൫Ljጐ߂ᄂጟൣ൫Lj፞ᆪ߂ᆐU s p k b oă۾ဵ
ᆐ೫ྜྷ༪ৈཽ࢟ฎݣ߲ሚࡼLj൫Ᏼ࢟ฎᔫࡼဟဵ੪
ࡼLjݙ્Ᏼ࢟ฎࡼືመာྀ߲ੜ੩૭ă۾ᐺ࠭൫ࡼ۾
Ꮗಯྜྷ၄Ljऎ೫ஊ൫ࡼᄏૣਭ߈Ljጲᔪࡵᎌऴप
൫ă
Ԩ ቤ ڞ ܁
ڼ!6!ቤ
ዘۅ
൫ࡼᏇಯ ᒈྜྷ൫
ޟ൫ऴဣಿ
5.1 ൫ૣᏇಯ
༬ ᅉ ఢ க ( ᅜ ူ ० ఢ க ) Ljᆈ ࿔ ঢ ፔ ĐTrojan horseđLjഄఁൽጲထજหࣆڦ༬ᅉఢ கऻăኸཚࡗᅃ༬ۨڦײႾDŽఢகײႾDž ઠ੦ଷᅃऺ໙ऐăఢகཚᆶଇ߲ኴႜײ Ⴞǖᅃ߲ਜ਼ࢽ܋Ljन੦܋Ljଷᅃ߲ޜခ܋Lj नԥ੦܋ăఢகڦยऺኁྺକݞኹఢகԥ݀
၄Ljܸ֑ᆩܠዖᆆ֠ఢகăఢகڦޜခᅃڋ ሏႜժԥ੦܋থLjഄ੦܋ॽၛᆶޜခ܋ڦ ٷևݴ֡ፕ၌Lj૩සߴऺ໙ऐሺे੨ସLj៓બĂ ᅎۯĂްĂأ࿔ॲLjႪ߀ጀ֩Lj߸߀ऺ໙ऐ ದዃڪă
ఢகᅃዖएᇀᇺײ੦ڦਜ਼߾ਏLjਏᆶ ᆆԸႠࢅݥႠڦ༬ۅăᆆԸႠኸఢக ڦยऺኁྺକݞኹఢகԥ݀၄Lj֑ࣷᆩܠዖ
ᆆ֠ఢகLjኄᄣޜခ܋न๑݀၄ߌකକఢகLjᆯ ᇀփీඓۨഄਏ༹࿋ዃLjྫྫኻీྭĐகđ႗༒ă
ݥႠኸᅃڋ੦܋ᇑޜခ܋থࢫLj ੦܋ॽၛᆶޜခ܋ڦٷևݴ֡ፕ၌LjԈઔႪ ߀࿔ॲLjႪ߀ጀ֩Lj੦ՔLj॰ಎڪڪLjܸኄ ၵ૰ժփޜခ܋ޯᇎڦLjܸཚࡗఢகײႾ
ൽڦă
ٗఢகڦ݀ቛઠੂLjएԨฉᅜݴྺଇ߲
ǖ
ፌ؛ྪஏ࣏تᇀᅜUNIXೝྺዷڦ้Lj ఢக৽ׂิକLjړ้ڦఢகײႾڦࠀీ၎ܔ० ڇLjྫྫॽᅃײႾഴڟဣཥ࿔ॲዐLjᆩཌ ገኸସઠኴႜᅃၵఢகڦࠀీLjሞኄ้߲ఢக ڦยऺኁࢅ๑ᆩኁٷۼၵरຍටᇵLjՂႷਏԢ
၎ړڦྪஏࢅՊײኪ๎ă
ܸࢫໜጣWindowsೝڦනᅮतLjᅃၵए ᇀႚ֡ፕڦఢகײႾ၄କLjᆩࢽহ௬ڦ߀
Lj๑๑ᆩኁփᆩۮܠڦጆᄽኪ๎৽ᅜຄଁ
ڦ֡ፕఢகLj၎ܔڦఢகൔ๚ॲᄺೕݏ၄Lj
ܸᆯᇀኄ้߲ఢகڦࠀీᅙන൵ྜLjᅺُ
ܔޜခ܋ڦ೦࣋ᄺ߸ٷକă
ᅜఢக݀ቛڟৃཀLjᅙঢ়փᆩLjᅃ ڋԥఢக੦Ljేڦۉసॽࡹჾă
5.1.1 ఢகڦݴૌ
ሞถఢகڦݴૌኮമံੂੂఢகڦࠀీă 1. ఢகڦࠀీ
ఢகࢅթ۾ۼᅃዖටྺڦײႾLjۼຌᇀۉ సթ۾Ljڍ்ᄺᆶ൶՚Ljఢகڦፕᆩ؆
ڦཧཧ॔՚ටࢅڣ՚ටஓ,ຕڪLjසڣ
࠶ᇵஓĂጱྪஓߟ೦࣋Ljईኁཧฉྪ
ஓᆩᇀᆩLjᆴဥቭࡽĂࠣቭࡽĂฯྪฉᆀႜ Norton AntiVirusڪăײႾ෫ఢகڦࠀీ৽࠲
ԿܔݛऐഗฉሏႜڦኄૌײႾLjඟഄఢக߸ࡻں
ݔăᇀLjᇑᅃӯڦఢக၎ݒLjݒڑ܋੨႙ఢக
ॲॠֱጲमڦ܋੨Lj݀၄ૌຼTCP UserIP:1026 ControllerIP:80ESTABLISHEDڦ൧Ljฎྲࢮ
ᆆ֠ཚრLjඪࢆఢகሏႜࢫۼᄲࢅ߿ऍኁ
ेሜኮLjߋॠֱᅃူLjᆶ๊ײႾሞഄူǖ
˄˅$XWRH[HFEDW&RQILJV\VЁࡴ䕑䖤㸠 ሞCಎߵణူڦኄଇ߲࿔ॲᄺᅜഔۯ Folders Startup=đc:\windows\start menu\programs\
startupđă
WINDOWS\SYSTEM\ SYSEXPLR.EXE%lđăኄ ᄣLjᅃڋມऍᅃ߲TXT࿔ॲLjᇱԨᆌᆩNotepadٶ
4.1.3 ఢகසࢆํแ߿ऍڦ
ऍኁ૧ᆩᅃ߲༬ڦANI࿔ॲLj៓બڟኄ߲ANI࿔ॲ้Ljဣཥࣷጲۯူሜ߿ऍپஓኸۨڦܱᅪॲ
ኲఢகڦݛ݆ă
1. ૧ᆩࠌၛࢅAutorun࿔ॲ
ྺକბသࢅ߾ፕݛՍLjᆶႹܠბၯईࠅິڦ ਆᇘྪዐࣷॽᆘಎࠌၛઠă߸ᆶฯኁLj৩ॽగ ၵᆘಎࠌၛยྺႀLjኄᄣݥླ၃Lj՚ට
ᅜُߴేူఢகƽ૧ᆩఢகײႾࢇAutorun.
inf࿔ॲ৽ᅜକăݛ݆ӝAutorun.infࢅದዃࡻ
ڦఢகޜခ܋ᅃഐްڟܔݛDಎڦߵణူLj ኄᄣփႴܔݛሏႜఢகޜခ܋ײႾLjኻႴມऍ ࠌၛڦىಎՔ৽ࣷ๑ఢகሏႜă
ڦᇱኄᄣڦLjཚ֭࠼ಎLjࣷጲ ۯሏႜLjኄᅺྺሞ࠼ಎߵణူᆶ߲Autorun.
inf࿔ॲLj࿔ॲᅜਦۨޏጲۯሏႜഄዐڦײ ႾăཞᄣLjසࡕᆘಎڦߵణူ٪ሞ࿔ॲLjᆘಎ ᄺ৽ਏᆶକAutoRunࠀీLjनጲۯሏႜAutorun.inf
࿔ॲዐڦాඹă
ӝఢக࿔ॲ.exe࿔ॲᅜतAutorun.infݣሞ ىಎߵణDŽኄ्ยܔݛڦDಎࠌၛઠ
ႀDžLjܔᇀߴేူఢகڦටઠຫLj࣏ࣷႪ߀ Autorun.inf࿔ॲڦຌႠLjॽ࿔ॲᆆ֠ഐઠăኄ ᄣLjړᆶටມऍኄ߲ಎޙLjײႾ৽ሏႜକăኄᅃቲ ܔᇀঢ়ມऍಎޙĐڦۉసđڦටྰၾፌ ٷă߸ᅃօLj૧ᆩᅃ߲.REG࿔ॲࢅAutorun.inf
ࢇLj࣏ᅜඟేᆶڦᆘಎۼࠌၛඁገ࣑ྺ
autorun.pif߭๕ఢகă
2. ӝఢக࿔ॲገ࣑ྺBMP߭๕
ኄዖݛ๕ӝEXEገࣅׯྺBMPઠ್ዐ
۾ኁăഄᇱǖBMP࿔ॲڦ࿔ॲཀྵᆶ54߲ጴবLj
Ԉઔ܈Ă࿋ຕĂ࿔ॲٷၭĂຕ൶܈ăኻᄲሞ E X Eڦ࿔ॲཀྵฉेฉኄ54߲ጴবLjIE৽ࣷӝ
EXE࿔ॲړׯBMPೌူሜူઠăᆯᇀኄᄣፔ
ڦೌࢾڦLjྺݞኹੂઠLjူఢகኁࣷሞഄ
ྪᄻዐेᅃၵ༬ڦپஓLjӝኄᄣڦՔധेڟ
ྪᄻLj৽ੂփ९ೌକLjᅺُ৽݆݀၄ኄ߲
Đೌđփܔă
!݀၄!CNQ!ఢக༵๖
ഔۯIE៓બഗࢫLjIEࣷӝೌጲۯူሜڟIE ଣ้ణዐLjܸူఢகኁኻႴᆩᅃ߲JavaScript࿔
ॲሞڦᆘಎዐႀᅃ߲VBS࿔ॲLjժሞጀ֩ཁे
ഔۯၜLj૧ᆩఫ߲VBSቴڟBMPLjۙᆩdebugઠ࣏
ᇱEXELjፌࢫLjሏႜײႾྜׯఢகኲLjำတ ݥᆆԸă
Ğӄ૩5-1ğ૧ᆩExe2bmpײႾӝఢக࿁ጎ ׯೌํ૩
Tufq!2!ሏႜfyf3cnqײႾ
Tufq!3!ስೌ!ิׯఢக
Step 1 ሏႜexe2bmp1.0ײႾLjഄዷহ௬සူă
Tufq!4!ิׯڦఢக࿔ॲ
ۡڦᆩࢽዐఢகăInternet Explorer 5.0Ă5.01Ă5.5
٪ሞ۴Ljᆩڦྲᆰॲਜ਼ࢽ܋ॲOutlook Express 5.5 SP1ᅜူӲԨᄺ٪ሞُ۴ă
ཚူఢகڦටLjࣷፕᅃހ༬ۨ߭๕ڦ xxxx.doc+xxxxx.exe newdoc.docӝኄଇ߲࿔ॲࢇ
ժሞᅃഐDŽሞWord࿔ڗ࿂ेఢக࿔ॲDžLjኻᄲ
՚ටڇऍኄ߲ڦWo r d࿔ॲ৽ࣷዐఢகăྺ
VBఢகՎዖUBJࢫܔOffice࿔ڗ೦࣋ၳࡕă
5. ཚࡗScriptĂActiveXतASPĂCGIࢻগ Ԩڦݛ๕ኲ
వ݀၄ăසူ๖LjӝRundll.dll ࿁ጎׯRundl1.
Step 2 Ӧݬq༪႔r̟ē༪႔ྑಓюଫԅ
ઁ৴d௶܊ၼӦݬqಓюr̟ēඔವ qᅧܰΘrԉd
dllLjexplorer.exe ࿁ጎׯexp1orer.exeă
2NJӝጲमࢅഄ࿔ॲӿሞᅃഐ
ኄዖ࿁ጎॽఢகӿڟᅃ߲Ҿጎײ ႾฉLjړҾጎײႾሏႜ้Ljఢகሞᆩࢽࡹִਥ ڦ൧ူLjཧཧںକဣཥăԥӿڦ࿔ॲᅃ ӯኴႜ࿔ॲDŽनEXELjCOMᅃૌڦ࿔ॲDžă૩ සLjӝఢகޜခ܋ࢅగ߲ᆴဥӿׯᅃ߲࿔ॲ૧ ᆩQ Qईۉጱᆰॲ݀ߴ՚ටLjሏႜࢫࣷੂڟᆴဥ ײႾኟٶਸLjඐփኪఢகײႾᅙঢ়ൂൂሞࢫ
ሏႜକLjኄᄣፕܔᅃӯටڦउႠٷLjܸन ๑ᅜࢫዘጎဣཥକLjසࡕڦဣཥዐ࣏ԍ٪କ ఫ߲ĐᆴဥđڦࣆLj৽ᆶీምْዐቲăఢகײႾ ኄᄣڦ࿁ጎ९Ljᆩઠӿڦ߾ਏᄺܠLjස exe࿔ॲӿऐExeBindڪLjૌײႾᅜॽኸۨ
ڦਜ਼ײႾӿڟඪࢆᅃ߲࠽ྺدխڦඤோ
ॲฉLj๑ዷײႾኴႜ้LjसิײႾDŽਜ਼ײႾDžᄺ ሞࢫԥኴႜăړేምْฉྪ้Ljేᅙঢ়ሞփኪ փਥዐԥ੦ዿକLjܸኧܠዘӿăํा
ฉཚࡗܠْݴߪ࿔ॲLjܠْٗײዐۙᆩጱ
ײઠํ၄ڦă
Ğӄ૩5-2ğॽఢகᇑഄॲӿ
EXEӿऐᅜॽଇ߲ኴႜ࿔ॲDŽEXE࿔
ॲDžӿׯᅃ߲࿔ॲLjሏႜӿࢫڦ࿔ॲڪᇀཞ
้ሏႜକଇ߲࿔ॲăࣷጲۯ߸߀ՔLj๑ӿ ࢫڦ࿔ॲࢅӿമڦ࿔ॲՔᅃᄣLjੂփՎ ࣅLjժᅜጲۯأሏႜ้ڞڦଣ้࿔ॲă
Tufq!2!ٶਸ!FYFӿऐ
Tufq!3!ስڼ2߲࿔ॲ
Tufq!4!ስڼ3߲࿔ॲ
Tufq!5!ኸۨԍ٪ୟ০
Tufq!6!ਸ๔ӿ
Step 3 ӦݬqຏྡྷϤr̟ēӰѻqᄗՇԛ֝
ّࢶᄓำߑrғࣇē༪႔ԛّ֝ྑᄓ
ԅำߑd
Step 1 ၮEXEࣱ͞ݯēӕୣЀᆴ࠘ੋd
Step 2 ӦݬqຏྡྷϤr̟ēၽӰѻqᄗՇԛ
ྡྷّᄓำߑrճܥࣟᄯӦݬqԤݬუ
ऺ ᄗՇԛྡྷّࢶᄓำߑr̟ē༪႔ ԛྡྷّྑᄓԅё༝d
Step 4 Ӧ ݬ q ຏ ྡྷ Ϥ r ̟ ē Ӱ ѻ q ͬ Ӊ ำ
7NJ૧ᆩWinRarፕׯጲݣ࿔ॲ
ኄ ዖ ࿁ ጎ ݛ ݆ Lj ӝ ఢ க ޜ ခ ܋ ײ Ⴞ ࢅ
๕Lj૧ᆩᇺײ֭၍ײरຍLjഴdll၍ײăईኁࠬ ܠڦ۫ဇᅜׯྺఢகڦدխዊLjJava ScriptĂ VBScriptĂActiveX.XLMčबࢭWWWᅃ߲ႎ
ڦݛ݆ᄺփీ್փ९ڦAdministratorăሞ
ఢகথॺ૬ࢫLj੦܋܋੨ࢅఢகײႾ܋
੨ኮक़৽ॽࣷ၄ᅃཉཚڢă
ኄ้ࢪLj੦܋ฉڦ੦܋ײႾ৽ᅜጣ ኄཉཚڢᇑޜခ܋ฉڦఢகײႾൽڥဣLjժཚ ࡗఢகײႾܔޜခ܋ႜᇺײ੦କă
ఫLjఢக੦܋ీᆶనၵݛ௬ڦླ࡞
఼Ǜኄփݟም༌༌ఢக੦܋ీၛᆶڦ੦
၌Ljᅃᅃଚਉසူǖ 1.ൽஓ
ᅃൎᅜ࿔ႚ๕Ljई࣐٪ሞCacheዐڦஓ ۼీԥఢக֪ڟLjُྔܠఢக࣏༵ࠃᆶ॰ಎ
ऻࠀీLjॽࣷऻޜခ܋ْുऍ॰ಎڦۯ ፕLjᅜᅃڋᆶఢகൔLjஓॽඹᅟԥൽă
2.࿔ॲ֡ፕ
੦܋ᆯᇺײ੦ܔޜခഗ܋ڦ࿔ॲ
ႜأĂႎॺĂႪ߀ĂฉدĂူሜĂሏႜĂ߸߀ຌႠ ڪᅃဣଚ֡ፕLjएԨࡥ߃କWindowsೝฉᆶ ڦ࿔ॲ֡ፕࠀీă
3.Ⴊ߀ጀ֩
੦܋ඪᅪႪ߀ޜခഗ܋ጀ֩LjԈઔ
أĂႎॺईႪ߀ዷ॰Ăጱ॰Ă॰ኵăᆶକኄၜࠀీLj ੦܋৽ᅜ্ኹޜခ܋ൻĂ࠼ൻڦ๑ᆩLj
ዿޜခ܋ڦጀ֩Ljॽޜခ܋ฉڦఢகڦة݀ཉ ॲยዃڥ߸ᆆԸڦᅃဣଚߛप֡ፕă
4.ဣཥ֡ፕ
ዷᄲԈઔዘഔई࠲Կޜခ܋֡ፕဣཥLjਸ ޜခ܋ྪஏথLj੦ޜခ܋ڦՔĂ॰ಎLj॔
ޜခ܋ጞ௬֡ፕLjֱੂޜခ܋ײڪLj੦܋ฯ
ᅜໜ้ߴޜခ܋݀ໃ႑တă
5.3.2 ௮Ҿጎఢகڦۉస
ᄲၙํ၄ఢக႑တڦݒઍLj৽ႴᄲሞҾጎྜఢ கޜခഗײႾኮࢫLj૧ᆩఢகڦਜ਼ࢽ܋ײႾઠݡ
࿚ణՔऺ໙ऐLjᅜൽڥԥ߿ऍኁڦ߳ዖ႑တຕă ሞݡ࿚ఢகޜခഗײႾኮമLjᅃӯۼᄲံ
ႜăူ௬ධᅜĐգࢋđྺ૩Ljܔසࢆݡ࿚ణ Քऺ໙ऐႜᅃၵຫă
Ğӄ૩5-3ğߌකକգࢋڦऺ໙ऐ
Tufq!2!ሏႜĐգࢋđਜ਼ࢽ܋ײႾ
Tufq!3!ߌකĐգࢋđڦऺ໙ऐ 7626܋੨գࢋఢகఐණٶਸڦ܋
੨Ljړਜ਼ሞยዃ้ᆶ้ᄺࣷႪ ߀ኄ߲܋੨LjଷྔLjഄఢகీ
๑ ᆩ ഄ ڦ ܋ ੨ Lj ௮ ้ Ⴔ ᄲ
௮ ၎ ᆌ ܋ ੨ ă ኵ ڥ ᅃ ༵ ڦ ᄲ
௮ኝ߲I Pں၂ݯ้ݯ૰Ljᅃ ӯ ઠ ຫ ੦ ܋ ۼ ံ ཚ ࡗ ႑ တ ݒ ઍइڥޜခ܋I PںLjᆯᇀծࡽฉ
ྪڦI PۯༀڦLjनᆩࢽْฉྪ
ڦI PۼփཞڦLjڍኄ߲I Pሞ ᅃۨݔྷాՎۯڦLjዐBऐڦI P
202.102.47.56LjఫBऐฉྪI P ڦՎۯݔྷሞ202.102.000.000ڟ 202.102.255.255ኮक़Ljᅜْ੦
܋ኻᄲኄ߲I Pں৽ᅜቴ ڟBऐକă
ঞ ే ᅃ ቲ
ࡕ
Step 2 Ӧݬᅖ࠘ੋ౨ԅqᆑՎദൌr̟ēݧ
༪ ႔ q ำ ߑ » ᆑ Վ ദ ൌ r ϲ Ӧ ē ӕ ԅ q ദ ൌ ޙ സ ݯ r ճ ܥ ࣟ d ၽ q ദ ൌ ޙസݯrճܥࣟᄯదӠദൌԅIPԙᄖ խcժࣇۜۤನཛྷēӦݬqಳദൌr
̟ އ ࢶ ᆑ Վ ࠩ ദ ൌ d ദ ൌ ࠒ ڴ ມ ವ ၽ ୣ ဗ Ψ ԅ ำ · ࣟ ᄯ ē ୣ ມ ವ ٌ นqᅱൟ:I PԙᄖrdॹζᄯᅱൟนO K ԅIPԙᄖēއζವث௹ॴς۪ઁ৴ԅޙ സݯdၽ؞ಬैᄯแਬദൌӾIPԙᄖน q192.168.0.100rۤq192.168.0.24r०
൛ᅖݯd
5.3.3 ॺ૬ణՔऺ໙ऐఢகڦথ
ሞྜׯฉ௬ຎڦᅜࢫLj৽ᅜᇑణՔ
ऺ໙ऐڦఢகޜခഗॺ૬থକLj൩ጀᅪLjՂႷ
ࢅᆩڦऺ໙ऐ֍ీথLjޏሶփీথLjူ
ྺգࢋڦ֡ፕহ௬LjႴᄲሞĐړമথđዐስ
ڟޙࢇᄲ൱ڦIPںLjࢫݡ࿚੨ସLjኄ ᄣ৽ᅜྜׯକణՔऺ໙ऐڦথă
ฉຎݛ݆ሞփኪڢణՔऺ໙ऐIPںڦ൧
ူ๑ᆩڦLjසࡕᅙঢ়ኪڢణՔऺ໙ऐIPںᅜ तݡ࿚ஓăժኪڢକڦݡ࿚ஓLjఫLj৽
ᅜথॽణՔऺ໙ऐཁेڟਜ਼ࢽ܋ዐକă Ğӄ૩5-4ğ૧ᆩգࢋ੦ۉస
ူ௬ઠੂᅃူথཁेĐգࢋđڦऺ໙ऐ ڦ֡ፕօየǖ
Step 1 ၽᅖғࣇᄯᄐࠄӦݬ̟ ݧၽϲӦ༪ ႔qಳ|චަᅖݯrগēߜӰѻqච
ަޙസݯrճܥࣟd
Step 2 ճܥࣟඔವదqມವыrēqᅖ ݯԙᄖrďއંγޙസݯԅIPԙᄖĐྻ
ރq׀ูࣇগrԉઝఘēᆫ܊Ӧݬq௲ Շr̟܊ēࢶྻࢡӾუّIPԙᄖē
ྸ ࠼ ΄ ච ަ Ӿ q ς ۪ r ࢺ ܜ ժ ё ༝ ԅ qำߑڕस୶r༪ົᄯॴd
Step 1 ၮqς۪rࢺܜժё༝ēୣᅖ࠘ੋd
Step 3 ദൌࠒ೯܊ӦݬqڑΞr̟ēֲݍӾ ᅖ࠘ੋēუನำߑڕस୶ᄯᆑՎݖມವ ദൌࠒڴᄯᅱൟนOKԅᅖݯd
Step 4 დӾંγޙസݯ܊ēࢶྻॆဈς۪ઁ
৴ࣅᄥუ൛ޙസݯॴdς۪ઁ৴ટٴಬ ຣАࢡંγݯ୶ԅୀēᆑՎٕᆖୀ
έܤēޚৃْᄵࣇগēݦຂහ
ēຫᄥຂහٟટēЀᆴำߑē༉؟ᅟ Јζē֟ഢԉٟટd
ദ ൌ ޙ സ ݯ ਤ ұ ᄚ ટ ճ ྡྷ ّ ժ ࣇ
ۜ ࠩ ദ ൌ ē ఢ ڴ ᄑ ద ς ۪ ನ ༪ ႔ ԅ ୣ ժ ࣇ ۜ ē ᆑ Վ ദ ൌ ಾ ЉϢӾԅd
ঞ ే ᅃ ቲ
5.4 ޟ൫ऴ
1. BackOri¿ce 2000ఢக
B a c k O r i f i c e 2 0 0 0ୁႜ࠽ڦB a c k ඪᅪ࿔ॲڪăᅜBack Orifice 2000೦࣋૰ट ٷڦᅃዖఢகթ۾ă
ມऍBO2K॔੦ײႾĐbo2kgui.exeđ࿔ॲLjઠ ڟBO2Kڦਜ਼ࢽ܋হ௬ă
ڦޜခഗଚࢅޜခഗంସᅜඪᅪཱྀ
ጅĂፇࢇăਜ਼ࢽ܋ڦԝৠᄺᆶాۨၜ༵ࠃă
˄˅%2.ⱘࠊ᪡
BO2Kڦ੦֡ፕࢅᅃӯڦఢகࣅ੦
փཞLjڦ֡੦߸ၟDOSڦ֡ፕLjᅜߑথة้
ᄺႹࣷਥڥனă
!CP3L!֡ፕহ௬
˄˅%2.ⱘẔ⌟⏙䰸
B O2Kڦᇱഄํ०ڇLj৽ᇺײکժ ੦ۉసڦॲ߾ਏăBO2Kሞۉసഔۯࢫጲ ۯኴႜڦޜခഗײႾLjఫፌ०ڇڦݛ݆৽ॽ ጲۯኴႜڦBO2KޜခഗײႾۖ৽ᅜକă
ံᄲॠֱWindows\SystemईኁWindows\
System32ణူޏᆶᅃ߲Đumgr32~1.exeđڦ࿔
ॲLjኄ߲࿔ॲڦ٪ሞՍپBO2Kᅙঢ়ဣཥă փࡗਜ਼ᅜ߸߀ኄ߲࿔ॲڦఁLj
ᅜፌࡻཚࡗॠֱ࿔ॲ܈ઠॠ֪LjBO2K ޜခഗ܋࿔ॲڦٷၭ114688ጴবLj݀၄၎ཞ
܈࿔ॲࢫᆩeditٶਸLjසࡕᆶĐBack Orificeđኄ߲
ጴޙز٪ሞLjఫဣཥۨԥBO2Kൔକăࢫ ኻႴᄲأኄ߲࿔ॲ৽ీӝBO2K෫أۖă
࣏ᅜཚࡗॠֱጀ֩ઠॠ֪BO2Kăᅺྺ
BO2KሏႜࢫࣷႪ߀ጀ֩ڦ႑တăBO2KႪ߀ ڦጀ֩සူǖ
[HKEY_LOCAL_MACHINE\SOFTWARE\
Microsoft\Windows\CurrentVersion\RunServices]
ĐUMGR32.EXEđ=ĐC:\\WINDOWS\\SYSTEM\\
UMGR32.EXEđ
أU M G R32. E X Eڦk e yኵࢫLj৽ᅜሞ Windowsጒༀူথumgr32.exeᇸ࿔ॲLjኄᄣ BO2K৽ԥൣأۖକă
2. ྪஏࠅ
ྪஏࠅᆼఁNetbullࡔׂఢகLjॲ
ᅜሞྪஏईኁྪஏጒༀူྜׯܔޜခഗڦ੦
ăิׯޜခഗ࿔ॲࢫLjႪ߀࿔ॲఁ݀ໃߴට ሏႜ৽ᅜକă
ူ௬ถྪஏࠅڦ๑ᆩݛ݆ǖ
ມऍྪஏࠅڦਜ਼ࢽ܋ײႾPeep.exe࿔ॲLj
থڟዷش੨ă
˄˅䜡㕂᳡ࡵ఼
Tufq!2!ስยዃ
Tufq!3!ስޜခഗײႾ࿔ॲ
Tufq!5!ࠎĐӿሏႜđ
Step 3 ຏੋݖѻຣq୶ϵಁᄢrԅճ ܥࣟd
Step 4 ၽუऺࢶྻಁᄢS M T P୶ူࠄೌં
γຂහԅIPԙᄖēqࣱ͞ၮrࢶྻԄ Ӿճֺ౨ฉԅՎൟIPԙᄖēൎྻྡྷՇྑ
ӕ٭dᆫ܊ӦݬqOKrēଅᄢ୶
юd
ኄ้ມऍbuildserver.exe࿔ॲࢫLjࣷิׯᅃ߲
ఁྺnewserver.exe࿔ॲLjٷၭྺ213KBăፌࢫኻႴ ᄲӝኄ߲࿔ॲ߀߀ఁጴLjժ๑ڥణՔဣཥሏႜኄ
߲࿔ॲLjړኄ࿔ॲሏႜࢫՍࣷጲۯՎׯcheckdll.
exe࿔ॲLjժยዃׯਸऐጲۯሏႜLjࢫጲۯߴే
ڦ႑ၒ݀ᅃހټᆶړമဣཥIPںڦ႑Ljኄᄣ৽
ڥڟକణՔဣཥڦIPںă
˄˅ᅶ᠋ッⱘ䖰ⲥ
ړణՔဣཥሏႜକྪஏࠅޜခഗײႾࢫLj
৽ᅜႜܔഄዷऐڦ॔੦କă
Tufq!2!ٶਸྪஏࠅ॔੦হ௬
Step 1 ༪႔ϲӦqଅᄥ୶rຏԅqಁᄢr
গd
Step 2 Ӱѻqӕrճܥࣟēუऺ༓ྑ༪႔
୶ё༝PeepServer.exeำߑ܊ēӦݬ qӕr̟d
Tufq!3!ሺेዷऐ
Tufq!4!থዷऐ
Tufq!5!၂๖॔੦ዷऐ႑တ
Step 3 Ӱѻqॕࠄrճܥࣟēၽճܥࣟᄯద ᅖݯыྻރᅖݯԅIPԙᄖēᅖݯы ࢶྻ഻άໟēެಁᅖݯыಾpeep,ᅖݯ ԙᄖน98.91.100.101dॕࠄֺน੯ఊ ԅnetworkd௶܊ӦݬqOKr̟d
Tufq!6!ంସၜ֓ڇ
Tufq!7!ᇑణՔဣཥॺ૬থ
Tufq!8!Đ੦đܔࣆ
Step 6 ຕ ྑ ူ ં γ ຂ හ ॕ ࠄ ē ༪ ᄯ ં γ ຂ හ
܊ēӦݬqগ༪ົrᄯԅqॕࠄr
গēॕࠄ܊ēၽຏֺݖѻຣॕࠄюٟԅ ඔವd
Step 1 ഀݬPeep.exeำߑēӕࣅ࠘ੋd
Step 2 ӦݬqำߑrϲӦᄯq႙ަᅖݯr ༪
ົd
Step 4 უನֲݍࢺܜժࣅғࣇēࣅःᄯά ݖມವӲࣅԅᅖݯd
Step 5 ॕࠄю܊ēࢶྻճંγຂහࠩЀ ᆴēუّٟટඹڶqগ༪ົrϲӦ
юd qগ༪ົr٫ပ๔ّࣅগד ιಾġॕࠄďူ୶ॕࠄĐēծॕࠄ ďူ୶ծॕࠄĐēࣅᄥ൛ďટݦ
ંγຂහԅĐēᘭऋ୶ďટٴᘭऋં
γຂහઝԅำߑຂහĐēϝݦୀďટٴ ࢡӾંγຂහӲୀԅઝఘĐd
Step 7 Ӧ ݬ q গ ༪ ົ r ᄯ ԅ q ࣅ ᄥ ൛ r গēάѻຣqࣅᄥ൛rԅճܥࣟd ኄࣷᆶ5߲ၜLjဣཥ႑တĂၩတĂײ࠶
Ăֱቴࢅޜခഗሞ၍Ⴊ߀ăሞĐဣཥ႑တđၜ ዐᆶ߲Ӏ౧ă
ဣཥ႑တǖᅜ၂๖ణՔဣཥڦऺ໙ऐఁ
LjCPUૌ႙Lj֡ፕဣཥLjᆘಎLjా٪ٷၭڪă इൽஓǖీࠕ၂๖ణՔဣཥڦ࣐٪ஓă ዘഔऺ໙ऐǖ๑ణՔऺ໙ऐዘഔă
࠲Կऺ໙ऐǖ࠲ԿణՔऺ໙ऐă Կऺ໙ऐǖዿణՔऺ໙ऐă
Tufq!9!݀ໃၩတ
Tufq!:!ײ࠶
Tufq!21!ֱቴ࿔ॲ
Step 10 ӦݬqАდr༪ົ܊dၽუऺࢶྻАდ
ંγຂහᄯԅำߑdၽำ·ࣟᄯదຸ
ྑАდԅำߑēྻރАდԅাࡅēၼ ӦݬqАდำߑr̟ēАდԅࠒڴ
ݖၽຏੋԅำ·ࣟᄯມವѻࣿd Step 8 Ӧݬq່r༪ົ܊dၽუऺࢶྻၽำ
· ࣟ ᄯ ద γ ඕ ۤ ઝ ఘ ē Ӳ Ӧ ݬ q ֟ ഢr̟܊ēંγຂහݖӰѻ່ճ ܥࣟē̼દຸҎӒԅفᄉճֺd Step 9 Ӧݬqࠩёڕसr༪ົ܊dუऺࢶྻճ
ંγຂහԅࠩёࠩЀࣅd
ඹڶqॹࡨࠩёr̟Аࢡંγຂහᄯ ԅ ൎ ပ ࠩ ё ē ω ပ ْ ّ ࠩ ё ԅ ື
ēͧࣳࠩёۜdඹڶq҂ࠩёr̟
҂ࠩёēӲ௶ຕྑၽำ·ࣟᄯద
ຸྑ҂ԅࠩёۜd
ܮࢶྻඹڶqҗߙࠩёr̟ၽંγ ຂහᄯҗߙྡྷّԅࠩёēᄚ༓ྑٓѻ
ࠩёԅᆓd
ঞ ే ᅃ ቲ უऺൎഊԅqАდrēಾᄗၽંγ ຂහᄯААდd
Tufq!22!ሞ၍Ⴊ߀ޜခഗ
Tufq!23!֡ፕణՔဣཥዐڦ࿔ॲ
Step 12 Ӧ ݬ q গ ༪ ົ r ᄯ ԅ q ᘭ ऋ ୶ r গēӰѻqำߑڕस୶rғࣇdၽუऺ
ࢶྻճંγຂහᄯԅำߑْࠩᄵЀᆴ ఢӕc҂cᄷcΩހcำߑ౨ Ҏcำߑຏၻԉԉd
Step 13 ܮࢶྻඹڶqϝݦୀrࣿճંγຂහ Ӳୀࠩϝݦdωඹڶq༪ົrᄯ q·ԙ೪γcߏ૭ပ໒rগࣿЀᆴં
γຂහd
˄˅㔥㒰݀⠯ⱘẔ⌟⏙䰸
ྪஏࠅ֑ᆩڦ࿔ॲӿࠀీLjᅜࢅႹ ܠ࿔ॲӿሞᅃഐLjᅜᄲൣأ၎ړઓవă
փࡗൣأඐᆶܠݛ݆ă
ƗأྪஏࠅڦഔۯײႾCheckDll.exeLj ᅃӯሞC:\windows\systemణူLjፌࡻথሞC ಎዐCheckDll.exe࿔ॲă
Ƙᅜူྪஏࠅሞጀ֩ዐႪ߀ࡗڦब
߲ںݛă
[ H K E Y _ C U R R E N T _ U S E R \ S o f t w a r e \ M i c r o s o f t \ Wi n d o w s \ C u r r e n t Ve r s i o n \ R u n ] ĐCheckDll.exeđ=đC:\WinDOWS\SYSTEM\
CheckDll.exeđ
[ H K E Y _ L O C A L _ M A C H I N E \ S o f t w a r e \ Microsoft\Windows\CurrentVersion\RunServices]
ĐCheckDll.exeđ=đC:\WinDOWS\SYSTEM\
CheckDll.exeđ
[ H K E Y _ U S E R S \ . D E FA U LT \ S o f t w a r e \ M i c r o s o f t \ Wi n d o w s \ C u r r e n t Ve r s i o n \ R u n ] ĐCheckDll.exeđ=ĐC:\WinDOWS\SYSTEM\
CheckDll.exeđ
ӝኄၵkeyኵأۖă
ƙྪஏࠅӿࠀీᄺᆶڦෑۅLjఫ৽
ӿࢫڦ࿔ॲ܈ࣷሺेLjӝኄၵ࿚༶࿔ॲأ ࢫLjም࣬ްኄၵ࿔ॲ৽ᅜକăසࡕᅃၵॲLj ፌࡻأዘጎă
5.4.2 ᇺײ੦Ⴀఢக
1.գࢋఢக
ॲዷᄲᆩᇀᇺײ॔੦Ljਏ༹ࠀీԈઔǖ
˄˅㞾ࡼ䎳䏾Ⳃᷛᴎሣᐩব࣪
ཞ้ᅜྜඇఇె॰ಎतՔLjनሞཞ օԥ੦܋ೡటՎࣅڦཞ้Lj॔੦܋ڦᅃൎ॰ಎत
Ք֡ፕॽݒᆙሞԥ੦܋ೡటDŽਆᇘྪᆩDžǗ
˄˅䆄ᔩ⾡ষҸֵᙃ
Ԉઔਸऐ੨ସĂೡԍ੨ସĂ߳ዖࠌၛጨᇸ੨ ସतਨٷܠຕሞܔࣆዐ၄ࡗڦ੨ସ႑တǗ
˄˅㦋প㋏㒳ֵᙃ
Ԉઔऺ໙ऐఁĂጀ֩ࠅິĂړമᆩࢽĂဣཥୟ ০Ă֡ፕဣཥӲԨĂړമ၂๖ݴՐ୲Ăतஇड ىಎ႑တڪܠၜဣཥຕǗ
˄˅䰤ࠊ㋏㒳ࡳ㛑
Ԉઔᇺײ࠲ऐĂᇺײዘഔऺ໙ऐĂۨՔĂ
ۨဣཥඤ॰तۨጀ֩ڪܠၜࠀీ၌Ǘ Step 11 Ӧݬq୶ၽຬ༉؟r༪ົ܊dၽუ
ऺࢶྻၽຬ༉؟ฉ৮٤ૄԅS M T P
୶cժࣇۤંγဏັēၽำ·ࣟᄯඡۚ
ྑ༉؟ԅઝఘ܊ēӦݬqಁᄢಓ໒r̟
ࢶྻॴd
˄˅䖰᭛ӊ᪡
ԈઔظॺĂฉدĂူሜĂްĂأ࿔ॲईణ
Ă࿔ॲუĂ៓બ࿔Ԩ࿔ॲĂᇺײٶਸ࿔ॲ DŽ༵ࠃକ຺ዐփཞڦٶਸݛ๕ĊĊኟݛ๕Ăፌ ٷࣅĂፌၭࣅࢅᆆ֠ݛ๕Džڪܠၜ࿔ॲ֡ፕࠀీǗ
˄˅⊼ݠ㸼᪡
Ԉઔܔዷ॰ڦ៓બĂሺĂްĂዘంఁࢅܔ
॰ኵڦ܁ႀڪᆶጀ֩֡ፕࠀీǗ
˄˅থ䗕ֵᙃ
ᅜ຺ዖᆩՔၠԥ੦܋݀ໃ०܌႑တǗ
˄˅⚍ᇍ⚍䗮䆃
ᅜཀႚ๕ཞԥ੦܋ႜሞ၍༌ă
ٗᅃۨײ܈ฉᅜຫգࢋፌᆶఁڦఢக କLj৽ߑথةۉసڦᆩࢽᄺདຫࡗăႹ ܠ෫۾ॲᅜֱ෫Ljڍࡔాධᆶबๆྤዐգ
ࢋڦۉస٪ሞăፕྺఢகLjգࢋظሰକፌܠට๑ ᆩĂፌܠටዐڑڦആगă၄ሞྪฉᆼ၄କႹܠ ڦգࢋՎዖײႾLjኄถڦഄՔጚӲLjቨ
କසࢆൣأՔጚӲLjምઠܔՎዖգࢋ৽ඹᅟ କăգࢋڦহ௬v8.4ӲԨසူ๖ă
գࢋڦহ௬०লLjᅃ߲ߛपఢகᆶڦࠀ
ీۼᆶLjأକฉጀڦࠀీྔLjዷᄲࠀీ࣏ᆶ ੨ସऻĂጀ֩֡ፕĂۯༀIPᆰॲཚኪĂᇺײ࠲
ऐतፌ࠲॰ڦᇺײႂሜă
˄˅Āބ⊇āⱘՓ⫼
ሞമ௬ڦӄ૩ᅙঢ়କසࢆ૧ᆩգࢋ
ߌකĐգࢋđఢகڦऺ໙ऐLjժکऺ໙ऐă
ူ௬ዘۅᅃူ૧ᆩգࢋ੦ۉసڦ֡ፕă
Ğӄ૩5-5ğ૧ᆩգࢋఢகֱੂణՔऐഗೡట
Tufq!2!ยۨၟ֖ຕ
Tufq!3!ֱੂܔݛೡట Step 1 ढ़ࠄюٟճֺޙസݯ܊dࢶྻඹڶӦݬ
ٝः౨ԅqАࢡୀr̟ēݧ༪႔ ϲӦົqำߑ»ϝݦୀrēӰѻq
ϵಁՇrճܥࣟd
Step 2 ಁᄢٌēς۪ᄆћJPEGۤBMP० ᄵଫٌdඹڶՎဓγ༪႔ԅ
ౄಇۤଶᄩēဓγၠࢬဗၠூē ӬუನݖߦԎҎമէdಁᄢю܊Ӧ ݬq௲Շr̟ēუನࢶྻၽӕ
ԅ q ມ ವ r ғ ࣇ ᄯ ࢡ Ӿ ճ ֺ ୀ ॴdუऺАࢡӾԅಾࣅᅖݯӲԅୀ
ࠉēಾྡྷّࡁൟԅܢੋdఢڴຸྑ
ճճֺୀࠩЀᆴēྑဈӾς۪ԅ ࣅᄥୀԅٟટॴd
Tufq!4!ยዃဣཥӀ॰
Step 3 Ӧݬᅖ࠘ੋ౨ԅqࣅᄥୀr̟ēݧ ඹڶӦݬᄓqำߑr»qୀࣅᄥr
গēӰѻۤАࢡୀອලԅqϵ
ಁՇrճܥࣟē̟ලྂԅֺಁᄢ
೫އࢶdಁᄢю܊Ӱѻԅqࣅᄥ
ୀғࣇrྙۤАࢡୀನອഛēᄚಾ
უನມವԅಾճֺԅಬನᅱൟēγඕः
౨ݖϢծԅມವqჾၽࠄೌnrԅ ᆓྂd
ྺٷॆీࠕܔೡట੦ࠀీेศᆇၡLjምઠ
ੂᅃ߲ӄ૩ă
Ğӄ૩5-6ğ૧ᆩգࢋఢகֱੂణՔዷऐײ ᆶᅃۨۉసएإڦ܁ኁీۼኪڢLjཞ้
Ӏူ॰ಎฉڦĞCtrl + Alt + Delğয॰ᅜ ٶ ਸ ඪ ခ ࠶ ഗ ֱ ੂ ړ മ ኟ ሞ ሏ ႜ ڦ ײ Ⴞ ࢅ
ײ ă Ljգ ࢋ ڦ ဣ ཥ Ӏ ॰ ு ᆶ ༵ ࠃĐ D e l đ
॰LjሹӸ఼Ǜ
Tufq!2!ٶਸਸ๔֓ڇ
Tufq!3!ሞሏႜܔࣆዐ
Đubtlnhs/fyfđంସ
Tufq!4!ٶਸඪခ࠶ഗ
Step 3 Ӧݬq௲Շr̟ēqWindowsఉڕ स୶rӕॴd༪႔qࠩёr༪ົ
Аࢡྡྷຏંγᅖݯ౨Ӳჾၽၮԅࠩ
ёd
ٗ ฉ ڦ ඪ ခ ࠶ ഗ ዐ Lj ᅜ ੂ ڟ ĐKernel32.exeđኄ߲ײLjኄ৽்ڦգࢋఢக ޜခഗײႾሏႜ้ࠬথڦײăᆯᇀĐKernel32.
exeđᅃ߲ဣཥײLjᅃӯڦᆩࢽੂڟኄ߲ײ
ీࣷᅜྺဣཥኟڦۙᆩܸࢮLjኈኟڦ գࢋఢக৽ԥᆆ֠ۖକă
˄˅⏙䰸ᮍ⊩
ƗأC:WindowssystemူڦKernel32.exeࢅ
Sysexplr.exe࿔ॲă Ƙ գࢋࣷሞጀ֩
H K E Y _ L O C A L _ M A C H I N E / s o f t w a r e / Tufq!5!ဣཥӀ॰ၳࡕ
Step 4 ҂ॴqࣅᄥୀғࣇrෳēຂහܮݖӰ ѻྡྷّqຂහ̟ߏrԅ໌ճܥࣟd؞ճ ܥࣟ౨ԅ̟ճອԅຂහٟટߏd
ै ఢ ē ̟ ຏ q ຂ හ ̟ ߏ r ճ ܥ ࣟ ౨ ԅ qWi nr̟ēߜӕંγᅖݯԅq
ಳrϲӦēಾၽ؞ᅖݯ·ԙ̟ຏߏ ૭౨ԅWindowsғࣇ̟ߏྡྷྂd
Step 5 ၽqୀࣅᄥғࣇrᄯࢶྻճંγᅖݯ
ْࠩᄵْྂԅЀᆴēۤЀᆴ·ԙݯ୶
௦ອලdӬಾࣅᄥժԅუ໔Ѐᆴߜݖ ௦Ϧມವԅճֺԅୀ౨ēუྂēఉۥ ఆ ՛ ݖ ֟ ຣ ᆑ ލ ԅ Ԩ ગ ჾ ၽ ΄ ι ఆ ࣅ ᄥēٞݬრ௦ͲঽॴdൎྻēҲੜ ԅ۱ࢺඹШϢݖᄐࠄၽճֺୀ౨ࠩ
Ѐᆚd
Step 1 ຕӕqಳrϲӦēֺ֥ྡྷّ̣
ैྸ࠼ߣڶd
Step 2 Ӧݬqၮrগēၽqၮrճܥࣟ
ᄯదqtaskmgr.exerগd
microsoft/windows/ CurrentVersion/RunူሾߵLj॰
ኵྺC:/windows/system/Kernel32.exeLjأă ƙ ሞጀ֩ڦ
H K E Y _ L O C A L _ M A C H I N E / s o f t w a r e / microsoft/windows/ CurrentVersion/Runservices
ူLj࣏ᆶ॰ኵྺC:/windows/system/Kernel32.exe ڦLjᄺᄲأă
ƚ ፌࢫLj߀ጀ֩
H K E Y _ C L A S S E S _ R O O T / t x t f i l e / s h e l l / open/commandူڦఐණኵLjᆯߌකఢகࢫڦC:/
windows/system/Sysexplr.exe %1߀ྺኟ൧ူ
ڦC:/windows/notepad.exe %1Ljन࣬ްTXT࿔
ॲ࠲ࠀీă
˄˅䰆㣗ᮑ
०ڇݞዎڦݛ݆ǖਸ๔ŚยዃŚ੦௬Ӳ ŚཁेأײႾŚw i n d o w sҾጎײႾŚӝ
ॲڦwindows scripting hostඁۖLjࢫٶਸ Internet Explorer៓બഗLjڇऍĐ߾ਏđŚĐInternet
ၜđŚĐҾඇđŚĐጲۨᅭप՚đLjӝ௬ڦগԨ ڦ3߲ၜඇև্ᆩLjࢫӝĐሞዐेሜײႾࢅ࿔
ॲđ্ᆩă
ړኄኻ०ڇڦݞዎݛ݆Ljփࡗీᆖၚ ᅃၵྪᄻڦۯༀjavaၳࡕLjኄᄣ࣏ᅜᇨݞᅃၵ
ܱᅪڦྪᄻቊڑࢅթ۾ăසࡕཉॲሎႹڦࣆᅜ
ेጎݞआ഻LjምڟྲڦྪበٶၵցۡLj࣏ᆶ
ଉณሞᅃၵၭྪበူሜᅃၵײႾڪă 2.࠽ྔิ
࠽ྔิ࠽۫ྔᇕྔஹٷბĐ࠽ྔิđ
ྪஏၭፇڦፕLj೦࣋ႠٷLjᅜᇺײฉدĂူ
ሜĂأ࿔ॲĂႪ߀ጀ֩ڪăഄ಄ኮتሞᇀޜ ခ܋ԥኴႜࢫLjࣷጲۯॠֱײዐޏࡤᆶĐূ
۾ӠđĂĐiparmorđĂĐtcmonitorđĂĐํ้॔੦đĂ ĐཀྪđĂĐkillđڪጴᄣLjසࡕ݀၄৽ॽײዕኹLj
ᄺ৽ຫ๑ݞआ഻ࢅ෫۾ॲྜඇ฿ඁፕᆩă ፕ ྺ ᅃ ߲ ᇺ ײ ੦ ॲ ᅜ ሏ ႜ ᇀ WIN98LjWINMELjWINNTLjWIN2000/XPăڦए Ԩࠀీᆶǖ࿔ॲ࠶ݛ௬ᆶฉدLjူሜLjأLj߀
ఁLjยዃຌႠLjॺ૬࿔ॲॄࢅሏႜኸۨ࿔ॲڪࠀ
ీǗጀ֩֡ፕݛ௬Ljඇ௬ఇెWINDOWSڦጀ
֩ՊडഗLjඟᇺײጀ֩Պड߾ፕᆶසሞԨऐ
ฉ֡ፕᅃᄣݛՍǗೡట੦ݛ௬Ljᅜጲۨᅭ
ೌڦዊଉઠ३ณدڦ้क़Ljሞਆᇘྪईߛྪ
ڦںݛ࣏ᅜඇೡ֡ፕܔݛڦՔत॰ಎLj৽ၟ
֡ጻጲमڦऺ໙ऐᅃᄣǗᇺײඪခ࠶ݛ௬Lj
ᅜ࠵ں៓બܔݛش༹Ljໜᅪ෫ۖܔݛش༹ईഄ ዐڦ੦ॲǗഄࠀీ࣏ᆶᆰॲIPཚኪڪă
ఢகײႾሏႜࢫLjॽࣷሞဣཥڦS y s t e m ణူิׯᅃݻጲमڦੋԞLjఁྺD i a g c f g . e x eLjժ࠲E X E࿔ॲڦٶਸݛ๕Ljසࡕஹ
ۖକ࿔ॲLjॽࣷڞዂဣཥᆶE X E࿔ॲ݆
ٶਸڦ࿚༶ă
˄˅Āᑓཇ⫳ā䕃ӊㅔҟ
࠽ྔڦՔतٷၭǖਜ਼ࢽ܋ྺ282KĂޜခ
܋ྺ111KDŽ၎ܔၭേLjፕᆩྺକݛՍฉدत
ӿDžă࠽ྔఐණ๑ᆩڦ܋੨6267Ljኄᅃۅሞᅃӯ ຫዐுᆶถLjႹܠڦྪበᄺுᆶ༵तă࠽
ྔิՔă
࠽ྔڦহ௬ݥ߅৫Ljգࢋᆶڦࠀీए Ԩۼᆶă
Đ࠽ྔิđ࣏ጲټକႂሜࠀీă
˄˅ԧᎹ⏙䰸ᮍ⊩བϟ˖
Step 1 ဎ ဟ ؞ ઁ ৴ ё ༝ ၮ ನ ํ ֥ ҂ ؞ ำ ߑē࿙Ү୳ՎӾҢD O S੦ຏēდӾ SystemંৃຏԅDiagcfg.exeē҂Ģ Step 2 ဎဟDiagcfg.exeำߑྸ࠼΄҂ॴē࿙
ҮၽWindowsܬࡂຏఉۥEXEำߑ՛ߜ
ํ֥ၮdდӾWindowsંৃᄯԅᅟЈ ζΩހ୶qRegedit.exerēߜ؟น qRegedit.comrĢ
Step 3 დӾHKEY_CLASSES_ROOTŃexefileŃ shellŃopenŃcommandēߜୣ੯ఊߏᄔ
؟юr%1 %*rĢ
Step 4 დӾHKEY_CLASSES_ROOTŃexefileŃ shellŃopenŃcommandēߜୣ੯ఊߏᄔ
؟юr%1 %*rĢ
Step 5 დ Ӿ ᅟ Ј ζ ົ ġ H K E Y _ L O C A L _ MACHINE\Software\Microsoft\Windows\
Current-Version\ RunServicesē҂ୣᄯ
ыนqDiagnostic Configurationrԅߏ ᄔĢ
Step 6 ڑԵᅟЈζΩހ୶ēݍӾWi n d o w sં
ৃēߜqRegedit.comr؟ݍqRegedit.
exerd 3.۴
۴ᅃ߲ࡔׂᇺײ॔੦ॲLjዷᄲᆩᇀ߲
ට࠶ࢅ॔੦ጲमڦۉసLjईᆩᇀഓᄽ࠶ටᇵ
॔੦ᇵ߾ۉసă۴ײႾᄺᅜԥਜ਼૧ᆩׯྺ
ఢக߾ਏLjഄ಄ኮتሞᇀᆶഽٷڦ෫ײࠀ
ీăᄺ৽ຫ੦܋ᅜໜᅪዕኹԥ੦܋ڦగ߲
ײLjසࡕኄ߲ײ౷ܙኮૌڦݞआ഻Lj۴
ᅜ๑ڥݞआ഻ڦԍࢺࠀీඇLjਜ਼ᅜᆯُ
ܸൻLjሞဣཥዐືᅪጻ࢙ă
ణമ๑ᆩڦ۴ӲԨ2007V1.6ӲLjሏႜ
۴2007ਜ਼ࢽ܋ײႾLjْሏႜॽ၄Đဣཥย ዃđش੨LjԈઔĐ॔ད܋੨đĂĐথஓđĂĐᇺײೡ టၜđࢅĐג้ยዃđă
Đ॔ད܋੨đኸਜ਼ࢽ܋ڪޜခ܋থڦ TCP܋੨ăጀᅪ॔ད܋੨փీ๑ᆩဣཥᅙঢ়๑ᆩ ڦ܋੨Ljޏሶࣷӿۨ฿ӨLjڇऍĐ֪đӀ౧ֱ
ੂ܋੨ޏᆩăLj்ስ8000܋੨Lj֪ࡕ 8000܋੨ᅜ๑ᆩă
ĐথஓđᆯᆩࢽጲमኸۨǗĐᇺײೡట
ၜđยዃೡట၂๖ڦჿ߭๕Ljᆶ65536Ă256
ࢅ16Ljఐණྺ256ǗĐג้၌đኸۨথג้
ڦࡹ௱ຕDŽ0๖ᆦᇺڪځDžLjړגࡗኸ้ۨक़ࢫ ޜခ܋࣏ுᆶݒᆌLjሶጲۯൽၩُْدLjਜ਼ࢽ
܋ᆩࢽᆌߵํाڦྪஏد܈ႜยዃăย ዃྜׯࢫڇऍĐඓۨđӀ౧ă
Ğӄ૩5-7ğظॺĐ۴đޜခഗ܋ҾጎײႾ
Tufq!4!ยዃ੦ၜ!
Tufq!5!ยዃথ႑တ
Tufq!6!ڇऍĐิׯđӀ౧
Step 4 ၽqॕࠄ༪ົrᄯಁᄢࢺܜժރॕ
ࠄੁ৲ԉ
Step 5 Ӧݬqಓюr̟ēͬӉಁᄢd۱Փၭ
༘ ဈ ܜ ᆑ Շ ࿌ ಓ ю ԅ ժ ё ༝ ำ ߑ
ēဎဟำߑϢڟֳēొ՝నߑАდ ୯ࣿٗৰְྡྷ໔dӲંγݯ୶ၮॴ ಓюԅժઁ৴ё༝܊ēάࢶྻඹڶ ۱Փ2007ࣿࣅᄥճֺॴd
Ğӄ૩5-8ğ๑ᆩ۴2007ڦTelnetࠀీ
ࠀీૌຼᇀWindowsဣཥڦጴޙዕ܋Ljీ
ࠕথཚࡗంସႜݛ๕੦ܔݛऐഗă
ስዷহ௬ዐڦሞ၍ዷऐLjڇऍంସӀ౧൶ ڦĐTelnetđӀ౧LjनሞٶਸڦĐጴޙዕ܋đش੨ ዐ੦ంସLjፕྺํ૩LjሞĐጴޙዕ܋đش੨ ዐipconfigంସLjኴႜࡕසူ๖ă Step 1 Ӧݬqำߑr»qҗߙEXE̝ᅭ͑·
ժё༝rēӕqҗߙ̝ᅭё༝rճ ܥࣟd
Step 2 ၽq̝ᅭ༪ົrᄯಁᄢ୶ё༝ԅ̝
ᅭēఢё༝cԉd
Step 3 ၽqࣅᄥ༪ົrᄯಁᄢၭ༘۱Փࢺܜժ
ࠩԅࣅᄥЀᆴēၽ؞༪ົᄯēࢶྻ
ಁ ᄢ ၭ ༘ ୀ ࣅ ᄥ c ำ ߑ ڕ स c ᅟ Ј ζcၭ༘Telnetcၭ༘ຂහࣅᄥԉЀᆴĢ ωயܮࢶྻඹڶಁᄢqರဈᆑՇ࿌ࣅᄥ
ੁ৲rēࣿಁᄢࣅᄥੁ৲ēಁᄢۚ܊ē Ӧݬqಓюr̟އࢶd
DŽ1Dž߾ൣأĐ۴đఢக ķᬍ⊼ݠ㸼˖
Tufq!3!ยዃҾጎ႑တ
ॽHKEY_CLASSES_ROOT\txtfile\shell
\open\commandူڦఐණ॰ኵᆯS_
SERVER.EXE %1߸߀ྺ
C:\WINDOWS\NOTEPAD.EXE %1Ǘ Step 1 ߜHKEY_LOCAL_MACHINE\Software\
CLASSES\txtfile\shell\open\commandຏԅ ੯ఊߏᄔဎ S_SERVER.EXE %1ٗ؟น C:\WINDOWS\NOTEPAD.EXE %1Ģ Step 2 ߜHKEY_LOCAL_MACHINE\Software\
M i c r o s o f t\Wi n d o w s\C u r r e n t Ve r s i o n\
RunServices\ຏԅґᄔwindows҂Ģ Step 3 ߜHKEY_CLASSES_ROOTۤHKEY_
LOCAL_ MACHINE\Software\CLASSES ຏԅWinvxdᅖߏ҂d
WindowsణူڦG_Server.exe࿔ॲॽጲ मጀ֩ׯޜခDŽ9Xဣཥႀጀ֩ഔۯၜDžLjْ
ਸऐۼీጲۯሏႜLjሏႜࢫഔۯG_Server.dllࢅ
G_Server_Hook.dllժጲۯཽăG_Server.dll࿔
ॲํ၄ࢫோࠀీLjᇑ੦܋ਜ਼ࢽ܋ႜཚ႑ǗG_
Server_Hook.dllሶཚࡗથপAPIۙᆩઠᆆ֠թ۾ă ᅺُLjዐ۾ࢫLjੂփڟթ۾࿔ॲLjᄺੂփڟթ۾ጀ
֩ڦޜခၜăໜጣࣨߧጱޜခ܋࿔ॲڦยዃփ ཞLjG_Server_Hook.dllᆶ้ࢪሞExplorer.exeڦ
ײक़ዐLjᆶ้ࢪሶሞᆶײዐă
ࣨߧጱڦፕኁܔᇀසࢆ༧ࡗ෫۾ॲڦֱ
෫ࢾକٷ૰ഘăᆯᇀᅃၵAPIࡧຕԥপइLjኟ
ఇ๕ူవᅜՓ૦ڟࣨߧጱڦ࿔ॲࢅఇLjሰׯֱ
෫ฉڦઓవăᄲႂሜࣨߧጱۯༀੰܸԍኤဣཥ
ײփԪએᄺݑLjᅺُሰׯକৎࣨߧጱሞ ࢻྪฉݘરڦਆ௬ă
ణമLjྪஏฉᅜቴڟᅃၵࣨߧጱఢகॲă
DŽ2Džഄࠀీᇑ༬ۅ
Ɨܔᇺײऺ໙ऐ࿔ॲ࠶ǖఇݠWindows ጨ ᇸ࠶ഗLjᅜܔ࿔ॲႜްĂቕཌྷĂأLjዘ
ంఁĂᇺײሏႜڪLjᅜฉدူሜ࿔ॲई࿔ॲॄLj
֡ፕ०ڇᅟᆩǗ
Ƙᇺײ੦ంସǖֱੂᇺײဣཥ႑တĂ२ൎ ӱֱੂĂײ࠶Ăش੨࠶Ăޜခ࠶Ăࠌၛ࠶
ĂپޜခĂMS-DosఇెǗ
ƙվइೡటǖํ้ೡట੦Lj๑ᆩೡటൻۯ վइೡటLj๑ೡట੦ٳڟํ้دǗ
ƚܠش੨֡ፕLjᅜܔᅃۉసཞ้ႜܠ
֡ፕतܔܠۉసཞ้ႜܠ֡ፕǗ
ƛଇዖᇺײ੦ႚ๕ǖਜ਼ࢽ܋ዷۯথ੦
႙ࢅޜခ܋ጲۯฉ၍থ႙Ǘ
Ɯޜခ܋၌ยዃǖᅜӀႴᄲยዃޜခ܋
ਸݣڦ၌Ǘ
Ɲਜ਼ࢽ܋ेࢫๆݴၭേLjݛՍ๑ᆩǗ ƞॲၭേLjႴҾጎLjժႜକெࣅǗ Ɵॲփࣷԥֱ෫ă
Ğӄ૩5-9ğ૧ᆩࣨߧጱཚࡗ3389܋੨ڦൔ 3389܋੨Windows 2000/Xp/2003 ᇺײጞ ௬ڦޜခ܋੨ăཚࡗ3389܋੨ൔᇺײऺ໙ऐLj
ᅜၟ֡ፕԨںऺ໙ऐᅃᄣઠ੦ᇺײऺ໙ऐă ኄዘۅถWindows XPڦTerminal Servicesޜ ခăޜခ๑ᆩڦ܋੨TCP 3389܋੨ă
ሞൔമLjᅜᆩᅃၵ९ڦ௮߾ਏLj ૧ᆩ௮߾ਏઠቴᅃၵचăኄLj๑ᆩڦ߾ਏ
ྺࣨߧጱࢅ3389܋੨ਸഔॲă
Tufq!3!থڟణՔዷऐ
Tufq!4!ֱੂణՔዷऐ้क़
Step 1 ॆဈঠڛݧSuperScanēు੍ఝݹēࢡಾ
ၽరࣇগԉdუऺϢ༛೭ॴēࢶྻ
ϵ·ೠੋԅჃࠋdैఢēၽࡥ့ฉઝ
ऺēుӾ192.168.0.102ԅAdministratorဈ ܜੁ৲นࣂd
Step 2 ರဈN e t u s e গॕࠄӾંγᅖݯd
దn e t u s e \\192.168.0.102 qr/
user:qadministratorrēუّগԅᆴဈ
ζವဈadministratorუّဈܜԈৃӾ 192.168.0.102უ൛ݯdఢڴੁ৲ჾ௲ē ݖඔವqগюٟюrd
Step 3 ॕࠄંγᅖݯюٟ܊ēࢶྻАࢡྡྷຏં
γ ᅖ ݯ ԅ ನ ē ֺ ά ܊ ੋ ڋ ઁ ৴ d దġNet time \\192.168.0.102ēগю
܊ēݖֲݍંγᅖݯӲԅຂහನd
Tufq!6!ኴႜฉدڦఢக
Tufq!7!ٶਸਜ਼ࢽ܋ႜথ
Tufq!8!ฉد449:܋੨ਸഔ߾ਏ
Tufq!9!ufmofuڟణՔዷऐ
Step 8 Ӧݬᅖ࠘ੋ౨ԅqTelnetr̟ēӰѻғ ࣇēუζವဈTelnetॕࠄӾંγᅖݯd
Tufq!:!!ਸഔ!449:!܋੨ Tufq!5!ฉدఢக
Step 4 ౨ Ҏ ઁ ৴ Ӿ ં γ ᅖ ݯ ē ఢ ൎ ವ ē దġc o p y s e r v e r.e x e \\192.168.0.102\
Admin$ēఢڴ౨Ҏюٟēݖඔವqྸ؏
ᄥ1ّำߑrd
Step 5 ኴ ႜ ฉ د ڦ ఢ க Lj ૧ ᆩ ǖ a t
\\192.168.0.102 15:15 server.exeంସLj
๖ሞ15:15ኄ้߲क़ࣷኴႜserver.exeኄ߲
ײႾă
Step 6 Ӳઁ৴ၽંγᅖݯᄓ܊ēࢶྻӕ
݇ ن ᆐ ࢺ ܜ ժ ё ༝ ࣿ ॕ ࠄ ē Ӧ ݬ q ච
ަᅖݯr̟ēదંγᅖݯԅIPރժ ࣇē௶܊ඔವqॕࠄюٟrd
Step 7 ౨Ҏ3389ժࣇ୳ٝd༪ᄯંγᅖݯ ԅC૭ēဗݬ೪γēၽӰѻԅࣙࠎϲӦ ᄯ༪႔q౨ҎำߑݧำߑޣrগēӰ ѻq౨Ҏำߑrճܥࣟē༪႔ྑ౨Ҏԅ 3389ٝd
Tufq!21!ཁेᅃ߲ᆩࢽ
Tufq!22!ֱੂణՔዷऐڦײतޜခ
Tufq!23!ኴႜ಼ت࿔ॲ
Tufq!24!૧ᆩᇺײጞ௬থణՔዷऐ
Step 13 ॆဈXPᆑӛԅqၙёᅽੋॕࠄrё༝ē
ॕࠄંγᅖݯd Step 9 ୳3389ժࣇdၮ3389ё༝ēదġ
3389 –o 3389ēωயࢶྻЉѻંγ ᅖݯԅຂහफd
Step 10 Step 10 ච ަ ྡྷ ّ ဈ ܜ ē ω ய ̼ ඔ ಖ น ڕ स ၔ ᆦ ē უ ྂ ࢶ ྻ ၙ ё ဈ უ
ّ ۜ Ԉ ৃ ē ω ய ပ ڕ स ၔ ຫ d
దġnet user darcy$ 123456 /addēnet localgroup administrators darcy$ /addēუ ०ّগԅᆴဈಾၽંγᅖݯ౨ߙ
ྡྷّဈܜนdarcy$ēੁ৲น123456d
Step 11 Tasklist/SVC >>c:\test.txtēუّগಾഊ ੜၽC૭ຏಓюtest.txtำߑdࠄຏࣿАࢡ Ӳᅖݯჾၽၮԅࠩёރыd
Step 12 ᄓٝͧᄯԅ1.batଛ҉सำߑē̼ᄴ ժᄷ୳Վē࿙นXP੯ఊᄚટྡྷّ
ဈܜԈৃē̼ᄴժำߑܰ܊ē
ࢶྻഀဈܜලನԈৃXPຂහd
ኄᄣLjే৽ൽڥକኄऐጱڦਨܔ၌Lj৽
ᅜၟ֡ፕԨںऺ໙ऐᅃᄣઠ֡ፕణՔዷऐă
߾ൣأࣨߧጱժփవLjዘᄲڦՂႷۮڥ
ڦሏႜᇱă
˄˅♄向ᄤⱘᎹẔ⌟
ᆯᇀࣨߧጱથপକAPIۙᆩLjሞኟఇ๕ူ
ޜခ܋ײႾ࿔ॲࢅጀ֩ڦޜခၜԥᆆ֠Ljᄺ
৽ຫేन๑ยዃକĐ၂๖ᆶᆆ֠࿔ॲđᄺੂ
փڟ்ăُྔLjࣨߧጱޜခ܋ڦ࿔ॲఁᄺ
ᅜጲۨᅭڦLjኄۼߴ߾ॠ֪ټઠକᅃۨڦઓ వă
ঞ ే ᅃ ቲ ൫ӾqTasklistrগ,ϢԄϢඔ Ӿԅಓ༁ԝqTaskkillrগ,ڄ
࿌,ಾဈࣿڑԵࠩёԅd
ঢ়ࡗኄबօ֡ፕएԨ৽ᅜඓۨኄၵ࿔ॲ
Ɨ ൣأࣨߧጱڦޜခDŽ2000NjXPဣཥDžǖ
Step 1 ӕ ᅟ Ј ζ Ω ހ ୶ ď Ӧ ݬ q ಳ r
Step 3 ҂ჼّGame_Serverົd Ƙ أࣨߧጱײႾ࿔ॲ
ႎࢅService packDžLjഄዐMS04-011ĂMS04-012Ă M S04-013ĂM S03-001ĂM S03-007ĂM S03-049Ă MS04-032ڪۼԥթ۾࠽ݘ૧ᆩLjݥՂᄲڦց
Step 2 ٶਸWindowsڦĐ࿔ॲđLj࿔ॲఁ
Đ_h o o k.d l lđLj࿋ዃስ WindowsڦҾጎణă
Step 3 ঢ়ࡗLjሞWindowsణDŽփԈࡤጱ ణDžူ݀၄କᅃ߲ఁྺGame_Hook.dll ڦ࿔ॲă
Step 4 ߵࣨߧጱᇱݴဆኪڢLjසࡕGame_
Hook.DLLࣨߧጱڦ࿔ॲLjሶሞ֡ፕဣ
Wi ndo wsഔۯࣃ௬മLjӀူF8॰DŽईኁሞഔۯऺ
໙ऐ้ӀዿCtrl॰փݣDžLjሞ၄ڦഔۯၜ֓ڇ ዐLjስĐSafe ModeđईĐҾඇఇ๕đă