ÉîÈë½â¶Á£ºWindows HTTP.sysÔ¶³Ì´úÂëÖ´ÐÐÎó²î¸ú×ÙÏ£Íû
2015-04-17
´Ë´Î΢Èíͨ¸æMS15-034 IIS7 http.sysÎó²î£¬ÒýÀ´Òµ½çµÄ¹Ø×¢£¬ÆäÕðµ´ÐÔ²»ÑÇÓÚWindowsÁìÓòµÄÐÄÔà³öѪÊÂÎñ¡£AG¹«Ë¾¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄÆô¶¯½ôÆÈÏìÓ¦»úÖÆ£¬ÔÚ4ÔÂ15ÈÕ¡¢4ÔÂ16ÈÕ»®·ÖÐû²¼½ôÆÈͨ¸æ¼°²úÆ·¹æÔòÉý¼¶Í¨¸æ£¬ÊÜÈçÏÂϵͳӰÏìµÄÓû§»¹Ç뾡¿ìÉý¼¶³§É̵IJ¹¶¡¼°AG¹«Ë¾¿Æ¼¼²úÆ·¹æÔò°ü¡£
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2008 R2 SP1
Microsoft Windows 8.1
Microsoft Windows 8
Microsoft Windows 7 SP1
http.sysÎó²îÓ°Ïì¹æÄ£
Ëæ×Ÿ÷·½µÄÉîÈëÆÊÎö£¬¸÷µØÇøÊÜWindows HTTP.sysÎó²îÓ°ÏìµÄÇéÐÎÕýÔÚÖ𽥸¡³öË®Ãæ¡£×òÌìµÄͨ¸æÐÅÏ¢ÖÐÌáµ½Http.sysÊÇMicrosoft Windows´¦Öóͷ£HTTPÇëÇóµÄÄÚºËÇý¶¯³ÌÐò£¬¾ÝAG¹«Ë¾¿Æ¼¼»¥ÁªÍø¹ãÆ×ƽ̨Êý¾ÝÏÔʾ£¬È«Çò°²ÅÅIISµÄϵͳÊýÄ¿»òÐíÓÐ444ÍòÓ࣬´ÓÏÖÔÚÊÜÓ°ÏìµÄIIS¸÷°æÌìÖ°²¼Í³¼ÆÊý¾ÝÀ´¿´£¬ÆäÖÐIIS 7.5°²ÅÅÁ¿ÊÇÊ×λ£¬Õ¼±È42.3%£¬Ò²ÊDZ¾´Î×·×ÙÆÊÎöµÄÖØµã¡£
ÔÚÈçÏÂÈ«ÇòIIS7.5ÂþÑÜÌ¬ÊÆÍ¼ÖУ¬¿ÉÒÔ¿´µ½ÃÀÖÞ¡¢Å·ÖÞ¡¢ÑÇÖ޵ȹú¼ÒÊÜÓ°Ïì½ÏÁ¿ÑÏÖØ£¬ÆäÖÐÃÀ¹ú¡¢Öйú¡¢Ó¢¹ú¼°µÂ¹úΪÊÜÓ°ÏìµÄŨÃÜÇøÓò¡£
http.sysÎó²îΣº¦ÐÔÆÊÎö
Ðí¶à´óÐÍÆóÒµ»ò×éÖ¯ÔÚÓ¦¶Ôhttp.sysÎó²îµÄʱ¼ä£¬ÍùÍùÐèÒª½ÓÄÉÉóÉ÷µÄ̬¶È£¬¹ØÓÚÓ¦¶Ô²½·¥ÐèÒª£¬²¢ÇÒÍŽá×ÔÉíµÄÓªÒµÇéÐμ°ÍøÂçÇéÐΣ¬¶¨ÖÆÐж¯ÍýÏ룬ÒÔ×èÖ¹¶ÔӪҵϵͳÔì³ÉË𺦣¬Õâ¾ÍÐèÒªÉîÈëÏàʶ´Ë´ÎÎó²îµÄÔÀí£¬²Å»ª¸ø³öºÏÊʵļƻ®¡£Î´Öª¹¥ÑÉÖª·À£¡ÏÂÃæÁÙ´ËÎó²îµÄÔÀí¾ÙÐÐÆÊÎö£¬ÒÔ±ã¸÷È˸üºÃµÄÃ÷È·ºÍ·ÀÓùÕâÒ»¸ßΣÇå¾²Îó²î¡£
1¡¢Îó²î´¥·¢
ƾ֤PastebinÉÏÅû¶µÄPoC£¨http://pastebin.com/ypURDPc4£©£¬ºÜÈÝÒ׽ṹ³öÄÜ´¥·¢BSODµÄPoC£¬ºÃ±ÈÒÔÏÂÇëÇó£º
GET /welcome.png HTTP/1.1
Host: PoC
Range: bytes=12345-18446744073709551615
¿ÉÒÔʹװÖÃÓÐIIS 7.5µÄWindows 7 SP1ϵͳBSOD¡£
2¡¢Îó²îÔÀí
ÕâÀïÒÔWindows 7 SP1 X64ϵͳÉÏ×°ÖõÄIIS 7.5ΪÀý¾ÙÐÐÆÊÎö£¬ÆäÄں˵İ汾Ϊ6.1.7601.18409£¬HTTP.sysµÄ°æ±¾Îª6.1.7601.17514¡£
¶ÔBSODÍß½âµÄÏÖ³¡¾ÙÐÐÆÊÎö£¬·¢Ã÷ÊÇÖÖÖÖÇéÐεÄÄÚ´æ¹ýʧ£¬ÓÉ´ËÍÆ²â´¥·¢Îó²îºó¿ÉÄÜÔì³ÉÁËÄÚ´æÆÆËð¡£¶ÔHTTP.sysµÄ´¦Öóͷ£Á÷³Ì¾ÙÐÐÆÊÎö¡¢Öð²½ÅŲ飬¿ÉÒÔÈ·¶¨ÄÚ´æÆÆË𱬷¢ÔÚº¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÖУ¬Å²ÓÃÕ»ÈçÏ£º
º¯ÊýHTTP!UlBuildFastRangeCacheMdlChainÓÃÓÚÌìÉúÏìÓ¦±¨ÎĵĻº´æMDLÁ´£¬À´ÐÎòHTTPÏìÓ¦µÄ״̬ÐС¢Í·²¿ÓëÐÂÎÅÌ壬Á´Éϵĸ÷MDLͨ¹ýŲÓÃnt! IoBuildPartialMdlÀ´ÌìÉú¡£
MSDNÖжÔnt! IoBuildPartialMdlµÄ˵Ã÷ÈçÏ£º
×¢ÖØÕâÀïÃ÷È·ÒªÇóÁËÓÉVirtualAddressÓëLengthÈ·¶¨µÄÇø¼ä±ØÐèÊÇSourceMdlÐÎòµÄ»º³åÇøµÄÒ»¸ö×ÔÇø¼ä£¬ÕýÊǶԴËÒªÇóµÄÎ¥·´µ¼ÖÂÁË´ËÎó²îÖеÄÄÚ´æÆÆËð¡£
µÚ3´ÎŲÓÃnt! IoBuildPartialMdlÀ´ÌìÉúÐÂÎÅÌåMDLʱµÄ²ÎÊýÈçÏ£º
SourceMdl = 0xfffffa801a38cb60
SourceMdl.VirtualAddress = 0xfffffa801ac94000
SourceMdl.ByteCount = 0x2d315
SourceMdl.ByteOffset = 0x0
TargetMdl = 0xfffffa801a2ed580
TargetMdl.VirtualAddress = 0xfffffa801ac97000
TargetMdl.ByteCount = 0xffffcfc7
TargetMdl.ByteOffset = 0x39
VirtualAddress = 0xfffffa801ac97039
Length = 0xffffcfc7
ÕâÀïµÄLengthÊÇÆ¾Ö¤HTTPÇëÇóÐÂÎÅÍ·²¿ÖеÄRange×Ö¶ÎÅÌËã»ñµÃµÄ£¬Àú³ÌÈçÏ£º
Ê×ÏÈ£¬ÔÚHTTP!UlpParseRangeÖжÔRange×ֶξÙÐÐÆÊÎö£¬»ñµÃRangeBegin¡¢RangeEnd£»
È»ºó£¬ÅÌËãRangeLength = RangeEnd - RangeBegin + 1£»
×îºó£¬½«RangeLength½Ø¶ÏΪ32λ»ñµÃLength¡£
ÒÔPoCÖеÄRange: bytes=12345-18446744073709551615ΪÀý£º
RangeBegin = 12345 = 0x3039
RangeEnd = 18446744073709551615 = 0xffffffffffffffff
RangeLength = 0xffffffffffffffff - 0x00003039 + 1 = 0xffffffffffffcfc7
Length = 0xffffcfc7
ÏÔÈ»ÓÉÓÚLength³¬³¤¶øµ¼ÖÂÎ¥·´ÁËnt! IoBuildPartialMdlµÄÒªÇ󣬽ø¶øÔì³ÉÄÚ´æÆÆËð¡£
3¡¢ÏÞÖÆÌõ¼þ
HTTP.sysÖеÄһЩУÑé²½·¥¿ÉÄÜÔÚ½øÈëHTTP!UlBuildFastRangeCacheMdlChainº¯Êýǰ½«RangeLengthÐÞ¸ÄΪÕýµ±Öµ£¬´Ó¶ø²»»á´¥·¢Îó²î¡£
ÀýÈ磬ÔÚWindows 7 SP1 X64ϵͳµÄIIS 7.5ÖУ¬º¯ÊýHTTP!UlAdjustRangesToContentSize»á¶ÔRangeLength¾ÙÐмì²é£¬²¢ÔÚÐëҪʱ¾ÙÐе÷½â£¬ÈçÏ£º
µ±RangeBegin >= ContentLengthʱ£¬ÒƳý¶ÔÓ¦µÄÊý¾Ý£»
µ±RangeLength== -1ʱ£¬RangeLength= ContentLength ¨C RangeBegin£»
µ±RangeEnd + 1 >= ContentLengthʱ£¬RangeLength= ContentLength ¨C RangeBegin£»
Òò´Ë£¬Òª¼á³ÖRangeLength²»±»ÐÞÕý¶øÓÖÄÜ´¥·¢Îó²î£¬±ØÐèҪͬʱ֪×ãRangeEnd + 1 < ContentLengthÓëRangeEnd > ContentLength£¬RangeEnd¾ÍÖ»ÄÜΪ0xffffffffffffffff¡£
ÕâÑù£¬RangeBegin¾Í±ØÐèСÓÚContentLength£¬Í¬Ê±»¹²»¿ÉΪ1£¨²»È»½«Ê¹RangeLength = 0xffffffffffffffff ¨C 1 + 1 = -1¶øµ¼ÖÂRangeLength±»ÐÞÕý£©¡£
ÔÚÆäËû°æ±¾µÄϵͳÖпÉÄÜ»áÓиü¶àµÄÏÞÖÆ¡£
4¡¢´úÂëÖ´ÐÐ
´ÓÉÏÊöÆÊÎö¿ÉÒÔ¿´³ö£¬´¥·¢´ËÎó²î¿ÉÔ½½çдÊý¾Ý¶øÔì³ÉÄÚ´æÆÆËð£¬ÀíÂÛÉϱ£´æÔ¶³ÌÖ´ÐдúÂëµÄ¿ÉÄÜÐÔ¡£¿ÉÊÇÔ½½çËùдÊý¾ÝµÄ³¤¶ÈÏÂÏÞÓÉContentLength¾öÒ飬ͨ³£»áÊÇÒ»¸ö½Ï´óµÄÖµ¶øÁ¢×ÝȻϵͳÍ߽⡣×ÝȻĿµÄ·þÎñÆ÷Éϱ£´æÒ»Ð©´óµÄÎļþ£¬¿ÉÒÔÓÃÀ´Ô½½çдÉÙÁ¿Êý¾Ý£¬ËùдÊý¾ÝÄÚÈÝÓë±»ÁýÕÖÄ¿µÄÒ²ºÜÄÑ¿ØÖÆ¡£Òò´Ë£¬ÔÚÏÖÕæÏàÐÎÖÐÏëÒªÎȹ̵ÄʹÓôËÎó²îÀ´Ö´ÐдúÂëÊǺÜÊÇÄÑÌâµÄ¡£
Óëhttp.sysÎó²î¹¥»÷ÈüÅÜ
ͨ¹ýÇ°ÃæµÄÆÊÎö¿ÉÒÔ¿´µ½£¬Ê¹ÓôËÎó²îµÄ¹¥»÷´óÖ»áÓÐÁ½ÖÖÐÎʽ£º1ÖÖÄѶȽÏÁ¿µÍ£¬ºÜÈÝÒ×µ¼Ö·þÎñÆ÷ϵͳÀ¶ÆÁ£»2ÈôÊǹ¥»÷ÕßµÄˮƽ½ÏÁ¿¸ß£¬¾Í¿ÉÒÔ׼ȷµÄ¿ØÖÆÄڴ棬ͨ¹ýÔ¶³ÌÖ´ÐдúÂ룬½ø¶ø»ñµÃ¶ÔϵͳµÄÍêÈ«¿ØÖÆ¡£ÓÈÆäÊÇÃæÁٸ߼ÛÖµ»Ø±¨µÄ¹¥»÷Ä¿µÄʱ£¬±¬·¢µÄ¼¸Âʾ͸ü¸ßÁË£¬ÆóÒµ»ò×éÖ¯µÄITÖ°Ô±ÐèÒª¾¡¿ì˼Á¿Ó¦¶Ô¼Æ»®£¬×èÖ¹ÔÚÇå¾²·ÀÓù²½·¥ÉÏÏß֮ǰÔâÊܹ¥»÷¡£ÕâÖÁÉÙÓ¦¸Ã°üÀ¨ÈçÏ»·½Ú£º
- l Ê×ÏÈ£¬Ó¦¸ÃÂíÉÏ»ñÈ¡Îó²îͨ¸æ¼°Ïà¹ØÐÅÏ¢£¬Ïàʶ´Ë´ÎÎó²îµÄÓ°Ïì¹æÄ£¼°Éî¶È¡£
- l ÔÙÕߣ¬ÐèÒª½«Í¨¸æÏ¢Õù¶ÁÓë×ÔÉíÏÖʵITӪҵϵͳ״̬ÏàÍŽᣬÖÜÈ«ÅжϳöÓ°Ïì¹æÄ£ºÍˮƽ£¨Õâ°üÀ¨¶Ô×ÔÉíÓªÒµ¼°¶ÔÆä¿Í»§µÄÓ°Ïìˮƽ£©£¬Õâ¸öÅжÏÀú³Ì£¬ÐèÒªÊý¾Ý×÷Ϊ׼ȷ¼Æ»®Öƶ©µÄÊÂʵÒÀ¾Ý£¬½¨ÒéÓû§Ê¹ÓÃÇå¾²¿É¿¿µÄÎó²îɨÃ蹤¾ß£¬Éý¼¶µ½ÐÂÐû²¼µÄ²å¼þ»ò¹æÔò¿â£¬¶ÔÈ«Íø¾ÙÐÐÇ徲ɨÃ裬Äõ½Ò»ÊÖÊý¾ÝºóÒÔ±ã×÷Ϊ¾öÒéÒÀ¾Ý£»
- l ÔٴΣ¬ITÖ°Ô±ÐèÒª´ÓÒµÎñÎȹÌÐÔ¡¢Î£º¦Ë®Æ½ºÍ¹æÄ£¼°Ö÷ÒªÐԵȶà¸öά¶È×ÛºÏ˼Á¿£¬Öƶ©Õû¸Äʱ¼äÍýÏë±í£¬È¨ÖØÓɸߵ½µÍÒÀ´Î¶Ô¾Ö²¿ÍøÂç¼°Ö÷»ú×°±¸»òijӪҵϵͳװ±¸Õö¿ªÕû¸ÄºÍ¼Ó¹ÌÊÂÇ飨½¨ÒéÔ¼ÇëÎó²îÏà¹Ø³§É̼°Çå¾²³§ÉÌһͬ¼ÓÈ룩¡£
n Õâ¸ö½×¶ÎÐèÒªÇå¾²³§ÉÌÌṩרҵÊÖÒÕÐÖú£¬ºÃ±ÈÎó²î¼Ó¹Ì×Éѯ¡¢ÑéÖ¤¼Ó¹ÌÊÇ·ñÀֳɣ»Í¬Ê±ÐèÒªÏàʶÇå¾²³§É̵ÄÄÄЩװ±¸ÒѾÐû²¼»ò¼´½«Ðû²¼·À»¤¹æÔò£¬Éý¼¶ºó¼´¿É¾ÙÐзÀ»¤£»
n ÈôÊÇ»¹Ã»ÓнÓÄÉÈκÎÒ»¿îÇå¾²×°±¸£¬¾ÍÐèÒª½ÓÄÉÔÝʱ·À»¤²½·¥£¬°üÀ¨½ÓÄÉÎó²îÏà¹Ø³§É̼°Çå¾²³§É̵ÄÏà¹Ø¼Æ»®£¬ÎªÕûÌå¼Ó¹ÌÕùȡʱ¼ä£¬×èÖ¹ÔÚδ¼Ó¹ÌÕû¸ÄÀÖ³É֮ǰÕâ¸ö´°¿Úʱ¼äÔâµ½¹¥»÷²¢Êܵ½Ëðʧ£¬ÕâÑùµÄÇéÐÎÔÚÏ൱¶àµÄ0dayÊÂÎñÖÐ˾¿Õ¼û¹ß£»
n ÁíÍ⣬»¹ÐèÒªÎó²îÏà¹Ø³§ÉÌÓëÇå¾²³§ÉÌͨÁ¦Ð×÷£¬Ï໥ÏàͬÎó²îÔÀíºÍʹÓÃÀú³Ì£¬¾ÙÐнÏÉîÌõÀíµÄ½â¶Á£¬²Å»ª¹»Ôö½øÎó²îÏà¹Ø³§É̵Ŀª·¢Ö°Ô±ÉîÈëÏàʶÕâ¸öÎó²î²¢Æ¾Ö¤Æä×ÔÉíÇéÐξÙÐдúÂë²ãÃæµÄÕû¸Ä£»
- l È»ºó£¬Ôڼӹ̽׶ÎÐÔ»òÕûÌåÍê³Éºó£¬ÐèÒªÔٴξÙÐÐÍêÕûɨÃèºÍÈ˹¤ÑéÖ¤Õû¸Ä¼Ó¹ÌЧ¹û£¬ÔÚÊÖÒÕͶÈëÔÊÐíµÄÌõ¼þÏ£¬½¨ÒéÄúÔٴξÙÐи÷·½ÃæÈÕÖ¾ÆÊÎö£¬ÊÓ²ìÕû¸Ä¼Ó¹Ìʱ´úÓÐûÓÐÀֳɵĹ¥»÷µ½ÆäϵͳÔì³ÉÆäËûËðʧ£»
- l ×îºó£¬ÔÚÕûÌåÏìÓ¦ÊÂÇéÍê³Éºó£¬¾ÙÐÐ×ܽáºÍ±¸°¸¼Í¼¡£
IISÎó²îÇéÐÎ
ǰ³µÖ®¼øºóÊÂ֮ʦ£¬IISÓÉÓÚʹÓÃÁ¿½Ï´ó£¬·ºÆðµÄÎÊÌâ²»ÉÙ£¬×ÜÊǸøÈËÒÔ²»ÔúʵµÄ¸ÐÊÜ¡£×ÅʵÔÚ2014Ä꣬΢ÈíIIS¾Í·ºÆðÁËÁ½¸ö¸ßΣÎó²î£¬ÆäÖеÚ2¸öÇÒÏÖÔÚ³§ÉÌ»¹Ã»ÓÐÌṩ²¹¶¡»òÕßÉý¼¶³ÌÐò£¬ÎÒÃǽ¨ÒéʹÓÃÕâЩIIS°æ±¾µÄÓû§ËæÊ±¹Ø×¢³§É̵ÄÖ÷Ò³ÒÔ»ñÈ¡×îа汾£¬²¢×ÉѯAG¹«Ë¾¿Æ¼¼µÄ·þÎñÖ°Ô±£¡
1. 2014-11-11£¬IISÇå¾²¹¦Ð§ÈƹýÎó²î£¨MS14-076£©£¨CVE-2014-4078£©
ÐÎò£ºIIS 8.0/8.5°æ±¾µÄIPÇå¾²¹¦Ð§Ã»ÓÐÆ¾Ö¤"IP Address and Domain Restrictions"Áбí׼ȷ´¦Öóͷ£½øÕ¾WebÇëÇó£¬Õâ¿ÉʹԶ³Ì¹¥»÷Õßͨ¹ýHTTPÇëÇó£¬Ê¹ÓôËÎó²îÈÆ¹ýÄ¿µÄ¹æÔò.
2. 2014-04-02£¬CGI CRLF×¢ÈëÎó²î£¨CVE-2011-5279£©
ÐÎò£ºWindows NT¼°Windows 2000ÉÏIIS 4.x¼°5.x°æ±¾µÄCGIʵÏÖÖб£´æCRLF×¢ÈëÎó²î£¬Õâ¿ÉʹԶ³Ì¹¥»÷Õßͨ¹ýCGIÇëÇóÖÐµÄ ×Ö·û£¨ÐÂÐУ©½á¹¹»ûÐÎÇëÇóÐÞ¸ÄÇéÐαäÁ¿£¬´Ó¶ø½øÒ»²½Ö´ÐÐí§Òâ´úÂë¡£
±ðµÄ£¬IISÔÚÆäÀúÊ·ÉÏÒ²³ö¹ýÒ»ÔÙÖØ´óÎó²î£¬AG¹«Ë¾¿Æ¼¼Ñо¿ÔºÌØÊâÕûÀíÁËÕâЩÐÅÏ¢£¬±ãÓÚÆóÒµºÍ×éÖ¯µÄITÖ°Ô±½è¼ø¡£ÒÔϼӴÖ×ÖÌ壬ΪÏÖÔÚ³§ÉÌ»¹Ã»ÓÐÌṩ²¹¶¡»òÕßÉý¼¶³ÌÐòµÄÎó²î£¬ÇëÓèÒÔÌØÊâ¹Ø×¢£º
1. 2010-09-14 Microsoft IIS FastCGIÇëÇóÍ·Ô¶³ÌÒç³öÎó²î£¨MS10-065£©£¨CVE-2010-2730£©
ÐÎò£º¹ØÓÚÆôÓÃÁËFastCGI¹¦Ð§µÄIIS·þÎñÆ÷£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÌá½»ÌØÖÆµÄHTTPÇëÇó´¥·¢»º³åÇøÒç³ö£¬µ¼ÖÂÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
2. 2010-06-08 Microsoft IISÈÏÖ¤ÁîÅÆ´¦Öóͷ£Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨MS10-040£©£¨CVE-2010-1256£©
ÐÎò£ºIIS Web·þÎñÆ÷ÔÚÆÊÎö´Ó¿Í»§¶ËËùÎüÊÕµ½ÁËÈÏÖ¤ÐÅϢʱûÓÐ׼ȷµØ·ÖÅÉÄڴ棬Զ³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËÍÌØÖÆµÄÈÏÖ¤±¨Îĵ¼ÖÂÒÔÊÂÇéÀú³Ì±êʶ£¨WPI£©µÄÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£±ØÐèÆôÓÃÁËExtended Protection for Authentication¹¦Ð§²Å¿ÉÒÔʹÓÃÕâ¸öÎó²î£¨Ä¬ÒÔΪ½ûÓã©¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
3. 2009-10-13 Microsoft IIS FTPd·þÎñNLSTÏÂÁîÔ¶³ÌÕ»Òç³öÎó²î£¨MS09-053£©£¨CVE-2009-3023£©
ÐÎò£º¹¥»÷Õß¿ÉÒÔµ¼Ö¾ܾø·þÎñ»òÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£Microsoft IISÄÚǶµÄFTP·þÎñÆ÷Öб£´æÕ»Òç³öÎó²î¡£ÈôÊÇÔ¶³Ì¹¥»÷Õß¶Ô´øÓÐÌØÖÆÃû³ÆµÄĿ¼Ðû²¼Á˰üÀ¨ÓÐͨÅä·ûµÄFTP NLST£¨NAME LIST£©ÏÂÁîµÄ»°£¬¾Í¿ÉÒÔ´¥·¢Õâ¸öÒç³ö£¬µ¼Ö¾ܾø·þÎñ»òÖ´ÐÐí§Òâ´úÂë¡£½öÔÚ¹¥»÷ÕßÓµÓÐд»á¼ûȨÏÞµÄÇéÐÎϲſÉÒÔ½¨Éè´øÓÐÌØÊâÃû³ÆµÄĿ¼¡£¹¥»÷Õß¿ÉÒÔµ¼Ö¾ܾø·þÎñ»òÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
4. 2009-09-15 Microsoft IIS¾ç±¾ÎļþÃû¹ýʧÆÊÎöÎó²î
ÐÎò£ºIISÔÚ´¦Öóͷ£¾ç±¾ÎļþÃûµÄÆÊÎöʱ±£´æÎó²î£¬µ±ÎļþÃûΪ[YYY].asp;[ZZZ].jpgÐÎʽʱ£¬IIS»á×Ô¶¯ÒÔaspÃûÌÃÀ´¾ÙÐÐÆÊÎö£¬¶øµ±ÎļþÃûΪ[YYY].php;[ZZZ].jpgÐÎʽʱ£¬IIS»á×Ô¶¯ÒÔphpÃûÌÃÀ´¾ÙÐÐÆÊÎö£¨ÆäÖÐ[YYY]Óë[ZZZ]Ϊ¿Éת±ä×Ö·û´®£©¡£Ô¶³Ì¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÍ»ÆÆWebÓ¦ÓöÔÉÏ´«ÎļþÀàÐ͵ÄÏÞÖÆ£¬ÔÚ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ¾ç±¾´úÂë´Ó¶ø»ñÈ¡¶Ô·þÎñÆ÷µÄ¿ØÖÆ¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
5. 2009-06-09 Microsoft IIS 5.0 WebDAVÈÆ¹ýÈÏÖ¤Îó²î£¨MS09-020£©£¨CVE-2009-1122£©
ÐÎò£ºIISµÄWebDAVÀ©Õ¹Ã»ÓÐ׼ȷ½âÂëÌØÖÆÇëÇóµÄURL£¬µ¼ÖÂWebDAVÔÚ´¦Öóͷ£¸ÃÇëÇóʱӦÓò»×¼È·µÄÉèÖá£ÈôÊÇÓ¦ÓõÄÉèÖÃÔÊÐíÄäÃû»á¼û£¬ÔòÌØÖÆµÄÇëÇó¿ÉÒÔÈÆ¹ýÉí·ÝÑéÖ¤¡£Çë×¢ÖØIISÔÚÉèÖõÄÄäÃûÓû§ÕÊ»§µÄÇå¾²ÉÏÏÂÎÄÖÐÈԻᴦÖóͷ£¸ÃÇëÇó£¬Òò´Ë´ËÎó²î²»¿ÉÓÃÓÚÈÆ¹ýNTFS ACL£¬ÎļþϵͳACL¶ÔÄäÃûÓû§ÕÊ»§Ç¿¼ÓµÄÏÞÖÆ½«ÈÔȻִÐС£¹¥»÷Õß¿ÉÒÔÈÆ¹ýÈÏÖ¤»ñµÃ·ÇÊÚȨ»á¼û¡£
6. 2009-06-09 Microsoft IIS WebDAV UnicodeÇëÇóÈÆ¹ýÈÏÖ¤Îó²î£¨MS09-020£©£¨CVE-2009-1535£©
ÐÎò£ºIISµÄWebDAV¹¦Ð§ÔÚÆÊÎöURI²¢·¢ËÍ»ØÊý¾ÝʱûÓÐ׼ȷµØ´¦Öóͷ£UnicodeÁîÅÆ»·£¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÌá½»¶ñÒâHTTP GETÇëÇóÈÆ¹ýÊÜ¿ÚÁî±£»¤µÄÎļþ¼ÐµÄÈÏÖ¤£¬»òÔÚÊÜ¿ÚÁî±£»¤µÄWebDAVĿ¼ÖÐÁгö¡¢ÉÏ´«»òÏÂÔØÎļþ¡£¹¥»÷Õß¿ÉÒÔÈÆ¹ýÈÏÖ¤Ö´ÐзÇÊÚȨ²Ù×÷¡£
7. 2008-02-12 Microsoft IIS ASPÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨MS08-006£©£¨CVE-2008-0075£©
ÐÎò£ºIIS´¦Öóͷ£ASPÍøÒ³ÊäÈëµÄ·½·¨±£´æÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¬ÔÊÐí¹¥»÷ÕßÏòÍøÕ¾µÄASPÒ³Ãæ´«ËͶñÒâÊäÈë¡£ÀÖ³ÉʹÓÃÕâ¸öÎó²îµÄ¹¥»÷Õß¿ÉÒÔÔÚIIS·þÎñÆ÷ÉÏÒÔWPIµÄȨÏÞ£¨Ä¬ÈÏÉèÖÃÎªÍøÂç·þÎñÕʺÅȨÏÞ£©Ö´ÐÐí§Òâ²Ù×÷¡£¹¥»÷Õß¿ÉÒÔÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£
ÇëÒ»Á¬¹Ø×¢ÍþвÇ鱨
AG¹«Ë¾¿Æ¼¼Ñо¿Ôº»á³¤Äê¸ú×ÙÆÊÎöÕâЩÎó²î£¬²¢½«ÕûÀíºóµÄЧ¹û·¢Ë͸øÄú£¬±ãÓÚÄúÒ»Á¬¹Ø×¢Îó²îµÄÉú³¤Ì¬ÊÆ£¬ÎªÆóÒµ¼°×éÖ¯µÄÇå¾²¼Æ»®ÌṩÊý¾Ý¼°ÐÅÏ¢Ö§³Ö£¬ÈôÊÇÄú¶ÔÎÒÃÇÌṩµÄÄÚÈÝÓÐÈκÎÒÉÎÊ£¬»òÕßÐèÒªÏàʶ¸ü¶àµÄÐÅÏ¢£¬¿ÉÒÔËæÊ±Í¨¹ýÔÚ΢²©¡¢Î¢ÐÅÖÐËÑË÷AG¹«Ë¾¿Æ¼¼ÁªÏµAG¹«Ë¾£¬½Ó´ýÄúµÄ´¹Ñ¯£¡

AG¹«Ë¾ÔÆ





