²é¿´: 425  |  »Ø¸´: 2
µ±Ç°Ö÷ÌâÒѾ­´æµµ¡£

sdlj8051

½ð³æ (ÖøÃûдÊÖ)

[½»Á÷] [zt]¹ØÓÚÂýËÙ¸ÐȾÓëÂýËÙ¶à̬±äÐεÄÕùÂÛ

Ô­ÎÄ£º  http://vx.netlux.org/lib/vrw01.html
¹Ø¼ü´Ê£º  ÂýËÙ¸ÐȾ ÂýËÙ¶à̬±äÐÎ



0ÒëÕß×¢
1.¹ØÓÚ´«²¥ËÙ¶ÈÓн϶àµÄÕùÂÛ£¬ÈÊÕß¼ûÈÊ£¬Kris KasperskyµÄ¡¶Shellcoder's Programming Uncovered¡·ÖжÔÈ䳿´«²¥ËٶȵÄÌÖÂÛÓë´ËÀàËÆ£¬ÓÐÐËȤÕß¿ÉÒԲο¼¡£
2.±¾ÎÄÖÐËùÌÖÂ۵ķ½·¨ÒѾ­¹ýʱ£¬µ«¹ØÓÚÂýËÙ¸ÐȾ¼°ÂýËÙ¶à̬±äÐεÄÏë·¨¿ÉÒÔ½è¼ø£¬Ï£Íû¶ÁÕßÄܾÙÒ»·´Èý£¬¶ø²»ÊǾÐÄàÓÚ±¾ÎĵÄÄÚÈÝ¡£

1ÂýËÙ´«²¥Õß
Ðí¶àÈËÈÏΪ¿ìËÙ´«²¥Õß±ÈÂýËÙ´«²¥ÕßÒªºÃһЩ£¬µ«ÎÒ²¢²»ÕâÑùÈÏΪ¡£²¡¶¾µÄÄ¿±êÊǾ¡¿ÉÄÜ´«²¥¸ü¶àµÄÖ÷»ú¡£ÄãÈÏÎªÄØ£¿
¶ÔÓÚÂýËÙ¸ÐȾµÄ²¡¶¾À´Ëµ£¬Ëü±ØÐë×ö£º

    1. ²»ÒýÆð×¢Òâ£¨ÃØÃÜÐж¯£©¡£
    2. ¸ÐȾµ±Ç°Ö÷»úÉÏÓпÉÄÜÍâ³öµÄÎļþ¡£

OK£¬Òò´Ë£¬ÎÒÃÇдһ¸öÃØÃܵĿìËÙ´«²¥Õߣ¬ËüÄܹ¤×÷Á¼ºÃÂ𣿴íÁË¡­

ÏÂÃæÊÇһЩÀíÓÉ£¬µÚÒ»µã¿ÉÒÔ·Ö³ÉÁ½²¿·ÖÀ´¿´£º

    1.1 ²»Äܱ»¼ì²â£¨Îļþ£¯´ÅÅÌ Òþ²Ø£©¡£
    1.2 ²»Äܱ»Óû§×¢Òâµ½£¨ÔËÐÐËÙ¶È£¬ÄÚ´æÕ¼Ó㬴ÅÅ̿ռäÕ¼Óã©¡£

´ó²¿·Ö±à³ÌÕߺöÂÔÁË1.2£¬´Ó¶øÊ¹ËûÃǵIJ¡¶¾ÔÚÖ÷»úϵͳÉϷdz£ÏÔÑÛ¨D¨Dµ¼ÖÂϵͳÐÔÄÜϽµ£¬ÓÐʱºò¾ÍÏñÎÏÅ£ÅÀÒ»Ñù¡£
ÔÚ²¡¶¾ÂÛ̳ÀÎÒÃÇ¿´µ½¹ýºÜ¶àÕâÑùµÄÌû×Ó£¬¡°ÎÒ×¢Òâµ½ÓÐЩÒì³£¨D¨DÒò´Ë£¬ÎÒ×öÁËһЩµ÷²éÑо¿£¬·¢ÏÖÁËX²¡¶¾¨D¨DÎÒÔõôÇå³ýËüÄØ£¿¡± £­ ÎÒÃǵÄÄ¿±êÊÇÊ×ÏȱÜÃâÓû§²úÉúÕâÖÖ²ÂÒÉ¡£
ÏëÏëAIDS£¯HIV£¿ËüÔÚÊܸÐȾµÄÈËÌåÄÚDZ·ü³¬¹ý10Ä꣬ÆÚ¼ä»á²»¶Ï¸ÐȾÓëÖ®½Ó´¥µÄÈË£­µ«Ö»ÏÔʾÁ˺ÜÉÙµÄÖ¢×´¡£
ÕâÖÖµÀÀíͬÑù¿ÉÓ¦Óõ½²¡¶¾´«²¥ÉÏ£¬ËüÃDz»ÄܽµµÍϵͳÐÔÄÜ»òÒýÆð²»¼æÈÝ£¨QEMM Òì³££¯±ÀÀ££¬µÈµÈ£©£¬ÒòΪÈËÃǷdz£ÔÚÒâ¼ÆËã»úÔËÐÐ×´¿ö¿ÉÄܳöÏֵIJîÒì¡£
Õâµ¼ÖÂÎÒÃDzÉÓÃÂýËÙ¸ÐȾ¼¼Êõ£¬ÏÖÔÚ£¬Èç¹ûÄ¿±êÊÇʹ²¡¶¾¸ÐȾÁíÍâµÄϵͳ£¬ÄÇÎÒÃÇÐèÒª×öµÄÊǸÐȾÄÇЩ·Ç³£ÓпÉÄܱ»ÒƵ½ÁíÍâ¼ÆËã»úϵͳÉϵÄÎļþ£¬ÕâЩÎļþÊÇ£º

    1.  ÈíÅÌÉϵÄÎļþ¡£
    2.  ÍøÂ磯Զ³ÌÉ豸ÉϵÄÎļþ¡£
    3.  ÔÚͨÐųÌÐòÄÚ´ò¿ªµÄÎļþ¡£
    4.  ÔÚѹËõ³ÌÐòÄÚ´ò¿ªµÄÎļþ¡£
    5.  ÔÚ±¸·Ý³ÌÐòÄÚ´ò¿ªµÄÎļþ¡£

ËùÓÐÕâЩÎļþ¶¼Óлú»áÀ뿪ϵͳ¡£
ÈíÅÌ£º- 14-y/o µÁ°æÕßÓÃËüÃǽ»»»ÓÎÏ·£¬ÊǽüºõÍêÃÀµÄ½Ó´¥ÆäËüÖ÷»úµÄ·½·¨¡£
ÍøÂçÉ豸£º- Èç¹ûÄãÓг¬¼¶Óû§·ÃÎÊȨÏ޵ϰÕâÌØ±ðÓÐÓã¬Äã¾ÍÓлú»á¸ÐȾÏñlogin.exeÖ®ÀàµÄÎļþ£¬ÄÇôÄã¾ÍÓÐ250̨£¨»ò¸ü¶à£¡£©³ÉΪ¸ÐȾԴµÄ¼ÆËã»ú¡£
N.B., Novell NetwareÔÊÐí°ÑÍêÕûµÄ¿ÉÒýµ¼ÅÌ×öΪÎļþ±£´æÔÚ·þÎñÆ÷ÉÏ¡£  Òò´Ë£¬ÍøÂç¿Í»§¶Ë¿ÉÒÔ´Ó·þÎñÆ÷ÉϵÄÎļþÆô¶¯¡£ÕâЩÎļþÒ²ÊǷdz£ÓÐÓõÄÄ¿±ê£¬µ«ÊÇÎÒȱ·¦ÕâÑùµÄÍøÂç»·¾³À´Éú³É£¯²âÊÔÕâÑùµÄ²¡¶¾¡£
ͨÐųÌÐò£º£­ÉÏ´«EXE£¯COMÎļþµÄÈ˶¼ÓÐËûµÄÀíÓÉ£¨»òÐíÊÇ·¢¸øÄ³¸öÈË£©¡£ÊÇÁíÍâÍêÃÀµÄ¸ÐȾһ̨»ò¶ą̀Ö÷»úµÄ·½·¨¡£
ѹËõ³ÌÐò£º£­Í¨³£ÊÇÔÚÓÃͨÐųÌÐòÉÏ´«£¯ÏÂÔØÇ°ÓÃÀ´Ñ¹ËõÈí¼þ£¬ÓÚÊÇ£¬Èç¹ûÎÒÃÇÔÚѹËõµÄ¹ý³ÌÖиÐȾEXE£¯COM³ÌÐò£¬ÄÇÎÒÃǾÍÓзdz£ºÃµÄ»ú»áʹÍâ³ö¼û¼ûÊÀÃæ¡£
±¸·Ý³ÌÐò£º£­Õâ¿ÉÒÔÔ¤·À´ÓÖ÷»úÉÏÒÆÈ¥ÎÒÃǵIJ¡¶¾£­£­Èç¹ûÓû§Í¨¹ýAV³ÌÐò·¢ÏÖÁ˲¡¶¾£¬ÄÇÎÒÃÇ»¹Óлú»áÖØÐ¸ÐȾËü¡£

    ͼʾ£º
                                      .-<<--backups-----.
        .HOST SYSTEM------------------|---.             |
        |.------------------..--------'--.|----------> floppies
        ||ethernet/modem/fdd|| HARD DISK ||----------> network
        |'------------------''--------.--'|----------> modem/comms
        '-----------------------------|---'             |
                                      '-compressed-->>--'

¸ÐȾӲÅÌÎļþÓô¦²»´ó£¬Òò´ËËüÃÇ´ÓÀ´²»»áËÄ´¦Ïй䣭²»Ïñ¸ÐȾÈíÅÌ£¬ÍøÂçºÍͨÐÅͨµÀµÄÎļþÄÇÑù¡£
È·±£ÄãµÄ²¡¶¾ÔÚÆäËü³ÌÐòǰ±»¼ÓÔØÊǸöºÃÖ÷Ò⣬ÕâÑùÒ»À´¿ÉÒÔÈ·±£²¡¶¾»î¶¯ÃØÃÜÐж¯¡£  ÄãÓ¦¸Ã×Ô¶¯¸ÐȾ\COMMAND.COM»ò°Ñ²¡¶¾·Ö³É¶à²¿·Ö£¨¸ÐȾmbr/track 0£©¡£

1.1ÕâЩ·½·¨µÄʵÏÖ£º
    ×îºÃµÄʵÏÖ·½·¨ÊÇ£º

        Floppy diskette and CDR (CD-ROM Writers) check:
            Use AX=4408, DL=Logical Drive#, INT 21h

        Network/Remote check:
            Use AX=4409, DL=Logical Drive#, INT 21h
            Use AX=440A, BX=File Handle, INT 21h

        Comms/Compression/Backup check:
            ÓÃLUT£¨lookup table£©½ûÖ¹ÃØÃܻ£¬²¢ÔÚÊʵ±µÄʱºò¼¤»î¿ìËÙ´«²¥Õߣº

            'CHKDSK'   - Stops CHKDSK errors (well known).
            'SCANDISK' - Ditto.
            'NDD'      - Ditto.
            'PKLITE'   - Protect virus in PKLITE compression wrapper.
            'DIET'     - Protect virus in DIET compression wrapper.
            'LZ'       - Protect virus in LZEXE compression wrapper.
            'TM'       - Telemate, to infect EXE/COM uploads.
            'TE'       - Telix/Terminate, to infect EXE/COM uploads.
            'BACKUP'   - To infect executable backups.
            'MSBACKUP' - Ditto.
            'CPBACKUP' - Ditto.

            µ±Ñ¹Ëõ³ÌÐòÊä³öÎļþ±»´ò¿ªÊ±£¬Ò²ÓÃÏÂÃæµÄLUTÀ´²é¿´¡£

                'ZIP' - PKZIP tmpfile extension opened.
                'LZH' - LHA tmpfile extension opened.
                'ARJ' - ARJ tmpfile extension opened.
                'ARC' - ARC tmpfile extension opened.
                'RAR' - RAR tmpfile extension opened.

            µ±Äã½ØÈ¡INT 21h AH=3CºÍINT 21h AH=3Dµ÷ÓÃʱ£¬¼ì²éÎļþµÄºó׺¡£

            Èç¹û±»´ò¿ªµÄÎļþÊÇÉÏÊöµÄÒ»ÖÖ£¬ÄÇô¼¤»î¿ìËÙ´«²¥Õß²¢½ûÖ¹ÃØÃܻ¡£

µ±Ëü±»¹Ø±Õʱ£¨ÓÃSFTÀ´¼ì²éAX=1220/INT2F AX=1216/INT2F£©£¬ÖØÐÂÆôÓÃÂýËÙ´«²¥Õß²¢ÖØÐÂÆôÓÃÃØÃܻ¡£

2ÂýËÙ¶à̬±äÐÎ
ÂýËÙ¶à̬±äÐβ¶àʹAVÍÅÌåÏÝÈëÁËÎÞ¾¡µÄ·³ÄÕÖ®ÖУ¬¹ØÓÚÕâ¸öÎÊÌâûÓÐÌ«¶àµÄÕùÒé¡£
ÕâЩÈË£¨AVer£©Ã¿Ìì¶¼»áÊÕµ½Ðí¶à²¡¶¾£¬ËûÃDz»¿ÉÄÜ·´»ã±àÿһ¸ö²¡¶¾À´¿´¸öÏêϸ£¬Õâ¶ÔÎÒÃÇÀ´ËµÊǸöºÃÏûÏ¢£¬ÒòΪÕâÒâζ×ÅÎÒÃÇÄÜʹËûÃÇÏÝÈëÀË·Ñʱ¼äµÄ·³ÄÕÖ®ÖС£
Èç¹ûÔÙºÍRajaat²ûÊöµÄanti-goat¼¼Êõ½áºÏÆðÀ´Ê¹Ó㬽«»áʹËûÃÇÏ൱µÄ·³ÄÕ¡£AVÍÅÌåΪÁËÏÂÃæµÄÄ¿µÄ£¬½«²»µÃ²»»¨ÉÏÖÁÉÙÒ»ÌìµÄʱ¼ä·ÖÎöºÃµÄ¶à̬±äÐβ¡¶¾£º

    a£©Ê¹Ëü¸ÐȾËûÃǵġ°Ìæ×ïÑò¡±Îļþ
    b£©Ê¹Ëü²úÉú´óÁ¿µÄÑù±¾£¨¶ÔÓÚSMEGÀ´Ëµ£¬ÎÒÈÏΪ´ó¸ÅÄÜÉú³É200,000¸öÑù±¾£©¡£

BTW: Èç¹ûÄã¾ö¶¨Ê¹ÄãµÄ´úÂëÒÀÀµanti-goat´úÂëµÄÍêÕûÐÔ£¬ÄÇôÄ㽫·¢ÏÖÑо¿Ô±ÔÚÎ¹Ñø200,000¸ö²¡¶¾Ñù±¾Ê±»áÓиü¶àµÄÎÊÌ⣺£©

2.1ʵÏÖ
¶à̬±äÐιý³Ì»ùÓÚËæ»úÊýµÄÉú³É£¬ÔõÑùÑ¡ÔñÒ»¸öÂýËÙÉú³ÉµÄËæ»úÊýÄØ£¿ÎÒÄÜÏëµ½µÄÁ½¸ö·½·¨ÊÇ£º

    1.  BIOS date.     -·Ç³£ÂýµÄ¶à̬±äÐΣ¬½ö¸ù¾Ýÿ¸ö¼ÆËã»ú¶ø¸Ä±ä£¡
    2.  µ±ÌìµÄÈÕÆÚ.   -·Ç³£Âý¡£

    -------------------------------------------------------------

    1.  push    0FFFF
        pop     ds
        mov     si,0005             ;DS:SI -> FFFF:0005 (8 bytes).
        xor     bx,bx               ;value=0
        mov     cx,4                ;size=4 words.
    L1: lodsw                       ;fetch word.
        add     bx,ax               ;checksum.
        loop    L1                  ;next 3 words.
        mov     ds:rnd_seed,bx      ;set seed.

    -------------------------------------------------------------

    2.  mov     ah,2A
        int     21                  ;get date.
        rol     dx,cl               ;random adjustment.
        xor     dx,cx               ;place cx into eqn.
        mov     ds:rnd_seed,dx      ;set seed.

--------------------------------------------------------------------------------

[ Last edited by sdlj8051 on 2006-12-24 at 23:34 ]
»Ø¸´´ËÂ¥

» ²ÂÄãϲ»¶

ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

sdlj8051

½ð³æ (ÖøÃûдÊÖ)

×Ô¼º¶¥
2Â¥2006-09-17 20:00:10
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû

gph-rabbit

½ð³æ (СÓÐÃûÆø)

°ï¶¥£¬¿´¿´Ñ§Ï°Ò»Ï¡£
3Â¥2006-12-29 01:12:59
ÒÑÔÄ   »Ø¸´´ËÂ¥   ¹Ø×¢TA ¸øTA·¢ÏûÏ¢ ËÍTAºì»¨ TAµÄ»ØÌû
Ïà¹Ø°æ¿éÌø×ª ÎÒÒª¶©ÔÄÂ¥Ö÷ sdlj8051 µÄÖ÷Ìâ¸üÐÂ
×î¾ßÈËÆøÈÈÌûÍÆ¼ö [²é¿´È«²¿] ×÷Õß »Ø/¿´ ×îºó·¢±í
[¿¼ÑÐ] Ò»Ö¾Ô¸»ª¶«Àí¹¤´óѧ081700£¬³õÊÔ·ÖÊý271 +4 kotoko_ik 2026-03-23 5/250 2026-03-23 23:23 by ´ô´ôʦ½ã
[¿¼ÑÐ] ²ÄÁÏ/ũҵרҵ£¬07/08¿ªÍ·¾ù¿É£¬¹ýÏß¾ÍÐÐ +3 ºÇßíŶ»í 2026-03-23 4/200 2026-03-23 22:30 by Íô£¡£¿£¡
[¿¼ÑÐ] 265Çóµ÷¼Á +10 ÁºÁºÐ£Ð£ 2026-03-17 10/500 2026-03-23 21:17 by Ò»ÇÐOK
[¿¼ÑÐ] Ò»Ö¾Ô¸ÉϺ£½»´óÉúÎïÓëҽҩר˶324·Ö£¬Çóµ÷¼Á +5 jiajunX 2026-03-22 5/250 2026-03-23 18:07 by YMUÊ©ÀÏʦ
[¿¼ÑÐ] 08¹¤Ñ§µ÷¼Á +7 Óû§573181 2026-03-20 11/550 2026-03-23 15:47 by ÎÒ°®Ñ§Ï°Ñ§Ï°Ê¹Î
[¿¼ÑÐ] 306Çóµ÷¼Á +9 chuanzhu´¨Öò 2026-03-18 9/450 2026-03-23 13:17 by luoyongfeng
[¿¼ÑÐ] ±±¿Æ281ѧ˶²ÄÁÏÇóµ÷¼Á +8 tcxiaoxx 2026-03-20 9/450 2026-03-23 12:16 by tcxiaoxx
[¿¼ÑÐ] 291Çóµ÷¼Á +5 ‹üÈA 2026-03-22 5/250 2026-03-23 09:20 by haoshis
[¿¼ÑÐ] 0854µç×ÓÐÅÏ¢Çóµ÷¼Á +3 ¦Á____ 2026-03-22 3/150 2026-03-22 21:28 by zhq0425
[¿¼ÑÐ] 285Çóµ÷¼Á +6 ytter 2026-03-22 6/300 2026-03-22 12:09 by ÐÇ¿ÕÐÇÔÂ
[»ù½ðÉêÇë] ɽ¶«Ê¡ÃæÉÏÏîÄ¿ÏÞ¶îÆÀÉó +4 ʯÈð0426 2026-03-19 4/200 2026-03-22 08:50 by Wei_ren
[¿¼ÑÐ] 286Çóµ÷¼Á +10 Faune 2026-03-21 10/500 2026-03-21 23:34 by 314126402
[¿¼ÑÐ] Çóµ÷¼Á +6 Mqqqqqq 2026-03-19 6/300 2026-03-21 08:04 by JourneyLucky
[¿¼ÑÐ] Ò»Ö¾Ô¸ÖØÇì´óѧ085700×ÊÔ´Óë»·¾³×¨Ë¶£¬×Ü·Ö308Çóµ÷¼Á +3 īīĮ 2026-03-18 3/150 2026-03-21 00:39 by JourneyLucky
[¿¼ÑÐ] 330Çóµ÷¼Á +4 С²Ä»¯±¾¿Æ 2026-03-18 4/200 2026-03-20 23:13 by JourneyLucky
[¿¼ÑÐ] Ò»Ö¾Ô¸Î÷ÄϽ»Í¨ ר˶ ²ÄÁÏ355 ±¾¿ÆË«·Ç Çóµ÷¼Á +5 Î÷ÄϽ»Í¨×¨²Ä355 2026-03-19 5/250 2026-03-20 21:10 by JourneyLucky
[¿¼ÑÐ] 086500 325 Çóµ÷¼Á +3 Áì´øÐ¡ÐÜ 2026-03-19 3/150 2026-03-20 18:38 by ¾¡Ë´Ò¢1
[¿¼ÑÐ] ²ÄÁÏ¿¼Ñе÷¼Á +3 xwt¡£ 2026-03-19 3/150 2026-03-19 11:22 by wãåÑôw
[¿¼ÑÐ] ±¾¿ÆÖ£ÖÝ´óѧÎïÀíѧԺ£¬Ò»Ö¾Ô¸»ª¿Æ070200ѧ˶£¬346Çóµ÷¼Á +4 ÎÒ²»ÊÇÒ»¸ù´Ð 2026-03-18 4/200 2026-03-19 09:11 by ¸¡ÔÆ166
[¿¼ÑÐ] ¡¾Í¬¼ÃÈí¼þ¡¿Èí¼þ£¨085405£©¿¼ÑÐÇóµ÷¼Á +3 2026eternal 2026-03-18 3/150 2026-03-18 19:09 by ²«»÷518
ÐÅÏ¢Ìáʾ
ÇëÌî´¦ÀíÒâ¼û