[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[port139:00694] Re: Nimda ワーム



山本です。

|Subject: [port139:00681] Re: Nimda ワーム
|From: hamamoto <r00t@xxxxxxxxxxx>
|Date: Wed, 19 Sep 2001 22:01:56 +0900
|Message-Id: <20010919215834.BB23.R00T@xxxxxxxxxxx>
|User-Agent: Becky! ver. 2.00

| > こんばんは、小川です。
| > なぜかここでは取り上げられていないようですので・・・(^^;
| > 一応多少情報を。
| > http://www.microsoft.com/japan/technet/security/nimdaalrt.asp
| > http://www.symantec.com/region/jp/sarcj/data/w/w32.nimda.a@xxxxxxx
| > サーバ設定に関してはCodeRed対策してた人は安心らしいです。

マイクロソフトのサイトから無償ダウンロードできる URLscan と、CCS 
長谷川氏の手による guard3.dll も適用したほうがベターですね。

当方、Windows 2000 Professional および Windows XP Professional 
RC2(MSDN にて入手) を用いていますが、上記 TechNet サイトでの記述
のほか、これらを適用したことも相俟って、何とか無難な状態になって
いるようです。 Windows XP Professional の Personal Firewall もと
りあえず有効にして、様子を見ています。

# しかし、感染したと思われる端末からのアクセスでひっきりなしにな
# る現状は、いやですねぇ。

URL Scan
http://www.microsoft.com/downloads/release.asp?ReleaseID=32571
IIS Lockdown Tool
http://www.microsoft.com/downloads/release.asp?ReleaseID=32362
Guard3.dll
http://www.trusnet.com/tools/guard3/index.html
http://www.port139.co.jp/guard3/

ログ出力例

URL Scan
------------------------------------------------------------
[金, 9 21 2001 - 21:23:31] ---------- UrlScan.dll Initializing ----------
[金, 9 21 2001 - 21:23:31] URLs will be normalized before analysis.
[金, 9 21 2001 - 21:23:31] URL normalization will be verified.
[金, 9 21 2001 - 21:23:31] URLs may contain OEM, international and UTF-8 characters.
[金, 9 21 2001 - 21:23:31] URLs must not contain any dot except for the file extension.
[金, 9 21 2001 - 21:23:31] Only the following verbs will be allowed (case sensitive):
[金, 9 21 2001 - 21:23:31] 	'GET'
[金, 9 21 2001 - 21:23:31] 	'HEAD'
[金, 9 21 2001 - 21:23:31] 	'POST'
[金, 9 21 2001 - 21:23:31] Requests for following extensions will be rejected:
[金, 9 21 2001 - 21:23:31] 	'.exe'
[金, 9 21 2001 - 21:23:31] 	'.bat'
[金, 9 21 2001 - 21:23:31] 	'.cmd'
[金, 9 21 2001 - 21:23:31] 	'.com'
[金, 9 21 2001 - 21:23:31] 	'.htw'
[金, 9 21 2001 - 21:23:31] 	'.ida'
[金, 9 21 2001 - 21:23:31] 	'.idq'
[金, 9 21 2001 - 21:23:31] 	'.htr'
[金, 9 21 2001 - 21:23:31] 	'.idc'
[金, 9 21 2001 - 21:23:31] 	'.shtm'
[金, 9 21 2001 - 21:23:31] 	'.shtml'
[金, 9 21 2001 - 21:23:31] 	'.stm'
[金, 9 21 2001 - 21:23:31] 	'.printer'
[金, 9 21 2001 - 21:23:31] 	'.ini'
[金, 9 21 2001 - 21:23:31] 	'.log'
[金, 9 21 2001 - 21:23:31] 	'.pol'
[金, 9 21 2001 - 21:23:31] 	'.dat'
[金, 9 21 2001 - 21:23:31] Requests containing the following headers will be rejected:
[金, 9 21 2001 - 21:23:31] 	'translate:'
[金, 9 21 2001 - 21:23:31] 	'if:'
[金, 9 21 2001 - 21:23:31] 	'lock-token:'
[金, 9 21 2001 - 21:23:31] Requests containing the following character sequences will be rejected:
[金, 9 21 2001 - 21:23:31] 	'..'
[金, 9 21 2001 - 21:23:31] 	'./'
[金, 9 21 2001 - 21:23:31] 	'\'
[金, 9 21 2001 - 21:23:31] 	':'
[金, 9 21 2001 - 21:23:31] 	'%'
[金, 9 21 2001 - 21:23:31] 	'&'
[金, 9 21 2001 - 21:33:44] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/scripts/root.exe'
[金, 9 21 2001 - 21:33:44] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/MSADC/root.exe'
[金, 9 21 2001 - 21:33:44] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/c/winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:44] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/d/winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:44] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/scripts/..%255c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL contains '.' in the path. Request will be rejected.  Raw URL='/scripts/..%c1%1C../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/scripts/..%c0%2F../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/scripts/..%c0%af../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/scripts/..%c1%9c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:45] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/scripts/..%255%63../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:46] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/scripts/..%255c../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:46] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/scripts/..%25%35%63../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:33:46] Client at (攻撃側ホストA): URL normalization was not complete after one pass. Request will be rejected.  Raw URL='/scripts/..%252f../winnt/system32/cmd.exe'
[金, 9 21 2001 - 21:49:09] Client at (攻撃側ホストB): URL contains extension '.exe', which is disallowed. Request will be rejected.  Raw URL='/scripts/root.exe'
[金, 9 21 2001 - 21:58:20] Client at (攻撃側ホストC): URL contains extension '.ida', which is disallowed. Request will be rejected.  Raw URL='/default.ida'
[金, 9 21 2001 - 22:00:09] Client at (攻撃側ホストD): URL contains extension '.ida', which is disallowed. Request will be rejected.  Raw URL='/default.ida'
------------------------------------------------------------

Guard3.dl
------------------------------------------------------------
*long_url_rejected: client=(攻撃側ホストA), server=www, date=2001/9/21_21:33:45
GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0
Host: www
Connnection: close

;;;

*characters_translated: client=(攻撃側ホストA), server=www, date=2001/9/21_21:33:45
GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0
Host: www
Connnection: close

;;;

*characters_translated: client=(攻撃側ホストA), server=www, date=2001/9/21_21:33:46
GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0
Host: www
Connnection: close

;;;

*long_url_rejected: client=(攻撃側ホストC), server=(私の端末), date=2001/9/21_21:58:20
GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379 

ネネ;;;

*long_url_rejected: client=(攻撃側ホストD), server=(私の端末), date=2001/9/21_22:00:09
GET /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078%u0000%u00=a  HTTP/1.0
Content-type: text/xml
Content-length: 3379
------------------------------------------------------------

以上

山本謙次

--
JWNTUG TechNote http://www.jwntug.or.jp/tech/technote/index-j.html
JWNTUG NT-FAQ-J http://www.jwntug.or.jp/tech/ntfaqj/index.html
Kenji Yamamoto MCP+I, MCSE(TCP/IP, IEAK4, IIS 4.0)
mailto:ethernet@xxxxxxxxxxxxxxxx