ARPÌØÕ÷£º
¸Ã²¡¶¾±äÖÖÓÐ
¾ÖÓòÍø¡°É±ÊÖ¡±Ö®³Æ£¬³ý¾ß±¸ÒÔÍùARP²¡¶¾·¢×÷µÄÌØÕ÷£¬ÖîÈ磺
¾ÖÓòÍøÄÚ²¿·Ö
¼ÆËã»ú²»ÄÜÕý³£ÉÏÍø£¬»òÊÇËùÓÐ
¼ÆËã»ú¾ù²»ÄÜÉÏÍø£¬»¹ÓÐÎÞ·¨´ò¿ª Web
ÍøÒ³»ò´ò¿ªWeb
ÍøÒ³ËٶȽÏÂýÒÔ¼°
¾ÖÓòÍøÁ¬½Óʱ¶ÏÊ±Ðø²¢ÇÒÍøËÙ½ÏÂýµÈÏÖÏóÒÔÍ⣬Ëü»¹»áÏò
¾ÖÓòÍøÄÚ·¢ËÍαÔìµÄARPÆÛƹ㲥£¬²¢½«ÊܸÐȾµÄ
¼ÆËã»úϵͳαװ³É
¾ÖÓòÍøÍø¹Ø£¬µ±
¾ÖÓòÍøÖеÄ
¼ÆËã»úϵͳ·¢³ö·ÃÎÊWeb
ÍøÒ³ÇëÇóµÄʱºò£¬Î±×°³ÉÍø¹ØµÄ
¼ÆËã»úϵͳ»á°ÑWeb
ÍøÒ³ÏÂÔØÏÂÀ´²¢ÔÚÆäÖÐÌí¼ÓÒ»¶Î¶ñÒâµØÖ·´úÂëÒ»²¢·¢Ë͸ø·¢³öÇëÇóµÄ
¼ÆËã»ú£¬Ôì³É¸Ã
¼ÆËã»úϵͳ·ÃÎÊWebÍøÕ¾Ê±»áÖ÷¶¯Á¬½Ó¸Ã¶ñÒâÍøÖ·¡£²¢ÇһᵼÖÂ
¾ÖÓòÍøÄÚÈÎÒâ
µçÄÔ·ÃÎÊ
ÍøÒ³Ê±£¬´ò¿ªµÄ
ÍøÒ³¶¼±»É±¶¾
Èí¼þ±¨¸æ´ø¶¾£¬Í¬Ê±¸Ã´ø¶¾
ÍøÒ³»áͨ¹ý
΢ÈíµÄMS06-014ºÍMS07-017Á½¸ö
ϵͳ©¶´¸ø
µçÄÔÖ²ÈëÒ»¸ö
ľÂíÏÂÔØÆ÷£¬¶ø¸Ã
ľÂíÏÂÔØÆ÷»á
ÏÂÔØ10¶à¸ö¶ñÐÔÍøÓÎ
ľÂí£¬¿ÉÒÔµÁ¶à¿î
ÍøÂçÕ˺ż°
ÃÜÂë¡£
·À·¶´ëÊ©£º
1¡¢Á¢¼´Éý¼¶²Ù×÷ϵͳÖеķÀ²¡¶¾Èí¼þºÍ
·À»ðǽ£¬Í¬Ê±´ò¿ª¡°ÊµÊ±¼à¿Ø¡±
¹¦ÄÜ£¬ÊµÊ±µØÀ¹½ØÀ´×Ô¾ÖÓòÍøÂçÉϵĸ÷ÖÖARP²¡¶¾±äÖÖ¡£
2¡¢Á¢¼´¸ù¾Ý×Ô¼ºµÄ²Ù×÷ϵͳ°æ±¾ÏÂÔØÎ¢ÈíMS06-014£¨
http://www.microsoft.com/china/technet/security/bulletin/ms06-014.mspx£©ºÍMS07-017£¨
http://www.microsoft.com/china/technet/security/bulletin/MS07-017.mspx£©Á½¸öϵͳ©¶´²¹¶¡
³ÌÐò£¬½«²¹¶¡
³ÌÐò°²×°µ½¾ÖÓòÍøÂçÖдæÔÚÕâÁ½¸ö©¶´µÄ¼ÆËã»úϵͳÖУ¬·ÀÖ¹²¡¶¾±äÖֵĸÐȾºÍ´«²¥¡£
3¡¢¼ì²éÊÇ·ñÒѾÖж¾£º
a. ÔÚÉ豸
¹ÜÀíÆ÷ÖÐ, µ¥»÷¡°²é¿´¡ªÏÔʾ
Òþ²ØµÄÉ豸¡±
b. ÔÚÉ豸Ê÷½á¹¹ÖÐ,´ò¿ª¡°·Ç¼´²å¼´ÓÃÉ豸¡±
c. ²éÕÒÊÇ·ñ´æÔÚ£º¡°NetGroup Packet Filter Driver¡± »ò ¡°NetGroup Packet Filter¡±£¬Èç¹û´æÔÚ£¬¾Í±íÃ÷ÒѾÖж¾¡£
4¡¢¶ÔûÓÐÖж¾»úÆ÷£¬¿ÉÒÔÏÂÔØÈí¼þAnti ARP Sniffer£¬ÌîÈëÍø¹Ø£¬ÆôÓÃ
×Ô¶¯·À»¤£¬±£»¤×Ô¼ºµÄipµØÖ·ÒÔ¼°Íø¹ØµØÖ·£¬±£Ö¤Õý³£ÉÏÍø¡£
5¡¢¶ÔÒѾÖж¾µçÄÔ¿ÉÒÔÓÃÒÔÏ·½·¨ÊÖ¶¯Çå³ý²¡¶¾£º
(1)ɾ³ý:%windows%\System32\LOADHW.EXE (ÓÐЩµçÄÔ¿ÉÄÜûÓÐ)
(2)a. ÔÚÉ豸¹ÜÀíÆ÷ÖÐ, µ¥»÷¡°²é¿´¡ªÏÔʾÒþ²ØµÄÉ豸¡±
b. ÔÚÉ豸Ê÷½á¹¹ÖÐ,´ò¿ª¡°·Ç¼´²å¼´ÓÃÉ豸¡±
c. ÕÒµ½ ¡°NetGroup Packet Filter Driver¡± »ò ¡°NetGroup Packet Filter¡±
d. ÓÒµã»÷£¬¡±Ð¶ÔØ¡±
e. ÖØÆôϵͳ
(3)ɾ³ý:%windows%\System32\drivers\npf.sys
(4)ɾ³ý%windows%\System32\msitinit.dll(ÓÐЩµçÄÔ¿ÉÄÜûÓÐ)
(5)ɾ³ý
×¢²á±í·þÎñÏî:¿ªÊ¼¡µÔËÐСµregedit¡µ´ò¿ª£¬½øÈë
×¢²á±í£¬È«
×¢²á±íËÑË÷npf.sys£¬°Ñ
ÎļþËùÔÚ
Îļþ¼ÐNpfÕû¸öɾ³ý.(Ó¦¸ÃÓÐ2¸ö).ÖÁ´Ëarp²¡¶¾Çå³ý.
(6)¸ù¾Ý¾Ñé,¸Ã²¡¶¾»áÏÂÔØ´óÁ¿²¡¶¾,ľÂí¼°¶ñÒâÈí¼þ,²¢ÐÞ¸Äwinsocks,µ¼Ö²»ÄÜ´ò¿ªÍøÒ³,²»ÄÜ´ò¿ªnetmeetingµÈ,Ϊ´Ë»¹ÐèÒª×öÏÂÃæ¼¸²½¹¤×÷:
a.ÓÃÇåÀí
ÖúÊÖ,360µÈÈí¼þÇåÀí¶ñÒâÈí¼þ,ľÂí.
b.¼ì²é²¢É¾³ýÏÂÁÐÎļþ²¢Ïà¹ØÆô¶¯Ïî:
1)%windows%\System32\nwizwmgjs.exe(Ò»°ã***ë)
2)%windows%\System32\nwizwmgjs.dll(Ò»°ã***ë)
3)%windows%\System32\ravzt.exe(Ò»°ã***ë)
4)%windows%\System32\ravzt.dat
3)%windows%\System32\googleon.exe
c.ÖØÖÃwinsocks(¿ÉÒÔÓÃÍÃ×ÓµÈÈí¼þÐÞ¸´,ÏÂÃæ½éÉÜÒ»¸ö±È½Ï¼òµ¥µÄ°ì·¨):
¿ªÊ¼>ÔËÐÐ>CMD,½øÈë
ÃüÁîÌáʾ·û,ÊäÈëcd..»Ø³µ,Ò»Ö±Í˳öÖÁcÅ̸ùĿ¼,ÔÚC:>ÏÂÊäÈënetsh winsock reset»Ø³µ,È»ºó°´ÌáÊ¾ÖØÆô¼ÆËã»ú