<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[C.I.S.R.T.]]></title> 
<link>http://www.cisrt.org/blog/index.php</link> 
<description><![CDATA[Chinese Internet Security Response Team (GMT +0800)]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[C.I.S.R.T.]]></copyright>
<item>
<link>http://www.cisrt.org/blog/read.php?507</link>
<title><![CDATA[Microsoft Security Advisory (977981)]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 25 Nov 2009 01:01:37 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?507</guid> 
<description>
<![CDATA[ 
	<strong>Microsoft Security Advisory (977981)</strong><br/>Vulnerability in Internet Explorer Could Allow Remote Code Execution<br/>Published: November 23, 2009<br/><br/>Version: 1.0<br/><br/>Microsoft is investigating new public reports of a vulnerability in Internet Explorer. This advisory contains information about which versions of Internet Explorer are vulnerable as well as workarounds and mitigations for this issue. <br/><br/>Our investigation so far has shown that Internet Explorer 5.01 Service Pack 4 and Internet Explorer 8 on all supported versions of Microsoft Windows are not affected, and that Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6 and Internet Explorer 7 on supported editions of Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008 are affected. <br/><br/>The vulnerability exists as an invalid pointer reference of Internet Explorer. It is possible under certain conditions for a CSS/Style object to be accessed after the object is deleted. In a specially-crafted attack, Internet Explorer attempting to access a freed object can lead to running attacker-supplied code.<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=css%252Fstyle" rel="tag">css/style</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=977981" rel="tag">977981</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?505</link>
<title><![CDATA[Microsoft Office Web 组件控件中的0-day漏洞（973472）]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Tue, 14 Jul 2009 01:25:05 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?505</guid> 
<description>
<![CDATA[ 
	MS 安全通报：<a href="http://www.microsoft.com/technet/security/advisory/973472.mspx" target="_blank"><u>Microsoft Security Advisory (973472)</u></a><br/><br/>MS 知识库：<a href="http://support.microsoft.com/kb/973472" target="_blank">http://support.microsoft.com/kb/973472</a><br/><br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=owc10" rel="tag">owc10</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=owc11" rel="tag">owc11</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=973472" rel="tag">973472</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?504</link>
<title><![CDATA[Green Dam-Youth Escort，绿坝]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Fri, 12 Jun 2009 08:00:10 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?504</guid> 
<description>
<![CDATA[ 
	这两天有关绿坝的新闻很多，今天有一篇来自密歇根大学计算机技术与工程系（Computer Science and Engineering at the University of Michigan）的漏洞报告在国内被广泛转载。<br/><br/><a href="http://www.cse.umich.edu/%7Ejhalderm/pub/gd/" target="_blank"><u><strong>Analysis of the Green Dam Censorware System</strong></u></a><br/><br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=greendam" rel="tag">greendam</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E7%25BB%25BF%25E5%259D%259D" rel="tag">绿坝</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?502</link>
<title><![CDATA[五一期间爆三个新0day,暴风影音和中国游戏中心大厅漏洞被用在挂马新宠]]></title> 
<author>hzqedison &lt;hzqedison@cisrt.org&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Sun, 03 May 2009 07:48:46 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?502</guid> 
<description>
<![CDATA[ 
	五一小长假，被爆出三个高危0day漏洞，且这些漏洞已经被用于挂马集团中，当用户安装有漏洞的软件，浏览黑客精心构造含有恶意代码的网页后，在用户不知情情况下下载木马。<br/><br/><br/>暴风影音2009(mps.dll)ActiveX远程栈溢出漏洞<br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>受影响的系统:<br/>暴风影音2009 &lt;=[3.09.04.17]<br/><br/>细节:<br/>CLSID:6BE52E1D-E586-474F-A6E2-1A85A9B4D9FB<br/>文件:mps.dll<br/>Sub OnBeforeVideoDownload(ByVal URL&nbsp;&nbsp;As String)<br/><br/>当参数URL是一个超长字符串时，发生栈溢出，利用堆填充技术，攻击者可以很轻松的利用此漏洞执行任意代码。<br/></div></div><br/><br/>暴风影音2009(Config.dll)ActiveX远程栈溢出漏洞<br/><div class="quote"><div class="quote-title">引用</div><div class="quote-content"><br/>受影响的系统:<br/>暴风影音2009 &lt;=[3.09.04.17]<br/><br/>细节:<br/>CLSID:BD103B2B-30FB-4F1E-8C17-D8F6AADBCC05<br/>文件:Config.dll<br/>Sub SetAttributeValue (<br/>&nbsp;&nbsp;ByVal lpQueryStr&nbsp;&nbsp;As String ,<br/>&nbsp;&nbsp;ByVal bstrAttributeName&nbsp;&nbsp;As String ,<br/>&nbsp;&nbsp;ByVal lpValueStr&nbsp;&nbsp;As String<br/>)<br/><br/>当参数lpQueryStr是一个超长字符串时，发生栈溢出，利用堆填充技术，攻击者可以很轻松的利用此漏洞执行任意代码。<br/></div></div><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%259A%25B4%25E9%25A3%258E%25E5%25BD%25B1%25E9%259F%25B3" rel="tag">暴风影音</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E4%25B8%25AD%25E5%259B%25BD%25E6%25B8%25B8%25E6%2588%258F%25E4%25B8%25AD%25E5%25BF%2583%25E6%25B8%25B8%25E6%2588%258F%25E5%25A4%25A7%25E5%258E%2585" rel="tag">中国游戏中心游戏大厅</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=mps.dll" rel="tag">mps.dll</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=cgagent.dll" rel="tag">cgagent.dll</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%258C%2582%25E9%25A9%25AC" rel="tag">挂马</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%2581%25B6%25E6%2584%258F%25E4%25BB%25A3%25E7%25A0%2581" rel="tag">恶意代码</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?474</link>
<title><![CDATA[微软发布更新修复“自动播放”设置]]></title> 
<author>海色の月 &lt;amezhs@cisrt.org&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 25 Feb 2009 03:03:00 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?474</guid> 
<description>
<![CDATA[ 
	当地时间昨天，微软发布了一个更新，用于解决用户不能正确设置“自动播放”的问题，微软在安全建议中提到：使用 NoDriveTypeAutoRun 注册表键值可以有选择性地设置自动播放项目，禁用自动播放可以保护用户的系统免受可能来自光驱、USB 移动设备、网络共享等媒介的安全威胁。<br/><br/>现在越来越多的病毒会利用自动播放的便利来传播自身，也有不少病毒更会破坏系统的自动播放设置，可能就是出于此原因微软发布了这个更新程序。这个更新程序将会通过自动更新发布，用户也可以自行下载安装：<a href="http://support.microsoft.com/kb/967715" target="_blank">http://support.microsoft.com/kb/967715</a><br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=%25E8%2587%25AA%25E5%258A%25A8%25E6%2592%25AD%25E6%2594%25BE" rel="tag">自动播放</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=nodrivetypeautorun" rel="tag">nodrivetypeautorun</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E5%25AE%2589%25E5%2585%25A8%25E5%25BB%25BA%25E8%25AE%25AE" rel="tag">安全建议</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=967940" rel="tag">967940</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=kb967715" rel="tag">kb967715</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?473</link>
<title><![CDATA[Adobe APSB09-01 Security Bulletin]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 25 Feb 2009 01:35:35 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?473</guid> 
<description>
<![CDATA[ 
	<strong>Adobe</strong>针对旗下Adobe Flash Player产品发布了一个最新的安全补丁 —— <a href="http://www.adobe.com/support/security/bulletins/apsb09-01.html" target="_blank"><u>APSB09-01</u></a>。<br/><br/>根据Adobe的报告，受影响的Flash Player版本包括：<br/><div class="code">Adobe Flash Player 10.0.12.36 and earlier <br/>Adobe Flash Player 10.0.15.3 and earlier for Linux</div><br/><br/>建议广大网友尽快将自己的Adobe Flash Player版本<a href="http://www.adobe.com/go/getflashplayer" target="_blank"><u>升级</u></a>至最新的<strong>10.0.22.87</strong>，同时Adobe针对Flash Player 9的用户也提供了相应的补丁下载<a href="http://www.adobe.com/go/kb406791" target="_blank"><u>地址</u></a>。<br/><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=adobe" rel="tag">adobe</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=flash" rel="tag">flash</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=10.0.22.87" rel="tag">10.0.22.87</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?472</link>
<title><![CDATA[Microsoft Security Advisory (968272)]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 25 Feb 2009 01:20:52 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?472</guid> 
<description>
<![CDATA[ 
	微软发布了<a href="http://www.microsoft.com/technet/security/advisory/968272.mspx" target="_blank"><u>Microsoft Security Advisory (968272) — Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution</u></a>。<br/><br/>与此同时，国外一些反病毒厂商也捕获了利用此漏洞的木马样本。<br/><br/>根据微软的报告，受影响的Excel版本包括：<br/><div class="code">Microsoft Office Excel 2000 Service Pack 3<br/>Microsoft Office Excel 2002 Service Pack 3<br/>Microsoft Office Excel 2003 Service Pack 3<br/>Microsoft Office Excel 2007 Service Pack 1<br/>Microsoft Office Excel Viewer 2003<br/>Microsoft Office Excel Viewer 2003 Service Pack 3<br/>Microsoft Office Excel Viewer<br/>Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 1<br/>Microsoft Office 2004 for Mac<br/>Microsoft Office 2008 for Mac</div><br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=%25E5%25BE%25AE%25E8%25BD%25AF" rel="tag">微软</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%25BC%258F%25E6%25B4%259E" rel="tag">漏洞</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=execl" rel="tag">execl</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=968272" rel="tag">968272</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?467</link>
<title><![CDATA[Adobe Reader和Acrobat 0-day漏洞攻击]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Fri, 20 Feb 2009 06:09:34 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?467</guid> 
<description>
<![CDATA[ 
	<strong>Adobe产品安全事件响应团队</strong>（PSIRT）发布<a href="http://www.adobe.com/support/security/advisories/apsa09-01.html" target="_blank"><u>APSA09-01</u></a>安全公告说，Adobe Reader和Acrobat 9.0及以前的版本存在缓冲区溢出漏洞。<br/><br/>受影响的版本包括：<br/><div class="code">Adobe Reader 9 and earlier versions<br/>Adobe Acrobat Standard, Pro, and Pro Extended 9 and earlier versions</div><br/><br/>而根据Shadowserver的<a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219" target="_blank"><u>报告</u></a>说，一些反病毒厂商已经可以检测到这些恶意的pdf文件，Symantec命名为<a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-021212-5523-99" target="_blank"><u>Trojan.Pidief.E</u></a>，TrendMicro命名为<a href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_PIDIEF.IN&amp;VSect=P" target="_blank"><u>TROJ_PIDIEF.IN</u></a>。<br/>............<br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%25BC%258F%25E6%25B4%259E" rel="tag">漏洞</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=adobe" rel="tag">adobe</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=acrobat" rel="tag">acrobat</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?462</link>
<title><![CDATA[计划外补丁 MS08-078 发布]]></title> 
<author>海色の月 &lt;amezhs@cisrt.org&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Thu, 18 Dec 2008 12:29:26 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?462</guid> 
<description>
<![CDATA[ 
	微软于今日发布了修补 <a href="http://www.cisrt.org/blog/read.php?456" target="_blank">IE 0-day 漏洞</a>的计划外补丁 MS08-078，请大家及时安装此补丁以免受针对此漏洞的攻击。<br/><br/>相关链接：<br/><br/>Microsoft 安全公告 MS08-078 - 严重<br/>Internet Explorer 安全更新 (960714)<br/><a href="http://www.microsoft.com/china/technet/security/bulletin/ms08-078.mspx" target="_blank">http://www.microsoft.com/china/technet/security/bulletin/ms08-078.mspx</a><br/><br/>Microsoft Security Bulletin MS08-078 - Critical<br/>Security Update for Internet Explorer (960714)<br/><a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx" target="_blank">http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx</a><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=ms08-078" rel="tag">ms08-078</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=kb960714" rel="tag">kb960714</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=ie" rel="tag">ie</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=0day" rel="tag">0day</a>
]]>
</description>
</item><item>
<link>http://www.cisrt.org/blog/read.php?461</link>
<title><![CDATA[微软又将于明日发布一个计划外补丁]]></title> 
<author>小陌 &lt;smallmo@cisrt.com&gt;</author>
<category><![CDATA[漏洞补丁]]></category>
<pubDate>Wed, 17 Dec 2008 11:51:54 +0000</pubDate> 
<guid>http://www.cisrt.org/blog/read.php?461</guid> 
<description>
<![CDATA[ 
	微软今天已经发布<a href="http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx" target="_blank"><u>Advance Notification</u></a>，将于明日发布一个计划外（out-of-band）补丁，这个补丁将修补上周发现的<a href="http://www.cisrt.org/blog/read.php?457" target="_blank"><u>IE XML 0day</u></a>漏洞。<br/><br/>这已是微软今年第二个计划外补丁，上一次计划外补丁是于今年10月24日发布的<a href="http://www.cisrt.org/blog/read.php?449" target="_blank"><u>MS08-067</u></a>。<br/><br/>让我们一起等待明天发布的补丁。<br/><br/><br/>Tags - <a href="http://www.cisrt.org/blog/tag.php?tag=%25E6%25BC%258F%25E6%25B4%259E" rel="tag">漏洞</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E8%25A1%25A5%25E4%25B8%2581" rel="tag">补丁</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=ms" rel="tag">ms</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=%25E5%25BE%25AE%25E8%25BD%25AF" rel="tag">微软</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=iexml" rel="tag">iexml</a> , <a href="http://www.cisrt.org/blog/tag.php?tag=0day" rel="tag">0day</a>
]]>
</description>
</item>
</channel>
</rss>