GA»Æ½ð¼×

¡°¼«¼ò¡±»ÀР¡¤ È«ÓòÖÇÁª Ø­ GA»Æ½ð¼×м«¼òÁ캽ÏÂÒ»´úÐ£Ô°Íø½¨Éè×êÑлá
date
Ô¤Ô¼Ö±²¥
ÎÞ¸Ð×¼Èë ÈËÎïͳ¹Ü Ø­ RG-SAM+5.X ÐÂÒ»´ú¸ßУAIÈÏ֤ƽ̨°ä²¼
date
Ô¤Ô¼Ö±²¥
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
²úÆ·
< ·µ»ØÖ÷²Ëµ¥
²úÆ·ÖÐÐÄ
²úÆ·
½â¾ö¹æ»®
< ·µ»ØÖ÷²Ëµ¥
½â¾ö¹æ»®ÖÐÐÄ
ÐÐÒµ
ºÏ×÷ͬ°é
·µ»ØÖ÷²Ëµ¥
Ñ¡ÔñÇøÓò/˵»°
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

¡°WannaCry¡±ºóÓÖÒ»ÀÕË÷Èí¼þ¡°Petya¡±±äÖÖ²¡¶¾Ï®À´£¡£¡ ³ï±¸ºÃÈôºÎÓ¦¶ÔÁËÂð£¿

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ °ä²¼¹¦·ò£º2017-07-10
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

Ò»¡¢ÊÂÎñ²¼¾°

±±¾©¹¦·ò6ÔÂ27ÈÕÍí¼ä£¬¾Ý¹ú±íýÌåHackerNews±¬ÁÏ£¬Ò»ÖÖÀàËÆÓÚ“WannaCry”µÄÐÂÐÍÀÕË÷²¡¶¾Ï¯¾íÁËÅ·ÖÞ£¬ÎÚ¿ËÀ¼¾³ÄÚµØÌú¡¢µçÁ¦¹«Ë¾¡¢µçÐŹ«Ë¾¡¢Çжûŵ±´ÀûºËµçÕ¾¡¢ÒøÐÐϵͳµÈ¶à¸ö¹ú¶ÈÉèÊ©¾ùÔâϰȾµ¼ÖÂÔËÐÐÒì³£¡£¸Ã²¡¶¾Îª“Petya”±äÖÖ²¡¶¾£¬Í¨¹ýÓÊÏ丽¼þ´«²¼¡£Áí¾ÝÎÚ¿ËÀ¼CERT¹Ù·½ÐÂÎųÆ£¬ÓÊÏ丽¼þ±»È·ÈÏÊǸôβ¡¶¾¹¥»÷µÄ´«²¼Ô´Í·¡£¸ÃÀÕË÷²¡¶¾ÔÚÈ«ÇòÁìÓòÄÚ·¢×÷£¬Êܲ¡¶¾ÇÖÏ®µÄ¹ú¶È³ýÁËÎÚ¿ËÀ¼±í£¬»¹ÓжíÂÞ˹¡¢Î÷°àÑÀ¡¢·¨¹ú¡¢Ó¢¹úÒÔ¼°Å·ÖÞ¶à¸ö¹ú¶È£¬ºóÐø²»Åųý»á³ÖÐøÊæÕ¹µ½Ô̺¬ÖйúÔÚÄÚµÄÑÇÖÞ¹ú¶È¡£

¶þ¡¢²¡¶¾·ÖÎö

¾­¹ýGA»Æ½ð¼×°²È«²úÆ·ÊÂÒµ²¿µÄȡ֤×êÑУ¬Õâ´Î¹¥»÷ÊÇÀÕË÷²¡¶¾“Petya”µÄ±äÖÖ£¬²¡¶¾´«²¼¹ý³ÌÀûÓõ½windowsµÄÁ½¸ö·ì϶¡£µÚÒ»²½ÊÇÀûÓÃCVE-2017-0199·ì϶·¢ËÍÓʼþ£¬½«²¡¶¾Ôö³¤ÔÚoffice¸½¼þÀPCÒ»µ©´ò¿ª¸½¼þ£¬µÚÒ»¸ö´«²¼µÄÔ´Í·±»Ï°È¾³É¹¦¡£µÚ¶þ²½ÊÇͨ¹ýMS17-010£¨ÓÀºãÖ®À¶£©·ì϶ºÍϵͳÈõ¿ÚÁî½øÐд«²¼¡£·ì϶µÄ¾ßÌåÀûÓÃÇé¿öÈçÏ£º

·ì϶һ£ºCVE-2017-0199·ì϶

·ì϶עÃ÷£ºCVE-2017-0199ÔÊÐí¹¥»÷ÕßÀûÓô˷ì϶ÓÕʹÓû§´ò¿ª´¦ÖÃÌØÊâ»ú¹ØµÄOfficeÎļþÔÚÓû§ÏµÍ³ÉÏÖ´ÐÐËÁÒâºÅÁ´Ó¶ø½ÚÔìÓû§ÏµÍ³¡£

ÀûÓò½Ö裺ÀûÓø÷ì϶£¬ºÚ¿ÍÄܹ»½«ÀÕË÷Èí¼þµÄ´úÂëǶÈëÁËofficeÎĵµÖУ¬ÀýÈçword¡¢PPT¡¢ExcelµÈ£¬×÷Ϊ¸½¼þ¼Ù×°³ÉÇóÖ°¡¢¸æ°×µÈͨ¹ýµç×ÓÓʼþ´«²¼¡£Óû§ÊÕµ½¾­¹ý¼Ù×°µÄÓʼþºó£¬Ò»µ©´ò¿ª£¬ÀÕË÷²¡¶¾¿ªÊͳɿÉÖ´ÐÐÎļþ¡£

·ì϶¶þ£ºMS17-010£¨ÓÀºãÖ®À¶£©SMB·ì϶

·ì϶עÃ÷£ºMS17-010£¨ÓÀºãÖ®À¶£©SMB·ì϶ÊǽñÄê4Ô·½³Ìʽ×é֯й¶µÄ³ÁÒª·ì϶֮һ¡£“ÓÀºãÖ®À¶”ÀûÓÃWindows SMBÔ¶³ÌÌáȨ·ì϶£¬Äܹ»¹¥»÷Ê¢¿ª445 ¶Ë¿ÚµÄ Windows ϵͳ²¢ÌáÉýȨÏÞ¡£

ÀûÓò½Ö裺Ê×ÏÈ£¬TCP ¶Ë¿Ú 445ÊÇÔÚWindows ϵͳÖÐÌṩ¾ÖÓòÍøÖÐÎļþ»ò´òÓ¡»ú¹²Ïí·þÎñ£¬ºÚ¿Í³¢ÊÔÓëµçÄÔ445¶Ë¿Ú³ÉÁ¢ÒªÇóÏνÓ£¬Ò»µ©Ïνӳɹ¦£¬¾Í¿ÉÄÜ»ñµÃ¾ÖÓòÍøÄÚ¹²ÏíµÄÎļþ»òÐÅÏ¢¡£Í¨¹ýµÚÒ»¸ö·ì϶ϰȾµÄµÚһ̨PC¼Ì¶øÀûÓÃMS17-010£¨ÓÀºãÖ®À¶£©SMB·ì϶ϰȾ¾ÖÓòÍøÖÐÊ¢¿ª445¶Ë¿ÚµÄËùÓÐPC¡£

±¾´ÎÀÕË÷²¡¶¾¸²¸ÇµÄÖÕ¶ËÊÇwindows XP¼¶ÒÔÉϲÙ×÷ϵͳ£¬µçÄÔ¡¢·þÎñÆ÷ϰȾÕâÖÖ²¡¶¾ºó»á±»¼ÓÃÜÌØ¶¨ÀàÐÍÎļþ£¬µ¼ÖÂϵͳÎÞ·¨Õý³£ÔËÐС£·ÖÆçÓÚ´«Í³ÀÕË÷Èí¼þ¼ÓÃÜÎļþµÄÐÐΪ£¬“Petya”ÊÇÒ»¸öѡȡ´ÅÅ̼ÓÃÜ·½Ê½£¬¼ÓÃܳɹ¦ºó£¬»áÏÔʾÀÕË÷ÐÅÏ¢µÄ½çÃæ£¬ÈôÊÇÊܺ¦Õß²»Ö§¸¶Êê½ð£¬µ××ÓÎÞ·¨½øÈëϵͳ¡£

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

±»¼ÓÃܺóµÄÀÕË÷ÐÅÏ¢

 

Èý¡¢°²È«½¨Òé

1¡¢ ¶ñÒâÓʼþ·À±¸

¸ÃÀÕË÷Èí¼þ³õ´Î´«²¼ÊÇͨ¹ýÓʼþ½øÐеÄ£¬¹Ê´Ë£¬Óöµ½Ð¯´ø²»Ã÷office¸½¼þºÍ²»Ã÷Á´½ÓµÄÓʼþÇëÎðµã»÷¸½¼þ¡£

2¡¢ Õë¶ÔCVE-2017-0199¡¢MS-17-010Á½¸ö·ì϶ʵʱװÖ÷ì϶²¹¶¡

£¨CVE-2017-0199) RTF·ì϶²¹¶¡µØÖ·£º

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0199

S17-010£¨ÓÀºãÖ®À¶£©·ì϶²¹¶¡µØÖ·£º

https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

3¡¢ ½ûÓÃWMI·þÎñ

https://msdn.microsoft.com/en-us/library/aa826517(v=vs.85).aspx

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

4¡¢ ·À»ðǽ·À»¤

GA»Æ½ð¼×ÍøÂçÒѸüзÀ»¤Ìصã¿â£¬ÈôÊÇÄúÊÇGA»Æ½ð¼×È«ÐÂÏÂÒ»´ú·À»ðǽ²úÆ·µÄÓû§£¬Çëʵʱ¸üе½Èçϰ汾£º²¡¶¾Ñù±¾¿â£º49.00830£» IPSÌØµã¿â£º11.00168

GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

ËÄ¡¢×ܽ᣺

 

»ØÊדPetya”±äÖÖ²¡¶¾ºÍ“wannacry”ÊÂÎñ£¬ÀÕË÷²¡¶¾ËùʹÓõļ¿Á©²¢²»ÊǼ«¶È¸ß¼¶µÄ¹¥»÷²½Ö裬ÀûÓõķì϶Ҳ²¢·Ç0-day·ì϶£¬¶øÊÇ΢ÈíÔçÒѰ䲼¹«¸æµÄÒÑÖª·ì϶£¬´«²¼µÄ¹Ø¼ü³É·ÖÔÚÓÚµçÄÔ»ò·þÎñÆ÷´æÔÚδʵʱ¸üеķì϶ºÍÈõ¿ÚÁî¡£Òò¶ø£¬ÆóÒµºÍÓ×ÎÒ¶¼¸Ãµ±ÕæË¼Âǰ²Õû¸öϵ½¨ÉèµÄ»ù´¡¹¤×÷£¬Ó×ÎÒµçÄÔӦʵʱװÖòÙ×÷ϵͳ²¹¶¡£¬»Ø¾øÈõ¿ÚÁî²¢¶¨ÆÚ¸ü»»ÃÜÂ룬Óöµ½²»Ã÷È·µÄÓʼþ²»ÒªµÈÏдò¿ª¡£ÆóÒµÓû§Ó¦ÔÚÍøÂçÌìǵ²¿ÊðÄܹ»ÊµÊ±ÌṩÏàÓ¦ÌØµã¿âºÍ·À»¤Õ½ÊõµÄ°²È«É豸£¬¾¡Ô翪Æô·À»¤Õ½Êõ²¢ÊµÊ±¸üÐÂÌØµã¿â¡£·À»¼ÓÚδȻ£¬×öºÃ°²È«£¬ÆóÒµÄÜÁ¦¸üºÃµØ·¢Õ¹¡£

¹Ø×¢GA»Æ½ð¼×
gfwx_logo
¹Ø×¢GA»Æ½ð¼×¹ÙÍøÎ¢ÐÅ
ËæÊ±Ïàʶ¹«Ë¾×îж¯Ì¬
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾

·µ»Ø¶¥²¿

ÊÕÆð
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµAI¸±ÊÖ
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾ ÎĵµÆÀ¼Û
ev-close
¸Ã×ÊÁÏÊÇ·ñ½â¾öÁËÄúµÄÎÊÌ⣿
ev-close
Äú¶Ôµ±Ç°Ò³ÃæµÄÖÐÒâ¶ÈÈôºÎ£¿
²»Õ¦µÎ
¼«¶ÈºÃ
dark-star dark-star dark-star dark-star dark-star
ev-close
ÄúÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
Äú²»ÖÐÒâµÄÔ­ÒòÊÇ£¨¶àÑ¡£©£¿
ev-close
ÄúÊÇ·ñ»¹ÓÐÆäËûÎÊÌâ»ò½¨Ò飿
ΪÁ˼±¾ç½â¾ö²¢»Ø¸´ÄúµÄÎÊÌ⣬ÄúÄܹ»ÁôÏÂÁªÏµ·½Ê½
ÓÊÏä
ÊÖ»úºÅ
ev-bg
¸Ð¼¤ÄúµÄ·´À¡£¡
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
GA»Æ½ð¼×¡¤(Öйú¼¯ÍÅ)¹Ù·½ÍøÕ¾
ÇëÑ¡Ôñ·þÎñÏîÄ¿
¹Ø¹ØÕ÷ѯҳ
ÊÛǰÕ÷ѯ ÊÛǰÕ÷ѯ
ÊÛǰÕ÷ѯ
ÊÛºó·þÎñ ÊÛºó·þÎñ
ÊÛºó·þÎñ
¶¨¼û·´À¡ ¶¨¼û·´À¡
¶¨¼û·´À¡
¸ü¶àÁªÏµ·½Ê½
¡¾ÍøÕ¾µØÍ¼¡¿