BevictorΰµÂ

֤ȯ¼ò³Æ£ºBevictorΰµÂ ֤ȯ´úÂ룺002212
È«Ììºò7x24Сʱ·þÎñ£º 400-777-0777

ÍþвÆÊÎöÓëÏìÓ¦-AntSword¼ÓÃܶñÒâÁ÷Á¿¼ì²â

Óдó×ڵĶñÒâ¾ç±¾¡¢ÀÕË÷²¡¶¾¡¢´úÀí¡¢ÍÚ¿ó¡¢Ô¶¿Ø¹¤¾ßµÈ½ÓÄɼÓÃÜÊÖ¶ÎÀ´ÌÓ±ÜÇå¾²·À»¤ºÍ¼ì²â¡£Í¨³£µÄÇå¾²²úÆ·¶ÔÎÞ·¨Ê¶±ð¡¢ÎÞ·¨¼ì²âµÄÁ÷Á¿»á·ÅÐС£ÆäÖÐWebShellÊǹ¥»÷ÍøÕ¾µÄÒ»ÖÖ¶ñÒâ¾ç±¾ £¬Ê¶±ð³öWebShellÎļþ»òͨѶÁ÷Á¿¿ÉÒÔÓÐÓõØ×èÖ¹ºÚ¿Í½øÒ»²½µÄ¹¥»÷ÐÐΪ¡£

ÍþвÆÊÎöÓëÏìÓ¦-AntSword¼ÓÃܶñÒâÁ÷Á¿¼ì²â

Ðû²¼Ê±¼ä£º2021-08-18
ä¯ÀÀ´ÎÊý£º2972
·ÖÏí£º

01¼ÓÃܶñÒâÁ÷Á¿¼ì²â

1.1 Åä¾°

Óдó×ڵĶñÒâ¾ç±¾¡¢ÀÕË÷²¡¶¾¡¢´úÀí¡¢ÍÚ¿ó¡¢Ô¶¿Ø¹¤¾ßµÈ½ÓÄɼÓÃÜÊÖ¶ÎÀ´ÌÓ±ÜÇå¾²·À»¤ºÍ¼ì²â¡£Í¨³£µÄÇå¾²²úÆ·¶ÔÎÞ·¨Ê¶±ð¡¢ÎÞ·¨¼ì²âµÄÁ÷Á¿»á·ÅÐС£ÆäÖÐWebShellÊǹ¥»÷ÍøÕ¾µÄÒ»ÖÖ¶ñÒâ¾ç±¾ £¬Ê¶±ð³öWebShellÎļþ»òͨѶÁ÷Á¿¿ÉÒÔÓÐÓõØ×èÖ¹ºÚ¿Í½øÒ»²½µÄ¹¥»÷ÐÐΪ¡£ÏÖÔÚWebShellµÄ¼ì²âÒªÁìÖ÷Òª·ÖΪÈý´óÀࣺ¾²Ì¬¼ì²â¡¢¶¯Ì¬¼ì²âºÍÈÕÖ¾¼ì²â¡£

±¾ÎÄÖ÷Òª»ùÓÚÁ÷Á¿À´ÊµÏÖWebShellÅþÁ¬¹¤¾ßµÄ¼ì²â¡£ÏÖÔÚ»ùÓÚÁ÷Á¿µÄ¼ì²âÈÔÈ»ÃæÁÙһЩÎÊÌâ¡£ÏÖ´æµÄһЩWebShellÅþÁ¬¹¤¾ß £¬ºÃ±È±ùЫ¡¢¸ç˹À­¡¢ÒϽ£µÈ £¬¶¼Ê¹ÓÃÁË»ìÏý»ò¼ÓÃÜ»úÖÆ £¬Í¨¹ý¼ÓÃÜͨѶÁ÷Á¿µÄ·½·¨À´Èƹý¹Å°åÇå¾²×°±¸ £¬Ìӱܼì²â¡£

1.2 AntSword ±àÂëÒªÁì

1.2.1 AntSword-default±àÂë

ÏÈÀ´¿´Ò»ÏÂĬÈϱàÂëģʽÁ÷Á¿¡£

ĬÈÏ״̬ϵÄÁ÷Á¿ÕվɽÏÁ¿ÓÑºÃµÄ £¬±£´æÐí¶àº¯Êý¿ÉÒÔ¾ÙÐÐÌØÕ÷¶¨Î» £¬ÔÚ¾­ÓÉ´ó×ÚµÄÊý¾Ý°üÆÊÎöºó £¬È·¶¨ÁËÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌà £»

ÌØÕ÷2£ºÔÚ2´¦¹ØÓÚº¯ÊýÏȺó˳Ðò¾ÙÐÐÆ¥Åä¡£

1.2.2 AntSword-base64±àÂë

Base64£ºÊÇÒ»ÖÖ»ùÓÚ64¸ö¿É´òÓ¡×Ö·ûÀ´ÌåÏÖ¶þ½øÖÆÊý¾ÝµÄÌåÏÖÒªÁì¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Base64±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷ʹÓÃÁËeval £¬base64_decodeµÈÃô¸Ðº¯Êý £¬ÔÚ¾­ÓÉ´ó×ÚµÄÊý¾Ý°üÆÊÎöºó £¬¶¨Î»ÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌà £»

ÌØÕ÷2£ºÈ¡2´¦µÄÁ½¸ö14λ×Ö·û¾ÙÐбÈÕÕÅжÏÊÇ·ñÏàͬ¡£

1.2.3 AntSword-chr±àÂë

CHR£º ASCII Öµ·µ»Ø×Ö·û¡£ASCII Öµ¿É±»Ö¸¶¨ÎªÊ®½øÖÆÖµ¡¢°Ë½øÖÆÖµ»òÊ®Áù½øÖÆÖµ¡£°Ë½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0 £¬Ê®Áù½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0x¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Chr±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷±£´æ¾Þϸд»ìÔÓµÄeVAlº¯Êý £¬Í¬Ê±ÐèÒªÅäºÏÆ¥Åä±àÂëµÄÃûÌÃÓ볤¶ÈÍŽá¾ÙÐмì²â¡£

ÌØÕ÷1£ºÊ¹ÓÃÕýÔòÆ¥Åä1´¦ £¬eValº¯ÊýÀ¨ºÅÖÐcHr(*).ChR(*),¶ÔChR(*)ÊýÄ¿½ç˵ãÐÖµÅäºÏ¼ì²â¡£

1.2.4 AntSword-chr16±àÂë

CHR16£º ASCII Öµ·µ»Ø×Ö·û¡£ASCII Öµ¿É±»Ö¸¶¨ÎªÊ®½øÖÆÖµ¡¢°Ë½øÖÆÖµ»òÊ®Áù½øÖÆÖµ¡£°Ë½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0 £¬Ê®Áù½øÖÆÖµ±»½ç˵Ϊ´øÇ°Öà 0x¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

Chr16±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷Ò²±£´æ¾Þϸд»ìÔÓµÄeVAlº¯Êý £¬ÓëChr±àÂëÀàËÆ £¬Ò²ÐèÒªÅäºÏÆ¥Åä±àÂëµÄÃûÌÃÓ볤¶ÈÍŽá¾ÙÐмì²â¡£

ÌØÕ÷1£ºÊ¹ÓÃÕýÔòÆ¥Åä1´¦ £¬eValº¯ÊýÀ¨ºÅÖÐcHr(0x*).ChR(0x*),¶ÔChR(0x*)ÊýÄ¿½ç˵ãÐÖµÅäºÏ¼ì²â¡£

1.2.5 AntSword-rot13±àÂë

ROT13£º±àÂëÊǰÑÿһ¸ö×ÖĸÔÚ×Öĸ±íÖÐÏòÇ°ÒÆ¶¯ 13 ¸ö×Öĸ»ñµÃ¡£Êý×ֺͷÇ×Öĸ×Ö·û¼á³ÖÎȹÌ¡£

ÏÂÃæÏÈÀ´¿´Ò»ÏÂÊý¾Ý°ü£º

ROT13±àÂëÏ´ÓÊý¾Ý°üÖпÉÒÔ·¢Ã÷±£´æeval,str_rot13µÈÃô¸Ðº¯ÊýÃû³Æ £¬ÔÚ¾­ÓÉ´ó×ÚÊý¾Ý°üÆÊÎöºó £¬È·¶¨ÁËÌØÕ÷ÈçÏ£º

ÌØÕ÷1£ºÔÚ1´¦Ê¹ÓÃÕýÔò¾ÙÐÐÆ¥ÅäÕâ´¦µÄº¯ÊýÃûÌà £»

ÌØÕ÷2£ºÈ¡2´¦µÄ14λ×Ö·û¾ÙÐбÈÕÕ £¬ÅжÏÊÇ·ñÏàͬ¡£

02×ܽá

ÔÚʵս²âÊÔÖÐ £¬Í¨¹ýÉÏÊö¼¸µã £¬¶Ô¼ÓÃÜÐÍ webshell µÄÁ÷Á¿¾ÙÐÐÆÊÎö £¬×ܽáÏà¹ØÈõÌØÕ÷ºÍÇ¿ÌØÕ÷ £¬¶àÖÖÌØÕ÷ÍŽá £¬¿ÉÒÔ׼ȷʶ±ðÕâÀà webshell µÄͨѶÀú³Ì £¬ÊµÊ±´¦Öóͷ£ºÍ·¢Ã÷ʧÏÝÖ÷»ú¡£µ«ÉÏÊö»ùÓÚ×Ö·û´®ÌØÕ÷¼ì²âµÄ¼Æ»® £¬ÐèÒªÇå¾²ÔËÓªÖ°Ô±ÖðÒ»ÆÊÎöÑù±¾ £¬»áÏûºÄ½Ï´óµÄÈËÁ¦ £¬²¢ÇÒÄÑÒÔ¼ì²â±äÖֵĶñÒâÍâÁ¬Á÷Á¿¡£

Ëæ×Ź¥·ÀÊÖÒÕÖ®¼äµÄÒ»Ö±²©ÞÄ £¬¶ñÒâÈí¼þÒ²Ô½À´Ô½ÒþÄä¡£ÏÖÔÚʹÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þ¼Ò×åÁè¼Ý200ÖÖ £¬Ê¹ÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þÕ¼±ÈÁè¼Ý40% £¬Ê¹ÓüÓÃÜͨѶµÄ¶ñÒâÈí¼þÏÕЩÁýÕÖÁËËùÓг£¼ûÀàÐÍ¡£ºóÐøÎÒÃÇ¿ÉÄÜÓöµ½µÄ³¡¾°¸ü¶àÊÇHTTPS £¬AES £¬XORµÈ¼ÓÃÜÀàÐÍ¡£¹ØÓÚÕâÖÖ¼ÓÃÜÀàÐÍ £¬¸üºÃµÄ½â¾ö¼Æ»®ÊÇʹÓûúеѧϰ»òÕßÉî¶Èѧϰ¶ÔÁ÷Á¿ÌØÕ÷¾ÙÐÐʶ±ð¡£

Ëæ×ÅÈ˹¤ÖÇÄÜÊÖÒÕµÄÉú³¤ £¬Í¨¹ý´ó×ڵIJâÊÔÑéÖ¤ £¬È˹¤ÖÇÄÜÓÃÓÚ¼ÓÃÜÁ÷Á¿Çå¾²¼ì²â½«ÊÇÒ»ÖÖÐÂÊÖÒÕÊֶΡ£×÷ΪÇå¾²ÔËÓªÖ°Ô± £¬Î¨ÓÐһֱ̽Ë÷ºÍÑо¿ÐµÄÌØÕ÷ºÍÒªÁì £¬²Å»ª¸üºÃµÄÓ¦¶ÔÍøÂçÁ÷Á¿ÖÐÈÕÒæÖØ´óµÄ¹¥»÷¡£

ÉùÃ÷£º

1£®±¾ÎĵµÓÉBevictorΰµÂÇå¾²ÍŶÓÐû²¼ £¬Î´¾­ÊÚȨեȡµÚÈý·½×ªÔؼ°×ªÍ¶¡£

2£®±¾ÎĵµËùÌáµ½µÄÊÖÒÕÄÚÈݼ°×ÊѶ½ö¹©²Î¿¼ £¬ÓйØÄÚÈÝ¿ÉÄÜ»áËæÊ±¸üР£¬BevictorΰµÂ²»ÁíÐÐ֪ͨ¡£

3£®±¾ÎĵµÖÐÌáµ½µÄÐÅϢΪÕý³£¹ûÕæµÄÐÅÏ¢ £¬ÈôÒò±¾Îĵµ»òÆäËùÌáµ½µÄÈκÎÐÅÏ¢ÒýÆðÁËËûÈËÖ±½Ó»ò¼ä½ÓµÄ×ÊÁÏÁ÷ʧ¡¢ÀûÒæËðʧ £¬BevictorΰµÂ¼°ÆäÔ±¹¤²»¼ç¸ºÈκÎÔðÈΡ£

Òªº¦´Ê±êÇ©£º
BevictorΰµÂ ÍþвÆÊÎöÓëÏìÓ¦ ¶ñÒâÁ÷Á¿¼ì²â
¿Í»§·þÎñÈÈÏß

400-777-0777
7*24Сʱ·þÎñ

ÁªÏµÓÊÏä

servicing@topsec.com.cn

ɨÂë¹Ø×¢
ÍøÕ¾µØÍ¼