October 29, 2008
通報簡述:
- 主旨:【數聯資安】資安預警通報:微軟 Windows Server Service (RPC) 允許惡意代碼執行
- 時間:2008/10/27
- 等級: 第二級(警告)
- 通報類別:弱點警報
- 編寫:G-Expert網路安全團隊-黃昭明
- 描述:
一改前例,微軟並非在每月的第二個星期二釋出修補程式,而是於 2008/10/23 緊急釋出 MS08-067 的修補程式,由此可知此弱點的重要性。
- 微軟 Windows Server Service被發現一項安全漏洞,允許遠端攻擊者對Remote Procedure Call (RPC)服務送出惡意RPC請求,可導致目標系統執行惡意程式碼。
此外,已出現第一支利用此漏洞,以植入木馬間諜的蠕蟲程式。
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 1
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP1 for Itanium-based Systems
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista and Windows Vista Service Pack 1
- Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for Itanium-based Systems
- 使用微軟相關修補程式,或利用Windows Update做相關軟體更新。
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
ISS產品相關防護:
-Content Version XPU 1.81
Proventia Network IDS
Proventia Network IPS
Proventia Network MFS
Proventia Server (Linux)
RealSecure Network
RealSecure Server Sensor
-Content Version 1820
Proventia Desktop
Proventia Server IPS (Windows)
若暫時無法修補時,可採取以下其中一種方式應急:
1.關閉 "Computer Browser Service" 與 "Server" 服務。
2.以本機防火牆限制TCP 139,445的可連線來源。
3.若作業系統為Windows Vista或Windows Server 2008,可藉由過濾RPC 代號 "4b324fc8-1670-01d3-1278-5a47bf6ee188" 禁止相關RPC存取。
上述應急措施操作步驟,請參閱微軟MS08-067通報之Wordgrounds部分:
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx#EMKAC
- Microsoft Security Bulletin MS08-067
Vulnerability in Server Service Could Allow Remote Code Execution (958644)
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx - Microsoft Windows Server Service RPC Code Execution
http://www.iss.net/threats/306.html - Vulnerability in Server Service Allows Code Execution (MS08-067)
http://www.securiteam.com/windowsntfocus/6G00Q0UMUG.html















