绕过KAV6检测shellcode的cmd.ex­e输入输出重定向

来源:互联网 发布:四川省畜牧兽医大数据 编辑:程序博客网 时间:2024/04/30 17:35
As I got from english words, you want to do reverse shell on a machine
with Kaspersky AV installed. Kaspersky installs kernel hooks on
NTCreateprocessEx  and NTCreateProcess and detects redirected input/
output for the processes. Even using a socket instead of a pipe wont
help. You should implement a custom reverse shell that sends output to
a temp file and submits to the remote side or fix kaspersky hooks ;)  
原创粉丝点击