˼Ë÷Íø£ºWWW.4SO.NET
ÍøÕ¾Ê×Ò³
ÉèΪÊ×Ò³
¼ÓÈëÊÕ²Ø
ÉçÇøÂÛ̳
ÁªÏµÎÒÃÇ
ÍøÕ¾µØÍ¼
·¢ÏÖ¸öÈ˼ÛÖµ
Ìá¸ßÆóÒµÄÚº
Ò»ÇÐÔ´ÓÚ˼Ë÷
Ê×Ò³
¡¡
ÆóÒµÖ®¼Ò
¡¡
¹«¹ØÎÄÃØ
¡¡
Ãâ·ÑÂÛÎÄ
¡¡
ÍøÉϰ칫ָÄÏ
¡¡
²Ù×÷ϵͳ
¡¡
¶àýÌåÓ¦ÓÃ
¡¡
ÏÖ´ú½Ìѧ
¡¡
ÏÂÔØÖÐÐÄ
רÌⱨµÀ
¡¡
ÍÆ¼öÎÄÕÂ
¡¡
ÆÀÂÛ
English Article
¡¡
IT×ÊѶ
¡¡
ÍøÒ³Éè¼Æ
¡¡
ÍøÕ¾ÔËÓª
¡¡
±à³Ì¿ª·¢
¡¡
Æ½ÃæÉè¼Æ¡¡
ÍøÂ簲ȫ
¡¡
¹¤¾ßÏÂÔØ
¡¡
Õ¾ÄÚËÑË÷
×îÐÂÎÄÕÂ
¡¡
ÈÈÃÅÎÄÕÂ
¡¡
ÂÛ̳
À¸Ä¿Áбí
ASP×¨Çø
PHP×¨Çø
JSP×¨Çø
.Net×¨Çø
XML×¨Çø
ÆäËüÍøÒ³±à³Ì
HTML&CSS
Dreamweaver
Frontpage
Javascript
Êý¾Ý¿âÏà¹Ø
·þÎñÆ÷Ïà¹Ø
ÍøÂçýÌå
½¨Õ¾¾Ñé
FLASH
ÍøÂ簲ȫ
Ê×Ò³
>
Õ¾³¤Ñ§Ôº
>
ÍøÂ簲ȫ
> Ö´ÐÐÎļþ·½Ê½¼ÓÃÜFLASHÎļþµÄ½âÃÜ·½·¨
Ö´ÐÐÎļþ·½Ê½¼ÓÃÜFLASHÎļþµÄ½âÃÜ·½·¨
ÈÕÆÚ£º
2005-06-15 00:00:00
À´Ô´£º
ÖйúÕ¾³¤Ñ§Ôº
ÇëÄú¼Çס˼Ë÷ÍøµÄÍøÖ·£º
http://www.4so.net
[¼ÓÈëÊղؼÐ]
¹¤¾ß£ºOD Lordpe 16½øÖÆ±à¼Æ÷
³ÌÐò£º¶à²ÊµÄÏÄÌì.exe
Ä¿µÄ£º´ÓEXEÎļþÖе¼³öSWF£¬Ö®ºó¿ÉÒÔ½øÐз´±à¼°Ð޸IJÙ×÷
˵Ã÷£ºÎªÁËÑо¿ÐèÒª¶ø´¦ÀíµÄ¡£²»¾´Ö®´¦ÇëÄúÁ½⡣
1¡¢ODµ¼Èë³ÌÐò¡£
Í£ÔÚÕâÀï
004B556B > $ 6A 60 PUSH 60
004B556D . 68 30805300 PUSH ¶à²ÊÏÄÌì.00538030
004B5572 . E8 E9EBFFFF CALL ¶à²ÊÏÄÌì.004B4160
004B5577 . BF 94000000 MOV EDI,94
004B557C . 8BC7 MOV EAX,EDI
004B557E . E8 CD95FFFF CALL ¶à²ÊÏÄÌì.004AEB50
2¡¢Ö´ÐгÌÐò£¬Ö®ºó¿ÉÒÔ¿´µ½³ÌÐòÔËÐеĽçÃæ¡£ÒÔ¼°²¥·ÅµÄFLASH¶¯»¡£
×¢Ò⣺´Ë³ÌÐò²»ÊÇÓÃFlash²¥·ÅÆ÷Éú³ÉµÄEXEÎļþ£¬ËùÒÔ²»ÄÜÓÃÍøÉϵÄһЩȥͷµÄ·½·¨½øÐд¦Àí¡£
µ½ODÖС£
ALT+MÏÔʾÄÚ´æÁÐ±í¡£
ѡһЩ±È½Ï´óµÄÄÚ´æ¿é£¬Êó±êÓÒ¼ü£¬ÔÚCPUÖнøÐÐת´æ£¬ÕâÑùÔÚÊý¾ÝÇøÊ±¿ÉÒÔ¿´µ½ÄÚ´æ¿éµÄÄÚÈÝÁË£¬
½øÐÐ ¶þ½øÖƵÄËÑË÷FlashÎļþµÄÍ· FWS ×Ö·û£¬Èç¹ûÄãÕÒµ½ÁË£¬¿ÉÒÔ¿´Ò»Ï£¬ÕâÒ»¿éÄÚÈÝÀë¿éµÄÍ·²¢²»Ô¶£¬
ʵ¼ÊÉϲ»ÓÃÕÒÒ²ÄÜ¿´µ½µÄ¡£
01DF0000 50 00 5F 01 50 00 5F 01 00 00 00 00 00 00 00 00 P._ P._ ........
01DF0010 00 60 27 00 00 60 27 00 11 08 00 00 00 0B 00 00 .`'..`'. .....
01DF0020 46 57 53 06 EE 57 27 00 78 00 07 D0 00 00 17 70 FWS îW'.x.?. p
01DF0030 00 00 0C 17 00 43 02 FF FF FF 44 0B 06 00 00 00 ... .C ÿÿD ...
01DF0040 3F 03 02 00 00 00 07 00 BF 05 76 2D 00 00 01 00 ? ....?v-.. .
´óÔ¼ÔÚ¿éÍ·µÄ20H¿ªÊ¼£¬¼òµ¥ËµÒ»ÏÂFlashÍ·µÄ¸ñʽ:
01DF0020 46 57 53 06 EE 57 27 00 78 00 07 D0 00 00 17 70 FWS îW'.x.?. p
====== -- =========
±êʾ °æ±¾ ³¤¶È
³¤¶ÈÄÚÈÝÒ»»áÒªÓõġ£µ±Ç°ÎļþµÄ³¤¶ÈÊÇ2757EEH×Ö½Ú³¤£¬1DF0020+2757EE=1E6580E ˵Ã÷ÎÒÃǵÄFlashµ½´ËλÖÃ
3¡¢ÉÏlordpe£¬ÔÚpathÖÐÑ¡ÖгÌÐòµÄÃû³ÆÁÐ±í¡£
Êó±êÓÒ¼ü dump region ººÓïÊÇ ÍѿDz¿·ÖÇøÓò¡£
ÔÚÁбíÖÐÑ¡ÖÐÎÒÃǸղŵÄÄÚ´æ¿éÁË¡£
ÓÒ¼ü dump£¬±£´æÎļþAA.SWF¡£
4¡¢ÓÃ16½øÖÆ±à¼Æ÷´ò¿ªÉú³ÉµÄÎļþAA.SWF,È¥µôÍ·20H×Ö½Ú£¬ Ö®ºóµ½2257EEH´¦£¬É¾³ýºóÃæµÄ×Ö½Ú¡£
Ö®ºóSWFÎļþ¾Í¿ÉÒÔ¿´µ½ÁË£¬Óò¥·ÅÆ÷¿ÉÒÔ¿´¡£ÓÃAVS¿ÉÒÔ·´±à¡£
5¡¢
×ܽá
ÏÖÔÚÍøÉϵÄFlashµÄÎļþ¼ÓÃÜ·½·¨ºÜ¶à£¬µ«³£ÊÇÄܱ»·´±àÒ룬֮ºó¸ÄÎļþ£¬¸Äµ×¸å£¬¸ÄͼƬ£¬ÎªÁ˱£»¤×÷ÕßµÄȨÁ¦£¬¿Éν±£»¤ÆðÀ´²»ÒÅÓàÁ¦ÁË¡£
ÕâÖÖ±£»¤·½·¨ÊÇÓÃVC
±à³Ì
£¬Ö®ºóÔÚ³ÌÐòÖе÷Óò¥·ÅFlashµÄ¿Ø¼þ£¬ÔÙµ÷ÓÃFlashÎļþ½øÐв¥·Å¡£ÒòΪÊý¾ÝÊDZ»Ñ¹ËõµÄ£¬²»ÄÜÖ±½Ódump³öÀ´µÄ¡£
±¾ÎĵØÖ·£º
http://www.4so.net/web/security/4684.html
½«±¾Ò³¼ÓÈëÊղؼÐ
½«µØÖ·¸´ÖƵ½¼ôÌù°å·¢Ë͸øºÃÓÑ
Èô·¢ÏÖ±¾ÎÄÓÐÎó»ò°æÈ¨ÎÊÌâµã»÷ÕâÀï
ÈÈÃÅÐÅÏ¢
Ïà¹ØÎÄÕÂ
[
ÍøÂ簲ȫ
]
³£¼ûµÄÍøÉÏÁÚ¾Ó·ÃÎÊÎÊÌâ»ã¼¯
[
ÍøÂ簲ȫ
]
Ë¿ØÖÆÁËÎÒÃǵÄä¯ÀÀÆ÷
[
ÍøÂ簲ȫ
]
½â¾ö3389µÇ½¿´²»µ½½çÃæÎÊÌâ
[
ÍøÂ簲ȫ
]
debianÓ²Å̰²×°¼Ç ÈÃsarge°²¼ÒÂä
[
ÍøÂ簲ȫ
]
webshellÌáȨ
[
ÍøÂ簲ȫ
]
ÆÊÎöWindowsÓÃ1GÄڴ滹ÂýµÄÔÒò
[
ÍøÂ簲ȫ
]
ÈçºÎ¶Ô¸¶WGA¼ì²é
[
ÍøÂ簲ȫ
]
·ÖÎö½â¾ö¾ÖÓòÍøÄÚµÁÓÃIPµÄ°²È«ÎÊ
[
ÍøÂ簲ȫ
]
¾Ñ»÷²¨²¡¶¾µÄÌØÕ÷
[
ÍøÂ簲ȫ
]
Íø¼Ê¿ì³µÊ¹Óü¼ÇÉÜöÝÍ
ÎÞÏà¹ØÐÅÏ¢
ÎÄÕÂÆÀÂÛ
Êղر¾ÎÄ
´òÓ¡±¾ÎÄ
¹Ø±Õ´°¿Ú