<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Eiven     记录生活 励志人生 &#187; arp</title>
	<atom:link href="http://eiven.com/tag/arp/feed/" rel="self" type="application/rss+xml" />
	<link>http://eiven.com</link>
	<description>健康、做自己喜欢的事、快乐。</description>
	<lastBuildDate>Tue, 31 Aug 2010 03:11:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>最新病毒播报</title>
		<link>http://eiven.com/2008/11/bingdu1119/</link>
		<comments>http://eiven.com/2008/11/bingdu1119/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 01:18:26 +0000</pubDate>
		<dc:creator>eiven</dc:creator>
				<category><![CDATA[日记]]></category>
		<category><![CDATA[33093 端口]]></category>
		<category><![CDATA[arp]]></category>
		<category><![CDATA[go.qwertyy.cn]]></category>
		<category><![CDATA[UDP 数据包]]></category>
		<category><![CDATA[攻击]]></category>
		<category><![CDATA[木马程序]]></category>
		<category><![CDATA[病毒]]></category>

		<guid isPermaLink="false">http://www.eiven.com/?p=144</guid>
		<description><![CDATA[  为什么最新的病毒总是会出现在我电脑里？ 很郁闷，今天下班之后什么也没做，就研究这个病毒了，只要一打开浏览器，就会出现这个网马，网络一直受到攻击，为此专门下载了防火墙，貌... ]]></description>
			<content:encoded><![CDATA[<p> </p>
<div><span style="font-size: 9pt">为什么最新的病毒总是会出现在我电脑里？</span></div>
<div><span style="font-size: 9pt">很郁闷，今天下班之后什么也没做，就研究这个病毒了，只要一打开浏览器，就会出现这个网马，网络一直受到攻击，为此专门下载了防火墙，貌似一年都没专门下过防火墙用了</span></div>
<div><span style="font-size: 9pt">nod不管用了，卡巴不管用了</span></div>
<div><span style="font-size: 9pt">大家谁有虚拟机抓个样本下来研究下，我电脑虚拟机可能被捆绑了</span></div>
<table style="width: 150pt;" border="1" cellspacing="1" cellpadding="0" width="200" align="left">
<tbody>
<tr>
<td style="border-right: #e9e9e9; padding-right: 0.75pt; border-top: #e9e9e9; padding-left: 0.75pt; padding-bottom: 0.75pt; border-left: #e9e9e9; padding-top: 0.75pt; border-bottom: #e9e9e9; background-color: transparent">
<div><span style="font-size: 9pt; color: #ff0000;">2008-11-18 23:28:16 </span><span style="font-size: 9pt"><span style="color: #ff0000;">http://go.qwertyy.cn/gg.htm</span><span style="color: #ff0000;"> Internet Explorer </span></span><span style="font-size: 9pt; color: #ff0000;">检测到威胁</span> <span style="font-size: 9pt; color: #ff0000;">木马程序</span><span style="font-size: 9pt; color: #ff0000;"> Trojan-Clicker.HTML.IFrame.yo </span><span style="font-size: 9pt; color: #ff0000;">高</span> <span style="font-size: 9pt; color: #ff0000;">精确</span><span style="font-size: 9pt; color: #ff0000;">  </span></div>
</td>
</tr>
</tbody>
</table>
<div> </div>
<div> </div>
<div> </div>
<div><span style="font-size: 9pt">防火墙一直顽抗</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 60.221.210.229 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 27447</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 58.252.70.115 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 21028</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 63.216.168.163 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 40953 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 43563</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:26] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 63.216.168.163 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 14294 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 15300</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:37:27] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 125.46.72.254 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 33093 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 21275</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:47] 60.7.198.169</span><span style="font-size: 9pt">试图连接本机的</span><span style="font-size: 9pt">Http[80]</span><span style="font-size: 9pt">端口，</span></div>
<div><span style="font-size: 9pt">           TCP</span><span style="font-size: 9pt">标志：</span><span style="font-size: 9pt">S</span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该操作被拒绝。</span></div>
<div><span style="font-size: 9pt">[22:50:50] 60.7.198.169</span><span style="font-size: 9pt">试图连接本机的</span><span style="font-size: 9pt">Http[80]</span><span style="font-size: 9pt">端口，</span></div>
<div><span style="font-size: 9pt">           TCP</span><span style="font-size: 9pt">标志：</span><span style="font-size: 9pt">S</span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该操作被拒绝。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 221.11.56.130 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 41454</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 119.118.133.164 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 24046</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 58.242.167.191 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 4194</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span></div>
<div><span style="font-size: 9pt">[22:50:52] </span><span style="font-size: 9pt">接收到</span><span style="font-size: 9pt"> 123.185.114.93 </span><span style="font-size: 9pt">的</span><span style="font-size: 9pt"> UDP </span><span style="font-size: 9pt">数据包，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">本机端口</span><span style="font-size: 9pt">: 12543 </span><span style="font-size: 9pt">，</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">对方端口</span><span style="font-size: 9pt">: 15000</span></div>
<div><span style="font-size: 9pt">           </span><span style="font-size: 9pt">该包被拦截。</span><span style="font-size: 9pt">………………………………</span></div>
<div><span style="font-size: 9pt">最终并没有解决这个病毒，还有这个攻击怎么防御，简直郁闷死</span></div>
<div><span style="font-size: 9pt">进一步研究中</span></div>
<div><span style="font-size: 9pt">抓住这小子一定判他妈死刑</span></div>
<div> </div>
<div>进一步研究结果</div>
<div>这个是arp</div>
<div>解决方法如下</div>
<div>先关闭浏览器（一定要关），清空所有浏览器缓存文件，如果是局域网建议安装个好一点的arp防火墙</div>
<div>风云防火墙吧，打开arp保护，看看是局域网中哪台机器中招了在扩散，清理干净他就好了。</div>
<h3  class="related_post_title">您可能对下面内容感兴趣</h3><ul class="related_post"><li><a href="http://eiven.com/2008/05/bingdu/" title="最新病毒报道">最新病毒报道</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://eiven.com/2008/11/bingdu1119/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
