<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>Kevins的天空 - 远控后门和攻击技术</title><link>http://blog.csdn.net/iiprogram/category/136508.aspx</link><description>普通木马技术,远程控制等攻击技术等</description><dc:language>zh-CN</dc:language><lastUpdateTime>Thu, 24 Jul 2008 21:32:00 GMT</lastUpdateTime><ttl>60</ttl><item><dc:creator>Kevins</dc:creator><title>A Catalog of Local Windows Kernel-mode Backdoor Techniques</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/24/2706870.aspx</link><pubDate>Thu, 24 Jul 2008 21:31:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/24/2706870.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2706870.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/24/2706870.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2706870.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2706870</trackback:ping><description>A Catalog of Local Windows Kernel-mode Backdoor Techniques&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2706870.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>Kwasek6 polymorphic code, modified Ruby Hash</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/23/2694920.aspx</link><pubDate>Wed, 23 Jul 2008 10:59:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/23/2694920.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2694920.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/23/2694920.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2694920.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2694920</trackback:ping><description>Kwasek6 polymorphic code, modified Ruby Hash&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2694920.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>XP下双开3389远程控制的源码</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687758.aspx</link><pubDate>Tue, 22 Jul 2008 08:09:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687758.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2687758.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687758.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2687758.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2687758</trackback:ping><description>XP下双开3389远程控制的源码&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2687758.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>C++ win32 下载者源码</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687757.aspx</link><pubDate>Tue, 22 Jul 2008 08:07:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687757.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2687757.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/22/2687757.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2687757.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2687757</trackback:ping><description>C++ win32 下载者源码&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2687757.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>注入winlogon</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664233.aspx</link><pubDate>Thu, 17 Jul 2008 09:55:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664233.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2664233.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664233.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2664233.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2664233</trackback:ping><description>注入winlogon&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2664233.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>一个注入winlogon的程序的代码，学习API用</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664215.aspx</link><pubDate>Thu, 17 Jul 2008 09:53:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664215.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2664215.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664215.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2664215.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2664215</trackback:ping><description>一个注入winlogon的程序的代码，学习API用&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2664215.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>暴力注入Explorer的apc方法</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664098.aspx</link><pubDate>Thu, 17 Jul 2008 09:36:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664098.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2664098.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/17/2664098.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2664098.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2664098</trackback:ping><description>暴力注入Explorer的apc方法&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2664098.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>利用CreateEvent函数不让微点启动</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/17/2663785.aspx</link><pubDate>Thu, 17 Jul 2008 08:50:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/17/2663785.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2663785.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/17/2663785.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2663785.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2663785</trackback:ping><description>利用CreateEvent函数不让微点启动&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2663785.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title> 通过PspTerminateThreadByPointer结束进程</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662873.aspx</link><pubDate>Wed, 16 Jul 2008 20:27:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662873.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2662873.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662873.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2662873.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2662873</trackback:ping><description> 通过PspTerminateThreadByPointer结束进程&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2662873.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title> 绕过安全软件挂钩SSDT的检测</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662854.aspx</link><pubDate>Wed, 16 Jul 2008 20:24:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662854.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2662854.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/16/2662854.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2662854.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2662854</trackback:ping><description> 绕过安全软件挂钩SSDT的检测&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2662854.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kevins</dc:creator><title>MS Office Snapshot Viewer ActiveX Exploit 最新网马</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/16/2659286.aspx</link><pubDate>Wed, 16 Jul 2008 11:18:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/16/2659286.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2659286.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/16/2659286.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2659286.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2659286</trackback:ping><description>MS Office Snapshot Viewer ActiveX Exploit 最新网马&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2659286.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>傻傻Kevins</dc:creator><title>下载者的新思路</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654068.aspx</link><pubDate>Tue, 15 Jul 2008 15:13:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654068.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2654068.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654068.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2654068.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2654068</trackback:ping><description>下载者的新思路&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2654068.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>傻傻Kevins</dc:creator><title>让对方运行你的木马的社会工程学艺术</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654043.aspx</link><pubDate>Tue, 15 Jul 2008 15:10:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654043.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2654043.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/15/2654043.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2654043.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2654043</trackback:ping><description>让对方运行你的木马的社会工程学艺术&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2654043.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>傻傻Kevins</dc:creator><title>最近流行的14种第三方0day挂马防御措施</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/15/2653191.aspx</link><pubDate>Tue, 15 Jul 2008 12:02:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/15/2653191.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2653191.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/15/2653191.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2653191.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2653191</trackback:ping><description>最近流行的14种第三方0day挂马防御措施&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2653191.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>傻傻Kevins</dc:creator><title>免杀之花指令</title><link>http://blog.csdn.net/iiprogram/archive/2008/07/15/2652369.aspx</link><pubDate>Tue, 15 Jul 2008 10:09:00 GMT</pubDate><guid>http://blog.csdn.net/iiprogram/archive/2008/07/15/2652369.aspx</guid><wfw:comment>http://blog.csdn.net/iiprogram/comments/2652369.aspx</wfw:comment><comments>http://blog.csdn.net/iiprogram/archive/2008/07/15/2652369.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/iiprogram/comments/commentRss/2652369.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=2652369</trackback:ping><description>免杀之花指令&lt;img src ="http://blog.csdn.net/iiprogram/aggbug/2652369.aspx" width = "1" height = "1" /&gt;</description></item></channel></rss>