·½³Ìʽ×éÖ¯×ß©´ó×ÚÕë¶ÔWindows¹¥»÷¹¤¾ßÍþв
2017-04-15
±±¾©Ê±¼ä4ÔÂ14ÈÕÍí¼ä£¬Shadow Brokers×éÖ¯Ðû²¼ÁË´ËǰÇÔÈ¡µÄ²¿·Ö·½³Ìʽ£¨Equation Group£©×éÖ¯µÄÉñÃØÎļþ¡£Õⲿ·Ö±»¹ûÕæµÄÎļþÒ»¾±»Shadow Brokers×éÖ¯ÒÔÊýÒÚÃÀ½ðÅÄÂô£¬ÓÉÓÚÕⲿ·ÖÎļþ°üÀ¨ÁËÊý¸öÁîÈËÕ𺳵ĺڿ͹¤¾ß£¬ÓÃÀ´¹¥»÷°üÀ¨WindowsÔÚÄڵĶà¸öϵͳÎó²î¡£´Ë´Î×ß©µÄÎļþ°üÀ¨Èý²¿·Ö£ºWindows SwiftÒÔ¼°Odd¡£
ÆäÖÐWindowsĿ¼Ïµĺڿ͹¤¾ß°üÀ¨ÁËIIS 6.0Ô¶³ÌÎó²îµÄʹÓã»SMB1µÄÖØÁ¿¼¶Ê¹Ó㬿ÉÒÔÓÃÀ´¹¥»÷¿ª·ÅÁË445¶Ë¿ÚµÄWindowsϵͳ²¢ÇÒÌáȨ£»RDP·þÎñÔ¶³ÌÎó²îµÄʹÓ㬿ÉÒÔ¹¥»÷¿ª·ÅÁË3389¶Ë¿ÚµÄWindows»úеµÈµÈ¡£¿ª·ÅÁË1354453389µÈ¶Ë¿ÚµÄWindows·þÎñÆ÷ÓкܻòÐíÂÊÊܵ½¹¥»÷¡£
·½³Ìʽ×éÖ¯Ìý˵ÊÇÃÀ¹ú¹ú¼ÒÇå¾²¾Ö(NSA)ÏÂÊôµÄÒ»¸öºÚ¿Í×éÖ¯£¬ÓµÓÐ×ų¬¸ßµÄÊÖÒÕÒÔ¼°´ó×ںڿ͹¤¾ß¡£Õâ´Î×ß©³öÀ´µÄÎó²î¹¥»÷¹¤¾ßÁýÕÖÁËÈ«Çò¾ø´ó²¿·ÖµÄWindows·þÎñÆ÷£¬ÇÒÈκÎÈ˾ù¿ÉÒÔÏÂÔØÖ±½ÓʹÓ㬿ÉÊÇ΢Èí£¨Microsoft£©¹Ù·½Ò²Ëæ¼´ÔÚ±±¾©Ê±¼ä15ÈÕÐû²¼Í¨¸æ£¬ÌåÏÖÕë¶ÔWindowsϵͳµÄ¹¥»÷ÒѾ´ó²¿·ÖÔÚ֮ǰµÄϵͳÉý¼¶²¹¶¡Öнâ¾ö¡£
Ïà¹ØµØµã£º
https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation
https://www.bleepingcomputer.com/news/security/shadow-brokers-release-new-files-revealing-windows-exploits-swift-attacks/
https://zhuanlan.zhihu.com/p/26375989?utm_medium=social&utm_source=wechat_timeline&from=groupmessage&isappinstalled=0
https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/
×ß©ÎļþÈçÏ£º

ÊÜÓ°ÏìµÄ°æ±¾
±¾´Îй¶µÄ¹¥»÷¹¤¾ßʹÓÃÁË´ó×ÚWindowsÎó²î£¬ÏêϸӰÏì°æ±¾Çëµã»÷ºóÃæ¸÷Îó²îÏêϸÐÅÏ¢Éó²é¡£
²»ÊÜÓ°ÏìµÄ°æ±¾
±¾´Îй¶µÄ¹¥»÷¹¤¾ßʹÓÃÁË´ó×ÚWindowsÎó²î£¬ÏêϸӰÏì°æ±¾Çëµã»÷ºóÃæ¸÷Îó²îÏêϸÐÅÏ¢Éó²é¡£
΢Èí¹Ù·½·À»¤¼Æ»®
΢ÈíMSRCÔÚ±±¾©Ê±¼ä15ÈÕÏÂÖçÐû²¼µÄÊÓ²ìЧ¹ûÏÔʾ£¬´Ë´Î×ß©µÄÕë¶ÔWindowsµÄ¹¥»÷Öоø´ó²¿·ÖÒѾÔÚ֮ǰµÄϵͳÉý¼¶²¹¶¡ÖÐÐÞ¸´£¨ÈçÏÂͼËùʾ£©£¬Ê£ÓàµÄ¹¥»÷¹¤¾ß£¨¡°EnglishmanDentist¡± ¡°EsteemAudit¡± and ¡°ExplodingCan¡±£©Ò²Ö»Ó°Ïì΢Èí²»ÔÙÖ§³ÖµÄ°æ±¾¡£
ÖµµÃ×¢ÖØµÄÊÇÔÚ3Ô·ݸոÕÐû²¼µÄMS17-010²¹¶¡£¬¸Ã²¹¶¡ÐÞ¸´ÁË3¸öÖØ´óµÄSMBÔ¶³ÌʹÓÃÎó²î£¬ÇëÓû§¾¡¿ìÏÂÔØÉý¼¶ÖÁа汾¡£
½¨ÒéÓû§½«Êܵ½Ó°ÏìµÄϽµµÍ¢¼´Éý¼¶µ½ÐµĹٷ½Ö§³Ö°æ±¾¡£
²Î¿¼Á´½Ó£º
https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/
ÔÝʱ·À»¤¼Æ»®
ÈôÊÇÓû§ÔÝʱδ±ãÉý¼¶Ïà¹ØÏµÍ³£¬¿ÉÒÔ½ÓÄÉÒÔÏÂÔÝʱ·À»¤ÒªÁ죺
- ƾ֤×îС»¯ÔÔò¿ª·Å·þÎñÆ÷¶Ë¿Ú£¬ÔÝʱ¹Ø±Õ135137139445Óë3389µÈ·þÎñ¶Ë¿Ú£¬ÇÒÔÚ·ÇÐëÒªµÄÇéÐÎϹرն˿ڶÔÓ¦µÄ·þÎñ¡£
- ÑÏ¿áÏÞÖÆ¿ÉÐÅIP¹ØÓÚÖ÷Òª·þÎñÆ÷µÄ»á¼û¡£
×¢£ºÓÉÓÚ´Ë´ÎÉæ¼°µÄÎó²îÊýÄ¿Öڶ࣬ÆÊÎöÆðÀ´½ÏÖØ´ó£¬Ïà¹ØµÄ¹æÔòÓë²å¼þ°²ÅÅËÙÂʽÏÂý£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Çå¾²ÍŶӽ¨ÒéÊÜÓ°ÏìµÄÓû§Á¬Ã¦Éý¼¶µ½×îеĹٷ½Ö§³Ö°æÔÀ´¹æ±ÜÕâЩÎó²î¹¥»÷¡£
¸½Â¼
Ïà¹Ø¶Ë¿Ú˵Ã÷£º
135£º
135¶Ë¿ÚÖ÷ÒªÓÃÓÚʹÓÃRPC£¨Remote Procedure Call£¬Ô¶³ÌÀú³ÌŲÓã©ÐÒé²¢ÌṩDCOM£¨ÂþÑÜʽ×é¼þ¹¤¾ßÄ£×Ó£©·þÎñ£¬Í¨¹ýRPC¿ÉÒÔ°ü¹ÜÔÚһ̨ÅÌËã»úÉÏÔËÐеijÌÐò¿ÉÒÔ˳ËìµØÖ´ÐÐÔ¶³ÌÅÌËã»úÉϵĴúÂ룻ʹÓÃDCOM¿ÉÒÔͨ¹ýÍøÂçÖ±½Ó¾ÙÐÐͨѶ£¬Äܹ»¿ç°üÀ¨HTTPÐÒéÔÚÄڵĶàÖÖÍøÂç´«Êä¡£
137£º
137¶Ë¿ÚµÄÖ÷Òª×÷ÓÃÊÇÔÚ¾ÖÓòÍøÖÐÌṩÅÌËã»úµÄÃû×Ö»òIPµØµãÅÌÎÊ·þÎñ£¬Ò»Ñùƽ³£×°ÖÃÁËNetBIOSÐÒéºó£¬¸Ã¶Ë¿Ú»á×Ô¶¯´¦ÓÚ¿ª·Å״̬¡£137¶Ë¿ÚÊôÓÚUDP¶Ë¿Ú£¬Ê¹ÓÃÕßÖ»ÐèÒªÏò¾ÖÓòÍø»ò»¥ÁªÍøÉϵÄij̨ÅÌËã»úµÄ137¶Ë¿Ú·¢ËÍÒ»¸öÇëÇ󣬾ͿÉÒÔ»ñÈ¡¸ÃÅÌËã»úµÄÃû³Æ¡¢×¢²áÓû§Ãû£¬ÒÔ¼°ÊÇ·ñ×°ÖÃÖ÷Óò¿ØÖÆÆ÷¡¢IISÊÇ·ñÕýÔÚÔËÐеÈÐÅÏ¢¡£
139£º
139 NetBIOS File and Print Sharing ͨ¹ýÕâ¸ö¶Ë¿Ú½øÈëµÄÅþÁ¬ÊÔͼ»ñµÃNetBIOS/SMB·þÎñ¡£Õâ¸öÐÒé±»ÓÃÓÚWindows¡±ÎļþºÍ´òÓ¡»ú¹²Ïí¡±ºÍSAMBA¡£ÔÚInternetÉϹ²Ïí×Ô¼ºµÄÓ²ÅÌÊÇ¿ÉÄÜÊÇ×î³£¼ûµÄÎÊÌâ¡£
445£º
445¶Ë¿ÚÒ²ÊÇÒ»ÖÖTCP¶Ë¿Ú£¬¸Ã¶Ë¿ÚÔÚwindows 20XX ServerϵͳÖÐʩչµÄ×÷ÓÃÓë139¶Ë¿ÚÊÇÍêÈ«ÏàͬµÄ¡£ÏêϸµØËµ£¬ËüÒ²ÊÇÌṩ¾ÖÓòÍøÖÐÎļþ»ò´òÓ¡»ú¹²Ïí·þÎñ¡£²»¹ý¸Ã¶Ë¿ÚÊÇ»ùÓÚCIFSÐÒ飨ͨÓÃÒòÌØÍøÎļþϵͳÐÒ飩ÊÂÇéµÄ£¬¶ø139¶Ë¿ÚÊÇ»ùÓÚSMBÐÒ飨·þÎñÆ÷ÐÒé×壩¶ÔÍâÌṩ¹²Ïí·þÎñ¡£Í¬ÑùµØ£¬¹¥»÷ÕßÓë445¶Ë¿Ú½¨ÉèÇëÇóÅþÁ¬£¬Ò²ÄÜ»ñµÃÖ¸¶¨¾ÖÓòÍøÄÚµÄÖÖÖÖ¹²ÏíÐÅÏ¢¡£
3389£º
3389¶Ë¿ÚÊÇWindows 20xx ServerÔ¶³Ì×ÀÃæµÄ·þÎñ¶Ë¿Ú£¬¿ÉÒÔͨ¹ýÕâ¸ö¶Ë¿Ú£¬Óá±Ô¶³Ì×ÀÃæ¡±µÈÅþÁ¬¹¤¾ßÀ´ÅþÁ¬µ½Ô¶³ÌµÄ·þÎñÆ÷£¬ÈôÊÇÅþÁ¬ÉÏÁË£¬ÊäÈëϵͳÖÎÀíÔ±µÄÓû§ÃûºÍÃÜÂëºó£¬½«±äµÃ¿ÉÒÔÏñ²Ù×÷±¾»úÒ»Ñù²Ù×÷Ô¶³ÌµÄµçÄÔ£¬Òò´ËÔ¶³Ì·þÎñÆ÷Ò»Ñùƽ³£¶¼½«Õâ¸ö¶Ë¿ÚÐÞ¸ÄÊýÖµ»òÕ߹رա£
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬¾ÅÓÎÀÏ¸ç¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£¾ÅÓÎÀÏ¸ç¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾¾ÅÓÎÀÏ¸ç¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£

¾ÅÓÎÀϸçÔÆ







