´òÓ¡

ARP¹¥»÷·À·¶´ëÊ©

ARP¹¥»÷·À·¶´ëÊ©

ARPÌØÕ÷£º
¸Ã²¡¶¾±äÖÖÓоÖÓòÍø¡°É±ÊÖ¡±Ö®³Æ£¬³ý¾ß±¸ÒÔÍùARP²¡¶¾·¢×÷µÄÌØÕ÷£¬ÖîÈ磺¾ÖÓòÍøÄÚ²¿·Ö¼ÆËã»ú²»ÄÜÕý³£ÉÏÍø£¬»òÊÇËùÓмÆËã»ú¾ù²»ÄÜÉÏÍø£¬»¹ÓÐÎÞ·¨´ò¿ª WebÍøÒ³»ò´ò¿ªWeb ÍøÒ³ËٶȽÏÂýÒÔ¼°¾ÖÓòÍøÁ¬½Óʱ¶ÏÊ±Ðø²¢ÇÒÍøËÙ½ÏÂýµÈÏÖÏóÒÔÍ⣬Ëü»¹»áÏò¾ÖÓòÍøÄÚ·¢ËÍαÔìµÄARPÆÛÆ­¹ã²¥£¬²¢½«ÊܸÐȾµÄ¼ÆËã»úϵͳαװ³É¾ÖÓòÍøÍø¹Ø£¬µ±¾ÖÓòÍøÖеļÆËã»úϵͳ·¢³ö·ÃÎÊWebÍøÒ³ÇëÇóµÄʱºò£¬Î±×°³ÉÍø¹ØµÄ¼ÆËã»úϵͳ»á°ÑWebÍøÒ³ÏÂÔØÏÂÀ´²¢ÔÚÆäÖÐÌí¼ÓÒ»¶Î¶ñÒâµØÖ·´úÂëÒ»²¢·¢Ë͸ø·¢³öÇëÇóµÄ¼ÆËã»ú£¬Ôì³É¸Ã¼ÆËã»úϵͳ·ÃÎÊWebÍøÕ¾Ê±»áÖ÷¶¯Á¬½Ó¸Ã¶ñÒâÍøÖ·¡£²¢ÇһᵼÖ¾ÖÓòÍøÄÚÈÎÒâµçÄÔ·ÃÎÊÍøÒ³Ê±£¬´ò¿ªµÄÍøÒ³¶¼±»É±¶¾Èí¼þ±¨¸æ´ø¶¾£¬Í¬Ê±¸Ã´ø¶¾ÍøÒ³»áͨ¹ý΢ÈíµÄMS06-014ºÍMS07-017Á½¸öϵͳ©¶´¸øµçÄÔÖ²ÈëÒ»¸öľÂíÏÂÔØÆ÷£¬¶ø¸ÃľÂíÏÂÔØÆ÷»áÏÂÔØ10¶à¸ö¶ñÐÔÍøÓÎľÂí£¬¿ÉÒÔµÁ¶à¿îÍøÂçÕ˺ż°ÃÜÂë¡£
·À·¶´ëÊ©£º
1¡¢Á¢¼´Éý¼¶²Ù×÷ϵͳÖеķÀ²¡¶¾Èí¼þºÍ·À»ðǽ£¬Í¬Ê±´ò¿ª¡°ÊµÊ±¼à¿Ø¡±¹¦ÄÜ£¬ÊµÊ±µØÀ¹½ØÀ´×Ô¾ÖÓòÍøÂçÉϵĸ÷ÖÖARP²¡¶¾±äÖÖ¡£
2¡¢Á¢¼´¸ù¾Ý×Ô¼ºµÄ²Ù×÷ϵͳ°æ±¾ÏÂÔØÎ¢ÈíMS06-014£¨http://www.microsoft.com/china/technet/security/bulletin/ms06-014.mspx£©ºÍMS07-017£¨http://www.microsoft.com/china/technet/security/bulletin/MS07-017.mspx£©Á½¸öϵͳ©¶´²¹¶¡³ÌÐò£¬½«²¹¶¡³ÌÐò°²×°µ½¾ÖÓòÍøÂçÖдæÔÚÕâÁ½¸ö©¶´µÄ¼ÆËã»úϵͳÖУ¬·ÀÖ¹²¡¶¾±äÖֵĸÐȾºÍ´«²¥¡£
3¡¢¼ì²éÊÇ·ñÒѾ­Öж¾£º
a. ÔÚÉ豸¹ÜÀíÆ÷ÖÐ, µ¥»÷¡°²é¿´¡ªÏÔʾÒþ²ØµÄÉ豸¡±
b. ÔÚÉ豸Ê÷½á¹¹ÖÐ,´ò¿ª¡°·Ç¼´²å¼´ÓÃÉ豸¡±
c. ²éÕÒÊÇ·ñ´æÔÚ£º¡°NetGroup Packet Filter Driver¡± »ò ¡°NetGroup Packet Filter¡±£¬Èç¹û´æÔÚ£¬¾Í±íÃ÷ÒѾ­Öж¾¡£
4¡¢¶ÔûÓÐÖж¾»úÆ÷£¬¿ÉÒÔÏÂÔØÈí¼þAnti ARP Sniffer£¬ÌîÈëÍø¹Ø£¬ÆôÓÃ×Ô¶¯·À»¤£¬±£»¤×Ô¼ºµÄipµØÖ·ÒÔ¼°Íø¹ØµØÖ·£¬±£Ö¤Õý³£ÉÏÍø¡£
5¡¢¶ÔÒѾ­Öж¾µçÄÔ¿ÉÒÔÓÃÒÔÏ·½·¨ÊÖ¶¯Çå³ý²¡¶¾£º
(1)ɾ³ý:%windows%\System32\LOADHW.EXE (ÓÐЩµçÄÔ¿ÉÄÜûÓÐ)
(2)a. ÔÚÉ豸¹ÜÀíÆ÷ÖÐ, µ¥»÷¡°²é¿´¡ªÏÔʾÒþ²ØµÄÉ豸¡±
b. ÔÚÉ豸Ê÷½á¹¹ÖÐ,´ò¿ª¡°·Ç¼´²å¼´ÓÃÉ豸¡±
c. ÕÒµ½ ¡°NetGroup Packet Filter Driver¡± »ò ¡°NetGroup Packet Filter¡±
d. ÓÒµã»÷£¬¡±Ð¶ÔØ¡±
e. ÖØÆôϵͳ
(3)ɾ³ý:%windows%\System32\drivers\npf.sys
(4)ɾ³ý%windows%\System32\msitinit.dll(ÓÐЩµçÄÔ¿ÉÄÜûÓÐ)
(5)ɾ³ý×¢²á±í·þÎñÏî:¿ªÊ¼¡µÔËÐСµregedit¡µ´ò¿ª£¬½øÈë×¢²á±í£¬È«×¢²á±íËÑË÷npf.sys£¬°ÑÎļþËùÔÚÎļþ¼ÐNpfÕû¸öɾ³ý.(Ó¦¸ÃÓÐ2¸ö).ÖÁ´Ëarp²¡¶¾Çå³ý.
(6)¸ù¾Ý¾­Ñé,¸Ã²¡¶¾»áÏÂÔØ´óÁ¿²¡¶¾,ľÂí¼°¶ñÒâÈí¼þ,²¢ÐÞ¸Äwinsocks,µ¼Ö²»ÄÜ´ò¿ªÍøÒ³,²»ÄÜ´ò¿ªnetmeetingµÈ,Ϊ´Ë»¹ÐèÒª×öÏÂÃæ¼¸²½¹¤×÷:
a.ÓÃÇåÀíÖúÊÖ,360µÈÈí¼þÇåÀí¶ñÒâÈí¼þ,ľÂí.
b.¼ì²é²¢É¾³ýÏÂÁÐÎļþ²¢Ïà¹ØÆô¶¯Ïî:
1)%windows%\System32\nwizwmgjs.exe(Ò»°ã***ë)
2)%windows%\System32\nwizwmgjs.dll(Ò»°ã***ë)
3)%windows%\System32\ravzt.exe(Ò»°ã***ë)
4)%windows%\System32\ravzt.dat
3)%windows%\System32\googleon.exe
c.ÖØÖÃwinsocks(¿ÉÒÔÓÃÍÃ×ÓµÈÈí¼þÐÞ¸´,ÏÂÃæ½éÉÜÒ»¸ö±È½Ï¼òµ¥µÄ°ì·¨):
¿ªÊ¼>ÔËÐÐ>CMD,½øÈëÃüÁîÌáʾ·û,ÊäÈëcd..»Ø³µ,Ò»Ö±Í˳öÖÁcÅ̸ùĿ¼,ÔÚC:>ÏÂÊäÈënetsh winsock reset»Ø³µ,È»ºó°´ÌáÊ¾ÖØÆô¼ÆËã»ú

TOP

²¡¶¾±äÖÖËÙ¶ÈÌ«¿ì£¬²»ÄÜÕÕ°áÇå³ý£¬²»¹ý˼·һÑù£¬Ð»Ð»

TOP

¹§Ï²Äú£¬ÄúÓöÉϲÆÉñÁË£¬Ë͸øÄã13Çìµä½ð±Ò£¡
dingdingding

TOP

¹§Ï²Äú£¬ÄúÓöÉϲÆÉñÁË£¬Ë͸øÄã28Çìµä½ð±Ò£¡
ÏÖÔڵIJ¡¶¾Ì«²þ¿ñÁË£¬¿´À´Å¼¸ÕÂòµÄ09°æÅµ¶ÙÓÖÊDz»´íµÄÑ¡ÔñçÛ£¬Åµ¶ÙÖÇÄÜɨÃè --- Òµ½ç¶À¾ß´´ÒâµÄÖÇÄܼ¼Êõ£¬Ö»É¨ÃèÓÐÍþвµÄÎļþ£¬Ê¹É¨ÃèÔÚ¸ü¾«×¼¸ü¿ìËÙ¼°¸ü¶Ìʱ¼äÄÚÍê³É¡£ÓÃ×Å»¹ÕæÊDz»Ò»°ã

TOP

¹§Ï²Äú£¬ÄúÓöÉϲÆÉñÁË£¬Ë͸øÄã10Çìµä½ð±Ò£¡
ÏÖÔÚÎÒµÄÍøÂçÖÐÒ²ÓÐARPÎÊÌ⣬ллÁË¡¤¡¤

TOP

arp²¡¶¾£¬Ó¦¸ÃÖ»ÒªÔÚ·ÓÉÆ÷ÉÏÃæÊµÐÐarpµÄmac°ó¶¨£¬Ó¦¸ÃÎÊÌâ²»´ó

TOP


¸ÐлһֱÒÔÀ´Äú¶ÔÎÒÃǵÄÖ§³Ö£¡
µ±Ç°Ê±Çø GMT+8, ÏÖÔÚʱ¼äÊÇ 2008-11-22 19:36 ¾©ICPÖ¤060528 ºÅ

Designed By 17DST