作者KarasuTW (泣くに泣けない)
看板AntiVirus
标题[情报] 又出包了... Microsoft Active X 0day 攻击
时间Tue Jul 7 19:49:29 2009
微软已发布 MS09-032 ActiveX Kill Bit 的积存安全性更新(973346)
继 JPEG 漏洞、QuickTime Parser 漏洞之後,
这次是 Microsoft Video ActiveX 出了问题。
明确的说,是 MPEG2TuneRequest。
受影响的产品:
Windows XP 各版本
Windows Server 2003 各版本
影响范围:
浏览到植入恶意程式码的网站之後,攻击者可以
取得与本地使用者同等权限,并执行任意程式码。
缓和策略:
‧套用 KB972890 的 Microsoft Fix it
http://support.microsoft.com/kb/972890
这会阻止 Video ActiveX 控制项启动,但是 msvidctl.dll 里面
没有任何一项 ActiveX Control Object 是设计给 IE 用的 = =" [1]
所以安心杀,对浏览网页是没影响的。
‧使用较低权限的帐户来浏览网页 (Limited User Account or DropMyRights)
‧使用不支援 ActiveX 技术的浏览器来浏览网路
以上。
--
[1] 引用 Microsoft Security Research & Defence 的文章:
〝During the investigation, we identified that none of the ActiveX Control
Objects hosted by msvidctl.dll are meant to be used in IE. Therefore, we
recommend to kill-bit all of these controls as a defense-in-depth practice,
as stated in Advisory 972890. The side effect is minimal.〞
--
And I begin to wonder... the dream I can't remember.
When I wake up in the morning, where in the world did they go?
--
※ 发信站: 批踢踢实业坊(ptt.cc)
◆ From: 114.43.115.224
1F:推 pttdog:一般家用使用者 需要修正吗?? 不想冒险装 07/07 20:11
2F:→ KarasuTW:如果你自认不会逛到相关的网站 或是其他资安防范做得够好 07/07 20:22
3F:→ KarasuTW:就可以不要装... Fix it 是 MS 官方提供的应变措施 :) 07/07 20:22
4F:推 ppFx4:谢谢,虽然我现在都用GC在浏览网页,但还是修吧! 07/07 21:51
※ 编辑: KarasuTW 来自: 114.43.115.68 (07/08 09:15)
8F:推 VCCS:推 感谢资讯提供 07/08 19:05
※ 编辑: KarasuTW 来自: 114.43.117.28 (07/15 17:29)
※ 编辑: KarasuTW 来自: 114.43.117.28 (07/17 12:26)