the file.

        • Path: The wildcard condition supports Contains, Starts With, and Ends With. Enter the specific path.

      • Manually Handled: After you manually resolve the risk that caused the alert, mark the alert as Manually Handled.

      • Mark as False Positive: Mark the current alert as a false positive. Security Center uses your feedback to continuously improve its scanning capabilities.

      • Ignore: Ignore only the current alert. If a subsequent scan matches the detection policy, another alert is generated.

Troubleshoot failed tasks

If a task has an abnormal status, you can view the failure reason on the Task Details page and refer to the following table for solutions.

Failure message

Cause of failure

Solution

The current region is not supported

The specified region is not supported.

Confirm that the region of the ECS instance is supported. For more information, see Scope.

Failed to connect to the disk

A temporary error occurred when the system was mounting the snapshot disk.

In the Actions column of the task, click Retry.

Failed to create the image

The number of ECS images has reached the quota limit.

Increase the image quota in the ECS console or delete old images that are no longer in use.

Task processing timed out

The scan volume was too large or the system was busy, causing a timeout.

Split the task into multiple subtasks based on the scan scope, and then run them again.

Performance impact and cost control

  • Performance impact: The Agentless Detection scanning process does not consume resources of the target server.

  • Cost control: Agentless Detection fees consist of "scanning + AI sandbox analysis" fees and snapshot/image storage fees. If you use AI vulnerability repair, an additional repair fee is charged based on the number of successful repairs. To effectively control costs, we recommend the following configurations:

    • When you create a task and configure the Snapshot/Image Storage Time setting, select Retain Only At-risk Snapshots or Images.

    • Regularly clean up snapshots that are no longer needed.

Quotas and limits

  • Disk specifications: A single cloud disk supports a maximum of 1 TiB. A maximum of 20,000,000 files can be scanned on a single disk. Any files beyond this limit will not be scanned.

  • Server limits: Each server supports scanning a maximum of 15 cloud disks. Any disks beyond this limit will not be scanned.

  • Result retention: Detection results are retained for 30 days and automatically cleared upon expiration. For multiple scans of the same asset, only the most recent results are retained.

  • Compressed file limits: Only JAR files are supported. Only the first layer is decompressed for scanning.

  • File system limits: ext2, ext3, ext4, XFS, and NTFS are supported. For NTFS, check items that rely on file permission information are not supported.

  • Storage and disk limits: For all hosts (Alibaba Cloud and non-Alibaba Cloud), scanning data disks that use LVM (Logical Volume Manager), RAID arrays, or the ReFS file system is not supported.

Appendix

Detailed detection capabilities

The following table lists the main detection items supported by Agentless Detection.

Detection Category

Detection Scope

Details

Vulnerabilities

Linux software vulnerabilities, Windows system vulnerabilities, application vulnerabilities

For supported operating system versions, see Supported operating systems for vulnerability scanning.

Baseline Check

Configuration compliance for operating systems, applications, and databases

Supports scanning hundreds of configuration items, including but not limited to:

  • Classified protection compliance

  • De facto standards such as CIS

  • Password policy checks

  • Access control

  • Log auditing

For more information, go to the Scan Configuration page in the console. For details about the operations, see Baseline Check Scope.

Malicious Sample

Malicious scripts, webshells, malware

  • Malicious scripts: Shell, Python, Perl, etc.

  • Webshells: PHP, JSP, ASP, ASPX, etc.

  • Malware: Mining programs, Trojans, worms, DDoS botnet programs, etc.

See Malicious samples.

Sensitive File

Credential information, key files, configuration files

Supports detection of common sensitive files, including but not limited to:

  • Plaintext passwords in application configurations

  • Certificate and key files (.key, .pem)

  • Authentication/login credentials

  • Cloud provider credentials (AccessKeys)

For more information, go to Scan Configuration in the console. For specific steps, see sensitive file check item.

Supported operating systems for vulnerability scanning

Operating System Type

Version

Windows Server

  • Windows Server 2008 (vulnerabilities before EOL)

  • Windows Server 2012 (vulnerabilities before EOL)

  • Windows Server 2016

  • Windows Server 2019

  • Windows Server 2022

Red Hat

  • Red Hat 5 (vulnerabilities before EOL)

  • Red Hat 6 (vulnerabilities before EOL)

  • Red Hat 7

CentOS

  • CentOS 5 (vulnerabilities before EOL)

  • CentOS 6 (vulnerabilities before EOL)

  • CentOS 7

Ubuntu

  • Ubuntu 12.04 (vulnerabilities before EOL)

  • Ubuntu 14.04 (vulnerabilities before EOL)

  • Ubuntu 16.04 (vulnerabilities before EOL)

  • Ubuntu 18.04 (vulnerabilities before EOL)

  • Ubuntu 18.10 (vulnerabilities before EOL)

Debian

  • Debian 6

  • Debian 7

  • Debian 8

  • Debian 9

  • Debian 10

Alpine

  • Alpine 2.3

  • Alpine 2.4

  • Alpine 2.5

  • Alpine 2.6

  • Alpine 2.7

  • Alpine 3.1

  • Alpine 3.2

  • Alpine 3.3

  • Alpine 3.4

  • Alpine 3.5

  • Alpine 3.6

  • Alpine 3.7

  • Alpine 3.8

  • Alpine 3.9

  • Alpine 3.10

  • Alpine 3.11

  • Alpine 3.12

Amazon Linux

  • Amazon Linux 2

  • Amazon Linux AMI

Oracle Linux

  • Oracle Linux 5

  • Oracle Linux 6

  • Oracle Linux 7

  • Oracle Linux 8

SUSE Linux Enterprise Server

  • SUSE Linux Enterprise Server 5

  • SUSE Linux Enterprise Server 6

  • SUSE Linux Enterprise Server 7

  • SUSE Linux Enterprise Server 8

  • SUSE Linux Enterprise Server 9

  • SUSE Linux Enterprise Server 10

  • SUSE Linux Enterprise Server 10 SP4

  • SUSE Linux Enterprise Server 11 SP3

  • SUSE Linux Enterprise Server 12 SP2

  • SUSE Linux Enterprise Server 12 SP5

Fedora Linux

  • Fedora Linux 2X

  • Fedora Linux 3X

openSUSE

  • openSUSE 10.0 (vulnerabilities before EOL)

  • openSUSE Leap 15.2 (vulnerabilities before EOL)

  • openSUSE Leap 42.3 (vulnerabilities before EOL)

Malicious samples

Malicious sample category

Description

Supported detection items

Malicious scripts

Detects whether system functions on an asset have been attacked or tampered with by malicious scripts and displays possible malicious script attacks in the detection results.

Malicious scripts are classified as file-based or fileless scripts. After attackers obtain permissions on a server, they use scripts as vehicles for further attacks. For example, attackers may implant mining programs, add system backdoors, or add system accounts.

Supported languages include Shell, Python, Perl, PowerShell, VBScript, and BAT.

WebShell

Checks whether web script files on an asset are malicious or provide backdoor communication or management capabilities. After implanting a WebShell, an attacker can control the server and use the WebShell as a backdoor for further attacks.

Supported languages include PHP, JSP, ASP, and ASPX.

Malware

Checks whether binary files on an asset are malicious and can damage the asset or maintain persistent control. After implanting a malicious binary file, an attacker can control the server to mine cryptocurrency, launch DDoS attacks, or encrypt asset files. Based on function, malicious binaries mainly include mining programs, Trojans, backdoor programs, hacker tools, ransomware, and worms.

Compromised basic software

Suspicious program

Spyware

Trojan program

File-infecting virus

Worm

Exploit program

Metamorphic Trojan

Hacker tool

DDoS Trojan

Reverse shell backdoor

Malicious program

Rootkit

Downloader Trojan

Scanner

Riskware

Proxy tool

Ransomware

Backdoor program

Mining program

Vulnerability fix support list

Vulnerability ID

Description

CVE-2018-1257

In the spring-messaging module of Spring Framework, when WebSocket endpoints are exposed through an in-memory STOMP broker, attackers can craft messages to cause a regular expression denial of service (ReDoS) attack.

CVE-2019-12415

In Apache POI 4.1.0 and earlier versions, the XSSFExportToXml tool can process a malicious Excel document to read local files or intranet resources through XML external entity (XXE) injection when converting user-provided Excel documents.

CVE-2019-14439

FasterXML jackson-databind 2.x (versions earlier than 2.9.9.2) has a polymorphic deserialization vulnerability when Default Typing is enabled and logback is present in the classpath.

CVE-2020-26259

XStream versions earlier than 1.4.15 have an arbitrary file deletion vulnerability during deserialization. Remote attackers may delete arbitrary known files on the host.

CVE-2020-26945

MyBatis versions earlier than 3.5.6 mishandle object stream deserialization.

CVE-2020-5398

In Spring WebFlux, when filenames are set based on user input in the Content-Disposition response header, a reflected file download (RFD) attack risk exists.

CVE-2020-5398

In Spring WebMVC, when filenames are set based on user input in the Content-Disposition response header, a reflected file download (RFD) attack risk exists.

CVE-2021-20190

jackson-databind versions earlier than 2.9.10.7 mishandle serialization gadgets and types, which may compromise data confidentiality, integrity, and availability.

CVE-2021-44228

Apache Log4j2 2.0-beta9 to 2.15.0 does not protect against attacker-controlled LDAP and other endpoints through the JNDI feature, allowing remote code execution (Log4Shell).

CVE-2022-25845

FastJSON versions earlier than 1.2.83 can bypass the autoType disable limit under specific conditions, leading to deserialization of untrusted data and allowing attacks on remote servers.

CVE-2023-20860

Spring Framework 6.0.0-6.0.6 or 5.3.0-5.3.25, when the ** pattern is used with mvcRequestMatcher in Spring Security configurations, may cause pattern matching inconsistencies and security bypasses.

CVE-2023-23638

Apache Dubbo has a deserialization vulnerability during generic invoke, which can lead to execution of malicious code. Affected versions include Dubbo 2.7.21 and earlier, 3.0.13 and earlier, and 3.1.5 and earlier.

CVE-2023-24998

Apache Commons FileUpload versions earlier than 1.5 do not limit the number of request parts processed, allowing attackers to trigger a denial of service through malicious uploads.

CVE-2023-25194

The Apache Kafka Connect API has a security vulnerability. An attacker with access to a Kafka Connect worker and the ability to create or modify connectors can achieve arbitrary code execution by configuring a JNDI login module.

CVE-2023-29017

vm2 sandbox versions earlier than 3.9.15 mishandle host objects in Error.prepareStackTrace when asynchronous errors are not handled, leading to sandbox escape and remote code execution.

CVE-2023-30547

vm2 sandbox versions 3.9.16 and earlier have an exception sanitization bypass in handleException(). Attackers can exploit unsanitized host exceptions to escape the sandbox and execute arbitrary code.

CVE-2023-32314

vm2 sandbox versions 3.9.17 and earlier have a sandbox escape vulnerability based on the Proxy specification that unexpectedly creates host objects, allowing remote code execution.

CVE-2023-37466

In vm2 versions 3.9.19 and earlier, Promise handler sanitization can be bypassed through the @@species accessor, allowing attackers to escape the sandbox and execute arbitrary code. The project is no longer maintained.

CVE-2023-43804

urllib3 may leak cookies to different origins when processing HTTP redirects if the Cookie header is explicitly set by the user.

CVE-2023-47248

PyArrow 0.14.0 to 14.0.0 has an untrusted data deserialization vulnerability in the IPC and Parquet readers, which can lead to arbitrary code execution.

CVE-2024-22243

Spring Web UriComponentsBuilder may have open redirect or SSRF attack risks when parsing externally provided URLs and validating the host.

CVE-2024-22257

Spring Security AuthenticatedVoter#vote may cause access control failures when a null Authentication parameter is passed.

CVE-2024-22259

Spring Web UriComponentsBuilder may have open redirect or SSRF attack risks when parsing externally provided URLs and validating the host (a variant of CVE-2024-22243).

CVE-2024-31141

The ConfigProvider plugin of the Apache Kafka client can be exploited by untrusted parties to read disk files or environment variables, which may lead to privilege escalation.

CVE-2024-38809

Spring Web applications may suffer a denial of service attack when parsing ETags in the If-Match or If-None-Match request headers.

CVE-2024-38816

The Spring WebMVC functional web framework has a path traversal attack risk when serving static resources through RouterFunctions using FileSystemResource.

CVE-2024-38819

The Spring WebFlux functional web framework has a path traversal attack risk when serving static resources, allowing attackers to obtain arbitrary files in the file system.

CVE-2024-38819

The Spring WebMVC functional web framework has a path traversal attack risk when serving static resources, allowing attackers to obtain arbitrary files in the file system.