Latest Security News

讻诇讬 command 讞讬谞诪讬 诇讘讬爪讜注 注讬讚讻讜谞讬 windows update


讘砖讬讟讜讟讬诐 讛讗讞专讜谞讬诐 讘专砖转 谞转拽诇转讬 讘讻诇讬 诪注讜诇讛 讛谞拽专讗- WuInstall1_1 诪讞讘专转 xeox
讛讻诇讬 讻转讜讘 讘 C++ 讜诪讗驻砖专 砖讬诪讜砖 讘 windows updateAPI 诇讘讚讬拽转 注讚讻讜谞讬诐 诇讛诐 讛转讞谞讛 讝拽讜拽讛
讛讗驻砖专讜讬讜转 讛诐 专讘讜转 讜讻讜诇诇讜转 :
讞讬驻讜砖 讘诇讘讚
讛转拽谞讛
讛转拽谞讛+REBOOT
讘谞讜住祝 拽讬讬诪讜转 讗驻砖专讬讜讬讜转 诇讞讬驻讜砖 注讚讻讜谉 诪住讜讬讬诐 讗讜 诇驻讬 住讜讙 讛注讚讻讜谉 (SOFTWARE,DRIVERS 讜讻讚讜诪讛).
讛讻诇讬 驻讜谞讛 诇驻讬 讛讛讙讚专讜转 讘转讞谞讛 诇 WSUS 讗讜 诇砖专转讬 WINDOWS UPDATE 讘讛转讗诪讛.

讛讙专住讛 讘转砖诇讜诐 讻讜诇诇转 驻讬爪'专讬诐 谞讜住驻讬诐
诪注讬讬讜 apt-get 拽讟谉 诇注讬讚讻讜谞讬 讞诇讜谞讜转.
诪诪诇讬抓 讘讞讜诐 诇砖讬诇讜讘 讘住拽讬驻讟讬诐 .
诇讛讜专讬讚 诪讻讗谉

OWASP 2010 TOP 10

诇爪驻讬讛 -

The new OWASP Top Ten can be seen below:

A1 – Injection
A2 – Cross Site Scripting XSS
A3 – Broken Authentication and Session Management
A4 – Insecure Direct Object References
A5 – Cross Site Request Forgery (CSRF
A6 – Security Misconfiguration(NEW
A7 – Failure to Restrict URL Access
A8 – Unvalidated Redirects and Forwards (NEW
A9 – Insecure Cryptographic Storage
A10 – Insufficient Transport Layer Protection

METASPLOIT 3.3 RELEASED!

诇讛讜专讚讛:
http://www.metasploit.com/

UserAssist - 讻诇讬 谞讜住祝 讜讟讜讘 诇 FORENSIC WINDOWS


UserAssist
explorer 砖讜诪专 讗转 专砖讬诪转 讛转讜讻谞讜转 砖讛讜专爪讜 注诇 讛诪讞砖讘 讘 KEY - UserAssist 讘 REGISTRY
讛转讜讻谞讛 讬讜讚注转 诇驻注谞讞 讗转 讛谞转讜谞讬诐 讜诇讛爪讬讙诐 讘讟讘诇讛 诇驻讬 住讚专 讛讛专爪讛 讗讜 讻诇 住讚专 讗讞专 砖谞专爪讛.

诇讗 驻注诐 讗讞转 谞讬砖讗诇转讬 讘诪讛诇讱 注讘讜讚转讬 砖讗诇讛 讻诪讜 :" 讛讗诐 讗转讛 讬讻讜诇 诇讛讙讬讚 诇讬 诪讛 讛注讜讘讚 注砖讛 注诇 讛诪讞砖讘 讘转讗专讬讱 X ?" - 讛转讜讻谞讛 讛讝讗转 讛讬讗 注讜讚 讻诇讬 注讝专 讞砖讜讘 诇谞住讬讜谉 诪注谞讛 注诇 砖讗诇讛 讻讝讗转 .
诇讛讜专讚讛:

* 讛转讜讻谞讛 诪讞讬讬讘转 dot net 2
* 讛转讜讻谞讛 诪讗驻砖专转 拽专讬讗转 拽讜讘抓 REG 诪讬讜讘讗 诪诪讞砖讘 讗讞专.(COOL!)

讛讗讬讜诐 讛驻谞讬诪讬 - 讛讙讚专讛 讜讚专讻讬诐 诇讛转诪讜讚讚讜转

讛讙讚专讛 : 注讜讘讚 诪讜注住拽 讗讜 诪讜注住拽 诇砖注讘专 , 砖讜转祝 注住拽讬 谞讜讻讞讬 讗讜 诇砖注讘专 砖讬砖 讗讜 砖讛讬讛 诇讜 讙讬砖讛 诇诪注专讻讜转 讛诪讬讚注 砖诇 讛讞讘专讛 ,讜讘讬爪注 讘讻讜讜谞转 讝讚讜谉 砖讬诪讜砖 诇专注讛,砖讬讘讜砖,诪讞讬拽讛 讜讻讜 讘诪讬讚注 .

讛讛讙讚专讛 讛讜专讞讘讛 诇讗讞专讜谞讛 讙诐 诇砖讜转驻讬诐 注住拽讬讬诐,住驻拽讬诐 讜讻讜 讘砖诇 讛谞讟讬讬讛 讛讛讜诇讻转 讜讙讜讘专转 砖诇 讛讜爪讗转 转讛诇讬讻讬诐 讜转诪讬讻讛 讘诪注专讻讜转 讛诪讬讚注 诇诪讬拽讜专 讞讜抓 ( outsourcing ) , 讛讞诇 讘讞讬讘讜专讬诐 诇爪讜专讱 转诪讬讻讛 讘诪注专讻讜转 诪专讻讝讬讜转 讻讙讜谉WEB ,DATABASES,STORAGE 讜讻诇讛 讘讛讜爪讗转 拽诪驻讬讬谞讬诐 , DATA MINING 讜诪砖讬诪讜转 讗讞专讜转 诇讞讘专讜转 爪讚 砖诇讬砖讬 讜住驻拽讬诐.

讗专讙讜谉 CERT 讛讗诪专讬讗讬 注专讱 诪讞拽专 诪拽讬祝 讛讞诇 诪 1996 讜注讚 讛讬讜诐 讜谞讬转讞 拽专讜讘 诇 300 诪拽专讬诐 砖诇 讛转拽驻讜转 注"讬 讙讜专诪讬诐 讛诪讜讙讚专讬诐 驻谞讬诪讬讬诐.

诇讛诇谉 讞诇拽 诪讛诪住拽谞讜转 砖讛讙讬注讜 讗诇讬讛诐:

谞讬转谉 诇讞诇拽 讗转 讛讛转拽驻讜转 诇砖诇讜砖 拽讟讙讜专讬讜转 诪专讻讝讬讜转:

  1. 讞讘诇讛 - 讘诪拽专讬诐 讗诇讜 讛转讜拽祝 诪注讜谞讬讬谉 诇讙专讜诐 谞讝拽 诇讗专讙讜谉 讗讜 诇讗讚诐 讘讗专讙讜谉, 诪讞讬拽转 诪讬讚注 , 讛讜专讚转 诪注专讻讜转 ,讜讛驻专注讛 诇讗讜驻专爪讬讛 讛谞讜专诪诇讬转 讘讗专讙讜谉 - 诪转讜讱 300 - 讻 100 诪讜讙讚专讜转 讻谞住讬讜谉 讞讘诇讛.
  2. 讙谞讘转 拽谞讬讬谉 专讜讞谞讬- 讘诪拽专讬诐 讗诇讜 讛转讜拽祝 讙讜谞讘 住讜讚讜转 讞讘专讛,转讜讻谞讬讜转 讞讘专讛,拽讜讚 驻讬转讜讞,转讜讻谞讬讜转 讗住讟专讟讙讬讜转 讜讻讜 . 讻 40 诪转讜讱 讛 300 诪讜讙讚专讬诐 讻讙谞讘转 拽谞讬讬谉 专讜讞谞讬.
  3. 讙谞讬讘讛 讗讜 讟讬驻讜诇 讘诪讬讚注 诇爪讜专讱 专讜讜讞 讻住驻讬 - 讘拽讟讙讜专讛 讝讜 谞讻诇诇讬诐 讙谞讬讘转 讗讜 砖讬谞讜讬 驻专讟讬诐 讗讬砖讬讬诐 , 讻专讟讬住讬 讗砖专讗讬 讜讻讜 诇爪讜专讱 诪讻讬专讛 砖诇 讛诪讬讚注 讘砖诇讘 诪讗讜讞专 讬讜转专 , 讘专讜讘 讛诪拽专讬诐 讛转讜拽祝 讛驻谞讬诪讬 诪拽讘诇 转砖诇讜诐 注"讬 讙讜专诐 讞讬爪讜谞讬 诇讘讬爪讜注 讛注讘专讛. 讻 106 诪拽专讬诐 讛诐 诪住讜讙 讝讛 .
  4. MISC - 讻 46 诪拽专讬诐 讘讛谉 讗讬谉 诪住驻讬拽 专讗讬讜转 讗讜 诪讬讚注 诇砖讬讬讱 讗转 讛讛转拽驻讛 诇讗讞转 诪讛拽讟讙讜专讬讜转.

讻诪讜讘谉 砖讞诇拽 诪讛诪拽专讬诐 诪转驻专住讬诐 注诇 讻诪讛 拽讟讙讜专讬讜转 讘讬讞讚.

50% 诪注讜讘讚讬诐 砖讘讬爪注讜 注讘讬专讜转 诪住讜讙 讝讛 讛讞讝讬拽 讘诪砖专讛 讟讻谞讬转 讘讗专讙讜谉.

谞拽讜讚讜转 讞砖讜讘讜转 讘讗讘讟讞转 诪讬讚注 砖注诇讜 诪讛诪拽专讬诐 .

  • 讘专诪转 谞讬讛讜诇 讛住讬讻讜谞讬诐 - 讬砖 诇讛专讞讬讘 讗转 诪注讙诇 讛讗讘讟讞讛 砖讬讻诇讜诇 讗转 讻诇 拽讘诇谞讬 讛诪砖谞讛,谞讜转谞讬 讛转诪讬讻讛,讜住驻拽讬诐 讞讬爪讜谞讬讬诐 讘注诇讬 讙讬砖讛 诇诪讬讚注 讗讬专讙讜谞讬 - 讛拽砖讞转 讜讛讙讘诇转 讛讙讬砖讛 诇诪砖讗讘讬诐 注"讬 讙讜专诪讬诐 讗讬诇讜,谞讬讟讜专 讜诪注拽讘 讻讻诇 讛谞讬转谉 诇驻注讜诇讜转 讛谞注砖讜转 注"讬 讛讙讜专诪讬诐 讛讞讬爪讜谞讬讬诐 讘转讜讱 讛讗专讙讜谉 讜讻谉 谞讬转讜拽 诪讬讚讬 砖诇 讛拽讘诇谉 讘转讜诐 讛注住拽转讜 注砖讜讬讬诐 诇诪谞讜注 讛转拽驻讜转 讚专讱 讙讜专诪讬诐 讗诇讜
  • need to know bases - 谞讬转讜讞 讛诪拽专讬诐 诪注诇讛 砖讘专讜讘 讛诪拽专讬诐 讛转讜拽祝 拽讬讘诇 讛专砖讗讜转 讙讬砖讛 讙讘讜讛讜转 讘讛专讘讛 诪诪讛 砖讛讬讛 爪专讬讱 诇注讘讜讚转讜 , 讘讗讞讚 诪讛诪拽专讬诐 诪爪讜讬讬谉 讻讬 讗讬砖 诪讻讬专讜转 讛爪诇讬讞 诇讙谞讜讘 拽讜讚 诪拽讜专 砖诇 诪讜爪专 讜讝讗转 诪讻讬讜讜谉 砖讛讬转讛 诇讜 讛专砖讗讛 诇住驻专讬讛 砖讛讬讻讬诇讛 拽讜讚 讝讛 .讛讙讘诇转 讛讛专砖讗讜转 诇爪专讻讬 注讘讜讚讛 讛讬转讛 诪讜谞注转 诪拽专讛 讝讛.
  • 讛驻专讚转 专砖讜讬讜转 - 驻讬爪讜诇 驻注讜诇讜转 拽专讬讟讬讜转 诇讙讜专诐 诪讗砖专 讜讙讜专诐 诪讘爪注 - 讘讞拽讬专转 讛诪拽专讬诐 讛转讙诇讛 讻讬 诇诪专讜转 砖讛驻专讚讛 讝讜 拽讬讬诪转 ,讘诪拽专讬诐 专讘讬诐 讗讬谉 讗讻讬驻讛 讘讗诪爪注讬诐 讟讻谞讬讬诐 讜讙诐 讗诐 拽讬讬诪转 , 讛讬讗 诇讗 诪讘讜爪注转 谞讻讜谉. 讘专讜讘 讘诪拽专讬诐 讛驻专讚讜转 讗诇讜 拽讬讬诪讜转 讘注讬拽专 "注诇 讛谞讬讬专".
  • 讛驻专讚转 讜驻讬爪讜诇 讛专砖讗讜转 讘转讜讱 拽讘讜爪转 讛 system administrators - 诪讞拽讬专转 讛诪拽专讬诐 注诇讛 砖诇讗 讻诇 诪谞讛诇讬 讛专砖转 爪专讬讻诐 讙讬砖讛 诇谞讬讛讜诇 讻诇 讛专砖转 :) 讬砖 诇谞住讜转 诇讛驻专讬讚 讛专砖讗讜转 讙诐 讘转讜讱 讛拽讘讜爪讛 讛讝讗转 讚讜讙诪讗 诇诪讬拽专讛 砖讛讜讘讗 讛讬转讛 ,诪谞讛诇 专砖转 讝讜讟专 砖注诪讚 诇驻谞讬 驻讬讟讜专讬诐 讗讱 注讚讬讬谉 讛讬讛 讘注诇 讛专砖讗讜转 ADMIN 讙讜专驻讜转 讘讗专讙讜谉 - 讚讘专 砖讗驻砖专 诇讜 诇讞讘诇 讘砖专转讬诐 专讘讬诐 讜讻谉 诇诪讞讜拽 讗转 讛诇讜讙讬诐 注诇 驻注讬诇讜转 讝讜 讜讗祝 诇讻讜谞讜谞诐 砖讬爪讘讬注讜 注诇 讛诪谞讛诇 砖诇讜 讻讙讜专诐 讛讗砖诐.
  • 谞讬讛讜诇 讞砖讘讜谞讜转 讜讛专砖讗讜转 - 讛诪讞拽专 诪注诇讛 砖专讜讘 驻注讜诇讜转 讛讞讘诇讛 讛转讘爪注讜 诇讗讞专 讛驻讬讟讜专讬谉 讗讱 讘注讝专转 讛转讞讘专讜转 诇专砖转 砖讛讜讻谞讛 诪专讗砖 注"讬 讛注讜讘讚 . 讘讚专讱 讻诇诇 讛砖讬诪讜砖 讛讬讛 讘讞砖讘讜谞讜转 诪砖讜转驻讬诐 (诪砖转诪砖 讗驻诇讬拽讟讬讘讬)test,traning,sysadmin,dba 讜讻讜 ,讞砖讘讜谞讜转 砖拽砖讛 诪讗讚 诇讝讛讜转 诪讬 讘注爪诐 讛诪砖转诪砖 讛讗诪讬转讬 讛"诪住转转专 " 诪讗讞讜专讬讛诐. 讘诪讬拽专讬诐 专讘讬诐 诪谞讛诇讬 专砖转 讬爪专讜 讞砖讘讜谞讜转 砖谞专讗讜 诇爪专讻讬诐 诇讙讬讟讬诪讬讬诐 讗讱 诇诪注砖讛 砖讬诪砖讜 讗讜转诐 诇讛转讞讘专讜转 诪专讞讜拽 诇讗专讙讜谉 诇讗讞专 讛驻讬讟讜专讬谉.
  • 住讬住诪讗讜转 - 诪拽专讬诐 专讘讬诐 讛专讗讜 讻讬 诪砖转诪砖讬诐 讛注讘讬专讜 讘讬谞讛诐 住住诪讗讜转 讘讻讚讬 诇讞住讜讱 讝诪谉 讜诇讘讟诇 讗转 讛爪讜专讱 讘讙讜专诐 讗讞讚 诪讗砖专 讜讗讞讚 诪讘爪注 .
  • 住讬住诪讗讜转 讞诇砖讜转 - 讘诪拽专讬诐 专讘讬诐 诪谞讛诇讬 专砖转 讜讙讜专诪讬诐 讗讞专讬诐 讛专讬爪讜 PASSWORD CRACKERS 讜驻专爪讜 诇讞砖讘讜谞讜转 讜诇拽讘爪讬诐 诪讜讙谞讬 住讬住诪讛 诇爪讜专讱 讙谞讬讘转 讛专砖讜诪讜转.讞诇拽 诪讛讞砖讘讜谞讜转 砖谞驻专爪讜 砖讬诪砖讜 诇讛诐 诇讗讞专 讛驻讬讟讜专讬诐 讚专讱 诇讛转讞讘专 诇讗专讙讜谉.
  • auditing and log mamagment - 讘诪拽专讬诐 专讘讬诐 谞专讗讜 讙讬砖讛 诇砖专转讬诐 专讙讬砖讬诐 讜讛讜专讚转 downloads 讻诪讜转 讙讚讜诇讛 砖诇 拽讘爪讬诐 ,驻专讟 诪注谞讬讬谉 谞讜住祝 讛讜讗 砖专讜讘 讛驻注讜诇讜转 诪住讜讙 讝讛 谞注砖讜 讘讞诇讜谉 讝诪谉 砖诇 3-1 讞讜讚砖讬诐 诇驻谞讬 驻讬讟讜专讬 注讜讘讚 讗讜 讛转驻讟专讜转 - 讘讚讬拽讛 砖诇 转讘谞讬讜转 讻讗诇讜 讬讻讜诇讜转 诇注讝讜专 讘讙讬诇讜讬 诪拽专讬诐 砖诇 驻注讜诇讛 驻谞讬诪讬转.
  • 讞砖讬讘讜转 砖讬转讜祝 驻注讜诇讛 讘讬谉 诪讞诇拽讜转 讻讜讞 讗讚诐 , IT ,诪谞讛诇讬诐, 讜讛讘注诇讬诐 砖诇 讛诪讬讚注 - 讞拽讬专转 讛诪拽专讬诐 诪注诇讛 砖诇讗 讚讬 讘讗诪爪注讬 IT ( 讟讻谞讬讬诐) 讘诇讘讚 诇讝讬讛讜讬 驻砖注 讛讛讜诇讱 诇讛讬转讘爪注 讗诇讗 讞讬讬讘 砖讬转讜祝 驻注讜诇讛 注诐 诪讞诇拽讜转 讻讜讞 讗讚诐 讜讘注诇讬 讛诪讬讚注 注爪诪讜 讛讬讜讚注讬诐 诇诪讬 讛爪讜专讱 讘诪讬讚注 讜诇诪讬 诇讗 讘讛转讗诪讛 诇讙讜专诪讬诐 讻讙讜谉 驻讬讟讜专讬诐, 诪讬专诪讜专 讘注讘讜讚讛 讜讻讜.

FYI

讛拽砖讞讜转 SSL 讘砖专转讬 IIS

转拽谉 PCI 讜转拽谞讬诐 谞讜住驻讬诐 诪讞讬讬讘讬诐 讛拽砖讞转 诪谞讙谞讜谉 讛 SSL HTTPS .
讛转拽谉 诪讞讬讬讘 - 讘讬讟讜诇 转诪讬讻讛 诇讗讞讜专 讘 ssl v 2 讜讛拽砖讞转 讗诇讙讜专讬转诐 讛讛爪驻谞讛 .
讛讛拽砖讞讛 诪转讘爪注转 讘 REGISTRY 砖诇 砖专转 讛 IIS 讜谞讬转谞转 诇讘讚讬拽转 注"讬 讻诇讬 砖诇 FOUND STONE = SSLDIGGER

http://stdout-dev-null.blogspot.com/2006/02/disable-ssl2-and-weak-ciphers-in-iis.html

讛砖讬谞讜讬讬诐:


Windows Registry Editor Version 5.00


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Server]

"Enabled"=dword:ffffffff[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server]

"Enabled"=dword:ffffffff[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server]

"Enabled"=dword:ffffffff





Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 128/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128]

"Enabled"=dword:ffffffff[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 64/128]

"Enabled"=dword:00000000[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168]

"Enabled"=dword:ffffffff







Security Event log logon/off 转讬讝讻讜专转

诪讚讬 驻注诐 , 讗谞讬 谞拽专讗 诇讚讙诇 讘讻讚讬 诇驻注谞讞 驻注讬诇转 转讞谞讛 讗讜 诪砖转诪砖 讘专砖转 .
讻讞诇拽 诪讛讘讚讬拽讜转 讛专讘讜转 砖讗谞讬 诪讘爪注 , 讗谞讬 诪转讬讞讞住 讙诐 诇EVENT LOGS 讘转讞谞讛 讜讘 DC 诇讙讘讬 讗讬专讜注讬 LOGON\OFF
讗讱 诪转拽砖讛 诇讝讻讜专 讗转 讛 EVENT ID 讛专诇讜讜谞讟讬讬诐.
讗讝 讛谞讛 专砖讬诪讛 拽爪专讛 诇转讝讻讜专转 (xp 2000):
诇专砖讬诪讛 讛诪诇讗讛:
http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/Default.aspx

528 - Successful Logon
529 - Logon Failure - Unknown user name or bad password
530 - Logon Failure - Account logon time restriction violation
531 - Logon Failure - Account currently disabled
533 - Logon Failure - User not allowed to logon at this computer
534 - Logon Failure - The user has not been granted the requested logon type at this machine
535 - Logon Failure - The specified account's password has expired
536 - Logon Failure - The NetLogon component is not active
537 - Logon failure - The logon attempt failed for other reasons
538 - User Logoff
539 - Logon Failure - Account locked out
551 - User initiated logoff
552 - Logon attempt using explicit credentials
682 - Session reconnected to winstation
683 - Session disconnected from winstation

ZER0 DAY SMB V2

FYI
驻讬专爪转 讗讘讟讞转 讛转讙诇转 讘驻专讜讟讜拽讜诇 SMB V2 砖驻讜转讞 注"讬 诪讬拽专讜住讜驻讟 讜诪讬讜砖诐 讘 VISTA 讜 SERVER 2008

诇驻讬 砖注讛 讗讬谉 PATCH 讛诪转拽谉 讗转 讞讜专 讛讗讘讟讞讛 .
诪讬拽专讜住讜驻讟 诪爪讬注讛 诇讘讟诇 讗转 讛砖讬诪讜砖 讘驻专讜讟讜拽讜诇 讝讛 讜讗祝 诪住驻拽转 讻诇讬 ( FIXIT) 讛诪讘爪注 讝讗转 讗讜讟讜诪讟讬转 .
谞讬转谉 诇讜讛讜专讬讚 讗转 讛讻诇讬 讻讗谉:
http://blogs.technet.com/srd/archive/2009/09/18/update-on-the-smb-vulnerability.aspx

cve id:
CVE-2009-3103

FYI

FLASH SECRETS - 讻诇讬诐 诇讘讚讬拽转 ACTION SCRIPTS

砖讬讻诇讜诇 讟讻谞讜诇讜讙讬转 讛 FLASH 诪讗驻砖专讻讬讜诐 诇注砖讜转 讛专讘讛 诪注讘专 诇讛爪讙转 讙专驻讬拽讛 .讚驻讬 LOGIN , 讛驻谞讬讜转 ,讜砖讗专 讬专拽讜转 诪转讗驻砖专讜转 注"讬 砖讬诪讜砖 讘 ACTION SCRIPTS .
讘诪讞拽专讬诐 砖注砖讜 诪爪讗讜 砖讛砖讬诪讜砖 讘 AS 讛诪拽讜讚讚 HARDCODED 讘拽讜讘抓 讛 FLASH 讛讜讗 谞专讞讘 讜讻谉 专诪转 讛讗讘讟讞讛 讘讜 谞诪讜讻讛.
诪驻转讞讬诐 诪讟讘讬注讬诐 砖诪讜转 诪砖转诪砖讬诐 讜住住诪讗讜转,讜讻谉 讛驻谞讬讜转 诇讚驻讬诐 讞住讜讬讬诐 讘转讜讱 讛拽讜讚 讘讛谞讞讛 讻讬 讗讬谉 讚专讱 诇讘爪注 砖诇讬驻讛 砖诇 讛拽讜讚 诪转讜讱 讛拽讜讘抓.
讛讗诪谞诐?
诪住转讘专 砖讗驻砖专 讜讝讛 讗驻讬诇讜 拽诇 诇讞诇抓 ACTION SCRIPT 诪转讜讱 拽讜讘抓 SWF 讗讜 讻诇 驻讜专诪讟 FLASH 讗讞专.
谞讬转讜讞 砖诇 讛诪讬讚注 讛讝讛 诪讗驻砖专 诇谞讜 诇讛讘讬谉 驻讙讬注讜讬讜转 讘讗转专 讛谉 讘专诪转 讛 FLASH 注爪诪讜 讜讛谉 讘专诪转 讞砖讬驻转 驻专讟讬诐 谞讜住驻讬诐.

2 讻诇讬诐 讞讬谞诪讬讬诐 砖诪爪讗转讬 讞讬诇讜抓 讜谞讬转讜讞 AS

FOCA RC1- 讻诇讬 讞讚砖 诇讞讬诇讜抓 METADATA 诪诪住诪讻讬诐.


METADATA = 诪讬讚注 讛诪讜住祝 诇诪住诪讻讬诐 讜拽讘爪讬诐 注"讬 转讜讻谞讜转 注专讬讻讛 诇诪讟专讜转 砖讬诪讜砖 讛转讜讻谞讜转 注爪诪诐 .

讛诪讬讚注 讬讻讜诇 诇讛讻讬诇:
  • 转讗专讬讱 讜砖注讛 讘讛诐 谞讜爪专 讛诪住诪讱
  • 砖诐 讛诪转砖诪砖 砖讬爪专 讗转 讛诪住诪讱
  • 砖诐 讛诪讞砖讘 讗讜 讛砖专转 讛驻谞讬诪讬
  • 讻转讜讘讜转 讚讜讗专 讗诇拽讟专讜谞讬
  • 谞转讬讘讬诐 讛诪住诪讻讬诐
  • 砖诪讜转 诪讚驻住讜转

谞讬转谉 诇注砖讜转 砖讬诪讜砖 讘诪讬讚注 讝讛 讘砖诇讘 讗讬住讜祝 讛谞转讜谞讬诐 讘讛诇讬讱 讛 PENTEST 讜讘诪讬讜讞讚 讻砖诪讘爪注讬诐 BLACK BOX PENTEST.

FOCA - 讛讜讗 讻诇讬 讛诇讜拽讞 讗转 讛讙讬诇讜讬 讜讛谞讬转讜讞 砖诇讘 讗讞讚 拽讚讬诪讛,注"讬 讛讙讚专转 讛讚讜诪讬讬谉 砖讗讜转讜 讗谞讜 专讜爪讬诐 诇讞拽讜专 ,讛讜讗 诪讘爪注 讞讬驻讜砖 诇讻诇 住讜讙讬 讛诪住诪讻讬诐 讛诪讗讜专讻讘讬诐 讘诪谞讜注讬 讛讞讬驻讜砖 ,诪讜专讬讚 讗讜转诐 诇诪讞砖讘 讛诪拽讜诪讬 ,诪讘爪注 谞讬转讜讞 砖诇 讛METADATA 讜诪爪讬讙 讗讜转讜 诇驻讬 拽讟讙讜专讬讜转 ( users,printers'computer'email) 讜讻讜.



NMAP GUI 讞讚砖 诪讘讬转 K_ZEE


GUI 驻砖讜讟 讬注讬诇 讜谞讜讞 诇讛专爪转 NMAP 讛诪讻讬诇 驻专诪讟专讬诐 诇讛专爪转 砖诇 讛住专讬拽讜转 讛谞驻讜爪讜转 讜讻诇 讛住拽专讬驻讟讬诐 讛讞讚砖讬诐.
讻诪讜讘谉 砖讬砖 诇讛转拽讬谉 NMAP 讻讛转拽谞讛 专讙讬诇讛 诇驻谞讬 讛砖讬诪讜砖 讘 GUI

tiger team - Google Videos

讛专爪讗讛 诪注谞讬讬谞转 讘诪住讙专转 OWASP 砖诇 诪讬住讚 TIGER TEAM


讛拽讘讜爪讛 注讜住拽转 讘驻专讬爪讜转 诪砖讜诇讘讜转 讛谉 驻讬讝讬讬讜转 (讗讝注拽讜转 诪谞注讜诇讬诐 讜讻讜) 讜讛谉 讚专讱 诪讞砖讘.

metasploit 3.3 dev -client side attack

讘讛诪砖讱 诇驻讜住讟 诪讬讜诐 砖讘转 砖注讘专, 讘metasploit 讘讙专住讛 3.3 诪讗驻砖专 诇谞讜 讬讻讜诇讜转 "讬驻讜转" 诇讘讚讬拽转 讞讚讬专讜转 砖诇 转讞谞讜转 拽爪讛 讘讞讘专讛.讻讗砖专 讛讘讚讬拽讛 转讻诇讜诇:


  1. 转讞谞转 拽爪讛 讛讙讜诇砖转 诇讗转专 讝讚讜谞讬 讛诪谞住讛 诇讞讚讜专 讚专讱 驻讙讬注讜转 讘讚驻讚驻谉 讗讜 讘转讜住驻讬诐 砖讜谞讬诐.


  2. 诪住诪讻讬诐 讘驻讜专诪讟讬诐 砖讜谞讬诐 讛谞砖诇讞讬诐 讘诪讬讬诇 讜诪谞爪诇讬诐 驻讙讬注讜转 讘讗驻诇讬拽爪讬讜转 (WORD,PDF 讜讻讜).

讛讬讻讜诇讜转 讛讘讜诇讟讜转 讛诐:


  • 讬爪讬专转 拽讜讘抓 PDF 讗讜 DOC 讛诪讻讜讜谉 诇驻讙讬注讜转 讗驻诇讬拽讟讬讘讬转 讘讙专住讗讜转 讛转讜讻谞讛 讛砖讜谞讜转
  • 讛拽诪转 讗转专 讛诪讻讬诇 ACTIVE X 讛诪谞爪诇讬诐 驻讙讬注讜转 讛讚驻讚驻谉 讘专讻讬讘 讝讛.
讘讻讚讬 诇讛驻讜讱 讗转 讛讙专住讛 讛专讬砖诪讬转 诇讙专住转 DEV 讛诪讻讬诇讛 讗转 讻诇 讛讞讬讚讜砖讬诐 讛讗讞专讜谞讬诐 讬砖 诇讛讜专讬讚 SVN 诪
$ svn co http://metasploit.com/svn/framework3/trunk/
诇讗讞专 诪讻谉 讬砖 诇讛专讬抓 讗转 讛 CONSOLE 诪转讜讱 住驻专讬转 讛 TRUNK .
讘讻讚讬 诇讛讘讬谉 讻讬爪讚 诪拽讬诪讬诐 讗转专 讛诪谞爪诇 讗转 讛驻讙讬注讜讬讜转 讛谞"诇 - 住专讟 砖讜讜讛 讗诇抓 转诪讜谞讜转
爪驻讜 讘讻诇 讛住专讟讬诐 砖诇
讛诐 诪讻讬诇讬诐 讛住讘专 诪拽讬祝 讜讘讻诇诇 讛讞讘专讛 讛讗诇讛 注讜砖讬诐 注讘讜讚讛 讟讜讘讛..
讘讛爪诇讞讛.


CLIENT SIDE ATTACKS 讜转讞谞讜转 讛拽爪讛 讘讗专讙讜谉.

client silde attacks
拽专讗拽专讬诐 讘专讞讘讬 讛注讜诇诐 讛讘讬谞讜 诪讝诪谉 讻讬 讛讚专讱 讗诇 讛讗讜砖专 注讜讘专转 转诪讬讚 讚专讱 讛讞讜诇讬讛 讛讞诇砖讛 讘砖专R砖专转.
讗讜 讗诐 转专爪讜: KEYLOGGER = 1000 RAINBOW TABELS .
讘诪拽讜诐 诇讛砖拽讬注 砖讘讜注讜转 讘驻注谞讜讞 谞拽讜讚讜转 讛转讜专驻讛 砖诇 FW 讛讞讘专讛 ,讗讜 讗讬讝讛 讞讜专 讗讝讜讟专讬 讗讞专,
驻砖讜讟 讬讜转专 讝讛 诇砖讻谞注 讗转 讬讜住讬 诪讛讻住驻讬诐 诇诇讞讜抓 注诇 诇讬谞拽 转诪讬诐 讜诪砖诐 "讛诐" 讻讘专 讬注砖讜 讘砖讘讬诇讜 讗转 讛注讘讜讚讛.
讻诇 讝讛 讻诪讜 砖讗诪专转讬 - 讞讚砖讜转 讬砖谞讜转 讜讗讻谉 讞讘专讜转 诪砖拽讬注讜转 讛讬讜诐 讬讜转专 讘讛讙谞讛 注诇 讛诪砖转诪砖 讛驻砖讜讟 讘讞讘专讛 .
讗讘诇.. 注讚讬讬谉 谞讬爪讘讜转 讘驻谞讬 诪谞讛诇 讛专砖转 讘注讬讜转 谞讬讛讜诇 专讘讜转 讘转讞讜诐 诇讚讜讙诪讛:
  1. 谞讬讛讜诇 PATCHS MICROSOFT- 转讛诇讬讱 讗讟讬讬 讜诪转诪砖讱 , 讛讬讻讜诇转 "诇讬讬砖专 拽讜" 诪讜讙讘诇转 讜讻诇讬 讛谞讬讛讜诇 讛砖讜谞讬诐 WSUSE,BIGFIX 讜讻讜 注讜砖讬诐 注讘讜讚讛 讘讬谞讜谞讬转 诇讻诇 讛讬讜转专,讚专讬砖讜转 诇 RESTART 讜讛转谞讙砖讜转 注诐 讗驻诇讬拽爪讬讜转 拽讬讬诪讜转 IN HOUSE 讜砖讗专 讬专拽讜转. 讘拽讬爪讜专,诇讗 谞注讬诐 诇讘爪注 ROLLBACK 诇6000 转讞谞讜转 . 诪谞讛诇 专砖转 讛讙讬讜谞讬 讬转拽讬谉 专拽 讗转 讛讞诇拽 讛拽专讬讟讬 砖诇 讛注讚讻讜谞讬诐 讘诪拽专讛 讛讟讜讘 ,讬驻住讞 注诇 注讚讻讜谞讬 讛 OFFICE 讜注讚讻讜谞讬诐 "砖讜诇讬讬诐" 讗讞专讬诐 ( REBOOT 诇注讚讻讜谉 MEDIA PLAYR? 讛砖转讙注转诐?) . 讙诐 转讛诇讬讱 讛讟诪注转 注讚讻讜谞讬诐 讘 IMAGES 讞讚砖讬诐 砖诇 讛讞讘专讛 诪爪专讬讱 住讟 讘讚讬拽讜转 讜注讚讻讜谉 讞讜讚砖讬 -砖讜讘 转讜爪讗讜转 讘讬谞讜谞讬讜转 讜讞诇拽讬讜转 诇讻诇 讛讬讜转专.
  2. 注讚讻讜谞讬 讗驻诇讬拽爪讬讜转 讗讞专讜转- 讻诪讛 诪谞讛诇讬 专砖转 诪注讚讻谞讬诐 讗转 砖讗专 讛讗驻诇讬拽爪讬讜转 讛讛讻专讞讬讜转 讻讬讜诐 诇讙专住讛 讛讗讞专讜谞讛? ADOBE,WINZIP 讜讻讜 -诪注讟 诪讗讚.
  3. 谞讬讛讜诇 讞转讬诪讜转 注讚讻谞讬讜转 诇讗谞讟讬 讜讬专讜住.- 讙诐 讻讗谉 拽砖讛 诪讗讚 诇拽讘诇 诪讬拽砖讛 讗讞讚 讘专讞讘讬 讛讗专讙讜谉 , 转讞谞讜转 讘 OFFLINE ,谞讬讬讚讬诐 讛诪转讞讘专讬诐 讘 VPN 驻注诐 讘注砖讜专 , 讘注讬讜转 专砖转讬讜转 诪讜诇 砖专转 讛谞讬讛讜诇 讛诪专讻讝讬 ,砖讚专讜讙讬诐 讛驻讜讙注讬诐 讘 CLIENT 讜砖讜专讛 讗专讜讻讛 砖诇 EXELUDES .讙诐 讻讗谉 讬住转驻拽 诪谞讛诇 讛专砖转 讛讛讙讬讜谞讬 讘75% 讛爪诇讞讛.
  4. 讞住讬诪转 讛转拽谞讬诐 谞讬讬讚讬诐 - 讙诐 讻讗谉 讬讗诇抓 诪谞讛诇 讛专砖转 诇驻转讜讞 讞住讬诪讜转 诇讗谞砖讬 VIP 讘讞讘专讛,爪讜讜转讬诐 讟讻谞讬讬诐 砖讜谞讬诐 讜砖讗专 诪拽讜专讘讬诐.
  5. personnal filrewall? hips? - 拽砖讬诐 诪讗讚 诇谞讬讛讜诇 讜讛讟诪注讛 ,诪讬爪专讬诐 讙讬诇讜讬讬诐 砖讙讜讬讬诐 (FP) 讜诪讻讘讬讚讬诐 注诇 讛转讞谞讜转 讜注诇 讛注讘讜讚讛 讛砖讜讟驻转 砖诇 讛诪砖转诪砖讬诐.诪谞讛诇 讛专砖转 ,讙诐 讗诐 讬讟诪讬注 驻讬爪'专讬诐 讗诇讛 ,转讛讬讛 讝讜 讘专讜讘 讛诪拽专讬诐 讛讟诪注讛 讘诪讬谞讬诪讜诐 讛拽砖讞讛.
  6. 讛拽砖讞转 住住诪讗讜转,讞讬谞讜讱 诪砖转诪砖讬诐 ,讛讙谞讛 驻讬讝讬转,讛爪驻谞讜转 讜讻讜 - 讙诐 讻讗谉 拽讬讬诐 砖讬驻讜专 讻诪讜讘谉 讗讱 讛讚专讱 注讜讚 讗专讜讻讛.

讻诪讜 砖讗谞讜 专讜讗讬诐 - 转讞讜诐 讛讙谞转 转讞谞讜转 讛拽爪讛 讗诪谞诐 讛砖转驻专 讗讱 注讚讬讬谉 诇诇讗 住驻拽 诇讜拽讛 讘讞住专 .讛转拽驻讜转 讚专讱 转讞谞讜转 讛拽爪讛 讘讞讘专讛 讬谞讬讘讜 驻讬专讜转 讬驻讬诐 讜讘讗讞讜讝讬诐 讙讘讜讛讬诐 .

讘讻诇 讘讚讬拽转 讞讚讬专讜转 , 讗谞讬 诪诪诇讬抓 诇砖诇讘 讙诐 client side attacks .

讘驻讜住讟 讛讘讗 讗谞讬 讬讚讘专 注诇 metasploit 3.3 dev 讜讛砖讬驻讜专讬诐 讘讬讻讜诇讜转 诇讘爪注 讛转拽驻讜转 诪住讜讙 讝讛 讚专讻讛.

conficker - 诪谞讬注讛-讛讙谞讛-讙讬诇讜讬-谞讬拽讜讬

-拽讜谞驻讬拽专 讘驻注讜诇讛


...
讗讬讟讬讜转 讻讘讚讛 讘专砖转 讛驻谞讬诪讬转, 讙讬砖讜转 诪讜讝专讜转 诇讗讬谞讟专谞讟 讜砖专转讬诐 砖讞讚诇讜 诪诇转转 砖讬专讜转 谞讜r诪诇讬 .
讟诇驻讜谞讬诐 讘讛讜诇讬诐 诪讗谞砖讬 讛住讬住讟诐 讜讛转拽砖讜专转 讘讝诪谉 讗专讜讞转 讛爪讛专讬讬诐 砖诇讬 :" 注砖讬转诐 砖讬谞讜讬 讘砖专转 讛 AV?","讛驻爪转诐 讗讬讝讛 诪砖讛讜?"
讗谞讬 注讜谞讛 诪讬讚 砖诇讗, 讜诪住讬讬诐 讗转 讛讗专讜讞讛.
讘诪砖专讚 讗谞讬 谞讬讙砖 诇讘讚讜拽 诇讜讙讬诐 讘砖专转讬 讛AV - 讛讻诇 专讙讬诇,讗讱 讗谞讬 砖诐 诇讘 诇诪讬讬诇讬诐 讛诪转专讬注诐 注诇 住专讬拽转 驻讜专讟讬诐 讘SIM SOC 砖诇谞讜...讛诪诪 诪砖讛讜 诪讜讝专 拽讜专讛.
讘讬谞转讬讬诐 讗谞砖讬 讛住讬住讟诐 讻讘专 诪讜专讟讬诐 砖讬注专讜转 讜讗谞讬 诪谞住讛 诇讛讘讬谉 讗转 驻砖专 讛住专讬拽讜转 讛诪讜讝专讜转 讘转讜讱 讛专砖转 .
诪讞砖讘讬诐 诪谞住讬诐 诇爪讗转 诇讗讬谞讟专谞讟 讘驻讜专讟 80 讜诇讗 讚专讱 讛驻专讜拽住讬...讘注讬讬转 谞讬转讜讘? 转拽诇讛 讘讛讙讚专讜转 讛驻专讜拽住讬?
砖注讛 注讜讘专转 讜讛转诪讜谞讛 诪转讞讬诇讛 诇讛讬转讘讛专 ,转诪讜谞讛 注讙讜诪讛.
诪讞砖讘讬 讛讗专讙讜谉 住讜专拽讬诐 讗转 注爪诪诐 讜诇讻讬讜讜谉 住讙诪讟讬 讛砖专转讬诐 讘驻讜专讟 445 诇诇讗 讛驻住拽讛 ,讻诇 诪讞砖讘 驻讜转讞 讞讬讘讜专讬诐 诇驻讬 讬讻讜诇转讜
10 - ++1000 ,讞讙讬讙讛.
讛诇讞抓 诪讙讬注 诇专诪讜转 讞讚砖讜转 , 注讻砖讬讜 讝讛 讻讘专 讘专讜专 : 讗谞讬 注讚 诇讛转驻专爪讜转 讞讝拽讛 砖诇 讜讬专讜住 讘专砖转 .
讗谞讬 讘讜讚拽 砖讜讘 讜砖讜讘 讗转 讛诇讜讙讬诐 诪讛讗谞讟讬 讜讬专讜住讬诐 - 谞讗讚讛! 诪讛 讝讛!
讗谞砖讬 讛住讬住讟诐 讻讘专 诪爪讗讜 诇驻讞讜转 10 砖诪讜转 砖诇 讜讬专讜住讬诐 讛诪转讗讬诪讬诐 诇讛转谞讛讙讜转 讛讜讬专讜住 ,讗讘诇 讗祝 讗讞讚 诇讗 诪讜驻讬注 诇讬 注诇 讛诪住讱.
讗谞讬 诪转拽砖专 诇讗讞讚 诪诪讜诪讞讬 讛讜讬专讜住讬诐 讘讗专抓 砖转诪讱 讘讬 驻注诪讬诐 专讘讜转 讘注讘专 :"诪讛 拽讜专讛 讗讬砖, 讬砖 诇谞讜 讻讻讛 讜讻讻讛...".
讜讛讜讗 注讜谞讛 :" 讻谉 讗谞讬 谞诪爪讗 注讻砖讬讜 讘讗专讙讜谉 讬讜转专 讙讚讜诇 诪诪讻诐, 讙诐 讻讗谉 讛诪爪讘 讚讜诪讛 , 讝讛 讻谞专讗讛 ZERO DAY ATTACK"
-讗谞讞谞讜 爪专讬讻讬诐 诇讘讗 讜诇拽讞转 讘讬讜驻住讬讛 诪诪讞砖讘 谞讙讜注 讜诇砖诇讜讞 诇讞讘专转 讛讗谞讟讬 讜讬专讜住 砖讬讻转讘讜 诇讝讛 讞转讬诪讛."
诪讛讛讛! ZERO DAY?

讻讱 诇诪讚转讬 诇讛讻讬专 讗转 讜讬专讜住 讛拽讜谞驻讬拽专.

讛讙谞讛 -诪谞讬注讛

  • 讛转拽谞转 讛驻讗爪' 砖诇 诪讬拽专讜住讜驻讟 kb958644 讛诪讜谞注 讗转 讜拽讟讜专 讛讛转拽驻讛 讛诪专讻讝讬 讚专讻讜 讞讜讚专 讛拽讜谞驻讬拽专 诇转讞谞讛. - 诇讛讜专讬讚 讜诇讛转拽讬谉 讘讛拽讚诐 讛讗驻砖专 注诇 讻诇 讛砖专转讬诐 讜讛转讞谞讜转.

诇讘讚讬拽讛 诪讬讚讬转 砖诇 讛诪爪讗讜转 讛 PATCH 注诇 转讞谞讛 讛专讬爪讜:



systeminfo find"KB958644" a

诇讛讜专讚转 讛 PATCH:

http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

  • 讘讬讟讜诇 AUTORUN 诇讻诇 住讜讙讬讜 讘转讞谞讜转 讜讘砖专转讬诐 = 注爪讬专转 讜拽讟讜专 讛讛转拽驻讛 讛砖谞讬 砖诇 讛讜讬专讜住 ( 讛讚讘拽讛 讚专讱 讛转拽谞讬 USB 讜诪讚讬讜转 谞砖诇驻讜转 讗讞专讜转).

讛注转拽\讛讚讘拽 讗转 讛砖讜专讜转 讛讘讗讜转 诇拽讜讘抓 讘住讬讜诪转 REG. 讜讛专抓:

REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf] @="@SYS:DoesNotExist"

讻诪讜讘谉 诇讗 诇砖讻讜讞 诇注讚讻谉 GPO :)





  • 讘讬讟讜诇 砖讬转讜驻讬诐 讗讚诪讬谞讬住讟专讟讬讘讬讬诐 讻讻诇 讛谞讬转谉 讜诪注讘专 注诇 砖讬转讜驻讬诐 讘专砖转 转讜讱 爪讬诪爪讜诐 讛讛专砖讗讜转 讘讻诇 砖讬转讜祝. -讜拽讟讜专 讛讛讚讘拽讛 讛砖诇讬砖讬 砖诇 讛拽讜谞驻讬拽专 讛讜讗 讘讗诪爪注讜转 讙讬砖讛 诇砖讬转讜驻讬诐 讘讻诇诇 讜讘驻专讟 诇 admin$ ,诇爪注专讬 住注讬祝 讝讛 拽砖讛 诇讘讬爪讜注 讘砖诇 砖讬诪讜砖 讗驻诇讬拽讟讬讘讬 讘砖讬转讜驻讬诐 讛谞"诇 讗讱 谞讬转谉 诇爪诪爪诐 讗转 讛讛专砖讗讜转 诇砖讬转讜驻讬诐 讻讞诇拽 诪驻注讬诇讜转 砖讜讟驻转 砖诇 讗讘讟讞转 诪讬讚注. 讘诪拽专讬 拽讬爪讜谉 砖诇 讛讚讘拽讛 诪讗住讬讘讬转 ,谞讬转谉 诇讛驻注讬诇 讝诪谞讬转 驻讜谞拽爪讬讛 讛拽讬讬诪转 讘专讜讘 讛讗谞讟讬 讜讬专讜住讬诐 - make all shares read only (注"注 诪拽讗驻讬).




  • 讛讙讘诇讛 讗讜 诪谞讬注转 讛专砖讗讜转 诇住驻专讬转 TASKS 砖诇 windows - 讜专讬讗谞讟讬诐 诪住讜讬诪讬诐 砖诇 讛讜讬专讜住 讬讜爪专讬诐 JOB -诪砖讬诪讛 讛诪驻注讬诇讛 讗转 诪谞讙谞讜谉 讛讛讚讘拽讛 ,住讙讬专转 讛讛专砖讗讜转 诇住驻专讬讛 讝讜 转诪谞注 讝讗转.




  • 讬砖 诇讚讗讜讙 诇AV 诪注讜讚讻谉 讘讞转讬诪讜转 讜讘诪谞讜注 讛讗讞专讜谉 ,讬砖 诇住专讜拽 讗转 讛专砖转 讛讗专讙讜谞讬转 讘讗诪爪注讬诐 谞讜住驻讬诐 诇诪爪讬讗转 转讞谞讜转 讜砖专转讬诐 "住讜专专讬诐" 诇诇讗 AV 讗讜 AV 讘 DISABLE 讜\讗讜 诪讙讜谉 转拽诇讜转 讗讞专讜讜转.
讙讬诇讜讬:

  • 讛拽讜谞驻讬拽专 诪砖转诪砖 讘诪谞讙谞讜谉 住专讬拽讛 讜讛讚讘拽讛 讚讬 专注砖谞讬讬诐 讗砖专 谞讬转谉 诇讝讬讛讜讬 讘拽诇讜转 注"讬 IPS 讗讜 HIPS ,注讜诪住 讘专砖转 讬讜专讙砖 讘注讬拽专 讘驻讜专讟讬诐 445 讜 139 讜讻谉 讙讬砖转 诪讞砖讘讬诐 讜砖专转讬诐 诇讗讬谞讟专谞讟.


  • GMER - 讻诇讬 诇讘讚讬拽转 ROOTKITS 讜讛讝专拽转 DLL 诇services 诇讙讬讟讬诪讬讬诐 砖诇 讜讬谞讚讜住 - 讛拽讜谞驻讬拽专 诪讝专讬拽 讗转 注爪诪讜 (DLL) 诇 svchost ,讛讻诇讬 诪讝讛讛 讜诪爪讬讙 ( 讘讗讚讜诐) 讗转 讛砖讬专讜转 讛谞讙讜注 讜讗转 砖诐 讛 DLL 讛专诇讜谞讟讬 , 讛讜讗 诪讗驻砖专 讙诐 讛住专讛 砖诇 讛 DLL 讗讱 诪谞住讬讜谉 讛驻注讜诇讛 讙讜专专转 讘专讜讘 讛诪拽专讬诐 诪住讱 讻讞讜诇.


  • tasklist /svc ----讞讬驻讜砖 驻专讜住住讬诐 讛专爪讬诐 转讞转 scvhost 讜讝讬讛讜讬 驻专讜住住诪讬诐 讘砖诪讜转 诪讜讝专讬诐 讗讜 诇讗 诪讜讻专讬诐

svchost.exe 1068 AudioSrv, CryptSvc, Dhcp, dmserver, ERSvc, EventSystem, helpsvc, HidServ, lanmanserver,lanmanworkstation, Netman, Nla, RasMan,Schedule, seclogon, SENS, SharedAccess, ShellHWDetection, srservice, TapiSrv,Themes, TrkWks, W32Time, winmgmt, wscsvc,ddfr , wuauserv, WZCSVC



  • McAfee Conficker Detection Tool - 讻诇讬 讞讬谞诪讬 砖讬爪讗 讬讞住讬转 诇讗讞专讜谞讛 讛住讜专拽 转讞谞讜转 讜专砖转讜转 诇诪爪讬讗转 诪讞砖讘讬诐 谞讙讜注讬诐 讘拽讜谞驻讬拽专 , 讛讻诇讬 讬讜讚注 诇讝讛讜转 (finger print) 转讞谞讜转 谞讙讜注讜转 诇诇讗 爪讜专讱 讘讛讝讚讛讜转

讛住专讛 :

讘诪讬讚讛 讜讛AV 诪讝讛讛 ,讙诐 讗诐 讛讗讬谞讚讬拽爪讬讛 讛讬讗 : removed 讗讜 deleted , 讗谞讬 诪诪诇讬抓 诇讘爪注 REBOOT 讘讻讚讬 诇讗驻砖专 诇 AV 诇讛住讬专 砖讬讬专讬诐 讘讝讬讻专讜谉.

砖讬讛讬讛 讘讛爪诇讞讛.