找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1490|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。
0 s  B5 U! `( j" @" v+ e漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:( b- d9 F, o7 K0 K# G. l) c7 o
/ |% p( X( o9 s) c
1. SACL 法
& b) u& c5 j6 G  E[Unicode]
* v0 i7 Z) F3 Z' l6 oUnicode=yes. S# K: \8 o' |. j, M; t4 o
[Version]$ E5 G5 p* Q/ {* e) d# P/ i" h
signature="$CHICAGO$"
; a% p, d6 i1 @* H/ d; [  Q* ZRevision=1
* O2 y7 S' a/ r2 [; g[File Security]5 g1 D) r6 n4 H2 W+ V+ p
"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"
. G3 B1 o% d% h* v  D8 o, K- X: w
4 @; I- y/ O% v! [; C将以上内容保存为 BlockAccess_x86.inf
7 `& ?5 e: Y( ?# z* v; b& A然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>
. V9 w+ e- w9 i8 Q& z* Q其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。
& z$ [# T2 F7 _+ Q6 E  G, `7 C. K: b  }8 d! T0 ]  v4 V' ^& k
2. 禁用 Row Position 功能法
, U* Z+ K" ^& \9 n/ @' t" d- `5 `) k6 y

" Y9 y6 ]: L& f$ p1 B  cHKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29}
; E% x: _8 c# N6 k( m4 @. o打开注册表编辑器,将此键删除即可。
4 s2 K$ b. y7 ?3 r5 Z, i9 p# _
: n) t# N7 B* w/ Q; L3. 取消 DLL 注册法
% x: v' T! _. q2 ?$ s/ U
# H2 B1 P7 S& W! b在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"
1 o+ C4 B' y2 l  @0 ?即可) Q5 ?5 X3 U* H( C! p5 o* T

1 ~  C: q2 V2 z3 T" b8 P1 L4. 权限设置法- H; c% W: J  S# y

' }4 A# y  \# |% @/ U; a在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N
9 ^7 K0 x9 F# O3 N1 o* e
) \7 H! H6 c" i, b. zVista 系统则需要输入3个命令:8 r6 r, Z; C3 L$ ^3 K
( _( S( R6 g. i
takeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll"# P: V8 L. t5 ^7 j
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT. J  X2 Y0 G' t) J  G
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F)
: g4 n* p' }& `$ ]2 v( a# @4 b0 @6 @0 R% n0 R# d
其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。6 i- V) J: Q- U  T, u# ~. A1 k+ o

, e. s/ b2 q/ ?. }附:此漏洞影响的系统、软件列表
  U$ u: Y/ N/ N
0 f; F1 F' X1 O7 O& m4 ]; J+ jWindows Internet Explorer 7
9 w1 m* M8 x* t/ q$ O0 C, nWindows Internet Explorer 7 for Windows XP & A% l) P( L3 s
Windows Internet Explorer 7 for Windows Server 2003 7 H& R8 ~( P9 T: P/ P4 q% x9 h! Z
Windows Internet Explorer 7 for Windows Server 2003 IA64 5 L1 d; c9 u8 Q  d6 D+ V
Windows Internet Explorer 7 in Windows Vista 4 ]' O4 G) x2 L, N( c7 ~
Windows Internet Explorer 8 Beta
- e$ x: d9 J, p6 \' ]Microsoft Internet Explorer 6.0 Service Pack 2
& `; {! @( G+ N/ l2 }7 RMicrosoft Internet Explorer 6.0 Service Pack 1 , X; A0 h; ]5 S: n0 s+ t' S
Microsoft Internet Explorer 6.0 * D  z- ]( C& U" ?- d# Y
Microsoft Internet Explorer 5.01 Service Pack 4 6 L: u% b. F) L1 C' _! L
Windows Server 2008 Datacenter without Hyper-V 8 J* M0 f  m' j. h. ^
Windows Server 2008 Enterprise without Hyper-V
8 z$ n( _, E' A+ g3 g& S) `Windows Server 2008 for Itanium-Based Systems
; r' s" J! _. [1 ?Windows Server 2008 Standard without Hyper-V
$ \/ c1 D. M, w& P# {0 XWindows Server 2008 Datacenter / c7 p9 N% s- ]6 Y  z
Windows Server 2008 Enterprise
6 r( q: n9 @) M9 o* `: ZWindows Server 2008 Standard
/ f( D) b; a* K* n3 NWindows Web Server 2008 - }" ~3 R6 ^' N4 |' H6 ]8 ^
Windows Vista Service Pack 1, when used with: . O5 e# x. b& Z  ?7 p" k
Windows Vista Business
8 a# F1 m1 Q( r% i( d' J; e$ qWindows Vista Enterprise
1 T& b) S9 t# k3 U9 VWindows Vista Home Basic
/ @* O! k5 Z% Q  HWindows Vista Home Premium
  I! J4 s7 K2 n2 ~Windows Vista Starter * a! v" L% T. x0 Z: b' j, m
Windows Vista Ultimate / b( Q( G, Z- \! I" Y3 y3 }1 u
Windows Vista Enterprise 64-bit Edition
: `$ q5 Z, M# d) a' T: oWindows Vista Home Basic 64-bit Edition 5 ?" a- H$ i3 K. O0 p
Windows Vista Home Premium 64-bit Edition
8 ]3 y. k* a" C! a' K; p& ZWindows Vista Ultimate 64-bit Edition
, }* d+ q* Q. O; W! H- W7 R6 K$ x  `  ^Windows Vista Business 64-bit Edition 3 K" i2 O, a1 A) _% N! y. `" Z0 q, s
Microsoft Windows Server 2003 Service Pack 1, when used with:
2 E/ g. c7 v4 z# i5 w  \Microsoft Windows Server 2003, Standard Edition (32-bit x86)
; S" @6 w2 s3 \Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) 3 r$ Y" j% H8 S, Q& H/ c' S9 s
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
, s' p! ]* L6 b& v9 z0 h9 b. `/ H( m9 MMicrosoft Windows Server 2003, Web Edition
) |+ B3 S* P7 _0 w5 rMicrosoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- @( e( y8 D$ |. FMicrosoft Windows Server 2003, Enterprise Edition for Itanium-based Systems + J0 m: v5 Y" m: a5 R- P# s
Microsoft Windows Server 2003, Datacenter x64 Edition , a/ j, S6 j! C; C) }
Microsoft Windows Server 2003, Enterprise x64 Edition : W/ ]9 q+ f+ Q9 K4 \0 K
Microsoft Windows Server 2003, Standard x64 Edition
" r7 X; r' I& F! n: _7 tMicrosoft Windows XP Professional x64 Edition 1 y4 F) Y2 z+ ?8 k) [& I  @
Microsoft Windows Server 2003 Service Pack 2, when used with: 3 F! B  j. e% d' _: [
Microsoft Windows Server 2003, Standard Edition (32-bit x86) 0 L- J$ M- R6 k+ `; q- R; Q
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) 2 `1 U2 O5 ?9 |3 ~
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
3 U/ N' F: ]6 b2 YMicrosoft Windows Server 2003, Web Edition
' g# m' ~) }4 v. }) @4 u* _Microsoft Windows Server 2003, Datacenter x64 Edition
  n* @) Q0 H# m% \$ e) r& iMicrosoft Windows Server 2003, Enterprise x64 Edition , ^7 i! h  ]5 w4 E  h
Microsoft Windows Server 2003, Standard x64 Edition
; r  [$ h3 C# G: x2 ~3 g+ {# i* c5 MMicrosoft Windows XP Professional x64 Edition
1 |/ [0 f  k7 y! z) r  TMicrosoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
% v# V9 v+ s9 x' N. TMicrosoft Windows Server 2003, Enterprise Edition for Itanium-based Systems 1 J7 y0 M7 J" @- X
Microsoft Windows XP Service Pack 2, when used with: ) C% o7 h# U( d" g, d
Microsoft Windows XP Home Edition
" a, j* \- p; ?4 S8 h! GMicrosoft Windows XP Professional 3 s9 f9 G* V% e
Microsoft Windows XP Service Pack 3, when used with:   j2 y+ {7 X" x4 {" B
Microsoft Windows XP Home Edition 0 K! C# b9 S7 G
Microsoft Windows XP Professional
$ ]# X) I$ _1 s% f* {8 A3 `/ L对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息
2 E! U+ j! u: [; R9 A' R6 A0 IInternet Explorer 0day漏洞可能会愈演愈烈
+ D( n+ {, {; @    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.
1 n. Q7 Q3 ]( F( U8 C$ {7 U0 @8 ]! {0 o9 x6 m
    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.
% I2 W( N7 h' f( T" e' P: s
, ^% r, W) E4 S+ L    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加.
- o9 W; q$ ^; m) G& b9 @7 i( O# @3 I. l' o8 S
    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.4 _( J: @' X  Q

6 Y2 @+ D6 U8 c- b& W[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:' L3 O3 @" j: }
微软IE漏洞麻烦大 超过10000个站点被劫持3 W. {5 d1 t6 S  D" K6 I0 T* P
    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.
5 T, ^, T: G: K    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势.0 f  L# Q9 n% C) f3 F

; |, m5 p6 s7 t/ b2 _    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-8-26 16:48 , Processed in 0.015668 second(s), 4 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表