| ²é¿´: 422 | »Ø¸´: 2 | |||
| µ±Ç°Ö÷ÌâÒѾ´æµµ¡£ | |||
sdlj8051½ð³æ (ÖøÃûдÊÖ)
|
[½»Á÷]
[zt]¹ØÓÚÂýËÙ¸ÐȾÓëÂýËÙ¶à̬±äÐεÄÕùÂÛ
|
||
|
ÔÎÄ£º http://vx.netlux.org/lib/vrw01.html ¹Ø¼ü´Ê£º ÂýËÙ¸ÐȾ ÂýËÙ¶à̬±äÐÎ 0ÒëÕß×¢ 1.¹ØÓÚ´«²¥ËÙ¶ÈÓн϶àµÄÕùÂÛ£¬ÈÊÕß¼ûÈÊ£¬Kris KasperskyµÄ¡¶Shellcoder's Programming Uncovered¡·ÖжÔÈ䳿´«²¥ËٶȵÄÌÖÂÛÓë´ËÀàËÆ£¬ÓÐÐËȤÕß¿ÉÒԲο¼¡£ 2.±¾ÎÄÖÐËùÌÖÂ۵ķ½·¨ÒѾ¹ýʱ£¬µ«¹ØÓÚÂýËÙ¸ÐȾ¼°ÂýËÙ¶à̬±äÐεÄÏë·¨¿ÉÒÔ½è¼ø£¬Ï£Íû¶ÁÕßÄܾÙÒ»·´Èý£¬¶ø²»ÊǾÐÄàÓÚ±¾ÎĵÄÄÚÈÝ¡£ 1ÂýËÙ´«²¥Õß Ðí¶àÈËÈÏΪ¿ìËÙ´«²¥Õß±ÈÂýËÙ´«²¥ÕßÒªºÃһЩ£¬µ«ÎÒ²¢²»ÕâÑùÈÏΪ¡£²¡¶¾µÄÄ¿±êÊǾ¡¿ÉÄÜ´«²¥¸ü¶àµÄÖ÷»ú¡£ÄãÈÏÎªÄØ£¿ ¶ÔÓÚÂýËÙ¸ÐȾµÄ²¡¶¾À´Ëµ£¬Ëü±ØÐë×ö£º 1. ²»ÒýÆð×¢Òâ£¨ÃØÃÜÐж¯£©¡£ 2. ¸ÐȾµ±Ç°Ö÷»úÉÏÓпÉÄÜÍâ³öµÄÎļþ¡£ OK£¬Òò´Ë£¬ÎÒÃÇдһ¸öÃØÃܵĿìËÙ´«²¥Õߣ¬ËüÄܹ¤×÷Á¼ºÃÂ𣿴íÁË¡ ÏÂÃæÊÇһЩÀíÓÉ£¬µÚÒ»µã¿ÉÒÔ·Ö³ÉÁ½²¿·ÖÀ´¿´£º 1.1 ²»Äܱ»¼ì²â£¨Îļþ£¯´ÅÅÌ Òþ²Ø£©¡£ 1.2 ²»Äܱ»Óû§×¢Òâµ½£¨ÔËÐÐËÙ¶È£¬ÄÚ´æÕ¼Ó㬴ÅÅ̿ռäÕ¼Óã©¡£ ´ó²¿·Ö±à³ÌÕߺöÂÔÁË1.2£¬´Ó¶øÊ¹ËûÃǵIJ¡¶¾ÔÚÖ÷»úϵͳÉϷdz£ÏÔÑÛ¨D¨Dµ¼ÖÂϵͳÐÔÄÜϽµ£¬ÓÐʱºò¾ÍÏñÎÏÅ£ÅÀÒ»Ñù¡£ ÔÚ²¡¶¾ÂÛ̳ÀÎÒÃÇ¿´µ½¹ýºÜ¶àÕâÑùµÄÌû×Ó£¬¡°ÎÒ×¢Òâµ½ÓÐЩÒì³£¨D¨DÒò´Ë£¬ÎÒ×öÁËһЩµ÷²éÑо¿£¬·¢ÏÖÁËX²¡¶¾¨D¨DÎÒÔõôÇå³ýËüÄØ£¿¡± £ ÎÒÃǵÄÄ¿±êÊÇÊ×ÏȱÜÃâÓû§²úÉúÕâÖÖ²ÂÒÉ¡£ ÏëÏëAIDS£¯HIV£¿ËüÔÚÊܸÐȾµÄÈËÌåÄÚDZ·ü³¬¹ý10Ä꣬ÆÚ¼ä»á²»¶Ï¸ÐȾÓëÖ®½Ó´¥µÄÈË£µ«Ö»ÏÔʾÁ˺ÜÉÙµÄÖ¢×´¡£ ÕâÖÖµÀÀíͬÑù¿ÉÓ¦Óõ½²¡¶¾´«²¥ÉÏ£¬ËüÃDz»ÄܽµµÍϵͳÐÔÄÜ»òÒýÆð²»¼æÈÝ£¨QEMM Òì³££¯±ÀÀ££¬µÈµÈ£©£¬ÒòΪÈËÃǷdz£ÔÚÒâ¼ÆËã»úÔËÐÐ×´¿ö¿ÉÄܳöÏֵIJîÒì¡£ Õâµ¼ÖÂÎÒÃDzÉÓÃÂýËÙ¸ÐȾ¼¼Êõ£¬ÏÖÔÚ£¬Èç¹ûÄ¿±êÊÇʹ²¡¶¾¸ÐȾÁíÍâµÄϵͳ£¬ÄÇÎÒÃÇÐèÒª×öµÄÊǸÐȾÄÇЩ·Ç³£ÓпÉÄܱ»ÒƵ½ÁíÍâ¼ÆËã»úϵͳÉϵÄÎļþ£¬ÕâЩÎļþÊÇ£º 1. ÈíÅÌÉϵÄÎļþ¡£ 2. ÍøÂ磯Զ³ÌÉ豸ÉϵÄÎļþ¡£ 3. ÔÚͨÐųÌÐòÄÚ´ò¿ªµÄÎļþ¡£ 4. ÔÚѹËõ³ÌÐòÄÚ´ò¿ªµÄÎļþ¡£ 5. ÔÚ±¸·Ý³ÌÐòÄÚ´ò¿ªµÄÎļþ¡£ ËùÓÐÕâЩÎļþ¶¼Óлú»áÀ뿪ϵͳ¡£ ÈíÅÌ£º- 14-y/o µÁ°æÕßÓÃËüÃǽ»»»ÓÎÏ·£¬ÊǽüºõÍêÃÀµÄ½Ó´¥ÆäËüÖ÷»úµÄ·½·¨¡£ ÍøÂçÉ豸£º- Èç¹ûÄãÓг¬¼¶Óû§·ÃÎÊȨÏ޵ϰÕâÌØ±ðÓÐÓã¬Äã¾ÍÓлú»á¸ÐȾÏñlogin.exeÖ®ÀàµÄÎļþ£¬ÄÇôÄã¾ÍÓÐ250̨£¨»ò¸ü¶à£¡£©³ÉΪ¸ÐȾԴµÄ¼ÆËã»ú¡£ N.B., Novell NetwareÔÊÐí°ÑÍêÕûµÄ¿ÉÒýµ¼ÅÌ×öΪÎļþ±£´æÔÚ·þÎñÆ÷ÉÏ¡£ Òò´Ë£¬ÍøÂç¿Í»§¶Ë¿ÉÒÔ´Ó·þÎñÆ÷ÉϵÄÎļþÆô¶¯¡£ÕâЩÎļþÒ²ÊǷdz£ÓÐÓõÄÄ¿±ê£¬µ«ÊÇÎÒȱ·¦ÕâÑùµÄÍøÂç»·¾³À´Éú³É£¯²âÊÔÕâÑùµÄ²¡¶¾¡£ ͨÐųÌÐò£º£ÉÏ´«EXE£¯COMÎļþµÄÈ˶¼ÓÐËûµÄÀíÓÉ£¨»òÐíÊÇ·¢¸øÄ³¸öÈË£©¡£ÊÇÁíÍâÍêÃÀµÄ¸ÐȾһ̨»ò¶ą̀Ö÷»úµÄ·½·¨¡£ ѹËõ³ÌÐò£º£Í¨³£ÊÇÔÚÓÃͨÐųÌÐòÉÏ´«£¯ÏÂÔØÇ°ÓÃÀ´Ñ¹ËõÈí¼þ£¬ÓÚÊÇ£¬Èç¹ûÎÒÃÇÔÚѹËõµÄ¹ý³ÌÖиÐȾEXE£¯COM³ÌÐò£¬ÄÇÎÒÃǾÍÓзdz£ºÃµÄ»ú»áʹÍâ³ö¼û¼ûÊÀÃæ¡£ ±¸·Ý³ÌÐò£º£Õâ¿ÉÒÔÔ¤·À´ÓÖ÷»úÉÏÒÆÈ¥ÎÒÃǵIJ¡¶¾££Èç¹ûÓû§Í¨¹ýAV³ÌÐò·¢ÏÖÁ˲¡¶¾£¬ÄÇÎÒÃÇ»¹Óлú»áÖØÐ¸ÐȾËü¡£ ͼʾ£º .-<<--backups-----. .HOST SYSTEM------------------|---. | |.------------------..--------'--.|----------> floppies ||ethernet/modem/fdd|| HARD DISK ||----------> network |'------------------''--------.--'|----------> modem/comms '-----------------------------|---' | '-compressed-->>--' ¸ÐȾӲÅÌÎļþÓô¦²»´ó£¬Òò´ËËüÃÇ´ÓÀ´²»»áËÄ´¦Ïй䣲»Ïñ¸ÐȾÈíÅÌ£¬ÍøÂçºÍͨÐÅͨµÀµÄÎļþÄÇÑù¡£ È·±£ÄãµÄ²¡¶¾ÔÚÆäËü³ÌÐòǰ±»¼ÓÔØÊǸöºÃÖ÷Ò⣬ÕâÑùÒ»À´¿ÉÒÔÈ·±£²¡¶¾»î¶¯ÃØÃÜÐж¯¡£ ÄãÓ¦¸Ã×Ô¶¯¸ÐȾ\COMMAND.COM»ò°Ñ²¡¶¾·Ö³É¶à²¿·Ö£¨¸ÐȾmbr/track 0£©¡£ 1.1ÕâЩ·½·¨µÄʵÏÖ£º ×îºÃµÄʵÏÖ·½·¨ÊÇ£º Floppy diskette and CDR (CD-ROM Writers) check: Use AX=4408, DL=Logical Drive#, INT 21h Network/Remote check: Use AX=4409, DL=Logical Drive#, INT 21h Use AX=440A, BX=File Handle, INT 21h Comms/Compression/Backup check: ÓÃLUT£¨lookup table£©½ûÖ¹ÃØÃܻ£¬²¢ÔÚÊʵ±µÄʱºò¼¤»î¿ìËÙ´«²¥Õߣº 'CHKDSK' - Stops CHKDSK errors (well known). 'SCANDISK' - Ditto. 'NDD' - Ditto. 'PKLITE' - Protect virus in PKLITE compression wrapper. 'DIET' - Protect virus in DIET compression wrapper. 'LZ' - Protect virus in LZEXE compression wrapper. 'TM' - Telemate, to infect EXE/COM uploads. 'TE' - Telix/Terminate, to infect EXE/COM uploads. 'BACKUP' - To infect executable backups. 'MSBACKUP' - Ditto. 'CPBACKUP' - Ditto. µ±Ñ¹Ëõ³ÌÐòÊä³öÎļþ±»´ò¿ªÊ±£¬Ò²ÓÃÏÂÃæµÄLUTÀ´²é¿´¡£ 'ZIP' - PKZIP tmpfile extension opened. 'LZH' - LHA tmpfile extension opened. 'ARJ' - ARJ tmpfile extension opened. 'ARC' - ARC tmpfile extension opened. 'RAR' - RAR tmpfile extension opened. µ±Äã½ØÈ¡INT 21h AH=3CºÍINT 21h AH=3Dµ÷ÓÃʱ£¬¼ì²éÎļþµÄºó׺¡£ Èç¹û±»´ò¿ªµÄÎļþÊÇÉÏÊöµÄÒ»ÖÖ£¬ÄÇô¼¤»î¿ìËÙ´«²¥Õß²¢½ûÖ¹ÃØÃܻ¡£ µ±Ëü±»¹Ø±Õʱ£¨ÓÃSFTÀ´¼ì²éAX=1220/INT2F AX=1216/INT2F£©£¬ÖØÐÂÆôÓÃÂýËÙ´«²¥Õß²¢ÖØÐÂÆôÓÃÃØÃܻ¡£ 2ÂýËÙ¶à̬±äÐÎ ÂýËÙ¶à̬±äÐβ¶àʹAVÍÅÌåÏÝÈëÁËÎÞ¾¡µÄ·³ÄÕÖ®ÖУ¬¹ØÓÚÕâ¸öÎÊÌâûÓÐÌ«¶àµÄÕùÒé¡£ ÕâЩÈË£¨AVer£©Ã¿Ìì¶¼»áÊÕµ½Ðí¶à²¡¶¾£¬ËûÃDz»¿ÉÄÜ·´»ã±àÿһ¸ö²¡¶¾À´¿´¸öÏêϸ£¬Õâ¶ÔÎÒÃÇÀ´ËµÊǸöºÃÏûÏ¢£¬ÒòΪÕâÒâζ×ÅÎÒÃÇÄÜʹËûÃÇÏÝÈëÀË·Ñʱ¼äµÄ·³ÄÕÖ®ÖС£ Èç¹ûÔÙºÍRajaat²ûÊöµÄanti-goat¼¼Êõ½áºÏÆðÀ´Ê¹Ó㬽«»áʹËûÃÇÏ൱µÄ·³ÄÕ¡£AVÍÅÌåΪÁËÏÂÃæµÄÄ¿µÄ£¬½«²»µÃ²»»¨ÉÏÖÁÉÙÒ»ÌìµÄʱ¼ä·ÖÎöºÃµÄ¶à̬±äÐβ¡¶¾£º a£©Ê¹Ëü¸ÐȾËûÃǵġ°Ìæ×ïÑò¡±Îļþ b£©Ê¹Ëü²úÉú´óÁ¿µÄÑù±¾£¨¶ÔÓÚSMEGÀ´Ëµ£¬ÎÒÈÏΪ´ó¸ÅÄÜÉú³É200,000¸öÑù±¾£©¡£ BTW: Èç¹ûÄã¾ö¶¨Ê¹ÄãµÄ´úÂëÒÀÀµanti-goat´úÂëµÄÍêÕûÐÔ£¬ÄÇôÄ㽫·¢ÏÖÑо¿Ô±ÔÚÎ¹Ñø200,000¸ö²¡¶¾Ñù±¾Ê±»áÓиü¶àµÄÎÊÌ⣺£© 2.1ʵÏÖ ¶à̬±äÐιý³Ì»ùÓÚËæ»úÊýµÄÉú³É£¬ÔõÑùÑ¡ÔñÒ»¸öÂýËÙÉú³ÉµÄËæ»úÊýÄØ£¿ÎÒÄÜÏëµ½µÄÁ½¸ö·½·¨ÊÇ£º 1. BIOS date. -·Ç³£ÂýµÄ¶à̬±äÐΣ¬½ö¸ù¾Ýÿ¸ö¼ÆËã»ú¶ø¸Ä±ä£¡ 2. µ±ÌìµÄÈÕÆÚ. -·Ç³£Âý¡£ ------------------------------------------------------------- 1. push 0FFFF pop ds mov si,0005 ;DS:SI -> FFFF:0005 (8 bytes). xor bx,bx ;value=0 mov cx,4 ;size=4 words. L1: lodsw ;fetch word. add bx,ax ;checksum. loop L1 ;next 3 words. mov ds:rnd_seed,bx ;set seed. ------------------------------------------------------------- 2. mov ah,2A int 21 ;get date. rol dx,cl ;random adjustment. xor dx,cx ;place cx into eqn. mov ds:rnd_seed,dx ;set seed. -------------------------------------------------------------------------------- [ Last edited by sdlj8051 on 2006-12-24 at 23:34 ] |
» ²ÂÄãϲ»¶
08¹¤Ñ§µ÷¼Á
ÒѾÓÐ11È˻ظ´
350Çóµ÷¼Á
ÒѾÓÐ6È˻ظ´
Çóµ÷¼ÁÒ»Ö¾Ô¸Î人Àí¹¤´óѧ²ÄÁϹ¤³Ì£¨085601£©
ÒѾÓÐ4È˻ظ´
Ò»Ö¾Ô¸ÖØÇì´óѧ085700×ÊÔ´Óë»·¾³£¬×Ü·Ö308Çóµ÷¼Á
ÒѾÓÐ6È˻ظ´
½ÓÊÕ2026˶ʿµ÷¼Á(ѧ˶+ר˶)
ÒѾÓÐ6È˻ظ´
081700 µ÷¼Á 267·Ö
ÒѾÓÐ5È˻ظ´
328Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
0854 ¿¼Ñе÷¼Á ÕÐÉúÁË£¡AI ·½Ïò
ÒѾÓÐ14È˻ظ´
ÕÐ08¿¼Êýѧ
ÒѾÓÐ14È˻ظ´
Ò»Ö¾Ô¸ÉϺ£½»´óÉúÎïÓëҽҩר˶324·Ö£¬Çóµ÷¼Á
ÒѾÓÐ4È˻ظ´
sdlj8051
½ð³æ (ÖøÃûдÊÖ)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ¹ó±ö: 0.1
- ½ð±Ò: 1149.8
- ºì»¨: 3
- Ìû×Ó: 2254
- ÔÚÏß: 18.1Сʱ
- ³æºÅ: 71297
- ×¢²á: 2005-05-30
- רҵ: µç·Óëϵͳ
2Â¥2006-09-17 20:00:10
gph-rabbit
½ð³æ (СÓÐÃûÆø)
- Ó¦Öú: 0 (Ó×¶ùÔ°)
- ½ð±Ò: 6187.4
- Ìû×Ó: 141
- ÔÚÏß: 85.2Сʱ
- ³æºÅ: 283155
- ×¢²á: 2006-10-08
- רҵ: ÐÅÏ¢°²È«
3Â¥2006-12-29 01:12:59













»Ø¸´´ËÂ¥