找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1577|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。
) M8 `6 M  O9 o7 _3 i2 m, l漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:, a  v3 \6 j2 r* H( X5 h9 e

) K. \. B4 {) l8 c- J) X1. SACL 法, a# B, A6 W4 Y7 E0 c9 ^
[Unicode]; V% p7 K4 U, n( H+ I' e
Unicode=yes2 w/ t, a: p% z8 U  ]$ B
[Version]. }" L5 Y( {, S- R0 W+ c" }2 z
signature="$CHICAGO$"0 c7 c2 m+ ]# G; l6 b5 @2 I
Revision=1* f) D+ {0 Y8 o: {
[File Security]
( `8 O* D3 Z! o. _. l+ P$ f"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"
  O: F$ a! l: o, E$ }- w
, |% _: w2 z6 L2 K0 [3 a: O3 o将以上内容保存为 BlockAccess_x86.inf; {- C0 {; @! i( a; O" T
然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>
9 `( t7 G. o$ I# i其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。
" D' j9 o4 v6 v1 F0 D8 V/ U
, X4 `$ ^! Z; v: M& ?; O' Z2. 禁用 Row Position 功能法
& {5 |8 L  J( `. U, @1 A! \" J" Y

+ u7 ^% P' F1 r! yHKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29}   x! J7 C: ~+ Q1 p1 Q8 }
打开注册表编辑器,将此键删除即可。
# c! q, d" R/ [0 y1 [
8 C3 }4 e8 X; A' z" N+ n: q3. 取消 DLL 注册法4 X, q, [! x7 h1 s* m3 y2 M0 x
5 c$ j" T5 m. ~! o: I. c
在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"
; n7 D$ K! j" j0 c0 g5 W* _即可3 X0 v8 j: N/ g! m$ I

* G4 ^) O; X) }3 V- D4. 权限设置法
% x% H) s0 Y$ o  U  `
$ t9 c) h( I1 F& A& K! H3 O7 s在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N $ l7 ^( M5 _  u: v

# ]" A1 c  Q0 ?) Y$ N+ UVista 系统则需要输入3个命令:) @# v" Q" S4 g% Z% i& E' L

+ R, }% P: l) t6 I2 T# Ztakeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll"
5 e  P. @& K) i4 ]% Picacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT
% \2 z! D5 X2 E, @9 r5 uicacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F)
# Q% o5 E  V# h3 g7 y9 M2 d4 h: P. M6 ?4 c
其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。  F4 D7 Z+ Q6 O0 O. k
6 q! D+ ]/ m3 I( z
附:此漏洞影响的系统、软件列表
' b# N' n& O' P0 r6 p5 k9 B; W7 _
5 i) \0 Z0 r6 W6 b3 ]Windows Internet Explorer 7 3 x5 @" Z/ d  a4 J* c0 V9 H
Windows Internet Explorer 7 for Windows XP
  E1 c0 i. l9 E' [Windows Internet Explorer 7 for Windows Server 2003
) f. p5 u* i0 q- t1 U. bWindows Internet Explorer 7 for Windows Server 2003 IA64 . l6 ^; t* ^+ [. e; w
Windows Internet Explorer 7 in Windows Vista : r4 J3 I' i7 c( B
Windows Internet Explorer 8 Beta
5 O4 P/ l( {  m2 W+ ZMicrosoft Internet Explorer 6.0 Service Pack 2 " q  R' n- j1 ^3 x/ J
Microsoft Internet Explorer 6.0 Service Pack 1 $ O! x& R! A) j: K
Microsoft Internet Explorer 6.0
5 [; ~" q3 T  ^- U0 BMicrosoft Internet Explorer 5.01 Service Pack 4
8 i9 G9 b4 e1 F+ J+ V( qWindows Server 2008 Datacenter without Hyper-V & i# ?- _8 D$ N* L% p& W" k
Windows Server 2008 Enterprise without Hyper-V , U+ T1 P& P  S3 h# M( z) {* v
Windows Server 2008 for Itanium-Based Systems ' p& p3 g9 I) K  j- I) ~( w
Windows Server 2008 Standard without Hyper-V / W" n' h) j% h7 M
Windows Server 2008 Datacenter
3 M- w& c3 W1 l. B* lWindows Server 2008 Enterprise 4 f6 Z. F) J8 o
Windows Server 2008 Standard
; H1 V7 c4 J3 ^  t7 |0 SWindows Web Server 2008
; e, q8 ?+ C( T/ c3 SWindows Vista Service Pack 1, when used with:
: _( |4 N! e( VWindows Vista Business 8 q7 k+ s4 j+ D- z( W& n
Windows Vista Enterprise * ?6 Q8 e+ @) J9 L$ E4 T) u% X
Windows Vista Home Basic % f0 l+ |9 }" M8 ]5 c! G! B' P
Windows Vista Home Premium
. M' x( f% Y" e" w7 l$ `8 PWindows Vista Starter / X, V$ l$ @4 `) J, D
Windows Vista Ultimate
) t0 K' ~5 t; s( vWindows Vista Enterprise 64-bit Edition
- K* t( F1 Q: D9 OWindows Vista Home Basic 64-bit Edition
* d. ?! d  h0 BWindows Vista Home Premium 64-bit Edition ( Z  p5 Q+ w  ~+ b# }6 @
Windows Vista Ultimate 64-bit Edition
/ ?3 N) L0 l& R. y; U$ IWindows Vista Business 64-bit Edition + v% N) [% c) V
Microsoft Windows Server 2003 Service Pack 1, when used with: ; B1 D$ s' [* W
Microsoft Windows Server 2003, Standard Edition (32-bit x86) 3 I4 ]* x% C2 x* U0 r
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) 5 d9 c: U/ b7 f: ]: ]* i( Q
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  h9 [! P: {. u1 q7 PMicrosoft Windows Server 2003, Web Edition   @) D0 j) m/ t" c1 n
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems ! F3 ~7 m$ c7 d- i0 w0 _
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems 1 p9 C: j3 f5 n4 p8 \0 Y& B5 B
Microsoft Windows Server 2003, Datacenter x64 Edition
7 z3 [  n% A: S9 ~6 y6 SMicrosoft Windows Server 2003, Enterprise x64 Edition
: |, o: [  @: ?  X' e% [Microsoft Windows Server 2003, Standard x64 Edition
8 `. w/ L/ s) ?2 V, y9 D  G( `: rMicrosoft Windows XP Professional x64 Edition
! ]$ V( A- t# y+ R' GMicrosoft Windows Server 2003 Service Pack 2, when used with: 4 i/ p  N7 \* A! F
Microsoft Windows Server 2003, Standard Edition (32-bit x86) 0 J! t2 G: K( \1 \
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) 2 i# w3 z2 S5 t1 N8 C; S# m
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86) # [) R( a' w9 q% H' y! Z# K1 L: l7 m( X
Microsoft Windows Server 2003, Web Edition , f) Z: N5 J7 P
Microsoft Windows Server 2003, Datacenter x64 Edition
+ a$ f' C) K& d6 }Microsoft Windows Server 2003, Enterprise x64 Edition 6 _. P! e& D* t0 Y2 H( t
Microsoft Windows Server 2003, Standard x64 Edition 9 T7 ^( U7 j/ x. H+ X, _8 [! L
Microsoft Windows XP Professional x64 Edition . d0 a" _1 N9 f! t
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems   H! ^, W' a% w, T
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems + U5 v* d+ w! b, [/ R- L+ o
Microsoft Windows XP Service Pack 2, when used with:
* a  e/ B" e5 I. o+ G& ZMicrosoft Windows XP Home Edition 5 ~6 U* h% T  U8 q
Microsoft Windows XP Professional
, A+ F5 ]' Z6 L5 oMicrosoft Windows XP Service Pack 3, when used with: : b& V) M3 m, ^  I" Q0 t) D/ L% h% C
Microsoft Windows XP Home Edition
) f) Y. z5 r7 i. aMicrosoft Windows XP Professional ; D9 `. J, c& U# X: H9 S$ N
对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息* q0 W7 u3 [2 n* ~/ y9 z9 G9 ]9 c
Internet Explorer 0day漏洞可能会愈演愈烈
# v" x9 k' M! j7 |+ u+ x    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.# b$ v( T. k+ {5 U- @" C
/ F$ x. S8 ~) ^$ L; z$ U* \8 t
    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.' Z4 b# `9 d' v6 X$ o

* [3 O) W5 Z! G9 t! |5 {    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加., _0 r+ |: R8 z" `

+ t- o% h* C8 R4 e7 W# i    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.2 k' O$ P) I6 a. U8 A- e+ f" X

- D9 X" T* ~  m, z5 w, z! [2 e[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:
  J" |% T3 y& t- @  k6 q; E% c" ~& a微软IE漏洞麻烦大 超过10000个站点被劫持
0 f) Q+ M/ @2 ~+ v  C3 q+ y' b    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.
4 A6 Q( o1 u9 C9 K    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势.+ V/ I% J  a1 R: S: l" C1 Y$ u5 o
( a' [9 G. J' U5 E" z+ b! a1 M
    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-10-3 03:42 , Processed in 0.020184 second(s), 5 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表