CuteK 发表于 2008-7-1 20:19

插件式溢出文件扫描工具

内置一些溢出格式的检测
插件可扩展检测内容


插件编写例子及程序

liveck 发表于 2008-7-7 10:33

居然有源码放出?

jinjjh 发表于 2008-11-4 19:01

溢出文件扫描工具用后

我的系统里有太多的PE文件不知道怎么处理
dobe Photoshop CS3\AdobeXMP.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeXMP.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeUpdater.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeUpdater.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobePDFL.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobePDFL.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeOwl.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeOwl.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLM_libFNP.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLM_libFNP.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLM.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLM.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLinguistic.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\AdobeLinguistic.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\ACE.dll        PE
C:\Program Files\Adobe\Adobe Photoshop CS3\ACE.dll        PE
C:\Program Files\360Safebox\uninst.exe        PE
C:\Program Files\360Safebox\uninst.exe        PE
C:\Program Files\360Safebox\safeext.dll        PE
C:\Program Files\360Safebox\safeext.dll        PE
C:\Program Files\360Safebox\safeboxTray.exe        PE
C:\Program Files\360Safebox\safeboxTray.exe        PE
C:\Program Files\360Safebox\SafeboxKrnl.sys        PE
C:\Program Files\360Safebox\SafeboxKrnl.sys        PE
C:\Program Files\360Safebox\SafeboxApi.dll        PE
C:\Program Files\360Safebox\SafeboxApi.dll        PE
C:\Program Files\360Safebox\safebank.exe        PE
C:\Program Files\360Safebox\safebank.exe        PE
C:\Program Files\360Safebox\rptup.dll        PE
C:\Program Files\360Safebox\rptup.dll        PE
C:\Program Files\360Safebox\liveupdate.dll        PE
C:\Program Files\360Safebox\liveupdate.dll        PE
C:\Program Files\360Safebox\LeakCheck.dll        PE
C:\Program Files\360Safebox\LeakCheck.dll        PE
C:\Program Files\360Safebox\GuardField.exe        PE
C:\Program Files\360Safebox\GuardField.exe        PE
C:\Program Files\360Safebox\antispy.dll        PE
C:\Program Files\360Safebox\antispy.dll        PE
C:\Program Files\360Safebox\AntiAdwa.dll        PE
C:\Program Files\360Safebox\AntiAdwa.dll        PE
C:\Program Files\360Safebox\360safebox.exe        PE
C:\Program Files\360Safebox\360safebox.exe        PE
C:\Program Files\360safe\修复工具.exe        PE
C:\Program Files\360safe\修复工具.exe        PE
C:\Program Files\360safe\uninst.exe        PE
C:\Program Files\360safe\uninst.exe        PE
C:\Program Files\360safe\SoftMgr\SoftWareMgr.dll        PE
C:\Program Files\360safe\SoftMgr\SoftWareMgr.dll        PE
C:\Program Files\360safe\SoftMgr\SoftManager.exe        PE
C:\Program Files\360safe\SoftMgr\SoftManager.exe        PE
C:\Program Files\360safe\SoftMgr\esslibupdate.exe        PE
C:\Program Files\360safe\SoftMgr\esslibupdate.exe        PE
C:\Program Files\360safe\SoftMgr\Download\wrar380sc.exe        PE
C:\Program Files\360safe\SoftMgr\Download\wrar380sc.exe        PE
C:\Program Files\360safe\SoftMgr\Download\sogou_pinyin_36_4370.exe        PE
C:\Program Files\360safe\SoftMgr\Download\sogou_pinyin_36_4370.exe        PE
C:\Program Files\360safe\SoftMgr\Download\setupbox.exe        PE
C:\Program Files\360safe\SoftMgr\Download\setupbox.exe        PE
C:\Program Files\360safe\SoftMgr\360sfchk.dll        PE
C:\Program Files\360safe\SoftMgr\360sfchk.dll        PE
C:\Program Files\360safe\Shield\Install\360sandbox.exe        PE
C:\Program Files\360safe\Shield\Install\360sandbox.exe        PE
C:\Program Files\360safe\safemon\safemon.dll        PE
C:\Program Files\360safe\safemon\safemon.dll        PE
C:\Program Files\360safe\safemon\safekrnl.dll        PE
C:\Program Files\360safe\safemon\safekrnl.dll        PE
C:\Program Files\360safe\safemon\360tray.exe        PE
C:\Program Files\360safe\safemon\360tray.exe        PE
C:\Program Files\360safe\safeext.dll        PE
C:\Program Files\360safe\safeext.dll        PE
C:\Program Files\360safe\rptup.dll        PE
C:\Program Files\360safe\rptup.dll        PE
C:\Program Files\360safe\mphreport.dll        PE
C:\Program Files\360safe\mphreport.dll        PE
C:\Program Files\360safe\modules\infocust.dll        PE
C:\Program Files\360safe\modules\infocust.dll        PE
C:\Program Files\360safe\makereport.exe        PE
C:\Program Files\360safe\makereport.exe        PE
C:\Program Files\360safe\live.dll        PE
C:\Program Files\360safe\live.dll        PE
C:\Program Files\360safe\links\links.dll        PE
C:\Program Files\360safe\links\links.dll        PE
C:\Program Files\360safe\LeakCheck.dll        PE
C:\Program Files\360safe\LeakCheck.dll        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB957095-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB957095-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956841-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956841-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956803-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956803-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956391-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB956391-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB954211-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB954211-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953839-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953839-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953838-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953838-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953155-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB953155-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB952954-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB952954-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB952287-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB952287-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951978-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951978-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951830-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951830-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951748-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951748-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951698-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951698-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951376-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951376-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951072-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951072-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951066-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB951066-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950974-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950974-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950762-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950762-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950760-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950760-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950749-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950749-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950582-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB950582-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB948590-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB948590-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946648-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946648-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946627-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946627-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946501-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946501-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946026-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB946026-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB945553-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB945553-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944653-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944653-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944338-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944338-v2-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944043-v3-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB944043-v3-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943485-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943485-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943460-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943460-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943055-x86-CHS.exe        PE
C:\Program Files\360safe\hotfix\WindowsXP-KB943055-x86-CHS.exe        PE

CuteK 发表于 2008-11-5 09:03

PE 文件是系统中正常的文件格式, 检测这个是插件扫描工具的例子

a20050031 发表于 2008-11-14 08:45

千福 发表于 2008-12-15 11:24

支持

lxsasd 发表于 2009-3-17 01:44

顶一下楼主

lxsasd 发表于 2009-3-17 01:54

C:\WINDO?       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\sound.drv       
C:\WINDOWS\system32\sound.drv       
C:\WINDOWS\system32\sound.drv       
C:\WINDOWS\system32\sound.drv       
C:\WINDOWS\system32\sound.drv       
       
C:\WINDOWS\system32\dllcache\ieakeng.dll       
C:\WINDOWS\system32\DirectX\Dinput\ms56_7.png       
C:\WINDOWS\system32\DirectSpy.dll       
       
       
       
       
       
       
C:\WINDOWS\Cursors\wait_rm.cur       
C:\Program Files\Opera\classes\opera.policy       
       
这些是什么,应该删除么

zengxingding 发表于 2009-6-7 00:35

看贴不回~不回不看贴~!!

avengert 发表于 2009-6-8 10:35

C:\WINDO ?       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\wbem\AutoRecover\701B705ED7DF100F88D5BC4A595E938D.mof       
C:\WINDOWS\system32\wbem\AutoRecove ...
lxsasd 发表于 2009-3-17 01:54 https://bbs.antiy.cn/images/common/back.gif

以上文件为系统正常文件,建议:请不要删除。在删除前请备份。

liveck 发表于 2009-6-8 16:22

垃圾,超级垃圾.缓冲区溢出自C出现后就有,从没有人写出一个通用的扫描工具.你的一个24KB的文件就能扫描所有的漏洞了.微软早就黄了,你可以称为微软杀手了,哈哈.缓冲益处区漏洞必须分析漏洞可能产生位置,对 ...
a20050031 发表于 2008-11-14 08:45 https://bbs.antiy.cn/images/common/back.gif
提供了一个架构,方便大家自己写着玩而已

贾代儒 发表于 2009-6-16 15:57

支持!

imcz 发表于 2009-6-24 20:21

支持!

原号忘记了 发表于 2009-8-28 17:25

好,顶一下

bjhgug 发表于 2010-9-9 14:07

哇好多了看看
页: [1] 2 3 4
查看完整版本: 插件式溢出文件扫描工具