找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1489|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。# u! M/ p/ h4 B! F9 X
漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:9 Q  f6 m9 o  m" O1 i5 a- }
' E' J4 M/ e% Q, o
1. SACL 法
* L& b  M  s0 F$ }& `  R0 m1 V/ B; R[Unicode]
. }# j' S  h: o" k( {9 L6 ]7 j9 lUnicode=yes' p  D: K$ }  C6 t" _
[Version]
2 r# P5 @% i1 vsignature="$CHICAGO$"
, \  S$ J& C" o7 N$ v7 cRevision=1
5 ?/ i: ~5 p& A. S$ f[File Security]. g1 O# a0 g7 E% F/ p# o7 H
"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"# d0 |2 k2 A* `0 X- b; a
% T( ^' a9 U/ P, U
将以上内容保存为 BlockAccess_x86.inf
) N7 t# w/ ^( g* z: W然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>, I% l/ L& Z( ~. k" l
其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。
0 e! a& A6 _, u
5 P# z0 j6 o% Y" }. P5 B2. 禁用 Row Position 功能法  e  U* ?7 B; R# G

- Q4 l) `$ x. _( ]$ z
5 b; H3 }% F) v; h8 b- GHKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29}
5 d# K8 a% q( T. o" A打开注册表编辑器,将此键删除即可。8 a* R' f/ w" b- J4 r. _

8 j% t! |, x# D. v) }& N3. 取消 DLL 注册法
# c/ j. f6 N( q* @$ l/ l2 N6 H! b
6 U3 {# c5 K6 u) l  F在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"3 x  R% a" ~$ x; `2 q4 m
即可
& i9 v% g0 {& b3 b. L6 r8 @+ a% m- w3 h8 ]1 H# a
4. 权限设置法
( `7 c3 b+ l8 P: ^2 ]: u- G2 N* V& a
在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N
6 J' b  Q$ C5 {+ `, O0 o2 i; r. ]" g& B: l7 W1 `
Vista 系统则需要输入3个命令:9 o" G* T2 c: b) u1 T* D4 c

  X7 R+ I/ q) s( \takeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll"# D" {. q2 }, ]* D  b
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT: c& ]7 o( H7 O0 \
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F) $ A+ m; I0 \: o$ r( R

/ F- i1 p( L( d8 S% G  q1 D& \/ u4 Q其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。* L( ?8 p) C) _8 q

  `1 ^2 s4 J, I' z附:此漏洞影响的系统、软件列表
6 S( \: M- w/ m! ?$ m
! d( U3 |7 e& Y* w) w: \Windows Internet Explorer 7
9 T' K; i' H8 l3 |+ M4 r6 IWindows Internet Explorer 7 for Windows XP ) B9 X, v' l  E5 y: d
Windows Internet Explorer 7 for Windows Server 2003 ; n% g4 a% @' N- k+ i2 B! P
Windows Internet Explorer 7 for Windows Server 2003 IA64
5 c: r0 m( o5 @  v. _Windows Internet Explorer 7 in Windows Vista
! `$ n# n, C( z, c% OWindows Internet Explorer 8 Beta 3 X  X' D7 C2 y4 B. J, }
Microsoft Internet Explorer 6.0 Service Pack 2 ; B8 _) o' m/ D. [5 c0 o
Microsoft Internet Explorer 6.0 Service Pack 1
3 b( t9 o/ E$ v4 L" LMicrosoft Internet Explorer 6.0
4 a! `# R3 i+ w3 L* NMicrosoft Internet Explorer 5.01 Service Pack 4 9 p  z) B8 g4 G* _- _' E9 P
Windows Server 2008 Datacenter without Hyper-V 1 E! H$ ~1 t& i0 o4 [- s- ^
Windows Server 2008 Enterprise without Hyper-V
! `" L: M8 u! K* Q( p: @& O6 K" {) j  R& AWindows Server 2008 for Itanium-Based Systems
1 o. e1 p0 v2 UWindows Server 2008 Standard without Hyper-V 6 s. K2 M  f% F, q+ A
Windows Server 2008 Datacenter
" m. t$ M; s8 Z0 L8 b+ xWindows Server 2008 Enterprise
/ X7 L" l, F$ W; ]9 oWindows Server 2008 Standard
1 e9 b/ ~% J+ c1 B# RWindows Web Server 2008
; M$ a- R. R+ E! m1 RWindows Vista Service Pack 1, when used with: 9 `1 @  g8 F6 Q( D7 _4 S
Windows Vista Business ) C) m, @7 j5 R7 Z
Windows Vista Enterprise ; l- p$ b( o9 ^' l" J
Windows Vista Home Basic 6 b0 g. p8 \0 r/ j
Windows Vista Home Premium   M+ [+ l9 G5 ~
Windows Vista Starter - E/ l, k2 x5 P- n
Windows Vista Ultimate
% A8 j+ d% B3 W. h( i% [* wWindows Vista Enterprise 64-bit Edition
; x( M! l7 T! O0 F3 n, j& ?Windows Vista Home Basic 64-bit Edition
1 E1 J6 S! p! m9 f/ lWindows Vista Home Premium 64-bit Edition / _& }% B  w) B5 C) K/ c5 P* b+ M! N- ]
Windows Vista Ultimate 64-bit Edition
' z0 w) y) O4 W, c" T8 g$ y4 YWindows Vista Business 64-bit Edition
, d  r6 ?, U9 P; Y6 {( cMicrosoft Windows Server 2003 Service Pack 1, when used with:
3 f0 d- o" [# g7 N" MMicrosoft Windows Server 2003, Standard Edition (32-bit x86)
" f7 o/ Y/ s$ f! m: h8 F$ XMicrosoft Windows Server 2003, Enterprise Edition (32-bit x86)
2 l) |5 w! _5 ?0 EMicrosoft Windows Server 2003, Datacenter Edition (32-bit x86)
8 x' A6 v) V) J) ~Microsoft Windows Server 2003, Web Edition
/ n9 }" M! `  L4 m6 c2 v: ZMicrosoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems ' O8 W- G. V4 r
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
$ k$ e6 W2 q3 ^$ k# ~& WMicrosoft Windows Server 2003, Datacenter x64 Edition
+ K- {+ M9 X- e  V4 j! w. sMicrosoft Windows Server 2003, Enterprise x64 Edition
8 J# j9 O% ?4 u# P, V* cMicrosoft Windows Server 2003, Standard x64 Edition 4 V( w4 Z3 J: K5 ]; b
Microsoft Windows XP Professional x64 Edition : k8 \: Y0 e# G, n
Microsoft Windows Server 2003 Service Pack 2, when used with:
  w. d0 ]: [( W' f6 b% _* f* yMicrosoft Windows Server 2003, Standard Edition (32-bit x86) 4 R( E* C9 O$ |) f* A
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) . u2 @/ P: \5 G, e, p$ ^/ L4 d6 i: a
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- E, J* R& W4 x! lMicrosoft Windows Server 2003, Web Edition ! \8 N! Z3 P, N4 T$ ^
Microsoft Windows Server 2003, Datacenter x64 Edition & U6 ^- @. Q8 e+ O* ?' L
Microsoft Windows Server 2003, Enterprise x64 Edition   l; r& h0 g0 _
Microsoft Windows Server 2003, Standard x64 Edition
, J% W% i4 _& }0 \! EMicrosoft Windows XP Professional x64 Edition % \  [) M; e. H5 D& c8 p
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
& E4 \# p3 A# c! mMicrosoft Windows Server 2003, Enterprise Edition for Itanium-based Systems : [( y) L, \0 ~: u/ V
Microsoft Windows XP Service Pack 2, when used with: 2 F' K; ^% Y) Z* h, l$ [
Microsoft Windows XP Home Edition ! S. ~: T/ k5 M8 }- T
Microsoft Windows XP Professional
: S* O$ k. s* `3 Q- j( ?. EMicrosoft Windows XP Service Pack 3, when used with:
% @6 `! W# P/ YMicrosoft Windows XP Home Edition
0 w' M5 v) b! G/ p1 g/ gMicrosoft Windows XP Professional
$ h% T0 v6 a+ J5 A对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息
+ v; t$ N& ^1 K$ `7 jInternet Explorer 0day漏洞可能会愈演愈烈
6 q, Q' {5 V: x4 H& C" {+ n; f- v3 L    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.5 x, Z& g( S' X5 r$ p& g, v

/ C5 j: `: a  A    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.: s& z. f$ E0 y! ]- M

0 v; j/ |. p; l8 D; p    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加.
, D  V8 ]- ^, e: j8 W$ {4 E. i
: s! E9 P* n& l, c' E    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.# t. P* }4 F/ Y- f' ?
$ u4 o6 x4 L; x1 I. r
[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:
, m; T. o: m( m+ o$ o微软IE漏洞麻烦大 超过10000个站点被劫持! B+ b' t, Q' h
    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.
7 J$ P. E; G& }0 v    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势.
  y# e. m5 H5 m
/ i" X% n3 l. G: i3 P    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-8-26 16:46 , Processed in 0.016463 second(s), 5 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表