windows 安全系列02-恶意隐藏文件风险

版权声明:本文为博主原创文章,未经博主允许不得转载,否则将追究法律责任。 https://blog.csdn.net/qq_29277155/article/details/85105876

0x00 前言

     windows文件夹和windows文件是我们经常接触到,但是我们经常会遇到这么一种恶意操作,强制把文件夹属性设置成隐藏属性并且变成灰色,这就导致我们在图形化界面无法对文件和文件夹进行操作。

0x01 分析

当我们遇到文件夹被恶意隐藏,并且通过图形化界面看到文件夹的属性已经被锁定成隐藏,并且无法更改,我们这时需要把进行dos界面进行操作方可

0x02 问题解决

 我们可以新建bat脚本,并且命名为folderUnhide.bat, 尝试把这段代码复制并且粘贴到这个脚本里面,然后放置到我们怀疑隐藏了文件夹或者文件的路径下面,双击运行即可。

:: To disclosure the folders 
:: Author : ym20111
:: Date: 2018-12-19
@echo off
echo ==================================================================
echo ==============================================================
echo ==========================================================
echo please waiting for a while, you can go have a  tea, return later
echo It is working for your purpose
echo ...............................
echo .............
echo ....
for /f "delims=" %%i in ('dir /ah /s/b') do attrib "%%i" -s -h
echo it done!, please close it
echo Goodbye
pause
del %0

0x03 问题复现

 当然我们做安全工程师,有时候也可以用这个来恶搞一下小白用户,具体代码如下:

:: To hide the folders 
:: Author : ym20111
:: Date: 2018-12-19
@echo off
echo ==================================================================
echo ==============================================================
echo ==========================================================
echo please waiting for a while, you can go have a  tea, return later
echo It is working for your purpose
echo ...............................
echo .............
echo ....
for /F "delims=" %%i in ('dir /A /S/B') do attrib "%%i" +S +H
echo it done!, please close it
attrib FolderHide.bat -S -H
del %0
pause

当我们运行这个 FolderHide.bat ,就会把当前文件夹及其子目录下所有文件夹和文件都隐藏起来,这样的操作对于小白用户来说也是挺头痛的,当然这也是一个windows安全风险问题。

欢迎大家分享更好的思路,热切期待^^_^^ !

猜你喜欢

转载自blog.csdn.net/qq_29277155/article/details/85105876