原作者:@火柴人AlanBecker 原视频:BV1hrpEz2EZJ 特别鸣谢: 开场白片头制作@日月の辉 文案指导@Anglia @AB柴专栏小助手 @芸茵small @霍普希尔 电脑与代码相关指导@风荣ForonG-H 剪辑穿帮发现@Taaaaaamigs 字幕校对@AB柴专栏小助手 标题@霍普希尔 水印制作@TR-救赎 配乐: 00:00 ~ 01:20:Music from ’Hacker‘ [Animator vs. Animation 12] - Scott Buckley 43:46 ~ 43:53:Music from ’Victim‘ [Animator vs. Animation 11] - Scott Buckley 43:54 ~ 44:05:Music from ’Hacker‘ [Animator vs. Animation 12] - Scott Buckley 其他:Timeless - Prototyperaptor 信息量史无前例的一次解析!希望大家看完能有所收获! 附录 cmd窗口1: > initiate_session --target ALANSPC [+] connection secured (TLS spoofed handshake) [+] SID acquired: 5-1-5-21-********** [-] Creating SYSTEM taken... success > shadow_clone –-disk \\ALANSPC\C$ --output \\temp\ing_ALANSPC.dd [IMFO] volume mount point detected: C:\ [CLONE] Enumerating sectors... [CLONE] NTFS structure locked [CLONE] Bypassing VSS throttling .. (partial image preserved) > enable_rdp – force –-shadowmode [+] Remote Desktop Protocol enabled [+] Port 3389 unblocked in firewall [+] Service: TermService started in stealth cmd窗口2: > ping ALANSPC.local -n 1 Reply from 45.36.254. > net use \\ALANSPC\ipc$ /user:admin ****** [+] IPC Connection established [!] WARNING: Access rights elevated beyond expected permissions > exec \\ALANSPC\c$\System32\breach_toolkit.exe [*] Injecting remote kernel hooks... [*] Disabling user controls... [ERROR] :: Task Manager is currently running :: Force-kill issued [#] Explorer.exe suspended > regedit /s legacy_xp_registry_patch.reg [!] SYSTEM WARNING: Unsigned driver detected [-] Bypassing digital signature enforcement... > del /f /q \\ALANSPC\C$\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost > del /f /q \\ALANSPC\C$\Windows\System32\smartscreen.exe [#] modern UI shell components purged (剩余代码片段在置顶评论补充)




换一换 































