我所在网吧的机子都是 Windows XP Service Pack 1
RPC溢出失败
已经启用分布COM
开放端口 135 445 无防火墙
--------------------------------------------------------------------------------
C:\Documents and Settings\Sicent>netstat -an
Active Connections
Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1027 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1028 0.0.0.0:0 LISTENING
TCP 0.0.0.0:1839 0.0.0.0:0 LISTENING
TCP 0.0.0.0:2233 0.0.0.0:0 LISTENING
TCP 0.0.0.0:18018 0.0.0.0:0 LISTENING
TCP 10.0.1.115:139 0.0.0.0:0 LISTENING
TCP 127.0.0.1:1027 127.0.0.1:1839 ESTABLISHED
TCP 127.0.0.1:1028 127.0.0.1:18018 ESTABLISHED
TCP 127.0.0.1:1839 127.0.0.1:1027 ESTABLISHED
TCP 127.0.0.1:18018 127.0.0.1:1028 ESTABLISHED
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:4000 *:*
UDP 0.0.0.0:4001 *:*
UDP 0.0.0.0:6000 *:*
UDP 0.0.0.0:6001 *:*
UDP 0.0.0.0:6002 *:*
UDP 0.0.0.0:6003 *:*
UDP 0.0.0.0:6004 *:*
UDP 0.0.0.0:6005 *:*
UDP 0.0.0.0:7557 *:*
UDP 0.0.0.0:7560 *:*
UDP 10.0.1.115:137 *:*
UDP 10.0.1.115:138 *:*
UDP 127.0.0.1:1049 *:*
UDP 127.0.0.1:1255 *:*
UDP 127.0.0.1:1353 *:*
UDP 127.0.0.1:1774 *:*
UDP 127.0.0.1:2225 *:*
--------------------------------------------------------------------------------
从注册表上看 系统没有打过补丁 相对应的补丁
________________________________________________________________________________
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB833509]
"Installed"=dword:00000001
"Comments"="Windows XP 修补程序包 - KB833509"
"Backup Dir"=""
"Fix Description"="Windows XP 修补程序包 - KB833509"
"Installed By"=""
"Installed On"=""
"Service Pack"=dword:00000002
"Valid"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB833509\File 1]
"Flags"=""
"New File"=""
"New Link Date"=""
"Old Link Date"=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q147222]
"Installed"=dword:00000001
________________________________________________________________________________
Remote Procedure Call (RPC)提供终结点映射程序 (endpoint mapper) 以及其它RPC 服务。已启动自动本地系统
以前溢出可以成功的 现在就不可以拉 |