·þÎñÆ÷Òç³öÌáȨ¹¥»÷µÄ½â¾ö°ì·¨ -µçÄÔ×ÊÁÏ

µçÄÔ×ÊÁÏ Ê±¼ä£º2019-01-01 ÎÒҪͶ¸å
¡¾www.unjs.com - µçÄÔ×ÊÁÏ¡¿

    ÔÚÆµÆµ¶ñÒâ¹¥»÷Óû§¡¢ÏµÍ³Â©¶´²ã³ö²»ÇîµÄ½ñÌ죬×÷ÎªÍøÂçÖÎÀíÔ±¡¢ÏµÍ³ÖÎÀíÔ±ËäÈ»ÔÚ·þÎñÆ÷µÄ°²È«É϶¼ÏÂÁ˲»ÉÙ¹¦·ò£¬ÖîÈ缰ʱ´òÉÏϵͳ°²È«²¹¶¡¡¢½øÐÐһЩ³£¹æµÄ°²È«ÅäÖ㬵«ÓÐʱÈÔ²»°²È«£¬

·þÎñÆ÷Òç³öÌáȨ¹¥»÷µÄ½â¾ö°ì·¨

¡£Òò´Ë±ØÐë¶ñÒâÓû§ÈëÇÖ֮ǰ£¬Í¨¹ýһЩϵÁа²È«ÉèÖã¬À´½«ÈëÇÖÕßÃǵ²ÔÚ“°²È«ÃŔ֮Í⣬ÏÂÃæ¾Í½«×î¼òµ¥¡¢×îÓÐЧµÄ·À(Overflow)Òç³ö¡¢±¾µØÌṩȨÏÞ¹¥»÷ÀàµÄ½â¾ö°ì·¨¸ø´ó¼Ò·ÖÏí¡£

    Ò»¡¢ÈçºÎ·ÀÖ¹Òç³öÀ๥»÷

    1¡¢¾¡×î´óµÄ¿ÉÄÜÐÔ½«ÏµÍ³µÄ©¶´²¹¶¡¶¼´òÍ꣬×îºÃÊDZÈÈçMicrosoft Windows ServerϵÁеÄϵͳ¿ÉÒÔ½«×Ô¶¯¸üзþÎñ´ò¿ª£¬È»ºóÈ÷þÎñÆ÷ÔÚÄúÖ¸¶¨µÄij¸öʱ¼ä¶ÎÄÚ×Ô¶¯Á¬½Óµ½Microsoft UpdateÍøÕ¾½øÐв¹¶¡µÄ¸üС£¼ÙÈçÄúµÄ·þÎñÆ÷ΪÁ˰²È«Æð¼û ½ûÖ¹Á˶Թ«ÍøÍⲿµÄÁ¬½ÓµÄ»°£¬¿ÉÒÔÓÃMicrosoft WSUS·þÎñÔÚÄÚÍø½øÐÐÉý¼¶¡£

    2¡¢Í£µôÒ»Çв»ÐèÒªµÄϵͳ·þÎñÒÔ¼°Ó¦ÓóÌÐò£¬×î´óÏÞÄܵĽµµ×·þÎñÆ÷µÄ±»¹¥»÷ϵÊý¡£±ÈÈçǰÕó×ÓµÄMSDTCÒç³ö£¬¾Íµ¼Öºܶà·þÎñÆ÷¹ÒµôÁË¡£Æäʵ¼ÙÈçWEBÀà·þÎñÆ÷¸ù±¾Ã»ÓÐÓõ½MSDTC·þÎñʱ£¬Äú´ó¿ÉÒÔ°ÑMSDTC·þÎñÍ£µô£¬ÕâÑùMSDTCÒç³ö¾Í¶ÔÄúµÄ·þÎñÆ÷²»¹¹³ÉÈκÎÍþвÁË¡£

    3¡¢Æô¶¯TCP/IP¶Ë¿ÚµÄ¹ýÂË£¬½ö´ò¿ª³£ÓõÄTCPÈç21¡¢80¡¢25¡¢110¡¢3389µÈ¶Ë¿Ú;¼ÙÈ簲ȫҪÇó¼¶±ð¸ßÒ»µã¿ÉÒÔ½«UDP¶Ë¿Ú¹Ø±Õ£¬µ±È»¼ÙÈçÕâÑùÖ®ºóȱÏݾÍÊÇÈçÔÚ·þÎñÆ÷ÉÏÁ¬Íⲿ¾Í²»·½±ãÁ¬½ÓÁË£¬ÕâÀィÒé´ó¼ÒÓÃIPSecÀ´·âUDP¡£ÔÚЭÒéɸѡÖÐ"Ö»´ðÓ¦"TCPЭÒé(ЭÒéºÅΪ£º6)¡¢UDPЭÒé(ЭÒéºÅΪ£º17)ÒÔ¼°RDPЭÒé(ЭÒéºÅΪ£º27)µÈ±ØÐèÓÃЭÒé¼´¿É;ÆäËüÎÞÓþù²»¿ª·Å¡£

    4¡¢ÆôÓÃIPSec²ßÂÔ:Ϊ·þÎñÆ÷µÄÁ¬½Ó½øÐа²È«ÈÏÖ¤£¬¸ø·þÎñÆ÷¼ÓÉÏË«±£ÏÕ¡£Èç¢ÛËù˵£¬¿ÉÒÔÔÚÕâÀï·âµôһЩΣÏÕµÄ¶ËÆ·ÖîÈç:135 145 139 445 ÒÔ¼°UDP¶ÔÍâÁ¬½ÓÖ®Àà¡¢ÒÔ¼°¶Ôͨ¶Á½øÐмÓÃÜÓëÖ»ÓëÓÐÐÅÈιØÏµµÄIP»òÕßÍøÂç½øÐÐͨѶµÈµÈ¡£(×¢:Æäʵ·À·´µ¯ÀàľÂíÓÃIPSec¼òµ¥µÄ½ûÖ¹UDP»òÕß²»³£ÓÃTCP¶Ë¿ÚµÄ¶ÔÍâ·ÃÎʾͳÉÁË,¹ØÓÚIPSecµÄÈçºÎÓ¦ÓÃÕâÀï¾Í²»ÔÙ°½Ðø£¬¿ÉÒÔµ½·þ°²ÌÖÂÛSearch "IPSec"£¬¾Í »áÓÐN¶à¹ØÓÚIPSecµÄÓ¦ÓÃ×ÊÁÏ..)

    5¡¢É¾³ý¡¢Òƶ¯¡¢¸üÃû»òÕßÓ÷ÃÎÊ¿ØÖƱíÁÐAccess Control Lists (ACLs)¿ØÖÆÒªº¦ÏµÍ³Îļþ¡¢ÃüÁî¼°Îļþ¼Ð£º

    £¨1£©. ͨ³£ÔÚÒç³öµÃµ½shellºó£¬À´ÓÃÖîÈçnet.exe net1.exe ipconfig.exe user.exe query.exe regedit.exe regsvr32.exe À´´ïµ½½øÒ»²½¿ØÖÆ·þÎñÆ÷µÄÄ¿µÄÈç:¼ÓÕ˺ÅÁË£¬¿Ë¡ÖÎÀíÔ±Á˵ȵÈ;ÕâÀï¿ÉÒÔ½«ÕâЩÃüÁî³ÌÐòɾ³ý»òÕ߸ÄÃû¡£(×¢ÖØ:ÔÚɾ³ýÓë¸ÄÃûʱÏÈÍ£µôÎļþ¸´ÖÆ·þÎñ(FRS)»òÕßÏȽ« %windir%\system32\dllcache\ϵĶÔÓ¦Îļþɾ³ý»ò¸ÄÃû¡£)

    £¨2£©.Ò²»òÕß½«ÕâЩ.exeÎļþÒÆ¶¯µ½Ö¸¶¨µÄÎļþ¼Ð,ÕâÑùÒ²·½±ãÒÔºóÖÎÀíÔ±×Ô¼ºÊ¹Óá£

    £¨3£©.·ÃÎÊ¿ØÖƱíÁÐACLS¿ØÖÆ£ºÕÒµ½%windir%\system32ÏÂÕÒµ½cmd.exe¡¢cmd32.exe net.exe net1.exe ipconfig.exe tftp.exe ftp.exe user.exe reg.exe regedit.exe regedt32.exe regsvr32.exe ÕâЩ ³£ÓõÄÎļþ£¬ÔÚ“ÊôÐÔ”→“°²È«”ÖжÔËûÃǽøÐзÃÎʵÄACLsÓû§½ø Ðж¨Ò壬ÖîÈçÖ»¸øadministratorÓÐȨ·ÃÎÊ£¬¼ÙÈçÐèÒª·À·¶Ò»Ð©Òç³ö¹¥»÷¡¢ÒÔ¼°Òç³ö³É¹¦ºó¶ÔÕâЩÎļþµÄ·Ç·¨ÀûÓã¬ÄÇôֻÐèÒª½«systemÓû§ÔÚACLsÖнøÐоܾø·ÃÎʼ´¿É£¬

µçÄÔ×ÊÁÏ

¡¶·þÎñÆ÷Òç³öÌáȨ¹¥»÷µÄ½â¾ö°ì·¨¡·(https://www.unjs.com)¡£

    £¨4£©.¼ÙÈç¾õµÃÔÚGUIÏÂÃæÌ«Âé·³µÄ»°£¬Ò²¿ÉÒÔÓÃϵͳÃüÁîµÄCACLS.EXEÀ´¶ÔÕâЩ.exeÎļþµÄAcls½øÐб༭ÓëÐ޸쬻òÕß˵½«Ëûд³ÉÒ»¸ö.batÅú´¦Àí ÎļþÀ´Ö´ÐÐÒÔ¼°¶ÔÕâЩÃüÁî½øÐÐÐ޸ġ£(¾ßÌåÓû§×Ô¼º²Î¼ûcacls /? °ïÖú½øÐУ¬ÓÉÓÚÕâÀïµÄÃüÁîÌ«¶à¾Í²»Ò»Ò»ÁоÙд³ÉÅú´¦Àí´úÂë¸ø¸÷λÁË!!)

    £¨5£©.¶Ô´ÅÅÌÈçC/D/E/FµÈ½øÐа²È«µÄACLSÉèÖôÓÕûÌ尲ȫÉÏ¿¼ÂǵĻ°Ò²ÊǺÜÓбØÒªµÄ£¬ÁíÍâ·Ç·²ÊÇwin2k£¬¶ÔWinnt¡¢Winnt\System¡¢Document and SettingµÈÎļþ¼Ð¡£

    6¡¢½øÐÐ×¢²á±íµÄÐ޸ĽûÓÃÃüÁî½âÊÍÆ÷: (¼ÙÈçÄú¾õµÃÓâݵķ½·¨Ì«·³ËöµÄ»°£¬ÄÇôÄú²»·ÀÊÔÊÔÏÂÃæÒ»ÀÍÓÀÒݵİ취À´½ûÖ¹CMDµÄÔËÐУ¬Í¨¹ýÐÞ¸Ä×¢²á±í£¬¿ÉÒÔ½ûÖ¹Óû§Ê¹ÓÃÃüÁî½âÊÍÆ÷(CMD.exe)ºÍÔËÐÐÅú´¦ÀíÎļþ(.batÎļþ)¡£¾ßÌå·½·¨:н¨Ò»¸öË«×Ö½Ú(REG_DWord)Ö´ÐÐ HKEY_CURRENT_USER\Software\PolicIEs\ Microsoft\Windows\System\DisableCMD£¬ÐÞ¸ÄÆäֵΪ1£¬ÃüÁî½âÊÍÆ÷ºÍÅú´¦ÀíÎļþ¶¼²»Äܱ»ÔËÐС£ÐÞ¸ÄÆäֵΪ2£¬ÔòÖ»ÊǽûÖ¹ÃüÁî½âÊÍÆ÷µÄÔËÐÐ,·´Ö®½«Öµ¸ÄΪ0£¬ÔòÊÇ´ò¿ªCMSÃüÁî½âÊÍÆ÷¡£¼ÙÈçÄú׬ÊÖ¶¯Ì«Âé·³µÄ»°,Ç뽫ÏÂÃæµÄ´úÂë±£´æÎª*.regÎļþ£¬È»ºóµ¼Èë¡£

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System]

    "DisableCMD"=dword:00000001

    7¡¢¶ÔһЩÒÔSystemȨÏÞÔËÐеÄϵͳ·þÎñ½øÐнµ¼¶´¦Àí¡£(ÖîÈç:½«Serv-U¡¢Imail¡¢IIS¡¢Php¡¢Mssql¡¢MysqlµÈһϵÁÐÒÔSystemȨÏÞÔËÐеķþÎñ»òÕßÓ¦ÓóÌÐò»»³ÉÆäËüadministrators³ÉÔ±ÉõÖÁusersȨÏÞÔËÐУ¬ÕâÑù¾Í»á°²È«µÃ¶àÁË...µ«Ç°ÌáÊÇÐèÒª¶ÔÕâЩ»ù±¾ÔËÐÐ״̬¡¢µ÷ÓÃAPIµÈÏà¹ØÇé¿ö½ÏΪÁ˽â. )

    Æäʵ£¬¹ØÓÚ·ÀÖ¹ÈçOverflowÒç³öÀ๥»÷µÄ°ì·¨³ýÁËÓÃÉÏÊöµÄ¼¸µãÒÔÍ⣬»¹ÓÐN¶àÖÖ°ì·¨:ÖîÈçÓÃ×é²ßÂÔ½øÐÐÏÞÖÆ£¬Ð´·À»¤¹ýÂ˳ÌÐòÓÃDLL·½Ê½¼ÓÔØwindowsµ½Ïà¹ØµÄSHellÒÔ¼°¶¯Ì¬Á´½Ó³ÌÐòÖ®ÖÐÕâÀà¡£µ±È»×Ô¼ºÐ´´úÂëÀ´½øÐÐÑéÖ¤¼ÓÃܾÍÐèÒªÓÐÏà¹ØÉîºñµÄWin32±à³Ì»ù´¡ÁË£¬ÒÔ¼°¶ÔShellcode½ÏÓÐÑо¿;ÓÉÓÚ´ËÎĽö½öÊÇÌÖÂÛ¼òµ¥µÄ½â¾ö°ì·¨£¬Òò´ËÆäËü°ì·¨¾Í²»ÔÚÕâÀïÏêÊöÁË¡£

×îÐÂÎÄÕÂ