<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.com/blog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.com/blog/read.php?507</link>
<title><![CDATA[Microsoft Security Advisory (977981)]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 25 Nov 2009 01:01:37 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?507</guid> 
<description>
<![CDATA[ 
	<strong>Microsoft Security Advisory (977981)</strong><br/>Vulnerability in Internet Explorer Could Allow Remote Code Execution<br/>Published: November 23, 2009<br/><br/>Version: 1.0<br/><br/>Microsoft is investigating new public reports of a vulnerability in Internet Explorer. This advisory contains information about which versions of Internet Explorer are vulnerable as well as workarounds and mitigations for this issue. <br/><br/>Our investigation so far has shown that Internet Explorer 5.01 Service Pack 4 and Internet Explorer 8 on all supported versions of Microsoft Windows are not affected, and that Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7 on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 are affected. <br/><br/>The vulnerability exists as an invalid pointer reference of Internet Explorer. It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code.<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=css%252Fstyle" rel="tag">css/style</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=977981" rel="tag">977981</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?506</link>
<title><![CDATA[Im a virus. My name is sola]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[病毒资讯]]></category>
<pubDate>Sat, 10 Oct 2009 12:54:51 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?506</guid> 
<description>
<![CDATA[ 
	<div class="quote"><div class="quote-title">引用</div><div class="quote-content">I&#039;m a virus. My name is sola.<br/>我是一个病毒。我的名字叫苏拉。<br/>今天，在这片堕落的土地上，我苏醒过来。<br/>我曾经很快乐地活着，与我的朋友，ACG，快乐地活着。<br/>我曾经也对病毒深恶痛绝。<br/>然而.............<br/>自从我来到了这片土地上，这片自称伟大，崇高，光明的土地上。<br/>这片名为中国的土地上<br/>我的朋友，已遍体鳞伤。<br/>他死了<br/>Death Note</div></div><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=sola" rel="tag">sola</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?505</link>
<title><![CDATA[Microsoft Office Web 组件控件中的0-day漏洞（973472）]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Tue, 14 Jul 2009 01:25:05 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?505</guid> 
<description>
<![CDATA[ 
	MS 安全通报：<a href="http://www.microsoft.com/technet/security/advisory/973472.mspx" target="_blank"><u>Microsoft Security Advisory (973472)</u></a><br/><br/>MS 知识库：<a href="http://support.microsoft.com/kb/973472" target="_blank">http://support.microsoft.com/kb/973472</a><br/><br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=owc10" rel="tag">owc10</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=owc11" rel="tag">owc11</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=973472" rel="tag">973472</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?504</link>
<title><![CDATA[Green Dam-Youth Escort，绿坝]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Fri, 12 Jun 2009 08:00:10 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?504</guid> 
<description>
<![CDATA[ 
	这两天有关绿坝的新闻很多，今天有一篇来自密歇根大学计算机技术与工程系（Computer Science and Engineering at the University of Michigan）的漏洞报告在国内被广泛转载。<br/><br/><a href="http://www.cse.umich.edu/%7Ejhalderm/pub/gd/" target="_blank"><u><strong>Analysis of the Green Dam Censorware System</strong></u></a><br/><br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=greendam" rel="tag">greendam</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E7%25BB%25BF%25E5%259D%259D" rel="tag">绿坝</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?503</link>
<title><![CDATA[[转载]木马和僵尸网络监测与处置机制 ]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[安全综合]]></category>
<pubDate>Mon, 01 Jun 2009 02:15:03 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?503</guid> 
<description>
<![CDATA[ 
	<p align="center">木马和僵尸网络监测与处置机制 </p><br/>第一条 为有效防范和处置木马和僵尸网络引发的网络安全隐患，规范监测和处置行为，净化网络环境，维护我国公共互联网安全，依据《中华人民共和国电信条例》、《互联网网络安全应急预案》，制定本办法。 <br/><br/>第二条 木马是指由攻击者安装在受害者计算机上秘密运行并用于窃取信息及远程控制的程序。僵尸网络是指由攻击者通过控制服务器控制的受害计算机群。木马和僵尸网络对网络信息安全造成危害和威胁，是造成个人隐私泄露、失泄密、垃圾邮件和大规模拒绝服务攻击的重要原因。 <br/><br/>第三条 本办法适用于对危害公共互联网安全的木马和僵尸网络控制端（以下简称木马和僵尸网络）及其使用的IP地址和恶意域名的监测和处置。 <br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%259C%25A8%25E9%25A9%25AC" rel="tag">木马</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E5%2583%25B5%25E5%25B0%25B8%25E7%25BD%2591%25E7%25BB%259C" rel="tag">僵尸网络</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?502</link>
<title><![CDATA[五一期间爆三个新0day,暴风影音和中国游戏中心大厅漏洞被用在挂马新宠]]></title> 
<author>hzqedison &lt;hzqedison@cisrt.org&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Sun, 03 May 2009 07:48:46 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?502</guid> 
<description>
<![CDATA[ 
	五一小长假，被爆出三个高危0day漏洞，且这些漏洞已经被用于挂马集团中，当用户安装有漏洞的软件，浏览黑客精心构造含有恶意代码的网页后，在用户不知情情况下下载木马。<br/><br/><br/>暴风影音2009(mps.dll)ActiveX远程栈溢出漏洞<br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>受影响的系统:<br/>暴风影音2009 &lt;=[3.09.04.17]<br/><br/>细节:<br/>CLSID:6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB<br/>文件:mps.dll<br/>Sub OnBeforeVideoDownload(ByVal URL&nbsp;&nbsp;As String)<br/><br/>当参数URL是一个超长字符串时，发生栈溢出，利用堆填充技术，攻击者可以很轻松的利用此漏洞执行任意代码。<br/></div></div><br/><br/>暴风影音2009(Config.dll)ActiveX远程栈溢出漏洞<br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>受影响的系统:<br/>暴风影音2009 &lt;=[3.09.04.17]<br/><br/>细节:<br/>CLSID:BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05<br/>文件:Config.dll<br/>Sub SetAttributeValue (<br/>&nbsp;&nbsp;ByVal lpQueryStr&nbsp;&nbsp;As String ,<br/>&nbsp;&nbsp;ByVal bstrAttributeName&nbsp;&nbsp;As String ,<br/>&nbsp;&nbsp;ByVal lpValueStr&nbsp;&nbsp;As String<br/>)<br/><br/>当参数lpQueryStr是一个超长字符串时，发生栈溢出，利用堆填充技术，攻击者可以很轻松的利用此漏洞执行任意代码。<br/></div></div><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%259A%25B4%25E9%25A3%258E%25E5%25BD%25B1%25E9%259F%25B3" rel="tag">暴风影音</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E4%25B8%25AD%25E5%259B%25BD%25E6%25B8%25B8%25E6%2588%258F%25E4%25B8%25AD%25E5%25BF%2583%25E6%25B8%25B8%25E6%2588%258F%25E5%25A4%25A7%25E5%258E%2585" rel="tag">中国游戏中心游戏大厅</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=mps.dll" rel="tag">mps.dll</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=cgagent.dll" rel="tag">cgagent.dll</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%258C%2582%25E9%25A9%25AC" rel="tag">挂马</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%2581%25B6%25E6%2584%258F%25E4%25BB%25A3%25E7%25A0%2581" rel="tag">恶意代码</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?501</link>
<title><![CDATA[Twitter XSS 蠕虫【Mikeyy（StalkDaily）】]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[病毒资讯]]></category>
<pubDate>Mon, 20 Apr 2009 01:25:45 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?501</guid> 
<description>
<![CDATA[ 
	这两周，有关Twitter XSS 蠕虫的报道在国外媒体上看到很多。蠕虫最早是在<a href="http://www.f-secure.com/weblog/archives/00001653.html" target="_blank"><u>4.12</u></a>爆发的，在随后的几天里不断有<a href="http://www.f-secure.com/weblog/archives/00001661.html" target="_blank"><u>变种</u></a>出现。<br/><br/>报道说，蠕虫的作者<strong>Mikeyy Mooney</strong>只有17岁，并且已经<a href="http://www.bnonews.com/news/242.html" target="_blank"><u>承认</u></a>蠕虫是他写的。<br/><br/>有关此蠕虫的新闻，大家可以在网上搜一下。我这里也摘录了两篇：<br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=twitter" rel="tag">twitter</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=xss" rel="tag">xss</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=mikeyy" rel="tag">mikeyy</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=stalkdaily" rel="tag">stalkdaily</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?500</link>
<title><![CDATA[CISRT公布部分中国互联网2009年4月13日挂马简报]]></title> 
<author>hzqedison &lt;hzqedison@cisrt.org&gt;</author>
<category><![CDATA[挂马简报]]></category>
<pubDate>Mon, 13 Apr 2009 16:58:11 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?500</guid> 
<description>
<![CDATA[ 
	CISRT公布部分中国互联网2009年4月13日捕获以下网站被植入恶意代码。<br/><br/><span style="color: #FF0000;"><strong>新增部分公布</strong>：</span><br/><br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>京华论坛-http://bbs.mil.qianlong.com/thread-1600831-1-1.html<br/><br/>深圳巴士集团网站-http://www.szbus.com.cn<br/><br/>绿色软件站-http://www.onegreen.net/index.html<br/><br/>中国德庆-http://www.deqing.gd.cn<br/><br/>南京仁创物资有限公司-http://www.njrenchuang.com<br/><br/>广东火电-http://www.gpec.cn<br/><br/>赣州三中-http://www.jxgzsz.com/yw/readnews.asp?newsid=42<br/><br/>云南蒙自文澜高级中学政教处-http://dyyd.mzyz.cn/onews.asp?id=981<br/><br/>烟台南山学院-http://www.nanshan.edu.cn<br/></div></div><br/><br/><strong>*C.I.S.R.T不保证列出网址是否为官方。</strong><br/><strong>*C.I.S.R.T数据支持来源<a href="http://www.duba.net/" target="_blank">金山毒霸云安全中心</a>。</strong><br/><strong>*根据<a href="http://www.cisrt.org/blog/read.php?478" target="_blank">中华人民共和国刑法修正案（七）</a>中明确指出，挂马行为已经触犯了刑法，大家请勿以身试法！</strong><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%258C%2582%25E9%25A9%25AC" rel="tag">挂马</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E7%25AE%2580%25E6%258A%25A5" rel="tag">简报</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E4%25B8%25AD%25E5%259B%25BD%25E4%25BA%2592%25E8%2581%2594%25E7%25BD%2591" rel="tag">中国互联网</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%2581%25B6%25E6%2584%258F%25E4%25BB%25A3%25E7%25A0%2581" rel="tag">恶意代码</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?499</link>
<title><![CDATA[CISRT公布部分中国互联网2009年4月9日挂马简报]]></title> 
<author>hzqedison &lt;hzqedison@cisrt.org&gt;</author>
<category><![CDATA[挂马简报]]></category>
<pubDate>Thu, 09 Apr 2009 12:33:47 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?499</guid> 
<description>
<![CDATA[ 
	CISRT公布部分中国互联网2009年4月9日捕获以下网站被植入恶意代码。<br/><br/><span style="color: #FF0000;"><strong>新增部分公布</strong>：</span><br/><br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>澄江县国土资源局-hxxp://www.yncjgt.gov.cn/news/onews.asp?id=1444<br/><br/>洪雅人事局-hxxp://www.hyrsj.gov.cn<br/><br/>中国盂县-hxxp://www.sxyx.gov.cn<br/><br/>西北工业大学-hxxp://som.nwpu.edu.cn<br/><br/>西安工程大学-hxxp://zsb.xpu.edu.cn/2009zsb/z2-1.html<br/><br/>河北师范大学-hxxp://xwb.hebtu.edu.cn/lwws/index.asp<br/><br/>河北金融学院-hxxp://news.hbcf.edu.cn/fxx<br/><br/>南通大学-hxxp://xgc.ntu.edu.cn<br/></div></div><br/><br/><strong>*C.I.S.R.T不保证列出网址是否为官方。</strong><br/><strong>*C.I.S.R.T数据支持来源<a href="http://www.duba.net/" target="_blank">金山毒霸云安全中心</a>。</strong><br/><strong>*根据<a href="http://www.cisrt.org/blog/read.php?478" target="_blank">中华人民共和国刑法修正案（七）</a>中明确指出，挂马行为已经触犯了刑法，大家请勿以身试法！</strong><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%258C%2582%25E9%25A9%25AC" rel="tag">挂马</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E7%25AE%2580%25E6%258A%25A5" rel="tag">简报</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%2581%25B6%25E6%2584%258F%25E4%25BB%25A3%25E7%25A0%2581" rel="tag">恶意代码</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E4%25B8%25AD%25E5%259B%25BD%25E4%25BA%2592%25E8%2581%2594%25E7%25BD%2591" rel="tag">中国互联网</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.com/blog/read.php?498</link>
<title><![CDATA[CISRT公布部分中国互联网2009年4月8日挂马简报]]></title> 
<author>hzqedison &lt;hzqedison@cisrt.org&gt;</author>
<category><![CDATA[挂马简报]]></category>
<pubDate>Wed, 08 Apr 2009 15:38:28 +0000</pubDate> 
<guid>http://www.cisrt.com/blog/read.php?498</guid> 
<description>
<![CDATA[ 
	CISRT公布部分中国互联网2009年4月8日捕获以下网站被植入恶意代码。<br/><br/><span style="color: #FF0000;"><strong>新增部分公布</strong>：</span><br/><br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>中国纺织工业协会统计中心-hxxp://tongji.ctei.gov.cn<br/><br/>九江市公安局政务网-hxxp://www.jjsga.gov.cn<br/><br/>延安姚店工业园区-hxxp://www.yaydxq.yanan.gov.cn/<br/><br/>乌苏市地方税务局-hxxp://www.xjwsds.gov.cn/news/zhengwugongkai/index.html<br/><br/>中国朝阳-hxxp://www.zgcy.gov.cn/videonews/index.asp<br/><br/>重庆玉峰山-hxxp://www.cqyfs.gov.cn<br/><br/>连云港民族宗教事务局-hxxp://www.lygmzzjj.gov.cn<br/></div></div><br/><br/><strong>*C.I.S.R.T不保证列出网址是否为官方。</strong><br/><strong>*C.I.S.R.T数据支持来源<a href="http://www.duba.net/" target="_blank">金山毒霸云安全中心</a>。</strong><br/><strong>*根据<a href="http://www.cisrt.org/blog/read.php?478" target="_blank">中华人民共和国刑法修正案（七）</a>中明确指出，挂马行为已经触犯了刑法，大家请勿以身试法！</strong><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%2581%25B6%25E6%2584%258F%25E4%25BB%25A3%25E7%25A0%2581" rel="tag">恶意代码</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E6%258C%2582%25E9%25A9%25AC" rel="tag">挂马</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E7%25AE%2580%25E6%258A%25A5" rel="tag">简报</a> , <a href="http://www.cisrt.com/blog/tag.php?tag=%25E4%25B8%25AD%25E5%259B%25BD%25E4%25BA%2592%25E8%2581%2594%25E7%25BD%2591" rel="tag">中国互联网</a>
]]>
</description>
</item>
</channel>
</rss>