computer °æ (¾«»ªÇø)
·¢ÐÅÈË: Arg (8Сʱ¹¤×÷ÈÕ), ÐÅÇø: network
±ê Ìâ: ¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
·¢ÐÅÕ¾: ÌýÌÎÕ¾ (2001Äê08ÔÂ06ÈÕ23:27:55 ÐÇÆÚÒ»), Õ¾ÄÚÐżþ
·¢ÐÅÈË: seak (½º£¿Í-¼ÓÇ¿¼Æ»®ÐÔ£¬¿ª·¢ÎÞ²»Ê¤), ÐÅÇø: Security
±ê Ìâ: ¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
·¢ÐÅÕ¾: BBS ˮľÇ廪վ (Mon Aug 6 07:48:35 2001) WWW-POST
¹ØÓÚIISÈ䳿CodeRedµÄ½ô¼±ËµÃ÷
È䳿IIS-Worm.Bady£¬ÓÖÃû"Code Red"£¬¹úÄÚ·ÒëΪ
ºìÉ«´úÂ룬ÒѾÔÚ¹úÄÚ´ó¹æÄ£·ºÀÄ¡£
ǰÌ죬8ÔÂ4ÈÕ£¬ÏȺóÊÕµ½¶à¸öWebÕ¾µã¸ºÔðÈ˵ÄÇóÖú£¬
Ö¢×´¾ùΪIISÆô¶¯ºó²»¾Ã¾ÍÍ£µô¡£
×òÌìÍíÉÏ£¬ÓÉÓÚÕûÒ¹ÉÏÔØÒòÍòÍøÔâµ½´ó¹æÄ£¹¥»÷¶ø
±»ÆÆ»µµÄ²¡¶¾¹Û²ì£¬»úÆ÷¿ªÁËÒ»ÕûÒ¹£¬½á¹ûÎÒÃÇ×Ô¼ºµÄ
IDS½Ø»ñµ½ÁËÀ´×Ô¼¸Ê®¸öIPµÄ´óÁ¿GET/ default.ida?XX
ÇëÇ󡣿ɼû¸ÃÈ䳿ÒѾ ºÀijÉÔÖ¡
£ ¹ØÓÚ¸ÃÈ䳿µÄ¾ßÌå»úÀíÀ´²»¼°ËµÁË£¬ÉÔºòÇë¿´²¡¶¾
¹Û²ìvirusview.netµÄÒßÇéÏìÓ¦¡£
˵Ã÷£º
1¡¢¸ÃÈ䳿ÊÇÒ»¸öIIS£¨Microsoft Internet Infom
ation Server£©È䳿£¬Ö»¶Ô°²×°ÁËIISϵͳµÄ»úÆ÷ÓÐÍþв¡£
2¡¢Õâ¸öÈ䳿ÊÇͨ¹ýÒ»¸öÃûΪ"Unchecked Buffer in
Index Server ISAPI Extension" µÄ©¶´£¬Ôì³ÉIISÒç³ö
À´Ê¹×ÔÉí´«²¥µÄ¡£ÓйØÏêÇéÇå¼ûeeyeµÈ¹«Ë¾µÄ·ÖÎö±¨¸æ
£¨Õâ´ÎCode RedÀûÓõÄ©¶´¾ÍÊÇeeye·¢Ïֵģ©
3¡¢²¡¶¾¹Û²ì»áÂíÉϸø³öÒßÇéÏìӦרÌâ¡£
ÉÐδ¸ÐȾ´ËÈ䳿µÄÓû§¿ÉÒÔÈçÏ´¦Àí£¬
¹ÜÀí¹¤¾ßIIS¹ÜÀíÆ÷/Ö÷Ŀ¼£¨»îÒ³£©/ÅäÖ㨰´Å¥£©/
°ÑÓ¦ÓóÌÐòÓ³ÉäµÄ.idqɾ³ý¡£
»òÕß°Ñ%windowsdir%\system32ÖеÄidq.dll±¸·Ýºóɾ³ý¡£
Õâ¸öÎļþÊôÓÚindex serverµÄÒ»²¿·Ö£¬°²×°iisʱĬÈϰ²×°µÄ
Ò»°ãµÄWEB Ó¦Óò»»áÓõ½index service£¬ÓÈÆäÊǹúÄÚÓû§£¬Ê¹ÓÃ
Õâ¸öµÃ±È½ÏÉÙ£¬²»±Øµ£ÐÄ¡£¿ÉÄܺܶàÓû§Ëµ²»ÖªµÀindex service
ÊÇʲô£¬¼ÈÈ»²»ÖªµÀÊÇʲô¾Í¸ü²»»áÓõ½ÁË£¬ÊDz»ÊÇ£»-£©
΢ÈíÒѾÌṩÁ˹ٷ½²¹¶¡£¬ÔÚ´ËÒ³ÃæÖÐÏÂÔØ
http://www.microsoft.com/technet/security/bulletin/MS01-033.asp
ÍøÂç¼à¿Ø£º
Èç¹ûÓû§´óÁ¿ÊÕµ½ÀàËÆÈçϵÄHTTPÇëÇóӦΪÊÇCode RedÔÚ´«²¥¡£
GET /default.ida?{Ö®ºóÓÐ224¸öÏàͬµÄ×Öĸ}%u9090%u6858%ucbd3%u7801%u9090
%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003
%u8b00%u531b%u53ff%u0078%u0000%u00....
²ÉÓÃsnort¹æÔò¼æÈÝϵͳµÄIDSÓû§£¬¿ÉÒÔÌí¼ÓÈçϹæÔò£¬À´¼à¿Ø²¡¶¾µÄÇëÇó¡£
alert tcp !$HOME_NET any -> $HOME_NET 80 (msg:" Code Red- IIS-Unchecked
Buffer in Index Server ISAPI Extension";flags:PA; content:"/default.ida";
nocase;)
²Ý²Ýд³É£¬Èç¹ûÓÐÎÊÌ⣬ÇëÐ޸IJ¹³ä¡£
--
--
¡ù À´Ô´:¡¤ÌýÌÎÕ¾ tingtao.dhs.org¡¤[FROM: ÄäÃûÌìʹµÄ¼Ò]
Powered by KBS BBS 2.0 (http://dev.kcn.cn)
Ò³ÃæÖ´ÐÐʱ¼ä£º1.114ºÁÃë