LSASSº|¬}¤jªù¤j¶}
ª÷«Ó§Ö³t¸Ñ°£¶s¡A¹ý©³¸Ñ°£LSASSº|¬}°ÝÃD
±þ¤â¯f¬rªº¹õ«á³]p¤Î´²§GªÌÁö¤w¸¨ºô¡A¦ý¤´¦³¨äÅܺئbºô¸ô¤W¬y«¡A¦Ó¥B¤wÅܺبì²Ä¤»¥N¡C¦Óªñ¤é¶Ç¥XBobax¯f¬r¤]¦P¼Ë§Q¥Î·L³nLSASSº|¬}¤J«I¡A¬Æ¦Ü¾ÉPExplorer.exe¥i¯à¦]¦¹¦Ó·lÃa¡AÅý¤H¤£¸Tı±o¹q¸£¦w¥þ¬O§_¤w¸g«G°_¤F¬õ¿O¡C
ª÷«Ó¤uµ{®vªí¥Ü¡Aªñ¨Ó¤£Â_¶Ç¥Xº|¬}ÀbÂΡA¬O¦]¬°±þ¤â¯f¬rªºShell code¤w³Q¤½§G¦bÀb«Èºô¯¸¤W¡A«Ü¥i¯à·|³Q¦³¤ß¤H§Q¥Î×§ï¶i¦æ¯f¬rÅܺءAShell code¦p¦P¸U¯àÆ_°Í¥ô¦ó¤H³£¥i¯à§Q¥Î³o§âÆ_°Í¨Óק令¦³¯}Ãa©Ê¦æ¬°ªº¯f¬r¡C
¬°¤F¦³®Ä¨¾¤îÃþ¦üº|¬}ÀbÂΪº¤J«I¡Aª÷«Ó«ØÄ³©Ò¦³¨Ï¥ÎWindows 2000, NT¥H¤W¨t²Îªº¥Î¤á¡A»°§Ö¨ì·L³n¤U¸ü§ó·s׸ɵ{¦¡(MS04-11)¡C¥t¥~¡Aª÷«Óºô¯¸´£¨Ñªº¡u§Ö³t¸Ñ°£¶s¡v¡A§K¶O¬°¨Ï¥ÎªÌ¶EÂ_¯f¬r¡C
§Ö³t¸Ñ°£¶sªº¥Dn¥\¯à: (¤@) ¥ß§YÀˬd±zªº¹q¸£¬O§_¤w¶i¦æ§ó·s¤Î¤Þ¾É±z׸ɺ|¬}¡C(¤G) Y±zªº¹q¸£©|¥¼§ó·s¡A¤]±N·|À°±z§âº|¬}Âê°_¨Ó¡AÅýº|¬}µLªk±Ò°Ê¤Î¸Ñ¨M¹q¸£¤£Â_«¶}¾÷ªº°ÝÃD¡C
ª÷«Ó¥þ²y¸ê°Tºô http://www.ggreat.com.tw/
·L³nLSASSº|¬}׸ɵ{¦¡¡G
http://www.microsoft.com/taiwan/security/bulletins/MS04-011.asp
(¤¤¤å)
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
(^¤å)
±þ¤â¯f¬r²¤¶
|
¯f¬r¦WºÙ |
Sasser.6 |
|
¯f¬r§O¦W |
W32.Sasser.F.worm |
|
¯f¬r«¬ºA |
Worm, Hole |
|
¯f¬rµo²{¤é´Á |
2004/05/17 |
|
§Q¥Îº|¬} |
MS04-011 |
|
¼vÅT¥¥x |
Windows 2000/NT/XP/2003 |
Sasser ÀbÂΦ欰¡G
1.¦¹¯f¬r·|¥ý³z¹Lport 445ªºLSASSº|¬}¤J«I¡A¦A§Q¥ÎFTP¥h»·ºÝ¹q¸£¤U¶Ç¯f¬rÀɮרì¨t²Î¥Ø¿ý°õ¦æ¡C¦¹ ®É¯f¬r·|¦Û°Ê¬[³]¤@ÓFTP
server¦bport 5554¥HÅý§O¥x¹q¸£¥i¥H¤U¶Ç¯f¬r¥»Åé¡A¯f¬r¤å¥ó©ñ¸m©ó<ÀH¾÷_up.exe>Àɮפº¡A¨Ã¶}±Òport 9996·í«áªù¡AÅý»·ºÝ¹q¸£¥i¥H·n±±¡C
2.¯f¬r°õ¦æ«á¡A±NÀbÂÎ¥»¨½Æ»s¨ì%Windir% napatch.exe
3.×§ïµn¿ýÀÉ¡A¦p¦¹¶}¾÷§Y·|±Ò°ÊÀbÂΡC
4.·|¦bC¼Ñ¤U²£¥Íwin2.logÀɮסA¨Ã°O¿ý¤w·P¬Vªº¹q¸£IP¡C
5.·í¶}±Ò¹q¸£®É·|¦Û°Ê±Ò°Ê¯f¬r¡A³y¦¨¹q¸£lsass.exe¨t²Î¿ù»~¦Ó1¤ÀÄÁ«á«·s¶}¾÷¡C
n ºô¯¸´£¨Ñ§K¶O±½¬r³nÅéhttp://www.y2000.com.tw/aews
n §K¶O²M°£©U§£«H¥óºô§}http://www.y2000.com.tw/mailscouter