Ò׽ؽØͼÈí¼þ¡¢µ¥Îļþ¡¢Ãâ°²×°¡¢´¿ÂÌÉ«¡¢½ö160KB

LinuxÏÂÓÃncʵÏÖDuplexPipe

nc ÊÇÒ»°ÑÍøÂçµÄÈðÊ¿¾üµ¶£¬ÎÒÒÔÇ°ÔÚ½éÉÜ DuplexPipe ʱҲÌáµ½¹ý£¬Èç¹ûÄãû½Ó´¥¹ýËü£¬¿ÉÒÔÏȲο´Ò»Ï¡¶DuplexPipe¶þÈýÊ£¨¶þ£©¡·¡£ÔÙÀ´¼òµ¥µØ½éÉÜһϠDuplexPipe£¬¹ËÃû˼Ò壬ËüÊÇÒ»¸ö“Ë«Ïò¹ÜµÀ”¡£ÔÚ shell ÖУ¬ÎÒÃÇͨ¹ý“|”ʹÓÃÄäÃû¹ÜµÀ£¬ÈÃÇ°Ò»ÌõÃüÁîµÄÊä³ö×÷ΪºóÒ»ÌõÃüÁîµÄÊäÈ룻˫Ïò¹ÜµÀ¼´ÔÚ´Ë»ù´¡ÉÏÔÚ¼ÓÉÏ“ºóÒ»ÌõÃüÁîµÄÊäÈë×÷ΪǰһÌõÃüÁîµÄÊäÈ딡£ÕâÊÇ×î³õ¿ª·¢ËüµÄÔ­Òò£¬µ«ºóÀ´·¢ÏÖËü¸üÏñÊÇÒ»¸öÍøÂç½Ó¿Úת»»Æ÷£¬“DuplexPipe”Õâ¸öÃû×Ö·´¶ø²»ÄÜÌåÏÖËüµÄ¹¦ÄÜ¡£¸ü¶àÄÚÈÝÇë²Î¿´DuplexPipeϵÁÐÎÄÕ¡£
ÁôÑÔ
½ñÌìÍøÓѻƺ£¸øÎÒÁôÑÔ£¬Ëûͨ¹ýÓà nc µÄ -e Ñ¡ÏîÀ´Ö´ÐÐ nc ±¾ÉíÀ´ÊµÏÖ DuplexPipe¡£ÁôÑÔÔ­ÎÄÈçÏ£º
¸çÃÇ£¬ÄãдµÄÄǸöDuplexPipe, ÎÒºÜÐÀÉÍ¡£²»¹ý½üÈÕÓÚÍøÉϹ䷢Ïִ˹¤¾ßµÄ¹¦Äܾ¹È»ÍêÈ«¿ÉÒÔÓÃnetcat×öµ½£¬ÓÐÁ½ÖÖ·½·¨£¬ÎҵIJ©¿ÍÉÏÔØÁËÒ»ÖÖ¡£¼òµ¥ÃèÊöÈçÏ£º
ÔÚwindowsÏ£º
echo nc [ip] [port] > relay.bat
nc -l -p [port2] -e relay.bat
ÆäÓàµÄÀàÍÆ
µÚ¶þÖÖ·½·¨ÊÇÓÃÃüÃû¹ÜµÀ£º(linuxÏÂ)
mknod backpipe p
nc -l -p [port] 0<backpipe | nc [ip] [port12] | tee backpipe
ÆäÖÐÑ¡Ïî -e µÄ×÷ÓÃÊÇ£º
for NT: -e prog inbound program to exec [dangerous!!]
for Linux: -e filename program to exec after connect [dangerous!!]
Windowsϲ»ÐÐ
ÔÚÎÒ¿ª·¢ DuplexPipe ʱȷʵ¿¼Âǹý¹¦Äܻ᲻»áºÍ nc Öصþ£¬µ±Ê±Ö»Ïë×Åͨ¹ý shell ¹ÜµÀÀ´Á¬½Ó£¬ÍüÁË nc ×Ô´øÁËÒ»¸öË«Ïò¹ÜµÀ£¡ÎÒÊ×ÏÈÔÚ Vista ÏÂ×öÁ˲âÊÔ£¬nc(win32) ÊÇ´Ó http://www.securityfocus.com/tools/139 ÏÂÔØ¡£¿ªÆôÈý¸öÃüÁîÌáʾ·û£¬·Ö±ðÖ´ÐУº
1) nc -l -p 1234
2) nc localhost 1234 -e "nc -l -p 1235"
3) nc localhost 1235
ÆäÖеڶþÌõºÍÁôÑÔÖÐʹÓÃÅú´¦ÀíµÈ¼Û¡£ÀíÂÛÉÏÔÚÌáʾ·û(3)ÖÐÊäÈëÒ»ÐÐÊý¾Ý£¬Ìáʾ·û(1)ÈýÖÐÂíÉÏÏÔʾ¡£µ«ÎÒÿ´ÎÔÚÌáʾ·û(3)ÖÐÊäÈëÒ»¶ÑÊý¾Ýºó£¬Ìáʾ·û(1)ÒªÊäÈëÁ½¸ö»Ø³µ²Å»á°ÑÊý¾ÝÏÔʾ³öÀ´¡£ÎÒÓÖÁíÍ⿪ÆôËĸöÃüÁîÌáʾ·û£¬Ä£Äâ DuplexPipe£º
1) nc -l -p 1234
2) nc -l -p 1235 -e "nc -l -p 1236"
3) nc localhost 1234 -e "nc localhost 1235"
4) nc localhost 1236
´ËʱÌáʾ·û(1)ÖеÄÊý¾ÝÄÜ·¢Ë͵½(4)ÖУ¬¶øÌáʾ·û(4)ÖеÄÊý¾ÝÈ´µ¹²»ÁË(1)¡£µ÷Õû(2)¡¢(3)Öж˿ڵÄ˳Ðò»á³öÏÖ²»Í¬½á¹û£¬µ«¶¼´ï²»µ½ÀíÏëЧ¹û¡£ºóÀ´ÓÖÏÂÁËÆäËû¼¸¸ö²»Í¬°æ±¾µÄ nc£¬²¢ÔÚ WinXP ÏÂÒ²½øÐÐÁ˲âÊÔ£¬µ«¶¼²»³É¹¦¡£
Li


Ïà¹ØÎĵµ£º

ʵսLinux Bluetooth±à³Ì£¨Èý£© HCI²ã±à³Ì

1. HCI²ãЭÒé¸ÅÊö£º
HCIÌṩһÌ×ͳһµÄ·½·¨À´·ÃÎÊBluetoothµ×²ã¡£ÈçͼËùʾ£º
´ÓͼÉÏ¿ÉÒÔ¿´³ö£¬Host Controller Interface(HCI)  ¾ÍÊÇÓÃÀ´¹µÍ¨HostºÍModule¡£Hostͨ³£¾ÍÊÇPC£¬ ModuleÔòÊÇÒÔ¸÷ÖÖÎïÀíÁ¬½ÓÐÎʽ£¨USB,serial,pc-cardµÈ£©Á¬½Óµ½PCÉϵÄbluetooth Dongle¡£
ÔÚHostÕâÒ»¶Ë£ºapplication,SDP,L2capµÈЭÒé ......

ʵսLinux Bluetooth±à³Ì(Áù) L2CAP±à³ÌʵÀý

ÀýÒ»£º·¢ËÍSignaling Packet£º
Signaling CommandÊÇ2¸öBluetoothʵÌåÖ®¼äµÄL2CAP²ãÃüÁî´«Êä¡£ËùÒÔµÃSignaling CommandʹÓÃCID 0x0001.
¶à¸öCommand¿ÉÒÔÔÚÒ»¸öC-frame£¨control frame£©Öз¢ËÍ¡£
 Èç¹ûÒªÖ±½Ó·¢ËÍSignaling Command.ÐèÒª½¨Á¢SOCK_RAWÀàÐ͵ÄL2CAPÁ¬½ÓSocket¡£ÕâÑù²ÅÓлú»á×Ô¼ºÌî³äCommand Code£¬Identi ......

linux Ó¦¼±ÏàÓ¦¹¤¾ß°üºÍlivecd

http://www.forensicswiki.org/wiki/Helix3
http://www.sleuthkit.org/index.php
»Ö¸´²½Öè:
root@srv01 [/home/recovery]# ./fls -a -r -p /dev/sdb3 > sdb3usrdirlist.txt
root@srv01 [/home/recovery]# grep -i "access_log" /home/recovery/sdb3usrdirlist.txt
r/r 2195490:    local/ ......

[תÔØ]linuxµÄtestÃüÁî

ÿһÖÖÌõ¼þÓï¾äµÄ»ù´¡¶¼ÊÇÅжÏʲôÊÇÕæʲôÊǼ١£ÊÇ·ñÁ˽âÆ乤×÷Ô­Àí½«¾ö¶¨Äú±àдµÄÊÇÖÊÁ¿Ò»°ãµÄ½Å±¾»¹ÊÇÄú½«ÒýÒÔΪÈٵĽű¾¡£
Shell ½Å±¾µÄÄÜÁ¦Ê±³£±»µÍ¹À£¬µ«Êµ¼ÊÉÏÆäÄÜÁ¦µÄ·¢»ÓÊÜÖÆÓڽű¾×«Ð´ÕßµÄÄÜÁ¦¡£ÄúÁ˽âµÃÔ½¶à£¬Äú¾ÍÔ½ÄÜÏñ±äÏ··¨ËƵØ׫дһ¸öÎļþÀ´Ê¹ÈÎÎñ×Ô¶¯»¯ºÍ¼ò»¯ÄúµÄ¹ÜÀí¹¤×÷¡£
ÔÚ shell ½Å±¾ÖнøÐеÄÃ¿Ò»Ö ......
© 2009 ej38.com All Rights Reserved. ¹ØÓÚE½¡ÍøÁªÏµÎÒÃÇ | Õ¾µãµØͼ | ¸ÓICP±¸09004571ºÅ