找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1473|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。* i- u2 B/ H8 k( v/ b) k+ s" T# x
漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:/ @7 O8 h& b( S; q% H

8 s& _3 e4 C& @2 x6 \( U* @6 u1. SACL 法3 W- g9 @# m0 F# ]7 X1 \; Y
[Unicode]
! ]  Y" H4 u# O  A, H! s& sUnicode=yes. Z4 x- A% ^# Q( H3 {6 k
[Version]
$ _2 N' `' T  c% msignature="$CHICAGO$"3 I# }  y' n0 v2 j/ u: N$ D  P" ^! s
Revision=1
. B! j3 Y$ W6 T: u3 l[File Security]7 C/ Y3 N' ]3 E, V& \
"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"
0 R- n* b4 R, k8 z. o6 B+ r
( [( P+ ~+ _! x* u' ?( n9 S  F将以上内容保存为 BlockAccess_x86.inf( y9 D4 o4 h2 U0 S, m9 o' k- A
然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>
7 R  N; ~, l" y/ V. g* g其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。1 ^+ ?# G: s3 o, A& ~4 U+ U

- a, P/ |4 u$ F4 r& m, U2. 禁用 Row Position 功能法
7 Q6 |) \2 E' O  e$ j
8 s- v& P  K7 }$ O" G- }, Q2 ~2 X0 S6 @  w/ x
HKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29} : V( u- p% U1 f% k0 n8 ?* ^
打开注册表编辑器,将此键删除即可。
4 j0 A" g/ ^; d. V+ h, t
$ N; g4 h* v+ j2 r' i6 Y% e3. 取消 DLL 注册法; d* `! C8 n' l; v$ l2 f5 v
* z3 r0 |7 E0 p. g% v, e
在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"$ p1 Q7 O! _& h: q  o
即可
  H* `  u5 a5 V$ _5 I/ G% H) M
; z) r" U, j% h: ]+ f1 j! K4. 权限设置法+ j6 y0 [2 R/ |# W* h8 [" u

# ], H1 }! w- K$ k在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N
, U: h7 k) s. T; M7 N3 x: h: i  A/ [6 N+ Y% t8 R2 u3 s/ ^2 b
Vista 系统则需要输入3个命令:) i/ w: i. r6 }& u- O
* n/ b5 F; g( [! F
takeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll"
7 n% X/ p7 H) h! m- P: Y* S; x; R3 Cicacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT/ D+ X0 c. H* ~6 l( A9 n/ @4 b4 F
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F) 7 I. h5 Z( d2 B: z9 G
, p& I( X' Y+ B' ^; h- I8 S
其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。: f1 O1 [3 s$ W" H$ }* o( W* t
/ c! N5 l& _$ h+ X) @
附:此漏洞影响的系统、软件列表) @5 X+ e4 R  ?- U+ I# c3 u) W, u
% A- \# S1 t3 t$ h. n$ A: H7 Y
Windows Internet Explorer 7
5 Q  ^5 u' I+ B7 @Windows Internet Explorer 7 for Windows XP $ m+ z" S7 e* M7 {
Windows Internet Explorer 7 for Windows Server 2003 * B, C, ]/ }  `8 i# ]
Windows Internet Explorer 7 for Windows Server 2003 IA64
& J& z: h) k: v3 oWindows Internet Explorer 7 in Windows Vista
) m% @$ W- {; H# ^7 M: {Windows Internet Explorer 8 Beta $ j9 W$ ~' \4 f
Microsoft Internet Explorer 6.0 Service Pack 2 ' k+ T8 b5 ]7 [' U
Microsoft Internet Explorer 6.0 Service Pack 1 7 [0 |# h- t9 Y: ?
Microsoft Internet Explorer 6.0
8 x5 l# ]; ]% g- |8 ^1 j; zMicrosoft Internet Explorer 5.01 Service Pack 4
! J6 Z5 t7 Q8 x5 J1 S( JWindows Server 2008 Datacenter without Hyper-V $ k7 [) m& _  P: z2 h4 {. p
Windows Server 2008 Enterprise without Hyper-V
/ s5 l, e( c$ a( v( d" rWindows Server 2008 for Itanium-Based Systems 8 a) Q& h% q0 N% y3 c5 E8 h# k
Windows Server 2008 Standard without Hyper-V
2 v& c8 P  d$ dWindows Server 2008 Datacenter , V5 |7 ~: n# o- y5 T
Windows Server 2008 Enterprise
2 }+ w6 ^" k% V' wWindows Server 2008 Standard
& @8 `/ H2 T- f' r+ y& d0 c, MWindows Web Server 2008
: P0 T( ^! ]" T* g+ w. zWindows Vista Service Pack 1, when used with:
( _' `, u+ J4 U: a  a% \Windows Vista Business . x) z9 o, |# B# |
Windows Vista Enterprise
4 R2 C3 t2 D1 m% J- [Windows Vista Home Basic
% l, e+ |* N/ d1 Z7 w& FWindows Vista Home Premium
& s: m) W( ?& k  z; {Windows Vista Starter 1 m8 X7 ^6 ~# V4 a
Windows Vista Ultimate 3 ]% v, V* g( r; m/ `
Windows Vista Enterprise 64-bit Edition
; d' ~, t* A' `4 Y0 ~3 Q/ mWindows Vista Home Basic 64-bit Edition 5 P; P  {& |4 u# Q; k9 R
Windows Vista Home Premium 64-bit Edition
' k6 k" g3 l. o& l* ], `5 ~Windows Vista Ultimate 64-bit Edition
! T/ O! W2 G0 Y/ d6 vWindows Vista Business 64-bit Edition
/ N) q% O; q: _' @( {" `Microsoft Windows Server 2003 Service Pack 1, when used with:
8 @  h, Q' T; }& w3 CMicrosoft Windows Server 2003, Standard Edition (32-bit x86) $ j' J3 o: D$ m' j& q" Z/ X
Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) & Z% h: ^, R! ~  T& q
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86) & p3 u) N+ g% w
Microsoft Windows Server 2003, Web Edition
6 T: p( G! M. j( D9 I4 z) xMicrosoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems 6 I2 s8 |6 c, E8 E& G
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems " W7 i: u& T/ u- y
Microsoft Windows Server 2003, Datacenter x64 Edition
9 {3 e# L3 Z9 v3 \6 e' i: VMicrosoft Windows Server 2003, Enterprise x64 Edition % [* m& g* [+ N- N' S
Microsoft Windows Server 2003, Standard x64 Edition ! X6 l. w, Z; p. m; a' G
Microsoft Windows XP Professional x64 Edition
/ R! d9 h: H2 g+ n; L: ~/ @& VMicrosoft Windows Server 2003 Service Pack 2, when used with: # z+ l0 m9 J3 @
Microsoft Windows Server 2003, Standard Edition (32-bit x86)
1 [9 A2 Z5 m( @2 b: {* B3 KMicrosoft Windows Server 2003, Enterprise Edition (32-bit x86) ; X8 F1 |7 i' z) I! @) m4 Z2 p
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86) 8 m; f) D# p: Q& E
Microsoft Windows Server 2003, Web Edition
! D/ _+ N+ Z  }& u8 EMicrosoft Windows Server 2003, Datacenter x64 Edition
" N. i! g& {+ `Microsoft Windows Server 2003, Enterprise x64 Edition
0 @) @& |  s: Q' j" _1 b# RMicrosoft Windows Server 2003, Standard x64 Edition ) T  \" O$ {/ G; w4 [" k
Microsoft Windows XP Professional x64 Edition % \4 m9 _% W& A. a* u) n
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems & d; O. q* c/ _
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
! r  G: g+ U6 h- G+ L9 OMicrosoft Windows XP Service Pack 2, when used with:
; Y  ~; \% t$ }& [/ _! tMicrosoft Windows XP Home Edition
7 l; w% h: ]/ d, GMicrosoft Windows XP Professional ) C" E& {9 T6 x( _% I8 k9 a
Microsoft Windows XP Service Pack 3, when used with:
3 |" B# ]5 I5 i: l5 eMicrosoft Windows XP Home Edition
9 f% ^2 @/ u; V7 C! fMicrosoft Windows XP Professional $ l7 _) J$ A6 L3 B
对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息
+ D5 a2 l" U, i, j$ wInternet Explorer 0day漏洞可能会愈演愈烈- |/ S3 q4 m2 a, |) m
    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.
  ?1 E  B3 y; q) z, R. t8 q) L8 p* I) X" E
    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.
% U) u+ }5 j- y9 r$ s4 p2 T  F7 M$ d, H) |" T" t5 z& o  R
    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加.# A0 E5 z  s& [4 [
6 F4 G  X9 P2 S3 r' E# T
    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.9 G0 \; c! O$ \, B: X5 |
; b! s% ^# t% C. [; D
[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:
. G0 \. v; \7 k& c& _- ^微软IE漏洞麻烦大 超过10000个站点被劫持$ u8 z0 x" ?& E! T1 b
    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.
$ A$ E* Y$ x, z! w6 N  L    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势.
6 x$ v; E  @$ m
6 ^4 J3 v6 N$ H' @7 r% L    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-8-3 05:00 , Processed in 0.059599 second(s), 5 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表