¹ãÖݱ±´óÇàÄñµçÄÔITÅàѵ--WINDOWS×îΣÏÕµÄÊ®¸ö©¶´
רְµÄÍøÂçºÍϵͳ°²È«¹ÜÀíÈËÔ±ÔÚÈÕ¸´Ò»ÈյĽøÐÐ×Ų¹¶¡¸üС¢ÏµÍ³Éý¼¶£¬Ã¿Ìì¶¼ÒªÖØ¸´°²È«¾¯¸æ¡¢Ó²¼þ¹ÊÕÏ¡¢Â©¶´É¨ÃèÒÔ¼°ÃÜÂë·´ÆÆ½âµÈ¹¤×÷£¬µ«ºÜÓбØÒª´ÓÕâЩ·³ÔÓµÄËöÊÂÖгéÉí³öÀ´£¬ÈÏÕæÁ˽âһϵ½µ×ÄÄЩ²ÅÊÇÍøÂ簲ȫµÄ×î´óµÐÈË£¬Ö»ÓÐÕâÑùÄã²ÅÄÜÁ˽âÊÇ·ñÀË·Ñ×ÊÔ´»òÊǺöÂÔÁ˹ؼüÎÊÌâ¡£
SANS£¨System Administration£¬ Networking£¬ Security-ϵͳ¹ÜÀí¡¢ÍøÂçºÍ°²È«Ñ§»á£©ºÍNIPC£¨¹ú¼Ò»ù´¡±£»¤ÖÐÐÄ£©ÔÚ×î½üÁªºÏ·¢²¼ÁËÓ뻥ÁªÍøÏà¹ØµÄSANS/FBI 20´óϵͳ°²È«ÍþвÁÐ±í¡££¨×¢Ò»£©
¾Ñé·á¸»µÄÍøÂç¹ÜÀíÔ±¿ÉÒԲο¼Õâ·Ý°²È«ÍþвÁÐ±í£¬Õë¶ÔÒÔÍù¹¤×÷ÖпÉÄÜÊ詵ĵط½£¬ÔÚ¸÷×Ô¹ÜÀíµÄÍøÂçºÍϵͳÖнøÐÐÒ»´Î¿ìËÙ¡¢³¹µ×µÄÇå²é£¬Í¬Ê±Õâ·ÝÁбí¶ÔÓÚ¸Õ½Ó´¥ÍøÂç¹ÜÀí¹¤×÷µÄ¹¤×÷ÈËÔ±¸üÓаïÖú£¬¿ÉÒÔ°´Í¼Ë÷æ÷µØ²éÕÒ¸÷ÖÖ¿ÉÄÜ´æÔÚµÄϵͳ©¶´ºÍΣÏÕ£¬ÒÔ±ãÄܹ»¼°Ê±¹Øµô×îΣÏյĩ¶´¡£
ÕâÆªÎÄÕÂÇ¿¼¯ÖÐÌÖÂÛÁбíÖÐÉæ¼°µÄWindowsϵͳ©¶´£¬»¹°üÀ¨SANS½¨Ò鹨±ÕµÄ·À»ðǽ¹ÜÀí¶Ë¿ÚÒÔ·ÀÖ¹´ó¶àÊýµÄ¹¥»÷£¬°ïÖú¹ÜÀíÔ±ÓÐ×ã¹»µÄʱ¼äÀ´°²×°ºÏÊʵIJ¹¶¡Èí¼þ¡£
Èç¹ûÒªµÃµ½¸ü¶àµÄ²Î¿¼×ÊÁÏ£¬Çë·ÃÎÊ2002Äê5ÔÂ2ÈÕ·¢²¼µÄTop 20 List ÒÔ¼°2001Äê·¢²¼µÄTop 10 list¡£
Windows ©¶´
À´×ÔSANS/FBIÁªºÏ·¢±íµÄ±¨¸æ²¢·ÇÖ»ÊǼòµ¥µÄÁÐ±í¡£ËüÌṩÁ˹ØÓÚ©¶´ºÍÈçºÎ½â¾öµÄÆÄÓмÛÖµµÄÐÅÏ¢¡£Óû§¿ÉÒÔ¸ù¾ÝÕâ·ÝÔ´´±¨¸æÀ´ÕÒ³ö¸ü¶àµÄÌØ¶¨Â©¶´¡£
ÒÔÏÂÁгöÁËÒÔÍùÕÒ³öµÄWindowsϵͳ´æÔÚÖØ´ó©¶´µÄ·þÎñÃûµ¥£º
W1 IIS£¨»¥ÁªÍøÐÅÏ¢·þÎñÆ÷£© W2 ΢ÈíÊý¾Ý·ÃÎʲ¿¼þ£¨MDAC£©£Ô¶³ÌÊý¾Ý·þÎñ W3 ΢ÈíSQL Server W4 NETBIOS£²»Êܱ£»¤µÄWindowsÍøÂç¹²Ïí W5 ÄäÃûµÇÈë -- Null Sessions£¨¿Õ»á»°£¬×¢¶þ£© W6 LAN Manager Éí·ÝÈÏÖ¤ £Ò×±»¹¥»÷µÄLAN Manager¿ÚÁîÉ¢ÁУ¨×¢Èý£© W7 Ò»°ãWindowsÉí·ÝÈÏÖ¤£ÕÊ»§ÃÜÂëÌ«´àÈõ»ò¸É´àΪ¿Õ W8 IEä¯ÀÀÆ÷©¶´ W9 Ô¶³Ì×¢²á±í·ÃÎÊ W10 WSH£¨Windows½Å±¾Ö÷»ú·þÎñ£©
ÈÃÎÒÃǽøÒ»²½Á˽âÉÏÊö©¶´¡£
1. IIS·þÎñÆ÷
΢ÈíµÄIIS·þÎñÆ÷´æÔÚ»º´æÒç³ö©¶´£¬ËüÄÑÒÔºÏÊʵعýÂ˿ͻ§¶ËÇëÇó£¬Ö´ÐÐÓ¦Óýű¾µÄÄÜÁ¦½Ï²î¡£²¿·ÖÎÊÌâ¿ÉÒÔͨ¹ýÒÑ·¢²¼µÄ²¹¶¡½â¾ö£¬µ«Ã¿´ÎIISµÄа汾·¢²¼¶¼´øÀ´ÐµÄ©¶´£¬Òò´ËIIS³öÏÖ°²È«Â©¶´²¢²»ÄÜÍêÈ«¹é×ïÓÚÍø¹ÜµÄÊè©¡£½¨Òé¹ÜÀíÈËÔ±ÔËÐÐHFNetChkÀ´¼ì²éĿǰ¿É¸üеIJ¹¶¡¡£
ÊÊÓÃÐÔ˵Ã÷¡ª¡ªWindows NT 4ÔËÐÐ IIS 4£¬ Windows 2000 ÔËÐÐIIS 5£¬Windows XP ProÔËÐÐ IIS 5.1 ¡£
ÐÞ¸´·½·¨¡ª¡ª°²×°²¹¶¡Îļþ¡£ÎªÄãµÄϵͳ°²×°×îеÄIIS²¹¶¡£¬²¢ÔÚIISÖÐÅųý¶ñÒâÓû§µÄ·ÃÎÊIPµØÖ·£¨Ïà¹Ø½âÊͼû£ºhttp://www.microsoft.com/technet/security/tools/urlscan.asp£©¡£É¾³ýIISÖÐȱʡ֧³ÖµÄISAPIÀ©Õ¹Ãû£¬ÖîÈ磺.htr¡¢.idq¡¢.ismÒÔ¼°.printer£¬ÕâЩ¿ÉÖ´Ðнű¾µÄÀ©Õ¹ÃûÔÚIIS°²×°Ê±È±Ê¡Ö§³Ö£¬µ«Óû§ºÜÉÙ»áÐèÒªËüÃÇ¡£É¾³ý\inetput\wwwroot\scriptsĿ¼ÖеĽű¾Ñù±¾Îļþ¡£Í¬Ñù£¬ÔÚ½øÐÐIIS°²×°Ê±²»Òª°²×°Ô¶³Ì¹ÜÀí¹¤¾ß¡£
2. MDAC
΢ÈíÊý¾Ý·ÃÎʲ¿¼þµÄÔ¶³ÌÊý¾Ý·þÎñµ¥ÔªÓÐÒ»¸ö±àÂë´íÎó£¬Ô¶³Ì·ÃÎÊÓû§ÓпÉÄÜͨ¹ýÕâһ©¶´»ñµÃÔ¶³Ì¹ÜÀíµÄȨÏÞ£¬²¢ÓпÉÄÜʹÊý¾Ý¿âÔâµ½ÍⲿÄäÃû¹¥»÷¡£
ÊÊÓÃÐÔ˵Ã÷¡ª¡ªNT 4.0ϵͳÔËÐÐIIS 3.0ºÍ4.0£¬RDS 1.5»òÊÇ VS 6.0¡£
ÐÞ¸´·½·¨¡ª¡ªÉý¼¶MDACµ½2.1»ò¸üеİ汾£¬»òÕß»ùÓÚÒÔÏ·¢²¼µÄ·½·¨½øÐÐϵͳÅäÖãº
Q184375 MS98-004 MS99-025
´ÓÉÏÊö¹«¸æ·¢²¼µÄʱ¼ä¿ÉÒÔ¿´³ö£¬ÕâЩ©¶´ÊÇËùνµÄwell-know (ÖøÃûµÄ) ©¶´¡£Êµ¼ÊÉÏÉÏÊö©¶´³£±»ÓÃÀ´¹¥»÷WindowsÍøÂç £¬ÓÈÆäÊÇÄÇЩ½ÏÔçµÄϵͳ¡£
3. ΢ÈíSQLÊý¾Ý¿â
Internet Storm CenterʼÖÕÔÚ¾¯¸æÓû§Î¢ÈíSQLÊý¾Ý¿âµÄ1433¶Ë¿ÚÊǹ¥»÷Õ߱ض¨É¨ÃèµÄÊ®´óÏÖ´æÂ©¶´¶Ë¿ÚÖ®Ò»¡£
ÊÊÓÃÐÔ˵Ã÷¡ª¡ªSQL·þÎñÆ÷7.0£¬SQL·þÎñÆ÷2000ÒÔ¼°SQL×ÀÃæ°²×°°æ±¾¡£
ÐÞ¸´·½·¨¡ª¡ª¸ù¾Ý¸÷×ÔµÄϵͳ°²×°ÏÂÃæµÄÆäÖÐÒ»¸ö²¹¶¡£º
SQL Server 7.0 ·þÎñ°ü 4 SQL Server 2000 ·þÎñ°ü 2
4. NETBIOS/WindowsÍøÂç¹²Ïí ÓÉÓÚʹÓÃÁË·þÎñÆ÷ÐÅÏ¢¿é(SMB) ÐÒé»òͨÓû¥ÁªÍøÎļþϵͳ(CIFS)£¬½«Ê¹Ô¶³ÌÓû§¿ÉÒÔ·ÃÎʱ¾µØÎļþ£¬µ«Ò²Ïò¹¥»÷Õß¿ª·ÅÁËϵͳ¡£
ÊÊÓÃÐÔ˵Ã÷¡ª¡ªËùÓеÄwindowsϵͳ¡£
·çÏÕ¡ª¡ªËÁŰһʱµÄSircamºÍNimdaÈ䳿²¡¶¾¶¼ÀûÓÃÕâһ©¶´½øÐй¥»÷ºÍ´«²¥£¬Òò´ËÓû§¶Ô´Ë¾ø¶Ô²»ÄܵôÒÔÇáÐÄ¡£
ÐÞ¸´·½·¨¡ª¡ªÏÞÖÆÎļþµÄ·ÃÎʹ²Ïí£¬²¢Ö¸¶¨Ìض¨IPµÄ·ÃÎÊÏÞÖÆÒÔ±ÜÃâÓòÃûÖ¸ÏòÆÛÆ¡£¹Ø±Õ²»±ØÒªµÄÎļþ·þÎñ£¬È¡ÏûÕâÒ»ÌØÐÔ²¢¹Ø±ÕÏàÓ¦¶Ë¿Ú¡£
×¢Ò»£ºSANS£¨System Administration£¬ Networking£¬ and Security-ϵͳ¹ÜÀí¡¢ÍøÂçºÍ°²È«Ñ§»á£©SANSºÍFBIÒÑ¾Â½ÐøÁªºÏ·¢±í¶à¸öÍøÂ簲ȫΣÏÕÃûµ¥£¬ÕâËÆºõÒѾ³ÉÁËÒ»¸ö¹ßÀý¡£
×¢¶þ£ºNull Session±»ÈÏΪÊÇWIN2K×Ô´øµÄÒ»¸öºóà |