AG¹«Ë¾

AG¹«Ë¾

AG¹«Ë¾¿Æ¼¼

  • »ù´¡ÉèÊ©Çå¾²

    »ù´¡ÉèÊ©Çå¾²
  • Êý¾ÝÇå¾²

    Êý¾ÝÇå¾²
  • ÔÆÅÌËãÇå¾²

    ÔÆÅÌËãÇå¾²
  • AIÇå¾²

    AIÇå¾²
  • ¹¤Òµ»¥ÁªÍøÇå¾²

    ¹¤Òµ»¥ÁªÍøÇå¾²
  • ÎïÁªÍøÇå¾²

    ÎïÁªÍøÇå¾²
  • ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì

    ÐÅÏ¢ÊÖÒÕÓ¦ÓÃÁ¢Òì
  • ËùÓвúÆ·

    ËùÓвúÆ·
  • ËùÓнâ¾ö¼Æ»®

    ËùÓнâ¾ö¼Æ»®

»ù´¡ÉèÊ©Çå¾²


  • Õþ¸®

    Õþ¸®
  • ÔËÓªÉÌ

    ÔËÓªÉÌ
  • ½ðÈÚ

    ½ðÈÚ
  • ÄÜÔ´

    ÄÜÔ´
  • ½»Í¨

    ½»Í¨
  • ÆóÒµ

    ÆóÒµ
  • ¿Æ½ÌÎÄÎÀ

    ¿Æ½ÌÎÄÎÀ

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÏàÖúͬ°éÉó²é¸ü¶à >

ÏàÖúͬ°é¶¯Ì¬

³ÉΪÏàÖúͬ°é

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

ÊÖÒÕÖ§³ÖÉó²é¸ü¶à >

²úÆ·Ö§³Ö

  • AG¹«Ë¾ÔÆ AG¹«Ë¾ÔÆ
  • AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI AG¹«Ë¾ÍþвÇ鱨ÖÐÐÄNTI
  • TechWorldÊÖÒÕ¼ÎÄ껪 TechWorldÊÖÒÕ¼ÎÄ껪
  • ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á ±±¾©AG¹«Ë¾¹«Òæ»ù½ð»á
  • ÊÖÒÕ²©¿Í ÊÖÒÕ²©¿Í
  • Àֳɰ¸Àý Àֳɰ¸Àý

·µ»ØÁбí

·À»¤¼Æ»®£ºWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î·À»¤

2015-04-21

Ðû²¼ÕߣºAG¹«Ë¾¿Æ¼¼

Ö´ÐÐÕªÒª


4ÔÂ14ÈÕ £¬Î¢Èíͨ¸æMS15-034/CVE-2015-1635 IIS7 http.sysÎó²î £¬AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄËæ¼´Æô¶¯Ó¦¼±»úÖÆ £¬ Ó¦¼±ÏìÓ¦ÊÂÇéËæ¼´Æô¶¯  ¡£

1    15ÈÕÒ¹ £¬Ðû²¼¸ßΣÎó²î½ôÆÈͨ¸æ £¬Ö§³ÖÐÅÏ¢À´×ÔÎó²îµÄʹÓûúÖÆÆÊÎö¼°POCÑéÖ¤ÊÂÇé £¬µÚһʱ¼ä¼û¸æ¿Í»§¹Ø×¢£»

2   16ÈÕ £¬Ðû²¼²úÆ·¹æÔòÉý¼¶Í¨¸æ £¬AG¹«Ë¾¿Æ¼¼NIPS¡¢WAF¡¢RSAS¡¢WVSS¡¢NFµÈ²úÆ·Éý¼¶Ïà¼ÌÍ£µ± £¬¿Í»§Í¨¹ýÔÚÏß¼°ÀëÏßÉý¼¶µÄÒªÁì £¬¼´¿É¾ÙÐзÀ»¤£»

3    17ÈÕ £¬Ðû²¼Îó²îÉîÈëÆÊÎö £¬´óÐÍÆóÒµ¼°×éÖ¯¿Í»§¿ÉÒÔͨ¹ýÕâЩÐÅÏ¢¶¨ÖÆ×Ô¼ºµÄ·ÀÓù¼Æ»®  ¡£ÔÚÏßÎó²î¼ì²âÒýÇæÍ£µ±  ¡£

4    21ÈÕ £¬ÎÒÃÇ»ØÊ×http.sysÎó²îµÄÐÅÏ¢Òªµã £¬´Óhttp.sysÎó²î·À»¤µÄ½Ç¶È¾ÙÐÐ×ܽá £¬Îª¸÷ÈËÖÆ¶©·ÀÓù¼Æ»®ÌṩÔö²¹ÐÅÏ¢  ¡£


http.sysÎó²î»ØÊ×

4ÔÂ14ÈÕ £¬Î¢Èíͨ¸æÁË https.sysÎó²î £¬¼´Windows http.sysÔ¶³Ì´úÂëÖ´ÐиßΣÎó²î£¨MS15-034£© £¬CVE±àºÅCVE-2015-1635.´ËÎó²îÓÉÓھ߱¸ÈçϵÄ4¸öÌØµã £¬Ò»¾­Ðû²¼ £¬Ñ¸ËÙÒý·¢¹¥»÷ÕߵĹØ×¢ £¬ÔÚÎó²îÐû²¼µÄµÚ2Ìì £¬Twitter¼°ÐÂÀË΢²©ÉÏ·ºÆð´ó×ÚÎó²îÐÅÏ¢ £¬Ò»Ð©ÄäÃûµÄPOC¼°¿ÉÔ¶³Ì´¥·¢²Ù×÷ϵͳÀ¶ÆÁµÄ¹¥»÷´úÂë×îÏÈÈö²¥  ¡£

1.          Http.sysÊÇ´¦Öóͷ£HTTPÇëÇóµÄÄÚºËÇý¶¯³ÌÐò £¬´¦ÓÚÑʺíÒªµÀ £¬Ò»µ©±»Ê¹Óúó»¼ÎÞÏÞ£»

2.          ¸ÃÎó²îºÜÈÝ½á¹¹ÌØ¶¨µÄhttpÇëÇó £¬µ¼Ö¹¥»÷Ä¿µÄÀ¶ÆÁ £¬ÕâÐÎʽ³£¼ûÓÚ²»Õýµ±ÉÌÒµ¾ºÕù£»

3.          Ò»µ©±»Ê¹ÓÃÀÖ³É £¬¿ÉÒÔ»ñµÃºÜ¸ßµÄϵͳȨÏÞ £¬¿ÉÔÚSystemÕÊ»§ÉÏÏÂÎÄÖÐÖ´ÐÐí§Òâ´úÂ룻

4.          IISÔÚÈ«ÇòµÄ°²ÅÅ×ÜÁ¿Áè¼Ý444Íò £¬µ«¾­³£ÊÇδ¾­¼Ó¹Ì»ò·À»¤ÊµÁ¦±¡Èõ


ÊÜ´ËÎó²îÓ°ÏìµÄÈí¼þ¼°ÏµÍ³°üÀ¨£º

        Microsoft Windows Server 2012 R2

        Microsoft Windows Server 2012

        Microsoft Windows Server 2008 R2 SP1

        Microsoft Windows 8.1

        Microsoft Windows 8

        Microsoft Windows 7 SP1


AG¹«Ë¾¿Æ¼¼ÓëÎó²îÏà¹Ø³§É̳¤Äê¼á³ÖÇ×½üÏàÖú¹ØÏµ  ¡£AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ»ñÖªÏà¹ØÐÅÏ¢ºó £¬Ëæ¼´Æô¶¯Ó¦¼±»úÖÆ £¬Ïà¹ØÊÂÇéËæ¼´Æô¶¯  ¡£

ÊÜÓ°ÏìÇøÓòÂþÑÜ

×èÖ¹2015Äê4ÔÂ15ÈÕ £¬¾ÝAG¹«Ë¾¿Æ¼¼»¥ÁªÍø¹ãÆ×ƽ̨Êý¾ÝÏÔʾ £¬È«Çò°²ÅÅIISµÄϵͳÊýÄ¿»òÐíÓÐ444ÍòÓà  ¡£ÒÔÕ¼±È×î´óµÄIIS 7.5£¨42.3%£©ÎªÀý £¬ÃÀ¹ú¡¢Öйú¡¢Ó¢¹ú¼°µÂ¹úΪÊÜÓ°ÏìµÄŨÃÜÇøÓò £¬ÆäÖÐÖйúÕ¼±È16.4% £¬II7.5µÄ°²ÅÅÁ¿Áè¼Ý35Íò £¬ÕâÒ²ÊÇ´Ë´ÎÎó²îÔÆÔÆÊܵ½¹Ø×¢µÄÔµ¹ÊÔ­ÓÉÖ®Ò»  ¡£

IIS 7.5ÂþÑÜÌ¬ÊÆÍ¼


http.sysÎó²îÆÊÎö

2015Äê4ÔÂ15ÈÕÒ¹ £¬AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ»ñÈ¡http.sysÎó²îÓ°Ïì¹æÄ£Êý¾ÝµÄͬʱ £¬Ò²ÔÚѸËÙÕö¿ªÎó²îµÄÆÊÎöÊÂÇé £¬Í¨¹ýÖØÏÖÎó²îµÄ¹¥»÷Àú³Ì £¬ÆÊÎöÆäÊÂÇéÔ­Àí £¬µÃÒÔÇåÎúʶ±ð¼°¼ì²â¸ÃÎó²îÒªÁì £¬ÔÚ׼ȷ½ç˵ÆäÍþв¶¨¼¶ºó £¬Ëæ¼´ÏòÎÒÃǵĿͻ§·¢³ö¸ßΣÎó²î½ôÆÈͨ¸æ  ¡£


http.sysÀ¶ÆÁ

ƾ֤PastebinÉÏÅû¶µÄPoC £¬ºÜÈÝÒ׽ṹ³öÄÜ´¥·¢À¶ÆÁ£¨BSOD£©µÄPoC £¬ºÃ±ÈÒÔÏÂÇëÇó£º

1          GET /welcome.png HTTP/1.1

2          Host: PoC

3          Range: bytes=12345-18446744073709551615

¿ÉÒÔʹװÖÃÓÐIIS 7.5µÄWindows 7 SP1ϵͳBSOD  ¡£


http.sysÎó²îʹÓÃ

¶ÔBSODÍß½âµÄÏÖ³¡¾ÙÐÐÆÊÎö £¬·¢Ã÷ÊÇÖÖÖÖÇéÐεÄÄÚ´æ¹ýʧ £¬ÓÉ´ËÍÆ²â´¥·¢Îó²îºó¿ÉÄÜÔì³ÉÁËÄÚ´æÆÆËð  ¡£¶ÔHTTP.sysµÄ´¦Öóͷ£Á÷³Ì¾ÙÐÐÆÊÎö¡¢Öð²½ÅŲé £¬¿ÉÒÔÈ·¶¨ÄÚ´æÆÆË𱬷¢ÔÚº¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÖÐ £¬º¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÓÃÓÚÌìÉúÏìÓ¦±¨ÎĵĻº´æMDLÁ´ £¬À´ÐÎòHTTPÏìÓ¦µÄ״̬ÐС¢Í·²¿ÓëÐÂÎÅÌå £¬Á´Éϵĸ÷MDLͨ¹ýŲÓÃnt! IoBuildPartialMdlÀ´ÌìÉú[3]  ¡£

´¥·¢´ËÎó²î¿ÉÔ½½çдÊý¾Ý¶øÔì³ÉÄÚ´æÆÆË𠣬ÀíÂÛÉϱ£´æÔ¶³ÌÖ´ÐдúÂëµÄ¿ÉÄÜÐÔ  ¡£¿ÉÊÇÔ½½çËùдÊý¾ÝµÄ³¤¶ÈÏÂÏÞÓÉContentLength¾öÒé £¬Í¨³£»áÊÇÒ»¸ö½Ï´óµÄÖµ¶øÁ¢×ÝȻϵͳÍ᫃  ¡£×ÝȻĿµÄ·þÎñÆ÷Éϱ£´æÒ»Ð©´óµÄÎļþ £¬¿ÉÒÔÓÃÀ´Ô½½çдÉÙÁ¿Êý¾Ý £¬ËùдÊý¾ÝÄÚÈÝÓë±»ÁýÕÖÄ¿µÄÒ²ºÜÄÑ¿ØÖÆ  ¡£Òò´Ë £¬ÔÚÏÖÕæÏàÐÎÖÐÏëÒªÎȹ̵ÄʹÓôËÎó²îÀ´Ö´ÐдúÂëÊǺÜÊÇÄÑÌâµÄ £¬µ«¹¥»÷ÕßÒªÏëʹÓôËÎó²îʹ¹¥»÷Ä¿µÄÀ¶ÆÁ £¬ÊǺÜÊǼòÆÓµÄÊÂÇ飡

ÕýÊÇ˼Á¿µ½À¶ÆÁµÄÒòËØ £¬AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÔÚ¶ÔÍâÐû²¼Îó²î¼ì²âÒªÁìµÄʱ¼äÓÈΪÉóÉ÷ £¬×èÖ¹¸øÊ¹ÓÃÕâЩ¼ì²âÒªÁìµÄÓû§Ôì³É²»ÐëÒªµÄ¶þ´ÎΣÏÕ £¬¾­ÓÉÖØ¸´ÑéÖ¤Çå¾²¿É¿¿Ö®ºó £¬²Å½«¼ì²âÒªÁìͶÈëÔÆ¶Ë¼ì²âϵͳ  ¡£


http.sysÎó²î¼ì²â

ÃæÁÙÔÆÔÆÑÏËàµÄÐÎʽ £¬ÆÊÎöְԱѸËÙ½«¾­ÓÉÇå¾²ÑéÖ¤ºóµÄ¼ì²âÒªÁìÏòÔÆ¶Ë¡¢²úÆ·¶Ë¼°·þÎñ¶Ëת´ï £¬²¢½¨ÒéÓû§¾¡¿ì¶ÔÆäÓªÒµÇéÐξÙÐÐÒ»´ÎÖÜÈ«µÄÎó²î¼ì²â £¬ÒÔ±ã¿ÉÒÔ¾¡¿ìÄõ½µÚÒ»ÊÖÊý¾Ý £¬ÎªºóÐøÖÆ¶©Îó²î·À»¤¼Æ»®¼°Ö´Ðв½·¥ÌṩÊý¾ÝÖ§³Ö¼°¾öÒéÒÀ¾Ý  ¡£http.sysÎó²îµÄ¼ì²â·½·¨¿ÉÒÔʹÓÃÈýÖÖ·½·¨ £¬Ôƶˡ¢²úÆ·¶Ë¼°¾ç±¾¹¤¾ß  ¡£


http.sysÎó²îÔÆ¶Ë¼ì²â

4ÔÂ17ÈÕÍí20:00 £¬AG¹«Ë¾¿Æ¼¼¿Í»§×ÔÖúÃÅ»§ÏµÍ³PortalÐû²¼http.sysÎó²î¼ì²âÒýÇæ £¬ÎªWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î(CVE-2015-1635)Ó¦¼±É¨ÃèÖ§³Ö £¬×èÖ¹ÖÁ4ÔÂ19ÈÕÆÆÏþ3:00 £¬ÒÑÓÐ348¼Ò¿Í»§ £¬¹²Ìá½»²¢É¨ÃèÓòÃûÊýÄ¿2086¸ö £¬ÆäÖÐ9¼Ò¿Í»§±£´æWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î £¬ÏìÓ¦ÍŶÓËæ¼´Í¨Öª¿Í»§  ¡£Í¬Ê±AG¹«Ë¾¿Æ¼¼Îó²îɨÃè²úÆ·RSAS¡¢AASÒÑÔÚµÚһʱ¼äÐû²¼Á˼ì²â²å¼þÉý¼¶°ü £¬ËæºóNF¡¢IDS¡¢IPSÒ²ÔÚ1ÌìÄÚÐû²¼Á˲úÆ·¹æÔòÉý¼¶°ü  ¡£

 

¿Í»§

ÊýÄ¿

ÓòÃû

ÊýÄ¿

ɨÃè¿Í»§

348

ɨÃèÓòÃû

2086

±£´æIISÎó²î¿Í»§

9

±£´æIISÎó²îÓòÃû

10

²»±£´æIISÎó²î¿Í»§

339

²»±£´æIISÎó²îÓòÃû

1541

 

ÏÖÔÚÄúËæÊ±¿ÉÒÔʹÓÃÕâ¸ö×ÔÖúϵͳ £¬¶ÔÓªÒµÇéÐξÙÐÐɨÃè £¬ÒÔ±ãÈ·ÈÏÊÇ·ñ±£´æ¸ÃÎó²î £¬É¨ÃèÇëµã»÷£ºhttps://portal.nsfocus.com/vulnerability/list/           IIS·þÎñÆ÷¸ßΣÎó²îɨÃè

 

Îó²îÈ·ÈÏ µ±É¨ÃèЧ¹ûÐÅÏ¢ÖзºÆðÐÅÏ¢¡°ÄúµÄ¼ì²âÄ¿µÄ±£´æ´ËÎó²î¡± £¬¼´¿ÉÈ·ÈÏÄ¿½ñÓªÒµÇéÐÎÖб£´æ¸ÃÎó²î £¬½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏë £¬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷  ¡£

IIS·þÎñÆ÷¸ßΣÎó²îÈ·ÈÏ

http.sysÎó²î²úÆ·¶Ë¼ì²â

4ÔÂ16ÈÕÖÐÎç £¬AG¹«Ë¾¿Æ¼¼¸÷²úÆ·Õë¶Ôhttp.sysµÄ¹æÔòÉý¼¶°ü¼°²å¼þÉý¼¶°üËùÓÐÍ£µ± £¬²¢ÔÚ¹Ù·½Ðû²¼²úÆ·Éý¼¶Í¨¸æ £¬Í¬Ê±Ïò·þÎñÖ°Ô±·¢ËÍÏà¹ØÐÅÏ¢  ¡£ÕâÀォÖ÷Òª²úÆ·Éý¼¶°æ±¾ÐÅϢժ¼ÈçÏ £¬Çë¿í´óÓû§¾¡¿ìÉó²éËùʹÓòúÆ·µÄ°æ±¾µÄÐÅÏ¢ £¬¸ü¶àÏêϸÐÅÏ¢ÇëÅÌÎÊ£ºhttp://update.nsfocus.com/

 

http.sysÎó²î·À»¤¹æÔòÉý¼¶°ü

http.sysÎó²î·À»¤²å¼þÉý¼¶°ü

²úÆ·

°æ±¾ºÅ

Éý¼¶Ê±¼ä

²úÆ·

°æ±¾ºÅ

Éý¼¶Ê±¼ä

NF 6.0.1

6.0.1.496 

2015/4/16

12:00:00

RSAS 6.0 

V6.0R02F00.0108 

2015/4/16

18:00:00

NF 6.0.0

5.6.7.496  

2015/4/16

12:00:00

RSAS 5.0

051347  

2015/4/16

19:00:00

IDS 5.6.9 

5.6.9.12244  

2015/4/16

13:00:00

RSAS-AAS 5.0

051130

2015/4/17

15:00:00

IDS 5.6.8 

5.6.8.496  

2015/4/16

11:00:00

WVSS 6.0

V6.0R02F00.28 

2015/4/16

18:00:00

IDS 5.6.7 

5.6.7.496  

2015/4/16

11:00:00

IDS 5.6.6 

5.6.0.422  

2015/4/16

11:00:00

IPS 5.6.9 

5.6.9.12244  

2015/4/16

11:00:00

IPS 5.6.8 

5.6.8.496  

2015/4/16

11:00:00

IPS 5.6.7 

5.6.7.496  

2015/4/16

11:00:00

IPS 5.6.6 

5.6.0.422  

2015/4/16

11:00:00

WAF 6.0.4

6.0.4.1.30345

2015/4/16

11:00:00

 

 

 

 

 

ÈôÊÇÄúµÄÓªÒµÇéÐÎÖÐÒѾ­°²ÅÅÁËÏà¹ØÎó²îɨÃèϵͳ £¬Ç뽫Îó²îɨÃèϵͳÉý¼¶µ½×îа汾ºó £¬¾¡¿ì×îÏȶÔӪҵϵͳ¾ÙÐÐɨÃè £¬ÓÈÆäÊÇÊÜ´Ë´Îhttp.sysÎó²îÓ°ÏìµÄӪҵϵͳƽ̨¾ÙÐÐÒ»´ÎÎó²îɨÃè  ¡£ÕâÀïÒÔAG¹«Ë¾Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨NSFOCUS Remote Security Assessment System  £¬¼ò³Æ£ºNSFOCUS RSAS£©ÎªÀý £¬µ±Äú°²ÅŸòúÆ·ºó £¬ÇëÏȶԲúÆ·¾ÙÐÐÉý¼¶£º

  • ?  RSAS v6ϵÁвúÆ·Éý¼¶µ½ÏµÍ³²å¼þ°æ±¾V6.0R02F00.0108£»
  • ?  RSAS v5ϵÁвúÆ·Éý¼¶µ½ÏµÍ³°æ±¾Îª051347£»
  • ?  AASϵÁвúÆ·Éý¼¶µ½ÏµÍ³°æ±¾Îª051130

 

Îó²îÈ·ÈÏ  ÈôÊÇÄúµÄÎó²îɨÃèЧ¹û°üÀ¨ÏÂͼÎó²î £¬ÌØÊâÊǰüÀ¨´øÓС°¡¾Ô­ÀíɨÃè¡¿¡±×ÖÑùµÄÎó²îʱ £¬¼´¿ÉÈ·ÈÏÄ¿½ñÇéÐÎÖб£´æ¸ÃÎó²î £¬½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏë £¬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷  ¡£

AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø


http.sysÎó²îÀëÏß¼ì²â

ÈôÊÇÄú»¹Ã»Óа²ÅÅÎó²îɨÃè²úÆ· £¬ÓÖ»òÕßÄúµÄӪҵϵͳÏÖÔÚ»¹²»ÊʺϾÙÐÐÈçÉϼì²â·½·¨ £¬»¹¿ÉÒÔ½ÓÄÉÀëÏß¼ì²âµÄ·½·¨ £¬¼´½ÓÄÉhttp.sys POCÑéÖ¤  ¡£ÕâÀïÌṩÁ½ÖÖÐÎʽ £¬°üÀ¨Python¾ç±¾¼°curl¹¤¾ß  ¡£

СÌùÊ¿£º

ÕâÀïÌáÐѸ÷ÈË £¬½üÆÚÊÜ´ËÎó²îÓ°Ïì £¬´ó×ÚÎó²î¼ì²â¾ç±¾¼°¹¤¾ßƵ³ö £¬ÈôÊÇÄúÐèÒª»ñÈ¡ÕâЩ¼ì²â¹¤¾ß £¬ÐèÒª´Ó¿É¿¿Í¾¾¶»ñÈ¡ £¬×èÖ¹±»Ö²Èë¶ñÒâ´úÂë £¬ÒÔÃâǰÞÜÀǺóÃŽø»¢£¡


 

ʹÓÃpython¾ç±¾¼ì²â    ½«ÏÂÁдúÂëдÈë.pyÎļþÖ´Ðм´¿É  ¡£

1          '''

2          ´Ë¾ç±¾½öÊÊÓÃÓÚ¼ì²âIIS·þÎñÆ÷ÊÇ·ñ±£´æHttp.sys ´¦Öóͷ£ Range ÕûÊýÒç³öÎó²î £¬²»ÊÊÓÃÓÚ¹¥»÷ʹÓà  ¡£

3          '''

4          import socket

5          import random

6           

7          ipAddr = ""    #Ìí¼ÓÄ¿µÄip

8          hexAllFfff = "18446744073709551615"

9           

10       req1 = "GET / HTTP/1.0 "

11       req = "GET / HTTP/1.1 Host: stuff Range: bytes=0-" + hexAllFfff + " "    #Ö÷Òª²âÊÔ´úÂë   

12        

13       print "[*] Audit Started"

14       client_socket = socket.socket(socket.AF_INET socket.SOCK_STREAM)

15       client_socket.connect((ipAddr 80))                 #ÈôÊÇweb·þÎñÆ÷¿ªÆô·Ç80¶Ë¿Ú £¬¿ÉÔÚ´Ë´¦ÐÞ¸ÄΪ׼ȷ¶Ë¿Ú

16       client_socket.send(req1)

17       boringResp = client_socket.recv(1024)

18       if "Microsoft" not in boringResp:                   #¼ì²âÄ¿½ñweb·þÎñÊÇ·ñΪIIS web·þÎñÆ÷

19                       print "[*] Not IIS"             

20                       exit(0) 

21       client_socket.close()

22       client_socket = socket.socket(socket.AF_INET socket.SOCK_STREAM)

23       client_socket.connect((ipAddr 80))

24       client_socket.send(req)

25       goodResp = client_socket.recv(1024)

26       if "Requested Range Not Satisfiable" in goodResp:           #ͨ¹ýÉó²é·þÎñÆ÷·µ»ØÅжÏÊÇ·ñ±£´æ¸ÃÎó²î £¬Æ¾Ö¤´òÓ¡³öµÄЧ¹ûÅжϣº

27                                                               #Looks VULNΪ±£´æ¸ÃÎó²î £¬Looks PatchedΪÒÑ´ò²¹¶¡ £¬ÆäËûÇéÐλ᷵»ØUnexpected response

28                       print "[!!] Looks VULN"

29       elif " The request has an invalid header name" in goodResp:

30                       print "[*] Looks Patched"

31       else:

32                       print "[*] Unexpected response cannot discern patch status"               


 

ʹÓÃcurl¹¤¾ß¼ì²â

1          $curl -v 192.168.174.140 -H "Host: irrelevant" -H "Range: bytes=0-18446744073709551615"


Îó²îÈ·ÈÏ  ±£´æ´ËÎó²î½ØÍ¼ £¬Èç·þÎñÆ÷·µ»ØRequested Range Not Satisfiable £¬Ôò˵Ã÷±£´æ´ËÎó²î  ¡£½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏë £¬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷  ¡£

CURL¹¤¾ß¼ì²âhttp.sysÎó²î

 

ʹÓ÷¢°ü¹¤¾ß½á¹¹httpÇëÇó°ü¼ì²â ÒÔfiddler¹¤¾ßΪÀý £¬½á¹¹ÈçÏÂͼµÄÇëÇó°ü£º

1          GET http://192.168.174.145/ HTTP/1.1

2          Host: 192.168.174.145

3          Range: bytes=0-18446744073709551615

4          Connection: keep-alive

5          Cache-Control: max-age=0

6          Accept: text/htmlapplication/xhtml+xmlapplication/xml;q=0.9image/webp*/*;q=0.8

 

Îó²îÈ·ÈÏ  ÈôÊÇÊÕµ½·þÎñÆ÷·µ»Ø°üÈçÏ Ôò˵Ã÷±£´æ´ËÎó²î  ¡£½¨ÒéÄú¾¡¿ìÖÆ¶©·À»¤ÍýÏë £¬ÒÔ×èֹϵͳÔÚ»ñµÃ¼Ó¹ÌǰÔâÊܹ¥»÷  ¡£


http.sysÎó²î·À»¤

¾­ÓÉÉÏÃæµÄÎó²î¼ì²â°ì·¨ºó £¬ÈôÊÇÈ·ÈÏÄúµÄÓªÒµÇéÐÎÖб£´æhttp.sysÎó²î £¬ÄÇô¾ÍÐèÒª¾¡¿ìÖÆ¶©²¢Æô¶¯¼Ó¹Ì¼Æ»® £¬ÕâЩ¼Ó¹Ì´ÓÎó²î²¹¶¡×îÏÈ £¬µ½²úÆ··À»¤ £¬µ½ÕûÌå·À»¤ £¬Öð²½Íƽø  ¡£

Îó²î¼Ó¹Ì

ʹÓÃIISµÄÓû§ £¬¿ÉÒÔͨ¹ýWindows UpdateµÄ·½·¨»ñµÃ¶ÔÓ¦µÄKB3042553ÈÈÐÞ²¹²¹¶¡ £¬½¨ÒéÓû§¿ªÆô×Ô¶¯¸üзþÎñÒÔʵʱװÖÃ×îв¹¶¡ £¬Ïà¹ØÍ¨¸æÇë¼û£º

http.sysÎó²î²¹¶¡Í¨¸æ£ºhttp://technet.microsoft.com/security/bulletin/MS15-034

ÈôÊÇÄúµÄӪҵϵͳÔÝʱ»¹ÎÞ·¨Éý¼¶²¹¶¡ £¬ÄÇô¿Éͨ¹ý½ûÓÃIIS Äں˻º´æÀ´ÔÝʱ»º½â´ËÎó²îµÄΣÏÕ £¬µ«ÐèÒª×¢ÖØÕâ¿ÉÄܻᵼÖÂIISÐÔÄÜϽµ £¬ÏêϸµÄÖ´ÐÐÒªÁì¿ÉÒԲο¼£º

http.sysÎó²î»º½â¼Æ»®£ºhttps://technet.microsoft.com/zh-cn/library/cc731903(v=ws.10).aspx

 

IIS¼Ó¹Ì

ËäÈ»IIS7ÖÐhttp.sysÒѾ­×ÔÁ¦³öÀ´³ÉΪϵͳ¼¶Çý¶¯³ÌÐò £¬µ«ÒÔʷΪ¼ø £¬½¨ÒéÓû§ÔÚ×°Öò¹¶¡µÄͬʱҲÐèҪ˼Á¿IIS¼Ó¹ÌÊÂÏî £¬ÏêϸµÄ×î¼Ñʵ¼ùÇë²Î¿¼£º

IIS7¼Ó¹Ì¼Æ»®£º https://technet.microsoft.com/zh-cn/library/cc731278(WS.10).aspx

²úÆ··À»¤

ÓÌÈçľͰЧӦһÑùƽ³£ £¬ÓªÒµÇéÐεļӹÌÖ»ÊÇÒÀÀµÓÚÎó²î¼Ó¹ÌÊDz»·óµÄ £¬ÕûÌåÇ徲Ʒ¼¶µÄÌáÉýÒÔ¼°Ó¦¶ÔδÀ´µÄ¹¥»÷ £¬Çå¾²²úÆ·ÊDZز»¿ÉÉÙµÄÒ»»· £¬½«WebϵͳÖÃÓÚDMZÇøÓò²¢¼ÓÒÔ¶à²úÆ·µÄÕûÌå·À»¤ £¬ÊÇÎÒÃÇÍÆ¼öµÄ×ö·¨  ¡£ÔÚÈçϰ²ÅÅÇéÐÎÖÐ £¬ÒÔAG¹«Ë¾WebÓ¦Ó÷À»ðǽ£¨Web Application Firewall £¬¼ò³ÆWAF£©ÎªÀý £¬¶ÔӪҵϵͳ°²ÅÅWAFÄܹ»´Ó¿Í»§×ʲúµÄÊÓ½Ç £¬ÊµÑé¶àÖÖ»ùÓÚ¹æÔòµÄ¼ì²â £¬²¢ÊµÑé¶àÌõÀíµÄÇå¾²»úÖÆ £¬ËæÊ±ÓëÔÆ¶Ë·þÎñЭ×÷ £¬ÌìÉúÏìÓ¦µÄWebÇå¾²½â¾ö¼Æ»® £¬´Ó¶øÓÐÓÃÓ¦¶ÔÎó²î·À»¤Ê¹Ãü  ¡£

ÇëËùÓÐʹÓÃAG¹«Ë¾²úÆ·µÄÓû§¾¡¿ìÉý¼¶²úÆ·¹æÔò  ¡£AG¹«Ë¾¿Æ¼¼ÒÑÔÚÈí¼þÉý¼¶Í¨¸æÖÐÌṩ¹æÔòÉý¼¶°ü £¬¹æÔò¿ÉÒÔͨ¹ý²úÆ·½çÃæµÄÔÚÏßÉý¼¶¾ÙÐÐ  ¡£ÈôÊÇÄúµÄӪҵϵͳÔÝʱ»¹ÎÞ·¨Éý¼¶¹æÔò°ü £¬ÄÇô¿ÉÒÔÔÚÈí¼þÉý¼¶Ò³ÃæÖÐ £¬ÕÒµ½¶ÔÓ¦µÄ²úÆ· £¬Í¨¹ýÏÂÔØÉý¼¶°ü £¬ÒÔÀëÏß·½·¨¾ÙÐÐÉý¼¶  ¡£ Ïà¹ØÐÅÏ¢Çë»á¼û£º

?             Çå¾²²úÆ·ÏÈÈÝ£ºhttp://www.nsfocus.com.cn/1_solution/1_2_1.html

?             ²úÆ·Éý¼¶Í¨¸æ£ºhttp://update.nsfocus.com/

 

ÓªÒµÇå¾²¼Ó¹Ì

ÔÚһЩ´óÐÍµÄÆóÒµ»ò×éÖ¯ÖÐ £¬http.sysÎó²îµÄ·À»¤»òÐí²¢²»¿É¿ìËÙÖ´ÐÐ £¬ÆäÔµ¹ÊÔ­ÓÉÔÚÓÚ£º1ÐèҪ˼Á¿ÓªÒµÏµÍ³µÄ¿ÉÓÃÐÔ£»2ÐèҪ˼Á¿ÕûÌåʵÑ鼯»®Öƶ©£»3ÐèÒª¾¡¿ÉÄܽµµÍ¼Ó¹ÌÐж¯¶ÔÓªÒµÇéÐεĶþ´ÎΣÏÕ  ¡£Õâ¾ÍÐèÒªÆóÒµ×ÔÉí¡¢Îó²îÏà¹Ø³§ÉÌ¡¢Çå¾²³§ÉÌÒ»ÆðЭ×÷²Å»ªÐγɿìËÙ¡¢Çå¾²¡¢ÓÐÓõÄÐж¯¼Æ»® £¬×èֹӪҵϵͳÔÚ»ñµÃÇå¾²¼Ó¹Ì֮ǰÔâÊܹ¥»÷  ¡£ÔÚ´Ë´ÎÓ¦¼±ÏìÓ¦Àú³ÌÖÐ £¬AG¹«Ë¾¿Æ¼¼µÄ·þÎñÖ°Ô±Ïò¿Í»§½¨ÒéÐж¯¼Æ»®Ó¦¸ÃÇÒÖÁÉÙ°üÀ¨ÈçÏ»·½Ú£º

?             Ê×ÏÈ £¬Ó¦¸ÃµÚһʱ¼ä»ñÈ¡Îó²îͨ¸æ¼°Ïà¹ØÐÅÏ¢ £¬Ïàʶ´Ë´ÎÎó²îµÄÓ°Ïì¹æÄ£¼°Éî¶È  ¡£

?             ÔÙÕß £¬ÐèÒª½«Í¨¸æÏ¢Õù¶ÁÓë×ÔÉíÏÖʵITӪҵϵͳ״̬ÏàÍŽá £¬ÖÜÈ«ÅжϳöÓ°Ïì¹æÄ£ºÍˮƽ£¨Õâ°üÀ¨¶Ô×ÔÉíÓªÒµ¼°¶ÔÆä¿Í»§µÄÓ°Ïìˮƽ£© £¬Õâ¸öÅжÏÀú³Ì £¬ÐèÒªÊý¾Ý×÷Ϊ׼ȷ¼Æ»®Öƶ©µÄÊÂʵÒÀ¾Ý £¬½¨ÒéÓû§Ê¹ÓÃÇå¾²¿É¿¿µÄÎó²îɨÃ蹤¾ß £¬Éý¼¶×îÐÂÐû²¼µÄ²å¼þ»ò¹æÔò¿â £¬¶ÔÈ«Íø¾ÙÐÐÇ徲ɨÃè £¬Äõ½µÚÒ»ÊÖÊý¾ÝºóÒÔ±ã×÷Ϊ¾öÒéÒÀ¾Ý£»

?             ÔÙ´Î £¬ITÖ°Ô±ÐèÒª´ÓÓªÒµÎȹÌÐÔ¡¢Î£º¦Ë®Æ½ºÍ¹æÄ£¼°Ö÷ÒªÐԵȶà¸öά¶È×ÛºÏ˼Á¿ £¬Öƶ©Õû¸Äʱ¼äÍýÏë±í £¬È¨ÖØÓɸߵ½µÍÒÀ´Î¶Ô¾Ö²¿ÍøÂç¼°Ö÷»ú×°±¸»òijӪҵϵͳװ±¸Õö¿ªÕû¸ÄºÍ¼Ó¹ÌÊÂÇ飨½¨ÒéÔ¼ÇëÎó²îÏà¹Ø³§É̼°Çå¾²³§ÉÌһͬ¼ÓÈ룩  ¡£

?             Õâ¸ö½×¶ÎÐèÒªÇå¾²³§ÉÌÌṩרҵÊÖÒÕЭÖú £¬ºÃ±ÈÎó²î¼Ó¹Ì×Éѯ¡¢ÑéÖ¤¼Ó¹ÌÊÇ·ñÀֳɣ»Í¬Ê±ÐèÒªÏàʶÇå¾²³§É̵ÄÄÄЩװ±¸ÒѾ­Ðû²¼»ò¼´½«Ðû²¼·À»¤¹æÔò £¬Éý¼¶ºó¼´¿É¾ÙÐзÀ»¤£»

?             ÈôÊÇ»¹Ã»ÓнÓÄÉÈκÎÒ»¿îÇå¾²×°±¸ £¬¾ÍÐèÒª½ÓÄÉÔÝʱ·À»¤²½·¥ £¬°üÀ¨½ÓÄÉÎó²îÏà¹Ø³§É̼°Çå¾²³§É̵ÄÏà¹Ø¼Æ»® £¬ÎªÕûÌå¼Ó¹ÌÕùȡʱ¼ä £¬×èÖ¹ÔÚδ¼Ó¹ÌÕû¸ÄÀÖ³É֮ǰÕâ¸ö´°¿Úʱ¼äÔâµ½¹¥»÷²¢Êܵ½Ëðʧ £¬ÕâÑùµÄÇéÐÎÔÚÏ൱¶àµÄ0dayÊÂÎñÖÐ˾¿Õ¼û¹ß£»

?             ÁíÍâ £¬»¹ÐèÒªÎó²îÏà¹Ø³§ÉÌÓëÇå¾²³§ÉÌͨÁ¦Ð­×÷ £¬Ï໥ÏàͬÎó²îÔ­ÀíºÍʹÓÃÀú³Ì £¬¾ÙÐнÏÉîÌõÀíµÄ½â¶Á £¬²Å»ª¹»Ôö½øÎó²îÏà¹Ø³§É̵Ŀª·¢Ö°Ô±ÉîÈëÏàʶÕâ¸öÎó²î²¢Æ¾Ö¤Æä×ÔÉíÇéÐξÙÐдúÂë²ãÃæµÄÕû¸Ä£»

?             È»ºó £¬Ôڼӹ̽׶ÎÐÔ»òÕûÌåÍê³Éºó £¬ÐèÒªÔٴξÙÐÐÍêÕûɨÃèºÍÈ˹¤ÑéÖ¤Õû¸Ä¼Ó¹ÌЧ¹û £¬ÔÚÊÖÒÕͶÈëÔÊÐíµÄÌõ¼þÏ £¬½¨ÒéÄúÔٴξÙÐи÷·½ÃæÈÕÖ¾ÆÊÎö £¬ÊÓ²ìÕû¸Ä¼Ó¹Ìʱ´úÓÐûÓÐÀֳɵĹ¥»÷µ½ÆäϵͳÔì³ÉÆäËûËðʧ£»

?             ×îºó £¬ÔÚÕûÌåÏìÓ¦ÊÂÇéÍê³Éºó £¬¾ÙÐÐ×ܽáºÍ±¸°¸¼Í¼  ¡£


ÍþвÇ鱨

ÒÔºó´Îhttp.sysÎó²îÇéÐοÉÒÔ¿´µ½ £¬ÎÞÂÛÎó²îÔ­ÀíÔõÑù £¬ÎÞÂÛÎó²î·À»¤¼Æ»®ÔõÑùʵÑé £¬Òªº¦ÔÚÓÚ¾¡¿ÉÄÜ¿ìµÄÏàʶµ½Îó²îÐÅÏ¢¼°Ïà¹ØµÄÇ鱨 £¬ÒԱ㾡¿ÉÄÜ¿ìµÄÆô¶¯Ó¦¼±ÏìÓ¦»úÖÆ  ¡£ÕâÎÞÂÛ¹ØÓÚ½â¾ö¹Å°åÇå¾²»òÕßAPT¹¥»÷À´Ëµ¶¼ÊÇÖ÷ÒªµÄÊÖ¶ÎÖ®Ò» £¬ÍþвÇ鱨µÄ»ñÈ¡¼°ÏìÓ¦¶¼ÌåÏÖÁË·ÀÓùÄÜÁ¦µÄ½¨Éèˮƽ £¬ÍþвÇ鱨·þÎñϵͳÖÁÉÙ°üÀ¨ÁËÍþв¼à²â¼°ÏìÓ¦¡¢Êý¾ÝÆÊÎö¼°ÕûÀí¡¢ÓªÒµÇ鱨¼°½»¸¶¡¢Î£º¦ÆÀ¹À¼°×Éѯ¡¢Çå¾²Íйܼ°Ó¦Óõȸ÷¸ö·½Ãæ £¬Éæ¼°Ñо¿¡¢²úÆ·¡¢·þÎñ¡¢ÔËÓª¼°ÓªÏúµÄ¸÷¸ö»·½Ú £¬AG¹«Ë¾¿Æ¼¼Í¨¹ýÑо¿¡¢Ôƶˡ¢²úÆ·¡¢·þÎñµÈÁ¢ÌåµÄÓ¦¼±ÏìӦϵͳ £¬ÏòÆóÒµºÍ×é֯ʵʱÌṩÍþвÇ鱨²¢Ò»Á¬¾ÙÐкóÐø·þÎñ £¬°ü¹Ü¿Í»§ÓªÒµµÄ˳³©ÔËÐÐ  ¡£

ÈôÊÇÄú¶ÔÎÒÃÇÌṩµÄÄÚÈÝÓÐÈκÎÒÉÎÊ £¬»òÕßÐèÒªÏàʶ¸ü¶àµÄÐÅÏ¢ £¬¿ÉÒÔËæÊ±Í¨¹ýÔÚ΢²©¡¢Î¢ÐÅÖÐËÑË÷AG¹«Ë¾¿Æ¼¼ÁªÏµAG¹«Ë¾ £¬½Ó´ýÄúµÄ´¹Ñ¯£¡




ÍþвÇ鱨ÏÂÔØ

·À»¤¼Æ»®£ºWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î·À»¤


?

ÄúµÄÁªÏµ·½·¨

*ÐÕÃû
*µ¥Î»Ãû³Æ
*ÁªÏµ·½·¨
*ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
Ìá½»µ½ÓÊÏä

¹ºÖÃÈÈÏß

  • ¹ºÖÃ×Éѯ:

    400-818-6868-1

Ìá½»ÏîÄ¿ÐèÇó

½Ó´ý¼ÓÈëAG¹«Ë¾¿Æ¼¼ £¬³ÉΪÎÒÃǵÄÏàÖúͬ°é£¡
  • *ÇëÐÎòÄúµÄÐèÇó
  • *×îÖÕ¿Í»§Ãû³Æ
  • *ÏîÄ¿Ãû³Æ
  • Äú¸ÐÐËȤµÄ²úÆ·
  • ÏîĿԤËã
ÄúµÄÁªÏµ·½·¨
  • *ÐÕÃû
  • *ÁªÏµµç»°
  • *ÓÊÏä
  • *Ö°Îñ
  • *¹«Ë¾
  • *¶¼»á
  • *ÐÐÒµ
  • *ÑéÖ¤Âë AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
  • Ìá½»µ½ÓÊÏä
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø
AG¹«Ë¾(Öйú¼¯ÍÅ)¡¤ÓÐÏÞ¹«Ë¾¹ÙÍø

·þÎñÖ§³Ö

ÖÇÄܿͷþ
ÖÇÄܿͷþ
¹ºÖÃ/ÊÛºóÊÖÒÕÎÊÌâ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
Ã˹ܼÒ-ÊÛºó·þÎñϵͳ
ÔÚÏßÌáµ¥|ÖÇÄÜÎÊ´ð|֪ʶ¿â
Ö§³ÖÈÈÏß
Ö§³ÖÈÈÏß
400-818-6868
AG¹«Ë¾¿Æ¼¼ÉçÇø
AG¹«Ë¾¿Æ¼¼ÉçÇø
×ÊÁÏÏÂÔØ|ÔÚÏßÎÊ´ð|ÊÖÒÕ½»Á÷
΢²©
΢²©

΢²©

΢ÐÅ
΢ÐÅ

΢ÐÅ

BÕ¾
BÕ¾

BÕ¾

¶¶Òô
¶¶Òô

¶¶Òô

ÊÓÆµºÅ
ÊÓÆµºÅ

ÊÓÆµºÅ

·þÎñÈÈÏß

400-818-6868

·þÎñʱ¼ä

7*24Сʱ

? 2026 NSFOCUS AG¹«Ë¾¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

ÍøÕ¾µØÍ¼