·À»¤¼Æ»®£ºWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î·À»¤
2015-04-21
Ö´ÐÐÕªÒª
4ÔÂ14ÈÕ£¬Î¢Èíͨ¸æMS15-034/CVE-2015-1635 IIS7 http.sysÎó²î£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄËæ¼´Æô¶¯Ó¦¼±»úÖÆ£¬ Ó¦¼±ÏìÓ¦ÊÂÇéËæ¼´Æô¶¯¡£
1 15ÈÕÒ¹£¬Ðû²¼¸ßΣÎó²î½ôÆÈͨ¸æ£¬Ö§³ÖÐÅÏ¢À´×ÔÎó²îµÄʹÓûúÖÆÆÊÎö¼°POCÑéÖ¤ÊÂÇ飬µÚһʱ¼ä¼û¸æ¿Í»§¹Ø×¢£»
2 16ÈÕ£¬Ðû²¼²úÆ·¹æÔòÉý¼¶Í¨¸æ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼NIPS¡¢WAF¡¢RSAS¡¢WVSS¡¢NFµÈ²úÆ·Éý¼¶Ïà¼ÌÍ£µ±£¬¿Í»§Í¨¹ýÔÚÏß¼°ÀëÏßÉý¼¶µÄÒªÁ죬¼´¿É¾ÙÐзÀ»¤£»
3 17ÈÕ£¬Ðû²¼Îó²îÉîÈëÆÊÎö£¬´óÐÍÆóÒµ¼°×éÖ¯¿Í»§¿ÉÒÔͨ¹ýÕâЩÐÅÏ¢¶¨ÖÆ×Ô¼ºµÄ·ÀÓù¼Æ»®¡£ÔÚÏßÎó²î¼ì²âÒýÇæÍ£µ±¡£
4 21ÈÕ£¬ÎÒÃÇ»ØÊ×http.sysÎó²îµÄÐÅÏ¢Òªµã£¬´Óhttp.sysÎó²î·À»¤µÄ½Ç¶È¾ÙÐÐ×ܽᣬΪ¸÷ÈËÖÆ¶©·ÀÓù¼Æ»®ÌṩÔö²¹ÐÅÏ¢¡£
http.sysÎó²î»ØÊ×
4ÔÂ14ÈÕ£¬Î¢Èíͨ¸æÁË https.sysÎó²î£¬¼´Windows http.sysÔ¶³Ì´úÂëÖ´ÐиßΣÎó²î£¨MS15-034£©£¬CVE±àºÅCVE-2015-1635.´ËÎó²îÓÉÓھ߱¸ÈçϵÄ4¸öÌØµã£¬Ò»¾Ðû²¼£¬Ñ¸ËÙÒý·¢¹¥»÷ÕߵĹØ×¢£¬ÔÚÎó²îÐû²¼µÄµÚ2Ì죬Twitter¼°ÐÂÀË΢²©ÉÏ·ºÆð´ó×ÚÎó²îÐÅÏ¢£¬Ò»Ð©ÄäÃûµÄPOC¼°¿ÉÔ¶³Ì´¥·¢²Ù×÷ϵͳÀ¶ÆÁµÄ¹¥»÷´úÂë×îÏÈÈö²¥¡£
1. Http.sysÊÇ´¦Öóͷ£HTTPÇëÇóµÄÄÚºËÇý¶¯³ÌÐò£¬´¦ÓÚÑʺíÒªµÀ£¬Ò»µ©±»Ê¹Óúó»¼ÎÞÏÞ£»
2. ¸ÃÎó²îºÜÈÝ½á¹¹ÌØ¶¨µÄhttpÇëÇ󣬵¼Ö¹¥»÷Ä¿µÄÀ¶ÆÁ£¬ÕâÐÎʽ³£¼ûÓÚ²»Õýµ±ÉÌÒµ¾ºÕù£»
3. Ò»µ©±»Ê¹ÓÃÀֳɣ¬¿ÉÒÔ»ñµÃºÜ¸ßµÄϵͳȨÏÞ£¬¿ÉÔÚSystemÕÊ»§ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룻
4. IISÔÚÈ«ÇòµÄ°²ÅÅ×ÜÁ¿Áè¼Ý444Íò£¬µ«¾³£ÊÇδ¾¼Ó¹Ì»ò·À»¤ÊµÁ¦±¡Èõ
ÊÜ´ËÎó²îÓ°ÏìµÄÈí¼þ¼°ÏµÍ³°üÀ¨£º
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2008 R2 SP1
Microsoft Windows 8.1
Microsoft Windows 8
Microsoft Windows 7 SP1
¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓëÎó²îÏà¹Ø³§É̳¤Äê¼á³ÖÇ×½üÏàÖú¹ØÏµ¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ»ñÖªÏà¹ØÐÅÏ¢ºó£¬Ëæ¼´Æô¶¯Ó¦¼±»úÖÆ£¬Ïà¹ØÊÂÇéËæ¼´Æô¶¯¡£
ÊÜÓ°ÏìÇøÓòÂþÑÜ
×èÖ¹2015Äê4ÔÂ15ÈÕ£¬¾Ý¾ÅÓÎÀÏ¸ç¿Æ¼¼»¥ÁªÍø¹ãÆ×ƽ̨Êý¾ÝÏÔʾ£¬È«Çò°²ÅÅIISµÄϵͳÊýÄ¿»òÐíÓÐ444ÍòÓà¡£ÒÔÕ¼±È×î´óµÄIIS 7.5£¨42.3%£©ÎªÀý£¬ÃÀ¹ú¡¢Öйú¡¢Ó¢¹ú¼°µÂ¹úΪÊÜÓ°ÏìµÄŨÃÜÇøÓò£¬ÆäÖÐÖйúÕ¼±È16.4%£¬II7.5µÄ°²ÅÅÁ¿Áè¼Ý35Íò£¬ÕâÒ²ÊÇ´Ë´ÎÎó²îÔÆÔÆÊܵ½¹Ø×¢µÄÔµ¹ÊÔÓÉÖ®Ò»¡£
http.sysÎó²îÆÊÎö
2015Äê4ÔÂ15ÈÕÒ¹£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ»ñÈ¡http.sysÎó²îÓ°Ïì¹æÄ£Êý¾ÝµÄͬʱ£¬Ò²ÔÚѸËÙÕö¿ªÎó²îµÄÆÊÎöÊÂÇ飬ͨ¹ýÖØÏÖÎó²îµÄ¹¥»÷Àú³Ì£¬ÆÊÎöÆäÊÂÇéÔÀí£¬µÃÒÔÇåÎúʶ±ð¼°¼ì²â¸ÃÎó²îÒªÁ죬ÔÚ׼ȷ½ç˵ÆäÍþв¶¨¼¶ºó£¬Ëæ¼´ÏòÎÒÃǵĿͻ§·¢³ö¸ßΣÎó²î½ôÆÈͨ¸æ¡£
http.sysÀ¶ÆÁ
ƾ֤PastebinÉÏÅû¶µÄPoC£¬ºÜÈÝÒ׽ṹ³öÄÜ´¥·¢À¶ÆÁ£¨BSOD£©µÄPoC£¬ºÃ±ÈÒÔÏÂÇëÇó£º
1 GET /welcome.png HTTP/1.1
2 Host: PoC
3 Range: bytes=12345-18446744073709551615
¿ÉÒÔʹװÖÃÓÐIIS 7.5µÄWindows 7 SP1ϵͳBSOD¡£
http.sysÎó²îʹÓÃ
¶ÔBSODÍß½âµÄÏÖ³¡¾ÙÐÐÆÊÎö£¬·¢Ã÷ÊÇÖÖÖÖÇéÐεÄÄÚ´æ¹ýʧ£¬ÓÉ´ËÍÆ²â´¥·¢Îó²îºó¿ÉÄÜÔì³ÉÁËÄÚ´æÆÆËð¡£¶ÔHTTP.sysµÄ´¦Öóͷ£Á÷³Ì¾ÙÐÐÆÊÎö¡¢Öð²½ÅŲ飬¿ÉÒÔÈ·¶¨ÄÚ´æÆÆË𱬷¢ÔÚº¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÖУ¬º¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÓÃÓÚÌìÉúÏìÓ¦±¨ÎĵĻº´æMDLÁ´£¬À´ÐÎòHTTPÏìÓ¦µÄ״̬ÐС¢Í·²¿ÓëÐÂÎÅÌ壬Á´Éϵĸ÷MDLͨ¹ýŲÓÃnt! IoBuildPartialMdlÀ´ÌìÉú[3]¡£
´¥·¢´ËÎó²î¿ÉÔ½½çдÊý¾Ý¶øÔì³ÉÄÚ´æÆÆËð£¬ÀíÂÛÉϱ£´æÔ¶³ÌÖ´ÐдúÂëµÄ¿ÉÄÜÐÔ¡£¿ÉÊÇÔ½½çËùдÊý¾ÝµÄ³¤¶ÈÏÂÏÞÓÉContentLength¾öÒ飬ͨ³£»áÊÇÒ»¸ö½Ï´óµÄÖµ¶øÁ¢×ÝȻϵͳÍ߽⡣×ÝȻĿµÄ·þÎñÆ÷Éϱ£´æÒ»Ð©´óµÄÎļþ£¬¿ÉÒÔÓÃÀ´Ô½½çдÉÙÁ¿Êý¾Ý£¬ËùдÊý¾ÝÄÚÈÝÓë±»ÁýÕÖÄ¿µÄÒ²ºÜÄÑ¿ØÖÆ¡£Òò´Ë£¬ÔÚÏÖÕæÏàÐÎÖÐÏëÒªÎȹ̵ÄʹÓôËÎó²îÀ´Ö´ÐдúÂëÊǺÜÊÇÄÑÌâµÄ£¬µ«¹¥»÷ÕßÒªÏëʹÓôËÎó²îʹ¹¥»÷Ä¿µÄÀ¶ÆÁ£¬ÊǺÜÊǼòÆÓµÄÊÂÇ飡
ÕýÊÇ˼Á¿µ½À¶ÆÁµÄÒòËØ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ¶ÔÍâÐû²¼Îó²î¼ì²âÒªÁìµÄʱ¼äÓÈΪÉóÉ÷£¬×èÖ¹¸øÊ¹ÓÃÕâЩ¼ì²âÒªÁìµÄÓû§Ôì³É²»ÐëÒªµÄ¶þ´ÎΣÏÕ£¬¾ÓÉÖØ¸´ÑéÖ¤Çå¾²¿É¿¿Ö®ºó£¬²Å½«¼ì²âÒªÁìͶÈëÔÆ¶Ë¼ì²âϵͳ¡£
http.sysÎó²î¼ì²â
ÃæÁÙÔÆÔÆÑÏËàµÄÐÎʽ£¬ÆÊÎöְԱѸËÙ½«¾ÓÉÇå¾²ÑéÖ¤ºóµÄ¼ì²âÒªÁìÏòÔÆ¶Ë¡¢²úÆ·¶Ë¼°·þÎñ¶Ëת´ï£¬²¢½¨ÒéÓû§¾¡¿ì¶ÔÆäÓªÒµÇéÐξÙÐÐÒ»´ÎÖÜÈ«µÄÎó²î¼ì²â£¬ÒÔ±ã¿ÉÒÔ¾¡¿ìÄõ½µÚÒ»ÊÖÊý¾Ý£¬ÎªºóÐøÖÆ¶©Îó²î·À»¤¼Æ»®¼°Ö´Ðв½·¥ÌṩÊý¾ÝÖ§³Ö¼°¾öÒéÒÀ¾Ý¡£http.sysÎó²îµÄ¼ì²â·½·¨¿ÉÒÔʹÓÃÈýÖÖ·½·¨£¬Ôƶˡ¢²úÆ·¶Ë¼°¾ç±¾¹¤¾ß¡£
http.sysÎó²îÔÆ¶Ë¼ì²â
4ÔÂ17ÈÕÍí20:00£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼¿Í»§×ÔÖúÃÅ»§ÏµÍ³PortalÐû²¼http.sysÎó²î¼ì²âÒýÇæ£¬ÎªWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2015-1635)Ó¦¼±É¨ÃèÖ§³Ö£¬×èÖ¹ÖÁ4ÔÂ19ÈÕÆÆÏþ3:00£¬ÒÑÓÐ348¼Ò¿Í»§£¬¹²Ìá½»²¢É¨ÃèÓòÃûÊýÄ¿2086¸ö£¬ÆäÖÐ9¼Ò¿Í»§±£´æWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÏìÓ¦ÍŶÓËæ¼´Í¨Öª¿Í»§¡£Í¬Ê±¾ÅÓÎÀÏ¸ç¿Æ¼¼Îó²îɨÃè²úÆ·RSAS¡¢AASÒÑÔÚµÚһʱ¼äÐû²¼Á˼ì²â²å¼þÉý¼¶°ü£¬ËæºóNF¡¢IDS¡¢IPSÒ²ÔÚ1ÌìÄÚÐû²¼Á˲úÆ·¹æÔòÉý¼¶°ü¡£
|
¿Í»§ |
ÊýÄ¿ |
ÓòÃû |
ÊýÄ¿ |
|
ɨÃè¿Í»§ |
348 |
ɨÃèÓòÃû |
2086 |
|
±£´æIISÎó²î¿Í»§ |
9 |
±£´æIISÎó²îÓòÃû |
10 |
|
²»±£´æIISÎó²î¿Í»§ |
339 |
²»±£´æIISÎó²îÓòÃû |
1541 |
ÏÖÔÚÄúËæÊ±¿ÉÒÔʹÓÃÕâ¸ö×ÔÖúϵͳ£¬¶ÔÓªÒµÇéÐξÙÐÐɨÃ裬ÒÔ±ãÈ·ÈÏÊÇ·ñ±£´æ¸ÃÎó²î£¬É¨ÃèÇëµã»÷£ºhttps://portal.nsfocus.com/vulnerability/list/
Îó²îÈ·ÈÏ µ±É¨ÃèЧ¹ûÐÅÏ¢ÖзºÆðÐÅÏ¢¡°ÄúµÄ¼ì²âÄ¿µÄ±£´æ´ËÎó²î¡±£¬¼´¿ÉÈ·ÈÏÄ¿½ñÓªÒµÇéÐÎÖб£´æ¸ÃÎó²î£¬½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏ룬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷¡£

http.sysÎó²î²úÆ·¶Ë¼ì²â
4ÔÂ16ÈÕÖÐÎ磬¾ÅÓÎÀÏ¸ç¿Æ¼¼¸÷²úÆ·Õë¶Ôhttp.sysµÄ¹æÔòÉý¼¶°ü¼°²å¼þÉý¼¶°üËùÓÐÍ£µ±£¬²¢ÔÚ¹Ù·½Ðû²¼²úÆ·Éý¼¶Í¨¸æ£¬Í¬Ê±Ïò·þÎñÖ°Ô±·¢ËÍÏà¹ØÐÅÏ¢¡£ÕâÀォÖ÷Òª²úÆ·Éý¼¶°æ±¾ÐÅϢժ¼ÈçÏ£¬Çë¿í´óÓû§¾¡¿ìÉó²éËùʹÓòúÆ·µÄ°æ±¾µÄÐÅÏ¢£¬¸ü¶àÏêϸÐÅÏ¢ÇëÅÌÎÊ£ºhttp://update.nsfocus.com/
|
http.sysÎó²î·À»¤¹æÔòÉý¼¶°ü |
http.sysÎó²î·À»¤²å¼þÉý¼¶°ü |
|||||||
|
²úÆ· |
°æ±¾ºÅ |
Éý¼¶Ê±¼ä |
²úÆ· |
°æ±¾ºÅ |
Éý¼¶Ê±¼ä |
|||
|
NF 6.0.1 |
6.0.1.496 |
2015/4/16 |
12:00:00 |
RSAS 6.0 |
V6.0R02F00.0108 |
2015/4/16 |
18:00:00 |
|
|
NF 6.0.0 |
5.6.7.496 |
2015/4/16 |
12:00:00 |
RSAS 5.0 |
051347 |
2015/4/16 |
19:00:00 |
|
|
IDS 5.6.9 |
5.6.9.12244 |
2015/4/16 |
13:00:00 |
RSAS-AAS 5.0 |
051130 |
2015/4/17 |
15:00:00 |
|
|
IDS 5.6.8 |
5.6.8.496 |
2015/4/16 |
11:00:00 |
WVSS 6.0 |
V6.0R02F00.28 |
2015/4/16 |
18:00:00 |
|
|
IDS 5.6.7 |
5.6.7.496 |
2015/4/16 |
11:00:00 |
|||||
|
IDS 5.6.6 |
5.6.0.422 |
2015/4/16 |
11:00:00 |
|||||
|
IPS 5.6.9 |
5.6.9.12244 |
2015/4/16 |
11:00:00 |
|||||
|
IPS 5.6.8 |
5.6.8.496 |
2015/4/16 |
11:00:00 |
|||||
|
IPS 5.6.7 |
5.6.7.496 |
2015/4/16 |
11:00:00 |
|||||
|
IPS 5.6.6 |
5.6.0.422 |
2015/4/16 |
11:00:00 |
|||||
|
WAF 6.0.4 |
6.0.4.1.30345 |
2015/4/16 |
11:00:00 |
|
|
|
|
|
ÈôÊÇÄúµÄÓªÒµÇéÐÎÖÐÒѾ°²ÅÅÁËÏà¹ØÎó²îɨÃèϵͳ£¬Ç뽫Îó²îɨÃèϵͳÉý¼¶µ½×îа汾ºó£¬¾¡¿ì×îÏȶÔӪҵϵͳ¾ÙÐÐɨÃ裬ÓÈÆäÊÇÊÜ´Ë´Îhttp.sysÎó²îÓ°ÏìµÄӪҵϵͳƽ̨¾ÙÐÐÒ»´ÎÎó²îɨÃè¡£ÕâÀïÒÔ¾ÅÓÎÀϸçÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨NSFOCUS Remote Security Assessment System £¬¼ò³Æ£ºNSFOCUS RSAS£©ÎªÀý£¬µ±Äú°²ÅŸòúÆ·ºó£¬ÇëÏȶԲúÆ·¾ÙÐÐÉý¼¶£º
- ? RSAS v6ϵÁвúÆ·Éý¼¶µ½ÏµÍ³²å¼þ°æ±¾V6.0R02F00.0108£»
- ? RSAS v5ϵÁвúÆ·Éý¼¶µ½ÏµÍ³°æ±¾Îª051347£»
- ? AASϵÁвúÆ·Éý¼¶µ½ÏµÍ³°æ±¾Îª051130
Îó²îÈ·ÈÏ ÈôÊÇÄúµÄÎó²îɨÃèЧ¹û°üÀ¨ÏÂͼÎó²î£¬ÌØÊâÊǰüÀ¨´øÓС°¡¾ÔÀíɨÃè¡¿¡±×ÖÑùµÄÎó²îʱ£¬¼´¿ÉÈ·ÈÏÄ¿½ñÇéÐÎÖб£´æ¸ÃÎó²î£¬½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏ룬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷¡£
http.sysÎó²îÀëÏß¼ì²â
ÈôÊÇÄú»¹Ã»Óа²ÅÅÎó²îɨÃè²úÆ·£¬ÓÖ»òÕßÄúµÄӪҵϵͳÏÖÔÚ»¹²»ÊʺϾÙÐÐÈçÉϼì²â·½·¨£¬»¹¿ÉÒÔ½ÓÄÉÀëÏß¼ì²âµÄ·½·¨£¬¼´½ÓÄÉhttp.sys POCÑéÖ¤¡£ÕâÀïÌṩÁ½ÖÖÐÎʽ£¬°üÀ¨Python¾ç±¾¼°curl¹¤¾ß¡£
СÌùÊ¿£º
ÕâÀïÌáÐѸ÷ÈË£¬½üÆÚÊÜ´ËÎó²îÓ°Ï죬´ó×ÚÎó²î¼ì²â¾ç±¾¼°¹¤¾ßƵ³ö£¬ÈôÊÇÄúÐèÒª»ñÈ¡ÕâЩ¼ì²â¹¤¾ß£¬ÐèÒª´Ó¿É¿¿Í¾¾¶»ñÈ¡£¬×èÖ¹±»Ö²Èë¶ñÒâ´úÂ룬ÒÔÃâǰÞÜÀǺóÃŽø»¢£¡
ʹÓÃpython¾ç±¾¼ì²â ½«ÏÂÁдúÂëдÈë.pyÎļþÖ´Ðм´¿É¡£
1 '''
2 ´Ë¾ç±¾½öÊÊÓÃÓÚ¼ì²âIIS·þÎñÆ÷ÊÇ·ñ±£´æHttp.sys ´¦Öóͷ£ Range ÕûÊýÒç³öÎó²î£¬²»ÊÊÓÃÓÚ¹¥»÷ʹÓá£
3 '''
4 import socket
5 import random
6
7 ipAddr = "" #Ìí¼ÓÄ¿µÄip
8 hexAllFfff = "18446744073709551615"
9
10 req1 = "GET / HTTP/1.0 "
11 req = "GET / HTTP/1.1 Host: stuff Range: bytes=0-" + hexAllFfff + " " #Ö÷Òª²âÊÔ´úÂë
12
13 print "[*] Audit Started"
14 client_socket = socket.socket(socket.AF_INET socket.SOCK_STREAM)
15 client_socket.connect((ipAddr 80)) #ÈôÊÇweb·þÎñÆ÷¿ªÆô·Ç80¶Ë¿Ú£¬¿ÉÔÚ´Ë´¦ÐÞ¸ÄΪ׼ȷ¶Ë¿Ú
16 client_socket.send(req1)
17 boringResp = client_socket.recv(1024)
18 if "Microsoft" not in boringResp: #¼ì²âÄ¿½ñweb·þÎñÊÇ·ñΪIIS web·þÎñÆ÷
19 print "[*] Not IIS"
20 exit(0)
21 client_socket.close()
22 client_socket = socket.socket(socket.AF_INET socket.SOCK_STREAM)
23 client_socket.connect((ipAddr 80))
24 client_socket.send(req)
25 goodResp = client_socket.recv(1024)
26 if "Requested Range Not Satisfiable" in goodResp: #ͨ¹ýÉó²é·þÎñÆ÷·µ»ØÅжÏÊÇ·ñ±£´æ¸ÃÎó²î£¬Æ¾Ö¤´òÓ¡³öµÄЧ¹ûÅжϣº
27 #Looks VULNΪ±£´æ¸ÃÎó²î£¬Looks PatchedΪÒÑ´ò²¹¶¡£¬ÆäËûÇéÐλ᷵»ØUnexpected response
28 print "[!!] Looks VULN"
29 elif " The request has an invalid header name" in goodResp:
30 print "[*] Looks Patched"
31 else:
32 print "[*] Unexpected response cannot discern patch status"
ʹÓÃcurl¹¤¾ß¼ì²â
1 $curl -v 192.168.174.140 -H "Host: irrelevant" -H "Range: bytes=0-18446744073709551615"
Îó²îÈ·ÈÏ ±£´æ´ËÎó²î½ØÍ¼£¬Èç·þÎñÆ÷·µ»ØRequested Range Not Satisfiable£¬Ôò˵Ã÷±£´æ´ËÎó²î¡£½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏ룬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷¡£
ʹÓ÷¢°ü¹¤¾ß½á¹¹httpÇëÇó°ü¼ì²â ÒÔfiddler¹¤¾ßΪÀý£¬½á¹¹ÈçÏÂͼµÄÇëÇó°ü£º
1 GET http://192.168.174.145/ HTTP/1.1
2 Host: 192.168.174.145
3 Range: bytes=0-18446744073709551615
4 Connection: keep-alive
5 Cache-Control: max-age=0
6 Accept: text/htmlapplication/xhtml+xmlapplication/xml;q=0.9image/webp*/*;q=0.8
Îó²îÈ·ÈÏ ÈôÊÇÊÕµ½·þÎñÆ÷·µ»Ø°üÈçÏ Ôò˵Ã÷±£´æ´ËÎó²î¡£½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏ룬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷¡£
http.sysÎó²î·À»¤
¾ÓÉÉÏÃæµÄÎó²î¼ì²â°ì·¨ºó£¬ÈôÊÇÈ·ÈÏÄúµÄÓªÒµÇéÐÎÖб£´æhttp.sysÎó²î£¬ÄÇô¾ÍÐèÒª¾¡¿ìÖÆ¶©²¢Æô¶¯¼Ó¹Ì¼Æ»®£¬ÕâЩ¼Ó¹Ì´ÓÎó²î²¹¶¡×îÏÈ£¬µ½²úÆ··À»¤£¬µ½ÕûÌå·À»¤£¬Öð²½Íƽø¡£
Îó²î¼Ó¹Ì
ʹÓÃIISµÄÓû§£¬¿ÉÒÔͨ¹ýWindows UpdateµÄ·½·¨»ñµÃ¶ÔÓ¦µÄKB3042553ÈÈÐÞ²¹²¹¶¡£¬½¨ÒéÓû§¿ªÆô×Ô¶¯¸üзþÎñÒÔʵʱװÖÃ×îв¹¶¡£¬Ïà¹ØÍ¨¸æÇë¼û£º
http.sysÎó²î²¹¶¡Í¨¸æ£ºhttp://technet.microsoft.com/security/bulletin/MS15-034
ÈôÊÇÄúµÄӪҵϵͳÔÝʱ»¹ÎÞ·¨Éý¼¶²¹¶¡£¬ÄÇô¿Éͨ¹ý½ûÓÃIIS Äں˻º´æÀ´ÔÝʱ»º½â´ËÎó²îµÄΣÏÕ£¬µ«ÐèÒª×¢ÖØÕâ¿ÉÄܻᵼÖÂIISÐÔÄÜϽµ£¬ÏêϸµÄÖ´ÐÐÒªÁì¿ÉÒԲο¼£º
http.sysÎó²î»º½â¼Æ»®£ºhttps://technet.microsoft.com/zh-cn/library/cc731903(v=ws.10).aspx
IIS¼Ó¹Ì
ËäÈ»IIS7ÖÐhttp.sysÒѾ×ÔÁ¦³öÀ´³ÉΪϵͳ¼¶Çý¶¯³ÌÐò£¬µ«ÒÔʷΪ¼ø£¬½¨ÒéÓû§ÔÚ×°Öò¹¶¡µÄͬʱҲÐèҪ˼Á¿IIS¼Ó¹ÌÊÂÏÏêϸµÄ×î¼Ñʵ¼ùÇë²Î¿¼£º
IIS7¼Ó¹Ì¼Æ»®£º https://technet.microsoft.com/zh-cn/library/cc731278(WS.10).aspx
ÓÌÈçľͰЧӦһÑùƽ³££¬ÓªÒµÇéÐεļӹÌÖ»ÊÇÒÀÀµÓÚÎó²î¼Ó¹ÌÊDz»·óµÄ£¬ÕûÌåÇ徲Ʒ¼¶µÄÌáÉýÒÔ¼°Ó¦¶ÔδÀ´µÄ¹¥»÷£¬Çå¾²²úÆ·ÊDZز»¿ÉÉÙµÄÒ»»·£¬½«WebϵͳÖÃÓÚDMZÇøÓò²¢¼ÓÒÔ¶à²úÆ·µÄÕûÌå·À»¤£¬ÊÇÎÒÃÇÍÆ¼öµÄ×ö·¨¡£ÔÚÈçϰ²ÅÅÇéÐÎÖУ¬ÒÔ¾ÅÓÎÀϸçWebÓ¦Ó÷À»ðǽ£¨Web Application Firewall£¬¼ò³ÆWAF£©ÎªÀý£¬¶ÔӪҵϵͳ°²ÅÅWAFÄܹ»´Ó¿Í»§×ʲúµÄÊӽǣ¬ÊµÑé¶àÖÖ»ùÓÚ¹æÔòµÄ¼ì²â£¬²¢ÊµÑé¶àÌõÀíµÄÇå¾²»úÖÆ£¬ËæÊ±ÓëÔÆ¶Ë·þÎñÐ×÷£¬ÌìÉúÏìÓ¦µÄWebÇå¾²½â¾ö¼Æ»®£¬´Ó¶øÓÐÓÃÓ¦¶ÔÎó²î·À»¤Ê¹Ãü¡£
ÇëËùÓÐʹÓþÅÓÎÀϸç²úÆ·µÄÓû§¾¡¿ìÉý¼¶²úÆ·¹æÔò¡£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÑÔÚÈí¼þÉý¼¶Í¨¸æÖÐÌṩ¹æÔòÉý¼¶°ü£¬¹æÔò¿ÉÒÔͨ¹ý²úÆ·½çÃæµÄÔÚÏßÉý¼¶¾ÙÐС£ÈôÊÇÄúµÄӪҵϵͳÔÝʱ»¹ÎÞ·¨Éý¼¶¹æÔò°ü£¬ÄÇô¿ÉÒÔÔÚÈí¼þÉý¼¶Ò³ÃæÖУ¬ÕÒµ½¶ÔÓ¦µÄ²úÆ·£¬Í¨¹ýÏÂÔØÉý¼¶°ü£¬ÒÔÀëÏß·½·¨¾ÙÐÐÉý¼¶¡£ Ïà¹ØÐÅÏ¢Çë»á¼û£º
? Çå¾²²úÆ·ÏÈÈÝ£ºhttp://www.nsfocus.com.cn/1_solution/1_2_1.html
? ²úÆ·Éý¼¶Í¨¸æ£ºhttp://update.nsfocus.com/
ÓªÒµÇå¾²¼Ó¹Ì
ÔÚһЩ´óÐÍµÄÆóÒµ»ò×éÖ¯ÖУ¬http.sysÎó²îµÄ·À»¤»òÐí²¢²»¿É¿ìËÙÖ´ÐУ¬ÆäÔµ¹ÊÔÓÉÔÚÓÚ£º1ÐèҪ˼Á¿ÓªÒµÏµÍ³µÄ¿ÉÓÃÐÔ£»2ÐèҪ˼Á¿ÕûÌåʵÑ鼯»®Öƶ©£»3ÐèÒª¾¡¿ÉÄܽµµÍ¼Ó¹ÌÐж¯¶ÔÓªÒµÇéÐεĶþ´ÎΣÏÕ¡£Õâ¾ÍÐèÒªÆóÒµ×ÔÉí¡¢Îó²îÏà¹Ø³§ÉÌ¡¢Çå¾²³§ÉÌÒ»ÆðÐ×÷²Å»ªÐγɿìËÙ¡¢Çå¾²¡¢ÓÐÓõÄÐж¯¼Æ»®£¬×èֹӪҵϵͳÔÚ»ñµÃÇå¾²¼Ó¹Ì֮ǰÔâÊܹ¥»÷¡£ÔÚ´Ë´ÎÓ¦¼±ÏìÓ¦Àú³ÌÖУ¬¾ÅÓÎÀÏ¸ç¿Æ¼¼µÄ·þÎñÖ°Ô±Ïò¿Í»§½¨ÒéÐж¯¼Æ»®Ó¦¸ÃÇÒÖÁÉÙ°üÀ¨ÈçÏ»·½Ú£º
? Ê×ÏÈ£¬Ó¦¸ÃµÚһʱ¼ä»ñÈ¡Îó²îͨ¸æ¼°Ïà¹ØÐÅÏ¢£¬Ïàʶ´Ë´ÎÎó²îµÄÓ°Ïì¹æÄ£¼°Éî¶È¡£
? ÔÙÕߣ¬ÐèÒª½«Í¨¸æÏ¢Õù¶ÁÓë×ÔÉíÏÖʵITӪҵϵͳ״̬ÏàÍŽᣬÖÜÈ«ÅжϳöÓ°Ïì¹æÄ£ºÍˮƽ£¨Õâ°üÀ¨¶Ô×ÔÉíÓªÒµ¼°¶ÔÆä¿Í»§µÄÓ°Ïìˮƽ£©£¬Õâ¸öÅжÏÀú³Ì£¬ÐèÒªÊý¾Ý×÷Ϊ׼ȷ¼Æ»®Öƶ©µÄÊÂʵÒÀ¾Ý£¬½¨ÒéÓû§Ê¹ÓÃÇå¾²¿É¿¿µÄÎó²îɨÃ蹤¾ß£¬Éý¼¶×îÐÂÐû²¼µÄ²å¼þ»ò¹æÔò¿â£¬¶ÔÈ«Íø¾ÙÐÐÇ徲ɨÃ裬Äõ½µÚÒ»ÊÖÊý¾ÝºóÒÔ±ã×÷Ϊ¾öÒéÒÀ¾Ý£»
? ÔٴΣ¬ITÖ°Ô±ÐèÒª´ÓÓªÒµÎȹÌÐÔ¡¢Î£º¦Ë®Æ½ºÍ¹æÄ£¼°Ö÷ÒªÐԵȶà¸öά¶È×ÛºÏ˼Á¿£¬Öƶ©Õû¸Äʱ¼äÍýÏë±í£¬È¨ÖØÓɸߵ½µÍÒÀ´Î¶Ô¾Ö²¿ÍøÂç¼°Ö÷»ú×°±¸»òijӪҵϵͳװ±¸Õö¿ªÕû¸ÄºÍ¼Ó¹ÌÊÂÇ飨½¨ÒéÔ¼ÇëÎó²îÏà¹Ø³§É̼°Çå¾²³§ÉÌһͬ¼ÓÈ룩¡£
? Õâ¸ö½×¶ÎÐèÒªÇå¾²³§ÉÌÌṩרҵÊÖÒÕÐÖú£¬ºÃ±ÈÎó²î¼Ó¹Ì×Éѯ¡¢ÑéÖ¤¼Ó¹ÌÊÇ·ñÀֳɣ»Í¬Ê±ÐèÒªÏàʶÇå¾²³§É̵ÄÄÄЩװ±¸ÒѾÐû²¼»ò¼´½«Ðû²¼·À»¤¹æÔò£¬Éý¼¶ºó¼´¿É¾ÙÐзÀ»¤£»
? ÈôÊÇ»¹Ã»ÓнÓÄÉÈκÎÒ»¿îÇå¾²×°±¸£¬¾ÍÐèÒª½ÓÄÉÔÝʱ·À»¤²½·¥£¬°üÀ¨½ÓÄÉÎó²îÏà¹Ø³§É̼°Çå¾²³§É̵ÄÏà¹Ø¼Æ»®£¬ÎªÕûÌå¼Ó¹ÌÕùȡʱ¼ä£¬×èÖ¹ÔÚδ¼Ó¹ÌÕû¸ÄÀÖ³É֮ǰÕâ¸ö´°¿Úʱ¼äÔâµ½¹¥»÷²¢Êܵ½Ëðʧ£¬ÕâÑùµÄÇéÐÎÔÚÏ൱¶àµÄ0dayÊÂÎñÖÐ˾¿Õ¼û¹ß£»
? ÁíÍ⣬»¹ÐèÒªÎó²îÏà¹Ø³§ÉÌÓëÇå¾²³§ÉÌͨÁ¦Ð×÷£¬Ï໥ÏàͬÎó²îÔÀíºÍʹÓÃÀú³Ì£¬¾ÙÐнÏÉîÌõÀíµÄ½â¶Á£¬²Å»ª¹»Ôö½øÎó²îÏà¹Ø³§É̵Ŀª·¢Ö°Ô±ÉîÈëÏàʶÕâ¸öÎó²î²¢Æ¾Ö¤Æä×ÔÉíÇéÐξÙÐдúÂë²ãÃæµÄÕû¸Ä£»
? È»ºó£¬Ôڼӹ̽׶ÎÐÔ»òÕûÌåÍê³Éºó£¬ÐèÒªÔٴξÙÐÐÍêÕûɨÃèºÍÈ˹¤ÑéÖ¤Õû¸Ä¼Ó¹ÌЧ¹û£¬ÔÚÊÖÒÕͶÈëÔÊÐíµÄÌõ¼þÏ£¬½¨ÒéÄúÔٴξÙÐи÷·½ÃæÈÕÖ¾ÆÊÎö£¬ÊÓ²ìÕû¸Ä¼Ó¹Ìʱ´úÓÐûÓÐÀֳɵĹ¥»÷µ½ÆäϵͳÔì³ÉÆäËûËðʧ£»
? ×îºó£¬ÔÚÕûÌåÏìÓ¦ÊÂÇéÍê³Éºó£¬¾ÙÐÐ×ܽáºÍ±¸°¸¼Í¼¡£
ÍþвÇ鱨
ÒÔºó´Îhttp.sysÎó²îÇéÐοÉÒÔ¿´µ½£¬ÎÞÂÛÎó²îÔÀíÔõÑù£¬ÎÞÂÛÎó²î·À»¤¼Æ»®ÔõÑùʵÑ飬Ҫº¦ÔÚÓÚ¾¡¿ÉÄÜ¿ìµÄÏàʶµ½Îó²îÐÅÏ¢¼°Ïà¹ØµÄÇ鱨£¬ÒԱ㾡¿ÉÄÜ¿ìµÄÆô¶¯Ó¦¼±ÏìÓ¦»úÖÆ¡£ÕâÎÞÂÛ¹ØÓÚ½â¾ö¹Å°åÇå¾²»òÕßAPT¹¥»÷À´Ëµ¶¼ÊÇÖ÷ÒªµÄÊÖ¶ÎÖ®Ò»£¬ÍþвÇ鱨µÄ»ñÈ¡¼°ÏìÓ¦¶¼ÌåÏÖÁË·ÀÓùÄÜÁ¦µÄ½¨Éèˮƽ£¬ÍþвÇ鱨·þÎñϵͳÖÁÉÙ°üÀ¨ÁËÍþв¼à²â¼°ÏìÓ¦¡¢Êý¾ÝÆÊÎö¼°ÕûÀí¡¢ÓªÒµÇ鱨¼°½»¸¶¡¢Î£º¦ÆÀ¹À¼°×Éѯ¡¢Çå¾²Íйܼ°Ó¦Óõȸ÷¸ö·½Ãæ£¬Éæ¼°Ñо¿¡¢²úÆ·¡¢·þÎñ¡¢ÔËÓª¼°ÓªÏúµÄ¸÷¸ö»·½Ú£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Í¨¹ýÑо¿¡¢Ôƶˡ¢²úÆ·¡¢·þÎñµÈÁ¢ÌåµÄÓ¦¼±ÏìӦϵͳ£¬ÏòÆóÒµºÍ×é֯ʵʱÌṩÍþвÇ鱨²¢Ò»Á¬¾ÙÐкóÐø·þÎñ£¬°ü¹Ü¿Í»§ÓªÒµµÄ˳³©ÔËÐС£
ÈôÊÇÄú¶ÔÎÒÃÇÌṩµÄÄÚÈÝÓÐÈκÎÒÉÎÊ£¬»òÕßÐèÒªÏàʶ¸ü¶àµÄÐÅÏ¢£¬¿ÉÒÔËæÊ±Í¨¹ýÔÚ΢²©¡¢Î¢ÐÅÖÐËÑË÷¾ÅÓÎÀÏ¸ç¿Æ¼¼ÁªÏµ¾ÅÓÎÀϸ磬½Ó´ýÄúµÄ´¹Ñ¯£¡

¾ÅÓÎÀϸçÔÆ





