|
[分享]番茄花园WinXP爆出严重漏洞
我的操作系统是 XP SP2, 不是番茄的。
系统默认的administrator、guest等用户 早就已经被我改了名字,而且禁止使用。
还是仔细查看了注册表。
发现limitblankpassworduse的键值是0, 莫非也是漏洞,Oh, My sense!
修改成1,导出这个分支,准备以后恢复系统时,再打上这个。
reg文件内容如下:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa]
"Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
00
"Bounds"=hex:00,30,00,00,00,20,00,00
"Security Packages"=hex(7):6b,00,65,00,72,00,62,00,65,00,72,00,6f,00,73,00,00,\
00,6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,73,00,63,00,68,00,61,00,6e,00,\
6e,00,65,00,6c,00,00,00,77,00,64,00,69,00,67,00,65,00,73,00,74,00,00,00,00,\
00
"LsaPid"=dword:000003ec
"SecureBoot"=dword:00000001
"auditbaseobjects"=dword:00000000
"crashonauditfail"=dword:00000000
"disabledomaincreds"=dword:00000001
"everyoneincludesanonymous"=dword:00000000
"fipsalgorithmpolicy"=dword:00000000
"forceguest"=dword:00000000
"fullprivilegeauditing"=hex:00
"limitblankpassworduse"=dword:00000001
"lmcompatibilitylevel"=dword:00000005
"nodefaultadminowner"=dword:00000001
"nolmhash"=dword:00000001
"restrictanonymous"=dword:00000001
"restrictanonymoussam"=dword:00000001
"Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00
"ImpersonatePrivilegeUpgradeToolHasRun"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders]
"roviderOrder"=hex(7):57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,20,00,4e,00,\
54,00,20,00,41,00,63,00,63,00,65,00,73,00,73,00,20,00,50,00,72,00,6f,00,76,\
00,69,00,64,00,65,00,72,00,00,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\Windows NT Access Provider]
"roviderPath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
6e,00,74,00,6d,00,61,00,72,00,74,00,61,00,2e,00,64,00,6c,00,6c,00,00,00
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Audit]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Audit\PerUserAuditing]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Audit\PerUserAuditing\System]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Data]
"attern"=hex:6d,f1,b9,b8,76,96,7d,7c,e5,3c,f3,95,d8,ca,fb,a9,66,33,39,65,39,\
30,37,33,00,68,07,00,01,00,00,00,d8,00,00,00,dc,00,00,00,48,fa,06,00,d6,48,\
50,74,04,00,00,00,a0,fd,06,00,b8,fd,06,00,6a,0d,49,6e
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\GBG]
"GrafBlumGroup"=hex:2f,dd,9e,07,67,81,4c,a3,ff
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\JD]
"Lookup"=hex:38,ca,44,6c,a2,a2
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Kerberos]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Kerberos\Domains]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Kerberos\SidCache]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\MSV1_0]
"Auth132"="IISSUBA"
"ntlmminclientsec"=dword:00000000
"ntlmminserversec"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\Skew1]
"SkewMatrix"=hex:30,f5,a7,67,f5,6e,79,f6,a2,85,1e,ab,71,da,56,40
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SSO]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SSO\Passport1.4]
"SSOURL"="http://www.passport.com"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache]
"Time"=hex:e0,72,d7,dd,5b,70,c6,01
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\digest.dll]
"Name"="Digest"
"Comment"="Digest SSPI Authentication Package"
"Capabilities"=dword:00004050
"RpcId"=dword:0000ffff
"Version"=dword:00000001
"TokenSize"=dword:0000ffff
"Time"=hex:80,30,95,2b,ea,83,c4,01
"Type"=dword:00000031
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msapsspc.dll]
"Name"="DPA"
"Comment"="DPA Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000011
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,7b,f2,30,ea,83,c4,01
"Type"=dword:00000031
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\SspiCache\msnsspc.dll]
"Name"="MSN"
"Comment"="MSN Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000012
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,a8,23,32,ea,83,c4,01
"Type"=dword:00000031
桐桐如果有时间,请帮我看看,是否有啥不妥。
Thank you so much!
(本公子这厢有礼了。)
|
|