LSASSº|¬}¤jªù¤j¶}

ª÷«Ó§Ö³t¸Ñ°£¶s¡A¹ý©³¸Ñ°£LSASSº|¬}°ÝÃD

±þ¤â¯f¬rªº¹õ«á³]­p¤Î´²§GªÌÁö¤w¸¨ºô¡A¦ý¤´¦³¨äÅܺئbºô¸ô¤W¬y«¡A¦Ó¥B¤wÅܺبì²Ä¤»¥N¡C¦Óªñ¤é¶Ç¥XBobax¯f¬r¤]¦P¼Ë§Q¥Î·L³nLSASSº|¬}¤J«I¡A¬Æ¦Ü¾É­PExplorer.exe¥i¯à¦]¦¹¦Ó·lÃa¡AÅý¤H¤£¸Tı±o¹q¸£¦w¥þ¬O§_¤w¸g«G°_¤F¬õ¿O¡C

ª÷«Ó¤uµ{®vªí¥Ü¡Aªñ¨Ó¤£Â_¶Ç¥Xº|¬}ÀbÂΡA¬O¦]¬°±þ¤â¯f¬rªºShell code¤w³Q¤½§G¦bÀb«Èºô¯¸¤W¡A«Ü¥i¯à·|³Q¦³¤ß¤H§Q¥Î­×§ï¶i¦æ¯f¬rÅܺءAShell code¦p¦P¸U¯àÆ_°Í¥ô¦ó¤H³£¥i¯à§Q¥Î³o§âÆ_°Í¨Ó­×§ï¦¨¦³¯}Ãa©Ê¦æ¬°ªº¯f¬r¡C

¬°¤F¦³®Ä¨¾¤îÃþ¦üº|¬}ÀbÂΪº¤J«I¡Aª÷«Ó«ØÄ³©Ò¦³¨Ï¥ÎWindows 2000, NT¥H¤W¨t²Îªº¥Î¤á¡A»°§Ö¨ì·L³n¤U¸ü§ó·s­×¸Éµ{¦¡(MS04-11)¡C¥t¥~¡Aª÷«Óºô¯¸´£¨Ñªº¡u§Ö³t¸Ñ°£¶s¡v¡A§K¶O¬°¨Ï¥ÎªÌ¶EÂ_¯f¬r¡C

§Ö³t¸Ñ°£¶sªº¥D­n¥\¯à: (¤@) ¥ß§YÀˬd±zªº¹q¸£¬O§_¤w¶i¦æ§ó·s¤Î¤Þ¾É±z­×¸Éº|¬}¡C(¤G) ­Y±zªº¹q¸£©|¥¼§ó·s¡A¤]±N·|À°±z§âº|¬}Âê°_¨Ó¡AÅýº|¬}µLªk±Ò°Ê¤Î¸Ñ¨M¹q¸£¤£Â_­«¶}¾÷ªº°ÝÃD¡C

ª÷«Ó¥þ²y¸ê°Tºô http://www.ggreat.com.tw/

    ·L³nLSASSº|¬}­×¸Éµ{¦¡¡G

*  http://www.microsoft.com/taiwan/security/bulletins/MS04-011.asp (¤¤¤å)

*  http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx (­^¤å)

±þ¤â¯f¬r²¤¶

¯f¬r¦WºÙ

Sasser.6

¯f¬r§O¦W

W32.Sasser.F.worm

¯f¬r«¬ºA

Worm, Hole

¯f¬rµo²{¤é´Á

2004/05/17

§Q¥Îº|¬}

MS04-011

¼vÅT¥­¥x

Windows 2000/NT/XP/2003


 Sasser ÀbÂΦ欰¡G

1.¦¹¯f¬r·|¥ý³z¹Lport 445ªºLSASSº|¬}¤J«I¡A¦A§Q¥ÎFTP¥h»·ºÝ¹q¸£¤U¶Ç¯f¬rÀɮרì¨t²Î¥Ø¿ý°õ¦æ¡C¦¹  ®É¯f¬r·|¦Û°Ê¬[³]¤@­ÓFTP server¦bport 5554¥HÅý§O¥x¹q¸£¥i¥H¤U¶Ç¯f¬r¥»Åé¡A¯f¬r¤å¥ó©ñ¸m©ó<ÀH¾÷_up.exe>Àɮפº¡A¨Ã¶}±Òport 9996·í«áªù¡AÅý»·ºÝ¹q¸£¥i¥H·n±±¡C

2.¯f¬r°õ¦æ«á¡A±NÀbÂÎ¥»¨­½Æ»s¨ì%Windir% napatch.exe

3.­×§ïµn¿ýÀÉ¡A¦p¦¹¶}¾÷§Y·|±Ò°ÊÀbÂΡC

4.·|¦bC¼Ñ¤U²£¥Íwin2.logÀɮסA¨Ã°O¿ý¤w·P¬Vªº¹q¸£IP¡C

5.·í¶}±Ò¹q¸£®É·|¦Û°Ê±Ò°Ê¯f¬r¡A³y¦¨¹q¸£lsass.exe¨t²Î¿ù»~¦Ó1¤ÀÄÁ«á­«·s¶}¾÷¡C

n ºô¯¸´£¨Ñ§K¶O±½¬r³nÅéhttp://www.y2000.com.tw/aews

n §K¶O²M°£©U§£«H¥óºô§}http://www.y2000.com.tw/mailscouter