In article <bhlblr$2kk5$1...@news2.wakwak.com>
"Tomoya Miyoshi" <tm...@ag.wakwak.com> writes:
> æè¿MSãã©ã¹ãã«ã€ããŠãã¹ã³ãã§å ±éãããŠããã®ãå€ãç®ã«ããŸãããå
容çã«
> æºè¶³ããããªãããšãå°ãªããããŸããã
å ·äœçã«ã©ã®èŸºããäžæºã§ããããã
> ãããã£ãã¯ãŒã ããŠã€ã«ã¹ã«ã€ããŠã®ãã¥ãŒã¹ã°ã«ãŒãã¯fjã«ãªãã§ããããïŒ
ã¯ããfj.comp.security ãããããããªãã§ãããããä»åã¯ã
Windows 2000/XP ãªã®ã§ãã·ã¹ãã åºæã®è©±ãªãã
fj.os.ms-windows.win2000 ãšãfj.os.ms-windows.xp ãšãã
fj.os.ms-windows.misc ã§ãããã§ãã
ãšãããããFollowup-To: fj.comp.security ã«ããŠãããŸãã
DCOM ãªããããã©ã«ãã§éããŠããèšèšã ã£ãããå¹³æ°ã ã£ãã®ã«ã
http://www.microsoft.com/japan/technet/security/virus/blaster.asp#workaround
ããã©ã«ãã§å®å
šåŽã«åããšããèšèšã¯ããã€ã¯ããœããèªä¿¡ãé
匵ã£ãŠããããšæ±ºæè¡šæããŠããã®ãèŠãèŠãããããŸããããã¯
ã©ããªã£ããã§ããããã
å人çã«ã¯ãæ¥åžžç䜿ã£ãŠããã®ã¯ãUnix 系㚠MacOSX ãªã®ã§ã
ä»åã® W32/Blaster Worm ã«é¢ããŠã¯å
šç¶å¹³æ°ãªãã ããã©ã
Blaster ã£ãŠã誰ãååãä»ãããã§ããããã
DDoS æ»æããããšãã話ã¯ã©ããªã£ããã§ããããã
ããããåœãã«ã¯ããããã¯ãŒã¯ã«ã€ãªããªããšãããªãããã©ã
ã€ãªãã ç¬éã«ããããŠããŸããšããã®ã¯ããªããªã倧å€ã§ããã
äœæ°åºæ¬å°åž³ãããã¯ãŒã¯ã®ãã®ã¯ãã¡ãããšããããåœã£ãŠãã
ãã§ããããã
ãæ°åãéãïŒãããããããããïŒã
ãç波倧åŠãé»åã»æ
å ±ããããããã
å ±éã§ã¯ããã¿çã«çµæžç£æ¥çã®å ±éè³æ
URL:http://www.meti.go.jp/kohosys/press/0004399/ ã䜿ãããã®ã§ã¯ãªãããšæããŸããããåžžææ¥ç¶ããŠãããŠãŒã¶ãŒãçã£ãããšããåæã«çµäºããŠããŸãããšãã£ãè³ã«ä»ãæãèšèã䜿ãããŠããŸããã確ãã«ã¯ãŒã ã®æ¡æ£ãé²ãããã®æ³šæåèµ·
ãšããŠã¯åœ¹ã«ç«ã€ã®ãããããŸããããæææ¹æ³ã®è©³çŽ°ãããããããã±ããã®ãã£
ã«ã¿ãªã³ã°ã§é²ããã®ããã¢ã³ããŠã€ã«ã¹ãœããã§é²ããã®ããããããŸããã§ã
ãã
ãŠã€ã«ã¹ãšã¯ãŒã ã®åºå¥ãã€ããŠããªãã®ãæ°ã«ãªããŸããææ¥æ°è
URL:http://www.asahi.com/special/pcvirus/ ã¯MSãã©ã¹ãããŸã ããŠã€ã«ã¹ããšåŒãã§ããŸããã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã®
ã§ãã¯ãŒã ããŠã€ã«ã¹ããšãã£ãæ
å ±ã¯éèŠã ãšæãã®ã§ããã
ã¯ãŒã ã®åºçŸã¯ã¢ãªã¹ã¯ãŒã 以æ¥ãããªãããšæããã§ããããã®èå³ãæºãããŠã
ããå ±éãèŠãããŸããã
[snip]
> DDoS æ»æããããšãã話ã¯ã©ããªã£ããã§ããããã
ãã€ã¯ããœããã¯ã¯ãŒã ã«å«ãŸããŠããæ»æ察象ã®IPã¢ãã¬ã¹ãWindows Updateã®
ãµãŒããžãªãã€ã¬ã¯ãããªããã察åŠããããã§ãã
> ããããåœãã«ã¯ããããã¯ãŒã¯ã«ã€ãªããªããšãããªãããã©ã
> ã€ãªãã ç¬éã«ããããŠããŸããšããã®ã¯ããªããªã倧å€ã§ããã
ãææããŠããããã ã£ãããããã¯ãŒã¯ããåãé¢ããŠãææããŠããªãå人ãã
é§é€ããŒã«ãããããªããããšNHKãèšã£ãŠãŸãããã©ããããŠãã®äººã«ãšã£ãŠã¯ç¡
è¶ã§ãïŒïŒŸïŒŸïŒ ãã€ã¯ããœããã®ãµã€ãã«ã¯ããå°ãçŸå®çãªå¯Ÿçæ¹æ³ãæžãããŠ
ããŸããã©ãç°¡åãªæ¹æ³ã§ã¯ãªãã§ãããã
> äœæ°åºæ¬å°åž³ãããã¯ãŒã¯ã®ãã®ã¯ãã¡ãããšããããåœã£ãŠãã
> ãã§ããããã
ã(ç·å)çåžçºæ課ã¯ããã¡ã€ã¢ãŒãŠãªãŒã«ã«ãã£ãŠãä»åã®ãŠã€ã«ã¹ãæ»æããçµ
è·¯ã¯å
ã
éããŠããã®ã§ãäœåºãããã®ãµãŒããŒãã®ãã®ãææããããšã¯äžç°è°·åº
ãå«ããŠããããªãããšè©±ããŠãããã
URL:http://www.asahi.com/special/pcvirus/TKY200308140260.html ã ããã§ãã
> ã¯ãŒã ã®åºçŸã¯ã¢ãªã¹ã¯ãŒã 以æ¥ãããªãããšæããã§ããããã®èå³ãæºãããŠã
> ããå ±éãèŠãããŸããã
ããŠãã
W32/SQLSlammerãä»å¹Žã®ïŒæäžæ¬ã®éåœã®ã€ã³ã¿ãŒãããã
äºå®äžåæ¢ãããããšãã¯ãããããããããŸãã
--
mailto:shi...@dd.iij4u.or.jp æžè°·äŒžæµ©
In article <bhoc9q$dbi$1...@news2.wakwak.com>
"Tomoya Miyoshi" <tm...@ag.wakwak.com> writes:
> ãŠã€ã«ã¹ãšã¯ãŒã ã®åºå¥ãã€ããŠããªãã®ãæ°ã«ãªããŸãã
ãŠã£ã«ã¹ãšã¯ãŒã ã®åºå¥ã£ãŠãå°ãªããšãäžè¬äººã«ãšã£ãŠã¯ã
ãã§ã«ãããŸãæå³ããªããšæããŸããã©ã
ïŒ ãã¡ãããæè¡å±ããã«ã¯éèŠãªãã ãã©ããµã€ïœã®äººã«
ïŒ ãšã£ãŠã¯ããåæã«ã³ã³ãã¥ãŒã¿ã«å
¥ã蟌ãã§æªãããã
ïŒ ãã®ããšããæå³ã§ã¯å€§å·®ãªãã®ã§ã
ïŒ ã§ãã£ãŠãããããç·ç§°ããèšèãšããŠãããŠã£ã«ã¹ã
ïŒ ãªãããã³ã³ãã¥ãŒã¿ãŠã£ã«ã¹ããšããã®ããã§ã«å®ç
ïŒ ãã¡ãã£ãŠãããã§...
ïŒïŒ ã£ãŠãªè©±ã㯠fj.net.words ã«æ¯ãã¹ãïŒ ;-)
> ã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã®
> ã§ãã¯ãŒã ããŠã€ã«ã¹ããšãã£ãæ
å ±ã¯éèŠã ãšæãã®ã§ããã
ã»ãšãã©ã®ã¢ã³ããŠã£ã«ã¹è£œåã¯ãä»åã®ãã®ãå«ããŠã
ã¯ãŒã ã«ã察å¿ããŠããŸããã
ïŒ ããããã¹ãã€ãŠã§ã¢ (ã¡ãããšã€ã³ã¹ããŒã«æã«ç¢ºèªã
ïŒ æ±ãããããã®) ã«ã¯ã察å¿ããŠãªã (ãšããããäžæã«
ïŒ å¯Ÿå¿ãããšéã«èšŽããããããã) å Žåãããã®ã§ããã®
ïŒ åºå¥ã®æ¹ãéèŠãããªãããªã...
ïŒïŒ ãŠã£ã«ã¹ãšã¯ãŒã ãäžæã«åºå¥ãã¡ãããšãéã«ãããã
ïŒïŒ 誀解ãæããããããããã;-p
ã»ã
In article <bhoc9q$dbi$1...@news2.wakwak.com>
"Tomoya Miyoshi" <tm...@ag.wakwak.com> writes:
> å ±éã§ã¯ããã¿çã«çµæžç£æ¥çã®å ±éè³æ
...
> ãææããŠããããã ã£ãããããã¯ãŒã¯ããåãé¢ããŠãææããŠããªãå人ãã
> é§é€ããŒã«ãããããªããããšNHKãèšã£ãŠãŸãããã©ããããŠãã®äººã«ãšã£ãŠã¯ç¡
> è¶ã§ãïŒïŒŸïŒŸïŒ ãã€ã¯ããœããã®ãµã€ãã«ã¯ããå°ãçŸå®çãªå¯Ÿçæ¹æ³ãæžãããŠ
> ããŸããã©ãç°¡åãªæ¹æ³ã§ã¯ãªãã§ãããã
ãã¬ããæ°èã ãšãããããã話ããããŸãããããããäŒãããª
ãã§ãããããããšã¯ãCERT ãšã IPA ãªãããèŠãªããšãã§ãã
ãããèŠãã«ã¯ãWWW ãã©ãŠã¶ãå¿
èŠã§ãããã«ã¯ããããã¯ãŒã¯
ã«ã€ãªããªããšãããªãããã§ããããš boot strap ã¯ã©ãããã
ã§ããããã
> ãŠã€ã«ã¹ãšã¯ãŒã ã®åºå¥ãã€ããŠããªãã®ãæ°ã«ãªããŸããææ¥æ°è
> URL:http://www.asahi.com/special/pcvirus/ ã¯MSãã©ã¹ãããŸã ããŠã€ã«ã¹ããšåŒãã§ããŸããã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã®
> ã§ãã¯ãŒã ããŠã€ã«ã¹ããšãã£ãæ
å ±ã¯éèŠã ãšæãã®ã§ããã
ãŠã€ã«ã¹ã¯ãåã
ãŸã§ãããšäžè¬çšèªã§ããããããŠã€ã«ã¹(äžè¬
çšèª)ã现ããèŠããšããŠã€ã«ã¹ïŒå°éçšèªïŒãšã¯ãŒã ãšããã€ã®
æšéŠ¬ããããšã
> [snip]
> > DDoS æ»æããããšãã話ã¯ã©ããªã£ããã§ããããã
> ãã€ã¯ããœããã¯ã¯ãŒã ã«å«ãŸããŠããæ»æ察象ã®IPã¢ãã¬ã¹ãWindows Updateã®
> ãµãŒããžãªãã€ã¬ã¯ãããªããã察åŠããããã§ãã
IP ã¢ãã¬ã¹ã® redirect ã£ãŠäœã§ããããã
HTTP ã® redirect ãªããããã®ã§ããã
DNS ã® alias ãåã£ãã®ããšæã£ãŠããŸãããã¯ãŒã ãããŸããŸ
å€ãã¢ãã¬ã¹ã䜿ã£ãŠããã®ã§ã
> ã(ç·å)çåžçºæ課ã¯ããã¡ã€ã¢ãŒãŠãªãŒã«ã«ãã£ãŠãä»åã®ãŠã€ã«ã¹ãæ»æããçµ
> è·¯ã¯å
ã
éããŠããã®ã§ãäœåºãããã®ãµãŒããŒãã®ãã®ãææããããšã¯äžç°è°·åº
> ãå«ããŠããããªãããšè©±ããŠãããã
> URL:http://www.asahi.com/special/pcvirus/TKY200308140260.html ã ããã§ãã
ç§ãç¥ãããã®ã¯ãã¡ãããšããããåœã£ãŠãããã©ãããªãã§ã
ãã誰ãç¥ããŸãããïŒãä»åã®è©±ã¯ãïŒæã«åºãããããåœã£ãŠ
ãããããåœã£ãŠããªããã°ã¢ãŠãã§ããããããåœãäœå¶ã
ããŸãã§ããŠãããã©ãããšããããšãåé¡ãªãã§ãã
ç·åçã®èšã£ãŠããã®ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãéããŠããïŒã€ããïŒã
ãšããã®ãæ£ç¢ºãªæãªãã§ãããããå®æœããã®ã¯äººéã ããã
ããšãå€ã§ææãããããã¡ã€ã¢ãŠã©ãŒã«ã®å
åŽã«æã¡èŸŒããš
çµãã§ãããã¡ã€ã¢ãŠã©ãŒã«ã§ã¯ãä»åã®ãã®ã¯é²ããªããŠãåã«
æéããããã§ããã ãã§ãã
In article <HOSHI.03A...@ext54.sra.co.jp>
ho...@sra.co.jp (Hoshi Takanori) writes:
> > ã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã®
> > ã§ãã¯ãŒã ããŠã€ã«ã¹ããšãã£ãæ
å ±ã¯éèŠã ãšæãã®ã§ããã
> ã»ãšãã©ã®ã¢ã³ããŠã£ã«ã¹è£œåã¯ãä»åã®ãã®ãå«ããŠã
> ã¯ãŒã ã«ã察å¿ããŠããŸããã
å ·äœçã«ãã©ãããæè¡ã§ã察å¿ãã§ããŠããã®ã§ããããã
ç§ã®ç解ããæã§ã¯ãä»åã®æ»æã¯ããµãŒããã«ãŒãã«ã®æ·±ãæã®
話ãªã®ã§ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãåãå Žé¢ã¯ååšããªããã
ã«æããŸãã
> å ·äœçã«ãã©ãããæè¡ã§ã察å¿ãã§ããŠããã®ã§ããããã
>
> ç§ã®ç解ããæã§ã¯ãä»åã®æ»æã¯ããµãŒããã«ãŒãã«ã®æ·±ãæã®
> 話ãªã®ã§ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãåãå Žé¢ã¯ååšããªããã
> ã«æããŸãã
Antivirus Software 㯠firewall æ©èœãæã£ãŠããããšãå€ãã§ããã§ãããã
135/TCP ããããã¯ããããšã§ãMSBlaster ã®æ»æãé²ãããšãã§ããŸãã
ãŸãã仮㫠firewall æ©èœãåããªãã£ã(ååšããªãã£ã)ãšããŠãã
ãã® MSBlaster ã¯ã¬ãžã¹ããªã« Windows ãèµ·åããæã«èµ·åããããã«
ãããšãããã¿ãªã³ãŒããæžããŠããŸãããã㯠Antivirus Software ã
äžçªæåã« block ããå Žæã§ãã
Windows ãåèµ·åãããããšãªããMSBlaster ãåäœããã°è¯ãã®ã§ããã
ããã©ãWindowsXP ã® default ã§ã¯ RPC service ãäžå®å®ã«ãªã£ãå Žå
ã«ã¯åèµ·åããããšã«ãªã£ãŠããŸãã
åŸã£ãŠãæ»æã¯åããŠããã¡ã€ã«ã¯äœåŠã⊠System folder ã®äžãäœåŠã
ã«æžãããŠããŸãã§ãããããã©ãããããå
ã®ããšã¯åºæ¥ãªããšæšæž¬ã§ã
ãŸãã
--
---
Takashi SAKAMOTO (PXG0...@nifty.ne.jp)
In article <YAS.03Au...@kirk.is.tsukuba.ac.jp>
y...@is.tsukuba.ac.jp (Yasushi Shinjo) writes:
> > ã»ãšãã©ã®ã¢ã³ããŠã£ã«ã¹è£œåã¯ãä»åã®ãã®ãå«ããŠã
> > ã¯ãŒã ã«ã察å¿ããŠããŸããã
>
> å
·äœçã«ãã©ãããæè¡ã§ã察å¿ãã§ããŠããã®ã§ããããã
ãŒãã¯ãçºèŠãšé§é€ãã®æå³ã§ã察å¿ããšæžããŸããã
ä»åã®ã¯ãŒã ã«å¯Ÿãããé²åŸ¡ãã¯ç¡çããç¥ããŸãããã
倱瀌ããŸããã
ïŒ ãã ãKlez ã Hybris ãªã©ã®ã¡ãŒã«ã§ææãããã®ã
ïŒ åé¡äžã¯ãã¯ãŒã ããšãããããšãå€ããããªã®ã§ã
ïŒ ãã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã
ïŒ ãšããããšã«ã¯ãªããªããšæããŸãã
ã»ã
> > ãŠã€ã«ã¹ãšã¯ãŒã ã®åºå¥ãã€ããŠããªãã®ãæ°ã«ãªããŸãã
...
> ãŠã€ã«ã¹ã¯ãåã
ãŸã§ãããšäžè¬çšèªã§ããããããŠã€ã«ã¹(äžè¬
> çšèª)ã现ããèŠããšããŠã€ã«ã¹ïŒå°éçšèªïŒãšã¯ãŒã ãšããã€ã®
> æšéŠ¬ããããšã
埡æã
> > ã(ç·å)çåžçºæ課ã¯ããã¡ã€ã¢ãŒãŠãªãŒã«ã«ãã£ãŠãä»åã®ãŠã€ã«ã¹ãæ»æããçµ
> > è·¯ã¯å
ã
éããŠããã®ã§ãäœåºãããã®ãµãŒããŒãã®ãã®ãææããããšã¯äžç°è°·åº
> > ãå«ããŠããããªãããšè©±ããŠãããã
> > URL:http://www.asahi.com/special/pcvirus/TKY200308140260.html ã ããã§ãã
>
> ç§ãç¥ãããã®ã¯ãã¡ãããšããããåœã£ãŠãããã©ãããªãã§ã
> ãã誰ãç¥ããŸãããïŒãä»åã®è©±ã¯ãïŒæã«åºãããããåœã£ãŠ
> ãããããåœã£ãŠããªããã°ã¢ãŠãã§ããããããåœãäœå¶ã
> ããŸãã§ããŠãããã©ãããšããããšãåé¡ãªãã§ãã
äžç°è°·åºç¬èªã®ïŒäœåºãããã§ãªãã»ãã®ïŒLAN ã§ã¯ã2000 å°ããããããã·ã³
ã®ãã¡ãææãããã·ã³ãçŸå°åäœã§ååšããŠããŠãããã¶é§é€ãããšãããã®
çŸå°åäœã®äžã«ã©ãã ãåºã®ææã®ãã·ã³ããã£ãŠãã©ãã ãè·å¡å人ãæã¡èŸŒ
ãã ãã®ãããã®ããããããªãã®ã§ãããæ®å¿µãªããäœå¶ã¯äžååãšãããã
ãåŸãªãã§ããã
ç©ççã«åãé¢ããšããåæ察å¿ã¯ç©åœã ã£ããšæããŸããããåå
ãããã°ç±
ãå¿ãããã§çµãããããªèããã·ãã·ãããŸããã
ã»ãã¥ãªãã£ããããŸã§åºã段éã§ã·ã¹ãã 管çè
ã¯å
šãã·ã³ã«ããŒãã¹ãã£ã³
ããããã
> ç§ã®ç解ããæã§ã¯ãä»åã®æ»æã¯ããµãŒããã«ãŒãã«ã®æ·±ãæã®
> 話ãªã®ã§ããŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ãåãå Žé¢ã¯ååšããªããã
> ã«æããŸãã
ä»åã«é¢ããŠã¯åæèŠã§ããã¢ã³ããŠã€ã«ã¹ãœãããšããããã¯ãç©Žã«ãªããã
ãªãããŒããžã®å€éšããã®ã¢ã¯ã»ã¹ãã«ãŒã¿ãŒã§é®æããã»ããå¹æçã§ããã
ããã§ãã
> ããšãå€ã§ææãããããã¡ã€ã¢ãŠã©ãŒã«ã®å
åŽã«æã¡èŸŒããš
> çµãã§ãã
ãšãªãããã§ãã
â
ããšããã㯠Windows åºæã®è©±ã«ãªããŸããããåããªãæ¹ãããã£ããããš
æãã®ã§æžããŠãããšãWindowsUpdate ã§ã¯ãèªæ©ã®ããŒãžã§ã³ã«é¢ä¿ãªãã
Windows ã®ãã¹ãŠã®ããŒãžã§ã³ïŒãã ããµããŒãåãã«ãªã£ãŠããªããã®ã«éãïŒ
çšã®ããããããŠã³ããŒãããŠãããŒã«ã«ã«ä¿åããŠããããšãã§ããŸããããš
ãã°ãç§ã®ãã·ã³ã¯ Windows Me ã§ããããã®ãã·ã³ã§ Windows 2000 çšã®ãã
ããããŠã³ããŒãã§ããŸãããã®ãããã¯ãWindows 2000 ãã·ã³ã«æã£ãŠããã°
åœãŠãããšãã§ããŸãã
ã©ããã«ãããä¿ç®¡çšã®ãã·ã³ãçšæããŠãå®æçã«ãã¹ãŠã®ããããããŠã³
ããŒãã㊠LAN å
éšã«çœ®ããŠããããšããã®ãã²ãšã€ã®å¯Ÿçã§ããã
========================================================================
é£¯å¶ æµ©å
/ ã§ããããã»ããã㟠http://www.ht.sakura.ne.jp/~delmonta/
IIJIMA Hiromitsu, aka Delmonta mailto:delm...@ht.sakura.ne.jp
âââã宣äŒ/ADVERTISEMENTãââââââââââââââââââââââ
fj.os.ms-windows.server2003 ãŸã㯠fj.os.ms-windows.server ã®æ°èšã®å¯åŠ
ãåãæ祚ãå®æœäžã§ãã
fj.news.group.comp ããåç
§ã®ããããµãã£ãŠãæ祚ãã ããã
æ祚æé㯠8/25(æ)ã§ãã
ââââââââââââââââââââââââââââââââââââ
"Yasushi Shinjo" <y...@is.tsukuba.ac.jp> wrote in message
news:YAS.03Au...@kirk.is.tsukuba.ac.jp...
> æ°åïŒ ç波倧åŠæ
å ±ã§ããããã«ã¡ã¯ã
>
> In article <bhoc9q$dbi$1...@news2.wakwak.com>
> "Tomoya Miyoshi" <tm...@ag.wakwak.com> writes:
> > å ±éã§ã¯ããã¿çã«çµæžç£æ¥çã®å ±éè³æ
> ...
> > ãææããŠããããã ã£ãããããã¯ãŒã¯ããåãé¢ããŠãææããŠããªãå人
ãã
> > é§é€ããŒã«ãããããªããããšNHKãèšã£ãŠãŸãããã©ããããŠãã®äººã«ãšã£ãŠ
ã¯ç¡
> > è¶ã§ãïŒïŒŸïŒŸïŒ ãã€ã¯ããœããã®ãµã€ãã«ã¯ããå°ãçŸå®çãªå¯Ÿçæ¹æ³ãæžã
ããŠ
> > ããŸããã©ãç°¡åãªæ¹æ³ã§ã¯ãªãã§ãããã
>
> ãã¬ããæ°èã ãšãããããã話ããããŸãããããããäŒãããª
> ãã§ãããããããšã¯ãCERT ãšã IPA ãªãããèŠãªããšãã§ãã
> ãããèŠãã«ã¯ãWWW ãã©ãŠã¶ãå¿
èŠã§ãããã«ã¯ããããã¯ãŒã¯
> ã«ã€ãªããªããšãããªãããã§ããããš boot strap ã¯ã©ãããã
> ã§ããããã
ãã€ã¯ããœããã®ãµã€ããããããããŒã⊠(ç¡çç¡ç(^^;)
> > ãŠã€ã«ã¹ãšã¯ãŒã ã®åºå¥ãã€ããŠããªãã®ãæ°ã«ãªããŸããææ¥æ°è
> > URL:http://www.asahi.com/special/pcvirus/ ã¯MSãã©ã¹ãããŸã ããŠã€ã«ã¹ã
ãšåŒã
> >ã§ããŸããã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã®ã§ãã¯ãŒã ããŠã€
ã«ã¹
> > ããšãã£ãæ
å ±ã¯éèŠã ãšæãã®ã§ããã
>
> ãŠã€ã«ã¹ã¯ãåã
ãŸã§ãããšäžè¬çšèªã§ããããããŠã€ã«ã¹(äžè¬
> çšèª)ã现ããèŠããšããŠã€ã«ã¹ïŒå°éçšèªïŒãšã¯ãŒã ãšããã€ã®
> æšéŠ¬ããããšã
ããã¿ããã§ããã
ç§ãšããŠã¯èªåã®ç°å¢ã§ææãããããªããå€æããããã®ææã欲ããã ããªã®
ã§ãæææ¹æ³ã®è©³çŽ°ãããããã°ããŠã€ã«ã¹ããšäžå£ã«èšãããŠãå°ãã¯ããªãã
ãã
> > > DDoS æ»æããããšãã話ã¯ã©ããªã£ããã§ããããã
> > ãã€ã¯ããœããã¯ã¯ãŒã ã«å«ãŸããŠããæ»æ察象ã®IPã¢ãã¬ã¹ãWindows Update
ã®
> > ãµãŒããžãªãã€ã¬ã¯ãããªããã察åŠããããã§ãã
>
> IP ã¢ãã¬ã¹ã® redirect ã£ãŠäœã§ããããã
> HTTP ã® redirect ãªããããã®ã§ããã
>
> DNS ã® alias ãåã£ãã®ããšæã£ãŠããŸãããã¯ãŒã ãããŸããŸ
> å€ãã¢ãã¬ã¹ã䜿ã£ãŠããã®ã§ã
ããããªãããIPã¢ãã¬ã¹äºã
ã¯åéãã§ããã£ãããéãWindows Updateã瀺ãå€
ãååã§åŒããŠãæ£ãããµã€ãã®IPã¢ãã¬ã¹ãè¿ãããã«ãã€ã¯ããœãããèšå®ããŠ
ããã®ãäžæ¢ãã ãšããããšã§ãã
URL:http://www.cyberpolice.go.jp/important/20030816_020142.html
> ç§ãç¥ãããã®ã¯ãã¡ãããšããããåœã£ãŠãããã©ãããªãã§ã
> ãã誰ãç¥ããŸãããïŒãä»åã®è©±ã¯ãïŒæã«åºãããããåœã£ãŠ
> ãããããåœã£ãŠããªããã°ã¢ãŠãã§ããããããåœãäœå¶ã
> ããŸãã§ããŠãããã©ãããšããããšãåé¡ãªãã§ãã
ããããåœãŠããšãããŸã§æ£åžžã«åäœããŠããããã°ã©ã ãç°åžžãèµ·ããã±ãŒã¹ãã
ãããšãããç§ã¯å¿
ãããææ°ã®ããããåœãŠãããšãæ£è§£ãšã¯æããŸããã
ã§ããOSãã³ããŒãå
¬è¡šããŠãããããã®é©çšãã©ã®ããã«å€æããŠããã - ãšã
ãéšåã«ã¯èå³ãåŒãããŸããã
"Hoshi Takanori" <ho...@sra.co.jp> wrote in message
news:HOSHI.03A...@ext54.sra.co.jp...
[snip]
> ïŒ ãã ãKlez ã Hybris ãªã©ã®ã¡ãŒã«ã§ææãããã®ã
> ïŒ åé¡äžã¯ãã¯ãŒã ããšãããããšãå€ããããªã®ã§ã
> ïŒ ãã¯ãŒã ã§ããã°ã¢ã³ããŠã€ã«ã¹ãœãããå©ããªãã
> ïŒ ãšããããšã«ã¯ãªããªããšæããŸãã
åæããŸãã
ã¢ã³ããŠã€ã«ã¹ãœãããå©ãå Žåãšå©ããªãå Žåã£ãŠãã©ãåé¡ãããšå€ãæãã§ã
ããããŠã€ã«ã¹ãæãŸããã¿ã€ãã³ã°ãããå Žåãšç¡ãå Žåã£ãŠããšã«ãªãããšæã
ãã ãã©ã
> > ãã¬ããæ°èã ãšãããããã話ããããŸãããããããäŒãããª
> > ãã§ãããããããšã¯ãCERT ãšã IPA ãªãããèŠãªããšãã§ãã
> > ãããèŠãã«ã¯ãWWW ãã©ãŠã¶ãå¿
èŠã§ãããã«ã¯ããããã¯ãŒã¯
> > ã«ã€ãªããªããšãããªãããã§ããããš boot strap ã¯ã©ãããã
> > ã§ããããã
>
> ãã€ã¯ããœããã®ãµã€ããããããããŒã⊠(ç¡çç¡ç(^^;)
CD-ROM ãã©ã€ãã« KnoppixïŒCD é§åå¯èœãª LinuxïŒãã€ã£ããã§èµ·åããŠã
Knoppix äžã®ãã©ãŠã¶ãã該åœãããããã ããããŠã³ããŒãããããããŒã
ãã£ã¹ã¯ãªããããããŒãªãã«èœãšããŠïŒKnoppix ã£ãŠ NTFS ã«æžã蟌ãã
ããªïŒïŒãããã©ã¯ãããã¯ãŒã¯ããåãé¢ã㊠Windows ãããŒãããããã
ãåœãŠãŠãããããã¯ãŒã¯ã«ã€ãªã㧠WindowsUpdate ãäžéãã
ãããããšãã®ããã«ãCD èµ·åã§åãã¬ã¹ãã¥ãŒç°å¢ãçšæããŠããã®ã§ã :-)
ãŸãããããªããšãããªããŠããã©ããã« Windows 95/98/Me ã®åããŠãããã·
ã³ãããã°ããã¡ããã WindowsUpdate ã«ã€ãªãã§ããããèœãšããŸããã©ã
In article <bhqecd$nvo$1...@news521.nifty.com>
"Takashi SAKAMOTO" <PXG0...@nifty.ne.jp> writes:
> Antivirus Software 㯠firewall æ©èœãæã£ãŠããããšãå€ãã§ããã§ãããã
> 135/TCP ããããã¯ããããšã§ãMSBlaster ã®æ»æãé²ãããšãã§ããŸãã
æåãã 135 çªãéããšããªãšããããšãªãã ãã©ãããããæ¢
ããŠãå¹³æ°ãªã³ã³ãã¥ãŒã¿ãå€ããšããããšã¯ã䜿ã£ãŠããæã«ã¯ã
éããªããšãããªããããããã§ã¯é²ããŸããã
> ãŸãã仮㫠firewall æ©èœãåããªãã£ã(ååšããªãã£ã)ãšããŠãã
> ãã® MSBlaster ã¯ã¬ãžã¹ããªã« Windows ãèµ·åããæã«èµ·åããããã«
> ãããšãããã¿ãªã³ãŒããæžããŠããŸãããã㯠Antivirus Software ã
> äžçªæåã« block ããå Žæã§ãã
çµå±ãä»åã¯ããŸã㟠MSBlaster ã®ã³ãŒããçãã£ããã察å¿ã§
ãããšããããšã§ããããã®éã® Slammer ã§ããã£ããã¬ãžã¹ã
ãªãäœãããããªããããªããã°ã©ã ã ã£ãããé²ããªãã£ããšã
ãããšã§ããã
> Windows ãåèµ·åãããããšãªããMSBlaster ãåäœããã°è¯ãã®ã§ããã
> ããã©ãWindowsXP ã® default ã§ã¯ RPC service ãäžå®å®ã«ãªã£ãå Žå
> ã«ã¯åèµ·åããããšã«ãªã£ãŠããŸãã
ãäžå®å®ãã£ãŠãæè¡çã«ã©ãããããšã§ããïŒ
èªåãå®å®ãäžå®å®ãå€æããã£ãŠããããªãã®ãååšãããã§ããïŒ
> åŸã£ãŠãæ»æã¯åããŠããã¡ã€ã«ã¯äœåŠã⊠System folder ã®äžãäœåŠã
> ã«æžãããŠããŸãã§ãããããã©ãããããå
ã®ããšã¯åºæ¥ãªããšæšæž¬ã§ã
> ãŸãã
ããŸããŸæ»æããã°ã©ã ããããŒãã£ããšããããšã§ããã
ãŸããæ»æããã°ã©ã ã£ãŠããããŒãããã°ã©ã ãå€ããšããã®ã¯
äºå®ãªãã ãã©ã
> ã¢ã³ããŠã€ã«ã¹ãœãããå©ãå Žåãšå©ããªãå Žåã£ãŠãã©ãåé¡ãããšå€ãæãã§ã
> ããããŠã€ã«ã¹ãæãŸããã¿ã€ãã³ã°ãããå Žåãšç¡ãå Žåã£ãŠããšã«ãªãããšæã
> ãã ãã©ã
ã€ãŸããšããããOS ã®éå±€æ§é ã®ã©ãã«ç©Žãããããã§ãããã
ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ïŒUNIX ç³» OS ã§ãããšããã®ãŠãŒã¶ãŒã©ã³ãïŒã®ç©Žã§
ããã°ãã¢ã³ããŠã£ã«ã¹ãœããããã®ã¢ããªã®æåãã»ãŒå®å
šã«ç£èŠããŠããŠã€
ã«ã¹ã»ã¯ãŒã ããã©ããã§ããŸãã
人éå¿çã®ç©Žãã€ãããã®ïŒãLove letter for youãã®é¡ãäºéæ¡åŒµåã§æ·»ä»
ãã¡ã€ã«ãéããããã®ïŒã§ããã°ãããããã©ããã§ããŸãã
IIS ãªã©ã®ãµãŒããŒã¢ããªã®ç©Žãã€ããããªãã®ã¯ãéåžžã¯ã¢ã³ããŠã€ã«ã¹ãœã
ãã®ç£èŠå¯Ÿè±¡ã«ã¯ãªã£ãŠããŸãããããããåççã«ã¯ãã©ããå¯èœã
ãã ä»åã®ããã«ãã«ãŒãã«ã¬ãã«ã®ç©Žã®å Žåã¯ãã¢ã³ããŠã€ã«ã¹ãœããã¯ç¡å¹
ã§ããç©Žãã¢ã³ããŠã€ã«ã¹ãœãããããäžã®éå±€ã«äœçœ®ãããããããã¯åéå±€
ã§ãã«ãŒãã«ãåé¡ã® TCP ããŒããå
ã«å æ ããŠããŸãããã§ãã
>ãã ä»åã®ããã«ãã«ãŒãã«ã¬ãã«ã®ç©Žã®å Žåã¯ãã¢ã³ããŠã€ã«ã¹ãœããã¯ç¡å¹
>ã§ããç©Žãã¢ã³ããŠã€ã«ã¹ãœãããããäžã®éå±€ã«äœçœ®ãããããããã¯åéå±€
>ã§ãã«ãŒãã«ãåé¡ã® TCP ããŒããå
ã«å æ ããŠããŸãããã§ãã
portã®å æ ã«ãšã©ãŸããããã¢ã³ããŠã£ã«ã¹ãœããèªèº«ãã©ãåããŠããã®ã
ïŒåããŠããªãã®ãïŒãããã¢ã³ããŠã£ã«ã¹ãœããèªèº«ã§ãã§ãã¯åºæ¥ãªããªã
ãããã§ã¯ãªãã§ããããã
åéå±€ã©ããããã¢ã³ããŠã£ã«ã¹ãœããèªèº«ã«ææãšèšãããå¯çãããã€
ãæããŸããããããŸã§è¡ããªããŠãããã°ã¯ãªãŒããããŒãã©ãããŒçã§
ã¢ã³ããŠã£ã«ã¹ãœããç¡å¹åããŠãã䟵å
¥ããããšããã®ãé«åºŠãªïŒåºçŸ©ã®ïŒ
ãŠã£ã«ã¹ã®äžè¬ç圢æ
ã§ãããããããã¢ã³ããŠã£ã«ã¹ãœããèªèº«ãææããŠ
ããªããã©ãããã©ããã£ãŠãã§ãã¯ããã®ïŒããšããããšã§ãUNIX
çšã®chkrootkitãªããã§ã¯ããã€ããªã§ã¯ãªãã·ã§ã«ã¹ã¯ãªãã(DOSã§èšã
ãšããã®ããããã¡ã€ã«ïŒã§æžãããŠããŸãããããªãããã°ã©ã ãæžããªã
ãŠããèªããçšåºŠã®äººã§ããã§ãã¯åºæ¥ãŸãã
--
äžæåå¿ïŒ ç¥æž <mailto:k...@kobe1995.net>
NAKAMURA Kazushi@KOBE <http://kobe1995.jp/>
- Be Free(BSD), or Die...
In article <YAS.03Au...@kirk.is.tsukuba.ac.jp>
y...@is.tsukuba.ac.jp (Yasushi Shinjo) writes:
> ç§ãç¥ãããã®ã¯ãã¡ãããšããããåœã£ãŠãããã©ãããªãã§ã
> ãã誰ãç¥ããŸãããïŒãä»åã®è©±ã¯ãïŒæã«åºãããããåœã£ãŠ
> ãããããåœã£ãŠããªããã°ã¢ãŠãã§ããããããåœãäœå¶ã
> ããŸãã§ããŠãããã©ãããšããããšãåé¡ãªãã§ãã
ãšæžããŸããããããããåœãŠãå±ãªããšããäŸããããšãã話ã
ãããŸããã
http://www.japan.cnet.com/news/ent/story/0,2000047623,20060440,00.htm
Windows Updateã ãã§ã¯ãMSBlast察çã«ã¯äžåå?
Windows Update ã¯ãããããåœããã©ããã¯ãã¬ãžã¹ããªãèŠãŠ
調ã¹ãŠããŸããã¬ãžã¹ããªã«ã¯ããããåœãããšã«ã¯ãªã£ãŠããã
ãã©ãå®éã«ã¯ããããåœã£ãŠããªãã£ããšããäŸãèŠã€ãã£ããš
ããããšã§ãã
ã§ãã©ãããã°ããããšãããšãMicrosoft Baseline Security
AnalyzerïŒMBSAïŒãå®è¡ãããšããããšã®ããã§ãã
ãšããããã§ãããããåœãããšããã®ã¯ééãã§ãããèšæ£
ããŸãã
In article <3F40FE4D...@ht.sakura.ne.jp>
IIJIMA Hiromitsu <delm...@ht.sakura.ne.jp> writes:
> ããããŸã§ãã
> ã€ãŸããšããããOS ã®éå±€æ§é ã®ã©ãã«ç©Žãããããã§ãããã
> ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ïŒUNIX ç³» OS ã§ãããšããã®ãŠãŒã¶ãŒã©ã³ãïŒã®ç©Žã§
> ããã°ãã¢ã³ããŠã£ã«ã¹ãœããããã®ã¢ããªã®æåãã»ãŒå®å
šã«ç£èŠããŠããŠã€
> ã«ã¹ã»ã¯ãŒã ããã©ããã§ããŸãã
å®éã«ã¯ãã®å±€ã§é²ãã®ã¯é£ããåé¡ããããããããŸãã
ããã°ã©ã æªããåãããã©ããã§ãããšããŠããããæ¬åœã«æªã
ããã®ãªã®ããæ£ãããã®ãªã®ããå€å®ããã®ã¯å€§å€ã§ããã€ãŸãã
ç¡å®ã®ããã°ã©ã ãæªãããšå€å®ããŠããŸããããããªãããã§ãã
ç¡å®ã®ããã°ã©ã ãåãããã³ã«ãããããèšãããã®ã§ã¯ä»äºã«
ãªããŸããã
æªããããã°ã©ã ãªãæªãããšå®çŸ©ããŠããã€ã³ã¿ããªã¿ç³»ãªãçµ
ãã ãããããã¡ã»ãªãŒããŒãããŒïŒæªãããªããšããããã°ã©ã
ãä¹ã£åãããŠããïŒã§ãçµãã§ãã
"Yasushi Shinjo" <y...@is.tsukuba.ac.jp> wrote in message
news:YAS.03Au...@kirk.is.tsukuba.ac.jp...
> çµå±ãä»åã¯ããŸã㟠MSBlaster ã®ã³ãŒããçãã£ããã察å¿ã§
> ãããšããããšã§ããããã®éã® Slammer ã§ããã£ããã¬ãžã¹ã
> ãªãäœãããããªããããªããã°ã©ã ã ã£ãããé²ããªãã£ããšã
> ãããšã§ããã
WindowsXP ãæ»æãããšãã·ã¹ãã ã reboot ãããŠããŸããšããã®ã
æ倧ã®åŒ±ç¹ã§ããããâŠãWindows2000 ã ãš reboot ããªãã®ã§ããã®
ãŸãŸ Worm ã掻åãã(ã§ããïŒ)ã§ãããããã©ã
# WindowsXP åŽã ãšããããããã¡ããš Worm ãã·ã¹ãã ãã®ã£ãšãåã«
# åèµ·åããŠããŸãå¯èœæ§ããããŸãã
# ãã® Worm ã®ã¿ã³ãªç¹ã®1ã€ã§ããããŸããã
# ãŸããèªå㧠WindowsXP ã« patch ãåœãŠãªãããã«ãå床èªåã®æ»æã§
# WindowsXP ã reboot ãããŠããŸããšããããšãããŠããŸãâŠã
# ã¬ãžã¹ããªã® Run ãããã£ãŠãâŠèªåã®æ»æã§çŽã« reboot âŠã
> ãäžå®å®ãã£ãŠãæè¡çã«ã©ãããããšã§ããïŒ
> èªåãå®å®ãäžå®å®ãå€æããã£ãŠããããªãã®ãååšãããã§ããïŒ
http://itpro.nikkeibp.co.jp/free/ITPro/NEWS/20030813/2/
æ柀æ°ã«ãããšïŒã»ãã¥ãªãã£ã»ããŒã«ãããRPCãµãŒãã¹ãïŒæ»æã¡ãã»ãŒ
ãžãåä¿¡ããŠãããã¡ã»ãªãŒããŒãããŒãçºçãã段éã§ïŒRPCãµãŒãã¹ã
äžå®å®ã«ãªããšãããã€ãŸãïŒäžèšã® 3 ã®æç¹ã§äžå®å®ã«ãªãããã®æç¹
ã§ïŒRPCãµãŒãã¹èªèº«ãRPCã«é¢ãããšã©ãŒã»ã¡ãã»ãŒãžã衚瀺ããŠïŒ
Windowsãåèµ·åãããå¯èœæ§ããããBlasterãWindowsãåèµ·åããã
ã®ã§ã¯ãªãïŒæ»æãåããRPCãµãŒãã¹ãåèµ·åãããã®ã§ããã
ã ããã§ãã
# æ»æ察象ãšãªãã®ã¯ svchost.exe ãšãã process ã§ãâŠã
> ãŸããæ»æããã°ã©ã ã£ãŠããããŒãããã°ã©ã ãå€ããšããã®ã¯
> äºå®ãªãã ãã©ã
äœãšããããInternet ã«å
¬éãããŠããæ»ææ¹æ³ããã®ãŸãŸäœ¿ã£ãŠã
ã·ã¹ãã ãã®ã£ãšãã ãâŠããã®åŸã®è¡åã«ã¯å
šãç¬åµæ§ãæããã
ãŸããâŠãæ㯠Worm ãVirus ãäœãã人ã¯åªç§ã ãšæã£ããã§ããã©âŠ
In article <bht7rr$a6j$1...@news521.nifty.com>
"Takashi SAKAMOTO" <PXG0...@nifty.ne.jp> writes:
> éªæ¬@nifty ã§ãã
> WindowsXP ãæ»æãããšãã·ã¹ãã ã reboot ãããŠããŸããšããã®ã
> æ倧ã®åŒ±ç¹ã§ããããâŠãWindows2000 ã ãš reboot ããªãã®ã§ããã®
> ãŸãŸ Worm ã掻åãã(ã§ããïŒ)ã§ãããããã©ã
匱ç¹ãšãããšãWorm ã®åŒ±ç¹ïŒ
äºæãããªããŒãããããšãå°ãå Žåãå€ãã®ã§ãæ»æãšããŠã¯æ
åããŠãããšãèšããŸããã¯ãŒã ã®ãåºãããšããç®çã«ã¯åããŠ
ããã®ã§ãããããã©ãç®çããµãŒãã¹éçšåŠšå®³ãªããããã§åå
ã§ãã
ããšã察çãšããŠãå±ãªããªã£ããã»ãæå³çã«ãæ©ãã«ã¯ã©ãã·ã¥
ãã(Unix çšèªã ãš panic()) ãšããã®ã¯ãäžæã«é 匵ãããã¯ã
ãå ŽåããããŸãããšããã®ããäžæã«é 匵ããšããã£ãŠè¢«å®³ãæ¡
倧ãããããšãããããã§ãã
> > ãäžå®å®ãã£ãŠãæè¡çã«ã©ãããããšã§ããïŒ
> > èªåãå®å®ãäžå®å®ãå€æããã£ãŠããããªãã®ãååšãããã§ããïŒ
>
> http://itpro.nikkeibp.co.jp/free/ITPro/NEWS/20030813/2/
>
> æ柀æ°ã«ãããšïŒã»ãã¥ãªãã£ã»ããŒã«ãããRPCãµãŒãã¹ãïŒæ»æã¡ãã»ãŒ
> ãžãåä¿¡ããŠãããã¡ã»ãªãŒããŒãããŒãçºçãã段éã§ïŒRPCãµãŒãã¹ã
> äžå®å®ã«ãªããšãããã€ãŸãïŒäžèšã® 3 ã®æç¹ã§äžå®å®ã«ãªãã
ããããæ柀æ°ã®èšäºã§ãããäžå®å®ãã¯ããã¯ãæªå®çŸ©ã§ãã
ãäžå®å®ãã¯ããã€ã¯ããœããçšèªãªãã§ããïŒ
ãäžå®å®ãã¯ãæè¡çã«ã©ãããæå³ãªãã§ããïŒ
èªåãå®å®ãäžå®å®ãå€æããã£ãŠããããªãã®ãååšãããã§ããïŒ
ãªããšãªãããäžå®å®ãã§æèãæ¢ããŠãã人ããããããããªã
ããã©ãç§ã¯ã¡ãã£ãšçŽåŸã§ããŸããã
> > ãŸããæ»æããã°ã©ã ã£ãŠããããŒãããã°ã©ã ãå€ããšããã®ã¯
> > äºå®ãªãã ãã©ã
>
> äœãšããããInternet ã«å
¬éãããŠããæ»ææ¹æ³ããã®ãŸãŸäœ¿ã£ãŠã
> ã·ã¹ãã ãã®ã£ãšãã ãâŠããã®åŸã®è¡åã«ã¯å
šãç¬åµæ§ãæããã
> ãŸããâŠãæ㯠Worm ãVirus ãäœãã人ã¯åªç§ã ãšæã£ããã§ããã©âŠ
ç¬åµæ§ãšãããŒãã¯ããããŸãé¢ä¿ãããŸãããç¬åµçãªãã ãã©ã
éåžžã«ãããŒãããã°ã©ã ãšããã®ã¯ãæè¿èŠãŸãããç¬åµçã§ã¯
ãªããŠãããããŒããªãããã°ã©ã ããããŸãã
"Yasushi Shinjo" <y...@is.tsukuba.ac.jp> wrote in message
news:YAS.03Au...@kirk.is.tsukuba.ac.jp...
> 匱ç¹ãšãããšãWorm ã®åŒ±ç¹ïŒ
Worm ã®ç®çã WindowsUpdate ãžã® DoS ãšå€éšããã® 4444/TCP
ã«ãã tftp service ã®èµ·åã ãšãããšãèªåæ¬æ¥ã®ç®çãæãããŠãª
ããšããæå³ã§ã匱ç¹ããªã®ã§ã¯ãªãããšæããŸããã
ãŸããèªå㧠Windows ã« patch ãåœãŠãªãããã« MSBlaster.D ãªã
ãã« MSBlast.exe ã kill process ã㊠hotfix ãåœãŠããããšããæ»æã
åããŠããŸãâŠã
# ãã£ãšãããã§ã¯ MSBlaster.D ã®æ¹ãããŸããªãã§ããã
# ããšãåå¿è
ãŠãŒã¶ã reboot ããŸããããšã§ãWorm ã«ããããŠãã
# ããšã«æ°ä»ããããã(åå¿è
ã«å¯Ÿãã)ã¹ãã«ã¹æ§èœãäœãã§ãã
# âŠå°éå¯èœãªä»ã® Windows PC å
šãŠãpatch ãåœãã£ãŠããŠãèª
# åã® PC ã§ã ã Worm ã掻åããŠãããšããããšã«ãªããšâŠæ°ä»ã
# ãªãã§ãããããã©ã
> äºæãããªããŒãããããšãå°ãå Žåãå€ãã®ã§ãæ»æãšããŠã¯æ
> åããŠãããšãèšããŸããã¯ãŒã ã®ãåºãããšããç®çã«ã¯åããŠ
> ããã®ã§ãããããã©ãç®çããµãŒãã¹éçšåŠšå®³ãªããããã§åå
> ã§ãã
ããã§ãããäœæè ã®æå³âŠãšã¯ç°ãªããŸããã
> ããšã察çãšããŠãå±ãªããªã£ããã»ãæå³çã«ãæ©ãã«ã¯ã©ãã·ã¥
> ãã(Unix çšèªã ãš panic()) ãšããã®ã¯ãäžæã«é 匵ãããã¯ã
> ãå ŽåããããŸãããšããã®ããäžæã«é 匵ããšããã£ãŠè¢«å®³ãæ¡
> 倧ãããããšãããããã§ãã
ã¯ãã
> ããããæ柀æ°ã®èšäºã§ãããäžå®å®ãã¯ããã¯ãæªå®çŸ©ã§ãã
>
> ãäžå®å®ãã¯ããã€ã¯ããœããçšèªãªãã§ããïŒ
> ãäžå®å®ãã¯ãæè¡çã«ã©ãããæå³ãªãã§ããïŒ
> èªåãå®å®ãäžå®å®ãå€æããã£ãŠããããªãã®ãååšãããã§ããïŒ
>
> ãªããšãªãããäžå®å®ãã§æèãæ¢ããŠãã人ããããããããªã
> ããã©ãç§ã¯ã¡ãã£ãšçŽåŸã§ããŸããã
æãã㯠buffer overrun æ»æãªã®ã§ããäžæ£ãªã¡ã¢ãªãã¢ã¯ã»ã¹ããŸããã
ãªã©ã®äŸå€ãçºçããã®ã ãšæããŸãããã®äŸå€ã trap ããŠãsvchost.exe
ã WindowsXP ã® restart ãèŠæ±ããã®ã§ãããã
# ãã¡ããšæ»æã³ãŒããæžãã°ããã®äŸå€ãåºããªãã§æžãã ãããªæ°ãããª
# ãããªãã§ãâŠã
> ç¬åµæ§ãšãããŒãã¯ããããŸãé¢ä¿ãããŸãããç¬åµçãªãã ãã©ã
> éåžžã«ãããŒãããã°ã©ã ãšããã®ã¯ãæè¿èŠãŸãããç¬åµçã§ã¯
> ãªããŠãããããŒããªãããã°ã©ã ããããŸãã
ããã§ãããç§ã®çºèšã¯ããããŒãããã°ã©ã ã°ãããã«ä¿®æ£ããŸãã
# ãã¡ããšæžãããããããŒããªããããã°ã©ã ã ãšè¢«å®³ã¯æ¡å€§ããŠããã§ããã
# ãâŠã
<3F40D489...@ht.sakura.ne.jp>ã®èšäºã«ãããŠ
delm...@ht.sakura.ne.jpããã¯æžããŸããã
>> ããšããã㯠Windows åºæã®è©±ã«ãªããŸããããåããªãæ¹ãããã£ããããš
>> æãã®ã§æžããŠãããšãWindowsUpdate ã§ã¯ãèªæ©ã®ããŒãžã§ã³ã«é¢ä¿ãªãã
>> Windows ã®ãã¹ãŠã®ããŒãžã§ã³ïŒãã ããµããŒãåãã«ãªã£ãŠããªããã®ã«éãïŒ
>> çšã®ããããããŠã³ããŒãããŠãããŒã«ã«ã«ä¿åããŠããããšãã§ããŸããããš
>> ãã°ãç§ã®ãã·ã³ã¯ Windows Me ã§ããããã®ãã·ã³ã§ Windows 2000 çšã®ãã
>> ããããŠã³ããŒãã§ããŸãããã®ãããã¯ãWindows 2000 ãã·ã³ã«æã£ãŠããã°
>> åœãŠãããšãã§ããŸãã
å
·äœçã«ã¯ã©ã®ããã«ãããå®çŸã§ããã®ã§ãããã?
WindowsUpdate ã§ãããã®ååšã確èªã§ããŠãWindowsUpdate ããã€ã³ã¹ããŒã«ã§
ããã®ã§ããããã¡ã€ã«ãããŒã«ã«ã«ä¿åããŠããå®è¡ãããããšæã£ãŠããŸãã
WindowsUpdate ã§è©³çŽ°ãèŠãŠãã£ãŠãå
ã®ããŒãžã«æ»ã£ãŠããŸã£ããã§ããã©ãç
ããŸããã
--
å·ç«¯äžä¹
E-mail:k-k...@tdc.minolta.co.jp
In article <bhufof$pth$1...@news521.nifty.com>
"Takashi SAKAMOTO" <PXG0...@nifty.ne.jp> writes:
> ããã§ãããäœæè
ã®æå³âŠãšã¯ç°ãªããŸããã
ããã¯ãæ¬æ
ãããããŸããããWorm ã®ãµãããŠãå®ã¯ãDoS æ»
æããã°ã©ã ã ã£ããããŠã
> > ãäžå®å®ãã¯ãæè¡çã«ã©ãããæå³ãªãã§ããïŒ
> æãã㯠buffer overrun æ»æãªã®ã§ããäžæ£ãªã¡ã¢ãªãã¢ã¯ã»ã¹ããŸããã
> ãªã©ã®äŸå€ãçºçããã®ã ãšæããŸãã
buffer overrun æ»æã¯ãæ»æãæåããæã«ã¯ãã¡ã¢ãªã¢ã¯ã»ã¹
ã®äŸå€ã¯ãçºçããŸããããæ»æã«ã¯ã絶察çªå°ãå¿
èŠã«ãªãã®ã§
ããããããã ãããã§ãããŠãnop åœä»€ãåããŠããã°ãããçš
床ã®ç¯å²å
ãªãïŒçºã§æåããŸãã
ïŒçºã§æåããªãå Žåã¯ãçªå°ãå€ããªããäœåãã«ãŒãããå¿
èŠ
ãããå ŽåããããŸãããã®å Žåã¯ãã¡ã¢ãªã¢ã¯ã»ã¹ã®äŸå€ãçºç
ããã®ã§ã
> ãã®äŸå€ã trap ããŠãsvchost.exe
> ã WindowsXP ã® restart ãèŠæ±ããã®ã§ãããã
ãšããããšã«ãªãã®ã§ãããã
svchost.exe ã¯ãWindows XP ã®æšæºã®ããã°ã©ã ã§ããã
äœããããã°ã©ã ãªãã§ããããã
ã§ããã¡ã¢ãªã¢ã¯ã»ã¹äŸå€ãçºçããŸãã£ãŠããµãŒãã»ããã»ã¹ã
åèµ·åããããšããäžå®å®ããšã¯æ®éèšããªããã ãã©ãªãããŸãã
æ®éãšãã€ã¯ããœããçšèªã®åºå¥ãã€ããªããšããããšã¯ãç¹ã«ã
ã€ã¯ããœããã«ã©ã£ã·ã挬ãã£ãŠãã人ã«ã¯æ®éã ãããªãã
次ã®å Žæã«ããªã«ããªã®æ¹æ³ãåºãŠããŸããã
W32/Blaster Recovery Tips
http://www.cert.org/tech_tips/w32_blaster.html
åºæ¬çã«ã¯ãããã»ã¹ã kill ããŠããã¡ã€ã«ãæ¶ããŠãInternet
Connection Firewall (ICF) ã§ãæ»æ察象ã®ããŒããå¡ãã(DCOM
ãèœãšããŠ)ãåèµ·åããŠãWindows Update ãããããšããããšã®
ããã§ãã
"Yasushi Shinjo" <y...@is.tsukuba.ac.jp> wrote in message
news:YAS.03Au...@kirk.is.tsukuba.ac.jp...
> ããã¯ãæ¬æ
ãããããŸããããWorm ã®ãµãããŠãå®ã¯ãDoS æ»
> æããã°ã©ã ã ã£ããããŠã
ãããããããŸããããåãæ¢ãããçŽ ã® MSBlast ããã¯ãBlast.D ã®
æ¹ã icmp ãæããŸããã®ã§è¿·æã ã£ããããŸãâŠã
> buffer overrun æ»æã¯ãæ»æãæåããæã«ã¯ãã¡ã¢ãªã¢ã¯ã»ã¹
> ã®äŸå€ã¯ãçºçããŸããããæ»æã«ã¯ã絶察çªå°ãå¿
èŠã«ãªãã®ã§
> ããããããã ãããã§ãããŠãnop åœä»€ãåããŠããã°ãããçš
> 床ã®ç¯å²å
ãªãïŒçºã§æåããŸãã
>
> ïŒçºã§æåããªãå Žåã¯ãçªå°ãå€ããªããäœåãã«ãŒãããå¿
èŠ
> ãããå ŽåããããŸãããã®å Žåã¯ãã¡ã¢ãªã¢ã¯ã»ã¹ã®äŸå€ãçºç
> ããã®ã§ã
>
> > ãã®äŸå€ã trap ããŠãsvchost.exe
> > ã WindowsXP ã® restart ãèŠæ±ããã®ã§ãããã
>
> ãšããããšã«ãªãã®ã§ãããã
ããã§ããâŠãç§ã¯åçŽã« svchost.exe ãä¹ã£åã£ãŠãmsblast.exe ã
èµ°ãããåŸãexit ãããããã®ãŸãŸé©åœã« return ãããããŠãç¶ç¶ã
㊠svchost.exe ãèµ°ããªãç¶æ
ã«ãªã£ãŠããŸã£ãã®ã ãšæ³åããŸããã
# return ããã stack ã¯ã§ããããªå ŽææããŠããã§ãããããã
# memory access äŸå€ãåºãã§ããããã
ããšã¯âŠããã¯ãã£ããå¿ããŠããã®ã§ãããWindows ã® Service ã¯
åäœäžã«ãå®æçã«ã¹ããŒã¿ã¹ãèŠæ±ãããã®ã§ãããã«å
šãå¿çã§ã
ãªããã°ãService Control Manager ã«ãšã©ãŒãçºçããŠãããšçãã
ãŠããŸããŸãã
# svchost.exe ãä¹ã£åã£ãåŸãstatus ããã¡ããšåºãç¶ãã code ã§ã¯
# ãªãã£ãâŠãšãã
> svchost.exe ã¯ãWindows XP ã®æšæºã®ããã°ã©ã ã§ããã
> äœããããã°ã©ã ãªãã§ããããã
WindowsXP ã®ç®¡çããŒã«ãããµãŒãã¹ãéããŠãRemote Procedure
Call (RPC) ãµãŒãã¹ã® property ãéããšã
C:\WINDOWS\system32\svchost -k rpcss
ãšãªã£ãŠããã®ãåãããšæããŸãã
> ã§ããã¡ã¢ãªã¢ã¯ã»ã¹äŸå€ãçºçããŸãã£ãŠããµãŒãã»ããã»ã¹ã
> åèµ·åããããšããäžå®å®ããšã¯æ®éèšããªããã ãã©ãªãããŸãã
> æ®éãšãã€ã¯ããœããçšèªã®åºå¥ãã€ããªããšããããšã¯ãç¹ã«ã
> ã€ã¯ããœããã«ã©ã£ã·ã挬ãã£ãŠãã人ã«ã¯æ®éã ãããªãã
ãã¿ãŸããâŠãOS ãäžå®å®ã«ãªãããšæžããèšæ¶ã¯ãªãã®ã§ããã
æžããŸããã§ããããïŒ åèµ·åããçç±ã«ã€ããŠã¯ãITPro ã® URL ã
æ瀺ãããšèšæ¶ããŠããã®ã§ããã
äžã®ããããã£ã®å埩ã®æ段ã®ãšãããåºãã°åããéãã«ã
---
ãã®ãµãŒãã¹ããšã©ãŒã«ãªã£ãå Žåã®ã³ã³ãã¥ãŒã¿ã®å¿çãæå®ããŠ
ãã ããã
æåã®ãšã©ãŒïŒ ã³ã³ãã¥ãŒã¿ãåèµ·åãã
次ã®ãšã©ãŒïŒ ã³ã³ãã¥ãŒã¿ãåèµ·åãã
ãã®åŸã®ãšã©ãŒïŒ ã³ã³ãã¥ãŒã¿ãåèµ·åãã
---
ã«ãªã£ãŠããã®ã§ãåèµ·åããŠããŸãã®ã âŠãšã
svchost.exe ããšã©ãŒãåºããŠããç¶æ³ããå®å®ãããŠããã®ããäžå®
å®ãã«ãªã£ãŠããã®ãã¯âŠã©ã¡ãããšèšããšãäžå®å®ããªããããªãããš
æãã®ã§ããã©âŠã
> W32/Blaster Recovery Tips
> http://www.cert.org/tech_tips/w32_blaster.html
>
> åºæ¬çã«ã¯ãããã»ã¹ã kill ããŠããã¡ã€ã«ãæ¶ããŠãInternet
> Connection Firewall (ICF) ã§ãæ»æ察象ã®ããŒããå¡ãã(DCOM
> ãèœãšããŠ)ãåèµ·åããŠãWindows Update ãããããšããããšã®
> ããã§ãã
ã¯ããâŠããã»ã¹ã kill ããåã«ãããã¯ãŒã¯ã±ãŒãã«ãã²ã£ãæãæ¹
ãå
ã ãšæããŸããã
MSBlast.D ã«ã€ããŠã¯ 2004 幎ã«ã¯èªåæ¶æ»
ãããããã®ã§ã
æèšã 2004 幎以éã«èšå®ããã°é§é€ã§ããããã§ãã
# ããããã£ãŠããŸããšãWindowsXP ã ãšãActivation ãèŠæ±ããã
# ã§ããããâŠã
In article <YAS.03Au...@kirk.is.tsukuba.ac.jp>
>> ããã§ãããäœæè
ã®æå³âŠãšã¯ç°ãªããŸããã
ããã§ããååæå³ãšèšãããäºæž¬ã®ç¯å²å
ã§ãã
>ããã¯ãæ¬æ
ãããããŸããããWorm ã®ãµãããŠãå®ã¯ãDoS æ»
>æããã°ã©ã ã ã£ããããŠã
Worm, Troyan, (ç矩ã®)virusãšããã®ã¯ææ圢æ
ã
DoS,DDoS,sniffer,spyware,æ¹ç«,LogCleaner,etc.ãšããã®ã¯ææã«æåãã
åŸã®actionã«äŸãåé¡ã
ãªã®ã§ãDosæ»æãä»æããwormãšããã®ãæãåŸãããšã
>buffer overrun æ»æã¯ãæ»æãæåããæã«ã¯ãã¡ã¢ãªã¢ã¯ã»ã¹
>ã®äŸå€ã¯ãçºçããŸããããæ»æã«ã¯ã絶察çªå°ãå¿
èŠã«ãªãã®ã§
>ããããããã ãããã§ãããŠãnop åœä»€ãåããŠããã°ãããçš
>床ã®ç¯å²å
ãªãïŒçºã§æåããŸãã
>
>ïŒçºã§æåããªãå Žåã¯ãçªå°ãå€ããªããäœåãã«ãŒãããå¿
èŠ
>ãããå ŽåããããŸãããã®å Žåã¯ãã¡ã¢ãªã¢ã¯ã»ã¹ã®äŸå€ãçºç
>ããã®ã§ã
ãã€ãŠRedHat Linuxã®ãšããããŒãžã§ã³ã§ãåæå€ã®ãŸãŸEnterãå©ã
ç¶ããŠã€ã³ã¹ããŒã«ãããšãWWWãµãŒããã€ã³ã¹ããŒã«ãããŠããã®
WWWãµãŒãã«ãšãããªã¯ãšã¹ããéããšbuffer overrunããŠãããã
ãããOSèµ·ååŸã®æåã®ãªã¯ãšã¹ãã ãšå¿
ãåãçªå°ã«é£ã¹ãããšãã
ç©Žãæã£ãŠããããæªçšããwormãæµè¡ã£ãæãæããŸããåæå€ã®
ãŸãŸEnteræŒãã£ã±ãªãã§ã€ã³ã¹ããŒã«ãã人ãå®ã¯å°ãªããªãæš¡æ§ã
ãªã®ã§æ»æè
ã«ãšã£ãŠã¯ãçã£ãç°å¢(OS,server,mailer,etc.)
ã§çã£ãäºæž¬ã¢ãã¬ã¹ïŒç¯å²ïŒã«é£ã¹ãã°ä¹ã£åãããïŒæå解ïŒã
ãããŸã§è¡ããªããŠãäŸå€çºçã§ãã®ãµãŒãã¹ãåæ¢ããããã
ïŒæ¬¡å解ïŒãšãããããã®æå³ã§ãããã
OpenBSDã§ã¯æ©ãææãã/dev/randomãªããŠãã©ã€ããŸã§çšæããŠã
ãããããã§ä¹±æ°ã䜿ã£ãŠãæ»æè
ããoverrunåŸã«é£ã¶ãšäžæã
ããã¢ãã¬ã¹ãäºæž¬ããé£ãããŠããŸãããFreeBSD 5-current
ã§ããæ§ã
ãªEntropy harvestingãå©çšããŠäºæž¬å°é£æ§ãäžããããš
åªåããŠããŸããWindowsãèŠããšããããã£ã泚æãæãããŠããªã
ãšèšããããdebugã®çºãåçŸæ§ã確ä¿ããããšããããŠããã®ã§ã¯ïŒ
ãªããŠéªæšãããããŸãããäžè¬ä¿è·äŸå€ 0E...ããªããŠæããŠãã
ã¡ãã£ãŠã©ãããã®ïŒ
>> ãã® MSBlaster ã¯ã¬ãžã¹ããªã« Windows ãèµ·åããæã«èµ·åããããã«
>> ãããšãããã¿ãªã³ãŒããæžããŠããŸãããã㯠Antivirus Software ã
>> äžçªæåã« block ããå Žæã§ãã
>
> çµå±ãä»åã¯ããŸã㟠MSBlaster ã®ã³ãŒããçãã£ããã察å¿ã§
> ãããšããããšã§ããããã®éã® Slammer ã§ããã£ããã¬ãžã¹ã
>> åŸã£ãŠãæ»æã¯åããŠããã¡ã€ã«ã¯äœåŠã⊠System folder ã®äžãäœåŠã
>> ã«æžãããŠããŸãã§ãããããã©ãããããå
ã®ããšã¯åºæ¥ãªããšæšæž¬ã§ã
>> ãŸãã
>
> ããŸããŸæ»æããã°ã©ã ããããŒãã£ããšããããšã§ããã
ä»åã® MSBLAST.D ã®ãã€ã®éšãããèŽåœçãªããšãŸã§ã¯ãããªããã©ãå
åã«
話é¡æ§ããã£ãããšããç¹ãçµæéåžžã«å€ãã®ã·ã¹ãã ã®ç©Žãå¡ããããšãã
ç¹ã§ããšãŠãèå³æ·±ãã§ããã... ãããªãããšãã§ããªãèŽåœçãªç©Žã
ã¿ã€ãã£ãããã»ããšãã«ã€ãããã€ãçŸããåã«å
ã«è»œã奎ã
ãã©æããšããèãæ¹ãïŒå
ç·ã§ã ã£ããïŒããããã
ïŒ ...匱ãèã§å ç«ãã€ããããããšã
--
æç° ä¿®åž NETside Technologies Inc.
-- Equal Opportunity for All Good Architectures, NetBSD. --
In article <0308212215...@ns.kobe1995.net>
k...@kobe1995.net (NAKAMURA Kazushi) writes:
> äžæåå¿ïŒ ç¥æžã§ããã»ãšãã©æ°åãããèªã£ãŠãããŠãããã©ãè£è¶³ã
> Worm, Troyan, (ç矩ã®)virusãšããã®ã¯ææ圢æ
ã
> DoS,DDoS,sniffer,spyware,æ¹ç«,LogCleaner,etc.ãšããã®ã¯ææã«æåãã
> åŸã®actionã«äŸãåé¡ã
> ãªã®ã§ãDosæ»æãä»æããwormãšããã®ãæãåŸãããšã
ãªãã»ã©ã
> ãã€ãŠRedHat Linuxã®ãšããããŒãžã§ã³ã§ãåæå€ã®ãŸãŸEnterãå©ã
> ç¶ããŠã€ã³ã¹ããŒã«ãããšãWWWãµãŒããã€ã³ã¹ããŒã«ãããŠããã®
> WWWãµãŒãã«ãšãããªã¯ãšã¹ããéããšbuffer overrunããŠãããã
> ãããOSèµ·ååŸã®æåã®ãªã¯ãšã¹ãã ãšå¿
ãåãçªå°ã«é£ã¹ãããšãã
> ç©Žãæã£ãŠããããæªçšããwormãæµè¡ã£ãæãæããŸããåæå€ã®
> ãŸãŸEnteræŒãã£ã±ãªãã§ã€ã³ã¹ããŒã«ãã人ãå®ã¯å°ãªããªãæš¡æ§ã
Unix ç³»(Linux å«ã)ã ãšãç°å¢å€æ°ãã¹ã¿ãã¯ã®åºã«ä»çµãããš
ãå€ãã®ãŠãç°å¢å€æ°ããŸã£ããåããªããå®å
šã«åãã«ãªããŸãã
> OpenBSDã§ã¯æ©ãææãã/dev/randomãªããŠãã©ã€ããŸã§çšæããŠã
> ãããããã§ä¹±æ°ã䜿ã£ãŠãæ»æè
ããoverrunåŸã«é£ã¶ãšäžæã
> ããã¢ãã¬ã¹ãäºæž¬ããé£ãããŠããŸãããFreeBSD 5-current
> ã§ããæ§ã
ãªEntropy harvestingãå©çšããŠäºæž¬å°é£æ§ãäžããããš
> åªåããŠããŸãã
ã«ãŒãã«ã§ãã¹ã¿ãã¯ã®åºãã©ã³ãã åããŠãããã§ããïŒ
DeleGate ã¯ãalloca(rand) ããŠãèªåã§ã©ã³ãã åããŠããŸããã
> WindowsãèŠããšããããã£ã泚æãæãããŠããªã
> ãšèšããããdebugã®çºãåçŸæ§ã確ä¿ããããšããããŠããã®ã§ã¯ïŒ
ãããããã°ãå€ããããšããã®ãããªããšãã§ããªããã§ãããã
äžçš®ã®æ¬ é¥åã売ã£ãŠããããã ãããèªåè»ãšãé£åãªã売ãäž
ããèœã¡ãŠäŒç€ŸãåŸãã¯ããªãã ãã©ããããŸã§ç¬å ãã²ã©ããªã
ãšããã°ã売ã£ãŠãå²ãããããããã ãã®è³éãããã°ã
Windows XP ãïŒïŒåãããéçºããŠããŸã ãéãæ®ãããããªã
ããªããçµå±ãããæ°ã®åé¡ãªã®ããæè¡ã®åé¡ãªã®ãã
æãªããèªåã§ã¯ Windows 䜿ã£ãŠããªãããé¢ä¿ãªãããšèšãã
ã®ã«ãã ãã ãããããã§ããŠãé¢ä¿ãªãã®ã«äœãäžè©±ãããªããš
ãããªã£ãŠã