历史图片暂不可用 字号:大 中 小
网页浏览不再安全12月9日,微软ie7爆发“0day”漏洞,正常浏览网页也会中毒,互联网用户面临极度安全威胁。
12月13日,微软发布安全公告,此次漏洞在微软其他版本的IE浏览器上也存在。
中毒现象:IE假死、游戏帐号被盗、QQ帐号被盗
波及范围:所有基于IE的浏览器和应用程序。如Maxthon、QQ、迅雷、MSN等。
微软IE 0day漏洞介绍:
“0Day漏洞”指微软官方未发现或发布补丁的漏洞。早在去年就出现过多起针对微软office“0Day漏洞”病毒,比如“ANI漏洞”病毒。
漏洞描述:病毒网页在javascript脚本中构造了一个恶意的xml串。xml串中存在一个格式异常标签且包含image标记的CDATA标记。因为CDATA标记的格式不正常,所以IE7解析xml时会继续解析CDATA标记中的image标记。这个image标记中的SRC也是经过构造的,它利用了IE7在解析URI时的一个漏洞。当IE7在解析image的SRC时, 会溢出执行javascript脚本中的shellcode来执行任意代码。
微软IE 0day漏洞是一个基于IE浏览器内核的漏洞,所有基于IE内核的浏览器和应用程序都会成为攻击对象。如傲游、世界之窗、腾讯TT、Office系统软件、Outlook、某些网游的登陆界面等等。
目前已经发现“IE 0day漏洞生成工具”,而且金山毒霸已经截获数个利用该漏洞的恶意挂马网站。目前挂马的网站都是通过这一类型的工具自动生成的,下载的病毒主要是超级AV终结者、weiai、扫荡波一类的下载器。这些下载器再下载大量的盗号木马、ARP攻击木马等。
电脑探究者①群:52013541 ②群:57440776 ③群:48827659 互相学习-共同探讨,欢迎加入!青松博客期待你的再次光临—请记住我的地址 http://fqs310.blog.hexun.com 影响 的平台是:windows xp\2003 Vista操作系统安装了IE的用户
微软IE 0day漏洞危害分析:
2.5亿网民的定时炸弹,所有上网的用户都有可能遭受攻击。
常用可能“中招”的软件列表:
浏览器类(基于IE内核的,访问挂马网站时可能会中招)
1)IE7浏览器
2)傲游浏览器
3)世界之窗
4)腾讯TT
5)糖果浏览器
6)greenbrowser.exe
邮件客户端软件(浏览含有攻击代码的邮件时可能中招)
1) outlook
2) foxmail
下载软件(局域网ARP攻击,可能将恶意代码插入到下载软件提供的内嵌网页中)
1) 迅雷
2) 快车
3) 超级旋风
4) 电驴
5) BT
6)ppstream
7) pplive
等等
音乐视听(局域网ARP攻击,将恶意代码插入到下载软件提供的内嵌网页中)
1)千千静听
2)酷我音乐
3)Real播放器等
IM软件
1) 腾讯QQ的迷你主页
2)MSN资讯
3)旺旺焦点等等
几乎所有通过互联网下载和升级的软件都会包含这种内嵌网页,如果有ARP攻击插入代码,则打开时都可能中招。
电脑探究者①群:52013541 ②群:57440776 ③群:48827659 互相学习-共同探讨,欢迎加入!青松博客期待你的再次光临—请记住我的地址 http://fqs310.blog.hexun.com临时解决方案:
由于微软尚未正式推出补丁,以下例出几条方案可临时解决。
1.暂时不要使用IE 浏览器(包括遨游浏览器、世界之窗浏览器、360安全浏览器、腾讯TT浏览器、搜狗浏览器等IE内核的浏览器),可以使 Firefox 或 Opera 或Chrome等非 IE 内核浏览器;推荐使用“Firefox中国版”下载地址 http://fqs310.blog.hexun.com/26036197_d.html
2.为IE打开系统的数据执行保护功能,虽然不能阻止漏洞的触发但有助于增加攻击者利用漏洞的难度,方法如下:
右键单击我的电脑 -> 属性 -> 高级 -> 性能 -> 设置 -> 数据执行保护,选择“除所选之外,为所有程序和服务启用数据执行保护”;如果里面有内容,确认下面的框里“Internet Explorer”前没有打勾;重启电脑后,系统就开启了数据执行保护功.
3.安装网页安全防护工具。
a.推荐使用“畅游巡警”下载地址 http://fqs310.blog.hexun.com/20837172_d.html
b.安装最新“360安全卫士”,开启网页防火墙。下载地址 http://fqs310.blog.hexun.com/12669554_d.html
4.利用安全工具安装漏洞补丁。
a.使用江民IE XML漏洞补丁检测工具安装防疫补丁。下载地址1 下载地址2 下载地址3
b.使用360IE XML漏洞补丁工具安装防疫补丁。下载地址1 下载地址2 下载地址3
另推荐金山提供的金山系统清理专家,它含有该漏洞的免疫功能,据说这个免疫方案是安全有效的。免疫方案与补丁不同,它不是去堵漏洞,而是采取别的措施,保证不会有恶意代码利用漏洞潜入电脑。青松建议安装此工具扫描安装系统漏洞,然后结合以上方案。可保系统安全!
金山系统清理专家 下载地址1 下载地址2 下载地址3
电脑探究者①群:52013541 ②群:57440776 ③群:48827659 互相学习-共同探讨,欢迎加入!青松博客期待你的再次光临—请记住我的地址 http://fqs310.blog.hexun.com已经中毒的解决方案:
此次挂马的几个网站下载的病毒中包含有目前最毒的下载器“超级AV 终结者”。推荐安装
金山病毒急救箱 http://www.duba.net/zhuansha/263.shtml
附:此漏洞影响的系统、软件列表
• Windows Internet Explorer 7• Windows Internet Explorer 7 for Windows XP• Windows Internet Explorer 7 for Windows Server 2003• Windows Internet Explorer 7 for Windows Server 2003 IA64• Windows Internet Explorer 7 in Windows Vista• Windows Internet Explorer 8 Beta• Microsoft Internet Explorer 6.0 Service Pack 2• Microsoft Internet Explorer 6.0 Service Pack 1• Microsoft Internet Explorer 6.0• Microsoft Internet Explorer 5.01 Service Pack 4• Windows Server 2008 Datacenter without Hyper-V• Windows Server 2008 Enterprise without Hyper-V• Windows Server 2008 for Itanium-Based Systems• Windows Server 2008 Standard without Hyper-V• Windows Server 2008 Datacenter• Windows Server 2008 Enterprise• Windows Server 2008 Standard• Windows Web Server 2008• Windows Vista Service Pack 1, when used with:• Windows Vista Business• Windows Vista Enterprise• Windows Vista Home Basic• Windows Vista Home Premium• Windows Vista Starter• Windows Vista Ultimate• Windows Vista Enterprise 64-bit Edition• Windows Vista Home Basic 64-bit Edition• Windows Vista Home Premium 64-bit Edition• Windows Vista Ultimate 64-bit Edition• Windows Vista Business 64-bit Edition• Microsoft Windows Server 2003 Service Pack 1, when used with:• Microsoft Windows Server 2003, Standard Edition (32-bit x86)• Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)• Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)• Microsoft Windows Server 2003, Web Edition• Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems• Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems• Microsoft Windows Server 2003, Datacenter x64 Edition• Microsoft Windows Server 2003, Enterprise x64 Edition• Microsoft Windows Server 2003, Standard x64 Edition• Microsoft Windows XP Professional x64 Edition• Microsoft Windows Server 2003 Service Pack 2, when used with:• Microsoft Windows Server 2003, Standard Edition (32-bit x86)• Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)• Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)• Microsoft Windows Server 2003, Web Edition• Microsoft Windows Server 2003, Datacenter x64 Edition• Microsoft Windows Server 2003, Enterprise x64 Edition• Microsoft Windows Server 2003, Standard x64 Edition• Microsoft Windows XP Professional x64 Edition• Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems• Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems• Microsoft Windows XP Service Pack 2, when used with:• Microsoft Windows XP Home Edition• Microsoft Windows XP Professional• Microsoft Windows XP Service Pack 3, when used with:• Microsoft Windows XP Home Edition• Microsoft Windows XP Professional文章转载请注明出处:青松博客 http://fqs310.blog.hexun.com/27007301_d.html
[ 本帖最后由 kaiki_aiolos 于 2008-12-17 20:14 编辑 ]