病毒通过修改cr0寄存器标志位的方法关闭写保护,然后替换KeServiceDescriptorTable中的函数地址来Hook API,并记下原函数的地址。病毒挂接了如下两个API:







Type Malware

Type Description Malware ("malicious software") consists of software with clearly malicious, hostile, or harmful functionality or behavior and that is used to compromise and endanger individual PCs as well as entire networks.

Category Rootkit

Category Description A Rootkit is software that cloaks the presence of files and data to evade detection, while allowing an attacker to take control of the machine without the user"s knowledge. Rootkits are typically used by malware including viruses, spyware, trojans, and backdoors, to conceal themselves from the user as well as from malware detection software such as anti-virus and anti-spyware applications. Rootkits are also used by some adware applications and DRM (Digital Rights Management) programs to thwart the removal of that unwanted software by users.

Level High

Level Description High risks are typically installed without user interaction through security exploits, and can severely compromise system security. Such risks may open illicit network connections, use polymorphic tactics to self-mutate, disable security software, modify system files, and install additional malware. These risks may also collect and transmit personally identifiable information (PII) without your consent and severely degrade the performance and stability of your computer.

Advice Type Remove

Release Date

Last updated on Jun 12 2008

File Traces


Exploit 的英文意思就是利用,它在黑客眼里就是漏洞利用。有漏洞不一定就有Exploit(利用),有Exploit就肯定有漏洞。们几乎每隔几天就能听到最近有一个新发现的可以被利用(exploit)的漏洞(vulnerability),然后给这个漏洞打上补丁。而事实上,这里面的内容比你想象的要多,因为你不可能知道所有软件的漏洞,而且那些可利用的漏洞也只是被少数人所了解。漏洞是存在于一个程序、算法或者协议中的错误,可能带来一定的安全问题。但不是所有的漏洞都是能够被利用来攻击(exploitable)的,理论上存在的漏洞,并不代表这个漏洞足以让攻击者去威胁你的系统。一个漏洞不能攻击一个系统,并不代表两个或多个漏洞组合就不能攻击一个系统。例如:空指针对象引用(null-pointer dereferencing)漏洞可以导致系统崩溃(如果想做拒绝服务攻击就足够了),但是如果组合另外一个漏洞,将空指针指向一个你存放数据的地址并执行,那么你可能就利用此来控制这个系统了。发现可利用的漏洞进行攻击一个利用程序(An exploit)就是一段通过触发一个漏洞(或者几个漏洞)进而控制目标系统的代码。攻击代码通常会释放攻击载荷(payload),里面包含了攻击者想要执行的代码。exploits利用代码可以在本地也可在远程进行。一个远程攻击利用允许攻击者远程操纵计算机,理想状态下能够执行任意代码。远程攻击对攻击者非常重 要,因为攻击者可以远程控制他/她的主机,不需要通过其它手段(让受害者访问网站,点击一个可执行文件,打开一个邮件附件等等),而本地攻击一般都是用来提升权限
WordPress是著名的开源CMS(内容管理)系统。近日,在4.0版本以下的Wordpress被发现存在跨站脚本漏洞(XSS),新版本的Wordpress已经修复了这些问题。为了安全起见,建议站长们尽早更新到WP新版本。 该漏洞是由芬兰IT公司Klikki Oy的CEO Jouko Pynnonen发现的,只存在于Wordpress4.0以下的版本中。据调查得知全球有86%的Wordpress网站都感染了这一漏洞,也就意味着全球数百万的网站都存在着潜在的危险。一些知名网站也使用了Wordpress软件,如Time、UPS、NBC Sports、CNN、Techcrunch 和FreeBuf:) 漏洞概述 WordPress中存在一系列的跨站脚本漏洞,攻击者利用跨站脚本伪造请求以欺骗用户更改登录密码,或者盗取管理员权限。 如Jouko Pynnonen解释道: 当博客管理员查看评论时,评论中的漏洞代码会自动在其Web浏览器上运行。然后恶意代码会偷偷接管管理员账户,从而执行管理员操作。 为了证明他们的观点,研究人员创建了一个漏洞利用程序(exploits)。利用这个exploits,他们创建了一个新的WordPress管理员账户,改变了当前管理员密码,并在服务器上执行了攻击PHP代码。 漏洞分析 问题出在wordpress的留言处,通常情况下留言是允许一些html标签的,比如、、等等,然而标签中有一些属性是在白名单里的,比如标签允许href属性,但是onmouseover属性是不允许的。 但是在一个字符串格式化函数wptexturize()上出现了问题,这个函数会在每一个留言上执行,函数的功能是把当前的字符转义成html实体,比如把“”转义为“”。为了防止干扰html格式,wptexturize()首先会以html标签为标准把文本分成若干段,除了html标签,还有方括号标签比如[code]。分割的功能是由下列正则表达式完成的。 在wp-includes/formatting.php代码的第156行: $textarr = preg_split(‘/(<.*>|[.*])/Us", $text, -1, PREG_SPLIT_DELIM_CAPTURE); 但是如果文章中混合着尖括号<>和方括号[]会造成转义混淆,导致部分代码没有转义。 攻击者可以通过这个漏洞在允许的HTML标签中注入样式参数形成XSS攻击,比如通过建立一个透明的标签覆盖窗口,捕捉onmouseover事件。 漏洞利用测试 以下代码可以用于测试 [[” NOT VULNERABLE] 修复建议 这一漏洞很容易被攻击者利用,WordPress官方建议用户尽快更新补丁,而在新版WordPress 4.0.1已经修复了所有的漏洞。 WordPress官方于11月20日发布了官方补丁,目前大多数的WordPress网站上都会收到补丁更新提醒通知;如果有一些其他原因使得你无法更新补丁,Klikki Oy公司还提供了另外一个解决方案(workaround)可以修复该漏洞。 wptexturize可以通过在wp-includes/formatting.php开头增加一个返回参数避免这个问题: function wptexturize($text) { return $text; // ADD THIS LINE global $wp_cockneyreplace; 额外提醒 如果你使用的是WP-Statistics WordPress插件,你也应该更新补丁。因为这些插件上也存在跨站脚本漏洞,攻击者同样可以实施攻击。
2023-06-05 11:30:021


您好,非常高兴为您解答:使用metasploit检测网站1.打开metasploit并输入命令show exploits会显示出目前可以使用的exploits;2.从显示出来的漏洞中找关于windows/browser开头的信息,找到lnk漏洞名称3.输入命令use exploit名称,使用该漏洞,并输入show options查看详细信息;可以看到默 认设置无需在配置4.使用show payloads查看该漏洞可以使用的padyload,会显示出很多可用的payloads5.使用set PAYLOAD payload 来设置该测试使用的payload,我们使用的payload如图所示并设置目标IP为,该IP为目标机的IP地址。6.然后使用exploit来生成漏洞利用程序,7.将http://复制并在目标机种打开ie并输入该url,即可完成测试。在metasploit端会显示如下信息,8.然后该渗透测试已经成功,只需进入该测试产生的sessions即可获得目标机的shell,本次渗透测试就算成功了并成功获取目标系统的shell,但这个测试的目标机是虚拟机,没有任何主防及杀毒软件。如果打过补丁或者有杀软是很难成功的!希望可以帮助到您!
2023-06-05 11:30:091

kali的show exploits为什么什么都不显示

应该先执行msfconsole命令启动Metasploit,show exploits是Metasploit内部的命令,不能直接在Kali中执行的。
2023-06-05 11:30:161


许多人喜欢阅读侦探小说听过福尔摩斯迷和一些文学家,而不是爵士福尔摩斯.杜可风的背后写的所有攻击福尔摩斯迷和一些文学家,著名侦探,其中他的名字命名的美国作家.伊尔生于苏格兰,在1859年.他的儿子,一个艺术家. 嗯,,, 没时间跟你逐字逐字德翻译,
2023-06-05 11:30:277


是什麼意思?是你拿本地msf测试注入你的虚拟机才可以的,但你说的XP系统没反应是你虚拟机上的系统还是你本地的系统?通常测试都是拿虚拟机的系统作为测速,用於测试看看可以通过一些漏洞进去,你本地的系统如果是XP的话,现在的MSF都是64位的,你电脑是多少位?或许有一些漏洞,如果是在虚拟机注入本地XP系统的话,需要看你的虚拟机裏面装的是什麼系统。exploits模块和payloads模块综合利用。举个例子比如Exploitwindows/smb/ms08_067_metapipayload:windows/shell/bind_uptarget:windows xp
2023-06-05 11:30:431


  在教学中,利用经典美文对学生进行 作文 指导和作文训练,能够提高学生的写作水平和技能,促进他们语文素养的全面提升。我精心收集了关于中英互译的英语短文,供大家欣赏学习!   关于中英互译的英语短文:可造就伟人的三大要素   Three Things go to a Prodigy   Three Things go to a Prodigy. They are the choicest gifts of Heaven"s prodigality--a fertile genius, a profound intellect, a pleasant and refined taste.   可造就伟人的三大要素.有三大要素可造就非凡之人。它们是上天慷慨赐予的大礼:丰富的智慧,深刻的判断力和高雅的品味。   To think well is good, to think right is better: u2019tis the understanding of the good. It will not do for the judgment to reside in the backbone: it would be of more trouble than use. To think aright is the fruit of a reasonable nature.    想象力 是一种伟大的秉赋,但是善于推理并能理解善良还要伟大得多。正确的思考是明智心性的果实。   At twenty the will rules; at thirty the intellect; at forty the judgment. There are minds that shine in the dark like the eyes of the lynx, and are most clear where there is most darkness. Others are more adapted for the occasion: they always hit on that which suits the emergency: such a quality produces much and good; a sort of fecund felicity. In the meantime good taste seasons the whole of life.   20岁人的意志力最强,30岁人的智慧力最强;40岁的人的判断力最强。有的人理解力像猫的眼睛一样,它们处于最黑暗的时候却最善于推理判断。有的人则长于随机应变。再纷乱的事物他们也能抓住要害。这种素质是福。至于高雅的品味,它可以使一个人的全部生活充满乐趣。   关于中英互译的英语短文:奏效前不邀功   Do not affect what you have not effected   Do not affect what you have not effected. Many claim exploits without the slightest claim.   奏效前不邀功最没有理由邀功的人往往最自豪。   "With the greatest coolness they makea mystery of all. Chameleons of applause they afford others a surfeit of laughter. Vanity is always objectionable, here it is despicable. These ants of honour go crawling about filching scraps of exploits. The greater your exploits the less you need affect them: content yourself with doing, leave the talking to others.   他们把什么都说得神乎其神,并且表现得若无其事;他们是一心只求别人喝彩的变色龙,徒令人捧腹大笑。虚荣心总是令人反感的。但这种情形比虚荣心还要受人鄙视。有的人为讨取功名,像蚂蚁一样四处攀爬、攒积荣誉。你纵有天大的才华,也应尽量避免虚荣。心安理得地做自己的事,不要理会别人的说法。   Give away your deeds but do not sell them. And do not hire venal pens to write down praises in the mud, to the derision of the knowing ones. Aspire rather to be a hero than merely to appear one.   功劳尽可拱手想让,万不可待价而沽。不要雇佣他人浮夸地对你进行赞美,这样违反常情的举动会惹人耻笑。与其表面上英雄气概,不如立志去拥有英雄品行。   关于中英互译的英语短文:假如我再回到童年   If I Were a Boy Again   If I were a boy again, I would practice perseverance more often, and never give up a thing because it was inconvenient. If I want light, I must conquer darkness.   假如我再回到童年,我会更多地培养自己的毅力,绝不因为事情艰难或者麻烦而撒手不干,我们要光明,就得征服黑暗。   Perseverance can sometimes equal genius in its results. "There are only two creatures," says a proverb, "who can surmount the pyramids —the eagle and the snail.   在产生的效果方面,毅力往往可以与天才相媲美。 谚语 说:"能登上金字塔的生物只有两种——雄鹰和蜗牛。"   "If I were a boy again, I would school myself in the habit of attention. I would let nothing come between myself and the subject in hand. I would remember that a good skater never tries to skate in two directions at the same time. The habit of attention becomes part of our life, if we begin early enough. I often hear grown- ups say "I could not fix my attention on the book, although I wanted to do so", and the reason is that the habit was not formed in youth.   假如我再回到童年,我就要养成专心致志的习惯。有事在手,就绝不允许任何东西让我分心。我要牢记:一位优秀的滑冰手从不试图同时滑向两个不同的方向。如果及早养成专心致志的习惯,它将成为我们生命的一部分。我常听成年人说:"尽管我希望能集中注意力读书,但往往做不到。"其原因就在于年轻时没有养成这种习惯。   If I were to live my life over again, I would pay more attention to the cultivation3 of my memory. I would strengthen that faculty by every possible means and on every possible occasion. It takes a little hard work to remember things accurately at first, but memory soon helps itself and gives very little trouble. It only needs early cultivation to become a skill.   假如我能重新活过,我会更注意培养自己的 记忆力 。我要采取一切可能的办法,在一切可能的场合, 增强记忆力 。要正确无误地记住一些事物,起初的确要做出一番小小的努力;但要不了多久,记忆力本身就会起作用,使记忆成为轻而易举的事。只需及早培养,记忆自会成为一种才能。
2023-06-05 11:32:531

MS14-068 Kerberos域用户提权漏洞

Kerberos协议是一种基于第三方可信主机的计算机网络协议,它允许两个实体之间在非安全网络环境(可能被窃听、被重放攻击)下以一种安全的方式证明自己的身份。 远程权限提升漏洞存在于 Microsoft Windows 的 Kerberos KDC 实现中。存在该漏洞的症状是,Microsoft Kerberos KDC 实现无法正确验证签名,这可能造成 Kerberos 服务票证的某些方面被人伪造。简单来说就是一个域内的普通账户可以利用此漏洞进行权限提升,升级为域管理员权限。 漏洞需要以下四样道具 MS14-068是横向移动Pass the Ticket技术的一种,利用Kerberos认证机制进行攻击。除此之外,常见的还有金票攻击和银票攻击。本次不再详细介绍。 T1550.003 Use Alternate Authentication Material: Pass the Ticket 票据传递 T1558.001 Steal or Forge Kerberos Tickets: Golden Ticket 黄金票据 T1558.002 Steal or Forge Kerberos Tickets: Silver Ticket 白银票据 查看系统补丁情况,没有打KB3011780补丁的机器是可以利用的 查看用户的SID 获得SID 还可以使用这条命令获取域内所有用户的 SID: PyKEK 是一个利用 Kerberos 协议进行渗透的工具包,使用 PyKEK 可以生成一个高权限的服务票据,之后通过 mimikatz 将服务票据导入到内存中。 github 上面的python脚本需要python2.7的环境,也可以把py文件打包为exe,github上有人已经完成,使用方法和py脚本一样,如果担心安全问题,也可以自己打包。 exe: 输入 在同级目录下生成票据 注入之前,查看域控的共享C盘,显示权限不足:(注意: 这边需要使用域控的完整名称 ) 清除票据 注入高权限票据 访问域控C盘共享,查看权限 阅读资料: IPC共享知识 接下来进一步尝试获取域控的shell,使用 PsExec64.exe ,下图可以看到我们已经获取了域控的shell。下一步可以根据自己的习惯进行一些持久化操作,例如添加域控账号等。 攻击脚本为,该脚本是 impacket 工具包里面的 打包好的exe版本 以下的缓解措施基于ATT&CK给出 M1026 Privileged Account Management 特权账户管理 M1051 Update Software 更新软件 M1052 User Account Control 用户账户控制 M1018 User Account Management 用户账户管理 Audit all logon and credential use events and review for discrepancies. Unusual remote logins that correlate with other suspicious activity (such as writing and executing binaries) may indicate malicious activity. NTLM LogonType 3 authentications that are not associated to a domain login and are not anonymous logins are suspicious. Event ID 4768 and 4769 will also be generated on the Domain Controller when a user requests a new ticket granting ticket or service ticket. These events combined with the above activity may be indicative of an overpass the hash attempt.[ 1] 监控LogonType为3且认证数据包为NTLM的登录日志 监控域控服务器上4768和4769的事件,并关联LogonType为3且认证数据包为Kerberos的登录日志。 参考连接:
2023-06-05 11:33:001


1 wizard, please tell the princess, Lao tze exploits in the road, and did not turn, the snow had been killed, beauty, dragon not make... Call her to die to sleep! 1 then forced me to push me to give you feign death!2 Lao tze not only a car, or own!3 I despise so many people, who are you?4 I also don"t say, haven"t you make beauty program!5. I only good luck, beriberi is good!6 there is a mirror of!7. Handsome a P? Maybe not to eat by pawns!8. To me, you don"t trust, no matter that can"t be wrong!9. Don"t be nervous, I am not a good...10) don"t thank, thanks to your finish is damned money!11. Don"t say with me - I"m make.come forward avanty!12 you ignore me, my dog ignored!13. When the moon is, ask easy meridian passage!14 reach on foot, on the left15. Some people live, she"s dead. Some people alive, he should have died!16 you say... Do you like me? Actually... I started to... Actually I also... Alas say with you, I also like myself.17. Are you drinking water, or drink, or? Whatever you choose!The castle is in, just a little red.19. Ah, said that the whispered shouldn"t say.The child had ever yue: don"t put me on your tolerance for you shameless capital!21. Don"t think I would think my long handsome unreachable, actually I"m rivers.And it"s a nice day today, it"s windy.For as the typical failure, you really great success!24. Three feet of death a cobbler smelly.25 in the red YeFeng the golden...26 I"m tired you lend arrows to tie grass on the boat!And the wind, cold, xiao xi xi you owe money to return!A: go and eat? I have no money.B: dined out in a restaurant, I ShuiGuanZi - please.29 a fall under the declining?30 I left, right, waist lines qinglong tiger a Mickey Mouse.31. A: vengeance will be mine! This evil spirit to swallow.B: how can you died?32 I thigh fat she twisted her arm but.33. Everybody has to do is clean, the road is short time as porridge.34. The world is ours, and his sons, but ultimately is the grandchildren.35 homework! I wrote it!A: 36 for homework yet?B: sit down! Here, in the P strands, still under the warm... You want to? It for you.37 the dealer who today, even the blackboard are not wipe!38) was really blind my eyes...39. The blind is a blind man?2 I isn"t literally of person, but literally isn"t a person.3 I turned in the river, but not about me呵呵 我自己翻译的哦
2023-06-05 11:33:096

