ÎÄÕÂÁбí
 
2008Äê01ÔÂ25ÈÕ ÐÇÆÚÎå 20:41

¡¡ÓÐÒ»Ö»ÎÚÑ»´òËã·ÉÍù¶«·½£¬Í¾ÖÐÓöµ½Ò»Ö»¸ë×Ó£¬Ë«·½Í£ÔÚÒ»¿ÃÊ÷ÉÏÐÝÏ¢¡£

¸ë×Ó¼ûÎÚѻһ¸±·ÉµÃºÜÐÁ¿àµÄÑù×Ó£¬¹ØÐĵØÎÊ£ºÄãÒª·Éµ½ÄÄÀïÈ¥£¿

ÎÚÑ»·ß·ß²»Æ½µØËµ£ºÆäʵÎÒ²»ÏëÀ뿪£¬¿ÉÊÇÕâ¸öµØ·½µÄ¾ÓÃñ¶¼ÏÓÎҵĽÐÉù²»ºÃÌý£¬ËùÒÔÎÒÖ»ºÃ·Éµ½±ðµÄµØ·½È¥¡£

¸ë×ÓºÃÐĵظæËßÎÚÑ»£º±ð°×·ÑÁ¦ÆøÁË£¡Èç¹ûÄã²»¸Ä±äÄãµÄÉùÒô£¬·Éµ½ÄÄÀï¶¼²»»áÊÜ»¶Ó­µÄ¡£

¡¡¡¡——Èç¹ûÄãÎÞ·¨¸Ä±ä»·¾³£¬Î¨Ò»µÄ·½·¨¾ÍÊǸıäÄã×Ô¼º

 
2008Äê01ÔÂ25ÈÕ ÐÇÆÚÎå 20:40

ÔÚ·ÇÖÞ´ó²ÝÔ­ÉÏ£¬ÈýÖ»ÊÝÈõµÄС¹·ÕýÓëÒ»Ö»¸ß´óµÄ°ßÂí½øÐÐÒ»³¡ÉúËÀ²«¶·¡£

Õ§Ò»¿´À´£¬ÈýÖ»ÈõСµÄС¹·ºÜÄÑÊÇ´ó°ßÂíµÄ¶ÔÊÖ¡£µ«Êµ¼ÊÇé¿öÊÇ£¬Ò»Ö»Ð¡¹·Ò§×¡°ßÂíµÄβ°Í£¬ÈÎÆ¾°ßÂíµÄβ°ÍÈçºÎ˦¶¯£¬Ò²ËÀËÀҧס²»·Å£»Ò»Ö»Ð¡¹·Ò§×¡°ßÂíµÄ¶ú¶ä£¬ÈÎÆ¾°ßÂíÈçºÎÒ¡Í·£¬Ò²¾ö²»Ëɿڣ»Ò»Ö»ÉÔÏÔǿ׳µÄС¹·Ò§×¡°ßÂíµÄÒ»ÌõÍÈ£¬ÈÎÆ¾°ßÂíÈçºÎÌßµ¯£¬Ò»µãÒ²²»¸Òиµ¡¡£

²»Ò»»á£¬ÔÚÈýֻС¹·µÄÆëÐĹ¥»÷Ï£¬“ÅÓÈ»´óÎï”°ßÂíÖÕÓÚÌåÁ¦²»Ö§Ì±µ¹Ôڵأ¬³ÉΪÈýֻС¹·µÄÅÌÖв͡£

Æôʾ£ºÖ»Òª´ëÊ©µÃÁ¦£¬Âéȸײ»µ·É»ú¡£ÔÚ×éÖ¯ÄÚ²¿£¬¹ÜÀíÕßÒ»¸öºÜÖØÒªµÄÖ°ÄܾÍÊÇ¿ÆÑ§·Ö¹¤£¬¸ù¾Ýʵ¼Ê¶¯Ì¬¶ÔÈËÔ±½øÐÐ×î¼ÑÅäÖá£Ö»ÓÐÿ¸öÔ±¹¤¶¼Ã÷È·×Ô¼ºµÄ¸ÚλְÔ𣬸÷˾ÆäÖ°£¬²Å²»»á²úÉúÍÆÚᢳ¶Æ¤µÈ²»Á¼ÏÖÏó¡£Ïà·´£¬Èç¹û¶ÓÎéÖÐÓÐÈËÀÄóijäÊý£¬¸øÆóÒµ´øÀ´µÄ²»½ö½öÊǹ¤×ʵÄËðʧ£¬»¹¿ÉÄܵ¼Ö¹«Ë¾¹¤×÷ЧÂÊÕûÌåϽµ£¬ÉõÖÁÔÚ¼¤ÁҵľºÕùÖлáÏñ°ßÂíÒ»ÑùÍÇÈ»µ¹Ï¡£

 
2008Äê01ÔÂ25ÈÕ ÐÇÆÚÎå 20:40

ÑÏËàµÄʲ»·ÁÓÃÓÄĬ·½Ê½±í´ï

×÷¼ÒÍþÁ®¡¤´÷Î¬Ë¹Ôø¾­Ëµ¹ý£º"ÎÒϲ»¶µÄÓÄĬ£¬ÊÇÄÜʹÎÒ·¢Ð¦5ÃëÖÓ¶ø³Á˼10·ÖÖÓµÄÄÇÒ»ÖÖ¡£"ȷʵ£¬½«ÑÏËàµÄÊÂÇéÓÃÇáËɵķ½Ê½À´±íÏÖµÄÓÄĬ£¬×îÄܹ»´ïµ½È°µ¼ºÍ˵·þ±ðÈ˵ÄЧ¹û¡£Ç¿ÊƵĹÜÀí×÷·çÍùÍùÈÝÒײúÉú·´Ð§¹û£¬µ¹ÊÇÓÃ"ÒÔÈá¿Ë¸Õ"µÄ·½Ê½£¬×îÈÝÒ×ÊÕ·þÈËÐÄ¡£

ÃÀ¹úÓÐλ¾¯²ì¾Ö³¤£¬ÒòÎªÏ½ÇøÄÚµÄÖΰ²Ó뽻ͨ·Ç³£²î£¬ÐÄÇé·Ç³£µÍÂä¡£Öΰ²Ö®ËùÒÔÕâô²î£¬ÊÇÒòΪÕâ¸öÏ½Çø±È½ÏƫƧ£¬Ðí¶àµØ·½ºÜÈÝÒ׳ÉΪ¹ÜÀíµÄËÀ½Ç£»ÖÁÓÚ½»Í¨·½Ã棬ÓÉÓÚµ±µØÊÇ»õ³µ¹«Ë¾µÄ×ÜÕ¾£¬Ðí¶à´óÐÍ»õ³µµÄ˾»úÿÌì¶¼ÔÚ¹«Â·Éϼݳµ±¼³Û£¬ÔÚ¹ý¶ÈÆ£À͵ÄÇé¿öÏ£¬½»Í¨Ê¹ʾͲ»¶ÏµØ·¢ÉúÁË¡£ËäÈ»¾Ö³¤ºÜÄÜÌåÁÂÏÂÊôµÄÐÁ¿à£¬Ò²Á˽âÐí¶à²»µÃÒѵÄÇé¿ö£¬µ«ÊÇÉÏÃæµÄ³¤¹ÙÖ»¿´³É¼¨£¬²»¹ÜÆäËûÒòËØ£¬¼´Ê¹ËûÔÙŬÁ¦£¬ÈÔÈ»²»±»Éϲã¿Ï¶¨£¬ËùÒÔ¾¡¹ÜÄê×ÊÒѹ»£¬ÈÔȻûÓÐÉýǨµÄ»ú»á¡£¾ÍÔÚÖΰ²Ó뽻ͨÎÊÌâÀ§Èžֳ¤µÄͬʱ£¬ÖÝÕþ¸®°ä²¼ÁËÒ»µÀÃüÁ½«ÕâÒ»¼¾¶¨Îª½»Í¨°²È«¼¾£¬ÎªÁËÅäºÏÕâ¸öÖ÷Ì⣬¾Ù°ìÁËÒ»³¡½»Í¨°²È«¾ºÈü¡£ÎªÁËÕâ¼þÊ£¬Ð¡Õò¾Ö³¤Ñ¹Á¦¶Ùʱ´óÔö£¬Ã¿ÌìÒ»³ö¼ÒÃűãÊÇÂúÁ³³îÈÝ¡£ÓÐÒ»Ì죬ËûÐÄÁ¦½»´áµØ»Øµ½¼ÒÀ½«Ã±×ÓËæÊÖÒ»ÈÓ£¬±ã¶Ë×ÅÆ¡¾Æ¿àÃÆµØ×øÔÚɳ·¢Àº¢×ÓºÍÀÏÆÅ¿´¼ûºóÒ²²»¸Ò¿ÔÉù£¬·×·×¶ã»ØÎÔ·¿Àï¡£¾Ö³¤´ò¿ªµçÊÓ£¬µçÊÓÕýÑݳöÍÑ¿ÚÐ㣬±íÑÝÕß˵Æð»°À´²»µ«ÃîȤºáÉú£¬¶øÇÒ×Ö×ÖÖéçᣬ¾Ö³¤È̲»×¡¹þ¹þ´óЦ£¬ÕâһЦ°ÑÐÄÍ·µÄѹÁ¦ÊÍ·ÅÁ˲»ÉÙ¡£¿´ÍêÍÑ¿ÚÐãÖ®ºó£¬¾Ö³¤ÌÉÔÚɳ·¢ÀïÉî˼£¬ºöÈ»¼ä£¬ËûµÄÑÛ¾¦ÎªÖ®Ò»ÁÁ£¬ÐÄÖÐÓÐÁËÒ»¸öÁé¸Ð¡£¸ôÌ죬¾Ö³¤ÕÙ¼¯ËùÓо¯²ì£¬¿ªÊ¼»ý¼«µØÐж¯ÆðÀ´¡£Èý¸öÔÂºÜ¿ìµØ¹ýÈ¥ÁË£¬ÖÝÕþ¸®ÅÉÈËÉó²é¸÷ÕòµÄ½»Í¨Çé¿ö£¬°üÀ¨½»Í¨×èÈûÇé¿ö¡¢³µÁ÷Á¿¿ØÖÆ¡¢Î¥¹æ¼þÊýµÈµÈ£¬µ±È»×îÖØÒªµÄ£¬»¹Êǽ»Í¨Ê¹ʵķ¢ÉúÂÊ£¬È»¶ø£¬»ü²éÈËÔ±Éó²éµÄ½á¹û£¬È´Èôó¼Ò¶¼µøÆÆÑÛ¾µ¡£Ã»Ïëµ½¼Ç¼һÏò²»ºÃµÄСÕò£¬¾ÓÈ»Á¬Ò»´Î³µ»öµÄ¼Ç¼¶¼Ã»ÓС£Ô­À´£¬¾Ö³¤Ïë³öÁËÒ»¸öºÃµã×Ó£¬Ëû°Ñ¹«Â·ÉϵÄËùÓо¯¸æÅƶ¼»»ÁË£¬¶øÐÂÅÆ×ÓÉÏÃæÔòд×Å"Ç뿪ÂýÒ»µã£¬ÎÒÃÇÒѾ­Ã¦²»¹ýÀ´ÁË£¡éëÒÇ¹ÝÆô"¡£ºÜÓÐÒâ˼°É£¿¾Ö³¤Í¨¹ýÕâ¸öÓÄĬСÓ¶ÔÀ´ÍùµÄ˾»ú½øÐÐÁËÐÄÀí°µÊ¾£¬Ë¾»úÃÇ¿´µ½Õâ¸öÓÄĬµÄÌáÐÑ£¬²»Öª²»¾õµØ°Ñ³µËÙ·ÅÂý£¬Ð¡ÐÄ¿ª³µ¡£

ûÓÐÈËϲ»¶Ç¿Ó²µÄÊֶΣ¬Èç¹û¾¯¸æÅÆÉÏд×Å"³¬ËÙ£¬·£Ò»Íò£¡¾¯²ì¾ÖÆô"£¬²»½öÊØ·¨µÄÈË¿´Á˲»Êæ·þ£¬ÄÇЩ³¬ËÙÕ߸ü²»ÓÃ˵ÁË¡£ÀûÓÃÒ»¸öССµÄÓÄĬ¸Ð£¬°Ñ½»Í¨°²È«µÄ¸ÅÄîÒÔ×îÌù½üÈËÃÇÉú»îµÄ·½Ê½´«µÝ³öÈ¥£¬ÈÃÈËÃDz»Öª²»¾õµØ²úÉúÁË"ËÀÍöËæÊ±ÔÚÉí±ß"µÄ¿Ö¾å¸Ð£¬¼´Ê¹³µËÙÔÙ¿ìµÄ˾»ú¿´ÁËÒ²È̲»×¡Òª·ÅÂýËÙ¶È¡£ËÀÍö£¬ÊÇÒ»¼þÔÙÑÏË಻¹ýµÄÊÂÁË£¬Ë­ËµÑÏËàµÄÊÂÒ»¶¨ÒªÓÃÑÏËàµÄ·½Ê½±í´ïÄØ£¿Èç¹ûͨ¹ýÓÄĬµÄ·½Ê½¿ÉÒÔÇÉÃîÇÒÓÐЧµØ´ïµ½Ä¿µÄ£¬²»ÊDZð¾ßÒâÒåÂð£¿

²»±ØÏÛĽ±ðÈ˵ÄÉú»î·½Ê½

ÄãÏÛĽ±ðÈ˵ÄÉú»î±ÈÄã¿ìÀÖÂð£¿ÄãÈÏΪËûµÄÈÕ×Ó¹ýµÃ±ÈÄãºÃÂð£¿È»¶ø£¬Äã¿´¹ýËûÃÇÉú»îÖеÄÁíÒ»ÃæÂ𣿲»±ØÏÛĽ±ðÈ˵ÄÃÀÀö»¨Ô°£¬ÒòΪÄãÒ²ÓÐ×Ô¼ºµÄÀÖÍÁ£¬Ö»ÒªÄãÓÃÐĸûÔÅ£¬ÑÛǰµÄÕâÆ¬»¨ÆÔ£¬ÖÕ»áÓл¨ÍŽõ´Ø¡¢ÏãÆøËÄÒçµÄÒ»Ìì¡£

ÔÚºÓµÄÁ½°¶£¬·Ö±ðס×ÅÒ»¸öºÍÉÐÓëÒ»¸öÅ©·ò¡£ºÍÉÐÿÌì¿´×ÅÅ©·òÈÕ³ö¶ø×÷£¬ÈÕÂä¶øÏ¢£¬Éú»î¿´ÆðÀ´·Ç³£³äʵ£¬ÁîËûÏ൱ÏÛĽ¡£¶øÅ©·òÒ²ÔÚ¶Ô°¶£¬¿´¼ûºÍÉÐÿÌì¶¼ÊÇÎÞÓÇÎÞÂǵØËо­¡¢ÇÃÖÓ£¬Éú»îÊ®·ÖÇáËÉ£¬ÁîËû·Ç³£ÏòÍù¡£Òò´Ë£¬ÔÚËûÃǵÄÐÄÖвúÉúÁËÒ»¸ö¹²Í¬ÄîÍ·£º"ÕæÏëµ½¶Ô°¶È¥£¡»»¸öÐÂÉú»î£¡"ÓÐÒ»Ì죬ËûÃÇÅöÇɼûÃæÁË£¬Á½ÈËÉÌ̸һ·¬£¬²¢´ï³É½»»»Éí·ÝµÄЭÒ飬ũ·ò±ä³ÉºÍÉУ¬¶øºÍÉÐÔò±ä³ÉÅ©·ò¡£µ±Å©·òÀ´µ½ºÍÉеÄÉú»î»·¾³ºó£¬Õâ²Å·¢ÏÖ£¬ºÍÉеÄÈÕ×ÓÒ»µãÒ²²»ºÃ¹ý£¬ÄÇÖÖÇÃÖÓ¡¢Ëо­µÄ¹¤×÷£¬¿´ÆðÀ´ºÜÓÆÏУ¬ÊÂʵÉÏÈ´·Ç³£·³Ëö£¬Ã¿¸ö²½Öè¶¼²»ÄÜÒÅ©¡£¸üÖØÒªµÄÊÇ£¬É®Â¿̰嵥µ÷µÄÉú»î·Ç³£¿ÝÔ﷦棬ËäÈ»ÓÆÏУ¬È´ÈÃËû¾õµÃÎÞËùÊÊ´Ó¡£ÓÚÊÇ£¬³ÉΪºÍÉеÄÅ©·ò£¬Ã¿ÌìÇÃÖÓ¡¢Ëо­Ö®Óà¶¼×øÔÚ°¶±ß£¬ÏÛĽµØ¿´×ÅÔڱ˰¶¿ìÀÖ¹¤×÷µÄÆäËûÅ©·ò¡£ÖÁÓÚ×öÁËÅ©·òµÄºÍÉУ¬ÖØ·µ³¾ÊÀºó£¬Í´¿à±ÈÅ©·ò»¹Òª¶à£¬Ãæ¶ÔË×ÊÀµÄ·³ÓÇ¡¢ÐÁÀÍÓëÀ§»ó£¬Ëû·Ç³£»³Äîµ±ºÍÉеÄÈÕ×Ó¡£Òò¶øËûÒ²ºÍÅ©·òÒ»Ñù£¬Ã¿Ìì×øÔÚ°¶±ß£¬ÏÛĽµØ¿´×Ŷ԰¶²½ÂÄ»ºÂýµÄÆäËûºÍÉУ¬²¢¾²¾²µØñöÌý±Ë°¶´«À´µÄËо­Éù¡£Õâʱ£¬ÔÚËûÃǵÄÐÄÖУ¬Í¬Ê±ÏìÆðÁËÁíÒ»¸öÉùÒô£º"»ØÈ¥°É£¡ÄÇÀï²ÅÊÇÕæÕýÊʺÏÎÒÃǵÄÉú»î£¡"

ÎÒÃǾ­³£Ìý¼ûÅóÓѼäµÄ±§Ô¹£º"ÄãµÄÉú»î¹ýµÃÕæºÃ£¬²»ÏñÎÒ£¬Ã¿Ìì¶¼µÃÃæ¶ÔÀϰåµÄßëß¶¡£"µ«ÊÇ£¬ÄãÔõô֪µÀÅóÓѵÄÉú»î¹ýµÃÓжàºÃ£¿±ðÖ»¿´ÊÂÇé±íÃæ£¡¾ÍÏñ¹ÊÊÂÀïµÄÁ½Î»Ö÷½Ç£¬Ã»Óо­Àú¹ý¶Ô·½µÄ¹¤×÷£¬×ÔȻҲ¿´²»¼ûÆäÖеÄÐÁ¿àÒ»Ãæ£¬¾ÍÏñÎÒÃÇÖ»¿´µÃ¼û³É¹¦ÕßµÄЦÈÝ£¬È´¿´²»¼ûËûÃǷܶ·µÄ¹ý³ÌÖÐÔø¾­Á÷ϵÄÑÛÀᡣÿ¸öÈ˶¼ÓÐ×Ô¼º±Ø¾­µÄÀú³Ì£¬ÆäÖеÄÐÁ¿àÓëÌðÃÀÖ»ÓÐ×Ô¼º¸ÐÊÜ×îÉî¿Ì¡£Ö»ÓÐÄãÇ××ÔÔÔÖֵύ¶ä£¬Äã²ÅÖªµÀÆäÌØÐÔÓëÅàÖ²µÄ¸ÐÊÜ£¬µ±»¨¶äæÌÈ»ÕÀ·Åʱ£¬Ò²Ö»ÓÐÄã²Å¶®µÃÐÀÉÍ¡£²»±ØÏÛĽ±ðÈ˹¤×÷ʱµÄЦÈÝ£¬ÄÇÒ²ÐíÖ»ÊÇ¿àÖÐ×÷ÀÖ£¬µ±È»£¬Ò²¿ÉÄÜÊÇËûÃÇÖªµÀÈçºÎÀÖÔÚ¹¤×÷ÖС£

 
2008Äê01ÔÂ25ÈÕ ÐÇÆÚÎå 20:39

¡¡¡¡ 1865Ä꣬ÃÀ¹úÄÚÕ½½áÊøºó£¬Ìտ˽«¾ü¾ºÑ¡¹ú»áÒéÔ±£¬ËûµÄ¶ÔÊÖÊÇËûµ±ÄêÊÖϵÄÒ»ÃûÊ¿±ø£¬Ãû½ÐÔ¼º²¡¤º£Âס£Ò»Î»Êǹ¦Ñ«×¿ÖøµÄ½«¾ü£¬Ò»Î»ÊÇÆÕÆÕͨͨµÄÊ¿±ø£¬¼¸ºõËùÓеÄÈ˶¼ÈÏΪ£¬Ê¤ÀûÒ»¶¨ÊôÓÚÌտ˽«¾ü¡£

¡¡¡¡ ¾ºÑ¡Ñݽ²¿ªÊ¼ÁË¡£Ìտ˽«¾üµÄÑݽ²¿¶¿®¼¤°º£¬Ëû˵£º“Öîλͬ°û£¬»¹¼ÇµÃ17ÄêǰÄǸö¼¤Õ½µÄÒ¹ÍíÂð£¿ÎÒÂÊÁìÊ¿±øµ½²è×ùɽ¾Ñ»÷µÐÈË¡£ÄÇÊǶàô¼è¿àµÄÕ½¶·Ñ½£¡µ«ÎÒ´ÓûÏë¹ýÍËÈ´£¬ÒòΪÎÒÖªµÀ£¬ÎªÁËÎÒÃǵĹú¼Ò£¬ÎªÁËÕýÒåºÍ×ÔÓÉ£¬ÎÒÔ¸Ò⸶³öËùÓУ¬°üÀ¨ÉúÃü¡£ÎÒÈýÌìÈýҹûºÏÑÛ£¬ÑªÕ½Ö®ºó£¬ÎÒ¾¹ÌÉÔÚÊ÷ÁÖÀï˯×ÅÁË¡­¡­”

¡¡¡¡ ±ÈÆðÌտ˽«¾üµÄÑݽ²£¬Ô¼º²¡¤º£Â×µÄÑݽ²ÒªÆÓʵµÃ¶à£¬Ëû˵£º“Ç×°®µÄͬ°ûÃÇ£¬Ìտ˽«¾ü˵µÃ²»´í£¬ËûȷʵÔÚÄÇ´ÎÕ½¶·ÖÐÁ¢ÏÂÁ˺¹Âí¹¦ÀÍ¡£ÎÒµ±Ê±Ö»²»¹ýÊÇËûÊÖϵÄÒ»ÃûÆÕͨʿ±ø£¬ºÍËûÒ»Æð³öÉúÈëËÀ¡£ÄǴΣ¬ËûÔÚÊ÷ÁÖÀïÈë˯ʱ£¬ÎÒ¾ÍÕ¾ÔÚËûµÄÉíÅÔÊØ»¤Ëû¡£µ±Ê±ÎÒЯ´ø×ÅÎäÆ÷£¬±¥³¢º®ÀäµÄ×Ìζ¡£»¹Ê±¿Ì×¼±¸×ÅÓÃÎÒµÄÉíÇûΪËûµ²×ÅËæÊ±»áÉäÀ´µÄ×Óµ¯¡£ÎÒÔÚÐÄÖÐ˵£¬ÎÒÊÇÒ»ÃûÊ¿±ø£¬ÎÒÒª±£»¤½«¾üµÄ°²È«¡­¡­”

¡¡¡¡ Ô¼º²¡¤º£Â×µÄÑݽ²Ó®µÃÁËÃñÖÚÈÈÁÒµÄÕÆÉù£¬Ëû³öÈËÒâÁϵØÓ®µÃÁËѡƱºÍ×îÖÕµÄʤÀû¡£

¡¡¡¡ Ô¼º²¡¤º£Â×Ö®ËùÒÔÄÜÔÚ¾ºÑ¡Ñݽ²Öлñʤ£¬Ô­ÒòÔÚÓÚËûµÄÑݽ²ÌýÆðÀ´¸üÕæÊµ¡¢¸üÇ×ÇС£ËûÐéÐĵسÐÈÏ×Ô¼ºÊÇÒ»ÃûÆÕͨµÄÊ¿±ø£¬ÕâÑù¾ÍÀ­½üÁËÓë¹ã´óÃñÖÚÖ®¼äµÄ¾àÀ룻×÷ΪһÃûÆÕͨʿ±ø£¬ÔÚ¶ñÁÓµÄÕ½Õù»·¾³ÖÐËûÈÔÄܼáÊØ×Ô¼ºµÄ¸Ú룬¾¤¾¤ÒµÒµ¡¢¾¡ÖÒÖ°ÊØ£¬ÈÃÈ˾õµÃËû¸üÖµµÃÐÅÀµ¡£Ìտ˽«¾üÔÚ¾ºÑ¡Ñݽ²ÖУ¬ÁоÙÁË×Ô¼ºµÄºÕºÕÕ½¹¦£¬ÑÔ´Ç¿¶¿®¼¤°º£¬µ«ÊÇËûµÄÑݽ²Ê¼ÖÕ±£³Ö×ŶÔÃñÖÚµÄÒ»ÖÖ¸ß×Ë̬£¬²»ÄܸøÈËÒÔÇ×ÇС¢Õæ³ÏµÄ¸ÐÊÜ¡£Òò´Ë£¬Ê§ÀûÒ²ÔÚÇéÀíÖ®ÖС£

 
2008Äê01ÔÂ25ÈÕ ÐÇÆÚÎå 20:38

¡¡¡¡²¢²»ÊÇÒòΪÊÂÇéÄÑÎÒÃDz»¸Ò×ö£¬¶øÊÇÒòΪÎÒÃDz»¸Ò×öÊÂÇé²ÅÄѵġ£

¡¡¡¡1965Ä꣬һλº«¹úѧÉúµ½½£ÇÅ´óѧÖ÷ÐÞÐÄÀíѧ¡£ÔÚºÈÏÂÎç²èµÄʱºò£¬Ëû³£µ½Ñ§Ð£µÄ¿§·ÈÌü»ò²è×ùÌýһЩ³É¹¦ÈËÊ¿ÁÄÌì¡£ÕâЩ³É¹¦ÈËÊ¿°üÀ¨Åµ±´¶û½±»ñµÃÕߣ¬Ä³Ò»Ð©ÁìÓòµÄѧÊõȨÍþºÍһЩ´´ÔìÁ˾­¼ÃÉñ»°µÄÈË£¬ÕâЩÈËÓÄĬ·çȤ£¬¾ÙÖØÈôÇᣬ°Ñ×Ô¼ºµÄ³É¹¦¶¼¿´µÃ·Ç³£×ÔÈ»ºÍ˳Àí³ÉÕ¡£Ê±¼ä³¤ÁË£¬Ëû·¢ÏÖ£¬ÔÚ¹úÄÚʱ£¬Ëû±»Ò»Ð©³É¹¦ÈËÊ¿ÆÛÆ­ÁË¡£ÄÇЩÈËΪÁËÈÃÕýÔÚ´´ÒµµÄÈËÖªÄѶøÍË£¬ÆÕ±é°Ñ×Ô¼ºµÄ´´Òµ¼èÐÁ¿ä´óÁË£¬Ò²¾ÍÊÇ˵£¬ËûÃÇÔÚÓÃ×Ô¼ºµÄ³É¹¦¾­ÀúÏÅ»£ÄÇЩ»¹Ã»ÓÐÈ¡µÃ³É¹¦µÄÈË¡£

¡¡¡¡×÷ΪÐÄÀíϵµÄѧÉú£¬ËûÈÏΪºÜÓбØÒª¶Ôº«¹ú³É¹¦ÈËÊ¿µÄÐÄ̬¼ÓÒÔÑо¿¡£1970Ä꣬Ëû°Ñ¡¶³É¹¦²¢²»ÏñÄãÏëÏñµÄÄÇôÄÑ¡·×÷Ϊ±ÏÒµÂÛÎÄ£¬Ìá½»¸øÏÖ´ú¾­¼ÃÐÄÀíѧµÄ´´Ê¼ÈËÍþ¶û;²¼À׵ǽÌÊÚ¡£²¼À׵ǽÌÊÚ¶Áºó£¬´óΪ¾ªÏ²£¬ËûÈÏΪÕâÊǸöз¢ÏÖ£¬ÕâÖÖÏÖÏóËäÈ»ÔÚ¶«·½ÉõÖÁÔÚÊÀ½ç¸÷µØÆÕ±é´æÔÚ£¬µ«´Ëǰ»¹Ã»ÓÐÒ»¸öÈ˴󵨵ØÌá³öÀ´²¢¼ÓÒÔÑо¿¡£¾ªÏ²Ö®Ó࣬ËûдПøËûµÄ½£ÇÅУÓÑ--µ±Ê±Õý×øÔÚº«¹úÕþ̳µÚÒ»°Ñ½»ÒÎÉϵÄÈË--ÆÓÕýÎõ¡£ËûÔÚÐÅÖÐ˵£¬“ÎÒ²»¸Ò˵Õâ²¿Öø×÷¶ÔÄãÓжà´óµÄ°ïÖú£¬µ«ÎҸҿ϶¨Ëü±ÈÄãµÄÈκÎÒ»¸öÕþÁî¶¼ÄܲúÉúÕ𶯡£”

¡¡¡¡ºóÀ´Õâ±¾Êé¹ûÈ»°éËæ×ź«¹úµÄ¾­¼ÃÆð·ÉÁË¡£Õâ±¾Êé¹ÄÎèÁËÐí¶àÈË£¬ÒòΪËûÃÇ´ÓÒ»¸öеĽǶȸæËßÈËÃÇ£¬³É¹¦Óë“ÀÍÆä½î¹Ç£¬¶öÆäÌå·ô”¡¢“Èý¸üµÆ»ðÎå¸ü¼¦”¡¢“Í·ÐüÁº£¬×¶´Ì¹É”ûÓбØÈ»µÄÁªÏµ¡£Ö»ÒªÄã¶ÔijһÊÂÒµ¸ÐÐËȤ£¬³¤¾ÃµØ¼á³ÖÏÂÈ¥¾Í»á³É¹¦£¬ÒòΪÉϵ۸³ÓèÄãµÄʱ¼äºÍÖǻ۹»ÄãÔ²Âú×öÍêÒ»¼þÊÂÇé¡£ºóÀ´£¬ÕâλÇàÄêÒ²»ñµÃÁ˳ɹ¦£¬Ëû³ÉÁ˺«¹ú·ºÒµÆû³µ¹«Ë¾µÄ×ܲá£

¡¡¡¡ÎÂܰÌáʾ£ºÈËÊÀÖеÄÐí¶àÊ£¬Ö»ÒªÏë×ö£¬¶¼ÄÜ×öµ½£¬¸Ã¿Ë·þµÄÀ§ÄÑ£¬Ò²¶¼Äܿ˷þ£¬Óò»×Åʲô¸ÖÌú°ãµÄÒâÖ¾£¬¸üÓò»×Åʲô¼¼ÇÉ»òıÂÔ¡£Ö»ÒªÒ»¸öÈË»¹ÔÚÆÓʵ¶øÈÄÓÐÐËȤµØÉú»î×Å£¬ËûÖÕ¾¿»á·¢ÏÖ£¬ÔìÎïÖ÷¶ÔÊÀʵݲÅÅ£¬¶¼ÊÇË®µ½Çþ³ÉµÄ¡£

 
2008Äê01ÔÂ22ÈÕ ÐÇÆÚ¶þ 9:26

¸Ã¸Éɶ¸Éɶ°É¡£Ä±ÊÂÔÚÈË£¬³ÉÊÂÔÚÌì

·´¶øÒ²Ã»ÓÐÍæµÄÓûÍû£¬²»ÖªµÀΪɶ

23»¹Óп¼ÊÔ£¬ÉϿξÍÈ¥Á˼¸´Î£¬»¹µÃ¸´Ï°Ò»ÏµÄ

 
2008Äê01ÔÂ15ÈÕ ÐÇÆÚ¶þ 18:30

15ºÅÊÇÅ©ÀúÀ°Ô³õ°Ë¡£ÕâÊÇÎÒ¹ýµÄµÚ¶þÊ®¶þ¸öÀ°°ËÁË¡£¸Õ²ÅÔÚ°Ù¶ÈÌù°ÉÉÏ¿´µ½ÁËÀ°°Ë½ÚµÄÀ´ÓÉ£¬Ëµ±±¾©È˺ÜÖØÊÓÕâ¸ö½ÚµÄ¡£µÄÈ·£¬Ð¡Ê±ºòÿÄê¹ýÉúÈÕÄÌÄ̶¼ÒªÖóÒ»´ó¹øµÄÖ࣬ÀïÃæ¶¹µÄÖÖÀàÒ²Êǹ̶¨µÄ£¬ºÃÏñÓÐÆß£¬°ËÖÖÄØ¡£²»¹ýÎÒСʱºò²»°®ºÈÄÇÖ࣬´ó²¿·Ö¶¼ÊÇÀÏÈËÃǺÈÁË¡£ÒÔǰÊÇÔÚн®¶Ë¹ýÀ´Ö಻ԸÒâºÈ£¬ÏÖÔÚÊÇÔÚ±±¾©ÏëºÈÈ´ÓÖºÜÂé·³²ÅÄܺȵ½£¬ºÇºÇ¡£ÄÌÄÌÀÏ˵À°°ËÉúµÄº¢×Ó³¤´óÁË»áºýÀïºýÍ¿£¬¸úÒ»¹øÖàÒ»Ñù¡£Æäʵ£¬ºýÀïºýÍ¿µÄͦºÃµÄ£¬·³ÄÕµÄÊÂÇé²»»á×ÜÊǼÇÔÚÐÄÉÏ¡£

À°°ËÊÇÒ»ÄêÖÐ×îÀäµÄʱºò£¬¿´À´½ñÄêÒ²²»ÀýÍâ¡£´©ºÃÒ·þ±ð¸Ðð¡£

19ºÅ¾ÍÒª¿¼ÊÔÁË£¬ËµÊµ»°£¬Ò²Í¦Ã»µ×µÄ¡£²»¹ý¸´Ï°ÁËÕâô¾Ã£¬ÉÏÕ½³¡É±ËüÒ»°Ñ°É¡£À´Ò»¸ö¸ÉÒ»¸ö£¬À´Á½¸öɱһ˫£¬¹þ¹þ

ÁíÍ⣬лл Anna ^_^,ÎÒ»á¼ÓÓ͵Ä

 
2008Äê01ÔÂ01ÈÕ ÐÇÆÚ¶þ 1:33

ÎÒÒªÓÐÐÂÆøÏó¡£

°ÑÕâÓàÏÂÊ®¼¸ÌìŪºÃ¡£

Ð¡ÍæÒ»Ï£¬Ã÷Ìì8µãÒªÆð´²£¬Ë¯ÁË¡£

 
2007Äê12ÔÂ10ÈÕ ÐÇÆÚÒ» 22:03

ÓеÄʱºò²»Ïë³¶µ­£¬¿ÉÊDz»³¶Éú»îÓÖÓÐЩÎÞȤ£¬ÚÀ¡£

ż¶û¿´µ½ÂÛ̳ÉÏÓÐЩÌÖÂÛ£¬ºÜÓ×ÖÉ£¬Ò²²»²ÎÓë¡£

ÈËÉú¾ÍÊÇÕâÑù£¬Ã¿¸öÈ˶¼ÓÐ×Ô¼ºµÄÂß¼­¡£Èç¹ûÄãµÄÂß¼­Óë±ðÈ˲»Í¬£¬¿ÉÄÜËû×ö³öµÄÊÂÇé»áÁîÄã´ó³ÔÒ»¾ª¡£

¿ÉÊǴ󲿷Öʱºò£¬ÄãµÄÂß¼­¶¼±ØÐëÊÇÉç»áÕâ¸ö´óÀàµÄ×ÓÀà.......

²»Ô¹ÌìÓÈÈË¡£¼ÇµÃ»ðÓ°ÀïµÄ¿­ÀÏÊ¦Ôø¾­Ëµ¹ý£¬ÔËÆøÒ²ÊÇʵÁ¦µÄ±íÏÖ¡£

ÔÚÕâ¸ö¸¡ÔêµÄ½ñÌ죬Èç¹ûÄãÄÜ×øµÄס£¬¿Ï¶¨ÊǸöÓÅÊÆ¡£¾ÍÏñÀϵù¸æËßÎҵ쬵±Äê¸ê±ÚÌ²ÑØÏßÉϰ࣬×ߺóÃÅ»ØÎÚ³ľÆëµÄ½á¹û¶¼µ±Á˹¤ÈË£¬Ã»ºóÃŵĺóÀ´ÔÙµ÷»ØÀ´ÒѾ­ÊǸɲ¿Éí·Ý¡£

ÔÚÏÂÒ»²½²»Ã÷È·µÄʱºòÖ»Äܾ¡Á¦×öºÃ±¾½×¶Î¸Ã×öµÄÊÂÇ飬ºÇºÇ

ÏÐÍ¥ÐŲ½²»ÊÇ˵ÏÖÔÚ£¬¶øÊÇÕû¸öÉú»îµÄ»ùµ÷²Å¶Ô¡£

ºÍ±ðÈ˱ÈûÓÐÓã¬ÓÐЩÈ˾ÍÊÇϲ»¶B»°£¬Ã»Ê²Ã´Òâ˼¡£

È¡Æä¾«»ª¾ÍOK

 
2007Äê11ÔÂ25ÈÕ ÐÇÆÚÈÕ 18:24

Êǰ¡£¬ËµÐ©Ê²Ã´ÄØ£¿

²»Ëµ£¬ºÈÎÒµÄˮȥ£¬×ì¸É

×î½ü²»ÉÙÐֵܽãÃÃÖ§³Ö¹ýÎÒ£¬¹þ¹þ£¬Ð¡µÜÏÈл¹ý¡£

×Ôϰȥ¡£

 
2007Äê11ÔÂ16ÈÕ ÐÇÆÚÎå 23:55

«έÄãÊÇ×î°ôµÄ

²»¹ýÄÇÁ½¸öרҵµÄ¸Ð¾õ²»Ó¦¸Ã¸úͨË×µÄÔÚÒ»Æð±ÈÈü

àÅ£¬ÎÒÒ²ÏëͶƱ£¬¿ÉÊÇû°³µÄ·Ý.............

 
2007Äê11ÔÂ10ÈÕ ÐÇÆÚÁù 19:51

àÅ£¬ÏÈÈ¥×ö¸ö±ÊÊÔ£¬È»ºóÈ¥ÑнÌ¥ȷÈÏ£¬ÕÕÏà

±ÊÊÔ²»¹ýÊǸö¹ý³¡¶øÒÑ£¬¾ÍËã¹ýÁËÒ²²»È¥¡£ÎÒÊÇ¿¼ÑеÄÈË¡£

Ñ¡ÔñÁË£¬¾ÍÒª¼á³Ö¡£

 
2007Äê11ÔÂ10ÈÕ ÐÇÆÚÁù 19:32
Ò»ÂùÁ¦¹¥»÷¹¹³Éǧ·½°Ù¼ÆÂ룬×éºÏ£¬»òÃÜÂ룬ֱµ½ÄãÕÒµ½ÕýÈ·µÄ¡£

Determining the Difficulty of a Brute Force Attack¶¨ÄѶÈÒ»¸öÂùÁ¦¹¥»÷

The difficulty of a brute force attack depends on several factors, such as:À§ÄÑÒ»¸öÂùÁ¦¹¥»÷£¬È¡¾öÓÚ¼¸¸öÒòËØ£¬ÀýÈ磺

  • How long can the key be?ÈçºÎÄܳ¤¾ÃµÄ¹Ø¼üÊÇʲô£¿
  • How many possible values can each component of the key have?ÓжàÉÙ¿ÉÄܵÄÖµ¿É¸÷×é³É²¿·ÖµÄ¹Ø¼üÊÇʲô£¿
  • How long will it take to attempt each key?¶à¾Ã²ÅÄܳ¢ÊÔÿ¸ö¹Ø¼ü£¿
  • Is there a mechanism which will lock the attacker out after a number of failed attempts?ÊÇ·ñÓÐÒ»¸ö»úÖÆ£¬Õâ»áËø¶¨¹¥»÷ºó£¬Ò»Ð©Ê§°ÜµÄ³¢ÊÔ£¿

As an example, imagine a system which only allows 4 digit PIN codes.×÷Ϊһ¸öÀý×Ó£¬ÏëÏóÒ»¸öϵͳ£¬Ö»ÔÊÐíµÚ4λÊý×ÖÃÜÂë¡£ This means that there are a maximum of 10,000 possible PIN combinations.ÕâÒâζ×ÅÓг¬¹ýÒ»Íò¾¡¿ÉÄÜÏú×éºÏ¡£

Increasing Security Against a Brute Force AttackÔ½À´Ô½¶àµÄ°²È«¶ÔÒ»¸öÂùÁ¦¹¥»÷

From the example above, PIN security could be increased by:´ÓÉÏÃæµÄÀý×ÓÖУ¬ÃÜÂëµÄ°²È«£¬¿ÉÒÔÔö¼Ó£º

  • Increasing the length of the PINÔö¼Ó³¤¶ÈµÄÃÜÂë
  • Allowing the PIN to contain characters other than numbers, such as * or #ÔÊÐí¸öÈËÃÜÂ룬ÒÔ¿ØÖÆ×Ö·ûÒÔÍâµÄÆäËûºÅÂ룬Èç*»ò££
  • Imposing a 30 second delay between failed authentication attemptsÖÆ¶¨Ò»¸ö30ÃëÖÓµÄÑÓÎóÖ®¼äûÓÐÈÏÖ¤µÄÆóͼ
  • Locking the account after 5 failed authentication attemptsËø¶¨ÕÊ»§ºó£¬ÎåÈÕδÈÏÖ¤³¢ÊÔ
 
2007Äê11ÔÂ10ÈÕ ÐÇÆÚÁù 18:21
¡¡¡¡1£®±ÜÃâ°²×°ÔÚÖ÷Óò¿ØÖÆÆ÷ÉÏ

¡¡¡¡ÔÚ°²×°IISÖ®ºó£¬½«ÔÚ°²×°µÄ¼ÆËã»úÉÏÉú³ÉIUSR_ComputernameÄäÃûÕË»§£¬¸ÃÕË»§±»Ìí¼Óµ½ÓòÓû§×éÖУ¬´Ó¶ø°ÑÓ¦ÓÃÓÚÓòÓû§×éµÄ·ÃÎÊȨÏÞÌṩ¸ø·ÃÎÊWeb·þÎñÆ÷µÄÿ¸öÄäÃûÓû§¡£Õâ²»½ö»á¸øIIS´øÀ´¾Þ´óµÄDZÔÚΣÏÕ£¬¶øÇÒ»¹¿ÉÄÜÇ£Á¬Õû¸öÓò×ÊÔ´µÄ°²È«¡£Òª¾¡¿ÉÄܱÜÃâ°ÑIIS°²×°ÔÚÓò¿ØÖÆÆ÷ÉÏ£¬ÓÈÆäÊÇÖ÷Óò¿ØÖÆÆ÷¡£

¡¡¡¡2£®±ÜÃâ°²×°ÔÚϵͳ·ÖÇøÉÏ

¡¡¡¡°ÑIIS°²·ÅÔÚϵͳ·ÖÇøÉÏ£¬»áʹϵͳÎļþÓëIISͬÑùÃæÁÙ·Ç·¨·ÃÎÊ£¬ÈÝÒ×ʹ·Ç·¨Óû§ÇÖÈëϵͳ·ÖÇø¡£

¡¡¡¡Óû§¿ØÖƵݲȫÐÔ

¡¡¡¡1£®ÄäÃûÓû§

°²×°IISºó²úÉúµÄÄäÃûÓû§IUSR_Computername£¨ÃÜÂëËæ»ú²úÉú£©£¬ÆäÄäÃû·ÃÎʸøWeb·þÎñÆ÷´øÀ´Ç±ÔڵݲȫÐÔÎÊÌ⣬Ӧ¶ÔÆäȨÏÞ¼ÓÒÔ¿ØÖÆ¡£ÈçÎÞÄäÃû·ÃÎÊÐèÒª£¬¿ÉÈ¡ÏûWebµÄÄäÃû·þÎñ¡£¾ßÌå·½·¨ÈçÏ¡£

£¨1£©Æô¶¯ISM£¨Internet Server Manager£©¡£
£¨2£©Æô¶¯WWW·þÎñÊôÐÔÒ³¡£
£¨3£©È¡ÏûÆäÄäÃû·ÃÎÊ·þÎñ¡£


¡¡¡¡2£®Ò»°ãÓû§

¡¡¡¡Í¨¹ýʹÓÃÊý×ÖÓë×Öĸ£¨°üÀ¨´óСд£©½áºÏµÄ¿ÚÁÌá¸ßÐÞ¸ÄÃÜÂëµÄƵÂÊ£¬·âËøÊ§°ÜµÄµÇ¼³¢ÊÔ¼°ÕË»§µÄÉú´æÆÚµÈ·½·¨¶ÔÒ»°ãÓû§ÕË»§½øÐйÜÀí¡£

¡¡¡¡IIS¶ÔIPµØÖ·ºÍÓòÃûµÄÏÞÖÆ

¡¡¡¡IIS¿ÉÒÔ±»ÉèÖÃΪ¸ù¾ÝÓû§»ò¹¤×÷×éµÄIPµØÖ·»òÓòÃû¿ØÖÆÆä·ÃÎÊWebÕ¾µã¡¢ÐéÄâĿ¼ºÍµ¥¶ÀÎļþ¡£ÔÚInternet·þÎñ¹ÜÀíÆ÷ÖУ¬Ñ¡ÔñÒªÉèÖõÄÕ¾µã£¬Èç"ĬÈÏWebÕ¾µã"£¬µ¥»÷¡¾ÊôÐÔ¡¿°´Å¥£¬ÔÚ¶Ô»°¿òÖеÄ"Ŀ¼°²È«ÐÔ"Ñ¡ÏÖУ¬µ¥»÷"IPµØÖ·¼°ÓòÃûÏÞÖÆ"¿òÖеġ¾±à¼­¡¿°´Å¥£¬Èçͼ£±Ëùʾ¡£



ͼ1 ÉèÖÃIISÖеÄIPµØÖ·ºÍÓòÃûÏÞÖÆ



¡¡¡¡Èç¹ûÊǸøÐéÄâĿ¼»ò·þÎñÆ÷ÏÂÃæµÄÎļþÅäÖÃIPµØÖ·»òÓòÃûÏÞÖÆ£¬·½·¨ÓëÉÏÃæÀàËÆ¡£Îªµ¥¶ÀÎļþ½øÐÐÅäÖÃʱ£¬ÔÚMMC´°¿ÚÓÒ±ßÑ¡ÔñÒª²Ù×÷µÄÎļþ£¬È»ºóµ¥»÷Êó±êÓÒ¼ü£¬´Óµ¯³öµÄ¿ì½Ý²Ëµ¥ÖÐÑ¡Ôñ¡¾ÊôÐÔ¡¿Ñ¡Ï¾Í»á¿´µ½"Îļþ°²È«ÐÔ"Ñ¡Ï£¬ÆäÓಽÖèÍêȫһÑù¡£

¡¡¡¡IISȨÏÞµÄÉèÖÃ

¡¡¡¡IISȨÏÞµÄÉèÖÃÊÇÔÚInternet·þÎñ¹ÜÀíÆ÷ÖÐÏàÓ¦µÄÐéÄâ·þÎñÆ÷¡¢ÐéÄâĿ¼¡¢Ä¿Â¼¡¢ÎļþµÄÊôÐÔÖеÄÖ÷Ŀ¼¡¢ÐéÄâĿ¼¡¢Ä¿Â¼ºÍÎļþÖнøÐС£IIS 5.0ÌṩÁËÁ½ÖÖ·ÃÎÊȨÏÞ£º¶ÁÈ¡ºÍдÈëȨÏÞ¡£¶ÔÓÚÓ¦ÓóÌÐò¶øÑÔ£¬ÓÐ3ÖÖÖ´ÐÐÐí¿ÉÀà±ð£ºÎÞ¡¢´¿½Å±¾¡¢½Å±¾ºÍ¿ÉÖ´ÐгÌÐò¡£Èçͼ2Ëùʾ¡£

ͼ2 ÉèÖÃIISÖÐijһÐéÄâÕ¾µãµÄÓ¦ÓóÌÐòµÄÖ´ÐÐÐí¿É

¡¡¡¡¶ÔÓÚ²»Í¬µÄ×ÊÔ´£¬ÍƼöʹÓò»Í¬µÄIISȨÏÞ¡£
¡¡¡¡¾²Ì¬WebÄÚÈÝ£ºÊ¹ÓöÁȡȨÏÞ¡¢ÎÞÖ´ÐÐÐí¿É¡£
¡¡¡¡¶¯Ì¬WebÄÚÈÝ£ºÊ¹ÓöÁȡȨÏÞ¡¢´¿½Å±¾Ö´ÐÐÐí¿É¡£
¡¡¡¡½Å±¾ÄÚÈÝ£ºÊ¹ÓöÁȡȨÏÞ¡¢´¿½Å±¾Ö´ÐÐÐí¿É¡£
¡¡¡¡¿ÉÖ´ÐгÌÐò£ºÊ¹ÓöÁȡȨÏÞ¡¢½Å±¾ºÍ¿ÉÖ´ÐгÌÐòÖ´ÐÐÐí¿É¡£
¡¡¡¡Êý¾Ý¿âÄÚÈÝ£ºÊ¹ÓöÁÈ¡¡¢Ð´ÈëȨÏÞ£¬ÎÞÖ´ÐÐÐí¿É¡£


¡¡¡¡IISÉí·ÝÑéÖ¤

¡¡¡¡IISµÄÉí·ÝÑéÖ¤°²È«»úÖÆÓÐ4ÖÖÑéÖ¤·½·¨£ºÄäÃû·ÃÎÊ¡¢»ù±¾Éí·ÝÑéÖ¤£¨ÃÜÂëÓÃÃ÷ÎÄËͳö£©¡¢WindowsÓòµÄ¼òÒªÑéÖ¤ºÍ¼¯³ÉWindowsÑéÖ¤¡£ÕâЩÑéÖ¤·½·¨µÄ°²È«¼¶±ðÓɵ͵½¸ß¡£

¡¡¡¡ÄäÃû·ÃÎÊ

¡¡¡¡ÕâÊÇIISĬÈϵÄÓû§ÕË»§¡£ËüµÄÓû§ÃûÊÇÖ÷»úÃû£¬ÈçÃûΪbrightµÄÖ÷»úÔòÏÔʾΪIUSR_BRIGHT¡£¸ÃÓû§²»Äܸü¸ÄÃÜÂ룬²¢ÇÒÃÜÂëÓÀ²»¹ýÆÚ£¬Á¥ÊôÓÚGuests×é¡£²é¿´ÏµÍ³Ä¬Èϵݲȫ²ßÂÔ£¬Èçͼ£³Ëùʾ¡£



ͼ3 ϵͳĬÈϵݲȫ²ßÂÔ


¡¡¡¡Ä¬ÈÏÇé¿öϸÃÕË»§ÊÇÄäÃûµÄ£¬²¢ÇÒ¿ÉÒÔÔÚ±¾µØµÇ¼£¬ÕâÑùµÄÉèÖÃÊÇÓкܴóµÄ°²È«·çÏյģ¬ºÜ¶àÌáÉýȨÏÞ¶¼ÊÇ´ÓÕâ¸öÕË»§¿ªÊ¼µÄ¡£Îª±ÜÃâȨÏÞÌáÉýµÄ·çÏÕ£¬¿ÉÒÔÔÚÑéÖ¤·½·¨Öиü¸ÄÉèÖ㬻òÕ߸ü¸Ä¸ÃÕË»§µÄÓû§Ãû£¬»òÕß½ûÖ¹·ÃÎÊ¡£

¡¡¡¡»ù±¾Éí·ÝÑéÖ¤

¡¡¡¡´Ë·½Ê½ÊǾø´ó¶àÊýWWWä¯ÀÀÆ÷¶¼Ö§³ÖµÄ±ê×¼HTTP·½·¨£¬Èç¹û²ÉÓôËÑéÖ¤·½Ê½£¬ÄÇô¿Í»§¶Ë·ÃÎÊʱ»á¿´µ½ÈçϵĶԻ°¿ò£¬Èçͼ£´Ëùʾ¡£



ͼ4 IIS²ÉÓûù±¾Éí·ÝÑéÖ¤µÄÇé¾°



¡¡¡¡Èç¹ûÊäÈë3´Î¶¼´íÎóµÄ»°£¬IIS·þÎñÆ÷½«»á·µ»ØÏÂÃæµÄ´íÎóÐÅÏ¢£ºHTTP 401.1Ò³Ãæ¡£µ«ÕâÖÖÑéÖ¤·½Ê½²¢²»ÊǺܰ²È«µÄ£¬Óû§ÃûºÍÃÜÂëÊÇASCIIÃ÷ÎÄ£¬¿ÉÒÔÓÃSnifferÖ®ÀàµÄ¹¤¾ß¼àÌýµ½¡£ËùÒÔËüÖ»ÄÜÓÃÓÚ°²È«ÐÔÒªÇ󲻸ߵĻ·¾³ÖС£

¡¡¡¡WindowsÓòµÄ¼òÒªÑéÖ¤

¡¡¡¡´ËÑéÖ¤·½Ê½²»ÊÇͨÓõģ¬Ö»ÓÐInternet Explorer 5.0ÒÔÉϰ汾²ÅÄÜÖ§³Ö´Ë·½Ê½£¬²¢ÇÒ±ØÐëÊÇÓÐWindows 2000Óò¿ØÖÆÆ÷µÄÕ¾µã¡£ËüÊÇͨ¹ýHashË㷨ת»»ºó·¢ËÍ¿ÚÁ½«¿ÚÁî×÷ΪÎı¾Îļþ´æ·ÅÔÚÓò¿ØÖÆÆ÷ÉÏ£¬ÓÃÀ´±È½ÏIIS·¢Ë͵ÄÉ¢ÁС£¸Ã·½Ê½µÄ°²È«ÐÔ²»ÊǺܸߣ¬Ò»µ©±»ÈË»ñµÃÕâ¸öÎļþ¾ÍÄÜÆÆ½â¿ÚÁîÁË¡£

¡¡¡¡¼¯³ÉWindowsÑéÖ¤

¡¡¡¡Èç¹ûÓû§ÊǺϷ¨µÄWindows ÓòÓû§£¬µÇ¼µ½Windows 2000Óò¿ØÖÆÆ÷µÄÕ¾µã£¬ÑéÖ¤¹ý³Ì¶ÔÓû§¶øÑÔÊÇ͸Ã÷µÄ¡£Óò¿ØÖÆÆ÷±ØÐë¿ÉÒÔ·ÃÎÊ£¬²¢ÇÒÖ»ÓÐInternet Explorer 2.0ÒÔÉϰ汾²ÅÄÜÖ§³ÖÕâÖÖÑéÖ¤·½Ê½¡£ÒÔÉÏÑéÖ¤·½Ê½¿ÉÒÔ×ÛºÏʹÓá£

¡¡¡¡·ÃÎÊȨÏÞ¿ØÖÆ

¡¡¡¡Îļþ¼ÐºÍÎļþµÄ·ÃÎÊȨÏÞ

¡¡¡¡°²·ÅÔÚNTFSÎļþϵͳÉϵÄÎļþ¼ÐºÍÎļþ£¬Ò»·½ÃæÒª¶ÔÆäȨÏÞ¼ÓÒÔ¿ØÖÆ£¬¶Ô²»Í¬µÄÓû§×éºÍÓû§½øÐв»Í¬µÄȨÏÞÉèÖã»ÁíÍ⣬»¹¿ÉÀûÓÃNTFSµÄÉóºË¹¦ÄܶÔÄ³Ð©ÌØ¶¨Óû§×é³ÉÔ±¶ÁÎļþµÄÆóͼµÈ½øÐÐÉóºË£¬ÓÐЧµØÍ¨¹ý¼àÊÓÎļþ·ÃÎÊ¡¢Óû§¶ÔÏóµÄʹÓõȷ¢ÏÖ·Ç·¨Óû§½øÐзǷ¨»î¶¯µÄǰÕ×£¬¼°Ê±¼ÓÒÔÔ¤·ÀÖÆÖ¹¡£¾ßÌå·½·¨ÈçÏ¡£

£¨1£©Æô¶¯"ÓòÓû§¹ÜÀíÆ÷"¡£

£¨2£©µ¥»÷¡¾¹æÔò¡¿²Ëµ¥Ïµġ¾ÉóºË¡¿Ñ¡Ïî¡£

£¨3£©ÉèÖÃ"ÉóºË¹æÔò"¡£

¡¡¡¡WWWĿ¼µÄ·ÃÎÊȨÏÞ

¡¡¡¡ÒѾ­ÉèÖóÉWebĿ¼µÄÎļþ¼Ð£¬¿ÉÒÔͨ¹ý²Ù×÷WebÕ¾µãÊôÐÔҳʵÏÖ¶ÔWWWĿ¼·ÃÎÊȨÏ޵ĿØÖÆ£¬¶ø¸ÃĿ¼ÏµÄËùÓÐÎļþºÍ×ÓÎļþ¼Ð¶¼½«¼Ì³ÐÕâЩ°²È«ÐÔ¡£WWW·þÎñ³ýÁËÌṩNTFSÎļþϵͳÌṩµÄȨÏÞÍ⣬»¹Ìṩ¶ÁȡȨÏÞ£¬ÔÊÐíÓû§¶ÁÈ¡»òÏÂÔØWWWĿ¼ÖеÄÎļþ£¬Ö´ÐÐȨÏÞÔòÔÊÐíÓû§ÔËÐÐWWWĿ¼ÏµijÌÐòºÍ½Å±¾¡£¾ßÌåÉèÖ÷½·¨ÈçÏ¡£

£¨1£©Æô¶¯ISM£¨Internet·þÎñÆ÷¹ÜÀíÆ÷£©¡£

£¨2£©Æô¶¯WebÊôÐÔÒ³²¢Ñ¡Ôñ"Ŀ¼"Ñ¡Ï¡£

£¨3£©Ñ¡ÔñWWWĿ¼¡£

£¨4£©Ñ¡Ôñ"±à¼­ÊôÐÔ"ÖеÄ"Ŀ¼ÊôÐÔ"½øÐÐÉèÖá£

¡¡¡¡¶Ë¿Ú°²È«ÐÔµÄʵÏÖ

¡¡¡¡¶ÔÓÚIIS·þÎñ£¬ÎÞÂÛÊÇWWWÕ¾µã¡¢FTPÕ¾µã£¬»¹ÊÇNNTP¡¢SMTP·þÎñµÈ¶¼Óи÷×Ô¼àÌýºÍ½ÓÊÕä¯ÀÀÆ÷ÇëÇóµÄTCP¶Ë¿ÚºÅ£¨Port£©¡£Ò»°ã³£ÓõĶ˿ںÅΪ£ºWWWÊÇ80£¬FTPÊÇ21£¬SMTPÊÇ25¡£Óû§¿ÉÒÔͨ¹ýÐ޸Ķ˿ںÅÌá¸ßIIS·þÎñÆ÷µÄ°²È«ÐÔ¡£Èç¹ûÓû§ÐÞ¸ÄÁ˶˿ÚÉèÖã¬Ö»ÓÐÖªµÀ¶Ë¿ÚºÅµÄÓû§²Å¿ÉÒÔ·ÃÎÊ£¬µ«Óû§ÔÚ·ÃÎÊʱÐèÒªÖ¸¶¨Ð¶˿ںš£

¡¡¡¡IPת·¢µÄ°²È«ÐÔ

¡¡¡¡IIS·þÎñ¿ÉÌṩIPÊý¾Ý°üת·¢¹¦ÄÜ£¬´Ëʱ£¬³äµ±Â·ÓÉÆ÷½ÇÉ«µÄIIS·þÎñÆ÷½«»á°Ñ´ÓInternet½Ó¿ÚÊÕµ½µÄIPÊý¾Ý°üת·¢µ½ÄÚ²¿ÍøÖУ¬½ûÓÃÕâÒ»¹¦Äܲ»Ê§ÎªÌá¸ß°²È«ÐԵĺð취¡£¾ßÌåÉèÖÃÈçÏ¡£

£¨1£©Æô¶¯"ÍøÂçÊôÐÔ"²¢Ñ¡Ôñ"ЭÒé"Ñ¡Ï¡£

£¨2£©ÔÚTCP/IPÊôÐÔÖÐÈ¥µô"·ÓÉÑ¡Ôñ"¡£

¡¡¡¡SSL°²È«»úÖÆ

¡¡¡¡IISµÄÉí·ÝÈÏÖ¤³ýÄäÃû·ÃÎÊ¡¢»ù±¾ÑéÖ¤ºÍWindows NTÇëÇó/ÏìÓ¦·½Ê½Í⣬»¹ÓÐÒ»ÖÖ°²È«ÐÔ¸ü¸ßµÄÈÏÖ¤£ºÍ¨¹ýSSL£¨Security Socket Layer£©°²È«»úÖÆÊ¹ÓÃÊý×ÖÖ¤Êé¡£

¡¡¡¡SSL£¨¼ÓÃÜÌ×½Ó×ÖЭÒé²ã£©Î»ÓÚHTTP²ãºÍTCP²ãÖ®¼ä£¬½¨Á¢Óû§Óë·þÎñÆ÷Ö®¼äµÄ¼ÓÃÜͨÐÅ£¬È·±£Ëù´«µÝÐÅÏ¢µÄ°²È«ÐÔ¡£SSLÊǹ¤×÷ÔÚ¹«¹²ÃÜÔ¿ºÍ˽ÈËÃÜÔ¿»ù´¡Éϵģ¬ÈκÎÓû§¶¼¿ÉÒÔ»ñµÃ¹«¹²ÃÜÔ¿À´¼ÓÃÜÊý¾Ý£¬µ«½âÃÜÊý¾Ý±ØÐëҪͨ¹ýÏàÓ¦µÄ˽ÈËÃÜÔ¿¡£

¡¡¡¡Ê¹ÓÃSSL°²È«»úÖÆÊ±£¬Ê×Ïȿͻ§¶ËÓë·þÎñÆ÷½¨Á¢Á¬½Ó£¬·þÎñÆ÷°ÑËüµÄÊý×ÖÖ¤ÊéÓ빫¹²ÃÜÔ¿Ò»²¢·¢Ë͸ø¿Í»§¶Ë¡£¿Í»§¶ËËæ»úÉú³É»á»°ÃÜÔ¿£¬ÓôӷþÎñÆ÷µÃµ½µÄ¹«¹²ÃÜÔ¿¶Ô»á»°ÃÜÔ¿½øÐмÓÃÜ£¬²¢°Ñ»á»°ÃÜÔ¿ÔÚÍøÂçÉÏ´«µÝ¸ø·þÎñÆ÷¡£¶ø»á»°ÃÜÔ¿Ö»ÓÐÔÚ·þÎñÆ÷¶ËÓÃ˽ÈËÃÜÔ¿²ÅÄܽâÃÜ£¬ÕâÑù£¬¿Í»§¶ËºÍ·þÎñÆ÷¶Ë¾Í½¨Á¢ÁËÒ»¸öΩһµÄ°²È«Í¨µÀ¡£¾ßÌå²½ÖèÈçÏ£º

£¨1£©Æô¶¯ISM²¢´ò¿ªWebÕ¾µãµÄÊôÐÔÒ³¡£

£¨2£©Ñ¡Ôñ"Ŀ¼°²È«ÐÔ"Ñ¡Ï¡£

£¨3£©µ¥»÷¡¾ÃÜÔ¿¹ÜÀíÆ÷¡¿°´Å¥¡£

£¨4£©Í¨¹ýÃÜÔ¿¹ÜÀíÆ÷Éú³ÉÃÜÔ¿¶ÔÎļþºÍÇëÇóÎļþ¡£

£¨5£©´ÓÉí·ÝÈÏ֤ȨÏÞÖÐÉêÇëÒ»¸öÖ¤Êé¡£

£¨6£©Í¨¹ýÃÜÔ¿¹ÜÀíÆ÷ÔÚ·þÎñÆ÷Éϰ²×°Ö¤Êé¡£

£¨7£©¼¤»îWebÕ¾µãµÄSSL°²È«ÐÔ¡£

¡¡¡¡½¨Á¢ÁËSSL°²È«»úÖÆºó£¬Ö»ÓÐSSLÔÊÐíµÄ¿Í»§²ÅÄÜÓëSSLÔÊÐíµÄWebÕ¾µã½øÐÐͨÐÅ£¬²¢ÇÒÔÚʹÓÃURL×ÊÔ´¶¨Î»Æ÷ʱ£¬ÊäÈëhttps://£¬¶ø²»ÊÇhttp://¡£SSL°²È«»úÖÆµÄʵÏÖ½«Ôö´óϵͳ¿ªÏú£¬Ôö¼ÓÁË·þÎñÆ÷CPUµÄ¶îÍ⸺µ££¬´Ó¶ø½µµÍÁËϵͳÐÔÄÜ£¬Ôڹ滮ʱ½¨Òé½ö¿¼ÂÇΪ¸ßÃô¸Ð¶ÈµÄWebĿ¼ʹÓá£ÁíÍ⣬SSL¿Í»§¶ËÐèÒªIE 3.0¼°ÒÔÉϰ汾²ÅÄÜʹÓá£
 
2007Äê11ÔÂ10ÈÕ ÐÇÆÚÁù 18:08
µÚÒ»²¿·Ö SYN FloodµÄ»ù±¾Ô­Àí

  

SYN FloodÊǵ±Ç°×îÁ÷ÐеÄDoS£¨¾Ü¾ø·þÎñ¹¥»÷£©ÓëDDoS£¨·Ö²¼Ê½¾Ü¾ø·þÎñ¹¥»÷£©µÄ·½Ê½Ö®Ò»£¬ÕâÊÇÒ»ÖÖÀûÓÃTCPЭÒéȱÏÝ£¬·¢ËÍ´óÁ¿Î±ÔìµÄTCPÁ¬½ÓÇëÇ󣬴ӶøÊ¹µÃ±»¹¥»÷·½×ÊÔ´ºÄ¾¡£¨CPUÂú¸ººÉ»òÄÚ´æ²»×㣩µÄ¹¥»÷·½Ê½¡£

  

ÒªÃ÷°×ÕâÖÖ¹¥»÷µÄ»ù±¾Ô­Àí£¬»¹ÊÇÒª´ÓTCPÁ¬½Ó½¨Á¢µÄ¹ý³Ì¿ªÊ¼ËµÆð£º

´ó¼Ò¶¼ÖªµÀ£¬TCPÓëUDP²»Í¬£¬ËüÊÇ»ùÓÚÁ¬½ÓµÄ£¬Ò²¾ÍÊÇ˵£ºÎªÁËÔÚ·þÎñ¶ËºÍ¿Í»§¶ËÖ®¼ä´«ËÍTCPÊý¾Ý£¬±ØÐëÏȽ¨Á¢Ò»¸öÐéÄâµç·£¬Ò²¾ÍÊÇTCPÁ¬½Ó£¬½¨Á¢TCPÁ¬½ÓµÄ±ê×¼¹ý³ÌÊÇÕâÑùµÄ£º

Ê×ÏÈ£¬ÇëÇó¶Ë£¨¿Í»§¶Ë£©·¢ËÍÒ»¸ö°üº¬SYN±êÖ¾µÄTCP±¨ÎÄ£¬SYN¼´Í¬²½£¨Synchronize£©£¬Í¬²½±¨ÎÄ»áÖ¸Ã÷¿Í»§¶ËʹÓõĶ˿ÚÒÔ¼°TCPÁ¬½ÓµÄ³õʼÐòºÅ£»

µÚ¶þ²½£¬·þÎñÆ÷ÔÚÊÕµ½¿Í»§¶ËµÄSYN±¨Îĺ󣬽«·µ»ØÒ»¸öSYN+ACKµÄ±¨ÎÄ£¬±íʾ¿Í»§¶ËµÄÇëÇó±»½ÓÊÜ£¬Í¬Ê±TCPÐòºÅ±»¼ÓÒ»£¬ACK¼´È·ÈÏ£¨Acknowledgement£©¡£

µÚÈý²½£¬¿Í»§¶ËÒ²·µ»ØÒ»¸öÈ·Èϱ¨ÎÄACK¸ø·þÎñÆ÷¶Ë£¬Í¬ÑùTCPÐòÁкű»¼ÓÒ»£¬µ½´ËÒ»¸öTCPÁ¬½ÓÍê³É¡£

ÒÔÉϵÄÁ¬½Ó¹ý³ÌÔÚTCPЭÒéÖб»³ÆÎªÈý´ÎÎÕÊÖ£¨Three-way Handshake£©¡£

  

ÎÊÌâ¾Í³öÔÚTCPÁ¬½ÓµÄÈý´ÎÎÕÊÖÖУ¬¼ÙÉèÒ»¸öÓû§Ïò·þÎñÆ÷·¢ËÍÁËSYN±¨ÎĺóͻȻËÀ»ú»òµôÏߣ¬ÄÇô·þÎñÆ÷ÔÚ·¢³öSYN+ACKÓ¦´ð±¨ÎĺóÊÇÎÞ·¨ÊÕµ½¿Í»§¶ËµÄACK±¨Îĵ썵ÚÈý´ÎÎÕÊÖÎÞ·¨Íê³É£©£¬ÕâÖÖÇé¿öÏ·þÎñÆ÷¶ËÒ»°ã»áÖØÊÔ£¨Ôٴη¢ËÍSYN+ACK¸ø¿Í»§¶Ë£©²¢µÈ´ýÒ»¶Îʱ¼äºó¶ªÆúÕâ¸öδÍê³ÉµÄÁ¬½Ó£¬Õâ¶Îʱ¼äµÄ³¤¶ÈÎÒÃdzÆÎªSYN Timeout£¬Ò»°ãÀ´ËµÕâ¸öʱ¼äÊÇ·ÖÖÓµÄÊýÁ¿¼¶£¨´óԼΪ30Ãë-2·ÖÖÓ£©£»Ò»¸öÓû§³öÏÖÒì³£µ¼Ö·þÎñÆ÷µÄÒ»¸öÏ̵߳ȴý1·ÖÖÓ²¢²»ÊÇʲôºÜ´óµÄÎÊÌ⣬µ«Èç¹ûÓÐÒ»¸ö¶ñÒâµÄ¹¥»÷Õß´óÁ¿Ä£ÄâÕâÖÖÇé¿ö£¬·þÎñÆ÷¶Ë½«ÎªÁËά»¤Ò»¸ö·Ç³£´óµÄ°ëÁ¬½ÓÁÐ±í¶øÏûºÄ·Ç³£¶àµÄ×ÊÔ´----ÊýÒÔÍò¼ÆµÄ°ëÁ¬½Ó£¬¼´Ê¹ÊǼòµ¥µÄ±£´æ²¢±éÀúÒ²»áÏûºÄ·Ç³£¶àµÄCPUʱ¼äºÍÄڴ棬ºÎ¿ö»¹Òª²»¶Ï¶ÔÕâ¸öÁбíÖеÄIP½øÐÐSYN+ACKµÄÖØÊÔ¡£Êµ¼ÊÉÏÈç¹û·þÎñÆ÷µÄTCP/IPÕ»²»¹»Ç¿´ó£¬×îºóµÄ½á¹ûÍùÍùÊǶÑÕ»Òç³ö±ÀÀ£---¼´Ê¹·þÎñÆ÷¶ËµÄϵͳ×㹻ǿ´ó£¬·þÎñÆ÷¶ËÒ²½«Ã¦ÓÚ´¦Àí¹¥»÷ÕßαÔìµÄTCPÁ¬½ÓÇëÇó¶øÎÞϾÀí²Ç¿Í»§µÄÕý³£ÇëÇ󣨱Ͼ¹¿Í»§¶ËµÄÕý³£ÇëÇó±ÈÂʷdz£Ö®Ð¡£©£¬´Ëʱ´ÓÕý³£¿Í»§µÄ½Ç¶È¿´À´£¬·þÎñÆ÷ʧȥÏìÓ¦£¬ÕâÖÖÇé¿öÎÒÃdzÆ×÷£º·þÎñÆ÷¶ËÊܵ½ÁËSYN Flood¹¥»÷£¨SYNºéË®¹¥»÷£©¡£

  

´Ó·ÀÓù½Ç¶ÈÀ´Ëµ£¬Óм¸ÖÖ¼òµ¥µÄ½â¾ö·½·¨£¬µÚÒ»ÖÖÊÇËõ¶ÌSYN Timeoutʱ¼ä£¬ÓÉÓÚSYN Flood¹¥»÷µÄЧ¹ûÈ¡¾öÓÚ·þÎñÆ÷Éϱ£³ÖµÄSYN°ëÁ¬½ÓÊý£¬Õâ¸öÖµ=SYN¹¥»÷µÄƵ¶È x   SYN Timeout£¬ËùÒÔͨ¹ýËõ¶Ì´Ó½ÓÊÕµ½SYN±¨Îĵ½È·¶¨Õâ¸ö±¨ÎÄÎÞЧ²¢¶ªÆú¸ÄÁ¬½ÓµÄʱ¼ä£¬ÀýÈçÉèÖÃΪ20ÃëÒÔÏ£¨¹ýµÍµÄSYN TimeoutÉèÖÿÉÄÜ»áÓ°Ïì¿Í»§µÄÕý³£·ÃÎÊ£©£¬¿ÉÒԳɱ¶µÄ½µµÍ·þÎñÆ÷µÄ¸ººÉ¡£

     µÚ¶þÖÖ·½·¨ÊÇÉèÖÃSYN Cookie£¬¾ÍÊǸøÃ¿Ò»¸öÇëÇóÁ¬½ÓµÄIPµØÖ··ÖÅäÒ»¸öCookie£¬Èç¹û¶Ìʱ¼äÄÚÁ¬ÐøÊܵ½Ä³¸öIPµÄÖØ¸´SYN±¨ÎÄ£¬¾ÍÈ϶¨ÊÇÊܵ½Á˹¥»÷£¬ÒÔºó´ÓÕâ¸öIPµØÖ·À´µÄ°ü»á±»Ò»¸Å¶ªÆú¡£

     ¿ÉÊÇÉÏÊöµÄÁ½ÖÖ·½·¨Ö»ÄܶԸ¶±È½ÏԭʼµÄSYN Flood¹¥»÷£¬Ëõ¶ÌSYN Timeoutʱ¼ä½öÔÚ¶Ô·½¹¥»÷Ƶ¶È²»¸ßµÄÇé¿öÏÂÉúЧ£¬SYN Cookie¸üÒÀÀµÓÚ¶Ô·½Ê¹ÓÃÕæÊµµÄIPµØÖ·£¬Èç¹û¹¥»÷ÕßÒÔÊýÍò/ÃëµÄËÙ¶È·¢ËÍSYN±¨ÎÄ£¬Í¬Ê±ÀûÓÃSOCK_RAWËæ»ú¸ÄдIP±¨ÎÄÖеÄÔ´µØÖ·£¬ÒÔÉϵķ½·¨½«ºÁÎÞÓÃÎäÖ®µØ¡£

  

  

  

  

  

  

  

  

µÚ¶þ²¿·Ý SYN FlooderÔ´Âë½â¶Á

  

     ÏÂÃæÎÒÃÇÀ´·ÖÎöSYN FlooderµÄ³ÌÐòʵÏÖ¡£

Ê×ÏÈ£¬ÎÒÃÇÀ´¿´Ò»ÏÂTCP±¨Îĵĸñʽ£º

  

0         1         2         3         4         5         6

     0 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 2 4 6 8 0 2 4

     +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |       £É£ÐÊײ¿       |     £Ô£Ã£ÐÊײ¿       |     £Ô£Ã£ÐÊý¾Ý¶Î¡¡¡¡   |

+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

               ͼһ TCP±¨ÎĽṹ

  

ÈçÉÏͼËùʾ£¬Ò»¸öTCP±¨ÎÄÓÉÈý¸ö²¿·Ö¹¹³É£º20×Ö½ÚµÄIPÊײ¿¡¢20×Ö½ÚµÄTCPÊײ¿Óë²»¶¨³¤µÄÊý¾Ý¶Î£¬£¨Êµ¼Ê²Ù×÷ʱ¿ÉÄÜ»áÓпÉÑ¡µÄIPÑ¡ÏÕâÖÖÇé¿öÏÂTCPÊײ¿Ïòºó˳ÑÓ£©ÓÉÓÚÎÒÃÇÖ»ÊÇ·¢ËÍÒ»¸öSYNÐźţ¬²¢²»´«µÝÈκÎÊý¾Ý£¬ËùÒÔTCPÊý¾Ý¶ÎΪ¿Õ¡£TCPÊײ¿µÄÊý¾Ý½á¹¹Îª£º

  

   0                   1                   2                   3  

   0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |             Ê®ÁùλԴ¶Ë¿ÚºÅ     |           Ê®ÁùλĿ±ê¶Ë¿ÚºÅ     |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                         ÈýÊ®¶þλÐòÁкŠ                        |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                         ÈýÊ®¶þλȷÈϺŠ                        |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   | ËÄλ   |           |U|A|P|R|S|F|                               |

   | Êײ¿   |Áùλ±£Áôλ |R|C|S|S|Y|I|         Ê®Áùλ´°¿Ú´óС         |

   | ³¤¶È   |           |G|K|H|T|N|N|                               |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |           Ê®ÁùλУÑéºÍ         |         Ê®Áùλ½ô¼±Ö¸Õë         |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                           Ñ¡ÏÈôÓУ©                         |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                           Êý¾Ý£¨ÈôÓУ©                         |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

                       ͼ¶þ   TCPÊײ¿½á¹¹

  

¸ù¾ÝTCP±¨Îĸñʽ£¬ÎÒÃǶ¨ÒåÒ»¸ö½á¹¹TCP_HEADERÓÃÀ´´æ·ÅTCPÊײ¿£º

typedef struct _tcphdr              

{

         USHORT th_sport;               //16λԴ¶Ë¿Ú

     USHORT th_dport;             //16λĿµÄ¶Ë¿Ú

         unsigned int th_seq;         //32λÐòÁкÅ

         unsigned int th_ack;         //32λȷÈϺÅ

         unsigned char th_lenres;         //4λÊײ¿³¤¶È+6λ±£Áô×ÖÖеÄ4λ

         unsigned char th_flag;             //2λ±£Áô×Ö+6λ±ê־λ

         USHORT th_win;                 //16λ´°¿Ú´óС

         USHORT th_sum;                 //16λУÑéºÍ

         USHORT th_urp;                 //16λ½ô¼±Êý¾ÝÆ«ÒÆÁ¿

}TCP_HEADER;

ͨ¹ýÒÔÕýÈ·µÄÊý¾ÝÌî³äÕâ¸ö½á¹¹²¢½«TCP_HEADER.th_flag¸³ÖµÎª2£¨¶þ½øÖƵÄ00000010£©ÎÒÃÇÄÜÖÆÔìÒ»¸öSYNµÄTCP±¨ÎÄ£¬Í¨¹ý´óÁ¿·¢ËÍÕâ¸ö±¨ÎÄ¿ÉÒÔʵÏÖSYN FloodµÄЧ¹û¡£µ«ÊÇΪÁ˽øÐÐIPÆÛÆ­´Ó¶øÒþ²Ø×Ô¼º£¬Ò²ÎªÁ˶ã±Ü·þÎñÆ÷µÄSYN Cookie¼ì²é£¬»¹ÐèÒªÖ±½Ó¶ÔIPÊײ¿½øÐвÙ×÷£º

0                   1                   2                   3  

   0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   | °æ±¾   | ³¤¶È   | °Ëλ·þÎñÀàÐÍ   |         Ê®Áùλ×ܳ¤¶È           |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |           Ê®Áùλ±êʶ           | ±êÖ¾|   Ê®ÈýÎ»Æ¬Æ«ÒÆ¡¡¡¡       |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   | °ËλÉú´æÊ±¼ä   |   °ËλЭÒé     |         Ê®ÁùλÊײ¿Ð£ÑéºÍ       |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                       ÈýÊ®¶þλԴ£É£ÐµØÖ·                   ¡¡¡¡|

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                     ÈýÊ®¶þλĿµÄ£É£ÐµØÖ·                       |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                           Ñ¡ÏÈôÓУ©                         |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

   |                           ¡¡¡¡Êý¾Ý¡¡¡¡                         |

   +-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+

                         ͼÈý   IPÊײ¿½á¹¹

ͬÑù¶¨ÒåÒ»¸öIP_HEADERÀ´´æ·ÅIPÊײ¿

typedef struct _iphdr

{

         unsigned char h_verlen;             //4λÊײ¿³¤¶È+4λIP°æ±¾ºÅ

         unsigned char tos;               //8λ·þÎñÀàÐÍTOS

         unsigned short total_len;       //16λ×ܳ¤¶È£¨×Ö½Ú£©

         unsigned short ident;             //16λ±êʶ

         unsigned short frag_and_flags;   //3λ±ê־λ

         unsigned char   ttl;               //8λÉú´æÊ±¼ä TTL

         unsigned char proto;         //8λЭÒéºÅ(TCP, UDP »òÆäËû)

         unsigned short checksum;         //16λIPÊײ¿Ð£ÑéºÍ

         unsigned int sourceIP;             //32λԴIPµØÖ·

         unsigned int destIP;         //32λĿµÄIPµØÖ·

}IP_HEADER;

È»ºóͨ¹ýSockRaw=WSASocket(AF_INET,SOCK_RAW,IPPROTO_RAW,NULL,0,WSA_FLAG_OVERLAPPED));

     ½¨Á¢Ò»¸öԭʼÌ×½Ó¿Ú£¬ÓÉÓÚÎÒÃǵÄIPÔ´µØÖ·ÊÇαÔìµÄ£¬ËùÒÔ²»ÄÜÖ¸Íûϵͳ°ïÎÒÃǼÆËãIPУÑéºÍ£¬ÎÒÃǵÃÔÚÔÚsetsockoptÖÐÉèÖÃIP_HDRINCL¸æËßϵͳ×Ô¼ºÌî³äIPÊײ¿²¢×Ô¼º¼ÆËãУÑéºÍ£º

     flag=TRUE;

     setsockopt(SockRaw,IPPROTO_IP,IP_HDRINCL,(char *)&flag,sizeof(int));

IPУÑéºÍµÄ¼ÆËã·½·¨ÊÇ£ºÊ×ÏȽ«IPÊײ¿µÄУÑéºÍ×Ö¶ÎÉèΪ0£¨IP_HEADER.checksum=0£©,È»ºó¼ÆËãÕû¸öIPÊײ¿£¨°üÀ¨Ñ¡ÏµÄ¶þ½øÖÆ·´ÂëµÄºÍ£¬Ò»¸ö±ê×¼µÄУÑéºÍº¯ÊýÈçÏÂËùʾ£º

USHORT checksum(USHORT *buffer, int size)

{

unsigned long cksum=0;

         while(size >1) {

             cksum+=*buffer++;

             size -=sizeof(USHORT);

         }

         if(size ) cksum += *(UCHAR*)buffer;

     cksum = (cksum >> 16) + (cksum & 0xffff);

         cksum += (cksum >>16);

         return (USHORT)(~cksum);

}

Õâ¸öº¯Êý²¢Ã»Óо­¹ýÈκεÄÓÅ»¯£¬ÓÉÓÚУÑéºÍº¯ÊýÊÇTCP/IPЭÒéÖб»µ÷ÓÃ×î¶àº¯ÊýÖ®Ò»£¬ËùÒÔÒ»°ã˵À´£¬ÔÚʵÏÖTCP/IPջʱ£¬»á¸ù¾Ý²Ù×÷ϵͳ¶ÔУÑéºÍº¯Êý½øÐÐÓÅ»¯¡£

TCPÊײ¿¼ìÑéºÍÓëIPÊײ¿Ð£ÑéºÍµÄ¼ÆËã·½·¨Ïàͬ£¬ÔÚ³ÌÐòÖÐʹÓÃͬһ¸öº¯ÊýÀ´¼ÆËã¡£

ÐèҪעÒâµÄÊÇ£¬ÓÉÓÚTCPÊײ¿Öв»°üº¬Ô´µØÖ·ÓëÄ¿±êµØÖ·µÈÐÅÏ¢£¬ÎªÁ˱£Ö¤TCPУÑéµÄÓÐЧÐÔ£¬ÔÚ½øÐÐTCPУÑéºÍµÄ¼ÆËãʱ£¬ÐèÒªÔö¼ÓÒ»¸öTCPαÊײ¿µÄУÑéºÍ£¬¶¨ÒåÈçÏ£º

struct                        

{

         unsigned long saddr;     //Ô´µØÖ·

         unsigned long daddr;     //Ä¿µÄµØÖ·

         char mbz;                     //ÖÿÕ

         char ptcl;                   //ЭÒéÀàÐÍ

         unsigned short tcpl;     //TCP³¤¶È

}psd_header;

È»ºóÎÒÃǽ«ÕâÁ½¸ö×ֶθ´ÖƵ½Í¬Ò»¸ö»º³åÇøSendBufÖв¢¼ÆËãTCPУÑéºÍ£º

memcpy(SendBuf,&psd_header,sizeof(psd_header));  

     memcpy(SendBuf+sizeof(psd_header),&tcp_header,sizeof(tcp_header));

     tcp_header.th_sum=checksum((USHORT *)SendBuf,sizeof(psd_header)+sizeof(tcp_header));

¼ÆËãIPУÑéºÍµÄʱºò²»ÐèÒª°üÀ¨TCPαÊײ¿£º

memcpy(SendBuf,&ip_header,sizeof(ip_header));

     memcpy(SendBuf+sizeof(ip_header),&tcp_header,sizeof(tcp_header));

     ip_header.checksum=checksum((USHORT *)SendBuf, sizeof(ip_header)+sizeof(tcp_header));

     ÔÙ½«¼ÆËã¹ýУÑéºÍµÄIPÊײ¿ÓëTCPÊײ¿¸´ÖƵ½Í¬Ò»¸ö»º³åÇøÖоͿÉÒÔÖ±½Ó·¢ËÍÁË£º

     memcpy(SendBuf,&ip_header,sizeof(ip_header));

     sendto(SockRaw,SendBuf,datasize,0,(struct sockaddr*) &DestAddr,sizeof(DestAddr));

  

ÒòΪÕû¸öTCP±¨ÎÄÖеÄËùÓв¿·Ö¶¼ÊÇÎÒÃÇ×Ô¼ºÐ´ÈëµÄ£¨²Ù×÷ϵͳ²»»á×öÈκθÉÉæ£©£¬ËùÒÔÎÒÃÇ¿ÉÒÔÔÚIPÊײ¿ÖзÅÖÃËæ»úµÄÔ´IPµØÖ·£¬Èç¹ûαÔìµÄÔ´IPµØÖ·È·ÊµÓÐÈËʹÓã¬ËûÔÚ½ÓÊÕµ½·þÎñÆ÷µÄSYN+ACK±¨Îĺó»á·¢ËÍÒ»¸öRST±¨ÎÄ£¨±ê־λΪ00000100£©£¬Í¨Öª·þÎñÆ÷¶Ë²»ÐèÒªµÈ´ýÒ»¸öÎÞЧµÄÁ¬½Ó£¬¿ÉÊÇÈç¹ûÕâ¸öαÔìIP²¢Ã»Óаó¶¨ÔÚÈκεÄÖ÷»úÉÏ£¬²»»áÓÐÈκÎÉ豸ȥ֪ͨÖ÷»ú¸ÃÁ¬½ÓÊÇÎÞЧµÄ£¨ÕâÕýÊÇTCPЭÒéµÄȱÏÝ£©£¬Ö÷»ú½«²»¶ÏÖØÊÔÖ±µ½SYN Timeoutʱ¼äºó²ÅÄܶªÆúÕâ¸öÎÞЧµÄ°ëÁ¬½Ó¡£ËùÒÔµ±¹¥»÷ÕßʹÓÃÖ÷»ú·Ö²¼ºÜÏ¡ÊèµÄIPµØÖ·¶Î½øÐÐαװIPµÄSYN Flood¹¥»÷ʱ£¬·þÎñÆ÷Ö÷»ú³ÐÊܵĸººÉ»áÏ൱µÄ¸ß£¬¸ù¾Ý²âÊÔ£¬Ò»Ì¨PIII 550MHz+128MB+100MbpsµÄ»úÆ÷ʹÓþ­¹ý³õ²½ÓÅ»¯µÄSYN Flooder³ÌÐò¿ÉÒÔÒÔ16,000°ü/ÃëµÄËÙ¶È·¢ËÍTCP SYN±¨ÎÄ£¬ÕâÑùµÄ¹¥»÷Á¦ÒѾ­×ãÒÔÍÏ¿å´ó²¿·ÖWEB·þÎñÆ÷ÁË¡£

     ÉÔ΢¶¯¶¯ÄÔ½îÎÒÃǾͻᷢÏÖ£¬Ïë¶ÔSYN Flooder³ÌÐò½øÐÐÓÅ»¯ÊǺܼòµ¥µÄ£¬´Ó³ÌÐò¹¹¼ÜÀ´¿´£¬¹¥»÷ʱѭ»·ÄڵĴúÂëÖ÷ÒªÊǽøÐÐУÑéºÍ¼ÆËãÓ뻺³åÇøµÄÌî³ä£¬Ò»°ãµÄ˼·ÊÇÌá¸ßУÑéºÍ¼ÆËãµÄËÙ¶È£¬ÎÒÉõÖÁ¼û¹ýÓûã±à´úÂë±àдµÄУÑéºÍº¯Êý£¬Êµ¼ÊÉÏ£¬ÓÐÁíÍâÒ»¸ö±äͨµÄ·½·¨¿ÉÒÔÇáËÉʵÏÖÓÅ»¯¶øÓÖ²»ÐèÒª¸ßÉîµÄ±à³Ì¼¼ÇɺÍÊýѧ֪ʶ£¬£¨ÀÏʵ˵°É£¬ÎÒÊýѧ±È½Ï²î:P£©£¬ÎÒÃÇ×ÐϸÑо¿ÁËÁ½¸ö²»Í¬Ô´µØÖ·µÄTCP SYN±¨Îĺó·¢ÏÖ£¬Á½¸ö±¨ÎĵĴ󲿷Ö×Ö¶ÎÏàͬ£¨±ÈÈçÄ¿µÄµØÖ·¡¢Ð­ÒéµÈµÈ£©£¬Ö»ÓÐÔ´µØÖ·ºÍУÑéºÍ²»Í¬£¨Èç¹ûΪÁËÒþ±Î£¬Ô´¶Ë¿ÚÒ²¿ÉÒÔÓб仯£¬µ«ÊDz¢²»Ó°ÏìÎÒÃÇËã·¨ÓÅ»¯µÄ˼·£©£¬Èç¹ûÎÒÃÇÊÂÏȼÆËãºÃ´óÁ¿µÄÔ´µØÖ·ÓëУÑéºÍµÄ¶ÔÓ¦¹ØÏµ±í£¨Èç¹ûÆäËûµÄ×Ö¶ÎÓб仯Ҳ¿ÉÒÔ¼ÓÈëÕâ¸ö±í£©£¬µÈ¼ÆËãÍê±ÏÁ˹¥»÷³ÌÐò¾ÍÖ»ÐèÒªµ¥´¿µÄ×éºÏ»º³åÇø²¢·¢ËÍ£¨ÓÃÖ¸ÕëÀ´Ö±½Ó²Ù×÷»º³åÇøµÄÌØ¶¨Î»Ö㬴ÓÊÂÏȼÆËãºÃµÄ¶ÔÓ¦¹ØÏµ±íÖжÁ³öÊý¾Ý£¬Ìæ»»»º³åÇøÏàÓ¦×ֶΣ©£¬ÕâÖÖ¼òµ¥µÄ¹¤×÷Íêȫȡ¾öÓÚϵͳ·¢ËÍIP°üµÄËÙ¶È£¬Óë³ÌÐòµÄЧÂÊûÓÐÈκιØÏµ£¬ÕâÑù£¬¼´Ê¹ÊÇCPUÖ÷Ƶ½ÏµÍµÄÖ÷»úÒ²ÄÜ¿ìËٵķ¢ËÍ´óÁ¿TCP SYN¹¥»÷°ü¡£Èç¹û¿¼Âǵ½»º³åÇøÆ´½ÓµÄʱ¼ä£¬ÉõÖÁ¿ÉÒÔ¶¨ÒåÒ»¸öºÜ´óµÄ»º³åÇøÊý×飬Ìî³äÍê±ÏºóÔÙ·¢ËÍ£¨³ûÓ¥¸øÕâÖÖ·½·¨ÏëÁËÒ»¸öºÜÌùÇеıÈÓ÷£º»ð¼ýÅÚ×°µ¯ËäÈ»ºÜÂý£¬µ«ÊÇÒ»µ©ÅÚµ¯ÉÏÌÅÁËÒÔºó¾Í¿ÉÒÔÁ¬ÐøÃÍÁҵط¢ÉäÁË:£©¡£

  

  

  

  

  

µÚÈý²¿·Ö SYN Flood¹¥»÷µÄ¼à²âÓë·ÀÓù³õ̽

     ¶ÔÓÚSYN Flood¹¥»÷£¬Ä¿Ç°ÉÐûÓкܺõļà²âºÍ·ÀÓù·½·¨£¬²»¹ýÈç¹ûϵͳ¹ÜÀíÔ±ÊìϤ¹¥»÷·½·¨ºÍϵͳ¼Ü¹¹£¬Í¨¹ýһϵÁеÄÉ趨£¬Ò²ÄÜ´ÓÒ»¶¨³Ì¶ÈÉϽµµÍ±»¹¥»÷ϵͳµÄ¸ººÉ£¬¼õÇá¸ºÃæµÄÓ°Ïì¡££¨ÕâÕýÊÇÎÒ׫д±¾ÎĵÄÖ÷ҪĿµÄ£©

     Ò»°ãÀ´Ëµ£¬Èç¹ûÒ»¸öϵͳ£¨»òÖ÷»ú£©¸ººÉͻȻÉý¸ßÉõÖÁʧȥÏìÓ¦£¬Ê¹ÓÃNetstat ÃüÁîÄÜ¿´µ½´óÁ¿SYN_RCVDµÄ°ëÁ¬½Ó£¨ÊýÁ¿>500»òÕ¼×ÜÁ¬½ÓÊýµÄ10%ÒÔÉÏ£©£¬¿ÉÒÔÈ϶¨£¬Õâ¸öϵͳ£¨»òÖ÷»ú£©Ôâµ½ÁËSYN Flood¹¥»÷¡£

     Ôâµ½SYN Flood¹¥»÷ºó£¬Ê×ÏÈÒª×öµÄÊÇȡ֤£¬Í¨¹ýNetstat –n –p tcp >resault.txt¼Ç¼ĿǰËùÓÐTCPÁ¬½Ó״̬ÊDZØÒªµÄ£¬Èç¹ûÓÐÐá̽Æ÷£¬»òÕßTcpDumpÖ®ÀàµÄ¹¤¾ß£¬¼Ç¼TCP SYN±¨ÎĵÄËùÓÐϸ½ÚÒ²ÓÐÖúÓÚÒÔºó×·²éºÍ·ÀÓù£¬ÐèÒª¼Ç¼µÄ×Ö¶ÎÓУºÔ´µØÖ·¡¢IPÊײ¿Öеıêʶ¡¢TCPÊײ¿ÖеÄÐòÁкš¢TTLÖµµÈ£¬ÕâЩÐÅÏ¢ËäÈ»ºÜ¿ÉÄÜÊǹ¥»÷ÕßαÔìµÄ£¬µ«ÊÇÓÃÀ´·ÖÎö¹¥»÷ÕßµÄÐÄÀí״̬ºÍ¹¥»÷³ÌÐòÒ²²»ÎÞ°ïÖú¡£ÌرðÊÇTTLÖµ£¬Èç¹û´óÁ¿µÄ¹¥»÷°üËÆºõÀ´×Ô²»Í¬µÄIPµ«ÊÇTTLֵȴÏàͬ£¬ÎÒÃÇÍùÍùÄÜÍÆ¶Ï³ö¹¥»÷ÕßÓëÎÒÃÇÖ®¼äµÄ·ÓÉÆ÷¾àÀ룬ÖÁÉÙÒ²¿ÉÒÔͨ¹ý¹ýÂËÌØ¶¨TTLÖµµÄ±¨ÎĽµµÍ±»¹¥»÷ϵͳµÄ¸ººÉ£¨ÔÚÕâÖÖÇé¿öÏÂTTLÖµÓë¹¥»÷±¨ÎIJ»Í¬µÄÓû§¾Í¿ÉÒÔ»Ö¸´Õý³£·ÃÎÊ£©

     Ç°ÃæÔø¾­Ìáµ½¿ÉÒÔͨ¹ýËõ¶ÌSYN Timeoutʱ¼äºÍÉèÖÃSYN CookieÀ´½øÐÐSYN¹¥»÷±£»¤£¬¶ÔÓÚWin2000ϵͳ£¬»¹¿ÉÒÔͨ¹ýÐÞ¸Ä×¢²á±í½µµÍSYN FloodµÄΣº¦£¬ÔÚ×¢²á±íÖÐ×÷ÈçÏ¸Ķ¯£º

Ê×ÏÈ£¬´ò¿ªregedit£¬ÕÒµ½HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters

Ôö¼ÓÒ»¸öSynAttackProtectµÄ¼üÖµ£¬ÀàÐÍΪREG_DWORD£¬È¡Öµ·¶Î§ÊÇ0-2£¬Õâ¸öÖµ¾ö¶¨ÁËϵͳÊܵ½SYN¹¥»÷ʱ²ÉÈ¡µÄ±£»¤´ëÊ©£¬°üÀ¨¼õÉÙϵͳSYN+ACKµÄÖØÊԵĴÎÊýµÈ£¬Ä¬ÈÏÖµÊÇ0£¨Ã»ÓÐÈκα£»¤´ëÊ©£©£¬ÍƼöÉèÖÃÊÇ2£»

Ôö¼ÓÒ»¸öTcpMaxHalfOpenµÄ¼üÖµ£¬ÀàÐÍΪREG_DWORD£¬È¡Öµ·¶Î§ÊÇ100-0xFFFF£¬Õâ¸öÖµÊÇϵͳÔÊÐíͬʱ´ò¿ªµÄ°ëÁ¬½Ó£¬Ä¬ÈÏÇé¿öÏÂWIN2K PROºÍSERVERÊÇ100£¬ADVANCED SERVERÊÇ500£¬Õâ¸öÖµºÜÄÑÈ·¶¨£¬È¡¾öÓÚ·þÎñÆ÷TCP¸ººÉµÄ×´¿öºÍ¿ÉÄÜÊܵ½µÄ¹¥»÷Ç¿¶È£¬¾ßÌåµÄÖµÐèÒª¾­¹ýÊÔÑé²ÅÄܾö¶¨¡£

     Ôö¼ÓÒ»¸öTcpMaxHalfOpenRetriedµÄ¼üÖµ£¬ÀàÐÍΪREG_DWORD£¬È¡Öµ·¶Î§ÊÇ80-0xFFFF£¬Ä¬ÈÏÇé¿öÏÂWIN2K PROºÍSERVERÊÇ80£¬ADVANCED SERVERÊÇ400£¬Õâ¸öÖµ¾ö¶¨ÁËÔÚʲôÇé¿öÏÂϵͳ»á´ò¿ªSYN¹¥»÷±£»¤¡£

  

     ÎÒÃÇÀ´·ÖÎöÒ»ÏÂWin2000µÄSYN¹¥»÷±£»¤»úÖÆ£ºÕý³£Çé¿öÏ£¬Win2K¶ÔTCPÁ¬½ÓµÄÈý´ÎÎÕÊÖÓÐÒ»¸ö³£¹æµÄÉèÖ㬰üÀ¨SYN Timeoutʱ¼ä¡¢SYN-ACKµÄÖØÊÔ´ÎÊýºÍSYN±¨ÎÄ´Ó·ÓÉÆ÷µ½ÏµÍ³ÔÙµ½WinsockµÄÑÓʱµÈ£¬Õâ¸ö³£¹æÉèÖÃÊÇÕë¶ÔϵͳÐÔÄܽøÐÐÓÅ»¯µÄ£¨°²È«ºÍÐÔÄÜÍùÍùÏ໥ì¶Ü£©ËùÒÔ¿ÉÒÔ¸øÓû§Ìṩ·½±ã¿ì½ÝµÄ·þÎñ£»Ò»µ©·þÎñÆ÷Êܵ½¹¥»÷£¬SYN°ëÁ¬½ÓµÄÊýÁ¿³¬¹ýTcpMaxHalfOpenRetriedµÄÉèÖã¬ÏµÍ³»áÈÏΪ×Ô¼ºÊܵ½ÁËSYN Flood¹¥»÷£¬´ËʱÉèÖÃÔÚSynAttackProtect¼üÖµÖеÄÑ¡Ïʼ×÷Óã¬SYN Timeoutʱ¼ä±»¼õ¶Ì£¬SYN-ACKµÄÖØÊÔ´ÎÊý¼õÉÙ£¬ÏµÍ³Ò²»á×Ô¶¯¶Ô»º³åÇøÖеı¨ÎĽøÐÐÑÓʱ£¬±ÜÃâ¶ÔTCP/IP¶ÑÕ»Ôì³É¹ý´óµÄ³å»÷£¬Á¦Í¼½«¹¥»÷Σº¦¼õµ½×îµÍ£»Èç¹û¹¥»÷Ç¿¶È²»¶ÏÔö´ó£¬³¬¹ýÁËTcpMaxHalfOpenÖµ£¬´ËʱϵͳÒѾ­²»ÄÜÌṩÕý³£µÄ·þÎñÁË£¬¸üÖØÒªµÄÊDZ£Ö¤ÏµÍ³²»»á±ÀÀ££¬ËùÒÔϵͳ½«»á¶ªÆúÈκ㬳öTcpMaxHalfOpenÖµ·¶Î§µÄSYN±¨ÎÄ£¨Ó¦¸ÃÊÇʹÓÃËæ»ú¶ª°ü²ßÂÔ£©£¬±£Ö¤ÏµÍ³µÄÎȶ¨ÐÔ¡£

     ËùÒÔ£¬¶ÔÓÚÐèÒª½øÐÐSYN¹¥»÷±£»¤µÄϵͳ£¬ÎÒÃÇ¿ÉÒÔ²âÊÔ/Ô¤²âһϷÃÎÊ·åֵʱÆÚµÄ°ëÁ¬½Ó´ò¿ªÁ¿£¬ÒÔÆä×÷Ϊ²Î¿¼É趨TcpMaxHalfOpenRetriedµÄÖµ£¨±£ÁôÒ»¶¨µÄÓàÁ¿£©£¬È»ºóÔÙÒÔTcpMaxHalfOpenRetriedµÄ1.25±¶×÷ΪTcpMaxHalfOpenÖµ£¬ÕâÑù¿ÉÒÔ×î´óÏ޶ȵط¢»ÓWIN2K×ÔÉíµÄSYN¹¥»÷±£»¤»úÖÆ¡£

     ͨ¹ýÉèÖÃ×¢²á±í·ÀÓùSYN Flood¹¥»÷£¬²ÉÓõÄÊÇ“°¤´ò”µÄ²ßÂÔ£¬ÎÞÂÛϵͳÈçºÎÇ¿´ó£¬Ê¼ÖÕ²»Äܹ⿿°¤´òÖ§³ÅÏÂÈ¥£¬³ýÁ˰¤´òÖ®Í⣬“ÍËÈÔҲÊÇÒ»ÖֱȽÏÓÐЧµÄ·½·¨¡£

     ÍËÈòßÂÔÊÇ»ùÓÚSYN Flood¹¥»÷´úÂëµÄÒ»¸öȱÏÝ£¬ÎÒÃÇÖØÐÂÀ´·ÖÎöÒ»ÏÂSYN Flood¹¥»÷ÕßµÄÁ÷³Ì£ºSYN Flood³ÌÐòÓÐÁ½ÖÖ¹¥»÷·½Ê½£¬»ùÓÚIPµÄºÍ»ùÓÚÓòÃûµÄ£¬Ç°ÕßÊǹ¥»÷Õß×Ô¼º½øÐÐÓòÃû½âÎö²¢½«IPµØÖ·´«µÝ¸ø¹¥»÷³ÌÐò£¬ºóÕßÊǹ¥»÷³ÌÐò×Ô¶¯½øÐÐÓòÃû½âÎö£¬µ«ÊÇËüÃÇÓÐÒ»µãÊÇÏàͬµÄ£¬¾ÍÊÇÒ»µ©¹¥»÷¿ªÊ¼£¬½«²»»áÔÙ½øÐÐÓòÃû½âÎö£¬ÎÒÃǵÄÇÐÈëµãÕýÊÇÕâÀ¼ÙÉèһ̨·þÎñÆ÷ÔÚÊܵ½SYN Flood¹¥»÷ºóѸËÙ¸ü»»×Ô¼ºµÄIPµØÖ·£¬ÄÇô¹¥»÷ÕßÈÔÔÚ²»¶Ï¹¥»÷µÄÖ»ÊÇÒ»¸ö¿ÕµÄIPµØÖ·£¬²¢Ã»ÓÐÈκÎÖ÷»ú£¬¶ø·ÀÓù·½Ö»Òª½«DNS½âÎö¸ü¸Äµ½ÐµÄIPµØÖ·¾ÍÄÜÔں̵ܶÄʱ¼äÄÚ£¨È¡¾öÓÚDNSµÄË¢ÐÂʱ¼ä£©»Ö¸´Óû§Í¨¹ýÓòÃû½øÐеÄÕý³£·ÃÎÊ¡£ÎªÁËÃÔ»ó¹¥»÷Õߣ¬ÎÒÃÇÉõÖÁ¿ÉÒÔ·ÅÖÃһ̨“ÎþÉü”·þÎñÆ÷Èù¥»÷ÕßÂú×ãÓÚ¹¥»÷µÄ“Ч¹û”£¨ÓÉÓÚDNS»º³åµÄÔ­Òò£¬Ö»Òª¹¥»÷ÕßµÄä¯ÀÀÆ÷²»ÖØÆð£¬Ëû·ÃÎʵÄÈÔÈ»ÊÇÔ­ÏȵÄIPµØÖ·£©¡£

     ͬÑùµÄÔ­Òò£¬ÔÚÖÚ¶àµÄ¸ºÔؾùºâ¼Ü¹¹ÖУ¬»ùÓÚDNS½âÎöµÄ¸ºÔؾùºâ±¾Éí¾ÍÓµÓжÔSYN FloodµÄÃâÒßÁ¦£¬»ùÓÚDNS½âÎöµÄ¸ºÔؾùºâÄܽ«Óû§µÄÇëÇó·ÖÅäµ½²»Í¬IPµÄ·þÎñÆ÷Ö÷»úÉÏ£¬¹¥»÷Õß¹¥»÷µÄÓÀÔ¶Ö»ÊÇÆäÖÐһ̨·þÎñÆ÷£¬ËäȻ˵¹¥»÷ÕßÒ²Äܲ»¶ÏÈ¥½øÐÐDNSÇëÇó´Ó¶ø´òÆÆÕâÖÖ“ÍËÈÔ²ßÂÔ£¬µ«ÊÇÒ»À´ÕâÑùÔö¼ÓÁ˹¥»÷Õߵijɱ¾£¬¶þÀ´¹ý¶àµÄDNSÇëÇó¿ÉÒÔ°ïÖúÎÒÃÇ×·²é¹¥»÷ÕßµÄÕæÕý×Ù¼££¨DNSÇëÇó²»Í¬ÓÚSYN¹¥»÷£¬ÊÇÐèÒª·µ»ØÊý¾ÝµÄ£¬ËùÒÔºÜÄѽøÐÐIPαװ£©¡£

  

     ¶ÔÓÚ·À»ðǽÀ´Ëµ£¬·ÀÓùSYN Flood¹¥»÷µÄ·½·¨È¡¾öÓÚ·À»ðǽ¹¤×÷µÄ»ù±¾Ô­Àí£¬Ò»°ã˵À´£¬·À»ðǽ¿ÉÒÔ¹¤×÷ÔÚTCP²ãÖ®ÉÏ»òIP²ã֮ϣ¬¹¤×÷ÔÚTCP²ãÖ®ÉϵķÀ»ðǽ³ÆÎªÍø¹ØÐÍ·À»ðǽ£¬Íø¹ØÐÍ·À»ðǽÓë·þÎñÆ÷¡¢¿Í»§»úÖ®¼äµÄ¹ØÏµÈçÏÂͼËùʾ£º

  

ÍⲿTCPÁ¬½Ó                 ÄÚ²¿TCPÁ¬½Ó

     [¿Í»§»ú] =================>[·À»ðǽ] =================>[·þÎñÆ÷]

    

     ÈçÉÏͼËùʾ£¬¿Í»§»úÓë·þÎñÆ÷Ö®¼ä²¢Ã»ÓÐÕæÕýµÄTCPÁ¬½Ó£¬¿Í»§»úÓë·þÎñÆ÷Ö®¼äµÄËùÓÐÊý¾Ý½»»»¶¼ÊÇͨ¹ý·À»ðǽ´úÀíµÄ£¬ÍⲿµÄDNS½âÎöҲͬÑùÖ¸Ïò·À»ðǽ£¬ËùÒÔÈç¹ûÍøÕ¾±»¹¥»÷£¬ÕæÕýÊܵ½¹¥»÷µÄÊÇ·À»ðǽ£¬ÕâÖÖ·À»ðǽµÄÓŵãÊÇÎȶ¨ÐԺ㬿¹´ò»÷ÄÜÁ¦Ç¿£¬µ«ÊÇÒòΪËùÓеÄTCP±¨ÎͼÐèÒª¾­¹ý·À»ðǽת·¢£¬ËùÒÔЧÂʱȽϵÍÓÉÓÚ¿Í»§»ú²¢²»Ö±½ÓÓë·þÎñÆ÷½¨Á¢Á¬½Ó£¬ÔÚTCPÁ¬½ÓûÓÐÍê³Éʱ·À»ðǽ²»»áÈ¥Ïòºǫ́µÄ·þÎñÆ÷½¨Á¢ÐµÄTCPÁ¬½Ó£¬ËùÒÔ¹¥»÷ÕßÎÞ·¨Ô½¹ý·À»ðǽֱ½Ó¹¥»÷ºǫ́·þÎñÆ÷£¬Ö»Òª·À»ðǽ±¾Éí×öµÄ×㹻ǿ׳£¬ÕâÖּܹ¹¿ÉÒÔµÖ¿¹Ï൱ǿ¶ÈµÄSYN Flood¹¥»÷¡£µ«ÊÇÓÉÓÚ·À»ðǽʵ¼Ê½¨Á¢µÄTCPÁ¬½ÓÊýΪÓû§Á¬½ÓÊýµÄÁ½±¶£¨·À»ðǽÁ½¶Ë¶¼ÐèÒª½¨Á¢TCPÁ¬½Ó£©£¬Í¬Ê±ÓÖ´úÀíÁËËùÓеÄÀ´×Ô¿Í»§¶ËµÄTCPÇëÇóºÍÊý¾Ý´«ËÍ£¬ÔÚϵͳ·ÃÎÊÁ¿½Ï´óʱ£¬·À»ðǽ×ÔÉíµÄ¸ººÉ»á±È½Ï¸ß£¬ËùÒÔÕâÖּܹ¹²¢²»ÄÜÊÊÓÃÓÚ´óÐÍÍøÕ¾¡££¨ÎҸоõ£¬¶ÔÓÚÕâÑùµÄ·À»ðǽ¼Ü¹¹£¬Ê¹ÓÃTCP_STATE¹¥»÷¹À¼Æ»áÏ൱ÓÐЧ:£©

     ¹¤×÷ÔÚIP²ã»òIP²ã֮ϵķÀ»ðǽ£¨Â·ÓÉÐÍ·À»ðǽ£©¹¤×÷Ô­ÀíÓÐËù²»Í¬£¬ËüÓë·þÎñÆ÷¡¢¿Í»§»úµÄ¹ØÏµÈçÏÂͼËùʾ£º

[·À»ðǽ] Êý¾Ý°üÐÞ¸Äת·¢

     [¿Í»§»ú]========|=======================>[·þÎñÆ÷]

TCPÁ¬½Ó

  

     ¿Í»§»úÖ±½ÓÓë·þÎñÆ÷½øÐÐTCPÁ¬½Ó£¬·À»ðǽÆðµÄÊÇ·ÓÉÆ÷µÄ×÷Óã¬Ëü½Ø»ñËùÓÐͨ¹ýµÄ°ü²¢½øÐйýÂË£¬Í¨¹ý¹ýÂ˵İü±»×ª·¢¸ø·þÎñÆ÷£¬ÍⲿµÄDNS½âÎöÒ²Ö±½ÓÖ¸Ïò·þÎñÆ÷£¬ÕâÖÖ·À»ðǽµÄÓŵãÊÇЧÂʸߣ¬¿ÉÒÔÊÊÓ¦100Mbps-1GbpsµÄÁ÷Á¿£¬µ«ÊÇÕâÖÖ·À»ðǽÈç¹ûÅäÖò»µ±£¬²»½ö¿ÉÒÔÈù¥»÷ÕßÔ½¹ý·À»ðǽֱ½Ó¹¥»÷ÄÚ²¿·þÎñÆ÷£¬ÉõÖÁÓпÉÄÜ·Å´ó¹¥»÷µÄÇ¿¶È£¬µ¼ÖÂÕû¸öϵͳ±ÀÀ£¡£

     ÔÚÕâÁ½ÖÖ»ù±¾Ä£ÐÍÖ®Í⣬ÓÐÒ»ÖÖеķÀ»ðǽģÐÍ£¬ÎÒ¸öÈËÈÏΪ»¹ÊDZȽÏÇÉÃîµÄ£¬Ëü¼¯ÖÐÁËÁ½ÖÖ·À»ðǽµÄÓÅÊÆ£¬ÕâÖÖ·À»ðǽµÄ¹¤×÷Ô­ÀíÈçÏÂËùʾ£º

µÚÒ»½×¶Î£¬¿Í»§»úÇëÇóÓë·À»ðǽ½¨Á¢Á¬½Ó£º

SYN                           SYN+ACK                           ACK

     [¿Í»§»ú]---- >[·À»ðǽ]   =>   [·À»ðǽ]-------- >[¿Í»§»ú]   =>   [¿Í»§»ú]--- >[·À»ðǽ]

  

µÚ¶þ½×¶Î£¬·À»ðǽαװ³É¿Í»§»úÓëºǫ́µÄ·þÎñÆ÷½¨Á¢Á¬½Ó

[·À»ðǽ]< =========== >[·þÎñÆ÷]

TCPÁ¬½Ó

  

     µÚÈý½×¶Î£¬Ö®ºóËùÓдӿͻ§»úÀ´µÄTCP±¨ÎÄ·À»ðǽ¶¼Ö±½Óת·¢¸øºǫ́µÄ·þÎñÆ÷

·À»ðǽת·¢

[¿Í»§»ú]< ======|======= >[·þÎñÆ÷]

                     TCPÁ¬½Ó

     ÕâÖֽṹÎüÈ¡ÁËÉÏÁ½ÖÖ·À»ðǽµÄÓŵ㣬¼ÈÄÜÍêÈ«¿ØÖÆËùÓеÄSYN±¨ÎÄ£¬ÓÖ²»ÐèÒª¶ÔËùÓеÄTCPÊý¾Ý±¨ÎĽøÐдúÀí£¬ÊÇÒ»ÖÖÁ½È«ÆäÃÀµÄ·½·¨¡£

½üÀ´£¬¹úÍâºÍ¹úÄÚµÄһЩ·À»ðǽ³§ÉÌ¿ªÊ¼Ñо¿´ø¿í¿ØÖƼ¼Êõ£¬Èç¹ûÄÜÕæÕý×öµ½Ñϸñ¿ØÖÆ¡¢·ÖÅä´ø¿í£¬¾ÍÄܴܺó³Ì¶ÈÉÏ·ÀÓù¾ø´ó¶àÊýµÄ¾Ü¾ø·þÎñ¹¥»÷£¬ÎÒÃÇ»¹ÊÇÊÃÄ¿ÒÔ´ý°É¡£

  

 
   
 
 
ÎÄÕ·ÖÀà
 
   
 
ÎÄÕ´浵
 
     
 
×îÐÂÎÄÕÂÆÀÂÛ
  
 

³É¾ÍÅ®ÈË£¬¾ÍÊdzɾÍ×Ô¼º~~
 

ÓÐÒâ˼£¬¹þ¹þ¹þ
 
 

µÚ¶þ¸öÊÓÆµ×îºóÄǶÎÇú×ÓÊÇÄÄÀïµÄ£¬ºÜ¶úÊ죬Ïë²»ÆðÀ´ÁË¡£¡£¡£
   
°ïÖúÖÐÐÄ | ¿Õ¼ä¿Í·þ | Í¶ËßÖÐÐÄ | ¿Õ¼äЭÒé
©2012 Baidu