ºÚ°µÖÐÕÒѰϣÍû

»¶Ó­À´µ½ºÚ°µÖÐÕÒѰϣÍû>>¡¡¡¡ | Ê×Ò³ ×ÊÔ´ÖÐÐÄ | ¾­µäÓ°ÊÓ | Ó¢Óïѧϰ | ¶ñÒâÈí¼þ·À·¶ | ÍøÎĹ²Ïí | ѧϰ½ø½× | ÐÄÇéÈÕ¼Ç | ITPUBÂÛ̳

ÐÜèÉÕÏ㲡¶¾×¨É±ÏÂÔØ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2007ÄêÒ»ÔÂ16ÈÕ, 08:32

´ó³ÉÌìϳöÊÖµÄרɱ¹¤¾ß,ÏÖÔÚÉý¼¶µ½ÁË1.6°æ

http://dswlab.com/dow/d2.html


UÅÌ(auto²¡¶¾)Àಡ¶¾·ÖÎöÓë½â¾ö·½°¸(zt)

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2007ÄêÒ»ÔÂ15ÈÕ, 11:11

ÄÚÈÝ£º

UÅÌ(auto²¡¶¾)Àಡ¶¾·ÖÎöÓë½â¾ö·½°¸

À´×Ô´ó³ÉÌìÏÂ

 ²é¿´È«ÎÄ

2006-9-19 Dr.WEBÍÆ³öµÄÃâ·Ñ²éɱ²¡¶¾¹¤¾ß

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ19ÈÕ, 08:44

ÄÚÈÝ£º¶ÔÓÚOffice¡¢rarµÈ¿ÉÖ´ÐÐÎļþ´ò²»¿ª£¬ÖÐÁËW32.Looked.AH

²ÉÓÃDr.WEBµÄ²¡¶¾²éɱ¹¤¾ß·Ç³£µÄºÃÓã¡

 ²é¿´È«ÎÄ

2006-9-18 symantec 10.0·À²¡¶¾¿Í»§¶Ë²¡¶¾¶¨ÒåÎÞ·¨¸üеĽâ¾ö

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ18ÈÕ, 13:27

ÄÚÈÝ£ºSymantec 10.0ÆóÒµ°æÒÔºóÔö¼ÓÁËPKIÈÏÖ¤¹¦ÄÜ£¬¿Í»§¶Ë¶¨ÒåÎÞ·¨¸üеĽâ¾ö ²é¿´È«ÎÄ

2006-9-18 Symantec 10.0²¡¶¾¶¨Òå¸üÐÂ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ18ÈÕ, 10:47

ÄÚÈÝ:

PKIÎļþ½øÐи²¸Ç¼´¿É

 ²é¿´È«ÎÄ

2006-9-14 EXEÎļþ¹ØÁªµÄÐÞ¸´

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ15ÈÕ, 08:07

ÄÚÈÝ£º×î½üÍøÂçÄڵIJ¡¶¾¡¢Ä¾ÂíµÈÌØ±ð²þâ±£¬SymantecÔÚ²éɱÍ겡¶¾ÒԺ󣬲¿·Ö»úÆ÷³öÏÖ¡°ExeÎļþ¹ØÁªµÄ´íÎ󡱿ÉÖ´ÐÐÎļþ´ò²»¿ª£¬ÉÏÍøGoogleÁËһϣ¬ÔÚÆ®Ñ©µÄÍøÕ¾ÕÒµ½Á˽â¾öµÄ·½·¨£º

http://www.pxue.com/Html/23.html

 ²é¿´È«ÎÄ

2006-9-12 office²¡¶¾

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ12ÈÕ, 16:20

ÄÚÈÝ£ºÍøÄÚ±¬·¢ÁËoffice²¡¶¾ ²é¿´È«ÎÄ

·À²¡¶¾¹¥»÷×î¼Ñʵ¼ù---office

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê¾ÅÔÂ04ÈÕ, 15:27

ÄÚÈÝ£ºÕë¶ÔofficeÎĵµ·À²¡¶¾¹¥»÷µÄ×î¼Ñʵ¼ù

http://office.microsoft.com/en-us/assistance/HA011030692052.aspx

 ²é¿´È«ÎÄ

½«¶ñÒâÀ¬»øÆÀÂÛdenyÁË

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006Äê°ËÔÂ17ÈÕ, 16:04

ÄÚÈÝ£º

ǰ¶Îʱ¼ä·¢ÏÖ×Ô¼ºµÄBlogµÄ¶ñÒâÀ¬»øÆÀÂÛ¿ì·ÉÁË£¬É¾¶¼É¾²»µô£¬ÕûµØÎÒµÄÍ·¶¼´óÁË£¬ÉÏÂÛ̳¿´ÁËһϣ¬°ÑÒ»¸ö²å¼þµÄ¹¦Äܸø´ò¿ªÁË£¬ÏÖÔÚ¿´Ã»ÎÊÌâÁË£¬ºÇºÇ£¬¾ÍÊÇÒ»¸öÆÀÂÛÑéÖ¤µÄ¹¦ÄÜ£¡

²»´í£¬Ê¡ÐÄÁË£¡


ravmone.exe²¡¶¾µÄÇå³ý

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006ÄêÁùÔÂ27ÈÕ, 11:27

UÅ̵ÄÒ»ÖÖ¶ñÐÔ²¡¶¾£ºRavmone.exe ²é¿´È«ÎÄ

΢Èí·¢²¼Èý¸ö¸ßΣ©¶´

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2006ÄêÒ»ÔÂ12ÈÕ, 10:44

ÄÚÈÝ£ºÎ¢Èí×îз¢²¼ÁËÈý¸ö¸ßΣ©¶´ ²é¿´È«ÎÄ

±£»¤¸öÈ˵çÄÔ°²È«µÄ±Ø±¸¹¤¾ß

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêÊ®¶þÔÂ16ÈÕ, 15:10

ÄÚÈÝ£ºÊ¹ÓÃÃâ·Ñ¹¤¾ß±£»¤ÄãµÄ¸öÈ˵çÄÔ°²È« ²é¿´È«ÎÄ

2005ÄêÊ®´ó²¡¶¾ÅÅÐÐZafi-D³ÉΪж¾Íõ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêÊ®¶þÔÂ09ÈÕ, 20:26

ÈçÌâ

 ²é¿´È«ÎÄ

sober²¡¶¾ºáÐÐ×¢Òâ½øÐзÀ»¤

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ29ÈÕ, 11:24

ÄÚÈÝ£ºsober²¡¶¾µÄ±äÖÖÕýÔÚ½øÐÐÈ«Çò´«²¥£¬Çë×¢Òâ×öºÃ·À»¤¹¤×÷¡£

 ²é¿´È«ÎÄ

Worm about intec32.exe

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ29ÈÕ, 08:22

×î½üÓÐÍøÓÑËµÍøÄÚÖÐÁËÒ»ÖÖintec32.exeµÄ²¡¶¾£¬
goolgeÁËÒ»ÏÂTrendµÄÓ¢ÎÄÍøÕ¾ËµÁËÏêϸµÄ½â¾ö
·½·¨£¬ÕâÊÇÒ»ÖÖºóÃŲ¡¶¾¡£

From :

http://www.trendmicro.com.au/enterprise/vinfo

 ²é¿´È«ÎÄ

SANS·¢²¼2005È«Çò»¥ÁªÍø20´ó°²È«Òþ»¼ÅÅÐÐ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ24ÈÕ, 15:58

ÄÚÈÝ£º

11ÔÂ23ÈÕÏûÏ¢£¬¼ÆËã»ú°²È«Ñо¿×éÖ¯SANSÈÕ
ǰ·¢²¼ÁË2005Äê¡°20´ó»¥ÁªÍø°²È«Òþ»¼¡±ÅÅ
Ðаñ¡£¾Ý°ñµ¥ÏÔʾ£¬É±¶¾Èí¼þɨÃèÒýÇæ¡¢web
Ó¦Óá¢Î¢Èí²úÆ·£¬ÒÔ¼°Ë¼¿ÆÍøÂç²úÆ·Ëù´æÔÚµÄ
©¶´¾ù±»ÁÐÈë20´óÍþв֮ÁС£

 ²é¿´È«ÎÄ

About CTFMON.exe

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ21ÈÕ, 14:19

ctfmon - ctfmon.exe - ½ø³ÌÐÅÏ¢

½ø³ÌÎļþ: ctfmon or ctfmon.exe
½ø³ÌÃû³Æ: Alternative User Input Services

ÃèÊö: ¿ØÖÆAlternative User Input Text Processor (TIP)ºÍMicrosoft OfficeÓïÑÔÌõ¡£Ctfmon.exeÌṩÓïÒôʶ±ð¡¢ÊÖдʶ±ð¡¢¼üÅÌ¡¢·­ÒëºÍÆäËüÓû§ÊäÈë¼¼ÊõµÄÖ§³Ö¡£
³£¼û´íÎó: N/A
ÊÇ·ñΪϵͳ½ø³Ì: ·ñ

 ²é¿´È«ÎÄ

ÔÚÏßɨÃ財¶¾µØÖ·

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ11ÈÕ, 11:12

ÔÚÏßɨÃèµØÖ·£º

Panda£º

http://www.pandasoftware.com/products/activescan.htm Ca etrust:

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

רɱ¹¤¾ßÏÂÔØ

symantec http://www.symantec.com/avcenter/tools.list.html/

panda

http://www.pandasoftware.com/download/utilities/


΢Èí·¢²¼ÁË11Ô·ݰ²È«¹«¸æ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ09ÈÕ, 16:42

΢Èí·¢²¼ÁË11Ô·ݰ²È«¹«¸æ£¬ÆäÖÐÓÐÒ»¸ö¸ßΣ©¶´£¡

http://www.microsoft.com/china/technet/security/bulletin/ms05-nov.mspx

hotfix×¢²á±íÖеÄλÖÃ

Hkey_local_machine:software:microsoft:Windows Nt:CurrentVersion:Hotfix


ÆóÒµÖеķÀ²¡¶¾¹ÜÀíÐèÒªÒ»¸ö½¡È«µÄÌåÖÆ

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ03ÈÕ, 16:19

¹«Ë¾ÄÚ²¿×ÜÓÐÒ»²¿·ÖÈËÒÔΪ×Ô¼ººÜÅ£XµÄ£¬¶ÔÓÚ×Ô¼ºµÄµçÄÔ°²×°ÁËÆäËüµÄ·À²¡¶¾Èí¼þ£¬¶øÇÒ°Ñsymantec±áµÍµÄÒ»ÎÞÊÇ´¦£¬×÷ÎªÍøÂç·À²¡¶¾µÄ¹ÜÀíÔ±£¬¹«Ë¾ÌåÖÆµÄ²»½¡È«£¬¶ÔÓÚÕⲿ·Ö´óÒ¯¼¶ÈËÎï¹ÜÒ²¹Ü²»µÃ˵Ҳ˵²»µÃ£¬ÕæÊÇÎÞÄΣ¡¸üºÎ¿öÁ¬×Ô¼ºÐÅÏ¢ÖÐÐÄÄÚ²¿µÄÈË·À²¡¶¾Èí¼þ¶¼Ê¹ÓÃÁ˺ܶàµÄ°æ±¾¡£

 ²é¿´È«ÎÄ

Know Your Enemy:Defining Virtual Honeynets

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ03ÈÕ, 16:15

Over the past several years Honeynets have demonstrated their value as a security mechanism, primarily to learn about the tools, tactics, and motives of the blackhat community. This information is critical for organizations to better understand and protect against the threats they face. One of the problems with Honeynets is they are resource intensive, difficult to build, and complex to maintain. Honeynets require a variety of both physical systems and security mechanisms to effectively deploy. However, the Honeynet Project has been researching a new possibility, virtual Honeynets. These systems share many of the values of traditional Honeynets, but have the advantages of running all the systems on a single system. This makes virtual Honeynets cheaper to build, easier to deploy, and simpler to maintain.

http://www.honeynet.org/papers/virtual/


Exfilter ÖÐÎÄÓòÃûÐ¶ÔØºóÁôϵÄ×ÔÆô¶¯Ïî

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ02ÈÕ, 08:43

ÊÔÓò쿴Æô¶¯¼ÓÔØÏîµÄÃâ·ÑÈí¼þAutorunsʱ·¢ÏÖÔÚ

HKLM_SOFTWARE_Microsoft_Windows_CurrentVersion_Run

ÏÂÓÐÒ»¸ö×ÔÆô¶¯ÏîExfilter £¬¶ÔÓ¦ÏîΪ

C:_Program Files_CNNIC_Cdn_cdnspie.dll

ÊôÓÚhookdll£¬ÊÇÖÐÎÄÓòÃûÐ¶ÔØºóµÄ×ÔÆô¶¯Ïî¡£


MS 05-039 Windows¼´²å¼´ÓôæÔÚ©¶´²¡¶¾W32.zotob

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêʮһÔÂ01ÈÕ, 09:28

ZotobÀûÓÃ΢Èí¹«²¼µÄÑÏÖØÏµÍ³Â©¶´£¬Windows Plug and Play ·þÎñ©¶´ (MS05-039)£¬ ¹¥»÷TCP¶Ë¿Ú445£¬ºÍ³å»÷²¨¡¢Õñµ´²¨·½·¨ÀàËÆ£¬¹¥»÷´úÂëÏòÄ¿±êϵͳµÄ445¶Ë¿Ú·¢ËÍ©¶´´úÂ룬ʹĿ±êϵͳÔì³É»º³åÇøÒç³ö£¬Í¬Ê±ÔËÐв¡¶¾´úÂ룬½øÐд«²¥¡£ ²é¿´È«ÎÄ

ssl.exe ²¡¶¾

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêÊ®ÔÂ31ÈÕ, 16:22

ssl.exeÊôÓÚspywareÈ䳿
¹ØÓÚssl.exeÈçϽâÊÍ
W32/Cuebot-D ÊÇÍøÂçÈ䳿Óë±³ºóTrojan ¹¦ÄÜΪ´°¿Úƽ̨¡£
W32/Cuebot-D ÊÔͼ´«²¥Ê¹Óõļ¼Êõ°üÀ¨PnPÈõµãµÄ¿ª·¢ (MS05-039) ¡£
µ±µÚÒ»´ÎÔËÐÐW32/Cuebot-D ¸´ÖÆ< System>ssl.exe ºÍ´´ÔìÎļþ< Windows>Debugdcpromo.log ¡£
Õâ¸öÎļþssl.exe ±»¼Ç¼,×÷ΪһеÄϵͳ·þÎñ±»ÃüÃû" Ô´Óï¾ä¿â", Óë" ΢ÈíÔ´Óï¾ä¿â" ºÍÒ»¿ªÊ¼½×¶ÎÀàÐÍÏÔʾÃû×Ö×Ô¶¯, ËùÒÔËü×Ô¶¯µØ¿ªÊ¼ÔÚϵͳÆð¶¯Ê±¡£¼Ç¼Ìõ±»´´ÔìÈçÏÂ:
HKLMSYSTEMCurrentControlSetServicesssl
ÉèÖà ÈçÏÂ:
HKLMSOFTWAREMicrosoftOle
EnableDCOM
n
HKLMSYSTEMCurrentControlSetControlLsa
restrictanonymous
1
Ò»¸ö²¹¶¡ÎªPnP ²Ù×÷ϵͳÈõµã:ms-05039

ÐÂÔö¶ñÒâÈí¼þ·À·¶Ä£¿é

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêÊ®ÔÂ26ÈÕ, 11:33

ÔÚblogÖÐÐÂÔö¼ÓÁ˹ØÓÚ¶ñÒâÈí¼þ·À·¶µÄ°å¿é£¬ÒÔºó·À²¡¶¾¡¢È䳿¡¢Ä¾ÂíµÈµÄÏà¹ØÎÄÕ¼¼ÇÉ×öÒ»¸ö»ã×Ü¡£

¡°Á÷Ã¥Èí¼þ¡±£¨zt£©

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005Äê°ËÔÂ15ÈÕ, 08:25

˵Ã÷£º½éÉÜÁËÁ÷Ã¥Èí¼þµÄһЩÄÚÄ»ÏûÏ¢£¬ÖµµÃÒ»¿´¡£

Óɱ±¾©ÊÐÍøÂçÐÐҵЭ»á½øÐÐǣͷµÄ¡°Á÷Ã¥Èí¼þ¡±ÍøÉϾٱ¨µ÷²é½á¹û×òÈÕÒý·¢ÁËÐùÈ»´ó²¨£¬¼¸´ó³öÏÖÔÚÃûµ¥Ö®Äڵij§ÉÌÒ²¸÷³ÖÒ»´Ê»¥½ÒÄÚÄ»¡£

 ²é¿´È«ÎÄ

Microsoft²¹¶¡µÄÃüÃû¹æÔò£¡

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005ÄêËÄÔÂ25ÈÕ, 16:29

ÀýÈçMS03-039 £¬´ú±í2003ÄêµÚ39¸öBug

¶ÔÓÚKB******£¬Q******»òÕßÀàËÆµÄ±íʾÕâ¸öÎÊÌâÔÚ֪ʶ¿âµÚ******ºÅÎÄÕÂÖÐÌÖÂÛ¹ý£¬Äã¿ÉÒÔͨ¹ýÁ´½Ó£º
http://support.microsoft.com/?id=****** Ö±½Ó·ÃÎÊ

ÐèҪעÒâµÄÊÇÏàÓ¦µÄ²¹¶¡³ÌÐòµÄÃüÃû¹æÔò£¬ÕâÀïÄÜ˵Ã÷²»ÉÙÎÊÌ⣬Äã¿ÉÒԲο¼ÕâÀ

http://support.microsoft.com/?id=816915
http://support.microsoft.com/?id=816916
http://support.microsoft.com/?id=822464
http://support.microsoft.com/?id=822499
http://support.microsoft.com/?id=822623
http://support.microsoft.com/?id=823419

 ²é¿´È«ÎÄ

2005Äê2Ô·Ý΢Èí×îз¢²¼ÁË12¸ö°²È«²¹¶¡£¬×¢Òâ¸üÐÂѽ£¡£¡£¡

·¢±íÈË:shadowgo | ·¢±íʱ¼ä: 2005Äê¶þÔÂ25ÈÕ, 08:20

ÄÚÈÝ£º ΢Èí×îз¢²¼ÁË12¸ö°²È«²¹¶¡£¬×¢Òâ¸üÐÂѽ£¡£¡£¡
 ²é¿´È«ÎÄ

Valid XHTML 1.0 Strict and CSS. Powered by pLog
Design by Blog.lvwo.com