Site hosted by Angelfire.com: Build your free website today!
³Ì·s®ø®§ ­º­¶ | ½Ð»P§Ú­ÌÁpµ¸

³Ì·s®ø®§
²£«~
±`¨£°ÝÃD
­n¨DªA°È
«Øij
¥Ø¿ý / ¨Ï¥Î¤â¥U
¤ä´©½×¾Â
¥Î¤á¨Ï¥Î±ø´Ú

¦¹ºô­¶Åã¥Ü§Ú­Ìªº«È¤áªA°È¤ä´©ºô¯¸ªº³Ì·sÅܧó¡A¤]·|©ñ¸m¦³Ãö²£«~§ó·s¡B¹w©wµo°âªº·s°Ó«~¡A©Î¥i¯à·|¼vÅT©Ò¦³«È¤áªº°ÝÃD¤Î·N¨£ªº¤½§i¡C­×´_«È¤á©Ò¦^³øªº·åÏÝ«á¡A§Ú­Ì·|¦b³oùؤ½§i¡A¨Ãªþ¤W°e¥X­×´_µ{¦¡ªº¦ô­p®É¶¡¡C

³Ì·s®ø®§

¡@

  • 11 ¤ë 13 ¤é¬P´Á¥|

    • ½Ðª`·N¥D¾÷«áªººô¥dºñ¿O,­Y¨S¦b¤Wºô¦Ó¦Û¦æ°{Ã{,¤Wºô³t«×©úÅãÅܺC,ªí¥Ü§Aªº¹q¸£¤w¤¤¬r,½Ð¸Ñ¬r,­Y¦³¼vÅT¾ãÅéªÀ°Ï³s½u³t«×,±N¼È°±´£¨Ñ¨ä¤WºôªºªA°È,¦Ü¹q¸£¥¿±`¤~»P¶}©ñ

      ¯e­·¯f¬r(MS.Blaster.worm)¦A¥X²{ÅܺØ

      ½Ð°È¥²°µ¦n¤U¦C¨Æ¶µ,¥H§K¨t²Î¦º·í»Ý­«Äé¨t²Î



      ºK­n¡G

      ¤é«e¾î±½¥þ²y¤§¡u¯e­·¯f¬r¡v(MS.Blaster.worm)¤S¦A¥X²{ÅܺءA®£±N¼vÅT¹q¸£®Ä¯à¡A
      ©Î³y¦¨ºô¸ô¾Ã¶ëµLªk¨Ï¥Î¡A½Ð¾¨³t§ó·sMicrosoft­×¸Éµ{¦¡¡C

      ¦¹ÅܺدfÂÎ¥D­n°õ¦æ¤U¦C¨Æ¶µ¡G

      1.§R°£MSBLAST.exe¯f¬r
      2.§PÂ_¨ü·P¬Vªº¥D¾÷ª©¥»¡A¨Ã¤U¸ü¾A·íªºMicrosfot DCOM RPC­×¸Éµ{¦¡
      3.¦w¸Ë­×¸Éµ{¦¡¨Ã­«·s¶}¾÷
      4.Ä~Äò·P¬Vºô¸ô¤W¨ä¥¦¥¼¦w¸Ëpatchªº¥D¾÷(§Q¥ÎDCOM RPC¤ÎWebDavº|¬})
      5.§PÂ_¨t²Î®É¶¡¡A¦pªG®É¶¡¬°2004¦~¡A¦¹¯f¬r±N¦Û°Ê±N¦Û¤w²¾°£¡C

      ¦¹Åܺتº§ðÀ»¼Ò¦¡§Q¥ÎMicrosoft RPCº|¬}(port 135)¤ÎMicrosoft WebDavº|¬}(port 80)¶i¦æ´²¼½¡A­ì¥»ªº¯f¬r©w¸qÀɵLªk°»´ú¨ìÅܺدf¬r¡A½ÐºÉ³t­×¸ÉMicrosoft RPC¡BMicrosoft WebDavº|¬}¤Î§ó·s¯f¬r©w¸qÀÉ¡C


      ¼vÅT¨t²Î¡G

      Microsoft Windows 2000
      Microsoft Windows XP


      ¨M¸Ñ¤èªk¡G

      ¦¹¯f¬r¬O§Q¥ÎMicrosoft MS03-026¤ÎMicrosoft MS03-007º|¬}¶i¦æ·P¬V¡B´²¼½¡C
      ½ÐºÉ³t¤U¸ü¦w¸Ë­×¸Éµ{¦¡

      ½Ð°Ñ¾\:
      http://www.microsoft.com/taiwan/security/bulletins/MS03-026.asp
      http://www.microsoft.com/taiwan/security/bulletins/MS03-007.asp


      ¦pªG±zªº¹q¸£¨ü¨ì¦¹Ä¯ÂηP¬V¡A¥i¥H¨Ì¤U¦C¤è¦¡¸Ñ¨M¡C

      ¡@

      I. ¦Û°Ê²M°£¨BÆJ¡G

      1.½Ð¤U¸üÁͶէK¶O±½¬r³nÅé¡G
      http://www.trendmicro.com/ftp/products/tsc/sysclean.com

      2.¤U¸üÁͶճ̷s¯f¬r½X:
      http://a928.g.akamai.net/f/928/485/10m/www.trend.com.tw/support/downloads/pattern/LPT$616.exe

      3.¥H·Æ¹«ÂI¨â¤ULPT$616.exeÀÉ¡A±N¦Û°Ê¸ÑÀ£ÁY¦¨LPT$VPN.616
      4.±NLPT$VPN.616¤Îsysclean.com©ñ¦b¦P¤@­Ó¥Ø¿ý¤U¡C
      5.°õ¦æsysclean.comµ{¦¡±½´y±zªº¨t²Î¡C


      II. ¤â°Ê²M°£¨BÆJ¡G

      A. ¨ú®ø´c·Nµ{¦¡ªºªA°È :

      ³o­Ó°Ê§@¥i¥H±NWindows NT,2000©MXP¤W¥¿¦b°õ¦æªº´c·Nµ{¦¡ªA°È±q°O¾ÐÅ餤²¾°£.

      A.1   ÂI¿ï¶}©l>°õ¦æ, ¿é¤JCMD¨Ã«öEnter¶i¤J©R¥O´£¥Ü¦r¤¸.
      A.2  ©ó©R¥O´£¥Ü¦r¤¸¤º¿é¤J¤U¦C«ü¥O:
              NET STOP "Network Connections Sharing"
      A.3  «ö¤UEnterÁä,·|¸õ¥X¤@­Ó°T®§¤è¶ô»¡©ú¦¹¦¨¥\°±¤î¸ÓªA°È.
      A.4  ­«½Æ¤W­z°Ê§@°±¤î¤U­zªA°È:
              NET STOP "WINS Client"
      A.5  Ãö³¬©R¥O´£¥Ü¦r¤¸µøµ¡.


      B. ²¾°£´c·Nµ{¦¡ªºªA°È:

      B.1  ­«·s±Ò°Ê¹q¸£¥H«KÃö³¬´c·Nµ{¦¡ªºªA°È.
      B.2  ÂI¿ï¶}©l>°õ¦æ,¿é¤JREGEDIT¨Ã«öEnter¶i¤Jµn¿ý½s¿èµ{¦¡.
      B.3  ©ó¥ªÃäµøµ¡¤¤·Æ¹«ÂùÀ»¤U­z¸ô®|:
             HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet>Services>
      B.4  ©ó¥ªÃäµøµ¡¤¤,§R°£¸Ó¸ô®|¤Uªº¨â­Ó¤lµn¿ý­È:
              RpcPatch,RpcTftpd
      B.5  Ãö³¬µn¿ý½s¿èµ{¦¡.


      C. ²¾°£¯f¬rÀÉ

      C.1 ½Ð¶}±ÒÀÉ®×Á`ºÞ¡A¨Ã§R°£¤U¦CÀÉ®×:
      C:\Winnt\System32\Wins\Dllhost.exe
      C:\Winnt\System32\Wins\Svchost.exe

      ½Ðª`·N:¬O²¾°£"C:\Winnt\System32\Wins"¤UªºSvchost.exe


      D. ¦w¸Ë­×¸Éµ{¦¡:
      ½Ð°Ñ¾\
      http://www.microsoft.com/taiwan/security/bulletins/MS03-026.asp
      http://www.microsoft.com/taiwan/security/bulletins/MS03-007.asp


      °Ñ¦Òºô¯¸¡G
      ÁɪùÅK§J(­^¤å):
      http://securityresponse.symantec.com/avcenter/venc/data/w32.welchia.worm.html

      ÁͶլì§Þ(¤¤¤å):
      http://www.trendmicro.com/vinfo/zh-tw/virusencyclo/default5.asp?VName=WORM_MSBLAST.D

      ¡@©Î±z¤]¥i¤Wºô¦Ühttp://www.hinet.net ¨t²Î¤½§i¬d¸ß

      ¡@
    • µo§Gªº§Þ³Nª`·N¨Æ¶µ #1
¦^¨ì­¶­º
  • 11 ¤ë 13 ¤é¬P´Á¥|

    • ³¡¤ÀªÀ°Ïºô¸ô¥Î¤á¤ÏÀ³¡A¤Wºô³t«×ÅܺC¡D¸g¬dµo²{¦³¨ÇªÀ°Ïºô¸ô¥Î¤á¨Ï¥Î¤F¤À¨É³nÅé¡AÄY­«¦Y±¼ÀW¼e©Ò­P¡D
      ­Y±z¦³¨Ï¥ÎeDonkey ( eMule ), Ezpeer, Kuro..µ¥¤À¨É³nÅé¤U¸üMP3©Î³nÅé¡A½Ð°È¥²­n±N¤À¨É¸ê®Æ§¨Ãö³¬ !! §_«h³y¦¨¬y¶q¶W¸ü¥»¤½¥q±NÂê¦í¸Ó¥Î¤á¤§IP¡A¥HºûÅ@¨ä¥L¥Î¤á¤WºôªºÅv§Q¡D
      ¦]¦¹Àµ½Ð±z¦b¨Ï¥Î³oÃþ³nÅ骺¦P®É¡A°È¥²±N¤À¨Éªº¸ê®Æ§¨Ãö³¬¡A¥»¤½¥q±N·|ÀH®ÉºÊ±±­ÓªÀ°Ï¤§ºô¸ô¬y¶q!
      ¡@

      ¡@

    • ¥i±q FTP ¤U¸ü¤å¥ó (¤Jªù¤Îª©¥»ª`·N¨Æ¶µ)
¦^¨ì­¶­º

11 ¤ë 14 ¤é ¬P´Á¤­

  • ¤ä´©ºô¯¸¤W½u
  • ½Ð¥Î¤á©ó11¤ë25¤é«eú¯Ç92¦~12¤ë¥÷¤Î93¦~1¤ë¥÷¤§¨t²Î¶O¥Î¡A½Ð°È¥²©ó25¤é«eú¯Ç¥H§Q¤½¥q®ø±b§@·~¡Aú´Ú«á¬ù1¬P´Á¤º§Y¥i®ø±b¡A¤£¨Ì³W©wú´Ú¤§¥Î¤á¶·°µÂê¥d­­¨î¤Wºô¡AÁÂÁ°t¦X¡I ú¯Ç±¡§Î¥i°Ñ¦Ò  ¥Î¤áú´Ú¬d¸ß

¡@

­º­¶³]©w«ö¶sÅܦǦâ¡AµLªk³]©w!¦ó¸Ñ?

  • ³Ìªñ«Ü¦h¥Î¤á¤Wºô³£¹J¨ì¹L³o­Ó°ÝÃD...­º­¶«ç»ò§ï´N¬O¨S¿ìªk§ï...
    ³o¬O¦]¬°µn¿ý¡]registry¡^¤¤ªº ¡uNoBrowserOptions¡v³Q³]©w±Ò°Ê¡A¦]¦¹¥²¶·­×§ïµn¿ý¡A±N¥¿½Tªº­È­×§ï¦^¨Ó¡C
    ³Q¦p¦¹§ó§ïªº §Ú­Ìµø¬°"­º­¶¸j¬[" (¤@¨Çºô¸ô¼s§i¦æ¬°)  

  • ¦^µª

    ¦]¬°µn¿ý¡]registry¡^¤¤ªº ¡uNoBrowserOptions¡v³Q³]©w±Ò°Ê¡A¦]¦¹­×§ïµn¿ý¡A±N¥¿½Tªº­È­×§ï¦^¨Ó¡C

«ö¡u¶}©l¡v¡A¨ì¡u°õ¦æ¡v¡A¿é¤J regedit «á«ö½T©w¡C¡]µù¤@¡^

¨ì¡G

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictions

±N ¡uNoBrowserOptions¡v§R°£¡A©Î±N¨ä­È³]¦¨ 0¡]DWORD­È¬° 0¬OÃö³¬¡A1¬O±Ò°Ê¡^¡A«ö¶s¥¯àÀ³¸Ó¥i«ì´_¡C

­Y§R°£©Î­×§ï¤§«á¡A¤´µMµLªk¶}±Ò internet ¿ï¶µ¡A½Ð´M§ä¡]°õ¦æµn¿ý½s¿èµ{¦¡ regedit ¡A¨ì¥¯àªí¤Wªº½s¿è>>´M§ä¡A¿é¤J NobrowserOptions ¥h§ä¡^

·j´M¨ä¥L¦ì¸m¤W¬O§_¦³NoBrowserOptions¡A±N©Ò¦³³£§R°£¡Aµ²§ô regedit.exe¡C

¨ì¡u±±¨î¥x¡v>>¡uInternet¿ï¶µ¡v¡A´ú¸Õ«ö¶s¡G¡u¨Ï¥Î¥Ø«eªº³]©w¡v¡B¡u¨Ï¥Î¹w³]ªºµe­±¡v¡B¡u¨Ï¥ÎªÅ¥Õ­¶¡v¬O§_¥¿±`¡C

¶}±Ò IE¡A¨ì¡u¤u¨ã¡v>>¡uInternet ¿ï¶µ¡v¡A´ú¸Õ«ö¶s¡G¡u¨Ï¥Î¥Ø«eªº³]©w¡v¡B¡u¨Ï¥Î¹w³]ªºµe­±¡v¡B¡u¨Ï¥ÎªÅ¥Õ­¶¡v¬O§_¥¿±`¡C

­Y¤´µM¬O¦Ç¦â¡A¦A¸ÕµÛ§ä¬O§_¦³¥H¤U¾÷½X¡G¡]³o¤@¬q¤£¤@©w·|¦³¡A¦pªG§A§ä¤£¨ì¡Aªí¥Ü¨S¦³³Q­×¹L¡A´N¤£¥²°µ¥H¤Uªº´ú¸Õ¡^°õ¦æ Regedit¡A¨ì¡G

HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerControl Panel

¦b "HomePage" ¤W«ö¨â¤U¡A±N¨ä­È§ï¦¨ 0¡A­«·s¶}¾÷´ú¸Õ¡C¡]©Î±N HomePage §R°£¡^¡}µù¤G¡~

¬Y¨Ç´c¦Hªººô¯¸¡}¦â±¡²á¤Ñºô¯¸¡B¼s§iºô¯¸©~¦h¡~¡A·|¾Õ¦Û­×§ï¨Ï¥ÎªÌªº ie ³]©w¡A Internet ¿ï¶µµL½tµL¬Gªº¤£¯à¨Ï¥Î¡A¦h¥b¬O³oÃþºô¯¸³y¦¨ªº¡AŪªÌ¦b¤Wºô®É½Ð¦h¯d·N¡C

¥t¥~¡A¦pªG§A»{¬°¤£´¿¤W¹L³oÃþªº¦â±¡¡B¼s§iºô¯¸¡A²ö¦W¨ä§®ªº Internet ¿ï¶µ´N¤£¯à¥Î¤F¡A½Ð¯d·N¬O§_¦³¯f¬r¡A¬O§_¬°¯f¬rµ{¦¡­×§ï¤F§Aªº³]©w¡C

´XÂI«Øij¡G

¤£ºÞ¬O§A¤w¸g¹J¤W¡B©ÎÁÙ¨S¹J¨ì³oÃþ³]©w³Q´c·N­×§ïªºÅªªÌ¡A§Ú¦³¥H¤Uªº«Øij¡G

¤@¡B«ØijÀH®É§ó·s¨¾¬r³nÅ骺¯f¬r½X¡C

¦]¬°¡A¬Y¨Çºô¯¸¦b´c·N¦ê§ï©Î´Ó¤Jµ{¦¡¨ì§A¹q¸£ªº®É­Ô¡A¨Ò¦p³z¹L ActiveX ©Î¬O¤@¨Ç¤£Ãh¦n·Nªº Script µ{¦¡­×§ï§A³]©w®É¡A¨¾¬r³nÅé³£¦³¾÷·|°»´ú±o¨ì¡AÁöµM¤£¯à«OÃÒ100%ÄdºI¡A¦ý¬O¦Ü¤Ö¥i¥H¦h¤@¼h«OÀI¡C

¤G¡B¸g±`¨ì·L³nªº Windows Update ¡}windowsupdate.microsoft.com¡~ºô¯¸¤W¥h¬d¬Ý¡A¯d·N¬O§_¦³·sªºÃö©ó¦w¥þ©Ê¤è­±ªº­×¥¿µ{¦¡¡C

¤@¨Ç´c·Nªºµ{¦¡¡A¦h¥b¬O§Q¥Î IE ¦b¦w¥þ¤Wªºº|¬}©Î¯Ê¥¢¡A¹F¨ì¥¦·t¤¤­×§ï§Aªº¨t²Îªº¥Øªº¡A©Ò¥H¡A§Y¨Ï§A¥»¨­¨S¦³¬[³]ºô¯¸¡A¥u¬O¤@¦ì´¶³q USER¡A¤´­n¯d·N¦w¥þ©Êªº°ÝÃD¡A¤£­n¦³­Ë·°ªº¨Æ±¡¤£·|µo¥Í¦b§A¨­¤Wªº³oºØ·Qªk¡C

¦b¡uWindows Update¡vºô¯¸¤W¡A¦³¤@­Ó¡u­«¤j§ó·s¡vªº³æ¤¸¡A¶i¥h¬Ý¤@¤U¡A¦pªG¥¦Àˬd¥X§Aªº¨t²Î¬O¦³»Ý­n§ó·sªº¤¸¥ó¡A§Ú«Øij§A¤U¸ü§ó·s¡AÁקK§Aªº¹q¸£¦bµL·N¤¤³Q¤H¶}¡u«áªù¡v¡C

¡@

µù¤@¡G

¦pªG§A¤£ª¾¹D¦p¦ó¨Ï¥Î Regedit.exe ¡}µn¿ý½s¿èµ{¦¡¡~¡A¥i¥Hª½±µ¤U¸ü³o­Ó reg ÀɮסAµM«á¶×¤J§Y¥i¡G

¤U¸ü¡Gunlock_ie_options.reg

±N³o­Ó reg Àɮ׶פJ§Y¥i¡}¤U¸ü«áª½±µ double-click¡~¡A­n¶×¤J¤§«e¡A½Ð±N©Ò¦³ªº ie µøµ¡Ãö³¬¡C¦pªG¦¹³BµLªk¤U¸ü¡A½Ð¨ì¥H¤Uºô§}´M§ä§A»Ý­nªº reg ÀɮפU¸ü¡C

http://tw.groups.yahoo.com/group/binbindigest/files/Reg/

¥H¤U¬O unlock_ie_options.reg ³o­ÓÀɮתº¤º®e¡A´£¨Ñµ¹¤F¸Ñµn¿ýÀɪºÅªªÌ°µ°Ñ¦Ò¡G

REGEDIT4

[HKEY_CURRENT_USERSoftwarePoliciesMicrosoftInternet ExplorerRestrictions]
"NoBrowserOptions"=dword:00000000

¡@

µù¤G¡G

¨Æ¹ê¤W¡A¦b HKEY_CURRENT_USERSoftwarePoliciesMicrosoft ¤§¤U¡A¤@¯ë±¡ªp¤U¬O¨S¦³ Internet Explorer »P¨ä¥H¤Uªº³¡¤À¡A³o§¹¥þ¬OÃB¥~ªº³]©w¡AÃB¥~¹ï IE ©Ò°µªº­­¨î³]©w¡A´«¨¥¤§¡AInternet Explorer ¸ê®Æ§¨¤¤ªºªF¦è¡}¥]§t¨ä¥»¨­¡~¡A³£¬O¥i¥H§R°£ªº¡A§R±¼ Internet Explorer ¾÷½X¡A´N¥i¥H¸Ñ°£©Ò¦³¹ï IE ªº­­¨î¡C

­Y­n§R°£¡A«h¦b Internet Explorer ¾÷½X¤W«ö¥kÁä¡A¿ï§R°£§Y¥i¡C

¡@

¦^¨ì­¶­º

¡@


­º­¶ | ³Ì·s®ø®§ | ²£«~ | ±`¨£°ÝÃD | ­n¨DªA°È | «Øij | ¥Ø¿ý / ¨Ï¥Î¤â¥U | ¤ä´©½×¾Â | ¥Î¤á¨Ï¥Î±ø´Ú

»P¦¹ Web ¦³Ãöªº°ÝÃDÀ³ª½±µ°e¦Ü tecvi.humlee@msa.hinet.net
Copyright(C) 2002 tecvi All rights reserved.
¤W¦¸§ó·s¤é´Á¡G 2003?12?05?¡C