computer °æ (¾«»ªÇø)

·¢ÐÅÈË: Arg (8Сʱ¹¤×÷ÈÕ), ÐÅÇø: network
±ê  Ìâ: ¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
·¢ÐÅÕ¾: ÌýÌÎÕ¾ (2001Äê08ÔÂ06ÈÕ23:27:55 ÐÇÆÚÒ»), Õ¾ÄÚÐżþ

·¢ÐÅÈË: seak (½­º£¿Í-¼ÓÇ¿¼Æ»®ÐÔ£¬¿ª·¢ÎÞ²»Ê¤), ÐÅÇø: Security
±ê  Ìâ: ¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
·¢ÐÅÕ¾: BBS Ë®Ä¾Ç廪վ (Mon Aug  6 07:48:35 2001) WWW-POST

¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
    È䳿IIS-Worm.Bady£¬ÓÖÃû"Code Red"£¬¹úÄÚ·­ÒëΪ
ºìÉ«´úÂ룬ÒѾ­ÔÚ¹úÄÚ´ó¹æÄ£·ºÀÄ¡£
    Ç°Ì죬8ÔÂ4ÈÕ£¬ÏȺóÊÕµ½¶à¸öWebÕ¾µã¸ºÔðÈ˵ÄÇóÖú£¬
Ö¢×´¾ùΪIISÆô¶¯ºó²»¾Ã¾ÍÍ£µô¡£
    ×òÌìÍíÉÏ£¬ÓÉÓÚÕûÒ¹ÉÏÔØÒòÍòÍøÔâµ½´ó¹æÄ£¹¥»÷¶ø
±»ÆÆ»µµÄ²¡¶¾¹Û²ì£¬»úÆ÷¿ªÁËÒ»ÕûÒ¹£¬½á¹ûÎÒÃÇ×Ô¼ºµÄ
IDS½Ø»ñµ½ÁËÀ´×Ô¼¸Ê®¸öIPµÄ´óÁ¿GET/ default.ida?XX
ÇëÇ󡣿ɼû¸ÃÈ䳿ÒѾ­ ºÀijÉÔÖ¡
£    ¹ØÓÚ¸ÃÈ䳿µÄ¾ßÌå»úÀíÀ´²»¼°ËµÁË£¬ÉÔºòÇë¿´²¡¶¾
¹Û²ìvirusview.netµÄÒßÇéÏìÓ¦¡£

    ËµÃ÷£º
    1¡¢¸ÃÈ䳿ÊÇÒ»¸öIIS£¨Microsoft Internet Infom
ation Server£©È䳿£¬Ö»¶Ô°²×°ÁËIISϵͳµÄ»úÆ÷ÓÐÍþв¡£
    2¡¢Õâ¸öÈ䳿ÊÇͨ¹ýÒ»¸öÃûΪ"Unchecked Buffer in
Index Server ISAPI Extension" µÄ©¶´£¬Ôì³ÉIISÒç³ö
À´Ê¹×ÔÉí´«²¥µÄ¡£ÓйØÏêÇéÇå¼ûeeyeµÈ¹«Ë¾µÄ·ÖÎö±¨¸æ
£¨Õâ´ÎCode RedÀûÓõÄ©¶´¾ÍÊÇeeye·¢Ïֵģ©
   3¡¢²¡¶¾¹Û²ì»áÂíÉϸø³öÒßÇéÏìӦרÌâ¡£


    ÉÐδ¸ÐȾ´ËÈ䳿µÄÓû§¿ÉÒÔÈçÏ´¦Àí£¬

    ¹ÜÀí¹¤¾ßIIS¹ÜÀíÆ÷/Ö÷Ŀ¼£¨»îÒ³£©/ÅäÖ㨰´Å¥£©/
°ÑÓ¦ÓóÌÐòÓ³ÉäµÄ.idqɾ³ý¡£
    »òÕß°Ñ%windowsdir%\system32ÖеÄidq.dll±¸·Ýºóɾ³ý¡£
   Õâ¸öÎļþÊôÓÚindex serverµÄÒ»²¿·Ö£¬°²×°iisʱĬÈϰ²×°µÄ
Ò»°ãµÄWEB Ó¦Óò»»áÓõ½index service£¬ÓÈÆäÊǹúÄÚÓû§£¬Ê¹ÓÃ
Õâ¸öµÃ±È½ÏÉÙ£¬²»±Øµ£ÐÄ¡£¿ÉÄܺܶàÓû§Ëµ²»ÖªµÀindex service
 ÊÇʲô£¬¼ÈÈ»²»ÖªµÀÊÇʲô¾Í¸ü²»»áÓõ½ÁË£¬ÊDz»ÊÇ£»-£©

    Î¢ÈíÒѾ­ÌṩÁ˹ٷ½²¹¶¡£¬ÔÚ´ËÒ³ÃæÖÐÏÂÔØ
    http://www.microsoft.com/technet/security/bulletin/MS01-033.asp

ÍøÂç¼à¿Ø£º
Èç¹ûÓû§´óÁ¿ÊÕµ½ÀàËÆÈçϵÄHTTPÇëÇóӦΪÊÇCode RedÔÚ´«²¥¡£

GET /default.ida?{Ö®ºóÓÐ224¸öÏàͬµÄ×Öĸ}%u9090%u6858%ucbd3%u7801%u9090
  %u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003
  %u8b00%u531b%u53ff%u0078%u0000%u00....


²ÉÓÃsnort¹æÔò¼æÈÝϵͳµÄIDSÓû§£¬¿ÉÒÔÌí¼ÓÈçϹæÔò£¬À´¼à¿Ø²¡¶¾µÄÇëÇó¡£

alert tcp !$HOME_NET any -> $HOME_NET 80 (msg:" Code Red- IIS-Unchecked
Buffer in Index Server ISAPI Extension";flags:PA; content:"/default.ida";
nocase;)

²Ý²Ýд³É£¬Èç¹ûÓÐÎÊÌ⣬ÇëÐ޸IJ¹³ä¡£


--

--
¡ù À´Ô´:¡¤ÌýÌÎÕ¾ tingtao.dhs.org¡¤[FROM: ÄäÃûÌìʹµÄ¼Ò] 
[°Ù±¦Ïä] [·µ»ØÊ×Ò³] [Éϼ¶Ä¿Â¼] [¸ùĿ¼] [·µ»Ø¶¥²¿] [Ë¢ÐÂ] [·µ»Ø]
Powered by KBS BBS 2.0 (http://dev.kcn.cn)
Ò³ÃæÖ´ÐÐʱ¼ä£º0.854ºÁÃë