ÔÚWindows²Ù×÷ϵͳÄÚÒ»¸öÒþ²Ø³¬¼¶Óû§

ʱ¼ä:2008-06-26 23:13:52  À´Ô´:  ×÷Õß:

 

¶Ôregedit.exeÎÒÏë´ó¼Ò¶¼ºÜÊìϤ£¬µ«È´²»ÄܶÔ×¢²á±íµÄÏî¼üÉèÖÃȨÏÞ£¬¶øregedt32.exe×î´óµÄÓŵã¾ÍÊÇÄܹ»¶Ô×¢²á±íµÄÏî¼üÉèÖÃȨÏÞ¡£

nt/2000/xpµÄÕÊ»§ÐÅÏ¢¶¼ÔÚ×¢²á±íµÄHKEY_LOCAL_MACHINE\SAM\SAM¼üÏ£¬µ«ÊdzýÁËϵͳÓû§SYSTEMÍ⣬ÆäËüÓû§¶¼ÎÞȨ²é¿´µ½ÀïÃæµÄÐÅÏ¢£¬Òò´ËÎÒÊ×ÏÈÓÃregedt32.exe¶ÔSAM¼üΪÎÒÉèÖÃΪ“ÍêÈ«¿ØÖƔȨÏÞ¡£ÕâÑù¾Í¿ÉÒÔ¶ÔSAM¼üÄÚµÄÐÅÏ¢½øÐжÁдÁËÁË¡£¾ßÌå²½¾ÛÈçÏ£º

 

1¡¢¼ÙÉèÎÒÃÇÊÇÒÔ³¬¼¶Óû§administratorµÇ¼µ½¿ªÓÐÖÕ¶Ë·þÎñµÄÈ⼦Éϵģ¬Ê×ÏÈÔÚÃüÁîÐÐÏ»òÕÊ»§¹ÜÀíÆ÷Öн¨Á¢Ò»¸öÕÊ»§£ºhacker$£¬ÕâÀïÎÒÔÚÃüÁîÐÐϽ¨Á¢Õâ¸öÕÊ»§ net user hacker$ 1234 /add

2¡¢ÔÚ¿ªÊ¼/ÔËÐÐÖÐÊäÈ룺regedt32.exe²¢»Ø³µÀ´ÔËÐÐregedt32.exe¡£

3¡¢µã“ȨÏÞ”ÒÔºó»áµ¯³ö´°¿ÚµãÌí¼Ó½«ÎҵǼʱµÄÕÊ»§Ìí¼Óµ½°²È«À¸ÄÚ£¬ÕâÀïÎÒÊÇÒÔadministratorµÄÉí·ÝµÇ¼µÄ£¬ËùÒÔÎҾͽ«administrator¼ÓÈ룬²¢ÉèÖÃȨÏÞΪ“ÍêÈ«¿ØÖÆ"¡£ÕâÀïÐèҪ˵Ã÷һϣº×îºÃÊÇÌí¼ÓÄãµÇ¼µÄÕÊ»§»òÕÊ»§ËùÔÚµÄ×飬ÇÐĪÐÞ¸ÄÔ­ÓеÄÕÊ»§»ò×飬·ñÔò½«»á´øÀ´Ò»ÏµÁв»±ØÒªµÄÎÊÌâ¡£µÈÒþ²Ø³¬¼¶Óû§½¨ºÃÒÔ£¬ÔÙÀ´ÕâÀォÄãÌí¼ÓµÄÕÊ»§É¾³ý¼´¿É¡£

4¡¢Ôٵ㓿ªÊ¼”→“ÔËÐД²¢ÊäÈë"regedit.exe" »Ø³µ£¬Æô¶¯×¢²á±í±à¼­Æ÷regedit.exe¡£ ´ò¿ª¼ü£ºHKEY_LOCAL_MAICHINE\SAM\SAM\Domains\account\user\names\hacker$"

5¡¢½«Ïîhacker$¡¢00000409¡¢000001F4µ¼³öΪhacker.reg¡¢409.reg¡¢1f4.reg£¬ÓüÇʱ¾·Ö±ð´òÕ⼸¸öµ¼³öµÄÎļþ½øÐб༭£¬½«³¬¼¶Óû§¶ÔÓ¦µÄÏî000001F4ϵļü"F"µÄÖµ¸´ÖÆ£¬²¢¸²¸Çhacker$¶ÔÓ¦µÄÏî00000409ϵļü"F"µÄÖµ£¬È»ºóÔÙ½«00000409.regÓëhacker.regºÏ²¢¡£

6¡¢ÔÚÃüÁîÐÐÏÂÖ´ÐÐnet user hacker$ /del½«Óû§hacker$ɾ³ý£ºnet user hacker$ /del

7¡¢ÔÚregedit.exeµÄ´°¿ÚÄÚ°´F5ˢУ¬È»ºó´òÎļþ-µ¼Èë×¢²á±íÎļþ½«Ð޸ĺõÄhacker.regµ¼Èë×¢²á±í¼´¿É

8¡¢µ½´Ë£¬Òþ²ØµÄ³¬¼¶Óû§hacker$ÒѾ­½¨ºÃÁË£¬È»ºó¹Ø±Õregedit.exe¡£ÔÚregedt32.exe´°¿ÚÄÚ°ÑHKEY_LOCAL_MACHINE\SAM\SAM¼üȨÏ޸ĻØÔ­À´µÄÑù×Ó£¨Ö»ÒªÉ¾³ýÌí¼ÓµÄÕÊ»§administrator¼´¿É£©¡£

9¡¢×¢Ò⣺Òþ²ØµÄ³¬¼¶Óû§½¨ºÃºó£¬ÔÚÕÊ»§¹ÜÀíÆ÷¿´²»µ½hacker$Õâ¸öÓû§£¬ÔÚÃüÁîÐÐÓÓnet user”ÃüÁîÒ²¿´²»µ½£¬µ«Êdz¬¼¶Óû§½¨Á¢ÒԺ󣬾Ͳ»ÄÜÔÙ¸ÄÃÜÂëÁË£¬Èç¹ûÓÃnet userÃüÁîÀ´¸Ähacker$µÄÃÜÂëµÄ»°£¬ÄÇôÔÚÕÊ»§¹ÜÀíÆ÷Öн«ÓֻῴÕâ¸öÒþ²ØµÄ³¬¼¶Óû§ÁË£¬¶øÇÒ²»ÄÜɾ³ý¡£


Tags£º


ÎÄÕÂÆÀÂÛ

¹²ÓÐ 0ÈË·¢±íÁËÆÀÂÛ ²é¿´ÍêÕûÄÚÈÝ

ÍÆ¼ö½Ì³Ì

×îн̳Ì