ׯÏÐÓÎÏ·

֤ȯ¼ò³Æ£º×¯ÏÐÓÎÏ· ֤ȯ´úÂ룺002212
È«Ììºò7x24СʱЧÀÍ£º 400-777-0777
Çå¾²ÔÆÐ§ÀÍ

ÍþвÆÊÎöÓëÏìÓ¦-AntSword¼ÓÃܶñÒâÁ÷Á¿¼ì²â

Óдó×ڵĶñÒâ¾ç±¾¡¢ÀÕË÷²¡¶¾¡¢ÊðÀí¡¢ÍÚ¿ó¡¢Ô¶¿Ø¹¤¾ßµÈ½ÓÄɼÓÃÜÊÖ¶ÎÀ´ÌÓ±ÜÇå¾²·À»¤ºÍ¼ì²â¡£¡£¡£Í¨³£µÄÇå¾²²úÆ·¶ÔÎÞ·¨Ê¶±ð¡¢ÎÞ·¨¼ì²âµÄÁ÷Á¿»á·ÅÐС£¡£¡£ÆäÖÐWebShellÊǹ¥»÷ÍøÕ¾µÄÒ»ÖÖ¶ñÒâ¾ç±¾ £¬ £¬£¬£¬£¬Ê¶±ð³öWebShellÎļþ»òͨѶÁ÷Á¿¿ÉÒÔÓÐÓõØ×èÖ¹ºÚ¿Í½øÒ»²½µÄ¹¥»÷ÐÐΪ¡£¡£¡£

ÍþвÆÊÎöÓëÏìÓ¦-AntSword¼ÓÃܶñÒâÁ÷Á¿¼ì²â

Ðû²¼Ê±¼ä£º2021-08-18
ä¯ÀÀ´ÎÊý£º2921
·ÖÏí£º

01¼ÓÃܶñÒâÁ÷Á¿¼ì²â

1.1 Åä¾°

Óдó×ڵĶñÒâ¾ç±¾¡¢ÀÕË÷²¡¶¾¡¢ÊðÀí¡¢ÍÚ¿ó¡¢Ô¶¿Ø¹¤¾ßµÈ½ÓÄɼÓÃÜÊÖ¶ÎÀ´ÌÓ±ÜÇå¾²·À»¤ºÍ¼ì²â¡£¡£¡£Í¨³£µÄÇå¾²²úÆ·¶ÔÎÞ·¨Ê¶±ð¡¢ÎÞ·¨¼ì²âµÄÁ÷Á¿»á·ÅÐС£¡£¡£ÆäÖÐWebShellÊǹ¥»÷ÍøÕ¾µÄÒ»ÖÖ¶ñÒâ¾ç±¾ £¬ £¬£¬£¬£¬Ê¶±ð³öWebShellÎļþ»òͨѶÁ÷Á¿¿ÉÒÔÓÐÓõØ×èÖ¹ºÚ¿Í½øÒ»²½µÄ¹¥»÷ÐÐΪ¡£¡£¡£ÏÖÔÚWebShellµÄ¼ì²âÒªÁìÖ÷Òª·ÖΪÈý´óÀࣺ¾²Ì¬¼ì²â¡¢¶¯Ì¬¼ì²âºÍÈÕÖ¾¼ì²â¡£¡£¡£

±¾ÎÄÖ÷Òª»ùÓÚÁ÷Á¿À´ÊµÏÖWebShellÅþÁ¬¹¤¾ßµÄ¼ì²â¡£¡£¡£ÏÖÔÚ»ùÓÚÁ÷Á¿µÄ¼ì²âÈÔÈ»ÃæÁÙһЩÎÊÌâ¡£¡£¡£ÏÖ´æµÄһЩWebShellÅþÁ¬¹¤¾ß £¬ £¬£¬£¬£¬ºÃ±È±ùЫ¡¢¸ç˹À­¡¢ÒϽ£µÈ £¬ £¬£¬£¬£¬¶¼Ê¹ÓÃÁË»ìÏý»ò¼ÓÃÜ»úÖÆ £¬ £¬£¬£¬£¬Í¨¹ý¼ÓÃÜͨѶÁ÷Á¿µÄ·½·¨À´Èƹý¹Å°åÇå¾²×°±¸ £¬ £¬£¬£¬£¬Ìӱܼì²â¡£¡£¡£

1.2 AntSword ±àÂëÒªÁì

1.2.1 AntSword-default±àÂë

ÏÈÀ´¿´Ò»ÏÂĬÈϱàÂëģʽÁ÷Á¿¡£¡£¡£

ĬÈÏ״̬ϵÄÁ÷Á¿ÕվɽÏÁ¿ÓÑºÃµÄ £¬ £¬£¬£¬£¬±£´æÐí¶àº¯Êý¿ÉÒÔ¾ÙÐÐÌØÕ÷¶¨Î» £¬ £¬£¬£¬£¬ÔÚ¾­ÓÉ´ó×ÚµÄÊý¾Ý°üÆÊÎöºó £¬ £¬£¬£¬£¬È·¶¨ÁËÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌ㻣»£»£»£»

ÌØÕ÷2£ºÔÚ2´¦¹ØÓÚº¯ÊýÏȺó˳Ðò¾ÙÐÐÆ¥Åä¡£¡£¡£

1.2.2 AntSword-base64±àÂë

Base64£ºÊÇÒ»ÖÖ»ùÓÚ64¸ö¿É´òÓ¡×Ö·ûÀ´ÌåÏÖ¶þ½øÖÆÊý¾ÝµÄÌåÏÖÒªÁì¡£¡£¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Base64±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷ʹÓÃÁËeval £¬ £¬£¬£¬£¬base64_decodeµÈÃô¸Ðº¯Êý £¬ £¬£¬£¬£¬ÔÚ¾­ÓÉ´ó×ÚµÄÊý¾Ý°üÆÊÎöºó £¬ £¬£¬£¬£¬¶¨Î»ÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌ㻣»£»£»£»

ÌØÕ÷2£ºÈ¡2´¦µÄÁ½¸ö14λ×Ö·û¾ÙÐбÈÕÕÅжÏÊÇ·ñÏàͬ¡£¡£¡£

1.2.3 AntSword-chr±àÂë

CHR£º ASCII Öµ·µ»Ø×Ö·û¡£¡£¡£ASCII Öµ¿É±»Ö¸¶¨ÎªÊ®½øÖÆÖµ¡¢°Ë½øÖÆÖµ»òÊ®Áù½øÖÆÖµ¡£¡£¡£°Ë½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0 £¬ £¬£¬£¬£¬Ê®Áù½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0x¡£¡£¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Chr±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷±£´æ¾Þϸд»ìÔÓµÄeVAlº¯Êý £¬ £¬£¬£¬£¬Í¬Ê±ÐèÒªÅäºÏÆ¥Åä±àÂëµÄÃûÌÃÓ볤¶ÈÁ¬Ïµ¾ÙÐмì²â¡£¡£¡£

ÌØÕ÷1£ºÊ¹ÓÃÕýÔòÆ¥Åä1´¦ £¬ £¬£¬£¬£¬eValº¯ÊýÀ¨ºÅÖÐcHr(*).ChR(*),¶ÔChR(*)ÊýÄ¿½ç˵ãÐÖµÅäºÏ¼ì²â¡£¡£¡£

1.2.4 AntSword-chr16±àÂë

CHR16£º ASCII Öµ·µ»Ø×Ö·û¡£¡£¡£ASCII Öµ¿É±»Ö¸¶¨ÎªÊ®½øÖÆÖµ¡¢°Ë½øÖÆÖµ»òÊ®Áù½øÖÆÖµ¡£¡£¡£°Ë½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0 £¬ £¬£¬£¬£¬Ê®Áù½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0x¡£¡£¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Chr16±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷Ò²±£´æ¾Þϸд»ìÔÓµÄeVAlº¯Êý £¬ £¬£¬£¬£¬ÓëChr±àÂëÀàËÆ £¬ £¬£¬£¬£¬Ò²ÐèÒªÅäºÏÆ¥Åä±àÂëµÄÃûÌÃÓ볤¶ÈÁ¬Ïµ¾ÙÐмì²â¡£¡£¡£

ÌØÕ÷1£ºÊ¹ÓÃÕýÔòÆ¥Åä1´¦ £¬ £¬£¬£¬£¬eValº¯ÊýÀ¨ºÅÖÐcHr(0x*).ChR(0x*),¶ÔChR(0x*)ÊýÄ¿½ç˵ãÐÖµÅäºÏ¼ì²â¡£¡£¡£

1.2.5 AntSword-rot13±àÂë

ROT13£º±àÂëÊǰÑÿһ¸ö×ÖĸÔÚ×Öĸ±íÖÐÏòÇ°ÒÆ¶¯ 13 ¸ö×Öĸ»ñµÃ¡£¡£¡£Êý×ֺͷÇ×Öĸ×Ö·û¼á³ÖÎȹÌ¡£¡£¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

ROT13±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷±£´æeval,str_rot13µÈÃô¸Ðº¯ÊýÃû³Æ £¬ £¬£¬£¬£¬ÔÚ¾­ÓÉ´ó×ÚÊý¾Ý°üÆÊÎöºó £¬ £¬£¬£¬£¬È·¶¨ÁËÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌ㻣»£»£»£»

ÌØÕ÷2£ºÈ¡2´¦µÄ14λ×Ö·û¾ÙÐбÈÕÕ £¬ £¬£¬£¬£¬ÅжÏÊÇ·ñÏàͬ¡£¡£¡£

02×ܽá

ÔÚʵս²âÊÔÖÐ £¬ £¬£¬£¬£¬Í¨¹ýÉÏÊö¼¸µã £¬ £¬£¬£¬£¬¶Ô¼ÓÃÜÐÍ webshell µÄÁ÷Á¿¾ÙÐÐÆÊÎö £¬ £¬£¬£¬£¬×ܽáÏà¹ØÈõÌØÕ÷ºÍÇ¿ÌØÕ÷ £¬ £¬£¬£¬£¬¶àÖÖÌØÕ÷Á¬Ïµ £¬ £¬£¬£¬£¬¿ÉÒÔ׼ȷʶ±ðÕâÀà webshell µÄͨѶÀú³Ì £¬ £¬£¬£¬£¬ÊµÊ±´¦Öóͷ£ºÍ·¢Ã÷ʧÏÝÖ÷»ú¡£¡£¡£µ«ÉÏÊö»ùÓÚ×Ö·û´®ÌØÕ÷¼ì²âµÄ¼Æ»® £¬ £¬£¬£¬£¬ÐèÒªÇå¾²ÔËÓªÖ°Ô±ÖðÒ»ÆÊÎöÑù±¾ £¬ £¬£¬£¬£¬»áÏûºÄ½Ï´óµÄÈËÁ¦ £¬ £¬£¬£¬£¬²¢ÇÒÄÑÒÔ¼ì²â±äÖֵĶñÒâÍâÁ¬Á÷Á¿¡£¡£¡£

Ëæ×Ź¥·ÀÊÖÒÕÖ®¼äµÄÒ»Ö±²©ÞÄ £¬ £¬£¬£¬£¬¶ñÒâÈí¼þÒ²Ô½À´Ô½ÒþÄä¡£¡£¡£ÏÖÔÚʹÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þ¼Ò×åÁè¼Ý200ÖÖ £¬ £¬£¬£¬£¬Ê¹ÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þÕ¼±ÈÁè¼Ý40% £¬ £¬£¬£¬£¬Ê¹ÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þÏÕЩÁýÕÖÁËËùÓг£¼ûÀàÐÍ¡£¡£¡£ºóÐøÎÒÃÇ¿ÉÄÜÓöµ½µÄ³¡¾°¸ü¶àÊÇHTTPS £¬ £¬£¬£¬£¬AES £¬ £¬£¬£¬£¬XORµÈ¼ÓÃÜÀàÐÍ¡£¡£¡£¹ØÓÚÕâÖÖ¼ÓÃÜÀàÐÍ £¬ £¬£¬£¬£¬¸üºÃµÄ½â¾ö¼Æ»®ÊÇʹÓûúеѧϰ»òÕßÉî¶Èѧϰ¶ÔÁ÷Á¿ÌØÕ÷¾ÙÐÐʶ±ð¡£¡£¡£

Ëæ×ÅÈ˹¤ÖÇÄÜÊÖÒÕµÄÉú³¤ £¬ £¬£¬£¬£¬Í¨¹ý´ó×ڵIJâÊÔÑéÖ¤ £¬ £¬£¬£¬£¬È˹¤ÖÇÄÜÓÃÓÚ¼ÓÃÜÁ÷Á¿Çå¾²¼ì²â½«ÊÇÒ»ÖÖÐÂÊÖÒÕÊֶΡ£¡£¡£×÷ΪÇå¾²ÔËÓªÖ°Ô± £¬ £¬£¬£¬£¬Î¨ÓÐһֱ̽Ë÷ºÍÑо¿ÐµÄÌØÕ÷ºÍÒªÁì £¬ £¬£¬£¬£¬²Å»ª¸üºÃµÄÓ¦¶ÔÍøÂçÁ÷Á¿ÖÐÈÕÒæÖØ´óµÄ¹¥»÷¡£¡£¡£

ÉùÃ÷£º

1£®±¾ÎĵµÓÉׯÏÐÓÎÏ·Çå¾²ÍŶÓÐû²¼ £¬ £¬£¬£¬£¬Î´¾­ÊÚȨեȡµÚÈý·½×ªÔؼ°×ªÍ¶¡£¡£¡£

2£®±¾ÎĵµËùÌáµ½µÄÊÖÒÕÄÚÈݼ°×ÊѶ½ö¹©²Î¿¼ £¬ £¬£¬£¬£¬ÓйØÄÚÈÝ¿ÉÄÜ»áËæÊ±¸üР£¬ £¬£¬£¬£¬×¯ÏÐÓÎÏ·²»ÁíÐÐ֪ͨ¡£¡£¡£

3£®±¾ÎĵµÖÐÌáµ½µÄÐÅϢΪÕý³£¹ûÕæµÄÐÅÏ¢ £¬ £¬£¬£¬£¬ÈôÒò±¾Îĵµ»òÆäËùÌáµ½µÄÈκÎÐÅÏ¢ÒýÆðÁËËûÈËÖ±½Ó»ò¼ä½ÓµÄ×ÊÁÏÁ÷ʧ¡¢ÀûÒæËðʧ £¬ £¬£¬£¬£¬×¯ÏÐÓÎÏ·¼°ÆäÔ±¹¤²»¼ç¸ºÈκÎÔðÈΡ£¡£¡£

Òªº¦´Ê±êÇ©£º
ׯÏÐÓÎÏ· ÍþвÆÊÎöÓëÏìÓ¦ ¶ñÒâÁ÷Á¿¼ì²â
¿Í»§Ð§ÀÍÈÈÏß

400-777-0777
7*24СʱЧÀÍ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿