NetSarangÈí¼þÖÐnssock2.dllÄ£¿é±»Ö²Èë¶ñÒâ´úÂëÊÖÒÕÆÊÎöÓë·À»¤¼Æ»®
2017-08-15
NetSarangÊÇÒ»¼ÒÌṩÇå¾²ÅþÁ¬½â¾ö¼Æ»®µÄ¹«Ë¾£¬¸Ã¹«Ë¾µÄ²úÆ·Ö÷Òª°üÀ¨Xmanager Xmanager 3D Xshell XftpºÍXlpd¡£×î½ü£¬¹Ù·½ÔÚ2017Äê7ÔÂ18ÈÕÐû²¼µÄÈí¼þ±»·¢Ã÷ÓжñÒâºóÃÅ´úÂ룬¸Ã¶ñÒâµÄºóÃÅ´úÂë±£´æÓÚÓÐÕýµ±ÊðÃûµÄnssock2.dllÄ£¿éÖС£´ÓºóÃÅ´úÂëµÄÆÊÎöÀ´¿´£¬¸Ã´úÂëÊÇÓÉÓÚ¹¥»÷ÕßÈëÇֵĿª·¢ÕßµÄÖ÷»ú»òÕß±àÒëϵͳ²¢ÏòÔ´ÂëÖвåÈëºóÃŵ¼Öµġ£¸ÃºóÃÅ´úÂë¿Éµ¼ÖÂÓû§Ô¶³ÌµÇ¼µÄÐÅϢй¶£¬ÉõÖÁ¿ÉÄÜÔ¶³ÌÖ´ÐдúÂë¡£
VirustotalÔÚÏß¼ì²âÇéÐΣº
ÓÉÆÊÎöЧ¹û¿ÉÒÔÖªµÀ£¬nssock2.dllÒѾ±»¶à¼Òɱ¶¾Èí¼þʶ±ðΪ¶ñÒâµÄ³ÌÐò¡£

Ïà¹ØµØµã£º
https://www.netsarang.com/news/security_exploit_in_july_18_2017_build.html
https://www.virustotal.com/#/file/462a02a8094e833fd456baf0a6d4e18bb7dab1a9f74d5f163a8334921a4ffde8/detection
ÊÜÓ°ÏìµÄ°æ±¾
· Xshell Build 1322
· Xshell Build 1325
· Xmanager Enterprise Build 1232
· Xmanager Build 1045
· Xmanager Build 1048
· Xftp Build 1218
· Xftp Build 1221
· Xlpd Build 1220
²»ÊÜÓ°ÏìµÄ°æ±¾
· Xmanager Enterprise Build 1236
· Xmanager Build 1049
· Xshell Build 1326
· Xftp Build 1222
· Xlpd Build 1224
Èí¼þÏÂÔØÇéÐÎ
±£´æºóÃŵÄÈí¼þÔÚº£ÄÚµÄÏÂÔØÇéÐΣº
· Xmanager£º

· Xshell£º

ÊÖÒÕÆÊÎö
¸ÅÊö
NetSarangµÄÖ÷ÒªÈí¼þ°æ±¾Öз¢Ã÷nssock2.dllÄ£¿éµÄ¹Ù·½Ô´ÂëÖб»Ö²Èë¶ñÒâºóÃÅ´úÂë¡£¾ÝϤ£¬ÊǺڿÍÉøÍ¸µ½ÁË¿ª·¢µÄ»úе£¬È»ºóÔÚ´úÂëÖмÓÈëÁ˶ñÒâµÄ´úÂëµ½¹Ù·½µÄÔ´´úÂëÖУ¬ÒÔÏÂΪ¶ñÒâ´úÂëÆÊÎö¡£
²Î¿¼£ºhttps://www.virustotal.com/#/user/jumze/comments
Èö²¥ÓëѬȾ
Óû§Ö±½ÓÏÂÔØ»òÈí¼þÀ¦°óÏÂÔØ¡£
ÑùÌìÖ°Îö
ÆÊÎöÇéÐÎ
|
ϵͳ |
Windows 7 32bit |
|
ʹÓù¤¾ß |
ProcessMonitor Xuetr Wireshark OllyDBG IDA CuteFTP |
TAC¼ì²âЧ¹û£º

ͼ TAC¼ì²âЧ¹û
Ö÷Òª¹¦Ð§
[1]ÐÅÏ¢ÇÔÈ¡£º»ñȡĿ½ñÅÌËã»úÃû³ÆºÍÄ¿½ñÓû§Ãû³Æ£»
[2]Ô¶³Ì¿ØÖÆ£º´úÂëÖÐÒѾʵÏÖ£¬µ«ÓÉÓÚ·þÎñÆ÷²»´æ»î£¬µ¼ÖÂÊý¾ÝÎÞ·¨½âÃÜÖ´ÐУ»
[3]ÍøÂçÐÐΪ£ºIP:8.8.8.8¡¢8.8.4.4¡¢4.2.2.2¡¢4.2.2.1¡¢Ä¿½ñÅÌËã»úÉèÖõÄDNS·þÎñÆ÷µØµã; Ïòdns·þÎñÆ÷·¢ËÍdns°ü¡£
HOST: nylalobghyhirgh.com; Ñù±¾½«ÍøÂçµÄÐÅÏ¢ÉÏ´«µ½ÉÏÊö·þÎñÆ÷£»

¸Ã¶ñÒâºóÃÅÖ²Èënssock2.dllÄ£¿éµÄÔ´ÂëÖУ¬ÊÇÒ»¶Î±»¼ÓÃܵÄshellcode¡£

Õâ¶Îshellcode±»Ìí¼ÓÁËÒ»¶¨Á¿µÄ»¨Ö¸Á¿ÌÒâÔöÌíÆÊÎöÄѶȣ¬È¥³ý»¨Ö¸ÁîÒԺ󣬿ÉÒÔ·¢Ã÷Æä½¨ÉèÁËÒ»¿éÄÚ´æÇø£¬½âÃÜ´úÂë²¢Ö´ÐС£

дúÂë¶ÎÖУ¬Ñù±¾½¨ÉèÁËÒ»¸öỊ̈߳¬Ö®ºó¾Í»Øµ½Õý³£µÄ³ÌÐòÁ÷³ÌÖУ¬Ê¹µÃÓû§ºÜÄÑ·¢Ã÷×Ô¼ºËùʹÓõIJúÆ·Öб£´æºóÃÅ¡£

ÔÚÏ̺߳¯ÊýÖУ¬ÎÒÃÇ¿ÉÒÔ¿´µ½£¬Ñù±¾ÔÚÒ»Ö±µÄ»ñȡϵͳʱ¼ä£¬Æ¾Ö¤ÏµÍ³Ê±¼äµÄ²î±ð£¬ÅÌËã³ö²î±ðµÄÓòÃû¡£ÏÂͼΪ2017Äê9ÔÂÌìÉúµÄÓòÃû£º

ÎÒÃÇͨ¹ýÐÞ¸Äϵͳʱ¼ä»ñÈ¡µ½µÄÓòÃûÇéÐÎÈçÏ£º
|
ʱ¼ä |
¶ÔÓ¦ÓòÃû |
|
2017-06 |
vwrcbohspufip.com |
|
2017-07 |
ribotqtonut.com |
|
2017-08 |
nylalobghyhirgh.com |
|
2017-09 |
jkvmdmjyfcvkf.com |
|
2017-10 |
bafyvoruzgjitwr.com |
|
2017-11 |
xmponmzmxkxkh.com |
|
2017-12 |
tczafklirkl.com |
½Ó×Å´úÂë»á»ñȡĿ½ñÅÌËã»úµÄÃû³ÆºÍÅÌËã»úÓû§ÃûÐÅÏ¢¡£

¾ÓÉÈçÏÂËã·¨¼ÓÃܺó£¨ÊäÈë²ÎÊýΪa1a2a3a4¡£a1=0£¬a3=0x2D£¨Óû§Êý¾ÝµÄ³¤¶È£©£¬a2=´æ·ÅÓû§Êý¾ÝµÄµØµã£¬a4=´æ·Å¼ÓÃܺóµÄÊý¾ÝµÄµØµã£©£º

Ч¹ûÈçÏ£º

È»ºóÔÙ½«Ð§¹û¾ÙÐмÓÃÜ

»ñµÃ×îÖÕ¼ÓÃÜЧ¹û²¢ÇÒ·¢ËÍdnsÆÊÎöÇëÇ󣬽«¼ÓÃܺóµÄÊý¾Ý׺ÔÚÓòÃûǰ·¢Ë͸ø¹¥»÷Õߣº

ͨ¹ý´ËÖÖÒªÁì¾ÙÐз¢ËÍ£¬¾ßÓм«¸ßµÄÒþ²ØÐÔ¡£
ÎÒÃÇ»¹·¢Ã÷£¬ÔÚ´úÂëÖ´ÐеÄÀú³Ìµ±ÖУ¬ÈÔ±£´æÒ»¶Î¼ÓÃÜ´úÂ룬ÐèÒª´Ó·þÎñÆ÷¶Ë»ñÈ¡ÃÜÔ¿À´¾ÙÐнâÃÜ£¬Ä¿½ñÇéÐÎÏÂÒÑÎÞ·¨¾ÙÐнâÃÜ¡£(ÃÜÔ¿´æ´¢ÔÚa1£¬a2£¬Å²ÓÃʱ´«ÈëµÄ²ÎÊýΪa3£¬Í¬ÑùÊÇ´Ó·þÎñÆ÷»ñÈ¡)

ÍøÂçÐÐΪ
ʵÑé¶ÔÕ⼸¸öµØµã¾ÙÐÐÅþÁ¬8.8.8.8¡¢8.8.4.4¡¢4.2.2.2¡¢4.2.2.1¡¢Ä¿½ñÇéÐÎϵÄDNS·þÎñÆ÷µØµã¡£
ƾ֤ʱ¼ä²î±ð£¬ÅþÁ¬ÓòÃûÒ²²î±ð¡£
ÈôÊÇÅþÁ¬ÓòÃûÀֳɣ¬Ôò½«ËѼ¯µ½µÄÐÅÏ¢·¢ËͳöÈ¥£¬·½·¨ÎªÍ¨¹ýDNSÇëÇó½«Êý¾ÝÖØ¶¨Ïòµ½¹¥»÷Õß×Ô¼ºµÄÓòÃû·þÎñÆ÷¡£
Æô¶¯·½·¨
Óû§ÏÂÔØxshell²¢×Ô¶¯ÔËÐС£
¹¥»÷¶¨Î»
ͨ¹ý¶Ô¸ÃÑù±¾µÄÍøÂçÐÐΪ¾ÙÐмòÆÓµÄ¸ú×Ù£¬·¢Ã÷±¨¸æÖÐ8Ô·ݵÄÓòÃûÔÚwhoisÖÐÅÌÎʵ½µÄÐÅÏ¢ÈçÏ£º


ÆäËûÐÅÏ¢±»ÉêÇëÕßÒþ²Ø¡£
·À»¤¼Æ»®
Óû§×Ô²é
Óû§¿Éͨ¹ýÉó²énssock2.dllµÄ°æÔÀ´È·¶¨ÊÇ·ñÊÜ´ËÓ°Ï죺
ÔÚÈí¼þ×°ÖÃĿ¼ÏÂÕÒµ½nssock2.dllÎļþ£¬ÓÒ¼ü¸ÃÎļþÉó²éÊôÐÔ£¬ÈôÊǰ汾ºÅΪ5.0.0.26Ôò±£´æºóÃÅ´úÂ룺


¹Ù·½½â¾ö¼Æ»®
Óû§¿Éͨ¹ýÉó²éµÄnssock2.dllµÄ°æ±¾ºÅµÄÒªÁìÀ´È·¶¨ÊÇ·ñʹÓú¬ÓкóÃŵÄÈí¼þ°æ±¾£¬ÈôÊÇÓû§ÕýÔÚʹÓÃÒÔÉÏÊÜÓ°ÏìµÄÈí¼þ°æ±¾£¬ÇëÉý¼¶µ½×îа汾¡£¹Ù·½ÔÚ×îеÄÈí¼þ°æ±¾ÖÐÒÑ¾ÒÆ³ýÁ˸úóÃÅ´úÂ룬×îеÄÈí¼þ°æÌìÖ°±ðΪ£º
· Xmanager Enterprise Build 1236
· Xmanager Build 1049
· Xshell Build 1326
· Xftp Build 1222
· Xlpd Build 1224.
¹Ù·½ÏÂÔØµØµãÈçÏ£º
https://www.netsarang.com/download/software.html
ÊÖÒÕ·À»¤¼Æ»®
²úÆ·Àà
? ÈôÊÇÄú²»ÇåÎúÊÇ·ñÊÜ´ËÎó²îÓ°Ï죺
1¡¢ÄÚÍø×ʲú¿ÉÒÔʹÓÃAG¹«Ë¾¿Æ¼¼µÄÔ¶³ÌÇå¾²ÆÀ¹Àϵͳ(RSASV6)¾ÙÐмì²â¡£
Ô¶³ÌÇå¾²ÆÀ¹Àϵͳ£¨RSAS V6£©
http://update.nsfocus.com/update/listRsas
2¡¢AG¹«Ë¾ÍþвÆÊÎöϵͳ(TAC)¿ÉÒÔ¾ÙÐмì²â¡£
http://update.nsfocus.com/update/listTac
ͨ¹ýÉÏÊöÁ´½Ó£¬Éý¼¶ÖÁ×îа汾¼´¿É¾ÙÐмì²â£¡
? ʹÓÃAG¹«Ë¾¿Æ¼¼·À»¤Àà²úÆ·£¨IPS/IDS/NF£©¾ÙÐзÀ»¤£º
ÈëÇÖ·À»¤ÏµÍ³£¨IPS£©
http://update.nsfocus.com/update/listIps
ÈëÇÖ¼ì²âϵͳ£¨IDS£©
http://update.nsfocus.com/update/listIds
ÏÂÒ»´ú·À»ðǽϵͳ£¨NF£©
http://update.nsfocus.com/update/listNf
ͨ¹ýÉÏÊöÁ´½Ó£¬Éý¼¶ÖÁ×îа汾¼´¿É¾ÙÐзÀ»¤£¡
·þÎñÀà
AG¹«Ë¾¿Æ¼¼ÌṩרҵµÄÇå¾²ÊÖÒÕ·þÎñ£¬È«·½Î»µÄ°ü¹Ü¿Í»§Ó¦ÓÃϵͳÇå¾²£¬×èÖ¹ÊÜ´ËÎó²îÓ°Ïì¡£
? ¶ÌÆÚ·þÎñ£ºÎÒÃÇ¿ÉÒÔÌṩӦ¼±·þÎñ£¬·þÎñÄÚÈݰüÀ¨¶Ô¿Í»§Ó¦ÓÃϵͳÓÐÕë¶ÔÐÔµÄÌṩÐÞ¸´½¨Ò飬°ü¹Ü¿Í»§ÏµÍ³µÄÇå¾²Éý¼¶¡£
? Öкã¾Ã·þÎñ£ºÍŽáAG¹«Ë¾¿Æ¼¼¼ì²âÓë·À»¤²úÆ·£¬Ìṩ7*24µÄÇå¾²ÔËÓª·þÎñ£¬ÔÚ¿Í»§Ó¦ÓÃϵͳÔâµ½Çå¾²ÍþвʱµÚһʱ¼ä֪ͨ¿Í»§£¬²¢°´ÆÚ¾ÙÐÐÇå¾²¼ì²â£¬Õë¶ÔÇ徲Σº¦ÌṩרҵµÄ½â¾ö¼Æ»®¡£

AG¹«Ë¾ÔÆ





