原帖由 <i>cyano</i> 于 2007-5-8 22:56 发表 <a href="http://bbs.ioage.com/redirect.php?goto=findpost&pid=296959&ptid=33212" target="_blank"><img src="http://bbs.ioage.com/images/common/back.gif" border="0" onload="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onmouseover="if(this.width>screen.width*0.7) {this.resized=true; this.width=screen.width*0.7; this.style.cursor='hand'; this.alt='Click here to open new window\nCTRL+Mouse wheel to zoom in/out';}" onclick="if(!this.resized) {return true;} else {window.open('http://bbs.ioage.com/images/common/back.gif');}" onmousewheel="return imgzoom(this);" alt="" /></a><br />
个人感觉 Microsoft Windows GDI WMF远程拒绝服务漏洞(MS07-017)危害程度并不是很高
即使不打安全补丁,在打开这类文件时也只会造成蓝屏或死机而已,重启就恢复了.
况且之所以要在网页上挂木马,绝大多数是因为能从中通过肉鸡盗号之类获利.
显然GDI漏洞 (MS07-017 )并不能为挂马者盈利.