¼òÒªÆÊÎö£ºHacking Team Ô¶³Ì¿ØÖÆÏµÍ³
2015-07-09
Content
-
¼òÒªÆÊÎö Hacking TeamÔ¶³Ì¿ØÖÆÏµÍ³
-
й¶£ºHacking Team
- Hacking Team
-
ÆÊÎö£ºÔ¶³Ì¿ØÖÆÏµÍ³
- Hacking Team RCSϵͳ¼Ü¹¹
- Hacking Team RCS»ù±¾¹¦Ð§
- Hacking Team RCSÈëÇÖÊÖ¶Î
-
ÍþвÇ鱨
-
¹ØÓÚ¾ÅÓÎÀÏ¸ç¿Æ¼¼
ÄÚÈݵ¼¶Á
7ÔÂ5ÈÕÍí£¬Ò»¼ÒÒâ´óÀûÔ¶³Ì¿ØÖÆÈí¼þ³§ÉÌHackingTeamµÄÄÚ²¿Êý¾Ý±»Ð¹Â¶³öÀ´£¬ÆäÓ°ÏìÁ¦²»ÑÇÓÚ˹ÂåµÇÊÂÎñ¼°Î¬»ù½âÃÜÊÂÎñ£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼ÍþвÏìÓ¦ÖÐÐÄËæ¼´Æô¶¯Ó¦¼±ÏìÓ¦ÊÂÇé¡£
- 6ÈÕ£¬ÍþвÏìÓ¦ÖÐÐÄÆô¶¯Ó¦¼±ÆÊÎöÊÂÇ飬¾ÅÓÎÀϸçTAC²úÆ·×èµ²µ½Flash 0DayÎó²î¹¥»÷£»
- 6ÈÕÒ¹£¬Ïà¹ØÐÅÏ¢¼°ÆðÔ´½¨Ò飬µÚһʱ¼ä¼û¸æ¿Í»§¹Ø×¢£»
- 7ÈÕ£¬ÔÚ¹ÙÍøÍøÕ¾Ðû²¼½ôÆÈͨ¸æ£¬½¨Òé¿í´óÓû§¹Ø×¢ÊÂÎñÏ£Íû¡£ÆÊÎöÊÂÇéÏ£ÍûÏ£ÍûÖУ»
- 9ÈÕ£¬Ðû²¼Hacking TeamÔ¶³Ì¿ØÖÆÏµÍ³¼òÒªÆÊÎö±¨¸æ£»
ÕâÊÇÒ»·Ý¿ìËÙ±¨¸æ£¬ÒÔ±ã¼òÒªÆÊÎöÆäÖеĽ¹µãÄÚÈÝ£¬Hacking Team RCS£¨Ô¶³Ì¿ØÖÆÏµÍ³£©¡£ÔÚºóÐøµÄ±¨¸æÖУ¬ÎÒÃǽ«»á¶Ô´Ë´ÎÊÂÎñ¾ÙÐÐÉîÈëÆÊÎö£¬²¢¸ø³öÓ¦¶Ô¼Æ»®¡£
й¶£ºHacking Team
7ÔÂ5ÈÕÍí£¬Ò»¼ÒÒâ´óÀûÈí¼þ³§É̱»¹¥»÷£¬ÆäÕÆÎÕµÄ400GBÎó²î£¨°üÀ¨0day£©Êý¾Ýй¶³öÀ´£¬ÓÉ´Ë¿ÉÄÜÒý·¢µÄ¶¯µ´£¬ÒýÆðÁËÒµ½çһƬ»©È»¡£Êý¾Ý°üÖÐÖ÷Òª°üÀ¨¼¸¸ö´óµÄ²¿·Ö£º
- Ô¶³Ì¿ØÖÆÈí¼þÔ´Â룬ҲÊÇÆä½¹µã£¬ÔÝÇÒ³ÆÖ®Îª Hacking Team RCS
- ·´²éɱÆÊÎö¹¤¾ß¼°Ïà¹ØÌÖÂÛÎĵµ
- 0Day¡¢Îó²î¼°Ïà¹ØÈëÇÖ¹¤¾ß
- ÈëÇÖÏîÄ¿Ïà¹ØÐÅÏ¢£¬°üÀ¨ÕË»§ÃÜÂë¡¢Êý¾Ý¼°ÒôÏñ×ÊÁÏ
- °ì¹«ë¹µµ¡¢Óʼþ¼°Í¼Æ¬
- ÆäËû
Hacking Team
Hacking TeamÔÚÒâ´óÀûÃ×À¼×¢²áÁËÒ»¼ÒÈí¼þ¹«Ë¾£¬Ö÷ÒªÏò¸÷¹úÕþ¸®¼°Ö´·¨»ú¹¹ÏúÊÛÈëÇÖ¼°¼àÊÓ¹¦Ð§µÄÈí¼þ¡£ÆäÔ¶³Ì¿ØÖÆÏµÍ³¿ÉÒÔ¼à²â»¥ÁªÍøÓû§µÄͨѶ¡¢½âÃÜÓû§µÄ¼ÓÃÜÎļþ¼°µç×ÓÓʼþ£¬¼Í¼Skype¼°ÆäËûVoIPͨѶ£¬Ò²¿ÉÒÔÔ¶³Ì¼¤»îÓû§µÄÂó¿Ë·ç¼°ÉãÏñÍ·¡£Æä×ܲ¿ÔÚÒâ´óÀû£¬¹ÍÔ±40¶àÈË£¬²¢ÔÚ°²Äɲ¨Àû˹ºÍÐÂ¼ÓÆÂÓµÓзÖÖ§»ú¹¹£¬Æä²úÆ·ÔÚ¼¸Ê®¸ö¹ú¼ÒʹÓá£
ÆÊÎö£ºÔ¶³Ì¿ØÖÆÏµÍ³
¸÷ÈËÖªµÀITÔËάÖÎÀíÖо³£Óõ½Ô¶³Ì¿ØÖÆÈí¼þ£¬ºÃ±ÈDameware£¬µ«Hacking Team RCSÏà±ÈÊÐÃæÉϳ£¼ûµÄÔ¶³Ì¿ØÖÆÈí¼þ¶øÑÔ£¬Ö÷񻂿±ðÈçÏ£º
-
ϵͳ»¯ÖÎÀí¸ÃÈí¼þ´ÓÈëÇÖµ½Ä¿µÄÐÅÏ¢ÍøÂçÆÊÎö£¬ÓÐÍêÕûµÄϵͳ¼Ü¹¹
- Õâ¸ö¼Ü¹¹ÖÐÓвî±ðµÄ¹¦Ð§Ä£¿é£¬Ï໥֮¼äÏ໥ÅäºÏ£¬Íê³ÉÈëÇÖ¡¢×°Öá¢ÐÅÏ¢ËѼ¯¡¢¼à¿Ø¡¢¼¯ÖÐÖÎÀíµÈ¹¦Ð§¡£
- ÍøÂçÐÅÏ¢¸ÃÈí¼þÔÚºóÌ¨ÍøÂç²¢ÉÏ´«Ä¿µÄÓû§µÄÐÅÏ¢£¬°üÀ¨ÖÖÖÖÊý¾Ý¡¢Í¼Æ¬¡¢Ó°ÒôµÈ
- ÈëÇÖ¹¤¾ßÅäºÏ¸ÃÈí¼þÓÐÖÖÖÖÎó²î¡¢Ê¹ÓÃÊֶμ°×Ô¶¯»¯¹¤¾ß£¬ÒÔ±ãÔÚÄ¿µÄÉÏÇ¿ÖÆ×°ÖÃAgent
- ˳ӦÄÜÁ¦Ç¿×ÀÃæOS´ÓWindowsµ½MacOs X£¬ÊÖ»úOS»ù±¾ÁýÕÖÁËÊг¡ÉÏÊ¢ÐеÄϵͳ
- ·´×·×Ù¸ÃÈí¼þÍâµØ¼°Èö²¥Àú³ÌÊý¾Ý¾ù¼ÓÃÜ£¬ÈÃ×·×ÙÕßÄÑÒÔÕÒµ½¹¥»÷Õß
- ·´Ð¶ÔØ·´²éɱ¸ÃÈí¼þAgent²»Ìá¹©Ð¶ÔØ·½·¨£¬²¢½ÓÄÉÖÖÖÖÊÖ¶ÎÌÓ±Üɱ¶¾Èí¼þ
Hacking Team RCSϵͳ¼Ü¹¹
RCS (Remote Control System)ϵͳÊÇÒ»Ì×ÓÃÓÚÕþ¸®×èµ²µÄºÚ¿ÍÌ×¼þ£¬ÊµÏÖÁËȫƽ̨µÄ¼à¿ØÏµÍ³¡£
RCSÖ÷Òª×é¼þ
ÿһ¿é×é¼þÏêϸµÄ¹¦Ð§ÈçÏ£¬
- Front-End:ÎüÊÕÔËÐÐÔÚ±»½ØÈ¡Éè±¹ØÁ¬ÄÊðÀí£¬×÷ΪBack-EndµÄ¸ôÀëÆÁÕÏ£¬°ü¹ÜRCS×°ÖõÄÇå¾²ÐÔ¡£ÏµÍ³ÒªÇóÊÇWindows 2003 or 2008¡£
- Back-end: ÊÇÕû¸öÉèÊ©µÄ½¹µã£¬Ëü´æ´¢ËùÓдÓÊðÀíÍøÂçµ½µÄÊý¾Ýͬʱ´¦Öóͷ£´ÓÖÎÀí¿ØÖÆÌ¨´«À´µÄÇëÇó¡£ËùÓеÄRCSÊý¾Ý´æ´¢ÄÚÀïÒ»¸ö±ê×¼µÄ¹ØÏµÐÍÊý¾Ý¿â£¬Òò´Ë¸Ã·þÎñ»¹Ìá¹©ÌØÁíÍ⹦Ч£¬ºÃ±Èƾ֤¿Í»§µÄÒªÇóʵÏÖ×Ô¶¯±¸·ÝºÍ¶¨ÖÆÊý¾ÝÍÚ¾ò¡£ÏµÍ³ÒªÇóÊÇWindows 2003 or 2008¡£
- Management console:RCSµÄ¿ØÖÆÌ¨ÊÇÓÃÓÚ»á¼ûºÍ¿ØÖÆËùÓеÄÔ¶³Ì¿ØÖÆÏµÍ³£¨RCS£©¹¦Ð§µÄÓ¦ÓóÌÐò¡£Operators¿ÉÒÔÊÚÓèϵͳ²î±ðÆ·¼¶µÄ»á¼ûȨÏÞ£ºAdmin¿ÉÒÔ½¨ÉèÓû§ºÍ×飬ÊÚÓèȨÏÞ£¬ÖÎÀíÊӲ죬ÉóºËϵͳ£»TechnicianÊǽ¨ÉèÄ¿µÄѬȾ¡¢ÉèÖÃ/ÖØÐÂÉèÖÃÊðÀíÐÐΪµÄÔØÌ壻Viewerä¯ÀÀÀ´×ÔtargetµÄÐÅÏ¢£¬¶ÔÆä¾ÙÐзÖÀà»òÕßÊä³ö¡£ÏµÍ³ÒªÇóÊÇWindows MacOS X or Linux¡£
-
Target:RCS AgentÊǼàÊÓÄ¿µÄÅÌËã»ú»òÖÇÄÜÊÖ»úÉϵÄÈí¼þ×é¼þ¡£Ò»µ©×°ÖÃÀֳɣ¬Agent½«»áͨ¹ý×°±¸µÄÍøÂç½«ÍøÂçµ½µÄÊý¾Ý´«Ë͵½Front-End£¬ÕâЩÊý¾ÝÓÐÐí¶àÖÖÀ࣬ºÃ±ÈÆÁÄ»½ØÍ¼¡¢µç»°ºô½ÐµÈ¡£
- RCS AgentÓÐÁ½ÖÖ×°Ö÷½·¨£ºÍâµØÒÔ¼°Ô¶³Ì¡£ÍâµØ×°ÖÃÖ÷ÒªÊÇͨ¹ý×ÀÃæÏµÍ³µÄCDºÍUSB´æ´¢×°±¸À´Ö¸µ¼£¬»òÕßÊÇÖÇÄÜÊÖ»úµÄusb¡£Ô¶³Ì×°ÖÃÔòͨ¹ýMelting tool¡¢Exploit portal¡¢Network InjectorÒÔ¼°Remote Mobile Installation¡£²¢ÇÒÿ¸öRCS Agent¶¼¿ÉÒÔͨ¹ýÔ¶³ÌÏÂÁîÐ¶ÔØ¡£
-
RCS AgentsµÄϵͳҪÇó£º
-
Windows XP Vista 7 (32/64 bit)
-
MacOs X 10.6 Snow Leopard 10.7 Lion
-
Windows Mobile 6 6.5
-
iOS 3 4 (iPhone/iPad)
-
Symbian S60 3rd and 5th edition
- BlackBerry 4.5 or newer
-
AnonymizersÄ¿µÄÊÇÒþ²ØFront EndÕæÊµIPµØµã£¬ÓÉÓÚAnonymizersÖ®¼äµÄÅþÁ¬Êý¾Ý±»ÍêÈ«¼ÓÃܲ¢ÇÒûÓнâÃÜÊý¾Ý£¬ÒÔÊÇ¿ÉÒÔ±»°²ÅÅÔÚÈκηÇÐÅÍеÄÍøÂçºÍ¹ú¼Ò¡£
-
Collection Node ÐÅÏ¢ËѼ¯¹¦Ð§ÊÇͨ¹ýCollection NodeÀ´Íê³ÉµÄ¿Í»§¶ËÉÏ´«ÐÅÏ¢µÄËѼ¯£¬²¢ÇÒÔÊÐí¿Í»§¶Ë´Ó·þÎñÆ÷ÉÏÏÂÔØÐµÄÉèÖúͲå¼þ£¬Õâ¸ö½ÚµãÊÇͨ¹ýÌṩASP·þÎñÍê³É½»»¥µÄ¡£Õâ¸ö½ÚµãÊÇÕû¸ö¿ØÖÆÏµÍ³Î¨Ò»ÄÜ´ÓÍⲿ¾ÙÐлá¼ûµÄ½Úµã£¬Òò´Ë¶ÔËüµÄ±£»¤Ò²ºÜÊÇÒªº¦£¬ºÃ±ÈʹÓ÷À»ðǽµÈ²½·¥¾ÙÐÐÒ»¶¨µÄ¸ôÀ룬ҲÐèҪʹÓõ½Anonymizer Á´À´¶ÔASPÕæÊµµÄIPµØµã¾ÙÐÐÒþ²Ø¡£
- RSSM(Mobile Collection Node)×÷ΪCollection NodeµÄÒ»¸öÔö²¹£¬Í¨¹ýÀ¶ÑÀµÈÊÖ¶ÎÍê³ÉCollection NodeµÄ¹¦Ð§£¬²¢ÇҸýڵãÒ²»áºÍCollection NodeÍê³Éͬ²½µÄÀú³Ì¡£
-
Log Repository Log Repository(RCSDB)ÊÇRCSϵͳµÄ´æ´¢²¿¼þ£¬´æ´¢ÐÅÏ¢°üÀ¨£º
- »á¼û¹ýµÄÍøÕ¾
- Îļþ²Ù×÷
- ¼üÅ̼ͼ
- ÎĵµºÍͼƬÐÅÏ¢
- VoIPµç»°¼à¿Ø(ÀýÈçskype)
- ³ÌÐòÖ´ÐÐÐÅÏ¢
- ÒôƵ¼àÊÓ
- WebÉãÏñÍ·¼àÊÓ
- ½ØÆÁ
- ¼´Ê±Í¨Ñ¶£¨Skype¡¢WindowsLiveMessenge¡¢WechatµÈ£©
- ¼ôÌù°åµÄÐÅÏ¢
- ÃÜÂëÐÅÏ¢£¨emailÕË»§¡¢WindowsLiveÕË»§µÈ£©
- ·¢ËͺÍÎüÊÕÓʼþ
- µç»°Â¼Òô
- GPSλÖÃ
- ÁªÏµÈËÐÅÏ¢
´ÓÉÏÃæµÄÆÊÎö¿ÉÒÔ¿´³öÀ´£¬ÕâÒ»´Îй¶µÄHacking TeamµÄÖÖÖÖ³ÌÐòÖУ¬½ÏÁ¿ÍêÕûµÄº¸ÇÁËʵÑé¹¥»÷¸÷¸ö½×¶ÎÐèÒªÓõ½µÄһЩ¿ØÖƺÍʹÓù¤¾ß£¬Õë¶ÔÆäÖеÄһЩ½ÏΪ¾µäµÄ´úÂ룬ÎÒÃǾÓÉÑо¿£¬¸ø³öÕâЩ¹¤¾ß°üµÄ¹¦Ð§£¬¶ÔʹÓùæÄ£×öÁË´óÖµÄÐÎò¡£ÔÚÕâÒ»Ì×RCSÀÕë¶Ôµç»°¡¢pc¡¢ÍøÂç¾ù¾ÙÐÐÁË¿ØÖƺÍÐÅÏ¢ËѼ¯¡£
Hacking Team RCS»ù±¾¹¦Ð§
µç»°¼à¿Ø
Õë¶Ôµç»°¼à¿Ø£¬¿ª·¢ÁËÕë¶Ô²î±ðƽ̨µÄagent³ÌÐò£¬ÏÂÃæÊÇÒ»·ÝÁбí
- core-winphone:Õë¶Ô Windows Phone ÒÆ¶¯Æ½Ì¨µÄÔ¶³Ì¿ØÖÆÄ¾Âí¿Í»§¶Ë£¬ÓÃÓÚÊµÊ±ÍøÂçÄ¿µÄϵͳ״̬ÐÅÏ¢£¬GPS£¬Í¨Ñ¶Â¼£¬Í¨»°¶ÌÐżÍ¼£¬ÈÕÀúÈճ̰²ÅŵÈÒþ˽ÐÅÏ¢£¬»¹¿ÉÒÔÖ´ÐмÒô£¬½ØÈ¡ÊÖ»úÆÁÄ»µÈ׼ʱʹÃü£¬¾ßÓÐÔ¶³Ì·¿ªÊÖ»úÉãÏñÍ·£¬¿ªÆô»°Í²µÈ¹¦Ð§¡£
- core-winmobile:Õë¶ÔÒѾÓÉʱµÄ Windows Mobile ÒÆ¶¯Æ½Ì¨µÄÔ¶³Ì¿ØÖÆÄ¾Âí¿Í»§¶Ë¡£Ò²ÊÇÓÃÓÚÍøÂçÄ¿µÄÒþ˽ÐÅÏ¢£¬ÇÒ¾ßÓÐÔ¶³Ì¿ØÖÆÍøÂç¼Òô£¬½ØÆÁµÈ¹¦Ð§¡£
- core-symbian:Õë¶Ô Symbian ÒÆ¶¯Æ½Ì¨µÄÔ¶¿ØÄ¾ÂíÊðÀí£¬ÓÃÓÚÍøÂçGPSλÖã¬Í¨Ñ¶¼Í¼£¬¶ÌÐÂÎŵÈÃô¸Ð¼Í¼£¬²¢¿ÉÔ¶³Ìʵʱ¼àÌý»°Í²µÈ¹¦Ð§¡£
- core-android-audiocapture:°²×¿Æ½Ì¨ÏµÄÓïÒô¼àÌý¹¤¾ß£¬Í¨¹ý×¢ÈëAudioFlingerÏà¹ØÀú³ÌµÖ´ï¼Í¼Âó¿ËºÍÌýͲÒôƵµÄ¹¦Ð§¡£Õû¸ö¹¤¾ß°üÀ¨×¢È빤¾ßhijack¡¢±»×¢ÈëµÄ¿âlibt.so£¬×¢Èëºó»á¼Í¼ÒôƵÐÅÏ¢µ½dumpÎļþ£¬ºÚ¿Íͨ¹ýdecoder.py¾ç±¾¿ÉÒÔ½«dumpÎļþ»¹Ô³ÉwavÎļþ¡£¿ÉÒÔÔÚ°²×¿3.xµ½4.xÏÂÔËÐС£
- core-android:Ò»¸ö°²×¿ÏµÄRCSÓ¦Óã¬Ó¦¸ÃÊǹ¦Ð§½ÏÁ¿ÍêÉÆµÄ¹¤¾ß£¬¿ÉÒÔÍøÂçÉç½»Èí¼þµÄÐÅÏ¢£¬Ó¦ÓÃÖл¹´ò°üÁËÐí¶àʹÓù¤¾ß
- core-blackberry:ÊǺÚݮϵÄRCSÈí¼þ¡£
×ÀÃæÏµÍ³¼à¿Ø
- core-macos:ÆäÖаüÀ¨Ò»¸öÓÃÓÚMax OS X ƽ̨¿ÉÖ´ÐÐÎļþ macho ÎļþµÄ¼Ó¿Ç¼ÓÃÜ»ìÏý³ÌÐò¡£Í¬Ê±»¹°üÀ¨Õë¶Ô Mac OS X ƽ̨µÄÔ¶³Ì¿ØÖÆÄ¾Âí¿Í»§¶Ë³ÌÐò£¬ÓÃÓÚÍøÂçÄ¿µÄÏµÍ³ÍøÂçÅþÁ¬£¬ÎļþϵͳµÈÐÅÏ¢£¬»¹¿ÉÒÔÇÔÈ¡iMessageSkype¼ôÌù°åµÈÓ¦ÓõÄÃô¸ÐÐÅÏ¢£¬Í¬Ê±»¹¿ÉÒÔ¼üÅ̼ͼ£¬½ØÆÁ£¬·¿ªÉãÏñÍ·µÈ¡£
- core-win32:windowsƽ̨ľÂí£¬Ö÷Òª¹¦Ð§°üÀ¨£º1.ÇÔÈ¡Ö÷Á÷ä¯ÀÀÆ÷ÈçChrome¡¢FireFoxºÍIE µÄCookiesµÈÐÅÏ¢2.¶ÔÓû§GMail¡¢Outlook¡¢Facebook¡¢Twitter¡¢MSN¡¢Skype¡¢ICQ¡¢Yahoo¡¢Google Talk¡¢Mozilla ThunderbirdµÈʹÓþÙÐÐ¼à¿Ø£¬ÍøÂçÏà¹ØÐÅÏ¢ÍøÂçÈ磺ÕʺÅÐÅÏ¢¡¢Ïà¹ØÁªÏµÈËÐÅÏ¢µÈ¡£¼à¿ØµÄMSN°æ±¾´Ó6.0µ½2011£¬Yahoo Messager°æ±¾´Ó7.xµ½10.x£¬ICQ Messenger v7.x 3.¶ÔÂó¿Ë·çºÍÉãÏñÍ·¾ÙÐÐ¼à¿Ø
- core-win64:ºÍcore-win32¶ÔÓ¦£¬Í¬ÑùÊÇwindowsƽ̨ľÂí£¬µ«ÏîĿֻÊǰüÀ¨ÁË64Î»ÏµÍ³ÌØÓеÄapi hook¿ò¼Ü.
- soldier-win:windowsƽ̨ľÂí£¬¹¦Ð§°üÀ¨£º»ñȡĿµÄÅÌËã»ú»ù±¾ÐÅÏ¢ÇÔÈ¡ä¯ÀÀÆ÷chrome¡¢firefox¡¢IEÃÜÂëºÍcookiesÇÔÈ¡facebook¡¢gmail¡¢twitter¡¢YahooÏà¹ØÐÅÏ¢ÆÁÄ»¼à¿Ø¡¢ÉãÏñÍ·¼à¿ØµÈ
- scout-win:windowsƽ̨ľÂí£¬¹¦Ð§Ïà¶Ô¼òÆÓ£ºscreenshot¡¢»ñȡĿµÄÅÌËã»úµÄ»ù±¾ÐÅÏ¢È磺CPU£¬Äڴ棬Óû§ÃûµÈÐÅÏ¢¡£¾ßÓÐÉÙÁ¿¼òÆÓµÄ·´¼ì²â»úÖÆ£¬ÈçAntiVM¡¢¶¯Ì¬»ñÈ¡APIµØµã¡¢ºÚÃûµ¥µÈ¡£×ÓÏîÄ¿VMProtectDumperÊÇÕë¶Ôijһ°æ±¾VMProtectµÄÍѿǻú
¸¨ÖúÈëÇÖ¹¦Ð§
ΪÁËÔÚtargetÉÏ×°ÖÃÊܿضËÈí¼þ²¢»ñÈ¡Ö÷»ú¿ØÖÆÈ¨£¬ÉÐÓÐÌṩÁËһЩÐëÒªµÄ¹¦Ð§
- driver-macos:°üÀ¨Ò»¸ö Mac OS X ƽ̨µÄÄں˼¶ Rootkit £¬¾ßÓÐÓû§Àú³ÌÒþ²Ø£¬ÎļþϵͳÒþ²ØµÈ¹¦Ð§£¬»¹¿ÉÒÔ hook ϵͳŲÓ㬠mach_trap_table £¬²¢ÊµÊ±×·×ÙÓû§¿Õ¼äºóÃŵÄÔËÐÐ״̬¡£
- core-packer:ÓÃÓÚWindows ƽ̨ PE ¿ÉÖ´ÐÐÎļþµÄ¼Ó¿Ç¼ÓÃÜ»ìÏý³ÌÐò¡£
- core-android-market:Ó¦¸ÃÊǰ²×¿ÏµÄÀàËÆÍÆËÍÐÂÎŵÄÓ¦Ó㬰üÀ¨Ò»¸öÃûΪorg.benews.BeNewsµÄ°²×¿¶ËµÄapkÓ¦ÓúÍÍâµØÔËÐеÄserver£¬Í¨Ñ¶Êý¾ÝΪbsonÃûÌá£apkÓ¦ÓþßÓÐ×ÔÆô¶¯¹¦Ð§£¬»áÆô¶¯ÍÆËÍ·þÎñ
- core-android-native:׿Ïà¹ØÊ¹Óù¤¾ßµÄÜöÝÍ£¬°üÀ¨ÁËËùÓа²×¿4.1°æ±¾ÒÔǰµÄʹÓù¤¾ß£¬°üÀ¨ÁËput_user_exploit¡¢towelrootÖеÄʹÓù¤¾ß¡¢selinuxµÄʹÓù¤¾ßµÈ
-
vector-ipa:ipaÊÇ Injection Proxy Appliance µÄËõд Injection Proxy ApplianceÊÇRCSϵͳһ²¿·Ö¡£
- RCS Injection Proxy Appliance (RCS IPA)ÊÇÓÃÓÚ¹¥»÷µÄÇå¾²×°±¸£¬Ê¹ÓÃÖÐÐÄÈ˹¥»÷ÊÖÒÕºÍstreamline injection»úÖÆ£¬Ëü¿ÉÒÔÔÚ²î±ðµÄÍøÂçÇéÐÎÏÂ͸Ã÷µØ¾ÙÐвÙ×÷£¬ÎÞÂÛÊÇÔÚ¾ÖÓòÍøÕÕ¾ÉÄÚ²¿½»Á÷»úÉÏ¡£
- IPA ¿É´Ó¼à¿ØµÄÍøÂçÁ÷Á¿Öмì²âHTTPÅþÁ¬£¬¾ÙÐÐÖÐÐÄÈ˹¥»÷£¬Ö÷ÒªÓÐÈýÖÖ¹¥»÷·½·¨:×¢ÈëEXE ×¢ÈëhtmlºÍÌæ»»¹¥»÷¡£µ±¼à¿ØµÄHTTPÅþÁ¬ÖÀÖÐÔ¤ÏÈÉèÖõĹæÔòʱ£¬IPA ½«Ö´ÐÐ×¢Èë¹¥»÷¡£IPA ¿ÉÒÔÉèÖÃÐèҪעÈëµÄÓû§(ÈçIPµØµã)£¬×ÊÔ´(Èç¿ÉÖ´ÐÐÎļþ)µÈ¹æÔò¡£
-
driver-win32:core-win32¶ÔÓ¦µÄÄÚºËÇý¶¯Ä£¿é£¬Ìṩ¹¦Ð§ÖîÈ磺ȨÏÞÌáÉý¡¢²Ù×÷Ãô¸Ð×¢²á±í¡¢»Ö¸´SSDTµÈ¡£
-
driver-win64:Ïà¶Ô32λ°æ±¾µÄÇý¶¯£¬Ö»ÊÇ×¢Ê͵ôÁËÐí¶à¹¦Ð§´úÂë¡£
-
vector-silent:ľÂí¸¨Öú³ÌÐò£ºDropperºÍdepacker
-
vector-ap
plet:Ó¦¸ÃÊÇÓÃÓÚ¹ÒÂíµÄJava ap plet¡£Ê¹ÓõÄÓпÉÄÜÊÇδ֪Îó²î£¬Îó²îÔÚtwostageºÍweaponizedÎļþ¼ÐϵÄreadmeÖÐÓÍÐÎò£¬¡±Í¨¹ýXMLDecoder»ñȡһ¸öBridgeʵÀýµÄÒýÓ㬴Ӷøµ¼ÖÂÒ»¸öÀà»ìÏý¡±¡£ -
vector-edk:Intel UEFI£¨Í³Ò»¿ÉÀ©Õ¹¹Ì¼þ½Ó¿Ú£©BIOSºóÃÅÖ²È빤¾ß
- vector-offline2:ÀëÏß×°ÖÃRCS¹¤¾ß°ü£¬¿ÉÔÚÎïÀí½Ó´¥Ê±Ö²ÈëRCSºóÃÅ¡£ ¿É½«ÀëÏß×°Öù¤¾ß¿Ì¼ÔÚCD-DVD/USBµÈ¿ÉÖ¸µ¼½éÖÊÉÏ£¬µ±¿ÉÎïÆÊÎö¼ûµ½ÅÌËã»úϵͳʱ£¬¿ÉʹÓøýéÖÊÆô¶¯ÏµÍ³£¬½«ºóÃÅÖ±½ÓÖ²ÈëÅÌËã»úÖеIJÙ×÷ϵͳÖС£ÏÖÔÚÖ§³Ö¶ÔLinux/OS X/WindowsϵͳµÄÀëÏß×°Öá£ÌṩÁËÓѺõÄͼÐνçÃæ£¬¿É×Ô¶¯Ê¶±ðÅÌËã»úÉϱ£´æµÄ²î±ð²Ù×÷ϵͳ£¬²¢¿Éʶ±ðÿ¸ö²Ù×÷ϵͳÉϱ£´æµÄÓû§£¬È»ºó¿ÉÕë¶Ô²î±ðÓû§»®·ÖÖ²Èë²î±ðÀàÐ͵ĺóÃÅ¡£
- vector-offline:Windows°æµÄÀëÏß×°Öù¤¾ßÔ´Âë¡£
- vector-recover:Ò»¸öWindows°æµÄÏÂÔØÆ÷¡£ÏÂÔØÆ÷×Ô¼º»áÐÞ¸Äͼ±êºÍ°æ±¾ÐÅÏ¢£¬½«×Ô¼ºÎ±×°³É¶«Ö¥µÄÀ¶ÑÀÖúÊÖ¹¤¾ß:btassist.exe¡£ÏÂÔØÆ÷×Ô¼º»áÑ»·»á¼ûÁ½¸öµØµãµÄÀο¿URL:GET /gh/3735928545/deadbee2ÅжÏÏÂÔØÊý¾ÝµÄǰ32×Ö½ÚÊÇ·ñÊÇ¡±3j9WmmDgBqyU270FTid3719g64bP4s52¡å£¬ÈôÊÇÊǵϰ»á´ÓµÚ33×Ö½Ú×îÏÈÉúÑĺóÐøÊý¾Ý¹âÔÝʱĿ¼ÏµÄmsupd64.exeÎļþÖУ¬È»ºóÖ´ÐиÃÎļþ¡£
- vector-rmi:Ò»¸ö·¢ËÍWAP PUSHÐÅÏ¢µÄÏÂÁîÐй¤¾ß£¬¿ÉÒÔ½«Á´½ÓÒÔ¶ÌÐÅÐÎʽ·¢Ë͵½Ö§³ÖWAP PUSH¹¦Ð§µÄÊÖ»úÉÏ¡£¿É×Ô½ç˵ÖݪֲÎÊý¡£
Hacking Team RCSÈëÇÖÊÖ¶Î
Hacking Team RCSÈí¼þÈëÇÖÄ¿µÄ£¬Ö÷Ҫͨ¹ýÈçÏÂÈýÖÖ·½·¨£º
Ñ¬È¾ÒÆ¶¯½éÖÊ
ÓëÐí¶àľÂí¡¢²¡¶¾¼°Á÷Ã¥Èí¼þµÄÈö²¥·½·¨Ò»Ñù£¬¸ÃÈí¼þÊ×ÏÈÕվɽÓÄÉÕâÖֵͱ¾Ç®µÄ·½·¨¾ÙÐУ¬Ñ¬È¾Ò»Ð©Äܹ»½Ó´¥Ä¿µÄµÄÒÆ¶¯Ã½Ì壬ºÃ±ÈCD-ROM¡¢USBµÈ£¬¼´¼´ÊÇOS »òÕßBIOSÉèÖÃÁËÃÜÂëÒ²Ò»Ñù¿ÉÒÔѬȾ£¬´Ó¶ø»ñȡһЩÇéÐÎÊý¾Ý£¬ºÃ±ÈµçÄÔÊÇ·ñ¿ÉÒÔÉÏÍøµÈ£¬ÎªºóÐøµÄÐж¯Ìṩ²Î¿¼ÒÀ¾Ý¡£
ÊðÀí¹¥»÷
½ÓÄÉÈí¼þ»òÓ²¼þµÄϵͳ£¬Äܹ»ÔÚÍøÂç»á»°Àú³ÌÖÐÐ޸ĺÍ×¢ÈëÊý¾Ý£¬ÔÚijЩÇéÐÎÏ£¬¿ÉÒÔ×¢È뵽ϵͳ²¢ÄÑÒÔ±»¼ì²âµ½¡£Í¬Ê±£¬Ò²Äܹ»Ñ¬È¾Windowsƽ̨ÉϵĿÉÖ´ÐÐÎļþ£¬ÈôÊÇÄ¿µÄµçÄÔ´ÓÍøÕ¾ÉÏÏÂÔØ²¢Ö´ÐÐÕâЩ¿ÉÖ´ÐÐÎļþʱ£¬Agent½«ÔÚºǫ́×Ô¶¯×°Öã¬Óû§²»»áÖªÏþ¡£
APT
ÈçÉÏÁ½ÖÖ·½·¨¶¼ÎÞ·¨×àЧµÄʱ¼ä£¬¾Í»á½ÓÄɶàÖÖÐÎʽ×éºÏÈëÇÖ£¬½ÓÄÉÏà¹ØµÄÎó²î¡¢ÈëÇÖ¹¤¾ß¼°¸ü¶àʹÓÃÊֶΣ¬ÏêϸµÄÆÊÎö¼°·À»¤¼Æ»®£¬ÔÚºóÐøµÄ±¨¸æÖзºÆð¡£
Hacking Team RCSÐÅÏ¢ÉÏ´«
ÓÃÓÚËѼ¯¿Í»§¶ËËѼ¯ÐÅÏ¢µÄÉÏ´«Í¨µÀ£¬ÊÇÒ»¸öÇ¿¼ÓÃܺÍÐèÒªÈÏÖ¤µÄͨѶÀú³Ì£¬Í¬Ê±Õû¸öÉÏ´«Í¨µÀµÄÉè¼ÆÊÇ»ùÓÚÖØ´óÍøÂçÇéÐεģ¬Ë¼Á¿µ½·À»ðǽ¡¢´øÓÐÓòÈÏÖ¤¹¦Ð§µÄÊðÀíµÈµÈ£¬»áͨ¹ýÄ£ÄâÒ»¸öÕý³£Óû§ä¯ÀÀwebµÄÀú³ÌÀ´¾ÙÐÐÕâһЩ²Ù×÷¡£
ÐÅÏ¢ËѼ¯¹¦Ð§ÊÇͨ¹ýCollection NodeÀ´Íê³ÉµÄ¿Í»§¶ËÉÏ´«ÐÅÏ¢µÄËѼ¯£¬²¢ÇÒÔÊÐí¿Í»§¶Ë´Ó·þÎñÆ÷ÉÏÏÂÔØÐµÄÉèÖúͲå¼þ£¬Õâ¸ö½ÚµãÊÇͨ¹ýÌṩASP·þÎñÍê³É½»»¥µÄ¡£Õâ¸ö½ÚµãÊÇÕû¸ö¿ØÖÆÏµÍ³Î¨Ò»ÄÜ´ÓÍⲿ¾ÙÐлá¼ûµÄ½Úµã£¬Òò´Ë¶ÔËüµÄ±£»¤Ò²ºÜÊÇÒªº¦£¬ºÃ±ÈʹÓ÷À»ðǽµÈ²½·¥¾ÙÐÐÒ»¶¨µÄ¸ôÀ룬ҲÐèҪʹÓõ½Anonymizer Á´À´¶ÔASPÕæÊµµÄIPµØµã¾ÙÐÐÒþ²Ø¡£
RSSM(Mobile Collection Node)×÷ΪCollection NodeµÄÒ»¸öÔö²¹£¬Í¨¹ýÀ¶ÑÀµÈÊÖ¶ÎÍê³ÉCollection NodeµÄ¹¦Ð§£¬²¢ÇҸýڵãÒ²»áºÍCollection NodeÍê³Éͬ²½µÄÀú³Ì¡£
ÍþвÇ鱨
´ÓÏÖÔÚ´Ë´ÎHacking Teamй¶ÊÂÎñÇéÐÎÀ´¿´£¬ÆäÔì³ÉµÄ·´Ó¦ÓÌÈç˹ÂåµÇ¼°Î¬»ù½âÃÜÊÂÎñµÄÓ°Ï죬Ҫº¦ÔÚÓÚ¾¡¿ÉÄÜ¿ìµÄÏàʶµ½Ïà¹ØµÄÇ鱨£¬ÒԱ㾡¿ÉÄÜ¿ìµÄÆô¶¯Ó¦¼±ÏìÓ¦»úÖÆ¡£ÍþвÇ鱨µÄ»ñÈ¡¼°ÏìÓ¦¶¼ÌåÏÖÁË·ÀÓùÄÜÁ¦µÄ½¨Éèˮƽ£¬ÍþвÇ鱨·þÎñϵͳÖÁÉÙ°üÀ¨ÁËÍþв¼à²â¼°ÏìÓ¦¡¢Êý¾ÝÆÊÎö¼°ÕûÀí¡¢ÓªÒµÇ鱨¼°½»¸¶¡¢Î£º¦ÆÀ¹À¼°×Éѯ¡¢Çå¾²Íйܼ°Ó¦Óõȸ÷¸ö·½Ãæ£¬Éæ¼°Ñо¿¡¢²úÆ·¡¢·þÎñ¡¢ÔËÓª¼°ÓªÏúµÄ¸÷¸ö»·½Ú£¬¾ÅÓÎÀÏ¸ç¿Æ¼¼Í¨¹ýÑо¿¡¢Ôƶˡ¢²úÆ·¡¢·þÎñµÈÁ¢ÌåµÄÓ¦¼±ÏìӦϵͳ£¬ÏòÆóÒµºÍ×é֯ʵʱÌṩÍþвÇ鱨£¬²¢Ò»Á¬¶Ô¶ÔÄäÃûÕß¹¥»÷ÊÂÎñ¾ÙÐйØ×¢£¬°ü¹Ü¿Í»§ÓªÒµµÄ˳³©ÔËÐС£
ÈôÊÇÄú¶ÔÎÒÃÇÌṩµÄÄÚÈÝÓÐÈκÎÒÉÎÊ£¬»òÕßÐèÒªÏàʶ¸ü¶àµÄÐÅÏ¢£¬¿ÉÒÔËæÊ±Í¨¹ýÔÚ΢²©¡¢Î¢ÐÅÖÐËÑË÷¾ÅÓÎÀÏ¸ç¿Æ¼¼ÁªÏµ¾ÅÓÎÀϸ磬½Ó´ýÄúµÄ´¹Ñ¯£¡

¾ÅÓÎÀϸçÔÆ







