转至繁体中文版     | 网站首页 | 图文教程 | 资源下载 | 站长博客 | 图片素材 | 武汉seo | 武汉网站优化 | 
最新公告:     敏韬网|教学资源学习资料永久免费分享站!  [mintao  2008年9月2日]        
您现在的位置: 学习笔记 >> 图文教程 >> 软件使用 >> 系统软件 >> 正文
Win2K/XP SDT Restore 0.2 (Proof-Of-Concept)         

Win2K/XP SDT Restore 0.2 (Proof-Of-Concept)

作者:闵涛 文章来源:闵涛的学习笔记 点击数:1904 更新时间:2009/4/25 0:44:48
by unknown at F754CDB7]-- ZwDeleteFile 34 --[hooked by unknown at F754C80C]-- ZwGetTickCount 4C --[hooked by unknown at F754CE27]-- ZwLoadDriver 55 --[hooked by unknown at F754CBF2]-- ZwQueryDirectoryFile 7D --[hooked by unknown at F754C6E8]-- ZwQuerySystemInformation 97 --[hooked by unknown at F754C623]-- ZwSetInformationFile C2 --[hooked by unknown at F754C8A8]-- Number of Service Table entries hooked = 10 WARNING: THIS IS EXPERIMENTAL CODE. FIXING THE SDT MAY HAVE GRAVE CONSEQUENCES, SUCH AS SYSTEM CRASH, DATA LOSS OR SYSTEM CORRUPTION. PROCEED AT YOUR OWN RISK. YOU HAVE BEEN WARNED. Fix SDT Entries (Y/N)? : y [+] Patched SDT entry 10 to 804A257F [+] Patched SDT entry 20 to 80497EF9 [+] Patched SDT entry 23 to 804B2483 [+] Patched SDT entry 29 to 804A9212 [+] Patched SDT entry 34 to 804D0584 [+] Patched SDT entry 4C to 80463FF2 [+] Patched SDT entry 55 to 8052DC72 [+] Patched SDT entry 7D to 80498541 [+] Patched SDT entry 97 to 80493B5B [+] Patched SDT entry C2 to 80498C08
 
Limitations

This version is tested only on English Win2K SP2 and SP4, WinXP SP0 and SP1.

THIS IS EXPERIMENTAL CODE. FIXING THE SDT MAY HAVE GRAVE CONSEQUENCES, SUCH AS SYSTEM CRASH, DATA LOSS OR SYSTEM CORRUPTION. IT IS RECOMMENDED THAT YOU USE THIS CODE ONLY ON A TEST SYSTEM. PROCEED AT YOUR OWN RISK.
 

Credits

  1. hoglund - original and first public NT ROOTKIT
  2. fuzen_op - FU Rootkit
  3. hf - Hacker Defender
  4. joanna - klister
  5. 90210//HI-TECH - phide
  6. 90210 - Thanks for the more stable way of finding the address of KiServiceTable.

 

Contacts

For further enquries or to submit malicious code for our analysis, email them to the following.

Overall-in-charge: Tan Chew Keong

上一页  [1] [2] 


[MySql]Linux网络代码导读v0.2  [MySql]Linux网络服务软件安装备忘录 ver 0.2
教程录入:mintao    责任编辑:mintao 
  • 上一篇教程:

  • 下一篇教程:
  • 【字体: 】【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口
      注:本站部分文章源于互联网,版权归原作者所有!如有侵权,请原作者与本站联系,本站将立即删除! 本站文章除特别注明外均可转载,但需注明出处! [MinTao学以致用网]
      网友评论:(只显示最新10条。评论内容只代表网友观点,与本站立场无关!)

    同类栏目
    · 办公软件  · 系统软件
    · 常用软件  · 聊天工具
    更多内容
    热门推荐 更多内容
  • 没有教程
  • 赞助链接
    更多内容
    闵涛博文 更多关于武汉SEO的内容
    500 - 内部服务器错误。

    500 - 内部服务器错误。

    您查找的资源存在问题,因而无法显示。

    | 设为首页 |加入收藏 | 联系站长 | 友情链接 | 版权申明 | 广告服务
    MinTao学以致用网

    Copyright @ 2007-2012 敏韬网(敏而好学,文韬武略--MinTao.Net)(学习笔记) Inc All Rights Reserved.
    闵涛 投放广告、内容合作请Q我! E_mail:admin@mintao.net(欢迎提供学习资源)

    站长:MinTao ICP备案号:鄂ICP备11006601号-18

    闵涛站盟:医药大全-武穴网A打造BCD……
    咸宁网络警察报警平台