找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1576|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。) d) @) |" O1 v5 C* {
漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:6 ~; i" I' ^; G
* f( T0 o2 |  s- }, b
1. SACL 法4 b/ S' N3 y% H0 o
[Unicode]& B* }, N5 f/ m. ?
Unicode=yes7 K6 S. c8 @3 q
[Version]
2 C3 I9 n2 s! G* D( M) Osignature="$CHICAGO$"
5 L' `4 k+ x  l1 A* A( w9 WRevision=1
* \( l  c% ]9 y0 F5 M1 a[File Security]
8 R- v/ M6 A0 W- ~"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"( y. s6 ?+ j' Q3 e
: P: C# ?$ o$ R
将以上内容保存为 BlockAccess_x86.inf
& @7 s0 e, K+ A/ D3 h" k9 \然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>
8 j2 W: H6 g9 W4 f" |  M. ~( y其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。
7 l& T0 R$ s+ [$ Z% d: f' f+ S
+ A8 m" _4 ]" T' y  X; X5 D& e2. 禁用 Row Position 功能法/ |) P1 h; ?8 W9 u9 G$ Y0 Z$ G

" l9 W7 q* e: p/ }- g  U
, a+ f2 m+ i0 x' T; sHKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29} 4 i9 e! C: `: t) o* X, S4 v6 p* N
打开注册表编辑器,将此键删除即可。
& j+ z( k& z8 |0 k* M1 \. @5 F2 W: i' `! o; q, E
3. 取消 DLL 注册法' `2 S9 A6 Y! C+ z; N+ F& A
" G8 y. i. L' t4 g4 E2 `: S
在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"
+ A* g$ \9 P6 n, P% x即可
5 n) Z* H# [* N, q6 c4 t4 v/ `- x5 F! ]9 l! v
4. 权限设置法
7 }9 v0 W, p: n1 W6 `2 k8 Q: w
6 l. _* q& c% r0 @+ }; @在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N
3 u! O$ H) ?1 B) g/ F. I. C* s
Vista 系统则需要输入3个命令:& R: X* v( y- f+ s- p

4 n* N/ ~7 f. I' V+ n5 P# |: z# p5 wtakeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll"& O8 @! }8 f$ d/ V4 d
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT7 |/ Q! S4 k+ W
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F) % i6 H  @6 q$ y
% Q0 o5 I6 `+ s8 n3 b
其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。
: y6 F( t- L, R  h0 P6 f
9 I9 X6 d5 w* v' Z! p9 D: ?附:此漏洞影响的系统、软件列表
) H, w# }# N: V/ Q5 p4 b! w" {
; }$ u! Y) l, m2 A4 T! A% aWindows Internet Explorer 7
1 R) [$ G& s1 u2 K. J) ?Windows Internet Explorer 7 for Windows XP
' j; N5 Z2 G7 ^% ?' u  f) \Windows Internet Explorer 7 for Windows Server 2003 * N0 ~' t5 A4 p3 t# x% e1 C3 H% ^+ U
Windows Internet Explorer 7 for Windows Server 2003 IA64 6 _+ p# U" N9 F: I# M# t: G! E
Windows Internet Explorer 7 in Windows Vista : j2 ^1 n( i, Z% U# c7 d# z
Windows Internet Explorer 8 Beta
! P* N& G3 F  l2 N7 V- c* w2 EMicrosoft Internet Explorer 6.0 Service Pack 2
1 F3 O% i1 r6 q! v- C0 d9 b, tMicrosoft Internet Explorer 6.0 Service Pack 1 6 [0 h& g7 k# M% b3 X% l4 e5 n
Microsoft Internet Explorer 6.0 2 ]2 ]3 Z/ a: g7 R4 m, y% d
Microsoft Internet Explorer 5.01 Service Pack 4
% [% t# ?0 \$ {, G* e" V  |) ~9 g* u* hWindows Server 2008 Datacenter without Hyper-V 2 `8 G# O, u" A, s4 C# B
Windows Server 2008 Enterprise without Hyper-V
5 ?8 E. l/ b- uWindows Server 2008 for Itanium-Based Systems 1 X: Q8 v" ^% i1 z
Windows Server 2008 Standard without Hyper-V
! F0 y5 I! ]' Q* o  S* ~5 B* ]Windows Server 2008 Datacenter : g/ \$ n. m2 x; b! \  t5 X
Windows Server 2008 Enterprise
' \, z9 E5 J( S8 K/ B' v. mWindows Server 2008 Standard . b9 F' L$ m. n' n9 d
Windows Web Server 2008 8 m  o! v/ d6 `  a$ A
Windows Vista Service Pack 1, when used with: * Y. p. r% w" `- [9 t: B
Windows Vista Business
/ r3 g+ C% l% n( @$ |& qWindows Vista Enterprise 6 c# Y3 q5 G  p# J: {# L
Windows Vista Home Basic ! h/ {: M6 o+ P; T' |/ D
Windows Vista Home Premium
  d% G, ?! l1 ?) f- Q' sWindows Vista Starter . ?' y. D; Q% M& i7 h
Windows Vista Ultimate
- ~4 M) U# ^* w/ J) KWindows Vista Enterprise 64-bit Edition + Y; d3 M3 p% B1 u8 L
Windows Vista Home Basic 64-bit Edition 5 X% o8 G( L' \
Windows Vista Home Premium 64-bit Edition
) V; j0 a3 Y& P1 ^Windows Vista Ultimate 64-bit Edition
4 t0 L. Q8 g' B# `  U: _8 GWindows Vista Business 64-bit Edition 3 [% Y& {- _! W+ Y1 Z
Microsoft Windows Server 2003 Service Pack 1, when used with:
* x) Y3 z3 I5 j, cMicrosoft Windows Server 2003, Standard Edition (32-bit x86) * c4 h: C/ _: A9 N4 [
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) ' r  ?9 y, N8 s3 \9 ?
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
( ^) v- r# j3 h% S' JMicrosoft Windows Server 2003, Web Edition 1 s$ L4 D' p! |- x1 |0 m. C5 H
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems 1 B! ]5 h2 B/ k
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
6 ?( L7 Z+ Q5 s( nMicrosoft Windows Server 2003, Datacenter x64 Edition ! b' j" A! V6 @" n2 J  E
Microsoft Windows Server 2003, Enterprise x64 Edition " k6 F  @4 L4 f. O
Microsoft Windows Server 2003, Standard x64 Edition
7 a" Z5 A  [; Y& S' [. gMicrosoft Windows XP Professional x64 Edition
% h& e, i2 c4 G7 W0 s) [Microsoft Windows Server 2003 Service Pack 2, when used with:
) d" \& S9 E, t) EMicrosoft Windows Server 2003, Standard Edition (32-bit x86)
; ?6 E2 ^5 o! l2 I& S( C& E( t: iMicrosoft Windows Server 2003, Enterprise Edition (32-bit x86) 7 \0 [" Y' Q$ P8 R
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)   _. z6 g# ]. I1 V9 ~+ W4 H
Microsoft Windows Server 2003, Web Edition
8 Z. u$ g6 b0 yMicrosoft Windows Server 2003, Datacenter x64 Edition ; Q6 d" V- x- F, Y# |
Microsoft Windows Server 2003, Enterprise x64 Edition
4 r0 X9 a% |6 i# o) |2 C! |+ f: rMicrosoft Windows Server 2003, Standard x64 Edition 8 _, F; p7 _  V
Microsoft Windows XP Professional x64 Edition , t. J) J- B' D# y( q4 K8 b
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
. X# t+ [% |+ F1 n+ P5 X( I( MMicrosoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- B) e. t6 L/ G6 E" y8 L% {Microsoft Windows XP Service Pack 2, when used with:
) Z* F! v8 I2 ]  S4 E. O* W& O8 CMicrosoft Windows XP Home Edition
& [) j( R+ b6 C) r, y- I+ jMicrosoft Windows XP Professional
8 l9 t2 U6 K! A/ Z: [3 P% jMicrosoft Windows XP Service Pack 3, when used with: 2 `* X: B4 d" [1 @4 V
Microsoft Windows XP Home Edition
/ R' ]7 x& ^3 f. ^& \" yMicrosoft Windows XP Professional & Y6 D* r' Q  O& i1 \8 ?
对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息
/ R( _* b% Y/ _0 j* FInternet Explorer 0day漏洞可能会愈演愈烈
. ?- s3 |& M% t0 f% T) d6 W- P& H    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.) Z& r+ y5 F6 d% y5 s8 K" p: y2 a7 U

) ]) u" V6 d: B4 c: Q! l    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.: z& u# H/ E  F' P
' ^& \' h2 @# v
    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加.
/ P  S0 w7 |& V) ^5 P
* }9 O4 M9 T* `    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.
. @+ u+ Y/ o# ]/ V( q7 q6 u6 {3 x- n6 P: ]( b7 K
[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:4 k* Z/ T# h* X- T4 @) ^
微软IE漏洞麻烦大 超过10000个站点被劫持
+ Q" T/ Z& ]9 r9 Q; h% x    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.4 H& l. w( _+ F6 Q
    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势.
2 m9 U; W  U5 A1 L% f9 O
0 ^/ g+ F* `, x! ~% B    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-10-3 01:05 , Processed in 0.015727 second(s), 5 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表