<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5732268608163464795</id><updated>2011-06-07T23:27:45.011-07:00</updated><title type='text'>VX Z0ne</title><subtitle type='html'>VIRII,ROOTKIT</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>11</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-2773014084797239756</id><published>2007-06-08T09:06:00.001-07:00</published><updated>2007-06-08T09:06:58.841-07:00</updated><title type='text'>DIY a InlineHook</title><summary type='text'>应用层的InlineHook汇编实现.586.model flat,stdcalloption casemap:noneinclude     ../include/windows.incinclude     ../include/user32.incincludelib ../lib/user32.libinclude     ../include/kernel32.incincludelib ../lib/kernel32.libinclude     ../include/shell32.incincludelib ../lib/shell32.lib.datakernel32 db 'kernel32.dll',0P32First db 'Process32Next',0inline db 'Hook Process32Next Hide Process:)',0sztext </summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/2773014084797239756/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=2773014084797239756' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/2773014084797239756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/2773014084797239756'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/06/diy-inlinehook.html' title='DIY a InlineHook'/><author><name>浪心</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://bp3.blogger.com/_GAhBdMLjyxc/SFeZ5AWq0cI/AAAAAAAAAYM/_IR3PgZU5ok/S220/Snap1.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-7559079603077473859</id><published>2007-05-03T22:20:00.000-07:00</published><updated>2007-05-03T22:21:13.370-07:00</updated><title type='text'>看过《windows internals》前两章 作了个小程序</title><summary type='text'>/*===================================================================* Filename CheckKernel.c** Author: kcrazy* Email:    thekcrazy@gmail.com** Description: 检查Windows所使用的内核及HAL的原始版本** Date:     2007-4-27 Original from kcrazy*         * Version: 1.0==================================================================*/#include #include #include #pragma comment (lib, "Version.lib")DWORD IsPAE( VOID );</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/7559079603077473859/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=7559079603077473859' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/7559079603077473859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/7559079603077473859'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/05/windows-internals.html' title='看过《windows internals》前两章 作了个小程序'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-5306301223913618023</id><published>2007-04-21T01:27:00.000-07:00</published><updated>2007-04-21T01:55:16.972-07:00</updated><title type='text'>Win32Drowor.a的分析过程和清除手段</title><summary type='text'>************************************************************************************以下为分析过程************************************************************************************00436716 &gt;  55              PUSH EBP00436717    8BEC            MOV EBP,ESP00436719    83C4 D0         ADD ESP,-300043671C    53              PUSH EBX0043671D    56              PUSH ESI0043671E    57              PUSH </summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/5306301223913618023/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=5306301223913618023' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/5306301223913618023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/5306301223913618023'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/win32drowora.html' title='Win32Drowor.a的分析过程和清除手段'/><author><name>Santiago</name><uri>http://www.blogger.com/profile/08641560320859150156</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-4410830926581687438</id><published>2007-04-15T06:58:00.000-07:00</published><updated>2007-04-15T07:00:14.305-07:00</updated><title type='text'>修改PE的e_lfanew感染法~~~</title><summary type='text'>实验性质的东西仍然属于bind infection的一种，只不过他是把宿主文件的e_lfanew指向了后面病毒PE的PE     HEADER，我测试了一下，如果PE HEADER的SizeOfHeaders大于4k的话程序就不能被load，也就是说宿主程序大小+病毒的所有头大小+病毒的节表大小不能大于4K，这样的话这种感染方式就没有实用价值了。以上说法如有错误，请批评指正嘿嘿～BOOL CInfection::InfectFile(LPCTSTR lpVirus, LPCTSTR lpHost){ CFileMap fm(lpHost) ; DWORD dwHostSize = fm.GetSize() ; if (0 == dwHostSize)  return false ; /*  如果宿主文件大于4k的话,被感染后的SizeOfHeaders有可能大于4k  如果</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/4410830926581687438/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=4410830926581687438' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4410830926581687438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4410830926581687438'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/peelfanew.html' title='修改PE的e_lfanew感染法~~~'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-4930970269155211179</id><published>2007-04-15T06:43:00.000-07:00</published><updated>2007-04-15T06:47:29.283-07:00</updated><title type='text'>用C实现简单的EPO（修改bug版）</title><summary type='text'>//修改了几个BUG,但是仍有一处致命问题是thunk code里的函数地址是编译时确定的//修改了PE空隙大小计算问题，读写文件问题//感谢icefall以及看雪上的网友的指正。//有时间时我将继续修改这个代码#include #include #pragma comment(lib,"kernel32.lib")#pragma comment(lib,"user32.lib")char szHostFile[] = "c:\\hello.exe" ;PIMAGE_DOS_HEADER pImageDosHeader ;PIMAGE_NT_HEADERS pImageNtHeaders ;PIMAGE_SECTION_HEADER pImageSectionHeader ;unsigned char thunkcode[] = "\x60\x9c\xe8\x00\x00\x00\x00</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/4930970269155211179/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=4930970269155211179' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4930970269155211179'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4930970269155211179'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/cepobug.html' title='用C实现简单的EPO（修改bug版）'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-4811655188290863914</id><published>2007-04-15T06:34:00.000-07:00</published><updated>2007-04-15T06:37:41.342-07:00</updated><title type='text'>头一回写驱动...</title><summary type='text'>/*##################################################################  HideProc.C  Author   :robinh00d[F-13 Lab]  Email    :cr4zyexpl0rer_at_gmail.com  HomePage   :http://cr4zyexpl0rer.googlepages.com  Last Updated :2006-03-23  个人练习之作，都是几年前的老技术了  基本上是copy别人的代码  通过HOOK SSDT来实现对指定进程的隐藏  windows自带的任务管理器以及PSAPI都是利用ZwQuerySystemInformation  来实现进程的遍历######################################################</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/4811655188290863914/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=4811655188290863914' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4811655188290863914'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/4811655188290863914'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/blog-post_7053.html' title='头一回写驱动...'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-1502159315042636937</id><published>2007-04-15T06:29:00.000-07:00</published><updated>2007-04-15T06:32:39.169-07:00</updated><title type='text'>一个“壳感染”病毒的分析</title><summary type='text'>作者：Robinh00d最近几个月，互联网上突然出现大量的感染式的病毒比如威金、熊猫烧香等，这些病毒都是使用了文件捆绑的方式实现的感染，清除起来比较容易。近日，我偶然获得了一个比较特殊的病毒样本，被感染的是QQ的在线升级程序，它并没有采用前面所说的“捆绑式”感染，而是采用了“壳”的技术实现的感染，比较新颖，下面是我对这个病毒进行的分析：【样本下载地址】http://cr4zyexpl0rer.googlepages.com/NewVirus.rar【分析环境】VMWARE+WINDOWS XP SP2+OLLYDBG+PEID+PEInfo首先用PEID扫描一下没有扫描出壳或者编译器特征，入口点RVA是0x70000,进一步使用PE分析工具查看关键的数据信息，我这里使用的是PEInfo：可以看到，代码入口不是在常规的.text节里而是在.rdata节里再看输入表信息：输入表的RVA是</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/1502159315042636937/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=1502159315042636937' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/1502159315042636937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/1502159315042636937'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/blog-post_15.html' title='一个“壳感染”病毒的分析'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-9011945052005046789</id><published>2007-04-10T00:55:00.000-07:00</published><updated>2007-04-10T00:56:28.071-07:00</updated><title type='text'>一个内核级的SHELL工具源代码</title><summary type='text'>驱动部分;@echo off;goto make;********************************************************************;author  :dge;homepage:http://llfdge.googlepages.com/;date    :2007.3.16;********************************************************************.386.model flat, stdcalloption casemap:noneinclude                d:\masm32\include\w2k\ntstatus.incinclude                d:\masm32\include\w2k\ntddk.incinclude</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/9011945052005046789/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=9011945052005046789' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/9011945052005046789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/9011945052005046789'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/shell.html' title='一个内核级的SHELL工具源代码'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-8239181464882532588</id><published>2007-04-10T00:49:00.000-07:00</published><updated>2007-04-10T00:53:47.849-07:00</updated><title type='text'>“和谐”</title><summary type='text'>我左八荣，右八耻，三个代表在腰间，一团和谐在胸口，王挡杀王，后挡杀后，佛挡杀佛！</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/8239181464882532588/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=8239181464882532588' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/8239181464882532588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/8239181464882532588'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/blog-post.html' title='“和谐”'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-2200656315321634575</id><published>2007-04-01T22:31:00.000-07:00</published><updated>2007-04-01T22:33:00.625-07:00</updated><title type='text'>blogspot终于又能访问了</title><summary type='text'>blogspot终于又能访问了，汗一个。。。</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/2200656315321634575/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=2200656315321634575' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/2200656315321634575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/2200656315321634575'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/04/blogspot.html' title='blogspot终于又能访问了'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5732268608163464795.post-861131477092291569</id><published>2007-03-29T04:11:00.000-07:00</published><updated>2007-04-01T22:30:34.446-07:00</updated><title type='text'>关于VX Z0ne</title><summary type='text'>致力于病毒，rootkit研究的组织</summary><link rel='replies' type='application/atom+xml' href='http://vxz0ne.blogspot.com/feeds/861131477092291569/comments/default' title='帖子评论'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5732268608163464795&amp;postID=861131477092291569' title='0 条评论'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/861131477092291569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5732268608163464795/posts/default/861131477092291569'/><link rel='alternate' type='text/html' href='http://vxz0ne.blogspot.com/2007/03/vx-z0ne.html' title='关于VX Z0ne'/><author><name>robinh00d</name><uri>http://www.blogger.com/profile/10060088227706465751</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp3.blogger.com/_eMc1upSDCaw/RhCU7C_5m3I/AAAAAAAAAAU/FKTbH_zVri8/s72-c/cooltext50316823.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
