¦W¬°¡uPetrwrap¡vªº°Ç¯Á³n¥ó§ðÀ»¥¿¦b¥þ²y¤Î¼Ú¬wÂX´²¡A¼vÅT¦h¶¡¾÷ºc¡A¥]¬A¬F©²©M¤½¥Î¨Æ·~¾÷ºc¡C¸ò¤W¤ë¡uWannaCry¡v°Ç¯Á³n¥ó¬ÛÃþ¦ü¡A¦¹§ðÀ»¬O°w¹ï Windows¨t²Î¡A¨Ã©ó¸Ë¸m¨ü·P¬V«á¶Ç¼½¦Ü¨ä¥L¸Ë¸m¡C®Ú¾Ú²{¦³¸ê®Æ¡A¡uPetrwrap¡v¬O³z¹L¥é«_¶BÄF¹q¶l©ó¤¬Ápºô¶¡½¯©µ¡A¸Ó°Ç¯Á³n¥ó¤]¯à°÷§Q¥Î¡uWannaCry¡v§ðÀ»¤âªk¬Û¦Pªº SMB º|¬}¶Ç¼½¡C³s±µºôµ¸¨Ã¤w¦w¸ËSMB º|¬}׸ɵ{¦¡ªºWindows¨t²Î¡A¥ç·|³Q¡uPetrwrap¡v³z¹L¤@¨Ç Windows ¨t²Îªº¥¿±`¥\¯à¡A¥]¬A¡uWindows Management Instrumentation Command-line (WMIC)¡v©M¡uPsExec¡v¤J«I¡C¸ÓSMB º|¬}¥i¥H¸g Microsoft ¦w¥þ¤½§i MS17-010 ¤º©Òµo¥¬ªº¬ÛÃö׸ɵ{¦¡°ô¶ë¡C
©Ò¦³ Windows ¨t²ÎÀ³¾¨§Ö§¹¦¨§Ú̸û¦«e«O¦wĵ³ø¡]A17-05-04 ©M A17-03-03¡^¤¤«Øijªº¬ÛÃö¦w¥þ§ó·s¡Cų©ó¨Ï¥Î WMIC ©M PsExec ¶·nºô°ìºÞ²zûÅv¡A¨t²ÎºÞ²zûÀ³±N WMIC ©M PsExec ©w¥u¨ÑÀò±ÂÅvªº¸ê°T¬ì§Þ¤ä´©¤Hû¨Ï¥Î¡C¥Ñ©ó±¡ªp¥¿¤£Â_µo®i¡A¥Î¤áÀ³¥[±jºò«æÀ³¹ï±¹¬I¡A¥H¨¾¿m°Ç¯Á³n¥ó§ðÀ»¡A«O»Ù¹q¸£¥H§K¨ü¨ì§ðÀ»©Ò¼vÅT¡C½Ð¥ß§Y±Ä¨ú¥H¤U¦æ°Ê¡G (a) ½T«O¤w³Æ¥÷¹q¶l©M¨ä¥L¸ê®Æ¡A¨Ã©w´Á°õ¦æ³Æ¥÷¤u§@¡F (b) ¤£n§â³Æ¥÷³s±µ¦Ü¹q¸£¡A¨Ã¥[¥H紬ݺޡA¥HÁקK³Æ¥÷¾D¨üºô¤WŧÀ»¡B¿ò¥¢©Î³QµsÅÑ¡F (c) Àˬd¤Î§ó·s§Ü´c·Nµ{¦¡½X³n¥ó¤ÎÃѧO½X¦Ü³Ì·sª©¥»¡F (d) ¬°©Ò¦³ Windows ¨t²Î¦w¸Ë³Ì·sªº«O¦w׸ɵ{¦¡¡F¤Î (e) ¤£n¶}û£¥iºÃªº¹q¶l¡Bªþ¥ó¤Î¶W³sµ²¡C
¦pªG¤£©¯¨ü¨ì·P¬V¡A½Ð¥ß§Y¤ÁÂ_¨ü·P¬V¹q¸£ªººôµ¸³s½u¡A¨Ã¾¨§Ö¦V»´ä¹q¸£«O¦w¨Æ¬G¨ó½Õ¤¤¤ß³ø§i¡]¹q¸Ü¡G8105 6060¡A¹q¶l¡Ghkcert@hkcert.org¡^¡C |