ÔÚÉøÍ¸²âÊÔÖÐ×î½ôÕŴ̼¤µÄʱ¼ä£¬Äª¹ýÓÚ¹¥»÷Õ߷Ѿ¡Ç§ÐÁÍò¿àÖÕÓڳɹ¦»ñÈ¡µ½Ä³Ì¨»úÆ÷µÄ¿ØÖÆÈ¨ÏÞÖ®ºó¡£´Ëʱ¹¥»÷ÕßµÄÈκÎÐÐΪ»ò¶¯×÷£¬¶¼ÓпÉÄܱ©Â¶×Ô¼º´Ó¶øÈ÷ÀÊØ·½²ì¾õ£¬½ø¶øÍ¨¹ý¹Ü¿Ø»òÐÞ²¹Â©¶´µÄ·½Ê½Èù¥»÷Õß֮ǰµÄŬÁ¦¶¼¸¶Ö®¶«Á÷¡£ÄÇôÏÔÈ»£¬³öÓÚÍçÇ¿µÄ¡°ÇóÉúÒâÖ¾¡±£¬¹¥»÷ÕßÔڳɹ¦µÇÈëϵͳºó»á²»ÔñÊֶεÄÁôϺóÃÅ£¬·½±ãºóÐøµÄÉøÍ¸²½Ö裬¶øÕâÒ»²Ù×÷Ò²±»³ÆÎªÈ¨ÏÞά³Ö¡£
±¾ÆÚ»Æ½ð³Ç»Æ½ð³Ç¹ÙÍøÊµÑéÊÒ½«¸ø´ó¼Ò½éÉÜÔÚWindows»·¾³Ï¹¥»÷Õß³£ÓõÄȨÏÞά³Ö¼¼ÇÉ¡£
TOP1WindowsÓòÄÚ³£¼ûµÄ³Ö¾Ã»¯ºóÃÅ·½·¨
²»Í¬ÓÚLinuxϵͳ£¬WindowsÒ»Ö±ÒÔÀ´¶¼Êǹ¥»÷ÕßÇàíùµÄ¹¥»÷¶ÔÏó£¬Ôݲ»Ìá¹¥»÷Óò¿ØÖ÷»úµÄÓ°ÏìÖ®´ó£¬µ¥¾Íһ̨ÆÕͨµÄWindows»úÆ÷À´Ëµ£¬ÓÉÓÚÆäÌṩÁË´óÁ¿µÄ¹¦ÄÜÓë·þÎñ£¬µ¼Ö¹¥»÷ÕßÔÚWindows»·¾³ÏµÄȨÏÞά³Ö·½Ê½²ã³ö²»Çî¡£ÏÂÃæÁоÙÁËһЩ³£¼ûµÄȨÏÞά³Ö·½Ê½£¬¸²¸Ç²»µ½Ö®´¦»¹Çë°üº¬£º
WindowsϵͳÒþ²ØÕË»§
Windows¼Æ»®ÈÎÎñºóÃÅ
Windows·þÎñºóÃÅ
WindowsÆô¶¯ÏîºóÃÅ
ShiftÕ³Öͽ¡ºóÃÅ£¨¸¨Öú¾µÏñ½Ù³Ö£©
TOP2WindowsϵͳÒþ²ØÕË»§
ϵͳÒþ²ØÕË»§ÊÇÒ»ÖÖ×îΪ¼òµ¥ÓÐЧµÄȨÏÞά³Ö·½Ê½£¬Æä×ö·¨¾ÍÊÇÈù¥»÷Õß´´½¨Ò»¸öеľßÓйÜÀíԱȨÏÞµÄÒþ²ØÕË»§£¬ÒòΪÊÇÒþ²ØÕË»§£¬ËùÒÔ·ÀÊØ·½ÊÇÎÞ·¨Í¨¹ý¿ØÖÆÃæ°å»òÃüÁîÐп´µ½Õâ¸öÕË»§µÄ¡£¾ßÌå²½ÖèÈçÏ£º
1. ¹¥»÷Õß¿ØÖÆÄ³Ì¨»úÆ÷£¬²¢Ö´ÐÐÌí¼ÓÓû§Ö¸Áî
Netuser hacker$ 123456 /add #Ìí¼Óhacker$Òþ²ØÓû§
Netlocalgroup administrators hacker$ /add #½«hacker$Óû§Ìí¼Ó½ø¹ÜÀíÔ±×éÖÐ

´ËʱËäȻʹÓÃÃüÁîÐÐÎÞ·¨¿´µ½hacker$Óû§£¬µ«ÊÇͨ¹ý¿ØÖÆÃæ°åÒÀÈ»»¹ÊÇ¿ÉÒÔ¿´µ½hacker$ÕË»§´æÔڵġ£ÎªÁ˸üºÃµÄÒþ²ØÐ½¨µÄÕË»§£¬»¹ÐèÒª½øÐÐÈçϲÙ×÷¡£
2. ÐÞ¸Ä×¢²á±íÎļþ
Ê×ÏÈ´ò¿ª×¢²á±í±à¼Æ÷£¬ÕÒµ½HKEY_LOCAL_MACHINESAMSAM£¬µã»÷ÓÒ¼ü£¬Ñ¡Ôñ¡°È¨ÏÞ¡±£¬½«AdministratorÓû§µÄȨÏÞ£¬ÉèÖóɡ°ÍêÈ«¿ØÖÆ¡±£¬È»ºóÖØÐ´ò¿ª×¢²á±í£¬È·±£¿ÉÒÔ¿´µ½SAM·¾¶ÏµÄÎļþ¡£

Æä´ÎǰÍùSAM/Domains/Account/Users/Names´¦£¬Ñ¡ÔñAdministratorÓû§£¬ÔÚÓÒ²àµÄ¼üÖµ´¦¿ÉÒÔÕÒµ½¶ÔÓ¦µÄÖµÈç0x1f4£¬È»ºó´Ó×ó²àµÄUsersĿ¼Ï¿ÉÒÔÕÒµ½¶ÔÓ¦µÄÎļþ¡£

È»ºó´Ó¶ÔÓ¦µÄ000001F4ÎļþÖн«¼üÖµ¶ÔFµÄÖµ¸´ÖƳöÀ´¡£È»ºóͬÀíÕÒµ½Òþ²ØÕË»§hacker$Ëù¶ÔÓ¦µÄÎļþ£¬²¢½«´ÓAdministratorÎļþÖи´ÖƳöÀ´µÄFÖµÕ³Ìù½øhacker$ÎļþÖС£

×îºó½«hacker$ºÍ000003EE´Ó×¢²á±íÖÐÓÒ¼üµ¼³ö£¬²¢É¾³ýhacker$Óû§£¬È»ºó½«¸Õ¸Õµ¼³öµÄÁ½¸öÎļþÖØÐµ¼Èë½ø×¢²á±íÖм´¿ÉʵÏÖhackerÓû§µÄÒþ²Ø¡£


TOP3Windows¼Æ»®ÈÎÎñºóÃÅ
¼Æ»®ÈÎÎñÊǾ³£±»¹¥»÷ÕßÄÃÀ´ÀûÓõĿØÖƵ㣬¼Æ»®ÈÎÎñ¿ÉÒÔÈÃÄ¿±êÖ÷»úÔÚÌØ¶¨µÄʱ¼äÖ´ÐÐÎÒÃÇÔ¤ÏÈ×¼±¸µÄºóÃųÌÐò´Ó¶ø°ïÖúÎÒÃǽøÐÐȨÏÞά³Ö¡£
Ê×ÏÈÀûÓÃMSFÉú³ÉÒ»¸öEXEÀàÐ͵ĺóÃÅľÂí¡£

Æä´Î½«Éú³ÉµÄºóÃÅľÂíÉÏ´«µ½Ä¿±ê»úÄÚ£¬È»ºóÔÚÄ¿±ê»úÄÚÖ´ÐÐÒÔÏÂÖ¸Á´´½¨Ò»¸öbackdoor¼Æ»®ÈÎÎñ£¬Ã¿Ò»·ÖÖÓÖ´ÐÐÒ»´Îshell.exe¡£

ÔÚ¹¥»÷»úÉϼàÌýÏà¹ØµÄ¶Ë¿Ú9999£¬µÈ´ý1·ÖÖÓ×óÓÒ½Óµ½Ä¿±êµÄ·´µ¯shell¡£

TOP4¡¢Windows·þÎñºóÃÅ
ÔÚWindowsϵͳÖл¹ÓÐÒ»¸öÖØÒªµÄ»úÖÆ£¬¾ÍÊÇ·þÎñ¡£Í¨³£´ó²¿·ÖµÄ·þÎñ¶¼ÓµÓÐSYSTEMȨÏÞ£¬Èç¹û¹¥»÷ÕßÀûÓÃWindowsµÄ·þÎñ»úÖÆ´´½¨Ò»¸öºóÃÅ·þÎñ£¬ÄÇôÕâ¸öºóÃŽ«±ÈÒ»°ãµÄ³Ö¾Ã»¯·½·¨¸üΪǿ½¡¡£Ê×ÏÈÓ¦¸Ã½«ºóÃųÌÐòÉÏ´«½üÄ¿±ê»úÄÚ£¬È»ºóÖ´ÐÐÒÔÏÂÃüÁ
sccreate ¡°Backdoor¡± binpath= ¡°C:UsersAdministratorDesktopshell.exe¡±
scdescription "Backdoor" "description" #ÉèÖ÷þÎñµÄÃèÊö×Ö·û´®
scconfig "backdoor" start= auto #ÉèÖÃÕâ¸ö·þÎñΪ×Ô¶¯Æô¶¯
netstart "backdoor" #Æô¶¯·þÎñ

ÔÚ¹¥»÷»úÉϼàÌý¶Ë¿Ú9999£¬ÂíÉϾͽÓÊÕµ½Ä¿±ê»úµ¯»ØÀ´µÄshell£¬ÇÒÄ¿±ê»úÿ´ÎÖØÆô¶¼»áÆô¶¯backdoor·þÎñ¡£

TOP5¡¢WindowsÆô¶¯ÏîºóÃÅ
WindowsÆô¶¯ÏîºóÃÅÒ²Êǹ¥»÷Õß³£ÓõÄȨÏÞά³Ö·½Ê½£¬´óÌåÉÏ¿ÉÒÔ·ÖΪÁ½ÖÖ¡£Ò»ÖÖÊÇÖØÆôµçÄÔʱ×ÔÆô¶¯ºóÃųÌÐòʵÏÖȨÏÞά³Ö£»ÁíÒ»ÖÖÊǵã»÷ijӦÓᢷþÎñ¡¢³ÌÐòʱ×ÔÆô¶¯ºóÃųÌÐòʵÏÖȨÏÞά³Ö¡£
¿ªÊ¼²Ëµ¥ÊÇWindows¼ÆËã»úÔÚÆô¶¯Ê±¶¼»á·ÃÎʵ½µÄ·¾¶£¬¿ªÊ¼²Ëµ¥Æô¶¯ÏîָʾÁËÆô¶¯Îļþ¼ÐµÄλÖ㬾ßÌåλÖÃÈçÏ£º
C:UsersAdministratorAppDataRoamingMicrosoftWindowsStartMenuProgramsStartup
Ïà¹ØµÄ¼üÖµÈçÏ£º
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerUser Shell Folders
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerShell Folders
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerShell Folders
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerUser Shell Folders

ÔÙÖØÆôÖ®ºó£¬Ëù·ÅÖõĺóÃųÌÐò»á×Ô¶¯Æô¶¯£¬´Ó¶ø´ïµ½È¨ÏÞά³ÖÄ¿µÄ¡£

TOP6¡¢shiftÕ³Ìù¼üºóÃÅ
£¨¸¨Öú¹¦ÄܾµÏñ½Ù³Ö£©
ShiftÕ³ÖͼüÊǵ±Óû§Á¬°´5´Îshift¾Í»á×Ô¶¯µ¯³öµÄÒ»¸ö³ÌÐò£¬Æäʵ²»¹âÊÇÕ³Öͼü£¬»¹Óи÷ÖÖ¸¨Öú¹¦ÄÜ£¬ÕâÀศÖú¹¦Äܶ¼ÓµÓÐÒ»¸öÌØµã¾ÍÊǵ±Óû§Î´½øÐеǼʱҲ¿ÉÒÔ´¥·¢¡£ËùÒÔ¹¥»÷ÕߺÜÓпÉÄÜͨ¹ý´Û¸ÄÕâЩ¸¨Öú¹¦ÄܵÄÖ¸Ïò³ÌÐòÀ´´ïµ½È¨ÏÞά³ÖµÄÄ¿µÄ¡£
ÒÔÕ³Öͼü¾ÙÀý£¬Õ³ÖͼüµÄÆô¶¯³ÌÐòÔÚCÅ̵ÄWindows/system32Ŀ¼ÏÂΪsethc.exe¡£ËùÒÔÎÒÃÇ´ò¿ª×¢²á±í£¬¶¨Î»µ½ÒÔÏ·¾¶£º
HKEY_LOCAL_MACHINE SOFTWARE Microsoft Windows NT CurrentVersion Image File ExecutionOption

ÔÚĿ¼ÖÐн¨Ò»¸ösethc.exeµÄ×ÓÏ²¢Ìí¼ÓÒ»¸öмüdebugger£¬debuggerµÄ¶ÔÓ¦¼üֵΪºóÃÅľÂíµÄ·¾¶£¬ÕâÀïÎÒÓÃcmd·¾¶´úÌæÒ»Ï¡£

ÔÚδµÇ½µÄÇé¿öÏ£¬Á¬°´5´Îshift¼´¿É´ò¿ªcmd³ÌÐò