CreateProcessA²ÎÊýÐÍShellcodeµÄ±àÂëÎÊÌâÑо¿

Ðû²¼Ê±¼ä 2021-12-22
¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬ÔÚ¶ÔWebAccess/SCADAϵͳµÄÎó²îÑо¿ÖУ¬£¬£¬£¬£¬£¬£¬¿­·¢k8ADLabµÄ¹¤¿ØÇå¾²Ñо¿Ô±·¢Ã÷ÁËÒ»¸öδ±»ÆÕ±é̸ÂÛµÄÎó²îʹÓÃÊÖÒÕÎÊÌ⣬£¬£¬£¬£¬£¬£¬¼´¾­ÓÉCreateProcessA²ÎÊý¾ÙÐÐת´ïµÄshellcodeµÄ±àÂëÎÊÌâ¡£¡£¡£¡£¡£¡£


¼òÆÓÀ´½²£¬£¬£¬£¬£¬£¬£¬¸Ã¿ØÖÆÏµÍ³µÄÎó²îÓÉÁ½¸ö³ÌÐò×é³É£º½¹µã³ÌÐòCoreProcessºÍ¸¨Öú³ÌÐòHelpProcess£¬£¬£¬£¬£¬£¬£¬½¹µã³ÌÐòCoreProcessͨ¹ýϵͳº¯ÊýCreateProcessAÀ´Æô¶¯HelpProcess£¨Í¬Ê±×ª´ïÁËÏà¹Ø²ÎÊý£©¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬CoreProcessµÄ¼ò»¯´úÂëÈçÏ£º


´úÂë.png


ÏÔÈ»£¬£¬£¬£¬£¬£¬£¬HelpProcessµÄWinMainº¯Êý±£´æÒ»¸ö¾­µäµÄÕ»Òç³öÎó²î¡£¡£¡£¡£¡£¡£µ±lpCmdLineµÄÊý¾Ý³¤¶ÈÁè¼Ý400×Ö½Úʱ£¬£¬£¬£¬£¬£¬£¬¶ÔbuffµÄstrcpy²Ù×÷¾Í»á±¬·¢Òç³ö£»£»£»£»£»µ±³¤¶ÈÁè¼Ý404×Ö½Úʱ£¬£¬£¬£¬£¬£¬£¬¾Í»áÁýÕÖµ½eipCallerNext£¬£¬£¬£¬£¬£¬£¬´Ó¶øÐ®ÖÆHelpProcessµÄ³ÌÐò¿ØÖÆÁ÷¡£¡£¡£¡£¡£¡£


»ØËÝ´úÂë¿ÉÖª£¬£¬£¬£¬£¬£¬£¬lpCmdLineµÄÊý¾ÝȪԴÊÇCoreProcessµÄCreateProcessAŲÓ㬣¬£¬£¬£¬£¬£¬ÇÒÊÇÓû§¿É¿ØµÄ¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬¸ÃÎó²îµÄʹÓÿ´ÆðÀ´ÊǼòÆÓµÄ£¬£¬£¬£¬£¬£¬£¬Ö»ÐèÒªÅÌËãºÃeipCallerNextµÄÆ«ÒÆÁ¿²¢Ê¹ÓÃshellcodeÌî³äbuff¼´¿É¡£¡£¡£¡£¡£¡£¸ÃÎó²îµÄʹÓÃÁ´ºÍ¿ÍÕ»½á¹¹ÈçÏÂËùʾ£º


»ØËÝ´úÂë.png

 

ÔÚʹÓÃÀú³ÌÖУ¬£¬£¬£¬£¬£¬£¬½ÓÄɲâÊÔÌî³ä×Ö·û¾ÙÐÐÒç³öʱ£¬£¬£¬£¬£¬£¬£¬eipCallerNextµÄÁýÕÖ×ÜÊÇ׼ȷµÄ£»£»£»£»£»µ«½ÓÄÉmetasploitµÄshellcodeÀ´Òç³öʱ£¬£¬£¬£¬£¬£¬£¬eipCallerNextµÄÁýÕ־ͱäµÃ²»×¼È·¡£¡£¡£¡£¡£¡£¶ÔÊý¾Ý¾ÙÐнÏÁ¿ºó·¢Ã÷£¬£¬£¬£¬£¬£¬£¬shellcodeÔÚCoreProcessºÍHelpProcessÊÇ·×ÆçÑùµÄ£¬£¬£¬£¬£¬£¬£¬¼´shellcodeת´ïµ½HelpProcessºó±¬·¢Á˸ıä¡£¡£¡£¡£¡£¡£±ðµÄ£¬£¬£¬£¬£¬£¬£¬Í¨¹ýʵÑémetasploitµÄ²î±ðshellcode£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÕâÖָıäûÓÐÏÔ×ŵļÍÂÉ¿ÉÑ­¡£¡£¡£¡£¡£¡£


Õë¶ÔÕâ¸öÎÊÌ⣬£¬£¬£¬£¬£¬£¬ADLabµÄÇå¾²Ñо¿Ô±¾ÙÐÐÁËÉîÈëµÄÆÊÎö£¬£¬£¬£¬£¬£¬£¬ÅªÇåÁËCreateProcessA²ÎÊýת´ïµÄshellcodeµÄ±àÂëÎÊÌ⣬£¬£¬£¬£¬£¬£¬²¢¿ª·¢ÁË×Ô¶¯»¯´¦Öóͷ£ÒªÁ죬£¬£¬£¬£¬£¬£¬´Ó¶ø¼æÈÝí§Òâshellcode¡£¡£¡£¡£¡£¡£


CreateProcessAµÄ²ÎÊý´¦Öóͷ£


Windows²Ù×÷ϵͳµÄÄÚºËÊÇÖ§³ÖÈ«ÇòÖÖÖÖÓïÑԵ쬣¬£¬£¬£¬£¬£¬ÆäÌṩͳһµÄUnicode±àÂëÐÍÄÚºË̬API£»£»£»£»£»Õë¶ÔÏêϸµÄ¹ú¼Ò»òµØÇø£¬£¬£¬£¬£¬£¬£¬Windowsͨ¹ýÇøÓò±àÂëÀ´ÊµÏÖÍâµØÓïÑÔÖ§³Ö£¬£¬£¬£¬£¬£¬£¬¼´Ansi×Ö·û´®Ð͵ÄÓû§Ì¬API¡£¡£¡£¡£¡£¡£ÕâЩÓû§Ì¬APIÔÚÄÚ²¿ÏȰÑAnsi×Ö·û´®×ª»»ÎªUnicode×Ö·û´®£¬£¬£¬£¬£¬£¬£¬È»ºóÔÙŲÓÃÄÚºË̬API£»£»£»£»£»Õâ¸öת»»Àú³ÌÊÇ͸Ã÷µÄ£¬£¬£¬£¬£¬£¬£¬Óû§±àдµÄ³ÌÐò¶Ô´ËÎÞ¸ÐÖª¡£¡£¡£¡£¡£¡£


ÔÚWindow²Ù×÷ϵͳÉÏ£¬£¬£¬£¬£¬£¬£¬1¸öUnicode×Ö·ûÓÉ2¸ö×Ö½Ú×é³É£¬£¬£¬£¬£¬£¬£¬1¸öAnsi×Ö·ûÓÉ1¸ö×Ö½Ú»ò2¸ö×Ö½Ú×é³É¡£¡£¡£¡£¡£¡£µ±Ê××Ö½ÚµÄÖµÊÇ0µ½127ʱ£¬£¬£¬£¬£¬£¬£¬ËüÊÇ1¸öASCII×Ö·û£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦Unicode×Ö·ûµÄ2×Ö½ÚµÄÄÚÈݾÍÊǸÃASCII×Ö·û¼Ó1¸öÌî³ä×Ö·û0£»£»£»£»£»ÀýÈ磬£¬£¬£¬£¬£¬£¬Ansi×Ö·û¡±A¡±£¬£¬£¬£¬£¬£¬£¬Æä¶ÔÓ¦µÄUnicode×Ö·ûÊÇ¡±A\x00¡±¡£¡£¡£¡£¡£¡£µ±Ê××Ö½ÚµÄÖµ´óÓÚ127ʱ£¬£¬£¬£¬£¬£¬£¬ÔòÄ¿½ñ×Ö½ÚºÍϸö×Ö½Ú×éºÏÆðÀ´ÊÇÒ»¸öÇøÓòÓïÑÔµÄ×Ö·û£¬£¬£¬£¬£¬£¬£¬ÇøÓòÓïÑÔ×Ö·û±£´æ¶ÔÓ¦µÄUnicode×Ö·ûÓ³Éä±í£»£»£»£»£»ÀýÈ磬£¬£¬£¬£¬£¬£¬¡±\xce\xd2¡±µÄ¡°\xce¡±²»ÊÇ1¸öÕýµ±µÄASCII×Ö·û£¬£¬£¬£¬£¬£¬£¬ËüÖ»Äܺ͡°\xd2¡±ÁªÏàÖúΪ1ÆäÖÐÎÄ×Ö·û¡°ÎÒ¡±£¬£¬£¬£¬£¬£¬£¬¶ÔÓ¦µÄUnicode×Ö·ûÊÇ¡±\x11\x62¡±¡£¡£¡£¡£¡£¡£


ÈçÏÂËùʾ£¬£¬£¬£¬£¬£¬£¬CreateProcessA¾ÍÊÇÒ»¸öAnsi±àÂëÐ͵ÄÓû§Ì¬API£¬£¬£¬£¬£¬£¬£¬×Ö·û´®¡±AAAA¡±»á±»×Ô¶¯×ª»»ÎªUnicode×Ö·û´®²¢×ª´ï¸øHelpProcess£¬£¬£¬£¬£¬£¬£¬È»ºóÔÚŲÓÃWinMain֮ǰÓÖ±»×Ô¶¯»¹Ô­ÎªAnsi×Ö·û´®¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬¹ØÓÚAnsi×Ö·û´®¡±AAAA¡±£¬£¬£¬£¬£¬£¬£¬CoreProcessºÍHelpProcessÔÚ³ÌÐò¿ª·¢É϶¼ÎÞÐè×öÈκÎÌØÁíÍâ´¦Öóͷ£¡£¡£¡£¡£¡£¡£


´úÂë.png


ͨ³£ÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬CreateProcessA²ÎÊýlpCmdlineµÄȪԴÊǿɿ¿µÄ£¬£¬£¬£¬£¬£¬£¬ºÃ±È±àÒëʱԤ½ç˵µÄ×Ö·û´®ºÍAPIµÄ·µ»ØÖµ£¬£¬£¬£¬£¬£¬£¬´ËʱlpCmdline¶¼ÊÇ׼ȷµÄAnsi×Ö·û´®¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬CreateProcessÏÕЩ×ÜÄÜÔÚUnicodeºÍAnsiÖ®¼ä×ÔÓɵØ×¼È·×ª»»¡£¡£¡£¡£¡£¡£


ÏÖʵÉÏ£¬£¬£¬£¬£¬£¬£¬¹ØÓÚÈκÎÒ»ÃÅÇøÓòÓïÑÔ£¬£¬£¬£¬£¬£¬£¬ÆäAnsi×Ö·ûºÍUnicode×Ö·ûµÄÓ³Éä¶¼²»ÊÇÖðÒ»Ó³Éä¹ØÏµ£»£»£»£»£»¼´ÔÚ2×Ö½ÚµÄËùÓÐȡֵ¿Õ¼äÖУ¬£¬£¬£¬£¬£¬£¬Ansi×Ö·û±íµÄÓÐÓÃÏîÊý×ÜÊÇСÓÚUnicode×Ö·û±íµÄÓÐÓÃÏîÊý¡£¡£¡£¡£¡£¡£ÕâÒâζ×Å£¬£¬£¬£¬£¬£¬£¬Õë¶ÔÎÞ·¨È·ÈÏÊÇÇøÓòÓïÑÔµÄ2¸ö×Ö½Ú£¬£¬£¬£¬£¬£¬£¬ÈôÊÇÇ¿ÖÆÊÓ×÷Ansi×Ö·ûÔòת»»³ÉUnicode×Ö·ûºó·×Æç¶¨ÄÜ»¹Ô­Îª³õʼµÄAnsi×Ö·û¡£¡£¡£¡£¡£¡£ÀýÈ磺¡±\xeb\x2a¡±ÊÇÒ»ÌõͨÀýµÄjmp offsetÖ¸Á£¬£¬£¬£¬£¬£¬Ëü²»ÊÇ1¸öÕýµ±µÄÖÐÎÄ×Ö·û£»£»£»£»£»ÈôÊÇÊÓ×÷Ansi×Ö·ûÇ¿ÖÆ×ª»»ÎªUnicode×Ö·ûÔòÊÇ¡±\x3f\x00¡±£¬£¬£¬£¬£¬£¬£¬ÔÙ´Îת»»ÎªAnsi×Ö·û¼´ÊÇ¡±?¡±£¬£¬£¬£¬£¬£¬£¬É¥Ê§ÁËjmp offsetÖ¸ÁîµÄÓïÒå¡£¡£¡£¡£¡£¡£


Òò´Ë£¬£¬£¬£¬£¬£¬£¬Í¨¹ýCreateProcessAµÄcmdline²ÎÊý¾ÙÐÐshellcodeת´ï£¬£¬£¬£¬£¬£¬£¬±ØÐèҪ˼Á¿ÇøÓòÓïÑÔµÄAnsi×Ö·ûºÍUnicode×Ö·ûÏ໥ת»»µÄÎÊÌâ¡£¡£¡£¡£¡£¡£


ÔÚ±¾ÎĵÄÎó²îʹÓð¸ÀýÖУ¬£¬£¬£¬£¬£¬£¬ÍâµØÇøÓòµÄÓïÑÔÊÇÖÐÎļòÌ壬£¬£¬£¬£¬£¬£¬¶ÔÓ¦Ansi±àÂë±íÊÇGBK¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬±ØÐèÒª¶ÔmetasploitµÄshellcode¾ÙÐÐGBK±àÂ룬£¬£¬£¬£¬£¬£¬È·±£ÆäÊÇ׼ȷµÄAnsi×Ö·û´®¡£¡£¡£¡£¡£¡£


GBK±íµÄ±àÂëÔÚ2×Ö½Úȡֵ¿Õ¼äµÄ¹æÄ£ÊÇ8140£­FEFE£¬£¬£¬£¬£¬£¬£¬¼´µÚ1×Ö½ÚµÄȡֵ¹æÄ£ÊÇ0x81µ½0xFE£¬£¬£¬£¬£¬£¬£¬µÚ2×Ö½ÚµÄȡֵÊÇ0x40µ½0xFE£¬£¬£¬£¬£¬£¬£¬ÈçÏÂËùʾ£º


 ×Ö½Ú.png


±ðµÄ£¬£¬£¬£¬£¬£¬£¬µÚ2×Ö½ÚµÄÏÖʵÓÐÓÃȡֵÉÐÓиü¶àÔ¼Êø¡£¡£¡£¡£¡£¡£ºÃ±È£¬£¬£¬£¬£¬£¬£¬µÚ2×Ö½Ú²»¿ÉΪ0X7F¡£¡£¡£¡£¡£¡£Õë¶ÔijЩȡֵµÄ×Ö½Ú£¬£¬£¬£¬£¬£¬£¬µÚ2×Ö½ÚµÄȡֵ±È[0x40, 0xFE]µÄ¿Õ¼ä¸üС¡£¡£¡£¡£¡£¡£ÈçÏÂͼËùʾ£¬£¬£¬£¬£¬£¬£¬ÓеÄÖ»ÄÜÈ¡¸Ã¿Õ¼äµÄºó°ë²¿·Ö£¬£¬£¬£¬£¬£¬£¬ÓеÄÔòÖ»ÄÜȡǰ°ë²¿·Ö¡£¡£¡£¡£¡£¡£


¹ØÓÚshellcodeÀ´½²£¬£¬£¬£¬£¬£¬£¬Æäÿ¸ö×Ö½ÚµÄȡֵÔÚ0µ½255Ö®¼ä¶¼ÊÇÍêÈ«Õýµ±µÄ¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬±¾ÎĵÄÎó²îʹÓÃҪʵÏÖshellcodeµÄËæÒâÌæ»»£¬£¬£¬£¬£¬£¬£¬±ØÐèÒªÓÐÒ»ÖÖÒªÁìÀ´¶ÔshellcodeÖÐÎ¥·´GBK±àÂëµÄ×Ö½Ú¾ÙÐд¦Öóͷ££¬£¬£¬£¬£¬£¬£¬´Ó¶ø×èÖ¹Ansi×Ö·ûºÍUnicode×Ö·û¼äת»»µ¼ÖµÄshellcode×Ö·û±»¸Ä±äµÄÎÊÌâ¡£¡£¡£¡£¡£¡£Ò»¸ö»ù±¾µÄÒªÁìÊÇÆ¾Ö¤ÈçϵÄÁ÷³Ì¶Ôshellcode¾ÙÐд¦Öóͷ££¬£¬£¬£¬£¬£¬£¬ÆäÒªº¦ÊǶÔGBK±í¾ÙÐвé±í²¢ÐÞÕý»ã±àÖ¸Áî¡£¡£¡£¡£¡£¡£


 ×Ö½Úµ÷½â.png


ÒÔÈçϵÄshellcodeΪÀý£¬£¬£¬£¬£¬£¬£¬ÔÚɨÃèµ½×Ö½Ú0xEBʱ£¬£¬£¬£¬£¬£¬£¬·¢Ã÷ÊÇ·ÇASCII×Ö·ûÇÒ²é±íGBKЧ¹ûÊDz»±£´æ£¬£¬£¬£¬£¬£¬£¬ÐèÒª¾ÙÐÐת»»£»£»£»£»£»ÅÌÎÊGBK±íºó·¢Ã÷£¬£¬£¬£¬£¬£¬£¬ÔÚ0xEB֮ǰ²åÈë0x90¿ÉÒÔʹµÃ90 EBÊÇÒ»¸öÕýµ±µÄGBK×Ö·û£¬£¬£¬£¬£¬£¬£¬Í¬Ê±90EB 38ÓÖ²»¸Ä±äÔ­À´µÄ»ã±àÓïÒ壬£¬£¬£¬£¬£¬£¬×ª»»Àֳɡ£¡£¡£¡£¡£¡£Í¬Àí£¬£¬£¬£¬£¬£¬£¬¼ÌÐøÉ¨Ãèµ½ÏÂÒ»¸ö×Ö½Ú0XEBʱ£¬£¬£¬£¬£¬£¬£¬ÔÙ×öͬÑùµÄת»»¾Í¿ÉÒÔ¡£¡£¡£¡£¡£¡£¿ÉÊÇ£¬£¬£¬£¬£¬£¬£¬µÚ2´ÎµÄת»»²åÈëÁËеÄ×Ö½Ú0x90£¬£¬£¬£¬£¬£¬£¬µ¼ÖÂÁËԭʼlab1¶ÔÓ¦µÄÆ«ÒÆÁ¿±¬·¢Á˸ı䣻£»£»£»£»Ô­Ê¼labµÄÖ¸ÁîÏÖʵλÓÚתºóµÄlab+1λÖ㬣¬£¬£¬£¬£¬£¬Ê¹µÃµÚÒ»¸ö0XEBµÄÓïÒå²»·¨ÁË¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬×ª»»Àú³Ì»¹ÒªÇó¸ú×ÙÖ¸ÁîÇø¿éµÄ³¤¶Èת±ä¡£¡£¡£¡£¡£¡£


ת»»»ã±à.png


³ýÁËÖ¸ÁîÇø¿éµÄ³¤¶È¸Ä±äÍ⣬£¬£¬£¬£¬£¬£¬ÉÐÓÐÆäËü¼æÈÝÐÔÎÊÌâ¡£¡£¡£¡£¡£¡£ºÃ±È£¬£¬£¬£¬£¬£¬£¬shellcodeÖÐÌØÊâȡֵ£¨µä·¶ÓÐ0£©µÄ×Ö½Ú´¦Öóͷ£ÎÊÌ⣬£¬£¬£¬£¬£¬£¬¶ÔshellcodeµÄÄÚǶ²ÎÊýÐÞ¸ÄÎÊÌâµÈ¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬Ö»¹Ü²é±íת»»ÊÇ×î»ù´¡µÄ²½·¥£¬£¬£¬£¬£¬£¬£¬µ«È«±íÅÌÎʵĿռä´ó£¬£¬£¬£¬£¬£¬£¬ÏÞÖÆÁËshellcodeµÄÎÞаÐÔ¡£¡£¡£¡£¡£¡£ÎªÏàʶ¾ö¸ÃÎÊÌ⣬£¬£¬£¬£¬£¬£¬ADLabµÄÇå¾²Ñо¿Ô±Ìá³öÁËÒ»ÖÖ»ùÓÚÅÌËãµÄshellcode±àÂëÒªÁì¡£¡£¡£¡£¡£¡£


ShellcodeÅÌËãת»»


Ê×ÏÈ£¬£¬£¬£¬£¬£¬£¬ÎÒÃǰÑshellcode·ÖΪÁ½²¿·Ö£ºÍ·²¿µÄÀο¿decoderºÍβ²¿µÄ¶à±äpayload¡£¡£¡£¡£¡£¡£È»ºó£¬£¬£¬£¬£¬£¬£¬½ÓÄɲé±í·½·¨¾ÙÐÐÊÖ¹¤±àдÇкÏGBK±àÂëµÄ»ã±à´úÂë¡£¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬£¬£¬£¬decoderµÄ³¤¶ÈºÜÓÐÏÞ£¬£¬£¬£¬£¬£¬£¬¾öÒéÁËÕâ¸ö±àдµÄ¼ÛÇ®²»´ó£»£»£»£»£»Í¬Ê±£¬£¬£¬£¬£¬£¬£¬¶à±äpayloadÊÇûÓÐÌØÊâÏÞÖÆµÄ£¬£¬£¬£¬£¬£¬£¬Í¨¹ý±àд¶ÔÓ¦µÄencoderÀ´±àÂëpayloadʹÆä²»Î¥·´GBK±àÂ룬£¬£¬£¬£¬£¬£¬ÓÖ¿ÉÒÔ±»decoder»¹Ô­¡£¡£¡£¡£¡£¡£Í¨¹ýÕâÖÖ·½·¨£¬£¬£¬£¬£¬£¬£¬¶ÔԭʼshellcodeµÄÑ¡ÔñºÍ¸Ä±ä¾ÍÍêÈ«²»±ØÌåÌùGBK±àÂëÎÊÌ⣬£¬£¬£¬£¬£¬£¬Ê¹µÃ¸ÃÎó²îµÄʹÓÃÔ½·¢¸»ºñ¡£¡£¡£¡£¡£¡£


ΪÁËïÔÌ­decoderµÄÌå»ý£¬£¬£¬£¬£¬£¬£¬ÎÒÃÇÉè¼ÆÁËÒ»ÖÖÅÌËãÒªÁìÀ´±àÂëÏ¢ÕùÂ룬£¬£¬£¬£¬£¬£¬ÕâÑù¾Í²»ÐèÒª´æ´¢GBK×Ö·û±í»òÕßÖØ´óµÄ¹æÔò¡£¡£¡£¡£¡£¡£Ô­Ê¼shellcode±àÂëʱµÄÅÌËã¹æÔòÈçÏ£º


Óöµ½×Ö½ÚÊÇASCII¡¢0x80ºÍ0xff£¬£¬£¬£¬£¬£¬£¬Ö±½Ó±£´æ¡£¡£¡£¡£¡£¡£


Óöµ½×Ö½ÚÊÇ\x00£¬£¬£¬£¬£¬£¬£¬×ª»»³É¼Ó·¨ÔËËã·û\x90ºÍ2¸öÅÌËãÊý·û\x80ºÍ\x80¡£¡£¡£¡£¡£¡£


Óöµ½×Ö½ÚÊÇ\x90£¬£¬£¬£¬£¬£¬£¬×ª»»³É¼Ó·¨ÔËËã·û\x90ºÍ2¸öÅÌËãÊý·û\x48ºÍ\x48¡£¡£¡£¡£¡£¡£


Óöµ½2¸ö×Ö½Ú¿ÉÒÔת»»Îªunicode×Ö·û£¬£¬£¬£¬£¬£¬£¬Ö±½Ó±£´æÕâ2¸ö×Ö½Ú¡£¡£¡£¡£¡£¡£


Óöµ½Ç°Ãæ¶¼²»¿É´¦Öóͷ£µÄ×Ö½Ú£¬£¬£¬£¬£¬£¬£¬Ö±½Óת»»³É¼Ó·¨ÔËËã·û\x90ºÍ2¸öÅÌËãÊý·û£¬£¬£¬£¬£¬£¬£¬µÚ1¸öÊÇ\x80£¬£¬£¬£¬£¬£¬£¬µÚ2¸öÊDzîÖµ¡£¡£¡£¡£¡£¡£


½ÓÄÉÉÏÊöµÄ±àÂëÒªÁìºó£¬£¬£¬£¬£¬£¬£¬ÈκÎshellcode¶¼¿ÉÒÔ±»×ª»»ÎªÕýµ±GBK×Ö·û´®£¬£¬£¬£¬£¬£¬£¬²¢ÇÒdecoder¶ÔpayloadµÄ½âÂëÅÌËãҲʮ·Ö¼òÆÓ£¬£¬£¬£¬£¬£¬£¬Ö»ÐèÒªÈçϵÄ1Ìõ¹æÔò£º


Óöµ½×Ö·ûÊÇ\x90£¬£¬£¬£¬£¬£¬£¬Ö±½Ó¶Ôºó2¸ö×Ö·û¾ÙÐмӷ¨ÅÌË㣬£¬£¬£¬£¬£¬£¬²¢ÓÃЧ¹ûÌæ»»×Ö·û\x90¡£¡£¡£¡£¡£¡£ 


ÖÁ´Ë£¬£¬£¬£¬£¬£¬£¬CreateProcessA²ÎÊýת´ïµÄshellcodeµÄ±àÂëÎÊÌâ¾ÍËùÓб»Ô¼ÊøÔÚÁËÖ»ÓÐÒ»Ìõ¹æÔòµÄdecoder´úÂëÖУ¬£¬£¬£¬£¬£¬£¬ºÜÏÔÈ»ÕâÊÇÒ»¸ö½çÏßÊ®Ã÷È·È·µÄ¾Ö²¿ÎÊÌ⣬£¬£¬£¬£¬£¬£¬Òò´ËºÜÈÝÒ׾ͽâ¾öÁË¡£¡£¡£¡£¡£¡£½ÓÄÉÕâÖÖÒªÁ죬£¬£¬£¬£¬£¬£¬±¾ÎĵÄÎó²îʹÓÿÉÒÔËæÒâŲÓÃmetasploitÖеÄshellcode£¬£¬£¬£¬£¬£¬£¬ÎÞÐèÔÙµ£ÐÄËüÃǵÄÖ¸ÁîÄÚ²¿Ï¸½Ú¡£¡£¡£¡£¡£¡£


ÔÚ¶àÓïÑÔÇéÐÎÏ£¬£¬£¬£¬£¬£¬£¬shellcodeÈôÊDz»ÊÇÖ±½ÓµÄÄÚ´æ×ª´ï£¬£¬£¬£¬£¬£¬£¬Ôò¿ÉÄܻᱻϵͳAPIº¯ÊýËùת»»£¬£¬£¬£¬£¬£¬£¬´Ó¶øµ¼ÖÂÆäÒòÔÚ»ñµÃÖ´ÐÐȨ֮ǰ±¬·¢ÄÚÈÝ¸Ä±ä¶øÎÞЧ¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬£¬ÔÚÎó²îʹÓÃÀú³ÌÖУ¬£¬£¬£¬£¬£¬£¬ÐèÒª×¢ÖØshellcodeÊÇ·ñÊܵ½¶àÓïÑÔ°æ±¾µÄAPIÓ°Ïì¡£¡£¡£¡£¡£¡£