Lesi sihloko siyingxenye yochungechunge lwe-Fileless Malware. Zonke ezinye izingxenye zochungechunge:
I-Adventures ye-Elusive Malware, Ingxenye I I-Adventures ye-Elusive Malware, Ingxenye II: Izikripthi ze-VBA eziyimfihlo I-Adventures ye-Elusive Malware, Ingxenye III: I-VBA Scripts Tangled for Ukuhleka kanye Nenzuzo I-Adventures ye-Elusive Malware, Ingxenye IV: I-DDE kanye Nezinkundla Zedokhumenti Ye-Word I-Adventures ye-Elusive Malware, Ingxenye V: I-DDE Eningi nakakhulu ne-COM Scriptlets (sikhona)
Kulolu chungechunge lwezihloko, sihlola izindlela zokuhlasela ezidinga umzamo omncane ohlangothini lwabaduni. Esikhathini esedlule
Ukulungiswa kwengeza okufakiwe kokubhalisa okukhubaza Imisebenzi ye-DDE eZwini. Uma usakudinga lokhu kusebenza, ungabuyisela le nketho ngokunika amandla amakhono amadala e-DDE.
Kodwa-ke, isiqeshana sokuqala simboze iMicrosoft Word kuphela. Ingabe lobu buthakathaka be-DDE bukhona kweminye imikhiqizo ye-Microsoft Office engase isetshenziswe ekuhlaselweni okungekho ikhodi? Yebo, impela. Isibonelo, ungawathola ku-Excel.
Ubusuku be-DDE ephilayo
Ngikhumbula ukuthi okokugcina ngima encazelweni ye-COM scriptlets. Ngiyathembisa ukuthi ngizofika kubo kamuva kulesi sihloko.
Okwamanje, ake sibheke olunye uhlangothi olubi lwe-DDE enguqulweni ye-Excel. NjengaseZwini nje, abanye izici ezifihliwe ze-DDE ku-Excel ikuvumela ukuthi wenze ikhodi ngaphandle komzamo omkhulu. Njengomsebenzisi we-Word owakhula, ngangijwayele izinkambu, kodwa hhayi nhlobo mayelana nemisebenzi ku-DDE.
Kwangimangaza ukufunda ukuthi ku-Excel ngingabiza igobolondo kuseli njengoba kuboniswe ngezansi:
Ubuwazi ukuthi lokhu kungenzeka? Ngokwami, angikwenzi
Leli khono lokuqalisa igobolondo le-Windows lihlonishwe yi-DDE. Ungacabanga ngezinye izinto eziningi
Izinhlelo zokusebenza ongaxhuma kuzo usebenzisa imisebenzi ye-DDE eyakhelwe ngaphakathi ye-Excel.
Ingabe nawe ucabanga into efanayo engiyicabangayo?
Vumela umyalo wethu ongaphakathi kweseli uqale iseshini ye-PowerShell ebese ilanda futhi isebenzise isixhumanisi - lokhu
Vele unamathisele i-PowerShell encane ukuze ulayishe futhi usebenzise ikhodi yesilawuli kude ku-Excel
Kodwa kukhona okubambekayo: kufanele ufake ngokucacile le datha kuseli ukuze le fomula isebenze ku-Excel. I-hacker ingawusebenzisa kanjani lo myalo we-DDE ukude? Iqiniso liwukuthi uma ithebula le-Excel livuliwe, i-Excel izozama ukuvuselela zonke izixhumanisi ku-DDE. Izilungiselelo ze-Trust Center zinesikhathi eside zinekhono lokukhubaza lokhu noma ukuxwayisa lapho kubuyekezwa izixhumanisi emithonjeni yedatha yangaphandle.
Ngisho nangaphandle kwamapeshi akamuva, ungakhubaza ukubuyekezwa kwesixhumanisi okuzenzakalelayo ku-DDE
IMicrosoft uqobo ngokwayo
Nokho, kuthiwani ngezingodo zomcimbi?
I-Microsoft nokho ishiye i-DDE ye-MS Word ne-Excel, ekugcineni yabona ukuthi i-DDE ifana nesiphazamisi kunokusebenza. Uma ngesizathu esithile ungakazifaki lezi ziqephu, usengakwazi ukunciphisa ingozi yokuhlaselwa kwe-DDE ngokukhubaza izibuyekezo zezixhumanisi ezizenzakalelayo futhi unike amandla izilungiselelo ezisiza abasebenzisi ukuthi babuyekeze izixhumanisi lapho bevula amadokhumenti namaspredishithi.
Manje umbuzo wesigidi sedola: Uma uyisisulu salokhu kuhlasela, ingabe izikhathi ze-PowerShell eziqaliswe ezinkundleni ze-Word noma amaseli e-Excel azovela kulogi?
Umbuzo: Ingabe amaseshini e-PowerShell aqaliswe nge-DDE afakiwe? Impendulo: yebo
Uma usebenzisa amaseshini e-PowerShell ngokuqondile usuka kuseli ye-Excel kune-macro, iWindows izongena le micimbi (bona ngenhla). Ngesikhathi esifanayo, angikwazi ukusho ukuthi kuzoba lula ngethimba lezokuphepha ukuthi bese lixhuma wonke amachashazi phakathi kweseshini ye-PowerShell, idokhumenti ye-Excel kanye nomlayezo we-imeyili futhi liqonde ukuthi ukuhlasela kuqale kuphi. Ngizobuyela kulokhu esihlokweni sokugcina ochungechungeni lwami olungapheli ngohlelo olungayilungele ikhompuyutha.
Injani iCOM yethu?
Kwedlule
Kuvele ukuthi umuntu uhlakaniphe kakhulu
Boom! Enye indlela ecashile, ethule yokuvula igobolondo usebenzisa imibhalo ye-COM
Ngemuva kokuhlolwa kwekhodi yezinga eliphansi, umcwaningi uthole ukuthi kuyini ngempela iphutha ku-software yephakheji. Kwakungahloselwe ukusebenzisa imibhalo ye-COM, kodwa kuphela ukuxhuma kumafayela. Anginaso isiqiniseko sokuthi ngabe sesikhona yini isiqeshana salokhu kuba sengcupheni. Esifundweni sami siqu ngisebenzisa i-Amazon WorkSpaces ene-Office 2010 efakwe ngaphambili, ngikwazile ukuphindaphinda imiphumela. Nokho, lapho ngizama futhi ngemva kwesikhashana, ayizange isebenze.
Ngethemba ngempela ukuthi ngikutshele izinto eziningi ezithakazelisayo futhi ngasikhathi sinye ngibonise ukuthi abaduni bangangena enkampanini yakho ngendlela eyodwa noma enye efanayo. Ngisho noma ufaka zonke iziqephu zakamuva ze-Microsoft, abaduni basenawo amathuluzi amaningi okuthola isisekelo ohlelweni lwakho, kusukela kuma-VBA macros ngiqale lolu chungechunge kuya ekukhokheni okunonya ku-Word noma i-Excel.
Esihlokweni sokugcina (Ngiyathembisa) kule saga, ngizokhuluma ngendlela yokuhlinzeka ngokuvikela okuhlakaniphile.
Source: www.habr.com