好像是以前读书时记的笔记,说来惭愧,读的哪一本书现在已经记不清了,后门技术也学得不怎么样,但想来也不是毫无收获,默默地在此谢过作者。
典型的TCP套接字程序
/*
* 服务器端 server.cpp
*/
#include<stdio.h>
#include<winscok.h>
//使用前需要包含库ws2_32.lib
#pragma comment(lib,"ws2_32")
#define MYPORT 1234//监听端口
#define BACKlog 10//最大连接数
int main()
{
SOCKET sockfd,new_fd;//套接字
struct sockaddr_in my_addr;//本地地址信息
struct sockaddr_in my_addr;//客户地址信息
WSADATA ws;
WSAStartup(MAKEWORD(2,2),&WS);
if((sockfd=socket(AF_INET,SOCK_STREAM,0))=INVALID_SOCKET)
{
exit(0);
}
my_addr.sin_family=AF_INET;
my_addr.sin_port=htons(MYPORT);
my_addr.sin_addr.S_un.S_addr=INADDR_ANY;
if(bind(sockfd,(struct sockaddr*)&my_addr,sizeof(struct sockaddr))==-1)
{
closesocket(sockfd);
exit(0);
}
if(listen(sokfd,BACKLOG)==SOCKET_ERROR)
{
closesocket(sockfd);
exit(0);
}
int sin_size=sizeof(struct sockaddr_in);
if((new_fd=accept(sockfd,(struct sockaddr*)&their_addr,&sin_size)) ==INVALID_SOCKET)
{
closesocket(sockfd);
exit(0);
}
printf("\nRequest Has Been Accept!\n\n");
printf("\tClient IP: %s\n",inet_ntoa(their_addr.sin_port));
char Buffer[MAX_PATH];
int num=0;
num=recv(new_fd,Buffer,MAX_PATH,0);
Buffer[num - 1]='\0';
printf("\nMsg:%s\n",Buffer);
closesocket(sockfd);
closesocket(new_fd);
return 0;
}
/*
* 客户端 client.cpp
*/
#include<stdio.h>
#include<winsock.h>
#pragma comment(lib,"ws2_32")
#define PORT 1234
int main(int argc,char *argv[])
{
SOCKET sockfd;
struct sockaddr_in their_addr;
if(argc!=2)
{
printf("Useage:Client.exe<IP Address>\n");
return -1;
}
WSADATA ws;
WSAStartup(MAKEWORD(2,2),&ws);
if((sockfd=socket(AF_INET,SOCK_STREAM,0))==INVALID_SOCKET)
{
return -1;
}
their_addr.sin_family=AF_INET;
their_addr.sin_port=htons(PORT);
their_addr.sin_addr.S_un.S_addr=inet_addr(argv[1]);
if(connect(sockfd,(struct sockaddr*)&their_addr,sizeof(struct sockaddr))==SOCKET_ERROR)
{
closesocket(sockfd);
return -1;
}
char Buffer[MAX_PATH];
int num=0;
gets(Buffer);
num=send(sockfd,Buffer,MAX_PATH,0);
closesocket(sockfd);
return 0;
}
自身复制程序
将程序自身复制到“启动”文件夹的测试代码
#include<windows.h>
#include<stdio.h>
int main()
{
char FileName[MAX_PATH];
char TempPath[MAX_PATH];
char TempBuff[MAX_PATH];
GetModuleFileName(NULL,FileName,sizeof(FileName));
GetSystemDirectory(TempPath,sizeof(TempPath));
sprintf(TempBuff,"%c%c\\Docments and Settings\\All Users\\[开始] 菜单\\程序\\启动\\Test.exe",TempPath[0],TempPath[1]);
CopyFile(FileName,TempBuff,TRUE);
return 0;
}
作用是将自身复制到用户"All User"的“启动”文件夹,并改名为Test.exe
Win32服务程序
一般由4个部分组成:
main()
仅负责创建服务分派表并启动控制分派机制
void main()
{
SERVICE_TABLE_ENTRY ServTable[2];
//服务名称
ServTable[0].lpServiceName="Test";
//服务入口函数
ServTable[0].lpServiceProc=(LPSERVICE_MAIN_FUNCTION)ServiceMain;
ServTable[1].lpServiceName=NULL;
ServTable[1].lpServiceProc=NULL;
StartServiceCtrlDispatcher(ServTable);
}
ServiceMain()
首先注册一个Handler来处理控制程序和控制面板以及服务程序的控制要求,如启动,停止,暂停,重启等;
其次,实现所需要的功能,通常是通过创建新的工作线程实现。
需要先声明
SERVICE_STATUS ServiceStatus;
SERVICE_STATUS_HANDLE hStatus;
主体
VOID WINAPI ServiceMain(DWORD dwArgc,LPTSTR *lpszArgv)
{
DWORD result=0;
DWORD specificError=0xFFFFFFFF;
//状态设置
ServiceStatus.dwServiceType=SERVICE_WIN32;
ServiceStatus.dwCurrentState=SERVICE_START_PENDING;
ServiceStatus.dwControlsAccepted=SERVICE_ACCEPT_STOP |
SERVICE_ACCEPT_PAUSE_CONTINUE | SERVICE_ACCEPT_SHUTDOWN;
ServiceStatus.dwWin32ExitCode=0;
ServiceStatus.dwCheckPoint=0;
ServiceStatus.dwServiceSpecificExitCode=0;
ServiceStatus.dwWaitHint=0;
//注册控制函数
hStatus=RegisterServiceCtrlHandler("ServiceName",(LPHANDLER_FUNCTION)ServiceHandler);
if(!hStatus)
return;
result=GetLastError();
if(result!NO_ERROR)
{//如果出错,将其重设为停止状态
ServiceStatus.dwCurrentState=SERVICE_STOPPED;
ServiceStatus.dwCheckPoint=0;
ServiceStatus.dwWaitHint=0;
ServiceStatus.dwWin32ExitCode=result;
ServiceStatus.dwServiceSpecificExitCode=specificError;
SetServiceStatus(hStatus,&ServiceStatus);
return;
}
//没有错误就继续运行
ServiceStatus.dwCurrentState=SERVICE_RUNNING;
ServiceStatus.dwCheckPoint=0;
ServiceStstus.dwWaitHint=0;
//设置服务状态
SetServiceStatus(hStatus,&ServiceStatus);
//创建线程执行特定功能
HANDLE hThread=CreateThread(NULL,0,MainProc,NULL,0,NULL);
if(hThread==NULL)
return;
}
Handler()
是真正实现启动、停止、重启等功能的函数,该函数的名称并非固定。
只要收到一个控制消息,就会根据消息的要求重新设置服务的运行状态。
VOID WINAPI ServiceHandler(DWORD fdwControl)
{
switch(fdwControl)
{
case SERVICE_CONTROL_PAUSE:
ServiceStatus.dwCurrentState=SERVICE_PAUSED;
break;
case SERVICE_CONTROL_CONTINUE:
ServiceStatus.dwCurrentState=SERVICE_PAUSED;
break;
case SERVICE_CONTROL_STOP:
case SERVICE_CONTROL_SHUTDOWN:
ServiseStatus.dwCurrentState=SERVICE_STOPPED;
ServiseStatus.dwWin32ExitCode=0;
ServiseStatus.dwCheckPoint=0;
ServiseStatus.dwWaitHint=0;
SetServiceStatus(hStatus,&ServiceStatus);
return;
case SERVICE_CONTROL_INTERROGATE:
break;
default:
break;
}
//重设服务状态
SetServiceStatus(hStatus,&ServiceStatus);
return;
}
MyWork()
真正实现了服务的功能,格式固定,名称不固定。
END
这篇博客介绍了如何在Windows环境下编写TCP套接字程序,包括服务器端和客户端的实现,以及展示了如何创建一个简单的自身复制程序,将其放置在用户启动文件夹中。此外,还详细讲解了Win32服务程序的组成部分和服务生命周期,包括服务的启动、停止和控制处理函数。
4135

被折叠的 条评论
为什么被折叠?



