找回密码
 加入华同
搜索
黄金广告位联系EMAIL:[email protected] 黄金广告[email protected]
查看: 1471|回复: 4

Microsoft 安全通报:4 种方法暂时屏蔽 IE 最新 0day

[复制链接]
发表于 2008-12-14 09:16:52 | 显示全部楼层 |阅读模式
IE 最新 0day 波及了微软全线系统,目前暂时没有补丁。微软于近日发布了一份安全通报,指导您如何暂时屏蔽此漏洞。
+ K0 D7 Y; H0 a! r9 ^漏洞出在 OLEDB32.dll 这个文件上。所以我们的目的就是屏蔽这个文件。对此,微软连出了4个杀手锏:
# p8 I+ }, z. o9 }  l% d. R0 |
% P# ^; T9 _( \: I- _: g  Z; `" Q1. SACL 法
- v  m9 S; G: t7 N$ I. U  F/ l8 C[Unicode]7 N4 P$ ]  l7 k6 J' |) r0 ?1 w
Unicode=yes; Q, b" M8 V1 o* t( @1 c1 e  l
[Version]
4 I# T* @! E& M% [9 Bsignature="$CHICAGO$"/ z3 ]4 p# |, o7 m8 t, P9 `
Revision=1
4 |6 s6 ?4 C3 Z$ U7 m1 W" i[File Security]$ |  t$ ?# {1 W
"%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll",2,"S:(ML;;NWNRNX;;;ME)"7 Y& W% q. J! ~2 d! {

- O3 z! v' r) e0 a8 M2 c7 v将以上内容保存为 BlockAccess_x86.inf
0 ?% A& l: E5 T/ C" k1 r然后在命令提示符里执行 SecEdit/configure/db BlockAccess.sdb/cfg <inf file>, |' G" b" @# ?/ b
其中 <inf file> 为 inf 文件路径。若成功会看到“操作成功完成”的提示。2 W7 y$ Y; m+ ]7 j- D

0 J4 Z: p# \( c6 R$ Q2. 禁用 Row Position 功能法
0 a6 Y. k$ T& B  T- Y; D( i6 s" x
/ `9 t# S. A: p$ g8 D  T
2 G# q+ ]3 {" v3 R  V! e- lHKEY_CLASSES_ROOT\CLSID\{2048EEE6-7FA2-11D0-9E6A-00A0C9138C29}
0 l; m" j! ?0 ]3 V6 s打开注册表编辑器,将此键删除即可。8 j- o7 c! D7 I& p

" y( y* `& E5 M3. 取消 DLL 注册法( g( z- N0 u- ?6 v) S! I
/ T! A2 ^/ _. b$ i; E3 b% o7 }
在命令提示符中输入 Regsvr32.exe/u "Program Files\Common Files\System\Ole DB\oledb32.dll"  s8 \0 Q1 a3 w8 ^
即可
4 M1 I7 p: B: q) i; x
7 I5 h- a0 _8 R$ X: U2 N: B4. 权限设置法( X+ R' K; |& b- h# O
1 g( V/ E4 a: x
在命令提示符中输入 cacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/E/P everyone:N
/ O3 `* r" l# _
5 I& U4 s7 J( n! m: }# w/ Z, NVista 系统则需要输入3个命令:
9 v. Z2 ]0 L+ G9 C/ N2 B8 T; r3 G1 [6 @$ a( m) t3 |7 s
takeown/f "Program Files\Common Files\System\Ole DB\oledb32.dll": ]: j( E; d3 X% t! t5 _: E
icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/save %TEMP%\oledb32.32.dll.TXT
6 p8 Q& f6 N! Y: M" c' e8 \icacls "Program Files\Common Files\System\Ole DB\oledb32.dll"/deny everyone:(F) 1 B; S: u6 K* x7 o8 f
3 ^: Z* W8 L- N- `- l" V
其中第一种方法影响最小(只影响 IE 对此 DLL 的访问)。
4 F9 ^+ M) _) s$ Y! R  j: X( ^& }1 l
* y6 w. u% m$ s) O/ C附:此漏洞影响的系统、软件列表# z4 ~  S" F$ x
4 Q+ l& x# d7 T+ Y  O9 k* v( d
Windows Internet Explorer 7 ' x3 P" r' }+ K8 e
Windows Internet Explorer 7 for Windows XP * o+ j2 X( ?1 Y4 T
Windows Internet Explorer 7 for Windows Server 2003 # i- L5 r# u, z
Windows Internet Explorer 7 for Windows Server 2003 IA64
6 N7 j& E% B1 |0 T7 tWindows Internet Explorer 7 in Windows Vista
5 h, ~* x- W4 t: C* tWindows Internet Explorer 8 Beta # T# ^( z7 B' s  c
Microsoft Internet Explorer 6.0 Service Pack 2 & }7 K4 a. U8 s
Microsoft Internet Explorer 6.0 Service Pack 1 9 M( U2 [/ p- j6 e, \% a
Microsoft Internet Explorer 6.0
, x( J* p- L9 W* @' t  @. vMicrosoft Internet Explorer 5.01 Service Pack 4   P; n1 G6 M6 k) H6 Z; i/ x; J
Windows Server 2008 Datacenter without Hyper-V
) J' [; Z$ s& F2 B+ n8 VWindows Server 2008 Enterprise without Hyper-V   @0 {. y/ d# ^( F. L" E: o
Windows Server 2008 for Itanium-Based Systems 0 {8 y4 Q1 C. ]6 w: R1 q
Windows Server 2008 Standard without Hyper-V
3 s# e6 a9 X2 O% Y* |Windows Server 2008 Datacenter
% ]+ C1 M. s2 |* E8 UWindows Server 2008 Enterprise 7 z$ y4 f. h8 P5 f- T
Windows Server 2008 Standard 7 W& j8 J8 _. ]' T
Windows Web Server 2008 2 K# b! O- p. x- T4 @! {" }) K: {
Windows Vista Service Pack 1, when used with: : M; X, I* M8 S+ I
Windows Vista Business
7 p5 m" K1 H8 A, t; l5 oWindows Vista Enterprise ' J: D8 B0 g0 K
Windows Vista Home Basic ( e  I+ ~* l7 `& `  Z9 ~9 R
Windows Vista Home Premium - K1 z) Q  t. X6 V# u& j
Windows Vista Starter
9 R0 V3 l; c& [+ j4 K3 ]Windows Vista Ultimate . X* u3 G7 {" E5 F0 J# ?# d, i
Windows Vista Enterprise 64-bit Edition
5 A- h% ?) k' HWindows Vista Home Basic 64-bit Edition
. P4 o1 `. \+ s7 ]% VWindows Vista Home Premium 64-bit Edition
* z# r- g7 Q/ E" ^1 A2 H7 V3 i$ wWindows Vista Ultimate 64-bit Edition + I8 n% y9 R6 t" [3 _6 |
Windows Vista Business 64-bit Edition ; j: a& _3 ]* b1 I
Microsoft Windows Server 2003 Service Pack 1, when used with: * R0 k5 R& @0 [6 A8 k
Microsoft Windows Server 2003, Standard Edition (32-bit x86)
4 n0 x$ X2 k2 s6 l, ~Microsoft Windows Server 2003, Enterprise Edition (32-bit x86) 9 _0 `) K/ T: c+ [# B  e+ q
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86) % o8 B; h. W" ^
Microsoft Windows Server 2003, Web Edition $ H! P1 z# ~6 l) K3 N6 v* P$ O
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems 3 ~! w3 a  Y/ I+ j& c
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems 4 e, }: _, r. ]" i
Microsoft Windows Server 2003, Datacenter x64 Edition
9 `  |5 v$ V$ X$ d7 JMicrosoft Windows Server 2003, Enterprise x64 Edition
6 p6 l* _' S0 n4 A4 g6 H5 ?Microsoft Windows Server 2003, Standard x64 Edition - C" Q9 f- p3 p/ x; a. ?
Microsoft Windows XP Professional x64 Edition 2 V# k. H3 o& S" j
Microsoft Windows Server 2003 Service Pack 2, when used with:
; \; \" A- g. P! M3 S" TMicrosoft Windows Server 2003, Standard Edition (32-bit x86)
# _  @* B8 O7 q. e4 IMicrosoft Windows Server 2003, Enterprise Edition (32-bit x86) # j9 v( w3 E+ r2 i1 q
Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
' @, N' K  T: U# P# OMicrosoft Windows Server 2003, Web Edition
- ~( o- J& ?  ^) F# `3 U# CMicrosoft Windows Server 2003, Datacenter x64 Edition + u5 A: u" w( _: H9 M
Microsoft Windows Server 2003, Enterprise x64 Edition
$ Z# p. v( J- ^  d" a6 x( DMicrosoft Windows Server 2003, Standard x64 Edition
: k+ v3 e: q4 `6 ~: mMicrosoft Windows XP Professional x64 Edition : O0 @/ f# M) F8 d2 e* e5 ^% b6 [6 j$ L
Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems - M7 l# m' U/ O6 G
Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems , z0 s; t0 o- M2 K( j0 y
Microsoft Windows XP Service Pack 2, when used with:
; o7 c; G3 V4 b, OMicrosoft Windows XP Home Edition
$ g: L; @. q1 |8 cMicrosoft Windows XP Professional
3 U# R# v4 a9 [  pMicrosoft Windows XP Service Pack 3, when used with:
7 t) K9 \! Z: M  f% M9 e8 RMicrosoft Windows XP Home Edition # |; H: k! t/ e- W  Q# m
Microsoft Windows XP Professional # f* D  F& x6 ^( E& _& D
对于非 x86 系统请参考微软安全通报自行操作。

评分

1

查看全部评分

 楼主| 发表于 2008-12-14 09:21:16 | 显示全部楼层
另:附上一则最新消息9 @4 t: B. V5 `: ^
Internet Explorer 0day漏洞可能会愈演愈烈1 j, r8 H! o4 |! X( F
    美国安全公司SANS“互联网风暴中心”周五表示,一些黑客已对全球数千个合法网站发起攻击,并上传相应恶意代码,试图利用最新曝出的微软IE浏览器漏洞向网民发起攻击.SANS及其他安全公司预计,今后数天甚至数周内,这种攻击的数量将急剧增长.微软周三证实,IE 7浏览器中新发现了一个漏洞.该公司周五又表示,该漏洞存在于所有版本的IE当中(即从IE 5到IE 8 beta 2都受到影响).微软周五没有透露将于何时发布该漏洞的补丁程序,但建议用户屏蔽oledb32.dll文件.
  M5 j! E3 r# e! g8 u5 j! [6 g
" S- C+ j4 H5 h4 h- z: g    SANS首席技术官(CTO)约翰内斯·乌尔里奇(Johannes Ullrich)称,一些黑客向合法网站偷偷上传恶意代码后,如果普通网民使用各种版本的IE浏览器访问这些网站,这些恶意代码将自动执行,进而在用户机器中安装恶意软件,黑客就可达到窃取用户个人信息之目的.乌尔里奇透露,截止周五,被黑客入侵的合法网站已达数千个.
- \# e% f9 C2 h3 p9 W' L& [6 K4 X0 X  G3 g2 n) Y
    另一家美国安全公司Websense则表示,黑客已成功入侵一家中国主板厂商网站,目的是往那些访问该网站的网民机器上安装恶意软件.Websense称,就目前而言,这些黑客主要是想窃取网民的游戏账号.但SANS预计,今后数天甚至数周内,此类攻击的数量将急剧增加.9 L6 w- Z" A- Q1 f6 p$ a! X
, b8 P" D9 [+ ~
    对于微软屏蔽oledb32.dll文件的建议,一些网民表示,在Windows XP操作系统中可顺利完成该操作,但在Vista上却无法执行.美国安全公司nCircle主管安德鲁·斯特罗姆斯(Andrew Storms)认为,由于新发现的IE漏洞影响到所有版本,而今年圣诞节假日购物旺季即将来临,估计微软将尽快发布该漏洞补丁程序,而不会等到2009年 1月13日“补丁星期二”再作为常规补丁发布.
  N) ~& W% d! l! X1 ~: \
/ l1 `; a$ L2 ~7 Y- P0 s, n3 N[各位使用IE浏览器的坛友可要注意点咯,可要按照楼上的方法操作,暂时屏蔽oledb32.dll]
回复

使用道具 举报

发表于 2008-12-14 09:47:12 | 显示全部楼层
我都不用IE,感觉速度慢,而且容易发生假死。
回复

使用道具 举报

发表于 2008-12-14 23:32:27 | 显示全部楼层
IE- =唉,同意LS
回复

使用道具 举报

 楼主| 发表于 2008-12-16 21:34:44 | 显示全部楼层
最新信息一则:1 |1 V! c! d& L2 @4 M$ j
微软IE漏洞麻烦大 超过10000个站点被劫持
0 ?# O+ l. ?; M$ `* O3 f& S) _    趋势科技的安全专家们最近表示,他们已经发现超过10000个以上的站点被劫持,访问这些站点的用户都将被带往毒窝网站去尽情地感染病毒.' Q7 g: z. D' ]
    这些站点无一例外都是采用最近爆出的IE 0day漏洞进行入侵的,大多数的站点来自中国,主要目的是窃取游戏账户,并且有愈演愈烈的趋势./ F' q3 {& o2 s3 I( X# I% K

7 ~* l; c7 }4 n- I( ^    微软之前曾表示已经开始调查这个安全漏洞,并考虑通过一个紧急的软件补丁来解决燃眉之急.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 加入华同

本版积分规则

Archiver|手机版|小黑屋|华人同志

GMT+8, 2026-8-2 19:58 , Processed in 0.061460 second(s), 5 queries , Redis On.

Powered by Discuz! X3.5

© 2001-2026 Discuz! Team.

快速回复 返回顶部 返回列表