¾«×¼¶¨Î»£¬£¬£¬£¬£¬£¬¾ÛÁ¦³ö»÷£¡3377ÌåÓýÍø¹ÙÍøÈë¿Ú¶à¿î²úÆ·Áª¶¯·ÀÓùSymbiote
SymbioteÏÈÈÝ
SymbioteÊÇÖ÷ÒªÕë¶ÔLinuxϵͳµÄ¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬ÔÚ2021Äê11ÔÂÊ״α»·¢Ã÷£¬£¬£¬£¬£¬£¬Ö÷ÒªÕë¶ÔÀ¶¡ÃÀÖ޵ĽðÈÚ²¿·Ö£¬£¬£¬£¬£¬£¬Òµ½çÆÕ±éÐÎò¡°ÏÕЩ²»¿ÉÄܱ»¼ì²âµ½¡±¡£¡£¡£¡£¡£¸Ã¶ñÒâÈí¼þ¿Éͨ¹ý¡°¼ÄÉúѬȾ¡±ÏµÍ³Ñ¬È¾ËùÓÐÕýÔÚÔËÐеÄÀú³Ì£¬£¬£¬£¬£¬£¬²¢ÎªÍþв¼ÓÈëÕßÌṩrootkit¹¦Ð§¡¢Ô¶³Ì»á¼ûµÈ¡£¡£¡£¡£¡£
ÓÉÓÚSymbioteÒþ²ØÁËËùÓÐÎļþ¡¢Àú³Ì£¬£¬£¬£¬£¬£¬Òò´ËÔÚÊÜѬȾµÄ»úеÉÏÖ´ÐÐʵʱȡ֤¿ÉÄܲ»»á·¢Ã÷ÈκÎÎÊÌâ¡£¡£¡£¡£¡£³ýÁËRootkitÖ®Í⣬£¬£¬£¬£¬£¬Symbiote»¹Îª¹¥»÷ÕßÌṩÁËÒ»¸öºóÃÅ£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓÃÓ²±àÂëÃÜÂëÒÔ»úеÉϵÄÈκÎÓû§Éí·ÝµÇ¼£¬£¬£¬£¬£¬£¬²¢ÒÔ×î¸ßȨÏÞÖ´ÐÐÏÂÁî¡£¡£¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDR¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØÏµÍ³¡¢½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³£¬£¬£¬£¬£¬£¬ÒÔ¼°Ð°汾µÄÈëÇÖ¼ì²âϵͳ¡¢ÈëÇÖ·ÀÓùϵͳµÈ²úÆ·¾ù¿É¾«×¼¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ£¬£¬£¬£¬£¬£¬±ÜÃâÍþвÊÂÎñ±¬·¢£¬£¬£¬£¬£¬£¬Ìá¸ßÖÕ¶ËÇéÐÎÇå¾²¡£¡£¡£¡£¡£
½ÓÏÂÀ´£¬£¬£¬£¬£¬£¬Ò»Æð½ÒÏþSymbioteÊÇÔõÑùÒþ²Ø×Ô¼ºµÄ~
ÑùÌìÖ°Îö
¾²Ì¬ÑùÌìÖ°Îö
SymbioteÊÇÒ»ÖÖÒÉËÆÕë¶ÔÀ¶¡ÃÀÖÞ½ðÈÚ²¿·ÖµÄLinuxƽ̨rootkit£¬£¬£¬£¬£¬£¬ÆäʹÓÃÁ˶àÖÖhookÊÖÒÕÒþ²Ø×ÔÉíÐÐΪ£¬£¬£¬£¬£¬£¬¾ßÓнϺõÄÃâɱÐÔ£¬£¬£¬£¬£¬£¬Ö÷Òª¹¦Ð§ÊÇÇÔÈ¡µÇ¼ƾ֤²¢ÔÚÊÜѬȾ»úеÉÏÖ²ÈëºóÃÅ¡£¡£¡£¡£¡£
ÂÄÀú³¤Ê±ÆÚµÄ¿ª·¢Ñݽø£¬£¬£¬£¬£¬£¬ÏÖÔÚSymbiote½Ïеİ汾ÊÇÃûΪsearch.soµÄ64λELF¹²ÏíÄ¿µÄÎļþ¡£¡£¡£¡£¡£

Ëüͨ¹ýÉèÖÃLD_PRELOADÇéÐαäÁ¿µÄÖµ£¬£¬£¬£¬£¬£¬ÔÚ³ÌÐòÔËÐÐǰÓÅÏȼÓÔØ¶ñÒ⶯̬Á´½Ó¿âsearch.so£¬£¬£¬£¬£¬£¬search.soÔÚµ¼³öº¯ÊýÖÐÐ®ÖÆÁ˶à¸ö¿âº¯Êý¡£¡£¡£¡£¡£

SymbioteʹÓÃRC4Ëã·¨¼ÓÃÜËùÓÐ×Ö·û´®£¬£¬£¬£¬£¬£¬ÃÜԿΪHEXÊýÖµ¡°030F1513081609061C0A1A0D120217¡±£¬£¬£¬£¬£¬£¬Ó²±àÂëÔÚELFµÄÀο¿Î»ÖÃÖС£¡£¡£¡£¡£

ËùÓб»RC4¼ÓÃܵÄ×Ö·û´®µÄ½âÃÜpython3´úÂëÈçÏ£º
DEFAULT_KEY = "\x03\x0f\x15\x13\x08\x16\x09\x06\x1c\x0a\x1a\x0d\x12\x02\x17"
def rc4(data, key=DEFAULT_KEY, skip=0):
x = 0
box = list(range(256))
x = 0
for i in list(range(256)):
x = (x + box[i] + ord(key[i % len(key)])) % 256
tmp = box[i]
tmp2 = box[x]
box[i] = box[x]
box[x] = tmp
x = 0
y = 0
out = []
if skip > 0:
for i in list(range(skip)):
x = (x + 1) % 256
y = (y + box[x]) % 256
box[x], box[y] = box[y], box[x]
for char in data:
x = (x + 1) % 256
y = (y + box[x]) % 256
box[x], box[y] = box[y], box[x]
k = box[(box[x] + box[y]) % 256]
out.append(chr(ord(char) ^ k))
return ''.join(out)
if __name__ == '__main__':
data = "\x24\xa3\x8a\x5a\xe7\x58\x82\x82\xf7\x2c\x44\xf1\x20\x67"
result = rc4(data, DEFAULT_KEY, 0)
print(result)
¶¯Ì¬µ÷ÊÔÆÊÎö
µ±Å²Óñ»search.soÎļþhookµÄº¯Êýʱ£¬£¬£¬£¬£¬£¬ÄÚ´æÖвŻᶯ̬¼ÓÔØ¶ñÒâsoÎļþ£¬£¬£¬£¬£¬£¬Ã»Óб»hookµÄÇéÐÎÏ»áÔÚlibc-2.13.soÖÐÁ¬Ã¦Ìî³äϵͳŲÓúžÙÐÐsyscallϵͳŲÓ㬣¬£¬£¬£¬£¬¶øhookÖ®ºóµÄÔELF¾ÙÐÐAPIŲÓÃʱ»áͨ¹ýÒ»Ìõjmp»ã±àÖ¸ÁîÌø×ªµ½search.soµÄµ¼³öº¯ÊýÖÐÖ´ÐС£¡£¡£¡£¡£

ÐèÒª×èµ²µÄÀú³ÌÃû³ÆÁбíºÍÎļþÃû³ÆÁÐ±í»®·Ö´æ´¢ÔÚpthºÍfth±äÁ¿Ö¸ÏòµÄÆ«ÒÆ£¬£¬£¬£¬£¬£¬Ê¹ÓÃRC4Ëã·¨ÔÚ¶¯Ì¬ÔËÐÐÖнâÃܲ¢Ä¥Á·¡£¡£¡£¡£¡£

ÈçÏÂͼËùʾÊÇsearch.so±»¼ÓÔØÊ±¶¯Ì¬½âÃܳöµÄÒþ²ØÎļþÃû³Æ£¬£¬£¬£¬£¬£¬Ä¾ÂíÒþ²ØµÄËùÓÐÀú³ÌÁбíºÍÎļþÁбí¼û¸½Â¼²¿·Ö¡£¡£¡£¡£¡£

¹æ±ÜÊÖÒÕÆÊÎö
µ±Ê¹ÓÃlddÏÂÁîÏÔʾÈí¼þµÄÒÀÀµÏîʱ£¬£¬£¬£¬£¬£¬ÇéÐαäÁ¿LD_TRACE_LOADED_OBJECTS»á±»ÉèÖÃΪ1£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¹Ò¹³execveº¯Êý²¢Í¨¹ý¼ì²âLD_TRACE_LOADED_OBJECTSµÄÖµÊÇ·ñΪ1£¬£¬£¬£¬£¬£¬½ø¶ø¾öÒéÊÇ·ñÖ´ÐÐ×èµ²lddÏÂÁîµÄ´úÂ룬£¬£¬£¬£¬£¬´Ó¶øÔÚÈí¼þµÄÒÀÀµÏîÖн«×ÔÉíÈ¥³ýµÖ´ïÒþ²ØÄ¿µÄ¡£¡£¡£¡£¡£

SymbioteÔÚreaddirºÍreaddir64ÖÐʵÏÖÁËÒþ²ØÎļþºÍÒþ²ØÀú³Ì£¬£¬£¬£¬£¬£¬Ö®ºóÓ붯̬¼ÓÔØÖØ¶¨Ïòµ½pthµÄÄÚ´æÖд洢µÄÀú³ÌÃû³ÆÁбí¾ÙÐнÏÁ¿£¬£¬£¬£¬£¬£¬ÈôÊDZ£´æÁбíÖеÄÀú³ÌÃû×Ö£¬£¬£¬£¬£¬£¬ÄÇôreaddirºÍreaddir64º¯Êý»áÖ±½Ó·µ»Ø¡£¡£¡£¡£¡£µ±¹ÜÀíÔËάְԱʹÓÃlsÏÂÁîʱ£¬£¬£¬£¬£¬£¬ÎÞ·¨Éó²éµ½¶ñÒâsoÎļþ£¬£¬£¬£¬£¬£¬µ«ÈôÊÇÖªµÀÎļþÃû³Æ¿ÉÒÔʹÓÃfindÏÂÁî̻¶ÆäλÖᣡ£¡£¡£¡£

ÔÚreaddirºÍreaddir64ÖÐͬÑùʵÏÖÁË·´¸ú×Ù¡£¡£¡£¡£¡£ÈôÊÇÔÚÀú³ÌÖеÄcmdlineÖз¢Ã÷°üÀ¨sh -c strace»òÕßstrace -sµÈÓëstraceÓйصÄÏÂÁî²ÎÊý£¬£¬£¬£¬£¬£¬¼´ÆôÓÃÁË×·×Ù¹¦Ð§£¬£¬£¬£¬£¬£¬º¯ÊýÖ±½Ó·µ»Ø0¡£¡£¡£¡£¡£

ͨ¹ýhookһЩLinux¿É²åÈëÉí·ÝÑé֤ģ¿£¿£¿£¿£¿é(PAM)µÄº¯ÊýÈçpam_authenticate¡¢pam_set_itemºÍpam_acct_mgmtʵÏÖ¶Ô±»Ñ¬È¾»úеµÄÔ¶³Ì»á¼û¡£¡£¡£¡£¡£µ±Óû§ÊµÑéʹÓÃPAM·þÎñ£¨ºÃ±ÈSSHÔ¶³Ì·þÎñ£©¾ÙÐÐÉí·ÝÑé֤ʱ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ»áÅжÏÌṩµÄÃÜÂëÊÇ·ñΪӲ±àÂëµÄÊýÖµ¶øÑ¡Ôñ¶ÔÓ¦µÄ´¦Öóͷ£·½·¨¡£¡£¡£¡£¡£

Òþ²ØÁ÷Á¿µÄµÚÒ»ÖÖÒªÁ죺hook fopenºÍfopen64º¯Êý¡£¡£¡£¡£¡£
µ±Ó¦ÓóÌÐòʵÑé·¿ª/proc/net/tcpÎļþʱ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ½¨ÉèÒ»¸öÔÝʱÎļþ£¬£¬£¬£¬£¬£¬¶ÁÈ¡ÎļþÄÚÈÝʱ»á°´ÐÐÆ¥ÅäÊÇ·ñ±£´æÌض¨¶Ë¿Ú£º43253¡¢43753¡¢63424¡¢26424¡£¡£¡£¡£¡£ÈôÊÇÆ¥Åäµ½¾Í»áÌø¹ý£¬£¬£¬£¬£¬£¬²»È»£¬£¬£¬£¬£¬£¬¸ÃÐÐÄÚÈݻᱻдÈëÔÝʱÎļþ¡£¡£¡£¡£¡£µ±Îļþ±»É¨Ãè´¦Öóͷ£Íêʱ£¬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¾Í»á¹Ø±ÕÔÝʱÎļþ¾ä±ú²¢½«ÔÝʱÎļþµÄÎļþÐÎò·û×÷Ϊ·µ»ØÐ§¹û¡£¡£¡£¡£¡£´ÓʵÖÊÉϽ²£¬£¬£¬£¬£¬£¬ÕâÑùʵÏÖÁËͨ¹ýhook fopen»òfopen64µÄŲÓÃÀú³Ì£¬£¬£¬£¬£¬£¬Òþ²ØÁ˶ñÒâÈí¼þÏëÒªÒþ²ØµÄËùÓÐÍøÂç¶Ë¿ÚµÄÅþÁ¬ÌõÄ¿¡£¡£¡£¡£¡£

Òþ²ØÁ÷Á¿µÄµÚ¶þÖÖÒªÁ죺hookº¯Êýpcap_loopºÍpcap_stats¡£¡£¡£¡£¡£
Symbioteͨ¹ýhookº¯Êýpcap_loopºÍpcap_statsÀ´Íê³ÉÕâ¸öʹÃü,¹ýÂË͵»»Ã¶¾Ù±íÖÐÓòÃû×Ó×Ö·û´®µÄUDPÁ÷Á¿¡£¡£¡£¡£¡£¸ÃÒªÁìÓÃÓÚ¹ýÂ˵ô UDP Êý¾Ý°ü£¬£¬£¬£¬£¬£¬¶øÒÔϵÄeBPF»úÖÆÐ´×Ö½ÚÂëµÄÒªÁìÓÃÓÚ¹ýÂ˵ô TCP Êý¾Ý°ü¡£¡£¡£¡£¡£
Òþ²ØÁ÷Á¿µÄµÚÈýÖÖÒªÁ죺eBPF»úÖÆ¡£¡£¡£¡£¡£
eBPF£¨extended Berkeley Packet Filter£©ÆðÔ´ÓÚBPF£¬£¬£¬£¬£¬£¬ËüÌṩÁËÄں˵ÄÊý¾Ý°ü¹ýÂË»úÖÆ¡£¡£¡£¡£¡£BPFµÄ»ù±¾Í·ÄÔÊǶÔÓû§ÌṩÁ½ÖÖSOCKETÑ¡ÏSO_ATTACH_FILTERºÍSO_ATTACH_BPF£¬£¬£¬£¬£¬£¬ÔÊÐíÓû§ÔÚsokcetÉÏÌí¼Ó×Ô½ç˵µÄfilter£¬£¬£¬£¬£¬£¬Ö»ÓÐÖª×ã¸ÃfilterÖ¸¶¨Ìõ¼þµÄÊý¾Ý°ü²Å»áÉÏ·¢µ½Óû§¿Õ¼ä¡£¡£¡£¡£¡£SO_ATTACH_FILTER²åÈëµÄÊÇcBPF´úÂ룬£¬£¬£¬£¬£¬SO_ATTACH_BPF²åÈëµÄÊÇeBPF´úÂë¡£¡£¡£¡£¡£eBPFÊǶÔcBPFµÄÔöÇ¿£¬£¬£¬£¬£¬£¬ÏÖÔÚÓû§¶ËµÄtcpdumpµÈ³ÌÐòÕÕ¾ÉÓõÄcBPF°æ±¾£¬£¬£¬£¬£¬£¬Æä¼ÓÔØµ½ÄÚºËÖкó»á±»ÄÚºË×Ô¶¯µÄת±äΪeBPF¡£¡£¡£¡£¡£Linux 3.15 ×îÏÈÒýÈëeBPF¡£¡£¡£¡£¡£ÆäÀ©³äÁËBPFµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬¸»ºñÁËÖ¸Á¡£¡£¡£¡£¡£ËüÔÚÄÚºËÌṩÁËÒ»¸öÐéÄâ»ú£¬£¬£¬£¬£¬£¬Óû§Ì¬½«¹ýÂ˹æÔòÒÔÐéÄâ»úÖ¸ÁîµÄÐÎʽת´ïµ½Äںˣ¬£¬£¬£¬£¬£¬ÓÉÄÚºËÆ¾Ö¤ÕâЩָÁîÀ´¹ýÂËÍøÂçÊý¾Ý°ü¡£¡£¡£¡£¡£
ÈçÏÂΪÔÚÄں˱àÒëºóµÄ eBPF»ã±à´úÂ룺

ÈçÏÂΪÒÔÌ«ÍøÖ¡ÃûÌÃÊý¾Ý¡£¡£¡£¡£¡£Õý³£ÇéÐÎÏÂÊý¾ÝÖ¡ÊÇ´ÓDST×îÏÈËãÆð£¬£¬£¬£¬£¬£¬12¸ö×Ö½Ú£¨0xc£©ºó¼´Êdz¤¶È»òÀàÐÍ£¬£¬£¬£¬£¬£¬ldabsh 0xc»ã±àÖ¸Áî¼´Êǽ«Êý¾ÝÖ¡µÄÀàÐÍ×ֶμÓÔØµ½¼Ä´æÆ÷ÖС£¡£¡£¡£¡£½ÓÏÂÀ´jeq r0,0x86dd¼´ÅжÏÐÒéÀàÐÍÊÇ·ñΪIPv6¡£¡£¡£¡£¡£

×îºóÍŽáIPv6ºÍIPv4µÄÊý¾Ý±¨ÃûÌ㬣¬£¬£¬£¬£¬ÎÒÃÇ¿ÉÒÔµÃÖª£¬£¬£¬£¬£¬£¬ eBPF»ã±à³ÌÐòµÄ×îÖÕÄ¿µÄÊÇҪͨ¹ýУÑéÊý¾ÝÖ¡ÖÐIPÐÒéµÄÔ´¶Ë¿ÚºÍÄ¿µÄ¶Ë¿ÚÊÇ·ñΪ43253¡¢43753¡¢63424¡¢26424Ö®Ò»£¬£¬£¬£¬£¬£¬ÓеϰÔò¹ýÂËЧ¹ûÌØÊâ´¦Öóͷ£¡£¡£¡£¡£¡£
Symbioteͨ¹ýʹÓÃËùÓÐÕâÈýÖÖÒªÁ죬£¬£¬£¬£¬£¬¶ñÒâÈí¼þ¿ÉÈ·±£Òþ²ØËùÓÐÁ÷Á¿¡£¡£¡£¡£¡£
×ÛÉÏËùÊö£¬£¬£¬£¬£¬£¬SymbioteµÄrootkitÒþ²ØÊÖÒÕµã¿ÉÒÔ¹éÄÉÈçÏ£º

×·ËݹØÁª
ÔÚ»¥ÁªÍøÉÏ¿ÉÒÔ·¢Ã÷֮ǰ×÷ÕßÔÚ¿ª·¢µÄSymbiote¾É°æ±¾Îļþ£¬£¬£¬£¬£¬£¬Ãû³Æ»®·ÖΪkerneldev.so.bkp¡¢mt64_.so¡£¡£¡£¡£¡£ÆäÖÐÉÐÓÐÒ»¸öÃûΪcertbotx64ÊÇ¿ªÔ´µÄDNSËíµÀ¹¤¾ßÏîÄ¿dnscat±àÒë³öµÄ¿Í»§¶Ë£¬£¬£¬£¬£¬£¬Ê¹ÓÃCÓïÑÔ±àд¡£¡£¡£¡£¡£dnscat±àÒëµÄ·þÎñÆ÷ʹÓÃRubyÓïÑÔ±àд£¬£¬£¬£¬£¬£¬ÔËÐÐʱÒÀÀµRubyºÍGemÇéÐΡ£¡£¡£¡£¡£

Ñù±¾IOCsÁбí

¸½Â¼

·À»¤½¨Òé
ʵʱ¸üÐÂÈí¼þºÍϵͳÒÔ¼°´òÎó²î²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬£¬£¬½µµÍ±»Symbiote²¡¶¾Í¨¹ýÎó²îÈëÇÖµÄΣº¦¡£¡£¡£¡£¡£
ÔöÇ¿»á¼û¿ØÖÆ£¬£¬£¬£¬£¬£¬¹Ø±Õ²»ÐëÒªµÄ¶Ë¿Ú£¬£¬£¬£¬£¬£¬½ûÓò»ÐëÒªµÄÅþÁ¬£¬£¬£¬£¬£¬£¬½µµÍ×ʲúΣº¦Ì»Â¶Ãæ¡£¡£¡£¡£¡£
¸ü¸Äϵͳ¼°Ó¦ÓÃʹÓõÄĬÈÏÃÜÂ룬£¬£¬£¬£¬£¬ÉèÖøßÇ¿¶ÈÃÜÂëÈÏÖ¤£¬£¬£¬£¬£¬£¬²¢°´ÆÚ¸üÐÂÃÜÂ룬£¬£¬£¬£¬£¬±ÜÃâÈõ¿ÚÁî¹¥»÷¡£¡£¡£¡£¡£
¿É×°ÖÃ3377ÌåÓýÍø¹ÙÍøÈë¿ÚÇå¾²²úÆ·ÔöÇ¿·À»¤£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳ¡¢×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢¹ýÂËÍø¹ØÏµÍ³¡¢½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³£¬£¬£¬£¬£¬£¬ÒÔ¼°Ð°汾µÄÈëÇÖ¼ì²âϵͳ¡¢ÈëÇÖ·ÀÓùϵͳµÈ²úÆ·¾ù¿É׼ȷ¼ì²â²¢²éɱ¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳ·ÀÓùÉèÖÃ
1¡¢¿ªÆôÎļþʵʱ¼à¿Ø¹¦Ð§£¬£¬£¬£¬£¬£¬ÓÐÓÃÔ¤·ÀºÍ²éɱ¸Ã¶ñÒâÈí¼þ£»£»£»£»£»£»£»£»
2¡¢Í¨¹ýʹÃüÖÜÆÚÐÔ²éɱ£¬£¬£¬£¬£¬£¬×è¶Ï¶ñÒâ¹¥»÷ÐÐΪ£¬£¬£¬£¬£¬£¬·À»¤²¡¶¾¹¥»÷Íþв£»£»£»£»£»£»£»£»
3¡¢Í¨¹ýÄÚÖõÄWebshellºóÃſ⣬£¬£¬£¬£¬£¬¶ÔÍøÕ¾ºóÃÅרÏî²éɱ£¬£¬£¬£¬£¬£¬½µµÍºáÏòÈö²¥Î£º¦¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿Ú×Ô˳ӦÇå¾²·ÀÓùϵͳ·ÀÓùÉèÖÃ
1¡¢¿ªÆô²¡¶¾ÊµÊ±¼à¿Ø¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÓÐÓÃÔ¤·ÀºÍ²éɱ¸Ã¶ñÒâÈí¼þ£»£»£»£»£»£»£»£»
2¡¢Ö§³Ö¾«×¼¶¨Î»ÏµÍ³Îó²î£¬£¬£¬£¬£¬£¬ÊÂǰʵʱÐÞ²¹£¬£¬£¬£¬£¬£¬½µµÍºáÏòѬȾΣº¦£»£»£»£»£»£»£»£»
3¡¢Í¨¹ýΣº¦·¢Ã÷¹¦Ð§É¨ÃèϵͳÈõ¿ÚÁ£¬£¬£¬£¬£¬½µµÍÇ徲Σº¦¡¢ïÔÌ×ʲú̻¶¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿Ú¹ýÂËÍø¹Ø·ÀÓùÉèÖÃ
1¡¢Éý¼¶µ½×îв¡¶¾ÌØÕ÷¿â£»£»£»£»£»£»£»£»
2¡¢¿ªÆôHTTP¡¢POP3¡¢SMTP¡¢FTP¡¢IMAPµÈÐÒéµÄ²¡¶¾É¨Ãè¼ì²â£»£»£»£»£»£»£»£»
3¡¢ÉèÖò¡¶¾¼ì²â´¦Öóͷ£Õ½ÂÔ;
4¡¢¿ªÆôÈÕÖ¾¼Í¼ºÍ±¨¾¯¹¦Ð§¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿Ú½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³¼ì²âÉèÖÃ
1¡¢Éý¼¶ÍþвÇ鱨¿â°æ±¾£»£»£»£»£»£»£»£»
2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÓÐÓüì²â¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿ÚÈëÇÖ¼ì²âϵͳа汾¼ì²âÉèÖÃ
1¡¢¹ºÖÃÍþвÇ鱨¿â¹¦Ð§Ä£¿£¿£¿£¿£¿é£»£»£»£»£»£»£»£»
2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÓÐÓüì²â¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£
# 3377ÌåÓýÍø¹ÙÍøÈë¿ÚÈëÇÖ·ÀÓùϵͳа汾·À»¤ÉèÖÃ
1¡¢¹ºÖÃÍþвÇ鱨¿â¹¦Ð§Ä£¿£¿£¿£¿£¿é£»£»£»£»£»£»£»£»
2¡¢¿ªÆôÍþвÇ鱨-¶ñÒâÎļþ¼ì²â¹¦Ð§£¬£¬£¬£¬£¬£¬¿ÉÓÐÓ÷ÀÓù¸Ã¶ñÒâÈí¼þ¡£¡£¡£¡£¡£

²úÆ·»ñÈ¡·½·¨
¡ñ 3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳÆóÒµ°æ¡¢3377ÌåÓýÍø¹ÙÍøÈë¿Ú×Ô˳ӦÇå¾²·ÀÓùϵͳ¡¢3377ÌåÓýÍø¹ÙÍøÈë¿Ú¹ýÂËÍø¹Ø¡¢3377ÌåÓýÍø¹ÙÍøÈë¿Ú½©Ê¬ÍøÂçľÂíºÍÈ䳿¼à²âÓë´¦Öóͷ£ÏµÍ³¡¢3377ÌåÓýÍø¹ÙÍøÈë¿ÚÈëÇÖ¼ì²âϵͳ¡¢3377ÌåÓýÍø¹ÙÍøÈë¿ÚÈëÇÖ·ÀÓùϵͳÊÔÓ㺿Éͨ¹ý3377ÌåÓýÍø¹ÙÍøÈë¿ÚÌìÏ·ÖÖ§»ú¹¹»ñÈ¡£¡£¡£¡£¡£¨ÅÌÎÊÍøÖ·£º
http://www.topsec.com.cn/contact/£©
¡ñ 3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDRϵͳµ¥»ú°æÏÂÔØµØÖ·£ºhttp://edr.topsec.com.cn
¡ñ 3377ÌåÓýÍø¹ÙÍøÈë¿Ú¹ýÂËÍø¹ØÏµÍ³²¡¶¾¿âÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/·À²¡¶¾Íø¹Ø(Top-Filter)/²¡¶¾¿âÍÑ»úÉý¼¶°ü/
¡ñ 3377ÌåÓýÍø¹ÙÍøÈë¿ÚÍþвÇ鱨¿âÏÂÔØµØÖ·£ºftp://ftp.topsec.com.cn/3377ÌåÓýÍø¹ÙÍøÈë¿ÚÏÂÒ»´úÈëÇÖ·ÀÓùϵͳ(NGIDP)/ÍþвÇ鱨¿â/ ti-v2022.09.05.005.tor
TOPSEC
¶ñÒâÈí¼þÓ°ÏìÊý¾Ý¼°³ÌÐòµÄÇå¾²ÐÔ£¬£¬£¬£¬£¬£¬¶Ô¸÷ÕþÆóµ¥Î»ÍøÂçÇå¾²¼°Éç»áÖÈÐòÔì³ÉÑÏÖØÎ£º¦¡£¡£¡£¡£¡£×÷ΪÖйúÍøÂçÇå¾²¡¢´óÊý¾ÝÓëÔÆ·þÎñÌṩÉÌ£¬£¬£¬£¬£¬£¬3377ÌåÓýÍø¹ÙÍøÈë¿Ú¶àÄêÉî¸ûÍøÂçÇå¾²·À»¤ÁìÓò£¬£¬£¬£¬£¬£¬»ýµí¸»ºñµÄÊÖÒÕÓë²úÆ·ÄÜÁ¦£¬£¬£¬£¬£¬£¬²¢Ò»Ö±ÍƳ³öУ¬£¬£¬£¬£¬£¬Ò»Á¬ÖúÁ¦¹ú¼ÒÍøÂçÇå¾²¿µ½¡Éú³¤¡£¡£¡£¡£¡£
3377ÌåÓýÍø¹ÙÍøÈë¿ÚÚÐÌýʵÑéÊÒ
ÚÐÌýʵÑéÊÒÊÇ3377ÌåÓýÍø¹ÙÍøÈë¿ÚµÄ²¡¶¾ÆÊÎöºÍÏìÓ¦ÍŶӣ¬£¬£¬£¬£¬£¬»ã¾Ûרҵ²¡¶¾ÆÊÎöÓëÑо¿Ö°Ô±£¬£¬£¬£¬£¬£¬ÖÂÁ¦ÓÚÖն˶ñÒâ´úÂëµÄÄæÏòÆÊÎö¡¢ÍþвԤ¾¯¡¢×·±¾ËÝÔ´¡¢·´²¡¶¾ÊÖÒÕµÈÇå¾²Ñо¿ºÍÍþв·¢Ã÷£¬£¬£¬£¬£¬£¬Îª¼¯ÍÅȫϵ²úÆ·ÌṩÖÜÈ«µÄÊÖÒÕÖ§³ÖºÍÎó²îÆÊÎöÏìÓ¦¡£¡£¡£¡£¡£
- Òªº¦´Ê±êÇ©£º
- 3377ÌåÓýÍø¹ÙÍøÈë¿ÚEDR ×Ô˳ӦÇå¾²·ÀÓùϵͳ ¹ýÂËÍø¹ØÏµÍ³ ½©Ä¾Èäϵͳ ¾«×¼²éɱSymbiote

¾©¹«Íø°²±¸ 11010802026257ºÅ